Cybersecurity 101
How AI Is Used in Cyberattacks
A clear guide to how attackers use artificial intelligence — for phishing, malware, deepfakes, and attacks on AI systems — and how organizations can defend.
Cybersecurity 101
A clear guide to how attackers use artificial intelligence — for phishing, malware, deepfakes, and attacks on AI systems — and how organizations can defend.
Data Breaches
A threat actor advertised a 340 million-record OnlyFans dataset for 0.313 BTC on May 25, then privately admitted they did not breach the platform. The compilation stitches old breach data to public profiles, and the framing failure is itself the editorial story.
Data Breaches
Carnival Corporation began notifying 5,995,277 people on May 27, 2026 that their personal data was stolen in an April vishing breach — the corporate confirmation of an extortion claim ShinyHunters posted to its leak site 38 days earlier.
Threat Actors
Wiz disclosed JINX-0164, a previously unreported actor running LinkedIn recruiter lures, custom macOS malware, and CI/CD hijacking against cryptocurrency developers. The playbook mirrors documented North Korean tradecraft, but Wiz preserves the attribution hedge.
Data Breaches
Charter Communications, the parent of Spectrum, confirmed a cybersecurity incident on May 26-27, 2026 after ShinyHunters claimed 42 million customer records via the same vishing-to-Microsoft-Entra-to-Salesforce playbook documented across the 2026 cluster at ADT, Amtrak, Odido, and Vimeo.
Vulnerabilities
Rapid7 Labs disclosed an unpatched CVSSv4 9.4 argument-injection (CWE-88) flaw in Gogs that lets any authenticated user achieve remote code execution by injecting --exec into git rebase via a malicious branch name. The second critical self-hosted-Git flaw in one week.
Vulnerabilities
Microsoft's MSRC publicly condemned a six-flaw run of uncoordinated zero-day disclosures, saying the leaks put customers at 'unnecessary risk.' It's a position shift after six weeks of researcher disclosures that forced emergency response. The story is the tension itself.
Nation-State Cyber Threats
ESET's October 2025 - March 2026 APT report names two findings defenders cannot ignore: a Polish energy company hit in December 2025 by a new wiper, DynoWiper, attributed to Sandworm with medium confidence, and the npm package axios compromised by attackers ESET ties to Lazarus.
Public Sector Security
A City Hall clerk in Alexandria, Tennessee caught a hacker using the town's Amazon account to order three cameras and an iPad. The detection was a person noticing — no security control fired. Thousands of US municipalities are in the same posture.
Cybersecurity 101
SQL injection (SQLi) is one of the oldest and most damaging web vulnerabilities — a single unguarded input field can expose an entire database. Here is how SQLi attacks work, the main types, their real-world impact, and how to prevent them.
Security Research
Apple published the post-quantum cryptography implementations in corecrypto — the library behind iOS, iPadOS, and macOS — alongside formal proofs and verification tools. It does not change today's encryption posture, but it lets outside experts audit the math that will protect tomorrow's.
Artificial Intelligence (AI)
Google Cloud launched AI Threat Defense on May 27, 2026 — an automated platform that pairs Gemini, the Wiz cloud-security stack, and the CodeMender AI code-fixing agent to find, prioritize, and patch software vulnerabilities at machine speed.