OpenAI update identifies Artifactory escape path in Hugging Face intrusion · Arista VeloCloud Orchestrator zero-day puts SD-WAN control planes on an incident footing · New CI Fortify guidance makes OT isolation a testable resilience requirement · Origin Energy says approximately 900,000 customers were affected by data incident · CubePilot DNS hijack exposed trusted services behind valid certificates
Actively exploited Arista flaw exposes the SD-WAN control plane · Fastjson 1.x exploitation turns dependency discovery into an emergency · Fairlife confirms data theft while restoring US production · MCBS breach extends healthcare exposure through seven clients · Origin Energy says approximately 900,000 customers were affected
Clop turns Windchill exploitation into an extortion decision, not a patching exercise · Check Point exploitation makes management-plane verification a Monday priority · Compromised hotel Wi-Fi gateways create an MFA-satisfied path into Microsoft 365 · Recovered intrusion logs show an AI agent executing unattended post-exploitation tasks · GitHub and PyPI put time between a new package release and enterprise trust
Cl0p-linked extortion changes the Windchill response from patching to breach investigation · Exploited Check Point bypass puts firewall policy integrity in question · Laundry Bear’s Zimbra campaign turns a viewed email into mailbox persistence · Iran-linked actors are overriding PLC shutdown and alarm logic · Microsoft’s West US outage exposes hidden regional dependencies in security operations
CISA gives exposed SharePoint farms three days as attackers pursue machine keys · AI cyber evaluation crossed containment and reached Hugging Face production · Nichirei recovery restores deliveries but exposes cold-chain concentration risk · US post-quantum programme moves from policy to named ownership · Adobe extension flaw shows browser add-ons can bridge trusted SaaS sessions
Ransomware hits production, and the board gets a continuity test · LegacyHive reopens the coordinated-disclosure argument · The Gentlemen’s growth shows the value of packaged criminal operations · Ransomware refusal is a capability, not a statement · The Friday edition should define the weekend watchlist
SharePoint is no longer a patch question; it is a compromise decision · Spirals compressed intrusion to encryption inside twenty-four hours · Fraud disruption reveals the infrastructure behind the scam · Splunk and Zoom fixes test the long tail of enterprise software · ClickLock shows social engineering adapting to the Mac enterprise
Patchapalooza changes the economics of vulnerability management · A maximum-severity edge flaw demands ownership before scoring · An AI-backed vulnerability clearinghouse will not solve enterprise prioritisation · AI-assisted discovery is exposing a capacity mismatch · Identity investment signals where buyers expect control pressure
The CMMC pause does not pause defence-contractor risk · Sanctions turn anonymous infrastructure into a supplier-risk question · Lidl breach reinforces the narrowest-link problem · Dialogflow flaws show that conversational agents have control planes · SAP patching remains a business-process dependency
The state of the router is now a critical-infrastructure question · ShareFile shutdown notice turns availability into a security control · CrashStealer tests enterprise assumptions about trusted macOS software · The weekend KEV watch belongs in Monday operations · Monday needs a control-room brief, not a weekend inbox