OpenAI co-founder Andrej Karpathy joins Anthropic’s pre-training team

Andrej Karpathy, a co-founder of OpenAI and an AI researcher who previously worked at OpenAI and previously led AI at Tesla, has joined Anthropic. “I joined Anthropic,” Karpathy posted on X Tuesday. “I think the next few years at the LLM front will be a particularly formative time, and I’m very excited to join the […]

US cyber agency CISA releases tons of passwords and cloud keys to the open web

US cybersecurity agency CISA may have been spared a major security breach thanks to an honest security researcher who identified publicly exposed credentials that allowed access to government clouds and internal agency systems. As first reported by independent security reporter Brian Krebs, GitGuardian security researcher Guillaume Valadon found a large amount of plaintext credentials listed […]

DirtyDecrypt PoC released for Linux kernel CVE-2026-31635 LPE vulnerability

Proof-of-concept (PoC) exploit code has been published that could allow local privilege escalation (LPE) for a security flaw in the recently patched Linux kernel. The vulnerability, known as DirtyDecrypt (also known as DirtyCBC), was discovered and reported by Zellic and the V12 security team on May 9, 2026, but was informed by the maintainer that […]

How OAuth consent bypasses MFA

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, more than 340 Microsoft 365 organizations in five countries were compromised. Platform targets received a message asking them to enter a short code at microsoft.com/devicelogin to complete a regular MFA challenge and left believing they had confirmed a routine sign-in. In […]

Drupal releases emergency core security update on May 20th, sites are told to prepare

Ravi LakshmananMay 19, 2026Vulnerabilities / Website Security Drupal has issued an alert stating that it plans to release a “Core Security Release” for all supported branches on May 20, 2026 from 5:00 PM to 9:00 PM (UTC). A maintainer of a PHP-based content management system (CMS) said, “The Drupal security team recommends that you allow […]

Vulnerability in SEPPMail Secure E-Mail Gateway allows RCE and email traffic access

Ravi LakshmananMay 19, 2026Vulnerabilities / Email Security A critical security vulnerability has been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution. This vulnerability could be exploited to cause remote code execution and allow an attacker to read arbitrary email from the virtual appliance. “These vulnerabilities could be exploited to read all email […]