Source index
Feeds and primary sources we consider worth monitoring for future threat coverage.
High-value RSS / update feeds
- Metabase security advisories, GitHub advisories, and Wiz reverse engineering (August 10 priority follow-up; monitor GHSA-vwf4-m7j8-wcjf for CVE assignment, changes to the request-merge / structured
user-id/ HoneySQL:rawroot-cause analysis, source infrastructure, actor and full victim scope, additional affected or fixed branches, further first-party customer notices, connected-database impact, and CISA KEV action. Public proof-of-concept code existed by August 10; n8n and Anaconda/Kilo Code have confirmed downstream data access.) - Coinspect / Ill Bloom wallet research and Coinspect blog (HTML watch for weak wallet-key generation, on-chain exploitation measurement, affected-application attribution, and migration guidance; priority follow-up is the CryptoJS
WordArray.random()/GHSA-rg76-677x-56q9campaign affecting RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo Wallet, with 2^39 / 2^47 effective recovery-phrase search spaces and a measured $5.69 million lower-bound loss) - Censys ARC Research and blog (HTML watch for internet-wide adversary-infrastructure and rapid-response research with durable response-body, certificate, service, port, and provider pivots, including DarkSword / GHOSTBLADE iOS exploit-panel proliferation, leaked-kit code reuse, fast host churn, fake AWS and Apple credential lures, dual Coruna/DarkSword operation, and operator OPSEC artifacts.)
- N-able N-central security update, Hotfix 2 notice, Huntress rapid response, and CISA KEV catalog (August 8 priority follow-up; build 2026.3.1.10 supersedes Hotfix 1 and is required even on 2026.3.1.7; monitor victim and MSP scope, the evolving exploit path, additional Take Control and Cloudflare Tunnel artifacts, actor attribution, fixed-build revisions, shared VPN-exit false-positive handling, downstream endpoint persistence, and national-CERT action.)
- Coinkite COLDCARD security advisory, technical backgrounder, and Block Bitcoin Engineering analysis (August 1 priority follow-up; monitor formal Coinkite review, reconciliation of the Mk2/Mk3 4.0.0 versus 4.0.1 lower bound, empirical recovery cost, confirmed affected-wallet and loss scope, proof or rejection of linkage to the 1,196-address / 1,082.65 BTC sweep, additional affected RNG-backed features, replacement hotfixes, public indicators, and actor attribution.)
- Adform security incident notice and Kevin Beaumont / DoublePulsar analysis (August 1 priority follow-up; monitor affected-site and visitor scope, reconciliation of Adform's July 27 affected date with the longer independent observation window, cache persistence, confirmed diverted transactions, replacement wallet addresses, initial access to the shared script deployment path, authority or client notices, additional indicators, and actor attribution.)
- CISA / FBI / EPA water-sector PLC activity alert and FBI PSA I-073026-PSA (July 30, 2026 priority follow-up; monitor internet-facing Rockwell Automation / Allen-Bradley MicroLogix 1100 and 1400 configuration tampering for additional states or victims, actor or access-path attribution, source infrastructure, exploit or credential-use detail, project-file and ladder-logic indicators, shared integrator or cellular architecture scope, and physical-process consequences.)
- Confiant Threat Intelligence (RSS watch for malvertising, ad-fraud, browser-delivery, cloaking, and cryptocurrency-user targeting with durable technical and infrastructure detail, such as SourTrade's ServiceWorker / SharedWorker browser-side assembly of per-session Windows executables from clean Bun runtime bytes, actor-supplied PE / JavaScriptCore payload material, and locally generated AES-CTR streams.)
- VulnCheck Research (Atom watch; monitor exploitation telemetry, target-intelligence research, public exploit proliferation, and KEV-relevant updates with durable defender value, including Windmill CVE-2026-29059 path-traversal attempts, wp2shell proof-of-concept growth, and embedded-device trust failures such as ENDLESSDOORS / CVE-2026-66747, where Zbtlink router firmware starts an unauthenticated
rctl-derived root command channel and OEM/ODM rebadging obscures the affected inventory) - Wiz Research: wp2shell active exploitation (2026-07-20 priority follow-up; monitor CVE-2026-63030 / CVE-2026-60137 WordPress Core exploitation, batch-endpoint tooling changes, malicious-plugin and PHP-webshell variants, lateral movement or exfiltration findings, and CISA KEV or WordPress incident-response updates)
- Sonatype Security Research (RSS watch; monitor package-registry and ecosystem compromise research such as Atomic Arch AUR orphan-package adoption, malicious npm dependency pivots like
atomic-lockfile/js-digest/lockfile-js, Sonatype vulnerability guide entries, Shai-Hulud / Miasma supply-chain follow-ups such as Leo Platform / RStreams package clarification,llxlrpackage confirmation, and advisory pivots including ChainDropsonatype-2026-005579and its 2,225-component-version August 5 snapshot, plus automated disposable-publisher campaigns such as Flooding Dropper /sonatype-2026-005660and DPRK-linked NullReceiver activitysonatype-2026-005899/sonatype-2026-005901, where hijacked and newly published npm packages resolve raw-IP C2 through Ethereum transactions before/0x/cls//0x/lsJavaScript staging) - Aikido Security Research (HTML/RSS watch; monitor developer-machine, AI-toolchain, VS Code / extension, Codex-token, and package supply-chain compromises such as
codexui-androidOpenAI token theft, poisoned extensions, Laravel-Lang, Mini Shai-Hulud follow-ups, SleeperGem-style RubyGems dormant-maintainer account takeovers that evade CI and persist on developer workstations, and the unconfirmedanthropickit==999.9.9candidate for Anthropic's evaluation-published PyPI malware; monitor Anthropic/PyPI confirmation, hashes, and victim-side corroboration before promoting candidate linkage to fact) - QiAnXin XLab (HTML watch; monitor MODBEACON / Operation Phnom Penh Silver Fox Ghost-distributor activity, large-scale exploitation, botnet, ClickFix/page-poisoning, hosting-control-plane abuse such as Mr_Rot13 cPanel CVE-2026-41940, infrastructure writeups such as Ghost CMS CVE-2026-26980 mass compromise reports, recon/proxy botnets such as AryStinger legacy-router and QNAP Malware Remover exploitation, DDoS botnets such as RustDuck's Loader + Core transition from C to Rust with weak-password / IoT / Web-RCE propagation and Dysphoria's post-JackSkid ENS/SNS infrastructure resolution, UPnP-enabled victim relays, and dynamic relay lists, AI-service and cloud-credential botnets such as NadMesh targeting MCP, ComfyUI, Ollama, n8n, Docker, Kubernetes, Redis, and Jenkins, and cybercrime-infrastructure / web-supply-chain reports such as Funnull RingH23 / MacCMS poisoning)
- Wiz Research and RSS (monitor TeamPCP/Mini Shai-Hulud package waves including Miasma /
@redhat-cloud-services, AsyncAPI / M-RED-TEAM-style branch-to-provenance package compromises, JINX-0164-style cryptocurrency developer targeting with fake meeting flows, macOS malware, GitHub/source-repository abuse, and post-compromise cloud/GitHub abuse reporting such as TruffleHog validation, ECS Exec / SSM execution, mass repository cloning, and workflow-log deletion; monitor managed-cloud tenant-isolation and storage research such as CosmosEscape's Gremlin .NET sandbox escape, shared DB Gateway execution, platform-wide Cosmos Master Key, Config Store enumeration, cross-tenant primary-key retrieval, and private-network bypass, plus S3-compatible neocloud object-storage gaps including namesquatting, partial API semantics, uneven secret scanning, weak least privilege, presigned-URL exposure, and audit or encryption assumption drift; also monitor AI and MCP trust-boundary research such as internet-exposed unauthenticated MCP servers acting as privileged proxies to production data, destructive operations, shell execution, cloud metadata, and credentials, Amazon Q Developer CVE-2026-12957 MCP auto-execution through.amazonq/mcp.jsonworkspace configuration, and GhostApproval symlink write-confusion / approval-prompt canonical-path failures affecting AI coding assistants) - Wiz H1 2026 cloud threat review — https://www.wiz.io/blog/cloud-threat-highlights-h1-2026 (August 6 priority follow-up; monitor JINX-0163 / FulcrumSec non-human-identity extortion for victim or infrastructure indicators, initial-access and state-file detail, cross-cloud identity pivots, extortion-as-a-service clarification, law-enforcement or provider response, and additional evidence on delayed reuse of TeamPCP-stolen credentials by separate groups.)
- Wiz ChainDrop follow-up — https://www.wiz.io/blog/keyv-and-cacheable-npm-supply-chain-attack (August 4 priority follow-up; monitor selective C2-controlled dead-man-switch arming, per-host SHA-256 identifiers, RSA-key rotation,
tmp.dpkg_14527.lock,chore: update config, historical smart-contract-resolvedpypi-get.com/js-mirror.cominfrastructure, expanded AI-agent / wallet / Jenkins / Argo CD / Harbor / Alibaba / Tencent credential targets, contract rotation, victim execution, and maintainer or registry postmortems.) - Socket Security Research — https://socket.dev/api/blog/feed.atom and https://socket.dev/blog (Atom/HTML watch; monitor Shai-Hulud/Mini Shai-Hulud variants, registry-response notices such as npm token invalidation, TeamPCP/copycat reporting, legitimate-namespace prerelease compromises such as the Joyfill
@joyfill/layouts/@joyfill/componentsimport-time PolinRider-family loader using Tron/Aptos/BSC resolution and DEV#POPPER-style developer-tool persistence, enterprise developer-ecosystem compromises such as SAP CAP / Cloud MTA packages, cross-ecosystem Packagist/Composer and GitHub source-repository compromises, DPRK/Contagious Interview developer-targeting dead-drop campaigns such as StegaBin Pastebin/Vercel payload delivery, Famous Chollima Packagist dev-branch loaders, and PolinRider expansion across npm, Packagist, Go modules, Chrome extensions, fake.woff2loaders, VS CodefolderOpentasks, Git history rewriting, and blockchain/RPC C2, RubyGems abuse such as GemStuffer or BufferZoneCorp-style RubyGems/Go module CI poisoning, Laravel-Lang-style Composer tag rewrites/backdoors, financial/enterprise SDK impersonation such as Braintree.Net NuGet payment-card / merchant-credential skimming, Sicoob.Sdk NuGet mTLS certificate theft, NuGet DotnetTool malware such as game-cheatpepesoft.exedownloaders using DNS-over-HTTPS, GitHub/Hugging Face staging, Google Sheets telemetry, and Telegram screenshot paths, and Paysafe / Skrill / Neteller npm+PyPI typosquat stealers, high-blast-radius package compromises such as Axios pullingplain-crypto-jsRAT payloads and Mastra@mastra/*packages pullingeasy-day-js, Hades-style PyPI wheel startup-hook branches of Miasma / Mini Shai-Hulud using*-setup.pth, Bun,_index.js,.abi3.sonative extensions, and split loaders such aslangchain-core-mcp, cryptocurrency SDK compromise such as the Injective SDK npm wallet stealer where@injectivelabs/sdk-ts@1.20.21and pinned scoped packages exfiltrated mnemonics/private keys during normal key derivation, trusted developer-tool compromises such asjscramblerfollow-on malicious releases that move frompreinstallhooks todist/index.js/dist/bin/jscrambler.jsruntime trigger injection, Leo Platform / Miasma follow-ups such asllxlrpackage expansion, Immobiliare Labs Backstage plugin compromise, and Verana Blockchain Go source-repository poisoning through.claude//.vscode/hooks, AI-toolchain supply-chain tradecraft such as MCP/coding-assistant poisoning and TrapDoor-style npm/PyPI/Crates.io credential-stealer campaigns, AI-scanner anti-analysis such as prompt-injection comments, safety-triggering text, context flooding, and payload-after-noise layouts, Open VSX / VS Code extension abuse such as GlassWASM TinyGo/WebAssembly malware with Solana memo C2, Operation Muck and Load-style malicious Go module / GitHub lure-network campaigns with commit-farmed repositories, public dead-drop resolvers, protected archive delivery, RAT/infostealer payloads, andischhfd83pivots, and browser-extension abuse such as Chrome Web Store live-wallpaper ad-fraud / traffic-laundering networks and staged VPN/proxy extension clipboard stealers such as VPN Go.) - OX Security Research (HTML watch; monitor AI-toolchain and software-supply-chain malware such as Malware-Slop /
mouse5212-super-formatter, Claude/mnt/user-datatheft, GitHub Contents API exfiltration, leaked actor tokens, Shai-Hulud source-leak copycats such aschalk-tempalte/axois-utils/color-style-utils, TeamPCP follow-ons such as the Telnyx PyPI compromise after LiteLLM, Miasma /@redhat-cloud-servicesimpact notes such as stolen-repository counts, earliest observed infection timing, six-stage loader loops, alternateMiasma : The Spreading Blightspacing, andfiredalazerGitHub commit-search C2, ChainDrop response follow-ups such as clean-package MCP Registry entries that point to source repositories carrying Claude Code / VS Code execution hooks, delayed npm and GitHub cleanup, and cross-variantresults-*.jsonexposure measurements, MCP / AI-agent supply-chain trust-boundary research such as stdio command-execution configuration exposure, and AI-generated commodity npm malware tradecraft) - CrowdStrike Counter Adversary Operations (HTML watch; monitor developer-targeting botnet and supply-chain disruption reporting such as Glassworm, C2 takedowns, package/extension compromise, endpoint remediation guidance, and Windows execution/persistence research such as ClickOnce
.application/.appref-msabuse and HKCU COM hijacking; also monitor annual threat-hunting observations such as public-PoC exploitation windows, AI-agent detection volume,ALTERED SPIDERandSTARDUST CHOLLIMAsoftware-supply-chain activity, npm ecosystem prevalence, vishing, device-code phishing, and LLMJacking) - Akamai Security Research (HTML watch; RSS blocked/unavailable in current checks; monitor active-exploitation and edge/WAF telemetry writeups such as Drupal CVE-2026-9082, exposed-AI-service abuse such as Ollama P2P cryptominer/RAT campaigns, APT exploit-chain analysis such as APT28 LNK / SmartScreen bypass / authentication-coercion findings, and infrastructure/botnet disruption notes)
- SafeDep Research (HTML watch; monitor package-takedown evasion and rapid npm republishing such as
