Identity & access
-
GlobalProtect flaw is under attack
Palo Alto Networks has updated its GlobalProtect vulnerability advisory again. The affected PAN-OS issue can allow unauthorised VPN connections in specific configurations and is now marked as attacked.
-
Google binds sessions to devices
Google has made device-bound session credentials generally available for Workspace. The Chrome security change addresses session-cookie theft, one route attackers use to work around multi-factor authentication.
-
Italy reports sustained phishing pressure
CERT-AGID recorded 94 malicious campaigns in one reporting week alone. The data shows persistent identity, malware, and public-service impersonation pressure across a major European market.



