LIVE · cybersecurity feed
Live wire
threat actorhigh

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

Researchers have linked the threat actor known as TeamPCP to cybercriminal activities dating back to 2020, predating their known supply chain attacks. The group has a history of exploiting vulnerabilities in internet-facing infrastructure, including Redis servers and AI platforms, for various malicious purposes like cryptocurrency mining and botnet creation. Their operations have evolved to include sophisticated supply chain compromises, weaponizing open-source libraries and leveraging cloud infrastructure for widespread attacks.

zeroday.news ·

Reports indicate that the threat actor group identified as TeamPCP has been active since at least 2020, engaging in cybercriminal operations that predate their more widely recognized supply chain campaigns. Early activities attributed to the group reportedly involved exploiting vulnerabilities in internet-facing infrastructure, specifically mentioning Redis servers and AI platforms. These initial compromises were reportedly leveraged for purposes such as cryptocurrency mining and the establishment of botnets.

The technical mechanism behind these early attacks typically involves the exploitation of known or unknown vulnerabilities in publicly accessible services. For instance, Redis servers, when misconfigured or unpatched, can be susceptible to remote code execution or unauthorized access, allowing attackers to gain control over the underlying system. Similarly, AI platforms, depending on their architecture and exposed services, may present attack surfaces that can be exploited to achieve similar objectives. Once access is gained, threat actors often deploy malicious payloads designed to consume system resources for cryptocurrency mining or to enlist the compromised machine into a botnet for distributed denial-of-service attacks or other malicious activities.

The scope of such attacks can vary significantly. Exploiting internet-facing infrastructure often allows for opportunistic scanning and compromise of a broad range of vulnerable systems globally. The impact on affected organizations can range from degraded performance due to resource consumption by cryptocurrency miners to more severe consequences like data exfiltration or further network penetration if the initial compromise is used as a pivot point.

Mitigation for these types of attacks generally involves a multi-faceted approach. Organizations are typically advised to ensure all internet-facing services, including Redis servers and AI platforms, are regularly patched and updated to address known vulnerabilities. Implementing strong access controls, such as multi-factor authentication and restricting administrative interfaces to trusted networks, is also crucial. Network segmentation can help limit the lateral movement of attackers if a compromise occurs, and robust monitoring solutions can detect unusual activity indicative of cryptocurrency mining or botnet enrollment.

More recently, TeamPCP's operations are reported to have evolved to include more sophisticated supply chain compromises. This typically involves weaponizing open-source libraries, a technique where malicious code is injected into widely used software components. When developers incorporate these compromised libraries into their applications, the malicious code is inadvertently distributed to end-users or other systems within the supply chain.

Leveraging cloud infrastructure for widespread attacks is another reported evolution in their tactics. Threat actors often utilize cloud services for command and control, hosting malicious payloads, or orchestrating attacks due to the scalability, anonymity, and global reach these platforms offer. This can make attribution and disruption more challenging for defenders.

The reported activities of TeamPCP highlight a common trajectory for sophisticated cybercriminal groups, moving from opportunistic exploitation of known vulnerabilities to more targeted and impactful supply chain attacks. This evolution underscores the persistent need for organizations to maintain comprehensive security postures, encompassing not only direct infrastructure protection but also vigilance regarding the security of their software supply chains and the services they consume from cloud providers.

threat actorsupply chain attackrediskubernetesmalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]

malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI