<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>SecurityXP — Cybersecurity News</title><description>Stay ahead of cyber threats with SecurityXP — cybersecurity news, vulnerability analysis, data breach reports, and threat intelligence.</description><link>https://securityxp.com/</link><language>en</language><item><title>Critical VMware Zero-Day Vulnerability Under Active Exploitation</title><link>https://securityxp.com/articles/vmware-zero-day-cve-2025-1234/</link><guid isPermaLink="true">https://securityxp.com/articles/vmware-zero-day-cve-2025-1234/</guid><description>A critical remote code execution vulnerability in VMware vCenter Server is being actively exploited in the wild. CVE-2025-1234 carries a CVSS score of 9.8 and affects all recent versions. Immediate patching is recommended.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/sample-vulnerability.svg&quot; alt=&quot;Critical VMware Zero-Day Vulnerability Under Active Exploitation&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A critical remote code execution vulnerability in VMware vCenter Server is being actively exploited in the wild. CVE-2025-1234 carries a CVSS score of 9.8 and affects all recent versions. Immediate patching is recommended.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/sample-vulnerability.svg" length="0" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>SecurityXP Team</author></item><item><title>Ransomware Attack Disrupts Major Healthcare Provider Operations</title><link>https://securityxp.com/articles/ransomware-healthcare-disruption/</link><guid isPermaLink="true">https://securityxp.com/articles/ransomware-healthcare-disruption/</guid><description>A sophisticated ransomware attack has disrupted operations at a major healthcare provider, affecting patient care systems across multiple facilities. Learn about the attack vectors, impact, and mitigation strategies.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/sample-ransomware.svg&quot; alt=&quot;Ransomware Attack Disrupts Major Healthcare Provider Operations&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A sophisticated ransomware attack has disrupted operations at a major healthcare provider, affecting patient care systems across multiple facilities. Learn about the attack vectors, impact, and mitigation strategies.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/sample-ransomware.svg" length="0" type="image/png"/><category>Malware &amp; Ransomware</category><author>SecurityXP Team</author></item><item><title>New EU AI Security Regulations: What Organizations Need to Know</title><link>https://securityxp.com/articles/eu-ai-security-regulations/</link><guid isPermaLink="true">https://securityxp.com/articles/eu-ai-security-regulations/</guid><description>The European Union has introduced comprehensive AI security regulations requiring organizations to implement security measures for AI systems. We break down the requirements, timelines, and compliance steps.</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/sample-ai-security.svg&quot; alt=&quot;New EU AI Security Regulations: What Organizations Need to Know&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The European Union has introduced comprehensive AI security regulations requiring organizations to implement security measures for AI systems. We break down the requirements, timelines, and compliance steps.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/sample-ai-security.svg" length="0" type="image/png"/><category>AI/ML Security</category><author>SecurityXP Team</author></item><item><title>CISA Issues Nine Urgent Advisories on Industrial Control Systems Vulnerabilities</title><link>https://securityxp.com/articles/cisa-issues-nine-urgent-advisories-on-industrial-control-systems-vulnerabilities/</link><guid isPermaLink="true">https://securityxp.com/articles/cisa-issues-nine-urgent-advisories-on-industrial-control-systems-vulnerabilities/</guid><description>In a critical bulletin released on September 18, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published nine new advisories detailing high-severity vulnerabilities affecti...</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/cisa-issues-nine-urgent-advisories-on-industrial-control-systems-vulnerabilities.png&quot; alt=&quot;CISA Issues Nine Urgent Advisories on Industrial Control Systems Vulnerabilities&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;In a critical bulletin released on September 18, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published nine new advisories detailing high-severity vulnerabilities affecti...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/cisa-issues-nine-urgent-advisories-on-industrial-control-systems-vulnerabilities.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Critical Google Chrome Zero-Day CVE-2025-10585: What You Need to Know</title><link>https://securityxp.com/articles/critical-google-chrome-zero-day-cve-2025-10585-what-you-need-to-know/</link><guid isPermaLink="true">https://securityxp.com/articles/critical-google-chrome-zero-day-cve-2025-10585-what-you-need-to-know/</guid><description>Google has just patched a critical zero-day vulnerability in its Chrome web browser—CVE-2025-10585—which has been actively exploited in the wild. This flaw, a type confusion issue in Chrome’s V8 Ja...</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2025/09/image-1024x576.svg&quot; alt=&quot;Critical Google Chrome Zero-Day CVE-2025-10585: What You Need to Know&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Google has just patched a critical zero-day vulnerability in its Chrome web browser—CVE-2025-10585—which has been actively exploited in the wild. This flaw, a type confusion issue in Chrome’s V8 Ja...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2025/09/image-1024x576.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Malware Analysis Report on a malicious listener deployed on Ivanti Endpoint Manager Mobile (EPMM) systems</title><link>https://securityxp.com/articles/malware-analysis-report-on-a-malicious-listener-deployed-on-ivanti-endpoint-manager-mobile-epmm-systems/</link><guid isPermaLink="true">https://securityxp.com/articles/malware-analysis-report-on-a-malicious-listener-deployed-on-ivanti-endpoint-manager-mobile-epmm-systems/</guid><description>U.S. Cybersecurity and Infrastructure Security Agency’s new Malware Analysis Report on a malicious listener deployed on Ivanti Endpoint Manager Mobile (EPMM) systems by chaining CVE-2025-4427 and C...</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2025/09/image-1-1024x293.svg&quot; alt=&quot;Malware Analysis Report on a malicious listener deployed on Ivanti Endpoint Manager Mobile (EPMM) systems&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;U.S. Cybersecurity and Infrastructure Security Agency’s new Malware Analysis Report on a malicious listener deployed on Ivanti Endpoint Manager Mobile (EPMM) systems by chaining CVE-2025-4427 and C...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2025/09/image-1-1024x293.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>MSSP Alert Top 250 for 2024: A Deep Dive into the State of Cybersecurity</title><link>https://securityxp.com/articles/mssp-alert-top-250-for-2024-a-deep-dive-into-the-state-of-cybersecurity/</link><guid isPermaLink="true">https://securityxp.com/articles/mssp-alert-top-250-for-2024-a-deep-dive-into-the-state-of-cybersecurity/</guid><description>Discover the key findings from the 2024 MSSP Alert Top 250 report. Explore trends in MSSP growth, profitability, in-house SOCs, and the critical services defining modern cyber defense.</description><pubDate>Sun, 22 Jun 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/mssp-alert-top-250-for-2024-a-deep-dive-into-the-state-of-cybersecurity.png&quot; alt=&quot;MSSP Alert Top 250 for 2024: A Deep Dive into the State of Cybersecurity&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Discover the key findings from the 2024 MSSP Alert Top 250 report. Explore trends in MSSP growth, profitability, in-house SOCs, and the critical services defining modern cyber defense.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/mssp-alert-top-250-for-2024-a-deep-dive-into-the-state-of-cybersecurity.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Pakistan-Linked APT36 Exploits &quot;Pahalgam Terror Attack&quot; Theme in Multi-Pronged Cyber Espionage Campaign Against India</title><link>https://securityxp.com/articles/pakistan-linked-apt36-exploits-pahalgam-terror-attack-theme-in-multi-pronged-cyber-espionage-campaign-against-india/</link><guid isPermaLink="true">https://securityxp.com/articles/pakistan-linked-apt36-exploits-pahalgam-terror-attack-theme-in-multi-pronged-cyber-espionage-campaign-against-india/</guid><description>In a recent and concerning development in the ongoing cyber conflict landscape, the Pakistan-linked Advanced Persistent Threat (APT) group known as APT36 (also referred to as Transparent Tribe) has...</description><pubDate>Sat, 26 Apr 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2025/04/image.svg&quot; alt=&quot;Pakistan-Linked APT36 Exploits &quot;Pahalgam Terror Attack&quot; Theme in Multi-Pronged Cyber Espionage Campaign Against India&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;In a recent and concerning development in the ongoing cyber conflict landscape, the Pakistan-linked Advanced Persistent Threat (APT) group known as APT36 (also referred to as Transparent Tribe) has...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2025/04/image.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Unpacking CVE-2025-29927: A Deep Dive into the Next.js Path Traversal Vulnerability</title><link>https://securityxp.com/articles/unpacking-cve-2025-29927-a-deep-dive-into-the-next-js-path-traversal-vulnerability/</link><guid isPermaLink="true">https://securityxp.com/articles/unpacking-cve-2025-29927-a-deep-dive-into-the-next-js-path-traversal-vulnerability/</guid><description>Next.js has rapidly become a dominant force in the React ecosystem, lauded for its developer experience and performance optimizations. However, like any complex framework, it&apos;s not immune to securi...</description><pubDate>Tue, 25 Mar 2025 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/unpacking-cve-2025-29927-a-deep-dive-into-the-next-js-path-traversal-vulnerability.png&quot; alt=&quot;Unpacking CVE-2025-29927: A Deep Dive into the Next.js Path Traversal Vulnerability&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Next.js has rapidly become a dominant force in the React ecosystem, lauded for its developer experience and performance optimizations. However, like any complex framework, it&apos;s not immune to securi...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/unpacking-cve-2025-29927-a-deep-dive-into-the-next-js-path-traversal-vulnerability.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>MITRE ATT&amp;amp;CKcon 5.0: Elevating Cybersecurity Knowledge</title><link>https://securityxp.com/articles/mitre-attckcon-5-0-elevating-cybersecurity-knowledge/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attckcon-5-0-elevating-cybersecurity-knowledge/</guid><description>Cybersecurity remains at the forefront of the global conversation, and MITRE ATT&amp;CKcon 5.0 is a pivotal event in the field. Scheduled for October 22-23, 2024, in McLean, Virginia, the conference se...</description><pubDate>Sat, 07 Sep 2024 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/mitre-attckcon-5-0-elevating-cybersecurity-knowledge.png&quot; alt=&quot;MITRE ATT&amp;amp;CKcon 5.0: Elevating Cybersecurity Knowledge&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cybersecurity remains at the forefront of the global conversation, and MITRE ATT&amp;CKcon 5.0 is a pivotal event in the field. Scheduled for October 22-23, 2024, in McLean, Virginia, the conference se...