Programmatic feed

SecOpsAI JSON Feed

A structured JSON feed for applications, scripts, and automation workflows that consume SecOpsAI advisories and research.

Intelligence Categories
ORIGINAL RESEARCH 0 posts

No posts yet. Coming soon.

SECURITY NEWS 25 posts

25 posts with SecOpsAI context, detections, or operator guidance.

THREAT INTELLIGENCE 23 posts

23 posts with SecOpsAI context, detections, or operator guidance.

SUPPLY CHAIN 3 posts

3 posts with SecOpsAI context, detections, or operator guidance.

DETECTION ENGINEERING 1 post

1 posts with SecOpsAI context, detections, or operator guidance.

MITIGATION 1 post

1 posts with SecOpsAI context, detections, or operator guidance.

OPENCLAW 0 posts

No posts yet. Coming soon.

PRODUCT UPDATES 0 posts

No posts yet. Coming soon.

2026-07-15T18:04:45Z

VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys

Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. Description The tdeio

2026-07-15T18:04:45Z

Turning threat intelligence into decisive action with Defender Experts

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft Security Blog .

2026-07-11T21:47:53Z

CISA KEV: Balbooa Forms CVE-2026-56291

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

2026-07-11T21:47:53Z

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

GigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders detect and defend against similar threats. The post GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware appeared first on Microsoft Security Blog .

2026-07-09T07:02:27Z

CISA KEV: JoomShaper SP Page Builder CVE-2026-48908

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

2026-07-09T07:02:27Z

Protecting Microsoft at AI speed: How SFI proactively hardens our cloud

At Microsoft we encompass these security requirements, along with threat knowledge, and operational frameworks in our Secure Future Initiative (SFI), to guide what a well-defended cloud service looks like. But defining the requirements is only the start. Meeting the requirements means continuously evaluating our live services against them, at AI speed. The post Protecting Microsoft at AI speed: How SFI proactively hardens our cloud appeared first on Microsoft Security Blog .

2026-07-02T13:15:26Z

Unmasking the crawls with Attribution Business Insights

Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.

2026-06-25T22:40:03Z

Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms

Microsoft named a Leader in the Forrester Wave™: Endpoint Management Platforms, Q2 2026, with the highest scores in the current offering and strategy categories. The post Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms appeared first on Microsoft Security Blog .

2026-06-25T14:00:32Z

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them

On June 24, 2026, Microsoft’s Digital Crimes Unit (DCU) facilitated the takedown, suspension, and blocking of domains that formed the backbone of the StealC and Amadey infrastructure. This blog is a technical breakdown of StealC and Amadey. The post StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them appeared first on Microsoft Security Blog .

2026-06-04T00:28:14Z

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to protect your organization. The post Preinstall to persistence: Inside the Red Hat npm Miasma credential-st

2026-06-04T00:28:14Z

CISA KEV: Mirasvit Full Page Cache Warmer CVE-2026-45247

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

2026-06-01T20:20:55Z

CISA KEV: Oracle WebLogic Server CVE-2024-21182

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

2026-06-01T20:20:55Z

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target. The post The Gentlemen ransomware: Dissecting a self-propagating Go encryptor appeared first on Microsoft Security Blog .

2026-05-31T21:16:48Z

CISA KEV: Palo Alto Networks PAN-OS CVE-2026-0257

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.