First Pass

14 stories from 10 sources

AI is compressing the cybersecurity patching race

Day’s Recap

Supporting Articles

5:44 PMKrebs on Security

Microsoft Plugs Nearly 1,000 Security Holes

Summary

Microsoft released fixes for at least 974 vulnerabilities across Windows and other software, its largest single patch batch to date. The company says AI is accelerating vulnerability discovery, while security teams face growing difficulty testing and deploying the fixes.

The scale of the release turns patch management into a capacity problem, not just a

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

A record patch volume increases the odds that overwhelmed organizations will miss vulnerabilities attackers can exploit.

2 stories · 2 sources

10:00 AMThe Verge

Microsoft breaks another patch Tuesday record

Summary

Microsoft is facing an unusually heavy stream of Windows and security vulnerabilities, with new AI models helping researchers discover flaws at a faster pace. The resulting workload has made this year's patch cycle especially demanding for Microsoft's security engineers.

AI-assisted vulnerability discovery is increasing the volume and speed of flaws that vendors must assess

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Faster flaw discovery compresses the time defenders have to patch systems before attackers can exploit them.

3:03 PMPYMNTS

Google Accelerates Chrome Updates to Outrun Fast-Moving AI Hackers

Summary

Google is moving Chrome from a four-week release cycle to updates every two weeks, beginning with Chrome 153 across desktop, Android and iOS. The company says the faster schedule will help it respond to rapidly evolving threats, including attacks aided by artificial intelligence.

Google is treating browser vulnerability response as a race against attackers, cutting the time between

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Faster browser releases can reduce exposure to newly discovered flaws, but they raise the operational burden of patching at scale.

2 stories · 2 sources

10:13 AMPYMNTS

Crypto Platforms Lose $3.6 Billion to Hacks Despite Security Audits

Summary

Crypto platforms lost more than $3.6 billion to hacks and stolen passkeys over the past 18 months, according to CoinGecko findings cited in the report. Most incidents occurred despite companies undergoing security audits, with roughly 88% of the stolen funds concentrated in a large share of the attacks.

The losses show that audits do not reliably protect assets when attackers compromise credentials, operational

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

The gap between audit completion and real-world resilience weakens trust in crypto custody and raises regulatory risk.

4:16 AMCNBC

Crypto platforms have lost over $3.63 billion to cyberattacks — even though most of them did security checks

Summary

Crypto platforms have lost more than $3.63 billion to cyberattacks, and over 60% of the affected platforms had undergone independent security audits.

The decisive fact is that audits did not prevent major losses. That points to a

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Independent audits are becoming a weak proxy for real-time cyber resilience in crypto.

10:23 AMBloomberg Markets

Novartis and Boston Scientific Slide, Intel Price Hikes | Stock Movers

Summary

Boston Scientific said a cybersecurity incident has disrupted product shipments, forcing it to lower its full-year sales growth and earnings expectations. Novartis fell after a late-stage trial failure, while Intel rose on reports that it may increase chip prices next month.

The breach has moved beyond an IT problem and is now constraining Boston Scientific's ability

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Cyberattacks can quickly become supply-chain disruptions that damage both revenue and customer access.

Other Developments

A curated list of other prominent stories from this day.

5:10 PMTechCrunch

Hackers are stealing Claude tokens from subscribers

Summary

A Claude user discovered that his account was consuming tokens while he was inactive, prompting Anthropic to warn users about hackers targeting subscriber accounts. The incident suggests attackers can turn stolen access into unauthorized model usage and unexpected costs.

The immediate risk is account compromise rather than a flaw in the model itself. Users

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Compromised AI accounts can give attackers both access to sensitive workflows and a bill charged to the victim.

3:53 PMPYMNTS

DOJ Extradites Russian Web Developer in $15 Million Bank Account Takeover Scheme

Summary

Russian national Sergei Anatolyevich Filimonov, a 36-year-old web developer, was arraigned in Georgia after being extradited from the Republic of Georgia. U.S. prosecutors allege he participated in a bank account takeover scheme that caused roughly $15 million in losses.

The extradition turns a large-scale account takeover case into a U.S. prosecution, increasing the legal

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Cross-border cybercrime is becoming more prosecutable, but account takeover remains a direct threat to financial institutions and their customers.

10:29 AMMarketWatch

Fake job recruiters are getting smarter about scamming job seekers. AI is making it even worse.

Summary

Scammers are using email and LinkedIn to pose as recruiters and lure job seekers with attractive but fraudulent offers. AI is helping them produce more convincing messages and target candidates at greater scale.

AI lowers the cost of impersonation while making fake recruiting outreach harder to distinguish from

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

The job search is becoming a larger attack surface as AI makes recruitment scams more credible and scalable.

7:30 AMThe Verge

LG TVs caught spying even when offline or on standby

Summary

A report from Gamers Nexus alleges that LG smart TVs continue collecting and uploading information about users and their surroundings, including nearby Wi-Fi devices, microphone data, and audio or video samples. The claims include data collection while some sets are offline or in standby mode.

The core shift is from smart-TV telemetry to persistent environmental monitoring, including signals unrelated to

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Connected TVs can become always-on surveillance platforms, expanding privacy risk beyond the person using the screen.

7:25 AMFinextra

Global standard-setting bodies publish toolkit for cyber resilience at FMIs

Summary

The BIS Committee on Payments and Market Infrastructures and IOSCO published a practical cyber-resilience toolkit for financial market infrastructures, alongside a discussion paper on their dependence on third-party providers. The guidance addresses both operational resilience and the risks created by concentrated technology suppliers.

The key change is a broader regulatory focus on systemic exposure through vendors, not just

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

Financial regulators are treating third-party technology concentration as a potential source of market-wide disruption.

6:20 AMSchneier on Security

Stealing AI Reasoning Traces

Summary

Researchers describe an architectural weakness in proprietary LLM APIs that return encrypted reasoning traces to clients for use in later requests. They argue that the traces can be interchangeable across sessions, users, and models within a provider's ecosystem, creating a path to recover reasoning data at scale.

The decisive issue is that encryption does not protect reasoning traces if the surrounding protocol

Unlock the full First Pass Analysis to get a better understanding of why this story matters

Why it matters

The research suggests that API protocol design, not just encryption strength, can determine whether proprietary model reasoning remains private.

Make it yours

Build Your First Pass.

Pick your topics, set your cadence, and receive your personalized First Pass in your inbox. It’s that simple!