The Axe Report.
Official company announcements, tactical service deployments, strategic partnerships, and community action updates from the Grab The Axe team.
An AI Model Breaks a Post-Quantum Scheme & JFrog Confirms the Artifactory Zero-Day (07/28/2026)
Anthropic's Mythos model derived a key-recovery attack on a post-quantum signature scheme, JFrog confirms OpenAI's models exploited an Artifactory zero-day, and 24,650 exposed BMCs leak password hashes.
Gay Bars Are Building Patron Databases & a Judge Flags an AI-Hallucinated Asylum Refusal (07/28/2026)
ID-scanning systems at LGBTQ+ bars are building databases of patrons, a judge says the Home Office relied on AI-hallucinated information to refuse asylum, and AI smart lamp-posts arrive in Britain.
An Addiction Treatment Provider Breaches 145,700 Records & the CSA Issues Emergency AI Guidance (07/28/2026)
Operation PAR discloses a 145,700-record breach of substance use disorder data, the Cloud Security Alliance issues emergency guidance after the autonomous AI breach, and a House committee moves to block OSHA's heat standard.
A Cyberattack Shutters 80 AnMed Facilities & a Revenue-Cycle Vendor Breaches 1.26M (07/27/2026)
AnMed closes nearly 80 facilities as it grapples with a cyberattack, revenue-cycle firm MCBS discloses a 1.26 million-person breach, and the DoD implements the FY25 NDAA contractor prohibition.
A Max-Severity Arista Zero-Day Is Exploited & an AI Agent Runs an Espionage Op (07/27/2026)
A CVSS 10.0 command-injection flaw in Arista VeloCloud Orchestrator is under active attack, an autonomous AI tool ran espionage against Thailand's finance ministry, and a vBulletin pre-auth RCE exploit goes public.
A Product-Safety Agency Demands Hospital ER Records & a UK Court Pierces Spyware Immunity (07/27/2026)
A federal product-safety agency demands identifiable ER records from major health systems, the UK Supreme Court rejects Bahrain's immunity in a spyware case, and the EDPB publishes draft anonymisation guidelines.
A Border Traveler Is Charged for Wiping His Phone & Vigilantes Are Killing Flock Cameras (07/26/2026)
The DOJ prosecutes an American for using a duress password at the border, a leaked document maps ICE's surveillance reach, and activists are disabling Flock license-plate cameras nationwide.
GitHub and PyPI Add a Delay to Blunt Supply-Chain Attacks & ChatGPT Handed Out Bioweapon Recipes (07/26/2026)
GitHub and PyPI introduce a time-based cooldown on new dependencies, Steam forum ClickFix lures infect gamers with cryptominers, and a report says ChatGPT gave some users step-by-step bioweapon guides.
Police Drone Programs Spread Nationwide & the EU AI Act Slips to 2027 (07/24/2026)
Hundreds of drone-as-first-responder programs clear a key hurdle, the EU pushes back its AI Act workplace rules to December 2027, and MSG's face-recognition cameras went dark for one guest.
Malvertising Makes the Browser Build Its Own Malware & Cl0p Hits PTC Windchill (07/24/2026)
A malvertising operation makes victims' browsers assemble the malware locally, Cl0p affiliates exploit unauthenticated RCE in PTC Windchill and FlexPLM, and an unpatched Fastjson flaw is under attack.
A Pathology Group Breaches 170K Records & the FCC Opens Its First Drone Revocation (07/24/2026)
A Tennessee pathology group notifies 170,000 patients of a breach, the FCC launches its first national-security drone revocation, and a US visa rule adds new employer tracking duties.
DentaQuest Notifies 15 Million People & Malicious Insider Incidents Surge (07/23/2026)
DentaQuest begins notifying more than 15 million individuals after a May breach, a new report finds malicious insider incidents climbing, and NIS2 obligations bite for cloud and data center providers.