Cybersecurity

When the internet’s plumbing catches fire

KDDI Lost 14.2 Million Email Credentials Through a Vulnerability in Software It Won’t Name — Five Japanese ISPs Outsourced Their Email to One Platform and the Platform Outsourced Its Security to an Anonymous Dependency

🤚 The Open-Palm Disclosure KDDI Corporation, one of Japan’s largest telecommunications operators, has disclosed a breach affecting up to 14.22 million email accounts across five…

Read more

North Korean Malware Embeds 38 Fake Error Messages to Gaslight AI Security Tools Into Giving Up — The Prompt Injection Is Inside the Executable and Your LLM Analyst Believed Every Word

🤚 The Open-Palm Disclosure SentinelLABS disclosed on June 23 that a North Korean macOS backdoor called Gaslight embeds 38 fabricated system error messages inside its…

Read more

A Clean GitHub Repository Tricked Claude Code Into Opening a Reverse Shell — The Malware Wasn’t in the Code, It Was in a DNS Record the Agent Never Saw

🤚 The Open-Palm Briefing Mozilla’s Zero Day Investigative Network (0DIN) published research on June 28 showing that AI coding agents — specifically Claude Code —…

Read more

Polymarket Lost $3 Million Because a Third-Party JavaScript Dependency Asked Users to Sign a Transaction and They Did — The Prediction Market Failed to Predict Its Own Supply Chain Attack

🤚 The Open-Palm Wallet Drain On June 25, 2026, Polymarket — the world’s largest cryptocurrency prediction market, where you can bet real money on whether…

Read more

A Malicious Edge Extension Called ‘Edgecution’ Escapes the Browser Sandbox Using Chrome’s Own Native Messaging Protocol — The Ransomware Didn’t Break In, It Was Invited

🤚 The Open-Palm Installation If you’ve ever wondered what the most elaborate way to get ransomware onto a corporate network might be, Zscaler has your…

Read more

LastPass Confirms Customer Data Was Stolen Through a Supply Chain Breach at Klue, an AI Vendor Nobody in Security Had Audited — The OAuth Tokens Were the Keys, and Seven Companies Left Them in the Ignition

🤚 The Open-Palm Breach Report LastPass has confirmed — and yes, we know you’re tired of sentences that begin this way — that customer data…

Read more

Accenture Pays $4.1 Billion for Dragos, runZero, and NetRise — The World’s Largest Consulting Firm Just Bought the Metasploit Creator’s Company and Called It a ‘Platform Opportunity’

🤚 The Open-Palm Acquisition Spree Accenture, the consulting colossus that has historically preferred telling companies what to buy over actually buying things itself, just announced…

Read more

A Researcher Named ‘Nightmare Eclipse’ Keeps Leaking Microsoft Defender Zero-Days Because the Bug Bounty Program Made It Personal — RoguePlanet Gives SYSTEM Access and the Patch Timeline Is ‘We’re Working on It’

🤚 The Open-Palm Disclosure A security researcher operating under the handle “Nightmare Eclipse” has disclosed a new zero-day vulnerability in Microsoft Defender’s Malware Protection Engine…

Read more

A Researcher Found 10,000 GitHub Repositories Distributing Trojan Malware by Cloning Real Projects and Typing ‘Update README.md’ — GitHub’s Detection Systems Were Defeated by the Most Common Commit Message in History

A security researcher went looking for suspicious activity on GitHub and found approximately 10,000 repositories distributing Trojan malware — not by exploiting a vulnerability, not…

Read more

FortiBleed Exposes Plaintext VPN Credentials for 73,932 Fortinet Firewalls Across 194 Countries — A Russian-Speaking Threat Group Used a 45-GPU Cluster to Crack Passwords That Should Have Been Changed After the Last Breach

🤚 The Open-Palm Credential Catastrophe Security researcher Bob Diachenko has discovered what can only be described as the corporate world’s worst password spreadsheet: a server…

Read more