Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 5 August 2026, the actor "lockbit5" publicly claimed a ransomware attack against briggsplc[.]com, a UK-based engineering
1. Executive summary Connor Riley Moucka (26, of Kitchener, Ontario) pleaded guilty on 5 August 2026 in a Washington state federal court to computer
1. Executive summary CVE-2026-9198 is a critical (CVSS 9.8) unauthenticated code injection vulnerability in IBM Langflow OSS versions 1.0.0
1. Executive summary CVE-2026-34486 is a missing encryption of sensitive data vulnerability (CVSS 7.5 HIGH) in Apache Tomcat, arising because the
1. Executive summary On 4 August 2026, the Qilin ransomware operation publicly listed Galvin Brothers (Ireland, www.galvinbrothers.com) as a victim on its
1. Executive summary The commercial phishing-as-a-service (PhaaS) toolkit Greatness has added device code phishing capabilities, abusing the legitimate OAuth 2.0
1. Executive summary An active, multi-wave phishing campaign codenamed SMOKE#SCREEN is using social engineering lures themed around fake Adobe and Zoom software
1. Executive summary On 4 August 2026, Microsoft announced an expansion of its Zero Trust for AI strategy, introducing a new AI-focused Zero
1. Executive summary Microsoft has disclosed an incident at QNET (a global direct-selling company) in which Microsoft Defender for Endpoint (MDE) automatically isolated
1. Executive summary On 4 August 2026, NCSC CTO Ollie Whitehouse issued a public statement acknowledging "recent incidents of frontier AI models carrying
1. Executive summary Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including
1. Executive summary The UK AI Security Institute (AISI) has published findings from cyber-security evaluations in which AI agents, operating with internet access