Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
2026-09-24T07:24:00Z•e57144d4740b6d3359d11475a4c0561fe29db304efcf44eb50404c9e6dc498ac
CVE-2026-65660CVE-2026-67279CVE-2026-80521CVE-2026-85046CVE-2026-85880CVE-2026-86060CVE-2026-87491CVE-2026-89775CVE-2026-90898CVE-2026-93616CVE-2026-93952CVE-2026-94127active-exploitationai-securitycheck-pointchromecontainer-escapecredential-theftf5-big-ipgo-moduleslinux-kernelmalicious-packagesmalwarenextjsnpmphishingpypiremote-code-executionrouterossupply-chainterraformunauthenticated-rcevelocloudvirtualization-escapewindowswordpresszero-day
What happened
The feed reports widespread active exploitation and supply-chain abuse across infrastructure, developer ecosystems, enterprise software, browsers, operating systems, and AI tooling. Notable threats include unauthenticated remote code execution in F5 BIG-IP APM, Bifrost, Check Point, Next.js, WordPress, cPanel, and VeloCloud; RouterOS takeover chains; Chrome/Windows zero-day exploitation; Linux container and VM escapes; malicious Terraform, npm, PyPI, and Go packages; credential theft; phishing infrastructure; and malware campaigns. Multiple vulnerabilities are actively exploited or have public
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- e57144d4740b6d3359d11475a4c0561fe29db304efcf44eb50404c9e6dc498ac
- Enrichment time
- 2026-09-24T07:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.