Overdue WordPress exploit response now requires compromise evidence · WSUS research turns the patching plane into a domain-wide attack path · Pass-the-Passkey exposes replay paths around phishing-resistant MFA · Agent frameworks need containment after prompt injection succeeds · GitHub event streams belong in active detection, not audit storage
N-central patch bypass turns one RMM server into many access paths · INC ransomware activity raises the bar for SonicWall SMA closure · Liechtenstein ownership-register theft creates downstream identity risk · Amgen disclosure exposes a third-party cloud assurance gap · Reported AI-managed proxyjacking campaign needs verification, not dismissal
Water-system attacks widen into Michigan as OT campaign crosses state lines over the weekend · EU AI Act transparency enforcement begins, shifting AI inventory from programme work to evidence obligation · OpenAI–Hugging Face incident makes AI evaluation containment a privileged-system decision · EY extortion deadline passes with third-party support-platform scope still unresolved · Actively exploited SharePoint flaw demands compromise evidence after emergency remediation
Claude evaluations reached real production systems · Teams vishing delivered Chaos ransomware in under 17 hours · Amazon links four npm compromises to one DPRK group · KT penalty exposes telecom control and evidence failures · Analog Devices confirms file exfiltration
Cisco FMC zero-day requires hunting and secret rotation, not patching alone · OWAReaper persistence survives credential rotation and endpoint rebuilding · OpenAI evaluation incident expanded to four external service accounts · Analog Devices confirms files were exfiltrated in June intrusion · New OT guidance makes extended isolation a resilience requirement
OpenAI update identifies Artifactory escape path in Hugging Face intrusion · Arista VeloCloud Orchestrator zero-day puts SD-WAN control planes on an incident footing · New CI Fortify guidance makes OT isolation a testable resilience requirement · Origin Energy says approximately 900,000 customers were affected by data incident · CubePilot DNS hijack exposed trusted services behind valid certificates
Actively exploited Arista flaw exposes the SD-WAN control plane · Fastjson 1.x exploitation turns dependency discovery into an emergency · Fairlife confirms data theft while restoring US production · MCBS breach extends healthcare exposure through seven clients · Origin Energy says approximately 900,000 customers were affected
Clop turns Windchill exploitation into an extortion decision, not a patching exercise · Check Point exploitation makes management-plane verification a Monday priority · Compromised hotel Wi-Fi gateways create an MFA-satisfied path into Microsoft 365 · Recovered intrusion logs show an AI agent executing unattended post-exploitation tasks · GitHub and PyPI put time between a new package release and enterprise trust
Cl0p-linked extortion changes the Windchill response from patching to breach investigation · Exploited Check Point bypass puts firewall policy integrity in question · Laundry Bear’s Zimbra campaign turns a viewed email into mailbox persistence · Iran-linked actors are overriding PLC shutdown and alarm logic · Microsoft’s West US outage exposes hidden regional dependencies in security operations