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/mitre-attckcon-5-0-elevating-cybersecurity-knowledge.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>A CyberRisk Alliance Resource: MSSP Alert – Top 250 MSSPs Service Providers 2023 Edition</title><link>https://securityxp.com/articles/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-service-providers-2023-edition/</link><guid isPermaLink="true">https://securityxp.com/articles/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-service-providers-2023-edition/</guid><description>As cyber threats evolve, so do the strategies to combat them. The latest MSSP Alert: Top 250 MSSPs Service Providers 2023 Edition , released by CyberRisk Alliance , offers valuable insights in</description><pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-service-providers-2023-edition.png&quot; alt=&quot;A CyberRisk Alliance Resource: MSSP Alert – Top 250 MSSPs Service Providers 2023 Edition&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As cyber threats evolve, so do the strategies to combat them. The latest MSSP Alert: Top 250 MSSPs Service Providers 2023 Edition , released by CyberRisk Alliance , offers valuable insights in&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-service-providers-2023-edition.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Securing the Clouds: The Top 10 CSPM Tools Shaping Cloud Security</title><link>https://securityxp.com/articles/securing-the-clouds-the-top-10-cspm-tools-shaping-cloud-security/</link><guid isPermaLink="true">https://securityxp.com/articles/securing-the-clouds-the-top-10-cspm-tools-shaping-cloud-security/</guid><description>Introduction In the rapidly evolving landscape of cloud computing, security stands as a paramount concern for organizations across the globe. Cloud Security Posture Management (CSPM) tools have eme...</description><pubDate>Sat, 13 Apr 2024 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2024/04/image-1024x663.svg&quot; alt=&quot;Securing the Clouds: The Top 10 CSPM Tools Shaping Cloud Security&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Introduction In the rapidly evolving landscape of cloud computing, security stands as a paramount concern for organizations across the globe. Cloud Security Posture Management (CSPM) tools have eme...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2024/04/image-1024x663.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>MITRE ATT&amp;CK version 14</title><link>https://securityxp.com/articles/mitre-attck-version-14/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-version-14/</guid><description>I. Introduction: Importance of staying updated with frameworks like MITRE ATT&amp;CK In the realm of offensive security, staying updated with frameworks like MITRE ATT&amp;CK is pivotal. It provides a stru...</description><pubDate>Sat, 04 Nov 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/mitre-attck-version-14.png&quot; alt=&quot;MITRE ATT&amp;CK version 14&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;I. Introduction: Importance of staying updated with frameworks like MITRE ATT&amp;CK In the realm of offensive security, staying updated with frameworks like MITRE ATT&amp;CK is pivotal. It provides a stru...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/mitre-attck-version-14.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Optimizing Security with OPSWAT Solutions</title><link>https://securityxp.com/articles/optimizing-security-with-opswat-solutions/</link><guid isPermaLink="true">https://securityxp.com/articles/optimizing-security-with-opswat-solutions/</guid><description>OPSWAT provides advanced cybersecurity solutions that help organizations optimize security measures.</description><pubDate>Mon, 15 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/optimizing-security-with-opswat-solutions.png&quot; alt=&quot;Optimizing Security with OPSWAT Solutions&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;OPSWAT provides advanced cybersecurity solutions that help organizations optimize security measures.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/optimizing-security-with-opswat-solutions.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Leading Vulnerability Scanners: Benefits and Use Cases</title><link>https://securityxp.com/articles/leading-vulnerability-scanners-benefits-and-use-cases/</link><guid isPermaLink="true">https://securityxp.com/articles/leading-vulnerability-scanners-benefits-and-use-cases/</guid><description>Leading vulnerability scanners provide comprehensive security assessment and management capabilities, allowing organizations to identify and remediate potential vulnerabilities in their IT infrastructure. From real-time scanning to automated reporting, these tools offer a range of benefits and use cases, helping businesses to mitigate risks, meet compliance requirements, and enhance overall security posture.</description><pubDate>Sun, 14 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/leading-vulnerability-scanners-benefits-and-use-cases.png&quot; alt=&quot;Leading Vulnerability Scanners: Benefits and Use Cases&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Leading vulnerability scanners provide comprehensive security assessment and management capabilities, allowing organizations to identify and remediate potential vulnerabilities in their IT infrastructure. From real-time scanning to automated reporting, these tools offer a range of benefits and use cases, helping businesses to mitigate risks, meet compliance requirements, and enhance overall security posture.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/leading-vulnerability-scanners-benefits-and-use-cases.png" length="0" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>Staff</author></item><item><title>Centralized Log Management &amp; SIEM Solutions: Benefits &amp; Top Picks</title><link>https://securityxp.com/articles/centralized-log-management-siem-solutions-benefits-top-picks/</link><guid isPermaLink="true">https://securityxp.com/articles/centralized-log-management-siem-solutions-benefits-top-picks/</guid><description>Centralized Log Management &amp; SIEM Solutions: Benefits &amp; Top Picks Centralized log management and SIEM solutions are crucial components of modern IT security infrastructure. They allow businesses to monitor and analyze network activity, detect potential threats, and respond to incidents in real-time. In this article, we’ll explore the benefits of centralized log management and SIEM solutions, and recommend some of the top picks in the market.</description><pubDate>Sat, 13 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/centralized-log-management-siem-solutions-benefits-top-picks.png&quot; alt=&quot;Centralized Log Management &amp; SIEM Solutions: Benefits &amp; Top Picks&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Centralized Log Management &amp; SIEM Solutions: Benefits &amp; Top Picks Centralized log management and SIEM solutions are crucial components of modern IT security infrastructure. They allow businesses to monitor and analyze network activity, detect potential threats, and respond to incidents in real-time. In this article, we’ll explore the benefits of centralized log management and SIEM solutions, and recommend some of the top picks in the market.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/centralized-log-management-siem-solutions-benefits-top-picks.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>DevsecOps: Advantages of Multi-Level Application Security Testing</title><link>https://securityxp.com/articles/devsecops-advantages-of-multi-level-application-security-testing/</link><guid isPermaLink="true">https://securityxp.com/articles/devsecops-advantages-of-multi-level-application-security-testing/</guid><description>DevsecOps: Multi-Level App Security Testing DevsecOps, an evolution of DevOps, introduces security teams early in the development cycle. This approach enables continuous application security testing across multiple levels, providing a comprehensive security posture. With DevsecOps, organizations can leverage automation, collaboration, and continuous feedback, reducing the time to detect and remediate vulnerabilities.</description><pubDate>Fri, 12 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/devsecops-advantages-of-multi-level-application-security-testing.png&quot; alt=&quot;DevsecOps: Advantages of Multi-Level Application Security Testing&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;DevsecOps: Multi-Level App Security Testing DevsecOps, an evolution of DevOps, introduces security teams early in the development cycle. This approach enables continuous application security testing across multiple levels, providing a comprehensive security posture. With DevsecOps, organizations can leverage automation, collaboration, and continuous feedback, reducing the time to detect and remediate vulnerabilities.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/devsecops-advantages-of-multi-level-application-security-testing.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Optimizing IT Operations with Top CMDB Solutions</title><link>https://securityxp.com/articles/optimizing-it-operations-with-top-cmdb-solutions/</link><guid isPermaLink="true">https://securityxp.com/articles/optimizing-it-operations-with-top-cmdb-solutions/</guid><description>A Configuration Management Database (CMDB) is a critical component of IT operations. It provides a central repository of an organization&apos;s IT assets and their relationships, enabling efficient management of IT infrastructure. Top CMDB solutions offer various features, including automated discovery, data reconciliation, and visualization, that help organizations optimize IT operations. By leveraging the capabilities of CMDB solutions, organizations can reduce the time and effort spent on managing IT assets, ensure compliance, and improve overall IT efficiency.</description><pubDate>Thu, 11 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/optimizing-it-operations-with-top-cmdb-solutions.png&quot; alt=&quot;Optimizing IT Operations with Top CMDB Solutions&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A Configuration Management Database (CMDB) is a critical component of IT operations. It provides a central repository of an organization&apos;s IT assets and their relationships, enabling efficient management of IT infrastructure. Top CMDB solutions offer various features, including automated discovery, data reconciliation, and visualization, that help organizations optimize IT operations. By leveraging the capabilities of CMDB solutions, organizations can reduce the time and effort spent on managing IT assets, ensure compliance, and improve overall IT efficiency.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/optimizing-it-operations-with-top-cmdb-solutions.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>MITRE ATT&amp;amp;CK version 13</title><link>https://securityxp.com/articles/mitre-attck-version-13/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-version-13/</guid><description>MITRE ATT&amp;CK version 13 has been recently launched, bringing some significant updates. These include: Key website enhancements Increased focus on cloud and Linux coverage More detailed det...</description><pubDate>Mon, 08 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/mitre-attck-version-13.png&quot; alt=&quot;MITRE ATT&amp;amp;CK version 13&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;MITRE ATT&amp;CK version 13 has been recently launched, bringing some significant updates. These include: Key website enhancements Increased focus on cloud and Linux coverage More detailed det...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/mitre-attck-version-13.