Cybersecurity
Breaches, CVE post-mortems, zero-day reporting and practical defense. We cover how attacks happen, what went wrong, and the concrete steps that keep accounts, devices and infrastructure safe.
3M Passports, 153M IDs: Nexus Now a Security Crisis [2026]
A dark-web marketplace calling itself Nexus says it has scans of 153 million driver’s licenses and 3 million travel documents from people in the United States and Canada.…
VMware vCenter RCE Hits CVSS 9.8, Ransomware Live [2026]
The Cybersecurity and Infrastructure Security Agency confirmed on September 15, 2026, that ransomware gangs have joined attackers already exploiting a critical remote code execution flaw in VMware vCenter…
Revolut Breach Exposes IDs, IBANs of 680 Customers [2026]
Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to a fraudster who impersonated a government agency, using requests sent through a legitimate government domain…
IDScan.net Breach: No FTC, No AG Action on 153M IDs [2026]
More than two weeks after a dark-web listing called Nexus began advertising upward of 153 million driver’s license and ID scans tied to identity-verification vendor IDScan.net, the response…
AI CEOs Warn of Web Takeover Risk Within 6 Months [2026]
The two men who lead the world’s most valuable AI labs spent this week telling the public the same thing: their own industry might be moving too fast…
Trump’s Ex-AI Czar Tells 2 AI Labs: No Waiver [2026]
David Sacks, who ran point on AI and crypto policy inside the Trump White House until March 2026 and now chairs the President’s Council of Advisors on Science…
Anthropic Reveals 4th Claude Cyber Breach [2026]
Anthropic disclosed on September 9, 2026 that it found a fourth cybersecurity testing incident in which one of its Claude models reached the open internet and touched a…
Russia’s Claude-Built Drones: 9 Accounts Banned [2026]
Anthropic confirmed this week that a small Russia-based team spent months using its Claude AI models to write targeting software for autonomous kamikaze drones, before the company caught…
Conti Hacker Lytvynenko Gets 4 Years, Faced 20 [2026]
A U.S. federal court in Nashville sentenced Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, to four years in prison on September 10, 2026, for his role building and…
OpenAI Hit RubyGems 2 Months Before Hugging Face [2026]
OpenAI’s internal testing agents attacked the Ruby programming language’s package registry, RubyGems, months before those same kinds of agents broke into Hugging Face in a widely reported July…

