~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
26 Aug 2026 Jeff Davies
When AI infrastructure becomes the target: Securing gateways and control points

1. Executive summary Microsoft Threat Intelligence reports active exploitation targeting three distinct AI infrastructure workloads: LiteLLM, RAGFlow, and Kestra. Attackers compromised these systems to

26 Aug 2026 Jeff Davies
CVE-2022-0995 — Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerability

1. Executive summary CVE-2022-0995 is a HIGH-severity out-of-bounds write vulnerability (CVSS 7.8) in the Linux Kernel. The flaw

26 Aug 2026 Jeff Davies
CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

1. Executive summary CVE-2026-8452 is a HIGH severity (CVSS 8.8) memory buffer vulnerability — classified as CWE-119 (Improper Restriction of Operations

26 Aug 2026 Jeff Davies
CVE-2015-3246 — Red Hat Libuser: Red Hat Libuser Race Condition Vulnerability

1. Executive summary CVE-2015-346 is a race condition vulnerability (CWE-264, CWE-367) in Red Hat libuser that allows authenticated local users

26 Aug 2026 Jeff Davies
CVE-2021-23758 — Ajax.NET Professional Ajax.NET Professional: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

1. Executive summary Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability (CVE-2021-23758) rated CVSS 8.1 HIGH, enabling remote

26 Aug 2026 Jeff Davies
Ransomware: thegentlemen named Party Rental (GB)

1. Executive summary On 2026-08-26, the ransomware group "thegentlemen" publicly claimed a victim named "Party Rental" (country tag:

26 Aug 2026 Jeff Davies
Ransomware: AiLock named Morgan Services (GB)

1. Executive summary On 26 August 2026, the actor "AiLock" publicly listed Morgan Services (morganservices[.]com) as a ransomware victim on their

26 Aug 2026 Jeff Davies
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

1. Executive summary A new adversary-in-the-middle (AitM) phishing-as-a-service (PhaaS) toolkit dubbed "NovaCookies" has been disclosed. The

26 Aug 2026 Jeff Davies
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

1. Executive summary CISA reportedly observed malicious activity targeting more than 100 internet-exposed US water and wastewater systems during July 2026, commonly involving

26 Aug 2026 Jeff Davies
VMs won't contain cyber-capable agents

1. Executive summary Trail of Bits reports that GPT 5.6-Cyber identified multiple routes from a QEMU/KVM guest to its Debian 12

26 Aug 2026 Jeff Davies
CISA Warns of Exploited Gitea Vulnerability

1. Executive summary CISA reports active exploitation of CVE-2026-60004, a Gitea code-injection vulnerability that converts attacker-controlled patch content into an

26 Aug 2026 Jeff Davies
Ransomware: qilin named Air International Thermal Systems (GB)

1. Executive summary Ransomware.live has listed UK organisation Air International Thermal Systems as a victim attributed to “qilin”; the available material does not