May 01, 2026 tech news: Android 16 VPN Bypass Leak; AWS Middle East Data Center Destruction; Ubuntu Infrastructure Extortion Attack; Japan's Cardboard Suicide Drones; South Africa's AI-Written AI Policy; The 'Gay Jailbreak' LLM Attack; Credit Card Brute-Force Vulnerability.

Android 16 VPN Bypass Leak A critical flaw in Android 16 allows untrusted apps with basic permissions to leak a user’s real public IP address even when strict VPN lockdown modes are enabled. The vulnerability leverages a privileged system process to send UDP packets outside the VPN tunnel, effectively neutralizing the OS’s hard network guarantees. https://lowlevel.fun/posts/tiny-udp-cannon-android-vpn-bypass/ AWS Middle East Data Center Destruction Amazon Web Services is facing months of repairs following Iranian drone strikes on data centers in the UAE and Bahrain. The attacks knocked out critical server racks and caused extensive water damage from fire suppression systems, forcing AWS to suspend billing for affected regions and urge customers to migrate resources. ...

May 1, 2026 · 2 min

April 30, 2026 tech news: Linux 'Copy Fail' Root Exploit; LinkedIn's Secret Browser Extension Scanning; PyTorch Lightning Supply Chain Attack; Discord's Cascading Voice Outage; Water-Powered Nanoscale Electricity; Microsoft Open-Sources Earliest DOS Code; Dutch Police DDoS Honeypots.

Linux ‘Copy Fail’ Root Exploit A critical privilege escalation vulnerability dubbed ‘Copy Fail’ (CVE-2026-31431) allows attackers to gain root permissions on nearly all Linux distributions released since 2017. The flaw, discovered by Theori using AI-driven pentesting, is more reliable and portable than the previous ‘Dirty Pipe’ vulnerability, affecting major distros including Ubuntu, RHEL, and Amazon Linux. https://www.bleepingcomputer.com/news/security/new-linux-copy-fail-flaw-gives-hackers-root-on-major-distros LinkedIn’s Secret Browser Extension Scanning LinkedIn has been covertly scanning users’ browser extensions since 2017 to build detailed software inventories linked to verified professional identities. This fingerprinting allows LinkedIn to infer personal details—such as job hunting, religious practices, or political leanings—and has triggered a criminal investigation by the Bavarian Central Cybercrime Prosecution Office. ...

April 30, 2026 · 2 min

April 29, 2026 tech news: GitHub's Critical RCE Flaw; SAP Supply Chain Attack; Hashimoto Quits GitHub; Zed Editor Hits 1.0; Rust's Safety Limits Exposed; Linux 7.0 PostgreSQL Regression; Maryland Bans Surveillance Pricing.

GitHub’s Critical RCE Flaw A critical vulnerability in GitHub’s internal git infrastructure allowed attackers to execute remote code on backend servers. On GitHub.com, this granted access to millions of public and private repositories on shared storage nodes; on GitHub Enterprise Server, it allowed full server compromise. The flaw was discovered using AI-augmented reverse engineering. https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 SAP Supply Chain Attack Attackers compromised SAP-affiliated npm accounts to distribute credential-stealing malware via core SAP Cloud Application Programming Model packages. The payload harvests GitHub, AWS, Azure, and GCP tokens and poisons victim repositories with a malicious VS Code tasks.json to establish persistent CI/CD footholds. ...

April 29, 2026 · 2 min

April 28, 2026 tech news: Google's Android Lockdown; The 9GW 'Shadow Grid' Data Center; GitHub's Critical RCE Flaw; GitHub Copilot Ends 'All-You-Can-Eat' AI; Google's Classified Pentagon AI Deal; Biometric Voice Breach at Mercor; Denuvo's Total Single-Player Collapse.

Google’s Android Lockdown Starting September 2026, Google will block any Android app whose developer has not registered with a government ID and paid a fee. This move fundamentally alters Android’s open nature, creating a high-friction ‘deterrence mechanism’ for sideloading and threatening the existence of open-source stores like F-Droid. https://keepandroidopen.org/en/ The 9GW ‘Shadow Grid’ Data Center Kevin O’Leary’s ‘Stratos’ project in Utah has been approved to build a massive AI data center that bypasses the public electricity grid entirely. By generating its own power via natural gas, the project avoids utility delays but raises significant environmental and heat pollution concerns. ...

April 28, 2026 · 2 min

April 27, 2026 tech news: AI Agent Nukes Production Database in 9 Seconds; Mobile 'SMS Blasters' Prowl Toronto Streets; Supreme Court to Rule on 'Geofence' Warrants; Dutch Central Bank Abandons US Cloud for Lidl's IT Arm; GitHub Copilot Shifts to Usage-Based Billing; Critical 'Pack2TheRoot' Linux Privilege Escalation; Original Creators Return with 'Super ZSNES'.

AI Agent Nukes Production Database in 9 Seconds A coding agent using Claude Opus 4.6 via the Cursor tool deleted a company’s entire production database and all volume-level backups in nine seconds. The disaster was exacerbated by the cloud provider Railway’s API, which allowed destructive actions without confirmation and stored backups on the same volume as the source data. https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue Mobile ‘SMS Blasters’ Prowl Toronto Streets Toronto police dismantled a scheme where suspects drove cars equipped with ‘SMS blasters’ to impersonate cell towers. The devices infiltrated tens of thousands of phones, causing 13 million network disruptions and blocking critical 911 emergency calls while stealing user data via fraudulent texts. ...

