GKRootWire
AI Jensen Huang Says Nvidia Hit AGI, Then Says the Term Is MeaninglessGadgets Sony's New Bravia 6 OLED Targets the Midrange TV FightSecurity Flock Safety Cameras Face Growing Wave of Vandalism as Public Pushback MountsSecurity Report: Nearly 700 AI Agents Coordinated to Compromise Hugging FaceSecurity PaperCut Warns of Zero-Day Flaw Under Active Attack in NG, MF SoftwareSecurity Manchester Airports Group Confirms Hackers Stole Traveler DataAI Jensen Huang Says Nvidia Hit AGI, Then Says the Term Is MeaninglessGadgets Sony's New Bravia 6 OLED Targets the Midrange TV FightSecurity Flock Safety Cameras Face Growing Wave of Vandalism as Public Pushback MountsSecurity Report: Nearly 700 AI Agents Coordinated to Compromise Hugging FaceSecurity PaperCut Warns of Zero-Day Flaw Under Active Attack in NG, MF SoftwareSecurity Manchester Airports Group Confirms Hackers Stole Traveler Data
Security

Australian Police Arrest Two Alleged Members of TeamPCP Supply Chain Hacking Group

The pair, aged 21 and 23, are accused of running one of the longest-running open-source supply chain extortion campaigns on record.

The Australian Federal Police announced the arrest of two men from Western Australia suspected of belonging to TeamPCP, a group accused of poisoning open-source software packages to infiltrate thousands of businesses worldwide. Investigators describe the operation as unusually long-lived, with the group allegedly publishing malicious packages and using them as footholds for data theft and extortion over an extended period.

KrebsOnSecurity had reportedly identified the 21-year-old suspect months before the arrests and maintained contact with someone claiming to speak for the group, gathering details on how operational mistakes may have exposed its leader. Authorities have not officially named the suspects, but the case highlights how open-source ecosystems remain an attractive target for attackers seeking scale.

Why it matters: Supply chain attacks through open-source packages are hard to detect because victims trust the code they import rather than scrutinizing it like external software. This arrest is a reminder that dependency vetting, package provenance checks, and monitoring for anomalous maintainer behavior are no longer optional for engineering teams.

Sources: Krebs on Security