Identity & access
-
CERT-EU advisories expose infrastructure risk
CERT-EU’s 2026 advisory stream shows exploited and high-impact flaws across perimeter appliances, identity infrastructure, firewalls, and enterprise network systems.
-
Cursor flaws expose AI coding risk
Cato AI Labs says two critical Cursor IDE vulnerabilities show how prompt injection can escape an agent sandbox and reach developer workstations.
-
Pegasus breach reaches EU spyware oversight
Citizen Lab says a former MEP on the European Parliament’s spyware inquiry was infected with Pegasus, exposing fresh accountability concerns around surveillance, parliamentary confidentiality, and device assurance.
-
MuddyWater widens espionage exposure
WatchGuard’s report on Iran-linked MuddyWater activity points to credential theft, trusted tool abuse, and espionage against high-value organisations.
-
BioShocking exposes AI browser identity risk
LayerX research shows how AI browsers can be manipulated into exposing credentials, code, and signed-in account data.
-
BlueHammer reaches ransomware exposure
CISA’s ransomware link for Microsoft Defender’s BlueHammer flaw changes the operational framing from routine patching to endpoint privilege and containment.
-
GuardFall exposes coding-agent command risk
GuardFall research shows how AI coding agents can be pushed past command safeguards, exposing developer machines, secrets, repositories, and build environments.
-
Barracuda tracks phishing beyond passwords
Barracuda’s June Email Threat Radar shows phishing moving deeper into session tokens, OAuth flows, device-code lures, split-click evasion, and malware delivery.
-
Russian phishing targets Signal recovery keys
US agencies warn Russian intelligence-linked actors are soliciting Signal backup recovery keys, shifting secure messaging risk towards account recovery, user verification, and communications governance.
-
SimpleHelp flaw exposes managed access risk
Exploitation of a SimpleHelp authentication bypass shows how remote management tooling can become a privileged route into endpoints, cloud credentials, developer systems, and customers.





