~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
26 Aug 2026 Jeff Davies
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

1. Executive summary CVE-2026-60004 affects Gitea 1.17 through 1.27.0 and enables a repository writer to plant an executable Git

25 Aug 2026 Jeff Davies
Siemens SIMATIC IoT2050 Advanced

1. Executive summary Siemens disclosed CVE-2026-58115 affecting SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) before V4.3.4.1 when running Industrial OS

25 Aug 2026 Jeff Davies
Insurance benefits platform Paylogix says hackers stole financial and health data

1. Executive summary Paylogix disclosed that an unspecified cyberattack disrupted its systems and that intruders stole files from its network between 13 and 18

25 Aug 2026 Jeff Davies
PayRange API

1. Executive summary CISA disclosed CVE-2026-18965, a missing-authorization vulnerability affecting all versions of the PayRange API. CISA assigns CVSS v3.1

25 Aug 2026 Jeff Davies
CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response

1. Executive summary CISA has published lessons from authorised red-team assessments at two critical-infrastructure organisations. At one organisation, the SOC failed to

25 Aug 2026 Jeff Davies
CVE-2026-60004 — Gitea Gitea: Gitea Code Injection Vulnerability

1. Executive summary CVE-2026-60004 is a reported Gitea code-injection vulnerability through which a user with repository write access can submit a

25 Aug 2026 Jeff Davies
Fake AI, real malware: Attackers impersonating AI brands

1. Executive summary Sophos X-Ops reviewed 86 MDR cases tagged for AI involvement between 2 July 2025 and 29 June 2026: 34 met

25 Aug 2026 Jeff Davies
Zoneminder

1. Executive summary CVE-2026-76060 is an authenticated OS command-injection vulnerability in ZoneMinder’s event-export function. CISA reports CVSS v3.1

25 Aug 2026 Jeff Davies
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

1. Executive summary GitHub published GHSA-8hjw-25cg-g52h, identified there as CVE-2026-55523, describing a server-side request forgery bypass in praisonaiagents.

25 Aug 2026 Jeff Davies
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

1. Executive summary CVE-2026-44661 is a CWE-918 server-side request forgery vulnerability affecting utcp-gql 1.1.0 and utcp-websocket

25 Aug 2026 Jeff Davies
Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)

1. Executive summary SANS ISC reports SSRF scanning in which attacker-supplied hostnames resolve to the link-local cloud metadata address 169.254.169.

25 Aug 2026 Jeff Davies
What the ERMAC Source Leak Says About HookBot

1. Executive summary Censys reports that the August 2025 publication of ERMAC 3.0 source code exposed a deployable Android banking-trojan stack comprising