Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary The Contagious Interview campaign (MITRE G1052) has expanded into a new supply-chain attack cluster dubbed PolinRider, publishing 108 unique malicious
1. Executive summary ESET published a threat-landscape assessment for SMBs noting that AI is lowering the barrier to entry for attackers — improving lure
1. Executive summary JFrog has identified a campaign distributing malicious npm packages that impersonate the legitimate rollup-plugin-polyfill-node project to deliver remote-
1. Executive summary Citizen Lab researchers have confirmed that the mobile phone of Stelios Kouloglou — a former Member of the European Parliament (MEP) who
1. Executive summary An incorrect authorization vulnerability in Microsoft Exchange Online permits an authenticated, remote attacker to elevate privileges over a network. The flaw
1. Executive summary A local privilege escalation vulnerability (CVE-2026-13079) exists in the WatchGuard Mobile VPN with SSL client for Windows, affecting versions
1. Executive summary Over June 7–8 2026, a solo developer's Google Cloud account incurred $11,089.77 in unauthorised charges driven
1. Executive summary Sysdig threat researchers have documented what they assess as the first fully agentic ransomware operation, in which an LLM-driven agent
1. Executive summary Cisco Talos published research on ARToken, a phishing-as-a-service (PhaaS) operator panel that shares infrastructure, API contracts, and operational
1. Executive summary A U.S. Supreme Court ruling that President Trump acted legally in firing FTC Commissioner Rebecca Slaughter without cause has undermined
1. Executive summary An active, evolving ClickFix campaign uses fake Google and Cloudflare verification pages to socially engineer users into executing malicious PowerShell commands,
1. Executive summary A new CitrixBleed-like vulnerability (CVE-2026-8451, CVSS 8.8) in NetScaler ADC and NetScaler Gateway appliances was exploited in