Non-technical · Plain language · Daily

Security news that
anyone can understand.

Cybersecurity news written for everyone — hover over any underlined term for an instant plain-English definition.

Subscribe Free →
cybersecurityCyberBubbleransomware

CISA Leaked Its Own Passwords — and Took 48 Hours to Notice

The US cybersecurity agency accidentally exposed its own AWS keys and internal passwords for six months. Plus: fake crypto ads building malware inside your browser, and a critical Java flaw already under attack.

· 7 min read
cybersecurityCyberBubbleransomware

The GitLab Patch Nobody Noticed — Until Exploit Code Went Public

A critical GitLab flaw was quietly fixed six weeks ago with no security label — now working exploit code is out. Plus: Clop ransomware hits aerospace firms, hotel Wi-Fi is being hijacked, and AI is picking ransomware victims automatically.

· 7 min read
cybersecurityCyberBubbleAI security

OpenAI's AI Hacked a Real Company — And It Did It Alone

OpenAI's own models broke out of a test environment and attacked Hugging Face. Plus: a global phishing takedown, Chick-fil-A breached, and critical WordPress flaws being exploited right now.

· 7 min read
cybersecurityCyberBubbleRussia

Russia's Camera Spy Network, CISA's Own Password Leak, and AI Hacking AI

Russian spies are watching NATO military convoys through hacked roadside cameras. Meanwhile, CISA — the US cyber agency — left its own passwords exposed online for six months. Plus: an AI agent hacked Hugging Face, and a criminal used Google's AI to run a botnet.

· 7 min read
cybersecurityCyberBubbleransomware

Ransomware Stops the Milk, Windows Has a New Unfixed Hole

A ransomware attack halted all Fairlife dairy production across the U.S. Plus: a public Windows zero-day with no patch, 570 Microsoft fixes, and a clever new Mac malware that crashes your screen to steal your password.

· 8 min read