Skip to content
Threat Feed

Vendor

HashiCorp

7 briefs RSS
high threat

TraderTraitor Campaign Targeting DevOps Engineers via Weaponized Terraform Repositories

North Korean threat actor TraderTraitor is using fake job interview lures on GitHub containing weaponized Terraform lock files to deliver macOS backdoors to DevOps engineers, facilitating cloud credential theft.

Terraform TraderTraitor macos supply-chain social-engineering cloud-security devops
4t 5i
medium advisory

HashiCorp Terraform Information Disclosure and Security Bypass

A local vulnerability in HashiCorp Terraform identified as CVE-2024-7956 allows local attackers to bypass security controls and access sensitive configuration information.

Terraform
1t
high advisory

Privilege Escalation in HashiCorp Vault Secrets Operator

A vulnerability in the HashiCorp Vault Secrets Operator allows a remote, authenticated attacker to escalate privileges, leading to potential unauthorized data disclosure or manipulation within Kubernetes environments.

Vault Secrets Operator privilege-escalation kubernetes cloud-native cve
1t 1c
low advisory

Security Updates for HashiCorp Consul

HashiCorp has released security advisory HCSEC-2026-25 addressing multiple vulnerabilities in Consul Community Edition and Consul Enterprise that require immediate patching.

Consul Community Edition +1 informational product-news
1i
high advisory

Shai-Hulud Campaign Activity

Tracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.

jscrambler 8.14.0 +102 campaign shai-hulud
20i updated
medium advisory

Hashicorp Terraform: Information Disclosure Vulnerability

A vulnerability in Hashicorp Terraform allows a remote, authenticated attacker to disclose sensitive information, which could lead to the exposure of confidential data.

Terraform information-disclosure vulnerability hashicorp
1t
critical advisory

Malicious @beproduct/nestjs-auth Package Contains Mini Shai-Hulud Worm (CVE-2026-46412)

Between May 11th and May 12th of 2026, a threat actor compromised an npm publish token to publish 18 malicious versions of the '@beproduct/nestjs-auth' package (versions 0.1.2 through 0.1.19) containing payloads from the Mini Shai-Hulud npm supply-chain worm campaign that exfiltrated npm tokens, GitHub PATs/OAuth tokens, AWS credentials, and Vault tokens, impacting developer environments.

@beproduct/nestjs-auth +3 supply-chain npm credential-theft exfiltration worm
2r 4t 6i