ISC Stormcast For Tuesday, June 9th, 2026 https://isc.sans.edu/podcastdetail/9964, (Tue, Jun 9th)

2026-06-09T13:23:49Zd83d6fec951c1f457842ba6a02d3ecabb4276df1d54114f5d4a40b29b5e0046f
APICoreutilsJPEGMSIMicrosoftMini Shai-HuludSOAPSVGTeamPCPWeTransferWindowsmalwarephishingscanningsteganographysupply-chainsupply-chain-compromiseswagger.json

What happened

Collection of SANS ISC diaries (early June 2026) covering active and evolving threats: continued tracking of the TeamPCP supply-chain campaign and proliferation of the Mini Shai‑Hulud framework (now public and adopted by other actors), renewed malicious use of images (MSI‑branded payloads hidden in JPEGs delivered via WeTransfer), a surge in phishing that delivers malicious SVG files, ongoing internet scans for swagger.json endpoints and commentary on SOAP/API misconfigurations, and notes on Microsoft Coreutils for Windows. The TeamPCP supply‑chain activity has attracted formal government关注, و

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
d83d6fec951c1f457842ba6a02d3ecabb4276df1d54114f5d4a40b29b5e0046f
Enrichment time
2026-06-09T13:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.