~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
12 Aug 2026 Jeff Davies
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

1. Executive summary CISA has ordered U.S. federal agencies to patch CVE-2026-68820 by 25 August 2026 following confirmed in-the-wild

12 Aug 2026 Jeff Davies
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

1. Executive summary A sophisticated, ongoing campaign designated "City-Forum" has been actively exploiting unauthenticated guest user access in Salesforce and ServiceNow

12 Aug 2026 Jeff Davies
“Zoomsday” flaws could let one Zoom participant attack another

1. Executive summary Three memory-safety vulnerabilities in the Zoom annotation parser — CVE-2026-53413 (CVSS 8.3 HIGH, CWE-787 out-of-bounds

12 Aug 2026 Jeff Davies
Cisco says software vulnerability could let hackers crash firewalls

1. Executive summary Cisco has disclosed CVE-2026-20349, a high-severity vulnerability (CVSS 8.6) in Secure Firewall ASA Software and Secure Firewall

12 Aug 2026 Jeff Davies
Ransomware: clop named GATE7LLC.COMGBBEV.COM (GB)

1. Executive summary On 12 August 2026, the clop ransomware group publicly claimed a victim identified as GATE7LLC.COMGBBEV.COM, located in the United

12 Aug 2026 Jeff Davies
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

1. Executive summary Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (415 including two MITRE-assigned CVEs), comprising 42 critical, 355 important,

12 Aug 2026 Jeff Davies
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

1. Executive summary Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities across its product ecosystem, with 62 rated critical. One vulnerability, CVE-

12 Aug 2026 Jeff Davies
PentestGPT: Open-source automated penetration testing agentic framework

1. Executive summary PentestGPT is an open-source, LLM-driven automated penetration testing framework that autonomously executes recon, exploitation, and reporting against a target

12 Aug 2026 Jeff Davies
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

1. Executive summary A researcher operating under the aliases Chaotic Eclipse / Nightmare Eclipse has published a proof-of-concept (PoC) exploit named "ShieldBreak,

11 Aug 2026 Jeff Davies
Fake CCleaner installs GhostDesk Chrome spyware

1. Executive summary A fake CCleaner installer is being distributed via a typosquat/lookalike domain (ccleanerwind[.]top), delivering a multi-stage spyware payload that

11 Aug 2026 Jeff Davies
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

1. Executive summary A ransomware-as-a-service operation tracked as "Gunra" is actively targeting critical infrastructure sectors globally, including financial services,

11 Aug 2026 Jeff Davies
CVE-2026-63520: Microsoft SharePoint Remote Code Execution

1. Executive summary Rapid7 and Microsoft have disclosed CVE-2026-63520, a high-severity (CVSS 8.1) remote code execution vulnerability in Microsoft SharePoint