Cybersecurity
When the internet’s plumbing catches fire
KDDI Lost 14.2 Million Email Credentials Through a Vulnerability in Software It Won’t Name — Five Japanese ISPs Outsourced Their Email to One Platform and the Platform Outsourced Its Security to an Anonymous Dependency
🤚 The Open-Palm Disclosure KDDI Corporation, one of Japan’s largest telecommunications operators, has disclosed a breach affecting up to 14.22 million email accounts across five…
Read moreNorth Korean Malware Embeds 38 Fake Error Messages to Gaslight AI Security Tools Into Giving Up — The Prompt Injection Is Inside the Executable and Your LLM Analyst Believed Every Word
🤚 The Open-Palm Disclosure SentinelLABS disclosed on June 23 that a North Korean macOS backdoor called Gaslight embeds 38 fabricated system error messages inside its…
Read moreA Clean GitHub Repository Tricked Claude Code Into Opening a Reverse Shell — The Malware Wasn’t in the Code, It Was in a DNS Record the Agent Never Saw
🤚 The Open-Palm Briefing Mozilla’s Zero Day Investigative Network (0DIN) published research on June 28 showing that AI coding agents — specifically Claude Code —…
Read morePolymarket Lost $3 Million Because a Third-Party JavaScript Dependency Asked Users to Sign a Transaction and They Did — The Prediction Market Failed to Predict Its Own Supply Chain Attack
🤚 The Open-Palm Wallet Drain On June 25, 2026, Polymarket — the world’s largest cryptocurrency prediction market, where you can bet real money on whether…
Read moreA Malicious Edge Extension Called ‘Edgecution’ Escapes the Browser Sandbox Using Chrome’s Own Native Messaging Protocol — The Ransomware Didn’t Break In, It Was Invited
🤚 The Open-Palm Installation If you’ve ever wondered what the most elaborate way to get ransomware onto a corporate network might be, Zscaler has your…
Read moreLastPass Confirms Customer Data Was Stolen Through a Supply Chain Breach at Klue, an AI Vendor Nobody in Security Had Audited — The OAuth Tokens Were the Keys, and Seven Companies Left Them in the Ignition
🤚 The Open-Palm Breach Report LastPass has confirmed — and yes, we know you’re tired of sentences that begin this way — that customer data…
Read moreAccenture Pays $4.1 Billion for Dragos, runZero, and NetRise — The World’s Largest Consulting Firm Just Bought the Metasploit Creator’s Company and Called It a ‘Platform Opportunity’
🤚 The Open-Palm Acquisition Spree Accenture, the consulting colossus that has historically preferred telling companies what to buy over actually buying things itself, just announced…
Read moreA Researcher Named ‘Nightmare Eclipse’ Keeps Leaking Microsoft Defender Zero-Days Because the Bug Bounty Program Made It Personal — RoguePlanet Gives SYSTEM Access and the Patch Timeline Is ‘We’re Working on It’
🤚 The Open-Palm Disclosure A security researcher operating under the handle “Nightmare Eclipse” has disclosed a new zero-day vulnerability in Microsoft Defender’s Malware Protection Engine…
Read moreA Researcher Found 10,000 GitHub Repositories Distributing Trojan Malware by Cloning Real Projects and Typing ‘Update README.md’ — GitHub’s Detection Systems Were Defeated by the Most Common Commit Message in History
A security researcher went looking for suspicious activity on GitHub and found approximately 10,000 repositories distributing Trojan malware — not by exploiting a vulnerability, not…
Read moreFortiBleed Exposes Plaintext VPN Credentials for 73,932 Fortinet Firewalls Across 194 Countries — A Russian-Speaking Threat Group Used a 45-GPU Cluster to Crack Passwords That Should Have Been Changed After the Last Breach
🤚 The Open-Palm Credential Catastrophe Security researcher Bob Diachenko has discovered what can only be described as the corporate world’s worst password spreadsheet: a server…
Read more