Related Threat Clusters
-
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
GitLab's CVE-2026-19478, a critical code injection vulnerability with a CVSS score of 9.4, is currently under active exploitation just days after its public disclosure on August 17, 2026. Attackers are leveraging this…
2 articles · Updated August 22, 2026 -
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…
6 articles · Updated November 7, 2025 -
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
On July 1, 2026, security firm SlowMist identified a fake trading bot on GitHub designed to spread malware targeting Polymarket users and DeFi developers. The bot, named 'polymarket-arbitrage-bot', was promoted as a…
2 articles · Updated July 1, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
NPM Packages Distribute PylangGhost RAT in Supply Chain Attack
Malicious npm packages have been identified as vehicles for the PylangGhost remote access trojan (RAT), linked to North Korean state-sponsored group FAMOUS CHOLLIMA. The attack began with the release of compromised…
4 articles · Updated March 17, 2026 -
Supply Chain Attack Compromises Popular Rust Crates to Deliver Malware
On August 20, 2026, a supply chain attack targeted the Rust ecosystem, compromising the widely used crates arrayref, append-only-vec, and internment. The attackers injected a malicious dependency, proc-macro1, which…
22 articles · Updated August 20, 2026 -
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
3 articles · Updated May 26, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
North Korean Malware Targets Crypto Developers via NPM Packages
A malicious npm package named @validate-sdk/v2, introduced through Anthropic’s Claude Opus AI model, has been linked to a breach in the open-source crypto trading project openpaw-graveyard. This malware, dubbed…
6 articles · Updated May 1, 2026
Recent Intelligence Reports
- Communication Channel Identity Risks — unit42.paloaltonetworks.com · August 31, 2026
- Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more — Grahamcluley · August 28, 2026
- Australian cops cuff alleged TeamPCP masterminds — Theregister · August 28, 2026
- Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages. — Gbhackers · August 26, 2026
- Crooks push Mac malware through fake OpenAI Codex ads — Theregister · August 25, 2026
- [SecurityIntel] 22 Aug | GitLab CVE-2026-19478 Under Active Exploitation — Buttondown · August 22, 2026
- CVE-2026-57998: better-npm-audit OS Command Injection via registry flag [HIGH] CVSS 8.5 Exploit Intelligence - Recent CVEs / 3h better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A registry value containing shell metacharacters such as a — exploit-intel.com · August 22, 2026
- North Korean Hackers Tied to Rust Supply Chain Attack — Infosecurity-Magazine · August 21, 2026