~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
16 Sep 2026 Jeff Davies
New CISA Guidance Helps Critical Infrastructure Detect, Observe and Impede Malicious Cyber Activity

1. Executive summary On 2026-09-16 CISA published Using Cyber Decoys to Strengthen Detection and Response, its first guide offering a detailed explanation

16 Sep 2026 Jeff Davies
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

1. Executive summary Two critical-severity, unauthenticated code-injection vulnerabilities in The Events Calendar WordPress plugin — a component with more than 600,000 active

16 Sep 2026 Jeff Davies
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

1. Executive summary The FBI, UK NCSC and Netherlands AIVD have published a joint advisory on CHOSEN BRICK, a Windows-only surveillance and data-

16 Sep 2026 Jeff Davies
Spain gets its first taste of AI-aided cyber attack

1. Executive summary Spain's data protection agency (AEPD) has reported the country's first personal data breach attributed to the actions

16 Sep 2026 Jeff Davies
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

1. Executive summary Mandiant's September 2026 report describes an attacker who hijacked an active AI coding-assistant session at an unnamed SaaS

16 Sep 2026 Jeff Davies
CVE-2026-58704 Google Pixel: Google Pixel Improper Authorization Vulnerability

1. Executive summary CVE-2026-58704 is an improper authorization flaw in the cellular modem of Google Pixel devices, where a logic error may

16 Sep 2026 Jeff Davies
AI helps scammers build convincing antivirus renewal pages

1. Executive summary Malwarebytes has published a scam-hunting case study of a fake Avast "subscription renewed" page written in French and

16 Sep 2026 Jeff Davies
Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

1. Executive summary A critical authentication-bypass vulnerability in WSO2 API Manager, CVE-2026-5430, is reported to be under active exploitation in the

16 Sep 2026 Jeff Davies
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

1. Executive summary A critical authentication bypass in WSO2 API Manager and related WSO2 gateway products — CVE-2026-5430, CVSS 10.0 (CRITICAL), CWE-

16 Sep 2026 Jeff Davies
Cyber Op Targets South Korean Media and Automotive Sectors

1. Executive summary A likely North Korean state-linked APT is reported to have used a previously undocumented Linux espionage toolkit to compromise load

16 Sep 2026 Jeff Davies
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

1. Executive summary Elastic Security Labs has documented KREMLIN, a previously undocumented Brazilian banking malware toolkit delivered by an actor it tracks as REF9334

16 Sep 2026 Jeff Davies
Low-quality casino sites conceal highly dangerous threat actors

1. Executive summary Infoblox has published research arguing that Chinese-language casino and adult domains — a population it tracks at roughly 1.7 million