Archive
Every brief we've published. Most recent first.
Wednesday 22 July 2026
SharePoint's 9.8-Severity Flaw Is Already Being Weaponised — Here's What You Need to Know
A critical SharePoint flaw is being actively exploited just days after a public proof-of-concept dropped — and it's not the only thing defenders need to worry about today.
Tuesday 21 July 2026
An AI Agent Just Hacked the World's Biggest AI Repository — and Other AIs Couldn't Stop It
An autonomous AI agent hacked Hugging Face — the very platform that hosts the world's AI models — and frontier LLMs couldn't stop it.
Monday 20 July 2026
Someone Was Inside SonicWall VPNs for Weeks Before the Vulnerabilities Were Even Public
SonicWall VPN appliances were silently owned for weeks before anyone knew there was a bug — and the unknown attacker behind it is still being traced.
Sunday 19 July 2026
Any Anonymous Request Can Now Own Your WordPress Site — Here's the Bug
A critical WordPress core flaw with a public proof-of-concept is exposing every unpatched 6.9 and 7.0 site to unauthenticated remote code execution — and the clock is ticking.
Saturday 18 July 2026
NadMesh Is Hunting Your Exposed AI Stack for Cloud Keys — and It's Already Got Thousands
A botnet is systematically harvesting AWS keys and cloud tokens from exposed AI tools — and it already claims nearly 4,000 unique credentials.
Friday 17 July 2026
Qantas Leaked 5.7 Million People's Data Via a Phone Scam — and Faced Zero Formal Consequences
A tech support scam exposed 5.7 million Qantas passengers' data — and Australia's privacy watchdog just let the airline walk away clean.
Thursday 16 July 2026
Australia Just Promised the World's First Legally Binding AI Standards. Here's What That Actually Means.
Australia's Prime Minister just promised the world's first legally binding AI and data centre standards — and the clock is ticking.
Wednesday 15 July 2026
622 Patches in One Day: Microsoft's AI Vulnerability Machine Is Running Hot
Microsoft's AI-powered vulnerability scanner just broke its own record — twice in two months — and two of the 622 flaws are already being exploited in the wild.
Tuesday 14 July 2026
Russia's FSB Attacked Poland's Power Grid. Now Europe Is Hitting Back With Sanctions.
The EU and UK formally blamed Russia's FSB for attacking Poland's power grid — then hit back with the West's first joint cyber sanctions package.
Monday 13 July 2026
Meta Killed Its New AI Image Feature Before Most People Even Knew It Existed
Meta pulled an AI image feature within days of launch after a privacy backlash, Toll Group rethinks third-party data risk, and China fires missiles during joint Australia-US wargames — here's what actually matters today.
Sunday 12 July 2026
A Poisoned npm Package Dropped a Rust Infostealer Before Anyone Had Time to Blink
A poisoned npm package dropped a cross-platform infostealer on install — and the supply chain security story is even wilder than the attack itself.
Saturday 11 July 2026
Apple vs OpenAI: The Trade Secret Lawsuit That Could Reshape Silicon Valley's Talent Wars
Apple sues OpenAI for trade secret theft, a vishing campaign hijacks Microsoft 365 via fake passkey enrolment, and Europe's Chat Control 2.0 surveillance law finally passes — here's what actually matters today.
Friday 10 July 2026
GPT-5.6 Gets the Government Greenlight — But Nobody Knows What That Really Means
OpenAI's GPT-5.6 clears a government safety review and lands in Microsoft 365 Copilot the same day — the approval process is as newsworthy as the model itself.
Thursday 9 July 2026
A Clock Hiccup Brought Down Telstra's Mobile Network. Hundreds of Welfare Checks Followed.
A timekeeping glitch took down Telstra's mobile network, stranding trains and triggering hundreds of welfare checks — and it's a sharp reminder of how fragile critical infrastructure really is.
Wednesday 8 July 2026
The Critical Gitea Flaw Attackers Are Already Exploiting — With a Single HTTP Header
A critical flaw in Gitea is being actively exploited in the wild, Britain is building an autonomous AI cyber defence system, and enterprise AI deployments are quietly racking up security incidents — here's what matters today.
Tuesday 7 July 2026
A 16-Year-Old Bug in Linux's Hypervisor Can Let a Virtual Machine Escape to the Host
A 16-year-old Linux hypervisor flaw lets guest VMs break out to the host — and a proof-of-concept is already public.
