Identity & access
-
Ofcom moves messaging controls upstream
New Ofcom rules require mobile operators and messaging aggregators to strengthen sender verification, traffic monitoring, message blocking, and incident management across the business-messaging supply chain.
-
TikTok age controls face Ofcom investigation
Ofcom has opened an Online Safety Act investigation into whether TikTok’s age-assurance controls are sufficiently effective at identifying children and limiting their exposure to harmful content.
-
ClickLock puts macOS identity stores at risk
A newly documented macOS stealer targets Keychain records, browser sessions, password managers, wallets, and developer credentials, with more than half of identified victims located in Europe.
-
WINDTRE faces €1.7m penalty after retail breaches
Italy’s privacy regulator has fined WINDTRE after attackers exploited retail support processes and weak credential and certificate controls to access data belonging to more than 365,000 customers.
-
Microsoft 365 phishing moves beyond passwords
Jalisco and OmegaLord target Microsoft 365 identities by abusing device-code authentication and collecting information that can support interception of weaker MFA methods.
-
Zoom Windows clients face account takeover
A critical input-validation vulnerability could allow an unauthenticated attacker to take over accounts through affected Zoom Workplace and VDI clients for Windows.
-
Claude deep links exposed prompt controls
A crafted link could open Claude Desktop and submit hidden attacker instructions automatically, exposing the boundary between browsers, AI agents, and locally authorised tools.
-
Microsoft patches exploited AD FS and SharePoint flaws
Microsoft’s July security update includes exploited vulnerabilities affecting Active Directory Federation Services and SharePoint Server.
-
SonicWall warns SMA flaws are exploited
SonicWall says two SMA 1000 vulnerabilities are being actively exploited and is urging customers to upgrade, investigate, and reset credentials where needed.
-
Microsoft Kerberos change creates outage risk
Microsoft’s July 2026 Windows updates remove Audit mode for Kerberos RC4 hardening, raising authentication failure risk in legacy-dependent environments.





