News
Security advisories, vendor updates and industry trends
A live reading list assembled from the organisations that publish the information themselves: national cyber defence agencies, vendor security response teams and platform engineering groups. Every headline links straight to the original notice, and every CVE identifier links to its entry in the National Vulnerability Database.
Reading the source feeds.
Where these items come from
Advisory
CISA: Cybersecurity advisories
Alerts, ICS advisories and joint advisories issued by the United States Cybersecurity and Infrastructure Security Agency.
Advisory
NCSC UK: News and threat reports
Guidance, threat reports and alerts from the United Kingdom National Cyber Security Centre.
Advisory
SANS ISC: Internet Storm Center diaries
Daily practitioner analysis of live scanning activity, exploitation attempts and malware samples.
Advisory
Canonical: Ubuntu security notices
Package level fixes for Ubuntu server and desktop, mapped to CVE identifiers.
Vendor update
Microsoft: Microsoft Security blog
Threat intelligence, Entra and Defender product direction, and monthly servicing context from Microsoft.
Vendor update
AWS: Security bulletins
Issues affecting AWS services, shared responsibility notes and customer actions.
Vendor update
Google: Online Security blog
Chrome, Android and Workspace security engineering, plus platform wide cryptography changes.
Industry trend
Google Project Zero: Project Zero research
Deep vulnerability research on widely deployed software, published after disclosure.
Industry trend
Cloudflare: Cloudflare blog
Internet scale traffic analysis, outage post mortems, DDoS trends and protocol adoption data.
Industry trend
CNCF: Kubernetes blog
Release notes, deprecations and security posture changes for Kubernetes itself.
Vendor update
Red Hat: Red Hat security blog
Linux platform hardening, supply chain and enterprise patching practice.
How to turn an advisory into an action
An advisory on its own is information. These four steps are what turn it into a change in your estate.
- Establish exposure before urgency. Match the affected product, version and configuration against your own inventory rather than the headline severity.
- Check whether the vulnerability is being exploited. The CISA Known Exploited Vulnerabilities catalogue is the reference point, and it carries remediation due dates for federal agencies that make a reasonable private sector benchmark.
- Read the vendor notice, not only the summary. Mitigations, workarounds and the order of upgrade steps live in the vendor advisory.
- Record the decision. Patched, mitigated, not applicable or accepted, with the evidence, so the next audit and the next advisory both have a starting point.
The control expectations behind those steps are set out in control baselines and the attacker behaviour in threat techniques.
