FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
2026-07-04T08:51:43Z•290b450204e1d5aef6b3f87b3620c5c4d1b9f61f8f78fbb981f348cb820c6559
adobeai-driven-ransomwarecisacloud-credentialscoldfusion','campaign-classic'credential-theftdeveloper-toolsdkimdmarcemail-securityfortibleedfortigateknown-exploited-vulnerabilitymalwaremta-stsnetnutpegasusransomwareresidential-proxysharepointsoftware-supply-chainspfspywaresupply-chainvulnerability
What happened
Feed of security incidents and advisories: the FBI FLASH names TeamPCP for poisoning trusted developer/security tools to harvest cloud credentials, distribute malware via updates, and extort victims; Citizen Lab documents Pegasus spyware used against an MEP; Sysdig describes JADEPUFFER, an end-to-end LLM-driven ransomware operation; a Vercel shadow‑AI supply‑chain breach shows risks from unvetted AI tools; Google/FBI disrupted the NetNut malicious residential proxy network; research finds government and healthcare sectors lagging on SPF/DMARC/DKIM/MTA‑STS protections; the EU upholds a €4.1B罚款/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 290b450204e1d5aef6b3f87b3620c5c4d1b9f61f8f78fbb981f348cb820c6559
- Enrichment time
- 2026-07-04T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.