~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
08 Jul 2026 Jeff Davies
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

1. Executive summary GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel use-after-free vulnerability (CVSS 7.8 HIGH) disclosed by

07 Jul 2026 Jeff Davies
Accenture confirms breach after hacker offers stolen data for sale

1. Executive summary Accenture has confirmed a security breach after a threat actor using the alias "888" claimed to have stolen approximately

07 Jul 2026 Jeff Davies
Ransomware: dragonforce named hive360.com

1. Executive summary On 2026-07-07, the ransomware operator "dragonforce" publicly claimed a compromise of hive360.com, a UK-based employment

07 Jul 2026 Jeff Davies
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

1. Executive summary BeyondTrust has released updates for four vulnerabilities — two CRITICAL pre-authentication bypass flaws (CVE-2026-40138, CVSS 9.2; CVE-2026-

06 Jul 2026 Jeff Davies
Fake IT support calls on Microsoft Teams push EtherRAT malware

1. Executive summary Threat actors are conducting a multi-stage vishing campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support staff,

06 Jul 2026 Jeff Davies
Ransomware: qilin named Max Fordham (GB)

1. Executive summary On 2026-07-06, the Qilin ransomware group publicly claimed Max Fordham (www.maxfordham.com), a UK-based engineering consultancy, as

06 Jul 2026 Jeff Davies
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

1. Executive summary Check Point Research (CPR) has published a detailed analysis of "Cavern," a new modular .NET command-and-control (C2)

06 Jul 2026 Jeff Davies
New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

1. Executive summary LevelBlue researchers have disclosed QuimaRAT, a novel Java-based remote access trojan offered as a malware-as-a-service (MaaS) product

06 Jul 2026 Jeff Davies
When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website

1. Executive summary A phishing campaign observed from early April to mid-May 2026 abuses the OAuth 2.0 Device Authorization Grant (Device Code

04 Jul 2026 Jeff Davies
JadePuffer ransomware used AI agent to automate entire attack

1. Executive summary Sysdig's Threat Research Team has published findings on what they believe is the first documented end-to-end ransomware

04 Jul 2026 Jeff Davies
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

1. Executive summary A U.S. government entity — evidence points to Union County, Ohio — paid approximately $1 million (≈9.44 BTC) to a threat

04 Jul 2026 Jeff Davies
Ransomware: unsafe named Deutsche Bank (DE)

1. Executive summary On 2026-07-04, the ransomware tracking site ransomware.live published a listing attributing a ransomware attack against Deutsche Bank (DE)