Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A threat actor abused Anthropic's Claude Artifacts feature to host a fake Claude desktop-app download page on the
1. Executive summary Cisco Talos has published analysis of msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware-as-a-
1. Executive summary Cisco Talos has identified msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware-as-a-service (RaaS)
1. Executive summary On 2026-07-23, the Qilin ransomware group publicly named WellPerf (UK, www.wellperf.com) as a victim on its leak
1. Executive summary Check Point has released security updates addressing multiple vulnerabilities in Security Management and Multi-Domain Management (MDSM) products, including CVE-2026-
1. Executive summary A Brazilian banking trojan is actively targeting organisations in Portugal, exploiting the shared Portuguese-language attack surface to increase social-engineering
1. Executive summary A novel malware toolset dubbed "Sandworm_Mode" has been identified as an early example of threat actors exploiting trusted
1. Executive summary CVE-2026-50522 is a critical (CVSS 9.8) deserialization of untrusted data vulnerability in Microsoft Office SharePoint that permits an
1. Executive summary Check Point SmartConsole contains a critical improper authentication vulnerability (CVE-2026-16232, CVSS 9.1 CRITICAL, CWE-287) in its login
1. Executive summary On 2026-07-22, the Qilin ransomware operation publicly named Primeline Logistics (Ireland, www.primeline.ie) as a victim on its
1. Executive summary Active exploitation of CVE-2024-36401 (CVSS 9.8 CRITICAL, CWE-95/CWE-94) has been observed in the wild targeting
1. Executive summary On 22 July 2026, CISA, FBI, EPA and U.S. government partners published an update to a joint Cybersecurity Advisory (originally