CVE-2026-21962 reached CISA's exploited-vulnerabilities catalog on August 24 with an August 27 deadline. Honeypots logged attempts in March, and Oracle's fix has been available since January.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.
Perspective Coverage
17 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence62
Gambit Security says the ransomware crew used a commercial coding agent for hands-on post-compromise work between 8 April and 21 May, alongside a new Linux encryptor that force-kills running guests before it touches ESXi datastores.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence78
- Adoption60
- Hype gap+22
- Incentives58
- Confidence70
CloudSEK took administrator access to the panel and counted 5,137 stolen records coming off 42 VPS nodes into five leasing affiliates' Telegram bots, with the phishing pages dark for three weeks while the panel itself stays reachable.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption30
- Hype gap+25
- Incentives40
- Confidence60
CrowdSec kept a leaver's GitHub access open so he could finish some work, his laptop was hit by the TanStack npm compromise on May 11, and the repositories were copied on May 22 and posted to a forum on September 16.
Perspective Coverage
7 publishers
- Builder
- Builder 39%
- Operator
- Operator 52%
- Investor
- Investor 9%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives65
- Confidence60
An intruder inside the work platform shared by Japanese ministries took names, emails and phone numbers belonging to 246,000 staff and contractors, and the agency says none of it has shown up in a confirmed case of misuse.
Reality
- Evidence42
- Adoption45
- Hype gap+35
- Incentives62
- Confidence40
CloudSEK got inside the BigBear 2.0 administrative panel and found more captured Microsoft 365 session cookies than plaintext passwords, along with code written to switch FIDO2 off on the phishing pages.
Reality
- Evidence55
- Adoption58
- Hype gap+12
- Incentives72
- Confidence56
CloudSEK says the kit's JavaScript disrupts FIDO2 on a cloned Microsoft 365 login and steers the victim to TOTP, SMS or push, so the tenant's authentication strength policy decides whether the relay works.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+12
- Incentives50
- Confidence45
Two tracked clusters hit Mexican, Ecuadorian and Brazilian targets with living-off-the-land tradecraft, numbered batch scripts and shared SOCKS5 relays. The AI tooling they left running is the part defenders can query for.
Reality
- Evidence66
- Adoption52
- Hype gap+18
- Incentives70
- Confidence57
CloudSEK's BRIDGEHEAD report tracks forty npm typosquats whose install script tests for Windows underneath Linux, then pulls a Rust stealer that reads the host's wallets and cookies.
Publishers:cloudsek.com
Reality
- Evidence63
- Adoption27
- Hype gap+14
- Incentives74
- Confidence56
StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
Reality
- Evidence46
- Adoption42
- Hype gap+16
- Incentives79
- Confidence51
A researcher says an unreported campaign used a fake GSTR-3B overdue notice ahead of the 20 August filing deadline, delivering a patched DLL that a genuinely signed Microsoft binary loads.
Publishers:blog.himanshuanand.com
Reality
- Evidence62
- Adoption28
- Hype gap+18
- Incentives55
- Confidence54
Hudson Rock's analysis of the exfiltration archive ties 118,829 CI runner dumps to 2,488 organizations. The dumps carrying no identifying metadata are the harder half.
Publishers:blog.gitguardian.com
Reality
- Evidence56
- Adoption71
- Hype gap+12
- Incentives79
- Confidence54
SOCRadar's record-level data puts 95 percent of identified victims before the poisoned LiteLLM packages ever hit PyPI. Anyone who rotated only what LiteLLM touched is still exposed.
Reality
- Evidence52
- Adoption68
- Hype gap+12
- Incentives66
- Confidence55