Two alleged TeamPCP hackers arrested over the Shai-Hulud supply chain worm
Australian Federal Police arrested two men this week accused of operating as members of TeamPCP, the hacking group behind the Shai-Hulud supply-chain worm that has infected more than 1,000 organizations since December. The AFP statement says the men, from the Western Australian towns of Cottesloe and Mandurah, face 14 charges in a joint operation with […]
GLM-5.3 goes open-weight, and its specialty is unsettling
Z.ai has released the weights for GLM-5.3, its frontier coding model, on Hugging Face. The launch blog post from mid-August promised the weights two weeks after launch, once safety evaluation and hardening finished, and that window has now closed. What makes this release unusual is not the benchmark table, though the numbers are strong. It […]
Avada WordPress Theme Zero-Click RCE Chains Six Flaws into Remote Takeover
A zero-click remote code execution chain affecting the Avada WordPress theme and its companion Fusion Builder plugin allows unauthenticated attackers to execute arbitrary PHP code on vulnerable hosts. Tracked collectively as CVE-2026-18431, the vulnerability carries a CVSS score of 9.8. Because Avada stands as one of the most widely sold commercial WordPress themes in history […]
Attackers Abuse npm Mirrors and unpkg CDNs to Host Fake CAPTCHA Phishing Pages
Turning Public Package CDNs into Phishing Infrastructure A newly uncovered supply chain campaign has demonstrated how threat actors are repurposing npm package mirrors and public content delivery networks (CDNs) to host deceptive phishing pages. By publishing lightweight packages containing malicious HTML files to the npm registry, attackers exploit open CDN services like unpkg to serve […]
seL4 Microkernel Completes Full Formal Security Proofs on AArch64 Architecture
Formal verification represents the gold standard in software security, replacing probabilistic testing with mathematical proofs that code behaves exactly according to its formal specification. Proofcraft, in collaboration with the seL4 Foundation and supported by the UK National Cyber Security Centre (NCSC), has announced the completion of formal security proofs for the seL4 microkernel on the […]
Poisoned arrayref Rust Crate Shows Why Build-Time Execution Needs Guardrails
A Compromised Maintainer and Three Poisoned Crates Earlier this week, security researchers identified a coordinated supply-chain attack targeting the Rust package ecosystem. Attackers compromised the crates.io account of a maintainer responsible for arrayref, a widely used Rust library with tens of millions of downloads across cryptography, networking, and graphics packages. Once inside the account, the […]
Bridging Reverse Engineering and AI Agents: Deep Dive into the x64dbg MCP Server
Reverse engineering native binaries on Windows has traditionally been an intensely manual discipline, requiring reverse engineers to step through disassembly, inspect register states, analyze memory dumps, and reconstruct control flow graphs line by line. The release of the x64dbg-mcp-server project brings the Model Context Protocol (MCP) directly into the x64dbg debugger ecosystem. By exposing native […]
Qwen 3.8 27B Delivers Frontier Work on a Single GPU, If You Control Its Default Reasoning
Alibaba’s Qwen 3.8 27B is the latest open-weights flagship, and early impressions are strong: it is a 27B parameter, vision-capable model that hands a genuinely professional level of coding, tool-calling, and long-context work to a single consumer GPU. But it arrives with a catch that changes how you should use it. The default reasoning setting […]
OpenAI and Anthropic slash prices as Chinese AI rivals close the gap
OpenAI and Anthropic are slashing prices on their mid-tier AI models as cheaper Chinese alternatives gain traction among cost-conscious businesses and developers. The price cuts mark a shift from competing purely on model performance to competing on cost, with Chinese labs like DeepSeek and Moonshot forcing the market down. OpenAI cut prices on GPT-5.6 Luna, […]
DeepSeek Harness: the plugin first framework for AI agents
DeepSeek’s open source agent framework, DeepSeek Harness, exploded onto GitHub this week and picked up close to 70,000 stars in a single day. The repo’s tagline is simple and a little audacious: “everything is a plugin.” That phrasing is doing a lot of work, and it’s worth unpacking what the project actually ships, because the […]
Tailscale Traced Database Corruption to a 16-Year-Old SQLite Bug
SQLite is about as close to “boring, reliable” as a database gets. It sits inside phones, browsers, and countless desktop apps, and most developers never think about it twice. So when Tailscale, a company that runs a mesh VPN used by thousands, started seeing their SQLite databases get corrupted, the last thing anyone expected was […]
Researchers pull hidden reasoning out of Claude, GPT, and Gemini
Advanced AI models do not give you a straight answer all at once. They break a problem into pieces and work through them step by step, in a chain of thought that providers deliberately keep hidden. That hidden reasoning is valuable, because it is exactly what you would want if you were training your own […]