View all sources for this day →

The Signal

The priority items require different readings: an alleged campaign, a confirmed breach, and a historical risk assessment. The AI survey adds an organizational-control lens rather than another compromise report. [1][2][3][4]

Must Know

Supply Chain · Arstechnica Security

Supply Chain · Incident

What happened

TeamPCP allegedly tainted hundreds of open-source programs with malware, stole developer accounts, used a self-spreading worm, and ultimately breached more than a thousand companies. [1]

Google Threat Intelligence says an undercover researcher infiltrated TeamPCP during its campaign, enabling Google to monitor the activity, warn breach targets, and help disrupt attempted exploitation. [1]

Why it matters

According to Larsen, Google traced operational-security mistakes allegedly made by one accused TeamPCP leader and passed identifying details to law enforcement. [1]

The combination of supply-chain distribution and account theft makes intervention before further malicious publication and victim notification especially consequential, while preserving the distinction between allegations and established responsibility. [1]

Cloud · Helpnetsecurity

Cloud · Incident

What happened

Helpfeel confirmed a data breach affecting its Gyazo screenshot-sharing platform; attackers exploited a vulnerability in an image-upload server and stole approximately 23.62 million user records plus metadata tied to hundreds of millions of images. [2]

Gyazo is a cloud-based screenshot and screen-recording service that automatically uploads captures and generates shareable links. [2]

Why it matters

The service’s automatic upload-and-link design means incident scoping should distinguish stolen user records from metadata associated with images. [2]

Cloud · Securityaffairs

Cloud · Security

What happened

A 2017 UK assessment reviewed 15 risks of moving police data—including criminal records, victim statements, police-force information and some potentially secret-level material—to Microsoft Azure. [3]

The assessment identified Microsoft software vulnerabilities that could eventually be exploited by cybercriminals or other attackers, and specifically identified possible access by US government insiders. [3]

Why it matters

Five specialists who reviewed the assessment for The Guardian said the identified risks remain relevant today; the article also states that every UK police force now uses Microsoft’s cloud wholly or partly. [3]

The item describes an assessment of possible exposure, not a report of confirmed compromise in the assessed environment. [3]

AI & Agents · Helpnetsecurity

AI & Agents · Policy

What happened

A Sapio Research survey of 1,000 senior IT, operations, and transformation leaders found that 40% of large companies had an AI-related compliance or governance issue in the preceding 12 months. [4]

The surveyed leaders attributed 84% of the incidents to process-related problems. [4]

Why it matters

The researchers linked the exposure to workflows designed around human handling, including approvals, handoffs, and manual exceptions. [4]

Also Worth Knowing

Incident · Securityaffairs

Incident · Research

What happened

Blackpoint identified ChainScript as a previously undocumented Node.js remote access trojan distributed through ClickFix activity and disguised as software installers, including Spotify, Zoom Workplace, and Microsoft Teams versions. [5]

User-level execution means this activity can be relevant even where administrative access has not been granted. [5]

Incident · Helpnetsecurity

Supply Chain · Incident

What happened

Attackers are targeting Rust Project members and maintainers of widely used Rust crates to compromise their devices and accounts and ultimately publish malware. [6]

The lure links a social invitation to upstream accounts whose compromise could enable malicious publication. [6]

AI & Agents · Helpnetsecurity

Security

What happened

The FBI warns that scammers impersonate police officers and federal agents, threaten victims with arrest, and demand payment. [7]

The coercive pretext is designed to turn an impersonation claim into a payment demand. [7]

Sources (7)
  1. [1] An undercover Google analyst infiltrated a notorious supply-chain hacking gang

    arstechnica security · September 20, 2026

  2. [2] Hackers exploit Gyazo server flaw to steal 23.6 million user records

    helpnetsecurity · September 21, 2026

  3. [3] UK Police Data Faces Long-Standing Microsoft Cloud Security Concerns

    securityaffairs · September 21, 2026

  4. [4] AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

    helpnetsecurity · September 21, 2026

  5. [5] ChainScript: the RAT that hides its command server inside a blockchain contract

    securityaffairs · September 21, 2026

  6. [6] North Korea’s job interview scam runs both ways

    helpnetsecurity · September 21, 2026

  7. [7] Scammers impersonate cops, use arrest threats to extort victims

    helpnetsecurity · September 21, 2026