Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 4 September 2026, the U.S. Department of Justice and the U.K.'s National Crime Agency (NCA) and
1. Executive summary Beginning 1 September 2026, X users began receiving unsolicited, legitimate password-reset emails and codes they did not request, coinciding with
1. Executive summary CVE-2026-6471 ("PostGREShell") is a missing-authorization flaw (CVSS 7.2 HIGH, CWE-862, not in CISA KEV,
1. Executive summary The "Phantom Deal" campaign is a social-engineering operation in which threat actors conduct deep reconnaissance on target companies
1. Executive summary Cisco has disclosed three critical (CVSS 9.8) vulnerabilities following a comprehensive internal security review of IOS XR Software and a
1. Executive summary CISA has published ICS advisory ICSA-26-246-06 covering CVE-2026-77393 in Inductive Automation Ignition 8.1.53 and
1. Executive summary On 3 September 2026, the researcher known as Nightmare Eclipse (aliases Chaotic Eclipse, Infinite Nightmare, MSNightmare) published a working proof-of-
1. Executive summary CISA has published ICS advisory ICSA-26-246-02 covering CVE-2026-75925, a CRLF injection vulnerability (CWE-93, with CWE-
1. Executive summary Microsoft has documented a high-volume, finance-themed phishing campaign that repurposed "ASCII smuggling" — invisible Unicode tag characters (U+
1. Executive summary Recorded Future's Insikt Group identified 215 actively exploited CVEs in H1 2026, up 34% from 161 in H1 2025,
1. Executive summary The Children's Commissioner for England, Dame Rachel de Souza, told the House of Lords Communications and Digital Committee that
1. Executive summary A high-severity second-order SQL injection vulnerability, CVE-2026-19949 (CVSS 8.8, HIGH; not currently listed in CISA KEV,