New PCPJack worm steals credentials, cleans TeamPCP infections

2026-05-07T19:23:34Z2bc05c6c45ee914b0707dcb7df0de730f8630b21f30db73987f69cbf48c2ff3d
backdoorbeaglechaos-ransomwarecisco-dosclickfixcredential-theftdaemon-toolsfake-ai-sitegoogle-adsivanti-epmmmanagewpmuddywaterpalo-altopan-ospcpjackphishingrcesandbox-escapestealersupply-chainteampcpvidarvm2wormzero-day

What happened

Multiple active, high-risk campaigns and vulnerabilities were reported: a new PCPJack worm is stealing credentials from cloud infrastructure while removing TeamPCP access; Australian authorities warned of ClickFix social-engineering pushes distributing the Vidar stealer; Ivanti Endpoint Manager Mobile (EPMM) is being targeted in a high-severity RCE zero-day; a critical PAN-OS firewall zero-day has been exploited in the wild; and a critical vm2 Node.js sandbox escape allows host code execution. Additional incidents include a fake Claude AI site distributing a new Beagle backdoor, Google Ads–del

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
2bc05c6c45ee914b0707dcb7df0de730f8630b21f30db73987f69cbf48c2ff3d
Enrichment time
2026-05-07T19:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.