logo

The Good, the Bad and the Ugly in Cybersecurity – Week 13

ID: 5cb857bc-0a86-5ab2-abd8-ed1f783a91df

STIX ID: report--5cb857bc-0a86-5ab2-abd8-ed1f783a91df

Feed Name: SentinelOne Blog

Threat Score
85/100

Date Published: 2026-03-27

Date Updated: 2026-04-30

Author: SentinelOne

...
...

The report describes multiple high-impact incidents: U.S. prosecutions and extraditions tied to Yanluowang ransomware affiliates and a RedLine operator; an ongoing FAUX#ELEVATE phishing campaign using obfuscated VBScript to deliver credential stealers and cryptocurrency miners that target enterprise domain-joined systems and abuse legitimate services for staging and exfiltration; and a widespread supply-chain compromise by TeamPCP that injected credential-stealing backdoors into Trivy, npm packages (CanisterWorm), and the LiteLLM PyPI package, leading to credential, SSH key, cloud token, and secret theft across CI/CD and cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.