Rapid7 Labs uncovered a long-running espionage campaign by China‑nexus actor Red Menshen that embeds kernel‑level BPFdoor implants across core telecom infrastructure. The backdoor hides below normal visibility layers, can trigger via crafted packets and even disguised HTTPS, and observes telecom-native SCTP traffic—enabling long-term access, subscriber tracking, and stealth lateral movement. Rapid7 also released detection guidance and a scanner to help surface kernel filtering abuse, raw socket anomalies, and process masquerading.
Source: Rapid7
AI supply chain under active attack: LiteLLM campaign widens; KEV entry and detections released
SANS ISC issued the first post‑report update on the TeamPCP/LiteLLM supply‑chain campaign, noting newly observed scope beyond initial disclosures, a related CISA Known Exploited Vulnerabilities entry, and community detection tools now available. The incident underscores how developer AI gateways and Python packages can be weaponized to steal data and pivot through CI/CD and agent workflows—organizations should lock down registries, pin and verify packages, and monitor for anomalous agent behavior.
Source: SANS ISC
Coruna iOS exploit kit reuses Operation Triangulation kernel exploit
Kaspersky researchers found that Coruna’s kernel exploit for CVE‑2023‑32434 and CVE‑2023‑38606 is an updated version of the chain used in 2023’s Operation Triangulation. The code reuse signals iterative tradecraft against iPhones and highlights the value of rapid iOS patching, hardened MDM baselines, and mobile threat detection for high‑risk users and fleets that may lag OS updates.
Source: SecureList
Google sets 2029 deadline to migrate to post‑quantum cryptography
Warning of store‑now‑decrypt‑later risks, Google is pushing organizations to adopt NIST‑standard PQC by 2029 as part of an adjusted threat model. Security teams should inventory cryptographic usage, prioritize long‑lived sensitive data and protocols, test hybrid deployments (e.g., Kyber/Dilithium with existing suites), and map vendor dependencies to avoid late‑stage migration shocks.
Source: HelpNet Security
Secrets sprawl accelerates: 28.65M hardcoded credentials found in 2025
GitGuardian’s State of Secrets Sprawl 2026 reports 28.65 million new hardcoded secrets in public GitHub commits last year, with exposure also spreading across internal repos, CI logs, containers, and infrastructure tooling. To curb blast radius, implement pre‑commit scanning, enforce signed commits and branch protections, centralize secret management, and automate rotation and revocation pipelines.
Source: HelpNet Security
CISA flags critical PTC Windchill flaw after German police warn organizations
A critical vulnerability in PTC Windchill (CVE‑2026‑4681) prompted in‑person warnings by German police and has now been added to CISA’s advisories. PLM and engineering environments should treat this as a priority patch, restrict internet exposure, segment access to design repositories, and monitor for exploitation attempts targeting product data and IP.
Source: Security Week
EU moves to bolster CVE ‘bedrock’ as U.S. mulls stronger CISA oversight
A senior EU official signaled support for the foundational CVE program, while U.S. congressional staff work on legislation to give CISA greater oversight after last year’s contracting issues. Strengthening governance and resourcing for vulnerability enumeration could improve CNA coordination, CVE quality, and the timeliness that downstream SBOMs, scanners, and patch pipelines rely on.
Source: NextGov Cyber
You May Also Be Interested In...
Researchers release tool to detect stealthy BPFDoor implants in critical infrastructure networks
Make OpenAI’s models misbehave and earn a reward
Tails 7.6 ships automatic Tor bridge retrieval and a new password manager