Two arrested in TeamPCP supply chain attacks that compromised open-source security tools and cascaded into OpenAI, GitHub, and Meta breaches

Two arrested in TeamPCP supply chain attacks that compromised open-source security tools and cascaded into OpenAI, GitHub, and Meta breaches

Australian Federal Police and the FBI arrested two men in Perth over TeamPCP, a group that compromised open-source tools including the Trivy vulnerability scanner, weaponizing trusted security tooling to breach over 1,000 organizations and steal 500,000-plus credentials. Downstream victims included OpenAI, GitHub, and Meta's AI partner Mercor.

Published

Read at another depth