TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
2026-05-01T02:51:45Z•70b3aa006e26b0c2030570e767684d26d29f612de7c2af6cb31851fb91230df0
CVE-2026-1731SAPTeamPCPagentic-aiai-securityaptbluenoroffbomgarglassworminfostealerlazarusnpmopenemrphantomrpcprivilege-escalationprompt-injectionransomwarercesupply-chainunc6692vectvidarvs-code-extensionsvulnerabilitywiper
What happened
A DarkReading news roundup covering a broad set of active cybersecurity incidents and research: supply-chain compromises (TeamPCP seeding malicious npm packages targeting SAP cloud tooling; GlassWorm VS Code extensions), high-impact vulnerabilities and proof-of-concept exploits (Linux bug PoC with short exploit, unpatched PhantomRPC Windows privilege-escalation paths, Google 'Antigravity' agent sandbox-escape RCE), ransomware and wiper developments (Vect 2.0 design issues; rising gangs like 'The Gentlemen'), targeted APT activity (Lazarus, BlueNoroff, UNC6692, Tropic Trooper), and large-scale
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 70b3aa006e26b0c2030570e767684d26d29f612de7c2af6cb31851fb91230df0
- Enrichment time
- 2026-05-01T02:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.