Cybersecurity
When the internet’s plumbing catches fire
Microsoft Defender Has Two Zero-Days Being Actively Exploited — The Software Guarding Your Computer Needed Guarding From Itself
🤚 The Open-Palm Patch Notes On Wednesday, Microsoft began rolling out emergency security patches for two zero-day vulnerabilities in Microsoft Defender — the software that…
Read moreGoogle Accidentally Reveals Its Own Unfixed Chromium Zero-Day — Your Browser Closes, the JavaScript Doesn’t, and the Bug Report Leaked Itself
🤚 The Open-Palm Disclosure In a move that absolutely no one at Google’s security team would describe as “optimal,” Google accidentally revealed the full details…
Read moreGitHub Confirms 3,800 Internal Repos Were Stolen via a Poisoned VS Code Extension — The Platform That Hosts the World’s Code Just Got Owned by a Marketplace Plugin
🤚 The Open-Palm Incident Report On May 19, 2026, a single GitHub employee installed a Visual Studio Code extension. By the time the company detected…
Read moreGrafana’s Entire Source Code Was Stolen via a Single GitHub Token — Your CI/CD Pipeline Has More Access Than Your CEO and Less Security Than Your Wi-Fi
🤚 The Open-Palm Disclosure Grafana Labs — the company whose dashboards are plastered across every DevOps team’s second monitor like motivational posters made of metrics…
Read moreMicrosoft ‘Fixed’ a Windows Zero-Day in 2020 — A Researcher Just Proved It Still Works in 2026, and Published the Exploit on GitHub as a Resignation Letter to the Bug Bounty Program
🤚 The Open-Palm Patch That Wasn’t In September 2020, a Google Project Zero researcher named James Forshaw discovered a privilege escalation vulnerability in the Windows…
Read moreRussia’s Secret Blizzard Upgrades Kazuar Backdoor Into a Peer-to-Peer Botnet — Your Government’s Network Now Has Better Mesh Connectivity Than Your Wi-Fi
Secret Blizzard — the Russian state-sponsored threat group also tracked as Turla, one of the most sophisticated cyber-espionage outfits on the planet — has upgraded…
Read morePwn2Own Berlin Researchers Collect $908,750 for 39 Zero-Days in Two Days — Your Enterprise Software Just Got a Very Public Performance Review
🤚 The Open-Palm Exploit Buffet The second day of Pwn2Own Berlin 2026 concluded on May 15 with security researchers collecting $385,750 in prize money after…
Read moreOpenAI Confirms Two Employee Devices Were Compromised in the Shai Hulud Supply Chain Attack — The AI That Writes Code Just Got Owned by the Code Supply Chain
Two days ago, we reported that the Shai Hulud supply chain worm had compromised hundreds of signed npm and PyPI packages, including TanStack, Mistral AI,…
Read moreFoxconn Gets Ransomwared for the Fourth Time Since 2020 — 8 Terabytes of Apple, Intel, and Nvidia Secrets Are Now a Dark Web Tasting Menu
🤚 The Open-Palm Inventory of Stolen Goods In news that will surprise absolutely no one who has been paying attention to the state of industrial…
Read moreShai Hulud Supply Chain Attack Compromises Hundreds of Signed npm and PyPI Packages — Your Cryptographic Verification Just Verified the Malware
🤚 The Open-Palm Dissection If you thought the software supply chain had reached peak absurdity when a fake OpenAI privacy filter hit 244,000 downloads on…
Read more