Cloud Threat Highlights: H1 2026
ID: b9ad4be7-7dc1-50a7-a460-199ed193e13b
STIX ID: report--b9ad4be7-7dc1-50a7-a460-199ed193e13b
Feed Name: Wiz Blog
Wiz Research reports a sharp increase in large-scale software supply-chain attacks and AI-infrastructure targeting in H1 2026: coordinated campaigns (notably TeamPCP and IronWorm) trojanized packages across npm, PyPI, VSCode extensions and more, stealing developer credentials that were reused by other groups; North Korean actors conducted sizeable trojanizations as well, and a new extortion-focused cloud-native group (JINX-0163) targeted non-human identities to harvest secrets. The report details sophisticated TTPs (OIDC token extraction, CI poisoning, eBPF rootkits, Tor-based C2), active exploitation of AI toolchains and critical vulnerabilities, and provides detection guidance and telemetry-driven mitigations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
