~/f4n6 $ adversetrace --mode blog --sovereign true
// latest

Three companies, one OAuth token, and the case for sovereign AI

On 19 April 2026, Vercel disclosed a security incident. Within 48 hours, the public attack chain had resolved into something more interesting than the initial "cloud platform breach" framing: an infostealer infection

read post →
// field notes

Things I build & break

AI

GLM-4.7-Flash on Nvidia GB10

So I have gotten into running my own local llm for privacy reasons, and like to use it to assist with incident response tasks and collecting

31 Mar 2026 · 9 min read read →
// security feed

Curated, attributed, dated

full feed →
21 Jul 2026 f4n6
AI agents are still logging in as humans

1. Executive summary Okta's Enterprise AI Index, drawing on anonymised sign-on data from over 20,000 organisations (June 2022–June 2026)

21 Jul 2026 f4n6
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

1. Executive summary Pillar Security researchers demonstrated sandbox escapes across four widely used AI coding agents — Cursor, OpenAI Codex CLI, Google Gemini CLI, and

21 Jul 2026 f4n6
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

1. Executive summary JADEPUFFER, an actor attributed by Sysdig to an autonomous LLM-driven AI agent (no MITRE ATT&CK profile exists for

21 Jul 2026 f4n6
OVH reveals semi-secret plan to fix critical Januscape hypervisor bug with mass reboots – and an Australian crash-test dummy

1. Executive summary CVE-2026-53359 ("Januscape") is a HIGH-severity (CVSS 8.8) use-after-free vulnerability in the Linux KVM

21 Jul 2026 f4n6
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

1. Executive summary A critical code injection vulnerability (CVE-2026-6875, CVSS 9.5) in the ServiceNow AI Platform is being actively exploited in

view full security feed →