You Never Chose the Company That Just Leaked Your Face
More than 153 million driver's license records are allegedly for sale on the dark web for US$100, traced to an identity verification vendor most victims never heard of. You cannot change your face or your date of birth. Lawmakers want to make this exact model mandatory to use the internet.
OpenAI Built an AI Capable of Finding and Exploiting Flaws on Its Own
OpenAI says its upcoming Astra model can find unknown security flaws and write working exploits on its own, no human guiding each step. Treat the self-reported claim skeptically. But the direction is now corroborated across labs and real breaches, and that part is not up for debate.
Your Car Got Hacked Because It Is a Computer Nobody Was Watching
The first known malware built for car dashboards did not go after your brakes. It hijacked the update button, turned the head unit into a botnet node, and rented out your car's internet connection for ad fraud. The car was never the point. The always-on computer inside it was.
Dyson Put a Beautiful Camera in Your Mouth and a Trap in Your Bathroom
Dyson's $499 AI toothbrush is genuinely clever engineering, and also a networked lens in the most private room in your home, an unaudited privacy claim, a fresh attack surface, and a razor-and-blades model built backwards. All of it is true at once.
You Whitelisted the Malware Yourself
A China-nexus group hid a full-control backdoor inside a real Chinese wallpaper app, the kind of harmless adware nobody takes seriously. That is exactly why it worked. The disguise was so convincing the ads never even ran, and that was the tell that gave it away.
The Most Dangerous Intrusion Is the One That Turns the Alarms Off
Most attackers try not to get caught. Fire Ant breaks in, then disables the cameras and edits the tapes. The China-nexus actor turned Cisco routers into spying platforms, suppressed the logs, and altered what admins were even allowed to see.
Encryption Was the Costume, Access Was the Objective
A critical VMware vCenter flaw was patched on July 29. Five days later, a suspected China-nexus actor was already inside, across 361 IPs in 47 countries. It ended in ransomware, but QUIRSO says that was likely a smokescreen. The encryption was the costume. The access was the objective.
One Hijacked Account, One Crate, 245 Million Rust Downloads at Risk
For 86 minutes on August 20, compiling a Rust project was enough to install an infostealer, no malicious code ever called. An attacker hijacked the account behind arrayref, a tiny crate riding in three-quarters of all Rust environments. You never trusted arrayref. You trusted the account.
NovaCookies Phishing Kit Steals Microsoft 365 Sessions to Bypass MFA
For US$320 a month, NovaCookies rents anyone the ability to walk past your MFA. It does not steal your password. It steals your session, the proof you already logged in, after you authenticate perfectly. MFA did not fail. It just stopped being the finish line.
Microsoft Patched 400 Bugs This Month and That Is Not the Scary Part
Microsoft patched over 400 flaws in a single month, triple the normal load, because AI now hunts bugs faster than any human team. But real-world exploitation has not surged to match. The scary number is not 400. It is 13 of 14, and the gap is closing fast.
Berlin Won't Pay VICE SPIDER and Here Is Why It Changes Nothing
Berlin refused to pay the ransomware crew that breached its network. Good. But the data was already gone a week before anyone pulled the plug. Refusing to pay is the honorable call, and it does not save you. The failure that mattered happened quietly, days earlier.
The Ransomware Group Nobody Should Be Worried About Yet
TITAN says its AI reads 700GB of stolen data an hour. The number is unverified marketing, and the group is a nobody: 24 victims in four months against leaders posting 100 a month. The real AI-in-ransomware story is quieter, and it is not TITAN.