Identity is the control plane, and the control plane is an API. Files here follow permission paths rather than perimeters: what a role could do, what it did, and which log would have shown you.
Researchers published the second stage of a chain that turns a VoLTE video call into full Android kernel access on three Unisoc chipsets. The modem and application processor share memory with no hardware boundary, and the vendor has not answered.
A CVSS 10.0 flaw in a reporting tool that stores the credentials for every warehouse behind it.
361 hosts in 47 countries, and 95% of them taken inside two days of the first exploitation.
About 75% of insider incidents involve nobody acting maliciously. Programmes built to detect grievance address a quarter of the problem.
Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.
Execution moved from install to import. The flag everyone added after the last campaign is still set, and no longer covers anything.
Rotating the stolen key is the fix. It is also what erases the proof anyone used it.
Hidden native binaries executing at install, in a trusted package name. Compiled code is opaque to the review most registries actually perform.
A name concatenated from three crews. Attribution language implies a roster, and a coalition brand quietly breaks that implication.
24 billion credential records from 36 sources in one indexed store. The thefts were old; the index is what makes them usable.
A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.
A missing authentication check on a table query endpoint. One defect, and a different blast radius inside every tenant.
A phone call, a consent screen, and a refresh token that outlives every password change. No exploit is involved at any step.
A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.
1.4 million addresses, and instructor payout methods. A card can be reissued; a bank account configured to receive money cannot.
Four different things drive the 263%, and only one is bad news. The count measures workload, not software quality.
Install-time credential theft that republishes itself using the rights it steals. Around 1,948 repositories were tied to exfiltration activity.
AI-referencing complaints are ~4% of reported losses. The other 96% is the story — and the AI share is undercounted by construction.
Exploitation is arriving before organisations can deploy. Patching in twenty days is worth less than surviving a compromised appliance.
No intrusion, no misconfiguration — a functioning business selling movement traces. From the traced person’s position the distinction is thin.
More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.