~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
18 Jun 2026 Jeff Davies
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.

1. Executive summary A data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials

18 Jun 2026 Jeff Davies
F5 Patches Critical, High-Severity NGINX Vulnerabilities

1. Executive summary F5 has released out-of-band security updates addressing multiple vulnerabilities in NGINX, NGINX Plus, and NGINX Gateway Fabric. The two

18 Jun 2026 Jeff Davies
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)

1. Executive summary A server-side request forgery (SSRF) vulnerability exists in Open WebUI's OAuth profile-picture handling that allows an attacker

18 Jun 2026 Jeff Davies
Cisco adds another SD-WAN box to max-severity bug advisory

1. Executive summary Cisco has amended its February 2026 advisory for CVE-2026-20127 (CVSS 10.0, improper authentication) to add Cisco Catalyst SD-

16 Jun 2026 Jeff Davies
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic

1. Executive summary DragonForce ransomware operators have been observed deploying a custom Go-based remote access trojan (RAT) dubbed Backdoor.Turn that tunnels command-

16 Jun 2026 Jeff Davies
From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

1. Executive summary A multi-stage malware campaign delivers the Remcos remote access trojan (RAT) to Windows endpoints via a malicious ZIP archive containing

16 Jun 2026 Jeff Davies
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE

1. Executive summary Unit 42 has disclosed a vulnerability in the Google Cloud Vertex AI Python SDK (google-cloud-aiplatform) that allows an attacker

16 Jun 2026 Jeff Davies
Critical Fortinet FortiSandbox flaws now exploited in attacks

1. Executive summary Threat intelligence firm Defused reports active in-the-wild exploitation of three critical vulnerabilities in Fortinet's FortiSandbox platform (FortiSandbox,

16 Jun 2026 Jeff Davies
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

1. Executive summary North Korea-aligned threat actor ScarCruft (MITRE G0067, also tracked as APT37) is conducting a spear-phishing campaign against targets using

16 Jun 2026 Jeff Davies
EvilTokens: A phishing attack that doesn’t steal your password

1. Executive summary EvilTokens is a phishing-as-a-service (PhaaS) kit that compromises Microsoft 365 accounts by abusing the OAuth 2.0 device

16 Jun 2026 Jeff Davies
Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework

1. Executive summary Sekoia has documented ErrTraffic, a JavaScript-based Malware-as-a-Service (MaaS) framework injected into compromised WordPress sites to deliver ClickFix

16 Jun 2026 Jeff Davies
Cisco SD-WAN make-me-root bug under attack

1. Executive summary Cisco has released a fix for CVE-2026-20262, a file-upload input-validation flaw in the web UI of Cisco