ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)
2026-05-29T19:23:47Z•c542ed88e157ae61c5603de4f311dca72a6525a1237f2f6a2ca005d1e3dc1501
ACR-stealerAkiraDShieldGitHub-compromiseKibanaMicrosoft-AccessPythonTeamPCPVBAcredential-stealerfirewall-logsforensicsimpersonationincident-responsemacrosphishingransomwaresoftware-supply-chainsupply-chaintelemetrytrojanized-sdkwindows-event-logs
What happened
SANS ISC diary roundup (late May 2026) summarizing multiple posts: an analysis of one year of files uploaded to DShield sensors (Kibana queries; upload activity peaked Dec 2025–Feb 2026); a forensic walk-through reconstructing an Akira ransomware kill chain that emphasizes correlating perimeter firewall logs with Windows event logs to determine initial access and lateral movement; reporting on a TeamPCP supply-chain campaign that now operates across three package ecosystems, trojanized an officially Microsoft-published Python SDK, accessed GitHub internal code, and published its framework; a可能
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c542ed88e157ae61c5603de4f311dca72a6525a1237f2f6a2ca005d1e3dc1501
- Enrichment time
- 2026-05-29T19:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.