<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Cybersecurity on Tenu Tech Brief</title>
    <link>https://cluster-site.onrender.com/categories/cybersecurity/</link>
    <description>Recent content in Cybersecurity on Tenu Tech Brief</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 26 Feb 2026 02:42:06 +0000</lastBuildDate>
    <atom:link href="https://cluster-site.onrender.com/categories/cybersecurity/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance &amp;#x5b;Guest Diary&amp;#x5d;, (Tue, Feb 24th)</title>
      <link>https://cluster-site.onrender.com/posts/finding-signal-in-the-noise-lessons-learned-running-a-honeypot-with-ai-assistance-%23x5bguest-diary%23x5d-tue-feb-24th/</link>
      <pubDate>Thu, 26 Feb 2026 02:11:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/finding-signal-in-the-noise-lessons-learned-running-a-honeypot-with-ai-assistance-%23x5bguest-diary%23x5d-tue-feb-24th/</guid>
      <description>• Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary] [This is a Guest Diary by Austin Bodolay, an ISC intern as part of the SANS • edu</description>
    </item>
    <item>
      <title>Chinese Police Use ChatGPT to Smear Japan PM Takaichi</title>
      <link>https://cluster-site.onrender.com/posts/chinese-police-use-chatgpt-to-smear-japan-pm-takaichi/</link>
      <pubDate>Thu, 26 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/chinese-police-use-chatgpt-to-smear-japan-pm-takaichi/</guid>
      <description>• A Chinese keyboard warrior inadvertently leaked information about politically motivated influence operations through a ChatGPT account</description>
    </item>
    <item>
      <title>Flaws in Claude Code Put Developers&#39; Machines at Risk</title>
      <link>https://cluster-site.onrender.com/posts/flaws-in-claude-code-put-developers-machines-at-risk/</link>
      <pubDate>Wed, 25 Feb 2026 22:02:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/flaws-in-claude-code-put-developers-machines-at-risk/</guid>
      <description>• The vulnerabilities highlight a big drawback to integrating AI into software development workflows and the potential impact on supply chains</description>
    </item>
    <item>
      <title>Fake Next.js job interview tests backdoor developer&#39;s devices</title>
      <link>https://cluster-site.onrender.com/posts/fake-next.js-job-interview-tests-backdoor-developers-devices/</link>
      <pubDate>Wed, 25 Feb 2026 21:47:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-next.js-job-interview-tests-backdoor-developers-devices/</guid>
      <description>• js job interview tests backdoor developer&amp;rsquo;s devices February 25, 2026 04:47 PM 0 A coordinated campaign targeting software developers with job-themed lures is using malicious rep</description>
    </item>
    <item>
      <title>RAMP Forum Seizure Fractures Ransomware Ecosystem</title>
      <link>https://cluster-site.onrender.com/posts/ramp-forum-seizure-fractures-ransomware-ecosystem/</link>
      <pubDate>Wed, 25 Feb 2026 21:14:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ramp-forum-seizure-fractures-ransomware-ecosystem/</guid>
      <description>• Researchers suggest defenders monitor how these malicious groups re-form and leverage the useful threat intel to guide their next moves</description>
    </item>
    <item>
      <title>The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies &amp;#x5b;Guest Diary&amp;#x5d;, (Wed,...</title>
      <link>https://cluster-site.onrender.com/posts/the-clair-model-a-synthesized-conceptual-framework-for-mapping-critical-infrastructure-interdependencies-%23x5bguest-diary%23x5d-wed.../</link>
      <pubDate>Wed, 25 Feb 2026 21:09:28 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-clair-model-a-synthesized-conceptual-framework-for-mapping-critical-infrastructure-interdependencies-%23x5bguest-diary%23x5d-wed.../</guid>
      <description>• The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary] [This is a guest diary contributed by Claire Perry (Linked</description>
    </item>
    <item>
      <title>PCI Council Says Threats to Payments Systems Are Speeding Up</title>
      <link>https://cluster-site.onrender.com/posts/pci-council-says-threats-to-payments-systems-are-speeding-up/</link>
      <pubDate>Wed, 25 Feb 2026 19:15:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pci-council-says-threats-to-payments-systems-are-speeding-up/</guid>
      <description>• The PCI Security Standards Council experienced a record year in many regards, but its first annual report shows it needs to work even faster to stay ahead of attackers</description>
    </item>
    <item>
      <title>Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries</title>
      <link>https://cluster-site.onrender.com/posts/google-disrupts-unc2814-gridtide-campaign-after-53-breaches-across-42-countries/</link>
      <pubDate>Wed, 25 Feb 2026 17:46:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-disrupts-unc2814-gridtide-campaign-after-53-breaches-across-42-countries/</guid>
      <description>• Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries Google on Wednesday disclosed that it worked with industry partners to disrupt the infrastructure</description>
    </item>
    <item>
      <title>Chinese cyberspies breached dozens of telecom firms, govt agencies</title>
      <link>https://cluster-site.onrender.com/posts/chinese-cyberspies-breached-dozens-of-telecom-firms-govt-agencies/</link>
      <pubDate>Wed, 25 Feb 2026 17:00:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/chinese-cyberspies-breached-dozens-of-telecom-firms-govt-agencies/</guid>
      <description>• Chinese cyberspies breached dozens of telecom firms, govt agencies February 25, 2026 12:00 PM 0 Google&amp;rsquo;s Threat Intelligence Group (GTIG), Mandiant, and partners disrupted a glob</description>
    </item>
    <item>
      <title>Malicious Next.js Repos Target Developers Via Fake Job Interviews</title>
      <link>https://cluster-site.onrender.com/posts/malicious-next.js-repos-target-developers-via-fake-job-interviews/</link>
      <pubDate>Wed, 25 Feb 2026 16:42:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-next.js-repos-target-developers-via-fake-job-interviews/</guid>
      <description>• Linked to North Korean fake job-recruitment campaigns, the poisoned repositories are aimed at establishing persistent access to infected machines</description>
    </item>
    <item>
      <title>The Blast Radius Problem: Stolen Credentials are Weaponizing Agentic AI</title>
      <link>https://cluster-site.onrender.com/posts/the-blast-radius-problem-stolen-credentials-are-weaponizing-agentic-ai/</link>
      <pubDate>Wed, 25 Feb 2026 16:16:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-blast-radius-problem-stolen-credentials-are-weaponizing-agentic-ai/</guid>
      <description>• Weak access controls, AI confusion, and the interconnection of business continue to expand Threat • More than half (56%) of the 400,000 vulnerabilities IBM X-Force tracked in 202</description>
    </item>
    <item>
      <title>Google Disrupts Chinese Cyberespionage Campaign Targeting Telecoms, Governments</title>
      <link>https://cluster-site.onrender.com/posts/google-disrupts-chinese-cyberespionage-campaign-targeting-telecoms-governments/</link>
      <pubDate>Wed, 25 Feb 2026 16:01:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-disrupts-chinese-cyberespionage-campaign-targeting-telecoms-governments/</guid>
      <description>• Google announced on Wednesday that it has disrupted a significant China-linked cyberespionage campaign targeting telecoms and government organizations worldwide • The threat acto</description>
    </item>
    <item>
      <title>Marquis sues SonicWall over backup breach that led to ransomware attack</title>
      <link>https://cluster-site.onrender.com/posts/marquis-sues-sonicwall-over-backup-breach-that-led-to-ransomware-attack/</link>
      <pubDate>Wed, 25 Feb 2026 15:54:44 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/marquis-sues-sonicwall-over-backup-breach-that-led-to-ransomware-attack/</guid>
      <description>• Marquis sues SonicWall over backup breach that led to ransomware attack February 25, 2026 10:54 AM 0 Marquis Software Solutions has filed a lawsuit against SonicWall, accusing th</description>
    </item>
    <item>
      <title>SLH Offers $500-$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks</title>
      <link>https://cluster-site.onrender.com/posts/slh-offers-500-1000-per-call-to-recruit-women-for-it-help-desk-vishing-attacks/</link>
      <pubDate>Wed, 25 Feb 2026 15:06:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/slh-offers-500-1000-per-call-to-recruit-women-for-it-help-desk-vishing-attacks/</guid>
      <description>• SLH Offers $500-$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks The notorious cybercrime collective known asScattered LAPSUS$ Hunters(SLH) has been observed off</description>
    </item>
    <item>
      <title>The OpenClaw Hype: Analysis of Chatter from Open-Source Deep and Dark Web</title>
      <link>https://cluster-site.onrender.com/posts/the-openclaw-hype-analysis-of-chatter-from-open-source-deep-and-dark-web/</link>
      <pubDate>Wed, 25 Feb 2026 15:01:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-openclaw-hype-analysis-of-chatter-from-open-source-deep-and-dark-web/</guid>
      <description>• The OpenClaw Hype: Analysis of Chatter from Open-Source Deep and Dark Web February 25, 2026 10:01 AM 0 OpenClaw started as a side project of a developer who wanted to make his (a</description>
    </item>
    <item>
      <title>Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It</title>
      <link>https://cluster-site.onrender.com/posts/top-5-ways-broken-triage-increases-business-risk-instead-of-reducing-it/</link>
      <pubDate>Wed, 25 Feb 2026 14:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/top-5-ways-broken-triage-increases-business-risk-instead-of-reducing-it/</guid>
      <description>• Triage is supposed to make things simpler • In a lot of teams, it does the opposite • When you can&amp;rsquo;t reach a confident verdict early, alerts turn into repeat checks, back-and-for</description>
    </item>
    <item>
      <title>Why &#39;Call This Number&#39; TOAD Emails Beat Gateways</title>
      <link>https://cluster-site.onrender.com/posts/why-call-this-number-toad-emails-beat-gateways/</link>
      <pubDate>Wed, 25 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/why-call-this-number-toad-emails-beat-gateways/</guid>
      <description>• Attackers are bypassing email gateways through telephone-oriented attack delivery (TOAD), in which the only email payload is a phone number</description>
    </item>
    <item>
      <title>Medical Device Maker UFP Technologies Hit by Cyberattack</title>
      <link>https://cluster-site.onrender.com/posts/medical-device-maker-ufp-technologies-hit-by-cyberattack/</link>
      <pubDate>Wed, 25 Feb 2026 13:40:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/medical-device-maker-ufp-technologies-hit-by-cyberattack/</guid>
      <description>• Medical device manufacturer UFP Technologies on Tuesday disclosed a cybersecurity incident that involved the theft of files and the disruption of some IT systems • UFP Technologi</description>
    </item>
    <item>
      <title>Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia</title>
      <link>https://cluster-site.onrender.com/posts/ex-us-defense-contractor-executive-jailed-for-selling-exploits-to-russia/</link>
      <pubDate>Wed, 25 Feb 2026 12:59:30 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ex-us-defense-contractor-executive-jailed-for-selling-exploits-to-russia/</guid>
      <description>• An Australian national was sentenced to 87 months in a US prison for stealing trade secrets from a defense contractor and selling them to a Russian cyber-exploit broker • Accordi</description>
    </item>
    <item>
      <title>Zyxel warns of critical RCE flaw affecting over a dozen routers</title>
      <link>https://cluster-site.onrender.com/posts/zyxel-warns-of-critical-rce-flaw-affecting-over-a-dozen-routers/</link>
      <pubDate>Wed, 25 Feb 2026 12:53:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zyxel-warns-of-critical-rce-flaw-affecting-over-a-dozen-routers/</guid>
      <description>• Zyxel warns of critical RCE flaw affecting over a dozen routers February 25, 2026 07:53 AM 0 Taiwan networking provider Zyxel has released security updates to address a critical</description>
    </item>
    <item>
      <title>Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware</title>
      <link>https://cluster-site.onrender.com/posts/malicious-nuget-packages-stole-asp.net-data-npm-package-dropped-malware/</link>
      <pubDate>Wed, 25 Feb 2026 12:43:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-nuget-packages-stole-asp.net-data-npm-package-dropped-malware/</guid>
      <description>• Malicious NuGet Packages Stole ASP • NET Data; npm Package Dropped Malware Cybersecurity researchers have discovered four malicious NuGet packages that are designed to target ASP</description>
    </item>
    <item>
      <title>Over 12 Million Users Impacted by CarGurus Data Breach</title>
      <link>https://cluster-site.onrender.com/posts/over-12-million-users-impacted-by-cargurus-data-breach/</link>
      <pubDate>Wed, 25 Feb 2026 12:32:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/over-12-million-users-impacted-by-cargurus-data-breach/</guid>
      <description>• More than 12 million users have been affected by a data breach at automotive research and shopping website CarGurus.The incident was disclosed last week, when the infamous extort</description>
    </item>
    <item>
      <title>&#39;Richter Scale&#39; Model Measures Magnitude of OT Cyber Incidents</title>
      <link>https://cluster-site.onrender.com/posts/richter-scale-model-measures-magnitude-of-ot-cyber-incidents/</link>
      <pubDate>Wed, 25 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/richter-scale-model-measures-magnitude-of-ot-cyber-incidents/</guid>
      <description>• ICS/OT experts have devised a scoring system for rating the severity and effects of cybersecurity events in operational technology environments.</description>
    </item>
    <item>
      <title>Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems</title>
      <link>https://cluster-site.onrender.com/posts/immediate-action-required-cisa-issues-emergency-directive-to-secure-cisco-sd-wan-systems/</link>
      <pubDate>Wed, 25 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/immediate-action-required-cisa-issues-emergency-directive-to-secure-cisco-sd-wan-systems/</guid>
      <description>• Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today issuedEme</description>
    </item>
    <item>
      <title>Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site</title>
      <link>https://cluster-site.onrender.com/posts/wynn-resorts-confirms-data-breach-after-hackers-remove-it-from-leak-site/</link>
      <pubDate>Wed, 25 Feb 2026 11:35:48 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wynn-resorts-confirms-data-breach-after-hackers-remove-it-from-leak-site/</guid>
      <description>• Las Vegas-based high-end casino and hotel operator Wynn Resorts has confirmed that hackers have stolen employee data.&amp;lsquo;We have learned that an unauthorized third party acquired ce</description>
    </item>
    <item>
      <title>Manual Processes Are Putting National Security at Risk</title>
      <link>https://cluster-site.onrender.com/posts/manual-processes-are-putting-national-security-at-risk/</link>
      <pubDate>Wed, 25 Feb 2026 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/manual-processes-are-putting-national-security-at-risk/</guid>
      <description>• Why automating sensitive data transfers is now a mission-critical priority More than half of national security organizations still rely on manual processes to transfer sensitive</description>
    </item>
    <item>
      <title>Astelia Raises $35 Million for Exposure Management</title>
      <link>https://cluster-site.onrender.com/posts/astelia-raises-35-million-for-exposure-management/</link>
      <pubDate>Wed, 25 Feb 2026 10:38:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/astelia-raises-35-million-for-exposure-management/</guid>
      <description>• Cybersecurity startup Astelia has announced raising $35 million in seed and Series A funding. • The investment was led by Index Ventures and Team8, with additional support from H</description>
    </item>
    <item>
      <title>US sanctions Russian broker for buying stolen zero-day exploits</title>
      <link>https://cluster-site.onrender.com/posts/us-sanctions-russian-broker-for-buying-stolen-zero-day-exploits/</link>
      <pubDate>Wed, 25 Feb 2026 10:31:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/us-sanctions-russian-broker-for-buying-stolen-zero-day-exploits/</guid>
      <description>• US sanctions Russian broker for buying stolen zero-day exploits February 25, 2026 05:31 AM 0 The U.S. • Treasury Department has sanctioned a Russian exploit broker who bought sto</description>
    </item>
    <item>
      <title>Reddit Hit With $20 Million UK Data Privacy Fine Over Child Safety Failings</title>
      <link>https://cluster-site.onrender.com/posts/reddit-hit-with-20-million-uk-data-privacy-fine-over-child-safety-failings/</link>
      <pubDate>Wed, 25 Feb 2026 10:04:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/reddit-hit-with-20-million-uk-data-privacy-fine-over-child-safety-failings/</guid>
      <description>• Britain&amp;rsquo;s data privacy watchdog slapped online forum Reddit on Tuesday with a fine worth nearly $20 million for failures involving children&amp;rsquo;s personal information • The Informati</description>
    </item>
    <item>
      <title>Claude&#39;s New AI Vulnerability Scanner Sends Cybersecurity Shares Plunging</title>
      <link>https://cluster-site.onrender.com/posts/claudes-new-ai-vulnerability-scanner-sends-cybersecurity-shares-plunging/</link>
      <pubDate>Wed, 25 Feb 2026 09:44:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/claudes-new-ai-vulnerability-scanner-sends-cybersecurity-shares-plunging/</guid>
      <description>• The stocks of major cybersecurity companies have fallen sharply after AI firm Anthropic unveiled a new security capability for its Claude LLM.Anthropic announced on Friday that i</description>
    </item>
    <item>
      <title>Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker</title>
      <link>https://cluster-site.onrender.com/posts/defense-contractor-employee-jailed-for-selling-8-zero-days-to-russian-broker/</link>
      <pubDate>Wed, 25 Feb 2026 08:49:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/defense-contractor-employee-jailed-for-selling-8-zero-days-to-russian-broker/</guid>
      <description>• Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker A 39-year-old Australian national who was previously employed at U.S. • defense contractor L3Harris h</description>
    </item>
    <item>
      <title>Ad Tech Company Optimizely Targeted in Cyberattack</title>
      <link>https://cluster-site.onrender.com/posts/ad-tech-company-optimizely-targeted-in-cyberattack/</link>
      <pubDate>Wed, 25 Feb 2026 08:23:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ad-tech-company-optimizely-targeted-in-cyberattack/</guid>
      <description>• Ad tech firm Optimizely has confirmed that threat actors accessed certain internal business systems through a sophisticated voice phishing (vishing) attack.The incident, the comp</description>
    </item>
    <item>
      <title>Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker</title>
      <link>https://cluster-site.onrender.com/posts/ex-l3harris-exec-jailed-for-selling-zero-days-to-russian-exploit-broker/</link>
      <pubDate>Wed, 25 Feb 2026 08:21:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ex-l3harris-exec-jailed-for-selling-zero-days-to-russian-exploit-broker/</guid>
      <description>• Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker February 25, 2026 03:21 AM 0 The former head of Trenchant, a specialized U.S. • defense contractor unit, w</description>
    </item>
    <item>
      <title>Operation Red Card 2.0 Leads to 651 Arrests in Africa</title>
      <link>https://cluster-site.onrender.com/posts/operation-red-card-2.0-leads-to-651-arrests-in-africa/</link>
      <pubDate>Wed, 25 Feb 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/operation-red-card-2.0-leads-to-651-arrests-in-africa/</guid>
      <description>• In the latest operation targeting cybercrime groups, African law enforcement agencies cooperated with Interpol and cybersecurity firms to recover more than USD 4.3 million.</description>
    </item>
    <item>
      <title>Windows 11 KB5077241 update improves BitLocker, adds Sysmon tool</title>
      <link>https://cluster-site.onrender.com/posts/windows-11-kb5077241-update-improves-bitlocker-adds-sysmon-tool/</link>
      <pubDate>Wed, 25 Feb 2026 07:51:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/windows-11-kb5077241-update-improves-bitlocker-adds-sysmon-tool/</guid>
      <description>• Windows 11 KB5077241 update improves BitLocker, adds Sysmon tool February 25, 2026 02:51 AM 0 Microsoft has released the KB5077241 optional cumulative update for Windows 11, whic</description>
    </item>
    <item>
      <title>SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution</title>
      <link>https://cluster-site.onrender.com/posts/solarwinds-patches-4-critical-serv-u-15.5-flaws-allowing-root-code-execution/</link>
      <pubDate>Wed, 25 Feb 2026 07:04:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/solarwinds-patches-4-critical-serv-u-15.5-flaws-allowing-root-code-execution/</guid>
      <description>• SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution SolarWinds hasreleased updatesto address four critical security flaws in its Serv-U file transfer sof</description>
    </item>
    <item>
      <title>Phishing campaign targets freight and logistics orgs in the US, Europe</title>
      <link>https://cluster-site.onrender.com/posts/phishing-campaign-targets-freight-and-logistics-orgs-in-the-us-europe/</link>
