
Weekly Axis Of Easy #463
Last Week’s Quote was: “Future shock is the shattering stress and disorientation that we induce in individuals by subjecting them to too much change in too short a time.” — was by Alvin Toffler. Several got the right answer, but Andy got it right first! Congrats.
This Week’s Quote: “It is change, continuing change, inevitable change, that is the dominant factor in society today. No sensible decision can be made any longer without taking into account not only the world as it is, but the world as it will be.” By ???
THE RULES: No searching up the answer, must be posted at the bottom of this blog post, in the comments section.
The Prize: First person to post the correct answer gets their next domain or hosting renewal on us.
This is your easyDNS #AxisOfEasy Briefing for the week of August 10th, 2026. Our Technology Correspondent Joann L Barnes and easyCEO Mark E. Jeftovic send out a short briefing on the state of the ‘net and how it affects your business, security and privacy.
To Listen/watch this podcast edition with commentary and insight from Joey and Len the Lengend click here.
In this issue:
- Facial Recognition Comes to the London Underground, Whether You Signed Up or Not
- Google’s Synced Passkeys Have a Master Key — And It Can’t Be Revoked
- Metabase Zero-Day Bites Framework: Names, Emails, and a Reminder About Vendor Trust
- Hackers Pivot Through a Private Cell Network Into a Polish Power Plant’s OT Network
- North Carolina’s Ports Go Manual After a Cyberattack Nobody Wants to Talk About
- Your Kid’s GPS Watch Was Built on the Same Three Leaky Backends As Everyone Else’s
Elsewhere Online:
easyHermes is here…
We’re pleased to announce the expansion of our agentic hosting platform with the rollout of easyHermes, the latest agent-enabled VPS appliance on the easyNode.ai platform.

Now you can answer the “openclaw vs Hermes” question for yourself, or run them both.
Check it out today, and get your first month on us when you use promo code AXISOFEASY
Live facial recognition arrives on the Tube from Tuesday, starting at Victoria station, with British Transport Police running the cameras to flag people on a police watchlist — the pitch being “high-harm” offenders wanted for sexual offences, robbery, and knife crime. TfL says non-matches get deleted “automatically and immediately,” and the deployments will sit in signed areas with “alternative routes available” for anyone who’d rather not walk past a live-matching camera on their commute. It’s the expansion of a BTP trial that’s been running at major London rail stations since February.
Here’s the number that should be doing the talking instead of the press release: 18 deployments, over 530,000 faces scanned, zero true matches, zero arrests, one false identification. That’s the track record the Tube expansion is built on. Big Brother Watch calls it “dystopian,” and whatever you think of that word choice, “routine biometric scanning of a random half-million commuters produced one false positive and nothing else” is not the efficacy case anyone would choose to lead with. Watch what “signed areas” and “alternative routes” mean in practice — that’s the difference between a genuine opt-out and a notice board nobody reads.
More via BBC News
Google’s Synced Passkeys Have a Master Key — And It Can’t Be Revoked
Palo Alto Networks’ Unit 42 spent the past couple of weeks quietly dismantling the “passkeys fix everything” narrative. Their research, dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, shows that malware sitting on a Windows box with zero admin rights can lift the 32-byte Security Domain Secret that decrypts every passkey synced to a Google account, straight out of Chrome’s process memory while it briefly sits there in plaintext. No PIN prompt. No biometric check. No CVE, either — Google hasn’t assigned one, because this isn’t a bug in the cryptography, it’s a bug in the trust model.
The part that should actually worry you isn’t the theft — it’s the “cannot be revoked” part. Passwords get rotated. This key doesn’t. Steal it once and every passkey the victim creates in the future, under that same Google account, is protected by the same compromised secret. Enroll a hardware key like a YubiKey alongside your synced passkeys, because a device-bound credential never touches Chrome’s enclave state and can’t be pulled from memory. Passkeys still kill phishing outright. They just don’t survive a machine that’s already lost.
More via Malwarebytes
Metabase Zero-Day Bites Framework: Names, Emails, and a Reminder About Vendor Trust
Framework, the repairable-laptop people, got a call from their business-intelligence vendor Metabase informing them that someone had exploited a maximum-severity, still-unnumbered SQL injection zero-day in Metabase Cloud to gain administrator access to Framework’s instance. The attackers walked out with names, emails, phone numbers, physical addresses, and login IPs — no payment data, no order history, small mercies. Metabase says the flaw affects versions 58 and above and lets an unauthenticated remote attacker inject arbitrary SQL to reach admin, from which they can read anything the connected databases can see.
