Identity & access
-
Claude deep links exposed prompt controls
A crafted link could open Claude Desktop and submit hidden attacker instructions automatically, exposing the boundary between browsers, AI agents, and locally authorised tools.
-
Microsoft patches exploited AD FS and SharePoint flaws
Microsoft’s July security update includes exploited vulnerabilities affecting Active Directory Federation Services and SharePoint Server.
-
SonicWall warns SMA flaws are exploited
SonicWall says two SMA 1000 vulnerabilities are being actively exploited and is urging customers to upgrade, investigate, and reset credentials where needed.
-
Microsoft Kerberos change creates outage risk
Microsoft’s July 2026 Windows updates remove Audit mode for Kerberos RC4 hardening, raising authentication failure risk in legacy-dependent environments.
-
NCA charges five over Russian Coms
The National Crime Agency says Russian Coms enabled criminals to disguise scam calls as banks, telecoms companies, and law enforcement agencies.
-
Odido breach probe turns to Dutch suspects
Dutch police say their investigation into the Odido breach has found indications of local involvement, including a Dutch-speaking caller posing as IT staff.
-
Passkey vishing targets Entra users
Okta says vishing actors are using fake Microsoft Entra passkey enrolment flows, showing how attackers are adapting to passwordless authentication.
-
Fake payment SDKs target developer secrets
Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs show how payment-brand trust is being used to reach developer credentials and cloud tokens.
-
Estonia puts identity around AI agents
Estonia’s plan to create digital identities for AI agents turns machine identity, delegated authority, and auditability into a public-sector governance issue.
-
Fortinet exposure keeps edge risk in focus
The NCSC has urged UK organisations using Fortinet firewalls and VPN gateways to investigate potential compromise after a global credential targeting campaign.










