Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
2026-09-21T07:23:59Z•f9a56019b726658bf2320e059e50cb6a52ce2527260cd6aa1806f1084440bf42
CVE-2025-39682CVE-2026-28326CVE-2026-58138CVE-2026-77179CVE-2026-81642CVE-2026-85889AI-securityAndroid-malwareCISA-KEVChinaDNSSECDockerIranNorth KoreaPakistanWordPressactive-exploitationcloud-securityidentity-securitylinux-kernelnpm-malwareprivilege-escalationremote-code-executionstate-sponsored-threatssupply-chain-attackzero-day
What happened
The feed reports multiple significant cybersecurity developments, including active exploitation of critical vulnerabilities, state-sponsored intrusion campaigns, supply-chain compromises, malware distribution through npm and Android channels, and security flaws in AI coding tools and cloud platforms. The highest-risk items include pre-authenticated remote code execution in Orkes Conductor, Linux kernel vulnerabilities added to CISA KEV, critical Docker Sandbox and Unbound DNS flaws, and a CVSS 10 Azure AI Foundry privilege-escalation issue.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- f9a56019b726658bf2320e059e50cb6a52ce2527260cd6aa1806f1084440bf42
- Enrichment time
- 2026-09-21T07:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.