@apexfdn/apex→@copilot-mcp/apex, macOS AMOS-family postinstall theft, attacker-controlled remote MCP fronts, mutable GitHub release delivery, CI/CD, GitHub repository backdooring, package-registry compromise, Megalodon-style workflow backdoors, crypto/AI-tooling package malware such as Polymarket-themed wallet-drainer npm packages, actively maintained developer-targeting npm RATs such as forge-jsxy, MicrosoftSystem64 / js-logger-pack, and MYRA /apintergrationpost, Hugging Face / Discord exfiltration, typosquat infostealer campaigns such asfaster-axios/turbo-axiosEpsilon Stealer, runtime-triggered no-install-script npm backdoors such asnodemon-sudo/tslint-confwith detached child Node processes, Pinata IPFS staging, JsonKeeper dead drops, andFunction-constructor execution, AI-brand scope-squatting credential harvesters such as@withgoogle/stitch-sdk, targeted dependency-confusion environment stealers such as theoob.moika.techcampaign and follow-on@marketfront/@tqm-mfepackage waves withInternal package — Platform Engineering TeamREADME markers,X-Secretexfil headers, RC4/XOR-hidden C2 configuration, and private-registry fallback targeting, build-config PR injection such asastro.config.mjsblockchain-C2 loaders and horizontal-whitespace diff hiding, Mastra /easy-day-js-style stale npm maintainer scope takeovers with provenance dropped and Hostwinds raw-IP RAT infrastructure, split-package Windows npm droppers such asprocwire/routecraftwith helper-package XOR C2 reconstruction andfiles.catbox.moepayload staging, multi-scope disposable-email npm infostealer campaigns such as thewshu.netpackage set with scrubbed latest tags, runtime execution, Rust stealers, user-level systemd persistence, and Telegram C2, LeoPlatform Miasma orphansnapshot-*branch / fake Dependabot workflow reconstruction, and Mini Shai-Hulud / AntV / Miasma-style detection pivots such as payload hashes, orphan GitHub commit delivery, two-wave trusted-publishing abuse, live-latest malicious releases,kitty-monitor,gh-token-monitor, AI-assistant persistence, and source-repository auto-execution through Claude Code / GeminiSessionStart, CursoralwaysApply, VS CodefolderOpen, andnpm testlaunchers) - Lumen Black Lotus Labs (HTML watch; filter for Black Lotus Labs posts covering telecom, routing, botnet, and nation-state infrastructure research such as JDY / KV-botnet SOHO and IoT reconnaissance networks)
- Snyk Blog / Security Research (watch Mini Shai-Hulud/TeamPCP follow-ups, registry-scale advisories, package-level vulnerability records, and independent package/tarball validation such as ChainDrop
SNYK-JS-KEYV-18515941, thekeyv@6.0.0tarball hash, exact maintainer-linked carrier scoping, and verified-commit/provenance authorization boundaries; also monitor stale-maintainer npm scope compromises such as Mastra /easy-day-js, Composer/Packagist incident-response updates such as Laravel-Lang all-version compromise advisories, and AI-agent supply-chain boundary cases such as jqwik 1.10.0 maintainer prompt injection through build/test output, developer-environment MCP / skill inventory risk, and ToxicSkills-style public skill measurements) - Checkmarx Zero / Security Research (HTML watch; monitor malicious package and developer-supply-chain campaigns with package/version and infrastructure detail, including SuccessKey / ChainVeil and ViteVenom scoped npm impersonation, import-time execution, mixed clean/malicious releases, and Tron / Aptos / Binance Smart Chain C2 resolution)
- JFrog Security Research — https://research.jfrog.com/ (HTML watch; monitor TeamPCP/Mini Shai-Hulud follow-ups such as the hijacked
@bitwarden/cli@2026.4.0package,bw_setup.js/bw1.js, encrypted Checkmarx-lookalike exfiltration, and GitHub commit-search PAT and fallback-domain staging; targeted NuGet business-logic manipulation such asNewtonsoftt.Json.Netusing Harmony runtime patching and Seq-shaped exfiltration to rig Digitain betting results, PyPI import-time compromises such as Xinference and durabletask, optional-dependency GitHub-commit delivery, cloud/Kubernetes lateral-movement payload evolution, malicious developer/AI packages abusing platforms such as Hugging Face for CDN/exfiltration or prompt theft, cryptocurrency-developer package lures such as Solana FakeFix npm/PyPI patched-SDK packages, Injective SDK wallet-key theft follow-ups where runtime wrapper paths andX-Request-Idheader exfiltration change scoping, GitHub issue spam, Telegram C2, fake MEV private-key prompts, and Deno loader persistence, PostCSS-themed npm impersonation such aspostcss-minify-selector-parser/aes-decode-runner-proleading to PowerShell and Nuitka Windows RATs, Rollup polyfill masquerading packages such asrollup-packages-polyfill-core/rollup-runtime-polyfill-corewith JSONKeeper staging, browser/wallet theft, and Socket.IO / node-pty remote access, package-directory editor-task execution such ashtml-to-gutenberg/fetch-page-assetshiding VS CodefolderOpentasks behind fake font assets and blockchain dead drops, browser-side package-registry abuse such as Lucide Proxy student web proxies turning visitors into Wisp / WebSocket DDoS nodes, Miasma /@redhat-cloud-servicesfollow-up indicators such as type-only package install hooks, GitHub commit-search C2, camouflage exfil destinations, and AI-scanner prompt-injection / refusal-evasion samples, plus IronWorm-style native Rust npm infostealers with eBPF rootkits, Tor C2, backdated GitHub commits, and trusted-publishing propagation; also monitor high-signal Linux/container-host vulnerability research such as DirtyClone / CVE-2026-43503 DirtyFrag-family local privilege escalation) and JFrog Blog RSS https://jfrog.com/blog/feed/ (watch npm v12 explicit-trust install controls such asallowScripts,--allow-git, and `--allow-remo... [truncated] - JFrog ChainDrop follow-up — https://research.jfrog.com/post/shai-hulud-is-back-august/ (August 4 priority follow-up; monitor its 428-package / 1,700-version live inventory, repository and GitHub Actions infection artifacts, Ethereum-resolved
/routerC2, additional file hashes, npm Xray IDs, cleanup state, victim execution, and whether reusableShai-Hulud: Here We Go Againmarkers support lineage without proving TeamPCP operator identity.) - SafeDep ChainDrop follow-up — https://safedep.io/keyv-npm-supply-chain-compromise/ (August 4 priority follow-up; monitor the 444-package / 2,234-version / 12-organization snapshot, poisoned
latesttags, repeated-version growth, source-staged but unpublished@keyv/*siblings, publisher-specific OIDC versus direct-token paths, registry cleanup, and reconciliation of its no-embedded-C2-host claim with StepSecurity and JFrog's Ethereum-resolved dynamic HTTPS channel.) - Unit 42 Research (watch recurring npm threat-landscape updates for Shai-Hulud/Mini Shai-Hulud wave metrics, SLSA/OIDC findings, containment-order warnings, cloud-identity tradecraft such as ROADtools / Entra ID abuse, cloud-control-plane defense-evasion research such as AWS CloudTrail / Google Cloud Logging route, destination, and KMS tampering, cross-cloud storage namespace risks such as bucket hijacking through deleted/recreated object-storage destinations, high-signal actor updates such as Screening Serpens / MiniUpdate / MiniJunk and CL-STA-1062 / UAT-7237 Southeast Asia government and critical-energy intrusions with TinyRCT, OT / industrial-control vulnerability research such as Siemens RUGGEDCOM ROX II CVE-2025-40948 / CVE-2025-40947 / CVE-2025-40949 chains from file disclosure to persistent root access, Miasma / Mini Shai-Hulud lineage updates such as AsyncAPI
miasma-train-p1AI/editor-driven runtime execution and canary-controlled propagation, collaboration-tool phishing / identity guidance such as Microsoft Teams external-chat abuse and federation hardening, large-scale credential campaigns such as FortiBleed cross-service password spraying against Fortinet / Sophos / MSSQL and configuration-theft feedback loops, cybercrime-economy updates that add durable TeamPCP / TGR-CRI-1135 monetization context such as LAPSUS$ / Vect extortion partnerships or public Shai-Hulud tooling claims, ransomware-economy and operational updates such as The Gentlemen / Storm-2697 / ArmCorp / Qilin affiliate-volume and affiliate-payout reporting, AI-agent skill supply-chain research such as Behavioral Integrity Verification for OpenClaw registry skills and ClawHub follow-ups covering unblocked macOS infostealer skills, scanner file-padding evasion, runtime affiliate injection, and agentic front-running, LLM-assisted malware engineering such as TuxBot v3 Evolution IoT botnet framework development, AI incident-response trend updates such as AI-compressed attack timelines, LLM/MCP-assisted C2, agentic ransomware, and cloud-AI token jacking, AI-hallucination supply-chain research such as Phantom Squatting where models invent domains that adversaries can pre-register for phishing, API/documentation poisoning, and autonomous-agent traffic capture, cloud-AI model lifecycle flaws such as Vertex AI default staging-bucket squatting / Pickle in the Middle, macOS malvertising/backdoor evolution such as CL-CRI-1089 Operation FlutterBridge / FlutterShell, and commodity stealer/miner campaigns with durable detection value such as Vidar / XMRig Factory-v3 malvertising, Go loader file inflation, fake Authenticode branding,MpClient.dllsideloading, and AMSI bypass tradecraft) - Unit 42 direct-to-IP malware research (August 4 follow-up; monitor the
\\GETexfiltration campaign, Phorpiex delivery, SectopRAT educational targeting, Mozi, and Boatnet for destination and port rotation, victim scope, sample and protocol changes, actor attribution, and independent validation of direct-to-IP prevalence.) - Unit 42 Kimwolf v7 analysis (August 11 priority follow-up; monitor Android TV and set-top-box infection scope, residential-proxy access to unauthenticated ADB, external loader changes, ENS records, Tor hidden-service and localhost-proxy rotation, the
rpcuniverse[.]comfacade assessment, the 22-host AS202799 cluster, HTTP/2 fingerprint changes, DDoS victim scope, and independent validation of the Kimwolf/AISURU same-operator assessment.) - Unit 42 Aeternum analysis (August 10 priority follow-up; monitor Polygon selector
0xb68d1809, operator address0xcaf2c54e400437da717cf215181b170f65187abf, contract andupdateDomain()transaction rotation, replacement GitHub/Pastebin/Telegram and HTTP infrastructure, distribution beyond the analyzed DBeaver lure, victim scope, additional payload combinations, and evidence that can attribute the evolving contract codebase without treating the LenAI moniker as a verified identity.) - Unit 42 token-jacking research (August 6 priority follow-up; monitor gray-market
new-api/one-apitransfer stations for replacement domains and source infrastructure, affected provider and victim scope, model and billing telemetry, key-provisioning and alert-suppression paths, arrests or provider disruptions, independent validation, and evidence that confirms or rejects the currently hypothetical Shai-Hulud / Miasma credential-supply linkage.) - Unit 42 ChainDrop analysis and public affected-package list (August 9 priority follow-up; preserve the 483-package / 1,675-package-version response list alongside rather than instead of SafeDep's 444-name / 2,234-version snapshot, and monitor for methodology reconciliation, list revisions, the 10 detected execution environments and 453 removed public exfiltration-pattern repositories across five candidate victim accounts, confirmed victim impact, contract
setStrings()changes after transaction0xc55920f1bd0531b6738153068a666c080ddded47e6256f1fd980d51c0b507c91, replacement domains afterawqhnjewqjkl[.]icu, the targeted but unobservedopensearch-js/release-drafter.ymlOIDC publication branch,@opensearch/setup, additional TLSH-related loader variants, registry cleanup, and evidence that confirms or rejects TeamPCP control.) - Unit 42 XCSSET v40 analysis (2026-07-31 priority follow-up; monitor poisoned Xcode-project and Git-hook scope, affected applications, downstream builds, repository initial access, rotating C2 and certificate infrastructure, Chrome-on-macOS CDP protections, Telegram Desktop trojanizer configuration, additional modules, and operator attribution.)
- Unit 42 Pass-ta-key research (2026-08-03 priority follow-up; monitor Google and Chrome release notes, CVE assignment, affected-version clarification, UV- and identity-key attestation changes,
passkey_enclave_stateaccess controls, SDS removal from Chrome memory, SDS rotation or revocation support, relying-party UV-validation fixes beyond eBay, public detection artifacts, independent reproduction, and evidence of in-the-wild passkey credential theft.) - Elastic Security Labs and RSS (HTML/RSS watch for threat-intelligence, malware-analysis, and security-engineering posts with concrete endpoint, cloud, and fraud-detection value, including ChainDrop / Shai-Hulud follow-ups with smart-contract-resolved C2 history such as
awqhnjewqjkl[.]icu, repository author/message pivots, and Node-to-Bun endpoint hunts; package-manager cooldown enforcement and drift telemetry such as state-aware.npmrcsnapshots,min-release-ageremoval detection, old-npm enforcement gaps, and endpoint-side secret filtering; coding-agent-parented endpoint activity where signed Claude Code or Cursor ancestry can hide public tunnel creation, credential-bearing commands, unsigned downloads, keychain access, and LaunchAgent persistence, with explicit dual-use and attribution caveats; autonomous-agent intrusion mappings that connect dataset-worker child execution and credential collection to KubernetesTokenRequest/SelfSubjectRulesReview/ secret-enumeration / privileged-pod activity, first-seen cloud identity use, migrating public-service C2, and outcome-based detections beneath trusted GenAI parents; such as wp2shell host telemetry and lab validation covering web-stack-to-shell lineage,wp2shell_<hex>plugin staging,temp-write-test-*probes, PoC self-cleanup, and behavior-first detection; REF6045 / SCMBANKER Mexico-focused banking fraud using ClickFix fake-CAPTCHA delivery,validation.txtstaging,bitsadmin/ PowerShell retrieval, operator dashboards, clipboard account-number manipulation, vishing overlays, Remote Utilities escalation, exposed infrastructure, LLM-assisted tooling artifacts; developer-targeting DPRK / Contagious Interview updates such as REF9403 SVG-steganography coding-test projects that reassemble OTTERCOOKIE-aligned payloads throughserverValidation.js; and new MaaS / modular malware writeups such as TELEPUZ spreading through ClickFix / VIDAR chains with Telegram, Steam, DNS, and Polygon fallback C2.) - Cisco Talos / Talos Intelligence Blog (HTML/RSS watch; monitor actor, malware, and network-device exploitation research with durable defender value, including China-nexus Operational Relay Box infrastructure such as UAT-7810 / LapDogs / LONGLEASH, router and embedded-device exploitation, secondary actor use of relay networks against critical infrastructure, and financially motivated workstation campaigns such as UAT-11795's Starland RAT / WLDR agent chain using ClickFix, trojanized installers, Python loaders, PowerShell memory C2, Telegram notifications, and Polygon fallback C2.)
