Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary On 2026-06-28, the actor "stormous" publicly claimed a ransomware attack against eogb.co.uk, a UK-registered
1. Executive summary The FBI and CISA have published an updated public service announcement warning that a phishing campaign attributed to Russian Intelligence Services
1. Executive summary A phishing campaign delivering a Windows backdoor via a malicious Chrome extension is actively targeting users. The malware abuses Chrome Native
1. Executive summary CVE-2026-46331 ("pedit COW") is an out-of-bounds write vulnerability in the Linux kernel's traffic-
1. Executive summary A new wave of the Miasma/Mini Shai-Hulud supply-chain malware family has compromised at least 24 npm packages (LeoPlatform,
1. Executive summary Fortra researchers have identified "Mirage2FA," a phishing kit that uses short-lived HTML smuggling and obfuscated JavaScript loaders to
1. Executive summary A new backdoor tracked as Mistic (also tracked as MLTBackdoor) has been deployed in financially motivated intrusions since April 2026, targeting
1. Executive summary The Gamaredon Group (MITRE G0047) — a Russia-linked APT operation attributed to FSB state sponsorship — has reportedly upgraded its malware-loading
1. Executive summary The Bluekit phishing-as-a-service (PaaS) platform has added browser-in-the-middle (BitM) capabilities, replacing its previous adversary-in-
1. Executive summary Symantec and Carbon Black's Threat Hunter Team have identified a new backdoor dubbed Mistic (also tracked as MLTBackdoor by
1. Executive summary Google released Chrome 149.0.7827.196/197 (Windows/Mac) and 149.0.7827.196 (Linux), patching 18 vulnerabilities including four
1. Executive summary GitLab has released CE/EE security updates — versions 19.1.1, 19.0.3, and 18.11.6 — patching 13 vulnerabilities