Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary The Clop ransomware gang (also tracked as Cl0p) is actively exploiting CVE-2026-12569, a critical vulnerability (CVSS 9.3) in
1. Executive summary A Russia-linked threat actor tracked as Laundry Bear (aka Void Blizzard) has been conducting a year-long espionage campaign — ongoing
1. Executive summary On 23 July 2026, the UK NCSC and international partners publicly attributed a "zero-click" phishing campaign targeting Western
1. Executive summary Unit 42 has published details of a persistent cyberespionage campaign (tracked as CL-STA-1114) actively targeting unpatched Zimbra Collaboration Suite
1. Executive summary Recorded Future's Insikt Group published research identifying four new malware families — TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator
1. Executive summary A threat actor abused Anthropic's Claude Artifacts feature to host a fake Claude desktop-app download page on the
1. Executive summary Cisco Talos has published analysis of msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware-as-a-
1. Executive summary Cisco Talos has identified msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware-as-a-service (RaaS)
1. Executive summary On 2026-07-23, the Qilin ransomware group publicly named WellPerf (UK, www.wellperf.com) as a victim on its leak
1. Executive summary Check Point has released security updates addressing multiple vulnerabilities in Security Management and Multi-Domain Management (MDSM) products, including CVE-2026-
1. Executive summary A Brazilian banking trojan is actively targeting organisations in Portugal, exploiting the shared Portuguese-language attack surface to increase social-engineering
1. Executive summary A novel malware toolset dubbed "Sandworm_Mode" has been identified as an early example of threat actors exploiting trusted