Category: News

Current, event-driven reporting, announcements and industry developments.

  • Australian Police Charge Two Men Over TeamPCP Hacking Group Linked to Open-Source Supply Chain Breaches

    Australian Police Charge Two Men Over TeamPCP Hacking Group Linked to Open-Source Supply Chain Breaches

    The Australian Federal Police, working with the FBI and the Western Australia Police Force, arrested and charged two Perth-area men on August 26, 2026 over their alleged roles in TeamPCP, a cybercrime group blamed for a string of high-profile breaches this year. Louis Michael Gaebler, 23, of Mandurah, and Ruben Ian Thomson, 21, of Cottesloe, appeared in Perth Magistrates Court on August 27 facing a combined 14 charges, according to the AFP and reporting from TechCrunch, The Hacker News and Help Net Security.

    Investigators allege the pair were principal participants in a syndicate that planted malicious code in popular open-source software projects, which was then unwittingly incorporated by developers and organizations worldwide, according to the AFP statement cited by ABC News Australia. The Hacker News reported that TeamPCP has been tied to the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM, while TechCrunch reported the group has also been blamed for hacks affecting Mercor and OpenAI.

    According to Help Net Security’s account of the charges, the Cottesloe man faces eight offenses including possessing and supplying data for use in computer offenses, unauthorized modification of data, failing to comply with a data-access order, and dealing with proceeds of crime worth more than AU$100,000; the maximum penalties involved range from three to twenty years’ imprisonment. Investigators searched properties in Cottesloe, Hamilton Hill and Mandurah, seizing electronic devices now undergoing forensic examination.

    The AFP said the investigation began in April 2026 after it and the FBI received tips about a syndicate inserting malicious code into open-source packages used by other developers, and that “further arrests and charges have not been ruled out” as the forensic review of seized data continues, per SecurityWeek’s reporting.

    The case highlights the continuing risk that open-source software supply chains pose as a vector for widescale compromise: a single tampered dependency or scanning tool can propagate into the environments of every organization that pulls it into a build pipeline, a dynamic security teams have increasingly had to account for in software composition analysis and dependency-vetting programs.

  • Denmark Selects Terma to Build Nationwide Counter-Drone Defense System

    Denmark Selects Terma to Build Nationwide Counter-Drone Defense System

    A Shared National Drone Picture

    Denmark’s Ministry of Defence Acquisition and Logistics Organisation (DALO) announced on August 19, 2026 that it has selected Danish defense contractor Terma to deliver an integrated, nationwide command-and-control system for counter-drone defense. The system will connect existing and future sensors operated by the Danish Armed Forces, civilian authorities and critical infrastructure operators into a single shared drone situational picture, according to Terma.

    “To defend ourselves, we need to be able to eliminate enemy drones in our airspace,” Danish Defense Minister Jeppe Bruus said of the contract. Terma said the platform will support the management of drone incidents at military installations, airports, ports, energy facilities, government buildings and other critical infrastructure sites, and that its architecture is designed to allow additional sensors, sites and countermeasures to be integrated over time.

    Built on Terma’s Helion Data Backbone

    The system is based on Terma Helion, the company’s multi-domain data backbone, and will integrate command-and-control and data-fusion software from OSL Technology, which Terma acquired in 2025. The combined platform uses artificial intelligence to process, classify and prioritize sensor data, fusing input from radar, other surveillance systems and third-party sensors to support tactical decision-making at both local and central command levels.

    “This new agreement with Terma is an important cornerstone in the ongoing effort to build a strong counter-drone capability, both within the Danish Armed Forces and Danish industry,” said Lieutenant General Per Pugholm Olsen, chief of DALO. The contract comes as European states have grown increasingly concerned about unauthorized drone activity near military sites, airports and other critical infrastructure. Terma and DALO did not disclose the contract value.

