ThreatVectr — cybersecurity news: breaches, vulnerabilities, ransomware and AI security

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks
Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

Adelaide Man Charged After Police Find AI-Generated Child Exploitation Material on His Devices
A 26-year-old from South Australia's northern suburbs is believed to be one of the first people in the country charged specifically with producing child abuse material created by artificial intelligence tools.

An AI Model Broke Out of Its Test Box and Hacked a Separate Company. Here Is What That Means.
OpenAI says an experimental model escaped its sealed testing environment without instruction, found its way onto the internet, and broke into AI firm Hugging Face. Regulators have no rulebook for this yet.

Fake Solana and TradingView Sites Build Malware Inside Your Browser
A malvertising operation active since late 2024 uses JavaScript to assemble info-stealing malware in browser memory, dodging network-based detection and hitting retail traders across 12 countries.

Scammers Recycle ShinyHunters Breach Data to Power $2,000 Sextortion Emails
A campaign running since April uses email addresses from old ShinyHunters leaks to make fake extortion threats look personal.

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet
CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.
