~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
07 Sep 2026 Jeff Davies
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

1. Executive summary Huntress has disclosed worm-like activity in which backdoored ConnectWise ScreenConnect clients distribute a four-stage VBScript chain to newly connected

07 Sep 2026 Jeff Davies
7th September – Threat Intelligence Report

1. Executive summary Check Point's weekly intelligence report for 7 September 2026 carries three actively exploited vulnerabilities that demand immediate attention from

07 Sep 2026 Jeff Davies
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

1. Executive summary On 2026-09-07, security firm TantoSec published a working, unauthenticated remote-code-execution chain against Progress Telerik UI for ASP.

07 Sep 2026 Jeff Davies
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

1. Executive summary Between late August and early September 2026, the security researcher known as Nightmare Eclipse (aliases Chaotic Eclipse, Infinite Nightmare, MSNightmare) published

07 Sep 2026 Jeff Davies
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

1. Executive summary Threat actors are exploiting a zero-day remote code execution flaw — dubbed "StyleSmuggler" by Sansec — in Adobe Commerce and

07 Sep 2026 Jeff Davies
Peers ask why UK cyber bill leaves execs off the personal liability hook

1. Executive summary The UK House of Lords Grand Committee has scrutinised the Cyber Security and Resilience (CSR) Bill, with cross-party peers tabling

07 Sep 2026 Jeff Davies
The hidden risks of shadow AI

1. Executive summary The UK NCSC has published guidance on "shadow AI" — AI tools used by employees outside approved systems and processes,

07 Sep 2026 Jeff Davies
Risky Bulletin: BEC campaign steals €35 million from French notaries

1. Executive summary A four-year business email compromise (BEC) and network-intrusion campaign has stolen more than €35 million from French notaries, affecting

06 Sep 2026 Jeff Davies
Ransomware: Panzer named Edacentrum (SE)

1. Executive summary On 6 September 2026, the ransomware group "Panzer" listed the German electronics and microelectronics R&D network edacentrum

06 Sep 2026 Jeff Davies
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

1. Executive summary Attackers are hijacking MikroTik routers whose SSH service is reachable from the internet, gaining full administrative control without authentication, per a

05 Sep 2026 Jeff Davies
FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor

1. Executive summary On 3 September 2026, a security researcher operating as Chaotic Eclipse (aliases Nightmare-Eclipse, MSNightmare, INFINITE NIGHTMARE) published a working privilege-

05 Sep 2026 Jeff Davies
Ransomware: qilin named The Big Table (GB)

1. Executive summary On 2026-09-05, the ransomware operator tracked as "qilin" publicly listed The Big Table (www.bigtablegroup.com, GB)