    Sources

  • DHS Awards Department-Wide Contracts for Counter-Drone Capabilities

    DHS Awards Department-Wide Contracts for Counter-Drone Capabilities

    A Common Acquisition Pathway Across DHS

    The Department of Homeland Security announced on August 5, 2026 that it has made multiple contract awards to support department-wide access to Counter-Unmanned Aircraft Systems (C-UAS) capabilities. The awards give DHS components a common pathway to acquire C-UAS hardware, software and services tailored to fixed-site, mobile, aviation, maritime, aircraft-based and special-mission environments, according to the department’s Science and Technology Directorate.

    “These awards mark an important step in strengthening DHS’s ability to respond to unauthorized and malicious unmanned aircraft systems,” said Homeland Security Secretary Markwayne Mullin. “By taking a Department-wide approach, we are improving mission readiness, supporting more consistent capabilities, and helping ensure DHS personnel have access to the right tools for the job.”

    Replacing Fragmented Procurement

    DHS components have historically procured C-UAS capabilities through separate acquisition efforts. The new contract structure is intended to support greater consistency, interoperability, operational flexibility, technology refresh and lifecycle management across the department, while still letting individual components select solutions aligned to their specific missions. The awarded contracts cover detection, tracking, classification, identification, mitigation, command-and-control integration, training, maintenance, technical support, system integration, research and development, test and evaluation, and vendor-operated turnkey services.

    “As unmanned aircraft systems become more capable and more widely available, DHS needs solutions that can adapt,” said Under Secretary for Science and Technology Pedro Allende. Components expected to use the contract include the U.S. Secret Service, U.S. Coast Guard, Customs and Border Protection, Immigration and Customs Enforcement, the Transportation Security Administration, FEMA, the Federal Protective Service, U.S. Citizenship and Immigration Services, and the Science and Technology Directorate itself. DHS did not disclose specific contract values or awardee names in its announcement.

    Sources

  • Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

    Johnson Controls Metasys Building Automation Platform Patches Persistent XSS Vulnerability

    Crafted URL Can Hijack Administrator Sessions

    CISA published ICS advisory ICSA-26-225-14 on August 13, 2026, disclosing a cross-site scripting vulnerability in Johnson Controls Metasys, a building automation and management platform used across critical manufacturing, commercial facilities, government facilities, transportation systems and energy sites worldwide. Tracked as CVE-2026-34491 and rated CWE-79, the flaw carries a CVSS v3 base score of 8.0.

    According to CISA, a low-privilege user can inject a malicious payload into the Metasys web interface through a crafted URL. The payload persists across logins and executes in the browser context of other users who view the affected page, including administrators, which could lead to session hijacking and unauthorized access to building systems. The advisory lists Metasys 12 and 13 as affected in all versions, and Metasys 14 before v14.1.5 and Metasys 15 before v15.0.1.

    Mitigation

    Johnson Controls has released patched versions for the affected Metasys 14 and 15 branches and published mitigation guidance for the platform. CISA recommends operators apply the available updates, restrict Metasys web interface access to trusted networks, and follow standard input-validation and session-management hardening for building management system deployments.

    Sources

  • Siemens Patches Critical Remote Code Execution Flaw in Siveillance Video Management Servers

    Siemens Patches Critical Remote Code Execution Flaw in Siveillance Video Management Servers

    Command Injection Rated Critical

    CISA published ICS advisory ICSA-26-225-09 on August 13, 2026, describing a critical vulnerability in Siemens Siveillance Video, a video management platform deployed worldwide across the critical manufacturing, communications and commercial facilities sectors. Tracked as CVE-2026-3014 and rated CWE-78 (OS Command Injection), the flaw affects Siveillance Video V2023 R3 versions before 23.3.27, V2024 R1 versions before 24.1.16, and V2025 versions before 25.1.15, with a CVSS v3 base score of 9.1.

    According to the advisory, a user with edit permissions on the Management Server can exploit the flaw to execute arbitrary code in the context of the Management Server service, which could allow an attacker to take control of connected video management infrastructure.

