Copy.Fail (CVE-2026-31431): A Straight-Line Logic Flaw Roots Every Linux Distribution Since 2017
Copy.Fail (CVE-2026-31431): A Straight-Line Logic Flaw Roots Every Linux Distribution Since 2017
Linux Kernel Exploits CVE-2026-31431 Copy Fail Privilege Escalation AF_ALG Page Cache Container Escape May 15, 2026

CVE-2026-31431 (Copy Fail) lets any unprivileged Linux user gain root via a 732-byte Python PoC — no race, no offsets, no disk artifacts. Affects every distro since 2017.

Read full analysis →
Supply Chain Alert: TeamPCP Compromises SAP npm Ecosystem via 'mini Shai-Hulud' Campaign
Supply Chain Alert: TeamPCP Compromises SAP npm Ecosystem via 'mini Shai-Hulud' Campaign
Threat Intelligence npm Supply Chain SAP TeamPCP OIDC Credential Theft AI Coding Agents May 15, 2026

TeamPCP exploited a permissive npm OIDC trust policy to poison SAP's mbt and @cap-js packages, exfiltrating cloud and developer secrets to victim-owned GitHub repos. Here's the full attack chain and how to detect it.

Read full analysis →
LiteLLM Supply-Chain Attack: How Trojanized PyPI Packages Turned an AI Gateway Into a Data Exfiltration Tool
LiteLLM Supply-Chain Attack: How Trojanized PyPI Packages Turned an AI Gateway Into a Data Exfiltration Tool
AI Security Kubernetes Supply Chain Attack LiteLLM PyPI Data Exfiltration Apr 02, 2026

Trojanized LiteLLM releases on PyPI enabled data exfiltration with Kubernetes persistence—here’s the full attack chain and how to check if you’re affected.

Read full analysis →
Axios npm Package Compromised: Supply Chain Attack via Phantom Dependency Drops Cross-Platform RAT
Axios npm Package Compromised: Supply Chain Attack via Phantom Dependency Drops Cross-Platform RAT
RAT Axios npm Supply Chain Attack Dependency Injection JavaScript Mar 31, 2026

Axios npm package compromised—attackers hijacked the maintainer’s account and injected a phantom dependency that dropped a cross-platform RAT. Here’s the full attack chain.

Read full analysis →
OpenAI Patches ChatGPT DNS Data Exfiltration Flaw and Codex Command Injection Vulnerability
OpenAI Patches ChatGPT DNS Data Exfiltration Flaw and Codex Command Injection Vulnerability
AI Security OpenAI ChatGPT Codex DNS Exfiltration Command Injection Mar 30, 2026

Check Point found ChatGPT’s code sandbox could leak data via DNS. Separately, Codex’s branch name field allowed command injection to steal GitHub tokens.

Read full analysis →
Russian CTRL Toolkit: How Malicious LNK Files Enable RDP Hijacking via Reverse Tunnels
Russian CTRL Toolkit: How Malicious LNK Files Enable RDP Hijacking via Reverse Tunnels
Threat Intelligence CTRL Toolkit LNK Exploitation RDP Hijacking FRP Tunnels Russian APT Mar 30, 2026

A custom .NET RAT dubbed CTRL uses weaponized Windows shortcuts to hijack RDP sessions via FRP tunnels—here’s the full attack chain and how to defend against it.

Read full analysis →

Page 1 of 3 • 18 articles