May 21, 2026 tech news: AI Solves 80-Year-Old Geometry Mystery; GitHub Internal Breach via VS Code Extension; The AI Economic Bubble Warning; China Bans Nvidia's Latest China-Specific Chip; GitHub Actions Cache Poisoning Epidemic; Texas Official Proposes Total Tech Ban; Anna's Archive Hit With $19.5M Judgment.

AI Solves 80-Year-Old Geometry Mystery An OpenAI model has disproved the planar unit distance problem, a central conjecture in discrete geometry posed by Paul Erdős in 1946. Unlike previous AI efforts, this was achieved by a general-purpose reasoning model rather than a specialized math system, demonstrating a level of original ingenuity and complex reasoning that allows AI to move beyond a helper role to a primary researcher in frontier mathematics. ...

May 21, 2026 · 2 min

May 20, 2026 tech news: CISA Contractor Leaks High-Privilege Cloud Keys; Massive npm Supply Chain Attack via 'Mini Shai-Hulud'; Google Unveils Agentic Search and Gemini 3.5; OpenAI and Google Partner on AI Content Provenance; Proposed US Bill Targets Data Center Power Consumption; Machine Learning Inverts 'Irreversible' PhotoDNA Hashes; Formal Verification of Flight-Plan Bug Fix via LLMs.

CISA Contractor Leaks High-Privilege Cloud Keys A CISA contractor accidentally exposed highly privileged AWS GovCloud keys and plaintext passwords for internal systems on a public GitHub repository. The leak, described as one of the most egregious government data exposures in recent history, included credentials to the agency’s secure code development environment and internal artifactory, potentially allowing attackers to inject backdoors into government software. https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/ Massive npm Supply Chain Attack via ‘Mini Shai-Hulud’ Over 300 npm packages, including high-traffic libraries like size-sensor and echarts-for-react, were compromised in a rapid automated burst. The malware harvests a vast array of credentials (AWS, GCP, Azure, GitHub, Kubernetes) and employs advanced persistence techniques, including hijacking AI coding agents and escaping Docker containers to gain host filesystem access. ...

May 20, 2026 · 2 min

May 17, 2026 tech news: AI-Powered Exploit Breaks Apple M5 Security; Fisker Owners Build Open-Source Car Company; The Silicon Backdoor in 'Sovereign' Clouds; Linux Kernel Flaw Exposes SSH Keys; Signal Threatens Canada Exit Over Surveillance Bill; Bambu Lab Accused of Security Risks and License Theft; LinkedIn User Trolls AI Recruiters with Old English.

AI-Powered Exploit Breaks Apple M5 Security Security researchers used AI (Mythos Preview) and human expertise to build a working kernel exploit in five days, bypassing a hardware security system Apple spent five years and billions of dollars to develop. This demonstrates that even the most advanced hardware-level mitigations can be rapidly dismantled when paired with AI-driven vulnerability discovery. https://blog.calif.io/p/first-public-kernel-memory-corruption https://cyberinsider.com/signal-threatens-to-leave-canada-over-proposed-lawful-access-bill/ Fisker Owners Build Open-Source Car Company After Fisker’s bankruptcy left 11,000 Ocean SUV owners with ‘software-based cars’ that lost critical cloud functionality, the owners organized into a volunteer-run company. They reverse-engineered firmware and mapped CAN buses to prevent their vehicles from becoming e-waste, highlighting the urgent need for software escrow in the auto industry. ...

May 17, 2026 · 2 min

May 16, 2026 tech news: AI-Driven Exploits Breach Apple M5 Security; Pixel 10 Zero-Click Root Exploit Uncovered; AI Memory Wall Challenged by 3D CCD Architecture; Frontier AI Renders Competitive CTFs Obsolete; California Moves to Ban 'Killing' Online Games; AI Component Crunch Paralyzes PC Market; Orthrus: Lossless Parallel LLM Generation.

AI-Driven Exploits Breach Apple M5 Security Security researchers used Anthropic’s Claude Mythos to discover a privilege escalation exploit on Apple’s M5 chip, granting root access to macOS. The exploit successfully bypasses Memory Integrity Enforcement (MIE), a hardware-level security feature designed to prevent buffer overflows and use-after-free vulnerabilities. https://www.tomshardware.com/tech-industry/cyber-security/apple-m5-architecture-suffers-first-privilege-escalation-exploit-anthropics-claude-mythos-helps-researchers-bypass-memory-integrity-enforcement Pixel 10 Zero-Click Root Exploit Uncovered Google Project Zero discovered a 0-click exploit chain for the Pixel 10 that grants root access. The vulnerability lies in the VPU driver, which fails to bound mmap syscalls, allowing an attacker to map the entire kernel image into userspace and overwrite kernel functions. ...

May 16, 2026 · 2 min

May 14, 2026 tech news: The Secret 'Quirks' Files in Your Browser; BitLocker's 'YellowKey' Zero-Day Exploit; AI-Driven Kernel Exploits on Apple M5; The War Over 3D Printer Firmware; Americans Prefer Nuclear Plants Over AI Data Centers; The 'Emacsification' of Bespoke Software; Car Telemetry: The Physical Opt-Out.

The Secret ‘Quirks’ Files in Your Browser Modern browsers like Safari and Firefox ship hidden ‘quirks’ files containing thousands of lines of code that specifically target domains like TikTok, Netflix, and Instagram to fix bugs the sites themselves won’t repair. This creates a systemic asymmetry where the web is built for Chrome, and other browsers must either let sites break or write custom workarounds to maintain a functional user experience. ...

