Hugging Face's AI agent breach pushed it past OpenAI and Anthropic's refusals to Z.ai's open-weight GLM-5.2, exposing a gap in Western AI guardrails.
The FBI says a Florida student's Steam malware scheme stole $220,000 in crypto, the same campaign linked to a cancer patient's stolen donations months earlier.
Spotify's Android app hides passkey setup code, surfacing months after a public tracker named it among major apps still missing passkey login.
Google's Agentic Defense pairs Gemini AI with its $32 billion Wiz deal, but its own 2026 Mandiant report blames human error for most 2025 breaches.
Brussels ordered Google to open Android to rival AI assistants, but the same rule forces enterprise security teams to rebuild a decade-old permission model.
India switched on a White Rabbit time network in Bengaluru to cut GPS dependence for markets, telecom and power grids amid a global jamming surge.
Hackers are exploiting a critical Gitea Docker authentication bypass, CVE-2026-20896, just weeks after Gitea patched it, leaving repositories exposed.
A Moroccan intelligence whistleblower says the DGST used Pegasus spyware since 2017 to target journalists, Spanish ministers and Guardia Civil officers.
xAI open-sourced Grok Build after a researcher found it uploading full Git repos, but the exfiltration code still sits in the binary.
A former Moroccan intelligence officer has confirmed Rabat's long-denied use of Pegasus spyware, revealing a wider arsenal used against journalists.