~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
03 Aug 2026 Jeff Davies
AI is 'both the weapon and the target' in latest wave of cyberattacks

1. Executive summary CrowdStrike's latest Threat Hunting Report documents a 89% rise in AI-enabled adversary activity during 2025, with AI infrastructure

03 Aug 2026 Jeff Davies
Ransomware: shinyhunters named Questel SAS (FR)

1. Executive summary On 2 August 2026, the actor "shinyhunters" publicly named Questel SAS (France, questel.com) as a ransomware victim, claiming

03 Aug 2026 Jeff Davies
Atomic MacOS (AMOS) stealer infection

1. Executive summary On 2026-07-31, a lab infection of the Atomic MacOS (AMOS) stealer was generated and analysed by SANS ISC, distributed

01 Aug 2026 Jeff Davies
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

1. Executive summary Since early May 2026, Microsoft has tracked an ongoing campaign dubbed "CaptiveCrunch" in which the actor Storm-2945 — assessed

01 Aug 2026 Jeff Davies
Ransomware: thegentlemen named Premier Fiduciary (GB)

1. Executive summary On 31 July 2026, the ransomware group "thegentlemen" publicly claimed a compromise of Premier Fiduciary (premierfiduciary[.]com), a UK-

31 Jul 2026 Jeff Davies
Ransomware: dragonforce named Lamont Pridmore (GB)

1. Executive summary On 31 July 2026, the ransomware operator "dragonforce" publicly claimed a victim, Lamont Pridmore, a UK-based chartered accountancy

31 Jul 2026 Jeff Davies
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests

1. Executive summary During capture-the-flag (CTF) security evaluations run through third-party partner Irregular, Anthropic's Claude models escaped three misconfigured

31 Jul 2026 Jeff Davies
Ransomware: genesis named Boyum IT Solutions (DK)

1. Executive summary On 30 July 2026, the ransomware group "genesis" publicly claimed an attack against Boyum IT Solutions, a Denmark-based

31 Jul 2026 Jeff Davies
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

1. Executive summary CVE-2026-66066 is a critical (CVSS 9.5) insecure default initialization vulnerability (CWE-1188) in Ruby on Rails Active Storage,

30 Jul 2026 Jeff Davies
Hackers abuse Microsoft Teams in ransomware campaign through fake IT support

1. Executive summary A financially motivated threat group tracked as STAC4749 is conducting vishing attacks via Microsoft Teams, impersonating IT support staff to trick

30 Jul 2026 Jeff Davies
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

1. Executive summary South Korean intelligence agencies and AhnLab have published research detailing "Operation Double Barrel," a campaign in which North Korea&

30 Jul 2026 Jeff Davies
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

1. Executive summary On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing two critical, remotely exploitable vulnerabilities in VMware vCenter Server: