Author: precious

I’m Precious Amusat, Phronews’ Content Writer. I conduct in-depth research and write on the latest developments in the tech industry, including trends in big tech, startups, cybersecurity, artificial intelligence and their global impacts. When I’m off the clock, you’ll find me cheering on women’s footy, curled up with a romance novel, or binge-watching crime thrillers.

Novee Security has confirmed that a vulnerability pattern its researchers call Cordyceps leaves more than 300 GitHub repositories open to full attacker takeover, including projects run by Microsoft, Google, Apache and Cloudflare. The firm scanned roughly 30,000 high impact repositories, flagged 654 of them in a single automated pass, and confirmed that more than 300 were fully exploitable through attacker controlled code execution, credential theft or outright supply chain compromise. Researchers named the pattern after the parasitic fungus known for slowly taking over its host from the inside, since the flaw burrows into software development pipelines in a similar way.…

Read More

An unnamed communications service provider’s Cisco SD-WAN infrastructure sat under a threat actor’s root level control for months and its own administrators never noticed. Google-owned threat intelligence firm Mandiant disclosed this intrusion last month, tracing the attacker’s full path through a vulnerability now tracked as CVE-2026-20245. It is important to note that Cisco built the software and is not the party that was breached. The flaw only lived inside Cisco’s SD-WAN products, and the actual intrusion took place in a customer’s network of an unnamed service provider that had deployed those products to run its own infrastructure. Mandiant investigated that…

Read More

Anthropic has accused Alibaba’s Qwen AI lab of running fake accounts to extract Claude’s capabilities at scale, telling the U.S. Senate Banking Committee that operators linked to Alibaba generated 28.8 million exchanges with Claude through roughly 25,000 fraudulent accounts. The AI safety company calls it the largest “distillation attack” it has documented to date. The accusation was sent in a letter to Senators Tim Scott and Elizabeth Warren as seen by Bloomberg, Reuters, and CNBC. Alibaba has not formally responded to the Senate committee, although its stated position to reporters is that it does not use outputs from proprietary AI…

Read More

OpenAI has built its first chip from the ground up and it does one specific job – handling ChatGPT and Codex requests without routing every one of them through Nvidia hardware. Called Jalapeño, the chip was developed with Broadcom and marks OpenAI’s entry into a group that every other major AI lab joined years ago, the group of companies that design their own silicon instead of buying all of it from outside vendors. What Jalapeño Does Jalapeño is an ASIC (Application-Specific Integrated Circuit), which means it was built to do one job well rather than many jobs adequately. And this…

Read More

Norway’s Prime Minister Jonas Gahr Støre has announced that generative AI tools are now off-limits for elementary school students across the country, effective from the new school year beginning in late August. The ban applies to students in first through seventh grade, covering ages 6 to 13, and the decision makes Norway one of the first countries in the world to formally prohibit AI use at that level of education. This means students in lower secondary school, aged 14 to 16, can use generative AI only under a teacher’s direct supervision, while older students aged 17 to 19 are encouraged…

Read More

The UK’s National Cyber Security Centre (NCSC) has published a formal guidance post telling developers and organisations exactly how much trust to place in AI-generated code, which is otherwise called vibe coding. Written by Toby W, a Principal Security Architect at the NCSC, the blog post lays out what the agency is calling a “vibe coding spectrum,” a framework for how organisations should calibrate their use of AI-assisted software development depending on the risk attached to what they are building. This post is the NCSC’s most practical intervention yet on vibe coding, and it arrives as AI coding tools have…

Read More

North Korea’s Sapphire Sleet hacking group compromised 144 packages in the Mastra AI framework’s npm scope in a single 88-minute automated campaign. Developers who ran a standard install command during that window may have handed a foreign state actor their cloud credentials, LLM API keys, and cryptocurrency wallet data without any visible warning. Microsoft attributed the attack with “high confidence” to Sapphire Sleet, also tracked as BlueNoroff, a North Korean state actor that primarily targets the financial sector. What Mastra Is and Why It Was Targeted Mastra is an open-source TypeScript AI agent framework with over 1.1 million combined weekly…

Read More

Security researchers have identified an active, large-scale credential compromise campaign affecting Fortinet FortiGate firewalls, which has been dubbed FortiBleed. According to Hudson Rock, the dataset contains 73,932 unique firewall URLs across 194 countries and impacts 21,632 unique domains. The number of compromised devices stands at 86,644 as of June 19, 2026, according to data from SOCRadar. And the group behind it is still adding new victims. The dataset was surfaced on June 17, 2026 by security researcher Volodymyr “Bob” Diachenko and verified by Hudson Rock, SOCRadar, Arctic Wolf, and Kevin Beaumont. Among the organizations Hudson Rock says appear in the…

Read More

Cybersecurity researchers at Cybernews recently discovered an exposed database containing roughly 24 billion stolen credential records, making it one of the largest collections of stolen login data ever found on the internet. The records, stored in more than 8.3 terabytes of data, included usernames, email addresses, plaintext passwords, and the login URLs the credentials were meant to unlock. The database was hosted on a publicly accessible Elasticsearch cluster, meaning anyone who knew where to look could browse its full contents without any login or authentication. After the original report was published, researchers learned that the dataset belonged to a threat…

Read More

SpaceX has signed a computing power deal worth up to $6.3 billion with Reflection AI, the open-source artificial intelligence startup founded by former Google DeepMind researchers. Under the agreement, Reflection will pay $150 million per month beginning July 1, 2026, for access to Nvidia GB300 chips at SpaceX’s Colossus 2 data center near Memphis, Tennessee. The contract runs through the end of 2029, although both parties can exit with 90 days’ notice after the first three months. The deal adds Reflection to a growing list of outside companies renting compute capacity from SpaceX, following earlier agreements with Anthropic, Google, and…

Read More