Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A misconfigured Python web server (python3 -m http.server 8080) with directory listing enabled exposed the full toolkit, logs, and bash
1. Executive summary Progress Software has directed ShareFile customers to immediately manually shut down all Windows servers hosting on-premises Storage Zone Controllers (SZC)
1. Executive summary A 14-day log review of a low-traffic web host by SANS ISC has revealed a new category of internet-
We took two C2 IP addresses from a malware news article and pivoted through Shodan, DNS, reverse MX lookups, certificate transparency, WHOIS, and MITRE
1. Executive summary The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025, now ranked
1. Executive summary On 2026-07-11, the ransomware operator "thegentlemen" publicly claimed a compromise of BDO Greece (bdo.gr), an Athens-
1. Executive summary On 11 July 2026, the ransomware group "thegentlemen" publicly claimed a compromise of INTERNET AG (inet.de), a German
1. Executive summary The Australian Cyber Security Centre (ACSC) has issued an alert regarding a large-scale, global exploitation campaign targeting vulnerabilities in content
1. Executive summary Microsoft Threat Intelligence has published detailed analysis of GigaWiper, a Golang-based modular Windows backdoor first observed in compromised environments in
1. Executive summary An initial access broker weaponized the CitrixBleed 2 vulnerability in a series of attacks across multiple organizations during the first half
1. Executive summary On 2026-07-10, the ransomware group "Deadlock" publicly claimed a compromise of Integra S.r.l. and L&
1. Executive summary On 2026-07-10, the ransomware group "Deadlock" publicly claimed a ransomware attack against EFCA, a Paris-based accounting