~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
08 Sep 2026 Jeff Davies
CVE-2026-86218 — N-able N-central: N-able N-central Static Code Injection Vulnerability

1. Executive summary CVE-2026-86218 is a static code injection vulnerability in N-able N-central — the RMM platform widely deployed by managed

08 Sep 2026 Jeff Davies
CISA, NSA and FBI Warn of China-Based AI Companies Targeting US AI Models with Industrial-Scale Knowledge Distillation Campaigns to Shortcut AI Development

1. Executive summary CISA, NSA and FBI have issued a joint advisory warning that China-based AI companies — named as DeepSeek, Moonshot AI, Alibaba,

08 Sep 2026 Jeff Davies
Ransomware: akira named Brent Electric (GB)

1. Executive summary On 8 September 2026, the Akira ransomware operation (MITRE ATT&CK G1024) listed Brent Electric Inc., a US-founded electrical

08 Sep 2026 Jeff Davies
CVE-2026-85880 — Microsoft Windows: Microsoft Windows Heap-Based Buffer Overflow Vulnerability

1. Executive summary CVE-2026-85880 is a heap-based buffer overflow (CWE-122, with CWE-908 use of uninitialized resource also recorded) in

08 Sep 2026 Jeff Davies
Ransomware: lockbit5 named fdcputman.nl (NL)

1. Executive summary On 2026-09-08, the ransomware operator branding itself "lockbit5" listed the Dutch financial services firm FDC Putman (fdcputman.

08 Sep 2026 Jeff Davies
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

1. Executive summary Microsoft's September 2026 Patch Tuesday is the largest release on record: 973 vulnerabilities patched, 113 rated critical, well ahead

08 Sep 2026 Jeff Davies
CVE-2026-81963 — Microsoft Windows: Microsoft Windows Link Following Vulnerability

1. Executive summary CVE-2026-81963 is a link following vulnerability (improper link resolution before file access; CWE-59 / CWE-284) in the Microsoft

08 Sep 2026 Jeff Davies
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

1. Executive summary Cisco Talos has documented two related infection chains — tracked under loader names "pf.ch" and "verification.google"

08 Sep 2026 Jeff Davies
Threat actors are giving AI agents a bigger role in cyberattacks

1. Executive summary Google Threat Intelligence Group's (GTIG) Q3 2026 AI Threat Tracker documents threat actors moving from single AI prompts to

08 Sep 2026 Jeff Davies
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

1. Executive summary Check Point Research (Alexey Bukhteyev) has disclosed a cross-tenant isolation failure in ChatGPT's code-execution sandbox, discovered independently

08 Sep 2026 Jeff Davies
French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack

1. Executive summary French prosecutors have confirmed the 18 August 2026 arrest in the Paris region of an 18-year-old suspected member of

08 Sep 2026 Jeff Davies
“Zero-click” WeChat worm could hijack accounts and spread via a single call

1. Executive summary Security firm Calif privately demonstrated to Tencent a "zero-click" worm ("WeWorm") built on a critical memory-