~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
09 Sep 2026 Jeff Davies
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

1. Executive summary Proofpoint has identified a previously undocumented exploit kit, "BlueMoon," that chains a V8 type confusion (CVE-2026-85046, CVSS

09 Sep 2026 Jeff Davies
Threat Matrix: Mapping threats across cloud web applications

1. Executive summary Microsoft has published a new MITRE ATT&CK-aligned "Cloud web applications threat matrix" cataloguing attack techniques against

09 Sep 2026 Jeff Davies
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

1. Executive summary Proofpoint reports that at least four espionage-motivated threat clusters — the majority with a suspected China nexus — deployed a previously undocumented

09 Sep 2026 Jeff Davies
09 Sep 2026 Jeff Davies
CVE-2026-19490 — Citrix NetScaler: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

1. Executive summary CVE-2026-19490 is a critical (CVSS 9.3) authentication bypass vulnerability in Citrix NetScaler ADC and NetScaler Gateway, exploitable remotely

09 Sep 2026 Jeff Davies
CVE-2026-87491 — Google Chromium V8: Google Chromium V8 Out of Bounds Write Vulnerability

1. Executive summary CVE-2026-87491 is an out-of-bounds write vulnerability (CWE-787) in Google Chromium V8, rated CVSS 8.8 HIGH,

09 Sep 2026 Jeff Davies
CVE-2025-25249 — Fortinet Multiple Products: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

1. Executive summary CVE-2025-25249 is a heap-based buffer overflow (CWE-122 / CWE-787) affecting Fortinet FortiOS, FortiSwitchManager and FortiSASE, rated CVSS

09 Sep 2026 Jeff Davies
Passkey-themed social engineering leads to identity and cloud compromise

1. Executive summary Microsoft Security Research is tracking active, multi-account cloud intrusions — observed since May 2026 — that begin with helpdesk-impersonation vishing and

09 Sep 2026 Jeff Davies
Akeyless adds real-time enforcement for AI agents in production

1. Executive summary Akeyless has announced general availability of Akeyless Agentic Runtime Authority, a real-time identity control layer that enforces intent-based access

09 Sep 2026 Jeff Davies
August 2026 CVE Landscape

1. Executive summary Recorded Future Insikt Group identified 73 high-impact vulnerabilities actively exploited or operationally weaponised in August 2026, 43 of them rated

09 Sep 2026 Jeff Davies
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

1. Executive summary A Chinese-language criminal group is compromising Brazilian government and education web servers and using them to host gambling-themed phishing

09 Sep 2026 Jeff Davies
Microsoft fixes record 964 flaws, including 2 exploited zero-days

1. Executive summary Microsoft's September 2026 Patch Tuesday is the largest single-day release on record: 964 customer-actionable CVEs (104 Critical,