~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
20 Aug 2026 Jeff Davies
Johnson Controls Simplex Incident Manager

1. Executive summary CVE-2026-27875 affects Johnson Controls Simplex Incident Manager V2.01 and earlier, which retain passwords and authentication tokens in cleartext

20 Aug 2026 Jeff Davies
Using Microsoft Graph and Powershell - Risk Detection Commands

1. Executive summary SANS Internet Storm Center published a Microsoft Graph PowerShell workflow for reviewing Microsoft Entra risky-login detections; it does not report

20 Aug 2026 Jeff Davies
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

1. Executive summary U.S. agencies reportedly warned of active reconnaissance and capability development against Siemens S7 programmable logic controllers (PLCs), using AI-assisted

20 Aug 2026 Jeff Davies
CVE-2026-72530 — TrueConf Server: TrueConf Server Code Injection Vulnerability

1. Executive summary CVE-2026-72530 is a CVSS 9.5 CRITICAL CWE-94 code-injection vulnerability affecting TrueConf Server versions 5.3.X

20 Aug 2026 Jeff Davies
Ransomware crook poses as recovery firm to steal payments from fellow extortionists

1. Executive summary GuidePoint Security assesses with moderate confidence that “Ransom Busters” is a ransomware affiliate impersonating a recovery provider to divert payments from

20 Aug 2026 Jeff Davies
Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro WordPress Plugin

1. Executive summary Wordfence reports that Elementor Pro versions up to and including 4.2.1 permit unauthenticated arbitrary file upload when a published

20 Aug 2026 Jeff Davies
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

1. Executive summary SANS Internet Storm Center published a Microsoft Graph PowerShell workflow for identifying enabled Entra accounts, sign-in history, password-change dates

20 Aug 2026 Jeff Davies
Ransomware: everest named Capgemini Engineering (FR)

1. Executive summary On 20 August 2026, Ransomware.live recorded a claim naming Capgemini Engineering, France, as an Everest victim. The claim is single-

20 Aug 2026 Jeff Davies
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

1. Executive summary CVE-2026-32475 is a CWE-434 unrestricted-file-upload vulnerability affecting Elementor Pro versions up to and including 4.2.

19 Aug 2026 Jeff Davies
No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns

1. Executive summary Dark Reading reports that the “Kriminal” AI platform provides guardrail-free social-engineering, offensive-cybercrime and OSINT-scanning capabilities to users

19 Aug 2026 Jeff Davies
NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

1. Executive summary U.S. agencies have warned of an active campaign using AI-assisted exploit scripts and known vulnerabilities to target internet-exposed

19 Aug 2026 Jeff Davies
Ransomware: thegentlemen named CRASL (GB)

1. Executive summary On 19 August 2026, Ransomware.live indexed a ransomware claim naming Suffolk-based CRASL Accounting Services as a victim of “thegentlemen”