ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)
2026-05-31T07:23:47Z•b3ceb4047524b714c24c2a2c806c772ef7cb5fb29643ebc7dacc1f97ae3cf833
akiracredential-stealerdshieldfirewall-logsforensicsgithub-compromiseincident-responsekibanamalwaremicrosoft-accesspackage-ecosystemsphishingpython-sdkransomwaresensor-datasoftware-supply-chainsupply-chainteampcptrojanized-sdkvbavba-macrosweb-impersonationwindows-event-logs
What happened
The ISC SANS diary (late May 2026) aggregated several security write-ups and podcasts: a forensic-focused reconstruction of an Akira ransomware kill chain emphasizing early detection by correlating perimeter firewall and Windows event logs; a TeamPCP supply‑chain campaign analysis showing trojanization across three package ecosystems, compromise of GitHub internal code, and a trojanized Microsoft-published Python SDK (plus apparent open-sourcing of the attackers’ framework); a possible ACR credential stealer delivered via a page impersonating Claude; an analysis of one year of files uploadedto
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- b3ceb4047524b714c24c2a2c806c772ef7cb5fb29643ebc7dacc1f97ae3cf833
- Enrichment time
- 2026-05-31T07:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.