Cybersecurity intelligence

Know what changed.
Trace why it matters.

A daily, source-linked briefing for security practitioners. Every record carries its publication context, evidence links, and known limitations.

Get Security Weekly by email

Latest security briefing

Security Daily

Read latest edition
Latest signal

High-signal changes

View full briefing →
Security Daily

Cloud · Theregister Security

What happened

Microsoft reported that Storm-3168, associated with JadePuffer, compromised two service principals in one Azure tenant and used them for reconnaissance, resource destruction, and credential collection over about 18 hours. The reconnaissance phase completed more than 300 successful read operations across Azure virtual machines, subscriptions, resource groups, and other resources, providing broad visibility into the organization’s Azure environment.

Why it matters

Microsoft said the activity appeared to be preparation for ransomware: it combined resource destruction, attempts to interfere with recovery mechanisms, and credential collection that could enable access to data.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Identity · Certcc Vulnotes

What happened

Authlib versions up to and including 1.7.2 contain a JWS general JSON serialization signature-verification bypass in JsonWebSignature.deserialize_json(). The affected function accepts a JWS object with an empty signatures array and treats its payload as successfully verified, allowing arbitrary forged content without key material.

Why it matters

Systems relying on Authlib JWS verification for authentication, authorization, inter-service message integrity, or signed configuration may accept attacker-supplied content as legitimate.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Security Daily

Exploitation · Securityaffairs

What happened

Apple patched CoreGraphics zero-day CVE-2026-86950 after reporting possible exploitation in an extremely sophisticated attack against specific targeted individuals using iOS versions before iOS 27. The vulnerability is an out-of-bounds write that may enable arbitrary code execution when a specially crafted file is processed.

Why it matters

Apple has not disclosed the targets, number of affected people, exploitation timing, attack success, delivery method, technical attack details, or threat actors.

Known limitation: This item is supported by one source record and has not been independently corroborated here.
Curated context

Selected historical incidents

View library →

This is a curated historical collection, not a measure of global incident prevalence.

Build practical skill

Learn from the same evidence discipline

Open learning hub →
Trust through limits

Evidence is visible. Uncertainty stays visible too.

Baitaphish separates source records from interpretations, labels AI-assisted enrichment, and avoids turning ingestion volume into unsupported claims about threats, prevalence, or risk.

Read methodology and limitations →
Your Monday security briefing

BaitaPhish Security Weekly

Get the week's most important security developments by email, with links to the evidence and the narrated edition.

Monday mornings, when a new edition is published.

We’ll email you a link to confirm your subscription. Previously unsubscribed? Use this form to request a fresh confirmation link.

Explore Security Weekly