~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
24 Jun 2026 Jeff Davies
Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era

1. Executive summary A 29-year-old heap overread vulnerability in the Squid open-source caching proxy, tracked as CVE-2026-47729 and dubbed

24 Jun 2026 Jeff Davies
New macOS ClickFix attack silently mounts DMGs to push infostealer

1. Executive summary A new macOS ClickFix campaign uses fake CAPTCHA pages to trick users into pasting a Terminal command that silently downloads, mounts,

23 Jun 2026 Jeff Davies
SocGholish Takedown Highlights Malicious TDS Threats

1. Executive summary Law enforcement action against the SocGholish malware-as-a-service operation has been reported, drawing attention to the continued use of

23 Jun 2026 Jeff Davies
LastPass confirms data breach in Klue supply chain attack

1. Executive summary On 12 June 2026, LastPass was notified that market-intelligence platform Klue had suffered a security incident in which an attacker

23 Jun 2026 Jeff Davies
Russian Initial Access Broker Behind FortiBleed Campaign

1. Executive summary A financially motivated, Russian-speaking initial access broker (IAB) has been conducting a large-scale credential-harvesting campaign — dubbed FortiBleed — against

23 Jun 2026 Jeff Davies
Python dev saved from disaster by intuition... and AI

1. Executive summary A social-engineering campaign targeting software developers via fake LinkedIn recruiter profiles attempted to deliver a backdoored Node.js repository that

23 Jun 2026 Jeff Davies
He Thought He Was Secure; His Phone Number Got Stolen Anyway

1. Executive summary A SIM swap attack — in which a threat actor convinces or coerces a mobile carrier's staff to port a

23 Jun 2026 Jeff Davies
Guarding AI memory

1. Executive summary Microsoft has published a defensive architecture blog describing how AI "memory" features in M365 Copilot change the threat model

23 Jun 2026 Jeff Davies
Phishing hides in routine Microsoft 365 workflows

1. Executive summary Adversaries are abusing native Microsoft 365 collaboration surfaces — Outlook Groups, shared files, and calendar invitations — to deliver phishing lures that blend

23 Jun 2026 Jeff Davies
When a vendor's breach becomes yours: lessons from the Klue incident

1. Executive summary Market intelligence platform Klue suffered a supply-chain intrusion on 11 June 2026 when a threat actor exploited a compromised legacy

23 Jun 2026 Jeff Davies
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)

1. Executive summary CVE-2024-40766 is an improper access control vulnerability in SonicOS (CVSS 9.3) affecting the management interface and SSLVPN service

23 Jun 2026 Jeff Davies
WhatsApp phishing attack uses fake business docs to hack PCs

1. Executive summary An active malware campaign is distributing malicious VBScript (.vbs) attachments via direct messages on WhatsApp Desktop and WhatsApp Web, using compromised