1. Executive Summary (TL;DR)


2. Top IAM & Security News

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Identity Attacks Overtake Exploits as Top Ransomware Cause

Lessons Learned from CISA's Recent GitHub Leak

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

WordPress Core "wp2shell" RCE Flaws Get Public Exploits, Patch Now

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV


3. AI, Identity & Emerging Tech

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

OpenAI's GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6

Google Bets 'Agentic Defense' Strategy Can Outpace Attackers

1M+ Emails Use Hidden Text to Dupe AI Security Filters


4. Cyber Threats & Attack Trends

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack

Inc Ransomware Exploits SonicWall SMA Zero-Days

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images


5. Product Updates & Vendor News

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution