View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Australia Charges Two Alleged TeamPCP Hackers Over Supply-Chain

🚨 ACTIVE EXPLOITATION

  • UPDATE: Australia Charges Two Alleged TeamPCP Hackers Over Supply-Chain Attacks
    Australia has charged two alleged TeamPCP members over global software supply-chain attacks.
    • Government, academic, and private-sector organizations worldwide were affected.
    • Trivy, LiteLLM, Telnyx, SAP, and TanStack packages were among the targets.
    • Malicious code was injected into open-source repositories and then incorporated by developers.
    • The activity potentially compromised more than 1,000 organizations, stealing 500,000 credentials and at least 300GB of data.
    • Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, face 14 combined charges after arrests in Western Australia.
      πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer, SecurityWeek (+2)

πŸ’₯ BREACHES & INCIDENTS

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Russian-linked hackers target senior EU officials on Signal and WhatsApp
    Russian-linked hackers targeted senior EU officials through Signal and WhatsApp phishing.

    • Senior EU officials using Signal and WhatsApp were targeted, including political, military and diplomatic figures.
    • Attackers sought to hijack messaging accounts and read private and group conversations.
    • Personalized spearphishing messages used malicious links, files and social engineering.
    • Fake Signal support chatbots requested security codes that could link attacker-controlled devices to accounts.
      πŸ“„ Source: politico.eu Β· πŸ“Ž Coverage: darkreading.com Β· πŸ‘ via Dark Reading
  • Russian-Speaking Hackers Used Cursor AI in Intrusions Against Seven Companies
    Russian-speaking hackers used Cursor AI to accelerate intrusions against at least seven companies.

    • Victims included companies in chemicals, manufacturing, logistics, pharmaceuticals, and title insurance.
    • Aur0ra ransomware operators sought administrator accounts, credentials, and access to corporate networks.
    • Hackers used Cursor’s AI agent to plan attacks and generate technical guidance.
    • They bypassed Cursor’s refusals by claiming the activity was a security simulation.
    • The campaign was exposed after researchers found an unauthenticated server containing 28 Cursor chat sessions.
      πŸ“Ž Coverage: reuters.com Β· πŸ‘ via r/cybersecurity

πŸ”“ CVEs & KEV

  • CVE-2026-77554 β€” CVSS 10.0 β€” A malicious actor with access to the network could exploit an Improper Input ...

  • CVE-2026-77550 β€” CVSS 10.0 β€” A malicious actor with access to the network could exploit an Improper Neutra...

  • CVE-2026-77553 β€” CVSS 9.9 β€” A malicious actor with access to the network and low privileges could exploit...

  • CVE-2026-77548 β€” CVSS 9.9 β€” A malicious actor with access to the network and low privileges could exploit...

  • CVE-2026-77547 β€” CVSS 9.9 β€” A malicious actor with access to the network and low privileges could exploit...

  • CVE-2026-77546 β€” CVSS 9.9 β€” A malicious actor with access to the network and low privileges could exploit...

  • CVE-2026-18080 β€” CVSS 9.8 β€” ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce through 1.17.8 - Un...

  • CVE-2026-77557 β€” CVSS 9.8 β€” A malicious actor with access to the network could exploit an Improper Access...

  • CVE-2026-77552 β€” CVSS 9.8 β€” A malicious actor with access to the network could exploit an Improper Input ...

  • CVE-2026-77532 β€” CVSS 9.6 β€” A malicious actor with access to an adjacent network could exploit a Buffer O...

  • CVE-2026-80204 β€” CVSS 9.3 β€” Grav before 1.0.18 Authentication Bypass via Scoped API KeyThe Grav API plugi...

  • CVE-2026-80203 β€” CVSS 9.3 β€” Grav before 1.0.18 Authentication Bypass via Scoped API KeyThe getgrav/grav-p...

  • CVE-2026-77551 β€” CVSS 9.0 β€” A malicious actor with access to the network and under certain conditions cou...

  • CVE-2026-77549 β€” CVSS 9.0 β€” A malicious actor with access to the network and under certain conditions cou...

  • CVE-2026-81579 β€” CVSS 8.8 β€” WibuKey for Windows: Kernel Driver Privilege Escalation

  • CVE-2026-81662 β€” CVSS 8.6 β€” Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbit...

  • CVE-2026-15985 β€” CVSS 8.1 β€” Classified Listing - Mobile Number Verification through 1.6.0 - Unauthenticated Au...

  • CVE-2026-81743 β€” CVSS 7.5 β€” Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template I...

  • CVE-2026-81659 β€” CVSS 7.1 β€” Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX...

  • CVE-2026-81658 β€” CVSS 6.5 β€” Foreman: cross-tenant disclosure of template revisions via unauthorized audit...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check