Security gains from passkey adoption in central IT are negated by uncontrolled shadow IT using weak passwords, presenting organizational challenges for CISOs.
Chinese threat actors remained undetected in Microsoft 365 tenants for 18 months, exploiting a Managed Service Provider as a base for supply chain attack scenarios.
Over 400 Arch Linux AUR packages were compromised with infostealer malware, posing a data exfiltration risk to all systems that installed these packages on or after June 11, 2026.
A China-linked hacker group infiltrated fundamental Linux authentication systems PAM and OpenSSH over many years, evading conventional detection methods.
A China-linked hacker group operated undetected for nearly a decade through backdoors in Linux authentication components where standardized security tools do not look.