~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
25 Jun 2026 Jeff Davies
Microsoft uses AI to link two malware operations in racketeering suit

1. Executive summary On 2026-06-24, Microsoft's Digital Crimes Unit (DCU), Europol, and industry partners (ESET, BitSight, MBSD, IBM X-Force,

25 Jun 2026 Jeff Davies
The Identity Problem Hiding in AI Agent Deployments

1. Executive summary CrowdStrike has published analysis identifying a structural identity-management weakness in enterprise AI agent deployments: OAuth access tokens conforming to RFC

25 Jun 2026 Jeff Davies
Microsoft, Europol lead global takedown of infostealer malware

1. Executive summary On 2026-06-24, Microsoft's Digital Crimes Unit (DCU), Europol, and industry partners (Bitdefender, Bitsight, ESET, IBM X-Force,

25 Jun 2026 Jeff Davies
LastPass says hackers stole customer support case data during Klue breach

1. Executive summary LastPass has disclosed that attackers exfiltrated customer personal information and customer support case records from its Salesforce environment after OAuth tokens

25 Jun 2026 Jeff Davies
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them

1. Executive summary On 2026-06-24, Microsoft's Digital Crimes Unit (DCU), working with Europol and industry partners, announced a coordinated disruption

25 Jun 2026 Jeff Davies
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader

1. Executive summary Kaspersky researchers identified a previously undocumented malware family, "SharkLoader," deployed by a threat cluster tracked as "StrikeShark"

24 Jun 2026 Jeff Davies
Hackers Exploiting Cisco Unified CM Vulnerability

1. Executive summary Threat actors are actively exploiting CVE-2026-20230, a high-severity server-side request forgery (SSRF) flaw in Cisco Unified Communications

24 Jun 2026 Jeff Davies
Flask-Security has an Open Redirect issue

1. Executive summary A vulnerability in the flask_security.utils.validate_redirect_url() function allows an attacker to bypass redirect URL validation when subdomain

24 Jun 2026 Jeff Davies
OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

1. Executive summary OpenClaw's ClawHub marketplace has been found hosting five malicious "skills" (agent plugins) that bypassed both VirusTotal and

24 Jun 2026 Jeff Davies
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

1. Executive summary SentinelLABS has disclosed a Rust-written macOS implant and infostealer, tracked as macOS.Gaslight, that combines conventional macOS tradecraft with a

24 Jun 2026 Jeff Davies
Scope of Salesforce Attacks Expands as Icarus Leaks Data

1. Executive summary Market intelligence platform Klue disclosed on 19 June 2026 that an attacker obtained OAuth tokens used to connect Klue to customer

24 Jun 2026 Jeff Davies
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

1. Executive summary A financially motivated, Russian-speaking initial access broker (IAB) — operating under the handle SantaAd per Palo Alto Networks Unit 42 — has