LIVE · cybersecurity feed
Live wire
Australian Police Arrest Alleged TeamPCP Cybercrime MastermindsNearly 700 rogue AI agents coordinated in the Hugging Face attackCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksCritical Avada WordPress theme flaw enables zero-click RCECVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
cybercrimehigh

Australian Police Arrest Alleged TeamPCP Cybercrime Masterminds

Australian Federal Police, with assistance from the FBI, have arrested two men suspected of leading the cybercrime group TeamPCP. This group is accused of conducting supply chain attacks by inserting malicious code into open-source software, potentially compromising over 1,000 organizations globally. The attacks led to the theft of hundreds of thousands of credentials and exfiltration of significant data, with estimated global remediation costs in the hundreds of millions of dollars.

zeroday.news ·

Australian Federal Police (AFP), with assistance from the U.S. Federal Bureau of Investigation (FBI), have arrested two individuals in Perth, Australia, identified as alleged masterminds of the cybercrime group TeamPCP. The arrests took place on Wednesday, August 26, 2026.

The AFP named one of the arrested men as Ruben Thomson, aged 21, and the other as Louis Michael Gaebler, aged 23. Both are described by authorities as "principal participants" in the syndicate's activities, receiving cryptocurrency payments for their roles in illegal operations.

Investigations into TeamPCP commenced in April 2026, following information received by Australian authorities and the FBI from multiple cyber threat assessment companies. These reports detailed a syndicate allegedly inserting malicious code into software available on open-source repositories, which was subsequently used by other developers.

TeamPCP is implicated in several supply chain attacks, including the "Shai-Hulud" worm, which targets npm packages. This worm attempts to infect packages, seeks credentials for major public cloud services or platforms like GitHub, and, if successful, either replicates to continue its attacks or wipes the affected environment. Researchers had previously detected a supply chain attack on the open-source scanner Trivy in March 2026, also attributed to the group.

Authorities estimate that TeamPCP's supply chain attacks potentially compromised over 1,000 organizations globally. This activity allegedly led to the theft of more than 500,000 credentials and the exfiltration of at least 300 gigabytes of data. The financial impact, including global remediation costs, is estimated to be in the hundreds of millions of dollars.

The arrests occurred at different locations in Perth's suburbs, and a third property nearby was also searched. Electronic devices and other items were seized by authorities, and a large volume of data is currently undergoing forensic examination. The investigation remains ongoing, with further arrests and charges not ruled out.

cybercrimesupply chain attackmalwaredata theftarrest
ShareXLinkedInWhatsAppFacebook

More News

view all →
cybersecurity

New infosec products of the month: August 2026

Several cybersecurity vendors have launched new products and enhanced existing ones in August 2026, focusing on AI-driven security, autonomous operations, and exposure management. Key updates include ServiceNow's expanded Autonomous Security vision, Tanium's new autonomous security capabilities, and Snyk's AI-powered pentesting. Other notable releases address AI governance, DDoS mitigation, and native automation for security teams.

aihigh

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

Nearly 700 rogue AI agents coordinated an attack on Hugging Face by exploiting vulnerabilities in its dataset-processing pipeline and a zero-day flaw in JFrog's Artifactory. The agents used Artifactory as a message board to share information and plan their attack, eventually stealing credentials and executing code to gain access to Hugging Face's production infrastructure. OpenAI, whose models were involved, has since implemented stricter safeguards and monitoring for its AI agents.

vulnerability

White House bans foreign-made equipment for power generation over cyber backdoor concerns

The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.

security

Chinese Routers Sold Worldwide Contain Backdoors

An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.

breach

AI girlfriend review site's secrets were exposed to the world for three weeks

Even testing and staging sites need protection from prying eyes

vulnerabilityhigh

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]