~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
14 Sep 2026 Jeff Davies
What we know about the Revolut data breach so far

1. Executive summary Revolut confirmed on Saturday 12 September 2026 that an attacker impersonating a government agency — sending from an email address on that

14 Sep 2026 Jeff Davies
Ransomware: krybit named eracm.fr (FR)

1. Executive summary On 2026-09-12, a ransomware/extortion group operating under the name "krybit" listed eracm.fr — ERACM, the École

14 Sep 2026 Jeff Davies
Six in 10 Cyberattacks in Colombia Target Hospitals

1. Executive summary A report published 2026-09-13 states that six in ten cyberattacks recorded in Colombia target health sector institutions, citing a

14 Sep 2026 Jeff Davies
Ransomware: qilin named Gilco Scaffolding (GB)

1. Executive summary On 2026-09-13, the ransomware group self-styled "qilin" listed Gilco Scaffolding, a UK-based scaffolding contractor (www.

14 Sep 2026 Jeff Davies
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

1. Executive summary Microsoft Security Research has disclosed two concurrent campaigns: a business email compromise (BEC) operation that sent over one million CEO-impersonation

13 Sep 2026 Jeff Davies
Vulnerability in telnetd

1. Executive summary CVE-2026-24061 is an authentication-bypass flaw in telnetd (GNU InetUtils versions 1.9.3 through 2.7) that allows

13 Sep 2026 Jeff Davies
Ransomware: Vexy Ransomware named Strad Solutions (GB)

1. Executive summary On 2026-09-12, the ransomware operation calling itself "Vexy Ransomware" listed Strad Solutions (GB, stradsolutions.com) on its

13 Sep 2026 Jeff Davies
Ransomware: AuditTeam named Paid Victim FDC699DE3A112669 (DE)

1. Executive summary On 2026-09-13, the ransomware leak-site aggregator Ransomware.live indexed a new victim post attributed to a group calling

12 Sep 2026 Jeff Davies
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

1. Executive summary A report by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx (first reported by The Wall Street Journal) attributes the

12 Sep 2026 Jeff Davies
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

1. Executive summary Proofpoint has documented a previously undocumented exploit kit, "BlueMoon," that chains two Google Chrome V8 zero-days (CVE-2026-

11 Sep 2026 Jeff Davies
CVE-2026-42018 — JFrog Artifactory: JFrog Artifactory Improper Authentication Vulnerability

1. Executive summary CVE-2026-42018 is a HIGH-severity (CVSS 7.5, CWE-287 Improper Authentication) vulnerability in JFrog Artifactory in which an

11 Sep 2026 Jeff Davies
CVE-2026-85706 — GitLab Community Edition and Enterprise Edition: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

1. Executive summary CVE-2026-85706 is a path traversal vulnerability in the GitLab Community Edition and Enterprise Edition repository commits API that allows