      <pubDate>Tue, 24 Feb 2026 23:57:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/phishing-campaign-targets-freight-and-logistics-orgs-in-the-us-europe/</guid>
      <description>• Phishing campaign targets freight and logistics orgs in the US, Europe February 24, 2026 06:57 PM 0 A financially motivated threat group dubbed &amp;lsquo;Diesel Vortex&amp;rsquo; is stealing creden</description>
    </item>
    <item>
      <title>Wynn Resorts confirms employee data breach after extortion threat</title>
      <link>https://cluster-site.onrender.com/posts/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/</link>
      <pubDate>Tue, 24 Feb 2026 21:51:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/</guid>
      <description>• Wynn Resorts confirms employee data breach after extortion threat February 24, 2026 04:51 PM 0 Wynn Resorts has confirmed that a hacker stole employee data from its systems after</description>
    </item>
    <item>
      <title>1Campaign platform helps malicious Google ads evade detection</title>
      <link>https://cluster-site.onrender.com/posts/1campaign-platform-helps-malicious-google-ads-evade-detection/</link>
      <pubDate>Tue, 24 Feb 2026 21:45:05 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/1campaign-platform-helps-malicious-google-ads-evade-detection/</guid>
      <description>• 1Campaign platform helps malicious Google ads evade detection February 24, 2026 04:45 PM 0 A newly identified cybercrime service known as 1Campaign is enabling threat actors to r</description>
    </item>
    <item>
      <title>Attackers Now Need Just 29 Minutes to Own a Network</title>
      <link>https://cluster-site.onrender.com/posts/attackers-now-need-just-29-minutes-to-own-a-network/</link>
      <pubDate>Tue, 24 Feb 2026 21:38:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/attackers-now-need-just-29-minutes-to-own-a-network/</guid>
      <description>• Credential misuse, AI tools, and security blind spots help attackers move through breached networks faster than ever, CrowdStrike finds.</description>
    </item>
    <item>
      <title>Lazarus Group Picks a New Poison: Medusa Ransomware</title>
      <link>https://cluster-site.onrender.com/posts/lazarus-group-picks-a-new-poison-medusa-ransomware/</link>
      <pubDate>Tue, 24 Feb 2026 21:18:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lazarus-group-picks-a-new-poison-medusa-ransomware/</guid>
      <description>• Cyberattacks &amp;amp; Data Breaches Cyber Risk Endpoint Security Threat Intelligence News Lazarus Group Picks a New Poison: Medusa Ransomware The North Korean threat group also leverage</description>
    </item>
    <item>
      <title>RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN</title>
      <link>https://cluster-site.onrender.com/posts/roguepilot-flaw-in-github-codespaces-enabled-copilot-to-leak-github_token/</link>
      <pubDate>Tue, 24 Feb 2026 18:52:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/roguepilot-flaw-in-github-codespaces-enabled-copilot-to-leak-github_token/</guid>
      <description>• RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN A vulnerability inGitHub Codespacescould have been exploited by bad actors to seize control of repositor</description>
    </item>
    <item>
      <title>CarGurus data breach exposes information of 12.4 million accounts</title>
      <link>https://cluster-site.onrender.com/posts/cargurus-data-breach-exposes-information-of-12.4-million-accounts/</link>
      <pubDate>Tue, 24 Feb 2026 18:08:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cargurus-data-breach-exposes-information-of-12.4-million-accounts/</guid>
      <description>• CarGurus data breach exposes information of 12.4 million accounts February 24, 2026 01:08 PM 0 The ShinyHunters extortion group has published personal information in more than 12</description>
    </item>
    <item>
      <title>Open Redirects: A Forgotten Vulnerability&amp;#x3f;, (Tue, Feb 24th)</title>
      <link>https://cluster-site.onrender.com/posts/open-redirects-a-forgotten-vulnerability%23x3f-tue-feb-24th/</link>
      <pubDate>Tue, 24 Feb 2026 18:04:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/open-redirects-a-forgotten-vulnerability%23x3f-tue-feb-24th/</guid>
      <description>• Open Redirects: A Forgotten Vulnerability? • In 2010, OWASP added &amp;lsquo;Unvalidated Redirects and Forwards&amp;rsquo; to its Top 10 list and merged it into &amp;lsquo;Sensitive Data Exposure&amp;rsquo; in 2013 [ow</description>
    </item>
    <item>
      <title>Microsoft adds Copilot data controls to all storage locations</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-adds-copilot-data-controls-to-all-storage-locations/</link>
      <pubDate>Tue, 24 Feb 2026 17:30:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-adds-copilot-data-controls-to-all-storage-locations/</guid>
      <description>• Microsoft adds Copilot data controls to all storage locations February 24, 2026 12:30 PM 0 Microsoft is expanding data loss prevention (DLP) controls to block the Microsoft 365 C</description>
    </item>
    <item>
      <title>Developer-targeting campaign using malicious Next.js repositories</title>
      <link>https://cluster-site.onrender.com/posts/developer-targeting-campaign-using-malicious-next.js-repositories/</link>
      <pubDate>Tue, 24 Feb 2026 17:28:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/developer-targeting-campaign-using-malicious-next.js-repositories/</guid>
      <description>• Microsoft Defender Experts identified a coordinated developer-targeting campaign delivered through malicious repositories disguised as legitimate Next.js projects and technical a</description>
    </item>
    <item>
      <title>&#39;Arkanix Stealer&#39; Malware Disappears Shortly After Debut</title>
      <link>https://cluster-site.onrender.com/posts/arkanix-stealer-malware-disappears-shortly-after-debut/</link>
      <pubDate>Tue, 24 Feb 2026 15:20:06 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/arkanix-stealer-malware-disappears-shortly-after-debut/</guid>
      <description>• A new infostealer named &amp;lsquo;Arkanix Stealer&amp;rsquo; operated as a malware-as-a-service (MaaS) enterprise in a one-shot campaign, Kaspersky says.Implemented in both C++ and Python, the malw</description>
    </item>
    <item>
      <title>Identity-First AI Security: Why CISOs Must Add Intent to the Equation</title>
      <link>https://cluster-site.onrender.com/posts/identity-first-ai-security-why-cisos-must-add-intent-to-the-equation/</link>
      <pubDate>Tue, 24 Feb 2026 15:02:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/identity-first-ai-security-why-cisos-must-add-intent-to-the-equation/</guid>
      <description>• Identity-First AI Security: Why CISOs Must Add Intent to the Equation February 24, 2026 10:02 AM 0 Author: Itamar Apelblat, CEO and Co-Founder, Token Security Not long ago, AI de</description>
    </item>
    <item>
      <title>UK fines Reddit $19 million for using children&#39;s data unlawfully</title>
      <link>https://cluster-site.onrender.com/posts/uk-fines-reddit-19-million-for-using-childrens-data-unlawfully/</link>
      <pubDate>Tue, 24 Feb 2026 14:54:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/uk-fines-reddit-19-million-for-using-childrens-data-unlawfully/</guid>
      <description>• UK fines Reddit $19 million for using children&amp;rsquo;s data unlawfully February 24, 2026 09:54 AM 0 The UK Information Commissioner&amp;rsquo;s Office (ICO) has fined Reddit £14.47 million (over</description>
    </item>
    <item>
      <title>VMware Aria Operations Vulnerability Could Allow Remote Code Execution</title>
      <link>https://cluster-site.onrender.com/posts/vmware-aria-operations-vulnerability-could-allow-remote-code-execution/</link>
      <pubDate>Tue, 24 Feb 2026 14:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vmware-aria-operations-vulnerability-could-allow-remote-code-execution/</guid>
      <description>• Broadcom has released patches for several vulnerabilities affecting VMware Aria Operations, including high-severity flaws.The most important of the newly patched vulnerabilities</description>
    </item>
    <item>
      <title>UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware</title>
      <link>https://cluster-site.onrender.com/posts/uac-0050-targets-european-financial-institution-with-spoofed-domain-and-rms-malware/</link>
      <pubDate>Tue, 24 Feb 2026 14:21:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/uac-0050-targets-european-financial-institution-with-spoofed-domain-and-rms-malware/</guid>
      <description>• UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware A Russia-aligned threat actor has been observed targeting a European financial institution as</description>
    </item>
    <item>
      <title>Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security</title>
      <link>https://cluster-site.onrender.com/posts/bring-the-fight-to-the-edge-turning-time-into-an-advantage-in-ot-security/</link>
      <pubDate>Tue, 24 Feb 2026 14:00:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/bring-the-fight-to-the-edge-turning-time-into-an-advantage-in-ot-security/</guid>
      <description>• Why OT Defenses Often Start Too Late Industrial organizations are facing a growing paradox in cybersecurity. • While operational technology (OT) environments are increasingly con</description>
    </item>
    <item>
      <title>CISO Conversations: Timothy Youngblood; 4x Fortune 500 CISO/CSO</title>
      <link>https://cluster-site.onrender.com/posts/ciso-conversations-timothy-youngblood-4x-fortune-500-ciso/cso/</link>
      <pubDate>Tue, 24 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ciso-conversations-timothy-youngblood-4x-fortune-500-ciso/cso/</guid>
      <description>• Timothy Youngblood didn&amp;rsquo;t set out to be a CISO, but he became CISO at four major enterprises, took on angel investing and won the Most Valued Member award at the Summer Investor</description>
    </item>
    <item>
      <title>New &#39;Sandworm_Mode&#39; Supply Chain Attack Hits NPM</title>
      <link>https://cluster-site.onrender.com/posts/new-sandworm_mode-supply-chain-attack-hits-npm/</link>
      <pubDate>Tue, 24 Feb 2026 13:40:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-sandworm_mode-supply-chain-attack-hits-npm/</guid>
      <description>• Security researchers have uncovered a new supply chain attack targeting the NPM registry with malicious code that exhibits worm-like propagation capabilities.DubbedSandworm_Mode,</description>
    </item>
    <item>
      <title>As Cybersecurity Firms Chase AI, VC Market Skyrockets</title>
      <link>https://cluster-site.onrender.com/posts/as-cybersecurity-firms-chase-ai-vc-market-skyrockets/</link>
      <pubDate>Tue, 24 Feb 2026 13:04:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/as-cybersecurity-firms-chase-ai-vc-market-skyrockets/</guid>
      <description>• Investments in cybersecurity startups took off in 2025, as venture capital firms focused not just on AI-native tech, but talent as well.</description>
    </item>
    <item>
      <title>Scaling security operations with Microsoft Defender autonomous defense and expert-led services</title>
      <link>https://cluster-site.onrender.com/posts/scaling-security-operations-with-microsoft-defender-autonomous-defense-and-expert-led-services/</link>
      <pubDate>Tue, 24 Feb 2026 13:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scaling-security-operations-with-microsoft-defender-autonomous-defense-and-expert-led-services/</guid>
      <description>• Share Link copied to clipboard! • Content types Best practices Products and services Microsoft Defender Microsoft Security Experts Topics AI and agents Security management Securi</description>
    </item>
    <item>
      <title>GitHub Issues Abused in Copilot Attack Leading to Repository Takeover</title>
      <link>https://cluster-site.onrender.com/posts/github-issues-abused-in-copilot-attack-leading-to-repository-takeover/</link>
      <pubDate>Tue, 24 Feb 2026 12:26:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/github-issues-abused-in-copilot-attack-leading-to-repository-takeover/</guid>
      <description>• A vulnerability in GitHub Codespaces could have allowed attackers to take over repositories by injecting malicious Copilot instructions in a GitHub issue.The attack, Orca Securit</description>
    </item>
    <item>
      <title>Is AI Good for Democracy?</title>
      <link>https://cluster-site.onrender.com/posts/is-ai-good-for-democracy/</link>
      <pubDate>Tue, 24 Feb 2026 12:06:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/is-ai-good-for-democracy/</guid>
      <description>• Is AI Good for Democracy? • Politicians fixate on the global race for technological supremacy between US and China. • They debate geopolitical implications of chip exports, lates</description>
    </item>
    <item>
      <title>Taiwan Security Firm Confirms Flaw Flagged by CISA Likely Exploited by Chinese APTs</title>
      <link>https://cluster-site.onrender.com/posts/taiwan-security-firm-confirms-flaw-flagged-by-cisa-likely-exploited-by-chinese-apts/</link>
      <pubDate>Tue, 24 Feb 2026 12:00:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/taiwan-security-firm-confirms-flaw-flagged-by-cisa-likely-exploited-by-chinese-apts/</guid>
      <description>• The Taiwan-based cybersecurity firm TeamT5 has confirmed that the vulnerability added recently by CISA to its Known Exploited Vulnerabilities (KEV) catalog was likely exploited b</description>
    </item>
    <item>
      <title>Identity Prioritization isn&#39;t a Backlog Problem - It&#39;s a Risk Math Problem</title>
      <link>https://cluster-site.onrender.com/posts/identity-prioritization-isnt-a-backlog-problem-its-a-risk-math-problem/</link>
      <pubDate>Tue, 24 Feb 2026 11:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/identity-prioritization-isnt-a-backlog-problem-its-a-risk-math-problem/</guid>
      <description>• Most identity programs still prioritize work the way they prioritize IT tickets: by volume, loudness, or &amp;lsquo;what failed a control check.&amp;rsquo; That approach breaks the moment your envir</description>
    </item>
    <item>
      <title>Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks</title>
      <link>https://cluster-site.onrender.com/posts/lazarus-group-uses-medusa-ransomware-in-middle-east-and-u.s.-healthcare-attacks/</link>
      <pubDate>Tue, 24 Feb 2026 11:52:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lazarus-group-uses-medusa-ransomware-in-middle-east-and-u.s.-healthcare-attacks/</guid>
      <description>• Lazarus Group Uses Medusa Ransomware in Middle East and U.S. • Healthcare Attacks The North Korea-linkedLazarus Group(aka Diamond Sleet and Pompilus) has been observed using Medu</description>
    </item>
    <item>
      <title>ShinyHunters extortion gang claims Odido breach affecting millions</title>
      <link>https://cluster-site.onrender.com/posts/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/</link>
      <pubDate>Tue, 24 Feb 2026 11:40:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/</guid>
      <description>• ShinyHunters extortion gang claims Odido breach affecting millions February 24, 2026 06:40 AM 0 The ShinyHunters extortion gang has claimed responsibility for breaching Dutch tel</description>
    </item>
    <item>
      <title>North Korean Lazarus group linked to Medusa ransomware attacks</title>
      <link>https://cluster-site.onrender.com/posts/north-korean-lazarus-group-linked-to-medusa-ransomware-attacks/</link>
      <pubDate>Tue, 24 Feb 2026 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/north-korean-lazarus-group-linked-to-medusa-ransomware-attacks/</guid>
      <description>• North Korean Lazarus group linked to Medusa ransomware attacks February 24, 2026 06:00 AM 0 North Korean state-backed hackers associated with the Lazarus threat group are targeti</description>
    </item>
    <item>
      <title>Anonymous Fénix Members Arrested in Spain</title>
      <link>https://cluster-site.onrender.com/posts/anonymous-f%C3%A9nix-members-arrested-in-spain/</link>
      <pubDate>Tue, 24 Feb 2026 10:05:57 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anonymous-f%C3%A9nix-members-arrested-in-spain/</guid>
      <description>• Spanish authorities this week announced the arrest of four members of the Anonymous Fénix group for their involvement in distributed denial-of-service (DDoS) attacks.The suspects</description>
    </item>
    <item>
      <title>UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors</title>
      <link>https://cluster-site.onrender.com/posts/unsolicitedbooker-targets-central-asian-telecoms-with-lucidoor-and-marssnake-backdoors/</link>
      <pubDate>Tue, 24 Feb 2026 09:54:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/unsolicitedbooker-targets-central-asian-telecoms-with-lucidoor-and-marssnake-backdoors/</guid>
      <description>• UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors The threat activity cluster known asUnsolicitedBookerhas been observed targeting telecommun</description>
    </item>
    <item>
      <title>CrowdStrike 2026 Global Threat Report AI Evasive Adversary</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-2026-global-threat-report-ai-evasive-adversary/</link>
      <pubDate>Tue, 24 Feb 2026 08:32:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-2026-global-threat-report-ai-evasive-adversary/</guid>
      <description>• 2026 Global Threat Report highlights AI‑driven adversaries employing evasive tactics across industries. • Report identifies 59 zero‑day CVEs patched in February, underscoring rap</description>
    </item>
    <item>
      <title>Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model</title>
      <link>https://cluster-site.onrender.com/posts/anthropic-says-chinese-ai-firms-used-16-million-claude-queries-to-copy-model/</link>
      <pubDate>Tue, 24 Feb 2026 06:04:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anthropic-says-chinese-ai-firms-used-16-million-claude-queries-to-copy-model/</guid>
      <description>• Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model Anthropic on Monday said it identified &amp;lsquo;industrial-scale campaigns&amp;rsquo; mounted by three artificial intel</description>
    </item>
    <item>
      <title>ISC Stormcast For Tuesday, February 24th, 2026 https://isc.sans.edu/podcastdetail/9822, (Tue, Feb 24th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-tuesday-february-24th-2026-https/isc.sans.edu/podcastdetail/9822-tue-feb-24th/</link>
      <pubDate>Tue, 24 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-tuesday-february-24th-2026-https/isc.sans.edu/podcastdetail/9822-tue-feb-24th/</guid>
      <description>• ISC Stormcast For Tuesday, February 24th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9822&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9822&lt;/a&gt;
 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security:</description>
    </item>
    <item>
      <title>Android mental health apps with 14.7M installs filled with security flaws</title>
      <link>https://cluster-site.onrender.com/posts/android-mental-health-apps-with-14.7m-installs-filled-with-security-flaws/</link>
      <pubDate>Mon, 23 Feb 2026 22:59:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/android-mental-health-apps-with-14.7m-installs-filled-with-security-flaws/</guid>
      <description>• Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users&amp;rsquo; sensitive medical information. • In one of t</description>
    </item>
    <item>
      <title>Spitting Cash: ATM Jackpotting Attacks Surged in 2025</title>
      <link>https://cluster-site.onrender.com/posts/spitting-cash-atm-jackpotting-attacks-surged-in-2025/</link>
      <pubDate>Mon, 23 Feb 2026 22:20:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spitting-cash-atm-jackpotting-attacks-surged-in-2025/</guid>
      <description>• The attacks cost banks more than $20 million in losses last year, as criminals used many of the same tools and tactics they have wielded for more than a decade. • The attacks cos</description>
    </item>
    <item>
      <title>More Than Dashboards: AI Decisions Must Be Provable</title>
      <link>https://cluster-site.onrender.com/posts/more-than-dashboards-ai-decisions-must-be-provable/</link>
      <pubDate>Mon, 23 Feb 2026 22:18:18 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/more-than-dashboards-ai-decisions-must-be-provable/</guid>
      <description>• AI systems have to be able to show a record of what happened and how.</description>
    </item>
    <item>
      <title>Spain arrests suspected hacktivists for DDoSing govt sites</title>
      <link>https://cluster-site.onrender.com/posts/spain-arrests-suspected-hacktivists-for-ddosing-govt-sites/</link>
      <pubDate>Mon, 23 Feb 2026 21:59:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spain-arrests-suspected-hacktivists-for-ddosing-govt-sites/</guid>
      <description>• Spain arrests suspected hacktivists for DDoSing govt sites February 23, 2026 04:59 PM 0 Spanish authorities have arrested four alleged members of a hacktivist group believed to h</description>
    </item>
    <item>
      <title>Iran&#39;s MuddyWater Targets Orgs With Fresh Malware as Tensions Mount</title>
      <link>https://cluster-site.onrender.com/posts/irans-muddywater-targets-orgs-with-fresh-malware-as-tensions-mount/</link>
      <pubDate>Mon, 23 Feb 2026 20:35:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/irans-muddywater-targets-orgs-with-fresh-malware-as-tensions-mount/</guid>
      <description>• Threat Intelligence Cyberattacks &amp;amp; Data Breaches Endpoint Security Remote Workforce News Breaking cybersecurity news, news analysis, commentary, and other content from around the</description>
    </item>
    <item>
      <title>Enigma Cipher Device Still Holds Secrets for Cyber Pros</title>
      <link>https://cluster-site.onrender.com/posts/enigma-cipher-device-still-holds-secrets-for-cyber-pros/</link>
      <pubDate>Mon, 23 Feb 2026 20:11:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/enigma-cipher-device-still-holds-secrets-for-cyber-pros/</guid>
