Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A vulnerability in the flask_security.utils.validate_redirect_url() function allows an attacker to bypass redirect URL validation when subdomain
1. Executive summary OpenClaw's ClawHub marketplace has been found hosting five malicious "skills" (agent plugins) that bypassed both VirusTotal and
1. Executive summary SentinelLABS has disclosed a Rust-written macOS implant and infostealer, tracked as macOS.Gaslight, that combines conventional macOS tradecraft with a
1. Executive summary Market intelligence platform Klue disclosed on 19 June 2026 that an attacker obtained OAuth tokens used to connect Klue to customer
1. Executive summary A financially motivated, Russian-speaking initial access broker (IAB) — operating under the handle SantaAd per Palo Alto Networks Unit 42 — has
1. Executive summary A 29-year-old heap overread vulnerability in the Squid open-source caching proxy, tracked as CVE-2026-47729 and dubbed
1. Executive summary A new macOS ClickFix campaign uses fake CAPTCHA pages to trick users into pasting a Terminal command that silently downloads, mounts,
1. Executive summary Law enforcement action against the SocGholish malware-as-a-service operation has been reported, drawing attention to the continued use of
1. Executive summary On 12 June 2026, LastPass was notified that market-intelligence platform Klue had suffered a security incident in which an attacker
1. Executive summary A financially motivated, Russian-speaking initial access broker (IAB) has been conducting a large-scale credential-harvesting campaign — dubbed FortiBleed — against
1. Executive summary A social-engineering campaign targeting software developers via fake LinkedIn recruiter profiles attempted to deliver a backdoored Node.js repository that
1. Executive summary A SIM swap attack — in which a threat actor convinces or coerces a mobile carrier's staff to port a