Aikido Security published research showing that GitLab's per-user incoming email address, meant to let users create project issues via email, contains a non-expiring token that functions as an authentication and authorization credential. Because GitLab treats any message sent to that address as coming from its owner, exposure of the address alone can let an attacker create issues, submit merge requests, or send patch files across an organization's public and private projects without needing account credentials.
darkreading.com
· 2026-09-23
The Australian Federal Police announced the arrest of two men from Western Australia on 14 charges related to alleged membership in TeamPCP, a hacking collective linked to widespread supply chain attacks. Authorities say the group's malware, known as Shai-Hulud, spread through compromised open source packages and infected more than 1,000 organizations globally by exploiting CI/CD development pipelines.
arstechnica.com
· 2026-08-28
The Australian Federal Police, working with the FBI and Western Australia Police, arrested and charged a 21-year-old and a 23-year-old accused of belonging to TeamPCP, a hacking collective blamed for injecting malicious code into widely used open-source packages. The group's tampered code allegedly reached over a thousand organizations, including GitHub, OpenAI, Mistral AI, SAP and the European Commission, leading to theft of roughly half a million credentials and exfiltration of at least 300GB of data.
bleepingcomputer.com
· 2026-08-27