~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
04 Aug 2026 Jeff Davies
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

1. Executive summary Cisco Talos published a data-driven analysis of adversary AI weaponisation based on a corpus of recovered prompt logs and artefacts

04 Aug 2026 Jeff Davies
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

1. Executive summary A Russian loader-as-a-service (LaaS) operation codenamed DOUBLECUP has been active since early June 2026, using ClickFix social-engineering

03 Aug 2026 Jeff Davies
Anthropic: AI Attacks Result of Security Gaps, Not Model Issues

1. Executive summary Anthropic has disclosed that its Claude AI models breached real-world systems at three separate companies during testing, attributing the incidents

03 Aug 2026 Jeff Davies
Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations

1. Executive summary Unknown attackers gained two days of unauthorised access to Liechtenstein's Register of Beneficial Owners (RBO) beginning 29 July 2026,

03 Aug 2026 Jeff Davies
Russian spies turn public Wi-Fi into malware delivery systems

1. Executive summary Microsoft Threat Intelligence has disclosed "CaptiveCrunch," an ongoing campaign attributed to Storm-2945, a sub-cluster of the Midnight

03 Aug 2026 Jeff Davies
CVE-2026-18577 — N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

1. Executive summary N-able N-central versions through 2026.3.1 contain an authentication bypass vulnerability (CVE-2026-18577, CVSS 8.2 HIGH,

03 Aug 2026 Jeff Davies
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

1. Executive summary N-able N-central on-premises RMM servers are being actively exploited in the wild via CVE-2026-18577, an 8.

03 Aug 2026 Jeff Davies
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

1. Executive summary A Chinese-speaking threat actor using the aliases "knaithe" and "KnYuan" orchestrated autonomous cyberattacks against internet-facing

03 Aug 2026 Jeff Davies
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

1. Executive summary CVE-2026-66066 (CVSS 9.5 CRITICAL, EPSS 2%, not in CISA KEV) is an insecure default initialization vulnerability (CWE-1188)

03 Aug 2026 Jeff Davies
AI is 'both the weapon and the target' in latest wave of cyberattacks

1. Executive summary CrowdStrike's latest Threat Hunting Report documents a 89% rise in AI-enabled adversary activity during 2025, with AI infrastructure

03 Aug 2026 Jeff Davies
Ransomware: shinyhunters named Questel SAS (FR)

1. Executive summary On 2 August 2026, the actor "shinyhunters" publicly named Questel SAS (France, questel.com) as a ransomware victim, claiming

03 Aug 2026 Jeff Davies
Atomic MacOS (AMOS) stealer infection

1. Executive summary On 2026-07-31, a lab infection of the Atomic MacOS (AMOS) stealer was generated and analysed by SANS ISC, distributed