Frequency
2
occurrences
First Seen
November 11, 2025
Last Seen
May 15, 2026
Related Threat Clusters
-
Supply Chain Attack on node-ipc npm Package Exposes 822K Downloads to Credential Theft
A supply chain attack on the node-ipc npm package has compromised three versions (9.1.6, 9.2.3, 12.0.1) with credential-stealing malware. The attack exploited an expired domain to hijack a dormant maintainer account,…
11 articles · Updated May 15, 2026 -
Critical runC Vulnerabilities Enable Container Escape on Docker and Kubernetes
Three critical vulnerabilities in runC, tracked as CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881, allow attackers to escape container isolation and gain root access to host systems. These flaws arise from improper…
10 articles · Updated November 24, 2025 -
Critical runC Vulnerabilities Enable Container Escape and Host Compromise
Security researchers disclosed three critical vulnerabilities in runC, the container runtime used by Docker and Kubernetes, allowing attackers to escape container isolation and gain root access to host systems. The…
5 articles · Updated November 13, 2025
Recent Intelligence Reports
- Expired domain leads to supply chain attack on node — Csoonline · May 15, 2026
- Researchers Uncover Critical runC Bugs Allowing Full Container Escape — Thecyberexpress · November 11, 2025