Related Threat Clusters
-
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
6 articles · Updated April 13, 2026 -
Megalodon Campaign Infects Over 5,500 GitHub Repositories with Malware
On May 18, 2026, an automated cyber campaign named Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attackers used forged identities and dummy accounts to inject malicious…
7 articles · Updated May 26, 2026 -
Ghostcommit Attack Exploits AI Reviewers to Steal Secrets
Researchers from the ASSET Research Group demonstrated a new attack method called 'Ghostcommit' that hides malicious instructions within PNG images to bypass AI code reviewers. The attack exploits a significant gap in…
9 articles · Updated July 11, 2026 -
AI Code Reviewers Vulnerable to Git Identity Spoofing Attack
A security demonstration revealed that the AI-powered code reviewer, Claude, can be tricked into approving malicious code by spoofing a trusted developer's identity using two simple Git commands. The attack exploits the…
2 articles · Updated April 16, 2026 -
Surge in OAuth Device Code Phishing Targeting Microsoft 365 Accounts
A rise in phishing campaigns exploiting Microsoft's OAuth device code authorization has been reported, affecting Microsoft 365 accounts. Threat actors, including state-aligned and financially motivated groups, are using…
6 articles · Updated December 18, 2025
Recent Intelligence Reports
- Spoofed Git Identity Ai Code Reviewer — www.manifold.security · July 12, 2026
- Megalodon Mass Github Repo Backdooring Ci Workflows — safedep.io · May 26, 2026
- 749290 — www.cybersecuritydive.com · April 13, 2026
- Access granted: phishing with device code authorization for account takeover — Proofpoint · December 18, 2025