~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
08 Sep 2026 Jeff Davies
CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

1. Executive summary Rapid7 has disclosed two new vulnerabilities in N-able N-central — CVE-2026-86206 (CVSS 6.9 MEDIUM, CWE-791, not

08 Sep 2026 Jeff Davies
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

1. Executive summary Red Hat has disclosed a two-flaw chain that allows a completely unauthenticated network client to write a Kerberos identity of

08 Sep 2026 Jeff Davies
Cyberattack encrypts systems at Bavarian municipal utility

1. Executive summary Stadtwerke Landsberg, a city-owned municipal utility in Bavaria, disclosed on 8 September 2026 that attackers encrypted its central IT network

08 Sep 2026 Jeff Davies
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

1. Executive summary Cisco Talos documents a monthslong criminal campaign (active since early October 2025, ongoing as of August 2026) that weaponises the Google

08 Sep 2026 Jeff Davies
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

1. Executive summary CVE-2026-75650 ("StyleSmuggler") is a CVSS 10.0 CRITICAL unauthenticated remote code execution vulnerability in Adobe Commerce, Adobe

08 Sep 2026 Jeff Davies
Extortion crews have their eyes on high-value AI data, Google warns

1. Executive summary Google's Threat Intelligence Group and Mandiant have disclosed, via their Q2-2026 AI Threat Tracker, a series of data-

08 Sep 2026 Jeff Davies
IT help-desk vishing tricks executives into handing over Microsoft 365 access

1. Executive summary Arctic Wolf is tracking a widespread data theft and extortion cluster — tracked as PREY-0058 — that compromises Microsoft 365 and other

08 Sep 2026 Jeff Davies
OpenAI pledges $1B to provide resources, training for frontline cyber defenders

1. Executive summary On 3 September 2026, OpenAI announced a $1 billion commitment — the "Daybreak for Frontline Defenders" program — providing subsidized access

08 Sep 2026 Jeff Davies
Ransomware: thegentlemen named University of San Francisco (US)

1. Executive summary On 7 September 2026, the ransomware group self-identifying as "thegentlemen" listed the University of San Francisco (US) as

08 Sep 2026 Jeff Davies
Ransomware: thegentlemen named Chip7 (PT)

1. Executive summary On 7 September 2026, ransomware operator "thegentlemen" listed Portuguese IT and gaming retailer Chip7 (chip7.pt) on its leak

08 Sep 2026 Jeff Davies
MA: Springfield Public Schools will be closed Tuesday after a cyber incident

1. Executive summary Springfield Public Schools (Massachusetts, US) announced on Monday 7 September 2026 that all schools will be closed Tuesday after a cyber

07 Sep 2026 Jeff Davies
Ransomware: everest named KÖRBER (DE)

1. Executive summary On 7 September 2026, the ransomware group "everest" publicly listed the German technology conglomerate Körber (headquartered in Hamburg) as