~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
24 Aug 2026 Jeff Davies
Iran-Linked Hackers Shut Down UK Power Plant for Four Days

1. Executive summary In July 2026, a UK power plant was shut down for four days by a cyber attack attributed to Iran-linked

24 Aug 2026 Jeff Davies
Fake bank websites play dead to evade security scanners

1. Executive summary Fortra's threat intelligence unit (FIRE) has documented a phishing technique dubbed "Chameleon SEO Poisoning" that uses SEO-

22 Aug 2026 Jeff Davies
If you're not using AI to attack your own systems, your adversaries will

1. Executive summary AI agents can accelerate reconnaissance, vulnerability discovery, exploit-chain development, network mapping and sensitive-file identification while introducing privileged non-human

22 Aug 2026 Jeff Davies
CVE-2026-73570 — Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

1. Executive summary CVE-2026-73570 is a HIGH-severity OS command injection vulnerability (CVSS 8.9, CWE-78) in Synacor Zimbra Collaboration Suite

22 Aug 2026 Jeff Davies
U.S. Bank says breach claims related to fourth-party incident

1. Executive summary U.S. Bancorp (7th-largest U.S. bank) stated that LockBit ransomware gang claims of data theft are attributable to a

21 Aug 2026 Jeff Davies
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

1. Executive summary A new phishing-as-a-service (PhaaS) toolkit dubbed iAuthFlow V2, first advertised on a Russian-language cybercrime forum at $10,

21 Aug 2026 Jeff Davies
Ransomware: thegentlemen named dlp motive (DE)

1. Executive summary On 21 August 2026, the ransomware operator "thegentlemen" publicly claimed a compromise of dlp motive (dlp-motive.de), a

21 Aug 2026 Jeff Davies
Critical Isolated-vm Vulnerability Leads to RCE on Host

1. Executive summary A critical type confusion vulnerability in the isolated-vm Node.js library (GHSA-864f-rcv7-6rh4) enables sandboxed JavaScript to escape

21 Aug 2026 Jeff Davies
Ransomware: direwolf named Reviso Cloud Accounting Limited (DK)

1. Executive summary On 21 August 2026, the ransomware actor "direwolf" publicly listed Reviso Cloud Accounting Limited (DK; domain reviso.com) as

21 Aug 2026 Jeff Davies
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

1. Executive summary Microsoft has confirmed active in-the-wild exploitation of CVE-2026-69836, a CVSS 10.0 CRITICAL remote code execution vulnerability

21 Aug 2026 Jeff Davies
Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays

1. Executive summary A SANS Internet Storm Center (ISC) diary entry details practical techniques for querying Microsoft Entra ID (formerly Azure AD) sign-in

20 Aug 2026 Jeff Davies
CVE-2026-72529 — TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

1. Executive summary CVE-2026-72529 is a missing-authentication vulnerability in TrueConf Server that permits a remote, unauthorised attacker with network access to