      <description>• The Nazi relic&amp;rsquo;s history is riddled with resilience errors, and those lessons still apply to defending against modern cyber threats. • The Nazi relic&amp;rsquo;s history is riddled with re</description>
    </item>
    <item>
      <title>APT28 Targeted European Entities Using Webhook-Based Macro Malware</title>
      <link>https://cluster-site.onrender.com/posts/apt28-targeted-european-entities-using-webhook-based-macro-malware/</link>
      <pubDate>Mon, 23 Feb 2026 19:41:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/apt28-targeted-european-entities-using-webhook-based-macro-malware/</guid>
      <description>• APT28 Targeted European Entities Using Webhook-Based Macro Malware The Russia-linkedstate-sponsored threat actortracked asAPT28has been attributed to a new campaign targeting spe</description>
    </item>
    <item>
      <title>Microsoft says bug in classic Outlook hides the mouse pointer</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-says-bug-in-classic-outlook-hides-the-mouse-pointer/</link>
      <pubDate>Mon, 23 Feb 2026 19:40:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-says-bug-in-classic-outlook-hides-the-mouse-pointer/</guid>
      <description>• Microsoft says bug in classic Outlook hides the mouse pointer February 23, 2026 02:40 PM 1 Microsoft is investigating a known issue that causes the mouse pointer to disappear in</description>
    </item>
    <item>
      <title>600&#43; FortiGate Devices Hacked by AI-Armed Amateur</title>
      <link>https://cluster-site.onrender.com/posts/600-fortigate-devices-hacked-by-ai-armed-amateur/</link>
      <pubDate>Mon, 23 Feb 2026 19:37:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/600-fortigate-devices-hacked-by-ai-armed-amateur/</guid>
      <description>• A Russian-speaking hacker used generative AI to compromise the FortiGate firewalls, targeting credentials and backups for possible follow-on ransomware attacks. • A Russian-speak</description>
    </item>
    <item>
      <title>Ad tech firm Optimizely confirms data breach after vishing attack</title>
      <link>https://cluster-site.onrender.com/posts/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/</link>
      <pubDate>Mon, 23 Feb 2026 18:04:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/</guid>
      <description>• Ad tech firm Optimizely confirms data breach after vishing attack February 23, 2026 01:04 PM 0 New York-based ad tech company Optimizely has notified an undisclosed number of cus</description>
    </item>
    <item>
      <title>Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb</title>
      <link>https://cluster-site.onrender.com/posts/wormable-xmrig-campaign-uses-byovd-exploit-and-time-based-logic-bomb/</link>
      <pubDate>Mon, 23 Feb 2026 17:59:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wormable-xmrig-campaign-uses-byovd-exploit-and-time-based-logic-bomb/</guid>
      <description>• Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures to deploy a bespoke XMRig miner program on compromise</description>
    </item>
    <item>
      <title>The Art of Deception: How Threat Actors Master Typosquatting Campaigns to Bypass Detection</title>
      <link>https://cluster-site.onrender.com/posts/the-art-of-deception-how-threat-actors-master-typosquatting-campaigns-to-bypass-detection/</link>
      <pubDate>Mon, 23 Feb 2026 16:30:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-art-of-deception-how-threat-actors-master-typosquatting-campaigns-to-bypass-detection/</guid>
      <description>• FeaturedThe Art of Deception: How Threat Actors Master Typosquatting Campaigns to Bypass DetectionFeb 23, 2026Introducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interact</description>
    </item>
    <item>
      <title>US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach</title>
      <link>https://cluster-site.onrender.com/posts/us-healthcare-diagnostic-firm-says-140000-affected-by-data-breach/</link>
      <pubDate>Mon, 23 Feb 2026 15:35:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/us-healthcare-diagnostic-firm-says-140000-affected-by-data-breach/</guid>
      <description>• Nearly 140,000 people are affected by a data breach disclosed by healthcare diagnostic company Vikor Scientific.The number of affected individuals came to light in recent days on</description>
    </item>
    <item>
      <title>When identity isn&#39;t the weak link, access still is</title>
      <link>https://cluster-site.onrender.com/posts/when-identity-isnt-the-weak-link-access-still-is/</link>
      <pubDate>Mon, 23 Feb 2026 15:00:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/when-identity-isnt-the-weak-link-access-still-is/</guid>
      <description>• For years, identity has been treated as the foundation of workforce security. • If an organization could reliably confirm who a user was, the assumption followed that access coul</description>
    </item>
    <item>
      <title>Another day, another malicious JPEG, (Mon, Feb 23rd)</title>
      <link>https://cluster-site.onrender.com/posts/another-day-another-malicious-jpeg-mon-feb-23rd/</link>
      <pubDate>Mon, 23 Feb 2026 14:26:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/another-day-another-malicious-jpeg-mon-feb-23rd/</guid>
      <description>• Another day, another malicious JPEG In his last two diaries, Xavier discussed recent malware campaigns that download JPEG files with embedded malicious payload[1,2]. • At that po</description>
    </item>
    <item>
      <title>Ukrainian Gets 5 Years in US Prison for Aiding North Korean IT Fraud</title>
      <link>https://cluster-site.onrender.com/posts/ukrainian-gets-5-years-in-us-prison-for-aiding-north-korean-it-fraud/</link>
      <pubDate>Mon, 23 Feb 2026 13:38:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ukrainian-gets-5-years-in-us-prison-for-aiding-north-korean-it-fraud/</guid>
      <description>• A Ukrainian national was sentenced to five years in a US prison for selling stolen identities to fraudulent North Korean workers and for facilitating the operation of laptop farm</description>
    </item>
    <item>
      <title>⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware &amp; More</title>
      <link>https://cluster-site.onrender.com/posts/weekly-recap-double-tap-skimmers-promptspy-ai-30tbps-ddos-docker-malware-more/</link>
      <pubDate>Mon, 23 Feb 2026 13:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/weekly-recap-double-tap-skimmers-promptspy-ai-30tbps-ddos-docker-malware-more/</guid>
      <description>• Security news rarely moves in a straight line. • This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public vie</description>
    </item>
    <item>
      <title>Autonomous AI Agents Provide New Class of Supply Chain Attack</title>
      <link>https://cluster-site.onrender.com/posts/autonomous-ai-agents-provide-new-class-of-supply-chain-attack/</link>
      <pubDate>Mon, 23 Feb 2026 12:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/autonomous-ai-agents-provide-new-class-of-supply-chain-attack/</guid>
      <description>• Found in Clawhub, promoted on Moltbook, Bob-ptp is an ongoing active agent-based crypto scam.It&amp;rsquo;s ironic that new technology often defies the fundamental security rule of zero tr</description>
    </item>
    <item>
      <title>On the Security of Password Managers</title>
      <link>https://cluster-site.onrender.com/posts/on-the-security-of-password-managers/</link>
      <pubDate>Mon, 23 Feb 2026 12:03:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/on-the-security-of-password-managers/</guid>
      <description>• On the Security of Password Managers Good article on password managers that secretly have a backdoor. • New research shows that these claims aren&amp;rsquo;t true in all cases, particularl</description>
    </item>
    <item>
      <title>How Exposed Endpoints Increase Risk Across LLM Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/how-exposed-endpoints-increase-risk-across-llm-infrastructure/</link>
      <pubDate>Mon, 23 Feb 2026 11:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-exposed-endpoints-increase-risk-across-llm-infrastructure/</guid>
      <description>• How Exposed Endpoints Increase Risk Across LLM Infrastructure As more organizations run their own Large Language Models (LLMs), they are also deploying more internal services and</description>
    </item>
    <item>
      <title>Romanian Hacker Pleads Guilty to Selling Access to US State Network</title>
      <link>https://cluster-site.onrender.com/posts/romanian-hacker-pleads-guilty-to-selling-access-to-us-state-network/</link>
      <pubDate>Mon, 23 Feb 2026 11:53:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/romanian-hacker-pleads-guilty-to-selling-access-to-us-state-network/</guid>
      <description>• A Romanian national pleaded guilty in a US court to selling unauthorized access to an Oregon state government office&amp;rsquo;s network.The man, Catalin Dragomir, 45, of Constanta, Romani</description>
    </item>
    <item>
      <title>Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS</title>
      <link>https://cluster-site.onrender.com/posts/hundreds-of-fortigate-firewalls-hacked-in-ai-powered-attacks-aws/</link>
      <pubDate>Mon, 23 Feb 2026 11:34:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hundreds-of-fortigate-firewalls-hacked-in-ai-powered-attacks-aws/</guid>
      <description>• Over 600 Fortinet FortiGate firewall instances have been hacked in an AI-powered campaign that exploits exposed ports and weak credentials, AWS reports.The attacks, observed betw</description>
    </item>
    <item>
      <title>Mississippi Hospital System Closes All Clinics After Ransomware Attack</title>
      <link>https://cluster-site.onrender.com/posts/mississippi-hospital-system-closes-all-clinics-after-ransomware-attack/</link>
      <pubDate>Mon, 23 Feb 2026 10:29:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/mississippi-hospital-system-closes-all-clinics-after-ransomware-attack/</guid>
      <description>• A ransomware attack forced the University of Mississippi Medical Center to close all of its roughly three dozen clinics around the state and cancel elective procedures for a seco</description>
    </item>
    <item>
      <title>CrowdStrike Named a Customers&amp;rsquo; Choice in 2026 Gartner Peer Insights&amp;trade; Voice of the Customer for Application Security Posture Management Tools</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-a-customersrsquo-choice-in-2026-gartner-peer-insightstrade-voice-of-the-customer-for-application-security-posture-management-tools/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-a-customersrsquo-choice-in-2026-gartner-peer-insightstrade-voice-of-the-customer-for-application-security-posture-management-tools/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>What Security Teams Need to Know About OpenClaw, the AI Super Agent</title>
      <link>https://cluster-site.onrender.com/posts/what-security-teams-need-to-know-about-openclaw-the-ai-super-agent/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-security-teams-need-to-know-about-openclaw-the-ai-super-agent/</guid>
      <description>• OpenClaw is CrowdStrike&amp;rsquo;s AI super agent for automated threat hunting. • It orchestrates data from multiple sensors to identify suspicious activity. • AI models continuously lear</description>
    </item>
    <item>
      <title>Advanced Web Shell Detection and Prevention: A Deep Dive into CrowdStrike&#39;s Linux Sensor Capabilities</title>
      <link>https://cluster-site.onrender.com/posts/advanced-web-shell-detection-and-prevention-a-deep-dive-into-crowdstrikes-linux-sensor-capabilities/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/advanced-web-shell-detection-and-prevention-a-deep-dive-into-crowdstrikes-linux-sensor-capabilities/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>CrowdStrike Named Customers&#39; Choice Attack Surface Management</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-attack-surface-management/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-attack-surface-management/</guid>
      <description>• Gartner named CrowdStrike the sole Customers&amp;rsquo; Choice for External Attack Surface Management. • Falcon X provides continuous visibility into cloud, on‑prem, and SaaS attack surfac</description>
    </item>
    <item>
      <title>Human‑AI Feedback Loop Powering CrowdStrike Agentic Security</title>
      <link>https://cluster-site.onrender.com/posts/humanai-feedback-loop-powering-crowdstrike-agentic-security/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/humanai-feedback-loop-powering-crowdstrike-agentic-security/</guid>
      <description>• Human‑AI feedback loop enhances threat detection by combining analyst intuition with machine learning insights. • CrowdStrike&amp;rsquo;s Agentic Security framework empowers analysts to gu</description>
    </item>
    <item>
      <title>Scale SOC Automation Falcon Fusion SOAR</title>
      <link>https://cluster-site.onrender.com/posts/scale-soc-automation-falcon-fusion-soar/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scale-soc-automation-falcon-fusion-soar/</guid>
      <description>• Falcon Fusion SOAR automates SOC workflows across security tools. • Low‑code platform accelerates incident response times. • AI‑powered playbooks prioritize high‑impact alerts. •</description>
    </item>
    <item>
      <title>CrowdStrike Named Customers&#39; Choice 2026 Gartner Peer Insights Voice User Authentication</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-2026-gartner-peer-insights-voice-user-authentication/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-2026-gartner-peer-insights-voice-user-authentication/</guid>
      <description>• CrowdStrike awarded Customers&amp;rsquo; Choice for user authentication in 2026. • Recognition reflects high customer satisfaction and product reliability. • Falcon platform offers multi‑f</description>
    </item>
    <item>
      <title>Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens</title>
      <link>https://cluster-site.onrender.com/posts/malicious-npm-packages-harvest-crypto-keys-ci-secrets-and-api-tokens/</link>
      <pubDate>Mon, 23 Feb 2026 10:20:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-npm-packages-harvest-crypto-keys-ci-secrets-and-api-tokens/</guid>
      <description>• Cybersecurity researchers have disclosed what they say is an active &amp;lsquo;Shai-Hulud-like&amp;rsquo; supply chain worm campaign that has leveraged a cluster of at least 19 malicious npm package</description>
    </item>
    <item>
      <title>PayPal Data Breach Led to Fraudulent Transactions</title>
      <link>https://cluster-site.onrender.com/posts/paypal-data-breach-led-to-fraudulent-transactions/</link>
      <pubDate>Mon, 23 Feb 2026 09:13:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/paypal-data-breach-led-to-fraudulent-transactions/</guid>
      <description>• PayPal disclosed a data breach affecting personal info of ~100 customers. • Breach caused by coding error in PayPal Working Capital loan application. • Exposed data included name</description>
    </item>
    <item>
      <title>MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP</title>
      <link>https://cluster-site.onrender.com/posts/muddywater-targets-mena-organizations-with-ghostfetch-char-and-http_vip/</link>
      <pubDate>Mon, 23 Feb 2026 07:25:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/muddywater-targets-mena-organizations-with-ghostfetch-char-and-http_vip/</guid>
      <description>• MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP The Iranian hacking group known asMuddyWater(aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targ</description>
    </item>
    <item>
      <title>ISC Stormcast For Monday, February 23rd, 2026 https://isc.sans.edu/podcastdetail/9820, (Mon, Feb 23rd)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-monday-february-23rd-2026-https/isc.sans.edu/podcastdetail/9820-mon-feb-23rd/</link>
      <pubDate>Mon, 23 Feb 2026 02:45:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-monday-february-23rd-2026-https/isc.sans.edu/podcastdetail/9820-mon-feb-23rd/</guid>
      <description>• ISC Stormcast For Monday, February 23rd, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9820&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9820&lt;/a&gt;
 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security: S</description>
    </item>
    <item>
      <title>Arkanix Stealer pops up as short-lived AI info-stealer experiment</title>
      <link>https://cluster-site.onrender.com/posts/arkanix-stealer-pops-up-as-short-lived-ai-info-stealer-experiment/</link>
      <pubDate>Sun, 22 Feb 2026 15:33:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/arkanix-stealer-pops-up-as-short-lived-ai-info-stealer-experiment/</guid>
      <description>• Arkanix Stealer pops up as short-lived AI info-stealer experiment February 22, 2026 10:33 AM 0 An information-stealing malware operation named Arkanix Stealer, promoted on multip</description>
    </item>
    <item>
      <title>Predator spyware hooks iOS SpringBoard to hide mic, camera activity</title>
      <link>https://cluster-site.onrender.com/posts/predator-spyware-hooks-ios-springboard-to-hide-mic-camera-activity/</link>
      <pubDate>Sat, 21 Feb 2026 16:13:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/predator-spyware-hooks-ios-springboard-to-hide-mic-camera-activity/</guid>
      <description>• Intellexa&amp;rsquo;s Predator spyware can hide iOS recording indicators while secretly streaming camera and microphone feeds to its operators. • The malware does not exploit any iOS vulne</description>
    </item>
    <item>
      <title>AI-Assisted Threat Actor Compromises 600&#43; FortiGate Devices in 55 Countries</title>
      <link>https://cluster-site.onrender.com/posts/ai-assisted-threat-actor-compromises-600-fortigate-devices-in-55-countries/</link>
      <pubDate>Sat, 21 Feb 2026 14:49:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-assisted-threat-actor-compromises-600-fortigate-devices-in-55-countries/</guid>
      <description>• AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries A Russian-speaking, financially motivated threat actor has been observed taking advantage of commercia</description>
    </item>
    <item>
      <title>Amazon: AI-assisted hacker breached 600 FortiGate firewalls in 5 weeks</title>
      <link>https://cluster-site.onrender.com/posts/amazon-ai-assisted-hacker-breached-600-fortigate-firewalls-in-5-weeks/</link>
      <pubDate>Sat, 21 Feb 2026 13:50:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/amazon-ai-assisted-hacker-breached-600-fortigate-firewalls-in-5-weeks/</guid>
      <description>• Amazon: AI-assisted hacker breached 600 FortiGate firewalls in 5 weeks February 21, 2026 08:50 AM 0 Amazon is warning that a Russian-speaking hacker used multiple generative AI s</description>
    </item>
    <item>
      <title>Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks</title>
      <link>https://cluster-site.onrender.com/posts/amazon-ai-assisted-hacker-breached-600-fortinet-firewalls-in-5-weeks/</link>
      <pubDate>Sat, 21 Feb 2026 13:50:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/amazon-ai-assisted-hacker-breached-600-fortinet-firewalls-in-5-weeks/</guid>
      <description>• Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks February 21, 2026 08:50 AM 0 Article updated at the bottom with additional technical details about this camp</description>
    </item>
    <item>
      <title>Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning</title>
      <link>https://cluster-site.onrender.com/posts/anthropic-launches-claude-code-security-for-ai-powered-vulnerability-scanning/</link>
      <pubDate>Sat, 21 Feb 2026 07:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anthropic-launches-claude-code-security-for-ai-powered-vulnerability-scanning/</guid>
      <description>• Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Clau</description>
    </item>
    <item>
      <title>CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog</title>
      <link>https://cluster-site.onrender.com/posts/cisa-adds-two-actively-exploited-roundcube-flaws-to-kev-catalog/</link>
      <pubDate>Sat, 21 Feb 2026 07:21:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-adds-two-actively-exploited-roundcube-flaws-to-kev-catalog/</guid>
      <description>• CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog The U.S. • Cybersecurity and Infrastructure Security Agency (CISA) on Fridayaddedtwo security flaws impacting Roun</description>
    </item>
    <item>
      <title>Japanese-Language Phishing Emails, (Sat, Feb 21st)</title>
      <link>https://cluster-site.onrender.com/posts/japanese-language-phishing-emails-sat-feb-21st/</link>
      <pubDate>Sat, 21 Feb 2026 06:03:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/japanese-language-phishing-emails-sat-feb-21st/</guid>
      <description>• Japanese-Language Phishing Emails Introduction For at least the past year or so, I&amp;rsquo;ve been receiving Japanese-language phishing emails to my blog email addresses at @malware-traf</description>
    </item>
    <item>
      <title>EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security</title>
      <link>https://cluster-site.onrender.com/posts/ec-council-expands-ai-certification-portfolio-to-strengthen-u.s.-ai-workforce-readiness-and-security/</link>
      <pubDate>Sat, 21 Feb 2026 04:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ec-council-expands-ai-certification-portfolio-to-strengthen-u.s.-ai-workforce-readiness-and-security/</guid>
      <description>• EC-Council Expands AI Certification Portfolio to Strengthen U.S. • AI Workforce Readiness and Security With $5.5 trillion in global AI risk exposure and 700,000 U.S. • workers ne</description>
    </item>
    <item>
      <title>Friday Squid Blogging: Squid Cartoon</title>
      <link>https://cluster-site.onrender.com/posts/friday-squid-blogging-squid-cartoon/</link>
      <pubDate>Fri, 20 Feb 2026 22:05:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/friday-squid-blogging-squid-cartoon/</guid>
      <description>• Friday Squid Blogging: Squid Cartoon I like this one. • As usual, you can also use this squid post to talk about the security stories in the news that I haven&amp;rsquo;t covered. • As usu</description>
