News
-
U.S. orders Anthropic to suspend foreign access to Fable 5 and Mythos 5 models
The U.S. government ordered Anthropic to suspend foreign access to its Fable 5 and Mythos 5 AI models, citing national security concerns. Anthropic disabled the models and disputed the need for the broad export controls.
-
Kyushu Electric says missing drive exposed data of 10.9 million customers
Kyushu Electric Power said a missing backup drive may have exposed customer data tied to up to 10.9 million accounts after staff found a server room cabinet unlocked and the device gone on May 26.
-
Authorities dismantle AudiA6 crypto laundering service linked to ransomware proceeds
Authorities have dismantled the AudiA6 crypto laundering service, which investigators say moved more than $380 million for ransomware actors and other cybercriminals. The case led to arrests in Georgia and seizures across 11 countries.
-
South Korea fines Coupang record $409 million over data breach
South Korea’s privacy regulator fined Coupang a record 624.6 billion won, about $409 million, after a breach exposed data linked to more than 37 million customers and drew findings of weak security controls.
-
GitHub to disable npm install scripts by default in version 12
GitHub said npm version 12 will disable install scripts by default next month to curb supply chain abuse. The change will also restrict Git and remote dependencies unless users explicitly allow them.
-
Unpatched Langflow flaw under active exploitation, researchers say
An unpatched Langflow flaw tracked as CVE-2026-5027 is being actively exploited, researchers say. The bug can allow arbitrary file writes, and about 7,000 instances are exposed online.
-
Google patches Chrome zero-day CVE-2026-11645 after active exploitation
Google has patched 74 Chrome flaws, including CVE-2026-11645, a high-severity zero-day in the V8 engine that the company said was being exploited in the wild. Users are urged to update Chrome and other Chromium-based browsers.
-
Six protobuf.js flaws can expose Node.js apps to code execution, denial of service
Six vulnerabilities in protobuf.js could enable remote code execution or denial of service in Node.js apps, according to a Cyera technical analysis. Patches are available for affected protobufjs and protobufjs-cli releases.





