Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 28 July 2026, the ransomware group "anubis" publicly claimed a data breach against Prelys Courtage, a major mortgage
1. Executive summary An active email campaign distributing a multi-stage AutoIT payload injector has been observed since late July 2026. The attack chain
1. Executive summary LevelBlue reports a consistent and growing operational gap in EMEA financial services: employees are using unsanctioned generative AI platforms ("shadow
1. Executive summary JetBrains has disclosed CVE-2026-63077, a CRITICAL vulnerability (CVSS 9.8, CWE-502 — Deserialization of Untrusted Data) affecting all TeamCity
1. Executive summary CVE-2025-68686 is a MEDIUM-severity (CVSS 5.9, CVSS:3.1/AV:N/AC:H/PR:N/UI:N/
1. Executive summary A phishing campaign dubbed "Operation BlueDash" is targeting organisations with Microsoft Teams-themed "secure document" lures that
1. Executive summary Microsoft has disclosed two defects in Defender for Endpoint (MDE) on Linux arising from the 101.26042.x update train. The
1. Executive summary Progress Software has disclosed multiple high-severity vulnerabilities — including OS command injection, incorrect authorization, and missing authorization flaws — across LoadMaster, ECS
1. Executive summary CVE-2026-16812 is a CVSS 10.0 CRITICAL OS command injection vulnerability (CWE-78) in Arista VeloCloud Orchestrator (VCO) On-
1. Executive summary MedusaHVNC is a remote access trojan (RAT) offered as malware-as-a-service (MaaS) and promoted via a dedicated website and
1. Executive summary A proof-of-concept (PoC) exploit and technical details for CVE-2026-54121 (dubbed "Certighost") were publicly released on
1. Executive summary AWS has launched an AI-powered DevOps Agent feature for troubleshooting AWS Network Firewall incidents. The agent automates log inspection, firewall