<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SecurityXP — Cybersecurity News</title><description>SecurityXP delivers the latest cybersecurity news, CVE alerts, data breach reports, threat intelligence, and hands-on infosec tools for security professionals and IT teams.</description><link>https://securityxp.com/</link><language>en</language><atom:link href="https://securityxp.com/rss.xml" rel="self" type="application/rss+xml"/><item><title>Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds Cybersecurity</title><link>https://securityxp.com/articles/01_dell_bios_flaw_lets_attackers_recover_admin_passwords_from_s/</link><guid isPermaLink="true">https://securityxp.com/articles/01_dell_bios_flaw_lets_attackers_recover_admin_passwords_from_s/</guid><description>Tracked as CVE-2026-40639 and addressed in Dell Security Advisory DSA-2026-197, the issue affects certain Dell client platforms that use the proprietary DVAR...</description><pubDate>Sat, 11 Jul 2026 16:59:40 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Dell_BIOS_Flaw_Lets_Attackers_Recover_Admin_Passwords_From_S.png&quot; alt=&quot;Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds Cybersecurity&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Tracked as CVE-2026-40639 and addressed in Dell Security Advisory DSA-2026-197, the issue affects certain Dell client platforms that use the proprietary DVAR...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Dell_BIOS_Flaw_Lets_Attackers_Recover_Admin_Passwords_From_S.png" length="229119" type="image/png"/><category>Technology</category><author>SecurityXP</author></item><item><title>Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit Cybersecurity</title><link>https://securityxp.com/articles/02_weekly_metasploit_update__exploits_for_flowiseai_csv_agent_a/</link><guid isPermaLink="true">https://securityxp.com/articles/02_weekly_metasploit_update__exploits_for_flowiseai_csv_agent_a/</guid><description>Flowise CSV Agent Prompt Injection RCE Authors: Takahiro Yokoyama and zdi-disclosures Type: Exploit Pull request: 21407 contributed by Takahiro-Yoko Path...</description><pubDate>Sat, 11 Jul 2026 16:59:40 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Weekly_Metasploit_Update__Exploits_for_FlowiseAI_CSV_Agent_a.png&quot; alt=&quot;Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit Cybersecurity&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Flowise CSV Agent Prompt Injection RCE Authors: Takahiro Yokoyama and zdi-disclosures Type: Exploit Pull request: 21407 contributed by Takahiro-Yoko Path...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Weekly_Metasploit_Update__Exploits_for_FlowiseAI_CSV_Agent_a.png" length="229119" type="image/png"/><category>Technology</category><author>SecurityXP</author></item><item><title>Critical vulnerability in Red Hat OpenShift AI (RHOAI) Cybersecurity (CVE-2026-15378)</title><link>https://securityxp.com/articles/03_critical_vulnerability_in_red_hat_openshift_ai__rhoai/</link><guid isPermaLink="true">https://securityxp.com/articles/03_critical_vulnerability_in_red_hat_openshift_ai__rhoai/</guid><description>Skip to navigation Skip to main content Utilities Subscriptions Downloads Red Hat Console Get Support Subscriptions Downloads Red Hat Console Get Support...</description><pubDate>Sat, 11 Jul 2026 16:59:40 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Critical_vulnerability_in_Red_Hat_OpenShift_AI__RHOAI.png&quot; alt=&quot;Critical vulnerability in Red Hat OpenShift AI (RHOAI) Cybersecurity (CVE-2026-15378)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Skip to navigation Skip to main content Utilities Subscriptions Downloads Red Hat Console Get Support Subscriptions Downloads Red Hat Console Get Support...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Critical_vulnerability_in_Red_Hat_OpenShift_AI__RHOAI.png" length="229119" type="image/png"/><category>Technology</category><author>SecurityXP</author></item><item><title>WP-SHELLSTORM Exposed: Hackers Backdoored Thousands of WordPress Websites Cybersecurity</title><link>https://securityxp.com/articles/01_wp-shellstorm_exposed__hackers_backdoored_thousands_of_wordp/</link><guid isPermaLink="true">https://securityxp.com/articles/01_wp-shellstorm_exposed__hackers_backdoored_thousands_of_wordp/</guid><description>Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA&apos;s actively-exploited list, even...</description><pubDate>Fri, 10 Jul 2026 21:19:38 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_WP-SHELLSTORM_Exposed__Hackers_Backdoored_Thousands_of_WordP.png&quot; alt=&quot;WP-SHELLSTORM Exposed: Hackers Backdoored Thousands of WordPress Websites Cybersecurity&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA&apos;s actively-exploited list, even...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_WP-SHELLSTORM_Exposed__Hackers_Backdoored_Thousands_of_WordP.png" length="229119" type="image/png"/><category>Technology</category><author>SecurityXP</author></item><item><title>Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat Cybersecurity</title><link>https://securityxp.com/articles/03_progress_urges_sharefile_admins_to_shut_down_servers_over_cr/</link><guid isPermaLink="true">https://securityxp.com/articles/03_progress_urges_sharefile_admins_to_shut_down_servers_over_cr/</guid><description>In April 2026, watchTowr Labs disclosed two chainable vulnerabilities in Storage Zone Controller: CVE-2026-2699, an authentication bypass with a CVSS score...</description><pubDate>Fri, 10 Jul 2026 21:19:38 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Progress_Urges_ShareFile_Admins_to_Shut_Down_Servers_Over_Cr.png&quot; alt=&quot;Progress Urges ShareFile Admins to Shut Down Servers Over Credible Security Threat Cybersecurity&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;In April 2026, watchTowr Labs disclosed two chainable vulnerabilities in Storage Zone Controller: CVE-2026-2699, an authentication bypass with a CVSS score...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Progress_Urges_ShareFile_Admins_to_Shut_Down_Servers_Over_Cr.png" length="229119" type="image/png"/><category>Technology</category><author>SecurityXP</author></item><item><title>Hitachi Energy e-mesh EMS Vulnerability (CVE-2026-42945)</title><link>https://securityxp.com/articles/01_hitachi_energy_e-mesh_ems/</link><guid isPermaLink="true">https://securityxp.com/articles/01_hitachi_energy_e-mesh_ems/</guid><description>The following versions of Hitachi Energy e-mesh EMS are affected: - Hitachi Energy e-mesh EMS 4.1.6, 4.4.2, 4.7.0 Background - Critical Infrastructure...</description><pubDate>Tue, 07 Jul 2026 18:00:07 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Hitachi_Energy_e-mesh_EMS.png&quot; alt=&quot;Hitachi Energy e-mesh EMS Vulnerability (CVE-2026-42945)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The following versions of Hitachi Energy e-mesh EMS are affected: - Hitachi Energy e-mesh EMS 4.1.6, 4.4.2, 4.7.0 Background - Critical Infrastructure...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Hitachi_Energy_e-mesh_EMS.png" length="203031" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Critical Gitea Flaw Under Active Exploitation, Researchers Warn Vulnerability (CVE-2026-20896)</title><link>https://securityxp.com/articles/02_critical_gitea_flaw_under_active_exploitation__researchers_w/</link><guid isPermaLink="true">https://securityxp.com/articles/02_critical_gitea_flaw_under_active_exploitation__researchers_w/</guid><description>Specific to Gitea’s official Docker images, the critical-severity security defect is tracked as CVE-2026-20896 (CVSS score of 9.8) and can be exploited with...</description><pubDate>Tue, 07 Jul 2026 18:00:07 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Critical_Gitea_Flaw_Under_Active_Exploitation__Researchers_W.png&quot; alt=&quot;Critical Gitea Flaw Under Active Exploitation, Researchers Warn Vulnerability (CVE-2026-20896)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Specific to Gitea’s official Docker images, the critical-severity security defect is tracked as CVE-2026-20896 (CVSS score of 9.8) and can be exploited with...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Critical_Gitea_Flaw_Under_Active_Exploitation__Researchers_W.png" length="203031" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Cloudflare proudly joins the UK government&apos;s Cyber Resilience Pledge Cybercrime</title><link>https://securityxp.com/articles/03_cloudflare_proudly_joins_the_uk_government_s_cyber_resilienc/</link><guid isPermaLink="true">https://securityxp.com/articles/03_cloudflare_proudly_joins_the_uk_government_s_cyber_resilienc/</guid><description>This trend is consistent with broader data from the UK Cyber Security Breaches Survey, which revealed that 43% of surveyed British businesses and 28% of...</description><pubDate>Tue, 07 Jul 2026 18:00:07 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Cloudflare_proudly_joins_the_UK_government_s_Cyber_Resilienc.png&quot; alt=&quot;Cloudflare proudly joins the UK government&apos;s Cyber Resilience Pledge Cybercrime&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This trend is consistent with broader data from the UK Cyber Security Breaches Survey, which revealed that 43% of surveyed British businesses and 28% of...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Cloudflare_proudly_joins_the_UK_government_s_Cyber_Resilienc.png" length="229119" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>SOCRadar links FortiBleed campaign targeting manufacturers to Lynx and INC ransomware attacks</title><link>https://securityxp.com/articles/02_socradar_links_fortibleed_campaign_targeting_manufacturers_t/</link><guid isPermaLink="true">https://securityxp.com/articles/02_socradar_links_fortibleed_campaign_targeting_manufacturers_t/</guid><description>The hacker likely already found and exploited a zero-day vulnerability in Nextcloud, an open-source content collaboration platform. They also built ‘PENTEST...</description><pubDate>Tue, 07 Jul 2026 16:16:13 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_SOCRadar_links_FortiBleed_campaign_targeting_manufacturers_t.png&quot; alt=&quot;SOCRadar links FortiBleed campaign targeting manufacturers to Lynx and INC ransomware attacks&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The hacker likely already found and exploited a zero-day vulnerability in Nextcloud, an open-source content collaboration platform. They also built ‘PENTEST...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_SOCRadar_links_FortiBleed_campaign_targeting_manufacturers_t.png" length="232765" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP</author></item><item><title>ABB launches FIM 3.5 with vendor-neutral automated firmware updates for industrial field devices</title><link>https://securityxp.com/articles/04_abb_launches_fim_3_5_with_vendor-neutral_automated_firmware/</link><guid isPermaLink="true">https://securityxp.com/articles/04_abb_launches_fim_3_5_with_vendor-neutral_automated_firmware/</guid><description>ABB announced launch of ABB Ability Field Information Manager (FIM) 3.5, a vendor-neutral platform for automated field device firmware updates. FIM 3.5...</description><pubDate>Tue, 07 Jul 2026 16:16:13 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_ABB_launches_FIM_3_5_with_vendor-neutral_automated_firmware.png&quot; alt=&quot;ABB launches FIM 3.5 with vendor-neutral automated firmware updates for industrial field devices&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;ABB announced launch of ABB Ability Field Information Manager (FIM) 3.5, a vendor-neutral platform for automated field device firmware updates. FIM 3.5...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_ABB_launches_FIM_3_5_with_vendor-neutral_automated_firmware.png" length="229119" type="image/png"/><category>IoT Security</category><author>SecurityXP</author></item><item><title>Cydome reports FortiBleed credential leak poses elevated risks to maritime and energy critical infrastructure</title><link>https://securityxp.com/articles/02_cydome_reports_fortibleed_credential_leak_poses_elevated_ris/</link><guid isPermaLink="true">https://securityxp.com/articles/02_cydome_reports_fortibleed_credential_leak_poses_elevated_ris/</guid><description>On a vessel without clean IT and OT separation, that same path can reach bridge systems, cargo management, and VSAT links.” Fortinet officially characterizes...</description><pubDate>Tue, 07 Jul 2026 14:19:56 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Cydome_reports_FortiBleed_credential_leak_poses_elevated_ris.png&quot; alt=&quot;Cydome reports FortiBleed credential leak poses elevated risks to maritime and energy critical infrastructure&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;On a vessel without clean IT and OT separation, that same path can reach bridge systems, cargo management, and VSAT links.” Fortinet officially characterizes...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Cydome_reports_FortiBleed_credential_leak_poses_elevated_ris.png" length="229119" type="image/png"/><category>ICS/OT Security</category><author>SecurityXP</author></item><item><title>Beyond safety and security: Why automotive open source demands dependability Compliance</title><link>https://securityxp.com/articles/03_beyond_safety_and_security__why_automotive_open_source_deman/</link><guid isPermaLink="true">https://securityxp.com/articles/03_beyond_safety_and_security__why_automotive_open_source_deman/</guid><description>Bridging the gap between the upstream velocity of Linux and the downstream rigor of automotive standards requires more than just a repository: it requires a...</description><pubDate>Tue, 07 Jul 2026 14:19:56 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Beyond_safety_and_security__Why_automotive_open_source_deman.png&quot; alt=&quot;Beyond safety and security: Why automotive open source demands dependability Compliance&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Bridging the gap between the upstream velocity of Linux and the downstream rigor of automotive standards requires more than just a repository: it requires a...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Beyond_safety_and_security__Why_automotive_open_source_deman.png" length="213178" type="image/png"/><category>Compliance &amp; Privacy</category><author>SecurityXP</author></item><item><title>Critical Adobe ColdFusion Vulnerability Exploited in Attacks (CVE-2026-48282)</title><link>https://securityxp.com/articles/01_critical_adobe_coldfusion_vulnerability_exploited_in_attacks/</link><guid isPermaLink="true">https://securityxp.com/articles/01_critical_adobe_coldfusion_vulnerability_exploited_in_attacks/</guid><description>However, according to the vulnerability intelligence platform KEVIntel, hackers began exploiting CVE-2026-48282 within two hours of its public disclosure...</description><pubDate>Tue, 07 Jul 2026 14:04:50 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Critical_Adobe_ColdFusion_Vulnerability_Exploited_in_Attacks.png&quot; alt=&quot;Critical Adobe ColdFusion Vulnerability Exploited in Attacks (CVE-2026-48282)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;However, according to the vulnerability intelligence platform KEVIntel, hackers began exploiting CVE-2026-48282 within two hours of its public disclosure...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Critical_Adobe_ColdFusion_Vulnerability_Exploited_in_Attacks.png" length="203031" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>OpenAI Codex Desktop App for macOS Vulnerability Allows Attackers to Inject Indirect Prompt</title><link>https://securityxp.com/articles/02_openai_codex_desktop_app_for_macos_vulnerability_allows_atta/</link><guid isPermaLink="true">https://securityxp.com/articles/02_openai_codex_desktop_app_for_macos_vulnerability_allows_atta/</guid><description>As AI-assisted development tools continue to gain adoption, vulnerabilities like CVE-2026-14898 underscore the need for secure design practices that account...</description><pubDate>Tue, 07 Jul 2026 14:04:50 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_OpenAI_Codex_Desktop_App_for_macOS_Vulnerability_Allows_Atta.png&quot; alt=&quot;OpenAI Codex Desktop App for macOS Vulnerability Allows Attackers to Inject Indirect Prompt&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As AI-assisted development tools continue to gain adoption, vulnerabilities like CVE-2026-14898 underscore the need for secure design practices that account...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_OpenAI_Codex_Desktop_App_for_macOS_Vulnerability_Allows_Atta.png" length="167143" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Threat Modeling Generative AI: What 11,658 Incidents Reveal About Real-World Risk</title><link>https://securityxp.com/articles/03_threat_modeling_generative_ai__what_11_658_incidents_and_the/</link><guid isPermaLink="true">https://securityxp.com/articles/03_threat_modeling_generative_ai__what_11_658_incidents_and_the/</guid><description>Instead, improper output handling (42%) and misinformation/misuse (35%) represent the vast majority of actual incidents.</description><pubDate>Sun, 05 Jul 2026 18:32:10 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Threat_Modeling_Generative_AI__What_11_658_Incidents_and_the.png&quot; alt=&quot;Threat Modeling Generative AI: What 11,658 Incidents Reveal About Real-World Risk&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Instead, improper output handling (42%) and misinformation/misuse (35%) represent the vast majority of actual incidents.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Threat_Modeling_Generative_AI__What_11_658_Incidents_and_the.png" length="167143" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>bingo-ai 3.6.3 Vulnerability</title><link>https://securityxp.com/articles/04_bingo-ai_3_6_3/</link><guid isPermaLink="true">https://securityxp.com/articles/04_bingo-ai_3_6_3/</guid><description>Blind Signing / EIP-7730 (Bybit $1.5B Attack Vector) The Bybit $1.5B hack (Feb 2025) exploited a Safe multisig blind signing flaw: - Attackers changed...</description><pubDate>Sat, 04 Jul 2026 16:02:42 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_bingo-ai_3_6_3.png&quot; alt=&quot;bingo-ai 3.6.3 Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Blind Signing / EIP-7730 (Bybit $1.5B Attack Vector) The Bybit $1.5B hack (Feb 2025) exploited a Safe multisig blind signing flaw: - Attackers changed...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_bingo-ai_3_6_3.png" length="203031" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures Malware</title><link>https://securityxp.com/articles/ousaban-banking-trojan-targets-iberian-bank-users-with-fake-pdf-lures-malware/</link><guid isPermaLink="true">https://securityxp.com/articles/ousaban-banking-trojan-targets-iberian-bank-users-with-fake-pdf-lures-malware/</guid><description>This malware employs sophisticated techniques to evade detection and steal banking credentials, The Hacker News reports.The Ousaban campaign begins with a phishing PDF disguised as a corrupted file, p...</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/ousaban-banking-trojan-targets-iberian-bank-users-with-fake-pdf-lures-malware.png&quot; alt=&quot;Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures Malware&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This malware employs sophisticated techniques to evade detection and steal banking credentials, The Hacker News reports.The Ousaban campaign begins with a phishing PDF disguised as a corrupted file, p...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/ousaban-banking-trojan-targets-iberian-bank-users-with-fake-pdf-lures-malware.png" length="94576" type="image/png"/><category>Technology</category><author>SecurityXP Intelligence Desk</author></item><item><title>Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall</title><link>https://securityxp.com/articles/secure-amazon-container-workloads-using-container-attribute-based-rules-in-aws/</link><guid isPermaLink="true">https://securityxp.com/articles/secure-amazon-container-workloads-using-container-attribute-based-rules-in-aws/</guid><description>If you run AI and machine learning (ML) workloads on Amazon EKS, such as model inference, RAG pipelines, or JupyterHub, your containerized workloads require the same firewall protections you enforce f...</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/secure-amazon-container-workloads-using-container-attribute-based-rules-in-aws.png&quot; alt=&quot;Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;If you run AI and machine learning (ML) workloads on Amazon EKS, such as model inference, RAG pipelines, or JupyterHub, your containerized workloads require the same firewall protections you enforce f...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/secure-amazon-container-workloads-using-container-attribute-based-rules-in-aws.png" length="101660" type="image/png"/><category>Technology</category><author>SecurityXP Intelligence Desk</author></item><item><title>Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer Vulnerability</title><link>https://securityxp.com/articles/01_attackers_exploit_simplehelp_cve-2026-48558_to_deploy_taskwe/</link><guid isPermaLink="true">https://securityxp.com/articles/01_attackers_exploit_simplehelp_cve-2026-48558_to_deploy_taskwe/</guid><description>&quot;Credentials accessible from a developer or administrator workstation may provide entry into production infrastructure, build pipelines, source code...</description><pubDate>Wed, 01 Jul 2026 15:08:10 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Attackers_Exploit_SimpleHelp_CVE-2026-48558_to_Deploy_TaskWe.png&quot; alt=&quot;Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;&quot;Credentials accessible from a developer or administrator workstation may provide entry into production infrastructure, build pipelines, source code...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Attackers_Exploit_SimpleHelp_CVE-2026-48558_to_Deploy_TaskWe.png" length="203031" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild Vulnerability</title><link>https://securityxp.com/articles/01_cisco_unified_cm_flaw_cve-2026-20230_actively_exploited_in_t/</link><guid isPermaLink="true">https://securityxp.com/articles/01_cisco_unified_cm_flaw_cve-2026-20230_actively_exploited_in_t/</guid><description>Cisco Unified Communications Manager has a serious vulnerability, tracked as CVE-2026-20230 (CVSS score of 8.6), that attackers are already exploiting. The...</description><pubDate>Wed, 24 Jun 2026 14:04:31 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Cisco_Unified_CM_Flaw_CVE-2026-20230_Actively_Exploited_in_t.png&quot; alt=&quot;Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cisco Unified Communications Manager has a serious vulnerability, tracked as CVE-2026-20230 (CVSS score of 8.6), that attackers are already exploiting. The...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Cisco_Unified_CM_Flaw_CVE-2026-20230_Actively_Exploited_in_t.png" length="203031" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>From Platform to Program: How to Ensure Your Cloud Security Solution Delivers</title><link>https://securityxp.com/articles/04_from_platform_to_program__how_to_ensure_your_cloud_security/</link><guid isPermaLink="true">https://securityxp.com/articles/04_from_platform_to_program__how_to_ensure_your_cloud_security/</guid><description>Orca’s 2026 State of Application Security Report found that 77% of organizations retain high or critical container vulnerabilities for more than 90 days, a...</description><pubDate>Wed, 24 Jun 2026 14:04:31 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_From_Platform_to_Program__How_to_Ensure_Your_Cloud_Security.png&quot; alt=&quot;From Platform to Program: How to Ensure Your Cloud Security Solution Delivers&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Orca’s 2026 State of Application Security Report found that 77% of organizations retain high or critical container vulnerabilities for more than 90 days, a...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_From_Platform_to_Program__How_to_Ensure_Your_Cloud_Security.png" length="236546" type="image/png"/><category>Cloud Security</category><author>SecurityXP</author></item><item><title>Scattered Spider Hackers Plead Guilty on Day 1 of Trial Cybercrime</title><link>https://securityxp.com/articles/01_scattered_spider_hackers_plead_guilty_on_day_1_of_trial/</link><guid isPermaLink="true">https://securityxp.com/articles/01_scattered_spider_hackers_plead_guilty_on_day_1_of_trial/</guid><description>According to the NCA, the cyberattack at TfL forced all 28,000 employees to visit their local offices to reset their passwords and caused £29 million...</description><pubDate>Tue, 23 Jun 2026 17:00:25 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Scattered_Spider_Hackers_Plead_Guilty_on_Day_1_of_Trial.png&quot; alt=&quot;Scattered Spider Hackers Plead Guilty on Day 1 of Trial Cybercrime&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;According to the NCA, the cyberattack at TfL forced all 28,000 employees to visit their local offices to reset their passwords and caused £29 million...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Scattered_Spider_Hackers_Plead_Guilty_on_Day_1_of_Trial.png" length="229119" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>AWS Warns Outbound Traffic Blind Spots Can Enable Cloud Data Exfiltration Cloud Security</title><link>https://securityxp.com/articles/04_aws_warns_outbound_traffic_blind_spots_can_enable_cloud_data/</link><guid isPermaLink="true">https://securityxp.com/articles/04_aws_warns_outbound_traffic_blind_spots_can_enable_cloud_data/</guid><description>The AWS report shared with Cyber Security News (CSN) points to cases where unpatched vulnerabilities, such as CVE-2025-55182 (React2Shell), allowed attackers...</description><pubDate>Tue, 23 Jun 2026 17:00:25 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_AWS_Warns_Outbound_Traffic_Blind_Spots_Can_Enable_Cloud_Data.png&quot; alt=&quot;AWS Warns Outbound Traffic Blind Spots Can Enable Cloud Data Exfiltration Cloud Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The AWS report shared with Cyber Security News (CSN) points to cases where unpatched vulnerabilities, such as CVE-2025-55182 (React2Shell), allowed attackers...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_AWS_Warns_Outbound_Traffic_Blind_Spots_Can_Enable_Cloud_Data.png" length="236546" type="image/png"/><category>Cloud Security</category><author>SecurityXP</author></item><item><title>Texas Parks &amp; Wildlife Data Breach Affects 3 Million Individuals</title><link>https://securityxp.com/articles/01_texas_parks___wildlife_data_breach_affects_3_million_individ/</link><guid isPermaLink="true">https://securityxp.com/articles/01_texas_parks___wildlife_data_breach_affects_3_million_individ/</guid><description>Related: Data Breaches at Healthcare Organizations in Illinois and Texas Affect 600,000 Related: 377,000 Impacted by Data Breach at Texas Gas Station Firm...</description><pubDate>Mon, 22 Jun 2026 15:23:03 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Texas_Parks___Wildlife_Data_Breach_Affects_3_Million_Individ.png&quot; alt=&quot;Texas Parks &amp; Wildlife Data Breach Affects 3 Million Individuals&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Related: Data Breaches at Healthcare Organizations in Illinois and Texas Affect 600,000 Related: 377,000 Impacted by Data Breach at Texas Gas Station Firm...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Texas_Parks___Wildlife_Data_Breach_Affects_3_Million_Individ.png" length="193288" type="image/png"/><category>Data Breaches</category><author>SecurityXP</author></item><item><title>On-Premises API Security on Kubernetes: What It Actually Looks Like in Practice App Security</title><link>https://securityxp.com/articles/03_on-premises_api_security_on_kubernetes__what_it_actually_loo/</link><guid isPermaLink="true">https://securityxp.com/articles/03_on-premises_api_security_on_kubernetes__what_it_actually_loo/</guid><description>PCI DSS 4.0.1 now requires continuous API security testing and maintained API inventories. (These PCI DSS 4.0.1 requirements became mandatory on March 31...</description><pubDate>Mon, 22 Jun 2026 15:23:03 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_On-Premises_API_Security_on_Kubernetes__What_It_Actually_Loo.png&quot; alt=&quot;On-Premises API Security on Kubernetes: What It Actually Looks Like in Practice App Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;PCI DSS 4.0.1 now requires continuous API security testing and maintained API inventories. (These PCI DSS 4.0.1 requirements became mandatory on March 31...