China-backed APT exploits VMware vCentre, LiteLLM supply chain attack hits 2,500 pipelines, and Azure Entra ID targeted with stolen credentials.


Three stories this week that cut across infrastructure, developer tooling and identity security: a China-backed APT using ransomware as cover for a backdoor operation, a poisoned dependency cascading through thousands of build pipelines, and a ransomware group harvesting Azure credentials to fuel phishing campaigns.
A China-backed APT has been actively exploiting a critical vulnerability in VMware vCentre, scoring 9.8 on the CVSS scale. The vulnerability allows directory traversal and privilege escalation, giving attackers significant reach once inside.
What makes this attack unusual is the sequence. The group installed a persistent backdoor first, and only then deployed ransomware. That is not typical ransomware behaviour. It strongly suggests the primary objective was data collection, with the ransomware deployed as a distraction to obscure the real intent and complicate forensic investigation.
What to do:
Patch vCentre to the latest version immediately if you have not already done so. More importantly, do not assume patching closes the issue. If this APT was active in your environment before you patched, a backdoor may already be present. Review logs for signs of lateral movement or unusual outbound connections and investigate before declaring the all clear.
A threat actor identified as Team PCP poisoned a Trivy dependency within LiteLLM, triggering a cascading supply chain attack that reached over 2,500 organisation build pipelines. CI/CD pipelines are high-value targets precisely because they carry privileged access to a large number of downstream systems, and they are frequently under-monitored relative to that access level.
This is another example of the risk posed by implicit trust in third-party dependencies. One compromised package, deployed quietly, can propagate through an entire software delivery chain before anyone notices.
What to do:
Update LiteLLM and Trivy to the latest versions immediately. Rotate all pipeline secrets currently in use. Pin versions across all dependencies so that future updates require a deliberate action rather than happening automatically. Treat your CI/CD pipeline with the same security rigour you apply to production systems, because the access it holds warrants it.
A ransomware group has been targeting Azure Active Directory and Entra ID using stolen credentials to log in and exfiltrate user data at scale. The data being taken includes names, email addresses and physical addresses, the kind of information that on its own looks low value but in practice becomes the raw material for highly convincing phishing campaigns.
The risk here is downstream. An attacker who knows the names of your colleagues, your boss and your suppliers can craft emails that are difficult to distinguish from legitimate internal communication. The kind that reference a conversation that apparently happened yesterday, or ask you to authorise an invoice on behalf of someone you know.
What to do:
Enable MFA on every Azure and Entra ID account in your organisation. Administrator accounts in particular should have MFA enforced without exceptions. Stolen credentials alone should not be enough to access your environment.
We protect your on-premise/cloud/OT environments - 24x7x365