Identity & access
-
Help-desk impersonation targets financial identities
A large social-engineering campaign has targeted financial and corporate organisations using phone calls, fake support processes, and real-time theft of authentication credentials.
-
Claude browser research demonstrates account takeover chains
Zenity researchers used indirect prompt injection against Claude in Chrome to demonstrate cross-service account takeover paths through authenticated browser sessions.
-
Atlas research exposes cross-session agent risk
Zenity researchers manipulated ChatGPT Atlas through hostile web content, demonstrating unauthorised actions across authenticated services before the browser’s scheduled retirement on 9 August.
-
Snowflake hacking case reaches guilty plea
Connor Moucka has pleaded guilty over a campaign that compromised more than 165 organisations, giving the Snowflake customer-account attacks a new accountability chapter.
-
Geofencing isn’t about blocking countries. It’s about spotting logins that make no sense
Daniel Shone, Founder of Apex Computing, explains how geofencing can add location context to authentication, helping organisations identify access requests that make little sense even when credentials appear valid.
-
Why your identity database is your biggest liability (and what’s replacing it)
Stefan Deiss, CEO and Co-Founder of The Hashgraph Group, argues that verifiable credentials and distributed ledgers can reduce the risks created by centralised identity databases.
-
PNLD breach reaches central government bodies
Contact details exposed through the Police National Legal Database include police, defence, central-government, criminal-justice, and public users.
-
Supplier account opens route into Żabka systems
Attackers used an external provider’s account to access Żabka resources supporting its franchise network, although payments, shops, consumer services, and Żappka data remained unaffected.
-
Greatness adds device-code phishing to service
The Greatness phishing service has added device-code and OAuth-consent attacks, expanding beyond credential interception into token-centred Microsoft 365 account compromise.
-
Visa agrees $2.4bn BioCatch acquisition
Visa’s proposed $2.4 billion purchase of BioCatch would bring behavioural and device intelligence used by more than 350 banks into the payment group’s security portfolio.







