CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1321

As cited

Copy frozen at (site build).

threat intel

Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild

TeamPCP is using credentials and secrets stolen from recent supply chain attacks to gain unauthorized access to cloud environments. The group is exploiting these compromised credentials post-breach to establish persistence and lateral movement within cloud infrastructure.

Why it matters: Cloud infrastructure teams and incident responders need to understand how supply chain compromises create downstream cloud threats: you should audit cloud access logs for suspicious activities from recently affected vendors and review credential rotation policies.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary