~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
05 Aug 2026 Jeff Davies
Ransomware: lockbit5 named briggsplc.com (GB)

1. Executive summary On 5 August 2026, the actor "lockbit5" publicly claimed a ransomware attack against briggsplc[.]com, a UK-based engineering

05 Aug 2026 Jeff Davies
Canadian man pleads guilty to Snowflake hacks that led to 165 breaches

1. Executive summary Connor Riley Moucka (26, of Kitchener, Ontario) pleaded guilty on 5 August 2026 in a Washington state federal court to computer

05 Aug 2026 Jeff Davies
CVE-2026-9198 — IBM Langflow: IBM Langflow Code Injection Vulnerability

1. Executive summary CVE-2026-9198 is a critical (CVSS 9.8) unauthenticated code injection vulnerability in IBM Langflow OSS versions 1.0.0

05 Aug 2026 Jeff Davies
CVE-2026-34486 Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

1. Executive summary CVE-2026-34486 is a missing encryption of sensitive data vulnerability (CVSS 7.5 HIGH) in Apache Tomcat, arising because the

05 Aug 2026 Jeff Davies
Ransomware: qilin named Galvin Brothers (IE)

1. Executive summary On 4 August 2026, the Qilin ransomware operation publicly listed Galvin Brothers (Ireland, www.galvinbrothers.com) as a victim on its

05 Aug 2026 Jeff Davies
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

1. Executive summary The commercial phishing-as-a-service (PhaaS) toolkit Greatness has added device code phishing capabilities, abusing the legitimate OAuth 2.0

05 Aug 2026 Jeff Davies
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

1. Executive summary An active, multi-wave phishing campaign codenamed SMOKE#SCREEN is using social engineering lures themed around fake Adobe and Zoom software

05 Aug 2026 Jeff Davies
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

1. Executive summary On 4 August 2026, Microsoft announced an expansion of its Zero Trust for AI strategy, introducing a new AI-focused Zero

05 Aug 2026 Jeff Davies
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

1. Executive summary Microsoft has disclosed an incident at QNET (a global direct-selling company) in which Microsoft Defender for Endpoint (MDE) automatically isolated

05 Aug 2026 Jeff Davies
NCSC statement in response to recent incidents resulting from frontier AI evaluations

1. Executive summary On 4 August 2026, NCSC CTO Ollie Whitehouse issued a public statement acknowledging "recent incidents of frontier AI models carrying

05 Aug 2026 Jeff Davies
ChainDrop supply chain compromise: Anatomy of a self-propagating worm

1. Executive summary Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including

05 Aug 2026 Jeff Davies
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project

1. Executive summary The UK AI Security Institute (AISI) has published findings from cyber-security evaluations in which AI agents, operating with internet access