~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
09 Sep 2026 Jeff Davies
AI-Infra-Guard: Open-source security scanner for AI systems

1. Executive summary Tencent's Zhuque Lab has released AI-Infra-Guard, a free, open-source security scanner for AI infrastructure, available on

09 Sep 2026 Jeff Davies
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

1. Executive summary Google has patched CVE-2026-87491, an out-of-bounds write in the V8 JavaScript/WebAssembly engine, and states that an

09 Sep 2026 Jeff Davies
Ransomware: safepay named gsngestion.es (ES)

1. Executive summary On 2026-09-08, the ransomware operator "safepay" listed the Spanish firm GSN Gestión (gsngestion.es, Villaviciosa de Odón,

09 Sep 2026 Jeff Davies
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

1. Executive summary Microsoft's September 2026 Patch Tuesday is the largest on record: 973 vulnerabilities per Talos (Rapid7 counts 974 own-product

09 Sep 2026 Jeff Davies
Ransomware: safepay named hbpro.pt (PT)

1. Executive summary On 2026-09-08, the ransomware operator "safepay" publicly listed the Portuguese company hbpro.pt as a victim on

09 Sep 2026 Jeff Davies
Ransomware: safepay named gayafores.es (ES)

1. Executive summary On 2026-09-08, the ransomware group "safepay" listed the Spanish ceramics manufacturer Gayafores (gayafores.es, headquartered in Onda,

09 Sep 2026 Jeff Davies
Ransomware: safepay named assiprime.it (IT)

1. Executive summary On 2026-09-08, the ransomware group operating under the name "safepay" publicly listed the Italian insurance brokerage and

09 Sep 2026 Jeff Davies
Patch Tuesday - September 2026

1. Executive summary Microsoft's September 2026 Patch Tuesday is the largest single-day release in the company's history: 974 own-

08 Sep 2026 Jeff Davies
ClickFix Campaigns Abuse Legitimate Services for Persistent Access

1. Executive summary ClickFix — a social-engineering technique in which a fake webpage (styled as a CAPTCHA check, browser update notice, or meeting error)

08 Sep 2026 Jeff Davies
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

1. Executive summary Microsoft's September 2026 Patch Tuesday is the largest release on record: 964 CVEs patched, 104 rated critical and 860

08 Sep 2026 Jeff Davies
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

1. Executive summary Adobe has released patches for more than 170 vulnerabilities across its product line, headlined by CVE-2026-75650 (CVSS 10.0,

08 Sep 2026 Jeff Davies
CVE-2026-75650 — Adobe Commerce and Magento: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

1. Executive summary CVE-2026-75650 is a CVSS 10.0 CRITICAL unauthenticated remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and