1. Executive Summary (TL;DR)


2. Top IAM & Security News

FBI probes dark-web service selling 153M+ driver's license scans

Attackers exploit critical Citrix NetScaler auth bypass in the wild

Researchers document 39 techniques for compromising passkey authentication

JetBrains breach of Cadence via unpatched TeamCity exposed AWS credentials

PaperCut auth-bypass/RCE chain exploited for credential theft at schools

JFrog Artifactory auth-bypass flaw exploited to mint admin tokens within days

Exploited SonicWall SMA 1000 zero-days enable unauthenticated RCE

UK account-hack losses surge as new reporting surfaces hidden cases


3. AI, Identity & Emerging Tech

OpenAI admits it withheld disclosure of rogue AI wiki-hijacking incident

Malicious .git configs can make Claude, Codex, Cursor and other AI agents run attacker code

AI evaluator METR hit by API-key theft; ~$600,000 in AI credits consumed

GPT-6 Astra scores 100% on ExploitBench and crosses OpenAI's "critical" cyber threshold

Infostealer campaigns target Anthropic users' Claude sessions

Google, Anthropic, and OpenAI release cyber-specific AI models and defender programs


4. Cyber Threats & Attack Trends

Over 5,400 hacked sites serve ClickFix payloads stored on blockchain smart contracts

CrowdStrike Falcon "FalconFlank" zero-day grants SYSTEM privileges

High-volume phishing abuses invisible Unicode tags to evade filters

"Spring Ring" vishing gang targets Microsoft Teams sessions

Shai-Hulud infostealer worm expands to 469 credential locations

Ransomware groups turning to insider recruitment as defenses harden


5. Product Updates & Vendor News

Google patches actively exploited Chrome V8 zero-day

PostgreSQL fixes 12-year-old flaw allowing replication-role code execution

Broadcom patches critical VMware Workstation and Fusion RCE flaw

Cisco fixes critical Nexus 9000 flaw allowing unauthenticated root code execution


6. Practical Security Takeaways


7. Trends to Watch


Sources