Identity & access
-
Zimbra zero-day opens mailboxes on view
A Russian state-supported group exploited a Zimbra zero-day to steal mail and authentication material when victims merely viewed a malicious message.
-
Genetic data failures cost 23andMe €2.4m
Spain’s privacy regulator found that optional authentication, unrestricted data access, and delayed notification failed to protect highly sensitive genetic information.
-
Azure DevOps agent flaw shows hidden identity risk
Manifold Security says hidden pull request instructions can steer an Azure DevOps MCP agent into using a reviewer’s own permissions.
-
Kratos takedown exposes the limits of MFA
German and US authorities have disrupted Kratos, a phishing-as-a-service kit used to steal Microsoft 365 credentials and session cookies.
-
Ofcom moves messaging controls upstream
New Ofcom rules require mobile operators and messaging aggregators to strengthen sender verification, traffic monitoring, message blocking, and incident management across the business-messaging supply chain.
-
TikTok age controls face Ofcom investigation
Ofcom has opened an Online Safety Act investigation into whether TikTok’s age-assurance controls are sufficiently effective at identifying children and limiting their exposure to harmful content.
-
ClickLock puts macOS identity stores at risk
A newly documented macOS stealer targets Keychain records, browser sessions, password managers, wallets, and developer credentials, with more than half of identified victims located in Europe.
-
WINDTRE faces €1.7m penalty after retail breaches
Italy’s privacy regulator has fined WINDTRE after attackers exploited retail support processes and weak credential and certificate controls to access data belonging to more than 365,000 customers.
-
Microsoft 365 phishing moves beyond passwords
Jalisco and OmegaLord target Microsoft 365 identities by abusing device-code authentication and collecting information that can support interception of weaker MFA methods.
-
Zoom Windows clients face account takeover
A critical input-validation vulnerability could allow an unauthenticated attacker to take over accounts through affected Zoom Workplace and VDI clients for Windows.