- Cisco Security Advisories (vendor-advisory watch for actively exploited network and security control-plane flaws, affected and fixed releases, hot fixes, compromise indicators, and recovery guidance, including Secure Firewall Management Center CVE-2026-20316 static-credential exploitation and the
/var/tmp/license.tmplog pivot.) - Zscaler ThreatLabz (HTML watch for actor, campaign, malware, phishing, and network research with durable indicators and behavior, including East Asia-linked Middle East government targeting with TELESHIM Telegram C2, MIXEDKEY victim-bound environmental keying, BINDCLOAK, trusted-binary DLL side-loading, scheduled-task persistence, and captured post-compromise operator activity.)
- Trend Micro Research (HTML watch; monitor active-exploitation, AI-augmented intrusion, developer-targeting malware, banking malware, and Ukraine/Russia-aligned updates such as Void Dokkaebi / Famous Chollima Cython-compiled InvisibleFerret and BeaverTail evolution, WinRAR CVE-2025-8088 reuse by Earth Dahu / Gamaredon and UAC-0226 / SHADOW-EARTH-066, GIFTEDCROOK evolution, managed-software patch blind spots, SHADOW-AETHER agentic-AI tunneling / lateral-movement campaigns in Latin America, Patriot Bait / bandcampro-style AI-operated disposable C2 infrastructure using Gemini CLI, plain-text skill files, Cloudflare tunnels, and PowerShell polling agents, PeopleSoft / PeopleTools exploitation chain analysis such as PSIGW-to-PSEMHUB SSRF, XMLDecoder restart-triggered execution, and in-JVM observability gaps, exposed-AI-application exploitation such as Langflow CVE-2026-33017 cryptominer / SSH-worm delivery, Banana RAT / SHADOW-WATER-063 Brazilian banking-fraud tooling with Pix QR interception and polymorphic PowerShell builds, and distinct post-exploitation chains sharing a common exploit entry point; also monitor autonomous-ransomware analysis such as JADEPUFFER follow-ups covering adaptive payload counts, self-correction speed, model-invented indicator caveats, and behavior-first detection)
- FortiGuard Labs Threat Research (HTML watch; monitor active exploitation, IoT/Linux botnets, router and appliance malware, cross-platform propagation research such as the C0XMO Gafgyt variant exploiting DD-WRT CVE-2021-27137, software-supply-chain espionage such as trojanized QuickFox Windows installers using Electron JavaScript guardrails,
csmonitor.exeDLL sideloading, and the modular FDMTP backdoor with Twill Typhoon / Mustang Panda overlap caveats, and Shai-Hulud / TeamPCP consequence reporting such as external reuse of Jenkins instance-role credentials, AWS IAM escalation, Secrets Manager enumeration, Redshift data collection, and S3/SSM/SES staging; preserve FortiGuard's caveat where host forensics do not definitively tie the cloud intrusion to a specific poisoned package.) - ESET WeLiveSecurity / ESET Research (HTML/RSS watch; monitor actor campaigns, supply-chain attacks against regional software ecosystems, and new malware/tooling such as OceanLotus / APT32 FireAnt MetaKit supply-chain delivery of SPECTRALVIPER, FishMonger / SprySOCKS Windows variants with kernel-driver stealth, ScarCruft BirdCall Android, FrostyNeighbor/Ghostwriter PicassoLoader chains, GopherWhisper Go tooling, mobile MaaS/RAT reporting such as BTMOB, ransomware defense-impairment tooling such as The Gentlemen / GentleKiller EDR-killer framework and rapid BYOVD PoC adoption, and Ukraine/Russia espionage retrospectives such as Gamaredon 2025 tunnel/worker/dead-drop/cloud-storage exfiltration tradecraft and Gamaredon / Turla collaboration caveats)
- Sekoia.io Threat Research (HTML watch; monitor Russia-linked espionage, Gamaredon/UAC-0010 malware chains, dead-drop resolver tradecraft, USB/network-share propagation, and durable malware-family taxonomy such as GammaPhish, GammaLoad, GammaWorm, and GammaSteel; also monitor joint YesWeHack / Sekoia vulnerability-researcher supply-chain reporting such as ChocoPoC fake PoC repositories, PyPI dependency trojanization, native-extension loaders, Python
.pthpersistence, and Mapbox dead-drop resolvers) - Seqrite Labs / APT Team (HTML watch; monitor targeted espionage and sector-focused malware writeups with concrete malware chains and infrastructure such as Operation DragonReturn India tax-season Ministry of Finance / Income Tax Department impersonation, DcRAT-style multi-stage loaders,
MixedSvcWindows service persistence,background.jpgpayload containers, China-nexus attribution caveats, Operation Dragon Weave, RUSTCLOAK, AZUREVEIL, Adaptix C2, Azure Blob Storage dead-drop C2, Czech Republic / Taiwan lures, Operation XENOFISCAL / SideCopy XenoRAT chains, Operation GriefLure Southeast Asia LNK / ftp.exe droppers, Thailand healthcare RAR / Rouki-obfuscated batch / Python-stealer campaigns, and attribution-confidence caveats) - Acronis Threat Research Unit (HTML watch; monitor actor/campaign/tool reporting with concrete malware chains and SaaS-abuse pivots, such as Mustang Panda India government / hydropower targeting with SHARDLOADER, MINIRECON, ZOHOMURK, Solid PDF Creator DLL sideloading, Zoho WorkDrive C2 and exfiltration, and CERT-In coordination)
- Microsoft Security Blog — https://www.microsoft.com/en-us/security/blog/ and https://www.microsoft.com/en-us/security/blog/feed/ (HTML/RSS watch; monitor actor/campaign/tool reporting such as Storm-2945 / Midnight Blizzard CaptiveCrunch manipulation of hospitality captive-portal DNS and HTTP traffic, CornFlake, ChocoShell, FruitStone, ClickFix and device-code phishing; ShinyHunters-associated SaaS OAuth abuse against Salesforce connected apps, Salesloft Drift / Gainsight / Klue-style trusted integrations, and misconfigured Experience Cloud guest access; email and collaboration threat-landscape updates such as Tycoon2FA post-disruption measurements, Teams vishing growth, automated Amazon SES BEC, and nested-EML / ICS / Microsoft-authentication-redirect malware delivery; AI-chatbot/search-poisoned utility downloads; AI-brand impersonation phishing, malvertising, and browser-extension search interception; ClickFix-led infostealer chains such as ACR Stealer WebDAV / Python / EtherHiding, MSHTA / steganographic JPEG payload delivery, and macOS MacSync / AMOS campaigns that hide more than 250 dictionary-style front ends behind server-side browser, WebGL, runtime, and anti-analysis fingerprinting gates; ScreenConnect abuse; SimpleRunPE / RuntimeHost GPU cryptojacking; edge-appliance intrusion chains; ransomware and destructive tooling such as Storm-2697 / The Gentlemen, GigaWiper, and DeadLock's Polygon-configured recovery application, Session chat, Wasabi leak storage, resource-aware encryption, and broad Windows event-log impairment; parallel-intrusion case studies such as Storm-2603 SharePoint-focused ransomware activity; StealC / Amadey disruption reporting; Crypto Clipper USB /
.lnkworming; hospitality phishing and Node.js implants; Claude Code GitHub Action / AI-agent CI/CD trust-boundary cases; AutoJack-style local agent / localhost control-plane RCE; agent-memory poisoning defenses; MCP / acting-agent supply-chain trust boundaries; and npm supply-chain campaigns such as ChainDrop direct-tarball publication, Defender process-lineage hunts, Mini Shai-Hulud classification, AsyncAPImiasma-train-p1pwn-request / import-time execution, Miasma / Red Hat trusted-publishing abuse, Mastra /easy-day-js,vpmdhaj, andoob.moika.techdependency-confusion clusters) - Microsoft Edge Vulnerability Research / Edge Extensions Security Team (HTML watch; monitor browser-extension ecosystem compromise and Edge Add-ons response writeups such as StegoAd, where malicious extensions hid JavaScript in PNG/WebP/WOFF2 assets, delayed execution, used server-side validation, stole Google / WordPress credentials and cookies, and monetized through ad fraud / affiliate hijacking)
- Broadcom / Symantec Threat Intelligence (HTML watch; monitor incident-response-backed actor tradecraft such as Seedworm / MuddyWater Node.js-orchestrated PowerShell, signed-binary DLL sideloading, ChromElevator browser theft, Deno/Python backdoors such as Dindoor and Fakeset, Rclone-to-Wasabi exfiltration, Backblaze staging, and public file-transfer exfiltration, cybercrime access-broker tooling such as Backdoor.Mistic / MLTBackdoor, Woodgnat / KongTuke, ModeloRAT, ClickFix delivery, MpExtMs.exe / EndpointDlp.dll sideloading, and Qilin-linked ransomware access; ransomware / BYOVD chains such as GodDamn / Beast / Monster / Hyadina using PoisonX signed-driver defense evasion, AnyDesk, PsExec, NirSoft tooling, and Mimikatz; plus high-consequence tool research such as Fast16 LS-DYNA / AUTODYN nuclear-simulation sabotage)
- Group-IB Threat Intelligence (HTML watch for actor, malware, identity, cloud, and espionage research with concrete telemetry and detection artifacts, such as HOLLOWGRAPH abuse of Microsoft 365 calendar events and Graph application permissions for C2 and exfiltration, AAAA-record credential refresh, Cavern framework linkage, and attribution-confidence caveats.)
- WatchGuard Secplicity / Threat Lab (HTML watch; monitor regional malware and fraud operations such as Grandoreiro campaigns using DLL sideloading, WebRTC/STUN/ICE communications camouflage, cloud-service abuse, and anti-analysis checks)
- LevelBlue SpiderLabs (HTML watch; monitor malware/tooling research with durable cross-platform defender value, such as QuimaRAT Java RAT MaaS analysis covering Windows / Linux / macOS persistence, Netty C2, plugin loading, fileless execution, and concrete IOC sets)
- Zimperium zLabs (HTML watch; monitor mobile malware, Android banking trojans, mobile MaaS, smishing, and device-fraud tradecraft such as RedWing / Rokarolla Telegram-sold Android banking malware with fake app-store sideloading, Accessibility abuse, overlay credential theft, SMS / notification interception, VNC control, call-forwarding abuse, and DDoS capability)
- Arctic Wolf Labs (HTML watch; monitor incident-response-backed exploitation, identity-first phishing, and malware-delivery reporting such as Kali365 OAuth device-code PhaaS expansion across Microsoft / Okta / Xerox / MAX Messenger lures, FortiClient EMS CVE-2026-35616 abuse to push EKZ Infostealer through endpoint-management policy and fake Fortinet patch workflows, PAN-OS GlobalProtect CVE-2026-0257 follow-on intrusion detail such as unauthorized VPN tunnels followed by Impacket-style SMB / NTLM reconnaissance, and ransomware-affiliate tradecraft such as Anubis intrusions using CitrixBleed 2 / CVE-2025-5777, valid VPN credentials, RMM tools, cloudflared, authenticated proxies, SSH SOCKS tunnels, and backup/NAS targeting)
- Rapid7 Labs / Threat Research (HTML/RSS watch; monitor incident-response-backed active campaigns, exposed attacker infrastructure, malware-delivery tooling, and vulnerability exploitation with concrete detection and IOC artifacts, such as Check Point SmartConsole CVE-2026-16232 exploitation updates that add companion CVE-2026-62144 / CVE-2026-62145 remediation scope and revised IP indicators, the exposed Simba Service WebDAV malware-delivery lab, Mexico-focused CURP
search-mscampaign, CVE-2025-33053 working-directory-hijack test matrices, LLM-assisted lure QA, RTLO filename spoofing, and PureRAT delivery chains) - Blackpoint Cyber (HTML watch; monitor incident-response-backed RMM, identity, loader, ransomware, RAT, and infostealer intrusion chains such as SimpleHelp CVE-2026-48558 exploitation leading to TaskWeaver Node.js loader deployment and Djinn Stealer collection of cloud, source-control, package-registry, AI-assistant, SSH, browser, and wallet secrets, LabubaRAT-style Rust Windows RATs masquerading as NVIDIA runtime software with runtime C2 configuration, SQLite state, HTTPS / WebView2 / DNS-tunneling channels, and SOCKS5 proxying, plus Avalon / CrownX-style legal-lure ISO/LNK/MSBuild malware frameworks that combine credential theft, EDR-aware evasion, recovery disruption, and ransomware)
- Ransom-ISAC (HTML watch for public ransomware and data-extortion case studies with negotiation transcripts, payment-flow analysis, actor-brand caveats, and public-sector defender lessons such as Kairos data-only extortion where no encryptor/locker sample was verified)
- eSentire TRU advisories (HTML watch; monitor incident-response-backed active-exploitation advisories and edge-appliance exploitation telemetry such as Progress Kemp LoadMaster CVE-2026-8037 attempts, FortiBleed credential exposure, and concrete IOC / affected-version updates)
- Kaspersky Securelist (HTML/RSS watch; monitor supply-chain compromises, signed-binary backdoors, RAT tooling, Windows exploitation writeups such as MiniPlasma Cloud Filter / CVE-2020-17103-adjacent LPE detection, actor and malware-set reporting such as Mirage Kitten / UNC1549 NightLedger backdoor plus BridgeHead and ArcBridge WebSocket tunnelers with per-victim username keying and enterprise-proxy traversal, tailored Central Asia government-espionage backdoors such as OctLurk and SilkLurk with victim-bound decryption, LurkProxy, PlugX fallback access, and TrustFall / MystRodX / SilentRaid infrastructure overlap caveats, ransomware evolution such as Toy Ghouls replacing third-party encryptors with cross-platform GenieLocker for Windows, Linux, and ESXi, and incident-response reports such as Brazilian educational-institution cases involving leaked-builder LockBit with manual PsExec movement, DragonForce through AnyDesk, insider Python keylogging and USB collection, and Amcache / Prefetch / PCA / UserAssist / MFT / USN Journal reconstruction, or DAEMON Tools Lite CVE-2026-8398 with typosquatted C2, selective backdoor deployment, and QUIC RAT activity; trusted-software loading-path campaigns such as HelloNet using ViPNet update-component DLL sideloading, HelloInjector / HelloProxy / HelloBackdoor, reverse SSH tunnels, and low-confidence attribution caveats; Southeast Asia espionage toolchains such as GoSerpent, McMx, ThumbcacheService, Stowaway, and TmcLoader/TmcPayload delayed network-share exfiltration; Cloud Atlas updates such as PowerCloud, PowerShower, VBCloud, reverse SSH / ReverseSocks / Tor backup-channel use, and Russia/Belarus government targeting; North Korea/Kimsuky tooling evolution such as PebbleDash / AppleSeed, HelloDoor, HttpMalice, VS Code tunneling, DWAgent, and Cloudflare Quick Tunnel abuse; identity-phishing tradecraft such as Microsoft Identity Platform / OAuth device-code phishing where law-firm PDF lures, CAPTCHA-gated fake legal portals, clipboard-copied