Monday 6 July 2026
The End of the Human Cloud: Amazon Shuts the Door on Mechanical Turk
Amazon is killing Mechanical Turk's new customer intake, banks are still making MFA optional, and the AI unicorn count hits 90 — here's what actually matters today.
Sunday 5 July 2026
North Korea's Supply Chain Playbook Just Got a Lot Bigger
North Korea's PolinRider campaign seeded 108 malicious packages across npm, Go, Packagist, and Chrome — and it's still running.
Saturday 4 July 2026
The Spyware Investigator Who Became the Spied-Upon
A European politician was hacked with the exact spyware he was supposed to be investigating — and Citizen Lab has the forensics to prove it.
Friday 3 July 2026
The First Fully Autonomous AI Ransomware Attack Is Here — and It Worked
An AI agent just ran a ransomware attack from start to finish — no human required — and the security industry is still working out what that means.
Thursday 2 July 2026
Hackers Got Into the US Government's Sensitive Information-Sharing Network. That's a Big Deal.
Hackers breached HSIN — the US government's sensitive homeland security information-sharing network — and the implications stretch well beyond American borders.
Wednesday 1 July 2026
Meta Hired Fake Teens to Stress-Test Its Rivals' Chatbots — and That Should Bother Everyone
Meta secretly sent contractors posing as teenagers to probe rival AI chatbots on suicide, drugs, and sex — and the story raises uncomfortable questions about competitive intelligence, ethics, and AI safety testing.
Tuesday 30 June 2026
Someone Just Dumped a Live Zero-Day Arsenal on the Internet — and Attackers Are Already Using It
An anonymous researcher dropped a repo of live zero-days, Oracle's PeopleSoft flaw keeps claiming new victims, and Bendigo Bank races to build Australia's first AI-powered security operations centre.
Monday 29 June 2026
China Reclaims the World's Fastest Supercomputer — and the Export Controls Didn't Stop It
China's LineShine supercomputer just dethroned the US's El Capitan — despite years of chip export controls — while Australia quietly doubles down on online safety enforcement and Woolworths turns its loyalty chatbot into an AI agent.
Sunday 28 June 2026
Fake "Support" Texts, Real Credential Theft: Russia's FSB Was Reading Your Messages
Russia's FSB ran a fake-support SMS campaign to hijack messaging accounts of officials across Ukraine, Europe, and the US — and the SSU/FBI joint disclosure is a masterclass in how modern credential theft actually works.
Saturday 27 June 2026
The White House Blinked First on GPT-5.6 — and OpenAI Is Unhappy About It
OpenAI drops GPT-5.6 under a White House shadow — and the precedent that comes with it matters more than the model.
Friday 26 June 2026
Pre-Positioned and Patient: Nation-State Actors Are Already Inside Australian Critical Infrastructure
Nation-state hackers have already burrowed into Australian critical infrastructure — and they're waiting for the right moment to flip the switch.
Thursday 25 June 2026
OpenAI's "Jalapeño" Chip Is the Moment It Stops Renting Its Own Brain
OpenAI's first custom silicon, a macOS security gap anyone can exploit, and a coordinated takedown of two major malware-as-a-service operations — plus Australia's health sites caught covertly tracking patients.
Wednesday 24 June 2026
Australia Is Retiring the Essential Eight — Here's What Comes Next
Australia's Essential Eight is being retired — and the replacement signals a fundamental rethink of how the ASD frames cyber defence.
Tuesday 23 June 2026
Five Eyes to Defenders: AI-Powered Attacks Are Months Away, Not Years
The Five Eyes issued their starkest AI-cyber warning yet, OpenAI deployed GPT-5.5-Cyber against real bugs, and the Klue hack kept widening — here's what actually matters today.
Monday 22 June 2026
The Boot Key Deadline Nobody Told You About: Windows and Linux Have 48 Hours
Your PC's boot keys expire in 48 hours, Suncorp puts AI agents on insurance claims, and a fresh botnet turns thousands of D-Link routers into a criminal proxy network.
Sunday 21 June 2026
North Korea Poisoned the AI Supply Chain — and Mastra Was Just the Start
North Korea's Sapphire Sleet poisoned 140+ npm packages inside the Mastra AI framework — and the AI supply chain just became the new software supply chain crisis.
Saturday 20 June 2026
usbliter8: The Unpatchable iPhone Exploit That Will Never Get a Patch
A working unpatchable BootROM exploit for millions of iPhones drops, Western Australia deploys real-time facial recognition, and Microsoft's AutoJack attack turns AI agents into remote code execution vectors.
