T1059.006 - Python is a mitre_attack tracked across 50 threat clusters and 102 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity July 24, 2026.
T1059.006 Python refers to the use of Python as a scripting language to develop and execute malware payloads. Attackers favor Python for cross-platform tooling, rapid development, and the ability to embed or deliver Python-based scripts within other file formats, complicating detection. Recent reports show Python-based malware spread through social channels and through Blender 3D model workflows, underscoring Python’s versatility as an attack surface.
TeamPCP has launched a new cyber campaign deploying a destructive payload that targets Kubernetes clusters configured for Iran. This wiper malware, part of the ongoing CanisterWorm campaign, uses the same…
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
In March 2026, Iranian hackers linked to the Ministry of Intelligence and Security (MOIS) breached the Los Angeles County Metropolitan Transportation Authority (LACMTA), stealing at least 700 gigabytes of sensitive…
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
A new malware named NarwhalRAT has been discovered targeting Korean users through phishing emails impersonating the Microsoft security team. The malware, linked to the North Korean hacking group APT37, can perform over…
A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
A significant wave of cyberattacks has targeted ComfyUI servers, converting them into a botnet for cryptomining and proxy operations. Researchers from Censys reported that since March 12, 2026, over 1,000 publicly…
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…