U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
2026-07-05T01:24:07Z•26d8f5e65d9a08e8eabf73ad925e359c678d441bdaa4fca4a5fabd02cdac5678
androidargocdavalonchrome-extensionscisa-kevcitrix-bleedcredential-theftcrownxdata-theftembedded-devicesextortionfatfskuberneteslinux-kernelmalicious-packagesmalware-frameworknorth-koreanpmpackagistpamstealerpolinriderprivilege-escalationransomwaresharepointsupply-chain
What happened
A large batch of July 2026 security headlines: a U.S. government entity paid roughly $1M to stop a data-theft extortion (actor calling itself Kairos); widespread supply-chain and package-repository abuse (including 108 malicious packages/extensions in the North Korean-linked PolinRider campaign and npm packages mimicking Rollup tooling); multiple high-risk vulnerabilities and active exploits (Bad Epoll local privilege escalation, SharePoint RCE added to CISA KEV, Cursor sandbox-escape flaws); new malware/tooling (Avalon framework with CrownX ransomware capabilities, PamStealer for macOS, Pure-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 26d8f5e65d9a08e8eabf73ad925e359c678d441bdaa4fca4a5fabd02cdac5678
- Enrichment time
- 2026-07-05T01:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.