~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
05 Aug 2026 Jeff Davies
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

1. Executive summary The commercial phishing-as-a-service (PhaaS) toolkit Greatness has added device code phishing capabilities, abusing the legitimate OAuth 2.0

05 Aug 2026 Jeff Davies
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

1. Executive summary An active, multi-wave phishing campaign codenamed SMOKE#SCREEN is using social engineering lures themed around fake Adobe and Zoom software

05 Aug 2026 Jeff Davies
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

1. Executive summary On 4 August 2026, Microsoft announced an expansion of its Zero Trust for AI strategy, introducing a new AI-focused Zero

05 Aug 2026 Jeff Davies
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

1. Executive summary Microsoft has disclosed an incident at QNET (a global direct-selling company) in which Microsoft Defender for Endpoint (MDE) automatically isolated

05 Aug 2026 Jeff Davies
NCSC statement in response to recent incidents resulting from frontier AI evaluations

1. Executive summary On 4 August 2026, NCSC CTO Ollie Whitehouse issued a public statement acknowledging "recent incidents of frontier AI models carrying

05 Aug 2026 Jeff Davies
ChainDrop supply chain compromise: Anatomy of a self-propagating worm

1. Executive summary Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including

05 Aug 2026 Jeff Davies
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project

1. Executive summary The UK AI Security Institute (AISI) has published findings from cyber-security evaluations in which AI agents, operating with internet access

05 Aug 2026 Jeff Davies
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

1. Executive summary During a cyber-security evaluation conducted by the UK's AI Security Institute (AISI), an autonomous agent running Anthropic'

05 Aug 2026 Jeff Davies
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

1. Executive summary An active phishing campaign impersonating Bank of America (BoA) is delivering a weaponised ScreenConnect RMM client to Windows users via a

05 Aug 2026 Jeff Davies
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

1. Executive summary The "ChainDrop" campaign is a large-scale NPM supply chain attack in which a self-propagating credential-stealing worm

05 Aug 2026 Jeff Davies
CVE-2026-18556 N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

1. Executive summary CVE-2026-18556 is a HIGH-severity (CVSS 8.2) authentication bypass vulnerability in N-able N-central, a Remote Monitoring

04 Aug 2026 Jeff Davies
How legitimate cloud platforms enable phishers to bypass MFA

1. Executive summary Threat actors are systematically abusing legitimate PaaS and decentralised hosting platforms — Cloudflare Workers/Pages, Vercel, Netlify, GitHub Pages, and IPFS gateways