The intelligence feedUpdated as material events develop
Analysis / Research / Guidance

The Briefing

Independent reporting on AI security, exploited vulnerabilities, and enterprise cyber risk. Built to help defenders understand what changed and what deserves action.

Latest intelligence

Current coverage

Browse the full archive
Claude Artifacts malware editorial scene with an office laptop, a sponsored search result glow, and a fake software installer leading to a hidden remote access trojan

Claude Artifacts Malware: Why a Real claude.ai Link Can Still Deliver a RAT

Claude Artifacts malware became a same-day AI security story on July 23, 2026, after new reporting showed attackers abusing a public artifact on the real claude.ai domain to distribute a fake Claude desktop installer tied to SectopRAT. The practical lesson is that a trusted AI domain, a sponsored search result, and a user-generated download page can combine into a high-conviction malware path that many employees would treat as normal.

Read intelligence ↗
Editorial scene of a rack-mounted workflow automation server with dense ethernet cables and a blank incident clipboard in a compact server room

Windmill Vulnerability: Why One Workflow Automation Flaw Can Expose Secrets Before Anyone Logs In

Windmill vulnerability CVE-2026-29059 became a same-day security story on July 22, 2026, after new reporting tied the workflow automation flaw to active exploitation. The practical lesson is that one exposed automation server can leak server files, secrets, and high-trust access paths long before defenders realize a background-jobs platform belongs on the urgent patch list.

Read intelligence ↗
Editorial desk scene with a dark work laptop, a plain USB drive, and a small lockbox representing USB device security at work

USB Drive Security at Work in 2026: A Practical Device-Control Checklist

USB drives and other removable media still create quiet risk in 2026 because one borrowed thumb drive can bypass browser, email, and SaaS controls entirely. This practical checklist shows small teams how to limit unknown media, tighten file-transfer workflows, scan exceptions, and stop convenience from turning a plug-in habit into a breach path.

Read intelligence ↗
ACR Stealer attacks editorial scene with an office laptop, hardware security key, stacked document folders, and a tense hand over a keyboard under a red warning light

ACR Stealer Attacks: Why ClickFix Now Targets Browser Tokens and Microsoft 365 Files

ACR Stealer attacks became a same-day security story on July 18, 2026, when public reporting highlighted a surge in ClickFix-driven intrusions stealing browser passwords, live session tokens, and Microsoft 365 files. The real lesson is not the malware brand. It is how one copied command can turn a normal workstation into a fast path for cloud account abuse and document theft.

Read intelligence ↗
Fairlife ransomware attack editorial scene with a stopped milk bottling line, stainless steel tanks, sealed crates, and a dark red emergency beacon in a dairy plant

Fairlife Ransomware Attack: Why a Production System Breach Becomes a Supply Chain Crisis

The Fairlife ransomware attack became a major July 17, 2026 cybersecurity story after Coca-Cola disclosed that production-related systems were affected and US output was temporarily suspended. The incident is a sharp reminder that when ransomware reaches plant operations, the real damage is not just encrypted files. It is lost production, strained recovery options, and a supply chain problem customers can actually feel.

Read intelligence ↗

Showing 55-63 of 262 articles