~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
10 Aug 2026 Jeff Davies
IT threat evolution in Q2 2026. Non-mobile statistics

1. Executive summary Q2 2026 saw sustained ransomware operational tempo against enterprise targets, with Qilin (no MITRE ATT&CK profile; attribution unconfirmed) accounting

10 Aug 2026 Jeff Davies
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

1. Executive summary Two malicious VS Code extensions — helper-beeps.solidity-pro and web3devtoolsx.solidity-pro — have been identified as delivering a full-spectrum

09 Aug 2026 Jeff Davies
Ransomware: qilin named Clausing (DE)

1. Executive summary On 2026-08-08, the Qilin ransomware group publicly listed Clausing (Germany; www.clausing-tiefbau.com) as a victim on its

07 Aug 2026 Jeff Davies
July 2026 CVE Landscape

1. Executive summary Insikt Group identified 85 high-impact vulnerabilities actively exploited or weaponized in July 2026, a 44% increase from June. Ten of

07 Aug 2026 Jeff Davies
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

1. Executive summary A financially motivated data-theft and extortion campaign attributed to the threat cluster UNC6671 is actively targeting financial services, private equity,

07 Aug 2026 Jeff Davies
Ransomware: spacebears named Hitech Distribuzione Informatica S.r.l. (HTDI) (IT)

1. Executive summary On 2026-08-07, the ransomware operator "spacebears" publicly claimed an attack against Hitech Distribuzione Informatica S.r.l.

07 Aug 2026 Jeff Davies
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

1. Executive summary Security researcher Dirk-jan Mollema demonstrated that malware running in a signed-in Windows session can silently invoke the victim'

06 Aug 2026 Jeff Davies
OWASP 2026 LLM Top 10: “The model will be fooled”

1. Executive summary The OWASP GenAI Security Project released the 2026 edition of its Top 10 for LLM Applications, the first edition weighted by

06 Aug 2026 Jeff Davies
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink

1. Executive summary A sustained, automated SSH credential-stuffing campaign — correlated with the "mdrfckr" SSH campaign — continues to target internet-exposed Linux

05 Aug 2026 Jeff Davies
CVE-2026-63077 — JetBrains TeamCity: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

1. Executive summary CVE-2026-63077 is a critical (CVSS 9.8) deserialization of untrusted data vulnerability in JetBrains TeamCity On-Premises, enabling unauthenticated

05 Aug 2026 Jeff Davies
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm

1. Executive summary On August 4, 2026, an attacker compromised the maintainer account for the widely used keyv and cacheable npm namespaces and published

05 Aug 2026 Jeff Davies
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

1. Executive summary Microsoft Threat Intelligence documents a macOS ClickFix campaign distributing infostealers — including Atomic Stealer (AMOS) and MacSync — through 250+ algorithmically named domains.