JADEPUFFER agentic ransomware used an LLM agent to breach Langflow, harvest credentials, and destroy Nacos data in minutes. Full attack chain and defense guide.
TeamPCP hackers are hijacking developer tools and CI/CD pipelines to steal cloud tokens, SSH keys, Kubernetes secrets, and package credentials. The FBI TeamPCP alert confirms the group’s TTPs and IOCs, while public research shows repeated compromise across Trivy, KICS, LiteLLM, Bitwarden CLI, and related developer tooling.
A Microsoft Edge flaw chain involving CVE-2026-45492, CVE-2026-45494, and CVE-2026-45495 creates remote code execution risk through crafted web content.