~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
01 Sep 2026 Jeff Davies
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

1. Executive summary Kaspersky GReAT has documented a campaign of targeted cyber-espionage activity against the aviation, aerospace and FinTech sectors across the Middle

01 Sep 2026 Jeff Davies
Ransomware: krybit named dmt-group.com (DE)

1. Executive summary On 2026-09-01, the ransomware operator "krybit" listed dmt-group.com (DMT Consulting Private Limited, an Indian-incorporated

31 Aug 2026 Jeff Davies
Berlin says it won’t pay ransom after hackers steal government data

1. Executive summary Berlin state government has refused to pay an extortion demand following a breach of its government network, discovered in mid-August

31 Aug 2026 Jeff Davies
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

1. Executive summary Unit 42 has disclosed "Spring Ring," a coordinated social-engineering operation active January–April 2026 that used external Microsoft

31 Aug 2026 Jeff Davies
Ransomware: qilin named Absolute Consultancy Services (GB)

1. Executive summary On 30 August 2026, the ransomware operator "qilin" listed the UK company Absolute Consultancy Services (absolutecs.co.uk) as

31 Aug 2026 Jeff Davies
Ransomware: thegentlemen named MB Associates (GB)

1. Executive summary On 30 August 2026, ransomware operator "thegentlemen" listed UK social impact consultancy MB Associates (mbassociates.org; legal entity Mandy

31 Aug 2026 Jeff Davies
Ransomware: thegentlemen named Brebur (GB)

1. Executive summary On 30 August 2026, ransomware operator "thegentlemen" listed UK construction subcontractor Brebur Ltd (breburltd.co.uk, Barnsley, South Yorkshire)

31 Aug 2026 Jeff Davies
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

1. Executive summary An unattributed actor is running a "TerminalFix" campaign — a variant of the ClickFix social-engineering technique that tricks users

31 Aug 2026 Jeff Davies
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

1. Executive summary ESET has identified a technique, named "GuardBreaker", in which a Russia-aligned actor deliberately embeds safety-triggering text — specifically

31 Aug 2026 Jeff Davies
Extortion Group Claims Manchester Airports Group Data Breach

1. Executive summary On August 27, 2026, Manchester Airports Group (MAG) — operator of Manchester, London Stansted, and East Midlands airports — disclosed a data breach

31 Aug 2026 Jeff Davies
ValleyRAT masquerading as adware

1. Executive summary Kaspersky reports a campaign distributing the ValleyRAT backdoor disguised as a signed Chinese desktop-wallpaper adware application (QN Wallpaper), delivered via

31 Aug 2026 Jeff Davies
Ransomware: incransom named www.lichtvision.com (GB)

1. Executive summary On 31 August 2026, the ransomware group operating under the name "incransom" listed the UK-registered lighting design firm