This is the SaaS-vendor problem in miniature: Framework didn’t get breached, their dashboard tool did, and that was enough. If you’re piping customer data into a hosted BI tool, ask what happens to that data the day the vendor gets popped, not just the day you sign the contract. Patch Metabase now if you’re self-hosting; if you’re on Metabase Cloud, this one wasn’t yours to patch.
More via Help Net Security
Hackers Pivot Through a Private Cell Network Into a Polish Power Plant’s OT Network
CERT Polska finally closed the books on a piece of the December 29, 2025 attacks on Poland’s energy grid, and it took three months for good reason: the attackers found a genuinely new door. They compromised an internet-facing FortiGate VPN/firewall at a wind farm, tunneled through a Teltonika cellular router via SSH, and rode a private Access Point Name — the dedicated mobile network a distribution operator sets up with a carrier — straight into a Wago PLC controlling a combined heat-and-power plant that supplies heat to roughly 50,000 residents. A misconfiguration let arbitrary devices on that “private” APN talk to each other. Steam turbine and water treatment: down.
CERT Polska calls this the first documented real-world case of a private APN being used as an OT lateral-movement path, and warns the same misconfiguration is common in Poland and, they suspect, plenty of other countries. If your OT reachability story leans on “it’s on a private cellular network, so it’s isolated,” this is your invitation to go verify that claim instead of trusting it.
More via BleepingComputer
North Carolina’s Ports Go Manual After a Cyberattack Nobody Wants to Talk About
On August 4, an unidentified actor knocked out IT systems statewide at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, forcing all three back to manual gate processing. Wilmington alone averages 5,000 container gate moves a week; between the two seaports that’s 4.4 million short tons of cargo a year riding on the outage. The Ports Authority activated its cybersecurity contingency plan, contained the intrusion within a day, and had gates back on normal schedules by August 6 — though full IT restoration, and any word on attribution or data loss, is still pending as of this writing.
Notice what’s not in this story: a ransom note, a named threat actor, a leak site post. Either this was contained before extortion, or someone’s still negotiating quietly. Either way, “critical infrastructure, no OT touched, still shuts down a port” is becoming a very familiar sentence this year.
More via BleepingComputer
Your Kid’s GPS Watch Was Built on the Same Three Leaky Backends As Everyone Else’s
Researchers tore into more than 70 GPS-enabled kids’ smartwatches and vehicle trackers sold under dozens of different brand names and found that tens of millions of them trace back to just three shared backend platforms. The flaws let an attacker locate a device, intercept messages, swap out emergency contacts, falsify location data, and in some cases activate the microphone — remotely, on hardware marketed specifically as a child-safety device. The researchers reported the issues privately months ago; one vendor patched quietly before the public disclosure, others haven’t responded at all.
The brand on the box tells you almost nothing about who’s actually running the backend. If you’re shopping for one of these, the question that matters isn’t “which brand” — it’s “which of the three platforms,” and good luck getting a straight answer from the packaging.
More via Digital Trends
Also on AxisOfEasy this week:
Nothing new in the Curated Posts feed since issue #462 — it’s been quiet there since May. We’ll flag anything new the moment it lands.
Elsewhere Online:
CISA Sounds the Alarm on Gunra Ransomware Hitting Exposed VPNs
Read: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
WordPress Plugin Vendor BdThemes Breached, Poisoned JSON Creates Rogue Admins
Read: https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
OpenAI Ships GPT-5.6-Cyber, an “Offense-Grade” Model for Hire
Read: https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html
Red Hat ACM Bug Lets a Namespace Editor Become Cluster-Admin, CVSS 9.9
Read: https://cyberpress.org/red-hat-acm-flaw-namespace-editors-escalate/
421 CVEs Walk Into Patch Tuesday, One of Them’s Already Being Exploited
Read: https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/]
Previously on #AxisOfEasy
If you missed the previous issues, they can be read online here:
- August 7, 2026: #AxisOfEasy 462: The npm Worm That Ate The JavaScript Supply Chain
- July 31, 2026: #AxisOfEasy 461: In First-of-Its-Kind Case, Atlanta Man Charged Over Phone’s Self-Wiping Passcode
- July 24, 2026: #AxisOfEasy 460: AI Agent Breaches Hugging Face Infrastructure In Unprecedented Security Incident
- July 17, 2026: #AxisOfEasy 459: UK Protects Teens From Midnight Scrolling, As Long As Teens Consent To Being Protected
- July 10, 2026: #AxisOfEasy 458: Ottawa Weighed Suing Citizens Over “Misleading” Social Media Posts
