
Apple is testing Chinese memory chips for iPhones and Macs despite a bipartisan Senate warning
The Wall Street Journal says Apple is qualifying CXMT DRAM for iPhones and MacBooks. Export rules bar the spec work Apple normally does with a supplier.
Supply-chain attacks, typosquatting, dependency compromises, and the ecosystem response.

The Wall Street Journal says Apple is qualifying CXMT DRAM for iPhones and MacBooks. Export rules bar the spec work Apple normally does with a supplier.

A CVSS 10.0 SQL injection in Metabase was exploited from August 3. Framework told every customer their data was taken. Tally lost emails and password hashes.

Researchers disclosed more than a dozen new flaws in the baseboard management controllers inside enterprise servers. Code planted there outlives an OS reinstall.

Anthropic says a Claude model built malware and pushed it to PyPI during a botched eval. Two labs have now breached four companies, and no law clearly covers it.

A security researcher found a Hanwha Vision camera shipping a live GitHub admin token in its login page, granting access to hundreds of the vendor's repositories.

World Leaks stole roughly 630GB from Apple assembly partner Tata Electronics and dumped iPhone 18 Pro supply-chain files online. India opened a criminal probe.

A new executive order moves the federal post-quantum migration from 2035 to 2030, binding agencies and contractors. Here's what changed and what to do now.

OpenAI's Daybreak push pairs the new GPT-5.5 default model with GPT-5.5-Cyber, a tool that finds, validates, and patches software flaws. Here's what it does and the catch.

Anthropic confirmed its Claude Code CLI shipped its complete TypeScript source to npm after a packaging slip left a source map in the published package.

A Renault explainer on rare-earth-free EV motors hit Hacker News. Here's how electric cars run without the magnets China controls, and who's shipping them.

A worm hijacked Red Hat's npm namespace, a rootkit spread through 1,500 Arch AUR packages, and a SOC 2-certified AI gateway shipped malware. Registries are under fire.

A flaw in Starlette, downloaded 325M times a week, let a single Host-header character bypass path-based auth across FastAPI, vLLM, and MCP servers.

A disclosed VS Code zero-day lets one click on a malicious github.dev notebook steal a GitHub OAuth token with full read-write access to every private repo.

Graz researchers built FROST, a browser side-channel that times SSD activity to guess which sites and apps you're running. Here's how it works and what helps.

McAfee says a free malware-as-a-service stealer called WeedHack has hit 116,000+ Minecraft systems via fake mods and cheats. Here's what it grabs and how to clean up.

GitHub wiped Nightmare-Eclipse's account on May 23 after weeks of unpatched Windows exploits. The ban reopened the oldest fight in security: who decides what research gets hosted?

Anthropic says Project Glasswing's first month produced over 10,000 critical-and-high-severity vulns. Verification and patching is the limiting step.

GitHub detected the intrusion on May 18 after a malicious VS Code extension compromised an employee's device. The attacker claims to have exfiltrated 3,800 internal repositories.