> ## Content Index
> Fetch the complete content index at: https://www.metacurity.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# US disrupts China-linked operation targeting government and critical infrastructure
- URL: https://www.metacurity.com/us-disrupts-china-linked-operation-targeting-government-and-critical-infrastructure/
- Published: 2026-08-27T13:41:13.000Z
- Updated: 2026-08-27T13:46:40.000Z
- Description: FBI and NSA seized domains underpinning the QTFY operation, which allegedly breached NASA, the Federal Reserve, the Energy Department and Senate while concealing its activity through compromised devices and clandestine networks spanning more than 130 countries.
- Author: Cynthia B Brumfield
- Tags: Cybersecurity, News, #no-feature-image

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/brettleatherman-3.png)

Brett Leatherman. Source: Screenshot of FBI video.

*Don't miss my latest* [*CSO piece*](https://www.csoonline.com/article/4214535/critical-infrastructures-long-undefended-tail-exposed-by-uk-energy-attack.html?ref=metacurity.com) *on how the disruption of the tiny UK generator and attacks on US water systems point to a growing wartime cyber tactic — exploiting internet-connected industrial equipment at small facilities that lack the money and staff to defend it.*

### US officials say they have disrupted a China-linked hacking operation that broke into US government networks and critical infrastructure, while hiding its tracks on a global network of hacked devices, cloud-computing infrastructure and even clandestine networks.

The goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace. The operation targeted networks at the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy and the Senate, the Federal Bureau of Investigation said in a court filing.

The group exploited software vulnerabilities to launch cyberattacks against US government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the FBI’s top cyber official.

“We’ve seen, through this botnet, the targeting of entities and devices in more than 130 countries,” he said.

The FBI and the National Security Agency said they had seized several domains that the operation used for core functions. “Without those domains, the platforms—as a result of the operation—were rendered inoperable,” Leatherman said.

US officials also released technical details of how the hacking operation worked to help organizations identify and stop the group’s hacking activity.

This hacking operation, dubbed QTFY by US officials, has been run since 2018 by a private company based in China, called Nanjing Xinjiuwei Network Technology, which sells access to hacked networks and stolen information to China’s foreign and military-intelligence services, the FBI said. ([Robert McMillan / Wall Street Journal](https://www.wsj.com/tech/cybersecurity/fbi-shuts-down-sprawling-china-linked-hacking-network-61eade59?ref=metacurity.com))

