~/f4n6 $ adversetrace --mode blog --sovereign true
// latest

When Hosted Frontier AI Failed: Why Hugging Face Turned to Local GLM 5.2

Hugging Face says hosted frontier models blocked its forensic prompts during an AI-driven intrusion. A locally hosted GLM 5.2 helped analyse more than 17,000 events without the evidence or credentials leaving its environment.

read post →
// field notes

Things I build & break

Mirage2FA

Inside Mirage2FA — Reverse-Engineering

Inside Mirage2FA — Reverse-Engineering a Two-Year M365 Phishing Operation Adverse Trace OSINT · 2026-06-29 · TLP:CLEAR Campaign: AT-IR-2026-MIRAGE2FA · Activity: Jun 2024

30 Jun 2026 · 19 min read read →
AI

EvilTokens

Original inspiration for this from https://abnormal.ai/blog/eviltokens-oauth-device-codes-bec-operations EvilTokens Is Still Live: Three Months On, the PhaaS Platform Has

25 Jun 2026 · 19 min read read →
// security feed

Curated, attributed, dated

full feed →
21 Jul 2026 f4n6
AI agents are still logging in as humans

1. Executive summary Okta's Enterprise AI Index, drawing on anonymised sign-on data from over 20,000 organisations (June 2022–June 2026)

21 Jul 2026 f4n6
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

1. Executive summary Pillar Security researchers demonstrated sandbox escapes across four widely used AI coding agents — Cursor, OpenAI Codex CLI, Google Gemini CLI, and

21 Jul 2026 f4n6
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

1. Executive summary JADEPUFFER, an actor attributed by Sysdig to an autonomous LLM-driven AI agent (no MITRE ATT&CK profile exists for

21 Jul 2026 f4n6
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy

1. Executive summary CVE-2026-53359 ("Januscape") is a HIGH-severity (CVSS 8.8) use-after-free vulnerability in the Linux KVM

21 Jul 2026 f4n6
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

1. Executive summary A critical code injection vulnerability (CVE-2026-6875, CVSS 9.5) in the ServiceNow AI Platform is being actively exploited in

view full security feed →