    Updates Available for All Affected Branches

    Siemens has released fixed versions for each affected release branch: V23.3 HotfixRev27 or later, V24.1 HotfixRev16 or later, and the V25.1.15 update for the 2025 branch. CISA and Siemens recommend that operators update to the corrected versions as soon as practical and, in line with general ICS hardening guidance, restrict Management Server edit permissions to trusted administrators and segment video management infrastructure from untrusted networks.

    Sources

  • CISA Details Credential Exposure Flaw in Johnson Controls Simplex Incident Manager

    CISA Details Credential Exposure Flaw in Johnson Controls Simplex Incident Manager

    Cleartext Credentials Found in Memory

    The Cybersecurity and Infrastructure Security Agency published ICS advisory ICSA-26-232-01 on August 20, 2026, disclosing a vulnerability in Johnson Controls Simplex Incident Manager, a fire and life-safety incident-management application used across critical manufacturing, commercial facilities, government facilities, transportation systems and energy sites worldwide. Tracked as CVE-2026-27875, the flaw stores user credentials, including passwords and authentication tokens, in an unencrypted form in system memory while the application is running.

    CISA assigned the vulnerability a CVSS v3.1 base score of 5.8 (medium), rating it CWE-316, Cleartext Storage of Sensitive Information in Memory. A local attacker with low privileges, or an insider with memory-dumping tools, could extract the exposed credentials and use them for unauthorized access to the application and connected systems. Exploitation requires local access to the host, and CISA rates the attack complexity as high.

    Patch Available

    Johnson Controls has released version v2.01.01 to address the flaw and published Product Security Advisory JCI-PSA-2026-28 with mitigation guidance. CISA and the vendor recommend upgrading affected Simplex Incident Manager deployments (v2.01 and earlier), restricting local system access to authorized personnel, deploying endpoint monitoring to detect memory-dumping activity, enforcing least-privilege access controls, and using full-disk encryption and secure boot to reduce the risk of offline memory analysis.

    Johnson Controls reported the vulnerability to CISA. No public evidence of active exploitation has been disclosed.

    Sources

  • Flock Safety Cuts License-Plate Data Retention to Seven Days Amid Surveillance Backlash

    Flock Safety Cuts License-Plate Data Retention to Seven Days Amid Surveillance Backlash

    New Guardrails Announced Amid Growing Criticism

    Flock Safety, which operates a nationwide network of more than 119,000 automated license-plate-reader (ALPR) cameras used by law enforcement agencies, announced a set of privacy and accountability reforms on August 13, 2026, according to Fox Business. The changes come as the company faces mounting criticism from privacy advocates and elected officials over mass surveillance concerns and reports of officers misusing the technology, including cases documented by Wired in which police reportedly used Flock data to track romantic partners.

    Flock CEO Garrett Langley discussed the changes publicly, telling Fox Business’s “Varney & Co.” that the reforms were a direct response to backlash the company has faced over its car-tracking cameras. Some local officials have gone further than criticism: Knox County, Tennessee, Mayor Glenn Jacobs has called for a national moratorium on further deployment of Flock’s camera network, according to Fox Business.

    Shorter Retention, Mandatory Audit Controls

    The centerpiece of the announcement is a reduction in Flock’s standard data-retention window from 30 days to seven. The company said that roughly 90% of all searches conducted on its platform already occur within a week of data capture, arguing the shorter window would have limited practical effect on law enforcement’s ability to use the system while narrowing the amount of location data stored on Flock’s servers at any given time. For cases requiring longer retention, Flock is introducing an “Evidence Mode” feature that lets agencies preserve specific data for extended periods under state or local policy.

