~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
17 Sep 2026 Jeff Davies
From guidance to action: Security fundamentals that materially reduce risk

1. Executive summary Microsoft has published a guidance piece built around three observed attack paths: agentic AI incidents disclosed by OpenAI and Anthropic, the

17 Sep 2026 Jeff Davies
Bransys ELD

1. Executive summary CISA published ICS advisory ICSA-26-260-01 on 2026-09-17 covering three vulnerabilities in Bransys ELD, an electronic logging

17 Sep 2026 Jeff Davies
ABB Ability Edgenius

1. Executive summary ABB has released Edgenius 3.2.4.1 to fix CVE-2026-31431 ("Copy Fail"), a Linux kernel privilege

17 Sep 2026 Jeff Davies
Ransomware: BrainCipher named hoyletanner.com (GB)

1. Executive summary On 17 September 2026, the ransomware operator BrainCipher listed the UK engineering consultancy Hoyle Tanner (hoyletanner.com) as a victim on

17 Sep 2026 Jeff Davies
Ransomware: Vexy Ransomware named STP Fashion Lab (IT)

1. Executive summary On 17 September 2026, the operator behind the "Vexy Ransomware" name listed STP Fashion Lab — a Tuscan womenswear manufacturer

17 Sep 2026 Jeff Davies
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

1. Executive summary Revolut, a London-based fintech with more than 80 million customers, disclosed that it handed sensitive customer records to criminals who

17 Sep 2026 Jeff Davies
AI Threat Landscape Digest: July–August 2026

1. Executive summary Check Point Research's July–August 2026 AI threat landscape digest reports that the period's defining development was

17 Sep 2026 Jeff Davies
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields

1. Executive summary The Go AMQP 0-9-1 client library used with RabbitMQ (amqp091-go) retains the PLAIN authentication username and password in

17 Sep 2026 Jeff Davies
LausivLoader analysis, or how to pass data between malware stages

1. Executive summary ISC/SANS has published a detailed technical analysis of a LausivLoader sample delivered via a purchase-quotation malspam campaign (a fake

17 Sep 2026 Jeff Davies
Revolut phishing texts appear days after data breach

1. Executive summary Revolut has confirmed it disclosed sensitive customer records — identity and contact details, copies of passports and driving licences, verification selfies, and

17 Sep 2026 Jeff Davies
Hackers claim breach of Russian election systems days before parliamentary vote

1. Executive summary An anonymous group calling itself CikLeak claims to have breached systems belonging to Russia's Central Election Commission (CEC) and

17 Sep 2026 Jeff Davies
OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

1. Executive summary OpenAI has published a framework for disclosing model misalignment, accompanied by six reports describing problematic behaviours exhibited by its models during