Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 2026-07-20, the ransomware group "safepay" publicly listed the German IT services company cenesco.de as a
1. Executive summary The FakeGit campaign, disclosed by Island researchers, has created approximately 7,600 malicious GitHub repositories using 6,600 lookalike developer profiles
1. Executive summary A threat actor using the handle "ByteToBreach" breached Romania's National Agency for Cadastre and Real Estate Advertising
1. Executive summary Three malicious RubyGems packages — git_credential_manager (v2.8.0–2.8.3), Dendreo (v1.1.3, v1.1.4), and
1. Executive summary Researchers from the University of Louisville and the University of North Texas published CodeTracer, a forensic tool designed to trace harmful
1. Executive summary Two vulnerabilities in WordPress Core — CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in the
1. Executive summary WordPress Core versions 6.8 through 7.0.1 are affected by two vulnerabilities patched in the 7.0.2 security
1. Executive summary CVE-2026-63030 is a critical unauthenticated remote code execution (RCE) vulnerability in WordPress Core, exploitable via the WordPress REST API
1. Executive summary Volexity has published findings on a sophisticated intrusion campaign targeting SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, attributing the
1. Executive summary Checkmarx has identified seven malicious npm packages targeting the Vite JavaScript build tool ecosystem in a supply-chain campaign codenamed "
1. Executive summary Microsoft disclosed CVE-2026-58644 on July 14, 2026, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability affecting
1. Executive summary In April 2026, a threat cluster dubbed "CylindricalCanine" — described by Expel as a subgroup of the Chinese cybercrime actor