Lucy Green
Data breaches & privacy
Lucy worked breach-notification regulation before moving into journalism. She covers data exposures, the legal aftermath, and what victims should actually do — beyond the platitudes.
Recent stories

Threat Intelligence
Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke
Microsoft researchers flagged a counterfeit Perplexity Chrome extension that piped queries and omnibox input to an attacker server before completing the search.
Jun 29

AI Security
Prompt Injection in Git Repos Can Turn Claude Code Into a Reverse Shell Launcher
Malicious instructions buried in a repository's files can hijack Anthropic's Claude Code agent and open a backdoor on the developer's own machine — no obvious malware required.
Jun 29

Identity & Access
Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed
The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.
Jun 26

AI Security
Frontier AI Is a Pressure Test, Not a New Threat Model
The arrival of capable AI models like Mythos changes attacker economics. It doesn't change which controls actually matter — and most organizations are still failing the old ones.
Jun 26

AI Security
MCP's Enterprise Overhaul Hands Security Problems to Developers
A major revision to the Model Context Protocol repositions itself as enterprise-ready — then quietly offloads the hard security work onto the teams building on top of it.
Jun 26

Threat Intelligence
Iranian Group Handala Claimed It Could Poison California's Water. Forensics Say Otherwise.
California Water Service brought in Mandiant after Handala threatened disruption. Investigators found no evidence the group ever touched operational technology.
Jun 25

Policy & Regulation
Compliance Theatre Has a Reckoning Coming. FedRAMP 20x Is the Opening Act.
Most SOC 2 and ISO 27001 reports audit a curated version of history, not operational reality. A federal cloud-security overhaul is forcing the question nobody wanted to answer: does passing audits actually mean anything?
Jun 25

Vulnerabilities
Samsung KNOX Use-After-Free Bug Sat in Galaxy Devices for Eight Years Before Patch
A high-severity kernel-level flaw in Samsung's KNOX security framework affected Galaxy handsets from the S9 through the S25 — a product window spanning nearly a decade.
Jun 23

Vulnerabilities
GitHub Tightens Security to Counter Pwn Request Attacks
GitHub introduces actions/checkout v7 to block insecure pull request workflows.
Jun 23

Vulnerabilities
Squidbleed: A 1997 FTP Parsing Bug Is Still Leaking Cleartext HTTP in Squid Proxies
A heap over-read disclosed by Calif.io exposes other users' requests — credentials and session tokens included — to anyone permitted to send traffic through the same proxy.
Jun 22

Policy & Regulation
Android's Identity Wall Goes Up Sept. 30, 2026 — Starting With Four Countries
Brazil, Indonesia, Singapore and Thailand are the first markets where unverified developers lose the right to install apps on certified Android devices, sideload or not.
Jun 22

Threat Intelligence
AryStinger Quietly Conscripts 4,300 Old Routers Into a Recon Proxy Fabric
Researchers say the malware skips the usual DDoS playbook and instead builds infrastructure for pre-breach reconnaissance.
Jun 22

AI Security
AutoJack: When the AI Browser Becomes the Initial Access Broker
Microsoft researchers describe an exploit chain that turns an agentic browser into a one-click path from web page to host process execution.
Jun 19

Threat Intelligence
FortiBleed Campaign Hits 86,644 FortiGate Boxes; CISA Pushes Customers to Lock Down
Russian-speaking operators are working through internet-exposed Fortinet appliances at scale. CISA wants admins moving now.
Jun 19

AI Security
The Agents Nobody Owns: AI Identities Are Quietly Becoming Your Worst Insider Risk
Orphaned AI agents and standing privileges are accumulating across enterprise environments. Most security teams can't tell you who authorized them — or revoke them quickly when they go wrong.
Jun 18