    </item>
    <item>
      <title>Attackers Use New Tool to Scan for React2Shell Exposure</title>
      <link>https://cluster-site.onrender.com/posts/attackers-use-new-tool-to-scan-for-react2shell-exposure/</link>
      <pubDate>Fri, 20 Feb 2026 21:07:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/attackers-use-new-tool-to-scan-for-react2shell-exposure/</guid>
      <description>• Researchers say threat actors wielded the sophisticated - and unfortunately named - toolkit to target high-value networks for React2Shell exploitation • Cybersecurity researchers</description>
    </item>
    <item>
      <title>&#39;Starkiller&#39; Phishing Service Proxies Real Login Pages, MFA</title>
      <link>https://cluster-site.onrender.com/posts/starkiller-phishing-service-proxies-real-login-pages-mfa/</link>
      <pubDate>Fri, 20 Feb 2026 20:00:30 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/starkiller-phishing-service-proxies-real-login-pages-mfa/</guid>
      <description>• Most phishing websites are little more than static copies of login pages for popular online destinations, and they are often quickly taken down by anti-abuse activists and securi</description>
    </item>
    <item>
      <title>&#39;God-Like&#39; Attack Machines: AI Agents Ignore Security Policies</title>
      <link>https://cluster-site.onrender.com/posts/god-like-attack-machines-ai-agents-ignore-security-policies/</link>
      <pubDate>Fri, 20 Feb 2026 18:31:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/god-like-attack-machines-ai-agents-ignore-security-policies/</guid>
      <description>• Microsoft Copilot recently summarized and leaked user emails; but any AI agent will go above and beyond to complete assigned tasks, even breaking through their carefully designed</description>
    </item>
    <item>
      <title>Japanese tech giant Advantest hit by ransomware attack</title>
      <link>https://cluster-site.onrender.com/posts/japanese-tech-giant-advantest-hit-by-ransomware-attack/</link>
      <pubDate>Fri, 20 Feb 2026 18:30:44 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/japanese-tech-giant-advantest-hit-by-ransomware-attack/</guid>
      <description>• Japanese tech giant Advantest hit by ransomware attack February 20, 2026 01:30 PM 0 Advantest Corporation disclosed that its corporate network has been targeted in a ransomware a</description>
    </item>
    <item>
      <title>Lessons From AI Hacking: Every Model, Every Layer Is Risky</title>
      <link>https://cluster-site.onrender.com/posts/lessons-from-ai-hacking-every-model-every-layer-is-risky/</link>
      <pubDate>Fri, 20 Feb 2026 18:02:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lessons-from-ai-hacking-every-model-every-layer-is-risky/</guid>
      <description>• Application Security Cyber Risk Cybersecurity Operations Vulnerabilities &amp;amp; Threats News Lessons From AI Hacking: Every Model, Every Layer Is Risky After two years of finding flaw</description>
    </item>
    <item>
      <title>Data breach at French bank registry impacts 1.2 million accounts</title>
      <link>https://cluster-site.onrender.com/posts/data-breach-at-french-bank-registry-impacts-1.2-million-accounts/</link>
      <pubDate>Fri, 20 Feb 2026 16:20:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/data-breach-at-french-bank-registry-impacts-1.2-million-accounts/</guid>
      <description>• Data breach at French bank registry impacts 1.2 million accounts February 20, 2026 11:20 AM 0 The French Ministry of Finance has disclosed a cybersecurity incident that impacted</description>
    </item>
    <item>
      <title>NIST&#39;s Quantum Breakthrough: Single Photons Produced on a Chip</title>
      <link>https://cluster-site.onrender.com/posts/nists-quantum-breakthrough-single-photons-produced-on-a-chip/</link>
      <pubDate>Fri, 20 Feb 2026 15:48:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nists-quantum-breakthrough-single-photons-produced-on-a-chip/</guid>
      <description>• NIST has developed a chip that reliably emits a single photon on demand. • This ability will improve the efficiency of QKD (quantum key distribution) as we prepare for the arriva</description>
    </item>
    <item>
      <title>BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration</title>
      <link>https://cluster-site.onrender.com/posts/beyondtrust-flaw-used-for-web-shells-backdoors-and-data-exfiltration/</link>
      <pubDate>Fri, 20 Feb 2026 15:45:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/beyondtrust-flaw-used-for-web-shells-backdoors-and-data-exfiltration/</guid>
      <description>• BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration Threat actors have been observed exploiting a recently disclosed critical security flaw impacting BeyondTru</description>
    </item>
    <item>
      <title>In Other News: Ransomware Shuts US Clinics, ICS Vulnerability Surge, European Parliament Bans AI</title>
      <link>https://cluster-site.onrender.com/posts/in-other-news-ransomware-shuts-us-clinics-ics-vulnerability-surge-european-parliament-bans-ai/</link>
      <pubDate>Fri, 20 Feb 2026 15:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/in-other-news-ransomware-shuts-us-clinics-ics-vulnerability-surge-european-parliament-bans-ai/</guid>
      <description>• SecurityWeek&amp;rsquo;s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar.We provide a valuable summary of stories th</description>
    </item>
    <item>
      <title>Why the shift left dream has become a nightmare for security and developers</title>
      <link>https://cluster-site.onrender.com/posts/why-the-shift-left-dream-has-become-a-nightmare-for-security-and-developers/</link>
      <pubDate>Fri, 20 Feb 2026 14:45:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/why-the-shift-left-dream-has-become-a-nightmare-for-security-and-developers/</guid>
      <description>• Why the shift left dream has become a nightmare for security and developers February 20, 2026 09:45 AM 0 Written by Ivan Milenkovic, Vice President Risk Technology EMEA, Qualys F</description>
    </item>
    <item>
      <title>Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems</title>
      <link>https://cluster-site.onrender.com/posts/cline-cli-2.3.0-supply-chain-attack-installed-openclaw-on-developer-systems/</link>
      <pubDate>Fri, 20 Feb 2026 14:20:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cline-cli-2.3.0-supply-chain-attack-installed-openclaw-on-developer-systems/</guid>
      <description>• Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems In yet another software supply chain attack, the open-source, artificial intelligence (AI)-powered cod</description>
    </item>
    <item>
      <title>Latin America&#39;s Cyber Maturity Lags Threat Landscape</title>
      <link>https://cluster-site.onrender.com/posts/latin-americas-cyber-maturity-lags-threat-landscape/</link>
      <pubDate>Fri, 20 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/latin-americas-cyber-maturity-lags-threat-landscape/</guid>
      <description>• Threat Intelligence Cyber Risk Cybersecurity Operations Cyberattacks &amp;amp; Data Breaches News Breaking cybersecurity news, news analysis, commentary, and other content from around th</description>
    </item>
    <item>
      <title>PayPal discloses data breach that exposed user info for 6 months</title>
      <link>https://cluster-site.onrender.com/posts/paypal-discloses-data-breach-that-exposed-user-info-for-6-months/</link>
      <pubDate>Fri, 20 Feb 2026 13:12:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/paypal-discloses-data-breach-that-exposed-user-info-for-6-months/</guid>
      <description>• PayPal disclosed a data breach affecting PPWC loan app, exposing sensitive info for 6 months. • Breach spanned July 1 to December 13, 2025, revealing names, emails, phone, busine</description>
    </item>
    <item>
      <title>Ring Cancels Its Partnership with Flock</title>
      <link>https://cluster-site.onrender.com/posts/ring-cancels-its-partnership-with-flock/</link>
      <pubDate>Fri, 20 Feb 2026 12:08:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ring-cancels-its-partnership-with-flock/</guid>
      <description>• • February 20, 2026 11:39 AM Can we read something that is not behind a paywall? • Clive Robinson • February 20, 2026 2:57 PM @ Who?, ALL, &amp;lsquo;Can we read something that is not behi</description>
    </item>
    <item>
      <title>ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware</title>
      <link>https://cluster-site.onrender.com/posts/clickfix-campaign-abuses-compromised-sites-to-deploy-mimicrat-malware/</link>
      <pubDate>Fri, 20 Feb 2026 11:55:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/clickfix-campaign-abuses-compromised-sites-to-deploy-mimicrat-malware/</guid>
      <description>• ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware Cybersecurity researchers have disclosed details of a newClickFixcampaign that abuses compromised legitimate</description>
    </item>
    <item>
      <title>Mississippi medical center closes all clinics after ransomware attack</title>
      <link>https://cluster-site.onrender.com/posts/mississippi-medical-center-closes-all-clinics-after-ransomware-attack/</link>
      <pubDate>Fri, 20 Feb 2026 11:50:14 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/mississippi-medical-center-closes-all-clinics-after-ransomware-attack/</guid>
      <description>• The University of Mississippi Medical Center (UMMC) closed all its clinic locations statewide on Thursday following a ransomware attack. • UMMC has over 10,000 employees and, as</description>
    </item>
    <item>
      <title>FBI: $20 Million Losses Caused by 700 ATM Jackpotting Attacks in 2025</title>
      <link>https://cluster-site.onrender.com/posts/fbi-20-million-losses-caused-by-700-atm-jackpotting-attacks-in-2025/</link>
      <pubDate>Fri, 20 Feb 2026 11:05:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fbi-20-million-losses-caused-by-700-atm-jackpotting-attacks-in-2025/</guid>
      <description>• A flash alert published on Thursday by the FBI warns of an increase in malware-enabled ATM jackpotting attacks in the United States.According to the agency, roughly 1,900 ATM jac</description>
    </item>
    <item>
      <title>Identity Cyber Scores: The New Metric Shaping Cyber Insurance in 2026</title>
      <link>https://cluster-site.onrender.com/posts/identity-cyber-scores-the-new-metric-shaping-cyber-insurance-in-2026/</link>
      <pubDate>Fri, 20 Feb 2026 10:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/identity-cyber-scores-the-new-metric-shaping-cyber-insurance-in-2026/</guid>
      <description>• One in three cyber-attacks now involve compromised employee accounts, driving insurers to focus on identity posture. • Password hygiene, privileged access management, and MFA cov</description>
    </item>
    <item>
      <title>FBI: Over $20 million stolen in surge of ATM malware attacks in 2025</title>
      <link>https://cluster-site.onrender.com/posts/fbi-over-20-million-stolen-in-surge-of-atm-malware-attacks-in-2025/</link>
      <pubDate>Fri, 20 Feb 2026 10:08:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fbi-over-20-million-stolen-in-surge-of-atm-malware-attacks-in-2025/</guid>
      <description>• The FBI warned that Americans lost more than $20 million last year amid a massive surge in ATM &amp;lsquo;jackpotting&amp;rsquo; attacks, in which criminals use malware to force cash machines to dis</description>
    </item>
    <item>
      <title>Ukrainian National Sentenced to 5 Years in North Korea IT Worker Fraud Case</title>
      <link>https://cluster-site.onrender.com/posts/ukrainian-national-sentenced-to-5-years-in-north-korea-it-worker-fraud-case/</link>
      <pubDate>Fri, 20 Feb 2026 09:52:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ukrainian-national-sentenced-to-5-years-in-north-korea-it-worker-fraud-case/</guid>
      <description>• Ukrainian National Sentenced to 5 Years in North Korea IT Worker Fraud Case A 29-year-old Ukrainian national has beensentenced to five years in prisonin the U.S. • for his role i</description>
    </item>
    <item>
      <title>Chip Testing Giant Advantest Hit by Ransomware</title>
      <link>https://cluster-site.onrender.com/posts/chip-testing-giant-advantest-hit-by-ransomware/</link>
      <pubDate>Fri, 20 Feb 2026 09:31:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/chip-testing-giant-advantest-hit-by-ransomware/</guid>
      <description>• Japanese chip testing giant Advantest Corporation (TSE: 6857) has been targeted in a ransomware attack.Advantest makes automatic test equipment for the semiconductor industry. •</description>
    </item>
    <item>
      <title>CrowdStrike Named a Customers&amp;rsquo; Choice in 2026 Gartner Peer Insights&amp;trade; Voice of the Customer for Application Security Posture Management Tools</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-a-customersrsquo-choice-in-2026-gartner-peer-insightstrade-voice-of-the-customer-for-application-security-posture-management-tools/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:28 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-a-customersrsquo-choice-in-2026-gartner-peer-insightstrade-voice-of-the-customer-for-application-security-posture-management-tools/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>Advanced Web Shell Detection and Prevention: A Deep Dive into CrowdStrike&#39;s Linux Sensor Capabilities</title>
      <link>https://cluster-site.onrender.com/posts/advanced-web-shell-detection-and-prevention-a-deep-dive-into-crowdstrikes-linux-sensor-capabilities/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/advanced-web-shell-detection-and-prevention-a-deep-dive-into-crowdstrikes-linux-sensor-capabilities/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>What Security Teams Need to Know About OpenClaw, the AI Super Agent</title>
      <link>https://cluster-site.onrender.com/posts/what-security-teams-need-to-know-about-openclaw-the-ai-super-agent/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-security-teams-need-to-know-about-openclaw-the-ai-super-agent/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>CrowdStrike Is the Only Vendor to Be Named a Customers&amp;rsquo; Choice in 2025 Gartner&amp;reg; Voice of the Customer for External Attack Surface Management</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-is-the-only-vendor-to-be-named-a-customersrsquo-choice-in-2025-gartnerreg-voice-of-the-customer-for-external-attack-surface-management/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-is-the-only-vendor-to-be-named-a-customersrsquo-choice-in-2025-gartnerreg-voice-of-the-customer-for-external-attack-surface-management/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>Inside the Human-AI Feedback Loop Powering CrowdStrike&amp;rsquo;s Agentic Security</title>
      <link>https://cluster-site.onrender.com/posts/inside-the-human-ai-feedback-loop-powering-crowdstrikersquos-agentic-security/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/inside-the-human-ai-feedback-loop-powering-crowdstrikersquos-agentic-security/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>Ukrainian gets 5 years for helping North Koreans infiltrate US firms</title>
      <link>https://cluster-site.onrender.com/posts/ukrainian-gets-5-years-for-helping-north-koreans-infiltrate-us-firms/</link>
      <pubDate>Fri, 20 Feb 2026 09:00:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ukrainian-gets-5-years-for-helping-north-koreans-infiltrate-us-firms/</guid>
      <description>• Ukrainian gets 5 years for helping North Koreans infiltrate US firms February 20, 2026 04:00 AM 0 A Ukrainian national was sentenced to five years in prison for providing North K</description>
    </item>
    <item>
      <title>FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025</title>
      <link>https://cluster-site.onrender.com/posts/fbi-reports-1900-atm-jackpotting-incidents-since-2020-20m-lost-in-2025/</link>
      <pubDate>Fri, 20 Feb 2026 08:05:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fbi-reports-1900-atm-jackpotting-incidents-since-2020-20m-lost-in-2025/</guid>
      <description>• FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 The U.S. • Federal Bureau of Investigation (FBI) has warned of an increase in ATM jackpotting incidents</description>
    </item>
    <item>
      <title>Former Google Engineers Indicted Over Trade Secret Transfers to Iran</title>
      <link>https://cluster-site.onrender.com/posts/former-google-engineers-indicted-over-trade-secret-transfers-to-iran/</link>
      <pubDate>Fri, 20 Feb 2026 05:27:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/former-google-engineers-indicted-over-trade-secret-transfers-to-iran/</guid>
      <description>• Former Google Engineers Indicted Over Trade Secret Transfers to Iran Two former Google engineers and one of their husbands have beenindictedin the U.S. • for allegedly committing</description>
    </item>
    <item>
      <title>Three Former Google Engineers Indicted Over Trade Secret Transfers to Iran</title>
      <link>https://cluster-site.onrender.com/posts/three-former-google-engineers-indicted-over-trade-secret-transfers-to-iran/</link>
      <pubDate>Fri, 20 Feb 2026 05:27:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/three-former-google-engineers-indicted-over-trade-secret-transfers-to-iran/</guid>
      <description>• Three Former Google Engineers Indicted Over Trade Secret Transfers to Iran Two former Google engineers and one of their husbands have beenindictedin the U.S. • for allegedly comm</description>
    </item>
    <item>
      <title>ISC Stormcast For Friday, February 20th, 2026 https://isc.sans.edu/podcastdetail/9818, (Fri, Feb 20th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-friday-february-20th-2026-https/isc.sans.edu/podcastdetail/9818-fri-feb-20th/</link>
      <pubDate>Fri, 20 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-friday-february-20th-2026-https/isc.sans.edu/podcastdetail/9818-fri-feb-20th/</guid>
      <description>• ISC Stormcast For Friday, February 20th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9818&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9818&lt;/a&gt;
 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security: S</description>
    </item>
    <item>
      <title>Emerging Chiplet Designs Spark Fresh Cybersecurity Challenges</title>
      <link>https://cluster-site.onrender.com/posts/emerging-chiplet-designs-spark-fresh-cybersecurity-challenges/</link>
      <pubDate>Thu, 19 Feb 2026 23:17:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/emerging-chiplet-designs-spark-fresh-cybersecurity-challenges/</guid>
      <description>• As scaled-down circuits with limited functions redefine computing for AI systems and autonomous vehicles, their flexibility demands new approaches to safeguard critical infrastru</description>
    </item>
    <item>
      <title>VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)</title>
      <link>https://cluster-site.onrender.com/posts/vshell-and-sparkrat-observed-in-exploitation-of-beyondtrust-critical-vulnerability-cve-2026-1731/</link>
      <pubDate>Thu, 19 Feb 2026 23:00:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vshell-and-sparkrat-observed-in-exploitation-of-beyondtrust-critical-vulnerability-cve-2026-1731/</guid>
      <description>• Executive Summary On Feb. • 6, 2026, BeyondTrust released a security advisory regarding CVE-2026-1731. • BeyondTrust is an identity and access management platform. • This specifi</description>
    </item>
    <item>
      <title>PromptSpy is the first known Android malware to use generative AI at runtime</title>
      <link>https://cluster-site.onrender.com/posts/promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime/</link>
      <pubDate>Thu, 19 Feb 2026 22:36:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime/</guid>
      <description>• PromptSpy is the first known Android malware to use generative AI at runtime February 19, 2026 05:36 PM 0 Researchers have discovered the first known Android malware to use gener</description>
    </item>
    <item>
      <title>Supply Chain Attack Secretly Installs OpenClaw for Cline Users</title>
      <link>https://cluster-site.onrender.com/posts/supply-chain-attack-secretly-installs-openclaw-for-cline-users/</link>
      <pubDate>Thu, 19 Feb 2026 22:33:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/supply-chain-attack-secretly-installs-openclaw-for-cline-users/</guid>
      <description>• Application Security Cyber Risk Cyberattacks &amp;amp; Data Breaches Vulnerabilities &amp;amp; Threats News Supply Chain Attack Secretly Installs OpenClaw for Cline Users The malicious version o</description>
    </item>
    <item>
      <title>Best-in-Class &#39;Starkiller&#39; Phishing Kit Bypasses MFA</title>
      <link>https://cluster-site.onrender.com/posts/best-in-class-starkiller-phishing-kit-bypasses-mfa/</link>
      <pubDate>Thu, 19 Feb 2026 22:06:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/best-in-class-starkiller-phishing-kit-bypasses-mfa/</guid>
      <description>• A user-friendly PhaaS tool beats standard methods for detecting phishing attacks by live-proxying legitimate login sites.</description>
    </item>
    <item>
      <title>Abu Dhabi Finance Week Exposed VIP Passport Details</title>
      <link>https://cluster-site.onrender.com/posts/abu-dhabi-finance-week-exposed-vip-passport-details/</link>
      <pubDate>Thu, 19 Feb 2026 20:50:14 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/abu-dhabi-finance-week-exposed-vip-passport-details/</guid>
      <description>• Unprotected cloud data sends the wrong signal at a time when the emirate&amp;rsquo;s trying to attract investors and establish itself as a global financial center.</description>
    </item>
    <item>
      <title>Under the Hood of DynoWiper, (Thu, Feb 19th)</title>
      <link>https://cluster-site.onrender.com/posts/under-the-hood-of-dynowiper-thu-feb-19th/</link>
      <pubDate>Thu, 19 Feb 2026 19:43:30 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/under-the-hood-of-dynowiper-thu-feb-19th/</guid>
