logo

North Korea PolinRider expands to 108 packages; Avalon ransomware framework emerges

ID: a00d6bb6-f064-5bdc-9415-2a6ba7374281

STIX ID: report--a00d6bb6-f064-5bdc-9415-2a6ba7374281

Feed Name: defend.network

Threat Score
85/100

Date Published: 2026-07-06

Date Updated: 2026-07-06

Author: defend.network

...
...

This briefing highlights several high-risk threats: North Korean-linked PolinRider has published 108 malicious packages and extensions across multiple registries; a new modular malware framework, Avalon, is being used to steal credentials and stage CrownX ransomware; Linux kernel CVE-2026-46242 ('Bad Epoll') permits unprivileged local root escalation on Linux and Android; FatFs contains multiple unpatched flaws in embedded devices; and a U.S. government entity reportedly paid ~$1M to the Kairos extortion group. Recommended actions include urgent kernel patching, dependency audits and SCA, enhanced email security, MFA enforcement, and incident response preparations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.