ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th)

2026-05-28T19:24:06Z8c8a8ae7ae0165c22ae5c9c7ca5531c19c00ba4bc6d9c3303a473c9e32d36d14
ACR-stealerAkiraGitHubMicrosoft-AccessPython-SDKTeamPCPVBAWindows-event-logsWiresharkcredential-theftforensicsincident-responselog-correlationmalware-analysisperimeter-firewallphishingransomwarered-teamsoftware-supply-chainsupply-chainthreat-inteltrainingtrojanized-packagevulnerability

What happened

SANS ISC diary entries (late May 2026) covering multiple active threats and analyst resources: a forensic-oriented write-up on Akira ransomware that emphasizes answering intrusion questions by correlating perimeter firewall logs with Windows event logs (focus on pre-encryption activity); reporting on the TeamPCP supply-chain campaign that trojanized packages across multiple ecosystems — including a Microsoft-published Python SDK — and released its own framework on GitHub; an observed webpage impersonating Claude potentially used to steal Azure Container Registry (ACR) credentials; a note that

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
8c8a8ae7ae0165c22ae5c9c7ca5531c19c00ba4bc6d9c3303a473c9e32d36d14
Enrichment time
2026-05-28T19:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.