❌

Normal view

Using a VM to Contain an AI Agent

4 September 2026 at 18:31

It won’t work:

My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact.

An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.

Leaked Russian Cyber-Operations Training Materials

1 September 2026 at 18:29

This is interesting:

The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.

[…]

The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.

That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.

The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement.

The Bauman material reframes Russia’s cyber capability as an institutional system, not merely a collection of well-known threat groups.

It suggests that Moscow has formalized a recurring pathway from university recruitment to military service, where students receive supervised technical and ideological preparation before entering intelligence, cyber, and security roles.

For defenders, the leak reinforces the need to track Russian operations as a combined threat: espionage, destructive activity, military reconnaissance, technical surveillance, and influence campaigns may draw on related personnel pipelines and overlapping doctrine.

The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.

Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5

21 August 2026 at 19:21

Frontier AI has compressed attack timelines from weeks to minutes.Β 

For defenders to gain the upper hand, they need to fight back at machine speed. That’s why Palo Alto Networks Unit 42 launched Frontier AI Defense, our comprehensive service that pairs advanced frontier AI models with leading threat intelligence to uncover hidden risks, validate real attack paths, and accelerate remediation before adversaries strike.Β 

Today, in a major milestone for organizations to defend themselves against AI-powered attacks, Unit 42 is expanding its Frontier AI Exposure Analysis capabilities with Anthropic’s Claude Mythos 5, giving organizations access to its advanced cyber capabilities.

Unlocking High-Fidelity Security with the Right Models, Harness and Expertise

While incredibly powerful, achieving high-fidelity results with frontier AI requires three things: the right models, an advanced harness, and the expertise to run it. With Unit 42 Frontier AI Exposure Analysis, guided and reviewed by Unit 42 experts, Claude Mythos 5 goes beyond identifying exposures. It tests whether those exposures can actually be exploited, connects weaknesses into attack paths, and helps prioritize the most urgently needed fixes. That answers the questions conventional scanners alone cannot: Is this exploitable? What can an attacker reach from here? And what should we fix first?

Further, our research shows models have different strengths. Unit 42’s multi-model approach applies the model best suited for the task, improving coverage and results while allowing us to continuously incorporate the strongest new capabilities as models advance.Β 

Human expertise remains at the center. Unit 42 combines these models with our offensive security experts, global Palo Alto Networks telemetry, and Unit 42 Threat Intelligence to turn model output into validated attack paths, prioritized remediation, and clear defensive action.

How It Works

Our Frontier AI Defense service uses the most advanced AI models to discover exposures, test whether they are exploitable, validate attack paths and help customers prioritize what to fix first, including:Β 

  • Leading Cyber Models: Advanced AI applied to discovery, testing, and validation.
  • Multi-Model Harness: Dynamic routing for stronger results, wider coverage, and managed costs.
  • Exposure Discovery: Identification of vulnerabilities, misconfigurations, exposed credentials, and unmanaged attack surfaces across apps and networks.
  • Advanced Adversary Simulation: Live exploitability testing and end-to-end attack path validation.
  • Custom Remediation Plans: Prioritized fixes delivered directly into existing IT, development, and security workflows.

Security teams do not need more findings. They need to know which weaknesses lead to a viable attack path. Attackers do not think about applications, identity, cloud, and infrastructure in isolation. They look for ways to move across them to reach their objective.

By putting frontier models to work with Unit 42 experts, we can identify and validate those attack paths before attackers do, and help organizations close them first.

Visit Palo Alto Networks Frontier AI Defense to learn more.

The post Unit 42 Defends Organizations Against Next-Gen Frontier AI Risks with Anthropic’s Mythos 5 appeared first on Palo Alto Networks Blog.

Prisma AIRS - Unified Data Protection for Claude

As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers are accelerating software delivery with Claude Code and business functions are collaborating in Claude.ai, Claude Cowork, and Claude Design, using Anthropic's Claude to fundamentally rewire how they operate and drive complex, autonomous workflows across their most critical tasks.

