TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack

2026-05-12T01:24:17Zb1d62a2c539129d9f24c3b566039536669a4db9205d96e34a169658f759801a4
bleeding-llamacheckmarxcpanelcredential-theftcve-2026-0300cve-2026-41940cve-2026-6973cve-2026-7482dirty-fragfilemanager-backdoorhuggingface-malicious-repoivantijenkins-pluginlinux-lpemr_rot13ollamapamdoorapan-ospcpjackpyPI-malwarequasar-linux-ratsandbox-escapesupply-chainteampcpvm2

What happened

Multiple high-impact incidents and active exploitations reported: a supply-chain compromise by TeamPCP replaced the Checkmarx Jenkins AST plugin; cPanel/WHM vulnerability CVE-2026-41940 is being actively exploited to deploy a Filemanager backdoor (attributed to threat actor Mr_Rot13); Google disclosed an AI-assisted zero-day 2FA bypass used in mass exploitation; Ollama has a critical out-of-bounds read (CVE-2026-7482 “Bleeding Llama”) allowing full process memory leakage; PAN-OS CVE-2026-0300 RCE and Ivanti EPMM CVE-2026-6973 are under active exploitation; multiple supply-chain and repository‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b1d62a2c539129d9f24c3b566039536669a4db9205d96e34a169658f759801a4
Enrichment time
2026-05-12T01:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.