ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th)
2026-05-20T13:23:48Z•b4a9cb8834f01eb33cc37c3f1d0a169fbb563629b96b194e274a1c22f179828c
CI/CDCheckmarxJenkinsMini Shai-HuludOutlookPyPISANS ISCTeamPCPemail-securitylink-preview-bypassmalwaremalware-signaturesnpmpackage-managerphishingplugin compromisesupply-chainthreat-intelwebsite-fraudworm
What happened
SANS ISC diary highlights (mid-May 2026) covering multiple operational and research items. Key alert: TeamPCP supply‑chain campaign remains active through 2026‑05‑17 with an officially confirmed compromise of a Checkmarx Jenkins plugin and a new self‑spreading “Mini Shai‑Hulud” worm propagating across npm and PyPI — significant supply‑chain and package‑manager risk to CI/CD ecosystems. Other posts describe a simple bypass of Outlook’s link‑preview in the Junk folder that exposes true link destinations, the appearance of new malware libraries necessitating updated signatures, a deep‑dive into网站
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- b4a9cb8834f01eb33cc37c3f1d0a169fbb563629b96b194e274a1c22f179828c
- Enrichment time
- 2026-05-20T13:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.