Security Feed
Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.
1. Executive summary CISA has published an advisory detailing three local vulnerabilities in Rockwell Automation Studio 5000 Logix Designer. The flaws (CVE-2026-9108,
1. Executive summary German authorities (ZIT and BKA), supported by the US and Indonesia, have dismantled the primary infrastructure of the Kratos phishing-as-
1. Executive summary CrowdStrike has published analysis of SANDWORM_MODE, a multi-stage npm supply chain worm first documented by Socket.dev in February
1. Executive summary A path traversal vulnerability (CVE-2026-15724) affects Progress ShareFile Storage Zones Controller in all versions prior to 5.12.5
1. Executive summary German (ZIT/BKA) and U.S. law enforcement dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform,
1. Executive summary Okta's Enterprise AI Index, drawing on anonymised sign-on data from over 20,000 organisations (June 2022–June 2026)
1. Executive summary Pillar Security researchers demonstrated sandbox escapes across four widely used AI coding agents — Cursor, OpenAI Codex CLI, Google Gemini CLI, and
1. Executive summary JADEPUFFER, an actor attributed by Sysdig to an autonomous LLM-driven AI agent (no MITRE ATT&CK profile exists for
1. Executive summary CVE-2026-53359 ("Januscape") is a HIGH-severity (CVSS 8.8) use-after-free vulnerability in the Linux KVM
1. Executive summary A critical code injection vulnerability (CVE-2026-6875, CVSS 9.5) in the ServiceNow AI Platform is being actively exploited in
1. Executive summary Kaspersky has published analysis of a new .NET Native AOT communication module (AzureCommunication.dll) within the Project CAV3RN cyberespionage framework, targeting
1. Executive summary Rapid7's MDR team discovered an exposed, misconfigured server functioning as a comprehensive malware delivery and QA lab, containing over