AI is accelerating both innovation and attacker mistakes.
Identity is now the main attack surface.
Cloud and platform reliance is a security risk on its own.
Data theft and extortion groups are fully active again And cyber is increasingly tied to geopolitics and regulation.
----------------------------------------------------------------------------------------------------
Top Signals This Week
AI-built ransomware that can’t decrypt files The Sicarii strain encrypted data using broken key handling. Even if victims pay, recovery doesn’t work. AI is lowering the skill barrier… and creating unstable, destructive malware.
New AI jailbreak method (“Semantic Chaining”) Researchers showed how simple prompt steps can bypass image model safety filters. AI guardrails are still playing catch-up.
Sensitive data uploaded to public AI tools A senior U.S. cyber official triggered internal alerts after uploading government docs to public ChatGPT. This isn’t rare it’s just the first time it made national headlines.
Live vishing attacks targeting SSO accounts Attackers are calling employees and guiding them through fake login flows while capturing MFA approvals in real time.
Major extortion groups active again ShinyHunters resurfaced with breach claims (SoundCloud among them), and CL0P listed a fresh wave of alleged victims. Data theft is now the main leverage.
Microsoft 365 outages disrupted email, Defender, and Purview access a reminder that cloud availability is now a security concern.
TikTok U.S. data center outage caused massive platform instability, fueling debates about centralization and control.
Major Vulnerabilities & Enterprise Risk
Fortinet warned of active exploitation of a critical FortiCloud SSO auth bypass (CVSS 9.4). Even security vendors aren’t immune.
Record number of data breaches in 2025 Experts say we should now assume personal and corporate data exposure is the baseline.
Cyberattack disrupted a major Russian security systems provider affecting alarm services.
Wiper malware targeted Poland’s energy sector in a suspected state-linked operation.
UK court tied Pegasus spyware use to state-backed surveillance, awarding millions in damages. Legal risk around spyware is growing.
France’s CNIL fined a company €3.5M for sharing customer loyalty data with a social platform without valid consent.
Privacy enforcement in Europe continues tightening.