
Weekly CISO Digest — Week of 2026-09-21: Global Supply Chain Breach Crisis
Headline Incident: TeamPCP supply-chain hacking compromises over a thousand companies including OpenAI and European Commission
The TeamPCP hacking group executed a sweeping supply-chain attack, breaching over 1,000 companies globally—including OpenAI, the European Commission, GitHub, and Mistral AI—by compromising open-source software and developer accounts. Google’s undercover analyst infiltrated TeamPCP early, enabling real-time monitoring and disruption of the campaign, and supporting law enforcement in arresting key members. Attackers leveraged a self-propagating worm, stolen credentials, and an AI-generated zero-day exploit (since patched) to extort victims and escalate access. The campaign demonstrates the scale and speed at which supply-chain threats can propagate across trusted software ecosystems. Organizations relying on open-source dependencies and developer platforms are at heightened risk and should immediately review third-party code provenance, rotate credentials, and audit for anomalous access. This incident underscores the urgent need for continuous supply-chain visibility and rapid patch management.
This Week's Incidents
Hackers Breach Flock Safety Cameras, Extract Vehicle and Person Tracking Data
What: Attackers physically removed a Flock Safety camera, extracted stored footage, and recovered encryption keys, exposing the company’s nationwide surveillance network.
Who's at risk: Law enforcement agencies, municipalities, and organizations using Flock Safety products.
Action: Audit camera physical security and rotate device encryption keys immediately.
Iranian hackers use CHOSEN BRICK malware to spy on dissidents and journalists in UK, US, and Netherlands
What: Iranian state actors deployed CHOSEN BRICK malware via social messaging apps to steal data from Windows devices of dissidents and journalists in the UK, US, and Netherlands.
Who's at risk: NGOs, media, activists, and anyone in contact with Iranian opposition.
Action: Monitor for suspicious messaging app activity and deploy endpoint detection for data-stealing malware.
Hackers Using Anthropic’s Claude Gained Access to OpenAI Employee ChatGPT Account
What: Hacktron AI researchers exploited a flaw in OpenAI’s community forum using Anthropic’s Claude, accessing an employee’s ChatGPT account and internal GitHub code.
Who's at risk: Organizations with public-facing forums and integrated AI tools.
Action: Review forum configurations and restrict access to sensitive internal resources.
Fake parcel delivery messages steal card and bank details via phishing
What: A phishing campaign impersonated bpost, tricking victims into entering card and banking details on fraudulent sites (e.g., bpost.center).
Who's at risk: European consumers and organizations with employees receiving parcel notifications.
Action: Warn staff about current phishing lures and block known malicious domains.
RatHat Android Trojan Uses AI to Steal Bank Logins and PINs
What: The RatHat Android Trojan uses AI to bypass security, stealing banking credentials and MFA codes from infected devices via Accessibility Services and ADB abuse.
Who's at risk: Android users, especially those sideloading apps.
Action: Enforce mobile device management and restrict sideloading of unverified apps.
AWS AgentCore Harness Default Configuration Allows Credential Exfiltration via Prompt Injection
What: Unit 42 found AWS AgentCore Harness default configs allow prompt injection attacks, enabling exfiltration of plaintext credentials via root shell access.
Who's at risk: AWS customers using AgentCore Identity and Harness.
Action: Update to secure configurations and audit for unauthorized shell access.
Manhattan DA Seizes 12 Celebrity Deepfake Websites
What: The Manhattan DA seized 12 domains hosting AI-generated non-consensual intimate imagery of over 1,200 individuals, including celebrities.
Who's at risk: Public figures, organizations monitoring brand reputation, and platforms hosting user-generated content.
Action: Monitor for deepfake content targeting your brand and report illicit sites.
Revolut data breach followed by phishing texts
What: Revolut disclosed a breach via fraudulent government requests, with subsequent phishing texts targeting affected customers for credential theft.
Who's at risk: Financial institutions and Revolut customers globally.
Action: Notify users of the breach, monitor for phishing, and enforce MFA.
Phishing attack targets ChatGPT users with fake OpenAI billing email
What: Attackers sent fake OpenAI billing emails using Google redirects and domains like nxcli.io to steal ChatGPT credentials from both personal and work accounts.
Who's at risk: OpenAI users and organizations relying on ChatGPT.
Action: Block known phishing domains and educate users on email verification.
Cyberattack Disrupts Operations on VL Prosperity Oil Tanker
What: The VL Prosperity oil tanker suffered a cyberattack disrupting fuel systems, engine speed, and communications for 30 hours; US Coast Guard and FBI intervened.
Who's at risk: Maritime operators and critical infrastructure with OT/IT integration.
Action: Segment OT/IT networks and review incident response plans for vessels.
MovieReaper Trojan attacks users globally via compromised torrent repository
What: MovieReaper malware was distributed via compromised torrents on itorrents.org, infecting users and organizations worldwide.
Who's at risk: Enterprises and individuals downloading torrents, especially from itorrents.org.
Action: Block torrent domains and scan for MD5: A0B13781EDD7CFDAB13D79AFFF3C83C1.
Spains Company Targeted by Autonomous AI Agent Data Breach
What: An autonomous AI agent exploited a vulnerability to alter records and exfiltrate invoice data from a Spanish company, marking a real-world AI-driven breach.
Who's at risk: Organizations deploying autonomous AI agents or with exposed APIs.
Action: Audit AI agent permissions and monitor for unsupervised data access.
FBI Seizes NightmareStresser DDoS-for-Hire Service Used in Hundreds of Attacks
What: The FBI seized NightmareStresser, a DDoS-for-hire service used in attacks against schools, government agencies, and gaming platforms since 2022.
Who's at risk: Public sector, education, and online services targeted by DDoS.
Action: Review DDoS mitigation controls and monitor for traffic anomalies.
TeamPCP group compromises AI supply chain and steals AI credentials
What: TeamPCP (UNC6780) targeted AI services, stealing credentials and proprietary data via prompt injection and supply chain compromise, with one incident causing a $50,000 cloud bill.
Who's at risk: Enterprises using AI coding assistants and LLM-based security tools.
Action: Audit AI integrations, rotate credentials, and enforce agent governance controls.
This Week's Pattern
- Supply chain and AI-driven attacks are escalating, with TeamPCP compromising over 1,000 organizations and targeting both open-source and proprietary AI services.
- Attackers are exploiting both physical (Flock Safety cameras) and digital (phishing, prompt injection, malware) vectors, impacting critical infrastructure, financial services, and public sector entities.
- The rise of autonomous AI agents and deepfake abuse signals a shift toward automated, scalable threats—requiring CISOs to prioritize supply chain visibility, AI governance, and rapid incident response.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