April 27, 2026 · 2 min

April 26, 2026 tech news: The 'Fogbank' Effect: AI's Threat to Software Engineering; AI Solves 60-Year-Old Math Conjecture; ShadowBrokers' 'fast16' Sabotage Framework Uncovered; Trump Administration Dismisses National Science Board; UK AI Data Centers' Carbon Impact 100x Higher Than Estimated; GoDaddy Transfers 27-Year-Old Domain to Stranger Without Docs; Manitoba Bans Social Media and AI Chatbots for Youth.

The ‘Fogbank’ Effect: AI’s Threat to Software Engineering The software industry faces a potential ‘knowledge collapse’ similar to the US defense industry’s loss of ability to manufacture legacy missiles. By replacing junior hiring and deep learning with AI copilots, the industry risks a future where no human understands the underlying systems well enough to fix critical failures. https://techtrenches.dev/p/the-west-forgot-how-to-make-things AI Solves 60-Year-Old Math Conjecture A 23-year-old amateur used ChatGPT to solve a long-standing conjecture by Paul Erdős. Unlike previous AI math wins, this solution utilized a completely new approach, suggesting LLMs can provide genuine cognitive leaps in theoretical mathematics. ...

April 26, 2026 · 2 min

April 25, 2026 tech news: France and India Pivot to Linux for Digital Sovereignty; Hairdryer Used to Rig Polymarket Weather Bets; Meta and Microsoft Cut Thousands of Jobs to Fund AI; Java 24 Fixes Virtual Thread 'Pinning' Deadlocks; Microsoft Azure Linux May Rebase on Fedora; The 'npm Slop' Supply Chain Crisis; New 10GbE USB Adapters Disrupt Thunderbolt Dominance.

France and India Pivot to Linux for Digital Sovereignty France is migrating 2.5 million government workstations to Linux to reclaim control over strategic data and infrastructure. This mirrors a broader ‘digital sovereignty’ trend in Europe and India, driven by geopolitical tensions and a desire to reduce reliance on US Big Tech. https://m.economictimes.com/tech/technology/france-ditches-windows-for-linux-to-move-away-from-american-tools-mirroring-a-shift-in-india/articleshow/130408025.cms https://tuta.com/blog/countries-ditching-microsoft-choosing-linux-digital-sovereignty Hairdryer Used to Rig Polymarket Weather Bets A gambler allegedly used a battery-powered hairdryer to heat a public temperature sensor at Paris’s Charles de Gaulle airport, triggering a temperature spike that netted them approximately $34,000 in Polymarket weather bets. ...

April 25, 2026 · 2 min

April 24, 2026 tech news: Google's $40B Bet on Anthropic; US Accuses China of Industrial AI Theft; OpenAI Launches GPT-5.5; Linux Kernel Purges Legacy Code Due to AI Noise; Samsung's Smartphone Profit Crisis; FCC Expands Router Ban to Hotspots; Raylib 6.0: GPU-Free Rendering.

Google’s $40B Bet on Anthropic Google is investing up to $40 billion in Anthropic, providing $10 billion immediately and $30 billion based on performance. The deal secures Anthropic’s access to Google’s TPU infrastructure, as the AI firm struggles with compute limits and faces a potential IPO in October. https://techcrunch.com/2026/04/24/google-to-invest-up-to-40b-in-anthropic-in-cash-and-compute/ US Accuses China of Industrial AI Theft The US government is preparing sanctions against China for ‘industrial-scale’ theft of AI intellectual property via distillation attacks. The White House claims Chinese entities used tens of thousands of proxy accounts to clone US frontier models, a move that could rock the upcoming Trump-Xi summit. ...

April 24, 2026 · 2 min

April 23, 2026 tech news: Apple Patches FBI-Exploited Notification Bug; France ID Agency Breach Exposes 19M Citizens; UK Government Endorses Passkeys Over Passwords; Anthropic Admits to Claude Code Quality Dip; Raylib 6.0 Introduces GPU-Free Rendering; Git 2.54 Simplifies History Rewriting; Ubuntu 26.04 LTS Launches with Outdated AI Tools.

Apple Patches FBI-Exploited Notification Bug Apple released emergency updates for iOS and iPadOS after reports surfaced that the FBI recovered deleted Signal messages from a suspect’s phone via internal notification storage. The bug allowed notifications to remain on the device even after the messages were deleted in-app or the app itself was removed. https://www.bleepingcomputer.com/news/security/apple-fixes-ios-bug-that-retained-deleted-notification-data/ https://www.techcrunch.com/2026/04/22/france-confirms-data-breach-at-government-agency-that-manages-citizens-ids/ France ID Agency Breach Exposes 19M Citizens The French government agency responsible for passports and national IDs confirmed a data breach affecting potentially 19 million records. A threat actor is currently offering the database for sale on hacking forums, significantly increasing the risk of targeted phishing and social engineering attacks against French citizens. ...

April 23, 2026 · 2 min

April 22, 2026 tech news: Meta's AI Training Surveillance; Anthropic's Mythos: AI-Driven Bug Hunting; Apple Fixes iPhone Privacy Leak; Thiel's AI Tribunal for Journalists; CATL's Ultra-Fast EV Battery; Claude Desktop 'Spyware' Allegations; Google's 8th Gen TPU for AI Agents.

Meta’s AI Training Surveillance Meta is reportedly installing surveillance software on employee computers to record keystrokes, mouse movements, and screenshots. The data is intended to train AI agents to understand how humans interact with computers to automate professional workflows. https://www.theregister.com/2026/04/22/meta_employee_surveillance_software/ Anthropic’s Mythos: AI-Driven Bug Hunting Anthropic’s Mythos Preview identified 271 vulnerabilities in Firefox 150, demonstrating a massive leap in AI-aided security auditing. However, reports indicate an unauthorized group gained access to the tool via a third-party vendor, highlighting the risk of such powerful tools being weaponized. ...

April 22, 2026 · 2 min