The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
Lazarus Burns a Windows Zero-Day & 737 VPN Extensions Caught (08/12/2026)
Lazarus used a Windows zero-day against defense firms and wrapped delivery in post-quantum crypto, and 737 Chrome VPN extensions were routing traffic through proxies.
DOJ and DHS Issue Joint Trade Enforcement Guidance (08/11/2026)
New DOJ and DHS guidance reshapes trade enforcement exposure, healthcare providers got a Gunra ransomware warning, and the FTC sent Mortgage Connect a warning letter.
Facial Recognition Reaches the Underground, California Fines a Broker (08/11/2026)
British Transport Police put live facial recognition into London Underground stations, and California issued its first data broker fine under the state privacy law.
400 Microsoft Flaws, Malicious SIMs & a Polish Plant Shutdown (08/11/2026)
Microsoft patched 400 flaws including an exploited zero-day, researchers turned SIM cards into modem backdoors, and attackers stopped a Polish plant's turbine.
Ceva Breach Cascades Downstream & New Passkey Attacks Land (08/10/2026)
A breach at shipping giant Ceva Logistics reached its customers' customers, three research teams defeated passkey protections, and ransomware crews took SonicWall.
Ransomware Crews Are Targeting Managers Who Approve Payments (08/09/2026)
Zscaler mapped 351 victims across 334 organizations and found attackers picking managers with budget authority, average age 46, mostly outside IT.
A Metabase 10.0 Zero-Day, N-central Hotfix 2 & Kemp on KEV (08/08/2026)
Metabase disclosed a maximum-severity zero-day already under exploitation, N-able shipped a third round of fixes, and CISA added Kemp LoadMaster after 792 attempts.
800 Malicious npm Packages & a GitHub Issue That Reached CI (08/07/2026)
Nearly 800 npm packages shipped a cross-platform trojan, N-able confirmed attackers reached customer networks, and a GitHub issue executed code on coding-agent runners.
ICE Is Buying Credit Card Records, Meta Owes New Mexico $567M (08/07/2026)
ICE is buying credit card application data through brokers, a New Mexico judge ordered Meta to pay $567 million over child safety, and an NHS trust is probing record access.
A Phished Inbox Becomes an SEC Filing at a Defense Supplier (08/07/2026)
IEH Corporation disclosed a cyber incident to the SEC after a phished Microsoft 365 account exposed engineering files, and five providers settled pixel class actions.
ICE Took a Million DNA Samples, 20 States Sue Over Benefits Data (08/06/2026)
ICE collected close to a million DNA profiles last year including children's, the NYPD took a woman's DNA off a water cup, and 20 states sued over benefits records.
Snowflake Plea, 4,407 Exposed PLCs & Three Cisco 9.8s (08/06/2026)
Connor Moucka pleaded guilty over breaches touching 100 million people, Forescout counted 4,407 internet-facing Rockwell controllers, and Cisco shipped three 9.8s.