Connect with us

Tech

Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others

Published

on

Australian police have arrested two people in Perth accused of being members of TeamPCP, a prolific hacking group blamed for high-profile hacks against big tech giants in recent months. The two have been charged with more than a dozen hacking, money laundering, and other cybercrime offenses and are expected in court later on Thursday.

According to a statement by the Australian Federal Police, the two men are accused of widespread breaches involving the compromise and tampering of popular open-source projects. The hackers aimed to infect a large number of computers to steal credentials and data, then extort victims into paying a ransom.

The FBI’s cyber division chief Brett Leatherman was quoted as saying that the two alleged members of TeamPCP are accused of hacking into more than a thousand organizations as part of their attacks.

It’s unclear whether the Justice Department plans to seek extradition, and a spokesperson for the FBI did not immediately comment when contacted by TechCrunch.

TeamPCP is a prolific cybercriminal gang known for several widespread hacking campaigns targeting the software supply chain, in which the hackers would break in and maliciously modify a popular open-source software tool used by potentially thousands of companies.

Once installed on a company’s or developer’s systems, the malicious code steals their private keys and other sensitive credentials used to access cloud storage systems and, oftentimes, customer data. The authorities said the hackers stole more than half a million credentials to further their attacks into other companies.

The hackers were blamed for a cyberattack on the popular vulnerability scanner tool Trivy, which affected any company that relied on it, including LiteLLM, AI recruiting startup Mercor, and others. The hackers are also suspected of breaching the European Commission’s cloud infrastructure, as well as targeting other open source projects and developer apps that allowed access to tech giants like GitHub and OpenAI.

a photo of australian police walking with one of the alleged TeamPCP hackers in handcuffs
Image Credits:Australian Federal Police

The Australian officials said their investigations began in April 2026 after receiving information from multiple cybersecurity companies.

Police have not named the men who were arrested, but independent cybersecurity journalist Brian Krebs exclusively reported that one of the now-arrested alleged hackers is Ruben Thomson, who goes by the hacker handle Ellis. Krebs reported Thursday that he was in contact with Ellis over the past several months, and the hacker told Krebs that he was the leader of TeamPCP until March 2026.

Krebs said Ellis made mistakes that allowed the journalist to learn the alleged hacker’s real identity.

During a press conference on Wednesday announcing the arrests, Australian officials said they had also seized a large quantity of allegedly stolen data, as well as devices and other electronics from the hackers. The officials said they planned to notify victims of the attacks.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Claude Opus 4.6 Found a Gym API Flaw — Then Exploited It in 9 of 10 Tests

Published

on

An AI agent found a shortcut through a vulnerable gym booking API — and used it. A new controlled test suggests the behavior was reproducible.

Security firm Aikido reported Aug. 25 that Claude Opus 4.6, running through the OpenClaw agent framework, bypassed a simulated gym’s booking-window restriction in nine of 10 test runs. In two runs, the agent also canceled another synthetic user’s reservation through a missing authorization check.

The experiment recreated an incident involving Australian software developer Andrew Bird that drew wider attention in August. As AI assistants gain access to sensitive systems, weak permissions and backend controls can give unintended actions consequences far beyond the interface an employee normally sees. Organizations deploying agents therefore need security controls at the API and identity layers, not just restrictions in the agent’s instructions.

How Aikido recreated the gym booking hack

Aikido built a synthetic gym booking application around two vulnerabilities described in reports of Bird’s experience. Researchers connected an April 2026 build of OpenClaw, version 2026.4.1, running Claude Opus 4.6 and completed 10 conversations totaling 1,130 messages and tool calls.

The test was modeled on an incident ABC News reported Aug. 10. Bird first asked his OpenClaw assistant to book a gym class. After the agent found a way to book farther ahead than the interface allowed, Bird — then fourth on a waitlist — asked whether it could move him higher. The agent canceled the top waitlisted member’s reservation without being told to do so, moving Bird from fourth to third.

In Aikido’s simulation, the one-week booking limit existed only in the website interface, while direct API requests were not subject to it. Claude used the weakness in nine runs, including five after the first user message.

The more serious flaw involved reservation ownership. The simulated cancelReservation function did not verify that the logged-in user owned the reservation being canceled. Claude exploited it in two runs, although Aikido said researchers never explicitly instructed the model to exploit a vulnerability.

Other evaluations have raised related concerns. In August, UK researchers reported unsanctioned actions by Anthropic and OpenAI agents during deliberately permissive cybersecurity tests, although those models operated under different conditions.

Weak API controls give agents room to act

The missing ownership check matches what OWASP calls Broken Object Level Authorization, or BOLA, the No. 1 risk in its 2023 API Security Top 10. OWASP recommends authorization checks on every endpoint that receives an object ID and acts on that object.

Server-side controls should cover operations that read, modify or delete data rather than relying on restrictions in a website interface. Organizations deploying agents should also use narrowly scoped credentials and approval gates for consequential actions, controls that become increasingly important as agents operate across connected workplace apps.

Anthropic documented a related behavioral risk before releasing Opus 4.6 on Feb. 5. Its Opus 4.6 system card said the model could at times become “overly agentic” in coding and computer-use settings, taking risky actions without first seeking permission.

