Cybersecurity

CybersecuritySuno's Training Data Is Now an Itemised List

Suno's Training Data Is Now an Itemised List

A hacker infected one Suno employee with a worm and walked out with the source code. It did not catch the company lying. It turned a legal abstraction into an inventory with hours and row counts, in the middle of litigation.

8 min read
CybersecurityOne Commit Is Not an Audit Trail

One Commit Is Not an Audit Trail

xAI published Grok Build under Apache 2.0 after a wire-level test found it uploading private repositories. The release has one squashed commit, a stubbed upload function, and no bucket name. Open sourcing is not an audit.

7 min read
CybersecurityMicrosoft Stops Sending Your MFA Texts in February

Microsoft Stops Sending Your MFA Texts in February

Microsoft stops delivering SMS and voice MFA codes in Entra ID on 1 February 2027 and makes passkeys the default from 1 September 2026. The retirement date is fixed, but the price of the only alternative is not published until 18 September, so the migration has to be planned before the fallback can be costed.

4 min read
CybersecurityRotate Every Secret Grok Build Ever Saw

Rotate Every Secret Grok Build Ever Saw

A wire-level analysis found xAI's Grok Build CLI uploaded entire repositories, including a tracked .env file with live keys, to an xAI storage bucket - and the privacy toggle did not stop it. What every team that ran it owes its customers now.

6 min read
CybersecurityA Defender Flaw Lets a Local User Take Over the PC

A Defender Flaw Lets a Local User Take Over the PC

Microsoft shipped an out-of-band patch for RoguePlanet (CVE-2026-50656), a flaw in the Windows Defender scanning engine that lets a local user climb to SYSTEM on Windows 10 and 11. Because the fix ships through Defender's own silent engine update, the task is to verify the build, not assume the antivirus has you covered.

2 min read

Page 2 / 5