Related Threat Clusters
-
Gitea Vulnerability Exposes 30,000 Private Container Images to Attackers
A critical vulnerability, CVE-2026-27771, in Gitea's container registry allowed unauthenticated users to access private container images for nearly four years. Discovered by Noscope in April 2026, the flaw affects over…
8 articles · Updated May 28, 2026 -
TeamPCP Hackers Arrested for Major Supply Chain Attacks
On August 26, 2026, Australian Federal Police arrested two men, Ruben Thomson and Louis Gaebler, linked to the TeamPCP hacking group. This group is notorious for sophisticated supply chain attacks that compromised over…
26 articles · Updated August 27, 2026 -
SleeperGem: Malicious RubyGems Package Targets Developer Environments
A supply chain attack named SleeperGem has been identified targeting the RubyGems ecosystem, exploiting dormant maintainer accounts to publish a malicious gem called git_credential_manager. This gem, which has already…
3 articles · Updated July 19, 2026 -
Vulnerabilities Discovered in Forgejo Following Carrot Disclosure
A security researcher identified multiple vulnerabilities in Forgejo, a software platform used by Fedora, including SSRF, cryptographic issues, and authentication flaws. The researcher was able to chain these…
2 articles · Updated April 30, 2026
Recent Intelligence Reports
- 2026 04 02 Incident Report Litellm Telnyx Supply Chain Attack — blog.pypi.org · August 28, 2026
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts — Aikido.Dev · July 19, 2026
- CVE-2026-27771: Critical Gitea Container Registry Vulnerability Exposes Private Images to ... — Rescana · May 28, 2026
- Gitea Instances Exposing Private Container — www.noscope.com · May 28, 2026
- Gitea Flaw Left 30,000 Deployments' Private Container Images Readable for 4 Years — Techtimes · May 28, 2026
- Follow-up to Carrot disclosure: Forgejo — News.Ycombinator · April 30, 2026
- Carrot Disclosure: Forgejo — News.Ycombinator · April 28, 2026