Lidl and EY both disclosed third-party support and service-provider data breaches
Lidl notified customers in Germany, Belgium, and the Netherlands that a breach at an external IT service provider exposed customer data stored in a separate file. The retailer said
Google and Microsoft move decisively toward passkeys and stronger sign-in defaults
Microsoft announced major changes to Entra ID that make passkeys the default authentication experience in the public cloud, with SMS and voice gradually being phased down. The comp
A rash of CMS and Joomla flaws is being actively exploited for webshell and file-upload attacks
Australia's Signals Directorate warned that attackers are mounting a broad campaign against content management systems, including WordPress and Joomla, by exploiting known fla
CISA pushes vendors toward more disciplined coordinated vulnerability disclosure
CISA and allied agencies published new coordinated vulnerability disclosure guidance aimed at helping vendors handle reports more consistently. The guidance arrived shortly after C
ClickFix becomes a scalable social-engineering platform for malware delivery
ClickFix moved from a novelty to a widely used attack pattern that tricks users into running commands themselves, bypassing many endpoint defenses. Researchers said the technique n
CrashStealer malware abuses signed apps and fake crash-reporting prompts on macOS
CrashStealer is a new macOS infostealer that disguises itself as Apple's crash-reporting tool and uses signed or notarized components to get past Gatekeeper checks. The malwar
Microsoft and security vendors rush to address AI-era attack surfaces
A broad set of vendors and researchers focused this week on how AI changes security operations, from agentic defense to prompt injection and AI-powered attacks. Microsoft, Google,
AI-assisted intrusions in government networks show how frontier models are changing cyber espionage
Researchers found an active Chinese intrusion campaign that used Claude Code and DeepSeek to automate parts of espionage operations against government systems and financial firms.
AsyncAPI npm supply-chain compromise spreads malware through trusted packages
Attackers compromised the AsyncAPI npm organization and injected malicious code into multiple widely used packages, including generator and specs packages with more than two millio
Scattered Spider members are sentenced for the Transport for London attack
Two teenage members of the Scattered Spider cybercrime group were sentenced in the UK to five years and six months in prison each for the 2024 cyberattack on Transport for London.

