Identity & access
-
Microsoft starts Entra passkey default transition
Microsoft has begun automatically enabling passkeys for Entra users still configured for SMS or voice authentication ahead of the retirement of its native telecom delivery next February.
-
Infostealers hijack Claude sessions for paid usage
Anthropic is warning affected customers that commodity infostealers stole active Claude sessions, allowing attackers to access accounts without repeating the normal authentication process.
-
TerminalFix turns fake CAPTCHA into network access
Microsoft has documented a ClickFix variant that moves from fake CAPTCHA prompts to persistence, Active Directory reconnaissance, and an encrypted reverse tunnel through compromised endpoints.
-
Device trust blocks ReliaQuest breach escalation
A ReliaQuest employee surrendered credentials and approved an MFA prompt during a vishing attack, but device-trust controls prevented the attacker reaching business applications.
-
miniOrange SAML flaws expose WordPress admins
Attackers are probing miniOrange SAML authentication flaws that can allow forged identity assertions or malformed signatures to produce administrator access to WordPress sites.
-
Abnormal joins OpenAI cyber programme
Abnormal AI is joining OpenAI’s Daybreak programme while the companies explore how frontier cyber models can complement existing enterprise security workflows.
-
Leaked Stripe keys expose merchant accounts
Researchers have validated hundreds of exposed Stripe merchant API keys with access to payment and customer functions, without evidence of a Stripe platform breach.
-
HMRC expands MFA across agent accounts
HMRC has completed another phase of its multi-factor authentication rollout for tax agents ahead of automatic activation across remaining accounts this autumn.
-
Manic malware targets Ukrainian mobile services
Manic Android malware is combining financial theft, surveillance and remote control while targeting Ukrainian banks, identity services and communications applications.
-
North Korean workers scale fake hiring identities
A North Korean IT-worker cluster used at least 22 fabricated identities and applied to more than 1,100 companies, combining AI, remote access, and human facilitators.









