Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A maximum-severity vulnerability (CVE-2026-58231, CVSS 10.0, CRITICAL) in SAP Commerce Cloud's Data Hub Adapter is
1. Executive summary On 2026-08-17, the actor "bravox" publicly named UK company Moores (www.moores.co.uk) as a ransomware
1. Executive summary On 16 August 2026, the actor "lockbit5" publicly named dupouy-associes.fr — Dupouy et Associes / Crowe Horwath, a French
1. Executive summary Rapid7 added public Metasploit modules for multiple unauthenticated and authenticated remote-code-execution paths, a Linux local privilege escalation, and Ray
1. Executive summary On 16 August 2026, the Qilin ransomware group publicly claimed a victim, INVENSITY, a Germany-based organisation (domain: www.invensity.com)
1. Executive summary On 16 August 2026, the Qilin ransomware group publicly claimed a victim named DELTA WAYS, a Germany-based organisation (domain: www.
1. Executive summary Tenable's Research Special Operations (RSO) team has documented a cluster of seven confirmed incidents (November 2025–August 2026) in
1. Executive summary CVE-2026-53660 affects OpenAM Community Edition through version 16.0.6, shipping the iPlanetDirectoryPro SSO cookie with HttpOnly=false and
1. Executive summary On 14 August 2026, the Qilin ransomware group publicly claimed a victim named "Connections," a Belgium-based organisation (domain
1. Executive summary On 14 August 2026, the actor "coinbasecartel" publicly claimed a ransomware attack against Turner and Townsend, a UK-headquartered
1. Executive summary On 2026-08-12, a cybercriminal using the alias "ZeroBytes" advertised a database claiming to contain records of more
1. Executive summary The HoneyMyte APT group (also associated with the MITRE-confirmed actor Mustang Panda, G0129) has significantly upgraded the CoolClient backdoor with