Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary CVE-2025-39682 is a critical (CVSS 9.8, CWE-754) improper check for unusual or exceptional conditions vulnerability in the
1. Executive summary The ShinyHunters extortion gang (MITRE G1057) claims to have breached the Clop ransomware operation's Tor-based data leak site,
1. Executive summary SolarWinds has patched CVE-2026-28326, a hard-coded cryptographic key flaw (CWE-321) in Access Rights Manager (ARM) that permits
1. Executive summary On 18 September 2026 the ransomware operator using the name "lockbit5" listed hygear.com, a German hydrogen and industrial
1. Executive summary On 17 September 2026 Microsoft patched 18 vulnerabilities across its Azure cloud portfolio and Copilot-branded AI products, the majority of
1. Executive summary Zscaler ThreatLabz attributes a new campaign, Operation RapidRust, to Transparent Tribe (APT36), targeting government and defence entities in India and Afghanistan.
1. Executive summary CVE-2026-58138 is an unauthenticated remote code execution vulnerability in Orkes Conductor, an open source framework used to orchestrate microservices,
1. Executive summary Zimperium's zLabs has documented an Android banking Trojan, RatHat, that hands a live AI assistant control of the infected
1. Executive summary CVE-2026-53266 is a high-severity (CVSS 8.8) out-of-bounds write in the Linux kernel's ebtables
1. Executive summary Microsoft has patched CVE-2026-85889, a CVSS 10.0 CRITICAL missing-authentication flaw (CWE-306) in Azure AI Foundry that
1. Executive summary CVE-2025-39964 is a race condition (CWE-362) in the Linux kernel's AF_ALG cryptographic socket interface: concurrent
1. Executive summary Kaspersky reports that the cyberespionage group tracked as NightEagle (also APT-Q-95), active since at least 2023 and previously focused