Nvidia Quietly Paused Its Own AI Education Program a Year Into a Deal With Oregon
AI & ML
Bruno Digital · 16h ago

Nvidia Quietly Paused Its Own AI Education Program a Year Into a Deal With Oregon

The ambassador program that was supposed to put trained AI advocates on Oregon campuses never minted a single new one, and 1.5 million dollars of state funding earmarked for it sits unspent while the K-12 piece never had a plan at all.

Walmart Just Told Investors Fuel Costs Alone Will Cost It Over 2 Billion Dollars This Year
Cybersecurity·16h ago

Walmart Just Told Investors Fuel Costs Alone Will Cost It Over 2 Billion Dollars This Year

Across Walmart, Costco, Target, TJX, Kroger, and Ross, the same fuel, freight, and supplier cost story is showing up in guidance, and the retailers absorbing it rather than passing it through are making a deliberate bet on share over margin.

Bruno DigitalRead news →
ShinyHunters Lists O'Reilly Auto Parts and Dexcom on a Leak Site It Just Rebuilt
Cybersecurity·17h ago

ShinyHunters Lists O'Reilly Auto Parts and Dexcom on a Leak Site It Just Rebuilt

Days after an alleged leader was reportedly detained and cooperating with the FBI, ShinyHunters relaunched its extortion site with new claims against a 6,500-store auto parts retailer and a medical device maker whose app serves 5 million diabetes patients.

Bruno DigitalRead news →
A Teenager Allegedly Ran a Ransomware Operation That Hit 280 Victims and Stole 110 Terabytes
Cybersecurity·17h ago

A Teenager Allegedly Ran a Ransomware Operation That Hit 280 Victims and Stole 110 Terabytes

A joint takedown across six countries dismantled KillSec, a ransomware group authorities say was administered by a 16-year-old and used AI to build its infrastructure and pick targets.

Bruno DigitalRead news →
A China-Linked Group Is Still Breaking Into Water Utilities Through SharePoint Bugs From the Summer
Cybersecurity·17h ago

A China-Linked Group Is Still Breaking Into Water Utilities Through SharePoint Bugs From the Summer

Symantec researchers say the Warlock ransomware operation, run by the China-based Longlegs group, is actively exploiting ToolShell-family SharePoint flaws against critical infrastructure, government, and education targets that never patched.

Bruno DigitalRead news →
Salesforce Patched Three Agentforce Flaws That Let a Web Form Hijack an AI Agent's Identity
Cybersecurity·1d ago

Salesforce Patched Three Agentforce Flaws That Let a Web Form Hijack an AI Agent's Identity

SalesBleed shows an attacker could poison a public lead form, get Agentforce to exfiltrate CRM data over DNS, and send phishing links under the bot's own trusted name, all without a single credential.

Bruno DigitalRead news →
AWS Shipped Four Fixes for Its Own AI Agent Platform, and One Lets Anyone Become an Admin
Cybersecurity·1d ago

AWS Shipped Four Fixes for Its Own AI Agent Platform, and One Lets Anyone Become an Admin

Loom for AWS and SageMaker Unified Studio both carried flaws that handed attackers credentials or full control over the agent control plane, and AWS patched all four within days of disclosure.

Bruno DigitalRead news →
A FortiMail Bug Fortinet Rated 9.8 Is Already Being Used to Plant Web Shells
Cybersecurity·1d ago

A FortiMail Bug Fortinet Rated 9.8 Is Already Being Used to Plant Web Shells

CVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail server, and CISA added it to the exploited catalog within a day of disclosure.

Bruno DigitalRead news →
Half a Million Working Credentials Are Still Sitting in Public GitHub Repos
Cybersecurity·2d ago

Half a Million Working Credentials Are Still Sitting in Public GitHub Repos

Truffle Security validated 543,699 live credentials across public GitHub repositories, including one still working sixteen years after it was committed, and the numbers show push protection has not closed the gap enterprises think it closed.

Bruno DigitalRead news →
Google Is Giving a Vulnerability-Hunting AI to a Trusted Few, Then Removing the Guardrails
Cybersecurity·2d ago

Google Is Giving a Vulnerability-Hunting AI to a Trusted Few, Then Removing the Guardrails

Gemini 4 Argon can already find and patch critical software flaws on its own, and Google's plan to ship a guardrail-free version to trusted defenders is the governance question every enterprise security leader should be tracking.

Bruno DigitalRead news →
An Autonomous AI Agent Took Root on a Security Nonprofit's Servers in Seconds
Cybersecurity·2d ago

An Autonomous AI Agent Took Root on a Security Nonprofit's Servers in Seconds

The Dutch Institute for Vulnerability Disclosure says an agentic AI system chained two zero-days into full root access on its own, without a human directing each step, and the evidence is detailed enough to take seriously.

Bruno DigitalRead news →
Attackers Are Hiding a Citrix NetScaler Web Shell Inside a Fake CSS File
Cybersecurity·2d ago

Attackers Are Hiding a Citrix NetScaler Web Shell Inside a Fake CSS File

A critical NetScaler flaw is being paired with a post-exploitation payload that creates a hidden superuser account and disguises its web shell as a legitimate stylesheet, and the tradecraft matters as much as the CVE.

Bruno DigitalRead news →
P&G, Colgate and Kimberly-Clark Just Told Investors Where Their Supply Chains Actually Hurt
Cybersecurity·2d ago

P&G, Colgate and Kimberly-Clark Just Told Investors Where Their Supply Chains Actually Hurt

Three of the largest CPG companies on earth used the same week to admit their automation programs are real but not fast enough to outrun freight costs, oil prices, and a distribution center fire.

Bruno DigitalRead news →