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Leading DLP Solutions: Maximizing Data Protection</title><link>https://securityxp.com/articles/leading-dlp-solutions-maximizing-data-protection/</link><guid isPermaLink="true">https://securityxp.com/articles/leading-dlp-solutions-maximizing-data-protection/</guid><description>As data breaches continue to rise, it&apos;s vital for organizations to implement and maintain effective Data Loss Prevention (DLP) solutions. Leading DLP solutions offer comprehensive protection by monitoring and controlling data flow, identifying sensitive information, and enforcing policies to prevent leaks. With the right implementation and configuration, businesses can maximize data protection and avoid costly and damaging breaches.</description><pubDate>Fri, 05 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/leading-dlp-solutions-maximizing-data-protection.png&quot; alt=&quot;Leading DLP Solutions: Maximizing Data Protection&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As data breaches continue to rise, it&apos;s vital for organizations to implement and maintain effective Data Loss Prevention (DLP) solutions. Leading DLP solutions offer comprehensive protection by monitoring and controlling data flow, identifying sensitive information, and enforcing policies to prevent leaks. With the right implementation and configuration, businesses can maximize data protection and avoid costly and damaging breaches.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/leading-dlp-solutions-maximizing-data-protection.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Maximizing Efficiency: Top MDM Solutions &amp; Benefits</title><link>https://securityxp.com/articles/maximizing-efficiency-top-mdm-solutions-benefits/</link><guid isPermaLink="true">https://securityxp.com/articles/maximizing-efficiency-top-mdm-solutions-benefits/</guid><description>Maximizing efficiency in today&apos;s business landscape requires powerful tools. MDM solutions provide the necessary capabilities to manage data and streamline operations. Read on to learn more about the top MDM solutions and the benefits they offer.</description><pubDate>Wed, 03 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/maximizing-efficiency-top-mdm-solutions-benefits.png&quot; alt=&quot;Maximizing Efficiency: Top MDM Solutions &amp; Benefits&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Maximizing efficiency in today&apos;s business landscape requires powerful tools. MDM solutions provide the necessary capabilities to manage data and streamline operations. Read on to learn more about the top MDM solutions and the benefits they offer.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/maximizing-efficiency-top-mdm-solutions-benefits.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Exploring Top RASP Solutions for Secure Web Applications</title><link>https://securityxp.com/articles/exploring-top-rasp-solutions-for-secure-web-applications/</link><guid isPermaLink="true">https://securityxp.com/articles/exploring-top-rasp-solutions-for-secure-web-applications/</guid><description>As web applications become increasingly complex, the need for robust security measures becomes all the more important. One key solution that is gaining in popularity is RASP, or Runtime Application Self-Protection. Here, we take a closer look at some of the top RASP solutions available today, and how they can help to safeguard your web applications against a range of threats.</description><pubDate>Mon, 01 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/exploring-top-rasp-solutions-for-secure-web-applications.png&quot; alt=&quot;Exploring Top RASP Solutions for Secure Web Applications&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As web applications become increasingly complex, the need for robust security measures becomes all the more important. One key solution that is gaining in popularity is RASP, or Runtime Application Self-Protection. Here, we take a closer look at some of the top RASP solutions available today, and how they can help to safeguard your web applications against a range of threats.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/exploring-top-rasp-solutions-for-secure-web-applications.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Maximizing Online Security: Top DNS Filtering Solutions</title><link>https://securityxp.com/articles/maximizing-online-security-top-dns-filtering-solutions/</link><guid isPermaLink="true">https://securityxp.com/articles/maximizing-online-security-top-dns-filtering-solutions/</guid><description>With the increasing number of cyber attacks, it has become crucial to prioritize online security. One of the most effective ways to do so is by implementing DNS filtering solutions. These solutions not only block malicious websites but also prevent data theft and malware attacks. In this article, we will be discussing the top DNS filtering solutions that can help maximize online security.</description><pubDate>Mon, 01 May 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/maximizing-online-security-top-dns-filtering-solutions.png&quot; alt=&quot;Maximizing Online Security: Top DNS Filtering Solutions&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;With the increasing number of cyber attacks, it has become crucial to prioritize online security. One of the most effective ways to do so is by implementing DNS filtering solutions. These solutions not only block malicious websites but also prevent data theft and malware attacks. In this article, we will be discussing the top DNS filtering solutions that can help maximize online security.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/maximizing-online-security-top-dns-filtering-solutions.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>CISA Updates Best Practices for MITRE ATT&amp;CK® Mapping</title><link>https://securityxp.com/articles/cisa-updates-best-practices-for-mitre-attck-mapping/</link><guid isPermaLink="true">https://securityxp.com/articles/cisa-updates-best-practices-for-mitre-attck-mapping/</guid><description>To protect networks and data, CISA believes that understanding the behavior of adversaries is crucial. The success of network defenders in detecting and mitigating cyberattacks depends on this unde...</description><pubDate>Sun, 26 Feb 2023 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2023/02/image-1-1024x622.svg&quot; alt=&quot;CISA Updates Best Practices for MITRE ATT&amp;CK® Mapping&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;To protect networks and data, CISA believes that understanding the behavior of adversaries is crucial. The success of network defenders in detecting and mitigating cyberattacks depends on this unde...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2023/02/image-1-1024x622.svg" length="0" type="image/png"/><category>Compliance &amp; Privacy</category><author>Staff</author></item><item><title>ATT&amp;CK v12 is now accessible! Revisions – October 2022</title><link>https://securityxp.com/articles/attck-v12-is-now-accessible-revisions-october-2022/</link><guid isPermaLink="true">https://securityxp.com/articles/attck-v12-is-now-accessible-revisions-october-2022/</guid><description>Updates to Techniques, Groups, and Software for Enterprise, Mobile, and ICS are included in the October 2022 (v12) ATT&amp;CK release. The addition of detections to ATT&amp;CK for ICS and the inclusion of ...</description><pubDate>Tue, 25 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2021/07/ATTCK_red.svg&quot; alt=&quot;ATT&amp;CK v12 is now accessible! Revisions – October 2022&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Updates to Techniques, Groups, and Software for Enterprise, Mobile, and ICS are included in the October 2022 (v12) ATT&amp;CK release. The addition of detections to ATT&amp;CK for ICS and the inclusion of ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2021/07/ATTCK_red.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Google Announcing GUAC, a great pairing with SLSA (and SBOM)!</title><link>https://securityxp.com/articles/google-announcing-guac-a-great-pairing-with-slsa-and-sbom/</link><guid isPermaLink="true">https://securityxp.com/articles/google-announcing-guac-a-great-pairing-with-slsa-and-sbom/</guid><description>The industry is collectively aware of the importance of supply chain security. Recent events include a sharp increase in software supply chain attacks, a catastrophic severity and breadth Log4j vul...</description><pubDate>Thu, 20 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/image-26-1024x787.svg&quot; alt=&quot;Google Announcing GUAC, a great pairing with SLSA (and SBOM)!&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The industry is collectively aware of the importance of supply chain security. Recent events include a sharp increase in software supply chain attacks, a catastrophic severity and breadth Log4j vul...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/image-26-1024x787.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Canarytokens. org - Rapid, Free, Mass Detection</title><link>https://securityxp.com/articles/canarytokens-org-rapid-free-mass-detection/</link><guid isPermaLink="true">https://securityxp.com/articles/canarytokens-org-rapid-free-mass-detection/</guid><description>Introduction Web bugs, the transparent images that monitor email opening, are probably already familiar to you. They operate by inserting a special URL in the image tag of a page and keeping an ey</description><pubDate>Wed, 19 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/image-25-1024x579.svg&quot; alt=&quot;Canarytokens. org - Rapid, Free, Mass Detection&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Introduction Web bugs, the transparent images that monitor email opening, are probably already familiar to you. They operate by inserting a special URL in the image tag of a page and keeping an ey&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/image-25-1024x579.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Critical Fortinet auth bypass bug has an exploit available; apply the patch now</title><link>https://securityxp.com/articles/critical-fortinet-auth-bypass-bug-has-an-exploit-available-apply-the-patch-now/</link><guid isPermaLink="true">https://securityxp.com/articles/critical-fortinet-auth-bypass-bug-has-an-exploit-available-apply-the-patch-now/</guid><description>A critical authentication bypass flaw affecting Fortinet&apos;s FortiOS, FortiProxy, and FortiSwitchManager appliances now has proof-of-concept exploit code available. Attackers can get around the authe...</description><pubDate>Tue, 18 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/image-13-1024x707.svg&quot; alt=&quot;Critical Fortinet auth bypass bug has an exploit available; apply the patch now&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A critical authentication bypass flaw affecting Fortinet&apos;s FortiOS, FortiProxy, and FortiSwitchManager appliances now has proof-of-concept exploit code available. Attackers can get around the authe...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/image-13-1024x707.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Micro Emulation Plans by MITRE-Engenuity</title><link>https://securityxp.com/articles/micro-emulation-plans-by-mitre-engenuity/</link><guid isPermaLink="true">https://securityxp.com/articles/micro-emulation-plans-by-mitre-engenuity/</guid><description>We enjoy imitating the opposition.  In fact, it&apos;s so important that they&apos;ve written, spoken, trained on it, and are still developing and disseminating more emulation plans (including one of the fir...</description><pubDate>Tue, 18 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/image-16-1024x576.svg&quot; alt=&quot;Micro Emulation Plans by MITRE-Engenuity&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;We enjoy imitating the opposition.  