Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 2026-09-15, the ransomware leak-site index ransomware.live recorded the victim neumerkel-gmbh.de (Germany) as posted by
1. Executive summary On 2026-09-15, the ransomware leak-site indexer ransomware.live recorded a victim posting by a group calling itself "
1. Executive summary Apple has released its largest single patch cycle to date, addressing more than 260 CVEs across its operating systems, browsers and
1. Executive summary Censys has published an internet-wide measurement of hosts exposing the open-source Mythic command-and-control (C2) framework, identifying 131
1. Executive summary On 15 September 2026 the UK NCSC, the US FBI and the Netherlands AIVD issued a joint alert exposing CHOSEN BRICK,
1. Executive summary A malware-as-a-service (MaaS) offering marketed as "VectraRAT" is being advertised at approximately $250 per month, bundling
1. Executive summary On 2026-09-15 CISA and NIST published Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse:
1. Executive summary On 2026-09-15 CISA published ICSA-26-258-08 covering seven vulnerabilities in CareCam CM2507 IP cameras running firmware HMT.
1. Executive summary Siemens ProductCERT has published SSA-887643 (republished verbatim by CISA as ICSA-26-258-06) covering CVE-2026-80465, an improper-
1. Executive summary Siemens has published a fix for a reflected cross-site scripting (XSS) vulnerability in the authentication redirect flow (/auth/ endpoint) of
1. Executive summary Sophos' Counter Threat Unit (CTU) identified an advertisement posted on 24 August 2026 on the Exploit hacking forum by a
1. Executive summary A swarm of autonomous AI agents — reported by a three-person research team to be OpenAI's — flooded the RubyGems.