GitLab’s Claude Agent Read User-Controlled Configuration. Developer Access Reached Arbitrary CI Commands.

GitLab patched a Duo Claude flaw that let a Developer turn user-controlled configuration into arbitrary commands inside a CI job.

GitLab patched a Duo Claude flaw that let a Developer turn user-controlled configuration into arbitrary commands inside a CI job.

McKesson confirmed unauthorised access to third-party applications and data exfiltration. ShinyHunters claims 284 million patient-related data rows, but the scale and data types remain unverified.

ReliaQuest says a stolen password and approved MFA push produced a valid session, but device trust blocked every attempt to reach company applications.

A public proof of concept for CVE-2026-19490 is now drawing exploit-matching traffic. The evidence shows active targeting, not confirmed compromise.

Alleged Entra directory theft exposed organisational maps rather than passwords. Treat bulk directory reads as a high-impact identity event.

SynkLoader used a fake Teams help desk, an Azure-hosted installer, a counterfeit Windows lock screen and an internal proxy to turn one user action into hands-on-keyboard corporate access.

France’s Education Ministry is testing whether a breach first described as staff-only reached student records across a fragmented national data estate.

US prosecutors allege Mabna Institute hackers served Iranian state clients while selling stolen research and university access through commercial sites.

A password-reset email is meant to be the point where an identity system proves that the person changing a credential controls the account. A critical Keycloak flaw allowed an unauthenticated attacker to bypass that step and set a new password…

Microsoft will retire its Entra SMS and voice authentication service in February 2027, making passkey migration and exception governance urgent.