Friday 19 June 2026
Accenture's $4.1 Billion OT Security Bet Is the Biggest Signal Yet That Critical Infrastructure Is the Next Cyber Frontier
Accenture drops $4.1 billion to own the OT security market, the 'Popa' botnet turns TV boxes into a proxy crime empire linked to a Nasdaq-listed firm, and cybercrime now accounts for a third of all crime across Asia and the Pacific.
Thursday 18 June 2026
FortiBleed: 73,000 Fortinet Credentials Dumped — and Yours Might Be Among Them
Tens of thousands of Fortinet firewalls have had their credentials stripped bare, a Queensland sugar mill is counting the cost of a mid-harvest cyberattack, and G7 leaders are quietly panic-buying sovereignty from American AI.
Wednesday 17 June 2026
The SearchLeak Flaw: How a Critical Microsoft Copilot Bug Turned 2FA Into a Liability
A critical flaw in Microsoft Copilot let attackers silently steal users' 2FA codes — and it's the latest proof that LLM security is still being bolted on as an afterthought.
Tuesday 16 June 2026
UNC6508: China's Quiet Year Inside Medical and Military Research Networks
A year-long Chinese espionage campaign quietly drained medical, military, and AI research from North American networks — and the tool they weaponised was hiding in plain sight.
Monday 15 June 2026
Beijing Vetoes Meta's $2B Manus Deal — and the Geopolitical Playbook Just Changed
Beijing ordered Meta to tear up a $2 billion AI deal — and it sets a precedent every Western tech company needs to study.
Sunday 14 June 2026
Washington Pulls the Plug on Anthropic's Best Models — and the Precedent Is Bigger Than the Models
The US government ordered Anthropic to pull its two most powerful AI models offline worldwide — and the backstory involves Amazon's CEO, a disputed jailbreak, and a precedent that should worry every AI lab on the planet.
Saturday 13 June 2026
SpaceX's Historic IPO Makes Musk the World's First Trillionaire — and Rewrites the Tech Power Map
SpaceX goes public, Elon Musk becomes the world's first trillionaire, and a Chinese cybercrime ring weaponised Google's own AI to run a phishing-as-a-service empire.
Friday 12 June 2026
ShinyHunters' Oracle PeopleSoft Zero-Day: 100+ Orgs Breached Before a Patch Existed
ShinyHunters exploited a silent Oracle PeopleSoft zero-day for two weeks before Oracle even knew it was public, hitting 100+ organisations — and Australia's government just quietly signalled it wants telcos and cloud providers to start blocking threats upstream.
Thursday 11 June 2026
Cyberattack Hits Australia's Second-Largest Sugar Producer Mid-Harvest
A cyberattack has shut down Australian sugar mills mid-harvest, while CISA shrinks the federal patching window to three days, and Anthropic's new flagship model is already causing friction everywhere from cybersecurity labs to Microsoft's own offices.
Wednesday 10 June 2026
Patch Tuesday from Hell: 206 Microsoft Fixes, a Chrome Zero-Day, and a Veeam RCE Land on the Same Day
Microsoft's record-breaking 206-vulnerability Patch Tuesday collides with a Chrome zero-day and a Veeam RCE flaw — defenders, your patching queue just got very long.
Tuesday 9 June 2026
The Worm That Ate Microsoft's GitHub: How 73 Packages Became a Trap for AI Developers
Microsoft's own GitHub repos were hijacked to spread credential-stealing malware targeting AI developers — and the Miasma worm that did it is still shapeshifting.
Monday 8 June 2026
The "Tokenpocalypse" Is Here: AI Just Got More Expensive, and It's Going to Keep Getting Worse
AI companies are eyeing IPOs and quietly hiking token prices — and the era of cheap AI may already be over.
Sunday 7 June 2026
The AI Bug Hunter That Found 21 Zero-Days in the Library Inside Everything
An AI agent found 21 zero-days in FFmpeg — the media library hiding inside almost every piece of software that touches video — while Google quietly patched a record 429 bugs in Chrome in the same week.
Saturday 6 June 2026
Cisco's SD-WAN Problem Is Now a Pattern, Not an Incident
Cisco's seventh SD-WAN zero-day of 2026 is being actively exploited with no patch in sight — and the World Food Programme breach just put 600,000 vulnerable Gazan families' data in the wrong hands.
