The npm Worm Era: What Shai-Hulud Started, Who's Continuing It, and How Defenders Should Adapt
The npm Worm Era: What Shai-Hulud Started, Who's Continuing It, and How Defenders Should Adapt
Threat Intelligence npm Supply Chain Shai-Hulud TruffleHog GitHub Worm CISA Alert May 19, 2026

September 2025's self-replicating Shai-Hulud npm worm rewrote the supply-chain threat model. Six months later the playbook has been adopted by other actors (TeamPCP, April 2026). Here's the concrete tradecraft, the IOCs that actually fire, and the controls defenders need.

Read full analysis →
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
Research Privilege Escalation AD CS PKI Shadow Credentials Certificate Services May 16, 2026

Unit 42 reveals how AD CS template misconfigs and shadow credentials are driving privilege escalation in modern enterprises.

Read full analysis →
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
May 16, 2026

Max-severity CVE-2026-20127 exploited since 2023. Threat actors use vdaemon bypass & firmware downgrade to gain root access in Cisco SD-WAN.

Read full analysis →
Copy.Fail (CVE-2026-31431): A Straight-Line Logic Flaw Roots Every Linux Distribution Since 2017
Copy.Fail (CVE-2026-31431): A Straight-Line Logic Flaw Roots Every Linux Distribution Since 2017
Linux Kernel Exploits CVE-2026-31431 Copy Fail Privilege Escalation AF_ALG Page Cache Container Escape May 15, 2026

CVE-2026-31431 (Copy Fail) lets any unprivileged Linux user gain root via a 732-byte Python PoC — no race, no offsets, no disk artifacts. Affects every distro since 2017.

Read full analysis →
Supply Chain Alert: TeamPCP Compromises SAP npm Ecosystem via 'mini Shai-Hulud' Campaign
Supply Chain Alert: TeamPCP Compromises SAP npm Ecosystem via 'mini Shai-Hulud' Campaign
Threat Intelligence npm Supply Chain SAP TeamPCP OIDC Credential Theft AI Coding Agents May 15, 2026

TeamPCP exploited a permissive npm OIDC trust policy to poison SAP's mbt and @cap-js packages, exfiltrating cloud and developer secrets to victim-owned GitHub repos. Here's the full attack chain and how to detect it.

Read full analysis →
LiteLLM Supply-Chain Attack: How Trojanized PyPI Packages Turned an AI Gateway Into a Data Exfiltration Tool
LiteLLM Supply-Chain Attack: How Trojanized PyPI Packages Turned an AI Gateway Into a Data Exfiltration Tool
AI Security Kubernetes Supply Chain Attack LiteLLM PyPI Data Exfiltration Apr 02, 2026

Trojanized LiteLLM releases on PyPI enabled data exfiltration with Kubernetes persistence—here’s the full attack chain and how to check if you’re affected.

Read full analysis →

Page 1 of 4 • 21 articles