The Omada platform was found to be vulnerable in different ways, but TP-Link has already issued patches.
Operators of the Greatness PhaaS scam are targeting Microsoft 365 accounts by spoofing RingCentral.
Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages.
No passwords were stolen, and MFA never came into it; they walked away with access to mail, files, Teams, SharePoint, and calendars across around 120 organizations.
An increasingly expensive situation at a global scale
A new “invisible” Xeno Executor is actually a highly capable RAT and a potent infostealer.

Keeper is one of the best solutions to password storage and security, with up to 50% off across Personal, Family, and Business plans
Three Pass-ta-key techniques allowed security researchers to work around biometrics-protected locks.
Russian criminals are targeting hotel Wi-Fi networks with captive portals and using them to deploy infostealers.

Security researchers found a high-severity RCE flaw, which Apple later fixed.