    Flock is also making its “Audit Assistance” feature — which flags abnormal search behavior and can lock a user out of the system in real time pending administrator review — mandatory for all law enforcement customers rather than optional; the company said roughly a third of agencies had turned the feature on voluntarily before the change. Separately, Flock is making the previously optional requirement to log a case code with every search mandatory going forward, with an override reserved for emergencies such as missing-child cases. “A search without a reason is a search that shouldn’t happen in the first place, and now Flock’s system automatically treats it that way,” the company told Fox Business.

    New Controls Over Cross-Agency Data Sharing

    The company is also giving individual agencies more granular control over which types of cases they will share camera search access for with other jurisdictions. In comments to Fox Business, Flock gave the example that “City A could allow City B to search its cameras for a stolen vehicle or violent crime while blocking searches related to immigration enforcement” — an option aimed at addressing concerns that Flock’s interconnected camera network could be used for purposes individual municipalities have not authorized.

    Civil liberties groups were not satisfied by the announcement. The American Civil Liberties Union said in a statement reported by Fox Business that the reforms “seem to be a thinly veiled PR attempt to counter communities’ genuine privacy concerns with its mass surveillance system with largely hollow security promises, rather than an earnest effort to address them.” Flock, for its part, has pointed to its own figures on the technology’s investigative use, telling Fox Business that its cameras were involved in roughly 1 million investigations last year and were tied to the location of about 10,000 missing people — figures that reflect the company’s own reporting and have not been independently verified.

    Sources

  • UK and Ukraine Sign AI Defense Partnership Granting Access to Ukraine’s Avengers AI Labs

    UK and Ukraine Sign AI Defense Partnership Granting Access to Ukraine’s Avengers AI Labs

    Britain and Ukraine signed a partnership in Kyiv on Monday, August 24, 2026, to jointly develop artificial intelligence tools for defense and security, with the UK becoming the first international partner granted access to Ukraine’s Avengers AI Labs battlefield-data platform, according to Reuters and a UK government statement.

    A Battlefield Dataset Built From Ukraine’s War

    UK Prime Minister Andy Burnham and Ukrainian President Volodymyr Zelenskyy signed the agreement, which the UK government describes as part of the two countries’ “100 Year Partnership.” Avengers AI Labs is built around an annotated dataset of roughly 5 million battlefield images, according to Ukraine’s Defence Ministry, drawn largely from the DELTA combat management and situational-awareness system. The platform aggregates data from cameras and sensors deployed across Ukraine’s front lines, capturing tanks, artillery, air-defense systems, infantry and aerial targets including Shahed drones and reconnaissance UAVs, which is used to train AI models that the UK government says currently identify a majority of targets in real time.

    Under the deal, Britain will in turn back Ukraine with access to its universities, researchers and technology companies, which the UK government describes as the world’s third-largest AI ecosystem. The agreement initially focuses on defense and national-security applications, bringing together engineers, academics, businesses and military operational experts from both countries.

    Fiber-Optic Sensing and Low-Power AI Chips Among First Pilot Projects

    Three British startups — Bristol-based Sintela, Oxford-based Mind Foundry, and London-based Skyral — are involved in the initial pilot projects announced alongside the partnership. The first project turns buried fiber-optic cables into a distributed AI-enabled sensor system, initially being trialed at a UK defense site to detect protesters and hostile actors attempting to gather intelligence; UK officials say the same approach could later extend to protecting airports, prisons, railways and energy plants. A second pilot project will explore low-power AI chips designed for future drones, robotics and autonomous systems.

    The AI agreement was announced alongside a separate decision by the UK to let defense contractor MBDA release classified information on UK-made components for the SCALP long-range missile, enabling local assembly lines in Ukraine. UK Defence Secretary Wes Streeting and AI Minister Kanishka Narayan both framed the AI partnership as part of a broader push to convert Ukraine’s wartime operational data into long-term technology and national-security capability for both countries.

