YARA-X 1.17.0 Release, (Sun, May 31st)

2026-05-31T19:23:46Zf373736b04fb333b8a59f315ad2d30043b6063e14f835c3ca5e6524090e7f9ff
ACRAkira ransomwareDShieldGitHubISC StormcastMicrosoft AccessPythonTeamPCPVBAWindows event logsYARAYARA-Xbugfixcredential-stealerkill-chainlog-analysispackage-ecosystemsperformanceperimeter-firewallphishingpodcastransomwaresupply-chaintelemetrytrojanized SDK

What happened

Collection of SANS ISC diary entries (late May 2026) covering: YARA-X 1.17.0 release (performance improvements + one bugfix); analysis of a year of files uploaded to DShield sensors showing a winter peak (Dec 2025–Feb 2026); forensic guidance on reconstructing Akira ransomware kill chains by correlating perimeter firewall and Windows event logs; TeamPCP supply-chain campaign activity through 2026-05-24 (trojanized a Microsoft-published Python SDK, operating across three package ecosystems, reached GitHub internal codebase, and open-sourced components); a possible ACR credential stealer page im

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
f373736b04fb333b8a59f315ad2d30043b6063e14f835c3ca5e6524090e7f9ff
Enrichment time
2026-05-31T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · YARA-X 1.17.0 Release, (Sun, May 31st) · Baitaphish