Related Threat Clusters
-
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
Coder's Registry Compromised to Distribute Malicious Terraform Modules
On August 31, 2026, Coder's Cloudflare infrastructure was compromised by an unidentified actor who added unauthorized IP addresses to the module registry. This led to the delivery of malicious Terraform modules…
3 articles · Updated September 4, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Supply Chain Attack on node-ipc npm Package Exposes 822K Downloads to Credential Theft
A supply chain attack on the node-ipc npm package has compromised three versions (9.1.6, 9.2.3, 12.0.1) with credential-stealing malware. The attack exploited an expired domain to hijack a dormant maintainer account,…
11 articles · Updated May 15, 2026 -
North Korean Hackers Exploit React2Shell Vulnerability in Crypto Sector
A group of hackers suspected to be linked to North Korea has targeted cryptocurrency firms, exploiting the React2Shell vulnerability (CVE-2025-55182). The attackers compromised AWS access credentials to infiltrate cloud…
8 articles · Updated March 9, 2026 -
Megalodon Campaign Infects Over 5,500 GitHub Repositories with Malware
On May 18, 2026, an automated cyber campaign named Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attackers used forged identities and dummy accounts to inject malicious…
7 articles · Updated May 26, 2026 -
AI-Driven Ransomware Attack Completes in Under 10 Hours
On September 2, 2026, a human attacker utilized frontier AI agents to execute a ransomware attack on an enterprise, completing the breach in less than 10 hours. The attack involved over 50 techniques from the MITRE…
19 articles · Updated September 2, 2026 -
CISA Contractor Exposes Sensitive AWS Credentials on Public GitHub
A contractor for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) left a public GitHub repository named 'Private-CISA' exposed for six months, containing sensitive credentials including AWS GovCloud…
41 articles · Updated May 19, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
MCP Vulnerabilities Expose AI Systems to Remote Code Execution Risks
In 2026, the Model Context Protocol (MCP) has been identified as a significant security risk due to its unverified package management and decentralized registry ecosystem. This vulnerability allows attackers to exploit…
6 articles · Updated April 28, 2026
Recent Intelligence Reports
- Ai Assisted Cloud Intrusion Achieves Admin Access In 8 Minutes — www.sysdig.com · September 7, 2026
- Coder Registry Compromise: Malicious Terraform Modules Explained — Esecurityplanet · September 4, 2026
- GHSA Vx42 Ghc9 Gw65 — github.com · September 4, 2026
- Coder's registry infrastructure compromised to push malicious modules — Bleepingcomputer · September 3, 2026
- Agentic Ransomware Took Down Enterprise in Ten Hours: AI Left 80 — Techtimes · September 3, 2026
- AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs — Csoonline · September 3, 2026
- An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation — Unit42.Paloaltonetworks · September 2, 2026
- Cloud Security — securis360.com · August 26, 2026