logo

Cloud Threat Highlights: H1 2026

ID: b9ad4be7-7dc1-50a7-a460-199ed193e13b

STIX ID: report--b9ad4be7-7dc1-50a7-a460-199ed193e13b

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2026-08-06

Date Updated: 2026-08-10

Author: Wiz Threat Research

...
...

Wiz Research reports a sharp increase in large-scale software supply-chain attacks and AI-infrastructure targeting in H1 2026: coordinated campaigns (notably TeamPCP and IronWorm) trojanized packages across npm, PyPI, VSCode extensions and more, stealing developer credentials that were reused by other groups; North Korean actors conducted sizeable trojanizations as well, and a new extortion-focused cloud-native group (JINX-0163) targeted non-human identities to harvest secrets. The report details sophisticated TTPs (OIDC token extraction, CI poisoning, eBPF rootkits, Tor-based C2), active exploitation of AI toolchains and critical vulnerabilities, and provides detection guidance and telemetry-driven mitigations for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.