Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary London property management firm City Relay has notified current and former landlords that intruders accessed its Metabase Cloud analytics instance twice,
1. Executive summary A previously unknown modular, multi-stage Windows crimeware framework — dubbed MovieReaper — has been distributed at scale since mid-August 2026 through
1. Executive summary On 15 September 2026 AWS confirmed that customer data and resources hosted exclusively in its Middle East (Bahrain) region (me-south-
1. Executive summary Cisco has disclosed CVE-2026-76460, an authentication bypass in an API of Cisco Identity Services Engine (ISE) and ISE Passive
1. Executive summary Attackers are actively exploiting CVE-2026-89026 (CVSS 9.3, Critical; CWE-321, Use of Hard-coded Cryptographic Key) in Issabel
1. Executive summary On 2026-09-16 the ransomware leak-site aggregator ransomware.live indexed a listing in which the group "qilin"
1. Executive summary The U.S. Coast Guard confirmed it boarded an oil tanker in the Gulf of Mexico on 21 August 2026 after
1. Executive summary A single source IP, 94.102.49.125 (IP Volume, AS202425), has been conducting HTTP reconnaissance against hospitality-sector web applications
1. Executive summary The Spanish Data Protection Agency (AEPD) has published details of what it describes as the first personal-data breach notification in
1. Executive summary CVE-2026-87886 is a high-severity incorrect default permissions flaw in the Acronis Backup plugin for cPanel & WHM and
1. Executive summary On 2026-09-16 the Akira ransomware group published a victim entry for "Manders" (country listed as GB) on
1. Executive summary On 2026-09-15, CVE-2026-76460 was published for Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector