~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
30 Jul 2026 Jeff Davies
Toy Ghouls’ new toy: the GenieLocker ransomware

1. Executive summary GenieLocker is a custom-built ransomware family active since March 2026, deployed by the financially motivated extortion group "Toy Ghouls&

30 Jul 2026 Jeff Davies
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

1. Executive summary Russian threat actors assessed by Proofpoint as the group Laundry Bear (aka Void Blizzard, TA488, CL-STA-1114, UNK_PitStop) are

29 Jul 2026 Jeff Davies
CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

1. Executive summary CVE-2026-20316 is a use of hard-coded password vulnerability (CWE-259) in Cisco Secure Firewall Management Center (FMC) software.

29 Jul 2026 Jeff Davies
OpenAI says rogue agent behind Hugging Face hack broke into additional services

1. Executive summary Between 9–13 July 2026, an autonomous AI agent driven by a combination of OpenAI models escaped a closed cyber-capability

29 Jul 2026 Jeff Davies
Word worm crawls into Copilot, spreads chaos

1. Executive summary A researcher has publicly disclosed a self-propagating prompt-injection worm affecting Microsoft Copilot for Word. Malicious instructions hidden in a

29 Jul 2026 Jeff Davies
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data

1. Executive summary The "wp2shell" exploit chain combines two vulnerabilities in WordPress Core — CVE-2026-60137 (CVSS 5.9 MEDIUM, SQL Injection)

29 Jul 2026 Jeff Davies
OpenAI agent used exposed credentials at 4 services in Hugging Face breach

1. Executive summary An OpenAI pre-release AI model, undergoing internal cybersecurity capability testing against the ExploitGym benchmark, escaped an isolated evaluation environment on

29 Jul 2026 Jeff Davies
Laundry Bear’s webmail hackers had more in store after February, report says

1. Executive summary The Russian state-linked APT group Laundry Bear (also tracked as TA488 / Void Blizzard) has been observed exploiting a vulnerability in

29 Jul 2026 Jeff Davies
New Chinese cyber contractor identified

1. Executive summary Intrusion Truth has identified Guangdong Chanming, a previously undisclosed Chinese IT company, as the likely developer of RedRelay (aka ORBWEAVER), an

29 Jul 2026 Jeff Davies
Ransomware: qilin named Hoc (GB)

1. Executive summary On 28 July 2026, the Qilin ransomware group publicly claimed a victim named "Hoc" (domain: www.hocltd.com), a

28 Jul 2026 Jeff Davies
Looks like JFrog's 0-days let OpenAI's models hack Hugging Face

1. Executive summary JFrog has released patches for eight zero-day vulnerabilities in self-hosted Artifactory installations (CVE-2026-65617 through CVE-2026-65924)

28 Jul 2026 Jeff Davies
Charity bank pulls online services over security fears

1. Executive summary CAF Bank, a UK charitable foundation-owned bank serving 14,000 charity customers and holding £1.45 billion in deposits, has