ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)
2026-05-30T07:23:45Z•f3adcb723932ca7494fa008a4a8e2bb3ba19360b3486b87c8780c382f73668c6
ACR-impersonationAkiraDShieldGitHubTeamPCPVBAWindows-event-logscredential-stealerfirewall-logsforensicsmacrosmalwarepython-sdkransomwaresupply-chaintelemetrythreat-inteltrojan
What happened
Collection of SANS ISC diary entries (late May 2026) covering multiple defensive and threat topics: a TeamPCP supply-chain campaign that now operates across three package ecosystems, trojanized an officially Microsoft-published Python SDK and reached parts of GitHub’s internal codebase (broad supply-chain impact); forensic guidance for reconstructing Akira ransomware kill chains by correlating perimeter firewall and Windows event logs; analysis of a year of files uploaded to DShield sensors showing a winter peak in uploads; a reported page impersonating an AI service (Claude) potentially used
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- f3adcb723932ca7494fa008a4a8e2bb3ba19360b3486b87c8780c382f73668c6
- Enrichment time
- 2026-05-30T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.