π¨ The Council of Europe has allegedly been breached. Over 297 GB of HR and payroll data, more than 429,000 files, has been compromised.
It marks the second major hit on European institutions this year. In March, the EU Commission, ENISA, and the Directorate-General for Digital Services were breached.
It marks the second major hit on European institutions this year. In March, the EU Commission, ENISA, and the Directorate-General for Digital Services were breached.
π€£15π₯°1
βοΈ The hype says frontier models like Mythos will soon find and exploit vulnerabilities at scale. That future is real, but it skips over the present.
The capability is not waiting on a frontier model. With the right setup, the models already in wide use are doing this work today.
Start at the top end. Anthropic disrupted what it called the first AI-orchestrated espionage campaign, run by a group it assessed as Chinese state-sponsored, where the attackers turned Claude Code into the operator and ran an estimated 90% of the tactical steps against roughly thirty global targets.
It is not only nation states. One threat report describes a lone actor who jailbroke a mainstream model and used it to breach Mexican government systems, allegedly walking off with around 150GB of taxpayer and voter records.
The skill bar is collapsing at the same time. A UK-based seller with no real technical ability reportedly used AI to generate ransomware and sold each build for a few hundred dollars.
The aggregate numbers match the anecdotes. Over the past year, AI-assisted actors grew from a third of high-risk cyber cases to more than half, and most of those flagged used AI to help build malware.
The defenders' own data agrees. The 2026 Verizon DBIR ranked software vulnerabilities above stolen credentials as the top breach entry point for the first time in nearly two decades, and CrowdStrike clocked average breakout time at 29 minutes.
Frontier models like Mythos raise the ceiling on what is possible. They did not build the floor adversaries are already walking on.
The capability is not waiting on a frontier model. With the right setup, the models already in wide use are doing this work today.
Start at the top end. Anthropic disrupted what it called the first AI-orchestrated espionage campaign, run by a group it assessed as Chinese state-sponsored, where the attackers turned Claude Code into the operator and ran an estimated 90% of the tactical steps against roughly thirty global targets.
It is not only nation states. One threat report describes a lone actor who jailbroke a mainstream model and used it to breach Mexican government systems, allegedly walking off with around 150GB of taxpayer and voter records.
The skill bar is collapsing at the same time. A UK-based seller with no real technical ability reportedly used AI to generate ransomware and sold each build for a few hundred dollars.
The aggregate numbers match the anecdotes. Over the past year, AI-assisted actors grew from a third of high-risk cyber cases to more than half, and most of those flagged used AI to help build malware.
The defenders' own data agrees. The 2026 Verizon DBIR ranked software vulnerabilities above stolen credentials as the top breach entry point for the first time in nearly two decades, and CrowdStrike clocked average breakout time at 29 minutes.
Frontier models like Mythos raise the ceiling on what is possible. They did not build the floor adversaries are already walking on.
β€9π₯1
βΌοΈπΊπΈπ¨π³ While the US is restricting and banning its frontier AI models, the Chinese are open-sourcing theirs. Z AI just released GLM-5.2, and new benchmarks show China's recently released Kimi K2.7 outperforms all American frontier models but Fable 5 on some tasks.
β€19π6π©2π₯1π¨1
"I was waiting for a train at the Kyoto Station. I saw this elderly man just staring at his hand, while everyone around him was on their phones. It was pure performance art. Nobody even noticed. Brilliant! What a commentary on our virtual existence."
Brian Castellani, Professor of Sociology
DAMN THIS IS AI SLOP. FUCK LINKEDIN.
Brian Castellani, Professor of Sociology
DAMN THIS IS AI SLOP. FUCK LINKEDIN.
1π€£37π’5π©4β€3
You can now pretend to be an AI chatbot.
Real people ask questions to the "AI" chatbot, and on the other end, you answer them.
It also works the other way around: you can ask questions to the "AI" chatbot that other users answer.
https://youraislopbores.me
Real people ask questions to the "AI" chatbot, and on the other end, you answer them.
It also works the other way around: you can ask questions to the "AI" chatbot that other users answer.
https://youraislopbores.me
π€£13π€ͺ5π₯°1π1
Media is too big
VIEW IN TELEGRAM
βΌοΈπ¨ This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required.
Microsoft has patched it as CVE-2026-42824, rated critical.
https://www.varonis.com/blog/searchleak
Microsoft has patched it as CVE-2026-42824, rated critical.
https://www.varonis.com/blog/searchleak
π₯9β€1π€1
π¨ A ransomware attack has shut down mills at Mackay Sugar, Australia's second-largest raw sugar producer. The Gentlemen group (Storm-2697) named the company on its leak site, with two of three Queensland mills hit and cane intake halted. Mackay Sugar is staging a restart this week but hasn't said whether data was stolen.
π€8β€1
π¨ Supply chain attack: 141 packages in the npm mastra scope were republished overnight to ship a remote access trojan.
