Related Threat Clusters
-
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware
The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two…
6 articles · Updated September 1, 2026 -
Kimsuky Expands AI Capabilities for Cyberattacks
The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
49 articles · Updated August 10, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
Anonymous Researcher Publishes Zero-Day Exploits for Major Software Projects
An anonymous researcher known as Bikini has released exploit code for over a dozen zero-day vulnerabilities affecting 15 popular open-source projects, including the Linux kernel and Libssh2. The exploits were disclosed…
4 articles · Updated July 1, 2026 -
Cursor IDE Vulnerability Allows RCE via Malicious Git Repositories
A critical vulnerability in the Cursor IDE, tracked as CVE-2026-26268, has been disclosed, allowing arbitrary code execution (RCE) on developers' machines. The flaw arises from the interaction between Cursor's AI agent…
3 articles · Updated April 29, 2026 -
Critical Gitea Vulnerability CVE-2026-60004 Actively Exploited
A critical vulnerability in Gitea, tracked as CVE-2026-60004, is being actively exploited by attackers, allowing unauthorized users to execute arbitrary shell commands on vulnerable servers. This flaw affects…
18 articles · Updated August 26, 2026 -
Gogs Vulnerability Allows Remote Code Execution via Path Traversal
Gogs, a self-hosted Git service, has a vulnerability allowing path traversal in organization names. This flaw permits attackers to create nested Git repositories, leading to the potential for Remote Code Execution (RCE)…
3 articles · Updated June 24, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
GitHub Patches Critical RCE Vulnerability CVE-2026-3854
A critical remote code execution vulnerability, tracked as CVE-2026-3854, was discovered in GitHub's internal git infrastructure, allowing authenticated users to execute arbitrary commands via a crafted git push…
49 articles · Updated April 28, 2026 -
Multiple Exploits Targeting Android and Web Applications
A cluster of cybersecurity tools has emerged, targeting various vulnerabilities in Android and web applications. The tools include AndroTickler, designed for penetration testing of Android apps, and exposecheck, which…
15 articles · Updated September 7, 2026
Recent Intelligence Reports
- CVE-2024 — Sploitus · September 8, 2026
- ExtAnalysis exploit — Sploitus · September 8, 2026
- Ai Coding Agents Git Hijack — www.manifold.security · September 4, 2026
- Fake Recruiter Repos Are Spreading Malware—Here's How AI Can Catch Them — Hackernoon · September 3, 2026
- Claude Arbitrary Code Execution — www.sonarsource.com · September 2, 2026
- GHSA R5pp P5r8 466r — github.com · September 2, 2026
- Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code — Thehackernews · September 2, 2026
- AI agents automatically execute git malware when starting — Heise.De · September 2, 2026