ISC Stormcast For Tuesday, June 9th, 2026 https://isc.sans.edu/podcastdetail/9964, (Tue, Jun 9th)
2026-06-09T13:23:49Z•d83d6fec951c1f457842ba6a02d3ecabb4276df1d54114f5d4a40b29b5e0046f
APICoreutilsJPEGMSIMicrosoftMini Shai-HuludSOAPSVGTeamPCPWeTransferWindowsmalwarephishingscanningsteganographysupply-chainsupply-chain-compromiseswagger.json
What happened
Collection of SANS ISC diaries (early June 2026) covering active and evolving threats: continued tracking of the TeamPCP supply-chain campaign and proliferation of the Mini Shai‑Hulud framework (now public and adopted by other actors), renewed malicious use of images (MSI‑branded payloads hidden in JPEGs delivered via WeTransfer), a surge in phishing that delivers malicious SVG files, ongoing internet scans for swagger.json endpoints and commentary on SOAP/API misconfigurations, and notes on Microsoft Coreutils for Windows. The TeamPCP supply‑chain activity has attracted formal government关注, و
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- d83d6fec951c1f457842ba6a02d3ecabb4276df1d54114f5d4a40b29b5e0046f
- Enrichment time
- 2026-06-09T13:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.