The intelligence feedUpdated as material events develop
Analysis / Research / Guidance

The Briefing

Independent reporting on AI security, exploited vulnerabilities, and enterprise cyber risk. Built to help defenders understand what changed and what deserves action.

Latest intelligence

Current coverage

Browse the full archive
Klue OAuth breach illustration showing a compromised Salesforce integration, stolen CRM records, and an extortion path through trusted SaaS access

Klue OAuth Breach: Why Salesforce Integrations Are Becoming a CRM Extortion Path

The Klue OAuth breach became a same-day enterprise security warning on June 18, 2026, when fresh reporting tied a compromised Salesforce-connected integration to live CRM data theft and extortion. The bigger lesson is not just that one vendor was breached. It is that trusted SaaS integrations can quietly become the shortest route into customer records, pricing data, and deal intelligence.

Read intelligence ↗
FortiBleed Fortinet VPN credentials leak illustration showing exposed enterprise firewall gateways, credential records, and a global remote access attack path

FortiBleed Fortinet VPN Credentials Leak: Why 73,000 Exposed Devices Turn Perimeter Trust Into an Identity Crisis

The FortiBleed Fortinet VPN credentials leak became a same-day enterprise security warning on June 17, 2026, when fresh reporting tied a live exposure to tens of thousands of Fortinet and FortiGate access points worldwide. The bigger lesson is not just that passwords leaked. It is that perimeter appliances, stale credentials, and quiet login validation can turn trusted remote access into an identity crisis faster than many teams are prepared for.

Read intelligence ↗
DragonForce Microsoft Teams relay malware concept showing trusted Teams traffic masking covert ransomware command-and-control activity

DragonForce Microsoft Teams Relay Malware: Why Trusted Collaboration Traffic Is Now a Ransomware Blind Spot

DragonForce Microsoft Teams relay malware is the first known real-world case of ransomware operators hiding command-and-control traffic inside trusted Microsoft Teams relay infrastructure. The June 16, 2026 disclosure matters because it shows how normal collaboration traffic can now mask persistence, post-encryption access, and longer dwell time inside enterprise networks.

Read intelligence ↗
Microsoft 365 Copilot data theft concept showing a trusted Microsoft search window, an exposed mailbox and SharePoint data stream, and a covert outbound exfiltration path

Microsoft 365 Copilot Data Theft: Why SearchLeak Changes the Enterprise AI Threat Model

Microsoft 365 Copilot data theft moved from theory back into urgent practice on June 15, 2026, when fresh reporting detailed how the SearchLeak attack chain could turn a trusted Microsoft link into a one-click path for mailbox, OneDrive, and SharePoint exfiltration. For enterprise defenders, the lesson is bigger than one patched bug: retrieval plus prompt injection plus legacy web flaws can still collapse the boundary between helpful AI and silent data loss.

Read intelligence ↗

Showing 109-117 of 262 articles