~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
16 Jul 2026 Jeff Davies
Claude Chrome extension flaw lets malicious extensions trigger AI actions

1. Executive summary A flaw in Anthropic's Claude for Chrome browser extension allows a malicious extension co-installed in the same browser

16 Jul 2026 Jeff Davies
Begun, the Patch Wars have

1. Executive summary Cisco Talos has disclosed an active, financially motivated campaign by actor "UAT-11795" (no MITRE ATT&CK profile

16 Jul 2026 Jeff Davies
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

1. Executive summary Elastic Security Labs has published a technical report on TELEPUZ, a modular, C-based Windows malware offered under a malware-as-

16 Jul 2026 Jeff Davies
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

1. Executive summary Researchers from Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft published a paper on 6 July 2026 detailing

16 Jul 2026 Jeff Davies
Russian hackers trojanize WebEx, Zoom apps to push Starland malware

1. Executive summary A financially motivated Russian threat actor tracked as "UAT-11795" is distributing trojanized installers for common enterprise and developer

16 Jul 2026 Jeff Davies
New Spirals ransomware encrypts victim network in under 24 hours

1. Executive summary A new ransomware actor dubbed "Spirals" completed a full intrusion cycle — from initial access through data theft to file

16 Jul 2026 Jeff Davies
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities

1. Executive summary F5 released an out-of-band security rollout on 16 July 2026 patching eight vulnerabilities across NGINX Open Source, NGINX Plus,

16 Jul 2026 Jeff Davies
Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations

1. Executive summary A GuidePoint Security report details how data-extortion groups — principally FulcrumSec (active since ~September 2025) and DragonForce (active since 2023) — are

16 Jul 2026 Jeff Davies
Ransom demands are down, email is the top way attackers get in

1. Executive summary Sophos's State of Ransomware 2026 report, based on a survey of 2,158 IT and security leaders whose organisations

15 Jul 2026 Jeff Davies
Zoom warns of critical account takeover vulnerability

1. Executive summary Zoom has disclosed CVE-2026-53412, a critical vulnerability (CVSS 9.8) caused by improper input validation in the Zoom Desktop

15 Jul 2026 Jeff Davies
Google Gemini CLI abused as a hacking agent, malware botnet operator

1. Executive summary A Russian-speaking threat actor dubbed "bandcampro" used Google's open-source Gemini CLI as an autonomous hacking

15 Jul 2026 Jeff Davies
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains

1. Executive summary Elastic Security Labs reports active in-the-wild distribution of TELEPUZ, a modular, lightweight Windows DLL malware likely operated as a