npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in –
allowScripts defaults to off, meaning
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives.
The full ThreatsDay list is below.
Global
QIZ Security Raises $17 Million for Cryptographic Governance Platform
The Israeli company has developed a cryptographic posture and post-quantum cryptography management platform.
The post QIZ Security Raises $17 Million for Cryptographic Governance Platform appeared first on SecurityWeek.
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
Two announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK.
The post UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge appeared first on SecurityWeek.
The Hidden Security Risks of Reduced Summer IT Coverage
Palo Alto Networks Patches 13 Vulnerabilities
Buffer overflow, DoS, command injection, SSRF, authentication bypass, and other types of vulnerabilities have been found in PAN-OS software.
The post Palo Alto Networks Patches 13 Vulnerabilities appeared first on SecurityWeek.
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
That is the gap, and it is not your fault. The tools and runbooks most teams run on were built for attackers who work at human speed. AI-driven
12 Million Impacted by Data Breach at Japanese Telco KDDI
Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs.
The post 12 Million Impacted by Data Breach at Japanese Telco KDDI appeared first on SecurityWeek.
