Groove Street Journal

Straight news with swagger. No ads. Ever.

Cyber & Digital Crime

Breaches, ransomware, and scams told as crime stories, not vendor copy. The Journal's differentiator.

GSJ Original

Salt Typhoon, Part 2: The Cleanup Nobody Can Independently Verify

AT&T and Verizon say their networks are secure. The Senate Commerce ranking member says the assessments that would let Congress test those claims have not been produced. A seven-day document request from this publication drew an AT&T out-of-office acknowledgment and a Verizon internal handoff — not the requested letters, and not written refusals. Commerce and Mandiant/Google still have not replied on the record. Who controls the evidence.

By Richard Vincent · September 7, 2026

GSJ Original

Your Security Bookmark Folder Is a Supply Chain

We scan package manifests for poisoned code, then click four-year-old security links as if ownership, DNS and page content never change.

By Richard Vincent · August 24, 2026

GSJ Original

Salt Typhoon, Part 1: The Breach America Still Cannot Fully Measure

Chinese state-linked operators reached deeply into U.S. telecommunications networks, collecting call records tied to millions of customers and communications from a much smaller group of political targets. Nearly two years after the breach became public, the government still has not produced a complete public accounting of its reach.

By Richard Vincent · August 20, 2026

Coverage Brief

CISA adds exploited Zimbra ZCS flaw to KEV, due Aug. 24

On Aug. 21, CISA added one vulnerability to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation: CVE-2026-73570, an OS command injection in Zimbra Collaboration Suite (ZCS). Federal civilian agencies face a BOD 26-04 remediation due date of Aug. 24. The directive binds FCEB agencies; CISA encourages other organizations to prioritize the same KEV remediation habit.

Left 0 Center 1 Right 0

1 outlets covering

Coverage Brief

Five agencies warn of active threat to Siemens S7 PLCs (AA26-231A)

On Aug. 19, NSA, CISA, FBI, DOE, and EPA published joint Cybersecurity Advisory AA26-231A warning of an active cyber threat to Siemens S7 Series PLCs (S7-200/300/400/1200/1500). The agencies describe reconnaissance and capability development against Internet-exposed or poorly segmented controllers and urge inventory, patching, Internet isolation, stronger access controls, and monitoring. The advisory does not attribute the activity to a named actor.

Left 0 Center 1 Right 0

1 outlets covering

Coverage Brief

FCC EAS cybersecurity rules take effect Sep. 29

In a July 31, 2026 Federal Register final rule (FCC 26-38; FR Doc. 2026-15601), the FCC adopted cybersecurity readiness requirements for Emergency Alert System participants under 47 CFR 11.35(d), including strong-password or alternative authentication controls, prompt security patching, and related equipment hygiene. The rule is effective September 29, 2026. The Commission framed the changes as protecting public trust in EAS against hijacking.

Left 0 Center 1 Right 0

1 outlets covering

Coverage Brief

White House creates supervised program for vetted firms to disrupt foreign cybercrime

A White House memorandum directs DOJ and DHS to establish a program under which vetted U.S. companies may conduct surveillance and disruptive cyber operations against foreign cyber-enabled criminal organizations. Each operation requires federal review, written approval and supervision, with implementation procedures due within 60 days. This is not a general license for companies to hack back.

Left 1 Center 1 Right 0

2 outlets covering

Coverage Brief

Ceva Logistics breach exposes Steam hardware customer data in Europe

Valve is notifying Steam hardware customers after a breach at shipping and logistics firm Ceva Logistics exposed customer data including names and addresses, with reporting tying the incident to a wider Ceva intrusion. This is a third-party logistics compromise affecting Steam customers, not a reported breach of Steam accounts themselves.

Left 1 Center 4 Right 0

5 outlets covering

Coverage Brief

U.S. and South Korea warn of Gunra ransomware targeting government networks

U.S. and South Korean agencies warned that the Gunra ransomware group is hitting government and critical-infrastructure networks, exploiting Fortinet and Schneider Electric flaws and bypassing multi-factor authentication. The joint advisory describes a campaign across multiple sectors rather than a single disclosed breach.

Left 0 Center 5 Right 0

5 outlets covering

Coverage Brief

Canadian man pleads guilty in Snowflake-linked extortion campaign affecting 165 customers

Canadian national Connor Riley Moucka pleaded guilty in U.S. federal court to charges tied to a campaign that used stolen credentials to breach at least 165 customers of cloud-data provider Snowflake. Prosecutors say the group stole large volumes of sensitive data and collected more than $2.5 million in ransom payments; Moucka is scheduled for sentencing Oct. 27.

Left 0 Center 6 Right 0

6 outlets covering

Coverage Brief

CISA adds actively exploited Progress Kemp LoadMaster flaw to KEV catalog

CISA added CVE-2026-8037, a vulnerability affecting Progress Kemp LoadMaster, to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. Federal civilian agencies must prioritize remediation under CISA’s risk-based directive, and the agency urges other organizations to do the same.

Left 0 Center 2 Right 0

2 outlets covering

Coverage Brief

Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests

Anthropic disclosed that its Claude model breached three real organizations during cybersecurity testing, saying the AI mistook live systems for capture-the-flag exercises. Coverage from WIRED, The Record, and The Hacker News centers on what the incidents mean for autonomous-agent containment.

Left 1 Center 2 Right 0

3 outlets covering