Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Unit 42 has disclosed a design weakness in AWS AgentCore Harness: with default configuration, the harness's built-in shell
1. Executive summary Docker disclosed CVE-2026-77179 on 15 September 2026, a critical sandbox-escape flaw (CVSS 9.4, CWE-59) in Docker
1. Executive summary ESET Research reports that the China-aligned espionage group FamousSparrow has replaced its long-standing SparrowDoor implant with a new modular
1. Executive summary In June 2026 the IETF published RFC 10008, defining QUERY, the first new standard HTTP method since PATCH in 2010. QUERY
1. Executive summary Hush Security analysed roughly 82,000 publicly accessible MCP configuration files on GitHub and found that 12% of credential slots contained
1. Executive summary On 17 September 2026 the ransomware operator tracked as "qilin" listed the German engineering firm Vigatec (www.vigatec.com)
1. Executive summary A zero-click remote code execution flaw, dubbed Plugin4Shell, affects all major AI coding agents: Anthropic Claude Code, OpenAI Codex, Google
1. Executive summary CISA has republished Mitsubishi Electric advisory 2026-007 covering CVE-2026-15688, an incorrect implementation of an authentication algorithm (CWE-303)
1. Executive summary Schneider Electric has released version 1.6 of PowerChute Serial Shutdown to fix CVE-2026-13348, an improper restriction of excessive
1. Executive summary Schneider Electric has released firmware version 5.6.0 for its NetBotz 5 750 and 755 environmental and security monitoring appliances,
1. Executive summary Schneider Electric has published advisory SEVD-2025-224-05, republished by CISA as ICSA-26-260-04, covering CVE-2025-6625,
1. Executive summary CISA has republished Hitachi Energy PSIRT advisory 8DBD000229 covering five vulnerabilities in the FACTS Control Platform (FCP) with the GWS component,