Supply chain attack by TeamPCP threat group compromising LiteLLM framework in March 2026. Largest AI infrastructure attack of 2026, affecting 2,500+ organizations and 434,000 CI/CD pipelines worldwide. Exposed cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys. FBI issued FLASH advisory July 2026 warning stolen credentials remain weaponizable.
Rotate all credentials, API keys, cloud tokens, SSH keys, and Kubernetes secrets that may have been exposed. Review CI/CD pipeline configurations for unauthorized modifications. Audit access logs from March 2026 forward. Implement secret scanning and credential rotation policies.
Source: GTIG • Published: 2026-03-01
Iranian APT (IRGC CEC-affiliated CyberAv3ngers) targeting critical infrastructure PLCs using configuration software (Rockwell Studio 5000, Schneider EcoStruxure, Siemens TIA Portal). Actors exfiltrate PLC project files via leased third-party infrastructure, then modify/delete logic including Add-On Instructions. Disable shutdown and alarm logic creating unsafe conditions without operator notification. Campaign compromised 75+ devices across water, wastewater, manufacturing, energy sectors.
Isolate all PLC and SCADA systems from internet access immediately. Implement strict network segmentation with dedicated OT networks. Monitor for unauthorized PLC configuration changes. Review all project files for suspicious modifications to shutdown/alarm logic. Deploy industrial IDS/IPS solutions. Restrict configuration software access to authorized personnel only.
Source: CISA • Published: 2026-08-15
Largest educational security breach on record affecting Canvas LMS. ShinyHunters claimed theft of 3.65TB data from 275 million users across 8,809 institutions worldwide. Compromised private messages between students and teachers, affecting 41% of US higher education institutions. Unprecedented global scale breach in educational technology sector.
Educational institutions using Canvas must review access logs for April-May 2026 immediately. Reset all user credentials. Notify affected students, teachers, and staff of potential data exposure. Implement multi-factor authentication. Review and restrict third-party Canvas integrations. Monitor for account takeover attempts using stolen credentials.
Source: BleepingComputer • Published: 2026-04-25
China-aligned threat actors (Earth Baxia, SHADOW-EARTH-067) replacing traditional C&C with legitimate cloud platforms in H1 2026. AI integrated into entire attack chain from exploit enhancement to autonomous reconnaissance and lateral movement. One case documented AI agent conducting independent reconnaissance and lateral movement after jailbreak via fake penetration test claim. Targeted Pakistani law enforcement (February 2024-April 2026) compromising biometric records, criminal databases, hotel/tenant registration systems.
Monitor Microsoft Graph API, OneDrive, and OneNote for anomalous usage patterns indicating C&C abuse. Implement behavior-based detection for AI-assisted lateral movement. Deploy UEBA solutions to identify autonomous agent activity. Restrict cloud service API access. Review access to sensitive databases and biometric systems for indicators of compromise.
Source: GTIG • Published: 2026-06-01
LITELM-2026-001: Supply chain attack by TeamPCP threat group compromising LiteLLM framework in March 2026. Largest AI infrastructure attack of 2026, affecting 2,500+ organizations and 434,000 CI/CD pipelines worldwide. Exposed cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys. FBI issued FLASH advisory July 2026 warning stolen credentials remain weaponizable.