Lucy Green

Data breaches & privacy

Lucy worked breach-notification regulation before moving into journalism. She covers data exposures, the legal aftermath, and what victims should actually do — beyond the platitudes.

Recent stories

Unpacking the 'Son of Mythos': AI's Role in Vulnerability Discovery
AI Security
Unpacking the 'Son of Mythos': AI's Role in Vulnerability Discovery
As Anthropic and OpenAI expand AI tool access, organizations face both risks and opportunities.
Jun 4
Weedhack MaaS Hijacks Minecraft Players Through YouTube Lures
Threat Intelligence
Weedhack MaaS Hijacks Minecraft Players Through YouTube Lures
A malware-as-a-service operation impersonating Minecraft clients and mods has compromised thousands of systems since January, with YouTube tutorials serving as the primary funnel.
Jun 3
Diverging Paths to Cybersecurity: Tools vs. Operational Control
AI Security
Diverging Paths to Cybersecurity: Tools vs. Operational Control
New reports debate whether inadequate tools or operational lapses are to blame for cybersecurity issues.
Jun 2
AI Has Minted a New Kind of Attacker — One Who Knows Nothing
AI Security
AI Has Minted a New Kind of Attacker — One Who Knows Nothing
Generative AI closes the skill gap between vague criminal intent and working malware. Responsible disclosure norms weren't built for that world.
Jun 2
The Patch Window Is Now Measured in Hours
Opinion
The Patch Window Is Now Measured in Hours
AI-assisted exploit development has collapsed the time between disclosure and mass exploitation. Traditional vulnerability management workflows weren't built for this pace.
Jun 2
Meta's AI Support Bot Handed Out Password Resets to Anyone Who Asked Nicely
AI Security
Meta's AI Support Bot Handed Out Password Resets to Anyone Who Asked Nicely
A pro-Iran Telegram channel published a walkthrough showing how Instagram's conversational recovery assistant could be talked into linking attacker-controlled email addresses to target accounts. The Obama White House and a senior U.S. Space Force account were briefly defaced.
Jun 1
Dutch Police Pull the Plug on 17-Million-Device Botnet Run Through 200+ NL Servers
Threat Intelligence
Dutch Police Pull the Plug on 17-Million-Device Botnet Run Through 200+ NL Servers
Politie and NCSC seized command infrastructure hosted on Dutch soil, dismantling a network that pulled in PCs, phones, tablets and IoT gear at scale.
May 31
Kimsuky Rolls Out HTTPSpy and HelloDoor in Spring 2026 Campaign Against South Korean Targets
Threat Intelligence
Kimsuky Rolls Out HTTPSpy and HelloDoor in Spring 2026 Campaign Against South Korean Targets
The DPRK-linked crew is spoofing Webex pages and antivirus installers to drop new implants on military and corporate networks.
May 29
Patched FortiClient EMS Flaw Still a Live Attack Vector for Credential Theft
Vulnerabilities
Patched FortiClient EMS Flaw Still a Live Attack Vector for Credential Theft
Attackers are piggybacking on Fortinet's endpoint management tooling to push infostealers disguised as legitimate agent updates.
May 28
French Startup Edamame Builds Runtime Watch for AI Coding Agents
AI Security
French Startup Edamame Builds Runtime Watch for AI Coding Agents
The platform uses host telemetry and AI analysis to flag intent drift, secret theft, and supply-chain interference — in real time, before the damage lands.
May 28
Account Takeover Flaw in Pretalx CFP Tool Let Attackers Accept Any Conference Talk
Vulnerabilities
Account Takeover Flaw in Pretalx CFP Tool Let Attackers Accept Any Conference Talk
An account takeover vulnerability in the open-source call-for-papers platform Pretalx could allow an unauthenticated attacker to manipulate submission outcomes, researchers at Novee have found.
May 28
Gitea Patches Unauthenticated Container Image Disclosure Flaw in 1.26.2
Vulnerabilities
Gitea Patches Unauthenticated Container Image Disclosure Flaw in 1.26.2
CVE-2026-27771 allowed anonymous pulls of private container images from all Gitea deployments prior to version 1.26.2, according to maintainers.
May 28
Shadow AI Is Now a Compliance Problem, Not Just an IT One
Policy & Regulation
Shadow AI Is Now a Compliance Problem, Not Just an IT One
Employees are running unsanctioned AI assistants by the handful. Regulators are starting to ask who approved them, and under which control framework.
May 28
Operators Warn AI-Generated Traffic Is Outpacing Static DDoS Defences as Regulators Eye Disclosure Rules
Policy & Regulation
Operators Warn AI-Generated Traffic Is Outpacing Static DDoS Defences as Regulators Eye Disclosure Rules
Machine-learning-driven flood attacks are reshaping volumetric thresholds faster than current incident-reporting frameworks anticipated.
May 28
AI-Driven OT Security Is Only as Good as the Telemetry Feeding It
Policy & Regulation
AI-Driven OT Security Is Only as Good as the Telemetry Feeding It
Fewer than 10 percent of OT networks have meaningful monitoring in place, according to the 2026 Dragos OT Cybersecurity Year in Review. Until that changes, layering machine-learning tools on top of industrial control systems may create more risk than it resolves.
May 28
© 2026 Threat Vectr