Another Patch Tuesday, another round of industrial control system fixes—and this one’s a biggie for anyone running operational technology environments….
A Booz Allen Hamilton study found that three of four Chinese AI coding models produced more vulnerable code when prompts identified the user as a U.S. government developer, with Qwen3-Coder showing a 130% increase in vulnerabilities. The report raises urgent questions about AI supply chain security.
Researchers ran static analysis tools on 658 leaked malware projects and found nearly 90% contained recognizable code weaknesses — including disabled TLS validation and shared vulnerable code fragments that defenders could exploit across multiple threat families.
Broadcom released its largest-ever Spring security update and is using AI to hunt vulnerabilities across 100,000+ dependency builds — but zero-day patches are locked behind its enterprise paywall.
A French appeals court ordered Caisse d’Épargne to refund a spoofing scam victim, rejecting the bank’s negligence defense — a ruling that strengthens consumer fraud protections.
A French court has ruled in favor of a spoofing scam victim who was denied reimbursement by his bank, establishing that deceived customers aren’t negligent just because criminals exploited their bank’s own identity to trick them.