Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

2026-09-21T07:23:59Z•f9a56019b726658bf2320e059e50cb6a52ce2527260cd6aa1806f1084440bf42
CVE-2025-39682CVE-2026-28326CVE-2026-58138CVE-2026-77179CVE-2026-81642CVE-2026-85889AI-securityAndroid-malwareCISA-KEVChinaDNSSECDockerIranNorth KoreaPakistanWordPressactive-exploitationcloud-securityidentity-securitylinux-kernelnpm-malwareprivilege-escalationremote-code-executionstate-sponsored-threatssupply-chain-attackzero-day

What happened

The feed reports multiple significant cybersecurity developments, including active exploitation of critical vulnerabilities, state-sponsored intrusion campaigns, supply-chain compromises, malware distribution through npm and Android channels, and security flaws in AI coding tools and cloud platforms. The highest-risk items include pre-authenticated remote code execution in Orkes Conductor, Linux kernel vulnerabilities added to CISA KEV, critical Docker Sandbox and Unbound DNS flaws, and a CVSS 10 Azure AI Foundry privilege-escalation issue.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
f9a56019b726658bf2320e059e50cb6a52ce2527260cd6aa1806f1084440bf42
Enrichment time
2026-09-21T07:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.