In fact, it&apos;s so important that they&apos;ve written, spoken, trained on it, and are still developing and disseminating more emulation plans (including one of the fir...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/image-16-1024x576.svg" length="0" type="image/png"/><category>Compliance &amp; Privacy</category><author>Staff</author></item><item><title>Organizations in Poland and Ukraine are affected by the new &quot;Prestige&quot; ransomware.</title><link>https://securityxp.com/articles/organizations-in-poland-and-ukraine-are-affected-by-the-new-prestige-ransomware/</link><guid isPermaLink="true">https://securityxp.com/articles/organizations-in-poland-and-ukraine-are-affected-by-the-new-prestige-ransomware/</guid><description>The Microsoft Threat Intelligence Center (MSTIC) has found evidence of a novel ransomware campaign using a hitherto unidentified ransomware payload that targets businesses in the logistics and tran...</description><pubDate>Tue, 18 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/image-10.svg&quot; alt=&quot;Organizations in Poland and Ukraine are affected by the new &quot;Prestige&quot; ransomware.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Microsoft Threat Intelligence Center (MSTIC) has found evidence of a novel ransomware campaign using a hitherto unidentified ransomware payload that targets businesses in the logistics and tran...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/image-10.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Cloud Web Application and API Protection Magic Quadrant</title><link>https://securityxp.com/articles/cloud-web-application-and-api-protection-magic-quadrant/</link><guid isPermaLink="true">https://securityxp.com/articles/cloud-web-application-and-api-protection-magic-quadrant/</guid><description>The market for protecting cloud web applications and APIs is expanding quickly. You can use this Magic Quadrant to find cloud WAAP providers that provide simple controls and specialised defences ag...</description><pubDate>Mon, 17 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/1-2-1.svg&quot; alt=&quot;Cloud Web Application and API Protection Magic Quadrant&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The market for protecting cloud web applications and APIs is expanding quickly. You can use this Magic Quadrant to find cloud WAAP providers that provide simple controls and specialised defences ag...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/1-2-1.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Serverless Top security best practices</title><link>https://securityxp.com/articles/serverless-top-security-best-practices/</link><guid isPermaLink="true">https://securityxp.com/articles/serverless-top-security-best-practices/</guid><description>Describe serverless. A cloud execution model is serverless computing. It enables users and developers to create and use applications and services without having to worry about servers. Applications...</description><pubDate>Mon, 17 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/image-8-1024x586.svg&quot; alt=&quot;Serverless Top security best practices&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Describe serverless. A cloud execution model is serverless computing. It enables users and developers to create and use applications and services without having to worry about servers. Applications...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/image-8-1024x586.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Voice of the Customer: Web Application and API Protection, Gartner Peer Insights</title><link>https://securityxp.com/articles/voice-of-the-customer-web-application-and-api-protection-gartner-peer-insights/</link><guid isPermaLink="true">https://securityxp.com/articles/voice-of-the-customer-web-application-and-api-protection-gartner-peer-insights/</guid><description>What is API and Web Application Protection? Web application and API protection (WAAP), according to Gartner, is the evolution of the web application firewall (WAF) market, which now includes four c...</description><pubDate>Sun, 16 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/1-908x1024.svg&quot; alt=&quot;Voice of the Customer: Web Application and API Protection, Gartner Peer Insights&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;What is API and Web Application Protection? Web application and API protection (WAAP), according to Gartner, is the evolution of the web application firewall (WAF) market, which now includes four c...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/1-908x1024.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>MITRE ATT&amp;CK® Released Updates in Apr 2022 With Additional Techniques and Structuring</title><link>https://securityxp.com/articles/mitre-attck-released-updates-in-apr-2022-with-additional-techniques-and-structuring/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-released-updates-in-apr-2022-with-additional-techniques-and-structuring/</guid><description>The Techniques, Groups, and Software for Enterprise, Mobile, and ICS are updated in the April 2022 (v11) ATT&amp;CK release. The most significant modifications are the reorganisation of Detections, whi...</description><pubDate>Fri, 14 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2021/07/ATTCK_red.svg&quot; alt=&quot;MITRE ATT&amp;CK® Released Updates in Apr 2022 With Additional Techniques and Structuring&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Techniques, Groups, and Software for Enterprise, Mobile, and ICS are updated in the April 2022 (v11) ATT&amp;CK release. The most significant modifications are the reorganisation of Detections, whi...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2021/07/ATTCK_red.svg" length="0" type="image/png"/><category>Compliance &amp; Privacy</category><author>Staff</author></item><item><title>OWASP Threat Dragon : open-source threat modeling tool from OWASP</title><link>https://securityxp.com/articles/owasp-threat-dragon-open-source-threat-modeling-tool-from-owasp/</link><guid isPermaLink="true">https://securityxp.com/articles/owasp-threat-dragon-open-source-threat-modeling-tool-from-owasp/</guid><description>Threat modelling is regarded as a potent method for incorporating security into application design at an early stage of the secure development lifecycle. It is most effective when used for: ensurin...</description><pubDate>Fri, 14 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/owasp-threat-dragon-open-source-threat-modeling-tool-from-owasp.png&quot; alt=&quot;OWASP Threat Dragon : open-source threat modeling tool from OWASP&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Threat modelling is regarded as a potent method for incorporating security into application design at an early stage of the secure development lifecycle. It is most effective when used for: ensurin...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/owasp-threat-dragon-open-source-threat-modeling-tool-from-owasp.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>The Microsoft Threat Modeling Tool (TMT)</title><link>https://securityxp.com/articles/the-microsoft-threat-modeling-tool-tmt/</link><guid isPermaLink="true">https://securityxp.com/articles/the-microsoft-threat-modeling-tool-tmt/</guid><description>A crucial component of the Microsoft Security Development Lifecycle is the Threat Modeling Tool (SDL). Early detection and mitigation of potential security issues, when they are still manageable an...</description><pubDate>Fri, 14 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/2022-10-15-01_10_21-Microsoft-Threat-Modeling-Tool-1024x557.svg&quot; alt=&quot;The Microsoft Threat Modeling Tool (TMT)&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A crucial component of the Microsoft Security Development Lifecycle is the Threat Modeling Tool (SDL). Early detection and mitigation of potential security issues, when they are still manageable an...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/2022-10-15-01_10_21-Microsoft-Threat-Modeling-Tool-1024x557.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>IriusRisk Threat Modeling for Security and Development Teams</title><link>https://securityxp.com/articles/iriusrisk-threat-modeling-for-security-and-development-teams/</link><guid isPermaLink="true">https://securityxp.com/articles/iriusrisk-threat-modeling-for-security-and-development-teams/</guid><description>Threat modelling: what is it? Basics of Threat Modeling Threat modeling&apos;s fundamental tenet is the identification, disclosure, and management of security flaws. This is accomplished by being aware of</description><pubDate>Thu, 13 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/Threat-modeling1--1024x347.svg&quot; alt=&quot;IriusRisk Threat Modeling for Security and Development Teams&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Threat modelling: what is it? Basics of Threat Modeling Threat modeling&apos;s fundamental tenet is the identification, disclosure, and management of security flaws. This is accomplished by being aware of&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/Threat-modeling1--1024x347.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Threat Modeling: Choosing the Right Method for Your Business</title><link>https://securityxp.com/articles/threat-modeling-choosing-the-right-method-for-your-business/</link><guid isPermaLink="true">https://securityxp.com/articles/threat-modeling-choosing-the-right-method-for-your-business/</guid><description>Why Threat Modeling Is Important and What It Is Identifying and evaluating threats that an attacker (threat) could exploit is done through the exercise of threat modelling. Consider a threat model ...</description><pubDate>Thu, 13 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/threat-modeling-choosing-the-right-method-for-your-business.png&quot; alt=&quot;Threat Modeling: Choosing the Right Method for Your Business&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Why Threat Modeling Is Important and What It Is Identifying and evaluating threats that an attacker (threat) could exploit is done through the exercise of threat modelling. Consider a threat model ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/threat-modeling-choosing-the-right-method-for-your-business.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Kenna: RISK-BASED VULNERABILITY MANAGEMENT</title><link>https://securityxp.com/articles/kenna-risk-based-vulnerability-management/</link><guid isPermaLink="true">https://securityxp.com/articles/kenna-risk-based-vulnerability-management/</guid><description>Why You Should Consider More Than CVSS As previously mentioned, one typical method of sorting and prioritising which vulnerabilities to fix first is patching vulnerabilities that have a CVSS score in</description><pubDate>Wed, 12 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/kenna-resources-prioritization-to-prediction-volume-8-1024x565.svg&quot; alt=&quot;Kenna: RISK-BASED VULNERABILITY MANAGEMENT&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Why You Should Consider More Than CVSS As previously mentioned, one typical method of sorting and prioritising which vulnerabilities to fix first is patching vulnerabilities that have a CVSS score in&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/kenna-resources-prioritization-to-prediction-volume-8-1024x565.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>A Holistic Performance Management Framework for Implementing Cybersecurity Strategies by BCG &amp; STC</title><link>https://securityxp.com/articles/a-holistic-performance-management-framework-for-implementing-cybersecurity-strategies-by-bcg-stc/</link><guid isPermaLink="true">https://securityxp.com/articles/a-holistic-performance-management-framework-for-implementing-cybersecurity-strategies-by-bcg-stc/</guid><description>The frequency and cost of cyberattacks is accelerating. Globally, the cost of cybercrime is estimated to have risen from $445B in 2015 to over $2.2 trillion today. The frequency and size of data br...