RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecuritysupply-chain

Vercel breach traced to compromised Context.ai OAuth app, non-sensitive env vars harvested

Vercel disclosed that attackers reached internal systems through a third-party AI platform, Context.ai, whose compromise exposed a Vercel employee's Google Work

via BleepingComputer ·
cybersecuritysupply-chain

Vercel Credential Leak Traces Back to Context AI Compromise

Vercel has disclosed a security incident in which a limited set of customer credentials were exposed through a downstream breach at Context AI, a third-party se

via The Hacker News ·
cybersecuritymalware

ZionSiphon Malware Hits Israeli Water and Desalination OT Infrastructure

Researchers have identified a new malware strain dubbed ZionSiphon targeting operational technology systems at Israeli water and desalination facilities. The ca

via The Hacker News ·
aitech-culture

Anthropic launches Claude Design, a conversational prototyping tool powered by Opus 4.7

Anthropic Labs released Claude Design, a research-preview product that turns natural-language conversation into polished visual artifacts: prototypes, wireframe

via Hacker News ·
tech-culture

Apollo astronauts all got 'lunar hay fever' - and ESA is still trying to figure out why

Every one of the 12 Apollo astronauts who walked on the Moon developed respiratory irritation from lunar dust clinging to their suits, with symptoms ranging fro

via Hacker News ·
aidevops

Claude 4.7's new tokenizer quietly inflates session costs by 20-30%

An independent measurement of Anthropic's Claude Opus 4.7 tokenizer finds it consumes about 1.33x more tokens than 4.6 on real Claude Code content, and up to 1.

via Hacker News ·
cybersecuritypolicy

Coast Guard Maritime Cyber Rules Set a Template Other Sectors Will Follow

The U.S. Coast Guard's new cybersecurity regulations for the Marine Transportation System mark a shift from voluntary guidance to enforceable baseline controls

via Dark Reading ·
open-sourcedevops

Datasette 1.0a28 patches regressions from prior alpha, adds cleanup hooks

Simon Willison shipped Datasette 1.0a28 to fix breakages surfaced while upgrading Datasette Cloud to 1.0a27. The headline regression: execute_write_fn() callbac

via Simon Willison ·
vulnerabilitycybersecurity

NIST Reworks CVE Triage to Prioritize High-Impact Vulnerabilities

NIST is restructuring how it processes CVE entries, shifting effort away from exhaustive coverage of every reported flaw toward deeper analysis of vulnerabiliti

via Dark Reading ·
aitech-culture

PyCon US 2026 heads to Long Beach with dedicated AI and security tracks

PyCon US 2026 runs May 13-19 in Long Beach, marking the conference's first return to California since 2013 and to the West Coast since 2017. The main talks span

via Simon Willison ·
cybersecuritypolicy

Sanctioned crypto exchange Grinex halts after $15M drain, blames 'unfriendly states'

Grinex, a Kyrgyzstan-registered cryptocurrency exchange already under US Treasury sanctions, has suspended operations after attackers drained roughly $15 millio

via Ars Technica ·
aitech-culture

Satellite imagery shows 40% of US AI data centers will miss 2026 deadlines

Geospatial analysis from SynMax, cross-referenced with permit filings tracked by IIR Energy, indicates that nearly 40 percent of US data center projects schedul

via Ars Technica ·