Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary CVE-2026-20262 is a directory/path traversal vulnerability (CWE-22) in the web UI of Cisco Catalyst SD-WAN Manager
1. Executive summary The Council of Europe has confirmed it is investigating a breach in which the ShinyHunters extortion crew claims to have stolen
1. Executive summary Oracle has issued an out-of-band patch for CVE-2026-35273, a critical vulnerability (CVSS 9.8, IN CISA KEV
1. Executive summary GitHub has announced that npm v12 (expected July 2026) will change three security-focused defaults to disrupt the supply-chain attack
1. Executive summary Splunk has disclosed CVE-2026-20253, a critical (CVSS 9.8) flaw in the Splunk Enterprise PostgreSQL sidecar service that allows
1. Executive summary OpenClaw versions prior to 2026.5.18 contain an authorization bypass vulnerability (CVE-2026-53821) in the Gateway WebSocket control plane.
1. Executive summary The Iran-linked threat actor "Handala" claims to have compromised California Water Service (Cal Water), exfiltrating approximately 5GB of
1. Executive summary The threat actor group "ShinyHunters" claims to have compromised over 100 organizations, including the University of Nottingham, by exploiting
1. Executive summary Threat actor UNC6240 (attributed publicly to "ShinyHunters") is actively exploiting CVE-2026-35273, a critical remote code execution vulnerability
1. Executive summary Threat actors are actively exploiting CVE-2026-5027, a high-severity (CVSS 8.8) path traversal vulnerability in the AI development
1. Executive summary Threat actors are actively exploiting CVE-2026-10520, a maximum-severity (CVSS 10.0) OS command injection vulnerability in Ivanti Sentry
1. Executive summary A native Windows URI handler (search:) contains an unpatched NTLM credential leakage vulnerability functionally identical to the recently patched Snipping Tool