September 7, 2026 · 7 min read
Starting with this issue, the newsletter is expanding beyond OSINT and rolling out a new design. Alongside the open-source intelligence coverage you already know, we'll now also be tracking cybersecurity developments, cyber threat intelligence (CTI), and the latest in AI — the areas increasingly shaping the same landscape we've been reporting on.
Same commitment to sharp, relevant reporting, built to put the content itself front and center.

When Australian Federal Police officers walked into two houses around Perth on August 26, they finally uncovered part of what researchers have called the longest running spree of software supply chain attacks. Two men from Western Australia, aged 21 and 23, face a combined 14 charges over their alleged roles in TeamPCP, the Shai-Hulud npm worm, the LiteLLM compromise, and a March campaign that poisoned five software ecosystems in about five days. The AFP alleges the group's malicious code potentially compromised more than 1,000 organizations, enabled the theft of over 500,000 credentials and exfiltrated at least 300 gigabytes of data, with global remediation costs estimated in the hundreds of millions of dollars.
TeamPCP surfaced in late 2025 as an opportunistic cloud-exploitation crew, scanning the internet for exposed Docker APIs and Kubernetes control planes. In early 2026, it pivoted to the software supply chain, and specifically to the open source software tools everyone trusts. In late February, the group exploited a misconfigured GitHub Actions workflow in Aqua Security's Trivy, the most widely deployed open source vulnerability scanner, and walked away with a service-account token. Then, TeamPCP shipped a malicious Trivy release that laced thousands of CI/CD pipelines with a credential stealer. One of those pipelines belonged to LiteLLM, the AI gateway that draws roughly 95 million downloads a month: its PyPI publishing token was harvested, and two backdoored LiteLLM releases followed on March 24. CloudSEK later assessed that the LiteLLM attack alone exposed data from more than 2,500 organizations.
The group was also loud by choice, TeamPCP practiced something akin to cyclical recruitment. Last May, it published the Shai-Hulud worm's source code and ran a public contest offering $1,000 in Monero to whoever conducted the largest supply chain operation with it, scoring entries by the download counts of the packages they compromised. Participants were also promised additional compensation if they 'found something good'.
That same appetite for attention handed investigators their first thread. Flare's Emerging Threats Team, publishing on the day of the arrests, walked through the chain. It starts with DeadCatx3, a distinctive alias multiple security firms had flagged as part of TeamPCP. A username search surfaced a HackerOne profile registered under the name Ruben Thomson, plus a Hugging Face account whose bio listed masscan[.]cloud, a command-and-control domain used by the group's Mini Shai-Hulud worm in May.
From the name, Flare found a school email address in leaked credential data, then reverse-pivoted on the reused password to reach a personal Gmail. That Gmail led to a TikTok account under the same name, whose only video showed a Steam account. The Steam profile picture: a cat sitting in front of computer monitors, with zero reverse image search results. The exact same image fronted the TeamPCP Telegram channel. Brian Krebs ran a parallel investigation through passive DNS, breach records and Australian company registrations, which turned up a firm the 21-year-old suspect had registered under the name OPSEC Express. Australian media confirmed Ruben Thomson of Cottesloe was among those arrested; both men remain in custody ahead of a September 18 court date, and the allegations are untested in court.

AI runs through this story twice. As a weapon first: Aikido researcher Charlie Eriksen argues that LLMs have compressed the gap between reading about an attack technique and running it at scale, producing actors capable of enormous damage without the operational discipline that used to be necessary with that capability. As a target second: the crew's highest-yield move was hitting LiteLLM, an AI gateway sitting in front of the model traffic, and therefore the provider API keys, of thousands of companies. Poisoning one AI dependency bought them more credentials than months of scanning exposed Docker APIs ever did. The defensive fallout is real too: GitHub introduced a three-day cooldown for Dependabot version updates in direct response, and other package ecosystems followed with cooldown support of their own.
For defenders, the fixes are unglamorous: pin GitHub Actions to commit SHAs, treat credential rotation as an inventory exercise rather than an incident chore, scope publishing tokens narrowly and give them short lifetimes, and monitor your own domains in stealer logs. For the OSINT crowd, this case is a masterclass in pivoting: one alias, one leaked password and one sentimental cat picture collapsed years of anonymity. Every threat actor carries this kind of teenage-era debt, and it never gets cheaper. The crew that industrialized supply chain compromise was undone by exactly what it exploited in everyone else: credentials that should have died years ago, and didn't.
Sources: Krebs on Security, Flare, Australian Federal Police, CloudSEK, BleepingComputer
Enter your domain and instantly see which employee accounts, passwords, and systems have been compromised by infostealer malware.
Using the Flare threat intelligence platform, Predicta Lab reconstructs the trail left by Dumpsec across BreachForums, DarkForums and PwnForums. Seven suspected members of this French cybercrime group, aged 15 to 22, were arrested on June 11th, 2026. They had been operating since late 2025 and targeted French targets such as Colis Privé, the Assemblée Nationale, Assurea and several sports federations. [ Predicta Lab ]
Bellingcat spent over a year investigating the 1996 execution-style killing of a man whose remains were found in the woods of Sharon, Massachusetts in 1998, filing 27 public records requests to 18 law enforcement agencies and contacting more than two dozen people connected to the case. The records show authorities identified the victim as Fu Chun Wang, a 26-year-old undocumented Fujianese immigrant suspected of belonging to the Boston faction of the Fukienese Flying Dragons gang, and that investigators believed he was killed by members of his own gang after his arrest over stolen credit cards. No one was ever charged with the murder, and the case remains unsolved. [ Bellingcat ]
Nico Dekens argues that prompt injection has become a genuine OSINT tradecraft issue: any webpage, PDF, or dataset processed by an AI tool should be treated as potentially attacker-controlled input. Such content can contain hidden instructions designed to influence an analysis, suppress certain names, or obscure contradictions. He distinguishes this from hallucination, warns that the risk scales sharply when AI agents get access to case files and the ability to trigger actions, and sets one rule: no untrusted source should be able to trigger an action. The post ends with a CTF-style lab of three safe training files containing hidden instruction-like content for analysts to practice on. [ Dutch OSINT Guy ]
The Dutch government has opened public consultation on a new intelligence law for the domestic and military security and intelligence services. This new bill would let them tap or follow anyone for up to a year without prior approval; compel companies and citizens to hand over data under threat of criminal penalties; and share intelligence with police, tax and financial units. A "state of emergency" clause would suspend most oversight and reporting duties, with no definition of what triggers it. The consultation runs until 11 October 2026. [ Risky Business News // Dutch government consultation ]
Get the latest OSINT news, monthly recaps and product updates in your inbox.

October 5, 2026 · 8 min read
ShinyHunters claims it stole terabytes of FBI agent and applicant data through the bureau's jobs portal. What is verified, what is only claimed, and why the FBI answered with handcuffs.

August 3, 2026 · 1 min read
This month in OSINT: exposing Africa Corps' involvement in Mali, OSINT's dark side and exploring new investigation tools.

July 6, 2026 · 1 min read
This month in OSINT: exposing influence campaigns, following hidden digital trails, investigating AI-generated evidence, exploring new investigation tools and gearing up for an OSINT CTF this September.

June 1, 2026 · 1 min read
This month in OSINT: tracking troops, investigating mines with satellite imagery, exploring Discord as an OSINT pivot point, testing new investigation tools and incoming CTFs.