~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
17 Sep 2026 Jeff Davies
London property manager breach may have exposed bank details and lockbox codes

1. Executive summary London property management firm City Relay has notified current and former landlords that intruders accessed its Metabase Cloud analytics instance twice,

17 Sep 2026 Jeff Davies
The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

1. Executive summary A previously unknown modular, multi-stage Windows crimeware framework — dubbed MovieReaper — has been distributed at scale since mid-August 2026 through

17 Sep 2026 Jeff Davies
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

1. Executive summary On 15 September 2026 AWS confirmed that customer data and resources hosted exclusively in its Middle East (Bahrain) region (me-south-

17 Sep 2026 Jeff Davies
Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

1. Executive summary Cisco has disclosed CVE-2026-76460, an authentication bypass in an API of Cisco Identity Services Engine (ISE) and ISE Passive

16 Sep 2026 Jeff Davies
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

1. Executive summary Attackers are actively exploiting CVE-2026-89026 (CVSS 9.3, Critical; CWE-321, Use of Hard-coded Cryptographic Key) in Issabel

16 Sep 2026 Jeff Davies
Ransomware: qilin named Thema Foundries (FR)

1. Executive summary On 2026-09-16 the ransomware leak-site aggregator ransomware.live indexed a listing in which the group "qilin"

16 Sep 2026 Jeff Davies
Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’

1. Executive summary The U.S. Coast Guard confirmed it boarded an oil tanker in the Gulf of Mexico on 21 August 2026 after

16 Sep 2026 Jeff Davies
Scans Targeting Hospitality Applications

1. Executive summary A single source IP, 94.102.49.125 (IP Volume, AS202425), has been conducting HTTP reconnaissance against hospitality-sector web applications

16 Sep 2026 Jeff Davies
First Agentic AI Data Breach Reported to Spanish Regulator

1. Executive summary The Spanish Data Protection Agency (AEPD) has published details of what it describes as the first personal-data breach notification in

16 Sep 2026 Jeff Davies
CVE-2026-87886 Acronis Backup: Acronis Backup Incorrect Default Permissions Vulnerability

1. Executive summary CVE-2026-87886 is a high-severity incorrect default permissions flaw in the Acronis Backup plugin for cPanel & WHM and

16 Sep 2026 Jeff Davies
Ransomware: akira named Manders (GB)

1. Executive summary On 2026-09-16 the Akira ransomware group published a victim entry for "Manders" (country listed as GB) on

16 Sep 2026 Jeff Davies
CVE-2026-76460 Cisco Identity Services Engine: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

1. Executive summary On 2026-09-15, CVE-2026-76460 was published for Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector