News

Jscrambler’s npm Package Got Backdoored. The Malware Ran Before Your App Ever Started.
Jscrambler npm 8.14.0 shipped a Rust infostealer via preinstall hook, targeting cloud keys, wallets, and AI tool configs. Full technical breakdown and IOCs

Dutch Intelligence Got Caught Feeding Citizen Data Into Its Own AI, and It’s Not Even the First Time
A Dutch oversight report reveals AIVD and MIVD illegally accessed bulk citizen data, some bought from breach markets, and may now be training AI models on it

GhostLock (CVE-2026-43499): a fifteen-year-old rtmutex bug just handed root to anyone with a shell
GhostLock (CVE-2026-43499) is a 15-year rtmutex use-after-free giving root to any local Linux user. Full technical breakdown of the exploit chain

Accenture, 888, and the Anatomy of a Believable Breach Claim
Threat actor "888" claims 35GB of Accenture source code, SSH keys, and Azure tokens. A technical breakdown of the claim, the credentials, and what's actually verified

GitHub’s “Verified” Commit Isn’t Unique, and Its AI Agent Will Leak Your Private Repos If You Ask Nicely
New CMU research shows GitHub's Verified commit badge isn't a unique fingerprint, plus how GitLost tricks GitHub's AI agent into leaking private repos

Januscape (CVE-2026-53359): The 16-Year-Old KVM Bug That Lets a Guest VM Take Down Its Host
CVE-2026-53359, dubbed Januscape, is a 16-year-old KVM use-after-free letting guest VMs crash or escalate into the host. Here's the full technical breakdown

GoDaddy Is Quietly Fighting for WHOIS Privacy, and Almost No One’s Paying Attention
Delhi High Court ordered registrars to end default WHOIS privacy. GoDaddy's 5,000-page appeal explains why, and how it collides with RDAP's 2025 rollout

UK Green Paper Would Force YouTube, Meta and TikTok to Rank BBC and ITV Above Independent Creators
The UK's Green Paper would force YouTube, Meta and TikTok to rank BBC and ITV news higher. Here's the actual mechanism, timeline and legal status

DHS Confirms HSIN Breach: Inside the Hack That Hit America’s Homeland Security Coordination Platform Weeks Before the World Cup Final
DHS confirms a breach of HSIN, its SharePoint-linked intelligence network. Technical analysis of CVE-2026-45659, World Cup exposure, and the 2023 precedent

Apple’s Hide My Email has a Vulnerability in it and the company has known for over a year
Apple's Hide My Email has an unpatched flaw that reveals real addresses in minutes. Reported in June 2025, still exploitable. Full technical breakdown





