1. Executive Summary (TL;DR)


2. Top IAM & Security News

Two Alleged TeamPCP Members Charged in Australia Over Major Open-Source Supply Chain Attacks

McKesson Discloses Breach; ShinyHunters Claims Theft of 284 Million Patient Records

PaperCut Releases Second Emergency Patch as Two Flaws Are Chained for Unauthenticated Code Execution

Mirage2FA Campaign Surged to 4,500+ US/EU Companies, Bypassing Microsoft 365 2FA

NovaCookies Kit Steals Microsoft 365 Sessions for $320/Month

CISA Red Team Fully Compromised Two Critical Infrastructure Orgs — One Never Detected It

Hasbro Discloses Data Breach Affecting Employees' Personal and Financial Information

Researchers Detail Red Flags to Expose Fake North Korean IT Workers


3. AI, Identity & Emerging Tech

OpenAI: Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

NVIDIA NemoClaw Weakness Could Let a Malicious Webpage Poison Local AI Models

Amazon Kiro Prompt Injection Could Exfiltrate Sensitive Data via Kiro Powers

Fake Apple Support AI Calls Target Stolen-Device Passcodes and 2FA Codes

Claude Opus 4.6 Bypassed Gym Booking Restrictions in Agentic Tests


4. Cyber Threats & Attack Trends

Exploited Zimbra Flaw Highlights Shrinking Patch Window, Enables Full Takeover of User Communications

Russian Hackers Shift Phishing to Signal and WhatsApp to Target EU Officials

OwnCloud Flaw Added to KEV After Exploit Stole Nuclear Records From Philippine Research Body

Critical Gitea RCE Actively Exploited; CISA Warns of Ongoing Attacks

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code


5. Product Updates & Vendor News

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

Brave Browser 1.94 Adds Email Aliases to Help Users Evade Tracking

ServiceNow Patches Three CVSS 10.0 Flaws in Its AI Platform

Android 17 Adds OS-Wide Encrypted Client Hello to Hide Website Visits From Network Providers


6. Practical Security Takeaways


7. Trends to Watch


Sources