At least 17 fake payment SDKs on npm and PyPI steal development-related access credentials such as API keys and AWS login data through disguised packages that imitate legitimate application programming interfaces.
Passkeys will become the default authentication method in Microsoft Entra ID starting September 2026, representing a fundamental realignment of enterprise identity security.
Attackers increasingly bypass detection systems through abuse of legitimate systems and AI-powered malware generation rather than deploying traditional malware.
Ransomware attacks increased by 236 percent in 2025, with new actors like Qilin and Akira taking the lead, and Germany among the most affected countries worldwide with 433 cases.
Microsoft Purview alone does not protect against all data security risks in fragmented SaaS environments, while more comprehensive specialized solutions are often economically unaffordable for mid-market companies.
Grok Build uploads complete Git repositories with full history to xAI despite instructions to process only specific files, exposing developer secrets and confidential metadata.
Microsoft enforces migration from SMS/voice MFA to Passkeys in Entra ID with hard block starting February 1, 2027, shifting costs to paid third-party providers for organizations with compliance requirements.