Weekly threat intelligence roundup covering major attacks and breaches including a $3M supply chain attack on Polymarket via malicious JavaScript injection, a KDDI breach exposing 14.22 million email accounts, and a 630GB data theft from Tata Electronics. AI threats include EvilTokens phishing-as-a-service with a 1,380% surge in device-code phishing, a fake AI skill hijacking 26,000 agents, and the BioShocking AI technique bypassing agentic browser guardrails. Key vulnerabilities patched include a Cisco Catalyst SD-WAN zero-day, four Dify AI platform flaws, and three actively exploited Ubiquiti UniFi OS bugs linked to Mirai botnet activity. Threat intelligence highlights include the FortiBleed campaign stealing 110 million credentials from 430,000 FortiGate devices, Russia-linked Turla's StockStay malware targeting Ukraine, and a Chinese DCloud framework powering over 236,000 scam domains.