Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A new attack variant dubbed "ConsentFix" is being actively deployed against Microsoft 365 users, combining social engineering with OAuth
1. Executive summary Kaspersky GReAT has published details of a new toolset dubbed "Umbrij," attributed to the ToddyCat APT (MITRE G1022), which
1. Executive summary Cisco has confirmed active in-the-wild exploitation of CVE-2026-20230, an unauthenticated remote server-side request forgery (SSRF) vulnerability
1. Executive summary A critical vulnerability in Oracle E-Business Suite (EBS) Payments — CVE-2026-46817 — is being actively exploited in the wild following
1. Executive summary Rarlab has patched a remote code execution vulnerability (CVE-2026-14191) in WinRAR and UnRAR affecting RAR5 recovery-volume (.rev) file
1. Executive summary Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability (CVE-2026-45659, CVSS 8.8 HIGH, CWE-502) enabling authenticated,
1. Executive summary CISA added CVE-2026-45659 (CVSS 8.8, HIGH) to its Known Exploited Vulnerabilities (KEV) catalog on 2026-07-01, citing
1. Executive summary @apify/actors-mcp-server version 0.10.7 is vulnerable to URL authority injection via the webServerMcpPath field in Actor definitions
1. Executive summary The EvilTokens phishing-as-a-service (PhaaS) platform, which abuses Microsoft's OAuth 2.0 Device Authorization Grant (RFC 8628)
1. Executive summary The FortiBleed campaign — a large-scale credential-harvesting operation active since February 2026 — has been linked by SOCRadar's Threat
1. Executive summary Palo Alto Networks Unit 42 has published research on "phantom squatting," a technique where attackers register domains that large
1. Executive summary A massive, ongoing automated password-spray campaign targeting Microsoft's Azure CLI has been observed by Huntress, with over 81