1. Executive Summary (TL;DR)


2. Top IAM & Security News

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Hackers Exploit Critical Auth Bypass in Gitea Docker Image

Progress Urges ShareFile Customers to Shut Down Servers Over "Credible" Threat

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

Ryuk Ransomware Member Pleads Guilty in the US, Faces 15 Years in Prison


3. AI, Identity & Emerging Tech

AI Agents Are a New Kind of Identity — and Most Organizations Aren't Ready

The Replicant in Your Directory: AI Agents and the Identity Security Gap

Ghostcommit Hides Prompt Injection in Images to Fool AI Agents, Steal Secrets

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

State IDs for AI Agents: Will Estonia Set a Precedent?

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data


4. Cyber Threats & Attack Trends

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

JadePuffer: The First Complete LLM-Driven Ransomware Attack

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses