Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Fortra researchers have identified "Mirage2FA," a phishing kit that uses short-lived HTML smuggling and obfuscated JavaScript loaders to
1. Executive summary A new backdoor tracked as Mistic (also tracked as MLTBackdoor) has been deployed in financially motivated intrusions since April 2026, targeting
1. Executive summary The Gamaredon Group (MITRE G0047) — a Russia-linked APT operation attributed to FSB state sponsorship — has reportedly upgraded its malware-loading
1. Executive summary The Bluekit phishing-as-a-service (PaaS) platform has added browser-in-the-middle (BitM) capabilities, replacing its previous adversary-in-
1. Executive summary Symantec and Carbon Black's Threat Hunter Team have identified a new backdoor dubbed Mistic (also tracked as MLTBackdoor by
1. Executive summary Google released Chrome 149.0.7827.196/197 (Windows/Mac) and 149.0.7827.196 (Linux), patching 18 vulnerabilities including four
1. Executive summary GitLab has released CE/EE security updates — versions 19.1.1, 19.0.3, and 18.11.6 — patching 13 vulnerabilities
1. Executive summary CISA added CVE-2025-67038 (CVSS 9.8 CRITICAL, CWE-94 Code Injection) to its Known Exploited Vulnerabilities (KEV) catalog on
1. Executive summary DarkReading reports a strategic shift by ransomware operators toward European targets, specifically EU organisations and their supply-chain suppliers, following a
1. Executive summary A new stealthy backdoor dubbed Mistic (also tracked as MLTBackdoor) has been deployed in financially motivated attacks against organisations in the
1. Executive summary On 2026-06-24, an attacker published malicious versions of 20 npm packages in the Leo Platform ecosystem in a coordinated
1. Executive summary Mandiant has published detailed attack-chain analysis of CVE-2026-20245 (CVSS 7.8 HIGH, CWE-116), a now-patched privilege-