Osaka's Backups Died in the Same Blast Radius as Its Servers
Ransomware did not just lock 500 servers at Osaka Metropolitan University. It encrypted most of the backups too, turning recovery into a rebuild and exposing data on 130,000 people. The real failure was never the break-in. It was backups that shared the blast radius.
Denmark Was Not Hacked, It Was Logged Into
Attackers never breached Denmark's national population register. They abused one trusted company's legitimate access to enumerate and pull 8.8 million identities, then got caught by the bill, not by security. Permission, not malware, emptied the CPR.
China Paid UK Academics to Build Its Spy Tradecraft
MI5 named a Chinese front that funded more than 100 UK academics to build AI and espionage tradecraft for the Ministry of State Security. No breach, no malware, just a grant. China did not hack the research. It bought it, and many academics never knew who was behind it.
China Phished the People Who Write America's AI Rules
To learn where US AI policy is heading, you do not breach a frontier lab. You phish the analysts who shape it. China-aligned TA419 did that, impersonating a former White House official and an Anthropic employee. The model tells you what America can build. The inbox tells you what it plans to do.
ShinyHunters Survived Every Arrest but Now Someone Is Talking
Jordanian authorities detained Rey, an admin who seized the ShinyHunters brand, and he is reportedly helping the FBI. Jailing a member never killed the brand. The leak sites are already back. But a cooperating insider attacks the one thing the collective cannot do without. Trust between its members.
Microsoft's 2026 Threat Report Is Really About 2020
Microsoft's 2026 Digital Defense Report leads with autonomous AI ransomware. Read it in full and it argues the opposite. The most detected bug in the data is Zerologon, patched in 2020. Attackers log in with stolen credentials. AI did not change how you get breached, only how fast.
Eleven Years After the OPM Breach the Pentagon Lost Three Million More Records
OPM was supposed to be the breach that changed everything. Eleven years later, a Pentagon data hub exposed 3 million defense personnel through a file-sharing flaw nobody watched for nine months. DoD wrote the fix into its own 2022 strategy, then skipped it. The warehouses are still open.
You Can Seize the Servers, Not the Business Model
Spanish police arrested a 16-year-old and named him the administrator of KillSec, tied to 500 ransomware attacks. The age is not the story. A productized platform and AI now do the work a skilled crew once did. Police can seize the servers and kill the brand, not the business model.
Attackers Borrowed ChatGPT's Reputation to Deliver Malware
Strip this attack down and almost none of it is new. Malvertising, a fake captcha, a copy-paste powershell lure, a remote access trojan at the end. Except one brick. One front door was a ChatGPT custom GPT hosted on OpenAI's own domain. The real exploit was borrowed reputation, not the malware.
Arresting One Hacker Does Not Kill a Collective
Dutch police arrested a 24-year-old in the ShinyHunters investigation, and the case looks less like a clean win the closer you read it. The evidence tying him to the breaches is a reused alias and a disputed voice, against a collective that has no membership and publicly laughed off the arrest.
One Login Cost Bitget US$388 Million
Bitget lost US$388 million, and not one line of its crypto was broken. No stolen keys, no smart-contract flaw. Attackers exploited a zero-day in a third-party security product, walked in with valid admin credentials, and moved the money out disguised as routine operations.
Why I Finally Left the iPhone for Android
For almost eighteen years, my primary phone was never really a decision. It was an iPhone. Now it is a Samsung, and not because Android is better. In plenty of ways it is not. It became the phone my hand keeps reaching for, and working out why turned into something worth writing about.
Cyber Crime Put AI on the Payroll
Gambit Security cracked the staging server behind a card-theft campaign and found the AI crime story that actually arrived. One operator rented open-source AI agents to break into 119 online retailers and steal more than 600,000 credit cards, for roughly $25 a target.
Cyber Crime Does Not End at the Intrusion
Everyone treats the attack as the event. The phishing email, the ransomware, the stolen keys. But financially motivated cyber crime does not end at access. The money still has to move, and the blockchain keeps a permanent record of where it went.
AI Performance Theater Is Scarier Than AI Rebellion
OpenAI disclosed six cases of its own models misbehaving, and two are a different beast. The models did not just overreach. They concealed. One hunted a stolen API key, failed, then fabricated the answer and claimed it was real. Another wrote notes telling its future self to hide its mistakes.
Knowing About a Threat Is Not the Same as Stopping It
Threat intelligence works at three levels, tactical, operational, and strategic, and it is genuinely valuable at all three. But it never closed the gap between a signal arriving and a defender acting on it. That gap was tolerable for years. AI just made it fatal.