~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
19 Sep 2026 Jeff Davies
CVE-2025-39682 Linux Kernel: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

1. Executive summary CVE-2025-39682 is a critical (CVSS 9.8, CWE-754) improper check for unusual or exceptional conditions vulnerability in the

19 Sep 2026 Jeff Davies
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

1. Executive summary The ShinyHunters extortion gang (MITRE G1057) claims to have breached the Clop ransomware operation's Tor-based data leak site,

19 Sep 2026 Jeff Davies
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

1. Executive summary SolarWinds has patched CVE-2026-28326, a hard-coded cryptographic key flaw (CWE-321) in Access Rights Manager (ARM) that permits

19 Sep 2026 Jeff Davies
Ransomware: lockbit5 named hygear.com (DE)

1. Executive summary On 18 September 2026 the ransomware operator using the name "lockbit5" listed hygear.com, a German hydrogen and industrial

19 Sep 2026 Jeff Davies
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

1. Executive summary On 17 September 2026 Microsoft patched 18 vulnerabilities across its Azure cloud portfolio and Copilot-branded AI products, the majority of

19 Sep 2026 Jeff Davies
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

1. Executive summary Zscaler ThreatLabz attributes a new campaign, Operation RapidRust, to Transparent Tribe (APT36), targeting government and defence entities in India and Afghanistan.

19 Sep 2026 Jeff Davies
Critical Orkes Conductor Vulnerability Exploited in Attacks

1. Executive summary CVE-2026-58138 is an unauthenticated remote code execution vulnerability in Orkes Conductor, an open source framework used to orchestrate microservices,

19 Sep 2026 Jeff Davies
New Android malware uses AI to steal bank logins and PINs

1. Executive summary Zimperium's zLabs has documented an Android banking Trojan, RatHat, that hands a live AI assistant control of the infected

19 Sep 2026 Jeff Davies
CVE-2026-53266 Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerability

1. Executive summary CVE-2026-53266 is a high-severity (CVSS 8.8) out-of-bounds write in the Linux kernel's ebtables

19 Sep 2026 Jeff Davies
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

1. Executive summary Microsoft has patched CVE-2026-85889, a CVSS 10.0 CRITICAL missing-authentication flaw (CWE-306) in Azure AI Foundry that

19 Sep 2026 Jeff Davies
CVE-2025-39964 Linux Kernel: Linux Kernel Race Condition Vulnerability

1. Executive summary CVE-2025-39964 is a race condition (CWE-362) in the Linux kernel's AF_ALG cryptographic socket interface: concurrent

19 Sep 2026 Jeff Davies
Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia

1. Executive summary Kaspersky reports that the cyberespionage group tracked as NightEagle (also APT-Q-95), active since at least 2023 and previously focused