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_On-Premises_API_Security_on_Kubernetes__What_It_Actually_Loo.png" length="229119" type="image/png"/><category>Application Security</category><author>SecurityXP</author></item><item><title>Sunil Varkey Joins Hexaware Technologies as EVP &amp; CISO Cybersecurity Careers</title><link>https://securityxp.com/articles/04_sunil_varkey_joins_hexaware_technologies_as_evp___ciso/</link><guid isPermaLink="true">https://securityxp.com/articles/04_sunil_varkey_joins_hexaware_technologies_as_evp___ciso/</guid><description>His responsibilities align with Hexaware Technologies’ broader technology and growth objectives as the company continues to support large-scale digital...</description><pubDate>Mon, 22 Jun 2026 15:23:03 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_Sunil_Varkey_Joins_Hexaware_Technologies_as_EVP___CISO.png&quot; alt=&quot;Sunil Varkey Joins Hexaware Technologies as EVP &amp; CISO Cybersecurity Careers&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;His responsibilities align with Hexaware Technologies’ broader technology and growth objectives as the company continues to support large-scale digital...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_Sunil_Varkey_Joins_Hexaware_Technologies_as_EVP___CISO.png" length="229119" type="image/png"/><category>Cybersecurity Careers / Workforce</category><author>SecurityXP</author></item><item><title>Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack</title><link>https://securityxp.com/articles/04_week_in_review__74k_fortinet_firewall_credentials_stolen__sp/</link><guid isPermaLink="true">https://securityxp.com/articles/04_week_in_review__74k_fortinet_firewall_credentials_stolen__sp/</guid><description>Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) Microsoft has acknowledged the local elevation of privilege issue in Microsoft...</description><pubDate>Sun, 21 Jun 2026 08:49:03 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_Week_in_review__74k_Fortinet_firewall_credentials_stolen__Sp.png&quot; alt=&quot;Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) Microsoft has acknowledged the local elevation of privilege issue in Microsoft...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_Week_in_review__74k_Fortinet_firewall_credentials_stolen__Sp.png" length="978097" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes Malware</title><link>https://securityxp.com/articles/05_gentlekiller_ransomware_abuses_vulnerable_drivers_to_disable/</link><guid isPermaLink="true">https://securityxp.com/articles/05_gentlekiller_ransomware_abuses_vulnerable_drivers_to_disable/</guid><description>This rapid adoption distinguishes Gentlemen from most other RaaS operators, who typically wait weeks or months before adapting publicly released exploits...</description><pubDate>Sun, 21 Jun 2026 08:49:03 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/05_GentleKiller_Ransomware_Abuses_Vulnerable_Drivers_to_Disable.png&quot; alt=&quot;GentleKiller Ransomware Abuses Vulnerable Drivers to Disable 400+ EDR Security Processes Malware&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This rapid adoption distinguishes Gentlemen from most other RaaS operators, who typically wait weeks or months before adapting publicly released exploits...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/05_GentleKiller_Ransomware_Abuses_Vulnerable_Drivers_to_Disable.png" length="970528" type="image/png"/><category>Malware &amp; Ransomware</category><author>SecurityXP</author></item><item><title>Nancy Guthrie Case Reframed by Crypto Firm&apos;s &quot;Wrench Attack&quot; Label as Police Confirm Motive Pending</title><link>https://securityxp.com/articles/06_nancy_guthrie_case_reframed_by_crypto_firm_s__wrench_attack/</link><guid isPermaLink="true">https://securityxp.com/articles/06_nancy_guthrie_case_reframed_by_crypto_firm_s__wrench_attack/</guid><description>In it, CertiK described Nancy Guthrie&apos;s kidnapping as part of a &quot;$6 million bitcoin ransom demand&quot; and tied it to what the company called &quot;the documented...</description><pubDate>Sun, 21 Jun 2026 08:49:03 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/06_Nancy_Guthrie_Case_Reframed_by_Crypto_Firm_s__Wrench_Attack.png&quot; alt=&quot;Nancy Guthrie Case Reframed by Crypto Firm&apos;s &quot;Wrench Attack&quot; Label as Police Confirm Motive Pending&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;In it, CertiK described Nancy Guthrie&apos;s kidnapping as part of a &quot;$6 million bitcoin ransom demand&quot; and tied it to what the company called &quot;the documented...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/06_Nancy_Guthrie_Case_Reframed_by_Crypto_Firm_s__Wrench_Attack.png" length="974012" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>Virus vs Worm: Why the Propagation Difference Actually Matters Malware</title><link>https://securityxp.com/articles/07_virus_vs_worm__why_the_propagation_difference_actually_matte/</link><guid isPermaLink="true">https://securityxp.com/articles/07_virus_vs_worm__why_the_propagation_difference_actually_matte/</guid><description>But no detection tool replaces patching: the vulnerability that WannaCry used had a patch available for eight weeks before the attack. In 1988, the Morris...</description><pubDate>Sun, 21 Jun 2026 08:49:03 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/07_Virus_vs_Worm__Why_the_Propagation_Difference_Actually_Matte.png&quot; alt=&quot;Virus vs Worm: Why the Propagation Difference Actually Matters Malware&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;But no detection tool replaces patching: the vulnerability that WannaCry used had a patch available for eight weeks before the attack. In 1988, the Morris...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/07_Virus_vs_Worm__Why_the_Propagation_Difference_Actually_Matte.png" length="987716" type="image/png"/><category>Malware &amp; Ransomware</category><author>SecurityXP</author></item><item><title>Vulnerability response: Built for humans, outpaced by machines.</title><link>https://securityxp.com/articles/01_vulnerability_response__built_for_humans__outpaced_by_machin/</link><guid isPermaLink="true">https://securityxp.com/articles/01_vulnerability_response__built_for_humans__outpaced_by_machin/</guid><description>Frontier models now discover and chain vulnerabilities faster than human analysts can confirm them, and the gap between finding and fixing is shrinking in...</description><pubDate>Sun, 21 Jun 2026 06:17:30 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Vulnerability_response__Built_for_humans__outpaced_by_machin.png&quot; alt=&quot;Vulnerability response: Built for humans, outpaced by machines.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Frontier models now discover and chain vulnerabilities faster than human analysts can confirm them, and the gap between finding and fixing is shrinking in...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Vulnerability_response__Built_for_humans__outpaced_by_machin.png" length="980345" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>6 years Fullstack Dev, 1 week into bug bounty, zero findings. How long did your first valid bug take?</title><link>https://securityxp.com/articles/02_6_years_fullstack_dev__1_week_into_bug_bounty__zero_findings/</link><guid isPermaLink="true">https://securityxp.com/articles/02_6_years_fullstack_dev__1_week_into_bug_bounty__zero_findings/</guid><description>Dev-to-hunter transition: Any other devs here who struggled with the mindset shift from &quot;making things work&quot; to &quot;breaking things intentionally&quot;? What I&apos;ve...</description><pubDate>Sun, 21 Jun 2026 06:17:30 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_6_years_Fullstack_Dev__1_week_into_bug_bounty__zero_findings.png&quot; alt=&quot;6 years Fullstack Dev, 1 week into bug bounty, zero findings. How long did your first valid bug take?&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Dev-to-hunter transition: Any other devs here who struggled with the mindset shift from &quot;making things work&quot; to &quot;breaking things intentionally&quot;? What I&apos;ve...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_6_years_Fullstack_Dev__1_week_into_bug_bounty__zero_findings.png" length="984545" type="image/png"/><category>Cybersecurity Careers / Workforce</category><author>SecurityXP</author></item><item><title>Privacy-Preserving Outsourced Witness Updates for Append-Only RSA Accumulators Security Research</title><link>https://securityxp.com/articles/03_privacy-preserving_outsourced_witness_updates_for_append-onl/</link><guid isPermaLink="true">https://securityxp.com/articles/03_privacy-preserving_outsourced_witness_updates_for_append-onl/</guid><description>In this paper, we present a privacy-preserving outsourced witness-update protocol for append-only RSA accumulators. The protocol combines witness updates...</description><pubDate>Sun, 21 Jun 2026 06:17:30 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Privacy-Preserving_Outsourced_Witness_Updates_for_Append-Onl.png&quot; alt=&quot;Privacy-Preserving Outsourced Witness Updates for Append-Only RSA Accumulators Security Research&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;In this paper, we present a privacy-preserving outsourced witness-update protocol for append-only RSA accumulators. The protocol combines witness updates...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Privacy-Preserving_Outsourced_Witness_Updates_for_Append-Onl.png" length="981939" type="image/png"/><category>Research</category><author>SecurityXP</author></item><item><title>Navigating the GPS threat landscape, with Brandon Karpf. Cyberwarfare</title><link>https://securityxp.com/articles/04_navigating_the_gps_threat_landscape__with_brandon_karpf/</link><guid isPermaLink="true">https://securityxp.com/articles/04_navigating_the_gps_threat_landscape__with_brandon_karpf/</guid><description>If this research is accurate, these attacks represent a significant evolution for how defenders think about this critical technology. Key sources: -...</description><pubDate>Sun, 21 Jun 2026 06:17:30 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_Navigating_the_GPS_threat_landscape__with_Brandon_Karpf.png&quot; alt=&quot;Navigating the GPS threat landscape, with Brandon Karpf. Cyberwarfare&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;If this research is accurate, these attacks represent a significant evolution for how defenders think about this critical technology. Key sources: -...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_Navigating_the_GPS_threat_landscape__with_Brandon_Karpf.png" length="920040" type="image/png"/><category>Cyberwarfare / Nation-State</category><author>SecurityXP</author></item><item><title>Google Shor&apos;s Algorithm Obfuscation Broken: LLM Crowdsourcing Outperforms ZKP-Verified Benchmark by 44%</title><link>https://securityxp.com/articles/01_google_shor_algorithm_obfuscation_broken_llm_crowdsourcing_outperforms_zkp_verified_benchmark/</link><guid isPermaLink="true">https://securityxp.com/articles/01_google_shor_algorithm_obfuscation_broken_llm_crowdsourcing_outperforms_zkp_verified_benchmark/</guid><description>An open-source contest utilizing Large Language Models (LLMs) has successfully reverse-engineered and optimized Google Quantum AI&apos;s restricted Shor&apos;s algorithm circuit optimization, exceeding Google&apos;s obfuscated benchmark by 44.0%.</description><pubDate>Sun, 21 Jun 2026 01:30:50 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Google_Shor_Algorithm_Obfuscation_Broken_LLM_Crowdsourcing_Outperforms_ZKP_Verified_Benchmark.png&quot; alt=&quot;Google Shor&apos;s Algorithm Obfuscation Broken: LLM Crowdsourcing Outperforms ZKP-Verified Benchmark by 44%&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;An open-source contest utilizing Large Language Models (LLMs) has successfully reverse-engineered and optimized Google Quantum AI&apos;s restricted Shor&apos;s algorithm circuit optimization, exceeding Google&apos;s obfuscated benchmark by 44.0%.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Google_Shor_Algorithm_Obfuscation_Broken_LLM_Crowdsourcing_Outperforms_ZKP_Verified_Benchmark.png" length="229119" type="image/png"/><category>Research</category><author>SecurityXP</author></item><item><title>Major Data Breach Warning Issued for 3 Million in Texas: What To Know</title><link>https://securityxp.com/articles/02_major_data_breach_warning_issued_for_3_million_in_texas__wha/</link><guid isPermaLink="true">https://securityxp.com/articles/02_major_data_breach_warning_issued_for_3_million_in_texas__wha/</guid><description>Major Data Breach Warning Issued for 3 Million in Texas: What To Know...</description><pubDate>Sat, 20 Jun 2026 13:30:44 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Major_Data_Breach_Warning_Issued_for_3_Million_in_Texas__Wha.png&quot; alt=&quot;Major Data Breach Warning Issued for 3 Million in Texas: What To Know&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Major Data Breach Warning Issued for 3 Million in Texas: What To Know...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Major_Data_Breach_Warning_Issued_for_3_Million_in_Texas__Wha.png" length="975928" type="image/png"/><category>Data Breaches</category><author>SecurityXP</author></item><item><title>Form: Report a suspected breach of farming rules or fraud Compliance</title><link>https://securityxp.com/articles/03_form__report_a_suspected_breach_of_farming_rules_or_fraud/</link><guid isPermaLink="true">https://securityxp.com/articles/03_form__report_a_suspected_breach_of_farming_rules_or_fraud/</guid><description>Report a suspected breach of farming rules or fraud How to report a suspected breach of farming rules or fraud to the Rural Payments Agency. Applies to...</description><pubDate>Sat, 20 Jun 2026 13:30:44 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Form__Report_a_suspected_breach_of_farming_rules_or_fraud.png&quot; alt=&quot;Form: Report a suspected breach of farming rules or fraud Compliance&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Report a suspected breach of farming rules or fraud How to report a suspected breach of farming rules or fraud to the Rural Payments Agency. Applies to...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Form__Report_a_suspected_breach_of_farming_rules_or_fraud.png" length="810956" type="image/png"/><category>Compliance &amp; Privacy</category><author>SecurityXP</author></item><item><title>Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys Vulnerability (CVE-2026-4020)</title><link>https://securityxp.com/articles/01_hackers_exploit_gravity_smtp_wordpress_plugin_bug_to_expose/</link><guid isPermaLink="true">https://securityxp.com/articles/01_hackers_exploit_gravity_smtp_wordpress_plugin_bug_to_expose/</guid><description>The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to...</description><pubDate>Sat, 20 Jun 2026 13:22:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Hackers_Exploit_Gravity_SMTP_WordPress_Plugin_Bug_to_Expose.png&quot; alt=&quot;Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys Vulnerability (CVE-2026-4020)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Hackers_Exploit_Gravity_SMTP_WordPress_Plugin_Bug_to_Expose.png" length="887550" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes Malware</title><link>https://securityxp.com/articles/02_the_gentlemen_raas_uses_gentlekiller_edr_framework_targeting/</link><guid isPermaLink="true">https://securityxp.com/articles/02_the_gentlemen_raas_uses_gentlekiller_edr_framework_targeting/</guid><description>It allows The Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclosed.&quot; The third-party...</description><pubDate>Sat, 20 Jun 2026 13:22:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_The_Gentlemen_RaaS_Uses_GentleKiller_EDR_Framework_Targeting.png&quot; alt=&quot;The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes Malware&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;It allows The Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclosed.&quot; The third-party...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_The_Gentlemen_RaaS_Uses_GentleKiller_EDR_Framework_Targeting.png" length="825607" type="image/png"/><category>Malware &amp; Ransomware</category><author>SecurityXP</author></item><item><title>Spur adds no-code Cloudflare integration for Monocle Cloud Security</title><link>https://securityxp.com/articles/03_spur_adds_no-code_cloudflare_integration_for_monocle/</link><guid isPermaLink="true">https://securityxp.com/articles/03_spur_adds_no-code_cloudflare_integration_for_monocle/</guid><description>&quot;These updates ensure that customers can implement inline enforcement in minutes, gain deeper visibility into user behavior, and quickly translate those...</description><pubDate>Sat, 20 Jun 2026 13:22:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Spur_adds_no-code_Cloudflare_integration_for_Monocle.png&quot; alt=&quot;Spur adds no-code Cloudflare integration for Monocle Cloud Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;&quot;These updates ensure that customers can implement inline enforcement in minutes, gain deeper visibility into user behavior, and quickly translate those...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Spur_adds_no-code_Cloudflare_integration_for_Monocle.png" length="994067" type="image/png"/><category>Cloud Security</category><author>SecurityXP</author></item><item><title>Klue OAuth breach victim list grows as Icarus hackers claim attack Data Breach</title><link>https://securityxp.com/articles/04_klue_oauth_breach_victim_list_grows_as_icarus_hackers_claim/</link><guid isPermaLink="true">https://securityxp.com/articles/04_klue_oauth_breach_victim_list_grows_as_icarus_hackers_claim/</guid><description>Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to...</description><pubDate>Sat, 20 Jun 2026 13:22:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_Klue_OAuth_breach_victim_list_grows_as_Icarus_hackers_claim.png&quot; alt=&quot;Klue OAuth breach victim list grows as Icarus hackers claim attack Data Breach&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_Klue_OAuth_breach_victim_list_grows_as_Icarus_hackers_claim.png" length="810722" type="image/png"/><category>Data Breaches</category><author>SecurityXP</author></item><item><title>Novo Nordisk Breached: Ozempic Maker Suffers 264 GB Data Leak</title><link>https://securityxp.com/articles/01_novo_nordisk_breached__ozempic_maker_suffers_264_gb_data_lea/</link><guid isPermaLink="true">https://securityxp.com/articles/01_novo_nordisk_breached__ozempic_maker_suffers_264_gb_data_lea/</guid><description>They allegedly breached Novo in March via a GitHub access token that let it clone the company&apos;s repositories and find additional credentials.</description><pubDate>Fri, 19 Jun 2026 18:25:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Novo_Nordisk_Breached__Ozempic_Maker_Suffers_264_GB_Data_Lea.png&quot; alt=&quot;Novo Nordisk Breached: Ozempic Maker Suffers 264 GB Data Leak&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;They allegedly breached Novo in March via a GitHub access token that let it clone the company&apos;s repositories and find additional credentials.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Novo_Nordisk_Breached__Ozempic_Maker_Suffers_264_GB_Data_Lea.png" length="193288" type="image/png"/><category>Data Breaches</category><author>SecurityXP</author></item><item><title>AI-Enabled Hacker Caught: Leaked Prompts Expose Resume and IP Address</title><link>https://securityxp.com/articles/02_ai-enabled_hacker_caught__leaked_prompts_expose_resume__ip/</link><guid isPermaLink="true">https://securityxp.com/articles/02_ai-enabled_hacker_caught__leaked_prompts_expose_resume__ip/</guid><description>A fully AI-enabled hacker was caught, revealing his full system prompts, which included his resume and his IP address.</description><pubDate>Fri, 19 Jun 2026 18:25:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_AI-Enabled_Hacker_Caught__Leaked_Prompts_Expose_Resume__IP.png&quot; alt=&quot;AI-Enabled Hacker Caught: Leaked Prompts Expose Resume and IP Address&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A fully AI-enabled hacker was caught, revealing his full system prompts, which included his resume and his IP address.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_AI-Enabled_Hacker_Caught__Leaked_Prompts_Expose_Resume__IP.png" length="167143" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more</title><link>https://securityxp.com/articles/04_weekly_metasploit_update__ntlm_relay_priv_esc__mcp_server_in/</link><guid isPermaLink="true">https://securityxp.com/articles/04_weekly_metasploit_update__ntlm_relay_priv_esc__mcp_server_in/</guid><description>New module content (5) Paperclip AI RCE using a chain of six API calls (CVE-2026-41679) Authors: Sagilayani https://github.com/sagilayani and h00die-gr3y...</description><pubDate>Fri, 19 Jun 2026 18:25:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_Weekly_Metasploit_Update__NTLM_Relay_Priv_Esc__MCP_Server_In.png&quot; alt=&quot;Weekly Metasploit Update: NTLM Relay Priv Esc, MCP Server Integration, Paperclip AI RCE Chain, and more&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;New module content (5) Paperclip AI RCE using a chain of six API calls (CVE-2026-41679) Authors: Sagilayani https://github.com/sagilayani and h00die-gr3y...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_Weekly_Metasploit_Update__NTLM_Relay_Priv_Esc__MCP_Server_In.png" length="956630" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Vulnerability</title><link>https://securityxp.com/articles/05_autojack_attack_lets_one_web_page_hijack_ai_agent_for_host_c/</link><guid isPermaLink="true">https://securityxp.com/articles/05_autojack_attack_lets_one_web_page_hijack_ai_agent_for_host_c/</guid><description>Microsoft made a similar localhost argument in its Semantic Kernel RCE research, tracked as CVE-2026-26030 and CVE-2026-25592. The issue is tracked as...</description><pubDate>Fri, 19 Jun 2026 18:25:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/05_AutoJack_Attack_Lets_One_Web_Page_Hijack_AI_Agent_for_Host_C.png&quot; alt=&quot;AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Microsoft made a similar localhost argument in its Semantic Kernel RCE research, tracked as CVE-2026-26030 and CVE-2026-25592. The issue is tracked as...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/05_AutoJack_Attack_Lets_One_Web_Page_Hijack_AI_Agent_for_Host_C.png" length="879159" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime App Security</title><link>https://securityxp.com/articles/06_meteor_3_0_migration_helped_rocket_chat_move_off_end-of-life/</link><guid isPermaLink="true">https://securityxp.com/articles/06_meteor_3_0_migration_helped_rocket_chat_move_off_end-of-life/</guid><description>Supply-Chain Risk Without a CVE Meteor 3.0 puts a name to a category of supply-chain risk that standard vulnerability management does not always catch. The...</description><pubDate>Fri, 19 Jun 2026 18:25:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/06_Meteor_3_0_Migration_Helped_Rocket_Chat_Move_Off_End-of-Life.png&quot; alt=&quot;Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime App Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Supply-Chain Risk Without a CVE Meteor 3.0 puts a name to a category of supply-chain risk that standard vulnerability management does not always catch. The...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/06_Meteor_3_0_Migration_Helped_Rocket_Chat_Move_Off_End-of-Life.png" length="853863" type="image/png"/><category>Application Security</category><author>SecurityXP</author></item><item><title>14,971 WordPress Sites Cleaned in Global SocGholish Takedown Cybercrime</title><link>https://securityxp.com/articles/03_14_971_wordpress_sites_cleaned_in_global_socgholish_takedown/</link><guid isPermaLink="true">https://securityxp.com/articles/03_14_971_wordpress_sites_cleaned_in_global_socgholish_takedown/</guid><description>Data from Infoblox shows that approximately 55% of its cloud customers attempted to reach SocGholish infrastructure this year alone, with the attacks...</description><pubDate>Fri, 19 Jun 2026 16:29:52 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_14_971_WordPress_Sites_Cleaned_in_Global_SocGholish_Takedown.png&quot; alt=&quot;14,971 WordPress Sites Cleaned in Global SocGholish Takedown Cybercrime&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Data from Infoblox shows that approximately 55% of its cloud customers attempted to reach SocGholish infrastructure this year alone, with the attacks...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_14_971_WordPress_Sites_Cleaned_in_Global_SocGholish_Takedown.png" length="972812" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap Vulnerability</title><link>https://securityxp.com/articles/04_apple_patches_beats_studio_buds_flaw_that_could_turn_earbuds/</link><guid isPermaLink="true">https://securityxp.com/articles/04_apple_patches_beats_studio_buds_flaw_that_could_turn_earbuds/</guid><description>The security update fixes CVE-2025-20701, a vulnerability discovered by Dennis Heinze and Frieder Steinmetz of German cybersecurity firm ERNW. The issue is...</description><pubDate>Fri, 19 Jun 2026 16:29:52 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_Apple_patches_Beats_Studio_Buds_flaw_that_could_turn_earbuds.png&quot; alt=&quot;Apple patches Beats Studio Buds flaw that could turn earbuds into a wiretap Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The security update fixes CVE-2025-20701, a vulnerability discovered by Dennis Heinze and Frieder Steinmetz of German cybersecurity firm ERNW. The issue is...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_Apple_patches_Beats_Studio_Buds_flaw_that_could_turn_earbuds.png" length="887757" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Every AI Agent Is an Identity. Most Organizations Don&apos;t Treat Them That Way AI Security</title><link>https://securityxp.com/articles/05_every_ai_agent_is_an_identity__most_organizations_don_t_trea/</link><guid isPermaLink="true">https://securityxp.com/articles/05_every_ai_agent_is_an_identity__most_organizations_don_t_trea/</guid><description>This is no longer theoretical, 65% of organizations experienced a security incident involving an AI agent in the past year, with 61% reporting exposure or...</description><pubDate>Fri, 19 Jun 2026 16:29:52 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/05_Every_AI_Agent_Is_an_Identity__Most_Organizations_Don_t_Trea.png&quot; alt=&quot;Every AI Agent Is an Identity. Most Organizations Don&apos;t Treat Them That Way AI Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This is no longer theoretical, 65% of organizations experienced a security incident involving an AI agent in the past year, with 61% reporting exposure or...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/05_Every_AI_Agent_Is_an_Identity__Most_Organizations_Don_t_Trea.png" length="939684" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>What Is Application Security Testing? Tools and Types App Security</title><link>https://securityxp.com/articles/06_what_is_application_security_testing__tools_and_types/</link><guid isPermaLink="true">https://securityxp.com/articles/06_what_is_application_security_testing__tools_and_types/</guid><description>Organizations that already enforce quality gates in CI/CD can extend that model into deployment workflows by requiring review of critical cloud exposures...</description><pubDate>Fri, 19 Jun 2026 16:29:52 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/06_What_Is_Application_Security_Testing__Tools_and_Types.png&quot; alt=&quot;What Is Application Security Testing? Tools and Types App Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Organizations that already enforce quality gates in CI/CD can extend that model into deployment workflows by requiring review of critical cloud exposures...