1. Executive Summary (TL;DR)


2. Top IAM & Security News

Hackers Used Meta's AI Support Bot to Seize Instagram Accounts

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months

Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites


3. AI, Identity & Emerging Tech

New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

Securing AI Agents Before They Go Rogue Is Next to Impossible


4. Cyber Threats & Attack Trends

Chinese APT Deploys New Malware to Keep Access to Hacked Networks

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

FBI-Flagged Phishing Kit Kali365 Expands Its Reach

FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

Suspicious Polyfill Login Prompts Pop Up on Toshiba, Muji Websites


5. Product Updates & Vendor News

Opal Security Raises $23 Million for AI-Native Identity Governance

Cisco Warns of Unpatched SD-WAN Zero-Day Exploited in Attacks

Anthropic to