Cybersecurity

When the internet’s plumbing catches fire

153 Million Driver’s Licenses Surface on a Dark-Web ID Market — The Verification Economy Has Misplaced Its Wallet

A fresh identity-theft marketplace called Nexus has reportedly been offering more than 153 million driver’s-license records for sale, according to Ars Technica and reporting cited…

Read more

JFrog Artifactory Gets a 9.8-Rated Authentication Bypass Under Active Attack — The Software Supply Chain Has Misplaced the Master Key

JFrog Artifactory, the widely used repository manager for software artifacts, packages, binaries, and AI models, is facing active exploitation of CVE-2026-82329, a 9.8-rated authentication-bypass flaw.…

Read more

Healthcare Cyberattacks Hit Pacemaker Workflows and Patient Records — The Hospital Has Discovered Voice Phishing in Formalwear

Boston Scientific and McKesson have disclosed separate healthcare cybersecurity incidents, giving the week a particularly refined bouquet of medical anxiety, operational disruption, and patient data…

Read more

Britain Tells the Government to Keep Its Hands Off Encrypted Messages — The Backdoor Concierge Has Been Politely Ejected

The British public has delivered a rare and luxurious democratic product: a clear answer. According to The Register, polling commissioned by the Center for Democracy…

Read more

Claude Code Can Be Tricked by a Malicious Website Summary — The Agent Butler Has Downloaded a ZIP File and Called It Initiative

A new prompt-injection demonstration from security researcher Johann Rehberger, also known as wunderwuzzi, shows Anthropic’s Claude Code running Opus 5 in Auto Mode can be…

Read more

PaperCut Warns of Zero-Day Attacks on Exposed Print Servers — The Office Printer Has Requested Incident Response in Duplex Mode

PaperCut customers are being urged to act quickly after the print-management vendor disclosed active attacks exploiting a vulnerability in PaperCut NG and PaperCut MF. As…

Read more

Australian Police Arrest Alleged TeamPCP Operators — The Supply-Chain Banquet Has Lost Its Malware Sommelier

Australian Federal Police have arrested two men accused of being principal participants in TeamPCP, the cybercrime collective linked to major open-source supply-chain attacks including the…

Read more

FBI Seizes China-Linked Hacking Platforms Used Against NASA and the Senate — The Botnet Concierge Has Lost Its Reservation

The FBI says it has disrupted a China-linked hacking operation by seizing domains tied to two platforms allegedly used to attack NASA, the U.S. Senate,…

Read more

CISA Gives a Perfect-Ten Oracle Flaw Three Days to Leave the Premises — The Patch Calendar Has Become a Fire Drill in Formalwear

CISA has added CVE-2026-21962, a maximum-severity Oracle vulnerability rated CVSS 10.0, to its Known Exploited Vulnerabilities catalog and given U.S. federal agencies just three days…

Read more

AliExpress Accused of Silent Audio Fingerprinting — The Discount Bazaar Has Hired an Invisible Orchestra

AliExpress has been accused of using an old but deeply theatrical browser fingerprinting trick: silently sending inaudible audio through visitors’ browsers to help identify them.…

Read more