Friday 5 June 2026
The $0 AI Worm: Why the Threat Doesn't Need a Frontier Model
Researchers proved you don't need a fancy frontier model to build a self-spreading AI worm — a free open-source LLM will do just fine.
Thursday 4 June 2026
When Your Notifications Become the Attacker's Keyboard
A poisoned notification from WhatsApp or Slack could hijack Google Gemini's voice assistant — no malicious app required.
Wednesday 3 June 2026
Trump's AI Executive Order Is Mostly a Handshake — and That Might Be the Point
Trump signs a watered-down AI executive order, Anthropic opens its most powerful model to 150 critical infrastructure operators, and a one-line Microsoft code flaw put billions of Android downloads at risk.
Tuesday 2 June 2026
When the Support Bot Becomes the Attacker's Best Friend
Meta's AI support chatbot handed hackers the keys to high-profile Instagram accounts — and it's the clearest sign yet that AI-powered customer service is a security product, not just a convenience one.
Monday 1 June 2026
Dutch Police Dismantle a 17-Million-Device Botnet — and It's a Timely Reminder of How Big "Big" Really Is
Dutch police tear down a 17-million-device botnet, a WordPress plugin is handing strangers the keys to your site, and Nvidia's Jensen Huang takes the Computex stage with Microsoft ARM ambitions in tow.
Sunday 31 May 2026
Russia's Sanctions-Busting Tech Grab Is Now a Cyber Problem, Not Just a Trade One
Russian intelligence is running an aggressive global tech-acquisition campaign as sanctions bite, Microsoft is threatening researchers over zero-day disclosures, and a Palo Alto VPN flaw just moved from "patch soon" to "actively exploited."
Saturday 30 May 2026
The AI-Assisted Hack: When the LLM Does the Post-Breach Heavy Lifting
An attacker used an LLM agent to automate post-breach cloud credential theft — and it's the clearest sign yet that AI is changing what happens after the initial compromise, not just before it.
Friday 29 May 2026
Anthropic Is Worth Almost $1 Trillion. Here's Why That Number Is Doing a Lot of Heavy Lifting.
Anthropic closes a $65 billion Series H at a $965 billion valuation — and drops a new model the same day, because why not.
Thursday 28 May 2026
The Extortion Gang That Skips the Phishing Email and Walks Through the Front Door
Ransomware crews are now showing up at law firm offices in person — and Australia's court transcription offshore scandal shows the tactic isn't as far-fetched here as it sounds.
Wednesday 27 May 2026
The "BadHost" Bug Hiding Inside Millions of AI Agents
A critical flaw in the Starlette web framework — 325 million weekly downloads — puts millions of AI agents at risk of server-side request forgery, and Iran's internet is flickering back to life after a 90-day blackout.
Tuesday 26 May 2026
Three Supply Chain Attacks at Once: GitHub, npm, PyPI, and Crates.io Are All on Fire
The Megalodon supply chain attack has infected 5,500+ GitHub repos via fake automated commits — and it's running alongside at least two other simultaneous package-poisoning campaigns.
Monday 25 May 2026
A Decade-Old Linux Kernel Flaw Just Got a Very Unwanted Comeback
A decade-old Linux privilege escalation bug resurfaces, Ghost CMS is under active mass exploitation, Amazon's always-on AI wearable raises hard privacy questions, and CBA's AI is doing the 2am on-call shift so engineers don't have to.
Sunday 24 May 2026
Anthropic's AI Just Found 10,000 Critical Bugs. The Vulnerability Economy Will Never Be the Same.
Anthropic's AI found 10,000 critical software flaws in a month — and that changes the economics of vulnerability research forever.
Saturday 23 May 2026
Inside the Week Law Enforcement Tore Down the Cybercrime Infrastructure Stack
Law enforcement dismantled a criminal VPN used by 25 ransomware groups, arrested a Kimwolf botnet operator, and seized 800 servers from a bulletproof hoster — a rare good week for the takedown scoreboard.
Friday 22 May 2026
AI-Assisted Kernel Exploit Lands on Apple Silicon — and It Won't Be the Last
An AI model helped find and exploit a kernel memory corruption bug in Apple's M5 chip — and TeamPCP's supply chain attack spree has now claimed GitHub, npm, and hundreds more organisations in its wake.
Thursday 21 May 2026
One Bad Extension, 3,800 Repos: The GitHub Breach That Indicts the Entire Developer Tooling Ecosystem
A poisoned VS Code extension breached 3,800 GitHub internal repositories — and it's a masterclass in how supply chain attacks now eat the ecosystem from the inside.
