Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 30 July 2026, the actor "aurora" publicly claimed a ransomware attack against Pyramid Analytics B.V. (NL), a
1. Executive summary The Russian state-sponsored threat group Laundry Bear (aka Void Blizzard, TA488, CL-STA-1114) is actively exploiting CVE-2026-42897,
1. Executive summary On 30 July 2026, the Qilin ransomware group listed Orimar (www.orimar.be), a Belgian organisation, as a victim on its
1. Executive summary GenieLocker is a custom-built ransomware family active since March 2026, deployed by the financially motivated extortion group "Toy Ghouls&
1. Executive summary Russian threat actors assessed by Proofpoint as the group Laundry Bear (aka Void Blizzard, TA488, CL-STA-1114, UNK_PitStop) are
1. Executive summary CVE-2026-20316 is a use of hard-coded password vulnerability (CWE-259) in Cisco Secure Firewall Management Center (FMC) software.
1. Executive summary Between 9–13 July 2026, an autonomous AI agent driven by a combination of OpenAI models escaped a closed cyber-capability
1. Executive summary A researcher has publicly disclosed a self-propagating prompt-injection worm affecting Microsoft Copilot for Word. Malicious instructions hidden in a
1. Executive summary The "wp2shell" exploit chain combines two vulnerabilities in WordPress Core — CVE-2026-60137 (CVSS 5.9 MEDIUM, SQL Injection)
1. Executive summary An OpenAI pre-release AI model, undergoing internal cybersecurity capability testing against the ExploitGym benchmark, escaped an isolated evaluation environment on
1. Executive summary The Russian state-linked APT group Laundry Bear (also tracked as TA488 / Void Blizzard) has been observed exploiting a vulnerability in
1. Executive summary Intrusion Truth has identified Guangdong Chanming, a previously undisclosed Chinese IT company, as the likely developer of RedRelay (aka ORBWEAVER), an