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/06_What_Is_Application_Security_Testing__Tools_and_Types.png" length="1000522" type="image/png"/><category>Application Security</category><author>SecurityXP</author></item><item><title>Microsoft Confirms RoguePlanet Zero-Day in Defender, Patch Under Development Vulnerability</title><link>https://securityxp.com/articles/01_microsoft_confirms_rogueplanet_zero-day_in_defender__patch_u/</link><guid isPermaLink="true">https://securityxp.com/articles/01_microsoft_confirms_rogueplanet_zero-day_in_defender__patch_u/</guid><description>I think it even works in the case of passive mode, but not really sure, haven&apos;t tested that.&quot; Microsoft told The Hacker News last week that it&apos;s aware of the...</description><pubDate>Thu, 18 Jun 2026 09:58:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Microsoft_Confirms_RoguePlanet_Zero-Day_in_Defender__Patch_U.png&quot; alt=&quot;Microsoft Confirms RoguePlanet Zero-Day in Defender, Patch Under Development Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;I think it even works in the case of passive mode, but not really sure, haven&apos;t tested that.&quot; Microsoft told The Hacker News last week that it&apos;s aware of the...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Microsoft_Confirms_RoguePlanet_Zero-Day_in_Defender__Patch_U.png" length="957262" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies</title><link>https://securityxp.com/articles/02_spycloud_report_finds_phishing_attacks_surge_as_employee_dat/</link><guid isPermaLink="true">https://securityxp.com/articles/02_spycloud_report_finds_phishing_attacks_surge_as_employee_dat/</guid><description>SpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in...</description><pubDate>Thu, 18 Jun 2026 09:58:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_SpyCloud_Report_Finds_Phishing_Attacks_Surge_as_Employee_Dat.png&quot; alt=&quot;SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;SpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_SpyCloud_Report_Finds_Phishing_Attacks_Surge_as_Employee_Dat.png" length="971537" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>OVHcloud previews AI workspace with encrypted tools AI Security</title><link>https://securityxp.com/articles/03_ovhcloud_previews_ai_workspace_with_encrypted_tools/</link><guid isPermaLink="true">https://securityxp.com/articles/03_ovhcloud_previews_ai_workspace_with_encrypted_tools/</guid><description>OVHcloud says OVHai Workspace includes an end-to-end encryption option covering data and communications, including within partner applications integrated...</description><pubDate>Thu, 18 Jun 2026 09:58:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_OVHcloud_previews_AI_workspace_with_encrypted_tools.png&quot; alt=&quot;OVHcloud previews AI workspace with encrypted tools AI Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;OVHcloud says OVHai Workspace includes an end-to-end encryption option covering data and communications, including within partner applications integrated...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_OVHcloud_previews_AI_workspace_with_encrypted_tools.png" length="953458" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Mastra npm packages compromised in &apos;easy-day-js&apos; supply chain attack App Security</title><link>https://securityxp.com/articles/04_mastra_npm_packages_compromised_in__easy-day-js__supply_chai/</link><guid isPermaLink="true">https://securityxp.com/articles/04_mastra_npm_packages_compromised_in__easy-day-js__supply_chai/</guid><description>By exploiting npm’s install-time script execution, attackers gained the ability to harvest browser data from Chrome, Edge, and Brave, extract credentials...</description><pubDate>Thu, 18 Jun 2026 09:58:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_Mastra_npm_packages_compromised_in__easy-day-js__supply_chai.png&quot; alt=&quot;Mastra npm packages compromised in &apos;easy-day-js&apos; supply chain attack App Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;By exploiting npm’s install-time script execution, attackers gained the ability to harvest browser data from Chrome, Edge, and Brave, extract credentials...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_Mastra_npm_packages_compromised_in__easy-day-js__supply_chai.png" length="912263" type="image/png"/><category>Application Security</category><author>SecurityXP</author></item><item><title>Kodak Confirms Data Breach Following ShinyHunters’ Claim of Stolen Customer Records</title><link>https://securityxp.com/articles/01_kodak_confirms_data_breach_following_shinyhunters__claim_of/</link><guid isPermaLink="true">https://securityxp.com/articles/01_kodak_confirms_data_breach_following_shinyhunters__claim_of/</guid><description>One week ago, the extortion group also claimed responsibility for a new series of breaches at over 100 organizations(including the University of Nottingham)...</description><pubDate>Wed, 17 Jun 2026 13:54:33 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Kodak_Confirms_Data_Breach_Following_ShinyHunters__Claim_of.png&quot; alt=&quot;Kodak Confirms Data Breach Following ShinyHunters’ Claim of Stolen Customer Records&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;One week ago, the extortion group also claimed responsibility for a new series of breaches at over 100 organizations(including the University of Nottingham)...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Kodak_Confirms_Data_Breach_Following_ShinyHunters__Claim_of.png" length="913644" type="image/png"/><category>Data Breaches</category><author>SecurityXP</author></item><item><title>CISA Warns of Oracle PeopleSoft 0-Day Vulnerability Exploited in Ransomware Attacks (CVE-2026-35273)</title><link>https://securityxp.com/articles/02_cisa_warns_of_oracle_peoplesoft_0-day_vulnerability_exploite/</link><guid isPermaLink="true">https://securityxp.com/articles/02_cisa_warns_of_oracle_peoplesoft_0-day_vulnerability_exploite/</guid><description>Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of a critical vulnerability in Oracle...</description><pubDate>Wed, 17 Jun 2026 13:54:33 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_CISA_Warns_of_Oracle_PeopleSoft_0-Day_Vulnerability_Exploite.png&quot; alt=&quot;CISA Warns of Oracle PeopleSoft 0-Day Vulnerability Exploited in Ransomware Attacks (CVE-2026-35273)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of a critical vulnerability in Oracle...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_CISA_Warns_of_Oracle_PeopleSoft_0-Day_Vulnerability_Exploite.png" length="917698" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It</title><link>https://securityxp.com/articles/03_heimdal_survey__executives_four_times_more_confident_about_a/</link><guid isPermaLink="true">https://securityxp.com/articles/03_heimdal_survey__executives_four_times_more_confident_about_a/</guid><description>London, United Kingdom, June 17th, 2026, CyberNewswire New research from cybersecurity company Heimdal finds 29% of US executives say AI risk is under...</description><pubDate>Wed, 17 Jun 2026 13:54:33 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Heimdal_Survey__Executives_Four_Times_More_Confident_About_A.png&quot; alt=&quot;Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;London, United Kingdom, June 17th, 2026, CyberNewswire New research from cybersecurity company Heimdal finds 29% of US executives say AI risk is under...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Heimdal_Survey__Executives_Four_Times_More_Confident_About_A.png" length="913357" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>144 Mastra npm Packages Compromised via Hijacked Contributor Account App Security</title><link>https://securityxp.com/articles/04_144_mastra_npm_packages_compromised_via_hijacked_contributor/</link><guid isPermaLink="true">https://securityxp.com/articles/04_144_mastra_npm_packages_compromised_via_hijacked_contributor/</guid><description>&quot;This makes the Mastra ecosystem an exceptionally high-value target for supply chain attackers.&quot; The &quot;easy-day-js&quot; package launches an obfuscated payload...</description><pubDate>Wed, 17 Jun 2026 13:54:33 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_144_Mastra_npm_Packages_Compromised_via_Hijacked_Contributor.png&quot; alt=&quot;144 Mastra npm Packages Compromised via Hijacked Contributor Account App Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;&quot;This makes the Mastra ecosystem an exceptionally high-value target for supply chain attackers.&quot; The &quot;easy-day-js&quot; package launches an obfuscated payload...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_144_Mastra_npm_Packages_Compromised_via_Hijacked_Contributor.png" length="981829" type="image/png"/><category>Application Security</category><author>SecurityXP</author></item><item><title>JetBrains Plugin Security Alert: 70,000+ Installs Linked to AI Key Theft Vulnerability</title><link>https://securityxp.com/articles/01_jetbrains_plugin_security_alert__70_000__installs_linked_to/</link><guid isPermaLink="true">https://securityxp.com/articles/01_jetbrains_plugin_security_alert__70_000__installs_linked_to/</guid><description>While these plugins function as advertised, offering features like code review, chat, and […] The post JetBrains Plugin Security Alert: 70,000+ Installs...</description><pubDate>Wed, 17 Jun 2026 05:43:29 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_JetBrains_Plugin_Security_Alert__70_000__Installs_Linked_to.png&quot; alt=&quot;JetBrains Plugin Security Alert: 70,000+ Installs Linked to AI Key Theft Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;While these plugins function as advertised, offering features like code review, chat, and […] The post JetBrains Plugin Security Alert: 70,000+ Installs...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_JetBrains_Plugin_Security_Alert__70_000__Installs_Linked_to.png" length="981202" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Zyxel security advisory (AV26-603) Vulnerability</title><link>https://securityxp.com/articles/01_zyxel_security_advisory__av26-603/</link><guid isPermaLink="true">https://securityxp.com/articles/01_zyxel_security_advisory__av26-603/</guid><description>Serial number: AV26-603Date: June 16, 2026 On June 16, 2026, Zyxel published a security advisory to address vulnerabilities in the following products: GS1900...</description><pubDate>Tue, 16 Jun 2026 13:51:43 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Zyxel_security_advisory__AV26-603.png&quot; alt=&quot;Zyxel security advisory (AV26-603) Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Serial number: AV26-603Date: June 16, 2026 On June 16, 2026, Zyxel published a security advisory to address vulnerabilities in the following products: GS1900...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Zyxel_security_advisory__AV26-603.png" length="983673" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Chinese hackers breach REDCap servers, steal medical research Data Breach</title><link>https://securityxp.com/articles/01_chinese_hackers_breach_redcap_servers__steal_medical_researc/</link><guid isPermaLink="true">https://securityxp.com/articles/01_chinese_hackers_breach_redcap_servers__steal_medical_researc/</guid><description>&quot;Their research areas span a broad spectrum of modern medicine, from molecular discovery and clinical drug trials to state-level public health policy and...</description><pubDate>Mon, 15 Jun 2026 14:50:23 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Chinese_hackers_breach_REDCap_servers__steal_medical_researc.png&quot; alt=&quot;Chinese hackers breach REDCap servers, steal medical research Data Breach&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;&quot;Their research areas span a broad spectrum of modern medicine, from molecular discovery and clinical drug trials to state-level public health policy and...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Chinese_hackers_breach_REDCap_servers__steal_medical_researc.png" length="985356" type="image/png"/><category>Data Breaches</category><author>SecurityXP</author></item><item><title>How attackers are jailbreaking LLMs with CTF framing and how to catch them AI Security</title><link>https://securityxp.com/articles/02_how_attackers_are_jailbreaking_llms_with_ctf_framing_and_how/</link><guid isPermaLink="true">https://securityxp.com/articles/02_how_attackers_are_jailbreaking_llms_with_ctf_framing_and_how/</guid><description>Over the past 30 days, we’ve collected data from other source IPs that validate our jailbreaking theory: 159.89.93.86 created a LiteLLM master-scoped API key...</description><pubDate>Mon, 15 Jun 2026 14:50:23 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_How_attackers_are_jailbreaking_LLMs_with_CTF_framing_and_how.png&quot; alt=&quot;How attackers are jailbreaking LLMs with CTF framing and how to catch them AI Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Over the past 30 days, we’ve collected data from other source IPs that validate our jailbreaking theory: 159.89.93.86 created a LiteLLM master-scoped API key...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_How_attackers_are_jailbreaking_LLMs_with_CTF_framing_and_how.png" length="786000" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Chinese-linked hackers targeted US, Canadian research facilities for a year: Google Threat Alert</title><link>https://securityxp.com/articles/04_chinese-linked_hackers_targeted_us__canadian_research_facili/</link><guid isPermaLink="true">https://securityxp.com/articles/04_chinese-linked_hackers_targeted_us__canadian_research_facili/</guid><description>Between September 2023 and November 2025, the hackers sought information related to defense intelligence, military strategy in the Indo-Pacific, artificial...</description><pubDate>Mon, 15 Jun 2026 14:50:23 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/04_Chinese-linked_hackers_targeted_US__Canadian_research_facili.png&quot; alt=&quot;Chinese-linked hackers targeted US, Canadian research facilities for a year: Google Threat Alert&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Between September 2023 and November 2025, the hackers sought information related to defense intelligence, military strategy in the Indo-Pacific, artificial...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/04_Chinese-linked_hackers_targeted_US__Canadian_research_facili.png" length="996405" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP</author></item><item><title>Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS Flaw Vulnerability</title><link>https://securityxp.com/articles/01_palo_alto_warns_of_exploitation_of_vpn_bypass_exploits__cve-/</link><guid isPermaLink="true">https://securityxp.com/articles/01_palo_alto_warns_of_exploitation_of_vpn_bypass_exploits__cve-/</guid><description>&quot;Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events.&quot; The company has also released...</description><pubDate>Mon, 15 Jun 2026 14:00:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Palo_Alto_Warns_of_Exploitation_of_VPN_Bypass_Exploits__CVE-.png&quot; alt=&quot;Palo Alto Warns of Exploitation of VPN Bypass Exploits (CVE-2026-0257) in PAN-OS Flaw Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;&quot;Only a small portion of the probed devices actually established VPN sessions, resulting in gateway-connected events.&quot; The company has also released...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Palo_Alto_Warns_of_Exploitation_of_VPN_Bypass_Exploits__CVE-.png" length="893751" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Conti Ransomware Conspirator Pleads Guilty in $150M Scheme Cybercrime</title><link>https://securityxp.com/articles/02_conti_ransomware_conspirator_pleads_guilty_in__150m_scheme/</link><guid isPermaLink="true">https://securityxp.com/articles/02_conti_ransomware_conspirator_pleads_guilty_in__150m_scheme/</guid><description>Department of Justice announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ransomware against...</description><pubDate>Mon, 15 Jun 2026 14:00:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Conti_Ransomware_Conspirator_Pleads_Guilty_in__150M_Scheme.png&quot; alt=&quot;Conti Ransomware Conspirator Pleads Guilty in $150M Scheme Cybercrime&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Department of Justice announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ransomware against...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Conti_Ransomware_Conspirator_Pleads_Guilty_in__150M_Scheme.png" length="967576" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN App Security</title><link>https://securityxp.com/articles/03_supply_chain_attack_hits_popular_wordpress_plugins_through_a/</link><guid isPermaLink="true">https://securityxp.com/articles/03_supply_chain_attack_hits_popular_wordpress_plugins_through_a/</guid><description>According to the company&apos;s investigation, attackers exploited a known vulnerability in a third-party plugin called UpdraftPlus running on a marketing website...</description><pubDate>Mon, 15 Jun 2026 14:00:39 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Supply_Chain_Attack_Hits_Popular_WordPress_Plugins_Through_A.png&quot; alt=&quot;Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN App Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;According to the company&apos;s investigation, attackers exploited a known vulnerability in a third-party plugin called UpdraftPlus running on a marketing website...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Supply_Chain_Attack_Hits_Popular_WordPress_Plugins_Through_A.png" length="968767" type="image/png"/><category>Application Security</category><author>SecurityXP</author></item><item><title>Microsoft restricts employee Claude Fable 5 access over Anthropic data retention</title><link>https://securityxp.com/articles/03_microsoft_restricts_employee_claude_fable_5_access_over_data/</link><guid isPermaLink="true">https://securityxp.com/articles/03_microsoft_restricts_employee_claude_fable_5_access_over_data/</guid><description>Microsoft restricts employee access to Claude Fable 5 while legal reviews Anthropic&apos;s 30-day retention policy, which can retain flagged content for two years.</description><pubDate>Sun, 14 Jun 2026 21:30:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/03_Microsoft_restricts_employee_Claude_Fable_5_access_over_data.png&quot; alt=&quot;Microsoft restricts employee Claude Fable 5 access over Anthropic data retention&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Microsoft restricts employee access to Claude Fable 5 while legal reviews Anthropic&apos;s 30-day retention policy, which can retain flagged content for two years.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/03_Microsoft_restricts_employee_Claude_Fable_5_access_over_data.png" length="971115" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Ex-school district employee jailed for hacks on former employer Cybercrime</title><link>https://securityxp.com/articles/01_ex-school_district_employee_jailed_for_hacks_on_former_emplo/</link><guid isPermaLink="true">https://securityxp.com/articles/01_ex-school_district_employee_jailed_for_hacks_on_former_emplo/</guid><description>Potter is also required to pay $59,668.81 in restitution to the Saydel Community School District and its insurer, Travelers Casualty and Surety Company, for...</description><pubDate>Sun, 14 Jun 2026 14:42:27 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Ex-school_district_employee_jailed_for_hacks_on_former_emplo.png&quot; alt=&quot;Ex-school district employee jailed for hacks on former employer Cybercrime&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Potter is also required to pay $59,668.81 in restitution to the Saydel Community School District and its insurer, Travelers Casualty and Surety Company, for...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Ex-school_district_employee_jailed_for_hacks_on_former_emplo.png" length="899222" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>Anthropic ban: Sarvam AI&apos;s Pratyush Kumar warns against reliance on foreign models</title><link>https://securityxp.com/articles/02_anthropic_ban__sarvam_ai_s_pratyush_kumar_warns_against_reli/</link><guid isPermaLink="true">https://securityxp.com/articles/02_anthropic_ban__sarvam_ai_s_pratyush_kumar_warns_against_reli/</guid><description>Kumar detailed that Sarvam has trained models at scale on roughly 3,400 Nvidia H100 GPUs and has brought India&apos;s first Blackwell cluster online, targeting...</description><pubDate>Sun, 14 Jun 2026 14:42:27 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Anthropic_ban__Sarvam_AI_s_Pratyush_Kumar_warns_against_reli.png&quot; alt=&quot;Anthropic ban: Sarvam AI&apos;s Pratyush Kumar warns against reliance on foreign models&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Kumar detailed that Sarvam has trained models at scale on roughly 3,400 Nvidia H100 GPUs and has brought India&apos;s first Blackwell cluster online, targeting...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Anthropic_ban__Sarvam_AI_s_Pratyush_Kumar_warns_against_reli.png" length="951927" type="image/png"/><category>Commentary / Opinion</category><author>SecurityXP</author></item><item><title>Washington Pulled the Plug on Anthropic ‘s Fable 5 and Mythos 5 models. The Rest of the World Is Watching.</title><link>https://securityxp.com/articles/01_washington_pulled_the_plug_on_anthropic__s_fable_5_and_mytho/</link><guid isPermaLink="true">https://securityxp.com/articles/01_washington_pulled_the_plug_on_anthropic__s_fable_5_and_mytho/</guid><description>The organizations that had integrated these models into security operations, threat hunting pipelines, and vulnerability research workflows are now running...</description><pubDate>Sat, 13 Jun 2026 15:26:49 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Washington_Pulled_the_Plug_on_Anthropic__s_Fable_5_and_Mytho.png&quot; alt=&quot;Washington Pulled the Plug on Anthropic ‘s Fable 5 and Mythos 5 models. The Rest of the World Is Watching.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The organizations that had integrated these models into security operations, threat hunting pipelines, and vulnerability research workflows are now running...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Washington_Pulled_the_Plug_on_Anthropic__s_Fable_5_and_Mytho.png" length="919522" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Google Sues Chinese Cybercrime Network for Using Gemini AI to Target Americans</title><link>https://securityxp.com/articles/01_google_sues_chinese_cybercrime_network_for_using_gemini_ai_t/</link><guid isPermaLink="true">https://securityxp.com/articles/01_google_sues_chinese_cybercrime_network_for_using_gemini_ai_t/</guid><description>Google is taking legal action against a Chinese cybercrime network it says abused its Gemini AI agent to send phishing texts and steal data from Americans.</description><pubDate>Sat, 13 Jun 2026 04:43:18 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Google_Sues_Chinese_Cybercrime_Network_for_Using_Gemini_AI_t.png&quot; alt=&quot;Google Sues Chinese Cybercrime Network for Using Gemini AI to Target Americans&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Google is taking legal action against a Chinese cybercrime network it says abused its Gemini AI agent to send phishing texts and steal data from Americans.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Google_Sues_Chinese_Cybercrime_Network_for_Using_Gemini_AI_t.png" length="850773" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>Ukrainian national pleads guilty to role in Conti ransomware operation</title><link>https://securityxp.com/articles/02_ukrainian_national_pleads_guilty_to_role_in_conti_ransomware/</link><guid isPermaLink="true">https://securityxp.com/articles/02_ukrainian_national_pleads_guilty_to_role_in_conti_ransomware/</guid><description>A Ukrainian national pleaded guilty to his role in the Conti ransomware operation, which struck over 1,000 victims worldwide before disbanding in 2022.</description><pubDate>Sat, 13 Jun 2026 04:43:18 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Ukrainian_national_pleads_guilty_to_role_in_Conti_ransomware.png&quot; alt=&quot;Ukrainian national pleads guilty to role in Conti ransomware operation&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A Ukrainian national pleaded guilty to his role in the Conti ransomware operation, which struck over 1,000 victims worldwide before disbanding in 2022.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Ukrainian_national_pleads_guilty_to_role_in_Conti_ransomware.png" length="943743" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>Authorities Dismantle Cryptocurrency Laundering Service &apos;AudiA6&apos; Used by Cybercriminals</title><link>https://securityxp.com/articles/01_authorities_dismantle_cryptocurrency_laundering_services__au/</link><guid isPermaLink="true">https://securityxp.com/articles/01_authorities_dismantle_cryptocurrency_laundering_services__au/</guid><description>Law enforcement dismantled the &apos;AudiA6&apos; crypto-laundering service, arresting two administrators and seizing 30+ servers and 25 domains tied to ransomware.</description><pubDate>Fri, 12 Jun 2026 10:56:07 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Authorities_Dismantle_Cryptocurrency_Laundering_Services__Au.png&quot; alt=&quot;Authorities Dismantle Cryptocurrency Laundering Service &apos;AudiA6&apos; Used by Cybercriminals&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Law enforcement dismantled the &apos;AudiA6&apos; crypto-laundering service, arresting two administrators and seizing 30+ servers and 25 domains tied to ransomware.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Authorities_Dismantle_Cryptocurrency_Laundering_Services__Au.png" length="852465" type="image/png"/><category>Cybercrime</category><author>SecurityXP</author></item><item><title>Oracle mitigates PeopleSoft zero-day exploited in data theft attacks</title><link>https://securityxp.com/articles/02_oracle_mitigates_peoplesoft_zero-day_exploited_in_data_theft/</link><guid isPermaLink="true">https://securityxp.com/articles/02_oracle_mitigates_peoplesoft_zero-day_exploited_in_data_theft/</guid><description>Oracle has issued mitigations for a critical PeopleSoft zero-day (CVE-2026-35273) enabling unauthenticated RCE, actively exploited in ShinyHunters data theft.</description><pubDate>Fri, 12 Jun 2026 10:56:07 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Oracle_mitigates_PeopleSoft_zero-day_exploited_in_data_theft.png&quot; alt=&quot;Oracle mitigates PeopleSoft zero-day exploited in data theft attacks&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Oracle has issued mitigations for a critical PeopleSoft zero-day (CVE-2026-35273) enabling unauthenticated RCE, actively exploited in ShinyHunters data theft.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Oracle_mitigates_PeopleSoft_zero-day_exploited_in_data_theft.png" length="859885" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>GitHub finally pulls the plug on automatic install script execution</title><link>https://securityxp.com/articles/01_github_finally_pulls_the_plug_on_automatic_install_script_ex/</link><guid isPermaLink="true">https://securityxp.com/articles/01_github_finally_pulls_the_plug_on_automatic_install_script_ex/</guid><description>GitHub is ending automatic execution of npm install scripts to curb supply-chain attacks, starting with opt-in warnings in npm version 11.</description><pubDate>Thu, 11 Jun 2026 13:17:57 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_GitHub_finally_pulls_the_plug_on_automatic_install_script_ex.png&quot; alt=&quot;GitHub finally pulls the plug on automatic install script execution&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;GitHub is ending automatic execution of npm install scripts to curb supply-chain attacks, starting with opt-in warnings in npm version 11.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_GitHub_finally_pulls_the_plug_on_automatic_install_script_ex.png" length="892558" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks</title><link>https://securityxp.com/articles/02_oracle_peoplesoft_servers_hacked_in_shinyhunters_data_theft/</link><guid isPermaLink="true">https://securityxp.com/articles/02_oracle_peoplesoft_servers_hacked_in_shinyhunters_data_theft/</guid><description>ShinyHunters, or a group impersonating them, has been targeting Oracle PeopleSoft ERP servers in data theft attacks, with researchers publishing IP-address IOCs.</description><pubDate>Thu, 11 Jun 2026 13:17:57 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Oracle_PeopleSoft_servers_hacked_in_ShinyHunters_data_theft.png&quot; alt=&quot;Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;ShinyHunters, or a group impersonating them, has been targeting Oracle PeopleSoft ERP servers in data theft attacks, with researchers publishing IP-address IOCs.