Related Threat Clusters
-
Chinese-Speaking Actor Breaches Philippine Nuclear and Naval Targets
A suspected Chinese-speaking threat actor has compromised Philippine nuclear and naval organizations by exploiting known vulnerabilities in internet-facing systems. The attack targeted a nuclear research body and a…
2 articles · Updated August 31, 2026 -
Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise
AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…
30 articles · Updated April 1, 2026 -
TeamPCP Supply Chain Attack Compromises Databricks Platform
Databricks is investigating a potential security compromise linked to the TeamPCP supply chain attack. This incident follows a notification from International Cyber Digest, which indicated that Databricks was alerted…
4 articles · Updated March 30, 2026 -
MFA Lapses Lead to Data Theft of 50 Organizations
A major infostealer campaign has compromised sensitive data from 50 global enterprises, with the data available for sale on the dark web. Victims include firms such as Pickett and Associates, Sekisui House, and Iberia.…
4 articles · Updated January 6, 2026 -
ownCloud Users Urged to Enable MFA Amid Credential Theft Reports
ownCloud has advised its users to activate multi-factor authentication (MFA) following reports of credential theft that could allow attackers to access sensitive data. The warning comes as a threat actor, Zestix, is…
2 articles · Updated January 7, 2026
Recent Intelligence Reports
- Chinese Speaking Operator Philippine Nuclear Naval Contractor — hunt.io · August 31, 2026
- Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator — Securityaffairs.Co · August 29, 2026
- TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st) — Isc.Sans.Edu · April 1, 2026
- TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th) — Isc.Sans.Edu · March 30, 2026
- ownCloud urges users to enable MFA after credential theft reports — Bleepingcomputer · January 7, 2026
- One criminal, 50 hacked organizations, and all because MFA wasn't turned on — Theregister · January 6, 2026
- Cloud file — Bleepingcomputer · January 5, 2026