Federal agencies warn of active AI-assisted targeting of Siemens S7 PLCs · CareCloud breach scope rises to 3.76 million people · CISA adds MLflow SSRF flaw to exploited-vulnerability catalogue · Federal Medusa update raises critical-infrastructure victim count above 500 · Mirage2FA telemetry reframes Microsoft 365 MFA as a session-containment problem
Active Ray exploitation turns developer AI environments into an incident question · Clop’s PTC campaign gains company confirmation but victim scope remains uneven · France escalates tax-data breach response after containment missed extraction · CEVA breach reaches Pokémon customers as fulfilment disruption spreads · Bluesky’s 24-hour DDoS attack tests communications continuity
Fresh Windchill indicators force compromise reviews beyond patch status · Dutch cyber and critical-entity laws enter into force · RingCentral exposure gains scale as 1.6 million addresses are catalogued · SAP Commerce Cloud exploitation attempts collapse the patch window · Claude outage shows AI continuity must be service-specific
vCenter exploitation turns patching into a compromise investigation · US sets framework for supervised private-sector cyber operations · Trezor breach exposes the risk hidden in fulfilment data · Jewelbug turns one shared webmail template into a national-scale foothold · Apple spyware alerts require a high-risk-user incident path
Internet-exposed macOS Screen Sharing is yielding root access · White House creates a federally controlled private cyber operations programme · Lazarus campaign used a Windows zero-day to suppress endpoint visibility · Akira's Safe Mode tactic blinded controls before encryption failed · NIST asks how the NVD should operate in the age of AI
Gunra warning turns perimeter patching into a credential-and-recovery incident investigation · Saint Paul’s incident moves from operational recovery to disclosed data exposure · Swiss SharePoint concern demands identity evidence rather than breach assumptions · AI vulnerability artefacts need semantic verification, not a successful run · Microsoft 365 app-permission opacity requires a tenant control-plane decision
The keyv/cacheable npm worm changes the order of containment · Vishing extortion shifts the control problem to personal phones and SaaS sessions · Atuin can preserve Linux shell evidence that standard history collection misses · Self-evolving agent skills create a trajectory-poisoning control gap · Automated SSH actors can move from valid login to persistence in 22 seconds
OpenAI’s Black Hat timeline moves the first containment failure to 26 May 2026 · Vishing-extortion crews shift towards finance deal rooms and enterprise cloud · LightSpy’s new footprint puts routers inside the spyware incident boundary · Snowflake campaign guilty plea turns an old cloud-account failure into a verified legal record · WebKit paths can bypass Apple Private Relay and expose real IP addresses