TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
2026-05-12T01:24:17Z•b1d62a2c539129d9f24c3b566039536669a4db9205d96e34a169658f759801a4
bleeding-llamacheckmarxcpanelcredential-theftcve-2026-0300cve-2026-41940cve-2026-6973cve-2026-7482dirty-fragfilemanager-backdoorhuggingface-malicious-repoivantijenkins-pluginlinux-lpemr_rot13ollamapamdoorapan-ospcpjackpyPI-malwarequasar-linux-ratsandbox-escapesupply-chainteampcpvm2
What happened
Multiple high-impact incidents and active exploitations reported: a supply-chain compromise by TeamPCP replaced the Checkmarx Jenkins AST plugin; cPanel/WHM vulnerability CVE-2026-41940 is being actively exploited to deploy a Filemanager backdoor (attributed to threat actor Mr_Rot13); Google disclosed an AI-assisted zero-day 2FA bypass used in mass exploitation; Ollama has a critical out-of-bounds read (CVE-2026-7482 “Bleeding Llama”) allowing full process memory leakage; PAN-OS CVE-2026-0300 RCE and Ivanti EPMM CVE-2026-6973 are under active exploitation; multiple supply-chain and repository‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b1d62a2c539129d9f24c3b566039536669a4db9205d96e34a169658f759801a4
- Enrichment time
- 2026-05-12T01:24:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.