~/f4n6 $ adversetrace --mode blog --sovereign true
// latest

Anatomy of a Ledger Phishing Campaign: From One .eml to Live Credential-Harvesting Infrastructure

One spoofed "Ledger" email led to a 320-site phishing cluster, a deobfuscated seed-phrase harvester on Azure, a fake Ledger Identity API leaking its origin via CNAME, and a lesson in why vision models need a human in the loop.

read post →
// field notes

Things I build & break

// security feed

Curated, attributed, dated

full feed →
04 Sep 2026 f4n6
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

1. Executive summary CVE-2026-6471 ("PostGREShell") is a missing-authorization flaw (CVSS 7.2 HIGH, CWE-862, not in CISA KEV,

04 Sep 2026 f4n6
Large Enterprises Targeted in Fake Merger Acquisition Scams

1. Executive summary The "Phantom Deal" campaign is a social-engineering operation in which threat actors conduct deep reconnaissance on target companies

04 Sep 2026 f4n6
Cisco searched for IOS XR bugs and found so many it rolled them into an update release

1. Executive summary Cisco has disclosed three critical (CVSS 9.8) vulnerabilities following a comprehensive internal security review of IOS XR Software and a

04 Sep 2026 f4n6
Inductive Automation Ignition

1. Executive summary CISA has published ICS advisory ICSA-26-246-06 covering CVE-2026-77393 in Inductive Automation Ignition 8.1.53 and

04 Sep 2026 f4n6
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

1. Executive summary On 3 September 2026, the researcher known as Nightmare Eclipse (aliases Chaotic Eclipse, Infinite Nightmare, MSNightmare) published a working proof-of-

view full security feed →