ISC Stormcast For Friday, May 29th, 2026 https://isc.sans.edu/podcastdetail/9950, (Fri, May 29th)

2026-05-31T13:23:46Zf8f523412c7fd0336f6df301b7f33571b48671ad8aff568b743ad344fe3b2eb7
AkiraDShieldGitHub-compromiseMicrosoft-AccessTeamPCPVBAWindows-event-logscredential-theftforensicsincident-responsepage-impersonationperimeter-logsphishingpython-sdkransomwaresupply-chaintelemetrytrojanized-packages

What happened

A set of SANS ISC diary entries (late May 2026) covering multiple security topics: a forensic walkthrough reconstructing an Akira ransomware kill chain by correlating perimeter firewall and Windows event logs; an active supply-chain campaign attributed to 'TeamPCP' that trojanized packages across multiple ecosystems (including an officially Microsoft-published Python SDK) and reached GitHub internals; reporting of a phishing/stealer page impersonating the Claude AI interface (possible credential/ACR stealer); telemetry analysis of files uploaded to DShield sensors showing peak activity in Dec

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
f8f523412c7fd0336f6df301b7f33571b48671ad8aff568b743ad344fe3b2eb7
Enrichment time
2026-05-31T13:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.