Bigtech
Curated coverage and analysis in this editorial area.

ClickFix macOS: When Users Bypass Gatekeeper Themselves
Microsoft has documented the latest evolution of ClickFix campaigns on macOS: operators have ditched manual DMG installers for Termina…

Unit 42: Cloud Buckets Hijackable via Delete-and-Recreate
Unit 42 research shows how globally unique bucket names enable silent redirection of logs and messages across cloud accounts. Cross-CS…

WhatsApp Weaponized: VBS and RMM Delivered via DMs from Compromised Contacts
An active campaign since June 2026 uses WhatsApp Desktop to distribute malicious VBScript files, install legitimate RMM software, and…

Kodak Confirms Breach: ShinyHunters Threatens 2.2 Million Records
Kodak confirms a data breach after the ShinyHunters extortion group claimed theft of over 2.2 million records and threatened publicati…

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads
A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…

iRhythm: Patient Health Data Stolen via Social Engineering
iRhythm Holdings disclosed a data breach in which attackers exfiltrated PHI and PII from third-party business applications through soc…

Maine Disables Breach Notification Portal After Fake Discord and VRChat Disclosures
Maine's government portal automatically published data breach notifications without verification, facilitating the spread of misinform…

Microsoft Backtracks on Legal Threats Against Zero-Day Researcher Following Industry Backlash
Microsoft threatened criminal action against researcher Nightmare-Eclipse over six Defender zero-days, partially retracting its stance…

Microsoft Retracts Legal Threats Against Researchers Following Zero-Day Disclosure Backlash
Microsoft threatened criminal prosecution against researcher Nightmare-Eclipse for publishing six Windows zero-days before walking bac…

Trump Signs AI Executive Order: 30-Day Voluntary Review for Frontier Models
The executive order establishes a voluntary framework for pre-release government access to advanced AI models, tasking the NSA with mo…

Anthropic Grants ENISA Access to Mythos: A Strategic Shift for EU Cybersecurity
Anthropic is granting ENISA access to its Mythos model for vulnerability discovery. As the first EU entity to join Project Glasswing,…

ExifTool RCE: Kaspersky GReAT Uncovers macOS Command Injection via Metadata
CVE-2026-3102 impacts ExifTool versions 13.49 and earlier on macOS. The vulnerability allows for command injection within the SetMacOS…