OpenAI’s $1 Billion Daybreak Bet Will Be Measured in Fixes, Not Credits

OpenAI has committed $1 billion in subsidised Daybreak access and support for frontline defenders, with consumption targeted over the next six months.
Vulnerabilities, defensive security, architecture and operational security.

OpenAI has committed $1 billion in subsidised Daybreak access and support for frontline defenders, with consumption targeted over the next six months.

Microsoft has identified a new ransomware strain deployed by China-linked Storm-1175. The campaign coincides with active exploitation of N-able N-central, although the specific entry route remains unconfirmed.

Zoom has patched a set of memory-safety vulnerabilities that researchers combined into a zero-click remote-code-execution attack through the live-meeting annotation protocol. A malicious participant could target a presenter, while a malicious presenter could reach participants across Windows, macOS, iOS and…

128 approved operational patch records from Microsoft, Adobe and SAP, with 537 linked unique CVEs and 14 accelerated BlackTree actions.

Malware forced Suisun City to shut down its entire IT network, disrupting 911 routing and police and fire dispatch. A county-level failover kept emergency calls and field response operating.

When criminals stop attacking infrastructure and start applying pressure to the people who run it, cybersecurity becomes a question of leadership, duty of care and organisational design. Editor’s note: This article was inspired by “Ransomware gangs skip the CEO, head…

A crafted namespace header can bypass Nuclio's earlier command-injection fix and turn a local Docker dashboard into host-level root access.

MIT researchers demonstrated that branch-predictor defences can be re-poisoned in the brief interval between being cleared and being used. This is a local attack, not a drive-by remote compromise. At Black Hat USA on 6 August, MIT researchers Daniël Trujillo…

Attempted attacks on major US investment firms put the helpdesk and identity provider at the centre of the threat model. Public reporting does not establish that every named target was breached. Update, 22 August 2026: Apollo Global Management has confirmed…

A new Shai-Hulud descendant spread through npm packages with legitimate-looking provenance. The incident shows why a trusted build path is not necessarily a trustworthy one. Security researchers identified a fast-moving npm supply-chain campaign on 4 August and named it ChainDrop.…