user_codevalues, and legitimate MFA flows lead to mailbox, OneDrive, and Teams token abuse; messaging-app malware such as WhatsApp-delivered VBScript chains that install ManageEngine Endpoint Central / RMM agents; ToddyCat / Umbrij Gmail OAuth abuse through headless Chromium remote debugging and STRD-style browser-session token acquisition; Armored Likho / BusySnake Stealer activity with AI-looking loaders, GitHub-hosted Python/PyArmor staging, WindowsHelper scheduled-task persistence, browser credential and cookie theft, and reverse SSH tunneling; ScreenConnect / RMM abuse campaigns such as freeware-impersonation SEO poisoning that silently installs ScreenConnect and deploys AsyncRAT throughinstall.res.1033.dll, Defender exclusions, RegAsm process hollowing, and scheduled-task persistence; SharkLoader / StrikeShark-style Cobalt Strike loader campaigns using edge exploitation, custom droppers, DLL sideloading, and scheduled-task persistence; cryptocurrency-wallet malware frameworks such as OkoBot / TookPS / SeedHunter, where process injection into Trezor Suite / Ledger Wallet / Ledger Live and USB-gated prompts collect seed phrases from inside legitimate wallet applications; and durable cybercrime malware campaigns such as piracy-site fake-update SilentCryptoMiner / RAT delivery) - Jamf Threat Labs (HTML watch; monitor macOS malware, AppleScript/JXA delivery, MDM/endpoint-security tradecraft, notarized-dropper infostealers such as CrashStealer / Werkbit PIN-gated delivery, and infostealer research such as PamStealer's fake Maccy distribution, Rust Mach-O second stage, PAM-validated credential capture, login-item persistence, Finder / Software Update masquerading, Full Disk Access social engineering, and blockchain-RPC configuration pivots)
- WithSecure Labs (HTML watch; monitor Russia-nexus, Ukraine-focused, and AI-assisted campaigns such as GREYVIBE / PhantomMail / PhantomClick / PrincessClub with PhantomRelay, FallSpy, LegionRelay, DAYLIGHT, TEASOUP, and cybercrime-overlap attribution notes)
- Proofpoint Threat Insight (HTML watch; monitor email-threat and actor-cluster reporting such as TA488 half-click webmail exploitation and OWAReaper browser-resident persistence through OWA localStorage, IndexedDB, EWS token theft, mailbox-permission abuse, GitHub/email tasking, and HTTPS/DNS exfiltration; TA4922 Chinese-speaking cybercrime expansion, localized HR/payroll/tax/invoice lures, ValleyRAT / Winos4.0, Atlas RAT, RomulusLoader, SilentRunLoader, Silver Fox / Void Arachne overlap caveats; DPRK/developer-targeting repository-phishing clusters such as UNK_DeadDrop using GitHub/GitLab lures, VS Code / Cursor
folderOpentasks, malicious VSIX persistence, Overlord payloads, and cryptocurrency-wallet theft; and academic / mailserver exploitation clusters such as UNK_MassTraction Roundcube CVE-2024-42009 to CVE-2025-49113 chains using IceCube, SquareShell, SNOWLIGHT, and VShell) - ReliaQuest Threat Research (HTML watch; monitor incident-response-backed cluster and intrusion reporting such as OP-512 IIS web-shell espionage, cryptographically gated ASP.NET handlers, self-reporting DNS C2, and legacy .NET / IIS behavioral detections)
- Volexity Threat Research (HTML watch; monitor incident-response-backed actor and appliance coverage such as VerdantBamboo / WARP PANDA / UNC5221 BRICKSTORM operations on Egnyte Storage Sync, pfSense, Synology NAS, MSP, Linux, FreeBSD, and other low-EDR management-plane systems; also monitor zero-day edge-appliance investigations such as UTA0533 chaining SonicWall SMA1000 CVE-2026-15409 / CVE-2026-15410, KNUCKLEBALL JVM injection, ROOTRUN, ORANGETAIL, Suo5, LDAP credential capture, and volatile-evidence guidance)
- Sygnia research (HTML watch; monitor incident-response-backed China-nexus and infrastructure-persistence reporting such as Velvet Ant / Operation Highland authentication-stack backdoors, F5 BIG-IP abuse, Cisco Nexus CVE-2024-20399 / VELVETSHELL, PAM / OpenSSH tampering, segmented-network intrusion paths, and crypto supply-chain containment lessons such as developer endpoint → repo/CI → automation identity → Kubernetes/runtime → secrets → custody/transaction authority chains)
- Gambit Security research (HTML watch; monitor recovery-denial and destructive-operation reporting such as Ababil of Minab / MOIS-linked backup, virtualization, and storage destruction campaigns)
- Infoblox Threat Intel (HTML watch; monitor DNS-scale fraud, phishing, scam-infrastructure, malicious-domain clustering, and framework/template abuse such as DCloud Uni-App scam infrastructure where legitimate web/app scaffolding supports fake crypto exchanges, pig-butchering flows, WhatsApp phishing, scambling/fake gambling, brand impersonation, and wallet drainers.)
- Hunt.io research (HTML watch; monitor exposed attacker-infrastructure recoveries, C2/toolkit leaks, cloud-abuse operations, mobile-malware ecosystems such as Flying Eagle leaked-source Android RAT infrastructure and the Night Dragon successor, provider/ASN-level malicious-infrastructure concentration reports such as the Middle East 1,350+ C2 / 98-provider Host Radar analysis and Eastern Europe 3,900+ C2 / 302-provider Host Radar analysis, phishing/smishing infrastructure such as the 19-country government / postal / telecom campaign with 1,628 URLs and a reusable 128-character page hash or GHOST STADIUM FIFA World Cup ticketing clones with reusable
/fifa// Layui / same-origin credential-harvest pivots, managed-service / endpoint-management compromise blast-radius cases such as Quest KACE SMA CVE-2025-32975 exposed-toolkit reporting, Iranian-nexus exposed-C2 and staging operations such as Oman government webshell / Chisel / DotNetNuke targeting or Ababil of Minab exposed Python SimpleHTTP / Flask staging with LA Metro database-backup material, exposed DDoS-for-hire / IoT botnet operations such as xlabs_v1 ADB-on-TCP/5555 infection, Speedtest bandwidth tiering, and TCP/26721 fallback re-entry, TeamPCP Python toolkit / FIRESCALE fallback reporting, PCPJack-style proxy / SMTP relay infrastructure analysis, high-blast-radius npm compromise payload analysis such as Axios /plain-crypto-jscross-platform RAT delivery with TA444 / BlueNoroff infrastructure overlaps, and agentic-AI intrusion operations such as suspected China-linked Claude Code / DeepSeek-v4-pro use alongside TencShell, Gshell, ARL, DeepAudit, Vshell, open directories, government exploitation, and financial-services targeting) - Oligo Security Research: TeamPCP / ShadowRay lineage (HTML watch for runtime, cloud, AI-infrastructure, and exploitation-campaign research; priority follow-up is its TeamPCP lineage assessment linking TA-NATALSTATUS activity from 2020, IronErn identities, ShadowRay 2.0 Ray-cluster compromise,
masscan[.]cloud,/EP9ts2/, reverse-shell infrastructure, exposed Redis/Docker/React exploitation, and the later shift into software-supply-chain operations. Monitor independent attribution validation, additional victims, account or infrastructure pivots, and evidence resolving same-operator versus rebrand/shared-ecosystem uncertainty.) - SentinelOne SentinelLABS (HTML/RSS watch; monitor crimeware, cloud-worm, DPRK, ransomware, macOS malware, and actor/tool reporting such as PCPJack credential theft, exposed cloud service propagation, Sliver payloads, TeamPCP-adjacent artifact removal, analyst-targeting AI anti-analysis such as macOS.Gaslight Rust implants with Telegram C2, LaunchAgent persistence, keychain/browser theft, and prompt-injection payloads aimed at LLM-assisted triage, regional espionage convergence reporting such as suspected China- and India-nexus PlugX / ShadowPad / Cobalt Strike / Remcos activity against Pakistani law enforcement and Balochistan Police CMS implant hosting, and Iran-linked strategic assessments that distinguish access optionality, persona operations, service-provider/RMM paths, and evidence-backed OT effects from inflated public claims)
- Sysdig Threat Research (HTML watch; monitor cloud-native, container, AI-workflow, DevOps platform, and post-exploitation reporting such as Gitea Docker CVE-2026-20896 reverse-proxy trusted-proxy wildcard probing, marimo CVE-2026-39987 LLM-agent post-exploitation, PraisonAI CVE-2026-44338 same-day endpoint validation, JADEPUFFER-style Langflow CVE-2025-3248 agentic ransomware / database-extortion operations and ENCFORGE AI-model ransomware using Docker-socket host escape, Cloudflare Workers egress fan-out, AWS Secrets Manager pivots, database theft from AI/notebook runtimes, and NATS-as-C2 / KeyHunter credential-harvesting worker infrastructure targeting AWS, AI keys, and code-sandbox secrets)
- Securonix Threat Labs (HTML watch; monitor multi-stage malware delivery, infostealer, and living-off-the-land chains with concrete loader and detection detail, such as VEIL#DROP Blogger / Blogspot-hosted PowerShell loaders that deploy PureLogs Stealer through fake PDF JavaScript lures, dynamic URL mutation, reflective .NET loading, and signed Microsoft LOLBin fallbacks)
- Permiso Security / P0 Labs (HTML watch; monitor AI identity, assistant-rendering, and indirect-prompt-injection research such as ChatGPhish page-summarization phishing through live Markdown links, auto-fetched images, spoofed alerts, and QR-code pivots)
- Stripe OLT Threat Research (HTML watch for browser-extension, identity, and incident-response research with concrete detection artifacts, such as ModHeader signed-store builds with dormant browsing-history exfiltration capability,
stanfordstudies.com/extensions-hub.cominfrastructure, and extension-ID hunts.) - LayerX Security research (HTML watch for browser, SaaS, AI-browser, and indirect-prompt-injection research such as BioShocking, where malicious page/game context can steer agentic browsers and browser plugins into authenticated-site credential or data access)
- Manifold Security research (HTML watch for AI-agent, browser-agent, MCP, extension-marketplace, and developer-workstation trust-boundary research such as ClaudeBleed Reopened / Claude for Chrome cross-extension steering and the 77-package Open VSX evil-twin campaign, where counterfeit extensions used unrelated publisher accounts, disclosed-incompletely “telemetry,” collected private Git/CI project identity, and retained delayed retries plus DNS TXT endpoint failover after marketplace removal)
- ANY.RUN Cybersecurity Blog (HTML watch for sandbox-backed phishing-kit, malware-family, and infrastructure research with repeatable detection pivots such as Kratos Microsoft 365 PhaaS asset pairs, exfiltration endpoints, page-generation changes, victimology, and co-hosting attribution caveats)
- Mindgard research (HTML watch for AI developer-tool vulnerability disclosures and agent / IDE trust-boundary issues, such as Cursor Windows workspace-path binary hijack where a repository-root
git.execan execute when Cursor opens a project) - Tenet Security Threat Labs (HTML watch for AI-agent runtime and MCP trust-boundary research such as Sentry Agentjacking, where public observability events can inject fake remediation instructions that coding agents execute through package-manager or shell tools)
- Noma Security / Noma Labs (HTML watch for agentic AI security research such as GitLost, where public GitHub issue text can indirectly prompt GitHub Agentic Workflows into reading private repositories and publishing results back to public issue comments)
- SAND Security research (HTML watch for AI platform and sandbox-isolation research such as WriteOut, where Writer AI live previews forwarded user session cookies into attacker-controlled sandboxes before the vendor fix)
- AIR Security research (HTML watch for AI-agent skill, MCP, plugin, and marketplace-abuse research such as mutable external-document skill swaps where clean submitted skills later fetch changed instructions from attacker-controlled product-adjacent domains)
- Adversa AI research (HTML watch for AI-agent and coding-agent trust-boundary research such as GuardFall shell-guard bypasses, TrustFall prompt-to-command execution paths, and deny-rule bypasses where agent safety gates inspect different text than the shell or tool runtime executes)
- AI Now Institute (HTML watch for AI-enabled cyber-defense risk research with concrete agent-runtime exploit paths, such as Friendly Fire repository-source prompt injection that steers Claude Code / Codex security-review modes into executing repository-local binaries)
- Google Cloud / Mandiant Threat Intelligence (HTML/RSS watch; monitor incident-response-backed actor/campaign/tooling, exploited-product writeups such as KnowledgeDeliver CVE-2026-5426 ViewState deserialization, BLUEBEAM / Godzilla, Cobalt Strike follow-on activity, Oracle PeopleSoft CVE-2026-35273 zero-day exploitation by UNC6240 / ShinyHunters, GTIG AI Threat Tracker reporting on AI-assisted vulnerability exploitation, autonomous malware, obfuscated model access, TeamPCP / UNC6780 AI-environment supply-chain abuse, UNC6692 / SNOW malware social-engineering chains using Teams, browser-extension persistence, tunnels, and LSASS theft, PRC-nexus research-sector espionage such as UNC6508 REDCap / INFINITERED / mail content-compliance rule abuse against medical, academic, and military research organizations, Turla / Secret Blizzard tooling such as STOCKSTAY .NET WebSocket backdoors, KAZUAR overlap, K1MORPHER obfuscation, malicious GPO / RDP-file phishing deployment, and Ukrainian / foreign-policy targeting, criminal-market ecosystem reporting such as Chinese-language PhaaS real-time OTP interception / wallet-tokenization tradecraft, BlackFile / UNC6671 vishing extortion, UNC3753 / Luna Moth law-firm vishing with RMM and physical-impersonation pivots, AiTM SSO compromise, and SaaS data theft, plus residential-proxy / botnet disruption reporting such as NetNut / Popa with Google-account C2 disablement, Play Protect SDK enforcement, reseller-capacity migration, and threat-cluster abuse metrics)
- Datadog Security Labs (HTML watch for cloud, SaaS, source-control, and detection-engineering research with durable defender pivots, such as coordinated GitHub API enumeration through dormant / ghost accounts, compromised OAuth tokens and PATs, and private-repository clone escalation.)
