~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
28 Jul 2026 Jeff Davies
Exposed BMCs hand out password hashes before login

1. Executive summary CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol, is actively exposing authentication password hashes from internet-facing

28 Jul 2026 Jeff Davies
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

1. Executive summary Cisco Talos published its Q2 2026 IR trends report, identifying phishing as the dominant initial-access vector (present in >50%

28 Jul 2026 Jeff Davies
July Apple updates are especially important if you receive images

1. Executive summary Apple shipped a July 2026 security patch round covering iOS/iPadOS 26.6, macOS Tahoe 26.6, macOS Sequoia 15.7.

28 Jul 2026 Jeff Davies
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure

1. Executive summary Multiple "confused deputy" vulnerabilities persist in Google Cloud Platform (GCP) and Microsoft Azure, enabling attackers to acquire administrative-level

28 Jul 2026 Jeff Davies
Hackers target US firms in FastJson RCE zero-day attacks

1. Executive summary A critical unauthenticated remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) in Alibaba's FastJson 1.x library

28 Jul 2026 Jeff Davies
Ransomware: safepay named paritaet-nrw.org (DE)

1. Executive summary On 2026-07-27, the ransomware group "safepay" listed the German organisation paritaet-nrw[.]org on its victim site.

28 Jul 2026 Jeff Davies
New Certighost PoC exploit lets attackers hijack Windows domains

1. Executive summary A working proof-of-concept (PoC) exploit for CVE-2026-54121, dubbed "Certighost," has been publicly released, demonstrating how

28 Jul 2026 Jeff Davies
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

1. Executive summary A maximum-severity OS command injection vulnerability, CVE-2026-16812 (CVSS 10.0), in Arista VeloCloud Orchestrator (VCO) on-premises deployments

28 Jul 2026 Jeff Davies
Ransomware: anubis named Prelys Courtage (FR)

1. Executive summary On 28 July 2026, the ransomware group "anubis" publicly claimed a data breach against Prelys Courtage, a major mortgage

28 Jul 2026 Jeff Davies
AutoIT Payload Injector

1. Executive summary An active email campaign distributing a multi-stage AutoIT payload injector has been observed since late July 2026. The attack chain

28 Jul 2026 Jeff Davies
Shadow AI incident response begins with logs that may already be gone

1. Executive summary LevelBlue reports a consistent and growing operational gap in EMEA financial services: employees are using unsanctioned generative AI platforms ("shadow

28 Jul 2026 Jeff Davies
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

1. Executive summary JetBrains has disclosed CVE-2026-63077, a CRITICAL vulnerability (CVSS 9.8, CWE-502 — Deserialization of Untrusted Data) affecting all TeamCity