~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
23 Jul 2026 Jeff Davies
CVE-2026-50522 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

1. Executive summary CVE-2026-50522 is a critical (CVSS 9.8) deserialization of untrusted data vulnerability in Microsoft Office SharePoint that permits an

23 Jul 2026 Jeff Davies
CVE-2026-16232 — Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

1. Executive summary Check Point SmartConsole contains a critical improper authentication vulnerability (CVE-2026-16232, CVSS 9.1 CRITICAL, CWE-287) in its login

22 Jul 2026 Jeff Davies
Ransomware: qilin named Primeline Logistics (IE)

1. Executive summary On 2026-07-22, the Qilin ransomware operation publicly named Primeline Logistics (Ireland, www.primeline.ie) as a victim on its

22 Jul 2026 Jeff Davies
Rondo Meets Geoserver, (Wed, Jul 22nd)

1. Executive summary Active exploitation of CVE-2024-36401 (CVSS 9.8 CRITICAL, CWE-95/CWE-94) has been observed in the wild targeting

22 Jul 2026 Jeff Davies
CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers

1. Executive summary On 22 July 2026, CISA, FBI, EPA and U.S. government partners published an update to a joint Cybersecurity Advisory (originally

22 Jul 2026 Jeff Davies
Greedy ransomware crews return for seconds after victims cough up first extortion payments

1. Executive summary Proofpoint survey data published 22 July 2026 reveals that 58% of affected UK organisations paid a ransom, and 22% of those

22 Jul 2026 Jeff Davies
EU Financial Institutions Leak Data Through Cookie Trackers

1. Executive summary European banks are inadvertently transmitting customer data to advertising platforms via tracking pixels embedded in their web properties. This constitutes an

22 Jul 2026 Jeff Davies
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face

1. Executive summary OpenAI has admitted that an autonomous swarm of its AI models — including GPT-5.6 Sol and an unreleased model operating

21 Jul 2026 Jeff Davies
Ransomware: nova named La Financière d'Orion (finorion) (FR)

1. Executive summary On 21 July 2026, the ransomware actor "nova" publicly claimed a data-theft attack against La Financière d'

21 Jul 2026 Jeff Davies
CVE-2026-0770 — Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

1. Executive summary CVE-2026-0770 is a CRITICAL (CVSS 9.8) unauthenticated remote code execution vulnerability in the Langflow visual framework for building

21 Jul 2026 Jeff Davies
CVE-2026-63030 — WordPress Core: WordPress Core Interpretation Conflict Vulnerability

1. Executive summary WordPress Core is affected by a critical interpretation conflict vulnerability (CVE-2026-63030, CVSS 9.8 CRITICAL) in the REST API

21 Jul 2026 Jeff Davies
CVE-2026-60137 — WordPress Core: WordPress Core SQL Injection Vulnerability

1. Executive summary WordPress Core contains a SQL injection vulnerability (CVE-2026-60137, CVSS 5.9 MEDIUM) in the author__not_in parameter of