Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 2026-06-29, ransomware tracking site ransomware.live published a victim listing naming Bristol Place (bristolplace.net, GB) as a
1. Executive summary On 2026-06-29, the ransomware operator/group "qilin" publicly claimed a ransomware attack against Gsma, an organisation based
1. Executive summary On or around 11 June 2026, threat actors exploited a compromised legacy credential associated with Klue's Salesforce integration to
1. Executive summary Security researchers at Mozilla's Zero Day Investigative Network (0DIN) have demonstrated a proof-of-concept attack that abuses Anthropic&
1. Executive summary Microsoft's security team has removed 119 malicious Edge extensions from the official Microsoft Edge Add-ons store that were
1. Executive summary On 2026-06-28, the actor "stormous" publicly claimed a ransomware attack against eogb.co.uk, a UK-registered
1. Executive summary The FBI and CISA have published an updated public service announcement warning that a phishing campaign attributed to Russian Intelligence Services
1. Executive summary A phishing campaign delivering a Windows backdoor via a malicious Chrome extension is actively targeting users. The malware abuses Chrome Native
1. Executive summary CVE-2026-46331 ("pedit COW") is an out-of-bounds write vulnerability in the Linux kernel's traffic-
1. Executive summary A new wave of the Miasma/Mini Shai-Hulud supply-chain malware family has compromised at least 24 npm packages (LeoPlatform,
1. Executive summary Fortra researchers have identified "Mirage2FA," a phishing kit that uses short-lived HTML smuggling and obfuscated JavaScript loaders to
1. Executive summary A new backdoor tracked as Mistic (also tracked as MLTBackdoor) has been deployed in financially motivated intrusions since April 2026, targeting