~/f4n6 $ adversetrace --mode blog --sovereign true
// latest

GLM 5.3: A Red-Team Model for Blue-Team Work

Z.ai has announced GLM 5.3. It uses the same base model as GLM 5.2. No new pre-training run. No larger foundation model. Z.ai says the improvement comes entirely from

read post →
// field notes

Things I build & break

Mirage2FA

Inside Mirage2FA — Reverse-Engineering

Inside Mirage2FA — Reverse-Engineering a Two-Year M365 Phishing Operation Adverse Trace OSINT · 2026-06-29 · TLP:CLEAR Campaign: AT-IR-2026-MIRAGE2FA · Activity: Jun 2024

30 Jun 2026 · 19 min read read →
// security feed

Curated, attributed, dated

full feed →
16 Aug 2026 f4n6
Ransomware: lockbit5 named dupouy-associes.fr (FR)

1. Executive summary On 16 August 2026, the actor "lockbit5" publicly named dupouy-associes.fr — Dupouy et Associes / Crowe Horwath, a French

16 Aug 2026 f4n6
Metasploit Wrap Up: Lot of summer shells and fit http profiles

1. Executive summary Rapid7 added public Metasploit modules for multiple unauthenticated and authenticated remote-code-execution paths, a Linux local privilege escalation, and Ray

16 Aug 2026 f4n6
Ransomware: qilin named INVENSITY (DE)

1. Executive summary On 16 August 2026, the Qilin ransomware group publicly claimed a victim, INVENSITY, a Germany-based organisation (domain: www.invensity.com)

16 Aug 2026 f4n6
Ransomware: qilin named DELTA WAYS (DE)

1. Executive summary On 16 August 2026, the Qilin ransomware group publicly claimed a victim named DELTA WAYS, a Germany-based organisation (domain: www.

16 Aug 2026 f4n6
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

1. Executive summary Tenable's Research Special Operations (RSO) team has documented a cluster of seven confirmed incidents (November 2025–August 2026) in

view full security feed →