1. Executive Summary (TL;DR)


2. Top IAM & Security News

Chinese Hackers Backdoored Linux Login System (PAM/OpenSSH) to Spy for Nearly a Decade

Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs

CISA Orders Federal Agencies to Patch Actively Exploited Ivanti Flaw Within Three Days

ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities

Over 400 Arch Linux AUR Packages Hijacked to Deploy Credential Stealer and Rootkit

Check Point VPN Critical Flaw Exploited Since Early May — Qilin Ransomware Affiliate Implicated

phpBB Forum Fixes 10-Year-Old Authentication Bypass Bug


3. AI, Identity & Emerging Tech

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Researchers Build Self-Replicating AI Worm Operating Entirely on Local Open-Weight Models

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

US Gov Orders Anthropic to Ban Foreign National Access to Fable 5 and Mythos 5


4. Cyber Threats & Attack Trends

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

Silent Ransom Group Hits US Law Firms Using Vishing, IT Impersonation, and In-Person Intrusions

Phishing Attack Volume Down 20%, But Risk Still Rising

WinRAR Flaw Expl