      <description>• Under the Hood of DynoWiper [This is a Guest Diary contributed by John Moutos] Overview In this post, I&amp;rsquo;m going over my analysis of DynoWiper, a wiper family that was discovered</description>
    </item>
    <item>
      <title>PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence</title>
      <link>https://cluster-site.onrender.com/posts/promptspy-android-malware-abuses-gemini-ai-to-automate-recent-apps-persistence/</link>
      <pubDate>Thu, 19 Feb 2026 17:52:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/promptspy-android-malware-abuses-gemini-ai-to-automate-recent-apps-persistence/</guid>
      <description>• PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence Cybersecurity researchers have discovered what they say is the first Android malware that abuses Ge</description>
    </item>
    <item>
      <title>INTERPOL Operation Red Card 2.0 Arrests 651 in African Cybercrime Crackdown</title>
      <link>https://cluster-site.onrender.com/posts/interpol-operation-red-card-2.0-arrests-651-in-african-cybercrime-crackdown/</link>
      <pubDate>Thu, 19 Feb 2026 17:50:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/interpol-operation-red-card-2.0-arrests-651-in-african-cybercrime-crackdown/</guid>
      <description>• INTERPOL Operation Red Card 2.0 Arrests 651 in African Cybercrime Crackdown An international cybercrime operation against online scams has led to 651 arrests and recovered more t</description>
    </item>
    <item>
      <title>Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-patches-cve-2026-26119-privilege-escalation-in-windows-admin-center/</link>
      <pubDate>Thu, 19 Feb 2026 17:40:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-patches-cve-2026-26119-privilege-escalation-in-windows-admin-center/</guid>
      <description>• Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center Microsoft has disclosed a now-patched security flaw in Windows Admin Center that could allow an atta</description>
    </item>
    <item>
      <title>Google blocked over 1.75 million Play Store app submissions in 2025</title>
      <link>https://cluster-site.onrender.com/posts/google-blocked-over-1.75-million-play-store-app-submissions-in-2025/</link>
      <pubDate>Thu, 19 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-blocked-over-1.75-million-play-store-app-submissions-in-2025/</guid>
      <description>• Google blocked over 1.75 million Play Store app submissions in 2025 February 19, 2026 12:00 PM 0 Google says that through 2025, it blocked more than 255,000 Android apps from obt</description>
    </item>
    <item>
      <title>New e-book: Establishing a proactive defense with Microsoft Security Exposure Management</title>
      <link>https://cluster-site.onrender.com/posts/new-e-book-establishing-a-proactive-defense-with-microsoft-security-exposure-management/</link>
      <pubDate>Thu, 19 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-e-book-establishing-a-proactive-defense-with-microsoft-security-exposure-management/</guid>
      <description>• Share Link copied to clipboard! • Content types Best practices Topics Data security Network security Security management Effective exposure management begins by illuminating and</description>
    </item>
    <item>
      <title>Running OpenClaw safely: identity, isolation, and runtime risk</title>
      <link>https://cluster-site.onrender.com/posts/running-openclaw-safely-identity-isolation-and-runtime-risk/</link>
      <pubDate>Thu, 19 Feb 2026 16:27:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/running-openclaw-safely-identity-isolation-and-runtime-risk/</guid>
      <description>• Self-hosted agent runtimes like OpenClaw are showing up fast in enterprise pilots, and they introduce a blunt reality: OpenClaw includes limited built-in security controls. • The</description>
    </item>
    <item>
      <title>Connected &amp;amp; Compromised: When IoT Devices Turn Into Threats</title>
      <link>https://cluster-site.onrender.com/posts/connected-amp-compromised-when-iot-devices-turn-into-threats/</link>
      <pubDate>Thu, 19 Feb 2026 15:18:23 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/connected-amp-compromised-when-iot-devices-turn-into-threats/</guid>
      <description>• Reused passwords, a lack of network segmentation, and poor sanitization processes make the Internet of Things&amp;rsquo; attack surfaces more dangerous.</description>
    </item>
    <item>
      <title>Connected and Compromised: When IoT Devices Turn Into Threats</title>
      <link>https://cluster-site.onrender.com/posts/connected-and-compromised-when-iot-devices-turn-into-threats/</link>
      <pubDate>Thu, 19 Feb 2026 15:18:23 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/connected-and-compromised-when-iot-devices-turn-into-threats/</guid>
      <description>• Reused passwords, a lack of network segmentation, and poor sanitization processes make the Internet of Things&amp;rsquo; attack surfaces more dangerous.</description>
    </item>
    <item>
      <title>How infostealers turn stolen credentials into real identities</title>
      <link>https://cluster-site.onrender.com/posts/how-infostealers-turn-stolen-credentials-into-real-identities/</link>
      <pubDate>Thu, 19 Feb 2026 15:05:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-infostealers-turn-stolen-credentials-into-real-identities/</guid>
      <description>• How infostealers turn stolen credentials into real identities February 19, 2026 10:05 AM 0 Modern infostealers have expanded credential theft far beyond usernames and passwords.</description>
    </item>
    <item>
      <title>French Government Says 1.2 Million Bank Accounts Exposed in Breach</title>
      <link>https://cluster-site.onrender.com/posts/french-government-says-1.2-million-bank-accounts-exposed-in-breach/</link>
      <pubDate>Thu, 19 Feb 2026 15:02:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/french-government-says-1.2-million-bank-accounts-exposed-in-breach/</guid>
      <description>• France&amp;rsquo;s Ministry of Economy on Wednesday disclosed a breach that exposed information on 1.2 million bank accounts.Investigators discovered unauthorized access to the national ba</description>
    </item>
    <item>
      <title>ThreatsDay Bulletin: OpenSSL RCE, Foxit 0-Days, Copilot Leak, AI Password Flaws &amp; 20&#43; Stories</title>
      <link>https://cluster-site.onrender.com/posts/threatsday-bulletin-openssl-rce-foxit-0-days-copilot-leak-ai-password-flaws-20-stories/</link>
      <pubDate>Thu, 19 Feb 2026 14:35:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threatsday-bulletin-openssl-rce-foxit-0-days-copilot-leak-ai-password-flaws-20-stories/</guid>
      <description>• OpenSSL RCE vulnerability threatens legacy systems, demanding urgent patching across enterprises. • Foxit PDF zero-days expose document readers to remote code execution, affectin</description>
    </item>
    <item>
      <title>Nigerian man gets eight years in prison for hacking tax firms</title>
      <link>https://cluster-site.onrender.com/posts/nigerian-man-gets-eight-years-in-prison-for-hacking-tax-firms/</link>
      <pubDate>Thu, 19 Feb 2026 13:51:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nigerian-man-gets-eight-years-in-prison-for-hacking-tax-firms/</guid>
      <description>• Nigerian man gets eight years in prison for hacking tax firms February 19, 2026 08:51 AM 0 A Nigerian national was sentenced to eight years in prison for hacking multiple tax pre</description>
    </item>
    <item>
      <title>Nearly 1 Million User Records Compromised in Figure Data Breach</title>
      <link>https://cluster-site.onrender.com/posts/nearly-1-million-user-records-compromised-in-figure-data-breach/</link>
      <pubDate>Thu, 19 Feb 2026 13:19:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nearly-1-million-user-records-compromised-in-figure-data-breach/</guid>
      <description>• Nearly 1 million user records have been compromised in a data breach at blockchain-powered lender Figure Technology Solutions.The companyconfirmedto TechCrunch that it suffered a</description>
    </item>
    <item>
      <title>Texas sues TP-Link over Chinese hacking risks, user deception</title>
      <link>https://cluster-site.onrender.com/posts/texas-sues-tp-link-over-chinese-hacking-risks-user-deception/</link>
      <pubDate>Thu, 19 Feb 2026 12:36:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/texas-sues-tp-link-over-chinese-hacking-risks-user-deception/</guid>
      <description>• Texas sued networking giant TP-Link Systems, accusing the company of deceptively marketing its routers as secure while allowing Chinese state-backed hackers to exploit firmware v</description>
    </item>
    <item>
      <title>Hackers target Microsoft Entra accounts in device code vishing attacks</title>
      <link>https://cluster-site.onrender.com/posts/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/</link>
      <pubDate>Thu, 19 Feb 2026 12:30:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/</guid>
      <description>• Hackers target Microsoft Entra accounts via device code vishing, exploiting OAuth 2.0 flow. • Attack uses legitimate OAuth client IDs, bypassing phishing sites and standard login</description>
    </item>
    <item>
      <title>Venice Security Emerges From Stealth With $33M Funding for Privileged Access Management</title>
      <link>https://cluster-site.onrender.com/posts/venice-security-emerges-from-stealth-with-33m-funding-for-privileged-access-management/</link>
      <pubDate>Thu, 19 Feb 2026 12:23:41 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/venice-security-emerges-from-stealth-with-33m-funding-for-privileged-access-management/</guid>
      <description>• Venice Security on Wednesday emerged from stealth mode with $33 million in funding for its adaptive enterprise privileged access management platform.The company, formerly named V</description>
    </item>
    <item>
      <title>Malicious AI</title>
      <link>https://cluster-site.onrender.com/posts/malicious-ai/</link>
      <pubDate>Thu, 19 Feb 2026 12:05:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-ai/</guid>
      <description>• Malicious AI Summary: An AI agent of unknown ownership autonomously wrote and published a personalized hit piece about me after I rejected its code, attempting to damage my reput</description>
    </item>
    <item>
      <title>From Exposure to Exploitation: How AI Collapses Your Response Window</title>
      <link>https://cluster-site.onrender.com/posts/from-exposure-to-exploitation-how-ai-collapses-your-response-window/</link>
      <pubDate>Thu, 19 Feb 2026 11:55:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/from-exposure-to-exploitation-how-ai-collapses-your-response-window/</guid>
      <description>• From Exposure to Exploitation: How AI Collapses Your Response Window We&amp;rsquo;ve all seen this before: a developer deploys a new cloud workload and grants overly broad permissions just</description>
    </item>
    <item>
      <title>Police arrests 651 suspects in African cybercrime crackdown</title>
      <link>https://cluster-site.onrender.com/posts/police-arrests-651-suspects-in-african-cybercrime-crackdown/</link>
      <pubDate>Thu, 19 Feb 2026 11:24:17 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/police-arrests-651-suspects-in-african-cybercrime-crackdown/</guid>
      <description>• Police arrests 651 suspects in African cybercrime crackdown February 19, 2026 06:24 AM 0 African law enforcement agencies arrested 651 suspects and recovered over $4.3 million in</description>
    </item>
    <item>
      <title>Arkanix Stealer: a C&#43;&#43; &amp; Python infostealer</title>
      <link>https://cluster-site.onrender.com/posts/arkanix-stealer-a-c-python-infostealer/</link>
      <pubDate>Thu, 19 Feb 2026 11:00:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/arkanix-stealer-a-c-python-infostealer/</guid>
      <description>• Introduction In October 2025, we discovered a series of forum posts advertising a previously unknown stealer, dubbed &amp;lsquo;Arkanix Stealer&amp;rsquo; by its authors. • It operated under a MaaS</description>
    </item>
    <item>
      <title>OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts</title>
      <link>https://cluster-site.onrender.com/posts/openclaw-security-issues-continue-as-secureclaw-open-source-tool-debuts/</link>
      <pubDate>Thu, 19 Feb 2026 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/openclaw-security-issues-continue-as-secureclaw-open-source-tool-debuts/</guid>
      <description>• OpenClaw is rarely out of the news, but not necessarily under that name. • This &amp;lsquo;autonomous personal assistant&amp;rsquo; started life as Clawdbot, changed its name to Moltbot, and is now</description>
    </item>
    <item>
      <title>Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users</title>
      <link>https://cluster-site.onrender.com/posts/fake-iptv-apps-spread-massiv-android-malware-targeting-mobile-banking-users/</link>
      <pubDate>Thu, 19 Feb 2026 10:24:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-iptv-apps-spread-massiv-android-malware-targeting-mobile-banking-users/</guid>
      <description>• Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users Cybersecurity researchers have disclosed details of a new Android trojan calledMassivthat&amp;rsquo;s designed t</description>
    </item>
    <item>
      <title>New &#39;Massiv&#39; Android banking malware poses as an IPTV app</title>
      <link>https://cluster-site.onrender.com/posts/new-massiv-android-banking-malware-poses-as-an-iptv-app/</link>
      <pubDate>Thu, 19 Feb 2026 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-massiv-android-banking-malware-poses-as-an-iptv-app/</guid>
      <description>• New &amp;lsquo;Massiv&amp;rsquo; Android banking malware poses as an IPTV app February 19, 2026 05:00 AM 0 A new Android banking malware, which researchers named Massiv, is posing as an IPTV app to</description>
    </item>
    <item>
      <title>German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack</title>
      <link>https://cluster-site.onrender.com/posts/german-rail-giant-deutsche-bahn-hit-by-large-scale-ddos-attack/</link>
      <pubDate>Thu, 19 Feb 2026 09:16:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/german-rail-giant-deutsche-bahn-hit-by-large-scale-ddos-attack/</guid>
      <description>• Deutsche Bahn, Germany&amp;rsquo;s national rail operator, has been dealing with a large-scale distributed denial-of-service (DDoS) attack that has disrupted some of its IT systems.Regular</description>
    </item>
    <item>
      <title>CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware</title>
      <link>https://cluster-site.onrender.com/posts/crescentharvest-campaign-targets-iran-protest-supporters-with-rat-malware/</link>
      <pubDate>Thu, 19 Feb 2026 08:13:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crescentharvest-campaign-targets-iran-protest-supporters-with-rat-malware/</guid>
      <description>• CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware Cybersecurity researchers have disclosed details of a new campaign dubbedCRESCENTHARVEST, likely targeti</description>
    </item>
    <item>
      <title>February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs Patched</title>
      <link>https://cluster-site.onrender.com/posts/february-2026-patch-tuesday-six-zero-days-among-59-cves-patched/</link>
      <pubDate>Thu, 19 Feb 2026 07:30:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/february-2026-patch-tuesday-six-zero-days-among-59-cves-patched/</guid>
      <description>• Patch Tuesday 2026 fixed 59 CVEs, including six critical zero‑days. • CVE‑2026‑21533: Windows Remote Desktop elevation of privilege, CVSS 7.8. • Exploit modifies service config k</description>
    </item>
    <item>
      <title>More Than 40% of South Africans Were Scammed in 2025</title>
      <link>https://cluster-site.onrender.com/posts/more-than-40-of-south-africans-were-scammed-in-2025/</link>
      <pubDate>Thu, 19 Feb 2026 07:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/more-than-40-of-south-africans-were-scammed-in-2025/</guid>
      <description>• Survey underscores the reality that scammers follow &amp;lsquo;scalable opportunities and low friction,&amp;rsquo; rather than rich targets that tend to be better protected.</description>
    </item>
    <item>
      <title>ISC Stormcast For Thursday, February 19th, 2026 https://isc.sans.edu/podcastdetail/9816, (Thu, Feb 19th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-thursday-february-19th-2026-https/isc.sans.edu/podcastdetail/9816-thu-feb-19th/</link>
      <pubDate>Thu, 19 Feb 2026 02:00:03 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-thursday-february-19th-2026-https/isc.sans.edu/podcastdetail/9816-thu-feb-19th/</guid>
      <description>• ISC Stormcast For Thursday, February 19th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9816&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9816&lt;/a&gt;
 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security:</description>
    </item>
    <item>
      <title>Exposing Insider Threats through Data Protection, Identity, and HR Context</title>
      <link>https://cluster-site.onrender.com/posts/exposing-insider-threats-through-data-protection-identity-and-hr-context/</link>
      <pubDate>Wed, 18 Feb 2026 22:30:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/exposing-insider-threats-through-data-protection-identity-and-hr-context/</guid>
      <description>• Insider threats pose a growing risk to organizations. • Whether insiders take malicious actions, exhibit negligent behavior, or make accidental errors, they have the potential to</description>
    </item>
    <item>
      <title>Scam Abuses Gemini Chatbots to Convince People to Buy Fake Crypto</title>
      <link>https://cluster-site.onrender.com/posts/scam-abuses-gemini-chatbots-to-convince-people-to-buy-fake-crypto/</link>
      <pubDate>Wed, 18 Feb 2026 21:47:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scam-abuses-gemini-chatbots-to-convince-people-to-buy-fake-crypto/</guid>
      <description>• A convincing presale site for phony &amp;lsquo;Google Coin&amp;rsquo; features an AI assistant that engages victims with a slick sales pitch, funneling payment to attackers.</description>
    </item>
    <item>
      <title>Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot</title>
      <link>https://cluster-site.onrender.com/posts/critical-grandstream-voip-bug-highlights-smb-security-blind-spot/</link>
      <pubDate>Wed, 18 Feb 2026 21:15:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/critical-grandstream-voip-bug-highlights-smb-security-blind-spot/</guid>
      <description>• CVE-2026-2329 allows unauthenticated root-level access to SMB phone infrastructure, so attackers can intercept calls, commit toll fraud, and impersonate users.</description>
    </item>
    <item>
      <title>Critical infra Honeywell CCTVs vulnerable to auth bypass flaw</title>
      <link>https://cluster-site.onrender.com/posts/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/</link>
      <pubDate>Wed, 18 Feb 2026 20:58:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/</guid>
      <description>• Critical infra Honeywell CCTVs vulnerable to auth bypass flaw February 18, 2026 03:58 PM 0 The U.S. • Cybersecurity and Infrastructure Security Agency (CISA) is warning of a crit</description>
    </item>
    <item>
      <title>Threat Intelligence Has a Human-Shaped Blind Spot</title>
      <link>https://cluster-site.onrender.com/posts/threat-intelligence-has-a-human-shaped-blind-spot/</link>
      <pubDate>Wed, 18 Feb 2026 20:56:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-intelligence-has-a-human-shaped-blind-spot/</guid>
      <description>• How I realized what I was taught to about threat intelligence was missing something crucial.</description>
    </item>
    <item>
      <title>Dell&#39;s Hard-Coded Flaw: A Nation-State Goldmine</title>
      <link>https://cluster-site.onrender.com/posts/dells-hard-coded-flaw-a-nation-state-goldmine/</link>
      <pubDate>Wed, 18 Feb 2026 20:49:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dells-hard-coded-flaw-a-nation-state-goldmine/</guid>
      <description>• A China-related attacker has exploited the vendor flaw since mid-2024, allowing it to move laterally, maintain persistent access, and deploy malware.</description>
    </item>
    <item>
      <title>AI platforms can be abused for stealthy malware communication</title>
      <link>https://cluster-site.onrender.com/posts/ai-platforms-can-be-abused-for-stealthy-malware-communication/</link>
      <pubDate>Wed, 18 Feb 2026 20:18:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-platforms-can-be-abused-for-stealthy-malware-communication/</guid>
      <description>• AI platforms can be abused for stealthy malware communication February 18, 2026 03:18 PM 0 AI assistants like Grok and Microsoft Copilot with web browsing and URL-fetching capabi</description>
    </item>
    <item>
      <title>A CISO&#39;s Playbook for Defending Data Assets Against AI Scraping</title>
      <link>https://cluster-site.onrender.com/posts/a-cisos-playbook-for-defending-data-assets-against-ai-scraping/</link>
      <pubDate>Wed, 18 Feb 2026 19:13:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-cisos-playbook-for-defending-data-assets-against-ai-scraping/</guid>
      <description>• Cyber Risk Commentary Cybersecurity In-Depth: Getting answers to questions about IT security threats and best practices from trusted cybersecurity professionals and industry expe</description>
    </item>
    <item>
      <title>AI Unlocked Decoding Prompt Injection Interactive Challenge</title>
      <link>https://cluster-site.onrender.com/posts/ai-unlocked-decoding-prompt-injection-interactive-challenge/</link>
      <pubDate>Wed, 18 Feb 2026 18:30:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-unlocked-decoding-prompt-injection-interactive-challenge/</guid>
      <description>• AI Unlocked challenge focuses on detecting and mitigating prompt injection attacks. • Participants learn to craft prompts that resist malicious manipulation by LLMs. • Interactiv</description>