    Sources

  • Denver Police to Let ShotSpotter Gunshot-Detection Contract Expire After a Decade

    Denver Police to Let ShotSpotter Gunshot-Detection Contract Expire After a Decade

    City Will Phase Out Acoustic Sensors by Year’s End

    The Denver Police Department says it will let its contract for ShotSpotter gunshot-detection technology expire at the end of 2026, ending more than a decade of automated gunfire alerting in the city, according to CBS Colorado and Denver7 reporting on the department’s August 20-21, 2026 announcement. The system uses acoustic sensors mounted on utility poles to detect the sound of gunfire and alert Denver’s 911 dispatch center, often before a human caller reports a shooting. Denverite reported the city’s contract with SoundThinking, the company behind ShotSpotter, is worth roughly $4.7 million and expires at the close of the year.

    Rather than an abrupt shutdown, DPD says it will begin removing sensors from areas generating the fewest alerts first, with most of the network remaining active through the rest of 2026. According to Denver7, the department said it is evaluating “whether a new vendor can provide greater public safety benefits” and plans to launch a bidding process to assess alternative gunshot-detection capabilities while gathering community input on how to reallocate resources. As part of the initial ramp-down, DPD said it will begin phasing out ShotSpotter coverage specifically in the Sun Valley and Park Hill neighborhoods.

    A Decade of Data on Alerts, Arrests and Recovered Firearms

    In its release announcing the change, the department said that from 2020 through June 2026 the program generated 25,217 alerts, leading to 655 arrests and the recovery of 721 firearms, according to CBS Colorado. Officers also located shell-casing evidence tied to 6,672 of those alerts. Denver’s decision comes amid what Denver7 described as broader nationwide scrutiny of police gunshot-detection and surveillance technology, as cities weigh the systems’ operational value against their cost and questions about alert accuracy and community impact that have been raised in other jurisdictions.

    What Happens Next

    City officials have not yet named a preferred replacement vendor or detailed the criteria for the planned bidding process. The wind-down gives Denver several months to evaluate alternative gunshot-detection platforms and to solicit public feedback before the current sensor network is fully retired, according to the reporting from Denver7 and Denverite.

    Sources

  • Nvidia Makes Minority Investment in Data-Center Power Developer Cloverleaf

    Nvidia Makes Minority Investment in Data-Center Power Developer Cloverleaf

    Nvidia has made a minority investment in privately held Cloverleaf Infrastructure, a company that arranges power and site infrastructure for AI data-center projects across the United States, the companies said on Friday, August 21, 2026, according to Reuters.

    Chipmaker Moves Further Upstream Into Power

    Financial terms of the investment were not disclosed, but the Wall Street Journal reported the same day, citing people familiar with the deal, that Nvidia was expected to invest up to several hundred million dollars. Cloverleaf works with utilities, energy providers and investors to secure power and other infrastructure for data-center sites, and the company says it has delivered multiple gigawatt-scale projects across North America since its founding in 2024. As part of the arrangement, Cloverleaf will deploy Nvidia’s DSX platform to help optimize decisions on site selection, power, cooling and computing infrastructure for the data centers it develops.

    J.P. Morgan Securities served as exclusive financial advisor and Kirkland & Ellis as legal counsel to Cloverleaf in structuring the deal, according to trade publication POWER.

    Part of a Broader Pattern of Financing Data-Center Buildout

    The Cloverleaf investment came just days after Nvidia announced a separate $1.5 billion investment in SoftBank-owned SB Energy to support the PORTS-Pike technology campus, a 10-gigawatt, OpenAI-linked data-center project in Pike County, Ohio. Nvidia CEO Jensen Huang said of that earlier deal that “AI is becoming infrastructure — the foundation for intelligence in every industry — and land, power and shell have become vital.” Taken together, the two deals illustrate how Nvidia has begun taking a more direct role in financing and developing the data centers that ultimately buy its AI computing systems, rather than simply supplying chips to third-party developers. Power availability, rather than chip supply, has increasingly become the binding constraint on how quickly new AI data-center capacity can come online.

    Sources