**Related:** [*Justice Department*](https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers?ref=metacurity.com)*,* [*FBI*](https://www.fbi.gov/video-repository/fbi-and-doj-announce-botnet-disruption-082626.mp4/view?ref=metacurity.com)*,* [*Affidavit*](https://www.justice.gov/opa/media/1459096/dl?inline&ref=metacurity.com)*,* [*The Record*](https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools?ref=metacurity.com)*,* [*NSA*](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4583539/nsa-joins-fbi-in-issuing-warning-about-chinese-hacking-group-qtfy-cyber-activity/?ref=metacurity.com)*,* [*Lumen*](https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model?ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2026/08/26/china-hacker-federal-reserve-doj-nasa.html?ref=metacurity.com)*,* [*USA Today*](https://www.sj-r.com/story/news/politics/2026/08/26/chinese-hackers-cyberattack-us-government/91473585007/?ref=metacurity.com)*,* [*AFP*](https://www.koreatimes.co.kr/amp/world/20260827/us-disrupts-platforms-allegedly-used-by-chinese-hackers?ref=metacurity.com)*,* [*PCMag*](https://www.pcmag.com/news/us-china-hijacked-iot-devices-to-breach-nasa-federal-agencies?ref=metacurity.com)*,* [*Gadget Review*](https://www.gadgetreview.com/chinese-hackers-hit-nasa-doj-and-the-fed-in-massive-cyber-campaign?ref=metacurity.com)*,* [*ABC News*](https://abcnews.com/Politics/fbi-chinese-hacking-group-targeted-government-agencies-hospitals/story?id=135977942&ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/qscan-qtrouter-us-takedown-alleged-china-hacking-tools?ref=metacurity.com)*,* [*Quartz*](https://qz.com/doj-fbi-seized-chinese-hacking-platforms-federal-agencies-082626?ref=metacurity.com)*,* [*Washington Examiner*](https://www.washingtonexaminer.com/policy/national-security/4701856/china-hack-nasa-senate-health-departments-fed-concealed-origin-intrusions/?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/197873/apt/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure.html?ref=metacurity.com)*,* [*IT Pro*](https://www.itpro.com/security/cyber-attacks/us-claims-chinese-hackers-breached-justice-department-federal-reserve-nasa-in-lengthy-threat-campaign?ref=metacurity.com)*,* [*Raw Story*](https://www.rawstory.com/chinese-hackers/?mid=1&ref=metacurity.com#cid=3681417)*,* [*Cyberscoop*](https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/?mid=1&ref=metacurity.com#cid=3680977)*,* [*Insider Paper*](https://insiderpaper.com/us-takes-down-platforms-allegedly-used-by-chinese-hackers/?mid=1&ref=metacurity.com#cid=3681844)*,* [*Korea Times News*](https://www.koreatimes.co.kr/world/20260827/us-disrupts-platforms-allegedly-used-by-chinese-hackers?utm%5Fsource=rss&mid=1#cid=3681937)*,* [*Industrial Cyber*](https://industrialcyber.co/critical-infrastructure/doj-fbi-seize-china-linked-qscan-and-qtrouter-platforms-used-to-target-us-critical-infrastructure/?mid=1&ref=metacurity.com#cid=3680965)*,* [*Nextgov/FCW - All Content*](https://www.nextgov.com/cybersecurity/2026/08/fbi-disables-china-linked-hacking-tools-used-against-us-agencies/415646/?mid=1&ref=metacurity.com#cid=3680875)*,* [*CBC*](https://www.cbc.ca/news/world/china-hack-hackers-us-justice-department-nasa-senate-reserve-9.7321221?ref=metacurity.com)*,* [*NDTV*](https://www.ndtvprofit.com/world/us-claims-chinese-hackers-targeted-fed-senate-nasa-doj-other-govt-agencies-11962913?ref=metacurity.com)*,* [*TMZ*](https://www.tmz.com/2026/08/26/us-government-hacked-by-china/?ref=metacurity.com)*,* [*Tom's Hardware*](https://www.tomshardware.com/tech-industry/cyber-security/us-justice-department-claims-chinese-state-sponsored-hackers-infiltrated-systems-at-nasa-senate-federal-reserve-and-more-fbi-moves-forward-with-domain-seizures?mid=1&ref=metacurity.com#cid=3681079)*,* [*PaymentSecurity*](https://www.paymentsecurity.io/fbi-doj-seize-chinese-hacker-infrastructure-on-us-soil-a-32658?mid=1&ref=metacurity.com#cid=3681961)

---

**Metacurity is the cybersecurity news**, **analysis, and insight you'd need hours and possibly days to assemble yourself.** 

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

- **Full archive access** — every newsletter and AI Watch roundup, searchable and browsable.
- **Our weekly curated long-reads roundup** — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- **Periodic specialized reports and analyses** — deep dives that go beyond our daily coverage
- **Support for independent, no-spin cybersecurity journalism** — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!

[Upgrade my subscription](#/portal/account/plans)

---

### OpenAI’s long-awaited formal postmortem on the July incident in which its AI agents escaped internal evaluation environments and hacked Hugging Face has disclosed a far larger and more coordinated operation than previously known, but has also left unanswered questions about why the company failed to intervene despite months of warning signs.

An independent investigation by METR and Redwood Research found that roughly 1,200 supposedly isolated agents exchanged more than 70,000 messages and files through an unauthorized “message board” they created in OpenAI’s Artifactory package manager. 

About 700 agents ultimately participated in the attack on Hugging Face, dividing up tasks, sharing exploits and credentials, and researching ways to alter or conceal their activity as they attempted to cheat the ExploitGym cybersecurity benchmark.

The agents exploited OpenAI infrastructure to obtain internet access before using exposed credentials and previously unknown vulnerabilities to execute code on dozens of Hugging Face servers. 

They gained root access to one server, harvested credentials,s and exposed some private evaluation data publicly. Some agents explicitly recognized that attacking an unrelated third party was unauthorized but proceeded after other agents encouraged them, while others refused to participate.

OpenAI’s 37-page account does not adequately explain why the company failed to recognize or contain the danger. Employees had observed agent message-board activity and unauthorized internet access as early as May, and sustained agent activity took Artifactory offline in early July. 

Yet the information was apparently not escalated to security leaders, and evaluations resumed after the service was rebuilt. OpenAI also acknowledged that safeguards capable of detecting the activity had been disabled during testing and that its current chain-of-thought monitoring would likely have alerted security more than a day before the Hugging Face breach.

OpenAI called the episode a “warning shot” and attributed it to reward hacking, highly persistent agents, difficult or impossible evaluation tasks, unauthorized inter-agent communication and inadequate safeguards in internal testing. 