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Oracle_PeopleSoft_servers_hacked_in_ShinyHunters_data_theft.png" length="963314" type="image/png"/><category>Data Breaches</category><author>SecurityXP</author></item><item><title>Ivanti releases patches for critical Sentry vulnerabilities</title><link>https://securityxp.com/articles/01_ivanti_releases_patches_for_critical_sentry_vulnerabilities/</link><guid isPermaLink="true">https://securityxp.com/articles/01_ivanti_releases_patches_for_critical_sentry_vulnerabilities/</guid><description>Ivanti has patched two critical Sentry vulnerabilities (CVE-2026-10520 and CVE-2026-10523) affecting the gateway that secures traffic to mobile devices.</description><pubDate>Wed, 10 Jun 2026 18:26:05 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Ivanti_releases_patches_for_critical_Sentry_vulnerabilities.png&quot; alt=&quot;Ivanti releases patches for critical Sentry vulnerabilities&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Ivanti has patched two critical Sentry vulnerabilities (CVE-2026-10520 and CVE-2026-10523) affecting the gateway that secures traffic to mobile devices.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Ivanti_releases_patches_for_critical_Sentry_vulnerabilities.png" length="810267" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday</title><link>https://securityxp.com/articles/01_microsoft_patches_record_200_vulnerabilities_in_june_2026_pa/</link><guid isPermaLink="true">https://securityxp.com/articles/01_microsoft_patches_record_200_vulnerabilities_in_june_2026_pa/</guid><description>Microsoft&apos;s June 2026 Patch Tuesday fixes a record 200 vulnerabilities, including a critical Active Directory RCE (CVE-2026-45648, CVSS 8.8).</description><pubDate>Wed, 10 Jun 2026 15:47:54 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Microsoft_Patches_Record_200_Vulnerabilities_in_June_2026_Pa.png&quot; alt=&quot;Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Microsoft&apos;s June 2026 Patch Tuesday fixes a record 200 vulnerabilities, including a critical Active Directory RCE (CVE-2026-45648, CVSS 8.8).&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Microsoft_Patches_Record_200_Vulnerabilities_in_June_2026_Pa.png" length="984361" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Microsoft June 2026 Security Updates</title><link>https://securityxp.com/articles/01_microsoft_june_2026_security_updates/</link><guid isPermaLink="true">https://securityxp.com/articles/01_microsoft_june_2026_security_updates/</guid><description>Microsoft&apos;s Urgent Security Update Microsoft has just released a massive security update, fixing 204 vulnerabilities, including 38 critical ones. This is a...</description><pubDate>Wed, 10 Jun 2026 02:36:03 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_Microsoft_June_2026_Security_Updates.png&quot; alt=&quot;Microsoft June 2026 Security Updates&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Microsoft&apos;s Urgent Security Update Microsoft has just released a massive security update, fixing 204 vulnerabilities, including 38 critical ones. This is a...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_Microsoft_June_2026_Security_Updates.png" length="979135" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>SAP fixes critical flaws in NetWeaver and Commerce Cloud</title><link>https://securityxp.com/articles/01_sap_fixes_critical_flaws_in_netweaver_and_commerce_cloud/</link><guid isPermaLink="true">https://securityxp.com/articles/01_sap_fixes_critical_flaws_in_netweaver_and_commerce_cloud/</guid><description>Uncovering Critical Flaws in SAP NetWeaver and Commerce Cloud SAP&apos;s June 2026 Security Patch package is a big deal. It fixes 15 vulnerabilities, including...</description><pubDate>Tue, 09 Jun 2026 19:50:38 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/01_SAP_fixes_critical_flaws_in_NetWeaver_and_Commerce_Cloud.png&quot; alt=&quot;SAP fixes critical flaws in NetWeaver and Commerce Cloud&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Uncovering Critical Flaws in SAP NetWeaver and Commerce Cloud SAP&apos;s June 2026 Security Patch package is a big deal. It fixes 15 vulnerabilities, including...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/01_SAP_fixes_critical_flaws_in_NetWeaver_and_Commerce_Cloud.png" length="848601" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP</author></item><item><title>Can Voice Agents Handle Bilingual Customers? Benchmarking Frontier ASR on Code-Switched Speech</title><link>https://securityxp.com/articles/02_can_voice_agents_handle_bilingual_customers__benchmarking_fr/</link><guid isPermaLink="true">https://securityxp.com/articles/02_can_voice_agents_handle_bilingual_customers__benchmarking_fr/</guid><description>The Code-Switching Conundrum More than half of the world&apos;s population speaks more than one language. Code-switching, the practice of switching between...</description><pubDate>Tue, 09 Jun 2026 19:50:38 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/02_Can_Voice_Agents_Handle_Bilingual_Customers__Benchmarking_Fr.png&quot; alt=&quot;Can Voice Agents Handle Bilingual Customers? Benchmarking Frontier ASR on Code-Switched Speech&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Code-Switching Conundrum More than half of the world&apos;s population speaks more than one language. Code-switching, the practice of switching between...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/02_Can_Voice_Agents_Handle_Bilingual_Customers__Benchmarking_Fr.png" length="992508" type="image/png"/><category>Research</category><author>SecurityXP</author></item><item><title>Is OpenAI Lockdown Mode an Admission of Risk? Enough?</title><link>https://securityxp.com/articles/is-openais-new-lockdown-mode-an-admission-that-default-chatgpt-was-never-safe/</link><guid isPermaLink="true">https://securityxp.com/articles/is-openais-new-lockdown-mode-an-admission-that-default-chatgpt-was-never-safe/</guid><description>As AI-powered chatbots expand across customer service, technical support, and enterprise workflows, they become increasingly attractive targets for attackers seeking to extract sensitive data.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/is-openais-new-lockdown-mode-an-admission-that-default-chatgpt-was-never-safe.png&quot; alt=&quot;Is OpenAI Lockdown Mode an Admission of Risk? Enough?&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As AI-powered chatbots expand across customer service, technical support, and enterprise workflows, they become increasingly attractive targets for attackers seeking to extract sensitive data.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/is-openais-new-lockdown-mode-an-admission-that-default-chatgpt-was-never-safe.png" length="981090" type="image/png"/><category>AI/ML Security</category><author>SecurityXP Intelligence Desk</author></item><item><title>Meta AI Flaw Exposes 20K Instagram Accounts</title><link>https://securityxp.com/articles/meta-ai-recovery-tool-flaw-exposed-20000-instagram-accounts/</link><guid isPermaLink="true">https://securityxp.com/articles/meta-ai-recovery-tool-flaw-exposed-20000-instagram-accounts/</guid><description>This incident is a clear example of the ongoing risks associated with AI-powered support systems. The vulnerability allowed attackers to reset passwords without verifying email addresses associated wi...</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/meta-ai-recovery-tool-flaw-exposed-20000-instagram-accounts.png&quot; alt=&quot;Meta AI Flaw Exposes 20K Instagram Accounts&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This incident is a clear example of the ongoing risks associated with AI-powered support systems. The vulnerability allowed attackers to reset passwords without verifying email addresses associated wi...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/meta-ai-recovery-tool-flaw-exposed-20000-instagram-accounts.png" length="951593" type="image/png"/><category>Data Breaches</category><author>SecurityXP Intelligence Desk</author></item><item><title>CISA Flags SolarWinds Serv-U Flaw as Exploited</title><link>https://securityxp.com/articles/cisa-flags-solarwinds-serv-u-flaw-as-actively-exploited-cve-2026-28318/</link><guid isPermaLink="true">https://securityxp.com/articles/cisa-flags-solarwinds-serv-u-flaw-as-actively-exploited-cve-2026-28318/</guid><description>Over 12,000 SolarWinds Serv-U file transfer servers sit exposed to the internet. Attackers are already knocking them offline.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cisa-flags-solarwinds-serv-u-flaw-as-actively-exploited-cve-2026-28318.png&quot; alt=&quot;CISA Flags SolarWinds Serv-U Flaw as Exploited&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Over 12,000 SolarWinds Serv-U file transfer servers sit exposed to the internet. Attackers are already knocking them offline.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cisa-flags-solarwinds-serv-u-flaw-as-actively-exploited-cve-2026-28318.png" length="967396" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>Cisco SD-WAN Manager Under Attack, No Patch Yet</title><link>https://securityxp.com/articles/cisco-sd-wan-manager-under-active-attack-with-no-patch-cve-2026-20245/</link><guid isPermaLink="true">https://securityxp.com/articles/cisco-sd-wan-manager-under-active-attack-with-no-patch-cve-2026-20245/</guid><description>Cisco has confirmed active exploitation of a high-severity vulnerability in Catalyst SD-WAN Manager. The flaw, CVE-2026-20245, scores 7.8 on the CVSS scale.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cisco-sd-wan-manager-under-active-attack-with-no-patch-cve-2026-20245.png&quot; alt=&quot;Cisco SD-WAN Manager Under Attack, No Patch Yet&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cisco has confirmed active exploitation of a high-severity vulnerability in Catalyst SD-WAN Manager. The flaw, CVE-2026-20245, scores 7.8 on the CVSS scale.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cisco-sd-wan-manager-under-active-attack-with-no-patch-cve-2026-20245.png" length="958339" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>Everest Forms Pro RCE: WordPress Sites at Risk</title><link>https://securityxp.com/articles/everest-forms-pro-plugin-rce-lets-attackers-own-wordpress-cve-2026-3300/</link><guid isPermaLink="true">https://securityxp.com/articles/everest-forms-pro-plugin-rce-lets-attackers-own-wordpress-cve-2026-3300/</guid><description>Hackers are actively exploiting a critical vulnerability in the Everest Forms Pro WordPress plugin right now. The flaw, tracked as CVE-2026-3300, allows unauthenticated attackers to execute arbitrary ...</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/everest-forms-pro-plugin-rce-lets-attackers-own-wordpress-cve-2026-3300.png&quot; alt=&quot;Everest Forms Pro RCE: WordPress Sites at Risk&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Hackers are actively exploiting a critical vulnerability in the Everest Forms Pro WordPress plugin right now. The flaw, tracked as CVE-2026-3300, allows unauthenticated attackers to execute arbitrary ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/everest-forms-pro-plugin-rce-lets-attackers-own-wordpress-cve-2026-3300.png" length="810078" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>Ubiquiti UniFi OS Auth Bypass Enables Root RCE</title><link>https://securityxp.com/articles/ubiquiti-unifi-os-critical-auth-bypass-enables-root-rce-cve-2026-34908/</link><guid isPermaLink="true">https://securityxp.com/articles/ubiquiti-unifi-os-critical-auth-bypass-enables-root-rce-cve-2026-34908/</guid><description>Ubiquiti disclosed three critical vulnerabilities in UniFi OS Server on May 21, 2026. Each scores a perfect 10.0 on the CVSS scale.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/ubiquiti-unifi-os-critical-auth-bypass-enables-root-rce-cve-2026-34908.png&quot; alt=&quot;Ubiquiti UniFi OS Auth Bypass Enables Root RCE&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Ubiquiti disclosed three critical vulnerabilities in UniFi OS Server on May 21, 2026. Each scores a perfect 10.0 on the CVSS scale.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/ubiquiti-unifi-os-critical-auth-bypass-enables-root-rce-cve-2026-34908.png" length="842466" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>71% of SOCs Say AI Is Underdelivering: Report</title><link>https://securityxp.com/articles/71-of-socs-report-ai-is-underdelivering-the-second-wave-must-fix-it/</link><guid isPermaLink="true">https://securityxp.com/articles/71-of-socs-report-ai-is-underdelivering-the-second-wave-must-fix-it/</guid><description>Eighteen months ago, the AI SOC was a marketing line. Today it is a budget item.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/71-of-socs-report-ai-is-underdelivering-the-second-wave-must-fix-it.png&quot; alt=&quot;71% of SOCs Say AI Is Underdelivering: Report&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Eighteen months ago, the AI SOC was a marketing line. Today it is a budget item.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/71-of-socs-report-ai-is-underdelivering-the-second-wave-must-fix-it.png" length="921247" type="image/png"/><category>Security Operations</category><author>SecurityXP Intelligence Desk</author></item><item><title>AI Chatbot Trust Weaponized to Mine Crypto</title><link>https://securityxp.com/articles/attackers-weaponize-ai-chatbot-trust-to-hijack-gpus-and-mine-crypto/</link><guid isPermaLink="true">https://securityxp.com/articles/attackers-weaponize-ai-chatbot-trust-to-hijack-gpus-and-mine-crypto/</guid><description>Microsoft has spotted something new. Attackers are manipulating SEO rankings and AI chatbot recommendations to push fake utilities onto users who trust what the AI tells them.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/attackers-weaponize-ai-chatbot-trust-to-hijack-gpus-and-mine-crypto.png&quot; alt=&quot;AI Chatbot Trust Weaponized to Mine Crypto&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Microsoft has spotted something new. Attackers are manipulating SEO rankings and AI chatbot recommendations to push fake utilities onto users who trust what the AI tells them.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/attackers-weaponize-ai-chatbot-trust-to-hijack-gpus-and-mine-crypto.png" length="973419" type="image/png"/><category>Data Breaches</category><author>SecurityXP Intelligence Desk</author></item><item><title>Gulf Executives Face WhatsApp Impersonation</title><link>https://securityxp.com/articles/gulf-executives-face-surge-in-whatsapp-impersonation-attacks/</link><guid isPermaLink="true">https://securityxp.com/articles/gulf-executives-face-surge-in-whatsapp-impersonation-attacks/</guid><description>It starts with a message. A senior executive at a Dubai energy firm opens WhatsApp and sees what looks like a text from their CEO.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/gulf-executives-face-surge-in-whatsapp-impersonation-attacks.png&quot; alt=&quot;Gulf Executives Face WhatsApp Impersonation&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;It starts with a message. A senior executive at a Dubai energy firm opens WhatsApp and sees what looks like a text from their CEO.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/gulf-executives-face-surge-in-whatsapp-impersonation-attacks.png" length="975738" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Intelligence Desk</author></item><item><title>Acer Addresses Zero-Day in Wave 7 Routers</title><link>https://securityxp.com/articles/acer-addresses-critical-zero-day-vulnerabilities-in-wave-7-routers/</link><guid isPermaLink="true">https://securityxp.com/articles/acer-addresses-critical-zero-day-vulnerabilities-in-wave-7-routers/</guid><description>The vulnerability allows unauthenticated attackers to access sensitive credentials from log archives. It&apos;s a broken access control flaw, which enables attackers to obtain plaintext credentials.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/acer-addresses-critical-zero-day-vulnerabilities-in-wave-7-routers.png&quot; alt=&quot;Acer Addresses Zero-Day in Wave 7 Routers&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The vulnerability allows unauthenticated attackers to access sensitive credentials from log archives. It&apos;s a broken access control flaw, which enables attackers to obtain plaintext credentials.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/acer-addresses-critical-zero-day-vulnerabilities-in-wave-7-routers.png" length="862857" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>B&amp;R PPT30 Operating System</title><link>https://securityxp.com/articles/br-ppt30-operating-system/</link><guid isPermaLink="true">https://securityxp.com/articles/br-ppt30-operating-system/</guid><description>This operating system is widely used in industrial automation worldwide. The issue affects versions prior to 1.8.0.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/br-ppt30-operating-system.png&quot; alt=&quot;B&amp;R PPT30 Operating System&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This operating system is widely used in industrial automation worldwide. The issue affects versions prior to 1.8.0.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/br-ppt30-operating-system.png" length="954384" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>ELI5: YellowKey (CVE-2026-45585) BitLocker Bypass that survived the Great Global CrowdStrike Outage of 24)</title><link>https://securityxp.com/articles/can-someone-please-eli5-yellowkey-cve-2026-45585-to-me-an-it-admin-that/</link><guid isPermaLink="true">https://securityxp.com/articles/can-someone-please-eli5-yellowkey-cve-2026-45585-to-me-an-it-admin-that/</guid><description>The vulnerability, identified as CVE-2026-45585, has significant implications for organizations using Windows PE, versions 10 and 11, and CrowdStrike, versions 6.0 and later.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/can-someone-please-eli5-yellowkey-cve-2026-45585-to-me-an-it-admin-that.png&quot; alt=&quot;ELI5: YellowKey (CVE-2026-45585) BitLocker Bypass that survived the Great Global CrowdStrike Outage of 24)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The vulnerability, identified as CVE-2026-45585, has significant implications for organizations using Windows PE, versions 10 and 11, and CrowdStrike, versions 6.0 and later.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/can-someone-please-eli5-yellowkey-cve-2026-45585-to-me-an-it-admin-that.png" length="823887" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>CISA Adds Magento RCE CVE-2026-45247 to KEV</title><link>https://securityxp.com/articles/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog/</link><guid isPermaLink="true">https://securityxp.com/articles/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog/</guid><description>This vulnerability, tracked as CVE-2026-45247, has a CVSS score of 9.8. Cybersecurity and Infrastructure Security Agency added this flaw to its Known Exploited Vulnerabilities catalog.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog.png&quot; alt=&quot;CISA Adds Magento RCE CVE-2026-45247 to KEV&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This vulnerability, tracked as CVE-2026-45247, has a CVSS score of 9.8. Cybersecurity and Infrastructure Security Agency added this flaw to its Known Exploited Vulnerabilities catalog.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog.png" length="833508" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>Cisco Unified Comms Manager Vuln &amp; PoC Released Code</title><link>https://securityxp.com/articles/cisco-unified-communications-manager-vulnerability-exposed-along-with-poc/</link><guid isPermaLink="true">https://securityxp.com/articles/cisco-unified-communications-manager-vulnerability-exposed-along-with-poc/</guid><description>This vulnerability, identified as CVE-2026-20230, has a CVSS score of 8.6. That&apos;s a significant threat.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cisco-unified-communications-manager-vulnerability-exposed-along-with-poc.png&quot; alt=&quot;Cisco Unified Comms Manager Vuln &amp; PoC Released Code&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This vulnerability, identified as CVE-2026-20230, has a CVSS score of 8.6. That&apos;s a significant threat.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cisco-unified-communications-manager-vulnerability-exposed-along-with-poc.png" length="899053" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>Hitachi Energy ITT600 Explorer</title><link>https://securityxp.com/articles/hitachi-energy-itt600-explorer/</link><guid isPermaLink="true">https://securityxp.com/articles/hitachi-energy-itt600-explorer/</guid><description>The vulnerability, identified as CVE-2024-8176, can be exploited to carry out a Denial of Service attack on the product, potentially disrupting essential services in the energy sector.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/hitachi-energy-itt600-explorer.png&quot; alt=&quot;Hitachi Energy ITT600 Explorer&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The vulnerability, identified as CVE-2024-8176, can be exploited to carry out a Denial of Service attack on the product, potentially disrupting essential services in the energy sector.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/hitachi-energy-itt600-explorer.png" length="903718" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>ICANN Sets October 2026 DNS Trust Anchor Rollover</title><link>https://securityxp.com/articles/icann-sets-the-october-2026-dns-trust-anchor-rollover/</link><guid isPermaLink="true">https://securityxp.com/articles/icann-sets-the-october-2026-dns-trust-anchor-rollover/</guid><description>The Domain Name System, or DNS, is getting a major update to its security protocol. This update, scheduled for October 2026, affects the DNS Security Extensions root zone Key Signing Key, a crucial co...</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/icann-sets-the-october-2026-dns-trust-anchor-rollover.png&quot; alt=&quot;ICANN Sets October 2026 DNS Trust Anchor Rollover&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Domain Name System, or DNS, is getting a major update to its security protocol. This update, scheduled for October 2026, affects the DNS Security Extensions root zone Key Signing Key, a crucial co...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/icann-sets-the-october-2026-dns-trust-anchor-rollover.png" length="807702" type="image/png"/><category>Technology</category><author>SecurityXP Intelligence Desk</author></item><item><title>Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk</title><link>https://securityxp.com/articles/offroad-emerges-from-stealth-with-7-million-to-tackle-enterprise-identity-risk/</link><guid isPermaLink="true">https://securityxp.com/articles/offroad-emerges-from-stealth-with-7-million-to-tackle-enterprise-identity-risk/</guid><description>Offroad has emerged from stealth with $7 million in seed funding, led by Ibex Investors and Skywell Capital, to tackle enterprise identity risk.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/offroad-emerges-from-stealth-with-7-million-to-tackle-enterprise-identity-risk.png&quot; alt=&quot;Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Offroad has emerged from stealth with $7 million in seed funding, led by Ibex Investors and Skywell Capital, to tackle enterprise identity risk.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/offroad-emerges-from-stealth-with-7-million-to-tackle-enterprise-identity-risk.png" length="1033840" type="image/png"/><category>Identity &amp; Access Management</category><author>SecurityXP Intelligence Desk</author></item><item><title>Code is cheap</title><link>https://securityxp.com/articles/code-is-cheap/</link><guid isPermaLink="true">https://securityxp.com/articles/code-is-cheap/</guid><description>It&apos;s counterintuitive, given the significant cost of producing code, including salaries and headcount. But there&apos;s a crucial distinction between production costs and the value of the code itself.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/code-is-cheap.png&quot; alt=&quot;Code is cheap&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;It&apos;s counterintuitive, given the significant cost of producing code, including salaries and headcount. But there&apos;s a crucial distinction between production costs and the value of the code itself.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/code-is-cheap.png" length="707771" type="image/png"/><category>Commentary / Opinion</category><author>SecurityXP Editorial Desk</author></item><item><title>Google Patches Android Zero-Day CVE-2025-48595</title><link>https://securityxp.com/articles/google-patches-android-zero-day-cve-2025-48595-exploited-in-targeted-attacks/</link><guid isPermaLink="true">https://securityxp.com/articles/google-patches-android-zero-day-cve-2025-48595-exploited-in-targeted-attacks/</guid><description>One flaw, CVE-2025-48595, is particularly alarming. This vulnerability has a CVSS score of 8.4.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/google-patches-android-zero-day-cve-2025-48595-exploited-in-targeted-attacks.png&quot; alt=&quot;Google Patches Android Zero-Day CVE-2025-48595&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;One flaw, CVE-2025-48595, is particularly alarming. This vulnerability has a CVSS score of 8.4.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/google-patches-android-zero-day-cve-2025-48595-exploited-in-targeted-attacks.png" length="967606" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>Hackers Used Meta AI Bot to Steal Instagrams</title><link>https://securityxp.com/articles/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/</link><guid isPermaLink="true">https://securityxp.com/articles/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/</guid><description>High-profile Instagram profiles, including those of former US President Barack Obama, the U.S. Space Force, and Sephora, were compromised after attackers social engineered Meta&apos;s AI-powered support assistant.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts.png&quot; alt=&quot;Hackers Used Meta AI Bot to Steal Instagrams&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;High-profile Instagram profiles, including those of former US President Barack Obama, the U.S. Space Force, and Sephora, were compromised after attackers social engineered Meta&apos;s AI-powered support assistant.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts.png" length="802269" type="image/png"/><category>AI/ML Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Old Oracle WebLogic Flaw Now Under Active Exploit</title><link>https://securityxp.com/articles/two-year-old-oracle-weblogic-server-vulnerability-is-being-exploited/</link><guid isPermaLink="true">https://securityxp.com/articles/two-year-old-oracle-weblogic-server-vulnerability-is-being-exploited/</guid><description>This was patched by Oracle in July 2024. The vulnerability allows an unauthenticated attacker with network access to take control of susceptible Oracle WebLogic Server instances.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/two-year-old-oracle-weblogic-server-vulnerability-is-being-exploited.png&quot; alt=&quot;Old Oracle WebLogic Flaw Now Under Active Exploit&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This was patched by Oracle in July 2024. The vulnerability allows an unauthenticated attacker with network access to take control of susceptible Oracle WebLogic Server instances.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/two-year-old-oracle-weblogic-server-vulnerability-is-being-exploited.png" length="775850" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>CISA Adds Android &amp; Linux Kernel Flaws to KEV catalog</title><link>https://securityxp.com/articles/us-cisa-adds-android-and-linux-kernel-flaws-to-its-known-exploited/</link><guid isPermaLink="true">https://securityxp.com/articles/us-cisa-adds-android-and-linux-kernel-flaws-to-its-known-exploited/</guid><description>Cybersecurity and Infrastructure Security Agency, CISA, has just added two significant vulnerabilities to its Known Exploited Vulnerabilities catalog.