Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Okta's Enterprise AI Index, drawing on anonymised sign-on data from over 20,000 organisations (June 2022–June 2026)
1. Executive summary Pillar Security researchers demonstrated sandbox escapes across four widely used AI coding agents — Cursor, OpenAI Codex CLI, Google Gemini CLI, and
1. Executive summary JADEPUFFER, an actor attributed by Sysdig to an autonomous LLM-driven AI agent (no MITRE ATT&CK profile exists for
1. Executive summary CVE-2026-53359 ("Januscape") is a HIGH-severity (CVSS 8.8) use-after-free vulnerability in the Linux KVM
1. Executive summary A critical code injection vulnerability (CVE-2026-6875, CVSS 9.5) in the ServiceNow AI Platform is being actively exploited in
1. Executive summary Kaspersky has published analysis of a new .NET Native AOT communication module (AzureCommunication.dll) within the Project CAV3RN cyberespionage framework, targeting
1. Executive summary Rapid7's MDR team discovered an exposed, misconfigured server functioning as a comprehensive malware delivery and QA lab, containing over
1. Executive summary A threat campaign dubbed "The TFF Trap" is using business email compromise (BEC) phishing as an initial access vector
1. Executive summary Group-IB has disclosed HOLLOWGRAPH, a targeted espionage implant that uses compromised Microsoft 365 mailboxes as a command-and-control (C2)
1. Executive summary CVE-2026-63030 (CVSS 9.8 CRITICAL, CWE-436) is an unauthenticated remote code execution vulnerability in WordPress Core, exploited via
1. Executive summary On 2026-07-20, the group "safepay" publicly listed wdk.de — the Frankfurt am Main-based association of German
1. Executive summary On 2026-07-20, the ransomware group "safepay" publicly claimed a victim, lbb-treuhand.de, a German tax consulting,