Broad AI adoption has forced enterprise security into a difficult paradox: secure the business without stalling innovation. Today, security teams must answer three critical questions: How do we prevent sensitive data from leaking into AI models? How do we intercept runtime attacks, like prompt injection, before they execute? And how do we enforce these guardrails consistently across every AI interaction, in real-time?

We are thrilled to announce that Palo Alto Networks Prisma AIRS API now directly integrates with Claude Enterprise via inference hooks.

Key Takeaways:

  • Synchronous Governance at the Speed of AI: Enforce critical runtime policy guardrails instantly before model inference occurs. By evaluating every Claude interaction in real-time, security teams can confidently enable high-speed AI innovation without introducing unacceptable risk or operational bottlenecks.
  • Extending Proven DLP to AI Workflows: Safeguard PII, intellectual property, and proprietary code across all Claude environments (Claude Code, Claude.ai, Claude Cowork) seamlessly. By directly leveraging your organization’s existing enterprise DLP policies, you get consistent, unified data protection without the friction of managing disparate rule sets.
  • Neutralizing AI-Specific Threats Proactively: Deploy enterprise AI with confidence by intercepting malicious activity before it executes. Proactively block sophisticated runtime threats, including prompt injections, jailbreaks, and toxic inputs, enabling your AI workflows to remain secure and your business operations uninterrupted.

How It Works

Setting up zero-trust governance for your Claude Enterprise environment takes just a few clicks:

  • Configure Claude Enterprise: In your Claude Enterprise organization settings, navigate to inference hooks, set the hook endpoint URL to your designated Prisma AIRS webhook URL, and include your custom Prisma AIRS API key in the custom headers (x-pan-token).
  • Activate Cryptographic Verification in Prisma AIRS: Claude generates a unique, one-time signing secret. You simply drop this signing secret into the Prisma AIRS UI.

Prisma AIRS securely stores the signing secret in an encrypted edge Key-Value Map (KVM) to cryptographically verify the authenticity of every incoming request before processing.

Unified Governance Across All Claude Surfaces

Before Claude reads a prompt, Claude POSTs the payload to Prisma AIRS, which evaluates the input against the configured security profile and returns a synchronous allow or deny verdict back to Claude.

Removing the Data Inspection Blind Spot

This Prisma AIRS integration natively leverages the Palo Alto Networks Enterprise DLP engine your organization already runs. Your current policies, custom definitions of "confidential," and compliance dashboards now instantly govern Claude. No redundant rule creation, and no new management overhead. Every prompt is classified in real-time, before anything reaches the model. Data Policy updates reach Claude the moment they reach everything else, and Claude events land in the same dashboards and audit reporting as every other channel. AI stops being the exception to your data protection strategy and becomes just another channel that is covered.

In practice, this helps prevent:

  • Accidental exposure of PII and regulated data: a Social Security number, card number, or patient record pasted into a prompt is detectedΒ  on the spot by advanced RegEx patterns and ML classifiers,Β  with Exact Data Matching (EDM) recognizing your actual customer records. Β  When policy requires, Prisma AIRS enforces a deny policy to help keep Claude usage stays aligned with GDPR, HIPAA, and PCI-DSS requirements.
  • Misuse of credentials in code: Developers working in Claude Code can't inadvertently submit hardcoded API keys, private tokens, or environment credentials into prompt context.
  • Disclosure of confidential business matters. Document classifiers flag prompts touching M&A, legal, or HR material β€” even when they contain no identifier a pattern could match.

AI Safety & Runtime Threat Protection

Simultaneously, Prisma AIRS inspects payloads for operational risks specific to large language models:

  • Prompt Injection & Jailbreak Attacks: Intercepts malicious attempts to manipulate model context or bypass system instructions.
  • Malicious Code & Malicious URLs: Prevents execution or processing of untrusted scripts and risky links embedded within prompts.
  • Toxic Content & Topic Guardrails: Enforces compliance with corporate policies and custom business topics.

