1. Executive Summary (TL;DR)


2. Top IAM & Security News

Microsoft patches CVSS 10.0 Entra ID flaw and critical Azure Arc / Exchange Online vulnerabilities

More than 9,300 exposed AWS access keys remain active and valid

Suspected Russian espionage clusters abuse Google OAuth and WhatsApp linking to hijack accounts

Citrix patches critical authentication bypass in NetScaler Gateway and AAA server deployments

TWINLOOT implant runs C2 inside SharePoint and Teams to steal credentials

One attacker has scraped Salesforce and ServiceNow customer portals since 2025

N-able Passportal bug exposes password vault master keys


3. AI, Identity & Emerging Tech

AI "mind viruses" can propagate between agents through persistent prompt files

"Shady AI" governance gap: Meta AI agent exposed data to unauthorized employees

Cloudflare Workers Spectre attack leaks JWT from co-located worker

CoSnitch: Microsoft Copilot Personal flaws allow one-click exfiltration of connected-app data

Agentic AI presents a new insider-threat model for organizations

China-linked operator used AI framework in "near-autonomous" attack on APAC government agencies


4. Cyber Threats & Attack Trends

GitLab CVE-2026-19478 under active exploitation within days of disclosure

CISA adds four actively exploited flaws to KEV: macOS, SharePoint, vCenter, Microsoft IKE

Zimbra SNMP flaw exploited for unauthenticated remote code execution

SynkLoader malware distributed via Microsoft Teams phishing steals credentials with fake lock screen

Operation CameraSwarm: 14,500+ Dahua devices compromised via credential attacks and auth bypasses

Manic Android malware exfiltrates data from offline phones, targets banking and identity services


5. Product Updates & Vendor News

OpenAI pauses frontier RL training and tightens AI safety controls

OWASP debuts AI security blueprint: top 10 AI skill risks and Universal Skill Format

Cisco patches nine Crosswork and Secure Workload flaws, five rated CVSS 10.0

Hardware makers begin implementing post-quantum cryptography

Microsoft Defender's signed boot-time driver can be weaponized to delete security software


6. Practical Security Takeaways


7. Trends to Watch


Sources