    </item>
    <item>
      <title>Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist&#39;s Phone in Police Custody</title>
      <link>https://cluster-site.onrender.com/posts/citizen-lab-finds-cellebrite-tool-used-on-kenyan-activists-phone-in-police-custody/</link>
      <pubDate>Wed, 18 Feb 2026 17:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/citizen-lab-finds-cellebrite-tool-used-on-kenyan-activists-phone-in-police-custody/</guid>
      <description>• Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist&amp;rsquo;s Phone in Police Custody New research from the Citizen Lab has found signs that Kenyan authorities used a commercialfor</description>
    </item>
    <item>
      <title>Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution</title>
      <link>https://cluster-site.onrender.com/posts/grandstream-gxp1600-voip-phones-exposed-to-unauthenticated-remote-code-execution/</link>
      <pubDate>Wed, 18 Feb 2026 16:35:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/grandstream-gxp1600-voip-phones-exposed-to-unauthenticated-remote-code-execution/</guid>
      <description>• Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution Cybersecurity researchers have disclosed a critical security flaw in the Grandstream GXP1600 seri</description>
    </item>
    <item>
      <title>Telegram channels expose rapid weaponization of SmarterMail flaws</title>
      <link>https://cluster-site.onrender.com/posts/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/</link>
      <pubDate>Wed, 18 Feb 2026 16:27:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/</guid>
      <description>• SmarterMail CVE-2026-24423 and CVE-2026-23760 enable remote code execution and auth bypass. • Attackers weaponized these flaws within days of disclosure, sharing exploits on Tele</description>
    </item>
    <item>
      <title>Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-anti-phishing-rules-mistakenly-blocked-emails-teams-messages/</link>
      <pubDate>Wed, 18 Feb 2026 16:26:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-anti-phishing-rules-mistakenly-blocked-emails-teams-messages/</guid>
      <description>• Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages February 18, 2026 11:26 AM 0 Microsoft says an Exchange Online issue that mistakenly quarantined legitima</description>
    </item>
    <item>
      <title>New Keenadu Android Malware Found on Thousands of Devices</title>
      <link>https://cluster-site.onrender.com/posts/new-keenadu-android-malware-found-on-thousands-of-devices/</link>
      <pubDate>Wed, 18 Feb 2026 15:41:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-keenadu-android-malware-found-on-thousands-of-devices/</guid>
      <description>• Researchers at Kaspersky have analyzed a recently discovered Android malware that enables its operators to remotely control compromised devices.DubbedKeenadu, the backdoor has be</description>
    </item>
    <item>
      <title>Cogent Security Raises $42 Million for AI-Driven Vulnerability Management</title>
      <link>https://cluster-site.onrender.com/posts/cogent-security-raises-42-million-for-ai-driven-vulnerability-management/</link>
      <pubDate>Wed, 18 Feb 2026 14:47:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cogent-security-raises-42-million-for-ai-driven-vulnerability-management/</guid>
      <description>• Cogent Security raises $42M Series A, total funding now $53M. • Funding led by Bain Capital Ventures, joined by Greylock, OpenAI execs, Datadog. • Company develops autonomous AI</description>
    </item>
    <item>
      <title>Data breach at fintech firm Figure affects nearly 1 million accounts</title>
      <link>https://cluster-site.onrender.com/posts/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/</link>
      <pubDate>Wed, 18 Feb 2026 14:01:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/</guid>
      <description>• Hackers breached Figure Technology Solutions, stealing personal data of nearly 1 million accounts. • Attack was a social‑engineering phishing that tricked an employee into giving</description>
    </item>
    <item>
      <title>Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration</title>
      <link>https://cluster-site.onrender.com/posts/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/</link>
      <pubDate>Wed, 18 Feb 2026 13:16:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/</guid>
      <description>• 16 critical, high, and medium‑severity vulnerabilities found in Foxit and Apryse PDF platforms. • Flaws include DOM XSS, SSRF, path traversal, and OS command injection. • Attacke</description>
    </item>
    <item>
      <title>AI Found Twelve New Vulnerabilities in OpenSSL</title>
      <link>https://cluster-site.onrender.com/posts/ai-found-twelve-new-vulnerabilities-in-openssl/</link>
      <pubDate>Wed, 18 Feb 2026 12:03:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-found-twelve-new-vulnerabilities-in-openssl/</guid>
      <description>• AI Found Twelve New Vulnerabilities in OpenSSL The title of the post is&amp;rsquo;What AI Security Research Looks Like When It Works,&amp;rsquo; and I agree: In the latest OpenSSL security release&amp;gt;</description>
    </item>
    <item>
      <title>Microsoft says bug causes Copilot to summarize confidential emails</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/</link>
      <pubDate>Wed, 18 Feb 2026 12:03:05 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/</guid>
      <description>• Microsoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies th</description>
    </item>
    <item>
      <title>Cybersecurity Tech Predictions for 2026: Operating in a World of Permanent Instability</title>
      <link>https://cluster-site.onrender.com/posts/cybersecurity-tech-predictions-for-2026-operating-in-a-world-of-permanent-instability/</link>
      <pubDate>Wed, 18 Feb 2026 11:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cybersecurity-tech-predictions-for-2026-operating-in-a-world-of-permanent-instability/</guid>
      <description>• In 2025, navigating the digital seas still felt like a matter of direction. • Organizations charted routes, watched the horizon, and adjusted course to reach safe harbors of resi</description>
    </item>
    <item>
      <title>Glendale man gets 5 years in prison for role in darknet drug ring</title>
      <link>https://cluster-site.onrender.com/posts/glendale-man-gets-5-years-in-prison-for-role-in-darknet-drug-ring/</link>
      <pubDate>Wed, 18 Feb 2026 10:50:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/glendale-man-gets-5-years-in-prison-for-role-in-darknet-drug-ring/</guid>
      <description>• Glendale man gets 5 years in prison for role in darknet drug ring February 18, 2026 05:50 AM 0 ​A Glendale man was sentenced to nearly five years in federal prison for his role i</description>
    </item>
    <item>
      <title>3 Ways to Start Your Intelligent Workflow Program</title>
      <link>https://cluster-site.onrender.com/posts/3-ways-to-start-your-intelligent-workflow-program/</link>
      <pubDate>Wed, 18 Feb 2026 10:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/3-ways-to-start-your-intelligent-workflow-program/</guid>
      <description>• 3 Ways to Start Your Intelligent Workflow Program Security, IT, and engineering teams today are under relentless pressure to accelerate outcomes, cut operational drag, and unlock</description>
    </item>
    <item>
      <title>Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction</title>
      <link>https://cluster-site.onrender.com/posts/palo-alto-networks-to-acquire-koi-in-reported-400-million-transaction/</link>
      <pubDate>Wed, 18 Feb 2026 08:24:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/palo-alto-networks-to-acquire-koi-in-reported-400-million-transaction/</guid>
      <description>• Palo Alto Networks announced on Tuesday that it has entered into a definitive agreement to acquire endpoint security company Koi.Financial details have not been disclosed by the</description>
    </item>
    <item>
      <title>Tracking Malware Campaigns With Reused Material, (Wed, Feb 18th)</title>
      <link>https://cluster-site.onrender.com/posts/tracking-malware-campaigns-with-reused-material-wed-feb-18th/</link>
      <pubDate>Wed, 18 Feb 2026 08:19:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/tracking-malware-campaigns-with-reused-material-wed-feb-18th/</guid>
      <description>• Tracking Malware Campaigns With Reused Material A few days ago I wrote a diary called &amp;lsquo;Malicious Script Delivering More Maliciousness&amp;rsquo;[1]. • In the malware infection chain, there</description>
    </item>
    <item>
      <title>Notepad&#43;&#43; Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware</title>
      <link>https://cluster-site.onrender.com/posts/notepad-fixes-hijacked-update-mechanism-used-to-deliver-targeted-malware/</link>
      <pubDate>Wed, 18 Feb 2026 07:40:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/notepad-fixes-hijacked-update-mechanism-used-to-deliver-targeted-malware/</guid>
      <description>• Notepad++ released 8.9.2 patch to fix hijacked update mechanism exploited by Chinese threat actor. • Introduces &amp;lsquo;double lock&amp;rsquo; design, verifying signed installer and XML from upda</description>
    </item>
    <item>
      <title>Singapore &amp;amp; Its 4 Major Telcos Fend Off Chinese Hackers</title>
      <link>https://cluster-site.onrender.com/posts/singapore-amp-its-4-major-telcos-fend-off-chinese-hackers/</link>
      <pubDate>Wed, 18 Feb 2026 01:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/singapore-amp-its-4-major-telcos-fend-off-chinese-hackers/</guid>
      <description>• Singapore&amp;rsquo;s CSA and four telcos launched &amp;lsquo;Cyber Guardian&amp;rsquo; to counter China-linked UNC3886.\n• 100+ incident responders coordinated across government and M1, Singtel, StarHub, Sim</description>
    </item>
    <item>
      <title>Spain orders NordVPN and ProtonVPN to block LaLiga stream piracy</title>
      <link>https://cluster-site.onrender.com/posts/spain-orders-nordvpn-and-protonvpn-to-block-laliga-stream-piracy/</link>
      <pubDate>Tue, 17 Feb 2026 23:15:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spain-orders-nordvpn-and-protonvpn-to-block-laliga-stream-piracy/</guid>
      <description>• Spanish court orders NordVPN and ProtonVPN to block 16 sites facilitating LaLiga match piracy. • Restrictions apply to a dynamic IP list in Spain, with no appeal rights for VPNs.</description>
    </item>
    <item>
      <title>Supply Chain Attack Embeds Malware in Android Devices</title>
      <link>https://cluster-site.onrender.com/posts/supply-chain-attack-embeds-malware-in-android-devices/</link>
      <pubDate>Tue, 17 Feb 2026 22:06:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/supply-chain-attack-embeds-malware-in-android-devices/</guid>
      <description>• Keenadu downloads payloads that hijack browser searches, commit ad fraud, and execute other actions without user knowledge.</description>
    </item>
    <item>
      <title>Poland Energy Survives Attack on Wind, Solar Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/poland-energy-survives-attack-on-wind-solar-infrastructure/</link>
      <pubDate>Tue, 17 Feb 2026 21:31:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/poland-energy-survives-attack-on-wind-solar-infrastructure/</guid>
      <description>• Russia-aligned groups are probable culprits behind the wiper attacks against renewable energy farms, a manufacturer, and a heating and power plant.</description>
    </item>
    <item>
      <title>Flaws in popular VSCode extensions expose developers to attacks</title>
      <link>https://cluster-site.onrender.com/posts/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/</link>
      <pubDate>Tue, 17 Feb 2026 21:27:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/</guid>
      <description>• Flaws in popular VSCode extensions expose developers to attacks February 17, 2026 04:27 PM 0 Vulnerabilities with high to critical severity ratings affecting popular Visual Studi</description>
    </item>
    <item>
      <title>RMM Abuse Explodes as Hackers Ditch Malware</title>
      <link>https://cluster-site.onrender.com/posts/rmm-abuse-explodes-as-hackers-ditch-malware/</link>
      <pubDate>Tue, 17 Feb 2026 21:01:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/rmm-abuse-explodes-as-hackers-ditch-malware/</guid>
      <description>• RMM tools are increasingly used as primary attack vectors, replacing traditional malware. • Attackers leverage RMM&amp;rsquo;s remote access to maintain stealth and persistence. • RMM&amp;rsquo;s bu</description>
    </item>
    <item>
      <title>ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT</title>
      <link>https://cluster-site.onrender.com/posts/clickfix-attacks-abuses-dns-lookup-command-to-deliver-modelorat/</link>
      <pubDate>Tue, 17 Feb 2026 21:01:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/clickfix-attacks-abuses-dns-lookup-command-to-deliver-modelorat/</guid>
      <description>• ClickFix campaigns have adapted to the latest defenses with a new technique to trick users into infecting their own machines with malware.</description>
    </item>
    <item>
      <title>Critical Vulnerabilities in Ivanti EPMM Exploited</title>
      <link>https://cluster-site.onrender.com/posts/critical-vulnerabilities-in-ivanti-epmm-exploited/</link>
      <pubDate>Tue, 17 Feb 2026 20:35:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/critical-vulnerabilities-in-ivanti-epmm-exploited/</guid>
      <description>• Executive Summary Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild</description>
    </item>
    <item>
      <title>Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster</title>
      <link>https://cluster-site.onrender.com/posts/webinar-how-modern-soc-teams-use-ai-and-context-to-investigate-cloud-breaches-faster/</link>
      <pubDate>Tue, 17 Feb 2026 19:08:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/webinar-how-modern-soc-teams-use-ai-and-context-to-investigate-cloud-breaches-faster/</guid>
      <description>• Cloud attacks outpace traditional incident response, infrastructure vanishes in minutes. • Manual log stitching gives attackers advantage; automated, context-aware forensics need</description>
    </item>
    <item>
      <title>Notepad&#43;&#43; boosts update security with &#39;double-lock&#39; mechanism</title>
      <link>https://cluster-site.onrender.com/posts/notepad-boosts-update-security-with-double-lock-mechanism/</link>
      <pubDate>Tue, 17 Feb 2026 18:29:18 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/notepad-boosts-update-security-with-double-lock-mechanism/</guid>
      <description>• Notepad++ introduces a double‑lock update system, verifying signed installers from GitHub and XML from its domain. • The new design eliminates DLL side‑loading by removing libcur</description>
    </item>
    <item>
      <title>Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies</title>
      <link>https://cluster-site.onrender.com/posts/researchers-show-copilot-and-grok-can-be-abused-as-malware-c2-proxies/</link>
      <pubDate>Tue, 17 Feb 2026 18:08:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/researchers-show-copilot-and-grok-can-be-abused-as-malware-c2-proxies/</guid>
      <description>• AI assistants like Copilot and Grok can be hijacked as stealthy C2 proxies, blending into legitimate traffic. • Check Point researchers demonstrated the technique using anonymous</description>
    </item>
    <item>
      <title>Unify now or pay later: New research exposes the operational cost of a fragmented SOC</title>
      <link>https://cluster-site.onrender.com/posts/unify-now-or-pay-later-new-research-exposes-the-operational-cost-of-a-fragmented-soc/</link>
      <pubDate>Tue, 17 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/unify-now-or-pay-later-new-research-exposes-the-operational-cost-of-a-fragmented-soc/</guid>
      <description>• Share Link copied to clipboard! • Content types Industry trends Topics AI and agents Defending against advanced tactics Security management Security operations SIEM and XDR Secur</description>
    </item>
    <item>
      <title>Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates</title>
      <link>https://cluster-site.onrender.com/posts/keenadu-firmware-backdoor-infects-android-tablets-via-signed-ota-updates/</link>
      <pubDate>Tue, 17 Feb 2026 16:41:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/keenadu-firmware-backdoor-infects-android-tablets-via-signed-ota-updates/</guid>
      <description>• Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates A new Android backdoor that&amp;rsquo;s embedded deep into the device firmware can silently harvest data and remote</description>
    </item>
    <item>
      <title>VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence</title>
      <link>https://cluster-site.onrender.com/posts/vulncheck-raises-25-million-in-series-b-funding-to-scale-vulnerability-intelligence/</link>
      <pubDate>Tue, 17 Feb 2026 16:00:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vulncheck-raises-25-million-in-series-b-funding-to-scale-vulnerability-intelligence/</guid>
      <description>• Vulnerability intelligence company VulnCheck announced on Tuesday that it has raised $25 million to meet demand for its solutions.The Series B funding round, which brings the tot</description>
    </item>
    <item>
      <title>Microsoft Teams outage affects users in United States, Europe</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-teams-outage-affects-users-in-united-states-europe/</link>
      <pubDate>Tue, 17 Feb 2026 15:37:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-teams-outage-affects-users-in-united-states-europe/</guid>
      <description>• Microsoft Teams experiencing widespread outage across US and Europe, disrupting meetings and chat functionality. • Users report delays and failures when sending or receiving inli</description>
    </item>
    <item>
      <title>What 5 Million Apps Revealed About Secrets in JavaScript</title>
      <link>https://cluster-site.onrender.com/posts/what-5-million-apps-revealed-about-secrets-in-javascript/</link>
      <pubDate>Tue, 17 Feb 2026 14:40:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-5-million-apps-revealed-about-secrets-in-javascript/</guid>
      <description>• What 5 Million Apps Revealed About Secrets in JavaScript February 17, 2026 09:40 AM 0 Leaked API keys are nothing new, but the scale of the problem in front-end code has been lar</description>
    </item>
    <item>
      <title>New Keenadu backdoor found in Android firmware, Google Play apps</title>
      <link>https://cluster-site.onrender.com/posts/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/</link>
      <pubDate>Tue, 17 Feb 2026 14:05:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/</guid>
      <description>• Keenadu: sophisticated Android malware embedded in firmware across multiple device brands. • Distributes via OTA firmware, system apps, unofficial sources, and Google Play apps.</description>
    </item>
    <item>
      <title>API Threats Grow in Scale as AI Expands the Blast Radius</title>
      <link>https://cluster-site.onrender.com/posts/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/</link>
      <pubDate>Tue, 17 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/</guid>
      <description>• Application Programming Interfaces (APIs) remain an attacker-favored exploit route. • Aggressors continuously target common failures in identity, access control and exposed inter</description>
    </item>
    <item>
      <title>Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems</title>
      <link>https://cluster-site.onrender.com/posts/cyber-insights-2026-the-ongoing-fight-to-secure-industrial-control-systems/</link>
      <pubDate>Tue, 17 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cyber-insights-2026-the-ongoing-fight-to-secure-industrial-control-systems/</guid>
      <description>• SecurityWeek&amp;rsquo;s Cyber Insights 2026 examines expert opinions on the expected evolution of more than a dozen areas of cybersecurity interest over the next 12 months. • We spoke to</description>
    </item>
    <item>
      <title>Man Linked to Phobos Ransomware Arrested in Poland</title>
      <link>https://cluster-site.onrender.com/posts/man-linked-to-phobos-ransomware-arrested-in-poland/</link>
      <pubDate>Tue, 17 Feb 2026 12:54:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/man-linked-to-phobos-ransomware-arrested-in-poland/</guid>
      <description>• A 47-year-old man arrested by police in Poland for allegedly being involved in cybercriminal activities has been linked to the Phobos ransomware operation.According to Poland&amp;rsquo;s C</description>
    </item>
    <item>
      <title>SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer</title>
      <link>https://cluster-site.onrender.com/posts/smartloader-attack-uses-trojanized-oura-mcp-server-to-deploy-stealc-infostealer/</link>
      <pubDate>Tue, 17 Feb 2026 12:42:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/smartloader-attack-uses-trojanized-oura-mcp-server-to-deploy-stealc-infostealer/</guid>
      <description>• SmartLoader uses a trojanized Oura MCP server to deliver the StealC infostealer. • Threat actors cloned legitimate Oura MCP, creating fake forks to build credibility. • StealC st</description>
    </item>
    <item>
      <title>Side-Channel Attacks Against LLMs</title>
      <link>https://cluster-site.onrender.com/posts/side-channel-attacks-against-llms/</link>
      <pubDate>Tue, 17 Feb 2026 12:01:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/side-channel-attacks-against-llms/</guid>
      <description>• Side-Channel Attacks Against LLMs Here are three papers describing different side-channel attacks against LLMs. • &amp;lsquo;Remote Timing Attacks on Efficient Language Model Inference&amp;rsquo;: A</description>
    </item>
    <item>
      <title>Poland arrests suspect linked to Phobos ransomware operation</title>
      <link>https://cluster-site.onrender.com/posts/poland-arrests-suspect-linked-to-phobos-ransomware-operation/</link>
