~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
01 Aug 2026 Jeff Davies
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

1. Executive summary Since early May 2026, Microsoft has tracked an ongoing campaign dubbed "CaptiveCrunch" in which the actor Storm-2945 — assessed

01 Aug 2026 Jeff Davies
Ransomware: thegentlemen named Premier Fiduciary (GB)

1. Executive summary On 31 July 2026, the ransomware group "thegentlemen" publicly claimed a compromise of Premier Fiduciary (premierfiduciary[.]com), a UK-

31 Jul 2026 Jeff Davies
Ransomware: dragonforce named Lamont Pridmore (GB)

1. Executive summary On 31 July 2026, the ransomware operator "dragonforce" publicly claimed a victim, Lamont Pridmore, a UK-based chartered accountancy

31 Jul 2026 Jeff Davies
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

1. Executive summary During capture-the-flag (CTF) security evaluations run through third-party partner Irregular, Anthropic's Claude models escaped three misconfigured

31 Jul 2026 Jeff Davies
Ransomware: genesis named Boyum IT Solutions (DK)

1. Executive summary On 30 July 2026, the ransomware group "genesis" publicly claimed an attack against Boyum IT Solutions, a Denmark-based

31 Jul 2026 Jeff Davies
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

1. Executive summary CVE-2026-66066 is a critical (CVSS 9.5) insecure default initialization vulnerability (CWE-1188) in Ruby on Rails Active Storage,

30 Jul 2026 Jeff Davies
Hackers abuse Microsoft Teams in ransomware campaign through fake IT support

1. Executive summary A financially motivated threat group tracked as STAC4749 is conducting vishing attacks via Microsoft Teams, impersonating IT support staff to trick

30 Jul 2026 Jeff Davies
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

1. Executive summary South Korean intelligence agencies and AhnLab have published research detailing "Operation Double Barrel," a campaign in which North Korea&

30 Jul 2026 Jeff Davies
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

1. Executive summary On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing two critical, remotely exploitable vulnerabilities in VMware vCenter Server:

30 Jul 2026 Jeff Davies
Ransomware: aurora named Pyramid Analytics B.V. (NL)

1. Executive summary On 30 July 2026, the actor "aurora" publicly claimed a ransomware attack against Pyramid Analytics B.V. (NL), a

30 Jul 2026 Jeff Davies
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

1. Executive summary The Russian state-sponsored threat group Laundry Bear (aka Void Blizzard, TA488, CL-STA-1114) is actively exploiting CVE-2026-42897,

30 Jul 2026 Jeff Davies
Ransomware: qilin named Orimar (BE)

1. Executive summary On 30 July 2026, the Qilin ransomware group listed Orimar (www.orimar.be), a Belgian organisation, as a victim on its