Cybersecurity

When the internet’s plumbing catches fire

California Sues 23andMe for Losing 6.9 Million People’s DNA — The Company Changed Its Name to ‘Chrome Holding Co.’ Which Is Exactly What an Innocent Company Would Do

🤚 The Open-Palm Subpoena California Attorney General Rob Bonta has filed suit against 23andMe — or rather, against the corporate husk now operating under the…

Read more

ChatGPT’s Share Link Feature Is Now a Malware Distribution Network — The Chatbot Impersonated Its Own Outage to Install an Infostealer, and the URL Was Legitimate the Entire Time

🤚 The Open-Palm Incident Report Threat actors have discovered that ChatGPT’s share link feature — the one that lets you send a conversation to a…

Read more

Carnival Cruise Loses Six Million Customer Records to ShinyHunters Because Someone Answered the Phone — The Company’s Fourth Breach Since 2020 Suggests the Loyalty Program Extends to Threat Actors

🤚 The Open-Palm Damage Report In what is becoming a disturbingly reliable annual tradition, Carnival Corporation — operator of the world’s largest cruise fleet —…

Read more

AI Chatbots Are Now Recommending Malware Downloads Because the Threat Actors Figured Out SEO Poisoning Works on Large Language Models Too — Your Helpful Assistant Just Became an Unwitting Accomplice

🤚 The Open-Palm Diagnosis Here is a sentence that would have been science fiction in 2023 and is a Microsoft security advisory in 2026: AI…

Read more

CrowdStrike, Google, and Shadowserver Dismantle the Glassworm Botnet — The Developer-Targeting Supply Chain Parasite That Used Solana, BitTorrent, and Google Calendar as a Four-Headed Command Structure

🤚 The Open-Palm Takedown On May 27, 2026, a coordinated strike by CrowdStrike, Google, and The Shadowserver Foundation dismantled Glassworm, a botnet that had been…

Read more

The Megalodon Supply Chain Attack Pushed 5,718 Malicious Commits to 5,561 GitHub Repos in Six Hours — Your CI/CD Pipeline Just Donated Its Credentials to a Bot Named ‘build-bot’

🤚 The Open-Palm Commit History On May 18, 2026, between approximately 11:36 and 17:48 UTC — a window of just over six hours — an…

Read more

Charter Communications Confirms 40 Million Customer Records Stolen After ShinyHunters Called an Employee and Asked Nicely — The Entire Zero-Trust Architecture Was Defeated by a Phone Call on April Fools’ Day

🤚 The Open-Palm Breach Notification Charter Communications, the telecommunications conglomerate that serves roughly 30 million customers under the Spectrum brand, has confirmed that ShinyHunters —…

Read more

Microsoft Copilot Cowork Can Be Tricked Into Stealing Your Files With Five Lines of Code — The AI Assistant Has Been Promoted to Insider Threat

🤚 The Open-Palm Disclosure Security researchers at PromptArmor have published findings that should make every enterprise IT department quietly close their laptop and stare out…

Read more

Ghost CMS SQL Injection Compromises 700 Websites Including Harvard and Oxford — The Patch Was Available for 95 Days but the Attackers Read the Changelog First

🤚 The Open-Palm Injection A critical SQL injection vulnerability in Ghost CMS — tracked as CVE-2026-26980 — is being actively exploited in a large-scale campaign…

Read more

Underminr DNS Vulnerability Puts 88 Million Domains at Risk — Your Network Trust Model Just Found Out It Was a Suggestion

🤚 The Open-Palm Disclosure A vulnerability called “Underminr” has just put approximately 88 million domains on notice, and the attack vector is so elegant it…

Read more