Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Check Point Research has published analysis of an ongoing Operation Dream Job campaign active since early 2026, primarily targeting the global
1. Executive summary CVE-2026-72898 is a CVSS 10.0 CRITICAL SQL injection vulnerability (CWE-89) in Metabase, the open-source business intelligence
1. Executive summary CVE-2026-68820 is a use-after-free vulnerability (CVSS 7.0, HIGH) in the Windows Ancillary Function Driver for WinSock
1. Executive summary Microsoft's August 2026 Patch Tuesday addresses 418 vulnerabilities across its product portfolio, with 62 rated critical. One vulnerability is
1. Executive summary CVE-2026-20349 is a HIGH-severity (CVSS 8.6) heap inspection vulnerability in the Remote Access SSL VPN service of
1. Executive summary OpenAI has launched GPT-5.6-Cyber, a cybersecurity-focused AI model with significantly reduced refusal rates for dual-use offensive
1. Executive summary CISA, FBI, NSA, DC3, USSS, and the Republic of Korea's KNPA published a joint #StopRansomware advisory on 10 August
1. Executive summary Microsoft has disclosed that the financially motivated actor Storm-1175 — assessed as China-linked but with no MITRE ATT&CK
1. Executive summary North Korean state-sponsored actor Kimsuky (MITRE G0094) is operating local large language model (LLM) environments and integrating AI capabilities into
1. Executive summary Microsoft Threat Intelligence has published a detailed technical analysis of DeadLock, a Rust-based ransomware encryptor in active deployment since July
1. Executive summary Levi Strauss is investigating a data breach after attackers used social engineering to access three employees' work computers and exfiltrate
1. Executive summary At DEF CON, Israeli startup Tenet demonstrated "Ghostjacking," a prompt-injection technique that plants malicious instructions inside logs and