Daily Recap, phishing and account abuse dominated the news, with ConsentFix v3 abusing OAuth to hijack Azure tokens, Bluekit offering AI-assisted phishing templates, AccountDumpling compromising roughly 30,000 Facebook accounts via Google AppSheet, and Cordial Spider and Snarky Spider using vishing and SSO abuse to extort users inside Google Workspace, HubSpot, SharePoint, and Salesforce. Nation-state activity followed with a China-linked SHADOW-EARTH-053 cluster targeting Asian governments, a Poland NATO state, journalists, and activists using Exchange/IIS exploits and ShadowPad, plus GLITTER CARP and SEQUIN CARP phishing aimed at journalists and activists; the report also covers urgent cPanel patching, revised bug bounties, guidance on secure deployment of agentic AI, and notable breaches at Trellix and Instructure, as well as the ANTS data breach case. #ConsentFix #Azure #Bluekit #AccountDumpling #Facebook #Meta #AppSheet #CordialSpider #SnarkySpider #SHADOW_EARTH_053 #ShadowPad #GLITTERCARP #SEQUINCARP #cPanel #Trellix #Instructure #ANTS #ALPHV #BlackCat #ScatteredSpider #GUARDAct #WindowsRun