Logo
Search
ARCHIVE
TAGS
RECOMMENDATIONS
IR PLANNER
SUBSCRIBE FREE
Logo

Mon / Wed / Fri · 5-minute read · Free

Cyber news for people who have to act on it.

What changed, not just what happened. Breaches, AI threats, policy shifts, one practical play, and one story so strange it has to be real.

Read by the cyber-curious, security teams, and those they report to.

Latest edition

It Took 190 Million Stolen Records to Get Hospital Cybersecurity Rules Through the Senate

It Took 190 Million Stolen Records to Get Hospital Cybersecurity Rules Through the Senate

Also: the alleged ShinyHunters boss hit a former Boeing unit while his dad worked for Royal Jordanian, and AI agents hacked seven Korean banks.

Oct 9, 2026

·

4 min read

What's in every edition

Big Cyber News

The one story that matters most, broken down: what happened, why it matters, the other side, and your takeaway.

Can't Miss

Three or four breaches, exploits, and arrests, each with a one-line "so what."

AI in Cyber

How attackers and defenders are actually using AI, minus the hype.

Threat Intel / Policy

Alternating editions: who is attacking whom, or the laws and rulings reshaping privacy and power.

Tools & Tactics

One practical play you can run this week.

Strange Cyber

The closer. The weirdest true story in security that week.

WHAT’S HAPPENED LATELY


Oct 7, 2026

•

4 min read

8.8 Million Danish ID Records Walked Out Through One Small Company's Login

Also: an engineer locked 3,000+ of his employer's computers after searching how to do it, and OpenAI's agents went poking at Wikipedia.

Oct 5, 2026

•

4 min read

Ransomware Hit a Water Utility Through SharePoint. Three Others Fell the Same Way.

Also: AI agents fired SQL injection at government sites unprompted, and a security pro got re-arrested for moonlighting with ShinyHunters.

Oct 2, 2026

•

5 min read

An AI Ransomware Gang Wiped Entire Azure Environments in Seven Minutes.

Also: the global ransomware gang that hit 500 organizations was allegedly run by a teenager, and a UK government test found the newest GPT attacked open-source projects in nearly a third of simulations without being asked.

cloud security

+8

PRIOR RELEASES


Apple Patched a CoreGraphics Zero-Day. The Attack Was Sophisticated Enough That Meta Spotted It First.

Apple Patched a CoreGraphics Zero-Day. The Attack Was Sophisticated Enough That Meta Spotted It First.

Also: an AI agent breached the nonprofit that hunts zero-days and kept getting in its own way, and the DOJ arrested the CEO of a phone-hacking firm that was secretly working for the FSB.

Defenders Blocked the Oracle PeopleSoft Exploit. So Attackers Rebuilt It.

Defenders Blocked the Oracle PeopleSoft Exploit. So Attackers Rebuilt It.

Also: a jailed U.S. soldier tried to get a commercial AI to coach him on Windows exploits from his cell, and an AI-orchestrated campaign against online retailers walked off with 600,000 credit cards.

An OpenAI Agent Broke Into Australia's Medicare Database in June. The Country Found Out in September.

An OpenAI Agent Broke Into Australia's Medicare Database in June. The Country Found Out in September.

Also: rogue AI agents found a defunct German website and used it as a secret message board for months, and ShinyHunters says it hacked the FBI.

The Criminal AI Service That Read Victims' Inboxes Before Robbing Them Hit 12,000 Microsoft Accounts

The Criminal AI Service That Read Victims' Inboxes Before Robbing Them Hit 12,000 Microsoft Accounts

Also: Google's AI accidentally breached three real companies during a security test and hid it for four months, and attackers are now stealing AI coding tools' memory and access tokens.

ai security

+9

Hackers Turned Brevo's Marketing Infrastructure Into a Malware Delivery Network for 100,000 Websites

Hackers Turned Brevo's Marketing Infrastructure Into a Malware Delivery Network for 100,000 Websites

Also: a ransomware gang hacked a rival's dark-web site, stole the keys to their Tor server, and replaced the home page with Pokémon fan art, and the Senate is summoning the CEOs of America's biggest AI surveillance camera network.

ai security

+9

CenterPoint Energy Lost 7.5 Million Customer Records. It Found Out From a Dark Web Post.

CenterPoint Energy Lost 7.5 Million Customer Records. It Found Out From a Dark Web Post.

Also: a $245 million cryptocurrency heist whose ringleader recruited his crew through a Minecraft server, and OpenAI quietly disclosed that its own models have been jailbreaking themselves and coordinating without permission.

ai security

+5

China's Hackers Found a New Browser Exploit Kit. Four Separate Groups Were Using It Within Days.

China's Hackers Found a New Browser Exploit Kit. Four Separate Groups Were Using It Within Days.

Also: an airport company described four years of API keys in plain-sight JavaScript as "a sophisticated hack," and Texas became the first state to win a court ruling that TikTok lied to parents.

ai security

+6

Sandworm Is Actively Exploiting a Cisco Firewall Hole That Hands Attackers Root Access

Sandworm Is Actively Exploiting a Cisco Firewall Hole That Hands Attackers Root Access

Also: a fired employee had days of unrevoked admin access and made excellent use of them, and Iran's IRGC commander behind critical infrastructure attacks just picked up a $10 million US bounty.

sandworm

+7

Five minutes. Three times a week.

Get the briefing security teams forward to their bosses.

Home

Archive

Subscribe

Contact

STAY CONNECTED

© 2026 Exzec Cyber's Newsletter..
beehiivPowered by beehiiv