~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
11 Sep 2026 Jeff Davies
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

1. Executive summary A social engineering campaign tracked since May 2026 has attackers calling and texting employees directly on their personal (BYOD) phones while

11 Sep 2026 Jeff Davies
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

1. Executive summary FinCEN has issued an alert to the U.S. financial industry alongside a study of more than 33,000 cyber fraud

11 Sep 2026 Jeff Davies
Traefik entrypoint header-name sanitization bypassed via request trailers

1. Executive summary Traefik v3.2.0 through v3.7.12 fails to apply its entrypoint header-name sanitization — aliasHeadersStrategy / underscoreHeadersStrategy in delete or

11 Sep 2026 Jeff Davies
Detect and disrupt AI-themed attacks with Microsoft Defender

1. Executive summary Microsoft Threat Intelligence reports a sustained wave of campaigns impersonating major AI brands — ChatGPT, Microsoft Copilot, DeepSeek and Claude — as lures

11 Sep 2026 Jeff Davies
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

1. Executive summary Anthropic reports disrupting a cyberespionage operation (activity window December 2025–August 2026) whose tradecraft and targeting match the Russian state-nexus

11 Sep 2026 Jeff Davies
We've got one word for it, and it's usually the wrong one

1. Executive summary Cisco Talos is disclosing a WebDAV-based infection chain — investigated after an incident at a Ukrainian government organisation — that delivers the

11 Sep 2026 Jeff Davies
AVEVA Pipeline Integrity Monitor

1. Executive summary CISA has republished AVEVA security bulletin AVEVA-2026-006 covering four vulnerabilities in AVEVA Pipeline Integrity Monitor (PIMBoards) affecting versions up

11 Sep 2026 Jeff Davies
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

1. Executive summary Cisco Talos has disclosed three distinct post-compromise activity clusters — two state-sponsored-linked and one crimeware/ransomware — actively exploiting two

11 Sep 2026 Jeff Davies
Ransomware: lockbit5 named alphaomega-eng.com (DE)

1. Executive summary On 10 September 2026, the ransomware operator tracked as "lockbit5" listed the German-registered domain alphaomega-eng.com on

11 Sep 2026 Jeff Davies
BlueMoon exploit kit turns Chrome and Windows flaws into attacks

1. Executive summary Proofpoint has documented a previously unobserved exploit kit, "BlueMoon," that chains two Chrome V8 JavaScript engine flaws with a

11 Sep 2026 Jeff Davies
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

1. Executive summary A China-linked actor tracked as UNC3569 exploited an unpatched design flaw in the Windows version of Sogou Input Method — the

11 Sep 2026 Jeff Davies
Check Point Patches Critical VPN Vulnerabilities

1. Executive summary On 11 September 2026, Check Point released patches for two critical (CVSS 9.8) vulnerabilities — CVE-2026-85102 (CWE-295, improper