~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
17 Aug 2026 Jeff Davies
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

1. Executive summary A maximum-severity vulnerability (CVE-2026-58231, CVSS 10.0, CRITICAL) in SAP Commerce Cloud's Data Hub Adapter is

17 Aug 2026 Jeff Davies
Ransomware: bravox named Moores (GB)

1. Executive summary On 2026-08-17, the actor "bravox" publicly named UK company Moores (www.moores.co.uk) as a ransomware

16 Aug 2026 Jeff Davies
Ransomware: lockbit5 named dupouy-associes.fr (FR)

1. Executive summary On 16 August 2026, the actor "lockbit5" publicly named dupouy-associes.fr — Dupouy et Associes / Crowe Horwath, a French

16 Aug 2026 Jeff Davies
Metasploit Wrap Up: Lot of summer shells and fit http profiles

1. Executive summary Rapid7 added public Metasploit modules for multiple unauthenticated and authenticated remote-code-execution paths, a Linux local privilege escalation, and Ray

16 Aug 2026 Jeff Davies
Ransomware: qilin named INVENSITY (DE)

1. Executive summary On 16 August 2026, the Qilin ransomware group publicly claimed a victim, INVENSITY, a Germany-based organisation (domain: www.invensity.com)

16 Aug 2026 Jeff Davies
Ransomware: qilin named DELTA WAYS (DE)

1. Executive summary On 16 August 2026, the Qilin ransomware group publicly claimed a victim named DELTA WAYS, a Germany-based organisation (domain: www.

16 Aug 2026 Jeff Davies
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

1. Executive summary Tenable's Research Special Operations (RSO) team has documented a cluster of seven confirmed incidents (November 2025–August 2026) in

16 Aug 2026 Jeff Davies
OpenAM Insecure SSO Cookie Initialization

1. Executive summary CVE-2026-53660 affects OpenAM Community Edition through version 16.0.6, shipping the iPlanetDirectoryPro SSO cookie with HttpOnly=false and

16 Aug 2026 Jeff Davies
Ransomware: qilin named Connections (BE)

1. Executive summary On 14 August 2026, the Qilin ransomware group publicly claimed a victim named "Connections," a Belgium-based organisation (domain

14 Aug 2026 Jeff Davies
Ransomware: coinbasecartel named Turner and Townsend (GB)

1. Executive summary On 14 August 2026, the actor "coinbasecartel" publicly claimed a ransomware attack against Turner and Townsend, a UK-headquartered

14 Aug 2026 Jeff Davies
French tax authority admits data heist after crook touts 2M records

1. Executive summary On 2026-08-12, a cybercriminal using the alias "ZeroBytes" advertised a database claiming to contain records of more

14 Aug 2026 Jeff Davies
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

1. Executive summary The HoneyMyte APT group (also associated with the MITRE-confirmed actor Mustang Panda, G0129) has significantly upgraded the CoolClient backdoor with