North Korea PolinRider expands to 108 packages; Avalon ransomware framework emerges
ID: a00d6bb6-f064-5bdc-9415-2a6ba7374281
STIX ID: report--a00d6bb6-f064-5bdc-9415-2a6ba7374281
Feed Name: defend.network
This briefing highlights several high-risk threats: North Korean-linked PolinRider has published 108 malicious packages and extensions across multiple registries; a new modular malware framework, Avalon, is being used to steal credentials and stage CrownX ransomware; Linux kernel CVE-2026-46242 ('Bad Epoll') permits unprivileged local root escalation on Linux and Android; FatFs contains multiple unpatched flaws in embedded devices; and a U.S. government entity reportedly paid ~$1M to the Kairos extortion group. Recommended actions include urgent kernel patching, dependency audits and SCA, enhanced email security, MFA enforcement, and incident response preparations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
