The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
A Cyberattack Shutters 80 AnMed Facilities & a Revenue-Cycle Vendor Breaches 1.26M (07/27/2026)
AnMed closes nearly 80 facilities as it grapples with a cyberattack, revenue-cycle firm MCBS discloses a 1.26 million-person breach, and the DoD implements the FY25 NDAA contractor prohibition.
A Max-Severity Arista Zero-Day Is Exploited & an AI Agent Runs an Espionage Op (07/27/2026)
A CVSS 10.0 command-injection flaw in Arista VeloCloud Orchestrator is under active attack, an autonomous AI tool ran espionage against Thailand's finance ministry, and a vBulletin pre-auth RCE exploit goes public.
A Product-Safety Agency Demands Hospital ER Records & a UK Court Pierces Spyware Immunity (07/27/2026)
A federal product-safety agency demands identifiable ER records from major health systems, the UK Supreme Court rejects Bahrain's immunity in a spyware case, and the EDPB publishes draft anonymisation guidelines.
A Border Traveler Is Charged for Wiping His Phone & Vigilantes Are Killing Flock Cameras (07/26/2026)
The DOJ prosecutes an American for using a duress password at the border, a leaked document maps ICE's surveillance reach, and activists are disabling Flock license-plate cameras nationwide.
GitHub and PyPI Add a Delay to Blunt Supply-Chain Attacks & ChatGPT Handed Out Bioweapon Recipes (07/26/2026)
GitHub and PyPI introduce a time-based cooldown on new dependencies, Steam forum ClickFix lures infect gamers with cryptominers, and a report says ChatGPT gave some users step-by-step bioweapon guides.
Police Drone Programs Spread Nationwide & the EU AI Act Slips to 2027 (07/24/2026)
Hundreds of drone-as-first-responder programs clear a key hurdle, the EU pushes back its AI Act workplace rules to December 2027, and MSG's face-recognition cameras went dark for one guest.
Malvertising Makes the Browser Build Its Own Malware & Cl0p Hits PTC Windchill (07/24/2026)
A malvertising operation makes victims' browsers assemble the malware locally, Cl0p affiliates exploit unauthenticated RCE in PTC Windchill and FlexPLM, and an unpatched Fastjson flaw is under attack.
A Pathology Group Breaches 170K Records & the FCC Opens Its First Drone Revocation (07/24/2026)
A Tennessee pathology group notifies 170,000 patients of a breach, the FCC launches its first national-security drone revocation, and a US visa rule adds new employer tracking duties.
DentaQuest Notifies 15 Million People & Malicious Insider Incidents Surge (07/23/2026)
DentaQuest begins notifying more than 15 million individuals after a May breach, a new report finds malicious insider incidents climbing, and NIS2 obligations bite for cloud and data centre providers.
The EU Fines Google €890M & Origin Energy Loses Customer Banking Details (07/23/2026)
Brussels fines Google €890m over search and app store conduct, Origin Energy customers lose banking details in a breach, and Colorado's governor vetoes a surveillance-pricing bill.
A Russian Zero-Click Attack Loots Zimbra Mailboxes & Millions of Cars Open via Bluetooth (07/23/2026)
An international alert names Laundry Bear behind zero-click Zimbra attacks that steal mail and 2FA codes, researchers find millions of cars share one Bluetooth key, and Oracle ships 1,449 patches.
A Court Says Border Agents Can Search Your Phone By Hand & France Bans Social Media for Under-15s (07/22/2026)
The Fourth Circuit rules border agents can manually search phones without suspicion, the White House launches an AI-vulnerability clearinghouse, and France becomes the first EU country to ban social media for children under 15.