Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary CVE-2026-60004 affects Gitea 1.17 through 1.27.0 and enables a repository writer to plant an executable Git
1. Executive summary Siemens disclosed CVE-2026-58115 affecting SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) before V4.3.4.1 when running Industrial OS
1. Executive summary Paylogix disclosed that an unspecified cyberattack disrupted its systems and that intruders stole files from its network between 13 and 18
1. Executive summary CISA disclosed CVE-2026-18965, a missing-authorization vulnerability affecting all versions of the PayRange API. CISA assigns CVSS v3.1
1. Executive summary CISA has published lessons from authorised red-team assessments at two critical-infrastructure organisations. At one organisation, the SOC failed to
1. Executive summary CVE-2026-60004 is a reported Gitea code-injection vulnerability through which a user with repository write access can submit a
1. Executive summary Sophos X-Ops reviewed 86 MDR cases tagged for AI involvement between 2 July 2025 and 29 June 2026: 34 met
1. Executive summary CVE-2026-76060 is an authenticated OS command-injection vulnerability in ZoneMinder’s event-export function. CISA reports CVSS v3.1
1. Executive summary GitHub published GHSA-8hjw-25cg-g52h, identified there as CVE-2026-55523, describing a server-side request forgery bypass in praisonaiagents.
1. Executive summary CVE-2026-44661 is a CWE-918 server-side request forgery vulnerability affecting utcp-gql 1.1.0 and utcp-websocket
1. Executive summary SANS ISC reports SSRF scanning in which attacker-supplied hostnames resolve to the link-local cloud metadata address 169.254.169.
1. Executive summary Censys reports that the August 2025 publication of ERMAC 3.0 source code exposed a deployable Android banking-trojan stack comprising