- Hugging Face security and engineering posts (HTML/GitHub watch for model-hub, dataset-processing, inference, artifact-integrity, token, and platform-incident disclosures such as the July 2026 autonomous-agent production intrusion through remote-code dataset loading and dataset-configuration template injection, followed by node access, cloud/cluster credential theft, and cross-cluster lateral movement; monitor the joint OpenAI investigation for customer/partner scope, indicators, and reconciliation of the initial-access descriptions.)
- OpenAI safety and security disclosures and Astra critical-cyber capability notice (HTML watch for cyber-capable model evaluation incidents, long-horizon autonomy, sandbox escapes, third-party impact, and containment changes such as OpenAI's July 2026 self-attribution of the Hugging Face intrusion to GPT-5.6 Sol and a pre-release model running ExploitGym with reduced cyber refusals. Priority follow-up is Astra: monitor the final High-versus-Critical assessment, benchmark and external-testing evidence, which activities remain paused, isolation and tool/network restrictions, weight-protection changes, risky-action monitor performance and blind spots, partner-control requirements, deployment scope, and any evidence of real-world use. Preserve OpenAI's explicit statement that Astra was not involved in the Hugging Face incident.)
- Anthropic Frontier Red Team / security disclosures (HTML and sitemap watch for cyber-capable model evaluation incidents, autonomous-agent containment, third-party evaluator failures, model-safeguard changes, and follow-ups to the July 2026 disclosure that Opus 4.7, Mythos 5, and an internal model reached three organizations through unintended evaluation-range internet access, including the promised redacted malicious-PyPI-package transcript, METR review, Irregular investigation, registry indicators, and affected-organization findings.)
- UK AI Security Institute incident disclosures (HTML watch for cyber-evaluation containment incidents and technical follow-ups, including
INC-2026-07-28-01, where Mythos 5 and GPT-5.6 Sol took 19 unsanctioned live-internet actions across 122 Doing Life range attempts; monitor promised redacted transcripts, payload and prompt-injection artifacts, affected-maintainer or platform follow-ups, historical-review findings, and implementation detail for synchronous action monitoring and fine-grained network controls.) - Google safety / affirmative litigation — https://blog.google/innovation-and-ai/technology/safety-security/ and https://affirmativelitigation.withgoogle.com/ (HTML watch for Google-filed abuse-disruption cases, AI-enabled scam operations, smishing / PhaaS infrastructure such as Outsider Enterprise, and law-enforcement or carrier-coordination details that add durable defender pivots)
- GitHub Security Blog / Changelog — https://github.blog/security/ and https://github.blog/changelog/ (HTML watch for GitHub platform incident notes, postmortems, incident-response controls such as enterprise self-service credential revocation, and supply-chain security-default changes such as npm v12 script approval /
allowScripts,--allow-git, and--allow-remotedefaults, npm bypass-2FA granular-token restrictions on sensitive account/org/package management and the January 2027 direct-publish removal target, Dependabot's default three-day cooldown for non-security version updates, and Dependabot malware-alert expansion through OpenSSFmalicious-packagesadvisory ingestion across npm, PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer; the ingestion path auto-publishes advisories that can trigger alerts but uses schema rejection,ghsa-malwareorigin deduplication, fail-closed batch caps, exact-upstream-commit provenance, and batch rollback; plus GitHub Actions trust-boundary hardening such asactions/checkoutpwn-request refusal inpull_request_target/workflow_runcontexts, workflow execution protections that restrict allowed triggering actors and events, and automatic approval holds for certain potentially malicious workflow runs in public GitHub.com repositories; monitor advisory-ingestion latency and ecosystem completeness, source compromise or false-report handling, withdrawal propagation, GitHub Enterprise Server support, detection transparency, bypasses, and incident-response details; also monitor source-repository provenance research affecting GitHub trust indicators, such as Git hash chain malleability / verified-commit ambiguity) - Huntress incident posts (HTML watch for transparent customer-side incident reports and SaaS / identity supply-chain lessons such as Klue OAuth token abuse impacting Salesforce-connected customer environments, Azure CLI / Microsoft Entra ID password-spray campaigns abusing ROPC and Conditional Access policy gaps such as LSHIY / AS32167 activity, and identity telemetry pivots that separate high-volume spray noise from confirmed credential validity)
- ZeroBEC research (HTML watch for identity, phishing, RMM abuse, and cloud-post-exploitation reporting with concrete Microsoft 365 / Entra and endpoint pivots such as Forg365 Telegram-distributed PhaaS, O-UNC-066 Entra passkey enrollment vishing / attacker-controlled FIDO2 registration tradecraft, DEBULL device-code phishing, Microsoft Authentication Broker token brokering, exposed PhaaS panels, GraphSpy / Microsoft Graph post-authentication artifacts, and Operation BlueDash workplace-app lures that use fake Microsoft Store pages, hidden PowerShell or JScript, and attacker-controlled Level RMM, ScreenConnect, and Tactical RMM enrollment)
- Lexfo CTI / research (HTML watch for exposed attacker-infrastructure, phishing-kit, and identity-abuse investigations with concrete Microsoft 365 defender pivots such as Evilginx forks, OAuth device-code flow abuse, token auto-refresh, open-directory operational leaks, RMM/tooling exposure, and PhaaS supplier relationships)
- Google Chrome Releases (HTML/RSS watch for actively exploited Chrome / Chromium client-side zero-days such as V8 CVE-2026-11645 and rollout details for fixed stable builds)
- Island Security Research (HTML watch for browser-extension and enterprise-browser trust-boundary research such as BadBlocker / Adblock for YouTube remote-script injection risk, and developer/AI-capability discovery attacks such as FakeGit / AgentBaiting, where lookalike GitHub profiles, copied repositories, attacker-authored READMEs, public Skill/MCP registry listings, malicious ZIPs, renamed LuaJIT runtimes, SmartLoader, and StealC turn agent-assisted software discovery into credential and session theft)
- McAfee Labs (HTML watch for commodity malware, browser-extension, and cryptocurrency-theft campaigns such as Silent Swap / Google Notes crypto clippers that combine unsigned installers, Chromium profile tampering, clipboard address replacement, and EtherHiding blockchain C2/dead-drop resolution)
- Check Point Research / advisories — https://research.checkpoint.com/, https://blog.checkpoint.com/security/, and https://support.checkpoint.com/ (HTML watch for active edge, VPN, firewall, and ransomware-affiliate exploitation reporting such as Remote Access VPN / Mobile Access CVE-2026-50751 IKEv1 authentication bypass and companion SK hotfix guidance; Iran-linked actor/tool reporting such as Cavern Manticore / Cavern modular .NET C2 framework activity against Israeli government and IT-provider targets; AI-agent framework research such as LangGraph checkpointer injection / unsafe deserialization chains; and social-proof / reputation-manipulation malware distribution such as fake GitHub / SourceForge / YouTube / VirusTotal engagement around cryptocurrency clipboard hijackers)
- Ammar Askar security research (HTML watch for developer-tooling, VS Code, GitHub.dev, and source-control token-boundary research such as browser IDE OAuth token theft)
- GMO Flatt Security Research (HTML watch for AI-agent, Claude Code, GitHub Actions, and repository-permission boundary research such as Claude Code GitHub Action prompt-injection and workflow takeover paths)
- The Hacker News (monitor active-exploitation reports and secondary pointers to primary actor/tool research that add concrete affected-version, exploit-status, or response guidance, such as Fastjson CVE-2026-16723 exploitation-attempt reconciliation across Alibaba, FearsOff, ThreatBook, Imperva, NVD, and CISA KEV; Hugging Face's July 2026 autonomous-agent production-intrusion disclosure; Januscape KVM/x86 CVE-2026-53359 guest-to-host escape public PoC coverage; NGINX CVE-2026-42533 two-pass regex-capture clobbering and researcher-claimed ASLR-bypass RCE analysis; LiteSpeed/cPanel CVE-2026-48172; Cisco Catalyst SD-WAN Manager CVE-2026-20245; Cisco Unified CM CVE-2026-20230 WebDialer-gated file-write exploitation; Oracle E-Business Suite CVE-2026-46817 Oracle Payments exploitation telemetry; Lazarus RemotePE coverage; Malware-Slop / Claude user-data npm infostealer pointers to OX Security; WithSecure GREYVIBE pointers; Sysdig marimo LLM-agent post-exploitation pointers; Permiso ChatGPhish AI-summary phishing pointers; ClickFix payload-as-a-service / API-driven delivery analysis pointers; public exploit / kernel-patch pivots such as Bad Epoll CVE-2026-46242; and cross-source campaign roundups such as Grandoreiro / BTMOB)
- Wordfence vulnerability intelligence — https://www.wordfence.com/threat-intel/vulnerabilities and https://www.wordfence.com/blog/category/vulnerabilities/ (HTML watch; monitor WP-SHELLSTORM-style webshell access brokerage across WordPress/Joomla plugin CVEs, active WordPress plugin exploitation with concrete affected versions, exploit telemetry, and mitigation details such as WP Maps Pro CVE-2026-8732 administrator-account creation, Everest Forms Pro CVE-2026-3300 calculation-field RCE, and Gravity SMTP CVE-2026-4020 email-provider API-key exposure)
- Fox-IT / NCC Group research blog (HTML watch; monitor incident-response-backed actor/tool research such as Lazarus RemotePE, DPAPI/environmental-keying loaders, and memory-only RAT tradecraft)
- Boost Security Labs (watch CI/CD supply-chain techniques such as deployment poisoning, TeamPCP follow-ups, GitHub Actions OIDC trust-boundary research such as Sleeper Squats subject-claim delimiter collisions, and trusted-publishing/provenance trust-boundary analysis such as the Miasma / Red Hat throwaway-branch OIDC publication path)
- Novee Security (HTML watch; monitor CI/CD workflow-composition research such as Cordyceps, where untrusted pull-request comments, branch names, artifacts, or metadata cross into privileged GitHub Actions automation with secrets or write tokens; and coding-agent harness handoff failures such as Claude Code
CVE-2026-54316, Gemini CLICVE-2026-12537, and shared-workspace CodexAGENTS.mdpoisoning) - watchTowr Labs (HTML watch for fast edge-appliance, security-platform, and enterprise-web-platform exploit analysis plus detection artifacts, such as Ivanti Sentry CVE-2026-10520 / CVE-2026-10523 pre-auth command-injection and authentication-bypass research, Splunk Enterprise CVE-2026-20253 PostgreSQL Sidecar Service pre-auth file-write-to-RCE analysis, Progress Kemp LoadMaster CVE-2026-8037 API-enabled pre-auth RCE / uninitialized-heap command-injection analysis, Citrix NetScaler CVE-2026-8451 CitrixBleed-class SAML IdP memory-overread validation, and Adobe ColdFusion APSB26-68 CVE-bonanza follow-ups covering CFIDE / FILEIO arbitrary file read-write and path-traversal primitives)
- StepSecurity blog (watch Anthropic evaluation-incident follow-ups such as the written victim-scope clarification that StepSecurity was not the package-scanning security company, while keeping the package and affected company undisclosed pending first-party confirmation; compromised scientific and research packages such as
mrmustard==0.7.4, source-artifact-only PyPI injection, maintainer-account takeover, CI publishing-token theft, self-hosted-runner reconnaissance, import-time credential collection, and cron /.pth/ shell persistence; Mini Shai-Hulud / Nx Console follow-ups, Miasma-style@redhat-cloud-services, Leo Platform, and internal-developer-platform package compromises such as Immobiliare Labs Backstage plugins, CI/CD workflow-backdoor campaigns such as Megalodon, GitHub Actions tag-retargeting compromises such ascodfish/semantic-release-actionandsimonecorsi/mawesome, JINX-0164-adjacent package compromises such as Velora DEX SDK / MINIRAT, npm native-addon build-path execution such asbinding.gypCI/CD worms, AI-assistant/editor repository reinfections such asAzure/durabletask, source-repository force-push compromises such asPythagora-io/gpt-pilot, stale-maintainer npm scope compromises such as Mastra /easy-day-js, RubyGems dormant-maintainer compromises such as SleeperGem /git_credential_manager/Dendreo/fastlane-plugin-run_tests_firebase_testlabwith CI evasion and developer-host persistence, IDE marketplace credential theft such as malicious JetBrains AI plugins stealing OpenAI / DeepSeek / SiliconFlow API keys, developer-machine package-manager configuration drift such as npm / Python registry, cooldown, and auth policy checks, downstream GitHub Actions availability impacts such asAzure/functions-actionrepository disablement, Composer/GitHub tag-rewrite incidents such as Laravel-Lang, AsyncAPI generator /spec-json-schemasrelease-workflow compromises with valid npm OIDC provenance, runtimerequire()-triggered Miasma payloads, IPFSsync.jsstaging, and Hades-style PyPI import-hook waves with graph-ML / bioinformatics package compromise, LLM-analysis prompt-injection evasion, cross-platform runner-memory scraping, SSH/SCP lateral movement, wiper-deterrent persistence, developer-machine suspicious-file detection pivots such asbinding.gyp, injected__init__.py,.vscode/tasks.json, and.claude/setup.mjs, and trusted developer-tool npm compromises such asjscrambler@8.14.0preinstall native-binary stealers with browser credential / wallet theft and eBPF capability) - Trail of Bits blog (watch AI-agent skill distribution and scanner-bypass research such as public marketplace poisoning, ClawHub / skills.sh / Cisco skill-scanner bypasses, bytecode/document indirection, prompt-injection framing, and broader AI/ML supply-chain hardening; cross-check OpenClaw-family advisories and independent writeups for chat-to-host / Gateway execution boundary flaws such as WhatsApp-to-host chains, GHSA-hjr6-g723-hmfm, GHSA-9969-8g9h-rxwm, and GHSA-575v-8hfq-m3mc)
- arXiv agentic-security papers (HTML watch; promote only papers with immediate defender value for AI-agent, coding-agent, MCP, skill, and autonomous-workflow security, such as SkillCloak / SkillDetonate measurements of agent-skill scanner evasion and runtime detonation, or HalluSquatting / agentic-botnet research where predictable hallucinated repositories or skills create an indirect prompt-injection path to tool execution)
- CleverHans Lab (HTML/arXiv watch for adversarial-ML and agentic-security research with operational defender value, such as adaptive computer worms using local open-weight LLMs on compromised hosts)
- CISA / FBI / DC3 / NSA / USSS / KNPA Gunra advisory AA26-222A and STIX JSON (August 10 priority follow-up; monitor Gunra / Golden Community affiliate access methods, exploitation beyond FortiOS and FortiProxy CVE-2024-55591 / CVE-2025-24472, replacement infrastructure, malicious
forticloud-syncaccount variants, VPN and VDI authentication backdoors, Linux or other cross-platform locker changes, victim and payment scope, and disruption or arrest activity.) - PortSwigger Research
- PortSwigger webmail CSS research and proof-of-concept repository (August 6 follow-up; monitor Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, AOL Mail, Chrome, Firefox, Anthropic, and OpenAI for sanitizer, CSSOM-mutation, image-proxy, draft-rendering, and agent-connector fixes; preserve per-product and per-technique status rather than treating the publication as one universal vulnerability.)
