Systemd is a technology platform tracked across 15 threat clusters and 18 intelligence report mentions on ThreatCluster. First observed March 18, 2026; most recent activity July 20, 2026.
TeamPCP has launched a new cyber campaign deploying a destructive payload that targets Kubernetes clusters configured for Iran. This wiper malware, part of the ongoing CanisterWorm campaign, uses the same…
A local privilege escalation vulnerability, tracked as CVE-2026-3888, has been identified in default installations of Ubuntu Desktop 24.04 and later. Discovered by Qualys, the flaw arises from an unintended interaction…
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
Multiple vulnerabilities have been identified in dnsmasq, an open-source DNS and DHCP server, affecting various Linux distributions, including Ubuntu. The vulnerabilities, tracked as CVE-2026-2291, CVE-2026-4890,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of critical vulnerabilities in Lantronix EDS5000-series devices and Ubiquiti's UniFi OS. The Lantronix vulnerability,…
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…
On March 23, 2026, vulnerabilities in systemd were disclosed, impacting several Ubuntu versions, including 20.04 LTS, 18.04 LTS, 16.04 LTS, and 14.04 LTS. The vulnerabilities allow local attackers to exploit incorrect…
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
Two significant vulnerabilities in systemd have been reported, affecting Ubuntu 22.04 LTS, 24.04 LTS, and 25.10. The first, CVE-2026-40226, allows local attackers to escape to the host system and execute arbitrary code…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…