Containers on fire: from container escapes to supply chain attacks
2026-06-02T08:51:55Z•81eaa3df5de3ebee7894ea0a2a4794cfa7c2e9c415d72fe7605194885e6461af
api-compromiseappleseedcloud-atlascontainer-hardeningcontainer-securitydata-leakedr-evasioniot-threatskimsukykira-aimacosminermobile-threatspebbledashpirated-content-campaignspowercloudprivilege-misconfigurationransomware-trendsratreverse-sockssecrets-exposuresupply-chainvulnerability-disclosurewindows
What happened
Kaspersky Securelist roundup covering multiple high-risk trends and disclosures: detailed analysis of container attack vectors (exposed secrets, privilege misconfigurations, API compromise and supply‑chain attacks) and guidance on container security (including Kaspersky Container Security + KIRA). Threat actor reporting: Cloud Atlas campaigns (using ReverseSocks, SSH, Tor and a new PowerCloud payload) and Kimsuky activity employing PebbleDash tools linked to the AppleSeed cluster. Malware/living-off-the-land trends: consumer-targeted campaigns distributing miners and a new RAT via pirated‑site
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 81eaa3df5de3ebee7894ea0a2a4794cfa7c2e9c415d72fe7605194885e6461af
- Enrichment time
- 2026-06-02T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.