Cybersecurity

When the internet’s plumbing catches fire

Hackers Used Google Ads and Claude’s Own Website to Install Mac Malware — The URL Was Real, the Conversation Was Fake, and the Roofing Contractor Did the Rest

🤚 The Open-Palm Attack Vector In a campaign that deserves some kind of award for ironic creativity, hackers have been using Google Ads and Anthropic’s…

Read more

JDownloader’s Website Was Hacked to Serve Python RAT Malware — And the Breach Was Discovered by a Redditor Who Actually Reads Certificate Names

🤚 The Open-Palm Incident Report JDownloader, the beloved open-source download manager that has faithfully served power users and Linux enthusiasts since approximately the Mesozoic era…

Read more

Linux ‘Dirty Frag’ Zero-Day Gives Root With a Single Command — Your Kernel Has Been an Open Door Since the Obama Administration

🤚 The Open-Palm Root Shell A new Linux zero-day vulnerability dubbed “Dirty Frag” has arrived with all the subtlety of a freight train through your…

Read more

TCLBanker Trojan Hides Inside a Logitech AI Installer, Spreads via WhatsApp, and May Have Been Written by AI — The Future Is Exactly as Stupid as Promised

🤚 The Open-Palm Infection Report A new banking trojan called TCLBanker is doing something genuinely impressive, in the way that a house fire is technically…

Read more

Palo Alto Networks Firewalls Have Been Owned by State Hackers for a Month — Your Perimeter Defense Has Been Freelancing

🤚 The Open-Palm Disclosure If you run Palo Alto Networks firewalls — and statistically, a disconcerting number of you do — you may want to…

Read more

A Student With a 00 Radio Halted Taiwan’s Entire High-Speed Rail — The Security Parameters Hadn’t Changed Since the Bush Administration

A 23-year-old university student in Taiwan, identified by his surname Lin, has been arrested for doing something that sounds like the plot of a cyberpunk…

Read more

DAEMON Tools Was Trojanized for a Month and Nobody Noticed — Your ISO Mounter Is Now a Foreign Intelligence Asset

🤚 The Open-Palm Infection Report If you downloaded DAEMON Tools between April 8 and early May 2026, congratulations — you may have also downloaded a…

Read more

ShinyHunters Breach Canvas LMS and 275 Million Students Just Learned Their Most Expensive Lesson Yet — It Wasn’t on the Syllabus

🤚 The Open-Palm Incident Report Attention, students: your homework, private messages, and existential 2 a.m. emails to your professor about extension requests are now in…

Read more

Remember That cPanel Vulnerability? It’s Ransomware Now, and It Says Sorry

🤚 The Open-Palm Reminder Remember last week, when we told you about that critical cPanel authentication bypass? The one where we said half the internet…

Read more

cPanel Just Had a Critical Auth Bypass and Half the Internet Is Quietly Screaming

A decisive truth, applied directly to the forehead of every hosting provider running cPanel: on April 28, 2026, cPanel published a security advisory titled “Critical…

Read more