Cybersecurity

When the internet’s plumbing catches fire

The FBI and Google Dismantled a $1.9 Billion AI-Powered Phishing Empire That Had Better Product-Market Fit Than Most YC Startups — Outsider Enterprise Charged $88 a Week and Offered Customer Support

🤚 The Open-Palm Indictment The FBI, Google, and Black Lotus Labs just dismantled one of the largest phishing-as-a-service operations in history. The operation, called Outsider…

Read more

Chinese Hackers Replaced the Login System With Their Own and Nobody Noticed for Ten Years — Operation Highland Is the Longest Houseguest Story in Cybersecurity History

🤚 The Open-Palm Intrusion Report A Chinese state-sponsored hacking group called Velvet Ant compromised a critical infrastructure organization’s authentication system and maintained full access for…

Read more

The Atomic Arch Supply Chain Attack Compromised 400 Packages by Politely Adopting Them — The AUR’s Trust Model Just Graduated From ‘Use at Your Own Risk’ to ‘Your Risk Has Arrived’

🤚 The Open-Palm Package Heist Security researchers at Sonatype have uncovered a supply chain attack against the Arch User Repository (AUR) that compromised over 400…

Read more

ShinyHunters Exploit a CVSS 9.8 Oracle PeopleSoft Zero-Day to Breach 100 Organizations — 68% Are Universities Because Academia Updates Its Infrastructure With the Urgency of a Tenured Professor

🤚 The Open-Palm Breach Report ShinyHunters — the extortion gang that has been treating 2026 like a personal buffet of poorly secured enterprise software —…

Read more

Langflow’s AI Agent Platform Has a Path Traversal Bug That Requires No Authentication — 7,000 Exposed Servers Can’t Sanitize a Filename but They Can Build You a RAG Pipeline

Langflow, the open-source platform that lets you build AI agents, RAG pipelines, and MCP workflows using a cheerful drag-and-drop interface, has a vulnerability so elegantly…

Read more

The Shai Hulud Supply Chain Worm Just Compromised 73 of Microsoft’s Own GitHub Repositories — The Platform That Hosts the World’s Code Was Distributing Malware From Its Own Azure Namespace

🤚 The Open-Palm Repo Lockdown The Shai Hulud supply chain worm — a name we have now typed so many times it has its own…

Read more

Microsoft’s June Patch Tuesday Fixes 200 Vulnerabilities and Three Zero-Days — Including the HTTP/2 Bomb That Can Crash Any Server on Earth, Which Now Has a CVE Number and a Registry Key

🤚 The Open-Palm Patch Dump It’s the second Tuesday of June, which means Microsoft has once again gathered its quarterly shame into a tidy release…

Read more

NFCShare Android Malware Steals Your Credit Card by Asking You to Tap It — 56 Fake Banking Apps on GitHub Would Like to Verify Your Identity and Your PIN

🤚 The Open-Palm Tap A new Android trojan called NFCShare would like you to hold your credit card against your phone for “security verification.” It…

Read more

The C0XMO Botnet Exploits a Five-Year-Old DD-WRT Vulnerability, Supports Seven Architectures, and Murders Every Rival Botnet on Your Router — Your Firmware Update Can Wait, Said Nobody Ever

A new botnet variant called C0XMO is exploiting a five-year-old vulnerability in DD-WRT router firmware to compromise devices across seven CPU architectures — and its…

Read more

A Magecart Campaign Is Using Stripe’s Own API to Steal and Store Credit Card Data — Your Content Security Policy Is the Accomplice

🤚 The Open-Palm Transaction A new Magecart credit card theft campaign has achieved something genuinely elegant in the annals of cybercrime: it is using Stripe’s…

Read more