Containers on fire: from container escapes to supply chain attacks

2026-06-02T08:51:55Z81eaa3df5de3ebee7894ea0a2a4794cfa7c2e9c415d72fe7605194885e6461af
api-compromiseappleseedcloud-atlascontainer-hardeningcontainer-securitydata-leakedr-evasioniot-threatskimsukykira-aimacosminermobile-threatspebbledashpirated-content-campaignspowercloudprivilege-misconfigurationransomware-trendsratreverse-sockssecrets-exposuresupply-chainvulnerability-disclosurewindows

What happened

Kaspersky Securelist roundup covering multiple high-risk trends and disclosures: detailed analysis of container attack vectors (exposed secrets, privilege misconfigurations, API compromise and supply‑chain attacks) and guidance on container security (including Kaspersky Container Security + KIRA). Threat actor reporting: Cloud Atlas campaigns (using ReverseSocks, SSH, Tor and a new PowerCloud payload) and Kimsuky activity employing PebbleDash tools linked to the AppleSeed cluster. Malware/living-off-the-land trends: consumer-targeted campaigns distributing miners and a new RAT via pirated‑site

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
81eaa3df5de3ebee7894ea0a2a4794cfa7c2e9c415d72fe7605194885e6461af
Enrichment time
2026-06-02T08:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.