Today’s Briefing
A North Korea-nexus threat actor compromised the widely used Axios NPM package in a supply chain attack, while a separate campaign designated UNC6692 deployed a custom malware suite through social engineering. Six critical Adobe vulnerabilities appeared on the watchlist today, five affecting ColdFusion (CVE-2026-48327, CVE-2026-48325, CVE-2026-48324, CVE-2026-48322, CVE-2026-48321) including SQL injection, code injection, and authentication bypass flaws that permit remote code execution without user interaction, and one affecting Illustrator (CVE-2026-48334) requiring user interaction.
Top Stories
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.
Get the brief at 07:00, every weekday.
The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.