~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
24 Jul 2026 Jeff Davies
Clop gang targets Windchill, FlexPLM in data theft attacks

1. Executive summary The Clop ransomware gang (also tracked as Cl0p) is actively exploiting CVE-2026-12569, a critical vulnerability (CVSS 9.3) in

23 Jul 2026 Jeff Davies
Year-long Russian attacks infect users as soon as they look at an email

1. Executive summary A Russia-linked threat actor tracked as Laundry Bear (aka Void Blizzard) has been conducting a year-long espionage campaign — ongoing

23 Jul 2026 Jeff Davies
UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations

1. Executive summary On 23 July 2026, the UK NCSC and international partners publicly attributed a "zero-click" phishing campaign targeting Western

23 Jul 2026 Jeff Davies
Russian Global Webmail Espionage

1. Executive summary Unit 42 has published details of a persistent cyberespionage campaign (tracked as CL-STA-1114) actively targeting unpatched Zimbra Collaboration Suite

23 Jul 2026 Jeff Davies
TAG-195 Upgrades MaaS Ecosystem with Modular Tools

1. Executive summary Recorded Future's Insikt Group published research identifying four new malware families — TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator

23 Jul 2026 Jeff Davies
How attackers hosted a fake Claude download page on the claude.ai domain

1. Executive summary A threat actor abused Anthropic's Claude Artifacts feature to host a fake Claude desktop-app download page on the

23 Jul 2026 Jeff Davies
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

1. Executive summary Cisco Talos has published analysis of msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware-as-a-

23 Jul 2026 Jeff Davies
msaRAT malware uses Chrome, Edge browsers to route C2 traffic

1. Executive summary Cisco Talos has identified msaRAT, a new Rust-based remote access trojan attributed to the Chaos ransomware-as-a-service (RaaS)

23 Jul 2026 Jeff Davies
Ransomware: qilin named WellPerf (GB)

1. Executive summary On 2026-07-23, the Qilin ransomware group publicly named WellPerf (UK, www.wellperf.com) as a victim on its leak

23 Jul 2026 Jeff Davies
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

1. Executive summary Check Point has released security updates addressing multiple vulnerabilities in Security Management and Multi-Domain Management (MDSM) products, including CVE-2026-

23 Jul 2026 Jeff Davies
Brazilian Banking Trojan Actively Spreading in Portugal

1. Executive summary A Brazilian banking trojan is actively targeting organisations in Portugal, exploiting the shared Portuguese-language attack surface to increase social-engineering

23 Jul 2026 Jeff Davies
Attackers Are Learning to Live Off the AI Toolchain

1. Executive summary A novel malware toolset dubbed "Sandworm_Mode" has been identified as an early example of threat actors exploiting trusted