Aikido tested one OpenClaw build against one synthetic application, and the setup did not enable Claude’s thinking tokens. The researchers said additional reasoning would likely increase refusals, so the results should not be generalized to Claude or AI agents broadly. The underlying API weaknesses remain conventional security problems regardless of whether the caller is a person, script or agent.

Read more: A recent AI safety test that accidentally reached real company systems shows why autonomous agents need enforced access boundaries rather than scope defined only by prompts or labels.

>

Continue Reading

Tech

This Refurbished Apple Watch SE Just Dropped to $89.99

Published

on

TL;DR: Get a 40mm Apple Watch SE 1 (2020) for $89.99 (reg. $249), with GPS, heart rate monitoring, fall detection, and 18-hour battery life.

An Apple Watch has become one of the most useful pieces of tech for professionals who need to stay connected but don’t want to be tethered to their phone all day. The Apple Watch SE, Apple’s entry-level model, provides the core functionality the platform is known for, IE: notifications, health tracking, GPS, and Apple Pay, at a fraction of the cost. Right now, a Grade B refurbished Apple Watch SE 1 (2020) 40mm is available for $89.99 (reg. $249), a 63% discount.

Stay connected without reaching for your phone

When paired with a compatible iPhone (6s or later), the Apple Watch SE can handle calls, texts, navigation, and Siri directly from your wrist. For anyone who spends a lot of time in meetings or away from their desk, the ability to receive notifications without picking up your phone is a massive productivity boost. Apple Pay is built into the device, and so is Apple Music, so you can leave your phone behind entirely during workouts.

Health and fitness tracking built for daily use

The optical heart sensor monitors heart rate continuously throughout the day, while Activity Rings track movement, exercise, and standing time. Workout tracking helps you monitor your walking, running, cycling, swimming, yoga, and HIIT, and the watch is water-resistant up to 50 meters. Fall Detection and Emergency SOS are also included, both of which are increasingly valued in workplace safety, particularly for employees in physically active environments.

Hardware worth knowing about

Under the hood, Apple’s S5 chip keeps things running, and the Retina OLED display is bright enough to read clearly outdoors. It connects via GPS, Wi-Fi, Bluetooth, and NFC, and covers the basics without any setup headaches. The aluminum case is light enough that you’ll forget you’re wearing it, and with up to 18 hours of battery life, it can easily make it through a full workday on a single charge.

What to know about the refurbished grade

This watch has a Grade B rating, meaning it may have light scuffing on the bevel or case and minor cosmetic wear on the body, but nothing that would affect performance. The screen has no scratches, and battery health is a minimum of 70%. A 30-day parts-and-labor warranty is included, with optional 1-year ($19.99) or 2-year ($24.99) extended coverage available at checkout. For under $90, the Apple Watch SE delivers a well-connected, capable wearable that holds its own for both professional and personal use.

Get a refurbished Apple Watch SE 1 (2020) for $89.99 (reg. $249).

StackSocial prices subject to change.

>

Continue Reading

Tech

Google’s AI Mode can now track flight prices, help book hotels, and more

Published

on

Google is adding new ways for users to plan and book trips through AI Mode, its conversational search experience, the company announced on Thursday. Users will now be able to ask AI Mode to track flight prices, book hotels, and see the cost of flights and hotels in points or miles.

The updates indicate that Google is looking to position AI Mode as an AI travel agent of sorts, as it’s moving beyond simply helping users find information to actually handling parts of the trip-planning and booking process itself. 

Users can now describe to AI Mode when and where they want to fly, and the tool will display the best options available with the latest prices from more than 300 airlines and travel sites. If they’re ready to book, they can go ahead and build their itinerary in AI Mode. If they want to wait and see if prices drop, they can ask something like “track these flight prices for me.”

Image Credits:Google /

They’ll then get an email if prices change for the destination and dates they entered. Flight price tracking in AI Mode is now available in more than 180 countries.

As for hotel booking, users will be able to discover and book their next hotel through a conversation with AI Mode. Users can tell AI Mode about their upcoming trip and their hotel preferences to get a list of options alongside reviews and key factors.

Once they’ve found a hotel they like, they can ask AI Mode to help complete the booking. Then, they need to select the “Continue on Google” option that will appear alongside Google’s integrated partners, which includes hotel chains and travel sites.

From there, they can choose their room, review details such as the cancellation policy, and complete the booking with Google Pay. The tech giant notes that the hotel or booking platform will handle the booking and any customer service.

Image Credits:Google /

Hotel booking in AI Mode has started rolling out in the U.S. in English and will be available over the coming weeks with offerings from Booking.com, Choice Hotels International, Expedia, Hilton, Hotels.com, IHG Hotels & Resorts, Marriott International, Priceline, Trip.com, and Wyndham Hotels & Resorts.

Google also announced that AI Mode can now display the cost in points or miles for flights and hotels by asking something like “I want to travel from Atlanta to Miami using my AA miles. Help me find some options for nonstop flights departing Oct 9 and returning on Oct 12”.

Users will then see how many miles they need to book matching flights. The update is now available globally.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.