Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Microsoft Threat Intelligence has published detailed research on GigaWiper, a modular Golang-based Windows backdoor observed in intrusions since October 2025.
1. Executive summary A threat actor tracked by Okta as "O-UNC-066" is conducting voice-phishing (vishing) attacks against Microsoft 365
1. Executive summary On 10 July 2026, HM Treasury (HMT) designated the first four Critical Third Parties (CTPs) under the UK financial regulatory regime:
1. Executive summary On 2026-07-10, the ransomware actor "nova" publicly claimed a victim named Hynet, a UK-based provider of
1. Executive summary Huntress is tracking a massive, automated password spray attack targeting Microsoft's Azure command-line interface (CLI), originating from IPv6
1. Executive summary On 2026-07-09, the actor "cmdorganization" publicly claimed a ransomware attack against Finance Yorkshire (GB), a UK-based
1. Executive summary CISA ICS Advisory ICSA-26-190-02 discloses six vulnerabilities in Schneider Electric PowerChute Serial Shutdown (versions 1.4 and prior)
1. Executive summary Microsoft Threat Intelligence has detailed GigaWiper, a Golang-based modular backdoor first observed in October 2025 that integrates destructive wiper payloads,
1. Executive summary A new phishing-as-a-service (PhaaS) platform dubbed "Forg365" has been identified by ZeroBEC researchers, specifically targeting Microsoft
1. Executive summary Microsoft has released Microsoft Malware Protection Engine version 1.1.26060.3008, patching CVE-2026-50656 — a local elevation of privilege
1. Executive summary Infoblox has disclosed a threat actor dubbed "Lurking Lizard" operating an end-to-end malicious residential proxy business using
1. Executive summary On 2026-07-07, CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, all with confirmed evidence of active