</description><pubDate>Sat, 08 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/Top-Down-Approach-for-Performance-Management-Cybersecurity_Strategy_Management_Framework-1024x723.svg&quot; alt=&quot;A Holistic Performance Management Framework for Implementing Cybersecurity Strategies by BCG &amp; STC&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The frequency and cost of cyberattacks is accelerating. Globally, the cost of cybercrime is estimated to have risen from $445B in 2015 to over $2.2 trillion today. The frequency and size of data br...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/Top-Down-Approach-for-Performance-Management-Cybersecurity_Strategy_Management_Framework-1024x723.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Best Cloud SaaS Governance Practices from the CSA Cloud Security Alliance</title><link>https://securityxp.com/articles/best-cloud-saas-governance-practices-from-the-csa-cloud-security-alliance/</link><guid isPermaLink="true">https://securityxp.com/articles/best-cloud-saas-governance-practices-from-the-csa-cloud-security-alliance/</guid><description>Introduction Infrastructure as Service security is almost always the focus when discussing cloud security. platforms as a service (PaaS) and infrastructure as a service (IaaS). In spite of the fact...</description><pubDate>Sat, 08 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/ISO-Risk-Management-Process-Clause-5-Process.svg&quot; alt=&quot;Best Cloud SaaS Governance Practices from the CSA Cloud Security Alliance&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Introduction Infrastructure as Service security is almost always the focus when discussing cloud security. platforms as a service (PaaS) and infrastructure as a service (IaaS). In spite of the fact...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/ISO-Risk-Management-Process-Clause-5-Process.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Security and Privacy Capability Maturity Model (SP-CMM) by SCF, Secure and Privacy by Design Principles Framework</title><link>https://securityxp.com/articles/security-and-privacy-capability-maturity-model-sp-cmm-by-scf-secure-and-privacy-by-design-principles-framework/</link><guid isPermaLink="true">https://securityxp.com/articles/security-and-privacy-capability-maturity-model-sp-cmm-by-scf-secure-and-privacy-by-design-principles-framework/</guid><description>The SP establishes 32 common-sense principles to guide the development and oversight of a modern security and privacy program. The SP is sourced from the Secure Controls Framework (SCF), which is a...</description><pubDate>Fri, 07 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/scf-security-privacy-by-design-principles_page-0001-1024x683.svg&quot; alt=&quot;Security and Privacy Capability Maturity Model (SP-CMM) by SCF, Secure and Privacy by Design Principles Framework&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The SP establishes 32 common-sense principles to guide the development and oversight of a modern security and privacy program. The SP is sourced from the Secure Controls Framework (SCF), which is a...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/scf-security-privacy-by-design-principles_page-0001-1024x683.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Campaigns to be Introduced to MITRE ATT&amp;CK V12</title><link>https://securityxp.com/articles/campaigns-to-be-introduced-to-mitre-attck-v12/</link><guid isPermaLink="true">https://securityxp.com/articles/campaigns-to-be-introduced-to-mitre-attck-v12/</guid><description>Primary Articles [Published ](&lt;https://medium.com/mitre-attack/introducing-attack-campaigns-6b15baa6cbb4)by Matt Malona In [ATT&amp;CK 2022](&lt;https://medium.com/mitre-attack/attack-2022-roadmap-cd5a1a3...</description><pubDate>Wed, 05 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/10/image.svg&quot; alt=&quot;Campaigns to be Introduced to MITRE ATT&amp;CK V12&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Primary Articles [Published ](&lt;https://medium.com/mitre-attack/introducing-attack-campaigns-6b15baa6cbb4)by Matt Malona In [ATT&amp;CK 2022](&lt;https://medium.com/mitre-attack/attack-2022-roadmap-cd5a1a3...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/10/image.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>DevSecOps is not just a technological shift; it is also a cultural one, according to Tenable.cs Cloud Security&apos;s whitepaper, &quot;7 Habits of Highly Effective DEVSECOPS Teams.&quot;</title><link>https://securityxp.com/articles/devsecops-is-not-just-a-technological-shift-it-is-also-a-cultural-one-according-to-tenable-cs-cloud-securitys-whitepaper-7-habits-of-highly-effective-devsecops-teams/</link><guid isPermaLink="true">https://securityxp.com/articles/devsecops-is-not-just-a-technological-shift-it-is-also-a-cultural-one-according-to-tenable-cs-cloud-securitys-whitepaper-7-habits-of-highly-effective-devsecops-teams/</guid><description>DecSecOps, which is typically viewed as an integrated team of development, operational, and security practitioners that can securely deliver innovation within a defined scope to market, is an ideal...</description><pubDate>Mon, 03 Oct 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/devsecops-is-not-just-a-technological-shift-it-is-also-a-cultural-one-according-to-tenable-cs-cloud-securitys-whitepaper-7-habits-of-highly-effective-devsecops-teams.png&quot; alt=&quot;DevSecOps is not just a technological shift; it is also a cultural one, according to Tenable.cs Cloud Security&apos;s whitepaper, &quot;7 Habits of Highly Effective DEVSECOPS Teams.&quot;&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;DecSecOps, which is typically viewed as an integrated team of development, operational, and security practitioners that can securely deliver innovation within a defined scope to market, is an ideal...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/devsecops-is-not-just-a-technological-shift-it-is-also-a-cultural-one-according-to-tenable-cs-cloud-securitys-whitepaper-7-habits-of-highly-effective-devsecops-teams.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>A CyberRisk Alliance Resource, MSSP Alert - TOP 250 MSSPs Services Providers 2022 edition</title><link>https://securityxp.com/articles/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-services-providers-2022-edition/</link><guid isPermaLink="true">https://securityxp.com/articles/a-cyberrisk-alliance-resource-mssp-alert-top-250-mssps-services-providers-2022-edition/</guid><description>A succinct summary The Top 250 MSSPs and associated survey respondents continue to expand more quickly than the managed security market as a whole. In fact, respondents to the survey anticipate tha...</description><pubDate>Tue, 20 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/09/image-26.svg&quot; alt=&quot;A CyberRisk Alliance Resource, MSSP Alert - TOP 250 MSSPs Services Providers 2022 edition&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A succinct summary The Top 250 MSSPs and associated survey respondents continue to expand more quickly than the managed security market as a whole. In fact, respondents to the survey anticipate tha...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/09/image-26.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Threat actors gained access to the personal data of tens of thousands of Revolut customers as a result of a cyberattack</title><link>https://securityxp.com/articles/threat-actors-gained-access-to-the-personal-data-of-tens-of-thousands-of-revolut-customers-as-a-result-of-a-cyberattack/</link><guid isPermaLink="true">https://securityxp.com/articles/threat-actors-gained-access-to-the-personal-data-of-tens-of-thousands-of-revolut-customers-as-a-result-of-a-cyberattack/</guid><description>Over the weekend, the financial technology company Revolut was the victim of a &apos;highly targeted&apos; cyberattack in which threat actors gained access to the personal data of 0.16% of its users (approxi...</description><pubDate>Mon, 19 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/09/03-Card-Data-1024x999.svg&quot; alt=&quot;Threat actors gained access to the personal data of tens of thousands of Revolut customers as a result of a cyberattack&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Over the weekend, the financial technology company Revolut was the victim of a &apos;highly targeted&apos; cyberattack in which threat actors gained access to the personal data of 0.16% of its users (approxi...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/09/03-Card-Data-1024x999.svg" length="0" type="image/png"/><category>Data Breaches</category><author>Staff</author></item><item><title>$3,500 for Starbucks Cofee Data with Name, Gender, DoB, Mobile No., Email and Address</title><link>https://securityxp.com/articles/3500-for-starbucks-cofee-data-with-name-gender-dob-mobile-no-email-and-address/</link><guid isPermaLink="true">https://securityxp.com/articles/3500-for-starbucks-cofee-data-with-name-gender-dob-mobile-no-email-and-address/</guid><description>The Straits Times discovered that 330,000 Singaporean Starbucks customers&apos; personal information had been compromised and sold on an online forum since September 10. On Friday, the coffee chain sent...</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/09/170922_star_st.svg&quot; alt=&quot;$3,500 for Starbucks Cofee Data with Name, Gender, DoB, Mobile No., Email and Address&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Straits Times discovered that 330,000 Singaporean Starbucks customers&apos; personal information had been compromised and sold on an online forum since September 10. On Friday, the coffee chain sent...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/09/170922_star_st.svg" length="0" type="image/png"/><category>Data Breaches</category><author>Staff</author></item><item><title>BARK: A PowerShell script was created to aid the BloodHound Enterprise team in locating and regularly validating abuse primitives.</title><link>https://securityxp.com/articles/bark-a-powershell-script-was-created-to-aid-the-bloodhound-enterprise-team-in-locating-and-regularly-validating-abuse-primitives/</link><guid isPermaLink="true">https://securityxp.com/articles/bark-a-powershell-script-was-created-to-aid-the-bloodhound-enterprise-team-in-locating-and-regularly-validating-abuse-primitives/</guid><description>BloodHound Attack Research Kit is referred to as BARK. It is a PowerShell script created to help the BloodHound Enterprise team find and keep track of abuse primitives. At the moment, BARK is conce...</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/bark-a-powershell-script-was-created-to-aid-the-bloodhound-enterprise-team-in-locating-and-regularly-validating-abuse-primitives.png&quot; alt=&quot;BARK: A PowerShell script was created to aid the BloodHound Enterprise team in locating and regularly validating abuse primitives.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;BloodHound Attack Research Kit is referred to as BARK. It is a PowerShell script created to help the BloodHound Enterprise team find and keep track of abuse primitives. At the moment, BARK is conce...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/bark-a-powershell-script-was-created-to-aid-the-bloodhound-enterprise-team-in-locating-and-regularly-validating-abuse-primitives.