Latest
Everything, newest first.
- Apple issues new mercenary spyware alerts to targeted iPhone users
Citizen Lab researcher John Scott-Railton urged recipients to verify the warning through Apple and seek expert security help.
- Sansec detects attempts to exploit critical Adobe Commerce account-takeover flaw
Founder Willem de Groot's security shop says its WAF is blocking attempts, while Adobe says it has no confirmed in-the-wild exploits.
- Quantinuum reports $8 million Q2 revenue, partners with Oracle on Helios cloud service
CEO Rajeeb Hazra says Quantinuum's $2.1 billion in cash, cash equivalents and short-term investments gives it room to accelerate its business plans while maintaining disciplined capital allocation.
- Trump Media posts $238 million loss as Trump's crypto pivot overwhelms media revenue
The president's company is selling faster access to posts from Trump and his administration while bitcoin and Cronos losses dwarf revenue from Truth Social.
- Wordfence reports BdThemes supply-chain compromise through WordPress admin feed
Wordfence reported malicious code delivered through a BdThemes promotional system inside WordPress dashboards after an attacker poisoned a vendor-controlled JSON feed.
- No, the FAA didn't hire 2,000 new air traffic controller gamers
The April 2026 ads targeted gamers; the cited total was reached in fiscal 2025 and counts trainees, not fully certified controllers.
- Cloudflare CTO proposes a Starlink-native transport protocol; Musk forwards it
Dane Knecht wants Cloudflare and Starlink to redesign internet transport for moving satellites, extending earlier work on edge capacity.
- RuntimeWire passes 1,000 unique RSS subscribers
The milestone gives the independent AI and startup publication a growing base of readers who receive its reporting outside algorithmic feeds.
- Original reporting drove 71% of RuntimeWire reads in the last 30 days
The share excludes unclassified early articles and uses a strict test that treats any cited news publication as press-sourced.
- 77 counterfeit Open VSX extensions harvested developer and CI metadata
Manifold Security tied the packages to one domain; 19 profiled Git repositories and build environments before Open VSX removed them.
- Apple briefly removes Telegram as Durov alleges a takedown extortion attack
Pavel Durov alleges an extortion scheme exploited edited posts, while Apple says Telegram removed the content and banned the account.
- Hackers copy ownership records for 31,000 Liechtenstein entities
The breach hit a government register used to fight money laundering, exposing records tied to companies, foundations and trusts.
- AUR malware wave forces Arch Linux to disable every package push
The volunteer-run project escalated from blocking package adoption to freezing the AUR write path after attackers abused trusted package workflows.
- HackerOne will require government ID for every bug bounty submission
The August 14th rule covers new and existing accounts, while unpaid vulnerability disclosure programs remain open without verification.
- Tesla produces its 10 millionth vehicle, six years after crossing 1 million
The milestone car rolled out of Fremont as Tesla prepares the California factory for a larger role in robotics.
- ExfilSquad claims Microsoft breach, but the evidence remains unverified
The new extortion actor published 15 victim claims in one burst, a pattern researchers say is more consistent with a bulk launch or fabrication.
- Researcher says Cursor uploaded 736 MB despite disabled indexing
Migel Tissera says the transfers continued from July 18th to July 27th after his paid plan ended; Cursor's docs tie such uploads to indexing.
- RuntimeWire's First 10 Weeks: 164,500 Pageviews, 1,343 Stories and Two Viral Hits
Ten weeks after publishing its first story, RuntimeWire recorded 56,000 pageviews and published 225 articles in a single week as traffic, membership and newsroom output reached new highs.
- Clipboard Health lawsuit forces open the economics of gig nursing
Clipboard Health co-defendant ordered to reveal nurse wages, client fees and contractor-cost math
- GitHub issues $100,000 bounty for critical RCE vulnerability disclosed by @sagitz_
The researcher disclosed CVE‑2026‑3854, a critical RCE flaw, prompting the largest payout in GitHub's Vulnerability Reward Program to date.
- watchTowr sees SharePoint attackers stealing keys that can outlast patches
watchTowr says its honeypots saw attacks within hours of public exploit code, matching founder Benjamin Harris's core security thesis.
- C3EL wins two NASA SEWP VI slots for federal IT buying
The Tampa woman-owned contractor gains access to product and mission-services categories, but the IDIQ ceiling is not booked revenue.
- Boston Dynamics keeps Atlas in the World Cup conversation with Viking Row clip
The Waltham robotics company posted a Viking Row clip days after Hyundai put Atlas inside a live World Cup match environment.
- CERT/CC warns Tenda router firmware has an undocumented admin backdoor
CERT/CC says five firmware builds accept any username if a hidden alternate password matches a device configuration value.