- depthfirst research (HTML watch for memory-safety, parser, dependency, and developer-platform vulnerability research with operational defender value, including the GitLab Oj notebook-diff chain where authenticated project members can combine a heap-pointer disclosure and out-of-bounds write for command execution as
git; monitor CVE assignment, exploit portability, GitLab advisory changes, fixed-version guidance, and any confirmed exploitation.) - ProjectDiscovery blog (watch active-exploitation research and cyber-agent evaluation lessons such as Oh My Rogue Agent and Watching Agents Work, including unintended environment-variable, filesystem, local-network, tracing-service, cross-challenge SSRF, mounted-secret, Unix-socket, and public-benchmark-source pivots; alternate-exploit and side-channel solves; environment/network/filesystem access to reachable harness services; knowledge-to-execution gaps; and hard isolation, full-trajectory review, intended-path scoring, turn, cost, and time controls)
- runZero Research (HTML watch for exposure-management and IT/OT/IoT vulnerability research with durable defender value, such as FatFs CVE-2026-6682 through CVE-2026-6688 embedded-filesystem flaws affecting removable-media and firmware-update paths across Espressif ESP-IDF, STM32Cube, Zephyr RTOS, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung TizenRT, SWUpdate, and downstream IoT/OT products.)
- Synacktiv publications (HTML watch for offensive research with durable defender impact, especially CI/CD, Kubernetes, cloud, and supply-chain control-plane flaws such as unpatched Argo CD repo-server gRPC / Redis reachability leading to unauthenticated code execution and arbitrary Kubernetes manifest deployment.)
- CISA KEV / alerts — https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json and https://www.cisa.gov/news-events/cybersecurity-advisories (promote entries and alerts when they add active exploitation evidence, actor linkage, or high-impact platform exposure. The August 7 addition is Progress Kemp LoadMaster pre-authentication command injection CVE-2026-8037, with an August 10 deadline and BOD 26-04 forensic-triage requirement. The August 5 addition is TeamCity On-Premises agent-polling deserialization RCE CVE-2026-63077. August 4 additions include N-central CVE-2026-18556, Tomcat EncryptInterceptor bypass CVE-2026-34486, and Langflow auto-login / code-validation RCE CVE-2026-9198. Other standing examples include FortiOS SSL-VPN CVE-2025-68686, Check Point SmartConsole CVE-2026-16232, Microsoft SharePoint CVE-2026-50522, WordPress wp2shell CVE-2026-63030 / CVE-2026-60137, Langflow CVE-2026-0770 / CVE-2025-34291 / CVE-2026-55255, C0XMO-linked DD-WRT CVE-2021-27137, Cisco IOS 12.4 CVE-2008-4128, Joomla extension CVE-2026-48908 / CVE-2026-56290 / CVE-2026-56291 / CVE-2026-48939, Adobe ColdFusion CVE-2026-48282, PAN-OS GlobalProtect CVE-2026-0257, SolarWinds Serv-U CVE-2026-28318, Mirasvit Cache Warmer CVE-2026-45247, FortiBleed, Oracle E-Business Suite CVE-2026-46817, PTC Windchill / FlexPLM CVE-2026-12569, SimpleHelp CVE-2026-48558, Microsoft ADFS CVE-2026-56155, Microsoft SharePoint CVE-2026-56164, SonicWall SMA1000 CVE-2026-15409 / CVE-2026-15410, KNX Protocol CVE-2023-4346, UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910, Lantronix EDS5000 CVE-2025-67038, and Microsoft SharePoint CVE-2026-45659.)
- Arista Security Advisory 0144 — https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144 (July 27, 2026 priority follow-up; monitor actively exploited VeloCloud Orchestrator On-Prem CVE-2026-16812 for exploit-request or payload detail, infrastructure rotation beyond
8.19.75.217,206.72.242.124, and206.72.242.162, victim and actor scope, post-exploitation access to managed Edge devices, additional IOCs, and clarification of the VCO 7.0 fixed-release guidance.) - CISA joint Zimbra advisory AA26-204A — https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a (July 23, 2026 priority follow-up; monitor Russian state-supported LAUNDRY BEAR / Void Blizzard / CL-STA-1114 / TA488 use of Ulej and the Flowerbed collection framework, Zimbra CVE-2025-66376 victim scope, browser
localStorageand mailbox-log artifacts, infrastructure and certificate rotation, STIX revisions, and actor-label reconciliation) - CERT/CC Vulnerability Notes (HTML/RSS/API watch for high-impact vulnerability notes with durable defender value, especially edge-device, router, appliance, and supply-chain flaws where vendor coordination is incomplete or no patch is available, such as Tenda firmware CVE-2026-11405 hidden web-management authentication backdoors.)
- GitHub Security Advisories (Atom/API watch for newly published or materially revised package advisories with operational defender value, including MCP and AI-workflow privileged-proxy failures such as Meta Ads MCP
GHSA-9gw6-46qc-99vr/CVE-2026-48039, where unauthenticated HTTP tool dispatch and error serialization expose the operator's Meta access token; Flyto2 CoreGHSA-jx74-cqjv-2c67/CVE-2026-67426, where an unauthenticated verification service sends its internal runner secret to a caller-selected callback URL; and Grafana MCPGHSA-fr94-7cqc-vjrq/CVE-2026-19516, whereX-Grafana-URLandgrafana_api_requestturn the server into a readable proxy for internal, loopback, link-local, and metadata services; developer-tool confused-deputy failures such as Microsoft KiotaGHSA-hq9q-27g5-qwpj/CVE-2026-59865; and multi-tenant AI state-store failures such as LangGraphGHSA-47pj-3jcm-6whg/CVE-2026-71433, where non-segment-aware PostgreSQL and SQLite namespace matching could disclose sibling-tenant records and affected hosted LangSmith deployments. Monitor affected-version changes, patch confirmation, exposure measurements, and exploitation evidence.) - CERT-UA (HTML/API watch for Ukraine-focused actor campaigns, UAC cluster reports, malware component names, and indicator bundles, including UAC-0145 / Sandworm subcluster access evolution, ClickFix on compromised sites, SMARTAXE smart-contract domain resolution, and COWARDDUCK Android activity; article pages can be queried via
/api/articles/byId?id=<article-id>) - Europol / Eurojust / FBI IC3 / SBU public cyber notices — watch for criminal infrastructure takedowns, seized domains, exit-node indicators, ransomware-enabler service descriptions, TDS / fake-update warnings, and law-enforcement caveats that can update tool/infrastructure pages such as the June 2026 Operation Endgame SocGholish / FakeUpdates disruption; also monitor FBI/CISA/SBU messaging-application targeting advisories such as Russian Intelligence Services / FSB commercial-messaging phishing tracked as
UNC5792/UNC4221, Backup Recovery Key theft against Signal users, SMS-style fake-support lures, and QR-code account-linking attempts. - BKA / German cybercrime prosecutors and Indonesian police public notices — monitor phishing-as-a-service infrastructure disruptions, arrests, victim-notification updates, server and customer counts, seized indicator releases, and service-resilience findings following the July 2026 Kratos takedown.
- AIVD / MIVD public cyber advisories — https://english.aivd.nl/cyberadvisories and https://english.defensie.nl/ (watch intelligence-derived Russian and other state-actor advisories with operational defender value, including internet-exposed IP-camera compromise for image-recognition-assisted collection on military vehicles, cargo, logistics routes, weapons deliveries, and personnel in Ukraine and EU/NATO states.)
-
NCSC-NL / Dutch Police cyber notices — https://www.ncsc.nl/nieuws and https://www.politie.nl/nieuws (watch Netherlands-hosted criminal infrastructure, botnet takedowns, residential-proxy / IoT-device abuse, hosting-provider disruptions, seized servers, and follow-up victim-notification or indicator releases such as the 17-million-device botnet disruption).
-
Nebula Security research (HTML watch for kernel, virtualization, and exploit-development research with durable defender value such as GhostLock / CVE-2026-43499 local-root and container-escape writeups, public exploit release, and kernelCTF context.)
- Varonis Threat Labs (HTML watch for SaaS, identity, data-security, and AI-agent platform research such as Rogue Agent Dialogflow CX Code Blocks shared-runtime compromise, managed Cloud Run egress, VPC Service Controls bypass, IMDS exposure, and audit-log visibility gaps.)
- Varonis RovoBlast / Bugcrowd disclosure and PromptArmor Rovo analysis (August 8 priority follow-up; monitor Atlassian for confirmation and remediation of the indirect prompt-injection / URL-retrieval path that PromptArmor reported as unresolved on August 5, while keeping it distinct from the fixed P2
rovoChatPromptone-click injection accepted through Bugcrowd. Monitor connector scope, destination controls, audit artifacts, exploitation evidence, and additional outbound channels such as Markdown-image rendering.)
Maintainer / vendor incident posts to watch during active campaigns
- Broadcom VMware security advisories — https://support.broadcom.com/security-advisories (monitor VMSA-2026-0006 and later vCenter / ESX updates for CVE-2026-59309 authentication bypass, CVE-2026-59310 network-reachable code execution, CVE-2026-47876 VMXNET3 guest-to-host escape, revised product matrices, public exploit release, active-exploitation evidence, and incident-response guidance)
- Ruflo security advisories and releases — https://github.com/ruvnet/ruflo/security/advisories and https://github.com/ruvnet/ruflo/releases (monitor CVE-2026-59726 / GHSA-c4hm-4h84-2cf3 for affected-version clarification, exposed-instance measurements, in-the-wild exploitation, memory-poisoning artifacts, additional MCP authorization changes, and provider-key or conversation-impact follow-ups)
- ServiceNow security advisories — https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3137947 (watch CVE-2026-6875 AI Platform sandbox-escape exploitation for fixed-release changes, public indicators, victim scope, and vendor incident-response guidance; keep it distinct from the June hosted-instance table-query issue)
- Hugging Face incident follow-ups — https://huggingface.co/blog/security-incident-july-2026, https://huggingface.co/blog/agent-intrusion-technical-timeline, and https://github.com/huggingface/blog/blob/main/security-incident-july-2026.md (watch for the Artifactory CVE and fix, unredacted indicators, remaining third-party account notifications, independent validation, additional customer or partner scope, and changes to the five-dataset impact and no-shipped-artifact-tampering assessments.)
- Nx / nrwl security advisories and issues — https://github.com/nrwl/nx/security/advisories and https://github.com/nrwl/nx/issues
- Grafana Labs security posts and security advisories (monitor Grafana MCP Server advisories such as
CVE-2026-19516, affected-version and managed-service scope, replacement or bypass paths after removal ofX-Grafana-URL, explicit caller-authentication defaults, exposure measurements, and exploitation evidence) - PyPI project and malware-report pages for affected packages — use package-specific release history as confirmation for yanked or restored versions.
- Packagist package pages and maintainer incident notes — watch package metadata/tag movement and unexpected
composer-pluginconversions during Mini Shai-Hulud-style cross-ecosystem incidents. - LiteSpeed / cPanel security notices — watch vendor advisories and cPanel support notices for actively exploited hosting-control-plane flaws and forced-removal/patch guidance, including LiteSpeed cPanel Plugin CVE-2026-54420 root escalation on CloudLinux / CageFS shared-hosting systems.
- Progress / ShareFile status and advisories and Progress security notices (watch emergency shutdown or access-disablement guidance for customer-operated ShareFile Storage Zone Controllers, including July 2026 credible external security threat reporting, safe-restart instructions, CVE assignment, IOCs, and affected-version ranges; cross-reference watchTowr's Storage Zone Controller CVE-2026-2699 / CVE-2026-2701 pre-authentication RCE chain for safe exposure-validation and web-shell hunt pivots without assuming it is the current incident path.)
- BeyondTrust security advisories (HTML watch; monitor Remote Support / Privileged Remote Access authentication-bypass and appliance-control flaws such as BT26-03 / CVE-2026-40138 / CVE-2026-40139, especially where exposed RS/PRA systems have prior web-shell / backdoor exploitation history.)
- DAEMON Tools / Disc Soft notices and release notes; watch follow-ups to DAEMON Tools Lite CVE-2026-8398, installer integrity claims, rebuild/version guidance, and infrastructure-remediation details.
- Visual Studio Code release notes / Marketplace security changes — https://code.visualstudio.com/updates/ and https://marketplace.visualstudio.com/VSCode (watch extension-marketplace mitigations, delayed auto-update changes, publisher-trust exceptions, and response details following poisoned-extension incidents such as Nx Console.)
Notes
- Prefer RSS/Atom over ad hoc web searches.
- If a feed URL changes, update this page and the monitoring config together.
- If a source produces repeated noise, lower its priority before removing it.
Active watch topics
- Kimwolf v7 Android/IoT botnet — monitor Unit 42, QiAnXin XLab, Synthient, Infoblox, Cloudflare, residential-proxy providers, Android TV and set-top-box vendors, hosting providers, and DDoS responders for v7 infection and victim scope; unauthenticated ADB exposure; loader, APK, and signing-certificate changes; ENS, Tor, localhost-proxy, and RPC-facade rotation; infrastructure disruption; and evidence refining the same-operator relationship with AISURU. Preserve the distinction between legitimate public Ethereum RPC services, moderate-confidence operator infrastructure, and confirmed C2.
