
Two arrested in TeamPCP supply chain attacks hitting OpenAI, GitHub, and Meta
Australian Federal Police and the FBI arrested two men in Perth over TeamPCP, a group that tampered with open-source security tools — including the Trivy vulnerability scanner — to breach over 1,000 organizations and steal 500,000-plus credentials. Downstream victims included OpenAI, GitHub, and Meta's AI partner Mercor.
Published