View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Australia arrests two TeamPCP members over supply-chain attacks

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Australia arrests two alleged TeamPCP members over global supply-chain attacks
    Australian authorities arrested two alleged TeamPCP members over global supply-chain attacks.
    • Open-source developers and organizations across government, academia, and the private sector were affected.
    • TeamPCP allegedly compromised Trivy, LiteLLM, Telnyx, KICS, TanStack, and other packages and platforms.
    • The campaign potentially breached more than 1,000 organizations, stealing over 500,000 credentials and 300 GB of data.
    • Attackers injected malicious code into trusted repositories that developers unknowingly incorporated into their systems.
    • The Mini Shai-Hulud worm stole credentials and authentication tokens, then self-propagated across package registries and CI/CD environments.
      ๐Ÿ“Ž Coverage: techcrunch.com ยท ๐Ÿ‘ via Risky Business News

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for TranslatePress <=3.3.3 Exposes WordPress Sites to Unauthenticated Stored XSS โ€” wordfence.com

๐Ÿ”“ CVEs & KEV

  • CVE-2026-18983 โ€” CVSS 7.5 โ€” One User Avatar | User Profile Picture through 2.5.4 - Authenticated (Subscriber+)...

  • CVE-2026-18324 โ€” CVSS 7.2 โ€” Forminator Forms through 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting vi...

  • CVE-2026-18978 โ€” CVSS 7.2 โ€” LiteSpeed Cache through 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Co...

  • CVE-2026-77365 โ€” CVSS 7.2 โ€” Optimole through 4.2.10 - Unauthenticated Stored Cross-Site Scripting via 'a' (abo...

  • CVE-2026-16759 โ€” CVSS 6.5 โ€” Tutor LMS through 4.0.5 - Unauthenticated Remote Code Execution via 'template' and...

  • CVE-2026-16654 โ€” CVSS 6.4 โ€” Avada (Fusion) Builder through 3.15.6 - Authenticated (Contributor+) Stored Cross-...

  • CVE-2026-3129 โ€” CVSS 6.4 โ€” LiteSpeed Cache through 7.7 - Authenticated (Author+) Stored Cross-Site Scripting ...

  • CVE-2026-82081 โ€” CVSS 6.4 โ€” wallabag 2 through 2.6.14 allows SSRF because a crafted title or content fiel...

  • CVE-2026-15798 โ€” CVSS 6.4 โ€” Smart Slider 3 through 3.5.1.38 - Authenticated (Contributor+) Stored Cross-S...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check