§ Tag
Tag

Control

Cyber Tools

Pending Verification: What TeamPCP’s 4,000-Repo Claim Changes Either Way

TeamPCP — the supply-chain crew behind the Trivy / Checkmarx / KICS / LiteLLM compromises and the Shai-Hulud worm — surfaced a sale listing on May 19, 2026 claiming roughly 4,000 GitHub private repositories of internal source code. The claim is pending verification, the ESIX score is 7.96, and the group’s track record is exactly the mix of ‘demonstrably capable’ and ‘inclined to repackage’ that makes this kind of listing operationally annoying. Here’s the read.

·
CA

Volt Typhoon at Year Three: Pre-Positioning Detection in 2026

A defender-side look at where PRC pre-positioning campaigns against critical infrastructure stand heading into 2026, what living-off-the-land actually looks like in the SIEM, and which tuning calls separate the teams that catch it from the teams that don’t.

·
CM

Image-Mode Linux Concentrates Persistence Into /etc and /var

Image-mode RHEL and bootc move /usr to a read-only ostree commit and turn host updates into container pulls. That fixes one class of problem and creates a different one for defenders. Here is what actually changes on disk, what to detect, and where the model breaks.

·
AC

TPM-Only BitLocker: The Default Configuration YellowKey Fully Defeats

Chaotic Eclipse dropped two unpatched Windows zero-days on May 13, 2026. YellowKey turns an NTFS transaction log on a USB stick into a BitLocker bypass through WinRE — physical access, no recovery key, no PIN required on TPM-only boxes. GreenPlasma is the companion privilege escalation through CTFMON. No CVEs, no patches, and a researcher who has promised more for June’s Patch Tuesday.

·
Cyber Tools

ClickFix Detection Without the Fairy Tale

ClickFix initial access has been pasting PowerShell into RunMRU for two years and most detection content still treats it like a primer. Here is what the telemetry actually looks like, what tunes out, and where teams keep getting it wrong.

·