TeamPCP hackers advertise Mistral AI code repos for sale

2026-05-15T07:23:36Za9cf6e816e2cef5379371faf00ceec98cc48f9c05a9e9f68e023720e4a4933e3
BitLockerBurst StatisticsCVE-2026-20182CVE-2026-46300CiscoDoSEximFragnesiaGreenPlasmaKongTukeMicrosoft Teams social engineering','ransomware','data exfilMistral AINGINXOpenAIPwn2OwnRCESD-WANTanStackTeamPCPWordPressYellowKeyauthentication bypasskernel privilege escalationsupply-chainzero-day

What happened

Multiple high-severity incidents and active exploitations reported: TeamPCP is advertising stolen Mistral AI source code; attackers are exploiting a critical authentication-bypass in the Burst Statistics WordPress plugin to gain admin access; Cisco confirmed active zero-day exploitation of a critical SD‑WAN Controller auth-bypass (CVE-2026-20182) enabling administrative access; OpenAI experienced device breaches tied to the TanStack supply-chain attack and rotated code-signing certificates; researchers disclosed PoCs and exploits including BitLocker bypasses (YellowKey, GreenPlasma), an 18‑yr‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
a9cf6e816e2cef5379371faf00ceec98cc48f9c05a9e9f68e023720e4a4933e3
Enrichment time
2026-05-15T07:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.