<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Criminal-Prosecution on CuraSec</title><link>https://curasec.metacog.co.kr/tags/criminal-prosecution/</link><description>Recent content in Criminal-Prosecution on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/criminal-prosecution/index.xml" rel="self" type="application/rss+xml"/><item><title>TeamPCP Supply Chain Hackers Charged in Australia</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-alleged-teampcp-hackers-charged-in-australia-over-major-supp/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-alleged-teampcp-hackers-charged-in-australia-over-major-supp/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The underlying March 2026 compromise of Trivy, Checkmarx KICS, and LiteLLM should have already triggered audits; this arrest adds no new technical detail, but serves as a reminder to verify those security scanner pipelines were cleaned and dependency provenance checked at the time.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> An arrest announcement with no new IOCs or TTPs published; useful as campaign context if the March supply chain incident is already in your threat intel library, but yields no new detection or hunt work today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Confirms attribution and partial closure of a supply chain attack on widely-used DevSecOps tooling — a useful case study for board or risk-committee discussions on open-source software supply chain risk and the adequacy of your vendor/tooling provenance controls.&lt;/li>
&lt;/ul></description></item><item><title>Snowflake Hacker Pleads Guilty; 165 Orgs and 100M Records Exposed</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-snowflake-hacker-pleads-guilty-over-breaches-affecting-at-le/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-snowflake-hacker-pleads-guilty-over-breaches-affecting-at-le/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The guilty plea closes the loop on a major credential-based cloud breach campaign; review whether your org&amp;rsquo;s Snowflake tenant MFA and network policies would have detected or blocked the access patterns used in 2024.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A high-profile conviction in a breach affecting 100M people and 165 orgs is useful context for board discussions on cloud vendor risk and credential-based attack exposure; no immediate action required unless your org was among those affected.&lt;/li>
&lt;/ul></description></item></channel></rss>