Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary CVE-2026-63030 is a critical unauthenticated remote code execution (RCE) vulnerability in WordPress Core, exploitable via the WordPress REST API
1. Executive summary Volexity has published findings on a sophisticated intrusion campaign targeting SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, attributing the
1. Executive summary Checkmarx has identified seven malicious npm packages targeting the Vite JavaScript build tool ecosystem in a supply-chain campaign codenamed "
1. Executive summary Microsoft disclosed CVE-2026-58644 on July 14, 2026, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability affecting
1. Executive summary In April 2026, a threat cluster dubbed "CylindricalCanine" — described by Expel as a subgroup of the Chinese cybercrime actor
1. Executive summary Ernst & Young (EY) has notified clients of a data breach stemming from the compromise of a third-party support ticket
1. Executive summary Elastic Security Labs documented a new Contagious Interview campaign (tracked as REF9403) deploying OTTERCOOKIE-aligned malware via trojanized coding challenge repositories
1. Executive summary From late April to mid-June 2026, Microsoft Defender Experts observed two prevalent intrusion chains delivering ACR Stealer, an information-stealing
1. Executive summary Unit 42 published a supplementary analysis to its 2026 Global Incident Response (IR) Report on 16 July 2026, concluding that AI
1. Executive summary Cisco Talos has disclosed a financially motivated campaign by threat actor UAT-11795 distributing trojanized installers for widely used software (MobaXterm,
1. Executive summary CVE-2026-25089 is a critical (CVSS 9.8, CWE-78) OS command injection vulnerability in Fortinet FortiSandbox, FortiSandbox Cloud, and
1. Executive summary CVE-2026-58644 is a critical (CVSS 9.8) deserialization of untrusted data vulnerability in Microsoft SharePoint Server, enabling an unauthenticated,