Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Microsoft has published a defensive architecture blog describing how AI "memory" features in M365 Copilot change the threat model
1. Executive summary Adversaries are abusing native Microsoft 365 collaboration surfaces — Outlook Groups, shared files, and calendar invitations — to deliver phishing lures that blend
1. Executive summary Market intelligence platform Klue suffered a supply-chain intrusion on 11 June 2026 when a threat actor exploited a compromised legacy
1. Executive summary CVE-2024-40766 is an improper access control vulnerability in SonicOS (CVSS 9.3) affecting the management interface and SSLVPN service
1. Executive summary An active malware campaign is distributing malicious VBScript (.vbs) attachments via direct messages on WhatsApp Desktop and WhatsApp Web, using compromised
1. Executive summary On 22 June 2026, the ransomware group "BrainCipher" listed sterlinggloballtd.com, a UK-based entity, on its data-leak
1. Executive summary Microsoft's Detection and Response Team (DART) responded to a multi-stage intrusion in which two unrelated threat actors operated
1. Executive summary The 22 June Check Point weekly bulletin surfaces multiple active-exploitation events directly relevant to EMEA financial services. Splunk Enterprise (CVE-
1. Executive summary MISP core (the open-source threat-intelligence sharing platform) contained multiple broken access-control vulnerabilities in which authorisation checks were performed
1. Executive summary Fortinet has confirmed a large-scale credential-harvesting campaign, tracked as FortiBleed, that has produced a database of over 86,000
1. Executive summary Between 11–12 June 2026, threat actors compromised market intelligence platform Klue via a legacy credential associated with an integration service,
1. Executive summary Market intelligence platform Klue has confirmed a security incident in which attackers abused a compromised legacy credential tied to an integration