~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
23 Jul 2026 Jeff Davies
How attackers hosted a fake Claude download page on the claude.ai domain

1. Executive summary A threat actor abused Anthropic's Claude Artifacts feature to host a fake Claude desktop-app download page on the

23 Jul 2026 Jeff Davies
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

1. Executive summary Cisco Talos has published analysis of msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware-as-a-

23 Jul 2026 Jeff Davies
msaRAT malware uses Chrome, Edge browsers to route C2 traffic

1. Executive summary Cisco Talos has identified msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware-as-a-service (RaaS)

23 Jul 2026 Jeff Davies
Ransomware: qilin named WellPerf (GB)

1. Executive summary On 2026-07-23, the Qilin ransomware group publicly named WellPerf (UK, www.wellperf.com) as a victim on its leak

23 Jul 2026 Jeff Davies
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

1. Executive summary Check Point has released security updates addressing multiple vulnerabilities in Security Management and Multi-Domain Management (MDSM) products, including CVE-2026-

23 Jul 2026 Jeff Davies
Brazilian Banking Trojan Actively Spreading in Portugal

1. Executive summary A Brazilian banking trojan is actively targeting organisations in Portugal, exploiting the shared Portuguese-language attack surface to increase social-engineering

23 Jul 2026 Jeff Davies
Attackers Are Learning to Live Off the AI Toolchain

1. Executive summary A novel malware toolset dubbed "Sandworm_Mode" has been identified as an early example of threat actors exploiting trusted

23 Jul 2026 Jeff Davies
CVE-2026-50522 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

1. Executive summary CVE-2026-50522 is a critical (CVSS 9.8) deserialization of untrusted data vulnerability in Microsoft Office SharePoint that permits an

23 Jul 2026 Jeff Davies
CVE-2026-16232 — Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

1. Executive summary Check Point SmartConsole contains a critical improper authentication vulnerability (CVE-2026-16232, CVSS 9.1 CRITICAL, CWE-287) in its login

22 Jul 2026 Jeff Davies
Ransomware: qilin named Primeline Logistics (IE)

1. Executive summary On 2026-07-22, the Qilin ransomware operation publicly named Primeline Logistics (Ireland, www.primeline.ie) as a victim on its

22 Jul 2026 Jeff Davies
Rondo Meets Geoserver, (Wed, Jul 22nd)

1. Executive summary Active exploitation of CVE-2024-36401 (CVSS 9.8 CRITICAL, CWE-95/CWE-94) has been observed in the wild targeting

22 Jul 2026 Jeff Davies
CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers

1. Executive summary On 22 July 2026, CISA, FBI, EPA and U.S. government partners published an update to a joint Cybersecurity Advisory (originally