The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
Basic-Fit Breach Hits 1 Million Members, Adobe Patches Exploited Acrobat Zero-Day, APT41 Steals Cloud Creds
European gym chain Basic-Fit confirmed a breach exposing 1 million members across the EU. Adobe patched an actively exploited Acrobat Reader zero-day that lingered for months, and APT41 is harvesting cloud credentials with a zero-detection backdoor.
Booking.com Customers Warned of Data Hack, FTC Hits Publishing.com With $1.5M Penalty, Californians Sue AI Doctor Recorder
Booking.com is warning customers their data was accessed in a breach. The FTC extracted a $1.5M settlement from Publishing.com for deceptive income claims, and Californians filed suit over an AI tool that records doctor visits without consent.
DOJ Launches National Fraud Enforcement Division, New DEI Executive Order Hits Federal Contractors, CMS Opens Health Tech Ecosystem
The DOJ stood up a new National Fraud Enforcement Division. A new executive order reshapes DEI compliance for federal contractors, and CMS launched the first wave of its Health Tech Ecosystem information sharing tools.
CPUID Supply Chain Attack Distributes STX RAT, Three Gangs Drive 40% of March Ransomware
CPUID's website was compromised to push STX RAT through trojanized CPU-Z and HWMonitor downloads. Separately, Qilin, Akira, and Dragonforce drove 40% of 672 ransomware incidents in March as the threat landscape consolidates.
63 Healthcare Breaches in February Expose 8.1 Million Records, OCR Releases HIPAA Guidance
The HIPAA Journal reports 63 major healthcare data breaches in February 2026 exposing over 8.1 million records. OCR released new HIPAA Security Rule risk management guidance, the SEC named a new enforcement director, and FINRA launched a financial intelligence fusion center.
EFF Fights Section 702 Clean Extension, Post-Quantum Crypto Deadline Moved to 2029
The EFF is pushing Congress to reject a clean Section 702 reauthorization, demanding surveillance reforms before the authority expires. Meanwhile Google moved the post-quantum cryptography transition deadline to 2029, years earlier than expected.
Android Zero-Days, NPM Malware, CISA Alerts & ICS Flaws – 12/02/2025
Critical security alert on two actively exploited Android zero-days. Details on a massive NPM malware attack, new CISA KEVs, and critical ICS vulnerabilities.
Malicious LLMs, Digital ID & Online Blackmail – 11/28/2025
Privacy threats today: Malicious LLMs empower hackers, UK digital ID raises concerns, and online blackmail targets kids. Stay secure with our analysis.
SFO Guidance, HIPAA Breach, Data Lawsuit – 11/28/2025
SFO updates compliance guidance; HIPAA breaches at Ennoble Care & Circa Health. Main Line Fertility settles data lawsuit. Stay compliant! - 11/28/2025
Supply Chain Attacks, Tomiris APT & CISA KEV Alert – 11/28/2025
Daily security brief on critical supply chain attacks in npm and PyPI, new Tomiris APT techniques, and a CISA KEV alert for an actively exploited vulnerability.
OpenAI Breach, APT Attacks & AI Jailbreaks – 11/27/2025
Daily security summary covering the OpenAI API data breach via Mixpanel, expanded Bloody Wolf APT attacks, and a new poetic jailbreak technique for LLMs.
OpenAI Breach, Student Privacy & EU Social Media Ban – 11/27/2025
Privacy news: OpenAI data breach, EFF fights student surveillance, EU proposes social media ban for minors. Stay informed on key privacy issues.