Generative AI is fueling a rise in low-effort, high-volume email attacks, making phishing campaigns easier to launch than ever. PDF, Archive, and HTML files dominated as the preferred payload carriers. Meanwhile, DocuSign, DHL, and PayPal remained the top targets for brand impersonation scams.
TD Bank faced a data breach from an ex-employee, while the Medusa group attacked HCRG Care Group without disrupting services. Microsoft patched major flaws, including a critical Outlook bug, and Apple removed iCloud’s Advanced Data Protection in the UK under government pressure.
The U.S. Cyber Safety Review Board (CSRB) has been shut down. Leadership changes at CISA and more shifts likely. China’s DeepSeek LLM is gaining traction despite ongoing privacy and security concerns.