Cloud Threat Highlights: H1 2026
Summary
In the first half of 2026, cloud security threats increased dramatically, with supply-chain attacks (attacks targeting the software development process to compromise many organizations at once) more than doubling and now making up 25% of major incidents. A group called TeamPCP ran a particularly widespread campaign that stole developer credentials from poisoned packages on platforms like npm and PyPI, then used those credentials to break into cloud environments and steal more secrets, creating a chain reaction of compromises affecting thousands of organizations.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.wiz.io/blog/cloud-threat-highlights-h1-2026
First tracked: August 6, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 85%