Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A 29-year-old heap overread vulnerability in the Squid open-source caching proxy, tracked as CVE-2026-47729 and dubbed
1. Executive summary A new macOS ClickFix campaign uses fake CAPTCHA pages to trick users into pasting a Terminal command that silently downloads, mounts,
1. Executive summary Law enforcement action against the SocGholish malware-as-a-service operation has been reported, drawing attention to the continued use of
1. Executive summary On 12 June 2026, LastPass was notified that market-intelligence platform Klue had suffered a security incident in which an attacker
1. Executive summary A financially motivated, Russian-speaking initial access broker (IAB) has been conducting a large-scale credential-harvesting campaign — dubbed FortiBleed — against
1. Executive summary A social-engineering campaign targeting software developers via fake LinkedIn recruiter profiles attempted to deliver a backdoored Node.js repository that
1. Executive summary A SIM swap attack — in which a threat actor convinces or coerces a mobile carrier's staff to port a
1. Executive summary Microsoft has published a defensive architecture blog describing how AI "memory" features in M365 Copilot change the threat model
1. Executive summary Adversaries are abusing native Microsoft 365 collaboration surfaces — Outlook Groups, shared files, and calendar invitations — to deliver phishing lures that blend
1. Executive summary Market intelligence platform Klue suffered a supply-chain intrusion on 11 June 2026 when a threat actor exploited a compromised legacy
1. Executive summary CVE-2024-40766 is an improper access control vulnerability in SonicOS (CVSS 9.3) affecting the management interface and SSLVPN service
1. Executive summary An active malware campaign is distributing malicious VBScript (.vbs) attachments via direct messages on WhatsApp Desktop and WhatsApp Web, using compromised