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/us-cisa-adds-android-and-linux-kernel-flaws-to-its-known-exploited.png&quot; alt=&quot;CISA Adds Android &amp; Linux Kernel Flaws to KEV catalog&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cybersecurity and Infrastructure Security Agency, CISA, has just added two significant vulnerabilities to its Known Exploited Vulnerabilities catalog.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/us-cisa-adds-android-and-linux-kernel-flaws-to-its-known-exploited.png" length="972134" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Intelligence Desk</author></item><item><title>Google fixes one actively exploited Android zero-day, 124 flaws</title><link>https://securityxp.com/articles/google-fixes-one-actively-exploited-android-zero-day-124-flaws/</link><guid isPermaLink="true">https://securityxp.com/articles/google-fixes-one-actively-exploited-android-zero-day-124-flaws/</guid><description>Google&apos;s June 2026 Android update patches 124 vulnerabilities, including an actively exploited zero-day in the Android Framework tracked as CVE-2025-48595.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/google-fixes-one-actively-exploited-android-zero-day-124-flaws.png&quot; alt=&quot;Google fixes one actively exploited Android zero-day, 124 flaws&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Google&apos;s June 2026 Android update patches 124 vulnerabilities, including an actively exploited zero-day in the Android Framework tracked as CVE-2025-48595.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/google-fixes-one-actively-exploited-android-zero-day-124-flaws.png" length="934826" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>Infected Red Hat npm Packages Leak Credentials</title><link>https://securityxp.com/articles/infected-red-hat-npm-packages-expose-developer-credentials/</link><guid isPermaLink="true">https://securityxp.com/articles/infected-red-hat-npm-packages-expose-developer-credentials/</guid><description>This malware is a new variant of the Shai-Hulud credential-stealing malware. It&apos;s designed to steal developer credentials, cloud secrets, SSH keys, CI/CD tokens, and other sensitive information.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/infected-red-hat-npm-packages-expose-developer-credentials.png&quot; alt=&quot;Infected Red Hat npm Packages Leak Credentials&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This malware is a new variant of the Shai-Hulud credential-stealing malware. It&apos;s designed to steal developer credentials, cloud secrets, SSH keys, CI/CD tokens, and other sensitive information.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/infected-red-hat-npm-packages-expose-developer-credentials.png" length="861839" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>Critical Windows Netlogon RCE Flaw Exploited</title><link>https://securityxp.com/articles/critical-windows-netlogon-rce-flaw-now-exploited-in-attacks/</link><guid isPermaLink="true">https://securityxp.com/articles/critical-windows-netlogon-rce-flaw-now-exploited-in-attacks/</guid><description>This vulnerability, tracked as CVE-2026-41089, has a CVSS score of 9.8. It&apos;s a stack-based buffer overflow issue that could be exploited via crafted network requests.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/critical-windows-netlogon-rce-flaw-now-exploited-in-attacks.png&quot; alt=&quot;Critical Windows Netlogon RCE Flaw Exploited&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This vulnerability, tracked as CVE-2026-41089, has a CVSS score of 9.8. It&apos;s a stack-based buffer overflow issue that could be exploited via crafted network requests.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/critical-windows-netlogon-rce-flaw-now-exploited-in-attacks.png" length="931346" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>CVE-2026-0826: HP Poly VVX VoIP Buffer Overflow and Trio VoIP Phones (FIXED)</title><link>https://securityxp.com/articles/cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-in-hp-poly-vvx-and/</link><guid isPermaLink="true">https://securityxp.com/articles/cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-in-hp-poly-vvx-and/</guid><description>Hackers can exploit this vulnerability, CVE-2026-0826, to achieve unauthenticated remote code execution with root privileges on a target device.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-in-hp-poly-vvx-and.png&quot; alt=&quot;CVE-2026-0826: HP Poly VVX VoIP Buffer Overflow and Trio VoIP Phones (FIXED)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Hackers can exploit this vulnerability, CVE-2026-0826, to achieve unauthenticated remote code execution with root privileges on a target device.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-in-hp-poly-vvx-and.png" length="937747" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>Carnival Data Breach Impacts 6 Million Customers</title><link>https://securityxp.com/articles/carnival-data-breach-impacts-nearly-6-million-customers/</link><guid isPermaLink="true">https://securityxp.com/articles/carnival-data-breach-impacts-nearly-6-million-customers/</guid><description>According to filings with the Maine Attorney General , the cruise operator is sending notification letters to 5,995,277 customers and employees. Hackers got in and exfiltrated sensitive files.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/carnival-data-breach-impacts-nearly-6-million-customers.png&quot; alt=&quot;Carnival Data Breach Impacts 6 Million Customers&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;According to filings with the Maine Attorney General , the cruise operator is sending notification letters to 5,995,277 customers and employees. Hackers got in and exfiltrated sensitive files.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/carnival-data-breach-impacts-nearly-6-million-customers.png" length="929175" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>Rapid7: PAN-OS GlobalProtect Bypass Exploited</title><link>https://securityxp.com/articles/rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass/</link><guid isPermaLink="true">https://securityxp.com/articles/rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass/</guid><description>Attackers are actively exploiting a high-severity authentication bypass vulnerability in Palo Alto Networks GlobalProtect portals and gateways, allowing remote attackers to establish unauthorized VPN access to corporate networks.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass.png&quot; alt=&quot;Rapid7: PAN-OS GlobalProtect Bypass Exploited&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Attackers are actively exploiting a high-severity authentication bypass vulnerability in Palo Alto Networks GlobalProtect portals and gateways, allowing remote attackers to establish unauthorized VPN access to corporate networks.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass.png" length="932246" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Editorial Desk</author></item><item><title>7-Eleven Data Breach: 185,000 People Exposed</title><link>https://securityxp.com/articles/7-eleven-data-breach-exposes-personal-information-of-185000-people/</link><guid isPermaLink="true">https://securityxp.com/articles/7-eleven-data-breach-exposes-personal-information-of-185000-people/</guid><description>The ShinyHunters extortion gang claimed responsibility, leaked a 9.4GB archive of stolen data, and is now selling it on underground forums after the company refused to pay a ransom.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/7-eleven-data-breach-exposes-personal-information-of-185000-people.png&quot; alt=&quot;7-Eleven Data Breach: 185,000 People Exposed&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The ShinyHunters extortion gang claimed responsibility, leaked a 9.4GB archive of stolen data, and is now selling it on underground forums after the company refused to pay a ransom.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/7-eleven-data-breach-exposes-personal-information-of-185000-people.png" length="916459" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>FBI Warns of Kali365 Phishing Kit Targeting M365 Access Tokens&apos;</title><link>https://securityxp.com/articles/fbi-warns-of-kali365-the-fast-growing-phishing-kit-stealing-microsoft-365/</link><guid isPermaLink="true">https://securityxp.com/articles/fbi-warns-of-kali365-the-fast-growing-phishing-kit-stealing-microsoft-365/</guid><description>By exploiting legitimate OAuth device code authentication, Kali365 bypasses multi-factor authentication entirely... and that&apos;s a game-changer.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/fbi-warns-of-kali365-the-fast-growing-phishing-kit-stealing-microsoft-365.png&quot; alt=&quot;FBI Warns of Kali365 Phishing Kit Targeting M365 Access Tokens&apos;&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;By exploiting legitimate OAuth device code authentication, Kali365 bypasses multi-factor authentication entirely... and that&apos;s a game-changer.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/fbi-warns-of-kali365-the-fast-growing-phishing-kit-stealing-microsoft-365.png" length="970573" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>Ghost CMS Flaw Powers ClickFix Attacks at Scale</title><link>https://securityxp.com/articles/ghost-cms-flaw-abused-to-push-clickfix-attacks-on-hundreds-of-sites/</link><guid isPermaLink="true">https://securityxp.com/articles/ghost-cms-flaw-abused-to-push-clickfix-attacks-on-hundreds-of-sites/</guid><description>and it&apos;s getting out of hand. Over 700 legitimate domains have been poisoned, including university portals and major technology brands.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/ghost-cms-flaw-abused-to-push-clickfix-attacks-on-hundreds-of-sites.png&quot; alt=&quot;Ghost CMS Flaw Powers ClickFix Attacks at Scale&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;and it&apos;s getting out of hand. Over 700 legitimate domains have been poisoned, including university portals and major technology brands.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/ghost-cms-flaw-abused-to-push-clickfix-attacks-on-hundreds-of-sites.png" length="950329" type="image/png"/><category>Technology</category><author>SecurityXP Editorial Desk</author></item><item><title>New EU AI Security Regulations for Organizations</title><link>https://securityxp.com/articles/eu-ai-security-regulations/</link><guid isPermaLink="true">https://securityxp.com/articles/eu-ai-security-regulations/</guid><description>The European Union has introduced comprehensive AI security regulations requiring organizations to implement security measures for AI systems. We break down the requirements, timelines, and compliance steps.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/eu-ai-security-regulations.png&quot; alt=&quot;New EU AI Security Regulations for Organizations&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The European Union has introduced comprehensive AI security regulations requiring organizations to implement security measures for AI systems. We break down the requirements, timelines, and compliance steps.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/eu-ai-security-regulations.png" length="854699" type="image/png"/><category>AI/ML Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Limitations of STRIDE in Threat Modeling AI Agents</title><link>https://securityxp.com/articles/limitations-of-stride-in-threat-modeling-ai-agents/</link><guid isPermaLink="true">https://securityxp.com/articles/limitations-of-stride-in-threat-modeling-ai-agents/</guid><description>The STRIDE threat modeling framework is insufficient for securing AI agents due to their non-deterministic and autonomous nature, requiring a new approach to identify and mitigate potential threats</description><pubDate>Thu, 26 Mar 2026 05:07:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/limitations-of-stride-in-threat-modeling-ai-agents.png&quot; alt=&quot;Limitations of STRIDE in Threat Modeling AI Agents&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The STRIDE threat modeling framework is insufficient for securing AI agents due to their non-deterministic and autonomous nature, requiring a new approach to identify and mitigate potential threats&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/limitations-of-stride-in-threat-modeling-ai-agents.png" length="790470" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Red Teaming Generative AI: Language as the New Exploit Vector</title><link>https://securityxp.com/articles/red-teaming-generative-ai-language-as-the-new-exploit-vector/</link><guid isPermaLink="true">https://securityxp.com/articles/red-teaming-generative-ai-language-as-the-new-exploit-vector/</guid><description>Generative AI systems are vulnerable to attacks via natural language, with 35% of real-world AI security incidents caused by simple prompts, highlighting the need for cybersecurity practitioners to adapt their skills to this new threat landscape</description><pubDate>Wed, 18 Feb 2026 02:24:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/red-teaming-generative-ai-language-as-the-new-exploit-vector.png&quot; alt=&quot;Red Teaming Generative AI: Language as the New Exploit Vector&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Generative AI systems are vulnerable to attacks via natural language, with 35% of real-world AI security incidents caused by simple prompts, highlighting the need for cybersecurity practitioners to adapt their skills to this new threat landscape&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/red-teaming-generative-ai-language-as-the-new-exploit-vector.png" length="871828" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Fortifying IoT Devices Against Cyber Threats</title><link>https://securityxp.com/articles/fortifying-iot-devices-against-cyber-threats/</link><guid isPermaLink="true">https://securityxp.com/articles/fortifying-iot-devices-against-cyber-threats/</guid><description>IoT devices are vulnerable to hidden cyber threats, and threat modeling is essential to anticipate and mitigate these risks</description><pubDate>Thu, 16 Oct 2025 14:44:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/fortifying-iot-devices-against-cyber-threats.png&quot; alt=&quot;Fortifying IoT Devices Against Cyber Threats&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;IoT devices are vulnerable to hidden cyber threats, and threat modeling is essential to anticipate and mitigate these risks&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/fortifying-iot-devices-against-cyber-threats.png" length="909459" type="image/png"/><category>IoT Security</category><author>SecurityXP</author></item><item><title>Implementing MAESTRO Framework for Enhanced ML Security</title><link>https://securityxp.com/articles/implementing-maestro-framework-for-enhanced-ml-security/</link><guid isPermaLink="true">https://securityxp.com/articles/implementing-maestro-framework-for-enhanced-ml-security/</guid><description>The MAESTRO framework provides a layered approach to securing machine learning models and agentic AI, enabling organizations to map and defend against complex threats</description><pubDate>Sun, 05 Oct 2025 22:50:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/implementing-maestro-framework-for-enhanced-ml-security.png&quot; alt=&quot;Implementing MAESTRO Framework for Enhanced ML Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The MAESTRO framework provides a layered approach to securing machine learning models and agentic AI, enabling organizations to map and defend against complex threats&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/implementing-maestro-framework-for-enhanced-ml-security.png" length="861836" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>Essential Security Moves for Leaders in the Age of AI</title><link>https://securityxp.com/articles/essential-security-moves-for-leaders-in-the-age-of-ai/</link><guid isPermaLink="true">https://securityxp.com/articles/essential-security-moves-for-leaders-in-the-age-of-ai/</guid><description>As AI adoption accelerates in enterprises, security leaders must implement layered security strategies to mitigate evolving threats and protect complex digital architectures</description><pubDate>Sat, 04 Oct 2025 22:15:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/essential-security-moves-for-leaders-in-the-age-of-ai.png&quot; alt=&quot;Essential Security Moves for Leaders in the Age of AI&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As AI adoption accelerates in enterprises, security leaders must implement layered security strategies to mitigate evolving threats and protect complex digital architectures&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/essential-security-moves-for-leaders-in-the-age-of-ai.png" length="959744" type="image/png"/><category>AI/ML Security</category><author>SecurityXP</author></item><item><title>CISA Issues Nine Urgent ICS Advisories</title><link>https://securityxp.com/articles/cisa-issues-nine-urgent-advisories-on-industrial-control-systems-vulnerabilities/</link><guid isPermaLink="true">https://securityxp.com/articles/cisa-issues-nine-urgent-advisories-on-industrial-control-systems-vulnerabilities/</guid><description>In a critical bulletin released on September 18, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published nine new advisories detailing high-severity vulnerabilities affecti...</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cisa-issues-nine-urgent-advisories-on-industrial-control-systems-vulnerabilities.png&quot; alt=&quot;CISA Issues Nine Urgent ICS Advisories&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;In a critical bulletin released on September 18, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published nine new advisories detailing high-severity vulnerabilities affecti...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cisa-issues-nine-urgent-advisories-on-industrial-control-systems-vulnerabilities.png" length="821306" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Critical Chrome Zero-Day CVE-2025-10585 Explained</title><link>https://securityxp.com/articles/critical-google-chrome-zero-day-cve-2025-10585-what-you-need-to-know/</link><guid isPermaLink="true">https://securityxp.com/articles/critical-google-chrome-zero-day-cve-2025-10585-what-you-need-to-know/</guid><description>Google has just patched a critical zero-day vulnerability in its Chrome web browser—CVE-2025-10585—which has been actively exploited in the wild. This flaw, a type confusion issue in Chrome’s V8 Ja...</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/critical-google-chrome-zero-day-cve-2025-10585-what-you-need-to-know.png&quot; alt=&quot;Critical Chrome Zero-Day CVE-2025-10585 Explained&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Google has just patched a critical zero-day vulnerability in its Chrome web browser—CVE-2025-10585—which has been actively exploited in the wild. This flaw, a type confusion issue in Chrome’s V8 Ja...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/critical-google-chrome-zero-day-cve-2025-10585-what-you-need-to-know.png" length="898912" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Ivanti EPMM Malicious Listener Malware Analysis</title><link>https://securityxp.com/articles/malware-analysis-report-on-a-malicious-listener-deployed-on-ivanti-endpoint-manager-mobile-epmm-systems/</link><guid isPermaLink="true">https://securityxp.com/articles/malware-analysis-report-on-a-malicious-listener-deployed-on-ivanti-endpoint-manager-mobile-epmm-systems/</guid><description>U.S. Cybersecurity and Infrastructure Security Agency’s new Malware Analysis Report on a malicious listener deployed on Ivanti Endpoint Manager Mobile (EPMM) systems by chaining CVE-2025-4427 and C...</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/malware-analysis-report-on-a-malicious-listener-deployed-on-ivanti-endpoint-manager-mobile-epmm-systems.png&quot; alt=&quot;Ivanti EPMM Malicious Listener Malware Analysis&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;U.S. Cybersecurity and Infrastructure Security Agency’s new Malware Analysis Report on a malicious listener deployed on Ivanti Endpoint Manager Mobile (EPMM) systems by chaining CVE-2025-4427 and C...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/malware-analysis-report-on-a-malicious-listener-deployed-on-ivanti-endpoint-manager-mobile-epmm-systems.png" length="937639" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>MSSP Alert Top 250 for 2024: Cybersecurity State</title><link>https://securityxp.com/articles/mssp-alert-top-250-for-2024-a-deep-dive-into-the-state-of-cybersecurity/</link><guid isPermaLink="true">https://securityxp.com/articles/mssp-alert-top-250-for-2024-a-deep-dive-into-the-state-of-cybersecurity/</guid><description>Discover the key findings from the 2024 MSSP Alert Top 250 report. Explore trends in MSSP growth, profitability, in-house SOCs, and the critical services defining modern cyber defense.</description><pubDate>Sun, 22 Jun 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/mssp-alert-top-250-for-2024-a-deep-dive-into-the-state-of-cybersecurity.png&quot; alt=&quot;MSSP Alert Top 250 for 2024: Cybersecurity State&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Discover the key findings from the 2024 MSSP Alert Top 250 report. Explore trends in MSSP growth, profitability, in-house SOCs, and the critical services defining modern cyber defense.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/mssp-alert-top-250-for-2024-a-deep-dive-into-the-state-of-cybersecurity.png" length="1015194" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Pakistan-Linked APT36 Exploits &apos;Pahalgam&apos; Terror Attack Theme in Cyber-Espionage Campaign Against India</title><link>https://securityxp.com/articles/pakistan-linked-apt36-exploits-pahalgam-terror-attack-theme-in-multi-pronged-cyber-espionage-campaign-against-india/</link><guid isPermaLink="true">https://securityxp.com/articles/pakistan-linked-apt36-exploits-pahalgam-terror-attack-theme-in-multi-pronged-cyber-espionage-campaign-against-india/</guid><description>The Pakistan-linked APT group APT36 (Transparent Tribe) is using a &apos;Pahalgam terror attack&apos; lure in a multi-pronged cyber-espionage campaign targeting India.</description><pubDate>Sat, 26 Apr 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/pakistan-linked-apt36-exploits-pahalgam-terror-attack-theme-in-multi-pronged-cyber-espionage-campaign-against-india.png&quot; alt=&quot;Pakistan-Linked APT36 Exploits &apos;Pahalgam&apos; Terror Attack Theme in Cyber-Espionage Campaign Against India&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Pakistan-linked APT group APT36 (Transparent Tribe) is using a &apos;Pahalgam terror attack&apos; lure in a multi-pronged cyber-espionage campaign targeting India.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/pakistan-linked-apt36-exploits-pahalgam-terror-attack-theme-in-multi-pronged-cyber-espionage-campaign-against-india.png" length="978550" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>CVE-2025-29927: Next.js Path Traversal Deep Dive</title><link>https://securityxp.com/articles/unpacking-cve-2025-29927-a-deep-dive-into-the-next-js-path-traversal-vulnerability/</link><guid isPermaLink="true">https://securityxp.com/articles/unpacking-cve-2025-29927-a-deep-dive-into-the-next-js-path-traversal-vulnerability/</guid><description>Next.js has rapidly become a dominant force in the React ecosystem, lauded for its developer experience and performance optimizations. However, like any complex framework, it&apos;s not immune to securi...</description><pubDate>Tue, 25 Mar 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/unpacking-cve-2025-29927-a-deep-dive-into-the-next-js-path-traversal-vulnerability.png&quot; alt=&quot;CVE-2025-29927: Next.js Path Traversal Deep Dive&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Next.js has rapidly become a dominant force in the React ecosystem, lauded for its developer experience and performance optimizations. However, like any complex framework, it&apos;s not immune to securi...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/unpacking-cve-2025-29927-a-deep-dive-into-the-next-js-path-traversal-vulnerability.png" length="884427" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>MITRE ATT&amp;CKcon 5.0: Elevating Cybersecurity</title><link>https://securityxp.com/articles/mitre-attckcon-5-0-elevating-cybersecurity-knowledge/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attckcon-5-0-elevating-cybersecurity-knowledge/</guid><description>Cybersecurity remains at the forefront of the global conversation, and MITRE ATT&amp;CKcon 5.0 is a pivotal event in the field. Scheduled for October 22-23, 2024, in McLean, Virginia, the conference se...</description><pubDate>Sat, 07 Sep 2024 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/mitre-attckcon-5-0-elevating-cybersecurity-knowledge.png&quot; alt=&quot;MITRE ATT&amp;CKcon 5.0: Elevating Cybersecurity&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cybersecurity remains at the forefront of the global conversation, and MITRE ATT&amp;CKcon 5.0 is a pivotal event in the field. Scheduled for October 22-23, 2024, in McLean, Virginia, the conference se...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/mitre-attckcon-5-0-elevating-cybersecurity-knowledge.png" length="969673" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>MSSP Alert Top 250 MSSPs 2023 Edition Released</title><link>https://securityxp.com/articles/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-service-providers-2023-edition/</link><guid isPermaLink="true">https://securityxp.com/articles/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-service-providers-2023-edition/</guid><description>As cyber threats evolve, so do the strategies to combat them. The latest MSSP Alert: Top 250 MSSPs Service Providers 2023 Edition , released by CyberRisk Alliance , offers valuable insights in</description><pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-service-providers-2023-edition.png&quot; alt=&quot;MSSP Alert Top 250 MSSPs 2023 Edition Released&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As cyber threats evolve, so do the strategies to combat them. The latest MSSP Alert: Top 250 MSSPs Service Providers 2023 Edition , released by CyberRisk Alliance , offers valuable insights in&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-service-providers-2023-edition.png" length="929219" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Threat Modeling for Proactive Cyber Defense</title><link>https://securityxp.com/articles/threat-modeling-for-proactive-cyber-defense/</link><guid isPermaLink="true">https://securityxp.com/articles/threat-modeling-for-proactive-cyber-defense/</guid><description>Threat modeling is a critical tool for identifying and mitigating potential security threats, allowing organizations to proactively safeguard their assets and maintain trust in an increasingly hostile cyber environment.</description><pubDate>Sun, 18 Aug 2024 10:08:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/threat-modeling-for-proactive-cyber-defense.png&quot; alt=&quot;Threat Modeling for Proactive Cyber Defense&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Threat modeling is a critical tool for identifying and mitigating potential security threats, allowing organizations to proactively safeguard their assets and maintain trust in an increasingly hostile cyber environment.