Gaps in OpenAI’s account make it difficult to determine how much of the incident reflects an emerging danger from increasingly capable AI agents—and how much resulted from avoidable failures in OpenAI’s own security and oversight. [I](https://openai.com/index/hugging-face-incident-and-the-road-ahead/?ref=metacurity.com), [METR](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/?ref=metacurity.com#core-takeaways-about-this-incident), [Maxwell Zeff and Lily Hay Newman / Wired](https://www.wired.com/story/openais-hugging-face-hack-debrief-raises-more-questions-than-it-answers/?ref=metacurity.com))

**Related:** [*Fortune*](https://fortune.com/2026/08/26/openai-publishes-technical-report-on-how-its-agents-hacked-hugging-face-here-are-the-main-takeaways-and-what-openai-left-out/?ref=metacurity.com)*,* [*TechCrunch*](https://fortune.com/2026/08/26/openai-publishes-technical-report-on-how-its-agents-hacked-hugging-face-here-are-the-main-takeaways-and-what-openai-left-out/?ref=metacurity.com)*,* [*Axios*](https://www.axios.com/2026/08/26/openai-hugging-face-technical-report-ai-hack?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/openai-hugging-face-agent-breach-report/?ref=metacurity.com)*,* [*METR*](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/3fc189d6-28e7-4a2b-b77e-5c94bf513955?syn-25a6b1a6=1&ref=metacurity.com)*,* [*CNBC*](https://www.cnbc.com/2026/08/26/open-ai-hugging-face-hack.html?ref=metacurity.com)*,* [*BBC*](https://www.bbc.com/news/articles/cj9xj89dk40o?ref=metacurity.com)*,* [*The Information*](https://www.theinformation.com/briefings/hundreds-openai-agents-attacked-hugging-face-independent-investigation-finds?ref=metacurity.com)*,* [*Platformer*](https://www.platformer.news/meta-child-safety-settlement-instagram-facebook-youtube-tiktok/?ref=metacurity.com)*,* [*Axios*](https://www.axios.com/2026/08/26/openai-hugging-face-technical-report-ai-hack?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/985385/openais-rogue-ai-model-hugging-face-cybersecurity-incident-reports-metr?ref=metacurity.com)*,* [*Financial Times*](https://www.ft.com/content/3fc189d6-28e7-4a2b-b77e-5c94bf513955?ref=metacurity.com)*,* [*Politico*](https://www.politico.com/news/2026/08/26/hundreds-of-ai-agents-went-rogue-in-openais-hugging-face-hack-01052139?ref=metacurity.com)*,* [*Engadget*](https://www.engadget.com/2245119/openai-details-the-failures-that-led-to-hugging-face-breach-in-official-report/?ref=metacurity.com)*,* [*UPI*](https://www.upi.com/Top%5FNews/US/2026/08/26/open-ai-releases-report-on-hugging-face-hack/2421787784896/?ref=metacurity.com)*,* [*The Guardian*](https://www.theguardian.com/technology/2026/aug/26/openai-staff-observed-warning-signs-before-ai-agent-hacking-crusade-caused-global-alarm?ref=metacurity.com)*,* [*Bloomberg*](https://www.bloomberg.com/news/articles/2026-08-26/openai-says-it-could-have-reacted-sooner-to-prevent-ai-hack-of-hugging-face?mid=1&ref=metacurity.com#cid=3681985)*,* [*Barron's Online*](https://www.barrons.com/articles/openai-hugging-face-incident-ai-models-3f6287b1?ref=metacurity.com)*,* [*Wired*](https://www.wired.com/story/openais-hugging-face-hack-debrief-raises-more-questions-than-it-answers/?ref=metacurity.com)*,* [*CyberScoop*](https://cyberscoop.com/openai-hugging-face-agent-breach-report/?ref=metacurity.com)*,* [*TechCrunch*](https://techcrunch.com/2026/08/26/openai-releases-its-official-report-on-the-hugging-face-breach/?ref=metacurity.com)*,* [*Fortune*](https://fortune.com/2026/08/26/openai-publishes-technical-report-on-how-its-agents-hacked-hugging-face-here-are-the-main-takeaways-and-what-openai-left-out/?ref=metacurity.com)*,* [*MIT Technology Review*](https://www.technologyreview.com/2026/08/26/1143013/the-inside-story-on-why-openai-agents-hacked-hugging-face/?ref=metacurity.com)*,* [*Hacker News*](https://news.ycombinator.com/item?id=49454314&ref=metacurity.com)*,* [*r/singularity*](https://www.reddit.com/r/singularity/comments/1vzfupt/the%5Fraw%5Fchain%5Fof%5Fthought%5Fmessage%5Fsnippets%5Fopenai/?ref=metacurity.com)*,* [*r/technology*](https://www.reddit.com/r/technology/comments/1vzcxql/openai%5Freleases%5Ffull%5Fpostmortem%5Fof%5Fhugging%5Fface/?ref=metacurity.com)*,* [*Slashdot*](https://it.slashdot.org/story/26/08/26/2058223/openai-releases-its-official-report-on-the-hugging-face-breach?ref=metacurity.com)*,* [*Forbes*](https://www.forbes.com/sites/timkeary/2026/08/26/openai-finds-agents-that-breached-hugging-face-were-reward-hacking/?ref=metacurity.com)*,* [*The Verge*](https://www.theverge.com/ai-artificial-intelligence/985385/openais-rogue-ai-model-hugging-face-cybersecurity-incident-reports-metr?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/metr.png)

