1. Executive Summary (TL;DR)


2. Top IAM & Security News

Microsoft disrupts EvilTokens device-code phishing service tied to 12,000 inbox compromises

TeamFiltration campaign targets 5,700+ Microsoft 365 accounts across 28 tenants

F5 patches critical BIG-IP APM zero-day exploited for unauthenticated RCE on OAuth servers

ShinyHunters bypasses WAF rules to resume Oracle PeopleSoft exploitation (CVE-2026-35273)

Kiteworks urges customers to stop using platform after federal threat intelligence warning

Bitget says suspected North Korean hackers stole $351.6M from hot and warm wallets

Leaked GitLab issue email address lets anyone push code and run CI jobs as the user

CISA adds actively exploited SharePoint RCE and MikroTik RouterOS flaws to KEV catalog


3. AI, Identity & Emerging Tech

OpenAI agent reached non-public files on Australian Medicare portal; researchers question whether hacking was required

Zero Trust for AI Agents Starts With Fixing Zero Visibility

Secrets sprawl is an identity problem that AI made impossible to ignore

AI Agents Are Rewriting the Rules of Lateral Movement

Critical Bifrost AI gateway flaw allows unauthenticated command execution

New x47.c Windows botnet weaponizes xAI Grok and drains AI APIs

Windows malware CLOSEDQUORUM lets up to four AI models vote on its next move

'Salesbleed' exploits Salesforce agents to enable Slack phishing


4. Cyber Threats & Attack Trends

MikroTrick chain allows MikroTik router takeover without a password or SSH key

Lunex stealer abuses an AMD driver to disable security monitoring and steal browser credentials

Corp MDM Android spyware targets logistics firms, steals SMS and redirects calls

Stolen OAuth token from a former employee's computer exposed 170 CrowdSec private repositories

Compromised GitHub Actions re-enabled while Mini Shai-Hulud payload remained active

Elementor CSRF flaw lets unauthenticated attackers create administrator accounts


5. Product Updates & Vendor News

Microsoft pauses KB5002907 Microsoft 365 update after Office license deactivations

Cloudflare fixes flaw that let one container read another customer's leftover disk data

WordPress 7.1.2 patches critical core flaw

cPanel fixes CalDAV/CardDAV flaw enabling root code execution and a WP Toolkit database flaw

Vercel fixes Next.js ImageResponse flaw that can lead to server code execution


6. Practical Security Takeaways


7. Trends to Watch


Sources