Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary CVE-2026-27875 affects Johnson Controls Simplex Incident Manager V2.01 and earlier, which retain passwords and authentication tokens in cleartext
1. Executive summary SANS Internet Storm Center published a Microsoft Graph PowerShell workflow for reviewing Microsoft Entra risky-login detections; it does not report
1. Executive summary U.S. agencies reportedly warned of active reconnaissance and capability development against Siemens S7 programmable logic controllers (PLCs), using AI-assisted
1. Executive summary CVE-2026-72530 is a CVSS 9.5 CRITICAL CWE-94 code-injection vulnerability affecting TrueConf Server versions 5.3.X
1. Executive summary GuidePoint Security assesses with moderate confidence that “Ransom Busters” is a ransomware affiliate impersonating a recovery provider to divert payments from
1. Executive summary Wordfence reports that Elementor Pro versions up to and including 4.2.1 permit unauthenticated arbitrary file upload when a published
1. Executive summary SANS Internet Storm Center published a Microsoft Graph PowerShell workflow for identifying enabled Entra accounts, sign-in history, password-change dates
1. Executive summary On 20 August 2026, Ransomware.live recorded a claim naming Capgemini Engineering, France, as an Everest victim. The claim is single-
1. Executive summary CVE-2026-32475 is a CWE-434 unrestricted-file-upload vulnerability affecting Elementor Pro versions up to and including 4.2.
1. Executive summary Dark Reading reports that the “Kriminal” AI platform provides guardrail-free social-engineering, offensive-cybercrime and OSINT-scanning capabilities to users
1. Executive summary U.S. agencies have warned of an active campaign using AI-assisted exploit scripts and known vulnerabilities to target internet-exposed
1. Executive summary On 19 August 2026, Ransomware.live indexed a ransomware claim naming Suffolk-based CRASL Accounting Services as a victim of “thegentlemen”