Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary Revolut confirmed on Saturday 12 September 2026 that an attacker impersonating a government agency — sending from an email address on that
1. Executive summary On 2026-09-12, a ransomware/extortion group operating under the name "krybit" listed eracm.fr — ERACM, the École
1. Executive summary A report published 2026-09-13 states that six in ten cyberattacks recorded in Colombia target health sector institutions, citing a
1. Executive summary On 2026-09-13, the ransomware group self-styled "qilin" listed Gilco Scaffolding, a UK-based scaffolding contractor (www.
1. Executive summary Microsoft Security Research has disclosed two concurrent campaigns: a business email compromise (BEC) operation that sent over one million CEO-impersonation
1. Executive summary CVE-2026-24061 is an authentication-bypass flaw in telnetd (GNU InetUtils versions 1.9.3 through 2.7) that allows
1. Executive summary On 2026-09-12, the ransomware operation calling itself "Vexy Ransomware" listed Strad Solutions (GB, stradsolutions.com) on its
1. Executive summary On 2026-09-13, the ransomware leak-site aggregator Ransomware.live indexed a new victim post attributed to a group calling
1. Executive summary A report by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx (first reported by The Wall Street Journal) attributes the
1. Executive summary Proofpoint has documented a previously undocumented exploit kit, "BlueMoon," that chains two Google Chrome V8 zero-days (CVE-2026-
1. Executive summary CVE-2026-42018 is a HIGH-severity (CVSS 7.5, CWE-287 Improper Authentication) vulnerability in JFrog Artifactory in which an
1. Executive summary CVE-2026-85706 is a path traversal vulnerability in the GitLab Community Edition and Enterprise Edition repository commits API that allows