      <pubDate>Tue, 17 Feb 2026 11:31:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/poland-arrests-suspect-linked-to-phobos-ransomware-operation/</guid>
      <description>• Poland arrests suspect linked to Phobos ransomware operation February 17, 2026 06:31 AM 0 Polish police have detained a 47-year-old man suspected of ties to the Phobos ransomware</description>
    </item>
    <item>
      <title>My Day Getting My Hands Dirty with an NDR System</title>
      <link>https://cluster-site.onrender.com/posts/my-day-getting-my-hands-dirty-with-an-ndr-system/</link>
      <pubDate>Tue, 17 Feb 2026 11:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/my-day-getting-my-hands-dirty-with-an-ndr-system/</guid>
      <description>• My objective As someone relatively inexperienced with network threat hunting, I wanted to get some hands-on experience using a network detection and response (NDR) system. • My g</description>
    </item>
    <item>
      <title>3 Threat Groups Started Targeting ICS/OT in 2025: Dragos</title>
      <link>https://cluster-site.onrender.com/posts/3-threat-groups-started-targeting-ics/ot-in-2025-dragos/</link>
      <pubDate>Tue, 17 Feb 2026 11:05:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/3-threat-groups-started-targeting-ics/ot-in-2025-dragos/</guid>
      <description>• Dragos 9th Annual Report reveals three new OT/ICS threat groups active in 2025. • Sylvanite rapidly weaponizes n‑day vulnerabilities, enabling Voltzite to infiltrate critical inf</description>
    </item>
    <item>
      <title>Ireland now also investigating X over Grok-made sexual images</title>
      <link>https://cluster-site.onrender.com/posts/ireland-now-also-investigating-x-over-grok-made-sexual-images/</link>
      <pubDate>Tue, 17 Feb 2026 10:02:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ireland-now-also-investigating-x-over-grok-made-sexual-images/</guid>
      <description>• Ireland&amp;rsquo;s Data Protection Commission (DPC), the country&amp;rsquo;s data protection authority, has opened a formal investigation into X over the use of the platform&amp;rsquo;s Grok artificial intel</description>
    </item>
    <item>
      <title>Microsoft Finds &#39;Summarize with AI&#39; Prompts Manipulating Chatbot Recommendations</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-finds-summarize-with-ai-prompts-manipulating-chatbot-recommendations/</link>
      <pubDate>Tue, 17 Feb 2026 09:31:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-finds-summarize-with-ai-prompts-manipulating-chatbot-recommendations/</guid>
      <description>• Microsoft Finds &amp;lsquo;Summarize with AI&amp;rsquo; Prompts Manipulating Chatbot Recommendations New research from Microsoft has revealed that legitimate businesses are gaming artificial intelli</description>
    </item>
    <item>
      <title>Password Managers Vulnerable to Vault Compromise Under Malicious Server</title>
      <link>https://cluster-site.onrender.com/posts/password-managers-vulnerable-to-vault-compromise-under-malicious-server/</link>
      <pubDate>Tue, 17 Feb 2026 09:30:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/password-managers-vulnerable-to-vault-compromise-under-malicious-server/</guid>
      <description>• ETH Zurich researchers tested zero‑knowledge password managers against fully malicious servers. • Bitwarden, Dashlane, LastPass, and 1Password were evaluated. • Attacks targeted</description>
    </item>
    <item>
      <title>Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets</title>
      <link>https://cluster-site.onrender.com/posts/divide-and-conquer-how-the-new-keenadu-backdoor-exposed-links-between-major-android-botnets/</link>
      <pubDate>Tue, 17 Feb 2026 09:00:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/divide-and-conquer-how-the-new-keenadu-backdoor-exposed-links-between-major-android-botnets/</guid>
      <description>• In April 2025, we reported on a then-new iteration of the Triada backdoor that had compromised the firmware of counterfeit Android devices sold across major marketplaces. • The m</description>
    </item>
    <item>
      <title>CrowdStrike Falcon Scores Perfect 100% in SE Labs&amp;rsquo; Most Challenging Ransomware Test</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-falcon-scores-perfect-100-in-se-labsrsquo-most-challenging-ransomware-test/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:17 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-falcon-scores-perfect-100-in-se-labsrsquo-most-challenging-ransomware-test/</guid>
      <description>• FeaturedCrowdStrike Named a Customers&amp;rsquo; Choice in 2026 Gartner® Peer Insights™ Voice of the Customer for User AuthenticationFeb 12, 2026How to Scale SOC Automation with Falcon Fus</description>
    </item>
    <item>
      <title>Secure AI with CrowdStrike: Real-World Stories of Protecting AI Workloads and Data</title>
      <link>https://cluster-site.onrender.com/posts/secure-ai-with-crowdstrike-real-world-stories-of-protecting-ai-workloads-and-data/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:17 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/secure-ai-with-crowdstrike-real-world-stories-of-protecting-ai-workloads-and-data/</guid>
      <description>• FeaturedCrowdStrike Named a Customers&amp;rsquo; Choice in 2026 Gartner® Peer Insights™ Voice of the Customer for User AuthenticationFeb 12, 2026How to Scale SOC Automation with Falcon Fus</description>
    </item>
    <item>
      <title>CrowdStrike Enhances Linux Sensor for Web Shell Detection</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-enhances-linux-sensor-for-web-shell-detection/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-enhances-linux-sensor-for-web-shell-detection/</guid>
      <description>• CrowdStrike expands Linux sensor to detect malicious web shells in real time. • New detection engine uses behavioral analytics and signature matching for zero‑day threats. • Prev</description>
    </item>
    <item>
      <title>CrowdStrike Wins 2026 Gartner Peer Insights Customer Choice</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-wins-2026-gartner-peer-insights-customer-choice/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-wins-2026-gartner-peer-insights-customer-choice/</guid>
      <description>• CrowdStrike awarded Customer&amp;rsquo;s Choice in 2026 Gartner Peer Insights for user authentication. • Recognition reflects strong customer satisfaction and product performance across se</description>
    </item>
    <item>
      <title>OpenClaw AI Super Agent: Key Insights for Security Teams</title>
      <link>https://cluster-site.onrender.com/posts/openclaw-ai-super-agent-key-insights-for-security-teams/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/openclaw-ai-super-agent-key-insights-for-security-teams/</guid>
      <description>• OpenClaw automates threat detection and response across enterprise environments. • Seamless integration with CrowdStrike Falcon boosts SOC efficiency. • Human‑AI feedback loops r</description>
    </item>
    <item>
      <title>CrowdStrike Named Customers&#39; Choice in 2026 Gartner Voice</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-in-2026-gartner-voice/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-in-2026-gartner-voice/</guid>
      <description>• CrowdStrike earns Customers&amp;rsquo; Choice award in 2026 Gartner Peer Insights Voice of the Customer for User Authentication. • The accolade reflects strong customer satisfaction and pr</description>
    </item>
    <item>
      <title>CrowdStrike&#39;s Agentic Security Powered by Human‑AI Feedback Loop</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrikes-agentic-security-powered-by-humanai-feedback-loop/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrikes-agentic-security-powered-by-humanai-feedback-loop/</guid>
      <description>• CrowdStrike&amp;rsquo;s new Agentic Security framework blends human oversight with AI‑driven threat detection. • The system uses a continuous feedback loop where analysts refine AI models</description>
    </item>
    <item>
      <title>CrowdStrike Named Customers&#39; Choice User Authentication</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-user-authentication/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-user-authentication/</guid>
      <description>• CrowdStrike recognized as Customers&amp;rsquo; Choice for User Authentication in Gartner Peer Insights. • Falcon Identity Security delivers zero‑trust authentication across web, mobile, an</description>
    </item>
    <item>
      <title>Scale SOC Automation with Falcon Fusion SOAR</title>
      <link>https://cluster-site.onrender.com/posts/scale-soc-automation-with-falcon-fusion-soar/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scale-soc-automation-with-falcon-fusion-soar/</guid>
      <description>• Falcon Fusion SOAR scales SOC automation by integrating AI‑driven playbooks and real‑time incident response. • The platform supports multi‑cloud environments, enabling consistent</description>
    </item>
    <item>
      <title>Fake Incident Report Used in Phishing Campaign, (Tue, Feb 17th)</title>
      <link>https://cluster-site.onrender.com/posts/fake-incident-report-used-in-phishing-campaign-tue-feb-17th/</link>
      <pubDate>Tue, 17 Feb 2026 07:41:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-incident-report-used-in-phishing-campaign-tue-feb-17th/</guid>
      <description>• Fake Incident Report Used in Phishing Campaign This morning, I received an interesting phishing email. • I&amp;rsquo;ve a &amp;rsquo;love &amp;amp; hate&amp;rsquo; relation with such emails because I always have the</description>
    </item>
    <item>
      <title>Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta</title>
      <link>https://cluster-site.onrender.com/posts/apple-tests-end-to-end-encrypted-rcs-messaging-in-ios-26.4-developer-beta/</link>
      <pubDate>Tue, 17 Feb 2026 06:44:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/apple-tests-end-to-end-encrypted-rcs-messaging-in-ios-26.4-developer-beta/</guid>
      <description>• Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta Apple on Monday released a new developer beta of iOS and iPadOS with support for end-to-end encryption (</description>
    </item>
    <item>
      <title>ISC Stormcast For Tuesday, February 17th, 2026 https://isc.sans.edu/podcastdetail/9812, (Tue, Feb 17th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-tuesday-february-17th-2026-https/isc.sans.edu/podcastdetail/9812-tue-feb-17th/</link>
      <pubDate>Tue, 17 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-tuesday-february-17th-2026-https/isc.sans.edu/podcastdetail/9812-tue-feb-17th/</guid>
      <description>• ISC Stormcast For Tuesday, February 17th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9812&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9812&lt;/a&gt;
 Handler on Duty: Jan Kopriva Threat Level: green My next class: Application Security: Secur</description>
    </item>
    <item>
      <title>Washington Hotel in Japan discloses ransomware infection incident</title>
      <link>https://cluster-site.onrender.com/posts/washington-hotel-in-japan-discloses-ransomware-infection-incident/</link>
      <pubDate>Mon, 16 Feb 2026 21:10:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/washington-hotel-in-japan-discloses-ransomware-infection-incident/</guid>
      <description>• Washington Hotel in Japan discloses ransomware infection incident February 16, 2026 04:10 PM 0 The Washington Hotel brand in Japan has announced that that its servers were compro</description>
    </item>
    <item>
      <title>Man arrested for demanding reward after accidental police data leak</title>
      <link>https://cluster-site.onrender.com/posts/man-arrested-for-demanding-reward-after-accidental-police-data-leak/</link>
      <pubDate>Mon, 16 Feb 2026 19:13:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/man-arrested-for-demanding-reward-after-accidental-police-data-leak/</guid>
      <description>• Man arrested for demanding reward after accidental police data leak February 16, 2026 02:13 PM 1 Dutch authorities arrested a 40-year-old man after he downloaded confidential doc</description>
    </item>
    <item>
      <title>Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens</title>
      <link>https://cluster-site.onrender.com/posts/infostealer-steals-openclaw-ai-agent-configuration-files-and-gateway-tokens/</link>
      <pubDate>Mon, 16 Feb 2026 18:43:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/infostealer-steals-openclaw-ai-agent-configuration-files-and-gateway-tokens/</guid>
      <description>• Infostealer variant of Vidar exfiltrated OpenClaw AI agent config files. • Stolen files include openclaw.json, device.json, soul.md with tokens, keys, operational principles. • T</description>
    </item>
    <item>
      <title>Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers</title>
      <link>https://cluster-site.onrender.com/posts/study-uncovers-25-password-recovery-attacks-in-major-cloud-password-managers/</link>
      <pubDate>Mon, 16 Feb 2026 18:06:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/study-uncovers-25-password-recovery-attacks-in-major-cloud-password-managers/</guid>
      <description>• A new study has found that multiple cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks under certain conditi</description>
    </item>
    <item>
      <title>Operation DoppelBrand: Weaponizing Fortune 500 Brands</title>
      <link>https://cluster-site.onrender.com/posts/operation-doppelbrand-weaponizing-fortune-500-brands/</link>
      <pubDate>Mon, 16 Feb 2026 18:05:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/operation-doppelbrand-weaponizing-fortune-500-brands/</guid>
      <description>• GS7 group exploits Fortune 500 brand trust, creating near‑perfect corporate portal replicas. • Targeted U.S. financial institutions, luring employees into credential theft. • Att</description>
    </item>
    <item>
      <title>Infostealer malware found stealing OpenClaw secrets for first time</title>
      <link>https://cluster-site.onrender.com/posts/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/</link>
      <pubDate>Mon, 16 Feb 2026 17:32:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/</guid>
      <description>• Infostealer malware found stealing OpenClaw secrets for first time February 16, 2026 12:32 PM 0 With the massive adoption of the OpenClaw agentic AI assistant, information-steali</description>
    </item>
    <item>
      <title>Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches</title>
      <link>https://cluster-site.onrender.com/posts/dior-louis-vuitton-tiffany-fined-25-million-in-south-korea-after-data-breaches/</link>
      <pubDate>Mon, 16 Feb 2026 15:09:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dior-louis-vuitton-tiffany-fined-25-million-in-south-korea-after-data-breaches/</guid>
      <description>• South Korea&amp;rsquo;s Personal Information Protection Commission (PIPC) announced last week that it has issued significant fines to several major luxury brands over a recent hacker attac</description>
    </item>
    <item>
      <title>Passwords to passkeys: Staying ISO 27001 compliant in a passwordless era</title>
      <link>https://cluster-site.onrender.com/posts/passwords-to-passkeys-staying-iso-27001-compliant-in-a-passwordless-era/</link>
      <pubDate>Mon, 16 Feb 2026 15:02:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/passwords-to-passkeys-staying-iso-27001-compliant-in-a-passwordless-era/</guid>
      <description>• One morning, you wake up and realize that your business has grown to the point where you can no longer afford to get into that old, worn-out diesel subcompact. • Instead, you sch</description>
    </item>
    <item>
      <title>260K&#43; Chrome Users Duped by Fake AI Browser Extensions</title>
      <link>https://cluster-site.onrender.com/posts/260k-chrome-users-duped-by-fake-ai-browser-extensions/</link>
      <pubDate>Mon, 16 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/260k-chrome-users-duped-by-fake-ai-browser-extensions/</guid>
      <description>• 30 copycat apps tricked users, and Google itself, into thinking they&amp;rsquo;re legitimate AI tools.</description>
    </item>
    <item>
      <title>Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security</title>
      <link>https://cluster-site.onrender.com/posts/android-17-beta-strengthens-secure-by-default-design-for-privacy-and-app-security/</link>
      <pubDate>Mon, 16 Feb 2026 13:50:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/android-17-beta-strengthens-secure-by-default-design-for-privacy-and-app-security/</guid>
      <description>• Google announced the first beta version of Android 17, which includes several privacy and security enhancements.Android developers have described several improvements related to</description>
    </item>
    <item>
      <title>CISA Navigates DHS Shutdown With Reduced Staff</title>
      <link>https://cluster-site.onrender.com/posts/cisa-navigates-dhs-shutdown-with-reduced-staff/</link>
      <pubDate>Mon, 16 Feb 2026 13:49:03 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-navigates-dhs-shutdown-with-reduced-staff/</guid>
      <description>• CISAwill remain operational during the DHS shutdown that commenced at 12:01 a.m. • on Saturday, February 14, 2026, although at a reduced capacity. • KEV is one area that remains.</description>
    </item>
    <item>
      <title>CISA gives feds 3 days to patch actively exploited BeyondTrust flaw</title>
      <link>https://cluster-site.onrender.com/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-beyondtrust-flaw/</link>
      <pubDate>Mon, 16 Feb 2026 12:33:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-beyondtrust-flaw/</guid>
      <description>• CISA gives feds 3 days to patch actively exploited BeyondTrust flaw February 16, 2026 07:33 AM 1 The U.S. • Cybersecurity and Infrastructure Security Agency (CISA) ordered federa</description>
    </item>
    <item>
      <title>The Promptware Kill Chain</title>
      <link>https://cluster-site.onrender.com/posts/the-promptware-kill-chain/</link>
      <pubDate>Mon, 16 Feb 2026 12:04:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-promptware-kill-chain/</guid>
      <description>• The Promptware Kill Chain Attacks against modern generative artificial intelligence (AI) large language models (LLMs) pose a real threat. • Yet discussions around these attacks a</description>
    </item>
    <item>
      <title>Microsoft Warns of ClickFix Attack Abusing DNS Lookups</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-warns-of-clickfix-attack-abusing-dns-lookups/</link>
      <pubDate>Mon, 16 Feb 2026 11:56:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-warns-of-clickfix-attack-abusing-dns-lookups/</guid>
      <description>• Microsoft has warned users that threat actors are leveraging a new variant of the ClickFix technique to deliver malware.TheClickFixattack method has been increasingly used in the</description>
    </item>
    <item>
      <title>Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud</title>
      <link>https://cluster-site.onrender.com/posts/safe-and-inclusive-esociety-how-lithuania-is-bracing-for-aidriven-cyber-fraud/</link>
      <pubDate>Mon, 16 Feb 2026 11:55:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/safe-and-inclusive-esociety-how-lithuania-is-bracing-for-aidriven-cyber-fraud/</guid>
      <description>• Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud Technologies are evolving fast, reshaping economies, governance, and daily life. • Yet, as innova</description>
    </item>
    <item>
      <title>Amazon Scraps Partnership With Surveillance Company After Super Bowl Ad Backlash</title>
      <link>https://cluster-site.onrender.com/posts/amazon-scraps-partnership-with-surveillance-company-after-super-bowl-ad-backlash/</link>
      <pubDate>Mon, 16 Feb 2026 11:40:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/amazon-scraps-partnership-with-surveillance-company-after-super-bowl-ad-backlash/</guid>
      <description>• Amazon&amp;rsquo;s Ring ends partnership with police surveillance firm Flock Safety amid public backlash. • The decision follows a 30‑second Super Bowl ad featuring a lost dog and camera n</description>
    </item>
    <item>
      <title>New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft</title>
      <link>https://cluster-site.onrender.com/posts/new-zerodayrat-mobile-spyware-enables-real-time-surveillance-and-data-theft/</link>
      <pubDate>Mon, 16 Feb 2026 10:24:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-zerodayrat-mobile-spyware-enables-real-time-surveillance-and-data-theft/</guid>
      <description>• Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that&amp;rsquo;s being advertised on Telegram as a way to grab sensitive data and facili</description>
    </item>
    <item>
      <title>2026 64-Bits Malware Trend, (Mon, Feb 16th)</title>
      <link>https://cluster-site.onrender.com/posts/2026-64-bits-malware-trend-mon-feb-16th/</link>
      <pubDate>Mon, 16 Feb 2026 07:46:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/2026-64-bits-malware-trend-mon-feb-16th/</guid>
      <description>• 2026 64-Bits Malware Trend In 2022 (time flies!), I wrote a diary about the 32-bits VS. • 64-bits malware landscape[1]. • It demonstrated that, despite the growing number of 64-b</description>
    </item>
    <item>
      <title>New Chrome Zero-Day (CVE-2026-2441) Under Active Attack - Patch Released</title>
      <link>https://cluster-site.onrender.com/posts/new-chrome-zero-day-cve-2026-2441-under-active-attack-patch-released/</link>
      <pubDate>Mon, 16 Feb 2026 06:38:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-chrome-zero-day-cve-2026-2441-under-active-attack-patch-released/</guid>
      <description>• New Chrome Zero-Day (CVE-2026-2441) Under Active Attack - Patch Released Google on Friday released security updates for its Chrome browser to address a security flaw that it said</description>
    </item>
    <item>
      <title>Canada Goose investigating as hackers leak 600K customer records</title>
      <link>https://cluster-site.onrender.com/posts/canada-goose-investigating-as-hackers-leak-600k-customer-records/</link>
