Identity & access
-
AmnesiaStealer takes control of browser sessions
A macOS infostealer distributed through fake GitHub pages can progress from password and browser theft to interactive control of authenticated Chromium sessions.
-
Alleged Azure dumps expose cloud identity gap
Alleged Azure and Entra datasets linked to some of the world’s largest companies show how credential theft outside the cloud perimeter can become access inside it without any cloud zero-day.
-
Cybersecurity and AI: What Mythos means for organisations now
Todd Moore, Vice President of Encryption Products at Thales, examines how AI security models such as Claude Mythos are compressing cyber timelines and reshaping software protection, identity governance, and operational defence.
-
Apple spyware alerts reach 110 countries
Apple has sent a fresh wave of mercenary-spyware threat notifications across 110 countries and expanded how high-risk users are warned about targeted attacks.
-
678,000 caught in French tax breach
France’s tax authority has confirmed the extraction of fiscal data concerning 678,000 people and businesses after attackers used impersonated credentials to access internal systems.
-
Fortinet patches two authentication weaknesses
Fortinet has fixed separate authentication weaknesses in FortiWeb and FortiManager, including a configuration-dependent FortiWeb administrator bypass and a FortiManager device-impersonation flaw.
-
Ivanti fixes remotely reachable Endpoint Manager flaws
Ivanti has patched three high-severity Endpoint Manager vulnerabilities, including an unauthenticated agent denial-of-service flaw and a credential exposure requiring a man-in-the-middle position.
-
Back-to-school identity sprawl raises cyber exposure
Rapid account provisioning, new devices and expanding EdTech integrations are increasing identity-governance pressure across UK education as schools and colleges prepare for the new academic year.
-
Dutch NCSC confirms macOS Screen Sharing attacks
The Dutch NCSC has observed attackers exploiting CVE-2026-65400 against internet-reachable Macs, gaining root access and installing cryptomining software.
-
Guest access campaign targets Salesforce and ServiceNow
Researchers are tracking a campaign extracting information from exposed Salesforce and ServiceNow portals through legitimate guest-access mechanisms rather than vulnerabilities in either SaaS platform.







