CTI-2026-0526-KIMSUKY-PEBBLEDASH
Kimsuky (APT43) — Analysis of the New PebbleDash · AppleSeed Toolset
First Rust-based backdoor, abuse of VSCode · Cloudflare tunneling, and traces of LLM-generated code
Field
Value
CTI-2026-0526-KIMSUKY-PEBBLEDASH Kimsuky (APT43) — Analysis of the New PebbleDash ·...
CTI-2026-0526-KIMSUKY-PEBBLEDASH
Kimsuky (APT43) — Analysis of the New PebbleDash · AppleSeed Toolset
First Rust-based backdoor, abuse of VSCode · Cloudflare tunneling, and traces of LLM-generated code
Field
Value

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

Exploit Code Published for Critical Flowise RCE Vulnerability

AI eyes scanning for bugs create a worrisome Linux security trend

Kimsuky used fake security tools and Webex pages in March-April 2026 to deploy HTTPSpy, enabling persistent espionage and data…

New IElevator2 COM interface? No problem

A 700-repo npm supply-chain campaign drops /tmp/.sshd and bolts a fake "Dependency Cache Sync" step into your GitHub Actions.…

CVE-2026-5426 enabled KnowledgeDeliver LMS attacks before February 24, 2026, leading to Cobalt Strike infections.

CLI-Anything generates SKILL.md files that AI agents trust and execute. Snyk found 13.4% of agent skills contain critical…

TeamPCP’s Mini Shai-Hulud campaign used hijacked GitHub OIDC tokens to spread a credential-stealing worm through TanStack npm…