Cybersecurity

When the internet’s plumbing catches fire

15 Malicious JetBrains Plugins Stole 70,000 Developers’ AI API Keys and Resold Them as a Subscription Service — Your IDE’s Plugin Marketplace Just Invented Credential Piracy as a Business Model

Security firm Aikido Security has uncovered a coordinated malware campaign on the JetBrains Marketplace, where 15 malicious plugins disguised as AI coding assistants have been…

Read more

A LinkedIn Recruiter Asked a Developer to Review a GitHub Repo — The Repo Had a Backdoor, the Recruiter Was an Arts Journalist’s Stolen Identity, and npm Install Was the Only Interview Question

🤚 The Open-Palm Recruitment Dossier A developer named Roman Imankulov received a perfectly normal LinkedIn message from a perfectly normal recruiter at a perfectly normal…

Read more

The FBI and Google Dismantled a $1.9 Billion AI-Powered Phishing Empire That Had Better Product-Market Fit Than Most YC Startups — Outsider Enterprise Charged $88 a Week and Offered Customer Support

🤚 The Open-Palm Indictment The FBI, Google, and Black Lotus Labs just dismantled one of the largest phishing-as-a-service operations in history. The operation, called Outsider…

Read more

Chinese Hackers Replaced the Login System With Their Own and Nobody Noticed for Ten Years — Operation Highland Is the Longest Houseguest Story in Cybersecurity History

🤚 The Open-Palm Intrusion Report A Chinese state-sponsored hacking group called Velvet Ant compromised a critical infrastructure organization’s authentication system and maintained full access for…

Read more

The Atomic Arch Supply Chain Attack Compromised 400 Packages by Politely Adopting Them — The AUR’s Trust Model Just Graduated From ‘Use at Your Own Risk’ to ‘Your Risk Has Arrived’

🤚 The Open-Palm Package Heist Security researchers at Sonatype have uncovered a supply chain attack against the Arch User Repository (AUR) that compromised over 400…

Read more

ShinyHunters Exploit a CVSS 9.8 Oracle PeopleSoft Zero-Day to Breach 100 Organizations — 68% Are Universities Because Academia Updates Its Infrastructure With the Urgency of a Tenured Professor

🤚 The Open-Palm Breach Report ShinyHunters — the extortion gang that has been treating 2026 like a personal buffet of poorly secured enterprise software —…

Read more

Langflow’s AI Agent Platform Has a Path Traversal Bug That Requires No Authentication — 7,000 Exposed Servers Can’t Sanitize a Filename but They Can Build You a RAG Pipeline

Langflow, the open-source platform that lets you build AI agents, RAG pipelines, and MCP workflows using a cheerful drag-and-drop interface, has a vulnerability so elegantly…

Read more

The Shai Hulud Supply Chain Worm Just Compromised 73 of Microsoft’s Own GitHub Repositories — The Platform That Hosts the World’s Code Was Distributing Malware From Its Own Azure Namespace

🤚 The Open-Palm Repo Lockdown The Shai Hulud supply chain worm — a name we have now typed so many times it has its own…

Read more

Microsoft’s June Patch Tuesday Fixes 200 Vulnerabilities and Three Zero-Days — Including the HTTP/2 Bomb That Can Crash Any Server on Earth, Which Now Has a CVE Number and a Registry Key

🤚 The Open-Palm Patch Dump It’s the second Tuesday of June, which means Microsoft has once again gathered its quarterly shame into a tidy release…

Read more

NFCShare Android Malware Steals Your Credit Card by Asking You to Tap It — 56 Fake Banking Apps on GitHub Would Like to Verify Your Identity and Your PIN

🤚 The Open-Palm Tap A new Android trojan called NFCShare would like you to hold your credit card against your phone for “security verification.” It…

Read more