If a prompt violates your security policy, Prisma AIRS issues a deny verdict. Claude immediately blocks the prompt, optionally presenting a user-facing explanation while returning a unique audit correlation code to your security telemetry dashboards.

Deploy Claude Without the Risk

The Prisma AIRS integration with Claude transforms security from a deployment bottleneck into a business enabler. You no longer have to choose between the operational control of Palo Alto Networks and the cognitive velocity of Claude.

Choose Your Path Forward:

Β 


Forward-Looking Statements

This blog contains forward-looking statements that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of our products and technologies or future products and technologies. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this blog. We identify certain important risks and uncertainties that could affect our results and performance in our most recent Annual Report on Form 10-K, our most recent Quarterly Report on Form 10-Q, and our other filings with the U.S. Securities and Exchange Commission from time-to-time, each of which are available on our website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov.Β  All forward-looking statements in this blog are based on information available to us as of the date hereof, and we do not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

The post Prisma AIRS - Unified Data Protection for Claude appeared first on Palo Alto Networks Blog.

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

5 September 2026 at 15:00

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.

The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

4 September 2026 at 18:18

Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion.

The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek.

Two Alleged β€˜TeamPCP’ Hackers Arrested in Australia

27 August 2026 at 13:04

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a β€œsophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”

The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.

TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbedΒ Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.

Writing for Wired, journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers.

β€œThe hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May. β€œThe hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.”

TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised β€” directly incentivizing them to target the most popular code libraries.

A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.

β€œTeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote. β€œThe $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as β€˜just like participation trophy,’ adding β€˜if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.”

In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies.

In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub, after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware.

MEET THE CYBERCATS

Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.

β€œIt is not a structured criminal crew with a single operator,” said Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group. β€œIt is a peer community of individually-skilled actors, with one clear center of gravity.”

That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed β€œCybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.

A screenshot of the Matrix chat server β€œCybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.

Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.

The Cybercats administrator listed at the top of the screenshot above β€” β€œBoxturtle” β€” is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, as well as data allegedly taken from Snapchat and SportRadar.

The data leak site for the extortion group or handle β€œxpl0itrs.”

The Cybercats administrator β€œSeesawSec” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec, which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.

The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.

The Cybercats administrator β€œ@pcpcasper” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.

At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.

The Cybercats member roster pictured above also features an administrator with the username β€œT,” which is short for the now-banned Twitter/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia.

By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.

WHO IS THE TEAMPCP LEADER?

The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host, which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars.

DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.

According to the cyber intelligence firm Intel 471, Express registered on Breachforums using the email address shitstickpp@gmail.com. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.

The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram β€” Persy_PCP β€” Β who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. β€œI have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025.

Later that month, Persy_PCP complained, β€œMy whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that β€œthis country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign.

This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, β€œindicating the primary operator was located there during at least some of its attacks.”

BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. β€œMy life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.”

The identity threat protection company SpyCloud finds shitstickpp@gmail.com shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.

KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com, and found one of them β€” 211.27.196.111 β€” for several years was used as a private file server by a family in Perth with the last name of Thomson. Those records show at least three hosts β€” ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) β€” persisted at that address between 2022 and 2025.

Searching on β€œjoshuathomson39” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben, his father Ian, and his mom Cindy.

That Facebook profile also says Josh and his family are originally from Pietermaritzburg, in KwaZulu-Natal, South Africa, but currently living in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.

Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports ruben@thomson.org.au frequently reused the password β€œjoshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including yolosolo17@gmail.com and surfinup8@gmail.com.

According to Intel 471, surfinup8@gmail.com was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.

A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.

SpyCloud reports 10.141.230.15 was used by the email address sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account β€œSheep Stealing” on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen.

Epieos reports that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. β€œHey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography.”

Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.

β€œI’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. β€œI also script in Python mainly for writing social media bots.”

The Upwork profile for Ruben Thomson in Cottesloe, Australia.

Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).

