Cybersecurity

When the internet’s plumbing catches fire

AI Chatbots Are Now Recommending Malware Downloads Because the Threat Actors Figured Out SEO Poisoning Works on Large Language Models Too — Your Helpful Assistant Just Became an Unwitting Accomplice

🤚 The Open-Palm Diagnosis Here is a sentence that would have been science fiction in 2023 and is a Microsoft security advisory in 2026: AI…

Read more

CrowdStrike, Google, and Shadowserver Dismantle the Glassworm Botnet — The Developer-Targeting Supply Chain Parasite That Used Solana, BitTorrent, and Google Calendar as a Four-Headed Command Structure

🤚 The Open-Palm Takedown On May 27, 2026, a coordinated strike by CrowdStrike, Google, and The Shadowserver Foundation dismantled Glassworm, a botnet that had been…

Read more

The Megalodon Supply Chain Attack Pushed 5,718 Malicious Commits to 5,561 GitHub Repos in Six Hours — Your CI/CD Pipeline Just Donated Its Credentials to a Bot Named ‘build-bot’

🤚 The Open-Palm Commit History On May 18, 2026, between approximately 11:36 and 17:48 UTC — a window of just over six hours — an…

Read more

Charter Communications Confirms 40 Million Customer Records Stolen After ShinyHunters Called an Employee and Asked Nicely — The Entire Zero-Trust Architecture Was Defeated by a Phone Call on April Fools’ Day

🤚 The Open-Palm Breach Notification Charter Communications, the telecommunications conglomerate that serves roughly 30 million customers under the Spectrum brand, has confirmed that ShinyHunters —…

Read more

Microsoft Copilot Cowork Can Be Tricked Into Stealing Your Files With Five Lines of Code — The AI Assistant Has Been Promoted to Insider Threat

🤚 The Open-Palm Disclosure Security researchers at PromptArmor have published findings that should make every enterprise IT department quietly close their laptop and stare out…

Read more

Ghost CMS SQL Injection Compromises 700 Websites Including Harvard and Oxford — The Patch Was Available for 95 Days but the Attackers Read the Changelog First

🤚 The Open-Palm Injection A critical SQL injection vulnerability in Ghost CMS — tracked as CVE-2026-26980 — is being actively exploited in a large-scale campaign…

Read more

Underminr DNS Vulnerability Puts 88 Million Domains at Risk — Your Network Trust Model Just Found Out It Was a Suggestion

🤚 The Open-Palm Disclosure A vulnerability called “Underminr” has just put approximately 88 million domains on notice, and the attack vector is so elegant it…

Read more

Netherlands Seizes 800 Servers From a Russian Bulletproof Host Called ‘Stark Industries’ That Rebranded as ‘WorkTitans’ — The Corporate Shell Game Has Better Uptime Than Your Actual Infrastructure

🤚 The Open-Palm Raid Report Dutch financial crime investigators — the FIOD — have seized 800 servers and arrested two men in a sweeping operation…

Read more

Microsoft Defender Has Two Zero-Days Being Actively Exploited — The Software Guarding Your Computer Needed Guarding From Itself

🤚 The Open-Palm Patch Notes On Wednesday, Microsoft began rolling out emergency security patches for two zero-day vulnerabilities in Microsoft Defender — the software that…

Read more

Google Accidentally Reveals Its Own Unfixed Chromium Zero-Day — Your Browser Closes, the JavaScript Doesn’t, and the Bug Report Leaked Itself

🤚 The Open-Palm Disclosure In a move that absolutely no one at Google’s security team would describe as “optimal,” Google accidentally revealed the full details…

Read more