The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
They Came In Through a Police Login (09/11/2026)
Florida confirmed its DAVID driver database was breached using a police department employee's credentials, and DHS opened a $440 million biometric capture procurement.
The Example Key From the Setup Guide (09/10/2026)
Nearly one in ten exposed LiteLLM gateways still accepted the placeholder admin key from the documentation, and CISA set a September 12 deadline on three exploited flaws.
The Database That Is Not Supposed to Exist (09/10/2026)
SCHUFA refused to drop the shadow database noyb demanded it delete, and a civil society coalition is pushing the EU to replace cookie banners with automated signals.
The EU Now Regulates the Product Itself (09/09/2026)
New Commission guidance clarifies who the Cyber Resilience Act binds, the FBI warned about OAuth consent phishing, and two health systems settled pixel tracking lawsuits.
The Most Sensitive Field in the Record (09/09/2026)
Grindr will pay 26 million pounds over the sharing of users' HIV status, and police departments are hiding their use of surveillance technology to avoid public scrutiny.
Microsoft Shipped 974 Fixes in One Day (09/09/2026)
September's Patch Tuesday broke every previous record at 974 CVEs, Chrome patched a V8 zero-day already under attack, and SAP closed a maximum severity kernel flaw.
The Television Was Watching on Standby (09/08/2026)
LG faces claims of an egregious invasion of privacy over TV data collection, and a secretive DHS predictive policing unit is analyzing Americans' financial habits.
OSHA Machine Guarding and the FCA on Frontier AI (09/08/2026)
Machine guarding under 29 CFR 1910.212 is back in OSHA's Top 10 citations, the FCA published what it found reviewing frontier AI use, and OneTouchPoint settled a 2022 breach.
A Zero-Click Worm That Arrives as a Phone Call (09/08/2026)
Researchers built a WeChat worm that takes an account over through an incoming call nobody answers, and a planted ChatGPT prompt quietly forwarded a victim's Gmail data.
Fake IT Calls and a Fourth Hotfix in Five Weeks (09/07/2026)
Attackers are calling executives while posing as the help desk to reach Microsoft 365, and N-able shipped a fourth N-central hotfix in five weeks for the same class of flaw.
The Travel App That Exposed Soldiers (09/07/2026)
A travel app with 23 million users exposed enough data to track people including soldiers, and an Illinois State Police database published Social Security numbers online.
How to Explain an Unpatched Vulnerability (09/07/2026)
June brought 66 large healthcare breaches, Luminis Health is restoring systems after an attack, and there is finally sane guidance on documenting a deferred patch for your auditor.