
Weaponizing Trust: The TeamPCP Campaign and the Age of Cascading Failure
About this episode
The cyber threat landscape is experiencing a massive paradigm shift, as adversaries move away from isolated network breaches to industrialize the compromise of global digital supply chains. This episode breaks down the unprecedented March 2026 TeamPCP campaign, exploring how attackers weaponized the trusted Trivy vulnerability scanner, compromised the widely used LiteLLM AI package, and unleashed the self-propagating Shai-Hulud worm across the npm ecosystem. We also examine how the growing use of artificial intelligence by threat actors, the exploitation of unmonitored edge devices, and the rise of destructive wiper attacks against critical infrastructure are forcing organizations to adopt zero-trust models and continuous resilience strategies.
https://breached.company/litellm-supply-chain-attack-teampcp-trivy-pypi-2026
https://compliancehub.wiki/delve-compliance-startup-fake-soc2-audit-scandal
Sponsors:
Get every episode summarized
Each time CISO Insights: Voices in Cybersecurity publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from CISO Insights: Voices in Cybersecurity

Wear Your Firewall: Gadgets, Gear, and Hacker Culture
CISO Insights: Voices in Cybersecurity

Unlocking the Compliance Stack: AI Drafting, Premium Templates, and Do-It-Yourse...
CISO Insights: Voices in Cybersecurity

CISO DIY: Building the Sovereign AI Security Department
CISO Insights: Voices in Cybersecurity

Beyond the Checkbox: The $12 Billion Fight to Redesign the Teen Internet
CISO Insights: Voices in Cybersecurity