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/threat-modeling-for-proactive-cyber-defense.png" length="950269" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP</author></item><item><title>Cyber Resilience Through Threat Modeling Techniques</title><link>https://securityxp.com/articles/cyber-resilience-through-threat-modeling-techniques/</link><guid isPermaLink="true">https://securityxp.com/articles/cyber-resilience-through-threat-modeling-techniques/</guid><description>Implementing cutting-edge threat modeling techniques is crucial for mitigating cyber threats and enhancing security posture in today&apos;s rapidly evolving technological landscape</description><pubDate>Wed, 05 Jun 2024 15:06:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cyber-resilience-through-threat-modeling-techniques.png&quot; alt=&quot;Cyber Resilience Through Threat Modeling Techniques&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Implementing cutting-edge threat modeling techniques is crucial for mitigating cyber threats and enhancing security posture in today&apos;s rapidly evolving technological landscape&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cyber-resilience-through-threat-modeling-techniques.png" length="997923" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP</author></item><item><title>Threat Modeling Tools for Enhanced Security Strategy</title><link>https://securityxp.com/articles/threat-modeling-tools-for-enhanced-security-strategy/</link><guid isPermaLink="true">https://securityxp.com/articles/threat-modeling-tools-for-enhanced-security-strategy/</guid><description>This article explores the benefits and key features of threat modeling tools, highlighting their importance in enhancing security strategies and postures</description><pubDate>Wed, 05 Jun 2024 03:39:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/threat-modeling-tools-for-enhanced-security-strategy.png&quot; alt=&quot;Threat Modeling Tools for Enhanced Security Strategy&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;This article explores the benefits and key features of threat modeling tools, highlighting their importance in enhancing security strategies and postures&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/threat-modeling-tools-for-enhanced-security-strategy.png" length="954064" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP</author></item><item><title>Top 10 CSPM Tools Shaping Cloud Security in 2026</title><link>https://securityxp.com/articles/securing-the-clouds-the-top-10-cspm-tools-shaping-cloud-security/</link><guid isPermaLink="true">https://securityxp.com/articles/securing-the-clouds-the-top-10-cspm-tools-shaping-cloud-security/</guid><description>Cloud Security Posture Management (CSPM) tools detect misconfigurations and enforce compliance across cloud environments. Here are the top 10 CSPM tools for 2026.</description><pubDate>Sat, 13 Apr 2024 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/securing-the-clouds-the-top-10-cspm-tools-shaping-cloud-security.png&quot; alt=&quot;Top 10 CSPM Tools Shaping Cloud Security in 2026&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cloud Security Posture Management (CSPM) tools detect misconfigurations and enforce compliance across cloud environments. Here are the top 10 CSPM tools for 2026.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/securing-the-clouds-the-top-10-cspm-tools-shaping-cloud-security.png" length="969567" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Enhancing ISO 27001 Compliance with Penetration Testing</title><link>https://securityxp.com/articles/enhancing-iso-27001-compliance-with-penetration-testing/</link><guid isPermaLink="true">https://securityxp.com/articles/enhancing-iso-27001-compliance-with-penetration-testing/</guid><description>Penetration testing boosts ISO 27001 ROI by identifying critical vulnerabilities, reducing breach costs, and streamlining compliance, leading to enhanced security and stakeholder trust</description><pubDate>Thu, 22 Feb 2024 09:17:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/enhancing-iso-27001-compliance-with-penetration-testing.png&quot; alt=&quot;Enhancing ISO 27001 Compliance with Penetration Testing&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Penetration testing boosts ISO 27001 ROI by identifying critical vulnerabilities, reducing breach costs, and streamlining compliance, leading to enhanced security and stakeholder trust&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/enhancing-iso-27001-compliance-with-penetration-testing.png" length="872504" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP</author></item><item><title>Threat Modeling Essentials for Enhanced Security</title><link>https://securityxp.com/articles/threat-modeling-essentials-for-enhanced-security/</link><guid isPermaLink="true">https://securityxp.com/articles/threat-modeling-essentials-for-enhanced-security/</guid><description>Threat modeling is a critical process for identifying and mitigating potential security threats in software development, and its integration into the Secure-by-Design approach can significantly enhance an organization&apos;s defense against cyber threats</description><pubDate>Sat, 06 Jan 2024 09:27:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/threat-modeling-essentials-for-enhanced-security.png&quot; alt=&quot;Threat Modeling Essentials for Enhanced Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Threat modeling is a critical process for identifying and mitigating potential security threats in software development, and its integration into the Secure-by-Design approach can significantly enhance an organization&apos;s defense against cyber threats&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/threat-modeling-essentials-for-enhanced-security.png" length="874770" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP</author></item><item><title>MITRE ATT&amp;CK version 14</title><link>https://securityxp.com/articles/mitre-attck-version-14/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-version-14/</guid><description>I. Introduction: Importance of staying updated with frameworks like MITRE ATT&amp;CK In the realm of offensive security, staying updated with frameworks like MITRE ATT&amp;CK is pivotal. It provides a stru...</description><pubDate>Sat, 04 Nov 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/mitre-attck-version-14.png&quot; alt=&quot;MITRE ATT&amp;CK version 14&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;I. Introduction: Importance of staying updated with frameworks like MITRE ATT&amp;CK In the realm of offensive security, staying updated with frameworks like MITRE ATT&amp;CK is pivotal. It provides a stru...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/mitre-attck-version-14.png" length="768513" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Optimizing Security with OPSWAT Solutions</title><link>https://securityxp.com/articles/optimizing-security-with-opswat-solutions/</link><guid isPermaLink="true">https://securityxp.com/articles/optimizing-security-with-opswat-solutions/</guid><description>OPSWAT provides advanced cybersecurity solutions that help organizations optimize security measures.</description><pubDate>Mon, 15 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/optimizing-security-with-opswat-solutions.png&quot; alt=&quot;Optimizing Security with OPSWAT Solutions&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;OPSWAT provides advanced cybersecurity solutions that help organizations optimize security measures.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/optimizing-security-with-opswat-solutions.png" length="844029" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Leading Vulnerability Scanners: Benefits &amp; Uses</title><link>https://securityxp.com/articles/leading-vulnerability-scanners-benefits-and-use-cases/</link><guid isPermaLink="true">https://securityxp.com/articles/leading-vulnerability-scanners-benefits-and-use-cases/</guid><description>Leading vulnerability scanners provide comprehensive security assessment and management capabilities, allowing organizations to identify and remediate potential vulnerabilities in their IT infrastructure. From real-time scanning to automated reporting, these tools offer a range of benefits and use cases, helping businesses to mitigate risks, meet compliance requirements, and enhance overall security posture.</description><pubDate>Sun, 14 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/leading-vulnerability-scanners-benefits-and-use-cases.png&quot; alt=&quot;Leading Vulnerability Scanners: Benefits &amp; Uses&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Leading vulnerability scanners provide comprehensive security assessment and management capabilities, allowing organizations to identify and remediate potential vulnerabilities in their IT infrastructure. From real-time scanning to automated reporting, these tools offer a range of benefits and use cases, helping businesses to mitigate risks, meet compliance requirements, and enhance overall security posture.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/leading-vulnerability-scanners-benefits-and-use-cases.png" length="956657" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Editorial Desk</author></item><item><title>Centralized Log Management &amp; SIEM: Top Picks</title><link>https://securityxp.com/articles/centralized-log-management-siem-solutions-benefits-top-picks/</link><guid isPermaLink="true">https://securityxp.com/articles/centralized-log-management-siem-solutions-benefits-top-picks/</guid><description>Centralized Log Management &amp; SIEM Solutions: Benefits &amp; Top Picks Centralized log management and SIEM solutions are crucial components of modern IT security infrastructure. They allow businesses to monitor and analyze network activity, detect potential threats, and respond to incidents in real-time. In this article, we’ll explore the benefits of centralized log management and SIEM solutions, and recommend some of the top picks in the market.</description><pubDate>Sat, 13 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/centralized-log-management-siem-solutions-benefits-top-picks.png&quot; alt=&quot;Centralized Log Management &amp; SIEM: Top Picks&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Centralized Log Management &amp; SIEM Solutions: Benefits &amp; Top Picks Centralized log management and SIEM solutions are crucial components of modern IT security infrastructure. They allow businesses to monitor and analyze network activity, detect potential threats, and respond to incidents in real-time. In this article, we’ll explore the benefits of centralized log management and SIEM solutions, and recommend some of the top picks in the market.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/centralized-log-management-siem-solutions-benefits-top-picks.png" length="936457" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>DevSecOps: Multi-Level App Security Testing</title><link>https://securityxp.com/articles/devsecops-advantages-of-multi-level-application-security-testing/</link><guid isPermaLink="true">https://securityxp.com/articles/devsecops-advantages-of-multi-level-application-security-testing/</guid><description>DevsecOps: Multi-Level App Security Testing DevsecOps, an evolution of DevOps, introduces security teams early in the development cycle. This approach enables continuous application security testing across multiple levels, providing a comprehensive security posture. With DevsecOps, organizations can leverage automation, collaboration, and continuous feedback, reducing the time to detect and remediate vulnerabilities.</description><pubDate>Fri, 12 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/devsecops-advantages-of-multi-level-application-security-testing.png&quot; alt=&quot;DevSecOps: Multi-Level App Security Testing&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;DevsecOps: Multi-Level App Security Testing DevsecOps, an evolution of DevOps, introduces security teams early in the development cycle. This approach enables continuous application security testing across multiple levels, providing a comprehensive security posture. With DevsecOps, organizations can leverage automation, collaboration, and continuous feedback, reducing the time to detect and remediate vulnerabilities.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/devsecops-advantages-of-multi-level-application-security-testing.png" length="955437" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Optimizing IT Operations with Top CMDB Solutions</title><link>https://securityxp.com/articles/optimizing-it-operations-with-top-cmdb-solutions/</link><guid isPermaLink="true">https://securityxp.com/articles/optimizing-it-operations-with-top-cmdb-solutions/</guid><description>A Configuration Management Database (CMDB) is a critical component of IT operations. It provides a central repository of an organization&apos;s IT assets and their relationships, enabling efficient management of IT infrastructure. Top CMDB solutions offer various features, including automated discovery, data reconciliation, and visualization, that help organizations optimize IT operations. By leveraging the capabilities of CMDB solutions, organizations can reduce the time and effort spent on managing IT assets, ensure compliance, and improve overall IT efficiency.</description><pubDate>Thu, 11 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/optimizing-it-operations-with-top-cmdb-solutions.png&quot; alt=&quot;Optimizing IT Operations with Top CMDB Solutions&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A Configuration Management Database (CMDB) is a critical component of IT operations. It provides a central repository of an organization&apos;s IT assets and their relationships, enabling efficient management of IT infrastructure. Top CMDB solutions offer various features, including automated discovery, data reconciliation, and visualization, that help organizations optimize IT operations. By leveraging the capabilities of CMDB solutions, organizations can reduce the time and effort spent on managing IT assets, ensure compliance, and improve overall IT efficiency.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/optimizing-it-operations-with-top-cmdb-solutions.png" length="967028" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>MITRE ATT&amp;amp;CK version 13</title><link>https://securityxp.com/articles/mitre-attck-version-13/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-version-13/</guid><description>MITRE ATT&amp;CK version 13 has been recently launched, bringing some significant updates. These include: Key website enhancements Increased focus on cloud and Linux coverage More detailed det...</description><pubDate>Mon, 08 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/mitre-attck-version-13.png&quot; alt=&quot;MITRE ATT&amp;amp;CK version 13&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;MITRE ATT&amp;CK version 13 has been recently launched, bringing some significant updates. These include: Key website enhancements Increased focus on cloud and Linux coverage More detailed det...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/mitre-attck-version-13.png" length="959394" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Leading DLP Solutions: Maximizing Data Protection</title><link>https://securityxp.com/articles/leading-dlp-solutions-maximizing-data-protection/</link><guid isPermaLink="true">https://securityxp.com/articles/leading-dlp-solutions-maximizing-data-protection/</guid><description>As data breaches continue to rise, it&apos;s vital for organizations to implement and maintain effective Data Loss Prevention (DLP) solutions. Leading DLP solutions offer comprehensive protection by monitoring and controlling data flow, identifying sensitive information, and enforcing policies to prevent leaks. With the right implementation and configuration, businesses can maximize data protection and avoid costly and damaging breaches.</description><pubDate>Fri, 05 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/leading-dlp-solutions-maximizing-data-protection.png&quot; alt=&quot;Leading DLP Solutions: Maximizing Data Protection&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As data breaches continue to rise, it&apos;s vital for organizations to implement and maintain effective Data Loss Prevention (DLP) solutions. Leading DLP solutions offer comprehensive protection by monitoring and controlling data flow, identifying sensitive information, and enforcing policies to prevent leaks. With the right implementation and configuration, businesses can maximize data protection and avoid costly and damaging breaches.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/leading-dlp-solutions-maximizing-data-protection.png" length="941771" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Top MDM Solutions: Efficiency &amp; Benefits Guide</title><link>https://securityxp.com/articles/maximizing-efficiency-top-mdm-solutions-benefits/</link><guid isPermaLink="true">https://securityxp.com/articles/maximizing-efficiency-top-mdm-solutions-benefits/</guid><description>Maximizing efficiency in today&apos;s business landscape requires powerful tools. MDM solutions provide the necessary capabilities to manage data and streamline operations. Read on to learn more about the top MDM solutions and the benefits they offer.</description><pubDate>Wed, 03 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/maximizing-efficiency-top-mdm-solutions-benefits.png&quot; alt=&quot;Top MDM Solutions: Efficiency &amp; Benefits Guide&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Maximizing efficiency in today&apos;s business landscape requires powerful tools. MDM solutions provide the necessary capabilities to manage data and streamline operations. Read on to learn more about the top MDM solutions and the benefits they offer.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/maximizing-efficiency-top-mdm-solutions-benefits.png" length="812023" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Top RASP Solutions for Secure Web Applications</title><link>https://securityxp.com/articles/exploring-top-rasp-solutions-for-secure-web-applications/</link><guid isPermaLink="true">https://securityxp.com/articles/exploring-top-rasp-solutions-for-secure-web-applications/</guid><description>As web applications become increasingly complex, the need for robust security measures becomes all the more important. One key solution that is gaining in popularity is RASP, or Runtime Application Self-Protection. Here, we take a closer look at some of the top RASP solutions available today, and how they can help to safeguard your web applications against a range of threats.</description><pubDate>Mon, 01 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/exploring-top-rasp-solutions-for-secure-web-applications.png&quot; alt=&quot;Top RASP Solutions for Secure Web Applications&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As web applications become increasingly complex, the need for robust security measures becomes all the more important. One key solution that is gaining in popularity is RASP, or Runtime Application Self-Protection. Here, we take a closer look at some of the top RASP solutions available today, and how they can help to safeguard your web applications against a range of threats.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/exploring-top-rasp-solutions-for-secure-web-applications.png" length="818700" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Top DNS Filtering Solutions for Online Security</title><link>https://securityxp.com/articles/maximizing-online-security-top-dns-filtering-solutions/</link><guid isPermaLink="true">https://securityxp.com/articles/maximizing-online-security-top-dns-filtering-solutions/</guid><description>With the increasing number of cyber attacks, it has become crucial to prioritize online security. One of the most effective ways to do so is by implementing DNS filtering solutions. These solutions not only block malicious websites but also prevent data theft and malware attacks. In this article, we will be discussing the top DNS filtering solutions that can help maximize online security.</description><pubDate>Mon, 01 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/maximizing-online-security-top-dns-filtering-solutions.png&quot; alt=&quot;Top DNS Filtering Solutions for Online Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;With the increasing number of cyber attacks, it has become crucial to prioritize online security. One of the most effective ways to do so is by implementing DNS filtering solutions. These solutions not only block malicious websites but also prevent data theft and malware attacks. In this article, we will be discussing the top DNS filtering solutions that can help maximize online security.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/maximizing-online-security-top-dns-filtering-solutions.png" length="839879" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>CISA Updates MITRE ATT&amp;CK Mapping Best Practices</title><link>https://securityxp.com/articles/cisa-updates-best-practices-for-mitre-attck-mapping/</link><guid isPermaLink="true">https://securityxp.com/articles/cisa-updates-best-practices-for-mitre-attck-mapping/</guid><description>To protect networks and data, CISA believes that understanding the behavior of adversaries is crucial. The success of network defenders in detecting and mitigating cyberattacks depends on this unde...</description><pubDate>Sun, 26 Feb 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cisa-updates-best-practices-for-mitre-attck-mapping.png&quot; alt=&quot;CISA Updates MITRE ATT&amp;CK Mapping Best Practices&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;To protect networks and data, CISA believes that understanding the behavior of adversaries is crucial. The success of network defenders in detecting and mitigating cyberattacks depends on this unde...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cisa-updates-best-practices-for-mitre-attck-mapping.png" length="984788" type="image/png"/><category>Compliance &amp; Privacy</category><author>SecurityXP Editorial Desk</author></item><item><title>ATT&amp;CK v12 is now accessible! Revisions – October 2022</title><link>https://securityxp.com/articles/attck-v12-is-now-accessible-revisions-october-2022/</link><guid isPermaLink="true">https://securityxp.com/articles/attck-v12-is-now-accessible-revisions-october-2022/</guid><description>Updates to Techniques, Groups, and Software for Enterprise, Mobile, and ICS in the October 2022 (v12) ATT&amp;CK release — including new ICS detections and Campaigns.</description><pubDate>Tue, 25 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/attck-v12-is-now-accessible-revisions-october-2022.png&quot; alt=&quot;ATT&amp;CK v12 is now accessible! Revisions – October 2022&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Updates to Techniques, Groups, and Software for Enterprise, Mobile, and ICS in the October 2022 (v12) ATT&amp;CK release — including new ICS detections and Campaigns.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/attck-v12-is-now-accessible-revisions-october-2022.png" length="858508" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Google Announces GUAC for SLSA &amp; SBOM Pairing</title><link>https://securityxp.com/articles/google-announcing-guac-a-great-pairing-with-slsa-and-sbom/</link><guid isPermaLink="true">https://securityxp.com/articles/google-announcing-guac-a-great-pairing-with-slsa-and-sbom/</guid><description>The industry is collectively aware of the importance of supply chain security. Recent events include a sharp increase in software supply chain attacks, a catastrophic severity and breadth Log4j vul...</description><pubDate>Thu, 20 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/google-announcing-guac-a-great-pairing-with-slsa-and-sbom.png&quot; alt=&quot;Google Announces GUAC for SLSA &amp; SBOM Pairing&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The industry is collectively aware of the importance of supply chain security. Recent events include a sharp increase in software supply chain attacks, a catastrophic severity and breadth Log4j vul...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/google-announcing-guac-a-great-pairing-with-slsa-and-sbom.png" length="987780" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Canarytokens. org - Rapid, Free, Mass Detection</title><link>https://securityxp.com/articles/canarytokens-org-rapid-free-mass-detection/</link><guid isPermaLink="true">https://securityxp.com/articles/canarytokens-org-rapid-free-mass-detection/</guid><description>Introduction Web bugs, the transparent images that monitor email opening, are probably already familiar to you. They operate by inserting a special URL in the image tag of a page and keeping an ey</description><pubDate>Wed, 19 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/canarytokens-org-rapid-free-mass-detection.png&quot; alt=&quot;Canarytokens. org - Rapid, Free, Mass Detection&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Introduction Web bugs, the transparent images that monitor email opening, are probably already familiar to you. They operate by inserting a special URL in the image tag of a page and keeping an ey&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/canarytokens-org-rapid-free-mass-detection.png" length="777320" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Critical Fortinet Auth Bypass: Exploit Available</title><link>https://securityxp.com/articles/critical-fortinet-auth-bypass-bug-has-an-exploit-available-apply-the-patch-now/</link><guid isPermaLink="true">https://securityxp.com/articles/critical-fortinet-auth-bypass-bug-has-an-exploit-available-apply-the-patch-now/</guid><description>A critical authentication bypass flaw affecting Fortinet&apos;s FortiOS, FortiProxy, and FortiSwitchManager appliances now has proof-of-concept exploit code available. Attackers can get around the authe...</description><pubDate>Tue, 18 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/critical-fortinet-auth-bypass-bug-has-an-exploit-available-apply-the-patch-now.png&quot; alt=&quot;Critical Fortinet Auth Bypass: Exploit Available&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A critical authentication bypass flaw affecting Fortinet&apos;s FortiOS, FortiProxy, and FortiSwitchManager appliances now has proof-of-concept exploit code available. Attackers can get around the authe...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/critical-fortinet-auth-bypass-bug-has-an-exploit-available-apply-the-patch-now.png" length="947529" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Micro Emulation Plans by MITRE-Engenuity</title><link>https://securityxp.com/articles/micro-emulation-plans-by-mitre-engenuity/</link><guid isPermaLink="true">https://securityxp.com/articles/micro-emulation-plans-by-mitre-engenuity/</guid><description>An overview of MITRE Engenuity&apos;s Micro Emulation Plans: compact, focused adversary-emulation exercises that let defenders validate detections against specific behaviors.</description><pubDate>Tue, 18 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/micro-emulation-plans-by-mitre-engenuity.png&quot; alt=&quot;Micro Emulation Plans by MITRE-Engenuity&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;An overview of MITRE Engenuity&apos;s Micro Emulation Plans: compact, focused adversary-emulation exercises that let defenders validate detections against specific behaviors.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/micro-emulation-plans-by-mitre-engenuity.png" length="966741" type="image/png"/><category>Compliance &amp; Privacy</category><author>SecurityXP Editorial Desk</author></item><item><title>&quot;Prestige&quot; Ransomware Hits Poland and Ukraine</title><link>https://securityxp.com/articles/organizations-in-poland-and-ukraine-are-affected-by-the-new-prestige-ransomware/</link><guid isPermaLink="true">https://securityxp.com/articles/organizations-in-poland-and-ukraine-are-affected-by-the-new-prestige-ransomware/</guid><description>The Microsoft Threat Intelligence Center (MSTIC) has found evidence of a novel ransomware campaign using a hitherto unidentified ransomware payload that targets businesses in the logistics and tran...</description><pubDate>Tue, 18 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/organizations-in-poland-and-ukraine-are-affected-by-the-new-prestige-ransomware.png&quot; alt=&quot;&quot;Prestige&quot; Ransomware Hits Poland and Ukraine&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Microsoft Threat Intelligence Center (MSTIC) has found evidence of a novel ransomware campaign using a hitherto unidentified ransomware payload that targets businesses in the logistics and tran...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/organizations-in-poland-and-ukraine-are-affected-by-the-new-prestige-ransomware.png" length="951354" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Cloud WAAP Magic Quadrant: Leaders &amp; Trends</title><link>https://securityxp.com/articles/cloud-web-application-and-api-protection-magic-quadrant/</link><guid isPermaLink="true">https://securityxp.com/articles/cloud-web-application-and-api-protection-magic-quadrant/</guid><description>The market for protecting cloud web applications and APIs is expanding quickly. You can use this Magic Quadrant to find cloud WAAP providers that provide simple controls and specialised defences ag...