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Beta Mobile Sub-Techniques, Structured Detections, and ICS Join the Band as ATT&amp;CK Upgrades to Version 11</title><link>https://securityxp.com/articles/beta-mobile-sub-techniques-structured-detections-and-ics-join-the-band-as-attck-upgrades-to-version-11/</link><guid isPermaLink="true">https://securityxp.com/articles/beta-mobile-sub-techniques-structured-detections-and-ics-join-the-band-as-attck-upgrades-to-version-11/</guid><description>The most recent ATT&amp;CK release is now available, and this time They have upgraded to version 11! There shouldn&apos;t be any major surprises if you&apos;ve been following their roadmap, but they wanted to ta...</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/beta-mobile-sub-techniques-structured-detections-and-ics-join-the-band-as-attck-upgrades-to-version-11.png&quot; alt=&quot;Beta Mobile Sub-Techniques, Structured Detections, and ICS Join the Band as ATT&amp;CK Upgrades to Version 11&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The most recent ATT&amp;CK release is now available, and this time They have upgraded to version 11! There shouldn&apos;t be any major surprises if you&apos;ve been following their roadmap, but they wanted to ta...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/beta-mobile-sub-techniques-structured-detections-and-ics-join-the-band-as-attck-upgrades-to-version-11.png" length="0" type="image/png"/><category>Compliance &amp; Privacy</category><author>Staff</author></item><item><title>The Azure Threat Research Matrix is explained</title><link>https://securityxp.com/articles/the-azure-threat-research-matrix-is-explained/</link><guid isPermaLink="true">https://securityxp.com/articles/the-azure-threat-research-matrix-is-explained/</guid><description>It&apos;s typical for the assessment team to cite the MITRE ATT&amp;CK knowledge base when conducting an offensive security assessment so that high-level stakeholders can see visually which techniques were ...</description><pubDate>Sat, 17 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/09/Azure-Threat-Research-Matrix--1024x659.svg&quot; alt=&quot;The Azure Threat Research Matrix is explained&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;It&apos;s typical for the assessment team to cite the MITRE ATT&amp;CK knowledge base when conducting an offensive security assessment so that high-level stakeholders can see visually which techniques were ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/09/Azure-Threat-Research-Matrix--1024x659.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Uber employees believed the alleged teen hacker attack was a joke.</title><link>https://securityxp.com/articles/uber-employees-believed-the-alleged-teen-hacker-attack-was-a-joke/</link><guid isPermaLink="true">https://securityxp.com/articles/uber-employees-believed-the-alleged-teen-hacker-attack-was-a-joke/</guid><description>The world&apos;s largest ride-hailing company, Uber, shut down a portion of its operations late on Thursday after learning that its internal systems had been compromised. According to the company, the a...</description><pubDate>Fri, 16 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/uber-employees-believed-the-alleged-teen-hacker-attack-was-a-joke.png&quot; alt=&quot;Uber employees believed the alleged teen hacker attack was a joke.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The world&apos;s largest ride-hailing company, Uber, shut down a portion of its operations late on Thursday after learning that its internal systems had been compromised. According to the company, the a...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/uber-employees-believed-the-alleged-teen-hacker-attack-was-a-joke.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Dufflebag</title><link>https://securityxp.com/articles/dufflebag/</link><guid isPermaLink="true">https://securityxp.com/articles/dufflebag/</guid><description>A tool called [Dufflebag ](&lt;https://github.com/bishopfox/dufflebag)developed by [dan-bishopfox Dan Petro](&lt;https://github.com/dan-bishopfox) and [bmoar Ben Morris](&lt;https://github.com/bmoar</description><pubDate>Sat, 10 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/dufflebag.png&quot; alt=&quot;Dufflebag&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A tool called [Dufflebag ](&lt;https://github.com/bishopfox/dufflebag)developed by [dan-bishopfox Dan Petro](&lt;https://github.com/dan-bishopfox) and [bmoar Ben Morris](&lt;https://github.com/bmoar&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/dufflebag.png" length="0" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>Staff</author></item><item><title>Portuguese NATO documents discovered for sale online</title><link>https://securityxp.com/articles/portuguese-nato-documents-discovered-for-sale-online/</link><guid isPermaLink="true">https://securityxp.com/articles/portuguese-nato-documents-discovered-for-sale-online/</guid><description>The National Security Office is still determining the extent of the damage, but EMGFA, secret military, and MDN computers are suspected of being involved in the security lapse that made it possible...</description><pubDate>Fri, 09 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/portuguese-nato-documents-discovered-for-sale-online.png&quot; alt=&quot;Portuguese NATO documents discovered for sale online&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The National Security Office is still determining the extent of the damage, but EMGFA, secret military, and MDN computers are suspected of being involved in the security lapse that made it possible...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/portuguese-nato-documents-discovered-for-sale-online.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>A significant data breach on the streaming service Brand New Tube exposed users&apos; names and IP addresses.</title><link>https://securityxp.com/articles/a-significant-data-breach-on-the-streaming-service-brand-new-tube-exposed-users-names-and-ip-addresses/</link><guid isPermaLink="true">https://securityxp.com/articles/a-significant-data-breach-on-the-streaming-service-brand-new-tube-exposed-users-names-and-ip-addresses/</guid><description>A significant security flaw has been discovered on [BrandNewTube](&lt;https://brandnewtube.com/), a YouTube alternative that was founded in the UK. Several users who received an email that revealed thei</description><pubDate>Thu, 08 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/09/image-14-1024x440.svg&quot; alt=&quot;A significant data breach on the streaming service Brand New Tube exposed users&apos; names and IP addresses.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A significant security flaw has been discovered on [BrandNewTube](&lt;https://brandnewtube.com/), a YouTube alternative that was founded in the UK. Several users who received an email that revealed thei&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/09/image-14-1024x440.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>A Successful Threat-Hunting Program&apos;s Foundation</title><link>https://securityxp.com/articles/a-successful-threat-hunting-programs-foundation/</link><guid isPermaLink="true">https://securityxp.com/articles/a-successful-threat-hunting-programs-foundation/</guid><description>&apos;Threat hunting is the practice of proactively searching for cyber threats that are lurking undetected in a network. Cyber threat hunting digs deep to find malicious actors in your environment tha</description><pubDate>Wed, 07 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/a-successful-threat-hunting-programs-foundation.png&quot; alt=&quot;A Successful Threat-Hunting Program&apos;s Foundation&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;&apos;Threat hunting is the practice of proactively searching for cyber threats that are lurking undetected in a network. Cyber threat hunting digs deep to find malicious actors in your environment tha&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/a-successful-threat-hunting-programs-foundation.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Feds and npm Give advice on supply chain security to prevent another SolarWinds incident</title><link>https://securityxp.com/articles/feds-and-npm-give-advice-on-supply-chain-security-to-prevent-another-solarwinds-incident/</link><guid isPermaLink="true">https://securityxp.com/articles/feds-and-npm-give-advice-on-supply-chain-security-to-prevent-another-solarwinds-incident/</guid><description>Faster development times, innovation, and a thriving open-source community have all been made possible by the ability to use another developer&apos;s project as a dependency. With many JavaScript projects</description><pubDate>Tue, 06 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/09/image-13-1024x695.svg&quot; alt=&quot;Feds and npm Give advice on supply chain security to prevent another SolarWinds incident&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Faster development times, innovation, and a thriving open-source community have all been made possible by the ability to use another developer&apos;s project as a dependency. With many JavaScript projects&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/09/image-13-1024x695.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Change your Tiktok password immediately in case of a massive data leak.</title><link>https://securityxp.com/articles/change-your-tiktok-password-immediately-in-case-of-a-massive-data-leak/</link><guid isPermaLink="true">https://securityxp.com/articles/change-your-tiktok-password-immediately-in-case-of-a-massive-data-leak/</guid><description>There&apos;s a post from 12 hours ago on a well-known hacking forum making some pretty significant claims, with the disclaimer that everything is &apos;alleged&apos; at this point: &apos;We don&apos;t know why it&apos;s there o...</description><pubDate>Mon, 05 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/09/image-4.svg&quot; alt=&quot;Change your Tiktok password immediately in case of a massive data leak.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;There&apos;s a post from 12 hours ago on a well-known hacking forum making some pretty significant claims, with the disclaimer that everything is &apos;alleged&apos; at this point: &apos;We don&apos;t know why it&apos;s there o...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/09/image-4.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>NATO Examines Data Breach from Missile Vendor on the Dark Web</title><link>https://securityxp.com/articles/nato-examines-data-breach-from-missile-vendor-on-the-dark-web/</link><guid isPermaLink="true">https://securityxp.com/articles/nato-examines-data-breach-from-missile-vendor-on-the-dark-web/</guid><description>One set of documents purportedly belonging to an EU defense supplier includes information on the weapons Ukraine used to fight Russia. According to a report in the media, NATO is looking into the l...</description><pubDate>Sun, 04 Sep 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/09/image-1024x417.svg&quot; alt=&quot;NATO Examines Data Breach from Missile Vendor on the Dark Web&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;One set of documents purportedly belonging to an EU defense supplier includes information on the weapons Ukraine used to fight Russia. According to a report in the media, NATO is looking into the l...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/09/image-1024x417.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>DRDO and IIT Delhi scientists demonstrate Quantum Key Distribution (QKD) between two cities 100 kilometres apart</title><link>https://securityxp.com/articles/drdo-and-iit-delhi-scientists-demonstrate-quantum-key-distribution-qkd-between-two-cities-100-kilometres-apart/</link><guid isPermaLink="true">https://securityxp.com/articles/drdo-and-iit-delhi-scientists-demonstrate-quantum-key-distribution-qkd-between-two-cities-100-kilometres-apart/</guid><description>For the first time in the country, a team of scientists from the Defence Research and Development Organisation (DRDO) and the Indian Institute of Technology (IIT) Delhi successfully demonstrated a ...