July 5, 2026
- ChocoPoC RAT spreads via trojanized GitHub PoC repos, targeting researchers testing exploits. The malicious code isn't in the exploit itself — the repos pull poisoned Python packages from PyPI that later fetch the RAT, which can run commands and steal browser data, files, and shell history. BleepingComputer
· Threat Activity
in Confidential Computing's Root of Trust May Be Unfixable
July 4, 2026
- ChocoPoC RAT targets exploit researchers via trojanized GitHub PoCs. The RAT isn't in the exploit code — the repos pull malicious PyPI packages that fetch the payload, which can run commands and steal browser data, files, and shell history. BleepingComputer
· Threat Intelligence
in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat
July 3, 2026
- ChocoPoC, a new Python RAT, is being pushed through trojanized GitHub PoC repos claiming to exploit hot CVEs — the malice sits in pulled PyPI dependencies, not the exploit code — stealing browser data, files, and shell history from the researchers running them. BleepingComputer, The Hacker News.
· Threat Activity
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire
July 2, 2026
- ChocoPoC, a Python RAT, is being distributed inside weaponized proof-of-concept exploits on GitHub in a campaign aimed at security researchers — a reminder to detonate untrusted PoCs only in isolation. BleepingComputer.
· Threat Activity
in Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US