Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A supply-chain compromise originating in Aqua Security's Trivy scanner — not the LiteLLM PyPI package as initially reported — affected
1. Executive summary RingCentral has disclosed a data breach affecting approximately 1.6 million individuals, resulting from a "sophisticated social engineering campaign"
1. Executive summary Intruder's 2026 Cloud Security Index report finds that weak identity and access management (IAM) controls and missing logging/alerting
1. Executive summary Jamf Threat Labs has disclosed AmnesiaStealer, a Rust-based macOS infostealer distributed via a counterfeit GitHub download page using ClickFix social-
1. Executive summary Recorded Future / Insikt Group published analysis of 24 threat actors advertising malware crypting services, identifying a competitive, reputation-driven criminal market
1. Executive summary Check Point Research's Q2 2026 ransomware landscape report records 2,139 victims on data-leak sites — flat quarter-over-
1. Executive summary A persistent cross-site scripting (XSS) vulnerability — CVE-2026-34491, CVSS v3.1 8.0 (HIGH) / v4.0 8.6 (HIGH)
1. Executive summary On 12 August 2026, the clop ransomware group publicly claimed a victim identified as "SHELL.COM (August 2026)" with
1. Executive summary Siemens has disclosed a critical OS command injection vulnerability (CVSS 3.1: 9.1, CRITICAL) in Siveillance Video Management Servers, traced
1. Executive summary CISA published ICS advisory ICSA-26-225-03 disclosing two vulnerabilities in Johnson Controls Inc. (JCI) Airwall (versions ≤4.0.4)
1. Executive summary Cisco Talos has disclosed "JWR," a previously undocumented real-time phishing-as-a-service (PhaaS) framework and likely variant
1. Executive summary Cisco Talos has published a detailed analysis of "JWR," an undocumented, real-time phishing-as-a-service (PhaaS) framework