~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
29 Jun 2026 Jeff Davies
Ransomware: qilin named Bristol Place (GB)

1. Executive summary On 2026-06-29, ransomware tracking site ransomware.live published a victim listing naming Bristol Place (bristolplace.net, GB) as a

29 Jun 2026 Jeff Davies
Ransomware: qilin named Gsma (GB)

1. Executive summary On 2026-06-29, the ransomware operator/group "qilin" publicly claimed a ransomware attack against Gsma, an organisation based

29 Jun 2026 Jeff Davies
AI may be good at finding security vulnerabilities, but it can't beat human stupidity

1. Executive summary On or around 11 June 2026, threat actors exploited a compromised legacy credential associated with Klue's Salesforce integration to

29 Jun 2026 Jeff Davies
Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines

1. Executive summary Security researchers at Mozilla's Zero Day Investigative Network (0DIN) have demonstrated a proof-of-concept attack that abuses Anthropic&

29 Jun 2026 Jeff Davies
Risky Bulletin: Microsoft disrupts StegoAd operation

1. Executive summary Microsoft's security team has removed 119 malicious Edge extensions from the official Microsoft Edge Add-ons store that were

29 Jun 2026 Jeff Davies
Ransomware: stormous named eogb.co.uk (GB)

1. Executive summary On 2026-06-28, the actor "stormous" publicly claimed a ransomware attack against eogb.co.uk, a UK-registered

26 Jun 2026 Jeff Davies
FBI: Russian hackers now target Signal backup recovery keys

1. Executive summary The FBI and CISA have published an updated public service announcement warning that a phishing campaign attributed to Russian Intelligence Services

26 Jun 2026 Jeff Davies
Malware steals Chrome session cookies to take over your accounts

1. Executive summary A phishing campaign delivering a Windows backdoor via a malicious Chrome extension is actively targeting users. The malware abuses Chrome Native

26 Jun 2026 Jeff Davies
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

1. Executive summary CVE-2026-46331 ("pedit COW") is an out-of-bounds write vulnerability in the Linux kernel's traffic-

26 Jun 2026 Jeff Davies
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

1. Executive summary A new wave of the Miasma/Mini Shai-Hulud supply-chain malware family has compromised at least 24 npm packages (LeoPlatform,

26 Jun 2026 Jeff Davies
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials

1. Executive summary Fortra researchers have identified "Mirage2FA," a phishing kit that uses short-lived HTML smuggling and obfuscated JavaScript loaders to

26 Jun 2026 Jeff Davies
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs

1. Executive summary A new backdoor tracked as Mistic (also tracked as MLTBackdoor) has been deployed in financially motivated intrusions since April 2026, targeting