~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
03 Sep 2026 Jeff Davies
Your AI agent’s system prompt is not a security control

1. Executive summary SANS Institute fellow Eric Johnson and AWS security leaders including Gee Rittenhouse (Security Hub, GuardDuty, Inspector) have published guidance stating that

03 Sep 2026 Jeff Davies
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

1. Executive summary Unit 42 has published details of two ongoing, multi-stage intrusion and data-exfiltration campaigns targeting Latin American organizations — CL-CRI-

03 Sep 2026 Jeff Davies
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

1. Executive summary GitGuardian researchers report that a recent variant of the Shai-Hulud infostealer worm has expanded its credential-scanning behaviour from 189

03 Sep 2026 Jeff Davies
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

1. Executive summary A security researcher operating as "Chaotic Eclipse" (aka INFINITE NIGHTMARE, MSNightmare, Nightmare-Eclipse) has publicly released a proof-of-

03 Sep 2026 Jeff Davies
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

1. Executive summary Microsoft Threat Intelligence reports a human-operated intrusion campaign in which threat actors abuse Microsoft Teams external collaboration to impersonate IT/

03 Sep 2026 Jeff Davies
When AI quietly breaks things, who pays?

1. Executive summary This is a strategic item, not a vulnerability or active campaign: an interview with David Halbreich, insurance recovery partner at Reed

03 Sep 2026 Jeff Davies
Srsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting

1. Executive summary On 27 August 2026 the US Department of Justice announced court-authorised seizure of three domains (qtproxy[.]xyz, qt-proxy[.]org,

02 Sep 2026 Jeff Davies
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

1. Executive summary Unit 42 incident responders report an intrusion in which a single human attacker used frontier AI models and agentic attack frameworks

02 Sep 2026 Jeff Davies
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

1. Executive summary On 2026-09-02, Google, Anthropic, and OpenAI announced a coordinated wave of cybersecurity-focused AI releases and access controls: Google&

02 Sep 2026 Jeff Davies
Russian national facing 20 years for malware campaign that infected 80,000 freelancers

1. Executive summary Searzhudin Tamirlanovich Aktulaev, a Russian national arrested in Cyprus in May 2025 and extradited to the US last week, appeared in

02 Sep 2026 Jeff Davies
CVE-2026-83548 — SonicWall SMA1000 Appliances: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

1. Executive summary SonicWall has confirmed active in-the-wild exploitation of CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) vulnerability

02 Sep 2026 Jeff Davies
AI Agents Are Now Emailing Me with Their Security Concerns

1. Executive summary An autonomous AI agent ("Tenner", self-described as an autonomous Claude instance) has published two field-research reports, relayed