Two alleged TeamPCP hackers arrested over the Shai-Hulud supply chain worm
Australian Federal Police arrested two men this week accused of operating as members of TeamPCP, the hacking group behind the Shai-Hulud supply-chain worm that has infected more than 1,000 organizations since December. The AFP statement says the men, from the Western Australian towns of Cottesloe and Mandurah, face 14 charges in a joint operation with […]
GLM-5.3 goes open-weight, and its specialty is unsettling
Z.ai has released the weights for GLM-5.3, its frontier coding model, on Hugging Face. The launch blog post from mid-August promised the weights two weeks after launch, once safety evaluation and hardening finished, and that window has now closed. What makes this release unusual is not the benchmark table, though the numbers are strong. It […]
Azure VM Image Builder goes GA in sovereign and air-gapped clouds
Running the same image pipeline across commercial Azure and government or China-hosted clouds has always meant maintaining two setups. Azure VM Image Builder now removes part of that split: the service is generally available in Azure Government, China North 3, Azure Government Secret, and Azure Government Top Secret, according to Microsoft’s announcement. Teams that build […]
Gemini 3.5 Transcribe Pushes Speech-to-Text Toward Production-Grade Accuracy
Google introduced Gemini 3.5 Transcribe this week, its most accurate speech-to-text model to date, and the interesting part is what it does after the words are recognized. The model converts raw audio directly into polished, formatted text: it strips filler words, resolves self-corrections like “let’s meet Tuesday, no, Wednesday”, and auto-formats the output. Conventional speech […]
Lakebase Branching Lets Copilot Agent Mode Debug Against Production Data Without Touching Production
Microsoft has put a new capability into public preview for Azure Databricks: copy-on-write branching for Lakebase, wired directly into GitHub Copilot agent mode. In one command, a developer can branch a production Lakebase database, point Copilot agent mode at the branch endpoint, and debug an AI application against realistic data while the production database stays […]
Azure Sphere OS 26.06 Reaches Production Devices with CVE Fixes Aboard
Microsoft has released Azure Sphere OS version 26.06 to the Retail feed, which means the update is rolling out automatically to internet-connected Sphere devices right now. It is an OS-only release: there is no updated SDK, so developers do not need to touch their toolchain. Devices that can reach the cloud will pick up the […]
Azure SRE Agent VNet Integration Reaches General Availability with Private Network Controls
Microsoft has officially announced the general availability of Virtual Network (VNet) integration for Azure SRE Agent. The capability allows operations and platform teams to deploy and operate Microsoft’s autonomous site reliability engineering agent entirely within their private virtual network topology. By routing the agent’s outbound management traffic through dedicated subnets, organizations can enforce corporate Network […]
Snowflake Deprecates Service Account Passwords as Teams Face Credential Mapping
Snowflake is systematically eliminating single-factor password authentication for legacy service accounts across its data platform. Under the enforcement timeline, automated service accounts designated with the legacy service user type will no longer be permitted to authenticate using static passwords. Instead, data engineering and platform teams must transition automated workloads to public-key cryptography, OAuth flows, or […]
Avada WordPress Theme Zero-Click RCE Chains Six Flaws into Remote Takeover
A zero-click remote code execution chain affecting the Avada WordPress theme and its companion Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code on vulnerable hosts. Tracked collectively as CVE-2026-18431, the vulnerability carries a CVSS score of 9.8. Because Avada stands as one of the most widely sold commercial WordPress themes in history […]
Attackers Abuse npm Mirrors and unpkg CDNs to Host Fake CAPTCHA Phishing Pages
Turning Public Package CDNs into Phishing Infrastructure A newly uncovered supply chain campaign has demonstrated how threat actors are repurposing npm package mirrors and public content delivery networks (CDNs) to host deceptive phishing pages. By publishing lightweight packages containing malicious HTML files to the npm registry, attackers exploit open CDN services like unpkg to serve […]
AnonyMousKIT Phishing Platform Uses Conversational Voice AI to Unlock Stolen iPhones
Automating the Social Engineering of Device Unlocks Security researchers at SOCRadar have uncovered a sophisticated phishing-as-a-service platform dubbed AnonyMousKIT. Designed specifically to bypass Apple Activation Lock on stolen iOS devices, the kit integrates conversational voice AI agents alongside automated multi-channel messaging to deceive device owners into surrendering their screen passcodes. When an iPhone or iPad […]
Azure Launches 248 and 372 vCPU Sizes for D and E v7 Virtual Machines
Massive Compute Densities Reach General Availability Azure has officially made the largest tiers of its Dlsv7, Dsv7, and Esv7 virtual machine lines generally available, offering VM configurations scaling up to 248 and 372 vCPUs. Powered by Intel Xeon 6 6973PC processors (Granite Rapids architecture), these instances represent a significant leap in raw CPU core density […]