The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
Midnight Blizzard Hijacks Hotel Sign-In Portals & Chrome Fixes 1,442 Flaws (07/31/2026)
A Russian sub-cluster compromises hospitality sign-in portals to hit travelers worldwide, three Chrome releases fix more bugs than the prior 23 combined, and CISA warns of a spike in water system attacks.
The DOJ Issues Its First Healthcare Declination & Health-ISAC Warns on ShinyHunters (07/31/2026)
The DOJ declines criminal charges against a healthcare company under its new enforcement policy, Health-ISAC warns of rising ShinyHunters attacks, and Colorado's AI Act is amended after a long fight.
EU AI Act Transparency Enforcement Starts Sunday & South Carolina Adds Personal Liability (07/31/2026)
The EU AI Act's transparency rules take effect August 2 requiring chatbots to identify themselves, South Carolina's design code reaches employees personally, and the Tunick border case gets a closer read.
An Azure Flaw Exposed a Platform-Wide Key & Russian Actors Survive Credential Rotation (07/30/2026)
A patched Azure Cosmos DB flaw could have given access to any customer database, Russian actors exploit an OWA flaw to keep mailbox access after password resets, and Copilot for Word propagates hidden prompts.
The FTC Sues Hims & Hers Over Health Data Sharing & Flock Cameras Draw Safety Warnings (07/30/2026)
The FTC and two states sue Hims & Hers for sharing sensitive health information with advertisers, safety advocates say Flock camera poles may fail crash standards, and xAI sues Minnesota over its nudification ban.
OSF Healthcare Pays $552K to OCR & California Mandates AI Training-Data Disclosure (07/30/2026)
OSF Healthcare settles an OCR HIPAA investigation for $552,250, California's AB 2013 requires generative AI developers to disclose training data, and the EU finalizes AI Act transparency guidelines.
Two Health Systems Settle Pixel Suits & Breach Costs Climb to Nearly $5M (07/29/2026)
Banner Health and LifeStance settle website tracking lawsuits, IBM finds the global average breach now costs almost $5 million, and New Jersey's new privacy law widens who must comply.
A Coordinated Attack Hits 30+ Minnesota Water Systems & One Plant Goes Offline (07/29/2026)
More than 30 Minnesota community water systems were hit in a coordinated OT attack with Iran-linked CyberAv3ngers suspected, a single webpage visit can compromise Tor Browser, and a Check Point exploit goes public.
A Judge Blocks a Mass Phone Warrant & AI Age Checks Threaten Child Refugees (07/29/2026)
A federal judge refused a warrant covering thousands of uninvolved Ohio residents' phones, a charity warns AI age-detection will misclassify child refugees as adults, and the FCC bans Chinese humanoid robots.
An AI Model Breaks a Post-Quantum Scheme & JFrog Confirms the Artifactory Zero-Day (07/28/2026)
Anthropic's Mythos model derived a key-recovery attack on a post-quantum signature scheme, JFrog confirms OpenAI's models exploited an Artifactory zero-day, and 24,650 exposed BMCs leak password hashes.
Gay Bars Are Building Patron Databases & a Judge Flags an AI-Hallucinated Asylum Refusal (07/28/2026)
ID-scanning systems at LGBTQ+ bars are building databases of patrons, a judge says the Home Office relied on AI-hallucinated information to refuse asylum, and AI smart lamp-posts arrive in Britain.
An Addiction Treatment Provider Breaches 145,700 Records & the CSA Issues Emergency AI Guidance (07/28/2026)
Operation PAR discloses a 145,700-record breach of substance use disorder data, the Cloud Security Alliance issues emergency guidance after the autonomous AI breach, and a House committee moves to block OSHA's heat standard.