~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
29 Jul 2026 Jeff Davies
Ransomware: qilin named Hoc (GB)

1. Executive summary On 28 July 2026, the Qilin ransomware group publicly claimed a victim named "Hoc" (domain: www.hocltd.com), a

28 Jul 2026 Jeff Davies
Looks like JFrog's 0-days let OpenAI's models hack Hugging Face

1. Executive summary JFrog has released patches for eight zero-day vulnerabilities in self-hosted Artifactory installations (CVE-2026-65617 through CVE-2026-65924)

28 Jul 2026 Jeff Davies
Charity bank pulls online services over security fears

1. Executive summary CAF Bank, a UK charitable foundation-owned bank serving 14,000 charity customers and holding £1.45 billion in deposits, has

28 Jul 2026 Jeff Davies
Exposed BMCs hand out password hashes before login

1. Executive summary CVE-2013-4786, a flaw in the IPMI 2.0 authentication protocol, is actively exposing authentication password hashes from internet-facing

28 Jul 2026 Jeff Davies
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

1. Executive summary Cisco Talos published its Q2 2026 IR trends report, identifying phishing as the dominant initial-access vector (present in >50%

28 Jul 2026 Jeff Davies
July Apple updates are especially important if you receive images

1. Executive summary Apple shipped a July 2026 security patch round covering iOS/iPadOS 26.6, macOS Tahoe 26.6, macOS Sequoia 15.7.

28 Jul 2026 Jeff Davies
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure

1. Executive summary Multiple "confused deputy" vulnerabilities persist in Google Cloud Platform (GCP) and Microsoft Azure, enabling attackers to acquire administrative-level

28 Jul 2026 Jeff Davies
Hackers target US firms in FastJson RCE zero-day attacks

1. Executive summary A critical unauthenticated remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) in Alibaba's FastJson 1.x library

28 Jul 2026 Jeff Davies
Ransomware: safepay named paritaet-nrw.org (DE)

1. Executive summary On 2026-07-27, the ransomware group "safepay" listed the German organisation paritaet-nrw[.]org on its victim site.

28 Jul 2026 Jeff Davies
New Certighost PoC exploit lets attackers hijack Windows domains

1. Executive summary A working proof-of-concept (PoC) exploit for CVE-2026-54121, dubbed "Certighost," has been publicly released, demonstrating how

28 Jul 2026 Jeff Davies
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

1. Executive summary A maximum-severity OS command injection vulnerability, CVE-2026-16812 (CVSS 10.0), in Arista VeloCloud Orchestrator (VCO) on-premises deployments

28 Jul 2026 Jeff Davies
Ransomware: anubis named Prelys Courtage (FR)

1. Executive summary On 28 July 2026, the ransomware group "anubis" publicly claimed a data breach against Prelys Courtage, a major mortgage