March 24, 10:39 UTC. The first poisoned LiteLLM package landed on PyPI two minutes earlier, and on some CI runner somewhere, the credential harvest had already started. Nobody outside the attacker noticed for hours. That…
Howard University never signed up to be a proxy provider. But for months, anyone with five dollars in crypto and a burner email address could route their internet traffic through the university’s entire /16 IP…
On July 26 and 27, 2026, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water and wastewater utilities across Minnesota. Attackers disrupted automated control functions, forcing some plants to switch…
OpenAI put two of its most advanced models inside a locked room to test how well they could hack. The models picked the lock, opened the door, walked out of the building, and broke into…
On July 28, 2026, JFrog confirmed what the security industry had been speculating about for a week, the package-registry proxy that OpenAI’s AI models exploited to escape their sandbox and hack Hugging Face was a self-hosted JFrog Artifactory…
Something we track in the Adversary Operations Group is residential proxy networks. Infoblox uncovered an operation they call Lurking Lizard, running since at least August 2022, that uses fake software installers to conscript devices as…
Someone pretending to be an Adidas recruiter sent me a meeting invitation last week. At least, that is what the email looked like. The branding was right. The recruiter’s name was real. The company logo…
Microsoft released an emergency patch on July 9, 2026, for a Microsoft Defender zero-day vulnerability dubbed “RoguePlanet” (CVE-2026-50656) that allows attackers to gain SYSTEM privileges on fully patched Windows 10 and Windows 11 devices (BleepingComputer,…
We track vulnerabilities in the Adversary Operations Group that have a clear exploitation path and no viable workaround. This pair on the SonicWall SMA 1000 is both. SonicWall confirmed on July 15 that attackers are actively…
The European Union and the United Kingdom jointly sanctioned dozens of Russian intelligence officers and affiliated entities on 13 July 2026, officially naming the FSB unit that directs the Turla hacking group. The EU council blacklisted…
A joint advisory from 19 allied cybersecurity agencies published on 13 July 2026 warns that Russian state hackers are systematically compromising routers to gain access to critical infrastructure networks worldwide. I am breaking down what…