~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
19 Sep 2026 Jeff Davies
A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

1. Executive summary Unit 42 has disclosed a design weakness in AWS AgentCore Harness: with default configuration, the harness's built-in shell

18 Sep 2026 Jeff Davies
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

1. Executive summary Docker disclosed CVE-2026-77179 on 15 September 2026, a critical sandbox-escape flaw (CVSS 9.4, CWE-59) in Docker

18 Sep 2026 Jeff Davies
Beware the SparroWock: The backdoor that bites, the commands that catch

1. Executive summary ESET Research reports that the China-aligned espionage group FamousSparrow has replaced its long-standing SparrowDoor implant with a new modular

18 Sep 2026 Jeff Davies
HTTP QUERY Method: The Grey Zone Between GET And POST.

1. Executive summary In June 2026 the IETF published RFC 10008, defining QUERY, the first new standard HTTP method since PATCH in 2010. QUERY

18 Sep 2026 Jeff Davies
Hardcoded MCP credentials found in public GitHub files

1. Executive summary Hush Security analysed roughly 82,000 publicly accessible MCP configuration files on GitHub and found that 12% of credential slots contained

18 Sep 2026 Jeff Davies
Ransomware: qilin named Vigatec (DE)

1. Executive summary On 17 September 2026 the ransomware operator tracked as "qilin" listed the German engineering firm Vigatec (www.vigatec.com)

18 Sep 2026 Jeff Davies
AI coding agents' 0-click RCE flaw could hand attackers keys to the kingdom

1. Executive summary A zero-click remote code execution flaw, dubbed Plugin4Shell, affects all major AI coding agents: Anthropic Claude Code, OpenAI Codex, Google

17 Sep 2026 Jeff Davies
Mitsubishi Electric GX Works3 and Motion Control Settings

1. Executive summary CISA has republished Mitsubishi Electric advisory 2026-007 covering CVE-2026-15688, an incorrect implementation of an authentication algorithm (CWE-303)

17 Sep 2026 Jeff Davies
Schneider Electric PowerChute Serial Shutdown

1. Executive summary Schneider Electric has released version 1.6 of PowerChute Serial Shutdown to fix CVE-2026-13348, an improper restriction of excessive

17 Sep 2026 Jeff Davies
Schneider Electric NetBotz 5 750/755

1. Executive summary Schneider Electric has released firmware version 5.6.0 for its NetBotz 5 750 and 755 environmental and security monitoring appliances,

17 Sep 2026 Jeff Davies
Schneider Electric Modicon M340 Controller and Communication Modules

1. Executive summary Schneider Electric has published advisory SEVD-2025-224-05, republished by CISA as ICSA-26-260-04, covering CVE-2025-6625,

17 Sep 2026 Jeff Davies
Hitachi Energy FACTS Control Platform (FCP)

1. Executive summary CISA has republished Hitachi Energy PSIRT advisory 8DBD000229 covering five vulnerabilities in the FACTS Control Platform (FCP) with the GWS component,