New PCPJack worm steals credentials, cleans TeamPCP infections
2026-05-07T19:23:34Z•2bc05c6c45ee914b0707dcb7df0de730f8630b21f30db73987f69cbf48c2ff3d
backdoorbeaglechaos-ransomwarecisco-dosclickfixcredential-theftdaemon-toolsfake-ai-sitegoogle-adsivanti-epmmmanagewpmuddywaterpalo-altopan-ospcpjackphishingrcesandbox-escapestealersupply-chainteampcpvidarvm2wormzero-day
What happened
Multiple active, high-risk campaigns and vulnerabilities were reported: a new PCPJack worm is stealing credentials from cloud infrastructure while removing TeamPCP access; Australian authorities warned of ClickFix social-engineering pushes distributing the Vidar stealer; Ivanti Endpoint Manager Mobile (EPMM) is being targeted in a high-severity RCE zero-day; a critical PAN-OS firewall zero-day has been exploited in the wild; and a critical vm2 Node.js sandbox escape allows host code execution. Additional incidents include a fake Claude AI site distributing a new Beagle backdoor, Google Ads–del
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 2bc05c6c45ee914b0707dcb7df0de730f8630b21f30db73987f69cbf48c2ff3d
- Enrichment time
- 2026-05-07T19:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.