ReliaQuest Thwarts Intrusion & AI-Generated Siemens Exploits – Weekly News Roundup

Here is the most recent Cybersecurity news for the past week:

🛡️ReliaQuest Thwarts ShinyHunters Social Engineering Intrusion
ReliaQuest disclosed a targeted social engineering attack that temporarily exposed a single employee identity session. The attacker gained limited visibility into an identity dashboard, but the activity was contained before company applications, backend systems, or customer data were accessed.

https://cybermagazine.com/news/how-reliaquest-stopped-a-shinyhunters-breach

🤖CISA and FBI Warn of AI-Generated Exploits Targeting Siemens Industrial Systems
U.S. cybersecurity agencies warned critical infrastructure operators that attackers are using AI-generated exploitation scripts against exposed Siemens S7 programmable logic controllers. The activity demonstrates how AI can reduce the time and expertise required to develop attacks against operational technology.

https://www.securityweek.com/hackers-using-ai-to-target-siemens-plcs-in-critical-us-sectors/

🔑Microsoft Discloses Critical Entra ID Vulnerability
Microsoft disclosed CVE-2026-69836, a maximum-severity remote code execution vulnerability in Entra ID caused by unsafe deserialization. Microsoft says the cloud-hosted vulnerability has been mitigated and subsequently clarified that it was not exploited in the wild.

https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/

☁️Threat Actor Claims 3.6 Million Azure Employee Records Stolen from Major Corporations
A threat actor using the name “TheHatman” claimed to have stolen millions of employee records from Azure environments associated with several major companies after obtaining initial access through compromised credentials.

https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/

💳SafePal Crypto Wallet Discloses Order Tracking Breach Affecting 40,000 Users
SafePal disclosed an authorization flaw in an order-tracking plugin that exposed names, shipping addresses, email addresses, and phone numbers belonging to nearly 40,000 customers. The company said wallet private keys, seed phrases, and financial credentials were not affected.

https://www.securityweek.com/40000-impacted-by-safepal-data-breach/

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

newsletter signup

Our goal? To deliver the best cybersecurity insights you can read in five minutes or less — straight to your inbox, once a week.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.