ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th)

2026-05-20T13:23:48Zb4a9cb8834f01eb33cc37c3f1d0a169fbb563629b96b194e274a1c22f179828c
CI/CDCheckmarxJenkinsMini Shai-HuludOutlookPyPISANS ISCTeamPCPemail-securitylink-preview-bypassmalwaremalware-signaturesnpmpackage-managerphishingplugin compromisesupply-chainthreat-intelwebsite-fraudworm

What happened

SANS ISC diary highlights (mid-May 2026) covering multiple operational and research items. Key alert: TeamPCP supply‑chain campaign remains active through 2026‑05‑17 with an officially confirmed compromise of a Checkmarx Jenkins plugin and a new self‑spreading “Mini Shai‑Hulud” worm propagating across npm and PyPI — significant supply‑chain and package‑manager risk to CI/CD ecosystems. Other posts describe a simple bypass of Outlook’s link‑preview in the Junk folder that exposes true link destinations, the appearance of new malware libraries necessitating updated signatures, a deep‑dive into网站

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
b4a9cb8834f01eb33cc37c3f1d0a169fbb563629b96b194e274a1c22f179828c
Enrichment time
2026-05-20T13:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.