~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
11 Aug 2026 Jeff Davies
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

1. Executive summary Check Point Research has published analysis of an ongoing Operation Dream Job campaign active since early 2026, primarily targeting the global

11 Aug 2026 Jeff Davies
CVE-2026-72898 — Metabase Metabase: Metabase SQL Injection Vulnerability

1. Executive summary CVE-2026-72898 is a CVSS 10.0 CRITICAL SQL injection vulnerability (CWE-89) in Metabase, the open-source business intelligence

11 Aug 2026 Jeff Davies
CVE-2026-68820 — Microsoft Windows Ancillary Function Driver for WinSock : Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

1. Executive summary CVE-2026-68820 is a use-after-free vulnerability (CVSS 7.0, HIGH) in the Windows Ancillary Function Driver for WinSock

11 Aug 2026 Jeff Davies
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)

1. Executive summary Microsoft's August 2026 Patch Tuesday addresses 418 vulnerabilities across its product portfolio, with 62 rated critical. One vulnerability is

11 Aug 2026 Jeff Davies
11 Aug 2026 Jeff Davies
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

1. Executive summary OpenAI has launched GPT-5.6-Cyber, a cybersecurity-focused AI model with significantly reduced refusal rates for dual-use offensive

11 Aug 2026 Jeff Davies
CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors

1. Executive summary CISA, FBI, NSA, DC3, USSS, and the Republic of Korea's KNPA published a joint #StopRansomware advisory on 10 August

11 Aug 2026 Jeff Davies
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

1. Executive summary Microsoft has disclosed that the financially motivated actor Storm-1175 — assessed as China-linked but with no MITRE ATT&CK

11 Aug 2026 Jeff Davies
North Korean spies are running local LLMs to cause AI mischief

1. Executive summary North Korean state-sponsored actor Kimsuky (MITRE G0094) is operating local large language model (LLM) environments and integrating AI capabilities into

11 Aug 2026 Jeff Davies
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

1. Executive summary Microsoft Threat Intelligence has published a detailed technical analysis of DeadLock, a Rust-based ransomware encryptor in active deployment since July

10 Aug 2026 Jeff Davies
Attackers pick Levi's pockets in social engineering attack

1. Executive summary Levi Strauss is investigating a data breach after attackers used social engineering to access three employees' work computers and exfiltrate

10 Aug 2026 Jeff Davies
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

1. Executive summary At DEF CON, Israeli startup Tenet demonstrated "Ghostjacking," a prompt-injection technique that plants malicious instructions inside logs and