~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
10 Jun 2026 Jeff Davies
The ‘Miasma’ worm source code briefly leaked on GitHub

1. Executive summary The source code for 'Miasma', a credential-stealing supply chain worm previously targeting Red Hat and Microsoft ecosystems, was

10 Jun 2026 Jeff Davies
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

1. Executive summary The ShinyHunters extortion group claims to have compromised over 100 organizations by exploiting a "gadget chain" of legacy and

10 Jun 2026 Jeff Davies
Microsoft patches Exchange Server zero-day exploited in attacks

1. Executive summary Microsoft has released security updates addressing CVE-2026-42897, a high-severity Cross-Site Scripting (XSS) vulnerability in Microsoft Exchange Server

09 Jun 2026 Jeff Davies
ServiceNow discloses security incident exposing customer data

1. Executive summary ServiceNow has confirmed a security incident wherein threat actors exploited an unauthenticated access flaw in a specific API endpoint to query

09 Jun 2026 Jeff Davies
Ransomware: shinyhunters named nottingham.ac.uk (GB)

Issuer: Adverse Trace Date issued: 2026-06-09 Version: 1.0 1. Executive summary The ransomware group "shinyhunters" has claimed responsibility for

09 Jun 2026 Jeff Davies
New Veeam vulnerability exposes backup servers to RCE attacks

Issuer: Adverse Trace Date issued: 2026-06-09 Version: 1.0 1. Executive summary Veeam has released patches for CVE-2026-44963, a critical

09 Jun 2026 Jeff Davies
Miasma worms its way onto GitHub as attack kit goes open source

Issuer: Adverse Trace Date issued: 2026-06-09 Version: 1.0 1. Executive summary The "Miasma" supply-chain attack toolkit, previously used

09 Jun 2026 Jeff Davies
CVE-2026-50751 — Check Point Security Gateway: Check Point Security Gateway Improper Authentication Vulnerability

Issuer: Adverse Trace Date issued: 2026-06-09 Version: 1.0 1. Executive summary Check Point has confirmed active exploitation of CVE-2026-50751,

09 Jun 2026 Jeff Davies
A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7...

Issuer: Adverse Trace Date issued: 2026-06-09 Version: 1.0 1. Executive summary A critical YAML injection vulnerability (CVE-2026-8795) affects Rapid7

09 Jun 2026 Jeff Davies
LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

Issuer: Adverse Trace Date issued: 2026-06-09 Version: 1.0 1. Executive summary Active exploitation of CVE-2026-42271, a command injection flaw

09 Jun 2026 Jeff Davies
Google patches new Chrome zero-day flaw exploited in the wild

Issuer: Adverse Trace Date issued: 2026-06-09 Version: 1.0 1. Executive summary Google has released emergency patches for CVE-2026-11645, a

09 Jun 2026 Jeff Davies
CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

Issuer: Adverse Trace Date issued: 2026-06-09 Version: 1.0 1. Executive summary CISA has added CVE-2026-50751 to its Known Exploited