NYC Health + Hospitals Breach Exposes 1.8 Million Patient and Employee Records — Attackers Had 11 Weeks of Network Access
Summary A data breach at NYC Health + Hospitals Corporation — the largest public health system in the United States — has compromised personal and protected health information belonging to…
Cohere Releases Command A+ — A 218B Parameter Open-Source MoE Model Built for Sovereign Critical Infrastructure
Summary Cohere has released Command A+, a powerful open-source Mixture-of-Experts (MoE) model under an Apache 2.0 license, purpose-built for sovereign critical infrastructure. The model spans 218 billion parameters but activates…
NSA Releases Security Guidance for Model Context Protocol (MCP) — Warns Agentic AI Systems Introduce “Novel and Systemic Risks”
Summary The National Security Agency’s Artificial Intelligence Security Center (AISC) has released a Cybersecurity Information Sheet titled “Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation.” The guidance addresses…
Opexus Insider Attack Destroys 30+ Federal Agency Databases — FBI Investigating Twin Brothers Who Allegedly Wiped IRS and GSA Systems
Summary Opexus, a software services provider that handles sensitive data for nearly every U.S. federal agency, has disclosed a devastating insider attack. Two employees — identified as twin brothers Muneeb…
Microsoft Exposes Massive Credential Theft Campaign — 35,000 Users Across 13,000 Organizations in 26 Countries Targeted
Summary Microsoft has disclosed details of a large-scale credential theft campaign that targeted more than 35,000 users across 13,000 organizations in 26 countries. The sophisticated phishing operation used code-of-conduct-themed lures…
GitHub Breached — TeamPCP Exfiltrates 3,800 Internal Repositories via Poisoned VS Code Extension
Summary GitHub has confirmed a significant breach of its internal infrastructure after threat actor group TeamPCP listed approximately 3,800 of the platform’s internal repositories for sale on a cybercrime forum…
Google and Blackstone Launch $5B AI Cloud Venture to Commercialize TPU Compute-as-a-Service
Summary Google and Blackstone announced a joint venture today to create a new AI cloud company, with Blackstone committing an initial $5 billion. The venture will offer Google Cloud’s Tensor…
KPMG and Anthropic Sign Global Alliance — Launch Claude-Powered Digital Gateway for Enterprise Clients
Summary KPMG and Anthropic announced a global strategic alliance today, launching the “KPMG Digital Gateway Powered by Claude” — a platform that embeds Anthropic’s frontier AI models directly into KPMG’s…
Critical Vulnerability in Universal Robots Exposes Industrial Cobot Fleets to Remote Takeover (CVE-2026-8153)
Summary A critical OS command injection vulnerability (CVE-2026-8153, CVSS 9.8) has been disclosed in Universal Robots’ PolyScope 5 operating system — the software that powers and controls the Danish company’s…
Microsoft Dismantles Fox Tempest — A Malware-Signing-as-a-Service Operation Fueling Ransomware Gangs
Summary Microsoft’s Digital Crimes Unit announced today the seizure and disruption of infrastructure belonging to Fox Tempest, a financially-motivated threat group that operated a sophisticated malware-signing-as-a-service platform. The operation, backed…
