Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel use-after-free vulnerability (CVSS 7.8 HIGH) disclosed by
1. Executive summary Accenture has confirmed a security breach after a threat actor using the alias "888" claimed to have stolen approximately
1. Executive summary On 2026-07-07, the ransomware operator "dragonforce" publicly claimed a compromise of hive360.com, a UK-based employment
1. Executive summary BeyondTrust has released updates for four vulnerabilities — two CRITICAL pre-authentication bypass flaws (CVE-2026-40138, CVSS 9.2; CVE-2026-
1. Executive summary Threat actors are conducting a multi-stage vishing campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support staff,
1. Executive summary On 2026-07-06, the Qilin ransomware group publicly claimed Max Fordham (www.maxfordham.com), a UK-based engineering consultancy, as
1. Executive summary Check Point Research (CPR) has published a detailed analysis of "Cavern," a new modular .NET command-and-control (C2)
1. Executive summary LevelBlue researchers have disclosed QuimaRAT, a novel Java-based remote access trojan offered as a malware-as-a-service (MaaS) product
1. Executive summary A phishing campaign observed from early April to mid-May 2026 abuses the OAuth 2.0 Device Authorization Grant (Device Code
1. Executive summary Sysdig's Threat Research Team has published findings on what they believe is the first documented end-to-end ransomware
1. Executive summary A U.S. government entity — evidence points to Union County, Ohio — paid approximately $1 million (≈9.44 BTC) to a threat
1. Executive summary On 2026-07-04, the ransomware tracking site ransomware.live published a listing attributing a ransomware attack against Deutsche Bank (DE)