~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
25 Aug 2026 Jeff Davies
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication unauthenticated job execution, result theft, cancel and delete

1. Executive summary PraisonAI’s FastAPI async Jobs API contains no authentication or job-ownership control, allowing any caller who can reach /api/v1/

25 Aug 2026 Jeff Davies
CISA orders agencies to fix exploited Zimbra vulnerability

1. Executive summary Cybersecurity Dive and Dark Reading report active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite. The reported input-sanitisation failure

25 Aug 2026 Jeff Davies
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

1. Executive summary Threat reporting describes opportunistic attempts to exploit authentication flaws in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin;

25 Aug 2026 Jeff Davies
The safety penalty: Reclaiming operational sovereignty in the age of AI

1. Executive summary Commercial AI guardrails reportedly blocked Hugging Face’s initial analysis of attack commands, exploit payloads and command-and-control artefacts after

25 Aug 2026 Jeff Davies
GTA 6 leak hunt could expose data belonging to thousands of Discord users

1. Executive summary Malwarebytes reports that Take-Two Interactive subpoenaed Microsoft and Discord for identifying data associated with members of three Discord servers after

25 Aug 2026 Jeff Davies
Foul Language: WordlistLoader Disguises Malware as Ordinary Text

1. Executive summary WordlistLoader is being used in ClickFix-style campaigns to disguise malicious content as ordinary text and deliver the Amatera infostealer. The

24 Aug 2026 Jeff Davies
24th August – Threat Intelligence Report

1. Executive summary Check Point Research's weekly bulletin covers multiple developments relevant to EMEA financial services. The most urgent is an active

24 Aug 2026 Jeff Davies
ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

1. Executive summary Cybersecurity firm ReliaQuest has confirmed a limited breach attributed to the ShinyHunters threat actor (MITRE G1057). The attack combined a voice

24 Aug 2026 Jeff Davies
CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

1. Executive summary CVE-2026-21962 is a critical (CVSS 10.0) improper access control vulnerability in the Oracle HTTP Server and Oracle Weblogic

24 Aug 2026 Jeff Davies
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

1. Executive summary Rapid7 has published a technical analysis of CVE-2026-63520, a HIGH severity (CVSS 8.1) remote code execution vulnerability in

24 Aug 2026 Jeff Davies
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

1. Executive summary Security researchers at Socket have identified 77 linked malicious Firefox extensions — 40 confirmed as active info-stealers — in a campaign dubbed

24 Aug 2026 Jeff Davies
Tracking PavinLoader across ClickFix and fake download campaigns

1. Executive summary Malwarebytes tracking identifies PavinLoader, a multi-stage .NET loader, as a shared infrastructure component across disparate initial access vectors including ClickFix