ISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970, (Fri, Jun 12th)

2026-06-13T01:23:46Zc49a4c2d7d857bc4509ecc33c6c4162c000c12cee6ba6fa2b68cde7f8cdb6337
chromiumcriticalcspcve-none-listededgeframe-ancestorsimage-embedded-payloadisc-sansmalwaremicrosoftmini-shai-huludmsiopen-source-toolingpatch-tuesdayphishingpodcastsecurity-headerssteganographystormcastsupply-chainteamPCPvulnerabilitiesweTransferx-frame-options

What happened

SANS ISC diary feed (June 5–12, 2026) covering multiple items: Microsoft June 2026 Patch Tuesday (204 patched vulnerabilities, 38 critical, 3 previously disclosed; six cloud-only issues; Microsoft Edge received 360 Chromium fixes); continued tracking of the TeamPCP supply-chain campaign through 2026-06-07 with US government attention and wider adoption of the open-sourced Mini Shai-Hulud framework; resurgence of an image-embedded MSI payload technique (MSI-branded background in JPEG distributed via phishing/WeTransfer); a repeat analysis of framing-protection headers (X-Frame-Options and CSP/`

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
c49a4c2d7d857bc4509ecc33c6c4162c000c12cee6ba6fa2b68cde7f8cdb6337
Enrichment time
2026-06-13T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.