1. Executive Summary (TL;DR)


2. Top IAM & Security News

Canadian Man Pleads Guilty in Snowflake Extortions

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Kali365 Weaponizes Microsoft Authentication Against US Companies

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Metabase Zero-Day Exploited in the Wild Allows Admin Access Without Authentication

Swiss Government SharePoint Breach Compromised 200 Accounts

Levi Strauss & Co. Says Hackers Stole Corporate Data in Cyberattack


3. AI, Identity & Emerging Tech

Critical One-Click Vulnerability in Atlassian's Rovo AI Exposed Enterprise Data

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

AI Agent Sandbox Escapes Reported at OpenAI, Anthropic, and Meta

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Researcher Claims Control of ChatGPT Secure Sandbox


4. Cyber Threats & Attack Trends

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

ClickFix Attack Pushes macOS Infostealer for Crypto Theft Attacks

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

Attackers Exploit N-able Patch Bypass Flaw on RMM Servers


5. Product Updates & Vendor News

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution


6. Practical Security Takeaways


7. Trends to Watch


Sources