ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)

2026-05-31T07:23:47Zb3ceb4047524b714c24c2a2c806c772ef7cb5fb29643ebc7dacc1f97ae3cf833
akiracredential-stealerdshieldfirewall-logsforensicsgithub-compromiseincident-responsekibanamalwaremicrosoft-accesspackage-ecosystemsphishingpython-sdkransomwaresensor-datasoftware-supply-chainsupply-chainteampcptrojanized-sdkvbavba-macrosweb-impersonationwindows-event-logs

What happened

The ISC SANS diary (late May 2026) aggregated several security write-ups and podcasts: a forensic-focused reconstruction of an Akira ransomware kill chain emphasizing early detection by correlating perimeter firewall and Windows event logs; a TeamPCP supply‑chain campaign analysis showing trojanization across three package ecosystems, compromise of GitHub internal code, and a trojanized Microsoft-published Python SDK (plus apparent open-sourcing of the attackers’ framework); a possible ACR credential stealer delivered via a page impersonating Claude; an analysis of one year of files uploadedto

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
b3ceb4047524b714c24c2a2c806c772ef7cb5fb29643ebc7dacc1f97ae3cf833
Enrichment time
2026-05-31T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th) · Baitaphish