TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack

2026-05-01T02:51:45Z70b3aa006e26b0c2030570e767684d26d29f612de7c2af6cb31851fb91230df0
CVE-2026-1731SAPTeamPCPagentic-aiai-securityaptbluenoroffbomgarglassworminfostealerlazarusnpmopenemrphantomrpcprivilege-escalationprompt-injectionransomwarercesupply-chainunc6692vectvidarvs-code-extensionsvulnerabilitywiper

What happened

A DarkReading news roundup covering a broad set of active cybersecurity incidents and research: supply-chain compromises (TeamPCP seeding malicious npm packages targeting SAP cloud tooling; GlassWorm VS Code extensions), high-impact vulnerabilities and proof-of-concept exploits (Linux bug PoC with short exploit, unpatched PhantomRPC Windows privilege-escalation paths, Google 'Antigravity' agent sandbox-escape RCE), ransomware and wiper developments (Vect 2.0 design issues; rising gangs like 'The Gentlemen'), targeted APT activity (Lazarus, BlueNoroff, UNC6692, Tropic Trooper), and large-scale

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
70b3aa006e26b0c2030570e767684d26d29f612de7c2af6cb31851fb91230df0
Enrichment time
2026-05-01T02:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.