Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary The UK NCSC, the US FBI and the Netherlands' General Intelligence and Security Service have published a joint advisory exposing
1. Executive summary On 2026-09-15, the ransomware brand "qilin" listed a Spanish victim, Geieg (www.geieg.cat), on its leak
1. Executive summary On 2026-09-12 Revolut confirmed that it disclosed sensitive customer records to an unauthorised third party who submitted fraudulent information
1. Executive summary On 1 September 2026 a China-nexus cluster tracked by Volexity as UTA0560 ran a spear-phishing campaign against multiple non-
1. Executive summary Cisco has disclosed CVE-2026-76461, a CVSS 9.8 CRITICAL SQL injection (CWE-89) in AsyncOS for Cisco Secure Email
1. Executive summary Between roughly 6 and 9 September 2026, the verified HBO Max Reddit account (u/hbomax) was compromised and used to run
1. Executive summary GitLab patched CVE-2026-85706 on 2026-09-10, a path traversal flaw (CWE-22) in the repository commits API affecting
1. Executive summary CVE-2026-76461 is a SQL injection flaw (CWE-89) in Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) that
1. Executive summary On 2026-09-14, the ransomware leak-site aggregator ransomware.live indexed a victim listing under the group name "lockbit5&
1. Executive summary WordPress.org is adding an automated security review of every plugin release before it is distributed through the WordPress.org update
1. Executive summary On 2026-09-14 Apple shipped its annual coordinated OS refresh — iOS/iPadOS 27, macOS 27 ("Golden Gate"), macOS
1. Executive summary The School District of Monroe (Wisconsin, USA) has disconnected its internet connectivity following a possible network security incident, with reported loss