Skip to Content

Security News Update: How Are Passkey Phishing and GenAI Feature Risks Reshaping Enterprise Security? and more

Rhysida Leaks 1.4 Million Berlin Government Files

Berlin refused Rhysida’s ransom demand, prompting the group to publish nearly 1.4 million stolen government files.

This leaked data reportedly includes employee records, identity documents, and potentially sensitive emergency-planning material.

Not paying the ransom often gets the most attention, but security teams also need a plan for stolen data that becomes public and cannot be recovered.

Monitor for abnormal outbound data transfers and restrict compromised accounts from reaching sensitive repositories beyond what their roles require.

CISA Flags Exploited GitLab Flaw

CISA says attackers are exploiting CVE-2026-85706, a critical GitLab flaw that exposes sensitive files without authentication.

Exposed credentials, tokens, and CI/CD secrets could then provide access to source code and downstream development environments.

This vulnerability carries a CVSS score of 10.0, and attackers probing within a day of the patch release shows just how quickly the remediation window can close.

Patch self-managed GitLab instances, restrict internet exposure, and review logs for signs of exploitation.

Anthropic Uncovers Biological Research Using Claude

Anthropic says scientists used Claude for research with potential bioweapons applications, with some reportedly bypassing safeguards or concealing their activity.

The cases highlight how difficult AI misuse can be to detect when legitimate and potentially dangerous biological research may look similar in individual prompts.

I think the bigger security issue comes after a model refuses a request. If blocked prompts are simply rerouted to a provider with weaker safeguards, those controls become little more than a speed bump.

Monitor repeated AI refusals, unusual account routing, and attempts to switch models after sensitive requests are blocked.

LG Rejects Smart TV Eavesdropping Claims

Researchers claim some LG smart TVs capture audio while idle and collect data about other networked devices, findings that LG disputes.

The debate highlights a broader concern with smart TVs that combine microphones and network access and may remain in use long after security updates end.

I would treat a smart TV like any other IoT device rather than assuming it becomes inactive when the screen turns off.

Disable unused voice and content-recognition features, keep TV firmware updated, and place smart TVs on a separate IoT network when possible.

AI, Insider Risk Reshape CISO Security Plans

Proofpoint found that 78% of CISOs view GenAI as a security risk, while 79% consider human risk their biggest cyber vulnerability.

Those risks are converging as AI becomes embedded in everyday workflows that involve sensitive corporate data.

You can block a standalone AI tool, but that control becomes harder to enforce when AI is built directly into applications employees already use. The focus has to shift toward governing what data those AI features can access and what actions they can perform.

Map which AI tools can access sensitive data, then enforce least-privilege permissions and monitor how that data moves between users, applications, and AI services.

Passkey Phishing Hijacks Microsoft 365 Accounts

Scammers aren’t hacking passkeys; they’re weaponizing the idea of them to breach Microsoft 365 environments.

Fake IT staff call personal phones or use hijacked Teams accounts to steer employees to lookalike sign-in pages or legitimate device-code flows, hustling targets into handing over session tokens or unwittingly authorizing rogue devices via real Microsoft portals.

Once inside, intruders add their own MFA factors, map the tenant through Microsoft Graph, and siphon off SharePoint, OneDrive, and Exchange data. To stay under the radar, they throttle their theft to under 1,000 files or emails per hour.

Verify urgent authentication requests through a separate channel. Defenders should flag unusual MFA registrations, unmanaged-device sign-ins, and suspicious Graph probing. Boot the attackers by severing active sessions and tokens, nuking rogue methods, forcing credential resets, and mandating true phishing-resistant MFA and Conditional Access.

Passkeys passed the test. Surprise IT emergencies did not.

Revolut Falls for Fake Government Data Request

Digital bank Revolut unwittingly handed over sensitive records to a scammer who filed bogus information requests from a genuine government email domain. The fintech says a “limited” number of customers were affected, but it hasn’t provided a count or named the agency.

Exposed data may include passports, driver’s licenses, verification selfies, IBANs, and complete transaction histories, including Bitcoin activity. In short: what one expert called “a complete identity theft kit.” Revolut says its systems and users’ funds were uncompromised, though reports that attackers are leaking high-net-worth records and demanding a 10,000-BTC ransom remain unconfirmed.

If notified, monitor accounts, enable MFA, consider a fraud alert, and contact Revolut only through its app.