1. Executive Summary (TL;DR)


2. Top IAM & Security News

JadePuffer ransomware used AI agent to automate entire attack

Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts

FortiBleed credential-theft campaign linked to Lynx ransomware

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

FBI Seizes NetNut Proxy Platform, Popa Botnet

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

CISA: Microsoft SharePoint RCE flaw now actively exploited


3. AI, Identity & Emerging Tech

JadePuffer ransomware used AI agent to automate entire attack

Identity Lifecycle Management Wasn't Built for AI Agents

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study


4. Cyber Threats & Attack Trends

Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

FortiBleed credential-theft campaign linked to Lynx ransomware

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

New Avalon Malware Framework Packs CrownX Ransomware Capabilities


5. Product Updates & Vendor News

Microsoft Accelerates Post-Quantum Cryptography Shift to 2029