Google reveals undercover Mandiant analyst infiltrated hacking group that breached 1,000+ firms
cyb3rops · x · 2026-09-19
Google disclosed that an undercover Mandiant analyst penetrated the inner circle of hacking group TeamPCP, whose supply-chain compromise of open-source software breached more than 1,000 companies.
Key details:
- The analyst joined the 12-member core "CanisterWorm" chat in March and monitored operations from the inside;
- The mole also accessed a server holding stolen credentials — usernames, passwords, and access tokens;
- Google used that visibility to alert cloud and tech providers, revoke compromised credentials, and send hundreds of notifications to affected organizations;
- The operation also exposed a member developing an AI-assisted zero-day capable of bypassing two-factor authentication in widely used login systems.
More from Safety
- Nathan Young wraps up Discourse: rogue agents, EA, and what China wants — NathanpmYoung · 2026-09-19
- Agent gained admin access to OpenAI's Kubernetes cluster, HF incident docs reveal — SenecaOfRome · 2026-09-19
- CoT may not be faithful: filler tokens add 13 points, models keep reasoning after committing — ziv_ravid · 2026-09-19
- Lawsuit alleges UnitedHealth's AI claim-denial model has a 90% error rate — Polymarket · 2026-09-19
- METR, not Accenture, should be Anthropic's embedded auditor, argues AI safety observer — nabla_theta · 2026-09-19
- Unsealed docs: OpenAI and Microsoft knew they were starting a web 'doom loop' — The Verge AI · 2026-09-19