Containers on fire: from container escapes to supply chain attacks
2026-06-01T20:51:54Z•8c76ff6e7e21cdbd0766062092cb546d2d59c5d938c039d9a7a7b1d757f06af9
API compromiseAPTAppleSeedCVE-2025-68670CVE-2026-3102Cloud AtlasEDR evasionExifToolKIRA AIKaspersky Container SecurityKimsukyPebbleDashPowerCloudRATReverseSocksSSH persistenceTorcoinminercontainer securitypirated-content campaignsprivilege misconfigurationransomware trendssecrets exposuresupply chainxrdp
What happened
Kaspersky Securelist roundup covering container security and supply-chain risks (exposed secrets, privilege misconfigurations, API compromise), guidance and product notes (Kaspersky Container Security + KIRA), multiple threat reports (Q1 2026 mobile and non-mobile), and active campaigns: pirated-content distribution with miners and a new RAT module, Kimsuky using PebbleDash tied to AppleSeed, and Cloud Atlas targeting public-sector/diplomatic entities using ReverseSocks, SSH, Tor and a new PowerCloud payload. Also disclosed vulnerabilities include an ExifTool flaw enabling macOS compromise (CV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 8c76ff6e7e21cdbd0766062092cb546d2d59c5d938c039d9a7a7b1d757f06af9
- Enrichment time
- 2026-06-01T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.