Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary A critical unauthenticated arbitrary file upload vulnerability in the premium WordPress plugin WooCommerce Wholesale Lead Capture (approx. 6,000 active installations)
1. Executive summary Between 5 and 12 May 2026, a swarm of autonomous AI agents — attributed by a three-person research team to OpenAI&
1. Executive summary Google has begun routing some search-result links through opaque google.com/goto?url=... redirects, where the url parameter uses a
1. Executive summary GitLab patched CVE-2026-85706 — a CVSS 10.0 CRITICAL path traversal (CWE-22) in the repository commits API of GitLab
1. Executive summary China’s Ministry of Foreign Affairs publicly rejected Anthropic CEO Dario Amodei’s call for continued US restrictions on advanced AI
1. Executive summary GitLab patched a critical authentication-bypass and file-placement flaw, tracked as CVE-2026-85706, on 10 September 2026; CISA added
1. Executive summary Three authentication-related flaws in JFrog Artifactory — CVE-2026-42018, CVE-2026-42016 and CVE-2026-82329 — have been exploited in
1. Executive summary Check Point Research's weekly bulletin for 14 September 2026 covers a Microsoft September Patch Tuesday of 974 vulnerabilities including
1. Executive summary This item is not a vulnerability, breach or campaign report: it is a defensive research publication from Unit 42 describing a
1. Executive summary The UK government has expanded passkey authentication across GOV.UK One Login to a user base of more than 23 million,
1. Executive summary Telus, one of Canada's largest telecom providers, is notifying an undisclosed number of consumer telecom customers that their accounts
1. Executive summary On 10 September 2026 GitLab published an emergency patch release for CVE-2026-85706, a path traversal flaw (CWE-22) in