Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A GuidePoint Security report details how data-extortion groups — principally FulcrumSec (active since ~September 2025) and DragonForce (active since 2023) — are
1. Executive summary Sophos's State of Ransomware 2026 report, based on a survey of 2,158 IT and security leaders whose organisations
1. Executive summary Zoom has disclosed CVE-2026-53412, a critical vulnerability (CVSS 9.8) caused by improper input validation in the Zoom Desktop
1. Executive summary A Russian-speaking threat actor dubbed "bandcampro" used Google's open-source Gemini CLI as an autonomous hacking
1. Executive summary Elastic Security Labs reports active in-the-wild distribution of TELEPUZ, a modular, lightweight Windows DLL malware likely operated as a
1. Executive summary Progress Software has confirmed that a high-severity zero-day vulnerability in ShareFile Storage Zones Controller (SZC) versions 5.x and
1. Executive summary On 15 July 2026, the ransomware operator "AiLock" publicly claimed compromise of Ferrovial, a global infrastructure and mobility operator
1. Executive summary Kaspersky has published detailed analysis of "OkoBot," a sophisticated, multi-stage malware framework active since at least April 2025
1. Executive summary Four npm packages in the @asyncapi namespace (@asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@
1. Executive summary CrashStealer is a new macOS infostealer, discovered by Jamf Threat Labs and publicly reported in July 2026, that masquerades as Apple&
1. Executive summary Spanish National Police, supported by Interpol and Europol, dismantled a cybercrime and money-laundering organisation that generated approximately €140 million ($160
1. Executive summary Microsoft's July 2026 Patch Tuesday addresses a record 622 vulnerabilities across its product ecosystem, including 57 rated critical. Two