~/f4n6 $ adversetrace --feed --since 30d --attributed
// security feed

Security Feed

Curated advisories, threat briefs & field intel — attributed, dated & severity-tagged. Kept deliberately separate from my own writing.

all CVE advisory ransomware DORA / NIS2 APT
20 Jun 2026 Jeff Davies
New Prinz Eugen ransomware prioritizes recent files for encryption

1. Executive summary A new ransomware operation dubbed Prinz Eugen has been observed targeting organisations with a hands-on-keyboard approach, prioritising recently modified

20 Jun 2026 Jeff Davies
Microsoft links Mastra AI supply chain attack to North Korean hackers

1. Executive summary Microsoft has attributed the compromise of more than 140 npm packages in the @mastra scope to the North Korean state-sponsored

19 Jun 2026 Jeff Davies
FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems

1. Executive summary A dataset dubbed "FortiBleed" containing valid administrative and SSL VPN credentials for approximately 73,932 Fortinet FortiGate firewall URLs

19 Jun 2026 Jeff Davies
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment

1. Executive summary CrowdStrike has published Part 1 of a two-part series documenting abuse of Microsoft's ClickOnce deployment technology. ClickOnce is

19 Jun 2026 Jeff Davies
Cybersecurity Firms Impacted by Klue Supply Chain Attack

1. Executive summary Between 11–17 June 2026, threat actors compromised the backend of Klue, a market-intelligence platform that integrates with multiple SaaS

19 Jun 2026 Jeff Davies
Gentlemen ransomware uses multiple EDR killers to disable defenses

1. Executive summary The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and distributing a suite of endpoint detection and response (EDR)

19 Jun 2026 Jeff Davies
AutoJack: How a single page can RCE the host running your AI agent

1. Executive summary Microsoft Defender Security Research disclosed an exploit chain ("AutoJack") in AutoGen Studio, the open-source prototyping UI for Microsoft

19 Jun 2026 Jeff Davies
Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure

1. Executive summary CVE-2026-20253 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Splunk Enterprise, triggered by missing authentication

19 Jun 2026 Jeff Davies
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)

1. Executive summary A phishing campaign targeting customers of Belfius, a major Belgian bank, has been observed using an IPv4-mapped IPv6 address notation

19 Jun 2026 Jeff Davies
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

1. Executive summary CrowdStrike has published research on continued abuse of Microsoft's ClickOnce application deployment technology as a malware delivery and persistence

19 Jun 2026 Jeff Davies
Microsoft working on a fix for RoguePlanet, a flaw that grants full PC control

1. Executive summary A publicly disclosed proof-of-concept (PoC) exploit named RoguePlanet targets a local elevation-of-privilege (EoP) vulnerability in the Microsoft

19 Jun 2026 Jeff Davies
Active FortiBleed Campaign Impacting Fortinet Devices Across 194 Countries

1. Executive summary A large-scale, currently active credential-compromise campaign — dubbed "FortiBleed" — is targeting internet-exposed Fortinet FortiGate firewalls and VPN