CERT-EU: European Commission hack exposes data of 30 EU entities
2026-04-03T07:23:34Z•60c58be56eae860f21187fcf1a03ff1a7c3e3b3ef50ec68db978c77fb26d22a6
CERT-EUCisco IMCClaude Code leakDrift ProtocolEuropean CommissionGitHub supply-chain abuseHandalaIP reputation evasionNorth Korean actorsProgress ShareFileStrykerTeamPCPVidarauthentication bypasscloud hackcryptocurrency theftdata exposuredata-wipinghybrid cybercrimeinfostealermail interceptionpre-auth RCEresidential proxiesunauthenticated exfiltrationwiper
What happened
News roundup: CERT-EU attributes a cloud hack of the European Commission to TeamPCP, exposing data from the Commission and at least 29 other EU entities. Threat actors are abusing the leaked Claude Code on fake GitHub repos to deliver Vidar infostealer. The Drift Protocol lost ~$280M after attackers (linked to North Korea) seized governance powers. Researchers report residential proxy traffic evades IP reputation checks at scale, while adversaries exploit vacant homes as mail drop addresses for hybrid fraud. Two pre-auth vulnerabilities in Progress ShareFile can be chained for unauthenticatedR
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 60c58be56eae860f21187fcf1a03ff1a7c3e3b3ef50ec68db978c77fb26d22a6
- Enrichment time
- 2026-04-03T07:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.