Multiple weekly roundups and an industry report highlight a sustained shift toward AI-accelerated exploitation and third-party software as a primary entry point for cloud compromises. Google Cloud Security’s reporting (covering 2H 2025 observations) assesses that the time between public vulnerability disclosure and broad exploitation has compressed from weeks to days, with attackers increasingly focusing on unpatched third-party components rather than hyperscaler core infrastructure. The same reporting emphasizes that threat actors—including criminal groups and state-linked operators—are using automation and AI to probe targets and move faster, pushing organizations toward more automated, AI-augmented detection and response.
Separately, weekly security digests summarize a wide mix of developments rather than a single incident, including law-enforcement disruption activity against Tycoon 2FA (an adversary-in-the-middle phishing-as-a-service operation) and LeakBase infrastructure, plus broader themes such as dependency staleness, DevSecOps pipeline exposure, and the operational security gap created by increasingly autonomous AI agents. UK-focused highlights also include NCSC guidance urging organizations to review their cyber posture in light of Middle East conflict dynamics, alongside policy and standards updates (e.g., telecoms security/resilience principles and national cyber strategy items), reinforcing that geopolitical drivers and systemic software supply-chain weaknesses remain key risk multipliers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos' 2025 year-in-review said attackers were weaponizing newly disclosed flaws faster than ever, with the December-disclosed React2Shell bug becoming the firm's most-targeted vulnerability of the year. The report also said attackers increasingly targeted identity control points such as VPNs and application delivery controllers, while phishing remained the top initial access vector in 40% of Talos incident-response cases.
Flashpoint's 2026 Global Threat Intelligence Report said cybercriminals had increasingly automated end-to-end intrusion activity and that AI had shifted from an assistive tool to enabling infrastructure for scalable cybercrime. It also warned that exploitation timelines were compressing to hours and described emerging AI-workflow attack techniques and botnet-building activity.
ZDNET reported on a new Google Cloud Security report stating that AI is helping cybercriminals attack cloud environments faster, especially through third-party software weaknesses and developer-focused supply-chain paths. The report highlighted cases such as React2Shell and renewed exploitation of XWiki flaws, as well as North Korea-linked activity targeting developers and Kubernetes workloads.
Google's threat intelligence reporting said the Coruna iOS exploit kit had spread beyond a narrow set of operators and was being used across surveillance, espionage, and cybercrime actors. The finding showed broader adoption of a previously more specialized capability.
Law enforcement also took down LeakBase, a major forum used for stolen data and cybercrime tools. The action was reported alongside the Tycoon2FA disruption as a meaningful blow to criminal infrastructure.
Law enforcement dismantled the Tycoon2FA adversary-in-the-middle phishing infrastructure in a significant defensive action. Multiple roundups cited the disruption as one of the week's most notable cybercrime takedowns.
Cisco confirmed that vulnerabilities affecting Catalyst SD-WAN Manager were being exploited after patches had already been issued. The development was cited as an example of attackers quickly operationalizing known flaws.
Security reporting described an ongoing phishing campaign abusing OAuth redirection logic to deliver malware or steal credentials. The campaign was featured as a major current threat in the weekly review.
Reporting highlighted an unauthenticated remote code execution flaw in IceWarp, CVE-2025-14500, with more than 1,200 exposed servers reportedly still unpatched. The item underscored continued exposure from slow patch adoption.
A recent unauthenticated zero-click remote code execution flaw in FreeScout, tracked as CVE-2026-28289, was highlighted in the weekly roundup. The issue was presented as one of the notable vulnerability disclosures of the week.
Zenity Labs reported the 'PleaseFix' vulnerabilities affecting agentic browsers, including Perplexity Comet, as part of growing concern over autonomous AI agents creating new security and fraud risks. The flaws were highlighted in a weekly security roundup as a notable recent disclosure.
Flashpoint said stolen credentials remained the dominant initial access vector and that Vidar 2.0 had become the most prevalent infostealer by January 2026. This reflected the continued flooding of criminal markets with credentials harvested by infostealer malware.
Flashpoint reported that cybercriminal discussions about AI-enabled abuse, including deepfakes, jailbreak prompts, phishing lure generation, and malware development, rose sharply during 2025 and peaked in December. The firm characterized 2025 as a year when AI increasingly enabled scalable cybercrime operations.
Google Cloud Security's report on the second half of 2025 found attackers increasingly compromising organizations through unpatched third-party software, software supply-chain paths, and identity abuse rather than hyperscaler core infrastructure. The report also noted AI was shrinking the gap between disclosure and mass exploitation from weeks to days.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcezdnet.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.