Containers on fire: from container escapes to supply chain attacks

2026-06-01T20:51:54Z8c76ff6e7e21cdbd0766062092cb546d2d59c5d938c039d9a7a7b1d757f06af9
API compromiseAPTAppleSeedCVE-2025-68670CVE-2026-3102Cloud AtlasEDR evasionExifToolKIRA AIKaspersky Container SecurityKimsukyPebbleDashPowerCloudRATReverseSocksSSH persistenceTorcoinminercontainer securitypirated-content campaignsprivilege misconfigurationransomware trendssecrets exposuresupply chainxrdp

What happened

Kaspersky Securelist roundup covering container security and supply-chain risks (exposed secrets, privilege misconfigurations, API compromise), guidance and product notes (Kaspersky Container Security + KIRA), multiple threat reports (Q1 2026 mobile and non-mobile), and active campaigns: pirated-content distribution with miners and a new RAT module, Kimsuky using PebbleDash tied to AppleSeed, and Cloud Atlas targeting public-sector/diplomatic entities using ReverseSocks, SSH, Tor and a new PowerCloud payload. Also disclosed vulnerabilities include an ExifTool flaw enabling macOS compromise (CV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
8c76ff6e7e21cdbd0766062092cb546d2d59c5d938c039d9a7a7b1d757f06af9
Enrichment time
2026-06-01T20:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.