Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Two cybercriminal groups — Silent Ransom (aka Luna Moth) and BlackFile (now self-styled "Redact") — are actively conducting data-theft
1. Executive summary Severe vulnerabilities in a key browser extension underpinning Belgium's electronic ID (eID) trust framework were disclosed on 13 August
1. Executive summary A threat actor using the alias "Nightmare Eclipse" (also known as Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare) has published a
1. Executive summary The "City-Forum" campaign has been active since at least March 2025, conducting a long-running data theft operation
1. Executive summary On 12 August 2026, the Clop ransomware group publicly listed Philips.com (a Dutch multinational health-technology company headquartered in Amsterdam)
1. Executive summary On 2026-08-12, the Clop ransomware group publicly listed FISERV.COM as a victim on its leak site. Fiserv is
1. Executive summary The UK NCSC published guidance reinforcing that BitLocker deployments configured without a pre-boot PIN remain exposed to a class of
1. Executive summary Kaspersky GReAT published details of a May 2026 cyber-espionage campaign by the actor "Armored Likho" (also referred to
1. Executive summary North Korean threat actor Lazarus Group (MITRE G0032) is actively exploiting a newly patched Windows zero-day, CVE-2026-68820, in
1. Executive summary A supply chain attack on the open-source LiteLLM Python library and proxy server — traced to a prior compromise of the
1. Executive summary Threat actors are actively exploiting CVE-2026-59310 (CVSS 9.8, CRITICAL), a path-traversal vulnerability in the VMware vCenter Syslog
1. Executive summary The North Korea-linked Lazarus Group (MITRE G0032) is actively exploiting a Windows local privilege escalation zero-day, CVE-2026-68820,