Bottom line: The arrest of these two alleged TeamPCP members marks a significant blow to the group's operations, as it disrupts their ability to target US-based software companies.
What's happening: The Australian Federal Police (AFP) has arrested two men, aged 32 and 29, in New South Wales, with alleged ties to TeamPCP, a group believed to have launched 170+ software supply chain attacks since 2018, resulting in estimated damages of over $100M.
What to do: Security teams should immediately review their software supply chain security controls, verifying the authenticity of third-party components and ensuring vendors are patched against known vulnerabilities, such as the CVE-2022-22943 exploit.