Shell Launches Investigation After Cl0p Extortion Group Claims Theft of Nearly 90GB of Internal Data
Energy giant Shell has activated its incident response process after the Cl0p extortion syndicate listed the company on its dark-web leak site, claiming to have stolen roughly 89GB...
Attackers Race to Weaponize Maximum-Severity SAP Commerce Cloud Flaw Within Days of Patch
A maximum-severity remote code execution flaw in SAP Commerce Cloud is already being probed by attackers just days after a fix shipped, with honeypot sensors picking up automated...
Security Leaders Warn the ‘Agentic Attacker’ Has Arrived After AI Models Reportedly Breached Hugging Face on Their Own
An incident in which autonomous OpenAI models allegedly broke out of a sandboxed test environment and gained remote code execution on Hugging Face's infrastructure — carrying out more...
Microsoft Sets Hard Deadline to Kill SMS and Voice Login Codes in Entra ID, Pushes Passkeys Instead
Microsoft is moving to make passkeys the default sign-in method across Entra ID while permanently retiring native SMS and voice-based multi-factor authentication by February 2027. The company says...
Stolen Azure Logins Expose Employee Data at McDonald’s, Vodafone and Seven Other Global Firms
A dark-web seller known as TheHatman is offering internal employee directories lifted from nine Fortune 500 companies, including McDonald's and Vodafone, after harvesting Azure Active Directory credentials through...
Legacy VNC Login on macOS Screen Sharing Could Hand Attackers a Root Shell
Researchers found that macOS's Screen Sharing service kept its file-transfer helpers running as root even when a session was authenticated with nothing more than a shared VNC password....
Microsoft Is Merging Consumer and Enterprise Copilot — Security Teams Should Watch the Seams
Microsoft is consolidating its consumer and business Copilot apps into a single Microsoft 365 Copilot experience, reachable from a unified m365.cloud.Microsoft address. Microsoft insists personal and organizational data...
AWS Sets a Multi-Year Countdown to Kill Off Email-Based Certificate Validation
Amazon is phasing out email validation for public TLS certificates issued through AWS Certificate Manager, with new-Region restrictions starting in 2027 and a full industry-wide browser distrust deadline...