Related Threat Clusters
-
TeamPCP's CanisterWorm Targets Iranian Systems with Destructive Kubernetes Wiper
TeamPCP has launched a new cyber campaign deploying a destructive payload that targets Kubernetes clusters configured for Iran. This wiper malware, part of the ongoing CanisterWorm campaign, uses the same…
4 articles · Updated March 23, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
22 articles · Updated August 30, 2026 -
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks
In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to…
10 articles · Updated August 20, 2026 -
Critical Ubuntu Snap Flaw Allows Local Privilege Escalation
A local privilege escalation vulnerability, tracked as CVE-2026-3888, has been identified in default installations of Ubuntu Desktop 24.04 and later. Discovered by Qualys, the flaw arises from an unintended interaction…
11 articles · Updated March 18, 2026 -
LiteLLM Supply Chain Attack Exposes Critical Credentials
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
3 articles · Updated June 12, 2026 -
Critical Vulnerabilities in dnsmasq Expose Systems to DoS and Code Execution Risks
Multiple vulnerabilities have been identified in dnsmasq, an open-source DNS and DHCP server, affecting various Linux distributions, including Ubuntu. The vulnerabilities, tracked as CVE-2026-2291, CVE-2026-4890,…
37 articles · Updated May 13, 2026 -
Active Exploitation of Critical Vulnerabilities in Lantronix and Ubiquiti Devices
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of critical vulnerabilities in Lantronix EDS5000-series devices and Ubiquiti's UniFi OS. The Lantronix vulnerability,…
6 articles · Updated June 25, 2026 -
Critical Linux Vulnerability 'Copy Fail' Grants Root Access Across Major Distros
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…
227 articles · Updated April 30, 2026 -
Critical Vulnerabilities in systemd Affect Multiple Ubuntu Releases
On March 23, 2026, vulnerabilities in systemd were disclosed, impacting several Ubuntu versions, including 20.04 LTS, 18.04 LTS, 16.04 LTS, and 14.04 LTS. The vulnerabilities allow local attackers to exploit incorrect…
4 articles · Updated March 23, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026
Recent Intelligence Reports
- Fedora 44 ProFTPD Security Bugfix Advisory 2026 — Linuxsecurity · September 3, 2026
- Fedora 43 ProFTPD Update Important FTP Bugfixes FEDORA-2026 — Linuxsecurity · September 3, 2026
- Sygnia Reveals New Activity by China — Sg.Finance.Yahoo · August 30, 2026
- UAT-10147 deploys SPECTRE: A cross — Blog.Talosintelligence · August 20, 2026
- Ubuntu 26.04 systemd Important Local Privilege Escalation Vuln 8626 — Linuxsecurity · August 10, 2026
- Fedora 43 systemd 258.10 Important Bugfix Advisory 2026 — Linuxsecurity · July 27, 2026
- SleeperGem attack targets Ruby ecosystem with malicious gems — Feeds.Feedburner · July 20, 2026
- M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions — Wiz · July 14, 2026