TP-Link Kasa camera flaws expose admin credentials and device location on local networks
Researchers identified flaws in the TP-Link Kasa EC70 and EC71 camera models that let an attacker already on the same local network steal administrator credentials and infer the ca
SharkNinja cloud flaw could let attackers remotely control millions of Shark robot vacuums
A security researcher found a critical flaw in SharkNinja's cloud-connected robot vacuum ecosystem that could allow remote code execution on affected devices. The issue affect
RoguePlanet, GigaWiper, and other destructive Windows malware show the continued rise of high-impact endpoint abuse
The feed includes several destructive or quasi-destructive Windows malware stories, from backdoors that bundle wipers and ransomware capabilities to driver-based defenses blinding
Email security is shifting from static filters to identity, context, and human verification
Email remains the workhorse attack vector, but the feed shows that traditional filtering is being outpaced by social engineering and AI-enhanced lures. Attackers are using homoglyp
Microsoft 365, Entra ID, and OAuth abuse remain a top initial-access channel
Identity abuse is one of the clearest operational threats in the feed, especially around Microsoft 365 and Entra ID. Attackers are using fake passkey enrollment, device-code flow a
Ransomware and extortion operations continue to target organizations worldwide
Ransomware leak sites and reporting showed continued activity from groups such as Qilin, DragonForce, Akira, Play, Incransom, and others against companies, schools, hospitals, and
Credential theft, phishing, and fake downloads remain the main path to compromise
Attackers continued to rely on phishing, fake installers, and stolen credentials as their most reliable access methods. Reports covered trojanized Webex, Zoom, and MobaXterm instal
CrowdStrike, Microsoft, and others are using AI to reframe vulnerability discovery and remediation
A series of vendor posts and interviews emphasized that frontier AI models are now finding vulnerabilities faster than traditional review and fuzzing in some contexts. Chainguard d
Passwordless identity and MFA changes are reshaping enterprise access management
Vendors are steadily shifting away from SMS and older second factors toward passkeys and hardware-backed authentication. Microsoft announced passkeys as the default sign-in experie
Security teams are racing to manage AI, MCP, and coding-agent risk in software development
A growing body of discussion centered on how AI coding agents, MCP servers, and agent histories create new software-security exposures. Researchers and practitioners warned that AI

