~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
26 Jun 2026 Jeff Davies
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials

1. Executive summary Fortra researchers have identified "Mirage2FA," a phishing kit that uses short-lived HTML smuggling and obfuscated JavaScript loaders to

26 Jun 2026 Jeff Davies
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs

1. Executive summary A new backdoor tracked as Mistic (also tracked as MLTBackdoor) has been deployed in financially motivated intrusions since April 2026, targeting

26 Jun 2026 Jeff Davies
Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses

1. Executive summary The Gamaredon Group (MITRE G0047) — a Russia-linked APT operation attributed to FSB state sponsorship — has reportedly upgraded its malware-loading

25 Jun 2026 Jeff Davies
Bluekit phishing kit adopts browser-in-the-middle for login theft

1. Executive summary The Bluekit phishing-as-a-service (PaaS) platform has added browser-in-the-middle (BitM) capabilities, replacing its previous adversary-in-

25 Jun 2026 Jeff Davies
Stealthy new backdoor emerges in attacks on multiple sectors

1. Executive summary Symantec and Carbon Black's Threat Hunter Team have identified a new backdoor dubbed Mistic (also tracked as MLTBackdoor by

25 Jun 2026 Jeff Davies
Update Chrome to patch critical browser security flaws

1. Executive summary Google released Chrome 149.0.7827.196/197 (Windows/Mac) and 149.0.7827.196 (Linux), patching 18 vulnerabilities including four

25 Jun 2026 Jeff Davies
GitLab Patches Code Execution, Information Disclosure Vulnerabilities

1. Executive summary GitLab has released CE/EE security updates — versions 19.1.1, 19.0.3, and 18.11.6 — patching 13 vulnerabilities

25 Jun 2026 Jeff Davies
Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

1. Executive summary CISA added CVE-2025-67038 (CVSS 9.8 CRITICAL, CWE-94 Code Injection) to its Known Exploited Vulnerabilities (KEV) catalog on

25 Jun 2026 Jeff Davies
Europe Evolves Into Ransomware's Favorite Region

1. Executive summary DarkReading reports a strategic shift by ransomware operators toward European targets, specifically EU organisations and their supply-chain suppliers, following a

25 Jun 2026 Jeff Davies
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns

1. Executive summary A new stealthy backdoor dubbed Mistic (also tracked as MLTBackdoor) has been deployed in financially motivated attacks against organisations in the

25 Jun 2026 Jeff Davies
Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised

1. Executive summary On 2026-06-24, an attacker published malicious versions of 20 npm packages in the Leo Platform ecosystem in a coordinated

25 Jun 2026 Jeff Davies
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access

1. Executive summary Mandiant has published detailed attack-chain analysis of CVE-2026-20245 (CVSS 7.8 HIGH, CWE-116), a now-patched privilege-