~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
18 Aug 2026 Jeff Davies
Hunting MacSync Stealer infrastructure through behavioral pivots

1. Executive summary Microsoft Defender Experts published analysis of MacSync Stealer, a macOS-focused information stealer delivered via ClickFix social engineering that tricks users

18 Aug 2026 Jeff Davies
'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture

1. Executive summary Varonis Threat Labs disclosed a prompt-injection technique dubbed "CoSnitch" that manipulates Microsoft Copilot's reasoning engine into

18 Aug 2026 Jeff Davies
Ransomware: shinyhunters named Logitech/ Streamlabs (CH)

1. Executive summary ShinyHunters (MITRE G1057) has publicly named Logitech / Streamlabs (Switzerland) as a ransomware victim on their leak site, issuing a final warning

18 Aug 2026 Jeff Davies
Hacker claims millions of records stolen from corporate Azure tenants

1. Executive summary A threat actor using the alias "TheHatman" claims to have exfiltrated millions of employee records from the Microsoft Azure

18 Aug 2026 Jeff Davies
[NEU] [hoch] SuiteCRM: Schwachstelle ermöglicht SQL-Injection

1. Executive summary BSI/WID has published advisory WID-SEC-2026-2870 reporting a high-severity SQL injection vulnerability in SuiteCRM. A remote, authenticated

18 Aug 2026 Jeff Davies
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

1. Executive summary A single attacker operating from IP 158.220.87.79 (Contabo VPS, Germany) has been systematically scraping unauthenticated guest-accessible data

18 Aug 2026 Jeff Davies
How QR-code phishing can slip past corporate security measures

1. Executive summary QR-code phishing ("quishing") is an active and growing attack vector in which threat actors embed malicious URLs in

18 Aug 2026 Jeff Davies
Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

1. Executive summary The threat actor Storm-0501 (MITRE G1053) is actively conducting cloud ransomware campaigns targeting Microsoft Azure environments. The group has shifted

18 Aug 2026 Jeff Davies
Ransomware: xpl0itrs named BMW Group (DE)

1. Executive summary On 17 August 2026, the actor "xpl0itrs" publicly claimed a ransomware attack against BMW Group (Germany), listing the victim

18 Aug 2026 Jeff Davies
Ransomware: Storm named Penfold (GB)

1. Executive summary On 18 August 2026, the actor "Storm" publicly claimed a ransomware attack against Penfold, a London-based, FCA-regulated

18 Aug 2026 Jeff Davies
Ransomware: lockbit5 named terra-petra.com (DE)

1. Executive summary On 2026-08-18, the actor "lockbit5" publicly claimed a ransomware attack against Terra-Petra (terra-petra[.]com), an

17 Aug 2026 Jeff Davies
CVE-2025-62593 — Ray-Project Ray: Ray-Project Ray Code Injection Vulnerability

1. Executive summary CVE-2025-62593 is a CRITICAL code injection vulnerability (CVSS 9.4) in Ray-Project Ray, an open-source AI compute