ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)
2026-05-31T01:23:46Z•ac8d4308b62b0d42b75bda4ba6ad1c1789129b1cac5fb5379d68b9f27dc466c1
AkiraDShieldGitHubMicrosoft-AccessTeamPCPVBAcredential-stealerforensicsmalicious-webpageperimeter-logsphishingpython-sdkransomwaresoftware-supply-chainsupply-chaintelemetrytrojanized-packageswindows-event-logs
What happened
SANS ISC diary digest (late May 2026) covering multiple security topics: forensic reconstruction of an Akira ransomware kill chain using perimeter and Windows event logs; analysis of a year of files uploaded to DShield sensors (local and cloud) showing seasonal upload trends and most-uploaded threats; ongoing TeamPCP supply-chain campaign that trojanized packages across three ecosystems, reached GitHub internals and an officially Microsoft-published Python SDK; a reported phishing/malicious page impersonating the Claude service delivering a potential stealer; and notes on Microsoft Access VBA/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- ac8d4308b62b0d42b75bda4ba6ad1c1789129b1cac5fb5379d68b9f27dc466c1
- Enrichment time
- 2026-05-31T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.