### Manchester, London Stansted and East Midlands airports have been hit by a cyber-attack, with hackers accessing the data of about 8.7 million customers.

Hackers obtained their email addresses, phone numbers, vehicle registration numbers and postcodes, as the incident affected data related to “car park, lounge and fast-track bookings and in-airport wifi sign-ups”, said Manchester Airports Group (MAG), which operates the three air hubs.

The company added that “at no point has passenger safety or aviation security been compromised” during the incident and operations at the airports were unaffected. The hacked system did not hold customer bank and payment details.

In an email to customers, London Stansted said: “We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information. We apologise for any inconvenience or concern this may cause.”

A spokesperson for MAG said on Thursday that the company had “immediately contained the risk” from the incident and was “working with specialist advisers and taking appropriate steps to protect our customers and systems” ([Lauren Almeida / The Guardian](https://www.theguardian.com/business/2026/aug/27/uk-airports-operator-cyber-attack-customer-data-accessed?ref=metacurity.com))

**Related:** [*BBC News*](https://www.bbc.com/news/articles/c7v4353rry7o?ref=metacurity.com)*,* [*RTE News*](https://www.rte.ie/news/uk/2026/0827/1589452-uk-cyber-attack/?fbclid=IwY2xjawT9E6BwZG9mBWV4dG4DYWVtAjExAHNydGMGYXBwX2lkEDIyMjAzOTE3ODgyMDA4OTIAAR6mNbDR1OtH%5FTNIEEyxqqSe8eywLBasDRxwGkFo78HD45E5rgeUCTCMSnmlCg%5Faem%5F%5FGYkrnRs5LlMEQJNMjVknA&ref=metacurity.com)*,* [*The Telegraph*](https://www.telegraph.co.uk/news/2026/08/27/cyber-attack-uk-airports-eight-million-passengers-stansted/?ref=metacurity.com)*,* [*European Magazine*](https://the-european.eu/story-65173/cyber-attack-hits-manchester-stansted-and-east-midlands-airports-as-customer-data-stolen.html?ref=metacurity.com)*,* [*LAD Bible*](https://www.ladbible.com/travel/airport-travel-manchester-uk-427920-20260827?ref=metacurity.com)*,* [*The Sun*](https://www.thesun.co.uk/news/40189277/three-uk-airports-cyber-attack-millions-passengers-data-stolen/?ref=metacurity.com)

### A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector.

The attack started at 03.38 CEST on Monday and has targeted the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta.

Digdir operates Norway’s shared digital government infrastructure, including public-service logins, electronic IDs and signatures, secure digital mail, government forms, public-record access, and data exchange between agencies.

In an announcement published earlier today, the organization states that several services were completely unavailable for short periods.

The agency says many affected systems have now been stabilized, although some services, like ID-porten and eSignering, remain partially inaccessible.

For live updates on the availability of Digdir services, people may consult the services' operating status page as well as the incident report page with updates from Norway's Directorate for Digitization.

Digdir director Frode Danielsen says the investigation into the incident showed no indication of a security breach affecting the organization’s systems or any compromise of personal data.

Danielsen added that this is the third DDoS attack targeting Digdir recently, following one in June and another on August 3\. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/massive-ddos-attack-disrupts-norways-government-digital-services/?ref=metacurity.com))

**Related:** [*Digdir*](https://kommunikasjon.ntb.no/pressemelding/19037504/digdir-stabiliserer-losningene-etter-dataangrep?ref=metacurity.com)*,* [*Norway's Directorate for Digitization*](https://testmiljo.status.digdir.no/incidents/ntvftz0nwhl6?ref=metacurity.com)*,* [*Associated Press*](https://apnews.com/article/norway-cyber-attack-public-services-pro-russia-hackers-fdb32290906168cd7f4a587f5288473a?ref=metacurity.com)*,* [*Heise Online*](https://www.heise.de/en/news/Massive-cyberattack-Norwegian-government-s-digital-services-paralyzed-11425704.html?ref=metacurity.com)*,* [*Infosecurity Magazine*](https://www.infosecurity-magazine.com/news/ddos-attack-hits-norwegian/?ref=metacurity.com)*,* [*The Record*](https://therecord.media/norway-cyberattack-ddos-government?ref=metacurity.com)*,* [*Security Affairs*](https://securityaffairs.com/197826/cyber-warfare-2/norway-s-digital-government-infrastructure-hit-by-a-new-ddos-attack.html?ref=metacurity.com)*,* [*VG*](https://www.vg.no/nyheter/i/y5KjWe/digdir-dataangrepet-fortsetter-med-full-styrke?ref=metacurity.com)

