Related Threat Clusters
-
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
2 articles · Updated July 28, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
Amazon Q Developer Vulnerability Enables Cloud Credential Theft
A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server…
11 articles · Updated June 26, 2026 -
LiteLLM Supply Chain Attack Exposes Critical Credentials
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
3 articles · Updated June 12, 2026 -
Bitwarden CLI Compromised in Supply Chain Attack via npm
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
18 articles · Updated April 24, 2026 -
Iranian Hackers Breach US Gas Station Fuel Monitoring Systems
US officials suspect Iranian hackers have breached automatic tank gauge (ATG) systems at gas stations across multiple states. The attackers exploited unprotected internet-connected systems, allowing them to manipulate…
46 articles · Updated May 16, 2026 -
Critical Linux Vulnerability 'Copy Fail' Grants Root Access Across Major Distros
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named 'Copy Fail', allows unprivileged local users to gain root access on virtually all major Linux distributions released since 2017.…
227 articles · Updated April 30, 2026 -
Critical Gemini CLI Vulnerability Allows Arbitrary Code Execution
A critical vulnerability in Google’s Gemini CLI, tracked as CVE-2026-12537, has been disclosed, enabling attackers to execute arbitrary code in CI/CD environments, particularly within GitHub Actions workflows. This flaw…
2 articles · Updated June 29, 2026 -
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
Critical RCE Vulnerability in Microsoft GitHub Repository Disclosed
A critical flaw in Microsoft's Windows-driver-samples GitHub repository allowed for remote code execution (RCE) via issue submissions. The vulnerability, identified by Tenable, enabled attackers to inject arbitrary…
2 articles · Updated April 22, 2026
Recent Intelligence Reports
- KELA research leads to alleged TeamPCP Members Arrested — Markets.Businessinsider · August 27, 2026
- Gitlost How We Tricked Githubs Ai Agent Into Leaking Private Repos — noma.security · August 25, 2026
- Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed — Infosecurity-Magazine · August 18, 2026
- Wiz agent finds Snowflake repo flaw in code co — Feeds.Feedburner · August 18, 2026
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection — Thehackernews · August 17, 2026
- An AI broke Snowflake's code. Then another AI agent exploited it — Theregister · August 17, 2026
- AI-Generated GitHub Copilot "Autofix" Allowed Compromise of Snowflake's Jira — News.Ycombinator · August 17, 2026
- Keyv And Cacheable Compromise — socket.dev · August 6, 2026