Malware
“CrashStealer” macOS Malware Reportedly Uses a Notarized Dropper to Pass Gatekeeper
A macOS notarization-abuse malware disclosure — defender review for Mac-issuing organizations this week.
Malware
A macOS notarization-abuse malware disclosure — defender review for Mac-issuing organizations this week.
Phishing
A new named PhaaS platform targeting Microsoft 365 — defender teams review posture and OAuth-hygiene this week.
Artificial Intelligence (AI)
Another AI-agent supply-chain finding — defender posture review for organizations deploying memory-enabled agents this week.
Cybercrime
Another Ryuk-operator plea lands — the ransomware-operator prosecution pattern continues this week.
Policy & Government
An Australian government advisory on CMS exploitation — defender review across managed content platforms this week.
Vulnerabilities
The Progress ShareFile emergency continues — defender teams stay in verification posture this week.
Nation-State Cyber Threats
A formal EU/UK attribution against Russia's Turla for a Polish power-grid attack — critical-infrastructure defender posture stays elevated this week.
Nation-State Cyber Threats
A multilateral cybersecurity advisory on Russian router-targeting activity lands on critical-infrastructure defender teams' desks — the guidance reissues warnings the same agencies have made before, and asks operators to review posture this week.
Data Breaches
A consulting-and-IT-services sector signal: Accenture has confirmed an intrusion after a threat actor advertised stolen source code and cloud credentials for sale, calling it an isolated, remediated matter even as the scale and any client impact remain unverified.
Cybercrime
Another individual-conviction milestone against a ransomware operation — law-enforcement coverage this week.
Vulnerabilities
A critical Zimbra webmail advisory — defender teams accelerate patch verification this week.
Supply Chain Attack
A GitHub-organization reconnaissance campaign — defender posture and account-hygiene review this week.