I’ve spent this week watching a scam artist successfully impersonate a friend on LinkedIn, complete with his job title and a slightly better headshot. It was reported four days ago. The account is still up. LinkedIn’s verification process remains slower than their Premium upsell notifications.
Anyway, here’s what happened whilst I waited for customer support to acknowledge his existence.
The Most Expensive Breakup Letter of 2026
OpenAI cut off Cursor after SpaceX bought it, citing Musk’s companies’ “history of violating contracts.” Corporate divorce proceedings are now happening via blog post. The irony of OpenAI lecturing anyone about contract fidelity is not lost on those of us who remember how the company began.
https://openai.com/index/our-decision-on-cursor-following-its-acquisition-by-spacex/
Chrome Web Store Reviews Are Theatre
Extensions listed in Google’s official store got caught stealing crypto wallets and browser data. The “review process” apparently consists of checking whether the Submit button was successfully pressed. We’ve outsourced trust to a platform that outsourced verification to nobody.
153 Million Driver’s Licenses, Going Once
A Louisiana identity verification company got breached so comprehensively that 153 million driver’s licenses are now available on the dark web. The timestamps suggest the theft is ongoing. The US Defence Secretary’s licence is included in the bundle. You cannot make this up because reality stopped accepting editorial feedback.
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
Iran vs Small Power Plants: 2030 Edition
Iran just demonstrated that small UK power plants are trivially hackable. The government knew about this vulnerability last month. The fix is scheduled for sometime before 2030. This is not disaster recovery planning. This is a calendar entry hoping nobody reads the news.
https://www.theguardian.com/business/2026/aug/27/uk-small-power-plants-risk-cyber-attacks-iran-hack
The British Library’s £600k Lesson in MFA
The British Library could have enabled multi-factor authentication on one server. They didn’t. The resulting breach cost them millions in recovery and months of downtime. Sometimes the cheapest security control is the one that stops you explaining to Parliament why the ransom demand arrived before your risk assessment did.
https://www.defendersinitiative.com/p/breach-lessons-the-2023-british-library
When a Fine Becomes a Subscription
San Francisco fined Waymo $115 per traffic violation. Waymo did the maths and realised it’s cheaper than legitimate parking. The SFMTA is now accidentally running a premium lane rental service for autonomous vehicles. Enforcement only works if the penalty costs more than compliance.
Waymo Fines Really Just Billionaires Buying City Streets for Waymo Elites
CCPA Requests: A Choose Your Own Non-Compliance Adventure
Someone filed 100 data access requests under California law. Most companies either deleted the data without being asked, ignored their own privacy procedures, or creatively reinterpreted what “access” means. The regulations exist. The enforcement exists. The compliance apparently does not.
That’s your week. If you’ve got stories I’ve missed or just want to commiserate about the state of things, hit reply. I read them all, usually whilst waiting for LinkedIn support to respond.
Stay cynical, Javvad
