Tag: oligo security
3 articles

JFrog Artifactory Flaws Expose Software Supply Chain to Manipulation
Critical flaws in JFrog Artifactory have been uncovered, putting software supply chains at risk of manipulation by allowing low-privileged users to alter package metadata. These vulnerabilities, already patched by JFrog, highlight the importance of securing metadata generation and trusted internal paths to prevent potential software supply chain compromises.

TeamPCP Linked to Years-Old Cryptojacking Operation
New research reveals that TeamPCP, a notorious cryptojacking group, has been secretly operating for years, with evidence tracing back to 2020 and a recent connection to a massive supply-chain compromise in March 2026. Their operation, linked to the TA-NATALSTATUS activity, involved a sophisticated deployment framework and shared infrastructure.

TeamPCP's Origins Exposed in Long-Running Open-Source Attacks
Meet TeamPCP, a threat actor with a stealthy history of open-source attacks that dates back to 2020, and has evolved at an alarming rate to compromise over 1,000 software packages. Their rapid adaptation has experts sounding the alarm, with one researcher calling it the scariest thing about this campaign.