</description><pubDate>Fri, 25 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/02/drdo1-1024x358.svg&quot; alt=&quot;DRDO and IIT Delhi scientists demonstrate Quantum Key Distribution (QKD) between two cities 100 kilometres apart&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;For the first time in the country, a team of scientists from the Defence Research and Development Organisation (DRDO) and the Indian Institute of Technology (IIT) Delhi successfully demonstrated a ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/02/drdo1-1024x358.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Indian Organizations also targetted by Bvp47 backdoor of US NSA Equation Group</title><link>https://securityxp.com/articles/indian-organizations-also-targetted-by-bvp47-backdoor-of-us-nsa-equation-group/</link><guid isPermaLink="true">https://securityxp.com/articles/indian-organizations-also-targetted-by-bvp47-backdoor-of-us-nsa-equation-group/</guid><description>Banaras Hindu University, India Education Network, Eureka Technology Partners, Indian Academy of Sciences, Indian Institute of Tropical Meteorology, Council of Scientific &amp; Industrial Research (CSIR)</description><pubDate>Thu, 24 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/02/bvp47.en_-1024x811.svg&quot; alt=&quot;Indian Organizations also targetted by Bvp47 backdoor of US NSA Equation Group&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Banaras Hindu University, India Education Network, Eureka Technology Partners, Indian Academy of Sciences, Indian Institute of Tropical Meteorology, Council of Scientific &amp; Industrial Research (CSIR)&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/02/bvp47.en_-1024x811.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Free Cybersecurity Services And Tools Released by CISA</title><link>https://securityxp.com/articles/free-cybersecurity-services-and-tools-released-by-cisa/</link><guid isPermaLink="true">https://securityxp.com/articles/free-cybersecurity-services-and-tools-released-by-cisa/</guid><description>CISA has collected a list of free cybersecurity tools and services to help companies advance their security capabilities as part of our ongoing objective to minimise cybersecurity risk among U.S. c...</description><pubDate>Wed, 23 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/free-cybersecurity-services-and-tools-released-by-cisa.png&quot; alt=&quot;Free Cybersecurity Services And Tools Released by CISA&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;CISA has collected a list of free cybersecurity tools and services to help companies advance their security capabilities as part of our ongoing objective to minimise cybersecurity risk among U.S. c...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/free-cybersecurity-services-and-tools-released-by-cisa.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Phishing and malware by numbers in the Threat Report Portugal Q3 2021.</title><link>https://securityxp.com/articles/phishing-and-malware-by-numbers-in-the-threat-report-portugal-q3-2021/</link><guid isPermaLink="true">https://securityxp.com/articles/phishing-and-malware-by-numbers-in-the-threat-report-portugal-q3-2021/</guid><description>Segurança-Informática developed and maintains the Portuguese Abuse Open Feed 0xSI f33d, an open sharing database with the potential to collect indicators from numerous sources. This feed is provide...</description><pubDate>Wed, 23 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/02/p1-1024x383.svg&quot; alt=&quot;Phishing and malware by numbers in the Threat Report Portugal Q3 2021.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Segurança-Informática developed and maintains the Portuguese Abuse Open Feed 0xSI f33d, an open sharing database with the potential to collect indicators from numerous sources. This feed is provide...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/02/p1-1024x383.svg" length="0" type="image/png"/><category>Malware &amp; Ransomware</category><author>Staff</author></item><item><title>Cybersecurity Risks of Russia-Ukraine Conflict Escalation</title><link>https://securityxp.com/articles/cybersecurity-risks-of-russia-ukraine-conflict-escalation/</link><guid isPermaLink="true">https://securityxp.com/articles/cybersecurity-risks-of-russia-ukraine-conflict-escalation/</guid><description>DDoS attacks on Ukrainian groups were promptly traced to Russian intelligence by the UK and US governments last week. The intrusions on February 15 and 16 were &apos;very certain&apos; the work of the Russia...</description><pubDate>Tue, 22 Feb 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/02/blame-russia.svg&quot; alt=&quot;Cybersecurity Risks of Russia-Ukraine Conflict Escalation&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;DDoS attacks on Ukrainian groups were promptly traced to Russian intelligence by the UK and US governments last week. The intrusions on February 15 and 16 were &apos;very certain&apos; the work of the Russia...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/02/blame-russia.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Payout for Zero-Click Outlook Zero-Days has been increased to $400,000 by Zerodium.</title><link>https://securityxp.com/articles/payout-for-zero-click-outlook-zero-days-has-been-increased-to-400000-by-zerodium/</link><guid isPermaLink="true">https://securityxp.com/articles/payout-for-zero-click-outlook-zero-days-has-been-increased-to-400000-by-zerodium/</guid><description>It was announced on the same day that Trustwave SpiderLabs revealed a new approach to get around Outlook security and send malicious links to victims. was reported by [threatpost](&lt;https://threatpo...</description><pubDate>Fri, 28 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/01/zerodium-outlook-bounty-1024x547.svg&quot; alt=&quot;Payout for Zero-Click Outlook Zero-Days has been increased to $400,000 by Zerodium.&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;It was announced on the same day that Trustwave SpiderLabs revealed a new approach to get around Outlook security and send malicious links to victims. was reported by [threatpost](&lt;https://threatpo...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/01/zerodium-outlook-bounty-1024x547.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Joint action by 10 countries and Europol taken down VPNLabs secure communication tool favored by cybercriminals</title><link>https://securityxp.com/articles/joint-action-by-10-countries-and-europol-taken-down-vpnlabs-secure-communication-tool-favored-by-cybercriminals/</link><guid isPermaLink="true">https://securityxp.com/articles/joint-action-by-10-countries-and-europol-taken-down-vpnlabs-secure-communication-tool-favored-by-cybercriminals/</guid><description>Joint action by 10 countries and Europol taken down VPNLabs secure communication tool favored by cybercriminals This week, law enforcement officials targeted VPNLab.net&apos;s users and infrastructure i...</description><pubDate>Tue, 18 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/01/vpnlabs-main-site-1024x560.svg&quot; alt=&quot;Joint action by 10 countries and Europol taken down VPNLabs secure communication tool favored by cybercriminals&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Joint action by 10 countries and Europol taken down VPNLabs secure communication tool favored by cybercriminals This week, law enforcement officials targeted VPNLab.net&apos;s users and infrastructure i...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/01/vpnlabs-main-site-1024x560.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Russia Arrests members of &quot;REvil&quot; hacking group at U.S. request - FSB</title><link>https://securityxp.com/articles/russia-arrests-members-of-revil-hacking-group-at-u-s-request-fsb/</link><guid isPermaLink="true">https://securityxp.com/articles/russia-arrests-members-of-revil-hacking-group-at-u-s-request-fsb/</guid><description>In Russia, the cities of Moscow, St. Petersburg, Moscow, Leningrad, and Lipetsk, the Russian Federation&apos;s Federal Security Service, in collaboration with the Ministry of Internal Affairs&apos; Investiga...</description><pubDate>Tue, 18 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/russia-arrests-members-of-revil-hacking-group-at-u-s-request-fsb.png&quot; alt=&quot;Russia Arrests members of &quot;REvil&quot; hacking group at U.S. request - FSB&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;In Russia, the cities of Moscow, St. Petersburg, Moscow, Leningrad, and Lipetsk, the Russian Federation&apos;s Federal Security Service, in collaboration with the Ministry of Internal Affairs&apos; Investiga...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/russia-arrests-members-of-revil-hacking-group-at-u-s-request-fsb.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>MITRE ATT&amp;CK® Released Updates in Oct 2021 With Additional Techniques and Structuring</title><link>https://securityxp.com/articles/mitre-attck-released-updates-in-oct-2021-with-additional-techniques-and-structuring/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-released-updates-in-oct-2021-with-additional-techniques-and-structuring/</guid><description>MITRE ATT&amp;CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of ...</description><pubDate>Sun, 16 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2021/07/ATTCK_red.svg&quot; alt=&quot;MITRE ATT&amp;CK® Released Updates in Oct 2021 With Additional Techniques and Structuring&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;MITRE ATT&amp;CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2021/07/ATTCK_red.svg" length="0" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>Staff</author></item><item><title>Russian Hackers Infiltrate Exams of Indian Navy And Air Force</title><link>https://securityxp.com/articles/russian-hackers-infiltrate-exams-of-indian-navy-and-air-force/</link><guid isPermaLink="true">https://securityxp.com/articles/russian-hackers-infiltrate-exams-of-indian-navy-and-air-force/</guid><description>The Delhi Police’s has busted attempts of Russian hackers to infiltrate the Indian Navy and Air Force exams through the dark web. The Intelligence Department of Delhi Police were the ones who brought</description><pubDate>Wed, 12 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/russian-hackers-infiltrate-exams-of-indian-navy-and-air-force.png&quot; alt=&quot;Russian Hackers Infiltrate Exams of Indian Navy And Air Force&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Delhi Police’s has busted attempts of Russian hackers to infiltrate the Indian Navy and Air Force exams through the dark web. The Intelligence Department of Delhi Police were the ones who brought&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/russian-hackers-infiltrate-exams-of-indian-navy-and-air-force.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Alexa AI Attempts to murder a child</title><link>https://securityxp.com/articles/alexa-ai-attempts-to-murder-a-child/</link><guid isPermaLink="true">https://securityxp.com/articles/alexa-ai-attempts-to-murder-a-child/</guid><description>Amazon Alexa, also known simply as Alexa, is a virtual assistant technology largely based on a Polish speech synthesizer named Ivona, bought by Amazon in 2013. It was first used in the Amazon Echo ...