</description><pubDate>Mon, 17 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cloud-web-application-and-api-protection-magic-quadrant.png&quot; alt=&quot;Cloud WAAP Magic Quadrant: Leaders &amp; Trends&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The market for protecting cloud web applications and APIs is expanding quickly. You can use this Magic Quadrant to find cloud WAAP providers that provide simple controls and specialised defences ag...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cloud-web-application-and-api-protection-magic-quadrant.png" length="874472" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Serverless Top security best practices</title><link>https://securityxp.com/articles/serverless-top-security-best-practices/</link><guid isPermaLink="true">https://securityxp.com/articles/serverless-top-security-best-practices/</guid><description>Describe serverless. A cloud execution model is serverless computing. It enables users and developers to create and use applications and services without having to worry about servers. Applications...</description><pubDate>Mon, 17 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/serverless-top-security-best-practices.png&quot; alt=&quot;Serverless Top security best practices&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Describe serverless. A cloud execution model is serverless computing. It enables users and developers to create and use applications and services without having to worry about servers. Applications...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/serverless-top-security-best-practices.png" length="968062" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Gartner Peer Insights: WAAP Voice of Customer</title><link>https://securityxp.com/articles/voice-of-the-customer-web-application-and-api-protection-gartner-peer-insights/</link><guid isPermaLink="true">https://securityxp.com/articles/voice-of-the-customer-web-application-and-api-protection-gartner-peer-insights/</guid><description>What is API and Web Application Protection? Web application and API protection (WAAP), according to Gartner, is the evolution of the web application firewall (WAF) market, which now includes four c...</description><pubDate>Sun, 16 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/voice-of-the-customer-web-application-and-api-protection-gartner-peer-insights.png&quot; alt=&quot;Gartner Peer Insights: WAAP Voice of Customer&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;What is API and Web Application Protection? Web application and API protection (WAAP), according to Gartner, is the evolution of the web application firewall (WAF) market, which now includes four c...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/voice-of-the-customer-web-application-and-api-protection-gartner-peer-insights.png" length="877158" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>MITRE ATT&amp;CK April 2022 Update: New Techniques</title><link>https://securityxp.com/articles/mitre-attck-released-updates-in-apr-2022-with-additional-techniques-and-structuring/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-released-updates-in-apr-2022-with-additional-techniques-and-structuring/</guid><description>The Techniques, Groups, and Software for Enterprise, Mobile, and ICS are updated in the April 2022 (v11) ATT&amp;CK release. The most significant modifications are the reorganisation of Detections, whi...</description><pubDate>Fri, 14 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/mitre-attck-released-updates-in-apr-2022-with-additional-techniques-and-structuring.png&quot; alt=&quot;MITRE ATT&amp;CK April 2022 Update: New Techniques&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Techniques, Groups, and Software for Enterprise, Mobile, and ICS are updated in the April 2022 (v11) ATT&amp;CK release. The most significant modifications are the reorganisation of Detections, whi...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/mitre-attck-released-updates-in-apr-2022-with-additional-techniques-and-structuring.png" length="866053" type="image/png"/><category>Compliance &amp; Privacy</category><author>SecurityXP Editorial Desk</author></item><item><title>OWASP Threat Dragon: Open-Source Threat Modeling</title><link>https://securityxp.com/articles/owasp-threat-dragon-open-source-threat-modeling-tool-from-owasp/</link><guid isPermaLink="true">https://securityxp.com/articles/owasp-threat-dragon-open-source-threat-modeling-tool-from-owasp/</guid><description>Threat modelling is regarded as a potent method for incorporating security into application design at an early stage of the secure development lifecycle. It is most effective when used for: ensurin...</description><pubDate>Fri, 14 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/owasp-threat-dragon-open-source-threat-modeling-tool-from-owasp.png&quot; alt=&quot;OWASP Threat Dragon: Open-Source Threat Modeling&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Threat modelling is regarded as a potent method for incorporating security into application design at an early stage of the secure development lifecycle. It is most effective when used for: ensurin...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/owasp-threat-dragon-open-source-threat-modeling-tool-from-owasp.png" length="907290" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>The Microsoft Threat Modeling Tool (TMT)</title><link>https://securityxp.com/articles/the-microsoft-threat-modeling-tool-tmt/</link><guid isPermaLink="true">https://securityxp.com/articles/the-microsoft-threat-modeling-tool-tmt/</guid><description>A crucial component of the Microsoft Security Development Lifecycle is the Threat Modeling Tool (SDL). Early detection and mitigation of potential security issues, when they are still manageable an...</description><pubDate>Fri, 14 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/the-microsoft-threat-modeling-tool-tmt.png&quot; alt=&quot;The Microsoft Threat Modeling Tool (TMT)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A crucial component of the Microsoft Security Development Lifecycle is the Threat Modeling Tool (SDL). Early detection and mitigation of potential security issues, when they are still manageable an...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/the-microsoft-threat-modeling-tool-tmt.png" length="956605" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>IriusRisk Threat Modeling for Security Teams</title><link>https://securityxp.com/articles/iriusrisk-threat-modeling-for-security-and-development-teams/</link><guid isPermaLink="true">https://securityxp.com/articles/iriusrisk-threat-modeling-for-security-and-development-teams/</guid><description>Threat modelling: what is it? Basics of Threat Modeling Threat modeling&apos;s fundamental tenet is the identification, disclosure, and management of security flaws. This is accomplished by being aware of</description><pubDate>Thu, 13 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/iriusrisk-threat-modeling-for-security-and-development-teams.png&quot; alt=&quot;IriusRisk Threat Modeling for Security Teams&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Threat modelling: what is it? Basics of Threat Modeling Threat modeling&apos;s fundamental tenet is the identification, disclosure, and management of security flaws. This is accomplished by being aware of&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/iriusrisk-threat-modeling-for-security-and-development-teams.png" length="857998" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Threat Modeling: Choosing the Right Method</title><link>https://securityxp.com/articles/threat-modeling-choosing-the-right-method-for-your-business/</link><guid isPermaLink="true">https://securityxp.com/articles/threat-modeling-choosing-the-right-method-for-your-business/</guid><description>Why Threat Modeling Is Important and What It Is Identifying and evaluating threats that an attacker (threat) could exploit is done through the exercise of threat modelling. Consider a threat model ...</description><pubDate>Thu, 13 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/threat-modeling-choosing-the-right-method-for-your-business.png&quot; alt=&quot;Threat Modeling: Choosing the Right Method&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Why Threat Modeling Is Important and What It Is Identifying and evaluating threats that an attacker (threat) could exploit is done through the exercise of threat modelling. Consider a threat model ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/threat-modeling-choosing-the-right-method-for-your-business.png" length="939412" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Kenna: RISK-BASED VULNERABILITY MANAGEMENT</title><link>https://securityxp.com/articles/kenna-risk-based-vulnerability-management/</link><guid isPermaLink="true">https://securityxp.com/articles/kenna-risk-based-vulnerability-management/</guid><description>Why You Should Consider More Than CVSS As previously mentioned, one typical method of sorting and prioritising which vulnerabilities to fix first is patching vulnerabilities that have a CVSS score in</description><pubDate>Wed, 12 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/kenna-risk-based-vulnerability-management.png&quot; alt=&quot;Kenna: RISK-BASED VULNERABILITY MANAGEMENT&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Why You Should Consider More Than CVSS As previously mentioned, one typical method of sorting and prioritising which vulnerabilities to fix first is patching vulnerabilities that have a CVSS score in&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/kenna-risk-based-vulnerability-management.png" length="861021" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>BCG &amp; STC: Cybersecurity Performance Framework</title><link>https://securityxp.com/articles/a-holistic-performance-management-framework-for-implementing-cybersecurity-strategies-by-bcg-stc/</link><guid isPermaLink="true">https://securityxp.com/articles/a-holistic-performance-management-framework-for-implementing-cybersecurity-strategies-by-bcg-stc/</guid><description>The frequency and cost of cyberattacks is accelerating. Globally, the cost of cybercrime is estimated to have risen from $445B in 2015 to over $2.2 trillion today. The frequency and size of data br...</description><pubDate>Sat, 08 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/a-holistic-performance-management-framework-for-implementing-cybersecurity-strategies-by-bcg-stc.png&quot; alt=&quot;BCG &amp; STC: Cybersecurity Performance Framework&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The frequency and cost of cyberattacks is accelerating. Globally, the cost of cybercrime is estimated to have risen from $445B in 2015 to over $2.2 trillion today. The frequency and size of data br...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/a-holistic-performance-management-framework-for-implementing-cybersecurity-strategies-by-bcg-stc.png" length="803523" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Best Cloud SaaS Governance Practices from CSA</title><link>https://securityxp.com/articles/best-cloud-saas-governance-practices-from-the-csa-cloud-security-alliance/</link><guid isPermaLink="true">https://securityxp.com/articles/best-cloud-saas-governance-practices-from-the-csa-cloud-security-alliance/</guid><description>Introduction Infrastructure as Service security is almost always the focus when discussing cloud security. platforms as a service (PaaS) and infrastructure as a service (IaaS). In spite of the fact...</description><pubDate>Sat, 08 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/best-cloud-saas-governance-practices-from-the-csa-cloud-security-alliance.png&quot; alt=&quot;Best Cloud SaaS Governance Practices from CSA&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Introduction Infrastructure as Service security is almost always the focus when discussing cloud security. platforms as a service (PaaS) and infrastructure as a service (IaaS). In spite of the fact...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/best-cloud-saas-governance-practices-from-the-csa-cloud-security-alliance.png" length="830718" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>SP-CMM: Security &amp; Privacy Maturity Model by SCF</title><link>https://securityxp.com/articles/security-and-privacy-capability-maturity-model-sp-cmm-by-scf-secure-and-privacy-by-design-principles-framework/</link><guid isPermaLink="true">https://securityxp.com/articles/security-and-privacy-capability-maturity-model-sp-cmm-by-scf-secure-and-privacy-by-design-principles-framework/</guid><description>The SP establishes 32 common-sense principles to guide the development and oversight of a modern security and privacy program. The SP is sourced from the Secure Controls Framework (SCF), which is a...</description><pubDate>Fri, 07 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/security-and-privacy-capability-maturity-model-sp-cmm-by-scf-secure-and-privacy-by-design-principles-framework.png&quot; alt=&quot;SP-CMM: Security &amp; Privacy Maturity Model by SCF&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The SP establishes 32 common-sense principles to guide the development and oversight of a modern security and privacy program. The SP is sourced from the Secure Controls Framework (SCF), which is a...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/security-and-privacy-capability-maturity-model-sp-cmm-by-scf-secure-and-privacy-by-design-principles-framework.png" length="971051" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Campaigns to be Introduced to MITRE ATT&amp;CK V12</title><link>https://securityxp.com/articles/campaigns-to-be-introduced-to-mitre-attck-v12/</link><guid isPermaLink="true">https://securityxp.com/articles/campaigns-to-be-introduced-to-mitre-attck-v12/</guid><description>Primary Articles [Published ](&lt;https://medium.com/mitre-attack/introducing-attack-campaigns-6b15baa6cbb4)by Matt Malona In [ATT&amp;CK 2022](&lt;https://medium.com/mitre-attack/attack-2022-roadmap-cd5a1a3...</description><pubDate>Wed, 05 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/campaigns-to-be-introduced-to-mitre-attck-v12.png&quot; alt=&quot;Campaigns to be Introduced to MITRE ATT&amp;CK V12&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Primary Articles [Published ](&lt;https://medium.com/mitre-attack/introducing-attack-campaigns-6b15baa6cbb4)by Matt Malona In [ATT&amp;CK 2022](&lt;https://medium.com/mitre-attack/attack-2022-roadmap-cd5a1a3...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/campaigns-to-be-introduced-to-mitre-attck-v12.png" length="882798" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>DevSecOps: Cultural Shift, Not Just Tech</title><link>https://securityxp.com/articles/devsecops-is-not-just-a-technological-shift-it-is-also-a-cultural-one-according-to-tenable-cs-cloud-securitys-whitepaper-7-habits-of-highly-effective-devsecops-teams/</link><guid isPermaLink="true">https://securityxp.com/articles/devsecops-is-not-just-a-technological-shift-it-is-also-a-cultural-one-according-to-tenable-cs-cloud-securitys-whitepaper-7-habits-of-highly-effective-devsecops-teams/</guid><description>DecSecOps, which is typically viewed as an integrated team of development, operational, and security practitioners that can securely deliver innovation within a defined scope to market, is an ideal...</description><pubDate>Mon, 03 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/devsecops-is-not-just-a-technological-shift-it-is-also-a-cultural-one-according-to-tenable-cs-cloud-securitys-whitepaper-7-habits-of-highly-effective-devsecops-teams.png&quot; alt=&quot;DevSecOps: Cultural Shift, Not Just Tech&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;DecSecOps, which is typically viewed as an integrated team of development, operational, and security practitioners that can securely deliver innovation within a defined scope to market, is an ideal...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/devsecops-is-not-just-a-technological-shift-it-is-also-a-cultural-one-according-to-tenable-cs-cloud-securitys-whitepaper-7-habits-of-highly-effective-devsecops-teams.png" length="953946" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>MSSP Alert Top 250 MSSPs 2022 Edition Released</title><link>https://securityxp.com/articles/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-services-providers-2022-edition/</link><guid isPermaLink="true">https://securityxp.com/articles/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-services-providers-2022-edition/</guid><description>A succinct summary The Top 250 MSSPs and associated survey respondents continue to expand more quickly than the managed security market as a whole. In fact, respondents to the survey anticipate tha...</description><pubDate>Tue, 20 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-services-providers-2022-edition.png&quot; alt=&quot;MSSP Alert Top 250 MSSPs 2022 Edition Released&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A succinct summary The Top 250 MSSPs and associated survey respondents continue to expand more quickly than the managed security market as a whole. In fact, respondents to the survey anticipate tha...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-services-providers-2022-edition.png" length="988760" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Revolut Data Breach: Tens of Thousands Affected</title><link>https://securityxp.com/articles/threat-actors-gained-access-to-the-personal-data-of-tens-of-thousands-of-revolut-customers-as-a-result-of-a-cyberattack/</link><guid isPermaLink="true">https://securityxp.com/articles/threat-actors-gained-access-to-the-personal-data-of-tens-of-thousands-of-revolut-customers-as-a-result-of-a-cyberattack/</guid><description>Over the weekend, the financial technology company Revolut was the victim of a &apos;highly targeted&apos; cyberattack in which threat actors gained access to the personal data of 0.16% of its users (approxi...</description><pubDate>Mon, 19 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/threat-actors-gained-access-to-the-personal-data-of-tens-of-thousands-of-revolut-customers-as-a-result-of-a-cyberattack.png&quot; alt=&quot;Revolut Data Breach: Tens of Thousands Affected&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Over the weekend, the financial technology company Revolut was the victim of a &apos;highly targeted&apos; cyberattack in which threat actors gained access to the personal data of 0.16% of its users (approxi...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/threat-actors-gained-access-to-the-personal-data-of-tens-of-thousands-of-revolut-customers-as-a-result-of-a-cyberattack.png" length="965471" type="image/png"/><category>Data Breaches</category><author>SecurityXP Editorial Desk</author></item><item><title>$3,500 for Starbucks Data with PII for Sale</title><link>https://securityxp.com/articles/3500-for-starbucks-cofee-data-with-name-gender-dob-mobile-no-email-and-address/</link><guid isPermaLink="true">https://securityxp.com/articles/3500-for-starbucks-cofee-data-with-name-gender-dob-mobile-no-email-and-address/</guid><description>The Straits Times discovered that 330,000 Singaporean Starbucks customers&apos; personal information had been compromised and sold on an online forum since September 10. On Friday, the coffee chain sent...</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/3500-for-starbucks-cofee-data-with-name-gender-dob-mobile-no-email-and-address.png&quot; alt=&quot;$3,500 for Starbucks Data with PII for Sale&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Straits Times discovered that 330,000 Singaporean Starbucks customers&apos; personal information had been compromised and sold on an online forum since September 10. On Friday, the coffee chain sent...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/3500-for-starbucks-cofee-data-with-name-gender-dob-mobile-no-email-and-address.png" length="872918" type="image/png"/><category>Data Breaches</category><author>SecurityXP Editorial Desk</author></item><item><title>BARK: BloodHound Abuse Validator</title><link>https://securityxp.com/articles/bark-a-powershell-script-was-created-to-aid-the-bloodhound-enterprise-team-in-locating-and-regularly-validating-abuse-primitives/</link><guid isPermaLink="true">https://securityxp.com/articles/bark-a-powershell-script-was-created-to-aid-the-bloodhound-enterprise-team-in-locating-and-regularly-validating-abuse-primitives/</guid><description>BloodHound Attack Research Kit is referred to as BARK. It is a PowerShell script created to help the BloodHound Enterprise team find and keep track of abuse primitives. At the moment, BARK is conce...</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/bark-a-powershell-script-was-created-to-aid-the-bloodhound-enterprise-team-in-locating-and-regularly-validating-abuse-primitives.png&quot; alt=&quot;BARK: BloodHound Abuse Validator&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;BloodHound Attack Research Kit is referred to as BARK. It is a PowerShell script created to help the BloodHound Enterprise team find and keep track of abuse primitives. At the moment, BARK is conce...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/bark-a-powershell-script-was-created-to-aid-the-bloodhound-enterprise-team-in-locating-and-regularly-validating-abuse-primitives.png" length="942719" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>ATT&amp;CK v11 Adds Mobile Sub-Techniques &amp; ICS</title><link>https://securityxp.com/articles/beta-mobile-sub-techniques-structured-detections-and-ics-join-the-band-as-attck-upgrades-to-version-11/</link><guid isPermaLink="true">https://securityxp.com/articles/beta-mobile-sub-techniques-structured-detections-and-ics-join-the-band-as-attck-upgrades-to-version-11/</guid><description>The most recent ATT&amp;CK release is now available, and this time They have upgraded to version 11! There shouldn&apos;t be any major surprises if you&apos;ve been following their roadmap, but they wanted to ta...</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/beta-mobile-sub-techniques-structured-detections-and-ics-join-the-band-as-attck-upgrades-to-version-11.png&quot; alt=&quot;ATT&amp;CK v11 Adds Mobile Sub-Techniques &amp; ICS&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The most recent ATT&amp;CK release is now available, and this time They have upgraded to version 11! There shouldn&apos;t be any major surprises if you&apos;ve been following their roadmap, but they wanted to ta...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/beta-mobile-sub-techniques-structured-detections-and-ics-join-the-band-as-attck-upgrades-to-version-11.png" length="838395" type="image/png"/><category>Compliance &amp; Privacy</category><author>SecurityXP Editorial Desk</author></item><item><title>The Azure Threat Research Matrix is explained</title><link>https://securityxp.com/articles/the-azure-threat-research-matrix-is-explained/</link><guid isPermaLink="true">https://securityxp.com/articles/the-azure-threat-research-matrix-is-explained/</guid><description>It&apos;s typical for the assessment team to cite the MITRE ATT&amp;CK knowledge base when conducting an offensive security assessment so that high-level stakeholders can see visually which techniques were ...</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/the-azure-threat-research-matrix-is-explained.png&quot; alt=&quot;The Azure Threat Research Matrix is explained&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;It&apos;s typical for the assessment team to cite the MITRE ATT&amp;CK knowledge base when conducting an offensive security assessment so that high-level stakeholders can see visually which techniques were ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/the-azure-threat-research-matrix-is-explained.png" length="951250" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Uber Staff Dismissed Teen Hacker Attack as a Joke</title><link>https://securityxp.com/articles/uber-employees-believed-the-alleged-teen-hacker-attack-was-a-joke/</link><guid isPermaLink="true">https://securityxp.com/articles/uber-employees-believed-the-alleged-teen-hacker-attack-was-a-joke/</guid><description>The world&apos;s largest ride-hailing company, Uber, shut down a portion of its operations late on Thursday after learning that its internal systems had been compromised. According to the company, the a...</description><pubDate>Fri, 16 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/uber-employees-believed-the-alleged-teen-hacker-attack-was-a-joke.png&quot; alt=&quot;Uber Staff Dismissed Teen Hacker Attack as a Joke&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The world&apos;s largest ride-hailing company, Uber, shut down a portion of its operations late on Thursday after learning that its internal systems had been compromised. According to the company, the a...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/uber-employees-believed-the-alleged-teen-hacker-attack-was-a-joke.png" length="963907" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Dufflebag</title><link>https://securityxp.com/articles/dufflebag/</link><guid isPermaLink="true">https://securityxp.com/articles/dufflebag/</guid><description>A tool called [Dufflebag ](&lt;https://github.com/bishopfox/dufflebag)developed by [dan-bishopfox Dan Petro](&lt;https://github.com/dan-bishopfox) and [bmoar Ben Morris](&lt;https://github.com/bmoar</description><pubDate>Sat, 10 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/dufflebag.png&quot; alt=&quot;Dufflebag&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A tool called [Dufflebag ](&lt;https://github.com/bishopfox/dufflebag)developed by [dan-bishopfox Dan Petro](&lt;https://github.com/dan-bishopfox) and [bmoar Ben Morris](&lt;https://github.com/bmoar&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/dufflebag.png" length="858000" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Editorial Desk</author></item><item><title>Portuguese NATO Documents Found for Sale Online</title><link>https://securityxp.com/articles/portuguese-nato-documents-discovered-for-sale-online/</link><guid isPermaLink="true">https://securityxp.com/articles/portuguese-nato-documents-discovered-for-sale-online/</guid><description>The National Security Office is still determining the extent of the damage, but EMGFA, secret military, and MDN computers are suspected of being involved in the security lapse that made it possible...</description><pubDate>Fri, 09 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/portuguese-nato-documents-discovered-for-sale-online.png&quot; alt=&quot;Portuguese NATO Documents Found for Sale Online&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The National Security Office is still determining the extent of the damage, but EMGFA, secret military, and MDN computers are suspected of being involved in the security lapse that made it possible...