Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
2026-07-06T19:24:05Z•bf592e4c52d08a5bb114f77ebf832e1480b958b77e03e423aa0f2c55a4813379
APTArmored LikhoBad EpollBlogspot-hosted payloadsLangflowLinux privilege escalationPolinRiderPowerShellPureLogRATShinyHuntersVeil#Dropagentic AIbackdoorcrypto theftdata breachelectric power sectorfilelessgovernment targetinginformation stealeropen source compromiseprompt injectionproof-of-concept exploitransomware automationsupply chain compromise
What happened
Feed of security news covering multiple active threats and high-impact incidents: a Veil#Drop campaign abusing compromised sites and Blogspot to deliver PureLog information stealer via PowerShell and fileless techniques; PolinRider supply-chain attacks (North Korean-linked) compromising 100+ open-source packages to deliver backdoors and stealers; Armored Likho APT targeting government and electric power organizations with modular RATs and stealers; a proof-of-concept exploit published for the Linux “Bad Epoll” local root escalation vulnerability (patch urged); agentic AI and prompt-injection‑b
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- bf592e4c52d08a5bb114f77ebf832e1480b958b77e03e423aa0f2c55a4813379
- Enrichment time
- 2026-07-06T19:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.