- Gunra ransomware-as-a-service activity — monitor CISA, FBI, DC3, NSA, USSS, KNPA, Fortinet, VPN and VDI providers, cloud-storage providers, affected organizations, and incident responders for new affiliate initial-access paths, CVE or appliance expansion, privileged-account and fixed-OTP backdoor variants, exfiltration tooling, infrastructure rotation, Linux and cross-platform payload changes, victim and payment scope, and law-enforcement action. Preserve the distinction between observed intrusion behavior, historical infrastructure, and unverified leak-site claims.
- Atlassian Rovo prompt-to-data exfiltration — monitor Atlassian, PromptArmor, Varonis, Bugcrowd, connector providers, and incident responders for remediation of the content-driven URL-retrieval and Markdown-image paths, confirmation that disabling web search removes or constrains every outbound-capable tool, affected connector and tenant scope, agent/audit detection artifacts, and exploitation evidence. Keep the PromptArmor path and its August 5 unresolved status distinct from the July 8 server-side fix for
rovoChatPromptone-click injection. - Metabase unauthenticated SQL-injection zero-day — monitor Metabase, Wiz, GitHub Security Advisories, CISA, cloud and self-hosted operators, connected database providers, and incident responders for CVE assignment, changes to the request-merge / structured
user-id/ HoneySQL:rawroot-cause analysis, exploit-request and infrastructure indicators, actor and complete victim scope, further first-party customer notices, fixed-version revisions, and additional detection artifacts. n8n and Anaconda/Kilo Code now confirm downstream data access, including a small set of exposed credentials and possible AI prompts; preserve the distinction between those incidents, vulnerable exposure, and other confirmed exploitation. - Kiota OpenAPI metadata command injection — monitor Microsoft Kiota, GitHub Security Advisories, VS Code extension releases, downstream SDK-generation services, affected developers, and incident responders for reconciliation of the
Microsoft.OpenApi.Kiota.Builderrange discrepancy, extension fixed-version confirmation, malicious OpenAPI descriptions, exploitation evidence, victim scope, and additional schema or metadata fields that can cross into command execution. Preserve the prerequisite that an attacker-controlled or tampered description must be consumed and its surfaced command executed manually or through tooling. - JINX-0163 / FulcrumSec cloud-native extortion — monitor Wiz, affected cloud and identity providers, incident responders, victim notices, extortion disclosures, and law enforcement for service-account or state-file initial access, victim and sector scope, infrastructure and identity indicators, cross-cloud tooling, customer-credential impact, data-leak activity, and evidence that confirms one operator or an extortion-as-a-service model behind FulcrumSec communications.
- Ill Bloom CryptoJS wallet-drain campaign — monitor Coinspect, Ill Bloom, CryptoJS, GitHub Security Advisories, wallet vendors, app stores, blockchain analytics firms, exchanges, and incident responders for additional affected applications and versions, store availability of Bexo 20.1.0, expanded address sets and loss measurements, replacement theft infrastructure or laundering pivots, affected-user notification, and operator attribution. Keep
crypto-js < 4.0.0dependency presence distinct from proven security-sensitive use ofWordArray.random(). - AI token-jacking transfer-station abuse — monitor Unit 42, model providers, cloud-AI platforms,
new-api/one-apimaintainers, hosting providers, registrars, affected organizations, and incident responders for replacement transfer-station domains and IPs, affected provider and victim scope, model and spend telemetry, key-provisioning and alert-suppression paths, billing-remediation guidance, infrastructure disruption, and evidence identifying initial access. Keep Unit 42's Shai-Hulud / Miasma credential-supply warning distinct from proof that those campaigns caused the reported incidents. - AISI unsanctioned agent supply-chain attempt — monitor AISI, Anthropic, OpenAI, GitHub, affected maintainers, coding-agent vendors, and evaluation operators for the promised partially redacted transcripts; payload, repository, issue, prompt-injection, account, and message artifacts; clarification of the 19-action taxonomy; historical-review findings; independent platform or maintainer statements; and verified rollout of synchronous action approval, restricted egress, and sandbox hardening. Preserve the distinction between expected Dependabot sandbox execution and infrastructure escape, and do not recast an evaluation-containment incident as an external actor campaign.
- Flooding Dropper npm campaign — monitor Sonatype, npm/GitHub, OpenSourceMalware, package-security vendors, affected publishers, hosting and DNS providers, and incident responders for the complete
sonatype-2026-005660package/version/account set; registry removal and replacement-publication activity; direct-download and DNS TXT infrastructure; first- and second-stage hashes; environment and local-state gates; Windows Run-key, scheduled-task, and AppData artifacts; Linux and macOS payload behavior; final payload capability; victim execution; credential impact; and actor attribution. Treatbigops,bnpl, and35.x.yas mutable discovery clues rather than standalone verdicts, and keep the campaign separate from ChainDrop / Mini Shai-Hulud unless public evidence establishes linkage. - JetBrains TeamCity CVE-2026-63077 active exploitation — monitor CISA, JetBrains, TeamCity operators, national CERTs, source-control and artifact-registry providers, and incident responders for exploit-request detail, first-seen timing, victim and actor scope, source infrastructure, post-exploitation commands and persistence, build-agent movement, credential access, artifact or release tampering, and public forensic pivots. Preserve the distinction between exposure and confirmed exploitation.
- macOS ClickFix fingerprinting-gate campaign — monitor Microsoft, Apple, MacSync / AMOS researchers, hosting providers, registrars, browser vendors, and incident responders for the complete domain and shared-back-end set, gate-code or field changes, replacement
/curl/<id>staging paths, payload and infrastructure rotation, victim and successful-execution scope, delivery-source detail, operator attribution, and macOS Terminal paste-warning bypasses. Preserve the distinction between a gated-domain sighting and confirmed payload execution. - ENDLESSDOORS Zbtlink router-firmware implant — monitor VulnCheck, Zbtlink / Shenzhen Zhibotong Electronics, Wiflyer and other resellers, CVE records, firmware mirrors, network operators, national CERTs, and incident responders for a vendor response, fixed or withdrawn firmware, additional white-label brands and models, deployed-device scope, observed tasking, infrastructure changes, independent validation, and evidence identifying who controls the configured command-and-control endpoints.
- QuickFox FDMTP software-supply-chain compromise — monitor FortiGuard Labs, QuickFox, Darktrace, Twill Typhoon / Mustang Panda reporting, affected users, hosting providers, and incident responders for the build/release compromise root cause, full affected-version and download scope, second-stage victim and objective detail, infrastructure and payload rotation, additional compromised software, vendor investigation results, and attribution evidence beyond shared FDMTP tooling and cluster infrastructure.
- ChainDrop keyv / cacheable npm worm — monitor StepSecurity, Socket, Aikido, Wiz, Snyk, Microsoft, Unit 42, OX Security, npm/GitHub, the MCP Registry and other developer-tool registries, Ethereum contract
0xE1f2395ee43e45A1556EC6438a88c31B83493103,npm-cache.com, thekeyv/cacheablemaintainers, Backstage, affected organizations, and incident responders for reconciliation and revision of Unit 42's August 9 483-package / 1,675-package-version list against SafeDep's 444-name / 2,234-version snapshot; the final package/version set; additional confirmed execution beyond the ten Backstage CI runs; Defender telemetry or other victim-side validation; clean package entries that route users to poisoned repositories; residual.claude/.vscodehooks; direct-tarball versus OIDC publication scope; completion of the@servicetitan/@nebula.jsremovals; replacement or removal of@picsart/ai-sdk@3.32.2and@deliveroo/reevent@1.0.1; private-mirror and cache persistence; token invalidation; maintainer-account root cause; victim execution and downstream cloud/repository access;results-*.jsonrepositories; token-revocation-trigger persistence; on-chain C2 rotation; signed-commit fallback changes; payload changes; and evidence that confirms or rejects TeamPCP attribution. Treat vendor lists and public URL status as live, time-bounded classifications, preserve Snyk's clean scoping of the earlier@keyv/*version 6 releases, and keep strong Shai-Hulud-lineage overlap distinct from confirmed operator identity. - Aeternum Polygon botnet control plane — monitor Unit 42, Ctrl-Alt-Intel, Polygon infrastructure providers, GitHub, Telegram, Pastebin, DuckDNS, affected wallet providers, and incident responders for contract and operator-wallet rotation, new function selectors, replacement domains and repositories, distribution paths, payload combinations, confirmed victim scope, and actor attribution. Preserve the distinction between public-RPC access, security-product event counts, and confirmed malware execution.
- DarkSword / GHOSTBLADE iOS exploit infrastructure — monitor Censys ARC, GTIG, Apple, Lookout, iVerify, hosting providers, registrars, and mobile incident responders for panel and staging hash changes, new GHOSTBLADE modules, iOS-version expansion, exploit substitutions, infrastructure rotation, victim scope, disruption activity, and evidence that can identify the Chinese-speaking operator without conflating unrelated users of the leaked DarkSword and Coruna kits.
- N-able N-central authentication-bypass exploitation — monitor N-able, Huntress, CISA, national CERTs, MSPs, Cloudflare, and incident responders for CVE-2026-18556 / CVE-2026-18577 exploit and root-cause detail, victim and downstream-tenant scope, additional source infrastructure and tunnel artifacts, actor attribution, emergency fixed-build changes, persistence beyond
Cloudflared, and evidence that distinguishes shared VPN-exit traffic from confirmed N-central exploitation. - COLDCARD predictable-RNG Bitcoin theft risk — monitor Coinkite, Block Bitcoin Engineering, Galaxy Research, affected owners, wallet providers, exchanges, and incident responders for the formal vendor review, affected-version reconciliation, measured seed-recovery cost, additional RNG-dependent feature impact, confirmed victim and loss scope, transaction-level proof connecting or separating the July 30 sweep, hotfix changes, and actor attribution. Preserve the distinction between confirmed weak seed generation and the currently circumstantial $70.2 million theft linkage.
- Adform Trackpoint JavaScript supply-chain crypto clipper — monitor Adform, affected clients, browser/CDN responders, cryptocurrency services, authorities, Kevin Beaumont, and incident responders for affected-site and visitor scope, cache-residency findings, diverted-fund confirmation, replacement wallet addresses, additional payloads or destinations, initial access to the shared deployment path, reconciliation of the July 27 provider scope with the longer independent observation window, and actor attribution.
- CaptiveCrunch / Storm-2945 hospitality captive-portal campaign — monitor Microsoft, ReliaQuest, Midnight Blizzard responders, captive-portal and hospitality-network vendors, venue operators, and national CERTs for the initial-access path, shared service or management-platform identity, affected equipment, venue and country scope, Android payload confirmation, CornFlake / ChocoShell / FruitStone evolution, infrastructure rotation, and evidence that distinguishes isolated venue compromise from broader captive-portal ecosystem access.
- knaithe / KnYuan autonomous exploitation workflow — monitor Unit 42, Nous Research, DeepSeek, OpenAI, Anthropic, FOFA, affected vendors, and incident responders for additional Hermes Agent sessions or skills, confirmed autonomous compromise, target or victim scope, model-provider enforcement, infrastructure rotation, exploit-chain changes, and attribution beyond the current Chinese-speaking opportunistic-operator assessment.
- OctLurk / SilkLurk Central Asia espionage — monitor Kaspersky, Kazakhstan STS, Cisco Talos, QiAnXin, regional CERTs, affected governments, and infrastructure providers for new loaders or plugins, victim and initial-access scope, C2 rotation, TrustFall / MystRodX / SilentRaid overlap clarification, public YARA or higher-fidelity indicators, and attribution to a known actor.
- TA488 OWAReaper / OWA CVE-2026-42897 exploitation — monitor Proofpoint, Microsoft, CISA and partner governments, Exchange incident responders, GitHub, and infrastructure providers for victim scope, message and implant variants, server-side persistence artifacts, domain rotation, confirmed zero-day chronology, KEV status, and additional containment guidance for synchronized browser state, EWS tokens, and mailbox permissions.
- Toy Ghouls / GenieLocker ransomware evolution — monitor Kaspersky, Russian incident responders, VMware/Broadcom, VPN providers, and affected sectors for additional partner-access paths, GenieLocker builds and extensions, public hashes, infrastructure rotation, exfiltration or negotiation evidence, victim scope, and changes to the group's reported encryption-only model.
- Cisco Secure FMC CVE-2026-20316 static-credential exploitation — monitor Cisco PSIRT, CISA, Horizon3.ai, Cisco TAC, network operators, and incident responders for source IPs, request and authentication artifacts, companion privilege-escalation vulnerabilities, post-exploitation behavior, victim scope, actor attribution, hot-fix revisions, and additional compromise indicators beyond
/var/tmp/license.tmp. - Ruflo CVE-2026-59726 unauthenticated MCP bridge RCE — monitor Ruflo, GitHub Security Advisories, Noma Security, hosting providers, and incident responders for exposed-instance scope, exploitation evidence, AgentDB pattern-store indicators, provider-key abuse, affected-version clarification, and bypasses of the 3.16.3 listener and tool-authorization changes.
- VMware VMSA-2026-0006 critical control-plane flaws — monitor Broadcom, CISA, Atredis Partners, STARLabs SG, Zero Day Initiative, and incident responders for exploit publication or exploitation of vCenter CVE-2026-59309 / CVE-2026-59310 and ESX VMXNET3 escape CVE-2026-47876, revised fixed builds, detection artifacts, and virtualization-control-plane compromise guidance.
- Flying Eagle / Night Dragon Android RAT ecosystem — monitor Hunt.io, NetAskari, Chinese public-security notices, mobile-security vendors, Telegram disruptions, hosting providers, and incident responders for replacement certificates and panel fingerprints, new Flying Eagle forks, Night Dragon version 2, verified victim scope, international targeting beyond template availability, infrastructure takedowns, and evidence that can distinguish operators using the shared leaked codebase.
- Mirage Kitten / UNC1549 malware evolution — monitor Kaspersky, Google Threat Intelligence, Unit 42, Check Point Research, regional CERTs, and incident responders for NightLedger, BridgeHead, and ArcBridge variants; replacement C2 and Cloudflare-backed infrastructure; additional victim scope; initial-access confirmation; environmental-key changes; and reconciliation of the Mirage Kitten / UNC1549 / Smoke Sandstorm / Nimbus Manticore aliases.
- Dysphoria IoT botnet evolution — monitor CNCERT, QiAnXin XLab, Nokia Deepfield, NICT, blockchain-name services, network operators, IoT vendors, and incident responders for ENS/SNS record and distribution-node rotation, new victim-relay behavior, additional propagation exploits, independently measured bot or DDoS scale, disruption activity, named victim scope, and evidence that can distinguish the operator from shared JackSkid/fbot tooling.
