Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 5 September 2026, ransomware group "thegentlemen" listed Leo Schachter Diamonds (US, leoschachter.com) as a victim on its
1. Executive summary Unidentified threat actors exploited CVE-2026-63077 (CVSS 9.8, critical) — an unauthenticated deserialization-of-untrusted-data flaw in JetBrains TeamCity
1. Executive summary On 5 September 2026, the ransomware operator "thegentlemen" listed the Polish pharmacy chain Zdrowit S.A. (Bytom, Silesia) as
1. Executive summary On 5 September 2026, ransomware group "thegentlemen" listed US healthcare technology firm Veradigm (veradigm.com) on its leak site,
1. Executive summary A critical arbitrary file upload vulnerability, CVE-2026-32475 (CVSS 9.0 CRITICAL per NVD; the vendor press coverage quotes 9.
1. Executive summary This is not a vulnerability or campaign advisory: it covers the release and hands-on evaluation of numbat, Perplexity AI'
1. Executive summary On 4 September 2026, the ransomware operator tracked as "lockbit5" publicly listed PSC Industries (pscindustries.com), a US industrial
1. Executive summary On 2026-09-04, the ransomware operator branding itself "lockbit5" listed the German company KALA Health (kalahealth.eu), an
1. Executive summary On 2026-09-04, the ransomware operator branding as "lockbit5" listed the Dutch primary-care medical practice Huisartsencentrum Klein
1. Executive summary Microsoft has published architectural guidance on securing edge AI deployments — inference workloads running on customer-owned devices, gateways, and on-premises
1. Executive summary CVE-2026-85046 is a high-severity (CVSS 8.8) type confusion vulnerability in Google Chromium's V8 JavaScript and
1. Executive summary Recorded Future has announced Automated Signature Creation, a new capability in its Attack Surface Intelligence (ASI) product that uses agentic AI