Robin’s Newsletter #406

29 March 2026. Volume 9, Issue 13
TeamPCP software supply-chain attacks widen, target Iran with crude wiper. US bans foreign-made routers. FBI director Kash Patel email's compromised.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

Tim and I posted a 5 minute video round-up of RSAC 2026, covering our thoughts on the cyber security market and insights from the expo hall, which you may find interesting.

This week

Need to Know, 29th March 2026

  • LiteLLM compromised via TeamPCP/Trivy supply chain attack
  • TeamPCP goes to war with Iran
  • Iran-linked Handala nabs FBI director Kash Patel’s personal emails
  • US FCC bans ‘foreign-made’ wi-fi routers
  • Anthropic is holding back its latest model over cyber exploit concerns

Interesting stats

1.5x faster patch time for Macs than Windows devices, and  8.1x faster for iOS over Android, according to Omnissa.

Zero people using Lockdown Mode have been compromised with mercenary spyware, since the feature was introduced four years ago, according to Apple.

Five things

  1. TeamPCP/Trivy/LiteLLM: It’s got worse for users of Aqua Security’s Trivy vulnerability scanner, as the security firm acknowledged the TeamPCP attackers had regained access in an updated blog post. The malicious software steals credentials and authentication tokens and injects itself into other software packages. It’s unclear what the group’s ultimate aim is, beyond harvesting as many credentials as possible. Ultimately, the supply-chain attack managed to compromise LiteLLM, a popular Python package used to communicate with AI services, which could affect thousands of companies. While LiteLLM dealt with the issue in just over two hours, daily downloads are around 3 million. The self-propagating nature of TeamPCP’s malware is not dissimilar to the Shai-Hulud worm seen in the second half of 2025. Targeting continuous integration/deployment (CI/CD) pipelines is a way to rapidly scale their infection, especially since many developers pull the latest version of a given package each time.

  2. TeamPCP’s Wiper: Not content with software supply chain compromises, TeamPCP also fancies inserting itself into the US/Israel—Iran war. If their most recent malware detects that the timezone or locale on a victim’s machine is set to Iran, it will act as a crude wiper. Matching Iran and finding Kubernetes, then the script tries to wipe every node in the cluster; if no Kubernetes is found, it runs a good ol’ fashioned rm -rf to delete the hard drive’s contents. It’s not sophisticated stuff.

  3. Kash Patel: Handala, and Iran-linked threat group, compromised the personal gmail account of FBI director Kash Patel. Confirming the breach, an FBI spokesperson was quick to point out that this was Patel’s personal email, and that the agency had “taken all necessary steps to mitigate potential risks associated with this activity”. The photographs and email released by the group date up to 2019, and it’s unclear if that’s when they lost access or if they are keeping more recent information for themselves at present. Presumably, the intent is to embarrass the US government and show that they are not out of reach. The FBI is offering up to $10 million in rewards for information relating to Handala, who has also been linked to the breach of US medical device manufacturer Stryker. 

  4. Router Ban: The US Federal Communications Commission has moved to ban all routers “produced in a foreign country” over security fears. The Departments of Defense and Homeland Security are able to grant exceptions. It’s a step up from previous bans, such as Huawei from telco networks, or concerns over Chinese ownership of consumer brands like TP-Link. The new rules will require manufacturers to register with the FCC and manufacture their products in America. Netgear, a US-headquartered firm that manufactures overseas, for example, will have to apply for approval. If you have a foreign-manufactured device, it’s fine, no need to throw it away. The concern here is that there are millions of these devices — essentially in every home — that foreign powers may use in attacks against the US: Chinese firms are obliged to report vulnerabilities to the Chinese state before wider disclosure. Changing that balance won’t happen overnight and will, ultimately, result in higher prices for US consumers.

  5. Mythos: Anthropic accidentally leaked the name and some capabilities of its newest artificial intelligence model after human error resulted in draft website content being accessible to the internet. The post describes Mythos (or Capybara) as “by far the most powerful AI model we’ve ever developed.” No surprise there: newer, better models are being released all the time. What’s raising eyebrows are paragraphs where Anthropic worries about the cyber security implications, because Mythos is “currently far ahead of any other AI model in cyber capabilities,” and “it presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders.” Cyber stocks dropped following the news, with Tenable faring worse, dropping 9%.

In brief

And finally

Robin
  Iran TeamPCP Software Supply-Chain Kash Patel Sovereignty Artificial Intelligence (AI) Wiper