~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
02 Jul 2026 Jeff Davies
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

1. Executive summary A new attack variant dubbed "ConsentFix" is being actively deployed against Microsoft 365 users, combining social engineering with OAuth

02 Jul 2026 Jeff Davies
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

1. Executive summary Kaspersky GReAT has published details of a new toolset dubbed "Umbrij," attributed to the ToddyCat APT (MITRE G1022), which

02 Jul 2026 Jeff Davies
Cisco finally confirms attackers exploiting Unified CM flaw

1. Executive summary Cisco has confirmed active in-the-wild exploitation of CVE-2026-20230, an unauthenticated remote server-side request forgery (SSRF) vulnerability

02 Jul 2026 Jeff Davies
Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released

1. Executive summary A critical vulnerability in Oracle E-Business Suite (EBS) Payments — CVE-2026-46817 — is being actively exploited in the wild following

02 Jul 2026 Jeff Davies
WinRAR flaw could allow attackers to take control of your computer

1. Executive summary Rarlab has patched a remote code execution vulnerability (CVE-2026-14191) in WinRAR and UnRAR affecting RAR5 recovery-volume (.rev) file

02 Jul 2026 Jeff Davies
CVE-2026-45659 — Microsoft SharePoint Server: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

1. Executive summary Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability (CVE-2026-45659, CVSS 8.8 HIGH, CWE-502) enabling authenticated,

02 Jul 2026 Jeff Davies
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

1. Executive summary CISA added CVE-2026-45659 (CVSS 8.8, HIGH) to its Known Exploited Vulnerabilities (KEV) catalog on 2026-07-01, citing

02 Jul 2026 Jeff Davies
Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token

1. Executive summary @apify/actors-mcp-server version 0.10.7 is vulnerable to URL authority injection via the webServerMcpPath field in Actor definitions

02 Jul 2026 Jeff Davies
EvilTokens device-code phishing kit totally more evil than we all thought

1. Executive summary The EvilTokens phishing-as-a-service (PhaaS) platform, which abuses Microsoft's OAuth 2.0 Device Authorization Grant (RFC 8628)

02 Jul 2026 Jeff Davies
FortiBleed credential-theft campaign linked to Lynx ransomware

1. Executive summary The FortiBleed campaign — a large-scale credential-harvesting operation active since February 2026 — has been linked by SOCRadar's Threat

01 Jul 2026 Jeff Davies
Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware

1. Executive summary Palo Alto Networks Unit 42 has published research on "phantom squatting," a technique where attackers register domains that large

01 Jul 2026 Jeff Davies
Massive Password Spray Campaign Targeting Azure CLI

1. Executive summary A massive, ongoing automated password-spray campaign targeting Microsoft's Azure CLI has been observed by Huntress, with over 81