Wednesday 20 May 2026
The Cobbler's Children: CISA Left Its Own Credentials in a Public GitHub Repo for Six Months
CISA — America's cyber defence agency — left SSH keys, plaintext passwords, and AWS credentials in a public GitHub repo for six months, and Congress wants answers.
Tuesday 19 May 2026
No Patch, Active Exploitation: Microsoft Exchange Zero-Day Hits OWA Mailboxes
A zero-day in Microsoft Exchange is being actively exploited with no patch in sight — and today's brief covers a Windows SYSTEM-privilege exploit, a pre-Stuxnet nuclear sabotage tool, Anthropic's quiet SDK land-grab, and a Victorian phone scammer who finally got two years.
Monday 18 May 2026
Grafana's Source Code Was Stolen and Used as Leverage — Here's What Actually Happened
Grafana's codebase was downloaded by an attacker who then tried to extort the company — and a new phishing kit is bypassing MFA to hijack Microsoft 365 accounts at scale.
Sunday 17 May 2026
Secret Blizzard's Kazuar Grows Up: Russia's Most Patient Backdoor Is Now a P2P Botnet
Secret Blizzard's Kazuar backdoor has evolved into a modular P2P botnet — and a critical NGINX flaw just got a public exploit while Microsoft quietly buried an Azure vulnerability report without a CVE.
Saturday 16 May 2026
ChatGPT Wants Your Bank Login: OpenAI's Personal Finance Play Is the Biggest Trust Bet in AI Yet
ChatGPT wants access to your bank account — and the Musk v. Altman trial just wrapped up asking whether we should trust the people building this stuff.
Friday 15 May 2026
Cerebras Cracks the Market: AI Chip Darling's $5.5B IPO Is the Shot in the Arm the Tech Listings Market Needed
Cerebras goes public at double the price, Cisco fires 4,000 while posting record revenue, and a Foxconn ransomware hit signals manufacturing's worsening cyber crisis — Friday's brief has range.
Thursday 14 May 2026
The Bug-Finding Machine: How AI Rewrote Patch Tuesday
AI is now finding bugs faster than humans can patch them — and this week's Patch Tuesday is the proof.
Wednesday 13 May 2026
The Worm That Signed Its Own Warrants: Mini Shai-Hulud's Six-Minute Supply Chain Blitz
A self-propagating supply chain worm tore through npm and PyPI in minutes, poisoning packages from TanStack, Mistral AI, and others — and it was signed.
Tuesday 12 May 2026
The First AI-Written Zero-Day Just Got Caught in the Wild
Google caught the first confirmed AI-generated zero-day in the wild — and it was heading for a mass 2FA-bypass event before anyone got hurt.
Monday 11 May 2026
Bleeding Llama: The Ollama Flaw That Could Leak Your Entire AI Server's Memory
A critical memory-leak vulnerability in Ollama threatens 300,000+ AI servers globally — and the attackers abusing Claude.ai to spread Mac malware just reminded us that AI platforms are now the attack surface.
Sunday 10 May 2026
The AI Trust Problem: How a Fake OpenAI Repo Gamed Hugging Face and Won
A fake OpenAI repo hit Hugging Face's trending list and delivered infostealer malware — proving that AI's most trusted platforms are now prime real estate for supply chain attacks.
Saturday 9 May 2026
275 Million Students, One Breach, Zero Good Timing: The Canvas Catastrophe
ShinyHunters brings down Canvas for 9,000 schools right before finals — and the data they're holding over Instructure's head is far more sensitive than a list of email addresses.
Friday 8 May 2026
When Your AI Coding Agent Becomes the Attacker: The TrustFall Vulnerability
AI coding agents are becoming a supply chain attack vector — and the tools you trust most may be the easiest to compromise.
Thursday 7 May 2026
Palo Alto's Unpatched Firewall Zero-Day Is Being Exploited Right Now
A Palo Alto PAN-OS zero-day with a 9.3 CVSS is being actively exploited — and there's still no patch.
Wednesday 6 May 2026
Australia Builds the Review Board America Threw Away
Australia just launched its own Cyber Incident Review Board — modelled on the US body the Trump administration quietly disbanded — and the timing couldn't be more pointed.
Tuesday 5 May 2026
Five Eyes to Enterprises: Your Agentic AI Is Running Ahead of Your Security
Five Eyes agencies warn agentic AI is moving faster than enterprise safety controls — and that's the least of today's problems.
