~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
19 Jul 2026 Jeff Davies
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

1. Executive summary CVE-2026-63030 is a critical unauthenticated remote code execution (RCE) vulnerability in WordPress Core, exploitable via the WordPress REST API

17 Jul 2026 Jeff Davies
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

1. Executive summary Volexity has published findings on a sophisticated intrusion campaign targeting SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, attributing the

17 Jul 2026 Jeff Davies
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

1. Executive summary Checkmarx has identified seven malicious npm packages targeting the Vite JavaScript build tool ecosystem in a supply-chain campaign codenamed "

17 Jul 2026 Jeff Davies
CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild

1. Executive summary Microsoft disclosed CVE-2026-58644 on July 14, 2026, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability affecting

17 Jul 2026 Jeff Davies
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

1. Executive summary In April 2026, a threat cluster dubbed "CylindricalCanine" — described by Expel as a subgroup of the Chinese cybercrime actor

17 Jul 2026 Jeff Davies
Ernst & Young discloses data breach after support system hack

1. Executive summary Ernst & Young (EY) has notified clients of a data breach stemming from the compromise of a third-party support ticket

17 Jul 2026 Jeff Davies
New North Korean campaign uses fake coding interviews to steal developer credentials

1. Executive summary Elastic Security Labs documented a new Contagious Interview campaign (tracked as REF9403) deploying OTTERCOOKIE-aligned malware via trojanized coding challenge repositories

17 Jul 2026 Jeff Davies
ACR Stealer: Two observed intrusion chains amid increased threat activity

1. Executive summary From late April to mid-June 2026, Microsoft Defender Experts observed two prevalent intrusion chains delivering ACR Stealer, an information-stealing

17 Jul 2026 Jeff Davies
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report

1. Executive summary Unit 42 published a supplementary analysis to its 2026 Global Incident Response (IR) Report on 16 July 2026, concluding that AI

17 Jul 2026 Jeff Davies
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

1. Executive summary Cisco Talos has disclosed a financially motivated campaign by threat actor UAT-11795 distributing trojanized installers for widely used software (MobaXterm,

16 Jul 2026 Jeff Davies
CVE-2026-25089 — Fortinet FortiSandbox: Fortinet FortiSandbox OS Command Injection Vulnerability

1. Executive summary CVE-2026-25089 is a critical (CVSS 9.8, CWE-78) OS command injection vulnerability in Fortinet FortiSandbox, FortiSandbox Cloud, and

16 Jul 2026 Jeff Davies
CVE-2026-58644 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

1. Executive summary CVE-2026-58644 is a critical (CVSS 9.8) deserialization of untrusted data vulnerability in Microsoft SharePoint Server, enabling an unauthenticated,