Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary CTM360 reports identifying more than 3,000 recruitment-themed phishing URLs over two months, impersonating recruitment processes linked to more than
1. Executive summary A newly disclosed elevation of privilege (EoP) vulnerability in the Microsoft Malware Protection Engine, publicly referred to as "ShieldBreak"
1. Executive summary CVE-2026-65400 is a CVSS 9.8 CRITICAL macOS Screen Sharing vulnerability classified as CWE-287 (Improper Authentication); a network
1. Executive summary France's Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals. A threat
1. Executive summary Model Context Protocol (MCP) servers — the middleware connecting AI agents to enterprise data, APIs and infrastructure — are accumulating production credentials (API
1. Executive summary A maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter), tracked as CVE-2026-58231 (CVSS 10.0, CRITICAL, CWE-
1. Executive summary Rapid7 researchers discovered an exposed web directory on a server supporting a multi-stage cryptocurrency fraud operation tracked as "Operation
1. Executive summary Chinese AI company Zhipu announced GLM-5.3, a model it claims surpasses Anthropic and OpenAI offerings on the CyberGym benchmark
1. Executive summary ETSI has published 17 interim draft cybersecurity standards defining minimum security requirements for product categories — including operating systems, network devices, VPNs,
1. Executive summary German and Brazilian law enforcement have dismantled an international bank fraud ring responsible for stealing approximately €30 million from a German
1. Executive summary Microsoft has confirmed an indefinite delay in the release of Exchange Server Subscription Edition (SE) Cumulative Update 1 (CU1), attributing the
1. Executive summary SecurityWeek reports that an actor using the moniker “TheHatman” is advertising millions of employee-directory records allegedly obtained from the Azure/