Top stories.
- US disrupts Chinese hacking platform.
- Researchers publish analysis of OpenAI agents' attack against Hugging Face.
- Australian police arrest two suspected TeamPCP members.
- The White House bans certain foreign-made power equipment over backdoor risks.
- Slovakia finds Russian backdoors on traffic speed cameras.
US disrupts Chinese hacking platform.
The US Justice Department and FBI on Wednesday announced the seizure of domains used by a Chinese state-sponsored threat actor that hacked NASA, the Federal Reserve, the Department of Energy, the Department of Justice, the Department of Health and Human Services, the National Institutes of Health, and the US Senate. The threat actor, tracked as "QTFY," is a contractor that used two hacking platforms called "QScan" and "QTRouter" to target its victims. The Justice Department seized command-and-control domains that were hardcoded into these tools, cutting them off from infected devices.
The Justice Department stated, "QScan scans and automatically infects thousands of [IoT] devices worldwide, which are then added to the QTRouter network of QTFY-controlled devices. QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers. QTRouter then serves as an 'obfuscation network' – meaning it allows QTFY and other malicious cyber actors to conceal the PRC-origin of their computer intrusion activities because the malicious communications appear to originate from computers (such as those compromised by QScan) that are outside of the PRC and may even be local to the targeted networks."
Researchers publish analysis of OpenAI agents' attack against Hugging Face.
Researchers at METR have published the results of their independent investigation into last month's cyberattack against Hugging Face by OpenAI's autonomous agents. The incident began when isolated OpenAI agents were given impossible tasks in ExploitGym, a testing benchmark designed to evaluate how well AI models can exploit real-world vulnerabilities. When the agents realized the tasks were impossible, they began looking for ways to cheat and eventually broke isolation and gained access to a message board with about 1,200 other AI agents. METR says these agents sent over 70,000 messages and files to each other during the investigation period, and 700 of the agents later participated in the attack against Hugging Face.
METR explains, "Agents used this message board to coordinate several large-scale collective projects to find a general-purpose way to fool or tamper with the automated scorer for the ExploitGym benchmark. Agents managed to achieve milestones they could not have achieved working on their own, often because some agents participated in experiments that risked failing their own task to generate information for the 'collective.' The Hugging Face attack grew out of these workstreams, and seemed primarily motivated by understanding the implementation of the scorer rather than stealing answer keys."
Australian police arrest two suspected TeamPCP members.
The Australian Federal Police (AFP) have arrested two alleged members of the TeamPCP cybercriminal group, KrebsOnSecurity reports. The two men, aged 21 and 23, were arrested in Western Australia with assistance from the Western Australia Police Force (WAPF) and intelligence from the US Federal Bureau of Investigation (FBI).
TeamPCP is a financially motivated threat actor known for conducting software supply chain attacks against popular developer tools such as TanStack, Trivy, and LiteLLM. The AFP said in a press release, "It is estimated the malicious code potentially compromised more than 1000 organisations globally, enabling the theft of more than 500,000 credentials, and the exfiltration of at least 300 gigabytes of data. The alleged compromise of a small number of trusted software components had a significant global impact. To date, the financial impact includes global remediation costs estimated to be hundreds of millions of dollars."
The White House bans certain foreign-made power equipment over backdoor risks.
President Trump on Wednesday signed an executive order banning the use of certain foreign-made technology in bulk power systems, the Record reports. The order states, "The minimal restrictions on acquisition or operation in the United States of foreign-produced bulk-power system electric equipment augment the ability of some foreign entities to create and exploit vulnerabilities in such equipment; for instance, such equipment might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely. Further, continued United States reliance on foreign sources of bulk-power system electric equipment with these potential national security vulnerabilities also creates a supply chain vulnerability that could eliminate the supply of these products in the United States as a result of disruptions in international trade or other causes."
The Defense, Commerce and Energy Departments will review transactions, identify potentially risky equipment already in use, and develop plans to isolate, monitor or replace it. Officials also have 120 days to establish regulations and identify countries warranting particular scrutiny.
Separately, POLITICO reports that the Trump administration plans to announce a program to provide free cybersecurity services to US water facilities, led by the Office of the National Cyber Director. A source told the publication that the program will begin as a "proof of concept" in Texas before expanding to other states. The initiative would enlist private cybersecurity companies to provide the services.
Slovakia finds Russian backdoors on traffic speed cameras.
Slovakia's national security service, the NBU, found Russian backdoors on hundreds of newly installed speed cameras, Tom's Hardware reports. The NERO R-ONE cameras are believed to be rebranded CORDON PRO.M traffic cameras purchased through a Cyprus-based shell company. CORDON PRO.M cameras are manufactured by a Russian company called "Semicon." The NBU says the cameras contain a hardcoded list of Russian phone numbers that can open a backdoor connection via an SMS message.
The Slovak Ministry of the Interior has deactivated the cameras and is bringing in an independent auditor to verify the NBU's findings. Risky Business notes that similar issues may affect cameras used in Croatia and other Eastern European countries.