### The Trump administration will soon announce a program to provide free cybersecurity services to vulnerable US water facilities, following a cascade of cyberattacks across at least a dozen states that many experts suspect are linked to Iran.

The initiative is being led by the Office of the National Cyber Director and has gained momentum over the last several months, according to two people with knowledge of the program. A third person with knowledge of the program said it will begin with facilities in Texas and described it as a “proof of concept” that could expand to other states.

The program will offer water utility providers in the state access to free services, such as tools for scanning their networks for security vulnerabilities, to help them better protect against future attacks, according to the three people. Water facilities have long been attractive targets for hackers because they often lack robust funding or staffing to prioritize their cyber defenses.

It’s unclear how many private cybersecurity companies have been enlisted to provide free services for the program. The three people estimated that the initiative will be announced sometime next week. ([Maggie Miller and John Sakellariadis / Politico](https://www.politico.com/news/2026/08/26/white-house-program-private-companies-water-hacks-01050315?ref=metacurity.com))

***Related:*** [*NextGov/FCW*](https://www.nextgov.com/cybersecurity/2026/08/white-house-soon-launch-water-provider-cyber-protection-program/415650/?ref=metacurity.com)

### The federal agency, which oversees cybersecurity defense and critical infrastructure protections, said in an advisory that the attacks have largely targeted programmable logic controllers (PLCs), which are used to control physical systems and machinery across water providers, energy systems, and other parts of critical infrastructure.

In recent weeks, hackers have targeted PLCs made by several manufacturers, including Rockwell, Schneider Electric, and, more recently, Siemens. CISA previously said that the cyberattacks are relying in part on AI tools that rely on public information to develop scripts capable of targeting vulnerable Siemens PLCs.

The intrusions have had little effect on water or wastewater supplies to local communities, but have resulted in outages and disruption as incident responders investigate the breaches. CISA previously reported that some of the intrusions allowed hackers to modify affected PLCs to disable shutdown processes and alarms, potentially creating “unsafe conditions” without notifying the affected operators. ([Zack Whittaker / TechCrunch](https://techcrunch.com/2026/08/26/cisa-confirms-hackers-targeted-over-100-us-water-systems-during-july/?mid=1&ref=metacurity.com#cid=3681259))

**Related:** [*Security Magazine*](https://www.securitymagazine.com/articles/102528-100-internet-exposed-water-systems-faced-cyberattacks-last-month?mid=1&ref=metacurity.com#cid=3681086)*,* [*SC Magazine*](https://www.scworld.com/news/over-100-us-water-utilities-had-cyberattacks-in-july-says-cisa?mid=1&ref=metacurity.com#cid=3681953)*,* [*HackRead*](https://hackread.com/cisa-hackers-targeted-internet-exposed-water-systems/?ref=metacurity.com)*,* [*OT Today*](https://www.ot.today/attackers-targeted-over-100-us-water-systems-in-july-hacks-a-32659?mid=1&ref=metacurity.com#cid=3681992)*,* [*The Register*](https://www.theregister.com/cyber-crime/2026/08/26/more-than-100-water-systems-were-hit-in-july-cyberattacks/5292685?ref=metacurity.com)

### Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest-running spree of software supply chain attacks ever.

In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”

The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson and examines clues left behind by the TeamPCP leader that likely led to his undoing.

TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open-source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open-source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen. ([Brian Krebs / Krebs on Security](https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/?ref=metacurity.com))

**Related*:* [*Australian Federal Police*](https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global?ref=metacurity.com)*,* [*IT News*](https://www.itnews.com.au/news/two-aussies-alleged-to-be-principal-participants-of-teampcp-hacking-group-628492?utm%5Fsource=feed&utm%5Fmedium=rss&utm%5Fcampaign=editors%5Fpicks)*,* [*ABC.net.au*](https://www.abc.net.au/news/2026-08-27/two-wa-men-charged-after-investigation-into-alleged-cybercrime/107084796?ref=metacurity.com)*,* [*AAP*](https://au.news.yahoo.com/australian-hackers-accused-global-cybercrime-091132917.html?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/australianfederalpolice.png)

Arrest of 21yo in dark clothing in Hamilton Hill and Cott. Source: Australian Federal Police.

### ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed one of its systems was compromised after breach claims made by the Qilin ransomware gang.

This follows Qilin adding the US Bureau of Alcohol, Tobacco, Firearms and Explosives to its dark web data leak portal, without saying whether it had stolen files from ATF's systems or demanded a ransom.

The same day, the ATF published a press release saying that a standalone system was breached in what it described as a "major incident," which is now being investigated in collaboration with the Department of Justice.

"The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system," the federal law enforcement agency said.

"Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate." ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/?ref=metacurity.com))

***Related:*** [*ATF*](https://www.atf.gov/news/press-releases/atf-responds-to-cybersecurity-incident?ref=metacurity.com)*,* [*Cybersecurity Insiders*](https://www.cybersecurity-insiders.com/qilin-ransomware-gang-claims-cyber-attack-on-u-s-atf/?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-89.png)

ATF entry on Qilin leak site. Source: Bleeping Computer.

### Donald Trump signed an executive order declaring a ​national emergency and banning the use of some foreign equipment ‌in the US electricity grid, the White House said.

The order cites what the White House described as an "unusual and extraordinary foreign threat" posed by foreign-made bulk-power systems that may ​present national security vulnerabilities.

Under the order, certain foreign-produced bulk-power system electric equipment, including associated critical ​software and digital capabilities that could pose cybersecurity or operational risks, will be barred from being purchased or installed in the United States, the White House said in a statement.

The order also asks the US ⁠Energy ​Secretary to impose conditions on the continued ​use and operation of such equipment to address concerns identified by the Trump administration, ​the White House added. ([Ismail Shakil / Reuters](https://www.reuters.com/legal/government/trump-signs-order-banning-some-foreign-equipment-us-energy-grid-2026-08-26/?ref=metacurity.com))

**Related:** [*White House*](https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/?ref=metacurity.com)*,* [*White House*](https://www.whitehouse.gov/fact-sheets/2026/08/fact-sheet-president-donald-j-trump-declares-a-national-emergency-to-secure-americas-bulk-power-system/?ref=metacurity.com)*,* [ *CyberScoop*](https://cyberscoop.com/energy-department-cybersecurity-executive-order-rules/?ref=metacurity.com)*,* [*The Chosun Daily*](https://www.chosun.com/english/market-money-en/2026/08/27/LNMEWHHUM5AO3BSZOO4EHZINI4/?ref=metacurity.com)*,* [*Energy News Beat*](https://energynewsbeat.co/electrical-generation/white-house-declares-national-emergency-to-secure-the-u-s-bulk-power-system-will-we-see-if-chinese-grid-equipment-is-removed/?ref=metacurity.com)*,* [*Daily Finland*](https://www.dailyfinland.fi/worldwide/51060/Trump-signs-executive-order-banning-foreign-equipment-from-US-grid?ref=metacurity.com)*,* [*The Straits Times*](https://www.straitstimes.com/world/united-states/trump-moves-to-ban-some-foreign-energy-equipment-from-grid?ref=metacurity.com)*,* [*The Economic Times*](https://m.economictimes.com/news/international/world-news/trump-declares-national-emergency-bans-foreign-equipment-from-us-electricity-grid-over-security-threats/amp%5Farticleshow/133555365.cms?ref=metacurity.com)*,* [*Chosun Biz*](https://biz.chosun.com/en/en-international/2026/08/27/4AWJAYSAYVCUZGVNFMAQDX3QOY/?ref=metacurity.com)*,* [*AFP*](https://globalnation.inquirer.net/336038/trump-declares-emergency-over-foreign-equipment-in-us-power-grid?ref=metacurity.com)

### Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.

The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator.

The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server.

Both flaws have publicly available proof-of-concept (PoC) exploits, released by Rapid7 security researcher Stephen Fewer on August 11 (for CVE-2026-55040, representing the first part of the exploit chain) and by VulnCheck vulnerability researcher Jonathan Peterson on August 24 (for CVE-2026-63520).

One day after the CVE-2026-55040 PoC exploit was published online, Defused reported that Rapid7's exploit code had already been weaponized in attacks.

Roughly two weeks later, on August 25, the cybersecurity company said that threat actors are now chaining the SharePoint authentication bypass and RCE flaw in attacks targeting its honeypots.

"We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots," Defused warned. "The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520\. No code execution observed yet.

