1. Executive Summary (TL;DR)


2. Top IAM & Security News

Attackers breached Denmark's DTU identity and access management system, exposing data on up to 200,000 people

Cisco Catalyst SD-WAN Manager authentication bypass exploited and added to CISA KEV

Citrix NetScaler flaws exploited for root access, web shells, and configuration theft

FortiMail zero-day enabling unauthenticated arbitrary file writes added to KEV

French tax administration data theft using stolen staff passwords went undetected for seven weeks

Bitget confirms $387.5 million theft via third-party security product zero-day and internal credentials

Dutch police arrest suspect in ShinyHunters investigation as group escalates attacks

Frontline Education breach exposes school district employee data, including SSNs


3. AI, Identity & Emerging Tech

Analysis: AI agents are privileged users that are rarely audited

Framework guidance published for IAM for AI agents

'JadePuffer' agentic threat actor compromised an Azure tenant using exposed credentials

Official MCP Python SDK flaw lets malicious servers steal OAuth credentials

Nvidia launches AI agent safety platform to quarantine rogue agents

Carbonato botnet puts an AI agent on compromised Docker hosts

Google moves toward giving Gemini broad autonomous access on macOS

doxx.net raises $38 million for an AI agent identity platform


4. Cyber Threats & Attack Trends

CSuite phishing campaign steals Microsoft 365 sessions and deploys RMM tools

Attackers abuse MSP360 installers to drop ScreenConnect in dual-RMM phishing

Star Blizzard widens phishing to deliver CosmicPulse backdoor

Browser-based attacks evade endpoint telemetry, including session theft

Warlock ransomware exploits SharePoint flaws to disable security tools and deploy ransomware

Chrome Store hosts 'Poper Blocker' spyware downloaded by millions


5. Product Updates & Vendor News

Cloudflare announces a public certificate authority for the post-quantum web

Google rolls out Gemini 4 Argon to trusted cyber defenders, plans guardrail-free version

Android 17 Advanced Protection limits accessibility services to verified tools

Fortra patches critical BoKS vulnerabilities enabling authentication bypass

Dell patches max-severity CSM flaws enabling unauthenticated admin access on Kubernetes

Microsoft publishes 2026 Digital Defense Report


6. Practical Security Takeaways


7. Trends to Watch


Sources