This same sheepstealing email address registered a Twitter/X account in 2026 called β€œGone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.

Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.

The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson.

Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and another entity ironically named OPSEC Express. Recall that Express was BulkDMT’s nickname on Breachforums.

Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.

It’s ironic because OPSEC is short for the term β€œoperational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.

There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne, a popular β€œbug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

The HackerOne profile for β€œRuben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.

INTERVIEW WITH ELLIS

In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].

Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 β€” just before the attacks that compromised LiteLLM β€” and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.

β€œOne year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. β€œI had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.”

Prior to that, Ellis said, he was homeless and hopping between β€œsome very unstable places.”

β€œBlackhatting is fun,” he said. β€œThere are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.”

Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.

β€œI am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. β€œI no longer have to choose between rent and food for that I’m grateful and so are the team members.”

Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested.

β€œIf I’ve already been found out then its out of my control, I’ll make peace with that,” he said. β€œHonestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.”

It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to β€œtrip” with his β€œhomie.”

β€œWhat kind,” @kernelstub inquired.

β€œKetty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. β€œThere’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand.

Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.

Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.

An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.

The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.

β€œThey are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. β€œTheir motivations seem to mix money, disruption, attention, and ideology.”

Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.

β€œYou had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. β€œLLMs have compressed that gap significantly.”

According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.

β€œThey can be noisy, they can make mistakes,” he said. β€œThey can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.”

In a recent blog post, Eriksen called TeamPCP’s Shai-Hulud worm the β€œbest thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards.

In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day β€œcooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.

Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.

β€œThey managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. β€œBy compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.”

Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.

Data Center Physical Security: Mitigating FPV Drone Threats

Blogs

Blog

Data Center Physical Security: Mitigating FPV Drone Threats

In this post, we explore how shifting online sentiment and low-cost First-Person View (FPV) technology are creating an unprecedented airborne threat vector for critical data center infrastructure.

SHARE THIS:
Default Author Image
August 10, 2026

Data centers have become a driving force in the modern digital economyβ€”powering cloud services, global enterprise operations, and the explosive growth of artificial intelligence (AI). However, due to growing negative public discourse, data centers are facing a new physical threat vector: low-cost, payload-capable drones.

According to Flashpoint research, shifting public sentiment surrounding AI development, combined with the extreme accessibility of First-Person View (FPV) drone technology, is creating an unprecedented hybrid threat to physical critical infrastructure.

Here is what you need to know about this emerging threat landscape and what it means for physical security teams protecting critical assets.

Growing Online Sentiment and Anti-AI Hostility

Organizations tasked with protecting critical data infrastructure need to understand that this growing threat is not developing in a vacuum. Across both clearnet and Deep and Dark Web (DDW) forums, online discussions regarding data center expansion have intensified, with a significant portion bordering on hostility. Key drivers of negative sentiment include:

  • Environmental & Local Concerns: Debates over massive energy consumption, water usage, noise, and localized quality-of-life impacts.
  • Backlash against AI: Discontent directed at tech companies driving the rapid deployment of AI infrastructure.
  • Perceived Regulatory Inaction: Frustration among activists who feel local and state governments are failing to halt or regulate new construction.

While much of the current online chatter currently revolves around organized protests and aspirational threats, Flashpoint analysts note a troubling uptick in rhetoric targeting corporate tech executives and data center infrastructure.

The Evolving Data Center Threat Landscape

Data centers across the United States are seeing a rapid increase in physical and operational threats. Vandalism and property destruction have become common topics in illicit online spaces when discussing data centers and their impact on everyday life. Flashpoint research highlights two primary force multipliers driving this threat:

DIY Drones & Low Barriers to Entry

Historically, kinetic airborne strikes required specialized equipment and advanced training. Today, that barrier to entry has virtually collapsed. Rapid improvements in drone manufacturing have made payload-capable aircraft extraordinarily accessible. In today’s market, an individual can purchase an off-the-shelf system or assemble a customized drone for under $1,000 USD.

