Weekly Threat Intel: August 21–28, 2026
The ChainDrop npm worm picks up its sixth and seventh independent vendor confirmations — still persisting via the same .claude/settings.json and .vscode/tasks.json hooks — while PolySwarm publishes eight reports in under three minutes mixing new material (Kimsuky's AI-tooling-equipped Operation GitPower, an Iranian PLC campaign against US critical infrastructure) with second opinions on campaigns already tracked here. A suspected China-nexus APT chains a VMware vCenter CVE straight to root access and ransomware, Security.com matches PolySwarm's publishing cadence with four reports in 24 seconds, and this week's two largest reports both funnel fake-media lures into commodity RATs.