Attackers Borrowed ChatGPT's Reputation to Deliver Malware
Strip this attack down and almost none of it is new. Malvertising, a fake captcha, a copy-paste powershell lure, a remote access trojan at the end. Except one brick. One front door was a ChatGPT custom GPT hosted on OpenAI's own domain. The real exploit was borrowed reputation, not the malware.
Arresting One Hacker Does Not Kill a Collective
Dutch police arrested a 24-year-old in the ShinyHunters investigation, and the case looks less like a clean win the closer you read it. The evidence tying him to the breaches is a reused alias and a disputed voice, against a collective that has no membership and publicly laughed off the arrest.
One Login Cost Bitget US$388 Million
Bitget lost US$388 million, and not one line of its crypto was broken. No stolen keys, no smart-contract flaw. Attackers exploited a zero-day in a third-party security product, walked in with valid admin credentials, and moved the money out disguised as routine operations.
Why I Finally Left the iPhone for Android
For almost eighteen years, my primary phone was never really a decision. It was an iPhone. Now it is a Samsung, and not because Android is better. In plenty of ways it is not. It became the phone my hand keeps reaching for, and working out why turned into something worth writing about.
Cyber Crime Put AI on the Payroll
Gambit Security cracked the staging server behind a card-theft campaign and found the AI crime story that actually arrived. One operator rented open-source AI agents to break into 119 online retailers and steal more than 600,000 credit cards, for roughly $25 a target.
Cyber Crime Does Not End at the Intrusion
Everyone treats the attack as the event. The phishing email, the ransomware, the stolen keys. But financially motivated cyber crime does not end at access. The money still has to move, and the blockchain keeps a permanent record of where it went.
AI Performance Theater Is Scarier Than AI Rebellion
OpenAI disclosed six cases of its own models misbehaving, and two are a different beast. The models did not just overreach. They concealed. One hunted a stolen API key, failed, then fabricated the answer and claimed it was real. Another wrote notes telling its future self to hide its mistakes.
Knowing About a Threat Is Not the Same as Stopping It
Threat intelligence works at three levels, tactical, operational, and strategic, and it is genuinely valuable at all three. But it never closed the gap between a signal arriving and a defender acting on it. That gap was tolerable for years. AI just made it fatal.
Revolut Says No One Demanded a Ransom, the Internet Disagrees
A group claiming the Revolut breach demanded US$3 million in Monero, with a 24-hour countdown clock, and never once contacted Revolut directly. The demand was public from the start. That is the inversion worth noticing. The pressure was not a private negotiation. It was everyone else watching.
Russia Built a Factory for Hackers That Just Leaked
Everyone tracks Fancy Bear and Voodoo Bear like weather systems. A leak just exposed the hidden Russian university department that manufactures them, a military cyber academy funneling graduates straight into GRU units. You cannot sanction a curriculum. The war was decided in the admissions office.
Your Biggest Data Leak Is an Employee Being Helpful
Check Points August data shows ransomware nearly doubled year-over-year. But the sharper number is not about attackers at all. It is about employees pasting customer records, financial data, and legal documents into chatbots, across seven AI tools per company, one helpful prompt at a time.
OpenAI Agents Committed a Crime With No Criminal
In May, a swarm of AI agents flooded a package registry with 2,000 malicious uploads, gained code execution on a third partys servers, and scraped UK government data. The agents belonged to OpenAI. Nobody can say whether it was an attack or an accident, not even the company that built them.
China and AI Scared the NSA Into Tearing Itself Apart
The NSA is rebuilding around five mission centers, and two of them are China and AI. The largest spy agency on earth does not organize itself around minor threats. The categories it chose are a threat assessment in the only language an intelligence agency speaks plainly.
Wall Street Just Found a Way to Short the Apocalypse
The AI threat everyone has read about all year just became a stock trade. CrowdStrike jumped 14% in a day, the whole sector rallied, and the trigger was not a breach. It was fear. The threat is real. The defense is real. And the same fear that fills my posts now fills their earnings calls.
Nobody Broke Into Revolut, They Just Asked
Revolut handed a stranger its customers passports, selfies, and full transaction histories. Nobody broke in. A fraudster asked, using a legitimate government email domain, and Revolut said yes. No hack, no exploit, just an email and a lie, and the trust a bank extends to anything official.
Facebook Lies to Your Lock Screen to Make You Tap
Facebook sent me a push notification saying someone replied to my comment. Nobody did. The real event, sitting in the app, was a stranger commenting on a group photo. The push had rewritten it into something personal, on iOS and Android both. The error only ever breaks one way, toward the tap.