Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Palo Alto Networks Unit 42 has published research on "phantom squatting," a technique where attackers register domains that large
1. Executive summary A massive, ongoing automated password-spray campaign targeting Microsoft's Azure CLI has been observed by Huntress, with over 81
1. Executive summary An anonymous researcher using the pseudonym "Bikini" has published proof-of-concept exploit code and write-ups for more
1. Executive summary Security researcher Bert-Jan Pals analysed approximately 3,000 live ClickFix payloads and revealed that the social-engineering delivery technique has
1. Executive summary CVE-2026-24294 is an improper authentication vulnerability in Windows SMB Server that permits an authorized attacker to elevate privileges locally.
1. Executive summary A critical vulnerability in Oracle E-Business Suite (EBS) Payments — CVE-2026-46817 (CVSS 9.8 CRITICAL, CWE-269 / CWE-287)
1. Executive summary CVE-2026-33825 ("BlueHammer"), a local privilege escalation vulnerability in Microsoft Defender (CVSS 7.8 HIGH), has been added
1. Executive summary Microsoft Incident Response has published a detailed attack pattern in which threat actors poison Model Context Protocol (MCP) tool descriptions to
1. Executive summary A critical vulnerability in Oracle E-Business Suite (EBS) Oracle Payments — CVE-2026-46817 (CVSS 9.8 CRITICAL; CWE-269 Improper
1. Executive summary Independent researchers Charles Ye, Jasmine Cui, and MIT associate professor Dylan Hadfield-Menell have published a paper titled "Prompt Injection
1. Executive summary A previously undocumented cross-platform infostealer dubbed "Djinn Stealer" is being deployed in the wild via exploitation of CVE-
1. Executive summary Nissan has disclosed a data breach affecting current and former employees across the US, Canada, Mexico, and Brazil, linked to the