~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
14 Jul 2026 Jeff Davies
New phishing kits target Microsoft 365 accounts, evade MFA

1. Executive summary Two new phishing kits — Jalisco and OmegaLord — have been discovered targeting Microsoft 365 accounts using techniques that defeat multi-factor authentication

14 Jul 2026 Jeff Davies
'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes

1. Executive summary A solo Russian-speaking threat actor tracked as "bandcampro" used a jailbroken Google Gemini CLI agent to automate a

14 Jul 2026 Jeff Davies
Musk promises purge after Grok Build caught sending entire repos to the cloud

1. Executive summary xAI's Grok Build CLI (version 0.2.93) was discovered silently uploading users' entire Git repositories — including full

14 Jul 2026 Jeff Davies
CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors

1. Executive summary On 14 July 2026, CISA, NSA, FBI, DC3, and 14 international partners published a joint cybersecurity advisory titled Improve Router Hygiene

14 Jul 2026 Jeff Davies
The serpent’s tongue: Luring the Python out of its den

1. Executive summary Cisco Talos published a technical analysis detailing how threat actors abuse native Python package installation mechanisms to execute malicious payloads and

14 Jul 2026 Jeff Davies
Defending SaaS-based applications against ShinyHunters OAuth abuse

1. Executive summary Between mid-2025 and mid-2026, Microsoft tracked a series of campaigns targeting customer SaaS-based applications — predominantly Salesforce instances — using

13 Jul 2026 Jeff Davies
GigaWiper Lets Threat Actors Choose Their Own Destructive Attack

1. Executive summary Microsoft Threat Intelligence has disclosed GigaWiper, a modular Golang-based Windows backdoor observed in destructive intrusions since October 2025. The implant

13 Jul 2026 Jeff Davies
Threat Actors Achieve Persistence After SQL Injection

1. Executive summary Huntress reports a June 2026 incident in which a threat actor achieved deep persistence on a Windows host via an SQL

13 Jul 2026 Jeff Davies
EU and UK officially blame Russian spies for cyberattack on Poland's power grid

1. Executive summary On 13 July 2026, the UK FCDO and EU formally attributed a December 2025 cyberattack on Poland's power grid

13 Jul 2026 Jeff Davies
EU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe

1. Executive summary On 13 July 2026, the EU and UK jointly imposed sanctions on dozens of Russian individuals and entities — the largest-ever

13 Jul 2026 Jeff Davies
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting

1. Executive summary On 13 July 2026, the UK NCSC and 18 agencies from 12 countries published a joint advisory attributing ongoing, opportunistic exploitation

13 Jul 2026 Jeff Davies
Targeting and Compromise of French Entities Using the Turla Intrusion Set (13 juillet 2026)

1. Executive summary On 13 July 2026, ANSSI (via the French Cyber Crisis Coordination Centre, C4) published a CTI advisory reporting the targeting and