Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A flaw in Anthropic's Claude for Chrome browser extension allows a malicious extension co-installed in the same browser
1. Executive summary Cisco Talos has disclosed an active, financially motivated campaign by actor "UAT-11795" (no MITRE ATT&CK profile
1. Executive summary Elastic Security Labs has published a technical report on TELEPUZ, a modular, C-based Windows malware offered under a malware-as-
1. Executive summary Researchers from Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft published a paper on 6 July 2026 detailing
1. Executive summary A financially motivated Russian threat actor tracked as "UAT-11795" is distributing trojanized installers for common enterprise and developer
1. Executive summary A new ransomware actor dubbed "Spirals" completed a full intrusion cycle — from initial access through data theft to file
1. Executive summary F5 released an out-of-band security rollout on 16 July 2026 patching eight vulnerabilities across NGINX Open Source, NGINX Plus,
1. Executive summary A GuidePoint Security report details how data-extortion groups — principally FulcrumSec (active since ~September 2025) and DragonForce (active since 2023) — are
1. Executive summary Sophos's State of Ransomware 2026 report, based on a survey of 2,158 IT and security leaders whose organisations
1. Executive summary Zoom has disclosed CVE-2026-53412, a critical vulnerability (CVSS 9.8) caused by improper input validation in the Zoom Desktop
1. Executive summary A Russian-speaking threat actor dubbed "bandcampro" used Google's open-source Gemini CLI as an autonomous hacking
1. Executive summary Elastic Security Labs reports active in-the-wild distribution of TELEPUZ, a modular, lightweight Windows DLL malware likely operated as a