~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
01 Jul 2026 Jeff Davies
Risky Bulletin: Researcher drops giant cache of zero-day exploits

1. Executive summary An anonymous researcher using the pseudonym "Bikini" has published proof-of-concept exploit code and write-ups for more

01 Jul 2026 Jeff Davies
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

1. Executive summary Security researcher Bert-Jan Pals analysed approximately 3,000 live ClickFix payloads and revealed that the social-engineering delivery technique has

30 Jun 2026 Jeff Davies
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges...

1. Executive summary CVE-2026-24294 is an improper authentication vulnerability in Windows SMB Server that permits an authorized attacker to elevate privileges locally.

30 Jun 2026 Jeff Davies
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)

1. Executive summary A critical vulnerability in Oracle E-Business Suite (EBS) Payments — CVE-2026-46817 (CVSS 9.8 CRITICAL, CWE-269 / CWE-287)

30 Jun 2026 Jeff Davies
BlueHammer Vulnerability Exploited in Ransomware Attacks

1. Executive summary CVE-2026-33825 ("BlueHammer"), a local privilege escalation vulnerability in Microsoft Defender (CVSS 7.8 HIGH), has been added

30 Jun 2026 Jeff Davies
Securing AI agents: When AI tools move from reading to acting

1. Executive summary Microsoft Incident Response has published a detailed attack pattern in which threat actors poison Model Context Protocol (MCP) tool descriptions to

30 Jun 2026 Jeff Davies
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

1. Executive summary A critical vulnerability in Oracle E-Business Suite (EBS) Oracle Payments — CVE-2026-46817 (CVSS 9.8 CRITICAL; CWE-269 Improper

30 Jun 2026 Jeff Davies
Security researchers tricked LLMs into giving them cocaine recipes by abusing role models for prompt injection

1. Executive summary Independent researchers Charles Ye, Jasmine Cui, and MIT associate professor Dylan Hadfield-Menell have published a paper titled "Prompt Injection

29 Jun 2026 Jeff Davies
'Djinn' Stealer Targets Cloud, AI Credentials

1. Executive summary A previously undocumented cross-platform infostealer dubbed "Djinn Stealer" is being deployed in the wild via exploitation of CVE-

29 Jun 2026 Jeff Davies
Nissan discloses employee data breach linked to Oracle zero-day attacks

1. Executive summary Nissan has disclosed a data breach affecting current and former employees across the US, Canada, Mexico, and Brazil, linked to the

29 Jun 2026 Jeff Davies
The Gentlemen are knocking: сustom backdoors and evolving tactics

1. Executive summary The Gentlemen, a ransomware-as-a-service (RaaS) operation active since mid-2025 and ramping significantly through 2026, has been attributed

29 Jun 2026 Jeff Davies
Nissan says Oracle PeopleSoft break-in may have spilled payroll records, SSNs

1. Executive summary Nissan Americas has notified current and former employees across the US, Canada, Mexico, and Brazil that a cyberattack against Oracle PeopleSoft