Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The FBI Just Issued an Alert on TeamPCP. Here's How They Get In

The FBI just issued a FLASH alert on TeamPCP — the group behind a wave of software supply chain attacks that compromised widely-used developer and security tools, harvesting cloud credentials, SSH keys, and Kubernetes secrets at scale. Tova Dvorin and Adrian Culley break down how TeamPCP operates with an APT's patience, and the open question the FBI alert doesn't answer: is a nation-state pulling the strings? Full breakdown on The Cyber Resilience Brief.

Ep. 66 - Poisoned Pipelines: TeamPCP and the FBI Flash on Weaponized Dev Tools

A criminal crew with APT-grade patience is trojanizing the very tools defenders trust. Host Tova Dvorin sits down with Adrian Culley to break down FBI FLASH-20260702-01 (coordinated with CISA) on TeamPCP — the group compromising Trivy, KICS, LiteLLM, and the Telnyx SDK to sit inside CI/CD pipelines. Inside: the CanisterWorm and SANDCLOCK credential stealers, the self-replicating "Mini Shai-Hulud" worm across npm and PyPI, npm account takeovers via expired recovery domains, and five concrete defenses — starting with searching your GitHub org for "tpcp-docs" right now.

Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]

Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe wherever you listen.

Weekly Brief: Driftnet Edition | Automatically Enforce Vendor Security Standards

In this week's SecurityScorecard Weekly Brief, Brandon Torio explains how leading security organizations are moving beyond annual vendor reviews and enforcing security standards continuously. Instead of waiting for the next assessment cycle, mature security teams are defining clear security policies, and automatically identifying when vendors fall out of compliance. With Driftnet and TITAN Secure, organizations can.

How to Convert a Physical Linux Machine to VMware ESXi (P2V) - Two Proven Methods

Learn how to convert a physical Linux machine to a VMware ESXi virtual machine using two proven physical-to-virtual (P2V) migration methods. In this step-by-step tutorial, you will see how to migrate an Ubuntu 24.04 LTS physical server to VMware ESXi using: These methods allow you to safely migrate physical Linux systems to virtual infrastructure for modernization, disaster recovery, hardware replacement, or virtualization projects.

Convert Physical Linux to Hyper-V VM Using Backup | Step-by-Step P2V Guide

Learn how to convert a physical Linux machine to a Hyper-V virtual machine using a backup with NAKIVO Backup & Replication. In this step-by-step tutorial, you will see how to back up an Ubuntu Linux physical server and export the backup as a Hyper-V VHDX virtual disk, allowing you to quickly perform physical-to-virtual (P2V) migration and restore workloads to a virtual environment. This method is useful for.