What’s New

Headline: Microsoft Is Making Passkeys the Default Login Method … Passwords Are Losing Their Grip

News:

Microsoft just gave passwords another nudge toward the exit. Starting September 1, 2026, the company begins rolling out passkeys as the default sign-in method across Microsoft Entra ID, its identity platform used by millions of organizations. Users currently relying on SMS or voice codes will be gradually shifted toward passkey registration instead. This isn’t happening in isolation. The FIDO Alliance recently reported that passkeys have crossed 5 billion in active use worldwide, with 90 percent of consumers now aware of them and roughly half using them regularly when offered. Why should you care? Passkeys use your device’s fingerprint, face scan, or PIN instead of a typed password, which means there’s nothing for a hacker to steal through phishing. If your workplace uses Microsoft accounts, expect a passkey prompt sooner than you think.
Related Guide: Passkeys vs Passwords: Which Is More Secure?

CISA Confirms Active Exploitation of Langflow, Tomcat, and N-central Flaws

News:

The Cybersecurity and Infrastructure Security Agency added three vulnerabilities to its Known Exploited Vulnerabilities catalog today, confirming they’re being actively used in real attacks right now.The most severe is a code injection flaw in Langflow, an AI development platform, scoring a near-maximum 9.8 out of 10 on the severity scale. It lets attackers take full remote control of unpatched systems without even logging in. The other two affect Apache Tomcat, a widely used web server, and N-able N-central, IT management software used by businesses to remotely monitor computers.CISA’s catalog exists precisely for moments like this. When a flaw lands on it, federal agencies must patch immediately, and everyone else gets a clear signal too. If your organization runs any of these tools, this isn’t something to leave for next week’s IT queue. For regular users, it’s a reminder that even well-known software has active attackers waiting for the moment you skip an update.
Related Guide: What Is Cybersecurity?

Claude Code’s Auto Mode Becomes Default Starting August 14

News:


Anthropic announced this week that Auto Mode will become the default setting in Claude Code starting August 14, for Pro, Max, and Team plan users. Instead of approving every command by hand, sessions will run through a classifier that only pauses for actions it flags as irreversible, destructive, or outside your project environment.Why the switch? Anthropic’s internal testing with 1,053 paid users found that auto mode caught 89% of dangerous commands, while manual human reviewers caught only about 13.6%, largely because people tend to click “approve” out of habit. Anthropic is also dropping the extra token charge tied to running the classifier. BigGo Finance If you’ve already set a custom permission mode, nothing changes automatically—you may just get a one-time prompt asking if you’d like to switch. For everyday users, this means faster, less interrupted coding sessions, though Anthropic still recommends human oversight for anything touching production systems.
Related Guide: What Is Claude AI? A Complete Beginner’s Guide to Anthropic’s AI Assistant

Scroll to Top