Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
2026-09-24T01:24:01Z•e055877bc82383d0f2659a1361d79ad6a93f96d323a912bb585aff190b789596
CVE-2026-65660CVE-2026-67279CVE-2026-80521CVE-2026-85046CVE-2026-85880CVE-2026-86060CVE-2026-87491CVE-2026-89775CVE-2026-90898CVE-2026-93616CVE-2026-93952CVE-2026-94127AI-securityBifrostChromeF5 BIG-IPLinuxNext.jsRouterOSSharePointWindowsWordPressactive-exploitationcontainer-escapecredential-theftmalicious-npm-packagemalicious-pypi-packagemalicious-terraform-providerphishingprivilege-escalationransomware/extortionremote-code-executionsupply-chain-attackunauthenticated-rcevirtualization-escapevulnerabilitieszero-day
What happened
The document is a cybersecurity news feed reporting multiple high-impact vulnerabilities, active exploitation campaigns, supply-chain attacks, malicious packages, credential theft, zero-day exploitation, and AI-related security risks. Notable items include unauthenticated remote code execution in F5 BIG-IP APM, Bifrost, Check Point Security Management Server, Next.js, WordPress, and cPanel; router and virtualization escapes; Chrome/Windows zero-day exploitation; compromised npm, PyPI, Go Module, and Terraform packages; and phishing and credential-stealing services.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- e055877bc82383d0f2659a1361d79ad6a93f96d323a912bb585aff190b789596
- Enrichment time
- 2026-09-24T01:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.