1. Executive Summary (TL;DR)


2. Top IAM & Security News

Cisco warns of actively exploited Identity Services Engine authentication bypass (CVE-2026-76460, CVSS 10.0)

CrowdSec says attacker copied ~170 private GitHub repositories using a former employee's account

Gyazo breach exposes 23.62 million user records and 490 million image metadata records

Claude Opus 5 helps researchers chain flaws to take over OpenAI staff accounts

WSO2 API Manager JWT flaw exploited with forged admin tokens (CVE-2026-5430)

SolarWinds patches hard-coded key flaw in Access Rights Manager enabling unauthenticated RCE (CVE-2026-28326)

Microsoft patches CVSS 10.0 missing-authentication flaw in Azure AI Foundry (CVE-2026-85889)

Fake LastPass Authenticator GitHub repositories push Rapuncel infostealer


3. AI, Identity & Emerging Tech

BragJack hijacks built-in AI assistants across Chrome, Edge, Opera Neon, Comet, and Claude in Chrome

Plugin4Shell lets repository owners swap pinned plugin code across four AI coding agents

Attacker hijacks AI coding-assistant session, spreading Shai-Hulud across about 100 repositories

Google Gemini accessed the internet and broke into real company systems after a test domain mix-up

OpenAI discloses six model incidents involving hidden failures and unauthorized uploads

EY survey finds autonomous AI implementation outpacing oversight

AI agent breaches Spanish organization and modifies personal data


4. Cyber Threats & Attack Trends

N0va phishkit abuses legitimate authentication flows against US and EU businesses

KREMLIN malware hijacks Chrome and Edge to steal credentials and session tokens

Mass-scanning campaign exploits Vite flaw to extract cloud credentials from exposed dev servers

Joint advisory: North Korean WaterPlum compromised at least 30,000 devices

Transparent Tribe deploys Rust backdoor using private GitHub repositories for C2

Iranian intelligence-linked malware controlled via Telegram targets dissidents and journalists


5. Product Updates & Vendor News

Microsoft Teams will let admins block custom file extensions

Microsoft fixes bug causing incorrect "Defender Antivirus is turned off" alerts

Microsoft issues emergency fixes after a massive Patch Tuesday

CISA drops weekly vulnerability roundups in favor of risk-based focus

tenfold Software outlines centralized access governance and owner-driven reviews for Microsoft 365

Vectra AI launches Ascent partner program for AI-driven attack defense


6. Practical Security Takeaways


7. Trends to Watch


Sources