May 14, 2026 · 2 min

May 13, 2026 tech news: AI Data Centers Spark National Backlash; Fired IT Twins Wipe 96 Government Databases; Malware Crew Open-Sources Shai-Hulud Worm; MacBook Neo: High Performance, Thermal Cliff; Linux Gaming Gains Native Windows API Support; DuckDB Launches 'Quack' Client-Server Protocol; Elevator: Static x86 to ARM Translation.

AI Data Centers Spark National Backlash A growing ‘Not In My Backyard’ movement is emerging as AI data centers strain local resources. In Utah, a project twice the size of Manhattan is facing fierce opposition for its 9GW power demand; in Nevada, 49,000 residents may lose power as utilities redirect energy to AI hubs; and in Georgia, a facility drained 30 million gallons of water without payment. A Gallup poll confirms 71% of Americans now oppose local AI data center construction. ...

May 13, 2026 · 3 min

May 13, 2026 tech news: Massive Supply Chain Attack Hits AI and Dev Ecosystems; Google Warns of AI-Driven Zero-Day Exploits; Microsoft's $1B Kenya Data Center Stalls Over Power Crisis; Amazon Employees 'Tokenmaxxing' to Meet AI Quotas; Palantir Powers ICE's 20-Million Person Target List; Mythos AI Finds Vulnerability in cURL; Bambu Lab Threatens Open Source Developer.

Massive Supply Chain Attack Hits AI and Dev Ecosystems A massive coordinated attack compromised over 170 packages across the TanStack, Mistral AI, and UiPath ecosystems. The malware targets AWS, GitHub, and HashiCorp Vault credentials and uses a self-spreading vector by poisoning IDE configurations for Claude Code and VS Code users. https://safedep.io/mass-npm-supply-chain-attack-tanstack-mistral/ Google Warns of AI-Driven Zero-Day Exploits Google has disrupted a criminal operation that used AI to find a previously unknown security flaw, signaling a shift toward ‘industrial-scale’ AI-driven cyberattacks. The report highlights a race between defenders and attackers as AI lowers the barrier for reverse-engineering and exploit generation. ...

May 13, 2026 · 2 min

May 11, 2026 tech news: Linux Kernel Hit by 'Dirty Frag' Privilege Escalation; AI Data Centers Secretly Drain Millions of Gallons of Water; Git Repository Malware Targets Developers via Fake Recruiters; Nvidia's CUDA Moat: Software as the Ultimate Competitive Edge; Maryland Residents Face $2B Bill for AI Grid Upgrades; Fake DDR5 RAM with Plastic Chips Floods Markets; Iran Threatens to Tax and Control Undersea Internet Cables.

Linux Kernel Hit by ‘Dirty Frag’ Privilege Escalation A critical vulnerability nicknamed ‘Dirty Frag’ allows attackers with basic accounts to seize full administrative control of nearly all Linux distributions. The flaw enables container escapes, posing a severe risk to cloud infrastructure, and was released publicly after a coordinated disclosure embargo collapsed. https://therecord.media/dirty-frag-linux-kernel-hit-by-second-major-bug https://www.phoronix.com/news/Linux-7.0.6-Released AI Data Centers Secretly Drain Millions of Gallons of Water A data center project in Georgia secretly consumed 29 million gallons of water over 15 months, causing low water pressure for local residents. Despite the unauthorized use, county officials refused to fine the developer, citing the company’s status as their largest customer. ...

May 11, 2026 · 2 min

May 09, 2026 tech news: AI 'Vibe-Coding' Triggers Massive Data Leaks; Taiwan Rail System Hacked via 19-Year-Old Crypto Keys; Chinese Grey Market Sells Discounted Claude API Access; EU Targets VPNs as 'Loophole' for Age Verification; Zig 0.16 Redesigns Async I/O to Kill 'Function Coloring'; Meta Scraps End-to-End Encryption for Instagram DMs; GrapheneOS Patches Android VPN Leak Ignored by Google.

AI ‘Vibe-Coding’ Triggers Massive Data Leaks Over 5,000 AI-generated web applications are exposing sensitive corporate and personal data—including medical records and financial strategy documents—because ‘vibe-coding’ allows users to deploy apps without any security vetting or knowledge of authentication protocols. https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/ Taiwan Rail System Hacked via 19-Year-Old Crypto Keys A 23-year-old student stopped four high-speed trains for 48 minutes by broadcasting a General Alarm signal, exploiting a critical security failure where the rail network’s encryption keys had not been rotated in 19 years. ...

May 9, 2026 · 2 min

May 08, 2026 tech news: Dirty Frag: Critical Linux Root Exploit; AI-Driven Bug Hunting at Scale; The Danger of 'Vibe-Coding' Apps; AI Boom Triggers Storage Crisis; US Cities Block AI Data Centers; EU Targets VPNs as Age-Check Loophole; NVIDIA's Rust-to-CUDA Compiler.

Dirty Frag: Critical Linux Root Exploit A critical vulnerability chain dubbed “Dirty Frag” allows local users to gain root access on most major Linux distributions. Unlike race-condition bugs, this exploit is deterministic and highly reliable, targeting the kernel’s page-cache to overwrite sensitive files like /etc/passwd. No official patches are currently available for many affected systems. https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc https://afflicted.sh/blog/posts/copy-fail-2.html AI-Driven Bug Hunting at Scale Mozilla successfully used an AI-powered pipeline to identify 271 security vulnerabilities in Firefox, including numerous sandbox escapes. By wrapping the AI in a custom harness that could execute and verify crashes, Mozilla eliminated the “slop” typically associated with AI bug reports, achieving a near-zero false-positive rate. ...

May 8, 2026 · 2 min