GKRootWire
AI Jensen Huang Says Nvidia Hit AGI, Then Says the Term Is MeaninglessGadgets Sony's New Bravia 6 OLED Targets the Midrange TV FightSecurity Flock Safety Cameras Face Growing Wave of Vandalism as Public Pushback MountsSecurity Report: Nearly 700 AI Agents Coordinated to Compromise Hugging FaceSecurity PaperCut Warns of Zero-Day Flaw Under Active Attack in NG, MF SoftwareSecurity Manchester Airports Group Confirms Hackers Stole Traveler DataAI Jensen Huang Says Nvidia Hit AGI, Then Says the Term Is MeaninglessGadgets Sony's New Bravia 6 OLED Targets the Midrange TV FightSecurity Flock Safety Cameras Face Growing Wave of Vandalism as Public Pushback MountsSecurity Report: Nearly 700 AI Agents Coordinated to Compromise Hugging FaceSecurity PaperCut Warns of Zero-Day Flaw Under Active Attack in NG, MF SoftwareSecurity Manchester Airports Group Confirms Hackers Stole Traveler Data
Security

Australia Arrests Alleged Members of TeamPCP Hacking Group

Two young men face charges over a series of developer supply-chain attacks tied to the group.

Australian police have arrested and charged two young men accused of belonging to TeamPCP, a hacking group linked to multiple supply-chain attacks targeting software developers. Investigators allege the group compromised developer tools, packages, or accounts to slip malicious code into projects that would later spread to unsuspecting downstream users.

Details on the specific packages or platforms affected are still emerging, but the arrests suggest law enforcement had been tracking the group's activity for some time before making a move. Supply-chain attacks like these have become a favored tactic for threat actors because a single compromised package can quietly infect thousands of applications and organizations before anyone notices.

The case adds to a growing list of international law enforcement actions against groups exploiting the open-source and developer tooling ecosystem.

Why it matters: Developer supply-chain attacks are especially dangerous because they exploit trust relationships that most security tooling doesn't scrutinize closely, letting malicious code ride along into production systems. Arrests like this signal that authorities are increasingly prioritizing these cases, but they also underscore how much damage a small group can do before getting caught.

Sources: BleepingComputer