~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
16 Jun 2026 Jeff Davies
Critical Fortinet FortiSandbox flaws now exploited in attacks

1. Executive summary Threat intelligence firm Defused reports active in-the-wild exploitation of three critical vulnerabilities in Fortinet's FortiSandbox platform (FortiSandbox,

16 Jun 2026 Jeff Davies
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

1. Executive summary North Korea-aligned threat actor ScarCruft (MITRE G0067, also tracked as APT37) is conducting a spear-phishing campaign against targets using

16 Jun 2026 Jeff Davies
EvilTokens: A phishing attack that doesn’t steal your password

1. Executive summary EvilTokens is a phishing-as-a-service (PhaaS) kit that compromises Microsoft 365 accounts by abusing the OAuth 2.0 device

16 Jun 2026 Jeff Davies
Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework

1. Executive summary Sekoia has documented ErrTraffic, a JavaScript-based Malware-as-a-Service (MaaS) framework injected into compromised WordPress sites to deliver ClickFix

16 Jun 2026 Jeff Davies
Cisco SD-WAN make-me-root bug under attack

1. Executive summary Cisco has released a fix for CVE-2026-20262, a file-upload input-validation flaw in the web UI of Cisco

16 Jun 2026 Jeff Davies
CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

1. Executive summary CVE-2026-20262 is a directory/path traversal vulnerability (CWE-22) in the web UI of Cisco Catalyst SD-WAN Manager

16 Jun 2026 Jeff Davies
Council of Europe hacked in ShinyHunters' PeopleSoft heist

1. Executive summary The Council of Europe has confirmed it is investigating a breach in which the ShinyHunters extortion crew claims to have stolen

16 Jun 2026 Jeff Davies
Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

1. Executive summary Oracle has issued an out-of-band patch for CVE-2026-35273, a critical vulnerability (CVSS 9.8, IN CISA KEV

14 Jun 2026 Jeff Davies
NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

1. Executive summary GitHub has announced that npm v12 (expected July 2026) will change three security-focused defaults to disrupt the supply-chain attack

13 Jun 2026 Jeff Davies
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

1. Executive summary Splunk has disclosed CVE-2026-20253, a critical (CVSS 9.8) flaw in the Splunk Enterprise PostgreSQL sidecar service that allows

13 Jun 2026 Jeff Davies
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to...

1. Executive summary OpenClaw versions prior to 2026.5.18 contain an authorization bypass vulnerability (CVE-2026-53821) in the Gateway WebSocket control plane.

12 Jun 2026 Jeff Davies
Iranian Cyber Group Handala Claims Cal Water Hack

1. Executive summary The Iran-linked threat actor "Handala" claims to have compromised California Water Service (Cal Water), exfiltrating approximately 5GB of