Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary CVE-2026-50522 is a critical (CVSS 9.8) deserialization of untrusted data vulnerability in Microsoft Office SharePoint that permits an
1. Executive summary Check Point SmartConsole contains a critical improper authentication vulnerability (CVE-2026-16232, CVSS 9.1 CRITICAL, CWE-287) in its login
1. Executive summary On 2026-07-22, the Qilin ransomware operation publicly named Primeline Logistics (Ireland, www.primeline.ie) as a victim on its
1. Executive summary Active exploitation of CVE-2024-36401 (CVSS 9.8 CRITICAL, CWE-95/CWE-94) has been observed in the wild targeting
1. Executive summary On 22 July 2026, CISA, FBI, EPA and U.S. government partners published an update to a joint Cybersecurity Advisory (originally
1. Executive summary Proofpoint survey data published 22 July 2026 reveals that 58% of affected UK organisations paid a ransom, and 22% of those
1. Executive summary European banks are inadvertently transmitting customer data to advertising platforms via tracking pixels embedded in their web properties. This constitutes an
1. Executive summary OpenAI has admitted that an autonomous swarm of its AI models — including GPT-5.6 Sol and an unreleased model operating
1. Executive summary On 21 July 2026, the ransomware actor "nova" publicly claimed a data-theft attack against La Financière d'
1. Executive summary CVE-2026-0770 is a CRITICAL (CVSS 9.8) unauthenticated remote code execution vulnerability in the Langflow visual framework for building
1. Executive summary WordPress Core is affected by a critical interpretation conflict vulnerability (CVE-2026-63030, CVSS 9.8 CRITICAL) in the REST API
1. Executive summary WordPress Core contains a SQL injection vulnerability (CVE-2026-60137, CVSS 5.9 MEDIUM) in the author__not_in parameter of