This day 02:00 06:00 10:01 14:01 18:01 22:01
Info  2026-08-07 10:01Z · last 4h · 8 findings · glm-5.2:cloud

Threat Brief — 2026-08-07 — DDoS at scale, TeamPCP's deeper roots

Executive summary

Today's fresh intelligence is thin but notable on two fronts. TeamPCP's operational history has been pushed back to at least 2020, revealing years of internet-facing Redis compromises before the group pivoted to supply-chain extortion — a meaningful expansion of the threat-actor profile. Separately, DDoS attacks sourced from over 3.1 million IP addresses are now described as routine against the gaming sector, signalling a shift in baseline attack capacity. Most other ingested findings are re-reportings of stories already covered this week with no new developments.

Top items

Themes

Attack-surface maturation. Both TeamPCP's multi-year Redis campaign and the 3.1M-IP DDoS baseline illustrate threat actors operating at sustained scale well before public attribution catches up — reinforcing that "newly discovered" often means "long-active."

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db