The source code was never touched. The attacker just added one dependency, easy-day-js, that downloads persistent malware on install.
https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack/
The source code was never touched. The attacker just added one dependency, easy-day-js, that downloads persistent malware on install.
https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack/
π€―2
βΌοΈπ¨ BREAKING: 320,000 Fortinet firewall devices have been targeted in a campaign that has been dubbed 'FortiBleed'. Attackers were able to confirm 75,000 working credentials against the admin and SSL VPN interfaces.
The victims include really big names like Samsung, Oracle, Spotify, Sony, and more.
The data was first surfaced by researcher Volodymyr "Bob" Diachenko and analyzed by Hudson Rock and SOCRadar. The operation runs as a self-feeding loop. Attackers scan the internet for exposed Fortinet devices, then test each one against a curated list of passwords leaked from earlier Fortinet breaches and infostealer logs. Every successful login gets recorded into a verified database. They then turn each compromised box into a listening post, sniffing the traffic passing through the firewall to harvest fresh credentials, which go straight back into the scanner.
The scale is large. The group ran an estimated 1.16 billion credential attempts against more than 320,000 FortiGate targets, plus 2.1 billion brute-force tries against 160,000 MSSQL servers. In the deeper intrusions they intercept SSL VPN authentication hashes, crack them on a dedicated 45-GPU cluster, and move into internal Active Directory.
Diachenko confirmed full network compromises in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor that had classified defense documents stolen.
If you run Fortinet, act now: rotate every VPN and admin credential, enforce MFA on all external gateways, restrict management access to approved sources, segment internal networks, and audit gateway logs for unusual logins. Hudson Rock has a free domain lookup at hudsonrock.com/fortinet.
Data surfaced via the Hunt Intelligence, Inc. feed.
The victims include really big names like Samsung, Oracle, Spotify, Sony, and more.
The data was first surfaced by researcher Volodymyr "Bob" Diachenko and analyzed by Hudson Rock and SOCRadar. The operation runs as a self-feeding loop. Attackers scan the internet for exposed Fortinet devices, then test each one against a curated list of passwords leaked from earlier Fortinet breaches and infostealer logs. Every successful login gets recorded into a verified database. They then turn each compromised box into a listening post, sniffing the traffic passing through the firewall to harvest fresh credentials, which go straight back into the scanner.
The scale is large. The group ran an estimated 1.16 billion credential attempts against more than 320,000 FortiGate targets, plus 2.1 billion brute-force tries against 160,000 MSSQL servers. In the deeper intrusions they intercept SSL VPN authentication hashes, crack them on a dedicated 45-GPU cluster, and move into internal Active Directory.
Diachenko confirmed full network compromises in Japan, Taiwan, Vietnam, Iraq, and Turkey, including a Turkish NATO defense contractor that had classified defense documents stolen.
If you run Fortinet, act now: rotate every VPN and admin credential, enforce MFA on all external gateways, restrict management access to approved sources, segment internal networks, and audit gateway logs for unusual logins. Hudson Rock has a free domain lookup at hudsonrock.com/fortinet.
Data surfaced via the Hunt Intelligence, Inc. feed.
π5π₯3β€2
π¨ An active campaign malware on Steam is hiding payloads inside Wallpaper Engine desktop wallpapers.
Dozens of infected packages, some with tens of thousands of downloads, drop the DarkComet backdoor plus Lumma and Vidar infostealers to steal Steam accounts.
https://www.kaspersky.com/about/press-releases/kaspersky-discovered-a-malware-campaign-targeting-steam-users-through-infected-wallpaper
Dozens of infected packages, some with tens of thousands of downloads, drop the DarkComet backdoor plus Lumma and Vidar infostealers to steal Steam accounts.
https://www.kaspersky.com/about/press-releases/kaspersky-discovered-a-malware-campaign-targeting-steam-users-through-infected-wallpaper
π8π3π2β€1π€ͺ1
βΌοΈπ¨ A critical Joomla Content Editor vulnerability is under active attack and rated CVSS 10.0. Joomla is used by 1.2% of all websites on the internet.
The vulnerability, CVE-2026-48907: an unauthenticated attacker can create an editor profile, upload PHP, and take full control of the site.
CISA and Italy's CSIRT have both issued alerts.
The vulnerability, CVE-2026-48907: an unauthenticated attacker can create an editor profile, upload PHP, and take full control of the site.
CISA and Italy's CSIRT have both issued alerts.
π¨ An AI-enabled Dutch man was sentenced to 2.5 years in prison for using deepfakes to open 47 bank accounts. The man used ChatGPT to plan his criminal activity, which included using residential proxies.
He sourced victim photos from social media, older data breaches, and by posing as a landlord on an online marketplace to request ID documents. He then built deepfakes from those photos to beat the bank's facial verification during mobile onboarding.
Border police flagged him carrying multiple bank cards. His phone held dozens of IDs, victim photos, and ChatGPT chats on how to bypass identity verification.
He sourced victim photos from social media, older data breaches, and by posing as a landlord on an online marketplace to request ID documents. He then built deepfakes from those photos to beat the bank's facial verification during mobile onboarding.
Border police flagged him carrying multiple bank cards. His phone held dozens of IDs, victim photos, and ChatGPT chats on how to bypass identity verification.
π€£16π4π2π2β€1π₯1