Poppy debuts proactive AI assistant to help organize your digital life

Smartphones can be distracting with a dizzying number of apps and a constant stream of notifications. A new app called Poppy aims to clean up the clutter by consolidating your calendar, email, messages, and other sources into one dashboard. The idea, according to the company’s website, is that “Poppy takes care of you, so you […]

Azerbaijani energy company falls victim to repeated Microsoft Exchange exploits

Rabi LakshmananMay 13, 2026Cyber ​​espionage/malware Chinese-linked attackers were involved in “multi-wave intrusions” targeting unnamed oil and gas companies in Azerbaijan from late December 2025 to late February 2026, indicating an expansion of their targeting. Bitdefender has moderate to high confidence that this activity is the work of the hacker group known as FamousSparrow (also known […]

[Webinar] Why AppSec tools miss “fatal paths” (and how to fix them)

hacker newsMay 13, 2026AppSec / Webinar TL;DR: Stop chasing thousands of “toast” alerts. Join Wiz and the Okta/GitLab experts to learn how hackers link small flaws to create “deadly chains” in your data and how to break them. Sign up for strategic briefings here. Most security tools work like a smoke alarm that goes off […]

Most repair programs never confirm that the fix actually worked

hacker newsMay 13, 2026Cloud security/automation Security teams have never had greater visibility into their environments, and it has never been more difficult to ensure that what they fix stays fixed. Mandiant’s M-Trends 2026 report estimates the average usage time to be -7 days. Verizon 2025 DBIR states that the median time to remediate vulnerabilities on […]

Microsoft patches 138 vulnerabilities, including DNS and Netlogon RCE flaws

Microsoft on Tuesday released patches for 138 security vulnerabilities across its product portfolio, but none are listed as publicly known or under active attack. Of the 138 defects, 30 were rated critical, 104 were rated important, 3 were rated moderate, and 1 was rated low. As many as 61 vulnerabilities were categorized as privilege elevation […]

GemStuffer exploits over 150 RubyGems to leak scraped UK council portal data

Ravi LakshmananMay 13, 2026Software supply chain/data breach Cybersecurity researchers are warning people of a new campaign called GemStuffer. This campaign targets the RubyGems repository, which contains over 150 gems, and uses the registry as a data exfiltration channel rather than malware distribution. “The package does not appear to be designed to compromise large-scale developers,” Socket […]

Android adds intrusion logging for advanced spyware forensics

Google on Tuesday announced a new opt-in Android feature called Intrusion Logs to store forensic logs to better analyze advanced spyware attacks. Intrusion logging, available as part of Advanced Protection Mode, “enables persistent privacy-preserving forensic logging and allows devices to be investigated in case of a suspected breach,” the company said. It added that the […]

Former Tesla executive and Heron Power CEO Drew Baglino launches heat pump startup

Former Tesla executive Drew Baglino secretly founded a heat pump startup, TechCrunch has learned. This is the second company Baglino has founded in the two years since leaving Tesla. Sources have confirmed the existence of a startup called Sadi Thermal Machines, and TechCrunch reviewed the company’s filings in Delaware and California. Sadie was founded in […]