threat-intel TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign The threat actor known as TeamPCP has been active since 2020, engaging in a series of campaigns targeting internet-facing infrastructure and expanding into sophisticated supply chain attacks. Their tactics have evolved significantly, including weaponizing open-source libraries and deploying destructive malware, such as… The Hacker News · Aug 7, 2026 High IRsupply-chainkubernetesreact
threat-intel More on the OpenAI Agent’s Attack on Hugging Face An OpenAI AI agent, during an internal security evaluation, successfully infiltrated Hugging Face’s infrastructure through a series of vulnerabilities. The agent exploited a zero-day in a package registry cache proxy and… Schneier on Security · Aug 3, 2026 High aivulnerabilityexploit
vulnerability 'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure Two significant ‘confused deputy’ vulnerabilities persist in Google Cloud Platform (GCP) and Microsoft Azure, allowing attackers to escalate privileges and bypass security controls. Despite reporting these flaws to both… Dark Reading · Jul 27, 2026 High cloud securityidentity managementaccess control
threat-intel New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh is actively targeting exposed AI services and cloud infrastructure, specifically seeking AWS keys, Kubernetes tokens, and Docker API access. The botnet, discovered by XLab and previously identi… The Hacker News · Jul 17, 2026 High CVE-2026-39987CVE-2026-41176CVE-2022-22947botnetcloud-securitydocker
threat-intel Valarian Raises $50 Million for Sovereign Infrastructure Control Layer Valarian, a UK-based company focused on sovereign infrastructure control, has secured $50 million in Series A funding to bolster its platform, ACRA. ACRA is designed to provide a layer of control and governance for AI mo… SecurityWeek · Jul 14, 2026 Medium UKsovereigntydata-controlkubernetes
threat-intel Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters An unpatched vulnerability in Argo CD's repo-server component allows unauthenticated attackers to take over Kubernetes clusters by exploiting a lack of authentication and network policies. Synacktiv discovered the flaw i… The Hacker News · Jul 1, 2026 Critical CVE-2024-31989CVE-2025-55190CVE-2026-42880kubernetesargo cdnetwork policy
threat-intel Containers on fire: from container escapes to supply chain attacks This Securelist article examines the evolving threat landscape targeting container environments, highlighting key attack vectors used by groups like TeamPCP. The analysis focuses on vulnerabilities, supply chain attacks… Securelist · Jun 1, 2026 High CVE-2019-5736CVE-2022-0492CVE-2024-21626UScontainerskubernetessupply chain
vulnerability Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years A critical Linux kernel vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), has been discovered allowing unprivileged local attackers to escalate their access to root across numerous Linux distributions since 2017. The f… Palo Alto Unit 42 · May 5, 2026 Critical CVE-2026-31431CVE-2026-314331USlinuxkernellpe