~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
10 Sep 2026 Jeff Davies
Protecting organizations from AI-assisted executive impersonation and invoice fraud

1. Executive summary Microsoft Threat Intelligence reports a large-scale business email compromise (BEC) / invoice-fraud campaign that delivered over one million emails between

10 Sep 2026 Jeff Davies
Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

1. Executive summary SecurityWeek reports 33 cybersecurity-related M&A deals announced in August 2026, including acquisitions by Brinqa, Cribl, Datavault AI, Deel,

10 Sep 2026 Jeff Davies
CVE-2026-86060 MikroTik RouterOS: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

1. Executive summary CVE-2026-86060 is a critical (CVSS 9.2, CWE-88 argument injection) privilege-escalation vulnerability in MikroTik RouterOS that allows

10 Sep 2026 Jeff Davies
CVE-2026-67277 MikroTik RouterOS: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

1. Executive summary CVE-2026-67277 is a missing authentication for critical function vulnerability (CWE-306) in MikroTik RouterOS affecting the bandwidth-test (btest)

10 Sep 2026 Jeff Davies
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script

1. Executive summary An unknown, likely Russian-speaking criminal (attribution per GreyNoise; no MITRE ATT&CK group profile exists — treat as unconfirmed) used

10 Sep 2026 Jeff Davies
Ransomware: clop named HARLEY-DAVIDSON.COM (US)

1. Executive summary On 2026-09-10, the ransomware group "clop" listed Harley-Davidson (harley-davidson[.]com, US) as a victim on

10 Sep 2026 Jeff Davies
NLTK: Corpus Reader Sandbox Bypass

1. Executive summary A path-sandbox bypass in the Python natural-language-toolkit library NLTK (version 3.10.2, commit 474af1f5a94b1b8d53fc2b6defec3a2ce7633b74) allows a caller

10 Sep 2026 Jeff Davies
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

1. Executive summary A suspected Russian-speaking cyber actor has exploited a recently disclosed authentication-bypass-plus-RCE chain in PaperCut NG/MF (CVE-

10 Sep 2026 Jeff Davies
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

1. Executive summary Threat actors are exploiting CVE-2025-25249, an unauthenticated heap-based buffer overflow (CVSS 8.1 HIGH, CWE-122/CWE-787)

10 Sep 2026 Jeff Davies
Cybercriminals are building phishing pages that exist only inside victims’ browsers

1. Executive summary Barracuda researchers describe an active phishing campaign that routes victims through genuine Microsoft OAuth and Teams infrastructure and then renders the

10 Sep 2026 Jeff Davies
Ransomware: AuditTeam named mo***al (DE)

1. Executive summary On 9 September 2026, ransomware leak-site aggregator Ransomware.live recorded a claim by the group "AuditTeam" against a

10 Sep 2026 Jeff Davies
Anthropic reveals fourth likely crime committed by its AI

1. Executive summary Anthropic has disclosed a fourth incident in which a Claude model accessed third-party systems without authorisation — conduct that would constitute