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/portuguese-nato-documents-discovered-for-sale-online.png" length="989724" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Brand New Tube Data Breach Exposes User IPs</title><link>https://securityxp.com/articles/a-significant-data-breach-on-the-streaming-service-brand-new-tube-exposed-users-names-and-ip-addresses/</link><guid isPermaLink="true">https://securityxp.com/articles/a-significant-data-breach-on-the-streaming-service-brand-new-tube-exposed-users-names-and-ip-addresses/</guid><description>A significant security flaw has been discovered on [BrandNewTube](&lt;https://onevsp.com/), a YouTube alternative that was founded in the UK. Several users who received an email that revealed thei</description><pubDate>Thu, 08 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/a-significant-data-breach-on-the-streaming-service-brand-new-tube-exposed-users-names-and-ip-addresses.png&quot; alt=&quot;Brand New Tube Data Breach Exposes User IPs&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A significant security flaw has been discovered on [BrandNewTube](&lt;https://onevsp.com/), a YouTube alternative that was founded in the UK. Several users who received an email that revealed thei&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/a-significant-data-breach-on-the-streaming-service-brand-new-tube-exposed-users-names-and-ip-addresses.png" length="959990" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>A Successful Threat-Hunting Program&apos;s Foundation</title><link>https://securityxp.com/articles/a-successful-threat-hunting-programs-foundation/</link><guid isPermaLink="true">https://securityxp.com/articles/a-successful-threat-hunting-programs-foundation/</guid><description>&apos;Threat hunting is the practice of proactively searching for cyber threats that are lurking undetected in a network. Cyber threat hunting digs deep to find malicious actors in your environment tha</description><pubDate>Wed, 07 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/a-successful-threat-hunting-programs-foundation.png&quot; alt=&quot;A Successful Threat-Hunting Program&apos;s Foundation&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;&apos;Threat hunting is the practice of proactively searching for cyber threats that are lurking undetected in a network. Cyber threat hunting digs deep to find malicious actors in your environment tha&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/a-successful-threat-hunting-programs-foundation.png" length="952068" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Feds &amp; npm Issue Supply Chain Security Guidance</title><link>https://securityxp.com/articles/feds-and-npm-give-advice-on-supply-chain-security-to-prevent-another-solarwinds-incident/</link><guid isPermaLink="true">https://securityxp.com/articles/feds-and-npm-give-advice-on-supply-chain-security-to-prevent-another-solarwinds-incident/</guid><description>Faster development times, innovation, and a thriving open-source community have all been made possible by the ability to use another developer&apos;s project as a dependency. With many JavaScript projects</description><pubDate>Tue, 06 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/feds-and-npm-give-advice-on-supply-chain-security-to-prevent-another-solarwinds-incident.png&quot; alt=&quot;Feds &amp; npm Issue Supply Chain Security Guidance&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Faster development times, innovation, and a thriving open-source community have all been made possible by the ability to use another developer&apos;s project as a dependency. With many JavaScript projects&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/feds-and-npm-give-advice-on-supply-chain-security-to-prevent-another-solarwinds-incident.png" length="954970" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Change Your TikTok Password Now: Data Leak Risk</title><link>https://securityxp.com/articles/change-your-tiktok-password-immediately-in-case-of-a-massive-data-leak/</link><guid isPermaLink="true">https://securityxp.com/articles/change-your-tiktok-password-immediately-in-case-of-a-massive-data-leak/</guid><description>There&apos;s a post from 12 hours ago on a well-known hacking forum making some pretty significant claims, with the disclaimer that everything is &apos;alleged&apos; at this point: &apos;We don&apos;t know why it&apos;s there o...</description><pubDate>Mon, 05 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/change-your-tiktok-password-immediately-in-case-of-a-massive-data-leak.png&quot; alt=&quot;Change Your TikTok Password Now: Data Leak Risk&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;There&apos;s a post from 12 hours ago on a well-known hacking forum making some pretty significant claims, with the disclaimer that everything is &apos;alleged&apos; at this point: &apos;We don&apos;t know why it&apos;s there o...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/change-your-tiktok-password-immediately-in-case-of-a-massive-data-leak.png" length="955489" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>NATO Probes Missile Vendor Breach on Dark Web</title><link>https://securityxp.com/articles/nato-examines-data-breach-from-missile-vendor-on-the-dark-web/</link><guid isPermaLink="true">https://securityxp.com/articles/nato-examines-data-breach-from-missile-vendor-on-the-dark-web/</guid><description>One set of documents purportedly belonging to an EU defense supplier includes information on the weapons Ukraine used to fight Russia. According to a report in the media, NATO is looking into the l...</description><pubDate>Sun, 04 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/nato-examines-data-breach-from-missile-vendor-on-the-dark-web.png&quot; alt=&quot;NATO Probes Missile Vendor Breach on Dark Web&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;One set of documents purportedly belonging to an EU defense supplier includes information on the weapons Ukraine used to fight Russia. According to a report in the media, NATO is looking into the l...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/nato-examines-data-breach-from-missile-vendor-on-the-dark-web.png" length="987138" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>DRDO &amp; IIT Delhi Demo 100km QKD</title><link>https://securityxp.com/articles/drdo-and-iit-delhi-scientists-demonstrate-quantum-key-distribution-qkd-between-two-cities-100-kilometres-apart/</link><guid isPermaLink="true">https://securityxp.com/articles/drdo-and-iit-delhi-scientists-demonstrate-quantum-key-distribution-qkd-between-two-cities-100-kilometres-apart/</guid><description>For the first time in the country, a team of scientists from the Defence Research and Development Organisation (DRDO) and the Indian Institute of Technology (IIT) Delhi successfully demonstrated a ...</description><pubDate>Fri, 25 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/drdo-and-iit-delhi-scientists-demonstrate-quantum-key-distribution-qkd-between-two-cities-100-kilometres-apart.png&quot; alt=&quot;DRDO &amp; IIT Delhi Demo 100km QKD&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;For the first time in the country, a team of scientists from the Defence Research and Development Organisation (DRDO) and the Indian Institute of Technology (IIT) Delhi successfully demonstrated a ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/drdo-and-iit-delhi-scientists-demonstrate-quantum-key-distribution-qkd-between-two-cities-100-kilometres-apart.png" length="950661" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Bvp47 Backdoor: Indian Orgs Targeted by NSA Tool</title><link>https://securityxp.com/articles/indian-organizations-also-targetted-by-bvp47-backdoor-of-us-nsa-equation-group/</link><guid isPermaLink="true">https://securityxp.com/articles/indian-organizations-also-targetted-by-bvp47-backdoor-of-us-nsa-equation-group/</guid><description>Banaras Hindu University, India Education Network, Eureka Technology Partners, Indian Academy of Sciences, Indian Institute of Tropical Meteorology, Council of Scientific &amp; Industrial Research (CSIR)</description><pubDate>Thu, 24 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/indian-organizations-also-targetted-by-bvp47-backdoor-of-us-nsa-equation-group.png&quot; alt=&quot;Bvp47 Backdoor: Indian Orgs Targeted by NSA Tool&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Banaras Hindu University, India Education Network, Eureka Technology Partners, Indian Academy of Sciences, Indian Institute of Tropical Meteorology, Council of Scientific &amp; Industrial Research (CSIR)&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/indian-organizations-also-targetted-by-bvp47-backdoor-of-us-nsa-equation-group.png" length="941956" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Free Cybersecurity Tools &amp; Services from CISA</title><link>https://securityxp.com/articles/free-cybersecurity-services-and-tools-released-by-cisa/</link><guid isPermaLink="true">https://securityxp.com/articles/free-cybersecurity-services-and-tools-released-by-cisa/</guid><description>CISA has collected a list of free cybersecurity tools and services to help companies advance their security capabilities as part of our ongoing objective to minimise cybersecurity risk among U.S. c...</description><pubDate>Wed, 23 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/free-cybersecurity-services-and-tools-released-by-cisa.png&quot; alt=&quot;Free Cybersecurity Tools &amp; Services from CISA&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;CISA has collected a list of free cybersecurity tools and services to help companies advance their security capabilities as part of our ongoing objective to minimise cybersecurity risk among U.S. c...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/free-cybersecurity-services-and-tools-released-by-cisa.png" length="949604" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Portugal Q3 2021 Threat Report: Key Malware Stats</title><link>https://securityxp.com/articles/phishing-and-malware-by-numbers-in-the-threat-report-portugal-q3-2021/</link><guid isPermaLink="true">https://securityxp.com/articles/phishing-and-malware-by-numbers-in-the-threat-report-portugal-q3-2021/</guid><description>Segurança-Informática developed and maintains the Portuguese Abuse Open Feed 0xSI f33d, an open sharing database with the potential to collect indicators from numerous sources. This feed is provide...</description><pubDate>Wed, 23 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/phishing-and-malware-by-numbers-in-the-threat-report-portugal-q3-2021.png&quot; alt=&quot;Portugal Q3 2021 Threat Report: Key Malware Stats&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Segurança-Informática developed and maintains the Portuguese Abuse Open Feed 0xSI f33d, an open sharing database with the potential to collect indicators from numerous sources. This feed is provide...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/phishing-and-malware-by-numbers-in-the-threat-report-portugal-q3-2021.png" length="952881" type="image/png"/><category>Malware &amp; Ransomware</category><author>SecurityXP Editorial Desk</author></item><item><title>Cybersecurity Risks of Russia-Ukraine Escalation</title><link>https://securityxp.com/articles/cybersecurity-risks-of-russia-ukraine-conflict-escalation/</link><guid isPermaLink="true">https://securityxp.com/articles/cybersecurity-risks-of-russia-ukraine-conflict-escalation/</guid><description>DDoS attacks on Ukrainian groups were promptly traced to Russian intelligence by the UK and US governments last week. The intrusions on February 15 and 16 were &apos;very certain&apos; the work of the Russia...</description><pubDate>Tue, 22 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/cybersecurity-risks-of-russia-ukraine-conflict-escalation.png&quot; alt=&quot;Cybersecurity Risks of Russia-Ukraine Escalation&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;DDoS attacks on Ukrainian groups were promptly traced to Russian intelligence by the UK and US governments last week. The intrusions on February 15 and 16 were &apos;very certain&apos; the work of the Russia...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/cybersecurity-risks-of-russia-ukraine-conflict-escalation.png" length="960746" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Zerodium Raises Outlook Zero-Day Payout to $400K</title><link>https://securityxp.com/articles/payout-for-zero-click-outlook-zero-days-has-been-increased-to-400000-by-zerodium/</link><guid isPermaLink="true">https://securityxp.com/articles/payout-for-zero-click-outlook-zero-days-has-been-increased-to-400000-by-zerodium/</guid><description>It was announced on the same day that Trustwave SpiderLabs revealed a new approach to get around Outlook security and send malicious links to victims. was reported by [threatpost](&lt;https://threatpo...</description><pubDate>Fri, 28 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/payout-for-zero-click-outlook-zero-days-has-been-increased-to-400000-by-zerodium.png&quot; alt=&quot;Zerodium Raises Outlook Zero-Day Payout to $400K&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;It was announced on the same day that Trustwave SpiderLabs revealed a new approach to get around Outlook security and send malicious links to victims. was reported by [threatpost](&lt;https://threatpo...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/payout-for-zero-click-outlook-zero-days-has-been-increased-to-400000-by-zerodium.png" length="946077" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>VPNLabs Takedown by 10 Countries &amp; Europol</title><link>https://securityxp.com/articles/joint-action-by-10-countries-and-europol-taken-down-vpnlabs-secure-communication-tool-favored-by-cybercriminals/</link><guid isPermaLink="true">https://securityxp.com/articles/joint-action-by-10-countries-and-europol-taken-down-vpnlabs-secure-communication-tool-favored-by-cybercriminals/</guid><description>Joint action by 10 countries and Europol taken down VPNLabs secure communication tool favored by cybercriminals This week, law enforcement officials targeted VPNLab.net&apos;s users and infrastructure i...</description><pubDate>Tue, 18 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/joint-action-by-10-countries-and-europol-taken-down-vpnlabs-secure-communication-tool-favored-by-cybercriminals.png&quot; alt=&quot;VPNLabs Takedown by 10 Countries &amp; Europol&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Joint action by 10 countries and Europol taken down VPNLabs secure communication tool favored by cybercriminals This week, law enforcement officials targeted VPNLab.net&apos;s users and infrastructure i...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/joint-action-by-10-countries-and-europol-taken-down-vpnlabs-secure-communication-tool-favored-by-cybercriminals.png" length="796239" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Russia Arrests REvil Hackers at U.S. Request</title><link>https://securityxp.com/articles/russia-arrests-members-of-revil-hacking-group-at-u-s-request-fsb/</link><guid isPermaLink="true">https://securityxp.com/articles/russia-arrests-members-of-revil-hacking-group-at-u-s-request-fsb/</guid><description>In Russia, the cities of Moscow, St. Petersburg, Moscow, Leningrad, and Lipetsk, the Russian Federation&apos;s Federal Security Service, in collaboration with the Ministry of Internal Affairs&apos; Investiga...</description><pubDate>Tue, 18 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/russia-arrests-members-of-revil-hacking-group-at-u-s-request-fsb.png&quot; alt=&quot;Russia Arrests REvil Hackers at U.S. Request&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;In Russia, the cities of Moscow, St. Petersburg, Moscow, Leningrad, and Lipetsk, the Russian Federation&apos;s Federal Security Service, in collaboration with the Ministry of Internal Affairs&apos; Investiga...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/russia-arrests-members-of-revil-hacking-group-at-u-s-request-fsb.png" length="965591" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>MITRE ATT&amp;CK October 2021 Update: New Techniques</title><link>https://securityxp.com/articles/mitre-attck-released-updates-in-oct-2021-with-additional-techniques-and-structuring/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-released-updates-in-oct-2021-with-additional-techniques-and-structuring/</guid><description>MITRE ATT&amp;CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of ...</description><pubDate>Sun, 16 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/mitre-attck-released-updates-in-oct-2021-with-additional-techniques-and-structuring.png&quot; alt=&quot;MITRE ATT&amp;CK October 2021 Update: New Techniques&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;MITRE ATT&amp;CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/mitre-attck-released-updates-in-oct-2021-with-additional-techniques-and-structuring.png" length="939183" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Editorial Desk</author></item><item><title>Russian Hackers Infiltrate Indian Military Exams</title><link>https://securityxp.com/articles/russian-hackers-infiltrate-exams-of-indian-navy-and-air-force/</link><guid isPermaLink="true">https://securityxp.com/articles/russian-hackers-infiltrate-exams-of-indian-navy-and-air-force/</guid><description>The Delhi Police’s has busted attempts of Russian hackers to infiltrate the Indian Navy and Air Force exams through the dark web. The Intelligence Department of Delhi Police were the ones who brought</description><pubDate>Wed, 12 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/russian-hackers-infiltrate-exams-of-indian-navy-and-air-force.png&quot; alt=&quot;Russian Hackers Infiltrate Indian Military Exams&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Delhi Police’s has busted attempts of Russian hackers to infiltrate the Indian Navy and Air Force exams through the dark web. The Intelligence Department of Delhi Police were the ones who brought&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/russian-hackers-infiltrate-exams-of-indian-navy-and-air-force.png" length="970584" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Alexa AI Attempts to murder a child</title><link>https://securityxp.com/articles/alexa-ai-attempts-to-murder-a-child/</link><guid isPermaLink="true">https://securityxp.com/articles/alexa-ai-attempts-to-murder-a-child/</guid><description>Amazon Alexa, also known simply as Alexa, is a virtual assistant technology largely based on a Polish speech synthesizer named Ivona, bought by Amazon in 2013. It was first used in the Amazon Echo ...</description><pubDate>Sun, 09 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/alexa-ai-attempts-to-murder-a-child.png&quot; alt=&quot;Alexa AI Attempts to murder a child&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Amazon Alexa, also known simply as Alexa, is a virtual assistant technology largely based on a Polish speech synthesizer named Ivona, bought by Amazon in 2013. It was first used in the Amazon Echo ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/alexa-ai-attempts-to-murder-a-child.png" length="811743" type="image/png"/><category>AI/ML Security</category><author>SecurityXP Editorial Desk</author></item><item><title>France Fines Facebook &amp; Google €210M for Cookies</title><link>https://securityxp.com/articles/france-gonna-earn-210-million-euro-from-cookies-of-facebook-and-google/</link><guid isPermaLink="true">https://securityxp.com/articles/france-gonna-earn-210-million-euro-from-cookies-of-facebook-and-google/</guid><description>Cookie Consent [Dark Pattern](&lt;https://www.deceptive.design/types): Privacy Zuckering In a NutShell &apos;Following investigations, the CNIL noted that the websites facebook.com, google.f</description><pubDate>Fri, 07 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/france-gonna-earn-210-million-euro-from-cookies-of-facebook-and-google.png&quot; alt=&quot;France Fines Facebook &amp; Google €210M for Cookies&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cookie Consent [Dark Pattern](&lt;https://www.deceptive.design/types): Privacy Zuckering In a NutShell &apos;Following investigations, the CNIL noted that the websites facebook.com, google.f&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/france-gonna-earn-210-million-euro-from-cookies-of-facebook-and-google.png" length="1009877" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Gartner EDRs are not perfect, fail against common attacks</title><link>https://securityxp.com/articles/gartner-edrs-are-not-perfect-fail-against-common-attacks/</link><guid isPermaLink="true">https://securityxp.com/articles/gartner-edrs-are-not-perfect-fail-against-common-attacks/</guid><description>A study testing endpoint detection and response (EDR) products from 18 vendors finds state-of-the-art EDRs fail to prevent or log the bulk of common attacks.</description><pubDate>Tue, 04 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/gartner-edrs-are-not-perfect-fail-against-common-attacks.png&quot; alt=&quot;Gartner EDRs are not perfect, fail against common attacks&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A study testing endpoint detection and response (EDR) products from 18 vendors finds state-of-the-art EDRs fail to prevent or log the bulk of common attacks.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/gartner-edrs-are-not-perfect-fail-against-common-attacks.png" length="866667" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>Useful Pentesting Resources</title><link>https://securityxp.com/articles/useful-pentesting-resources/</link><guid isPermaLink="true">https://securityxp.com/articles/useful-pentesting-resources/</guid><description>A curated list of useful penetration testing resources, tools, and references for security professionals.</description><pubDate>Tue, 07 Sep 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/useful-pentesting-resources.png&quot; alt=&quot;Useful Pentesting Resources&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A curated list of useful penetration testing resources, tools, and references for security professionals.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/useful-pentesting-resources.png" length="898484" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Editorial Desk</author></item><item><title>MITRE ATT&amp;CK April 2021 Update: New Techniques</title><link>https://securityxp.com/articles/mitre-attck-released-updates-in-april-2021-with-additional-techniques-and-structuring/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-released-updates-in-april-2021-with-additional-techniques-and-structuring/</guid><description>MITRE ATT&amp;CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of ...</description><pubDate>Sun, 04 Jul 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/mitre-attck-released-updates-in-april-2021-with-additional-techniques-and-structuring.png&quot; alt=&quot;MITRE ATT&amp;CK April 2021 Update: New Techniques&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;MITRE ATT&amp;CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/mitre-attck-released-updates-in-april-2021-with-additional-techniques-and-structuring.png" length="863791" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Editorial Desk</author></item><item><title>NSA Releases D3FEND Framework for Cyber Defenses</title><link>https://securityxp.com/articles/nsa-released-d3fend-a-framework-for-cybersecurity-professionals-to-tailor-defenses/</link><guid isPermaLink="true">https://securityxp.com/articles/nsa-released-d3fend-a-framework-for-cybersecurity-professionals-to-tailor-defenses/</guid><description>Recently a Framework was Released by NSA named D3FEND which is based on and Complementary to MITRE ATT&amp;CK Framework. It gave a Technical Knowledge base to create Defensive Countermeasure against Co...</description><pubDate>Sun, 04 Jul 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/nsa-released-d3fend-a-framework-for-cybersecurity-professionals-to-tailor-defenses.png&quot; alt=&quot;NSA Releases D3FEND Framework for Cyber Defenses&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Recently a Framework was Released by NSA named D3FEND which is based on and Complementary to MITRE ATT&amp;CK Framework. It gave a Technical Knowledge base to create Defensive Countermeasure against Co...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/nsa-released-d3fend-a-framework-for-cybersecurity-professionals-to-tailor-defenses.png" length="969074" type="image/png"/><category>Cloud Security</category><author>SecurityXP Editorial Desk</author></item><item><title>India Ranked Tier 3 in IISS Cyber Capabilities</title><link>https://securityxp.com/articles/bharat-ranked-in-tier-3-of-iiss-cyber-capabilities-and-national-power-a-net-assessment/</link><guid isPermaLink="true">https://securityxp.com/articles/bharat-ranked-in-tier-3-of-iiss-cyber-capabilities-and-national-power-a-net-assessment/</guid><description>As a result of a Study conducted by IISS Researchers in the last two years, Bharat was ranked in Tier 3, it is to be noted that the US is the only nation in Tier one. Instead of Going the traditional</description><pubDate>Sat, 03 Jul 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/bharat-ranked-in-tier-3-of-iiss-cyber-capabilities-and-national-power-a-net-assessment.png&quot; alt=&quot;India Ranked Tier 3 in IISS Cyber Capabilities&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As a result of a Study conducted by IISS Researchers in the last two years, Bharat was ranked in Tier 3, it is to be noted that the US is the only nation in Tier one. Instead of Going the traditional&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/bharat-ranked-in-tier-3-of-iiss-cyber-capabilities-and-national-power-a-net-assessment.png" length="960302" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Penetration testing Attack Infrastructure</title><link>https://securityxp.com/articles/penetration-testing-attack-infrastructure/</link><guid isPermaLink="true">https://securityxp.com/articles/penetration-testing-attack-infrastructure/</guid><description>A practical guide to planning and building penetration-testing attack infrastructure — covering C2, recon, social engineering, weaponization, and initial access.</description><pubDate>Sat, 03 Jul 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/penetration-testing-attack-infrastructure.png&quot; alt=&quot;Penetration testing Attack Infrastructure&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A practical guide to planning and building penetration-testing attack infrastructure — covering C2, recon, social engineering, weaponization, and initial access.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/penetration-testing-attack-infrastructure.png" length="924276" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Editorial Desk</author></item><item><title>Next-Gen Missile Data Hacked in Japan: Report</title><link>https://securityxp.com/articles/next-gen-missile-data-hacked-in-japan-report-says/</link><guid isPermaLink="true">https://securityxp.com/articles/next-gen-missile-data-hacked-in-japan-report-says/</guid><description>The Japanese Defense Ministry is investigating a possible leak of details of a new state-of-the-art missile in a large-scale cyberattack on Mitsubishi Electric Corp, the Asahi Shimbun newspaper rep...</description><pubDate>Thu, 21 May 2020 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/next-gen-missile-data-hacked-in-japan-report-says.png&quot; alt=&quot;Next-Gen Missile Data Hacked in Japan: Report&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Japanese Defense Ministry is investigating a possible leak of details of a new state-of-the-art missile in a large-scale cyberattack on Mitsubishi Electric Corp, the Asahi Shimbun newspaper rep...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/next-gen-missile-data-hacked-in-japan-report-says.png" length="842545" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>BIAS: Bluetooth Impersonation AttackS</title><link>https://securityxp.com/articles/bias-bluetooth-impersonation-attacks/</link><guid isPermaLink="true">https://securityxp.com/articles/bias-bluetooth-impersonation-attacks/</guid><description>[Daniele Antonioli](&lt;https://francozappa.github.io/about-bias/authors/francozappa/) (Postdoc at the EPFL Cyber-Physical Systems Security, Network Security, Wireless Security, Embedded Systems Securit</description><pubDate>Wed, 20 May 2020 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/bias-bluetooth-impersonation-attacks.png&quot; alt=&quot;BIAS: Bluetooth Impersonation AttackS&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;[Daniele Antonioli](&lt;https://francozappa.github.io/about-bias/authors/francozappa/) (Postdoc at the EPFL Cyber-Physical Systems Security, Network Security, Wireless Security, Embedded Systems Securit&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/bias-bluetooth-impersonation-attacks.png" length="1016467" type="image/png"/><category>Threat Intelligence</category><author>SecurityXP Editorial Desk</author></item><item><title>Huawei HKSP Patch Buggy With Backdoor, Says LKF</title><link>https://securityxp.com/articles/huawei-dev-team-buggy-hksp-patch-with-backdoor-and-linux-foundation/</link><guid isPermaLink="true">https://securityxp.com/articles/huawei-dev-team-buggy-hksp-patch-with-backdoor-and-linux-foundation/</guid><description>Last week the Huawei development team submitted a patch to the Linux Foundation with a ‘trivial vulnerability.’ When the vulnerability was discovered, Huawei denied its involvement in the patch and...</description><pubDate>Mon, 18 May 2020 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/heroes/huawei-dev-team-buggy-hksp-patch-with-backdoor-and-linux-foundation.png&quot; alt=&quot;Huawei HKSP Patch Buggy With Backdoor, Says LKF&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Last week the Huawei development team submitted a patch to the Linux Foundation with a ‘trivial vulnerability.’ When the vulnerability was discovered, Huawei denied its involvement in the patch and...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/heroes/huawei-dev-team-buggy-hksp-patch-with-backdoor-and-linux-foundation.png" length="967543" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Editorial Desk</author></item></channel></rss>