Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 28 July 2026, the Qilin ransomware group publicly claimed a victim named "Hoc" (domain: www.hocltd.com), a
1. Executive summary JFrog has released patches for eight zero-day vulnerabilities in self-hosted Artifactory installations (CVE-2026-65617 through CVE-2026-65924)
1. Executive summary CAF Bank, a UK charitable foundation-owned bank serving 14,000 charity customers and holding £1.45 billion in deposits, has
1. Executive summary CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol, is actively exposing authentication password hashes from internet-facing
1. Executive summary Cisco Talos published its Q2 2026 IR trends report, identifying phishing as the dominant initial-access vector (present in >50%
1. Executive summary Apple shipped a July 2026 security patch round covering iOS/iPadOS 26.6, macOS Tahoe 26.6, macOS Sequoia 15.7.
1. Executive summary Multiple "confused deputy" vulnerabilities persist in Google Cloud Platform (GCP) and Microsoft Azure, enabling attackers to acquire administrative-level
1. Executive summary A critical unauthenticated remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) in Alibaba's FastJson 1.x library
1. Executive summary On 2026-07-27, the ransomware group "safepay" listed the German organisation paritaet-nrw[.]org on its victim site.
1. Executive summary A working proof-of-concept (PoC) exploit for CVE-2026-54121, dubbed "Certighost," has been publicly released, demonstrating how
1. Executive summary A maximum-severity OS command injection vulnerability, CVE-2026-16812 (CVSS 10.0), in Arista VeloCloud Orchestrator (VCO) on-premises deployments
1. Executive summary On 28 July 2026, the ransomware group "anubis" publicly claimed a data breach against Prelys Courtage, a major mortgage