Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Two new phishing kits — Jalisco and OmegaLord — have been discovered targeting Microsoft 365 accounts using techniques that defeat multi-factor authentication
1. Executive summary A solo Russian-speaking threat actor tracked as "bandcampro" used a jailbroken Google Gemini CLI agent to automate a
1. Executive summary xAI's Grok Build CLI (version 0.2.93) was discovered silently uploading users' entire Git repositories — including full
1. Executive summary On 14 July 2026, CISA, NSA, FBI, DC3, and 14 international partners published a joint cybersecurity advisory titled Improve Router Hygiene
1. Executive summary Cisco Talos published a technical analysis detailing how threat actors abuse native Python package installation mechanisms to execute malicious payloads and
1. Executive summary Between mid-2025 and mid-2026, Microsoft tracked a series of campaigns targeting customer SaaS-based applications — predominantly Salesforce instances — using
1. Executive summary Microsoft Threat Intelligence has disclosed GigaWiper, a modular Golang-based Windows backdoor observed in destructive intrusions since October 2025. The implant
1. Executive summary Huntress reports a June 2026 incident in which a threat actor achieved deep persistence on a Windows host via an SQL
1. Executive summary On 13 July 2026, the UK FCDO and EU formally attributed a December 2025 cyberattack on Poland's power grid
1. Executive summary On 13 July 2026, the EU and UK jointly imposed sanctions on dozens of Russian individuals and entities — the largest-ever
1. Executive summary On 13 July 2026, the UK NCSC and 18 agencies from 12 countries published a joint advisory attributing ongoing, opportunistic exploitation
1. Executive summary On 13 July 2026, ANSSI (via the French Cyber Crisis Coordination Centre, C4) published a CTI advisory reporting the targeting and