The report shows that even phishing-resistant passkeys can be bypassed through social engineering and abused email delivery infrastructure to take over Microsoft cloud accounts.
Bundling several already-patched zero-days into a circulating exploit kit lets even less skilled espionage-motivated actors exploit them, making the window between patch availability and patch deployment the decisive risk factor.
The report provides a quarterly overview of the threat landscape for industrial automation systems and documents new APT malware attributed to Mirage Kitten, which is strategically relevant for production environments.
The vulnerability requires user interaction and affects widely used compression software installed in many corporate environments; a CVE ID is not yet available.