RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

aiopen-source

Microsoft's VibeVoice ASR runs locally on Mac, transcribes an hour in under 9 minutes

Microsoft quietly released VibeVoice in January 2026, an MIT-licensed speech-to-text model in the Whisper lineage with speaker diarization baked into the model

via Simon Willison ·
supply-chainopen-source

pip 26.1 ships lockfiles and dependency cooldowns

Python's default package installer gets two long-requested capabilities in 26.1. The new `pip lock` command resolves a dependency tree and writes it to a `pyloc

via Simon Willison ·
cybersecuritymalware

Ransomware Crews Turn on Each Other, Spilling Rivals' Stolen Data

Infighting among ransomware operators has escalated into open data warfare, with competing crews dumping each other's exfiltrated victim caches onto leak sites.

via Dark Reading ·
aiopen-source

Talkie: a 13B language model trained only on pre-1931 English text

Nick Levine, David Duvenaud, and Alec Radford have released talkie-1930-13b, a 13B-parameter language model trained on 260B tokens of pre-1931 English text, alo

via Simon Willison ·
policy

V. vulnificus costs man a leg and forearm in 72 hours as climate expands its range

A patient arrived at hospital with a Vibrio vulnificus infection so advanced that his right leg required above-the-knee amputation and his forearm needed extens

via Ars Technica ·
malwarecybersecurity

VECT 2.0 ransomware bug shreds files over 128KB instead of encrypting them

Check Point researchers found a fatal flaw in VECT 2.0, a ransomware-as-a-service offering pushed on BreachForums and recently aligned with TeamPCP — the crew b

via BleepingComputer ·
aitech-culture

Yglesias on vibecoding: leave the AI to the pros

Matthew Yglesias, quoted by Simon Willison, lands on a sharp position five months into the vibecoding era: he doesn't want to do it himself. He'd rather have pr

via Simon Willison ·
aicybersecurity

Anthropic's Mythos and the Shifting Baseline of AI-Driven Vuln Hunting

Anthropic's Claude Mythos Preview can reportedly find vulnerabilities in operating systems and internet infrastructure and turn them into working exploits witho

via Schneier on Security ·
cybersecuritymalware

Carding Crew Publishes Three-Tier OPSEC Manual Borrowing From Intel Tradecraft

A cybercrime forum post analyzed by Flare lays out a structured operational security framework for high-volume carding crews, framing OPSEC less as hygiene and

via BleepingComputer ·
cybersecuritysupply-chain

Checkmarx confirms LAPSUS$ leaked 96GB of stolen GitHub data via Trivy supply-chain hit

Checkmarx has confirmed that data dumped by LAPSUS$ on its extortion portal was pulled from the company's private GitHub repositories, traced back to the March

via BleepingComputer ·
cybersecurityidentity

Data Movement Is the Zero Trust Gap Hiding in Plain Sight

Zero Trust architectures get most of their attention at the identity and network perimeters — verifying users, segmenting workloads, locking down east-west traf

via The Hacker News ·
vulnerabilitysupply-chain

GitHub RCE Flaw CVE-2026-3854 Triggers on a Single Git Push

Researchers have disclosed CVE-2026-3854, a critical remote code execution vulnerability in GitHub that can be triggered by a single git push operation. The fla

via The Hacker News ·