Identity & access
-
Microsoft Kerberos change creates outage risk
Microsoft’s July 2026 Windows updates remove Audit mode for Kerberos RC4 hardening, raising authentication failure risk in legacy-dependent environments.
-
NCA charges five over Russian Coms
The National Crime Agency says Russian Coms enabled criminals to disguise scam calls as banks, telecoms companies, and law enforcement agencies.
-
Odido breach probe turns to Dutch suspects
Dutch police say their investigation into the Odido breach has found indications of local involvement, including a Dutch-speaking caller posing as IT staff.
-
Passkey vishing targets Entra users
Okta says vishing actors are using fake Microsoft Entra passkey enrolment flows, showing how attackers are adapting to passwordless authentication.
-
Fake payment SDKs target developer secrets
Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs show how payment-brand trust is being used to reach developer credentials and cloud tokens.
-
Estonia puts identity around AI agents
Estonia’s plan to create digital identities for AI agents turns machine identity, delegated authority, and auditability into a public-sector governance issue.
-
Fortinet exposure keeps edge risk in focus
The NCSC has urged UK organisations using Fortinet firewalls and VPN gateways to investigate potential compromise after a global credential targeting campaign.
-
NHS warns on Citrix exploitation
NHS England Digital says exploitation of a Citrix NetScaler flaw is active, with further attacks assessed as almost certain after public proof of concept code.
-
FortiBleed turns credentials into ransomware risk
Fortinet says the reported FortiBleed activity involves credential reuse and weak authentication, while researchers warn stolen FortiGate access is circulating at scale.
-
Tchap breach tests French messaging
France says a compromised Tchap account exposed public rooms and account data for fewer than 9% of registered users.










