~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
21 Jul 2026 Jeff Davies
Rockwell Automation Studio 5000 Logix Designer

1. Executive summary CISA has published an advisory detailing three local vulnerabilities in Rockwell Automation Studio 5000 Logix Designer. The flaws (CVE-2026-9108,

21 Jul 2026 Jeff Davies
Kratos phishing-as-a-service kit loses its battle with international law enforcement

1. Executive summary German authorities (ZIT and BKA), supported by the US and Indonesia, have dismantled the primary infrastructure of the Kratos phishing-as-

21 Jul 2026 Jeff Davies
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks

1. Executive summary CrowdStrike has published analysis of SANDWORM_MODE, a multi-stage npm supply chain worm first documented by Socket.dev in February

21 Jul 2026 Jeff Davies
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an...

1. Executive summary A path traversal vulnerability (CVE-2026-15724) affects Progress ShareFile Storage Zones Controller in all versions prior to 5.12.5

21 Jul 2026 Jeff Davies
Police dismantle Kratos phishing platform, arrest developer

1. Executive summary German (ZIT/BKA) and U.S. law enforcement dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform,

21 Jul 2026 Jeff Davies
AI agents are still logging in as humans

1. Executive summary Okta's Enterprise AI Index, drawing on anonymised sign-on data from over 20,000 organisations (June 2022–June 2026)

21 Jul 2026 Jeff Davies
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

1. Executive summary Pillar Security researchers demonstrated sandbox escapes across four widely used AI coding agents — Cursor, OpenAI Codex CLI, Google Gemini CLI, and

21 Jul 2026 Jeff Davies
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

1. Executive summary JADEPUFFER, an actor attributed by Sysdig to an autonomous LLM-driven AI agent (no MITRE ATT&CK profile exists for

21 Jul 2026 Jeff Davies
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy

1. Executive summary CVE-2026-53359 ("Januscape") is a HIGH-severity (CVSS 8.8) use-after-free vulnerability in the Linux KVM

21 Jul 2026 Jeff Davies
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

1. Executive summary A critical code injection vulnerability (CVE-2026-6875, CVSS 9.5) in the ServiceNow AI Platform is being actively exploited in

21 Jul 2026 Jeff Davies
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

1. Executive summary Kaspersky has published analysis of a new .NET Native AOT communication module (AzureCommunication.dll) within the Project CAV3RN cyberespionage framework, targeting

20 Jul 2026 Jeff Davies
From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab

1. Executive summary Rapid7's MDR team discovered an exposed, misconfigured server functioning as a comprehensive malware delivery and QA lab, containing over