Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary The Gentlemen, a ransomware-as-a-service (RaaS) operation active since mid-2025 and ramping significantly through 2026, has been attributed
1. Executive summary Nissan Americas has notified current and former employees across the US, Canada, Mexico, and Brazil that a cyberattack against Oracle PeopleSoft
1. Executive summary On 2026-06-29, ransomware tracking site ransomware.live published a victim listing naming Bristol Place (bristolplace.net, GB) as a
1. Executive summary On 2026-06-29, the ransomware operator/group "qilin" publicly claimed a ransomware attack against Gsma, an organisation based
1. Executive summary On or around 11 June 2026, threat actors exploited a compromised legacy credential associated with Klue's Salesforce integration to
1. Executive summary Security researchers at Mozilla's Zero Day Investigative Network (0DIN) have demonstrated a proof-of-concept attack that abuses Anthropic&
1. Executive summary Microsoft's security team has removed 119 malicious Edge extensions from the official Microsoft Edge Add-ons store that were
1. Executive summary On 2026-06-28, the actor "stormous" publicly claimed a ransomware attack against eogb.co.uk, a UK-registered
1. Executive summary The FBI and CISA have published an updated public service announcement warning that a phishing campaign attributed to Russian Intelligence Services
1. Executive summary A phishing campaign delivering a Windows backdoor via a malicious Chrome extension is actively targeting users. The malware abuses Chrome Native
1. Executive summary CVE-2026-46331 ("pedit COW") is an out-of-bounds write vulnerability in the Linux kernel's traffic-
1. Executive summary A new wave of the Miasma/Mini Shai-Hulud supply-chain malware family has compromised at least 24 npm packages (LeoPlatform,