~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
13 Aug 2026 Jeff Davies
Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!

1. Executive summary Two cybercriminal groups — Silent Ransom (aka Luna Moth) and BlackFile (now self-styled "Redact") — are actively conducting data-theft

13 Aug 2026 Jeff Davies
Belgium's eID Authentication Opens Citizen Accounts to RCE

1. Executive summary Severe vulnerabilities in a key browser extension underpinning Belgium's electronic ID (eID) trust framework were disclosed on 13 August

13 Aug 2026 Jeff Davies
Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows

1. Executive summary A threat actor using the alias "Nightmare Eclipse" (also known as Chaotic Eclipse, INFINITE NIGHTMARE, MSNightmare) has published a

13 Aug 2026 Jeff Davies
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

1. Executive summary The "City-Forum" campaign has been active since at least March 2025, conducting a long-running data theft operation

13 Aug 2026 Jeff Davies
Ransomware: clop named PHILIPS.COM (NL)

1. Executive summary On 12 August 2026, the Clop ransomware group publicly listed Philips.com (a Dutch multinational health-technology company headquartered in Amsterdam)

13 Aug 2026 Jeff Davies
Ransomware: clop named FISERV.COM (US)

1. Executive summary On 2026-08-12, the Clop ransomware group publicly listed FISERV.COM as a victim on its leak site. Fiserv is

13 Aug 2026 Jeff Davies
How BitLocker PINs help protect your data and devices

1. Executive summary The UK NCSC published guidance reinforcing that BitLocker deployments configured without a pre-boot PIN remain exposed to a class of

13 Aug 2026 Jeff Davies
Armored Likho expands its cyber-espionage toolkit

1. Executive summary Kaspersky GReAT published details of a May 2026 cyber-espionage campaign by the actor "Armored Likho" (also referred to

12 Aug 2026 Jeff Davies
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

1. Executive summary North Korean threat actor Lazarus Group (MITRE G0032) is actively exploiting a newly patched Windows zero-day, CVE-2026-68820, in

12 Aug 2026 Jeff Davies
Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

1. Executive summary A supply chain attack on the open-source LiteLLM Python library and proxy server — traced to a prior compromise of the

12 Aug 2026 Jeff Davies
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

1. Executive summary Threat actors are actively exploiting CVE-2026-59310 (CVSS 9.8, CRITICAL), a path-traversal vulnerability in the VMware vCenter Syslog

12 Aug 2026 Jeff Davies
Lazarus hackers pair fake job offers with Windows zero-day exploit

1. Executive summary The North Korea-linked Lazarus Group (MITRE G0032) is actively exploiting a Windows local privilege escalation zero-day, CVE-2026-68820,