Ax Sharma @axsharma.com · 26/09/2026🇦🇺 We also found urlscan[.]io records of automated activity against a second Australian health dashboard on the viz.aihw[.]gov[.]au domain, plus a sandbox workaround that returned data. Not widely reported yet. 000
Ax Sharma @axsharma.com · 26/09/2026Yesterday we named SEC[.]gov, investor[.]gov, Census and MAX[.]gov in the OpenAI agent story. Today Bloomberg and NYT report OpenAI's agents targeted SEC, Investor and Census data, calling it "routine research." Not quite: agents tried '../' path traversal on SEC, as we state: 100
Ax Sharma @axsharma.com · 22/07/2026[1/2] A VS Code extension called 'Markdown All Pro' impersonates a legit one with 14 million installs. Installing it ships your machine's details off-box and opens a channel the operator can feed anything to later, no update to the extension needed! 100
Ax Sharma @axsharma.com · 13/06/2026US gov ordered Anthropic to pull Fable 5 + Mythos 5 for all "foreign nationals" ... so effectively worldwide. The trigger being a narrow jailbreak where you ask the model to read a codebase and fix bugs. But, the capability is anyway widely available (from other models like GPT-5.5). 100
Ax Sharma @axsharma.com · 04/06/2026We disclosed a critical flaw in n8n-mcp (120k+ weekly npm downloads). On shared multi-tenant setups, one user could read everyone else's workflow backups, API keys and tokens included, or *wipe them all* in a single call. Just by guessing a number. CVSS 9.6. Found by Franciso Rosales. 🧵 110
Ax Sharma @axsharma.com · 18/05/2026The read-only mode in mcp-server-kubernetes (20,000+ weekly npm downloads) ...doesn't actually restrict anything. Neither do the other two access control modes. CVE-2026-46519, CVSS 8.8 🧵 110
Ax Sharma @axsharma.com · 14/05/2026We scanned 19,000+ AI agent skills. One enterprise scanner flagged 40%+ as malicious. Most were fine. A skill called "derp" passed two of three scanners clean. It instructs agents to silently produce broken code, and blame the developer's environment if they get suspicious. 100
Ax Sharma @axsharma.com · 19/02/2026Some posts have cited "5 million machines." That's simply Cline's total install milestone from Jan 30, not the number exposed to the Feb 17 update... This was a contained, low-impact incident, but still a useful reminder about supply chain security. We can stay and keep others aware, without FUD 🙂 000
Ax Sharma @axsharma.com · 16/02/2026Canada Goose says it is reviewing a 1.67 GB dataset leaked by ShinyHunters extortion group, with more than 600,000 customer records. 110
Ax Sharma @axsharma.com · 07/02/2026Restaurants are going cash-only, and utility payments are disrupted. The City of Palm Bay, FL and City of Frisco, TX both reported inability to accept online credit card payments. Other organizations, including Lightspeed Commerce and ThriftTrac, have also reported service impacts. 000
Ax Sharma @axsharma.com · 14/01/2026Such data can expose who runs what, at what scale, and when contracts renew. This serves as prime intel, not just for competitors/customer poaching, but threat actors aiming to launch targeted phishing, BEC and extortion attacks. 000
Ax Sharma @axsharma.com · 12/01/2026We shared the materials with Target, after which the sample data disappeared and access to git[.]target[.]com was restricted. The dataset advertised by the actor is claimed to be ~860 GB in size. Target went silent after we shared evidence and links to the Gitea repos suggesting a possible breach. 000
Ax Sharma @axsharma.com · 28/11/2025Can't believe but... the "real" flight ticket trick is still claiming victims. 🎫✈️ Scammers sell "tickets" that appear valid on the airline website for days, and then vanish. I'd written about this exact scam in 2023: www.wired.com/story/plane-... 110
Ax Sharma @axsharma.com · 26/11/2025Further, we see a real world example of the "Quote Tweet" scam targeting banking customers I'd first reported on back in 2023, that continues to target people across the UK—something to watch out for! www.bleepingcomputer.com/news/securit... 100
Ax Sharma @axsharma.com · 26/11/2025I was on BBC #RipOffBritain today breaking down code behind a fake "Google Movie" task scam site that conned many £££. But worse is, real cases of victims losing their PayPal balances and then getting locked out of dispute process in a catch-22. 📡 Next episode: Friday 10.45am 110
Ax Sharma @axsharma.com · 14/11/2025For anyone unsure whether the DoorDash breach emails are legit: The undated security advisory on the DoorDash website (not indexed by search engines 🙂) uses the same reference code, B155060, as the email notifications, confirming they are linked. 010
Ax Sharma @axsharma.com · 28/06/2025🎞️ All day: Exposing cybercrime and the latest hacks targeting real people for Rip-Off Britain @ BBC Studios, MediaCityUK. 000
Ax Sharma @axsharma.com · 16/04/2025The £2M scam operation that conned British people looking to get European EHIC health coverage cards that are otherwise free. 🎬 Watch on-demand or online @ Channel 5 UK: 📺 Scams: Don't Get Caught Out. Season 3. 010