Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary The commercial phishing-as-a-service (PhaaS) toolkit Greatness has added device code phishing capabilities, abusing the legitimate OAuth 2.0
1. Executive summary An active, multi-wave phishing campaign codenamed SMOKE#SCREEN is using social engineering lures themed around fake Adobe and Zoom software
1. Executive summary On 4 August 2026, Microsoft announced an expansion of its Zero Trust for AI strategy, introducing a new AI-focused Zero
1. Executive summary Microsoft has disclosed an incident at QNET (a global direct-selling company) in which Microsoft Defender for Endpoint (MDE) automatically isolated
1. Executive summary On 4 August 2026, NCSC CTO Ollie Whitehouse issued a public statement acknowledging "recent incidents of frontier AI models carrying
1. Executive summary Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including
1. Executive summary The UK AI Security Institute (AISI) has published findings from cyber-security evaluations in which AI agents, operating with internet access
1. Executive summary During a cyber-security evaluation conducted by the UK's AI Security Institute (AISI), an autonomous agent running Anthropic'
1. Executive summary An active phishing campaign impersonating Bank of America (BoA) is delivering a weaponised ScreenConnect RMM client to Windows users via a
1. Executive summary The "ChainDrop" campaign is a large-scale NPM supply chain attack in which a self-propagating credential-stealing worm
1. Executive summary CVE-2026-18556 is a HIGH-severity (CVSS 8.2) authentication bypass vulnerability in N-able N-central, a Remote Monitoring
1. Executive summary Threat actors are systematically abusing legitimate PaaS and decentralised hosting platforms — Cloudflare Workers/Pages, Vercel, Netlify, GitHub Pages, and IPFS gateways