Typosquatting is no longer a user problem. it’s a supply chain issue

AI-generated lookalike domains are now embedded within third-party scripts that run on your web properties. Here’s why the current stack can’t recognize them, and what detection actually requires: Download the CISO expert guide to typosquatting in the age of AI → TL;DR Typosquatting is no longer a user problem. Attackers are currently embedding lookalike domains […]
Microsoft releases mitigation for YellowKey BitLocker bypass CVE-2026-45585 exploit

Rabi LakshmananMay 20, 2026Vulnerabilities/Encryption Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability called YellowKey, following a public release last week. This zero-day flaw is currently tracked as CVE-2026-45585 and has a CVSS score of 6.8. This is described as bypassing the BitLocker security feature. “Microsoft is publicly aware of a Windows security […]
Grafana GitHub breach exposes source code via TanStack npm attack

Rabi LakshmananMay 20, 2026Supply chain attack/cloud security Grafana Labs announced on May 19, 2026 that an investigation into a recent breach found no evidence that any of its customers’ production systems or operations were compromised. The scope of the incident is limited to Grafana Labs’ GitHub environment, which includes public and private source code and […]
TeamPCP claims nearly 4,000 internal repositories have been compromised, GitHub is investigating

Ravi LakshmananMay 20, 2026Malware/Cloud Security GitHub announced Tuesday that it is investigating unauthorized access to its internal repositories after a notorious threat actor known as TeamPCP listed the platform’s source code and internal organization for sale on a cybercrime forum. “At this time, there is no evidence of any impact to customer information stored outside […]
Elon Musk says Sam Altman ‘stole’ nonprofit organization – but trial reveals he had similar intentions

The jury’s swift decision to dismiss Elon Musk’s lawsuit against OpenAI and the other founders of Microsoft confirmed what we saw in court. That means Musk’s case was a weak one, in part because he waited so long to file his case. In last week’s closing arguments, OpenAI’s lawyers detailed point-by-point how the law was […]
Google unveils new audio-equipped smart glasses at IO 2026, excerpts from Mehta’s book

Google is getting into the smart glasses game (again). At Google I/O on Tuesday, the company announced new partnerships with Warby Parker and Gentle Monster to produce a new line of AI-powered glasses. The devices are built to pair with Android and iOS devices and were designed in collaboration with Samsung, the company said. The […]
With Gemini 3.5 Flash, Google bets the next wave of AI on agents, not chatbots

Google announced Gemini 3.5 Flash on Tuesday. This is a new AI model that the company claims is the most powerful yet for coding and autonomous AI agents. The model, announced at the company’s annual Google I/O developer conference, allows developers to run coding pipelines independently, manage research projects, and build operating systems completely from […]
As you know, Google search is dead

The era of “10 blue links” is officially over. At the Google I/O conference on Tuesday, Google announced an overhaul of AI-powered search centered around a reimagined “intelligent search box.” The company says this is the biggest change to this entry point to the web since the search box was introduced more than 25 years […]
Google updates Gemini app to counter ChatGPT and Claude at IO 2026

At its annual Google I/O event on Tuesday, Google announced a series of new updates to its Gemini app, including a “Daily Briefs” feature, a redesigned interface, access to a new AI video model called Gemini Omni, and a new personal AI agent called Gemini Spark. The update signals Google’s efforts to turn the Gemini […]
Trapdoor Android ad fraud scheme reaches 659 million bid requests per day using 455 apps

Ravi LakshmananMay 19, 2026Malvertising/Mobile Security Cybersecurity researchers have revealed details of a new ad fraud and malvertising operation called “Trapdoor” targeting Android device users. According to HUMAN’s Satori Threat Intelligence and Research Team, this activity involved 455 malicious Android apps and 183 threat actor-owned command and control (C2) domains, turning the infrastructure into a multi-stage […]