Microsoft Entra ID gets passkeys default authentication starting September

2026-07-14T13:23:29Zb78c69e242673ae727e10e7a23326f9195640298b8cc2c519af983a08d7770fa
AppRouterCISACommerce CloudJoomlaMFA bypassMicrosoft Entra IDNetWeaverSAPcritical infrastructurecybersecuritydata breachexploitedinfostealermacOSmalwarenpm backdoorpasskeysphishingransomwareremote code executionrouterssanctionssupply chainvulnerabilities

What happened

Batch of BleepingComputer stories (July 12–14, 2026) covering multiple active threats and major security developments: Microsoft will make passkeys the default for Entra ID and is testing ad-free Windows Search; two new phishing kits (Jalisco, OmegaLord) bypass MFA to target Microsoft 365; SAP patched 16 vulnerabilities including three rated critical in NetWeaver, Commerce Cloud and AppRouter; CISA warns of actively exploited RCE via Joomla extensions (iCagenda, Balbooa Forms); supply-chain and infostealer incidents include a backdoored Jscrambler npm package and a new macOS stealer (CrashSte­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b78c69e242673ae727e10e7a23326f9195640298b8cc2c519af983a08d7770fa
Enrichment time
2026-07-14T13:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.