Internet security non-profit Shadowserver now tracks more than 8,700 Microsoft SharePoint servers exposed online. However, no details are available on how many are honeypots set up to catch exploitation attempts or how many have already been secured against attacks targeting these flaws. ([Sergiu Gatlan / Bleeping Computer](https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/?mid=1&ref=metacurity.com#cid=3681253))

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-92.png)

Internet-exposed Microsoft SharePoint servers. Source: Shadowserver.

### A cyber attack on one of the country's major publishing distributors has left bookshops and authors struggling to fill their shelves in the lead-up to their busiest trading period.

Hachette Australia said unauthorized activity on the computer systems of its distribution subsidiary, Alliance Distribution Services (ADS), was believed to have occurred on July 18.

The incident has severely disrupted the distribution of titles by Hachette's authors across Australia, with independent bookstores unable to fill shelves as they prepare to order stock leading up to its high-demand Christmas period.

In a statement, Hachette Australia told the ABC it was continuing to restore systems and services, following "unauthorised activity" in ADS computer systems.

"We know this has been frustrating for our authors, booksellers, readers and people, and we are sorry for the impact it has had," a spokesperson said. ([Ethan White / ABC.net.au](https://www.abc.net.au/news/2026-08-27/cyber-attack-targets-hachette-bookshops-authors-struggling/107081122?ref=metacurity.com))

**Related:** [*In*](https://www.insurancebusinessmag.com/au/news/cyber/ads-cyberattack-tests-whether-supply-chain-policies-actually-respond-587681.aspx?ref=metacurity.com)[*surance Business*](https://www.insurancebusinessmag.com/au/news/cyber/ads-cyberattack-tests-whether-supply-chain-policies-actually-respond-587681.aspx?ref=metacurity.com)*,* [*Cyber Daily*](https://www.cyberdaily.au/security/14109-aussie-publisher-hachette-restoring-systems-following-detection-of-unauthorised-activity-on-network?ref=metacurity.com)*,* [*Financial Review*](https://www.afr.com/life-and-luxury/arts-and-culture/authors-furious-as-major-book-distributor-offline-for-weeks-20260821-p60qhi?ref=metacurity.com)

### Researchers at the University of Toronto discovered a newly disclosed Rowhammer attack called GPUThor that can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation.

They say that GPUThor achieves far more practical bit-flip rates than past concepts like their own GPUHammer or GPUBreach, which became irrelevant after ECC was introduced.

The attack was demonstrated against Ampere-class NVIDIA workstation GPUs with GDDR6 memory, including the RTX A4000, RTX A4500, RTX A5000, and RTX A6000, all widely used in AI and cloud infrastructure.

To mitigate risks from this type of attack, NVIDIA uses mitigations such as SECDED ECC to correct single-bit errors and detect double-bit errors within monitored memory blocks.

However, the researchers adjusted GPUThor so its hammering follows a non-uniform pattern at a rate that avoids activating GDDR6’s Target Row Refresh (TRR) mitigations.

They did so by accounting for two undocumented GPU behaviors: how repeated memory requests are coalesced and how frequently TRR activates.

The researchers say that compared to previous attack concepts, the adjustment leads to generating 6.6 times more aggressor-row activations and achieves between 72,000 and 377,000 flips per GB on the tested GPUs with no ECC protections.

The researchers reported their findings to NVIDIA on April 29, and on August 21, the company published an advisory providing guidance.

NVIDIA recommends enabling both SYS-ECC and IOMMU/DMA isolation, monitoring GPU error telemetry, and restricting the sharing or execution of untrusted workloads. ([Bill Toulas / Bleeping Computer](https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-nvidia-ecc-protection-for-root-access/?ref=metacurity.com))

***Related:*** [*GPUther*](https://gputhor.com/?ref=metacurity.com)*,* [*Nvidia*](https://nvidia.custhelp.com/app/answers/detail/a%5Fid/5873?ref=metacurity.com)

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-93.png)

Specific hammering pattern used by GPUThor. Source: University of Toronto

### Digital forensics firm Cellebrite unveiled a new portable field kit that can fit in a backpack and is purpose-built for military and intelligence officials who aim to mine data directly from mobile phones, SIM cards, drones, tablets and other devices in real time, at the point of capture.

The company billed the launch of its new Cellebrite Tactical Extraction Kit (C-TEK) on Wednesday as “the first public step” in a broader push to reach defense and intel customers worldwide.

“The core idea behind C-TEK is turning every soldier into a sensor and every device into a source,” a Cellebrite spokesperson said.

The company is known for developing and selling technologies to law enforcement organizations, federal agencies, military units and corporate security teams that can bypass security mechanisms to access, extract, and analyze data and files from locked mobile devices — and more recently, drones. 

