~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
19 Jun 2026 Jeff Davies
Gentlemen ransomware uses multiple EDR killers to disable defenses

1. Executive summary The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and distributing a suite of endpoint detection and response (EDR)

19 Jun 2026 Jeff Davies
AutoJack: How a single page can RCE the host running your AI agent

1. Executive summary Microsoft Defender Security Research disclosed an exploit chain ("AutoJack") in AutoGen Studio, the open-source prototyping UI for Microsoft

19 Jun 2026 Jeff Davies
Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

1. Executive summary CVE-2026-20253 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Splunk Enterprise, triggered by missing authentication

19 Jun 2026 Jeff Davies
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)

1. Executive summary A phishing campaign targeting customers of Belfius, a major Belgian bank, has been observed using an IPv4-mapped IPv6 address notation

19 Jun 2026 Jeff Davies
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

1. Executive summary CrowdStrike has published research on continued abuse of Microsoft's ClickOnce application deployment technology as a malware delivery and persistence

19 Jun 2026 Jeff Davies
Microsoft working on a fix for RoguePlanet, a flaw that grants full PC control

1. Executive summary A publicly disclosed proof-of-concept (PoC) exploit named RoguePlanet targets a local elevation-of-privilege (EoP) vulnerability in the Microsoft

19 Jun 2026 Jeff Davies
Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries

1. Executive summary A large-scale, currently active credential-compromise campaign — dubbed "FortiBleed" — is targeting internet-exposed Fortinet FortiGate firewalls and VPN

18 Jun 2026 Jeff Davies
Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)

1. Executive summary Oracle's June 2026 Critical Security Patch Update (CSPU) addresses 243 CVEs across 245 patches in 11 product families, with

18 Jun 2026 Jeff Davies
GentleKiller targets more than 400 security processes across 48 products

1. Executive summary ESET has disclosed a portfolio of EDR-killer tools used by the ransomware-as-a-service (RaaS) operation "Gentlemen,"

18 Jun 2026 Jeff Davies
Crypto Clipper uses Tor and worm-like propagation for persistence and control

1. Executive summary Microsoft Threat Intelligence has documented a Windows-based cryptocurrency clipper ("CryptoBandits") active since February 2026 that propagates via malicious

18 Jun 2026 Jeff Davies
Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the...

1. Executive summary A path traversal vulnerability (CVE-2026-55201, High severity, status: Unreviewed) has been disclosed in Evil-WinRM through version 3.9,

18 Jun 2026 Jeff Davies
Massive password-stealing attack hits 75k Fortinet firewalls

1. Executive summary A threat actor has compiled a verified database of working credentials for approximately 75,000 Fortinet / FortiGate firewall devices spanning 21,