1. Executive Summary (TL;DR)


2. Top IAM & Security News

Klue OAuth Breach Victim List Grows as Icarus Hackers Claim Attack

CISA Warns Fortinet Users to Secure Devices After FortiBleed Leak

Microsoft Links Mastra AI Supply Chain Attack to North Korean Hackers

Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

CISA: Splunk Enterprise Flaw Actively Exploited, Patch by Sunday

Texas Govt Data Breach Exposes Over 3 Million Driver's Licenses

Novo Nordisk Breach Highlights Software Development Pipeline Risk


3. AI, Identity & Emerging Tech

Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network

Forget Data Leakage: Shadow AI's Real Threat Is Access Control

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting


4. Cyber Threats & Attack Trends

FortiBleed: Sweeping Credential-Harvesting Campaign Compromises 30K+ Fortinet Devices

Klue OAuth Token Theft: Salesforce Disables Integration After Customer Data Exposed

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor C2 Traffic

INC Ransomware Emerges as Major RaaS Threat with 830+ Victims Since 2023