Cybersecurity
When the internet’s plumbing catches fire
California Sues 23andMe for Losing 6.9 Million People’s DNA — The Company Changed Its Name to ‘Chrome Holding Co.’ Which Is Exactly What an Innocent Company Would Do
🤚 The Open-Palm Subpoena California Attorney General Rob Bonta has filed suit against 23andMe — or rather, against the corporate husk now operating under the…
Read moreChatGPT’s Share Link Feature Is Now a Malware Distribution Network — The Chatbot Impersonated Its Own Outage to Install an Infostealer, and the URL Was Legitimate the Entire Time
🤚 The Open-Palm Incident Report Threat actors have discovered that ChatGPT’s share link feature — the one that lets you send a conversation to a…
Read moreCarnival Cruise Loses Six Million Customer Records to ShinyHunters Because Someone Answered the Phone — The Company’s Fourth Breach Since 2020 Suggests the Loyalty Program Extends to Threat Actors
🤚 The Open-Palm Damage Report In what is becoming a disturbingly reliable annual tradition, Carnival Corporation — operator of the world’s largest cruise fleet —…
Read moreAI Chatbots Are Now Recommending Malware Downloads Because the Threat Actors Figured Out SEO Poisoning Works on Large Language Models Too — Your Helpful Assistant Just Became an Unwitting Accomplice
🤚 The Open-Palm Diagnosis Here is a sentence that would have been science fiction in 2023 and is a Microsoft security advisory in 2026: AI…
Read moreCrowdStrike, Google, and Shadowserver Dismantle the Glassworm Botnet — The Developer-Targeting Supply Chain Parasite That Used Solana, BitTorrent, and Google Calendar as a Four-Headed Command Structure
🤚 The Open-Palm Takedown On May 27, 2026, a coordinated strike by CrowdStrike, Google, and The Shadowserver Foundation dismantled Glassworm, a botnet that had been…
Read moreThe Megalodon Supply Chain Attack Pushed 5,718 Malicious Commits to 5,561 GitHub Repos in Six Hours — Your CI/CD Pipeline Just Donated Its Credentials to a Bot Named ‘build-bot’
🤚 The Open-Palm Commit History On May 18, 2026, between approximately 11:36 and 17:48 UTC — a window of just over six hours — an…
Read moreCharter Communications Confirms 40 Million Customer Records Stolen After ShinyHunters Called an Employee and Asked Nicely — The Entire Zero-Trust Architecture Was Defeated by a Phone Call on April Fools’ Day
🤚 The Open-Palm Breach Notification Charter Communications, the telecommunications conglomerate that serves roughly 30 million customers under the Spectrum brand, has confirmed that ShinyHunters —…
Read moreMicrosoft Copilot Cowork Can Be Tricked Into Stealing Your Files With Five Lines of Code — The AI Assistant Has Been Promoted to Insider Threat
🤚 The Open-Palm Disclosure Security researchers at PromptArmor have published findings that should make every enterprise IT department quietly close their laptop and stare out…
Read moreGhost CMS SQL Injection Compromises 700 Websites Including Harvard and Oxford — The Patch Was Available for 95 Days but the Attackers Read the Changelog First
🤚 The Open-Palm Injection A critical SQL injection vulnerability in Ghost CMS — tracked as CVE-2026-26980 — is being actively exploited in a large-scale campaign…
Read moreUnderminr DNS Vulnerability Puts 88 Million Domains at Risk — Your Network Trust Model Just Found Out It Was a Suggestion
🤚 The Open-Palm Disclosure A vulnerability called “Underminr” has just put approximately 88 million domains on notice, and the attack vector is so elegant it…
Read more