Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary PraisonAI’s FastAPI async Jobs API contains no authentication or job-ownership control, allowing any caller who can reach /api/v1/
1. Executive summary Cybersecurity Dive and Dark Reading report active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite. The reported input-sanitisation failure
1. Executive summary Threat reporting describes opportunistic attempts to exploit authentication flaws in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin;
1. Executive summary Commercial AI guardrails reportedly blocked Hugging Face’s initial analysis of attack commands, exploit payloads and command-and-control artefacts after
1. Executive summary Malwarebytes reports that Take-Two Interactive subpoenaed Microsoft and Discord for identifying data associated with members of three Discord servers after
1. Executive summary WordlistLoader is being used in ClickFix-style campaigns to disguise malicious content as ordinary text and deliver the Amatera infostealer. The
1. Executive summary Check Point Research's weekly bulletin covers multiple developments relevant to EMEA financial services. The most urgent is an active
1. Executive summary Cybersecurity firm ReliaQuest has confirmed a limited breach attributed to the ShinyHunters threat actor (MITRE G1057). The attack combined a voice
1. Executive summary CVE-2026-21962 is a critical (CVSS 10.0) improper access control vulnerability in the Oracle HTTP Server and Oracle Weblogic
1. Executive summary Rapid7 has published a technical analysis of CVE-2026-63520, a HIGH severity (CVSS 8.1) remote code execution vulnerability in
1. Executive summary Security researchers at Socket have identified 77 linked malicious Firefox extensions — 40 confirmed as active info-stealers — in a campaign dubbed
1. Executive summary Malwarebytes tracking identifies PavinLoader, a multi-stage .NET loader, as a shared infrastructure component across disparate initial access vectors including ClickFix