Inspiration for these tactics is also readily available; widespread footage of FPV drones operating in conflict zones like Ukraine has demonstrated to online audiences how easily and effectively low-cost aircrafts can be weaponized. Threat actors view this as a high-yield investment, especially given the capability to deploy multiple drones in quick succession.

Protests as Cover for Physical Operations

Organized protests to stop data center development remain prevalent, and large crowds can easily overwhelm contracted security personnel, diminishing the effectiveness of a response to an aerial threat. A malicious actor could use a protest at a data center as cover to cause physical damage to the facility while security resources are spread thin. For example, on July 19, 2026, activists threw balloons filled with acetic acid at a data center construction site in Amsterdam. In its aftermath, Flashpoint analysts captured individuals online discussing the use of drones to deliver similar payloads.

Regulatory and Defense Measure Challenges

Current federal regulations limit the ability to effectively deter or stop an incoming drone threat because the US Federal Aviation Administration (FAA) classifies drones as aircraft. Therefore, organizations specializing in the physical security of data centers will likely need to increase their operational capabilities and advise companies on potential hardening to deter attacks.

Traditional foot patrols and monitoring perimeter access control points will be insufficient in mitigating overhead threats. The majority of data centers are currently not equipped with the specialized Counter-Unmanned Aircraft Systems (C-UAS) equipment, specialized training, or legal authorization needed to respond effectively to airborne incursions.

Protect Critical Infrastructure Using Flashpoint

Defending against aerial incursions requires moving from reactive security to proactive, intelligence-led physical protection. Physical security teams cannot afford to rely solely on ground-level surveillance when threat actors are leveraging open-source hardware and coordinating online.

Flashpoint Physical Security Intelligence (PSI) equips security teams and executive protection units with real-time visibility into emerging physical threats before they reach your perimeter:

  • Early Warning Indicator Tracking: Monitor chatter across mainstream social platforms, fringe networks, and illicit DDW forums to identify probe attempts or the targeting of specific data center facilities and executives.
  • Geospatial Threat Mapping: Overlay real-time intelligence onto physical assets using customizable geofencing to detect active incidents, protest activity, and drone-related discussions near sensitive sites.
  • Actionable Counter-UAS Insights: Receive finished intelligence and analyst support to benchmark threat actor TTPs (Tactics, Techniques, and Procedures), enabling your organization to harden physical structures and justify operational investments.

To learn more about how Flashpoint helps safeguard critical infrastructure, executives, and high-value assets against physical and cyber threats, request a demo today.

See Flashpoint in Action

The post Data Center Physical Security: Mitigating FPV Drone Threats appeared first on Flashpoint.

Beyond Cyber: How CTI Teams Are Solving Converged Threat Use Cases

Blogs

Blog

Beyond Cyber: How CTI Teams Are Solving Converged Threat Use Cases

In this post we explain how cyber threat intelligence teams are being expected to take on physical risk, how tradecraft overlaps, and how Flashpoint bridges the gap.

SHARE THIS:
Default Author Image
August 6, 2026

For years, the mandate of Cyber Threat Intelligence (CTI) teams has been narrow and well understood: track cyber threat actors, monitor for indicators of compromise, and defend the network. However, that mandate is widening. In today’s interconnected threat landscape, more CTI teams are being tasked with physical security, geopolitical and protective intelligence. Whether that is monitoring and securing executive travel, a facility, or an event, data shows that this new informal expansion is becoming an industry-wide shift.

What the Data Says About Cyber-Physical Security Convergence

The SANS 2026 CTI Survey affirms that CTI programs are being asked to cover more ground, including physical and geographical risk, without a proportional increase in headcount. Survey findings additionally emphasize that the risks CTI teams navigate increasingly span cyber, physical, and geopolitical domains simultaneously, rather than staying contained to the network.

