U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
2026-07-04T19:24:09Z•a219eeaa5a8779dc6a9b4d6470af5644824dbfd900b5eb093a1a0dedef59f6eb
androidargo-cdavaloncrownxcursor-prompt-injection-flaws','adobe-patches'data-extortionembedded-devicesfatfskairoslinux-kernelmacos-stealermalicious-packagesmalware-frameworknorth-koreanpmnpm-supply-chainpackagistpamstealerpegasusprivilege-escalationprompt-injectionransomwaresharepointspywaresupply-chain
What happened
A roundup of active high-impact threats and vulnerabilities: a U.S. government entity paid ~ $1M in a Kairos data-theft extortion case; North Korea-linked PolinRider activity published 108 malicious packages and npm supply-chain impostors; runZero disclosed seven FatFs flaws affecting millions of embedded devices; Bad Epoll Linux kernel privilege-escalation (CVE-2026-46242) affects Linux and Android; a new Avalon modular malware framework with CrownX ransomware capabilities was observed; multiple stealers and multi-stage campaigns (PamStealer, PureLogs via VEIL#DROP, AsyncRAT via SEO-poisoned/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- a219eeaa5a8779dc6a9b4d6470af5644824dbfd900b5eb093a1a0dedef59f6eb
- Enrichment time
- 2026-07-04T19:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.