Researchers have linked the threat actor known as TeamPCP to cybercriminal activities dating back to 2020, predating their known supply chain attacks. The group has a history of exploiting vulnerabilities in internet-facing infrastructure, including Redis servers and AI platforms, for various malicious purposes like cryptocurrency mining and botnet creation. Their operations have evolved to include sophisticated supply chain compromises, weaponizing open-source libraries and leveraging cloud infrastructure for widespread attacks.

Reports indicate that the threat actor group identified as TeamPCP has been active since at least 2020, engaging in cybercriminal operations that predate their more widely recognized supply chain campaigns. Early activities attributed to the group reportedly involved exploiting vulnerabilities in internet-facing infrastructure, specifically mentioning Redis servers and AI platforms. These initial compromises were reportedly leveraged for purposes such as cryptocurrency mining and the establishment of botnets.
The technical mechanism behind these early attacks typically involves the exploitation of known or unknown vulnerabilities in publicly accessible services. For instance, Redis servers, when misconfigured or unpatched, can be susceptible to remote code execution or unauthorized access, allowing attackers to gain control over the underlying system. Similarly, AI platforms, depending on their architecture and exposed services, may present attack surfaces that can be exploited to achieve similar objectives. Once access is gained, threat actors often deploy malicious payloads designed to consume system resources for cryptocurrency mining or to enlist the compromised machine into a botnet for distributed denial-of-service attacks or other malicious activities.
The scope of such attacks can vary significantly. Exploiting internet-facing infrastructure often allows for opportunistic scanning and compromise of a broad range of vulnerable systems globally. The impact on affected organizations can range from degraded performance due to resource consumption by cryptocurrency miners to more severe consequences like data exfiltration or further network penetration if the initial compromise is used as a pivot point.
Mitigation for these types of attacks generally involves a multi-faceted approach. Organizations are typically advised to ensure all internet-facing services, including Redis servers and AI platforms, are regularly patched and updated to address known vulnerabilities. Implementing strong access controls, such as multi-factor authentication and restricting administrative interfaces to trusted networks, is also crucial. Network segmentation can help limit the lateral movement of attackers if a compromise occurs, and robust monitoring solutions can detect unusual activity indicative of cryptocurrency mining or botnet enrollment.
More recently, TeamPCP's operations are reported to have evolved to include more sophisticated supply chain compromises. This typically involves weaponizing open-source libraries, a technique where malicious code is injected into widely used software components. When developers incorporate these compromised libraries into their applications, the malicious code is inadvertently distributed to end-users or other systems within the supply chain.
Leveraging cloud infrastructure for widespread attacks is another reported evolution in their tactics. Threat actors often utilize cloud services for command and control, hosting malicious payloads, or orchestrating attacks due to the scalability, anonymity, and global reach these platforms offer. This can make attribution and disruption more challenging for defenders.
The reported activities of TeamPCP highlight a common trajectory for sophisticated cybercriminal groups, moving from opportunistic exploitation of known vulnerabilities to more targeted and impactful supply chain attacks. This evolution underscores the persistent need for organizations to maintain comprehensive security postures, encompassing not only direct infrastructure protection but also vigilance regarding the security of their software supply chains and the services they consume from cloud providers.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed