Skip to content
root notes — live feed

whoami

Breaches, patches and the infrastructure underneath — in five minutes.

tail -f headlines.log

Most news sites re-package yesterday's press releases. This one doesn't — every post is capped at five minutes, opens with what actually changed, and tells you why it matters before it tells you what happened.

Latest analysis

Android can now move your passkeys between password managers. Whether it asks for your fingerprint is up to the app you leave

2026-09-15Gadgets

Google has switched on direct transfers of passwords and passkeys between password managers on Android, built on the FIDO Credential Exchange Format and live in Google Password Manager, 1Password, Bitwarden and Dashlane. Apple describes its version as secured by Face ID. Android's developer guide leaves the biometric prompt to the exporting app, and its sample code marks it optional.

The call is about your passkey. The break-in uses routes a passkey alone does not close

2026-09-15Security

Microsoft says extortion groups tied to ShinyHunters and Helix are phoning staff about urgent passkey or single sign-on updates, then steering them into relayed sign-ins or device-code approvals. Once in, they register an MFA method of their own, map the tenant through Microsoft Graph and take files at under 1,000 an hour to stay unremarkable.

The Trezor phishing needed no stolen password. Brevo's SSO let the attacker sign in as the people they invited

2026-09-15Security

Phishing that reached 347,000 Trezor newsletter subscribers came from Trezor's genuine Brevo account, so it passed every sender check. Brevo's post-mortem says the attacker created an account, switched on single sign-on, invited real Brevo users into it, and was then let into every organisation those users could reach. Early coverage spoke of stolen login details. Brevo's account involves none.

Europe's 24-hour exploit-reporting clock reaches products sold years ago. Its security rules do not

2026-09-15World

Since 11 September, manufacturers selling connected products in the EU must warn authorities within 24 hours of learning that a flaw in one is being exploited. The Cyber Resilience Act applies that duty to products already on the market, while its security requirements reach only those placed on the market from December 2027. For a device already on sale, the Act now requires the report, but not the patch.

Amodei's plan to slow AI has three steps. OpenAI matched the only one that needs no law

2026-09-15AI

Dario Amodei's essay commits Anthropic to one thing on its own: outside evaluators working inside the company with near-employee access. OpenAI said it would do the same. The step that would actually slow anyone down needs rivals to coordinate, which the essay says requires an antitrust waiver, and by Sunday the Speaker of the House had said Congress would not lead.

Nvidia may anchor Anthropic's IPO, and Nvidia is also the supplier

2026-09-12Startups

Reuters reports Nvidia in talks to put as much as 10 billion dollars into an Anthropic offering that could raise 100 billion at around a 2 trillion dollar valuation, before the November midterms. Anthropic buys Nvidia chips. The money and the hardware would be moving in a circle.

OpenAI asked Congress whether slowing down is legal. The bill on the table says yes, if almost nothing else is the reason

2026-09-11World

Sam Altman told staff OpenAI could pace frontier development alongside other labs, and OpenAI asked lawmakers whether that would breach antitrust law. The bipartisan bill that would answer it permits coordinated delays for loss-of-control risks — if not more than an insubstantial part of the reason is anything else. That week, OpenAI stopped selling its top tier for lack of compute.

Search all 293 articles →

Coverage

subscribe --daily

One email each morning. No filler.