China Did Not Steal American AI, It Interrogated It
NSA, CISA, and FBI accused six Chinese firms of extracting billions of tokens from Claude, ChatGPT, Gemini, and Grok to train competing models. It is the same playbook China ran on jet engines and semiconductors, now aimed at Silicon Valley's crown jewels. The theft looks exactly like ordinary use.
FalconFlank Turns the Bodyguard Into the Burglar
A researcher published a working exploit turning CrowdStrike Falcon, the software meant to protect a Windows machine, into a privilege escalation tool by abusing Falcon's macro cleanup feature. There is no exploit in the wild, and a mitigation exists. The same researcher hit other vendors too.
Slim Spider Steals the Keys the Cloud Hands Out for Free
A month after PLUMP SPIDER, CrowdStrike named a second Brazilian crew: Slim Spider, and this one is not faking transfers. It is stealing cryptocurrency custody keys straight out of the cloud, by learning to look like something the cloud already trusts. The perimeter never mattered. The token did.
You Bought a Screen, LG Installed a Microphone That Never Sleeps
A $70k investigation found LG OLED TVs capturing clear microphone audio in standby, storing it even with the ethernet unplugged, and mapping every device and wifi network around them. The mic cannot be turned off at the hardware level. And LG's denial is carefully worded around one specific phrase.
Four Dollars Is All the AI Costs to Break Into Your Company
An affiliate of The Gentlemen ran an automated AI pipeline that broke into 30-plus companies, stole 3.1TB, and wrote the ransom demands itself. The AI cost per victim was as little as 40 cents. That is not the whole operation, but it is the part that used to take a skilled human days.
A Human Set the Goal, AI Did the Breach in 10 Hours
A ransomware operator used frontier AI to break into an enterprise network and seize root in under 10 hours, work normally taking a human red team two weeks. No zero-day, no novel malware, just known techniques at machine speed. The one thing stopping it was a control forcing a human to sign off.
Your ATM Was Encrypted, Until It Was Not
A researcher found nine ways to strip the encryption off some ATMs, including a fail state that mounts the disk in plaintext. The flaws are patched. The unsettling part is where else this software hides, buried in products across banking, healthcare, and government that may never know it was broken.
McKesson Was Breached by a Phone Call, Not a Zero-Day
ShinyHunters claims 284 million patient records stolen from McKesson, which moves a third of North America's prescriptions. Read that carefully: records, not patients. McKesson confirmed a breach, not the number. The healthcare data now sits behind a login a convincing voice can open.
PLUMP SPIDER Makes the Bank Rob Itself
Most financial ecrime is theft. PLUMP SPIDER does something worse. This Brazil-based crew gets inside the bank's own software and pushes fraudulent transfers through the real payment rails, in a real customer's name, so the fraud looks exactly like a legitimate transaction.
You Never Chose the Company That Just Leaked Your Face
More than 153 million driver's license records are allegedly for sale on the dark web for US$100, traced to an identity verification vendor most victims never heard of. You cannot change your face or your date of birth. Lawmakers want to make this exact model mandatory to use the internet.
OpenAI Built an AI Capable of Finding and Exploiting Flaws on Its Own
OpenAI says its upcoming Astra model can find unknown security flaws and write working exploits on its own, no human guiding each step. Treat the self-reported claim skeptically. But the direction is now corroborated across labs and real breaches, and that part is not up for debate.
Your Car Got Hacked Because It Is a Computer Nobody Was Watching
The first known malware built for car dashboards did not go after your brakes. It hijacked the update button, turned the head unit into a botnet node, and rented out your car's internet connection for ad fraud. The car was never the point. The always-on computer inside it was.
Dyson Put a Beautiful Camera in Your Mouth and a Trap in Your Bathroom
Dyson's $499 AI toothbrush is genuinely clever engineering, and also a networked lens in the most private room in your home, an unaudited privacy claim, a fresh attack surface, and a razor-and-blades model built backwards. All of it is true at once.
You Whitelisted the Malware Yourself
A China-nexus group hid a full-control backdoor inside a real Chinese wallpaper app, the kind of harmless adware nobody takes seriously. That is exactly why it worked. The disguise was so convincing the ads never even ran, and that was the tell that gave it away.
The Most Dangerous Intrusion Is the One That Turns the Alarms Off
Most attackers try not to get caught. Fire Ant breaks in, then disables the cameras and edits the tapes. The China-nexus actor turned Cisco routers into spying platforms, suppressed the logs, and altered what admins were even allowed to see.
Encryption Was the Costume, Access Was the Objective
A critical VMware vCenter flaw was patched on July 29. Five days later, a suspected China-nexus actor was already inside, across 361 IPs in 47 countries. It ended in ransomware, but QUIRSO says that was likely a smokescreen. The encryption was the costume. The access was the objective.