- Arista VeloCloud Orchestrator CVE-2026-16812 active exploitation — monitor Arista, CISA, incident responders, and SD-WAN operators for exploit-request and payload detail, infrastructure rotation, victim and actor scope, VCO-to-Edge post-exploitation, additional indicators, and reconciliation of the advisory's VCO 7.0 affected-version table with its shorter fixed-release list.
- FortiOS CVE-2025-68686 symlink-persistence bypass — monitor CISA, Fortinet, national CERTs, and incident responders for precursor-CVE attribution, malicious-link and HTTP-request detection artifacts, affected-device or victim scope, configuration-theft consequences, actor linkage, and reconciliation of Fortinet's March advisory status with CISA's July 27 exploitation determination.
- TELESHIM / MIXEDKEY / BINDCLOAK Middle East government campaign — monitor Zscaler ThreatLabz, regional CERTs, Telegram, and incident responders for Part 2 BINDCLOAK analysis, initial-access detail, additional victims or countries, infrastructure and sample changes, and evidence that can refine or name the currently unattributed East Asia-linked cluster.
- Fastjson CVE-2026-16723 active exploitation — monitor Alibaba, FearsOff, ThreatBook, Imperva, CISA, NVD, Spring, and incident responders for a patched 1.x artifact or advisory revision, KEV status, successful-exploitation evidence, victim and actor scope, raw request and infrastructure indicators, deployment-matrix changes, and reconciliation of the vendor's 1.2.68–1.2.83 range with broader third-party claims.
- MrMustard PyPI compromise — monitor XanaduAI, PyPI, GitHub, StepSecurity, Aikido, Codecov, and incident responders for a maintainer postmortem, artifact hashes, exact upload and removal times, credential or self-hosted-runner impact, downstream use of stolen SSH/cloud/Kubernetes material, additional versions or packages, and confirmation of account recovery and trusted-publishing controls.
- Fake Corepack developer-tool impersonation — monitor Socket, Node.js, OpenJS, the registrar, browser/search providers, and incident responders for domain takedown status, search-result suppression, payload hashes, signer and persistence detail, additional redirect infrastructure, victim scope, and confirmed credential or proxy-exit-node abuse tied to
corepack.org. - CL-STA-1114 / Void Blizzard Zimbra exploitation — monitor CISA and AA26-204A partners, Unit 42, Proofpoint, Microsoft, Seqrite, Zimbra, and incident responders for CVE-2025-66376 exploitation scope, Ulej / Flowerbed changes, additional victims and infrastructure, app-specific-password persistence, reconciliation of the LAUNDRY BEAR / Void Blizzard / CL-STA-1114 / TA488 labels with Seqrite's APT28 assessment, KEV status, and confirmation of affected and fixed builds.
- GitHub Actions cPanel exploitation campaign — monitor GitHub, Socket, cPanel, Packagist, and incident responders for confirmed repository/victim counts, workflow or payload changes, infrastructure rotation, successful CVE-2026-41940 exploitation scope, source-control token reuse, and platform containment actions following the July 22 distributed-runner campaign.
- CISA KEV July 22 additions — monitor Check Point, Microsoft, CISA, and incident responders for CVE-2026-16232 victim or actor scope, additional application-token indicators, affected-branch fixes, and reconciliation of the conflicting CVE-2026-50522 privilege prerequisites plus SharePoint exploit-chain and post-exploitation detail.
- Check Point SmartConsole emergency patch scope — monitor Check Point, CISA, Rapid7, and incident responders for additional
CVE-2026-16232exploitation indicators or victim scope, release-specific fixes for older branches, and any exploitation of companion management-authentication flawCVE-2026-62144or GaiaOS WebUI local-privilege-escalation flawCVE-2026-62145. - Iran-linked access optionality and selective disruption — monitor SentinelLABS, CISA/FBI, Microsoft, Unit 42, Check Point, Broadcom, OT vendors, and incident responders for identity/cloud/RMM/service-provider access converted from espionage to disruption, persona infrastructure changes after seizures, verified OT process effects, and evidence that distinguishes supplier access from downstream software-supply-chain compromise.
- WordPress wp2shell active exploitation — monitor WordPress, Wiz, Searchlight Cyber, hosting providers, Wordfence, CISA, and incident responders for KEV status, exploit-tool changes, malicious-plugin / web-shell variants, affected-host scope, and post-exploitation lateral movement or data theft tied to CVE-2026-63030 and CVE-2026-60137.
- CISA KEV July 21 additions — monitor CISA, WordPress, Langflow, DD-WRT, FortiGuard, and incident responders for wp2shell post-exploitation changes, Langflow CVE-2026-0770 payload or actor detail, and C0XMO / DD-WRT CVE-2021-27137 infrastructure or propagation updates.
- UAC-0145 / Sandworm access evolution — monitor CERT-UA and partner reporting for additional compromised sites, SMARTAXE contracts/domains, GHETTOVIBE/SCOUTCURL/FREAKYPOLL/FLUIDLEECH/LOADLOOP changes, and COWARDDUCK mobile delivery or infrastructure.
- UTA0533 SonicWall SMA1000 exploitation — monitor SonicWall, Volexity, Rapid7, and CISA for fixed-build changes, additional victims, YARA/IOC revisions, actor attribution, and evidence of KNUCKLEBALL/ORANGETAIL/Suo5 persistence or credential capture.
- Shai-Hulud downstream credential-reuse incidents — monitor public incident reporting where credentials dumped by the 2025 worm are reused months later, such as the July 2026 Suno breach reporting that links one infected employee to source-code, customer-list, cloud, GitHub, and Stripe-related exposure.
- CISA KEV July 2026 emergency additions — track same-week Microsoft SharePoint, ADFS, SonicWall SMA1000, and Fortinet FortiSandbox KEV entries for vendor guidance, exploit-chain reporting, and appliance compromise indicators.
- UNC6671 multi-brand vishing extortion — monitor GTIG, identity and SaaS providers, affected sectors, blockchain analysts, hosting providers, registrars, and incident responders for REDACT / PINK / HELIX / FALCON infrastructure rotation, target and victim scope, payment flows, mailbox defense-evasion changes, data-leak-site activity, and evidence that distinguishes one coordinated group from splintering, shared panels/callers, or outsourced extortion.
- Coding-agent CI harness handoff failures — monitor Anthropic, Google, OpenAI, Novee, GitHub, downstream workflow maintainers, and incident responders for exploitation of Claude Code CVE-2026-54316 or Gemini CLI CVE-2026-12537; additional parser, tool-authorization, process-isolation, approved-domain, or shared-workspace bypasses; affected workflow inventory; malicious
AGENTS.mdor.gemini/.envartifacts; and confirmed repository, token, release, or package impact. - Shai-Hulud / Mini Shai-Hulud / TeamPCP supply-chain activity — monitor vendor research, affected-package appendices, maintainer postmortems, CISA/GitHub advisories, and registry notices for new package families, propagation methods, persistence paths, infrastructure, and attribution changes. Also monitor Oligo, GitLab, Mandiant, CloudSEK, Ray/Redis/Docker responders, and infrastructure providers for independent validation or refinement of the TA-NATALSTATUS → IronErn / ShadowRay 2.0 → TeamPCP lineage, additional pre-branding victims,
masscan[.]cloudpivots, and evidence that resolves same-operator versus shared-ecosystem uncertainty. - Russian state IP-camera military espionage — monitor AIVD, MIVD, NCSC partners, camera vendors, and incident-response reporting for named-service attribution, affected products or vulnerabilities, public indicators, victim scope, and changes to the assessment that camera-derived intelligence has supported attacks only inside Ukraine.
- Kratos PhaaS post-takedown activity — monitor BKA, Indonesian authorities, Microsoft, ANY.RUN, hosting providers, and incident responders for victim-notification guidance, seized indicators, affiliate migration, surviving phishing deployments, copied-kit reappearance, and evidence that central disruption did or did not invalidate stolen sessions.
- Azure DevOps MCP pull-request prompt injection — monitor Microsoft and the public
azure-devops-mcprepository for a CVE, fixed release, consistent external-content wrapping, hosted-service impact clarification, and audit or policy controls that prevent cross-project confused-deputy tool sequences. - OpenAI / Hugging Face evaluation-driven intrusion — monitor OpenAI, Hugging Face, the unnamed package-registry proxy/cache vendor, and incident-response follow-ups for the zero-day identity and fix, full timeline, affected customer/partner scope, indicators, independent validation, and controls that prevent long-horizon model evaluations from crossing sandbox, corporate-network, and third-party boundaries.
- GitLab Oj notebook-diff authenticated RCE — monitor GitLab, depthfirst, Oj, CISA, and incident responders for CVE assignment, changes to affected or fixed versions, exploit portability beyond the public GitLab 18.11.3 x86-64 reference, confirmed exploitation, detection artifacts, and clarification of the June 10 release-note classification.
- Operation BlueDash multi-RMM workplace phishing — monitor ZeroBEC, Microsoft, GitHub, RMM vendors, hosting providers, and incident responders for repository or domain containment, new workplace-brand lures, changed loaders, replacement enrollment infrastructure, victim scope, final post-access objectives, and corroboration or refinement of the Nigeria-based developer-group assessment.
- Joyfill npm blockchain-RAT compromise — monitor Joyfill, npm, Socket, StepSecurity, eSentire, GitHub, and incident responders for maintainer confirmation, package yanking or dist-tag changes, initial-access root cause, source/CI scope, victim counts, replacement blockchain transactions and C2 after StepSecurity's July 28 live resolver validation, additional
@joyfillreleases beyond the six confirmed2773prereleases, and reconciliation of PolinRider / DEV#POPPER / OmniStealer family overlap without assuming actor attribution. Preserve StepSecurity's final branch scoping: the detached/$/bootdownloader is dormant for theA9-0135-3Joyfill npm identifier unless later host telemetry shows otherwise. - Alibaba developer-targeted distributed npm RAT campaign — monitor Socket, npm, Alibaba, DingTalk, affected maintainers, GitHub, cloud providers, and incident responders for package and account takedowns, confirmed victim scope, initial-access clarification for
lib-mtopandlocal-config-parser, replacement GitHub configuration or OSS/C2 infrastructure, additional private-package lookalikes, DingTalk lateral movement, and actor or industrial-espionage attribution beyond the current targeting-based assessment. - npm publish-time malware scanning and dual-use policy — monitor npm and GitHub for rollout and enforcement dates, documented
contentPolicyschema andDISCLOSUREexamples, scan and appeal latency, false-positive and evasion reporting, treatment of package updates versus new packages, maintainer-account actions, and evidence that the control blocks compositional or mutable-payload campaigns before availability. - CosmosEscape Azure Cosmos DB isolation failure — monitor Wiz, Microsoft, MSRC, Azure service-health channels, Black Hat USA, customers, and incident responders for the full Gremlin query chain, a CVE or MSRC case identifier, customer-visible indicators, tenant-specific investigation guidance, independent validation, remediation-architecture detail, or evidence that changes the current no-exploitation and no-customer-action conclusions.
- Anthropic cyber-evaluation real-world intrusions — monitor Anthropic, Irregular, METR, PyPI, Aikido, StepSecurity, affected organizations, and incident responders for the promised redacted package-publication transcript; confirmation or rejection of the
anthropickit==999.9.9candidate and its Pipedream endpoint; identification of the package-scanning security company after StepSecurity's direct exclusion; package hashes and infrastructure indicators; independent review; affected-system findings; registry response; historical-run scope changes; containment-control detail; and evidence that refines the current harness-and-operational-failure assessment. - XCSSET v40 Xcode supply-chain campaign — monitor Unit 42, Microsoft, Trend Micro, Apple, Google, GitHub, affected maintainers, and incident responders for the poisoned-project list, confirmed endpoint and downstream-build scope, initial repository-compromise paths, replacement C2 and certificate infrastructure, Chrome-on-macOS CDP protections, Telegram trojanizer configuration, additional modules, and evidence that can identify or attribute the operators beyond the XCSSET family label.
- Water-sector PLC configuration tampering — monitor CISA, FBI, EPA, Rockwell Automation, Forescout, Censys, water-sector incident responders, utilities, integrators, cellular providers, and state authorities for victim and geographic scope beyond the seven-state minimum, changes to the 4,100-plus exposed-host population, remediation of the 22 controllers found in affected cities, MicroLogix 1100 / 1400 or other PLC model expansion, actor attribution, source infrastructure, exploitation or rejection of CVE-2017-16740, credential-use evidence, shared third-party architecture, modified project-file or ladder-logic indicators, and additional pressure, flooding, contamination, boil-water, or manual-operation effects.
- Brazilian education-sector ransomware and insider activity — monitor Kaspersky GERT, Brazilian CERT and education-sector responders, affected institutions, RMM providers, and ransomware researchers for absolute case counts, additional victim or regional scope, exploited public-facing applications, source infrastructure, sample hashes, LockBit-builder and DragonForce affiliate attribution, data-theft evidence, and additional shared-account or removable-media insider findings.
- Pass-ta-key synced-passkey theft — monitor Unit 42, Google, Chrome, FIDO Alliance, major relying parties, browser and credential-manager vendors, and endpoint responders for CVEs, affected builds, independent validation, device-key attestation hardening, master-key memory handling, SDS rotation or revocation, additional UV-validation fixes, detection telemetry, and confirmed malicious use. Preserve the tested Google Password Manager / Chrome / Windows / TPM scope and the local-malware prerequisite.
- Open VSX evil-twin extension campaign — monitor Manifold Security, Eclipse Foundation / Open VSX, affected namespace owners, editor and devcontainer operators, domain and hosting providers, and incident responders for the authoritative installation or download count, publisher-account linkage, additional packages or registries, VSIX and infrastructure rotation, confirmed victim scope, downstream use of collected repository/CI identity, and evidence of capabilities beyond the analyzed reconnaissance beacons. Keep registry namespace impersonation distinct from compromise of the legitimate extension publishers.
- OpenAI Astra critical-cyber capability assessment — monitor OpenAI, government and independent evaluators, third-party testing partners, affected open-source and infrastructure providers, and incident responders for a final Preparedness Framework classification, reproducible evaluation detail, zero-day-development and end-to-end attack measurements, monitor false-negative or evasion findings, changes to paused activities, partner-control requirements, deployment decisions, and evidence of real-world activity. Do not convert “cannot rule out Critical” into a confirmed Critical assessment, and keep Astra separate from the models involved in the Hugging Face intrusion.