ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th)
2026-05-28T19:24:06Z•8c8a8ae7ae0165c22ae5c9c7ca5531c19c00ba4bc6d9c3303a473c9e32d36d14
ACR-stealerAkiraGitHubMicrosoft-AccessPython-SDKTeamPCPVBAWindows-event-logsWiresharkcredential-theftforensicsincident-responselog-correlationmalware-analysisperimeter-firewallphishingransomwarered-teamsoftware-supply-chainsupply-chainthreat-inteltrainingtrojanized-packagevulnerability
What happened
SANS ISC diary entries (late May 2026) covering multiple active threats and analyst resources: a forensic-oriented write-up on Akira ransomware that emphasizes answering intrusion questions by correlating perimeter firewall logs with Windows event logs (focus on pre-encryption activity); reporting on the TeamPCP supply-chain campaign that trojanized packages across multiple ecosystems — including a Microsoft-published Python SDK — and released its own framework on GitHub; an observed webpage impersonating Claude potentially used to steal Azure Container Registry (ACR) credentials; a note that
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 8c8a8ae7ae0165c22ae5c9c7ca5531c19c00ba4bc6d9c3303a473c9e32d36d14
- Enrichment time
- 2026-05-28T19:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.