~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
13 Jul 2026 Jeff Davies
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

1. Executive summary A misconfigured Python web server (python3 -m http.server 8080) with directory listing enabled exposed the full toolkit, logs, and bash

13 Jul 2026 Jeff Davies
Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns

1. Executive summary Progress Software has directed ShareFile customers to immediately manually shut down all Windows servers hosting on-premises Storage Zone Controllers (SZC)

13 Jul 2026 Jeff Davies
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th)

1. Executive summary A 14-day log review of a low-traffic web host by SANS ISC has revealed a new category of internet-

11 Jul 2026 Jeff Davies
GigaWiper Infrastructure: From Two IPs to an Iranian APT Attribution Chain

We took two C2 IP addresses from a malware news article and pivoted through Shodan, DNS, reverse MX lookups, certificate transparency, WHOIS, and MITRE

11 Jul 2026 Jeff Davies
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware

1. Executive summary The Gentlemen (aka Storm-2697) is a Ransomware-as-a-Service (RaaS) program active since at least July 2025, now ranked

11 Jul 2026 Jeff Davies
Ransomware: thegentlemen named BDO Greece (GR)

1. Executive summary On 2026-07-11, the ransomware operator "thegentlemen" publicly claimed a compromise of BDO Greece (bdo.gr), an Athens-

11 Jul 2026 Jeff Davies
Ransomware: thegentlemen named INTERNET AG (DE)

1. Executive summary On 11 July 2026, the ransomware group "thegentlemen" publicly claimed a compromise of INTERNET AG (inet.de), a German

11 Jul 2026 Jeff Davies
Australia warns of global campaign targeting vulnerable CMS platforms

1. Executive summary The Australian Cyber Security Centre (ACSC) has issued an alert regarding a large-scale, global exploitation campaign targeting vulnerabilities in content

10 Jul 2026 Jeff Davies
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package

1. Executive summary Microsoft Threat Intelligence has published detailed analysis of GigaWiper, a Golang-based modular Windows backdoor first observed in compromised environments in

10 Jul 2026 Jeff Davies
Initial access broker linked to weaponization of CitrixBleed2 flaw

1. Executive summary An initial access broker weaponized the CitrixBleed 2 vulnerability in a series of attacks across multiple organizations during the first half

10 Jul 2026 Jeff Davies
Ransomware: Deadlock named Integra and Operosa (IT)

1. Executive summary On 2026-07-10, the ransomware group "Deadlock" publicly claimed a compromise of Integra S.r.l. and L&

10 Jul 2026 Jeff Davies
Ransomware: Deadlock named EFCA (DE)

1. Executive summary On 2026-07-10, the ransomware group "Deadlock" publicly claimed a ransomware attack against EFCA, a Paris-based accounting