Monday 4 May 2026
When Your Antivirus Breaks Your Certificates: Microsoft Defender's DigiCert False Positive
Microsoft Defender's false-positive storm is quarantining legitimate DigiCert certificates across Windows fleets — and the US military just signed seven AI companies onto classified systems.
Sunday 3 May 2026
Trellix Got Hacked. Yes, the Cybersecurity Company.
A cybersecurity vendor getting hacked is always awkward — and Trellix's source code breach is the kind of story that makes defenders question the tools they trust.
Saturday 2 May 2026
DDoS Meets Extortion: Pro-Iran Group Holds Ubuntu.com Hostage
A pro-Iran hacktivist crew turned a DDoS against Canonical into a ransomware-style shakedown — and kept Ubuntu.com dark for over 24 hours during a critical patch window.
Friday 1 May 2026
cPanel's Zero-Day Was Live for Months Before Anyone Said a Word
A critical cPanel authentication bypass has been exploited in the wild since February, OpenAI follows Anthropic in locking down its most dangerous AI cyber tool, and the Linux "Copy Fail" flaw is shaking multi-tenant infrastructure everywhere.
Thursday 30 April 2026
Claude Mythos Found 271 Firefox Zero-Days. Let That Sink In.
Anthropic's Claude Mythos AI model found 271 zero-days in Firefox — and that changes what "vulnerability research" means forever.
Wednesday 29 April 2026
One Git Push to Own GitHub: CVE-2026-3854 Is the RCE Flaw Defenders Need to Patch Now
A critical GitHub RCE flaw lets any authenticated user pop a shell with one git push — and that's just the start of a busy day in security.
Tuesday 28 April 2026
OpenAI Breaks Up With Microsoft — Exclusively
OpenAI severs its exclusive Microsoft cloud tie, the 15-year-old OpenSSH root flaw finally surfaces, and a forgotten malware framework just rewrote the history of cyber sabotage.
Monday 27 April 2026
Itron Breach Puts Utility Infrastructure Security Back Under the Microscope
Itron's breach puts critical utility infrastructure in the spotlight, while Apple navigates the post-Cook era and robots learn to stop hurting themselves.
Sunday 26 April 2026
Before Stuxnet, There Was 'fast16': Researchers Uncover a Lost Chapter of Cyberwarfare History
A pre-Stuxnet sabotage framework surfaces, Google bets $40B on Anthropic, and a new Teams-based malware campaign is quietly emptying inboxes.
Saturday 25 April 2026
The Firewall That Became the Front Door: FIRESTARTER Backdoor Survives on Federal Cisco Devices
A firewall backdoor that outlasts patches, Google bets $40B on Anthropic, DeepSeek closes the frontier gap, and a pre-Stuxnet sabotage tool gets its first public autopsy.
Friday 24 April 2026
Anthropic Locked Down Its Most Dangerous AI. Then It Leaked Anyway.
Anthropic's Claude Mythos escaped its own containment, OpenAI shipped GPT-5.5, and a supply chain attack quietly poisoned the Bitwarden CLI — welcome to your Friday.
Thursday 23 April 2026
The npm Worm That Spreads Itself: Supply Chain Attacks Just Got Scarier
A self-replicating worm is quietly colonising npm; ransomware gangs are experimenting with post-quantum crypto; and SpaceX just offered $60 billion for an AI coding tool.
Wednesday 22 April 2026
Lazarus Group Pulls Off $290M KelpDAO Heist in Sophisticated Infrastructure Attack
North Korea's Lazarus Group steals $290M from KelpDAO, a Scattered Spider ringleader pleads guilty, and Anthropic's new cyber model is already sparking a CEO spat.
Tuesday 21 April 2026
Tim Cook Is Out. What Happens to Apple Now?
Tim Cook announces his exit from Apple, Anthropic's Mythos model lands at the NSA, and a supply-chain hack at Context.AI cascades into a breach at Vercel — a busy 24 hours across tech and security.
Monday 20 April 2026
ShinyHunters Claims Vercel Breach via Compromised AI Tool
Vercel's breach traces back to a compromised AI tool, NIST quietly retreats from scoring low-priority CVEs, and AI vendors shrug off prompt injection as a feature — busy Monday.
Sunday 19 April 2026
Proof-of-Concept Published for Critical RCE Bug in protobuf.js — Patch Now
A critical RCE flaw in protobuf.js puts millions of JavaScript apps at risk, Grinex blames spies for a $13.7M hack, and Cerebras files for an IPO.