Identity & access
-
Barracuda tracks phishing beyond passwords
Barracuda’s June Email Threat Radar shows phishing moving deeper into session tokens, OAuth flows, device-code lures, split-click evasion, and malware delivery.
-
Russian phishing targets Signal recovery keys
US agencies warn Russian intelligence-linked actors are soliciting Signal backup recovery keys, shifting secure messaging risk towards account recovery, user verification, and communications governance.
-
SimpleHelp flaw exposes managed access risk
Exploitation of a SimpleHelp authentication bypass shows how remote management tooling can become a privileged route into endpoints, cloud credentials, developer systems, and customers.
-
Langflow attacks expose AI workflow risk
Observed exploitation of Langflow vulnerabilities shows how self-hosted AI workflow tools can expose API keys, cloud secrets, and agent infrastructure before governance catches up.
-
TfL cyber attackers plead guilty
Two men have pleaded guilty over the 2024 Transport for London cyberattack, creating a rare accountability moment after a major public transport incident.
-
Operation Endgame disrupts malware infrastructure
European authorities have disrupted SocGholish, StealC, and Amadey infrastructure, targeting malware services used for initial access, credential theft, and follow-on cybercrime.
-
Cisco flaw reaches communications layer
An exploited Cisco Unified Communications Manager flaw exposes how collaboration and telephony platforms can become privileged infrastructure risk.
-
VS Code tasks expose developer risk
JFrog says hijacked npm packages used hidden VS Code tasks and blockchain dead drops to deploy a credential and cryptocurrency stealer.
-
Signal phishing shifts to recovery keys
US agencies say Russian intelligence-linked actors are trying to obtain Signal backup recovery keys, creating account takeover and historic message exposure risk for high-value targets.
-
Hotel phishing campaign targets Europe
Microsoft says hospitality organisations in Europe and Asia are being targeted with photo-themed phishing that delivers a persistent Node.js implant.