Industry research confirms this shift from every angle:

  • ASIS International: The security standards body developed formal Enterprise Security Risk Management (ESRM) guidance specifically to address how organizations struggle to unify physical and cyber risk into a single program with shared visibility.
  • 2026 Physical Security Trends: Market analysis consistently identifies cyber-physical convergence and unified security operations as mainstream mandates rather than fringe concepts.
  • International Security Journal: Analysis highlights a fundamental shift from reactive to proactive security, driven by the reality that digital and physical systems are now so closely linked that a compromise on one side rarely stays contained.

Taken together, the picture is consistent across independent sources: intelligence teams are being pulled toward physical and human risk, and most organizations are still early in closing the gap between that mission and the tooling built to support it.

Why Physical Security is a Natural Extension

It might seem like a jump from tracking ransomware to monitoring executive travel risk, but the underlying methodology is similar. Both rely on:

  1. Situational awareness: Understanding the context around an event, whether digital or physical.
  2. Data aggregation: Bringing together disparate sources into a coherent picture.
  3. Predictive analysis: Identifying indicators of risk before they become incidents.


CTI analysts are already well positioned to bridge this gap. When an executive’s safety or a physical location’s security is at risk, the earliest warning signs are frequently digital via social media sentiment, localized chatter, and open-source discussions. Treating physical security as an adjacent mission means pointing skills a team already has at a new question, rather than starting net-new.

The Strategic Advantage: Breaking Down Operational Silos

Bringing these missions together has a practical benefit beyond the workloadβ€”it prevents security silos where digital and physical intelligence teams operate in isolation. When the same team that monitors cyber threats also informs physical security decisions, the organization achieves a more complete view of risk, reducing the chance that threats fall between the gaps of two disconnected functions.

Extending CTI to Physical Security with Flashpoint

Facing this convergence head-on doesn’t require a new platform, a new vendor evaluation, or creating a new discipline. Organizations leveraging Flashpoint Ignite already have the foundation needed to seamlessly extend their visibility into physical and geopolitical threat landscapes.

Using both Flashpoint Cyber Threat Intelligence (CTI) and Flashpoint Physical Security Intelligence (PSI), security teams can answer two essential questions: β€œwhat is this threat actor doing” and β€œwhat is happening right now around this specific person or place.” Both draw on much of the same underlying data and OSINT tradecraft, so extending into physical security only requires a change in Intelligence Requirements, not mastery of new systems or tools.

With Flashpoint PSI, organizations gain real-time access to mainstream sources where conversations about fast-moving events tend to surface first, plus a geospatial layer that maps that activity to a specific place. Analysts can also draw boundaries around geographic locations to monitor mentions of an executive within that area, or observe a venue on event day, seeing relevant activity as it surfaces. All of this can be accomplished using plain language, removing the need to learn secondary query syntax or lengthy manual processes to get started.

Navigating the Future of Converged Intelligence

The distinction between cyber and physical intelligence will likely keep blurring and Flashpoint is helping security teams on the ground level integrate these two functions. CTI teams that take on physical security as part of their mission shouldn’t be expected to abandon their core discipline. Instead, they should be given the workflows to apply it to a wider set of questions, using tools built to extend rather than replace the way they already work.

See how Flashpoint supports converged cyber and physical missions from a single platform. Request a demo to see what this could look like for your team.

See Flashpoint in Action

The post Beyond Cyber: How CTI Teams Are Solving Converged Threat Use Cases appeared first on Flashpoint.

AI 'watermark removers' flood the web. Almost none can prove they work.

13 August 2026 at 19:33
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims about defeating the text watermark can be verified, as Anthropic has not released a detector. [...]

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

13 August 2026 at 16:00
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]

Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out.

13 August 2026 at 15:00

Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is more interesting: new research gave us a rare look inside a top tier operation as it was being built, and it revealed just how little it now takes for a small and skilled group to reach the top of the field. Here’s what the quarter actually showed, and what it means for how you defend against it.Β  Key takeawaysΒ  Data leak sites recorded 2,139 ransomware victims in Q2 2026, essentially flat versus Q1 and up 33% […]

The post Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out. appeared first on Check Point Blog.

❌