Identity & access
-
Entra will treat device credentials as MFA
Microsoft Entra will recognise Windows Hello for Business and macOS Platform SSO as standalone multifactor authentication in supported scenarios, removing some additional authentication-method prompts.
-
Ransomware exploits SonicWall remote-access flaws
CISA says two previously exploited SonicWall SMA1000 vulnerabilities are now associated with ransomware activity, escalating weaknesses in infrastructure that controls privileged remote access.
-
Russian hackers turn recruitment into access route
CERT-UA says a Russian military-linked threat cluster is approaching Ukrainian IT professionals through legitimate recruitment channels before steering candidates towards malicious technical assessments.
-
Russian hackers turn recruitment into access route
CERT-UA says a Russian military-linked threat cluster is approaching Ukrainian IT professionals through legitimate recruitment channels before steering candidates towards malicious technical assessments.
-
Belgian eID flaws exposed trust-chain weaknesses
Flaws in software connecting Belgian electronic identity cards to web services exposed card data, PIN handling, signing functions, and local code execution across a widely deployed digital-trust system.
-
Belgian eID flaws exposed trust-chain weaknesses
Flaws in software connecting Belgian electronic identity cards to web services exposed card data, PIN handling, signing functions, and local code execution across a widely deployed digital-trust system.
-
CSS research crosses email and AI boundaries
PortSwigger research shows how weaknesses in webmail HTML and CSS handling can escape message boundaries, manipulate trusted interfaces, expose information, and influence AI browsers consuming email content.
-
RovoBlast exposes AI agent permission risks
A fixed flaw in Atlassian Rovo showed how a crafted link could place attacker instructions inside a trusted AI session and use the agent’s legitimate access across connected enterprise services.
-
‘No reply’ domains become accidental data sinks
Researchers controlling plausible placeholder domains are receiving large volumes of misdirected corporate and personal information, exposing persistent weaknesses in automated email and account-deprovisioning processes.
-
ClickFix Mac stealer targets credentials and crypto
Huntress has documented a ClickFix-delivered macOS stealer that harvests identity data and contains code capable of draining a configurable portion of cryptocurrency balances.






