~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
15 Sep 2026 Jeff Davies
UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists

1. Executive summary The UK NCSC, the US FBI and the Netherlands' General Intelligence and Security Service have published a joint advisory exposing

15 Sep 2026 Jeff Davies
Ransomware: qilin named Geieg (ES)

1. Executive summary On 2026-09-15, the ransomware brand "qilin" listed a Spanish victim, Geieg (www.geieg.cat), on its leak

15 Sep 2026 Jeff Davies
Hackers demand 10,000 Bitcoin from Revolut following data breach

1. Executive summary On 2026-09-12 Revolut confirmed that it disclosed sensitive customer records to an unauthorised third party who submitted fraudulent information

15 Sep 2026 Jeff Davies
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

1. Executive summary On 1 September 2026 a China-nexus cluster tracked by Volexity as UTA0560 ran a spear-phishing campaign against multiple non-

15 Sep 2026 Jeff Davies
Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

1. Executive summary Cisco has disclosed CVE-2026-76461, a CVSS 9.8 CRITICAL SQL injection (CWE-89) in AsyncOS for Cisco Secure Email

14 Sep 2026 Jeff Davies
HBO Max Reddit account compromised to serve ClickFix attacks

1. Executive summary Between roughly 6 and 9 September 2026, the verified HBO Max Reddit account (u/hbomax) was compromised and used to run

14 Sep 2026 Jeff Davies
Maximum Severity GitLab Flaw Puts Supply Chains at Risk

1. Executive summary GitLab patched CVE-2026-85706 on 2026-09-10, a path traversal flaw (CWE-22) in the repository commits API affecting

14 Sep 2026 Jeff Davies
CVE-2026-76461 Cisco Secure Email Gateway: Cisco Secure Email Gateway SQL Injection Vulnerability

1. Executive summary CVE-2026-76461 is a SQL injection flaw (CWE-89) in Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) that

14 Sep 2026 Jeff Davies
Ransomware: lockbit5 named comune.robeccosulnaviglio.mi.it (IT)

1. Executive summary On 2026-09-14, the ransomware leak-site aggregator ransomware.live indexed a victim listing under the group name "lockbit5&

14 Sep 2026 Jeff Davies
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

1. Executive summary WordPress.org is adding an automated security review of every plugin release before it is distributed through the WordPress.org update

14 Sep 2026 Jeff Davies
Apple Updates Everything

1. Executive summary On 2026-09-14 Apple shipped its annual coordinated OS refresh — iOS/iPadOS 27, macOS 27 ("Golden Gate"), macOS

14 Sep 2026 Jeff Davies
Possible cyber incident disrupts Monroe schools in Wisconsin

1. Executive summary The School District of Monroe (Wisconsin, USA) has disconnected its internet connectivity following a possible network security incident, with reported loss