Security News

Cybersecurity news aggregator

HIGH Attacks Ars Technica Security

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

The article details the arrest of two alleged members of the TeamPCP hacking group, which has conducted a nine-month campaign of supply chain attacks. The group's primary method was infecting open-source software packages with self-propagating malware that targeted and spread through organizations' CI/CD pipelines, ultimately compromising over 1,000 entities. The article does not provide technical details on specific vulnerabilities, CVSS scores, affected software versions, patches, or workarounds.
Read Full Article →

Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group of hackers that, over nine months, has carried out a relentless series of supply chain attacks that infected more than 1,000 organizations worldwide. In a statement , the Australian Federal Police said the two men were arrested and charged with 14 offenses. The statement said the men were members of TeamPCP, which by the authorities’ count, compromised more than 1,000 organizations worldwide. The statement didn’t identify the men, except to say they lived in the Western Australian towns of Cottesloe and Mandurah. KrebsOnSecurity, citing a lengthy investigation, provided what it reports to be both defendants' names , along with an extensive background of their lives and the mistakes that led to their downfall. The hacks that keep on hacking TeamPCP has vexed law enforcement officials and security personnel around the world since it emerged in December. The group is best known for a sustained series of supply chain attacks that laced open source software with malware that self-propagated from one package to another. The viral infections worked by targeting organizations’ CI/CD pipelines, which are used to rapidly develop, update, and deploy software. Read full article Comments

Share this article