daily cyber × ai intelligence

index

tagged

[teampcp]

7 editions · 7 items

September 9, 2026

  • A financially motivated group ran a large-scale credential-harvesting campaign end to end in under six hours using an autonomous multi-agent framework, according to Google Threat Intelligence Group. GTIG also reports actors in healthcare, government and media stealing proprietary-model API credentials and co-opting victim cloud environments to run their own AI workloads. It attributes a run of PyPI, npm and Docker Hub supply-chain compromises to TeamPCP (aka Altered Spider, UNC6780), which deploys the SANDCLOCK stealer — a Python, Linux- and Kubernetes-aware component of what has been publicly called CanisterWorm, with container-escape functionality — and its successor DUSTMAKER, both aimed at developer and AI coding-assistant credentials (The Hacker News, BleepingComputer). · AI & Model Security

in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android

September 1, 2026

  • Qilin briefly published 6.3 GB of data stolen from the US ATF after a 72-hour countdown expired, reportedly including criminal investigation target names, phone numbers, IP addresses, iCloud data and Cellebrite phone dumps, per Gun Owners of America (earlier coverage). · Threat Activity
  • ZeroTrace published a deep dive on how the Chinese state-linked QTFY botnet was organised and run, including espionage traffic routed through a paid commercial proxy subscription (Catalin Cimpanu) (earlier coverage). Flare separately documented how its researchers de-anonymised the TeamPCP members arrested in Australia last week (Catalin Cimpanu). · Threat Activity

in Attackers Are Living in the Management Plane

August 28, 2026

  • Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court facing 14 combined offences over alleged membership in TeamPCP, the group behind the March 2026 compromises of open-source scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM (The Hacker News). The AFP describes a syndicate that "created malicious open-source software to rob thousands of global businesses"; Krebs has the deepest account of the multi-year package-registry campaign and the US–Australian cooperation behind the arrests (KrebsOnSecurity). · Supply Chain & Takedowns

in Australia Charges Two Over the TeamPCP Supply-Chain Spree

August 15, 2026

A Heavy Day for Exploit Research and In-the-Wild N-Days

Citrix NetScaler CVE-2026-8452, VMware vCenter critical auth-bypass and VMXNET3 flaws, and SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) are all under active exploitation in enterprise environments. GeoServer, Exchange Server, PostGIS, and Ruby 4.0 join a heavy wave of zero-day and n-day research, while autonomous AI agents weaponized against critical infrastructure and a guardrail bypass in production Claude deployments expose new attack surfaces. Clop ransomware targeted Shell and Philips likely via PTC Windchill, and ShinyHunters breached RingCentral for 1.6 million accounts; Anthropic's new watermark-detection API for Claude faced immediate circumvention attempts.