Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Rapid7 has disclosed two new vulnerabilities in N-able N-central — CVE-2026-86206 (CVSS 6.9 MEDIUM, CWE-791, not
1. Executive summary Red Hat has disclosed a two-flaw chain that allows a completely unauthenticated network client to write a Kerberos identity of
1. Executive summary Stadtwerke Landsberg, a city-owned municipal utility in Bavaria, disclosed on 8 September 2026 that attackers encrypted its central IT network
1. Executive summary Cisco Talos documents a monthslong criminal campaign (active since early October 2025, ongoing as of August 2026) that weaponises the Google
1. Executive summary CVE-2026-75650 ("StyleSmuggler") is a CVSS 10.0 CRITICAL unauthenticated remote code execution vulnerability in Adobe Commerce, Adobe
1. Executive summary Google's Threat Intelligence Group and Mandiant have disclosed, via their Q2-2026 AI Threat Tracker, a series of data-
1. Executive summary Arctic Wolf is tracking a widespread data theft and extortion cluster — tracked as PREY-0058 — that compromises Microsoft 365 and other
1. Executive summary On 3 September 2026, OpenAI announced a $1 billion commitment — the "Daybreak for Frontline Defenders" program — providing subsidized access
1. Executive summary On 7 September 2026, the ransomware group self-identifying as "thegentlemen" listed the University of San Francisco (US) as
1. Executive summary On 7 September 2026, ransomware operator "thegentlemen" listed Portuguese IT and gaming retailer Chip7 (chip7.pt) on its leak
1. Executive summary Springfield Public Schools (Massachusetts, US) announced on Monday 7 September 2026 that all schools will be closed Tuesday after a cyber
1. Executive summary On 7 September 2026, the ransomware group "everest" publicly listed the German technology conglomerate Körber (headquartered in Hamburg) as