~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
17 Aug 2026 Jeff Davies
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

1. Executive summary CTM360 reports identifying more than 3,000 recruitment-themed phishing URLs over two months, impersonating recruitment processes linked to more than

17 Aug 2026 Jeff Davies
ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

1. Executive summary A newly disclosed elevation of privilege (EoP) vulnerability in the Microsoft Malware Protection Engine, publicly referred to as "ShieldBreak"

17 Aug 2026 Jeff Davies
Update your Mac: Screen Sharing vulnerability exploited in the wild

1. Executive summary CVE-2026-65400 is a CVSS 9.8 CRITICAL macOS Screen Sharing vulnerability classified as CWE-287 (Improper Authentication); a network

17 Aug 2026 Jeff Davies
680,000 Impacted by French Tax Authority Data Breach

1. Executive summary France's Directorate General of Public Finances (DGFiP) has disclosed a data breach impacting approximately 680,000 individuals. A threat

17 Aug 2026 Jeff Davies
How MCP Servers Can Expose Enterprise Secrets

1. Executive summary Model Context Protocol (MCP) servers — the middleware connecting AI agents to enterprise data, APIs and infrastructure — are accumulating production credentials (API

17 Aug 2026 Jeff Davies
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

1. Executive summary A maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter), tracked as CVE-2026-58231 (CVSS 10.0, CRITICAL, CWE-

17 Aug 2026 Jeff Davies
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

1. Executive summary Rapid7 researchers discovered an exposed web directory on a server supporting a multi-stage cryptocurrency fraud operation tracked as "Operation

17 Aug 2026 Jeff Davies
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI

1. Executive summary Chinese AI company Zhipu announced GLM-5.3, a model it claims surpasses Anthropic and OpenAI offerings on the CyberGym benchmark

17 Aug 2026 Jeff Davies
Risky Bulletin: The EU publishes its upcoming cybersecurity standards

1. Executive summary ETSI has published 17 interim draft cybersecurity standards defining minimum security requirements for product categories — including operating systems, network devices, VPNs,

17 Aug 2026 Jeff Davies
Police bust cybercrime ring accused of stealing €30 million in four-day spree

1. Executive summary German and Brazilian law enforcement have dismantled an international bank fraud ring responsible for stealing approximately €30 million from a German

17 Aug 2026 Jeff Davies
Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

1. Executive summary Microsoft has confirmed an indefinite delay in the release of Exchange Server Subscription Edition (SE) Cumulative Update 1 (CU1), attributing the

17 Aug 2026 Jeff Davies
Fortune 500 Companies Hit in Azure Data Theft Campaign

1. Executive summary SecurityWeek reports that an actor using the moniker “TheHatman” is advertising millions of employee-directory records allegedly obtained from the Azure/