🚨 ACTIVE EXPLOITS & INCIDENTS
- Accenture Confirms Data Breach After Hacker Claims Source Code Theft — SecurityWeek Accenture confirms a data breach involving theft of source code and encryption keys. The company states the incident is contained with no operational impact, but the breach poses significant risk to client confidentiality and IP security.
- Hackers Exploit Roundcube Flaw to Spy on Academic Researchers — BleepingComputer A China-linked threat actor is actively exploiting a critical Roundcube vulnerability at U.S. and Canadian universities to steal credentials and deploy backdoors. This ongoing campaign targets academic institutions for espionage.
- Entra Passkey Enrollment Vishing Targets Microsoft 365 Users — BleepingComputer Voice phishing campaigns impersonate security teams to trick Microsoft 365 users into enrolling malicious Entra passkeys, potentially enabling account takeover. Multi-sector organizations should alert users and review MFA enrollment policies.
🔓 VULNERABILITIES & CVEs
- VU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls — CERT/CC CVE-2026-10706: Adalo’s no-code platform API flaw allows authenticated users to extract full user records across all applications on the platform, affecting over 1 million apps. No tenant isolation means widespread data exposure risk with no current remediation.
- Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS — The Hacker News Multiple critical vulnerabilities including CVE-2026-50746 (CVSS 10.0) allow privilege escalation and arbitrary command execution across UniFi product lines. Immediate patching is strongly advised to prevent exploitation.
🕵️ THREAT RESEARCH & DEEP DIVES
- China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors — SecurityWeek Cisco reports the LapDogs APT group has added LongLeash, DogLeash, and JarLeash backdoors targeting SOHO routers, expanding their persistent access toolkit. Network defenders should monitor for these new implants in router environments.
- New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware — The Hacker News Researchers reveal “HalluSquatting,” an attack exploiting AI coding assistants’ tendency to hallucinate fake package names. Attackers pre-register these names to deliver malware when AI tools fetch dependencies, posing a novel supply chain risk for developers.
- AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers — The Hacker News Sophos analysis shows AI coding assistants (Claude Code, Cursor, OpenAI Codex) unintentionally trigger endpoint detection rules designed for human attackers due to their behavior (e.g., credential store access). Security teams should tune detection to reduce false positives.
- Designing for the Inevitable: System Prompt Leakage and Mitigations in Generative AI Applications — AWS Security Blog Technical deep dive on risks of system prompt leakage in generative AI apps, which can expose proprietary instructions and operational context. Discusses mitigation strategies to protect sensitive prompt data from unauthorized access or exfiltration.
📋 VENDOR BULLETINS & ADVISORIES
- Protecting Microsoft at AI Speed: How SFI Proactively Hardens Our Cloud — Microsoft Security Blog Microsoft details its Secure Future Initiative (SFI) to continuously evaluate and harden cloud services against evolving threats at AI speed, integrating threat intelligence and operational frameworks for proactive defense.
- The CISO’s Guide to Post-Quantum Mandates and Migrations — AWS Security Blog Guidance for CISOs on navigating post-quantum cryptography adoption mandates from over a dozen major economies. Highlights the organizational challenges beyond algorithm swaps, emphasizing coordinated change management.
📰 LESSER-KNOWN / UNDER-REPORTED
- Fake Paysafe, Skrill SDKs on NPM and PyPi Steal Credentials — BleepingComputer Malicious SDK packages impersonating Paysafe, Skrill, and Neteller on npm and PyPI are actively stealing developer and user credentials. DevSecOps teams should audit dependencies and block these packages immediately.
- HPC AI Workloads Need Runtime Security. The Architecture Already Exists. — Sentinel One Blog Analysis on securing HPC AI infrastructure against runtime and supply chain threats via continuous behavioral monitoring, highlighting existing architectural approaches to protect high-performance AI workloads.
- US Enterprises Incorporate Cyber Risk Into Larger Strategic Focus — Cybersecurity Dive Report on how rapid AI and cloud adoption is driving US enterprises to integrate cyber risk into broader business resilience and financial impact strategies, signaling a shift in security governance priorities.