</description><pubDate>Sun, 09 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/alexa-ai-attempts-to-murder-a-child.png&quot; alt=&quot;Alexa AI Attempts to murder a child&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Amazon Alexa, also known simply as Alexa, is a virtual assistant technology largely based on a Polish speech synthesizer named Ivona, bought by Amazon in 2013. It was first used in the Amazon Echo ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/alexa-ai-attempts-to-murder-a-child.png" length="0" type="image/png"/><category>AI/ML Security</category><author>Staff</author></item><item><title>France gonna Earn 210 Million Euro from fine on Cookies of facebook and google</title><link>https://securityxp.com/articles/france-gonna-earn-210-million-euro-from-cookies-of-facebook-and-google/</link><guid isPermaLink="true">https://securityxp.com/articles/france-gonna-earn-210-million-euro-from-cookies-of-facebook-and-google/</guid><description>Cookie Consent [Dark Pattern](&lt;https://www.darkpatterns.org/types-of-dark-pattern): Privacy Zuckering In a NutShell &apos;Following investigations, the CNIL noted that the websites facebook.com, google.f</description><pubDate>Fri, 07 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/01/image.svg&quot; alt=&quot;France gonna Earn 210 Million Euro from fine on Cookies of facebook and google&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Cookie Consent [Dark Pattern](&lt;https://www.darkpatterns.org/types-of-dark-pattern): Privacy Zuckering In a NutShell &apos;Following investigations, the CNIL noted that the websites facebook.com, google.f&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/01/image.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Gartner EDRs are not perfect, fail against common attacks</title><link>https://securityxp.com/articles/gartner-edrs-are-not-perfect-fail-against-common-attacks/</link><guid isPermaLink="true">https://securityxp.com/articles/gartner-edrs-are-not-perfect-fail-against-common-attacks/</guid><description>Advanced Persistent threats have been a pain for blue teams for a very long time, and one of the key tool in the arsenal is Endpoint Detection and Response tools since the recent past, however, the...</description><pubDate>Tue, 04 Jan 2022 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2022/01/jcp-01-00021-g001-1020x1024.svg&quot; alt=&quot;Gartner EDRs are not perfect, fail against common attacks&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Advanced Persistent threats have been a pain for blue teams for a very long time, and one of the key tool in the arsenal is Endpoint Detection and Response tools since the recent past, however, the...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2022/01/jcp-01-00021-g001-1020x1024.svg" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Useful Pentesting Resources</title><link>https://securityxp.com/articles/useful-pentesting-resources/</link><guid isPermaLink="true">https://securityxp.com/articles/useful-pentesting-resources/</guid><description>A curated list of useful penetration testing resources, tools, and references for security professionals.</description><pubDate>Tue, 07 Sep 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/useful-pentesting-resources.png&quot; alt=&quot;Useful Pentesting Resources&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;A curated list of useful penetration testing resources, tools, and references for security professionals.&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/useful-pentesting-resources.png" length="0" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>Staff</author></item><item><title>MITRE ATT&amp;CK® Released Updates in April 2021 With Additional Techniques and Structuring</title><link>https://securityxp.com/articles/mitre-attck-released-updates-in-april-2021-with-additional-techniques-and-structuring/</link><guid isPermaLink="true">https://securityxp.com/articles/mitre-attck-released-updates-in-april-2021-with-additional-techniques-and-structuring/</guid><description>MITRE ATT&amp;CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of ...</description><pubDate>Sun, 04 Jul 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2021/07/ATTCK_red.svg&quot; alt=&quot;MITRE ATT&amp;CK® Released Updates in April 2021 With Additional Techniques and Structuring&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;MITRE ATT&amp;CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&amp;CK knowledge base is used as a foundation for the development of ...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2021/07/ATTCK_red.svg" length="0" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>Staff</author></item><item><title>NSA Released D3FEND a framework for cybersecurity professionals to tailor defenses</title><link>https://securityxp.com/articles/nsa-released-d3fend-a-framework-for-cybersecurity-professionals-to-tailor-defenses/</link><guid isPermaLink="true">https://securityxp.com/articles/nsa-released-d3fend-a-framework-for-cybersecurity-professionals-to-tailor-defenses/</guid><description>Recently a Framework was Released by NSA named D3FEND which is based on and Complementary to MITRE ATT&amp;CK Framework. It gave a Technical Knowledge base to create Defensive Countermeasure against Co...</description><pubDate>Sun, 04 Jul 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/nsa-released-d3fend-a-framework-for-cybersecurity-professionals-to-tailor-defenses.png&quot; alt=&quot;NSA Released D3FEND a framework for cybersecurity professionals to tailor defenses&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Recently a Framework was Released by NSA named D3FEND which is based on and Complementary to MITRE ATT&amp;CK Framework. It gave a Technical Knowledge base to create Defensive Countermeasure against Co...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/nsa-released-d3fend-a-framework-for-cybersecurity-professionals-to-tailor-defenses.png" length="0" type="image/png"/><category>Cloud Security</category><author>Staff</author></item><item><title>Bharat Ranked in Tier 3 of IISS Cyber Capabilities and National Power: A Net Assessment</title><link>https://securityxp.com/articles/bharat-ranked-in-tier-3-of-iiss-cyber-capabilities-and-national-power-a-net-assessment/</link><guid isPermaLink="true">https://securityxp.com/articles/bharat-ranked-in-tier-3-of-iiss-cyber-capabilities-and-national-power-a-net-assessment/</guid><description>As a result of a Study conducted by IISS Researchers in the last two years, Bharat was ranked in Tier 3, it is to be noted that the US is the only nation in Tier one. Instead of Going the traditional</description><pubDate>Sat, 03 Jul 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/bharat-ranked-in-tier-3-of-iiss-cyber-capabilities-and-national-power-a-net-assessment.png&quot; alt=&quot;Bharat Ranked in Tier 3 of IISS Cyber Capabilities and National Power: A Net Assessment&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;As a result of a Study conducted by IISS Researchers in the last two years, Bharat was ranked in Tier 3, it is to be noted that the US is the only nation in Tier one. Instead of Going the traditional&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/bharat-ranked-in-tier-3-of-iiss-cyber-capabilities-and-national-power-a-net-assessment.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Penetration testing Attack Infrastructure</title><link>https://securityxp.com/articles/penetration-testing-attack-infrastructure/</link><guid isPermaLink="true">https://securityxp.com/articles/penetration-testing-attack-infrastructure/</guid><description>Attack Infra Penetration testing Planning Fill the planning gap Attack Infrastructure/C2 Recon Social Engineering Weaponization Initial Access/foothold Network Pro...</description><pubDate>Sat, 03 Jul 2021 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/penetration-testing-attack-infrastructure.png&quot; alt=&quot;Penetration testing Attack Infrastructure&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Attack Infra Penetration testing Planning Fill the planning gap Attack Infrastructure/C2 Recon Social Engineering Weaponization Initial Access/foothold Network Pro...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/penetration-testing-attack-infrastructure.png" length="0" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>Staff</author></item><item><title>Next-gen missile data, Hacked in Japan report says</title><link>https://securityxp.com/articles/next-gen-missile-data-hacked-in-japan-report-says/</link><guid isPermaLink="true">https://securityxp.com/articles/next-gen-missile-data-hacked-in-japan-report-says/</guid><description>The Japanese Defense Ministry is investigating a possible leak of details of a new state-of-the-art missile in a large-scale cyberattack on Mitsubishi Electric Corp, the Asahi Shimbun newspaper rep...</description><pubDate>Thu, 21 May 2020 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/next-gen-missile-data-hacked-in-japan-report-says.png&quot; alt=&quot;Next-gen missile data, Hacked in Japan report says&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;The Japanese Defense Ministry is investigating a possible leak of details of a new state-of-the-art missile in a large-scale cyberattack on Mitsubishi Electric Corp, the Asahi Shimbun newspaper rep...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/next-gen-missile-data-hacked-in-japan-report-says.png" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>BIAS: Bluetooth Impersonation AttackS</title><link>https://securityxp.com/articles/bias-bluetooth-impersonation-attacks/</link><guid isPermaLink="true">https://securityxp.com/articles/bias-bluetooth-impersonation-attacks/</guid><description>[Daniele Antonioli](&lt;https://francozappa.github.io/about-bias/authors/francozappa/) (Postdoc at the EPFL Cyber-Physical Systems Security, Network Security, Wireless Security, Embedded Systems Securit</description><pubDate>Wed, 20 May 2020 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/uploads/media/2020/05/2020-05-20-19_06_38--1024x484.svg&quot; alt=&quot;BIAS: Bluetooth Impersonation AttackS&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;[Daniele Antonioli](&lt;https://francozappa.github.io/about-bias/authors/francozappa/) (Postdoc at the EPFL Cyber-Physical Systems Security, Network Security, Wireless Security, Embedded Systems Securit&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/uploads/media/2020/05/2020-05-20-19_06_38--1024x484.svg" length="0" type="image/png"/><category>Threat Intelligence</category><author>Staff</author></item><item><title>Huawei dev team, buggy HKSP patch with backdoor and  Linux Foundation</title><link>https://securityxp.com/articles/huawei-dev-team-buggy-hksp-patch-with-backdoor-and-linux-foundation/</link><guid isPermaLink="true">https://securityxp.com/articles/huawei-dev-team-buggy-hksp-patch-with-backdoor-and-linux-foundation/</guid><description>Last week the Huawei development team submitted a patch to the Linux Foundation with a ‘trivial vulnerability.’ When the vulnerability was discovered, Huawei denied its involvement in the patch and...</description><pubDate>Mon, 18 May 2020 00:00:00 GMT</pubDate><content:encoded>
            &lt;p&gt;&lt;img src=&quot;https://securityxp.com/og-cards/huawei-dev-team-buggy-hksp-patch-with-backdoor-and-linux-foundation.png&quot; alt=&quot;Huawei dev team, buggy HKSP patch with backdoor and  Linux Foundation&quot; style=&quot;max-width: 100%; border-radius: 8px;&quot; /&gt;&lt;/p&gt;
            &lt;p&gt;Last week the Huawei development team submitted a patch to the Linux Foundation with a ‘trivial vulnerability.’ When the vulnerability was discovered, Huawei denied its involvement in the patch and...&lt;/p&gt;
          </content:encoded><enclosure url="https://securityxp.com/og-cards/huawei-dev-team-buggy-hksp-patch-with-backdoor-and-linux-foundation.png" length="0" type="image/png"/><category>Vulnerabilities &amp; Exploits</category><author>Staff</author></item></channel></rss>