Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 2026-09-16 CISA published Using Cyber Decoys to Strengthen Detection and Response, its first guide offering a detailed explanation
1. Executive summary Two critical-severity, unauthenticated code-injection vulnerabilities in The Events Calendar WordPress plugin — a component with more than 600,000 active
1. Executive summary The FBI, UK NCSC and Netherlands AIVD have published a joint advisory on CHOSEN BRICK, a Windows-only surveillance and data-
1. Executive summary Spain's data protection agency (AEPD) has reported the country's first personal data breach attributed to the actions
1. Executive summary Mandiant's September 2026 report describes an attacker who hijacked an active AI coding-assistant session at an unnamed SaaS
1. Executive summary CVE-2026-58704 is an improper authorization flaw in the cellular modem of Google Pixel devices, where a logic error may
1. Executive summary Malwarebytes has published a scam-hunting case study of a fake Avast "subscription renewed" page written in French and
1. Executive summary A critical authentication-bypass vulnerability in WSO2 API Manager, CVE-2026-5430, is reported to be under active exploitation in the
1. Executive summary A critical authentication bypass in WSO2 API Manager and related WSO2 gateway products — CVE-2026-5430, CVSS 10.0 (CRITICAL), CWE-
1. Executive summary A likely North Korean state-linked APT is reported to have used a previously undocumented Linux espionage toolkit to compromise load
1. Executive summary Elastic Security Labs has documented KREMLIN, a previously undocumented Brazilian banking malware toolkit delivered by an actor it tracks as REF9334
1. Executive summary Infoblox has published research arguing that Chinese-language casino and adult domains — a population it tracks at roughly 1.7 million