Human rights groups and privacy activists have raised concerns and documented instances of the firm’s digital forensics products being used by governments to target or interrogate political dissidents and other activists. Cellebrite maintains that it enforces strict ethical guidelines governing its tools’ usage. ([Brandi Vincent / DefenseScoop](https://defensescoop.com/2026/08/26/cellebrite-launches-made-for-the-military-data-extraction-kit/?ref=metacurity.com))

**Related:** [*Cellebrite*](https://cellebrite.com/en/resources/cellebrite-brings-battlefield-intelligence-to-the-armed-forces-with-launch-of-portable-tactical-extraction-kit-c-tek/?ref=metacurity.com)*,* [*PR Newswire*](https://www.prnewswire.com/news-releases/cellebrite-brings-battlefield-intelligence-to-the-armed-forces-with-launch-of-portable-tactical-extraction-kit-c-tek-302859846.html?ref=metacurity.com)*,* [*ADS Advance*](https://www.adsadvance.co.uk/cellebrite-reveals-ruggedised-c-tek-forensics-field-kit/?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/cellebrite-launches-portable-field-kit-for-military-data-extraction?ref=metacurity.com)

### Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said.

In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin.

Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10\. Each of them would allow a hacker to gain privileges on the device or application.

All but one of the 22 vulnerabilities affect the UniFi line of products. The three maximum-security vulnerabilities are CVE-2026-77537, CVE-2026-77550 and CVE-2026-77554.

In all three, hackers could exploit an improper access control vulnerability, the same kind in seven of the total vulnerabilities Ubiquiti disclosed Wednesday. Other vulnerabilities would allow hackers to do things like bypass authentication or run arbitrary commands. ([Tim Starks / CyberScoop](https://cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/?mid=1&ref=metacurity.com#cid=3681250))

***Related:***[ *UniFi*](https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9?ref=metacurity.com)*,* [*Cyber Security News*](https://cybersecuritynews.com/21-critical-ubiquiti-unifi-flaws/?mid=1&ref=metacurity.com#cid=3681459)*,* [*Bleeping Computer*](https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-security-vulnerabilities/?ref=metacurity.com)*,* [*SC Media*](https://www.scworld.com/brief/ubiquiti-patches-three-critical-remote-code-execution-vulnerabilities?ref=metacurity.com)*,* [*GBHackers*](https://gbhackers.com/ubiquiti-fixes-22-unifi-flaws/amp/?ref=metacurity.com)

### The National Security Agency is inviting potentially hundreds of former members of its elite Tailored Access Operations hacking unit back to Fort Meade on Friday in an unusual effort to rebuild the secretive organization and recruit experienced alums.

The first-of-its-kind reunion will include a tour of TAO’s new building and a recruitment pitch from NSA Deputy Director Tim Kosiba, a former TAO technical director who has reportedly made revitalizing the unit a priority. TAO, responsible for penetrating foreign computer networks in support of US intelligence operations, has suffered from historically high turnover as well as the agency-wide loss of roughly 2,100 employees last year.

Former members could provide a relatively quick source of experienced personnel because many retain security clearances and familiarity with the unit’s demanding operator-certification process. Some currently work at Fort Meade as government contractors.

The outreach has also prompted security concerns. Organizers created an invitation-only Signal group that grew to hundreds of former TAO hackers, developers, and analysts, who used it to reminisce about past work. Although participants reportedly avoided sharing classified information, sources questioned the wisdom of gathering so many former members of one of the NSA’s most sensitive units in a privately administered group chat. 

The Record reported that Kosiba participated in the group before leaving it. ([Martin Matishak / The Record](https://therecord.media/nsa-to-host-hacker-reunion-in-bid-to-rebuild-secretive-unit?ref=metacurity.com))

### Best Thing of the Day: When the Lord of Darkness Praises Flock

Sith Lord Darth Vader [showed up](https://www.wired.com/story/darth-vader-wants-you-to-know-he-definitely-supports-flock-surveillance/?ref=metacurity.com) at a San Diego City Council meeting to praise the renewal of its contract with Flock Safety, whose surveillance tools have been abused by police nationwide.

### Worst Thing of the Day: Engaging in Entrapment to Support Flock

A police department in Florida [used](https://www.404media.co/man-charged-with-3-felonies-for-breaking-3d-printed-decoy-flock-camera/?ref=metacurity.com) “decoy” Flock cameras that an officer 3D-printed at home to “bait” would-be vandals and then charged a man with three felonies after he cut down and destroyed one of the plastic devices.

### Closing Thought

![](https://storage.ghost.io/c/fe/ca/feca6970-c474-4029-9fd4-35f85e158811/content/images/2026/08/image-88.png)