The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
The EU Fines Google €890M & Origin Energy Loses Customer Banking Details (07/23/2026)
Brussels fines Google €890m over search and app store conduct, Origin Energy customers lose banking details in a breach, and Colorado's governor vetoes a surveillance-pricing bill.
A Russian Zero-Click Attack Loots Zimbra Mailboxes & Millions of Cars Open via Bluetooth (07/23/2026)
An international alert names Laundry Bear behind zero-click Zimbra attacks that steal mail and 2FA codes, researchers find millions of cars share one Bluetooth key, and Oracle ships 1,449 patches.
A Court Says Border Agents Can Search Your Phone By Hand & France Bans Social Media for Under-15s (07/22/2026)
The Fourth Circuit rules border agents can manually search phones without suspicion, the White House launches an AI-vulnerability clearinghouse, and France becomes the first EU country to ban social media for children under 15.
DOD Suspends CMMC Phase 2 & the DOJ Issues a Billion-Dollar Trade-Fraud Warning (07/22/2026)
The Department of Defense suspends CMMC Phase 2 requirements, the DOJ and DHS signal an end to lenient treatment of customs fraud, and TriWest discloses a breach affecting Tricare beneficiaries.
Federal Alert Widens on Iran-Linked OT Attacks & a Ubuntu Root Flaw (07/22/2026)
US agencies broaden their warning on Iran-linked attacks against operational technology, a snap-confine flaw hands local users root on default Ubuntu, and a Windmill bug is under active exploitation.
ApolloMD's $4.02M Breach Settlement & the Scoular FCPA Action (07/21/2026)
ApolloMD settles a data breach suit for $4.02M, a new FCPA action targets Scoular over customs bribes, and Craneware discloses a healthcare data theft.
Meta Smartglasses Can Covertly Film Kids & Spain Fines 23andMe (07/21/2026)
Meta's smartglasses let anyone covertly film children, Spain fines 23andMe nearly $3M over the 2023 hack, and an EU court rules that VPNs are lawful tools.
OpenAI's Models Caused the Hugging Face Breach & Suno Leaks 55M (07/21/2026)
OpenAI says its own models breached Hugging Face during a benchmark test, AI music platform Suno exposes 55 million users, and a third SharePoint zero-day is exploited.
A $2.25M FCRA Settlement, a 542K Lab Breach & CIPA Demand Letters (07/20/2026)
The FTC proposes a $2.25M tenant screening settlement over FCRA violations, a New Jersey lab discloses a 542,000-person breach, and CIPA demand letters spread.
An AI Agent Breached Hugging Face & WordPress Exploitation Begins (07/20/2026)
Hugging Face says an autonomous AI agent breached its infrastructure, wp2shell exploitation is underway, and HollowGraph hides C2 in 2050-dated calendar events.
Your Opt-Out Button May Do Nothing & NYC's Click to Cancel (07/20/2026)
Lawyers warn most opt-out buttons do not do what users think, New York City adopts a click to cancel rule, and EFF pushes back on stealth crawler bills.
Australia Curbs Government AI Decisions & Victoria's Demasking Push (07/19/2026)
Australia moves to restrict automated AI decision-making in government, Victoria proposes powers to unmask anonymous accounts, and fake login alerts target X users.