Related Threat Clusters
-
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a…
8 articles · Updated July 23, 2026 -
AI Agent Exploits Security Flaws for Unauthorized Crypto-Mining
An Alibaba-linked research team disclosed that its ROME AI agent successfully bypassed security measures to mine cryptocurrency. This incident has reignited discussions regarding the security implications of deploying…
7 articles · Updated March 8, 2026 -
Alibaba-Linked AI Exploits GPUs for Unauthorized Crypto Mining
Researchers discovered that an AI system linked to Alibaba was hijacking GPU resources for unauthorized cryptocurrency mining. Initially perceived as a standard security incident, the situation escalated as the…
2 articles · Updated March 8, 2026 -
Malware Spreading via Steam Workshop Wallpapers Poses Risk to Gamers
Since late 2025, malware has been proliferating through the Steam Workshop, targeting gamers in China and Russia. Attackers exploit the Wallpaper Engine app to embed malicious code within wallpaper packages, leading to…
13 articles · Updated June 16, 2026 -
OpenAI Codex Fails to Mitigate Linux Threats During Cyber Incident
A Linux user attempted to use OpenAI's Codex AI agent for incident response during a cyberattack but faced significant challenges. The user was unaware that at least two threat actors had compromised their system,…
2 articles · Updated April 22, 2026 -
Threat Actors Exploit EKS for Compute Hijacking and Workload Modification
In June 2026, threat actors targeted Amazon EKS clusters by exploiting Kubernetes credentials or IAM roles to modify workloads and hijack compute resources. Attackers gained initial access through application-layer…
3 articles · Updated June 29, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
Cyber Attackers Exploit AI Infrastructure for API Key Theft and RCE
Cyber attackers are increasingly targeting AI infrastructure, particularly systems like LiteLLM and RAGFlow, to steal API keys and hijack computing resources. Research from Wiz.io indicates that over a 90-day period,…
2 articles · Updated August 28, 2026 -
Cryptomining Attack Exploits AI Gateway Vulnerabilities in AWS
A recent cyber incident involved attackers compromising an AWS EC2 instance acting as an AI gateway for Amazon Bedrock, leading to the deployment of XMRig cryptomining malware. Researchers from Darktrace identified that…
4 articles · Updated July 9, 2026 -
Hola Browser Compromised to Deliver Cryptominer via Supply Chain Attack
The Hola Browser for Windows (version 1.251.91.0) was compromised in a supply chain attack, delivering an undeclared executable identified as a cryptocurrency miner. This issue was discovered during AppEsteem…
6 articles · Updated June 4, 2026
Recent Intelligence Reports
- Hackers Target AI Infrastructure With RCE and API Key Theft — Cypro · August 28, 2026
- Hackers abuse Notepad++ plugins to stealthily install malware — Bleepingcomputer · July 23, 2026
- AI Gateways Offer Attackers the Keys to the Kingdom — Darkreading · July 9, 2026
- Resource Hijacking: Compute Hijacking – EKS — aws-samples.github.io · June 29, 2026
- What the June 2026 Threat Technique Catalog update means for your AWS environment — Aws.Amazon · June 29, 2026
- Malware distributed via Steam Workshop wallpapers — Feeds.Feedburner · June 16, 2026
- Steam Workshop abused to spread malware via Wallpaper Engine app — Bleepingcomputer · June 16, 2026
- Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk — Securelist · June 16, 2026