~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
16 Jul 2026 Jeff Davies
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

1. Executive summary ClickLock Stealer is a previously undocumented macOS infostealer detailed by Group-IB, active since approximately May 2026, with at least 100

16 Jul 2026 Jeff Davies
New OkoBot framework deploys 20 payloads to steal data, crypto

1. Executive summary Kaspersky GReAT has published details of "OkoBot," a sophisticated Windows malware framework active since at least March 2025 that

16 Jul 2026 Jeff Davies
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

1. Executive summary CISA has confirmed active in-the-wild exploitation of four Microsoft SharePoint Server vulnerabilities — CVE-2026-32201 (CVSS 6.5 MEDIUM)

16 Jul 2026 Jeff Davies
CVE-2026-39808 — Fortinet FortiSandbox: Fortinet FortiSandbox OS Command Injection Vulnerability

1. Executive summary Fortinet FortiSandbox versions 4.4.0 through 4.4.8 contain CVE-2026-39808, a critical (CVSS 9.8) OS command

16 Jul 2026 Jeff Davies
Ransomware: incransom named asa-international.com (GB)

1. Executive summary On 16 July 2026, the ransomware group "incransom" publicly listed ASA International (asa-international.com) as a victim on

16 Jul 2026 Jeff Davies
Claude Chrome extension flaw lets malicious extensions trigger AI actions

1. Executive summary A flaw in Anthropic's Claude for Chrome browser extension allows a malicious extension co-installed in the same browser

16 Jul 2026 Jeff Davies
Begun, the Patch Wars have

1. Executive summary Cisco Talos has disclosed an active, financially motivated campaign by actor "UAT-11795" (no MITRE ATT&CK profile

16 Jul 2026 Jeff Davies
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

1. Executive summary Elastic Security Labs has published a technical report on TELEPUZ, a modular, C-based Windows malware offered under a malware-as-

16 Jul 2026 Jeff Davies
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

1. Executive summary Researchers from Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft published a paper on 6 July 2026 detailing

16 Jul 2026 Jeff Davies
Russian hackers trojanize WebEx, Zoom apps to push Starland malware

1. Executive summary A financially motivated Russian threat actor tracked as "UAT-11795" is distributing trojanized installers for common enterprise and developer

16 Jul 2026 Jeff Davies
New Spirals ransomware encrypts victim network in under 24 hours

1. Executive summary A new ransomware actor dubbed "Spirals" completed a full intrusion cycle — from initial access through data theft to file

16 Jul 2026 Jeff Davies
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities

1. Executive summary F5 released an out-of-band security rollout on 16 July 2026 patching eight vulnerabilities across NGINX Open Source, NGINX Plus,