ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th)

2026-05-28T07:23:46Zbc56851ddc10dbb00e1de54db6e636f654994a41529d38cc9ced5105826c9760
ACRAkiraGitHubMicrosoft-AccessTeamPCPVBAWiresharkcredential-stealerfirewall-logsforensicsphishingpython-sdkransomwaresupply-chaintrojanized-packagevulnerabilitywindows-event-logs

What happened

SANS ISC diary roundup (May 23–28, 2026) covering multiple security items: 1) Analysis guidance for reconstructing an Akira ransomware kill chain — emphasizes joining perimeter firewall logs with Windows event logs to determine initial access, lateral movement, and time-to-domain-admin before encryption. 2) TeamPCP supply-chain campaign activity through 2026-05-24 — actor trojanized a Microsoft-published Python SDK, expanded across three package ecosystems, and published tooling on GitHub (high-impact software supply-chain compromise). 3) Possible ACR credential stealer impersonating Claude —

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
bc56851ddc10dbb00e1de54db6e636f654994a41529d38cc9ced5105826c9760
Enrichment time
2026-05-28T07:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.