ISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970, (Fri, Jun 12th)
2026-06-14T19:23:45Z•e4407271cce2ff94e31b679fe2fb9e0ab3a7185411171ff86c8241f1e98839f4
chromiumcspedgemalwaremicrosoftmini-shai-huludmsi-branded-payloadpatch-tuesdayphishingsecurity-headerssteganographysupply-chainteampcpthreat-actor-activityvulnerabilitieswetransferx-frame-options
What happened
SANS Internet Storm Center digest (June 5–12, 2026): Microsoft’s June 2026 Patch Tuesday fixes 204 vulnerabilities (38 rated critical, 3 previously disclosed) and bundles 360 Chromium fixes into Edge. Ongoing TeamPCP supply-chain campaign continues to escalate—U.S. government attention and the open‑sourcing of the Mini Shai‑Hulud framework have broadened attacker access. A renewed malware delivery technique embeds payloads in MSI‑branded JPEG backgrounds (phishing email with WeTransfer link observed). Analysis was published on changes in adoption of framing-protection headers (X-Frame-Options,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- e4407271cce2ff94e31b679fe2fb9e0ab3a7185411171ff86c8241f1e98839f4
- Enrichment time
- 2026-06-14T19:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.