The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
Two Health Systems Settle Pixel Suits & Breach Costs Climb to Nearly $5M (07/29/2026)
Banner Health and LifeStance settle website tracking lawsuits, IBM finds the global average breach now costs almost $5 million, and New Jersey's new privacy law widens who must comply.
A Coordinated Attack Hits 30+ Minnesota Water Systems & One Plant Goes Offline (07/29/2026)
More than 30 Minnesota community water systems were hit in a coordinated OT attack with Iran-linked CyberAv3ngers suspected, a single webpage visit can compromise Tor Browser, and a Check Point exploit goes public.
A Judge Blocks a Mass Phone Warrant & AI Age Checks Threaten Child Refugees (07/29/2026)
A federal judge refused a warrant covering thousands of uninvolved Ohio residents' phones, a charity warns AI age-detection will misclassify child refugees as adults, and the FCC bans Chinese humanoid robots.
An AI Model Breaks a Post-Quantum Scheme & JFrog Confirms the Artifactory Zero-Day (07/28/2026)
Anthropic's Mythos model derived a key-recovery attack on a post-quantum signature scheme, JFrog confirms OpenAI's models exploited an Artifactory zero-day, and 24,650 exposed BMCs leak password hashes.
Gay Bars Are Building Patron Databases & a Judge Flags an AI-Hallucinated Asylum Refusal (07/28/2026)
ID-scanning systems at LGBTQ+ bars are building databases of patrons, a judge says the Home Office relied on AI-hallucinated information to refuse asylum, and AI smart lamp-posts arrive in Britain.
An Addiction Treatment Provider Breaches 145,700 Records & the CSA Issues Emergency AI Guidance (07/28/2026)
Operation PAR discloses a 145,700-record breach of substance use disorder data, the Cloud Security Alliance issues emergency guidance after the autonomous AI breach, and a House committee moves to block OSHA's heat standard.
A Cyberattack Shutters 80 AnMed Facilities & a Revenue-Cycle Vendor Breaches 1.26M (07/27/2026)
AnMed closes nearly 80 facilities as it grapples with a cyberattack, revenue-cycle firm MCBS discloses a 1.26 million-person breach, and the DoD implements the FY25 NDAA contractor prohibition.
A Max-Severity Arista Zero-Day Is Exploited & an AI Agent Runs an Espionage Op (07/27/2026)
A CVSS 10.0 command-injection flaw in Arista VeloCloud Orchestrator is under active attack, an autonomous AI tool ran espionage against Thailand's finance ministry, and a vBulletin pre-auth RCE exploit goes public.
A Product-Safety Agency Demands Hospital ER Records & a UK Court Pierces Spyware Immunity (07/27/2026)
A federal product-safety agency demands identifiable ER records from major health systems, the UK Supreme Court rejects Bahrain's immunity in a spyware case, and the EDPB publishes draft anonymisation guidelines.
A Border Traveler Is Charged for Wiping His Phone & Vigilantes Are Killing Flock Cameras (07/26/2026)
The DOJ prosecutes an American for using a duress password at the border, a leaked document maps ICE's surveillance reach, and activists are disabling Flock license-plate cameras nationwide.
GitHub and PyPI Add a Delay to Blunt Supply-Chain Attacks & ChatGPT Handed Out Bioweapon Recipes (07/26/2026)
GitHub and PyPI introduce a time-based cooldown on new dependencies, Steam forum ClickFix lures infect gamers with cryptominers, and a report says ChatGPT gave some users step-by-step bioweapon guides.
Police Drone Programs Spread Nationwide & the EU AI Act Slips to 2027 (07/24/2026)
Hundreds of drone-as-first-responder programs clear a key hurdle, the EU pushes back its AI Act workplace rules to December 2027, and MSG's face-recognition cameras went dark for one guest.