Why TeamPCP’s Russian Roulette Module is a False Flag

Prologue After Antiy released “Sandstorm-style Poisoning Targeting Developer Tool Supply Chains– Sample, Technical and Tactical Analysis of TeamPCP Organizations (Part 1)”, some experts in the industry communicated with us, and the other party paid special attention to a spec……

Continue Reading

Sandstorm-style Poisoning Targeting Developer Tool Supply Chains——Sample, Technical, and Tactical Analysis of TeamPCP Organization (Part 1)

Abstract TeamPCP is an emerging attack organization that has been extremely active in recent years (active at the end of 2025) and has attracted rapid attention. It focuses on the development ecosystem of GitHub Actions, npm, CI/CD Pipeline and cloud development environment, and carries out sy……

Continue Reading

Antiy AVL SDK Anti-Virus Engine Upgrade Announcement (20260523)

Based on the principles of transparency, accessibility, usability, verifiability and perceptibility of security capabilities, Antiy releases weekly updates of the AVL SDK anti-virus engine and the full set of capabilities to the public every week. 1.Weekly Update     &……

Continue Reading

The “Three-Body” Balance of Encryption Mechanism, Performance and System Security– A Summary Report on the Threefold “Dirty Family” Vulnerabilities in Linux Kernel

Abstract: During the two-week window from April 29 to May 13, 2026, the Linux kernel continuously disclosed three high-risk local privilege escalation vulnerabilities: Copy Fail (CVE-2026-31431), Dirty Frag (CVE-2026-43284, CVE-2026-43500) and Fragnesia (CVE-2026-46300). Together with the D……

Continue Reading

Antiy AVL SDK Anti-Virus Engine Upgrade Announcement (20260516)

Based on the principles of transparency, accessibility, usability, verifiability and perceptibility of security capabilities, Antiy releases weekly updates of the AVL SDK anti-virus engine and the full set of capabilities to the public every week. 1.Weekly Update     &……

Continue Reading

“Fragment Amnesia”—How the Dirty Frag Patch Gave Rise to the Fragnesia Vulnerability

1. Introduction 1.1 Incident Retrospective: The “Chain of Vulnerabilities” from Dirty Frag to Fragnesia In May 2026, the Linux kernel security community experienced a rare chain of security incidents. On May 4th, Kuan-TingChen submitted a patch based on the shared-frag method to……

Continue Reading

Thinking of “Attack Primitive” Based on Dirty Frag Vulnerability Discovery Process — Re-discussion on Human-machine Division of Vulnerability Discovery and Analysis

The original report is in Chinese, and this version is an AI-translated edition. Download PDF View in Chinese Thinking of “Attack Primitive” Based on Dirty Frag Vulnerability Discovery Process — Re-discussion on Human-machine Division of Vulnerability Discovery a……

Continue Reading

Antiy AVL SDK Anti-Virus Engine Upgrade Announcement (20260509)

Based on the principles of transparency, accessibility, usability, verifiability and perceptibility of security capabilities, Antiy releases weekly updates of the AVL SDK anti-virus engine and the full set of capabilities to the public every week. 1.Weekly Update     &……

Continue Reading

A New Paradigm for Vulnerability Analysis in Human-AI Collaboration: An Analysis of the “Copy Fail” Discovery Process

The original report is in Chinese, and this version is an AI-translated edition. Download PDF View in Chinese AI-powered vulnerability discovery and automated attacks are undoubtedly key focuses for 2026. Previously, Anthropic’s batch of discoveries of a FreeBSD remote root ……

Continue Reading

Antiy AVL SDK Anti-Virus Engine Upgrade Announcement (20260502)

Based on the principles of transparency, accessibility, usability, verifiability and perceptibility of security capabilities, Antiy releases weekly updates of the AVL SDK anti-virus engine and the full set of capabilities to the public every week. 1.Weekly Update                            ……

Continue Reading

CVE-2026-31431 (Copy Fail) Vulnerability FAQ (Part 2) — Vulnerability Mechanism, Historical Background, and Strategic Implications

The original report is in Chinese, and this version is an AI-translated edition. Download PDF View in Chinese Disclaimer: This article is based on a FAQ list compiled by Antiy CERT engineers, completed collaboratively by multiple AI agents, with some content manually revised and r……

Continue Reading