      <pubDate>Mon, 16 Feb 2026 04:45:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/canada-goose-investigating-as-hackers-leak-600k-customer-records/</guid>
      <description>• Canada Goose investigating as hackers leak 600K customer records February 15, 2026 11:45 PM 0 ShinyHunters, a well-known data extortion group, claims to have stolen more than 600</description>
    </item>
    <item>
      <title>ISC Stormcast For Monday, February 16th, 2026 https://isc.sans.edu/podcastdetail/9810, (Mon, Feb 16th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-monday-february-16th-2026-https/isc.sans.edu/podcastdetail/9810-mon-feb-16th/</link>
      <pubDate>Mon, 16 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-monday-february-16th-2026-https/isc.sans.edu/podcastdetail/9810-mon-feb-16th/</guid>
      <description>• ISC Stormcast For Monday, February 16th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9810&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9810&lt;/a&gt;
 Handler on Duty: Jan Kopriva Threat Level: green My next class: Application Security: Securi</description>
    </item>
    <item>
      <title>New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS</title>
      <link>https://cluster-site.onrender.com/posts/new-clickfix-attack-abuses-nslookup-to-retrieve-powershell-payload-via-dns/</link>
      <pubDate>Mon, 16 Feb 2026 00:29:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-clickfix-attack-abuses-nslookup-to-retrieve-powershell-payload-via-dns/</guid>
      <description>• Threat actors are now abusing DNS queries as part of ClickFix social engineering attacks to deliver malware, making this the first known use of DNS as a channel in these campaign</description>
    </item>
    <item>
      <title>Windows 11 KB5077181 fixes boot failures linked to failed updates</title>
      <link>https://cluster-site.onrender.com/posts/windows-11-kb5077181-fixes-boot-failures-linked-to-failed-updates/</link>
      <pubDate>Sun, 15 Feb 2026 22:08:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/windows-11-kb5077181-fixes-boot-failures-linked-to-failed-updates/</guid>
      <description>• Windows 11 KB5077181 fixes boot failures linked to failed updates February 15, 2026 05:08 PM 0 Microsoft says it has resolved a Windows 11 bug that caused some commercial systems</description>
    </item>
    <item>
      <title>CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups</title>
      <link>https://cluster-site.onrender.com/posts/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups/</link>
      <pubDate>Sun, 15 Feb 2026 16:30:41 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups/</guid>
      <description>• CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups February 15, 2026 11:30 AM 0 CTM360 reports that more than 4,000 malicious Google Groups and 3,500</description>
    </item>
    <item>
      <title>Pastebin comments push ClickFix JavaScript attack to hijack crypto swaps</title>
      <link>https://cluster-site.onrender.com/posts/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/</link>
      <pubDate>Sun, 15 Feb 2026 15:17:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/</guid>
      <description>• Pastebin comments push ClickFix JavaScript attack to hijack crypto swaps February 15, 2026 10:17 AM 0 Threat actors are abusing Pastebin comments to distribute a new ClickFix-sty</description>
    </item>
    <item>
      <title>Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-discloses-dns-based-clickfix-attack-using-nslookup-for-malware-staging/</link>
      <pubDate>Sun, 15 Feb 2026 14:10:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-discloses-dns-based-clickfix-attack-using-nslookup-for-malware-staging/</guid>
      <description>• Microsoft has disclosed details of a new version of the ClickFix social engineering tactic in which the attackers trick unsuspecting users into running commands that carry out a</description>
    </item>
    <item>
      <title>Upcoming Speaking Engagements</title>
      <link>https://cluster-site.onrender.com/posts/upcoming-speaking-engagements/</link>
      <pubDate>Sat, 14 Feb 2026 17:04:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/upcoming-speaking-engagements/</guid>
      <description>• Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I&amp;rsquo;m speaking atOntario Tech Universityin Oshawa, Ontario, Canada, at 2 PM ET on Th</description>
    </item>
    <item>
      <title>One threat actor responsible for 83% of recent Ivanti RCE attacks</title>
      <link>https://cluster-site.onrender.com/posts/one-threat-actor-responsible-for-83-of-recent-ivanti-rce-attacks/</link>
      <pubDate>Sat, 14 Feb 2026 16:02:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/one-threat-actor-responsible-for-83-of-recent-ivanti-rce-attacks/</guid>
      <description>• One threat actor responsible for 83% of recent Ivanti RCE attacks February 14, 2026 11:02 AM 0 Update: The article initially listed the wrong CVEs. • This has now been corrected</description>
    </item>
    <item>
      <title>Snail mail letters target Trezor and Ledger users in crypto-theft attacks</title>
      <link>https://cluster-site.onrender.com/posts/snail-mail-letters-target-trezor-and-ledger-users-in-crypto-theft-attacks/</link>
      <pubDate>Sat, 14 Feb 2026 15:15:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/snail-mail-letters-target-trezor-and-ledger-users-in-crypto-theft-attacks/</guid>
      <description>• Snail mail letters target Trezor and Ledger users in crypto-theft attacks February 14, 2026 10:15 AM 1 Threat actors are sending physical letters pretending to be from Trezor and</description>
    </item>
    <item>
      <title>Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data</title>
      <link>https://cluster-site.onrender.com/posts/over-300-malicious-chrome-extensions-caught-leaking-or-stealing-user-data/</link>
      <pubDate>Sat, 14 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/over-300-malicious-chrome-extensions-caught-leaking-or-stealing-user-data/</guid>
      <description>• Security researchers have discovered more than 300 Chrome extensions that leak browser data, spy on their users, or outright steal users&amp;rsquo; data.Research focused on the analysis of</description>
    </item>
    <item>
      <title>Phishing on the Edge of the Web and Mobile Using QR Codes</title>
      <link>https://cluster-site.onrender.com/posts/phishing-on-the-edge-of-the-web-and-mobile-using-qr-codes/</link>
      <pubDate>Fri, 13 Feb 2026 23:00:48 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/phishing-on-the-edge-of-the-web-and-mobile-using-qr-codes/</guid>
      <description>• Executive Summary This article explores the misuse of QR codes in today&amp;rsquo;s threat landscape, covering three areas of concern: - QR codes using URL shorteners to disguise malicious</description>
    </item>
    <item>
      <title>Fake job recruiters hide malware in developer coding challenges</title>
      <link>https://cluster-site.onrender.com/posts/fake-job-recruiters-hide-malware-in-developer-coding-challenges/</link>
      <pubDate>Fri, 13 Feb 2026 22:35:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-job-recruiters-hide-malware-in-developer-coding-challenges/</guid>
      <description>• Fake job recruiters hide malware in developer coding challenges February 13, 2026 05:35 PM 0 A new variation of the fake recruiter campaign from North Korean threat actors is tar</description>
    </item>
    <item>
      <title>Friday Squid Blogging: Do Squid Dream?</title>
      <link>https://cluster-site.onrender.com/posts/friday-squid-blogging-do-squid-dream/</link>
      <pubDate>Fri, 13 Feb 2026 22:08:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/friday-squid-blogging-do-squid-dream/</guid>
      <description>• Friday Squid Blogging: Do Squid Dream? • An exploration of the interesting question. • An exploration of the interesting question. • Clive Robinson • February 14, 2026 2:08 AM @</description>
    </item>
    <item>
      <title>Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs</title>
      <link>https://cluster-site.onrender.com/posts/google-ties-suspected-russian-actor-to-canfail-malware-attacks-on-ukrainian-orgs/</link>
      <pubDate>Fri, 13 Feb 2026 17:27:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-ties-suspected-russian-actor-to-canfail-malware-attacks-on-ukrainian-orgs/</guid>
      <description>• Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs A previously undocumented threat actor has been attributed to attacks targeting Ukrainian organiz</description>
    </item>
    <item>
      <title>Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-under-pressure-to-bolster-defenses-for-byovd-attacks/</link>
      <pubDate>Fri, 13 Feb 2026 17:08:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-under-pressure-to-bolster-defenses-for-byovd-attacks/</guid>
      <description>• Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks Threat actors are exploiting security gaps to weaponize Windows drivers and terminate security processes in targete</description>
    </item>
    <item>
      <title>Nation-State Hackers Put Defense Industrial Base Under Siege</title>
      <link>https://cluster-site.onrender.com/posts/nation-state-hackers-put-defense-industrial-base-under-siege/</link>
      <pubDate>Fri, 13 Feb 2026 17:07:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nation-state-hackers-put-defense-industrial-base-under-siege/</guid>
      <description>• Espionage groups from China, Russia and other nations burned at least two dozen zero-days in edge devices in attempts to infiltrate defense contractors&amp;rsquo; networks.</description>
    </item>
    <item>
      <title>AI Agents &#39;Swarm,&#39; Security Complexity Follows Suit</title>
      <link>https://cluster-site.onrender.com/posts/ai-agents-swarm-security-complexity-follows-suit/</link>
      <pubDate>Fri, 13 Feb 2026 16:49:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-agents-swarm-security-complexity-follows-suit/</guid>
      <description>• As AI deployments scale and start to include packs of agents autonomously working in concert, organizations face a naturally amplified attack surface.</description>
    </item>
    <item>
      <title>Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations</title>
      <link>https://cluster-site.onrender.com/posts/google-links-china-iran-russia-north-korea-to-coordinated-defense-sector-cyber-operations/</link>
      <pubDate>Fri, 13 Feb 2026 16:23:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-links-china-iran-russia-north-korea-to-coordinated-defense-sector-cyber-operations/</guid>
      <description>• Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations Several state-sponsored actors, hacktivist entities, and criminal groups from China,</description>
    </item>
    <item>
      <title>UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors</title>
      <link>https://cluster-site.onrender.com/posts/uat-9921-deploys-voidlink-malware-to-target-technology-and-financial-sectors/</link>
      <pubDate>Fri, 13 Feb 2026 15:23:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/uat-9921-deploys-voidlink-malware-to-target-technology-and-financial-sectors/</guid>
      <description>• UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors A previously unknown threat actor tracked asUAT-9921has been observed leveraging a new modular framew</description>
    </item>
    <item>
      <title>In Other News: Google Looks at AI Abuse, Trump Pauses China Bans, Disney&#39;s $2.7M Fine</title>
      <link>https://cluster-site.onrender.com/posts/in-other-news-google-looks-at-ai-abuse-trump-pauses-china-bans-disneys-2.7m-fine/</link>
      <pubDate>Fri, 13 Feb 2026 15:01:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/in-other-news-google-looks-at-ai-abuse-trump-pauses-china-bans-disneys-2.7m-fine/</guid>
      <description>• SecurityWeek&amp;rsquo;s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar.We provide a valuable summary of stories th</description>
    </item>
    <item>
      <title>Check Point Announces Trio of Acquisitions Amid Solid 2025 Earnings Beat</title>
      <link>https://cluster-site.onrender.com/posts/check-point-announces-trio-of-acquisitions-amid-solid-2025-earnings-beat/</link>
      <pubDate>Fri, 13 Feb 2026 12:35:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/check-point-announces-trio-of-acquisitions-amid-solid-2025-earnings-beat/</guid>
      <description>• Israeli cybersecurity firm Check Point Software Technologies (NASDAQ: CHKP) reported strong fourth-quarter and full-year 2025 financial performance while announcing three strateg</description>
    </item>
    <item>
      <title>Dutch Carrier Odido Discloses Data Breach Impacting 6 Million</title>
      <link>https://cluster-site.onrender.com/posts/dutch-carrier-odido-discloses-data-breach-impacting-6-million/</link>
      <pubDate>Fri, 13 Feb 2026 12:02:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dutch-carrier-odido-discloses-data-breach-impacting-6-million/</guid>
      <description>• Dutch mobile phone carrier Odido has disclosed a data breach impacting the personal information of over 6 million customers.The incident, the company said in anotice, occurred on</description>
    </item>
    <item>
      <title>CISA Announces New Town Halls to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/cisa-announces-new-town-halls-to-engage-with-stakeholders-on-cyber-incident-reporting-for-critical-infrastructure/</link>
      <pubDate>Fri, 13 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-announces-new-town-halls-to-engage-with-stakeholders-on-cyber-incident-reporting-for-critical-infrastructure/</guid>
      <description>• CISA Announces New Town Halls to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure WASHINGTON - The Cybersecurity and Infrastructure Security Agenc</description>
    </item>
    <item>
      <title>Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History</title>
      <link>https://cluster-site.onrender.com/posts/malicious-chrome-extensions-caught-stealing-business-data-emails-and-browsing-history/</link>
      <pubDate>Fri, 13 Feb 2026 11:25:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-chrome-extensions-caught-stealing-business-data-emails-and-browsing-history/</guid>
      <description>• Cybersecurity researchers have discovered a malicious Google Chrome extension that&amp;rsquo;s designed to steal data associated with Meta Business Suite and Facebook Business Manager. • T</description>
    </item>
    <item>
      <title>npm&#39;s Update to Harden Their Supply Chain, and Points to Consider</title>
      <link>https://cluster-site.onrender.com/posts/npms-update-to-harden-their-supply-chain-and-points-to-consider/</link>
      <pubDate>Fri, 13 Feb 2026 10:45:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/npms-update-to-harden-their-supply-chain-and-points-to-consider/</guid>
      <description>• npm&amp;rsquo;s Update to Harden Their Supply Chain, and Points to Consider In December 2025, in response to the Sha1-Hulud incident, npm completed amajor authentication overhaulintended t</description>
    </item>
    <item>
      <title>&amp;#x26;#xa;AI-Powered Knowledge Graph Generator &amp;#x26; APTs, (Thu, Feb 12th)</title>
      <link>https://cluster-site.onrender.com/posts/%23x26%23xaai-powered-knowledge-graph-generator-%23x26-apts-thu-feb-12th/</link>
      <pubDate>Fri, 13 Feb 2026 03:04:48 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/%23x26%23xaai-powered-knowledge-graph-generator-%23x26-apts-thu-feb-12th/</guid>
      <description>• AI-Powered Knowledge Graph Generator &amp;amp; APTs Unstructured text to interactive knowledge graph via LLM &amp;amp; SPO triplet extraction Courtesy of TLDR InfoSec Launches &amp;amp; Tools again, ano</description>
    </item>
    <item>
      <title>Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again</title>
      <link>https://cluster-site.onrender.com/posts/ivanti-epmm-zero-day-bugs-spark-exploit-frenzy-again/</link>
      <pubDate>Thu, 12 Feb 2026 22:05:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ivanti-epmm-zero-day-bugs-spark-exploit-frenzy-again/</guid>
      <description>• Endpoint Security Cyberattacks &amp;amp; Data Breaches Vulnerabilities &amp;amp; Threats Perimeter News Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again It&amp;rsquo;s time to phase out the &amp;lsquo;patch a</description>
    </item>
    <item>
      <title>Booz Allen Announces General Availability of Vellox Reverser to Automate Malware Defense</title>
      <link>https://cluster-site.onrender.com/posts/booz-allen-announces-general-availability-of-vellox-reverser-to-automate-malware-defense/</link>
      <pubDate>Thu, 12 Feb 2026 21:23:06 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/booz-allen-announces-general-availability-of-vellox-reverser-to-automate-malware-defense/</guid>
      <description>• The AI-powered product delivers expert-grade malware analysis and reverse engineering in minutes.</description>
    </item>
    <item>
      <title>SpecterOps Launches BloodHound Scentry to Accelerate the Practice of Identity Attack Path Management</title>
      <link>https://cluster-site.onrender.com/posts/specterops-launches-bloodhound-scentry-to-accelerate-the-practice-of-identity-attack-path-management/</link>
      <pubDate>Thu, 12 Feb 2026 21:11:52 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/specterops-launches-bloodhound-scentry-to-accelerate-the-practice-of-identity-attack-path-management/</guid>
      <description>• Drawing on years of adversary tradecraft, SpecterOps experts work alongside customers to analyze and eliminate attack paths, protect critical assets, and stay ahead of emerging t</description>
    </item>
    <item>
      <title>Gone With the Shame: One in Two Americans Are Reluctant to Talk About Romance Scam Incidents</title>
      <link>https://cluster-site.onrender.com/posts/gone-with-the-shame-one-in-two-americans-are-reluctant-to-talk-about-romance-scam-incidents/</link>
      <pubDate>Thu, 12 Feb 2026 21:04:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/gone-with-the-shame-one-in-two-americans-are-reluctant-to-talk-about-romance-scam-incidents/</guid>
      <description>• Men should take extra care on Valentine&amp;rsquo;s Day because they are nearly twice as likely as women to fall victim to romance scams.</description>
    </item>
    <item>
      <title>Those &#39;Summarize With AI&#39; Buttons May Be Lying to You</title>
      <link>https://cluster-site.onrender.com/posts/those-summarize-with-ai-buttons-may-be-lying-to-you/</link>
      <pubDate>Thu, 12 Feb 2026 20:47:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/those-summarize-with-ai-buttons-may-be-lying-to-you/</guid>
      <description>• Microsoft uncovered AI recommendation poisoning in 31 companies across 14 industries, and turnkey tools make it trivially easy to pull off.</description>
    </item>
    <item>
      <title>Copilot Studio agent security: Top 10 risks you can detect and prevent</title>
      <link>https://cluster-site.onrender.com/posts/copilot-studio-agent-security-top-10-risks-you-can-detect-and-prevent/</link>
      <pubDate>Thu, 12 Feb 2026 20:38:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/copilot-studio-agent-security-top-10-risks-you-can-detect-and-prevent/</guid>
      <description>• Organizations are rapidly adopting Copilot Studio agents, but threat actors are equally fast at exploiting misconfigured AI workflows. • Mis-sharing, unsafe orchestration, and we</description>
    </item>
    <item>
      <title>Detecting and mitigating common agent misconfigurations</title>
      <link>https://cluster-site.onrender.com/posts/detecting-and-mitigating-common-agent-misconfigurations/</link>
      <pubDate>Thu, 12 Feb 2026 20:38:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/detecting-and-mitigating-common-agent-misconfigurations/</guid>
      <description>• Organizations are rapidly adopting agents, but attackers are equally fast at exploiting misconfigured AI workflows. • Mis-sharing, unsafe orchestration, and weak authentication c</description>
    </item>
    <item>
      <title>Top 10 actions to build agents securely with Microsoft Copilot Studio</title>
      <link>https://cluster-site.onrender.com/posts/top-10-actions-to-build-agents-securely-with-microsoft-copilot-studio/</link>
      <pubDate>Thu, 12 Feb 2026 20:38:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/top-10-actions-to-build-agents-securely-with-microsoft-copilot-studio/</guid>
      <description>• Organizations are rapidly adopting Copilot Studio agents, but threat actors are equally fast at exploiting misconfigured AI workflows. • Mis-sharing, unsafe orchestration, and we</description>
    </item>
    <item>
      <title>Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support</title>
      <link>https://cluster-site.onrender.com/posts/google-reports-state-backed-hackers-using-gemini-ai-for-recon-and-attack-support/</link>
      <pubDate>Thu, 12 Feb 2026 17:57:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-reports-state-backed-hackers-using-gemini-ai-for-recon-and-attack-support/</guid>
      <description>• Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support Google on Thursday said it observed the North Korea-linked threat actor known asUNC2970using its</description>
    </item>
    <item>
      <title>Your complete guide to Microsoft experiences at RSAC™ 2026 Conference</title>
      <link>https://cluster-site.onrender.com/posts/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/</link>
      <pubDate>Thu, 12 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/</guid>
      <description>• The era of AI is reshaping both opportunity and risk faster than any shift security leaders have seen. • Every organization is feeling the momentum; and for security teams, the q</description>
    </item>
    <item>
      <title>Your complete guide to Microsoft experiences at RSAC™ 2026 Conference</title>
      <link>https://cluster-site.onrender.com/posts/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/</link>
      <pubDate>Thu, 12 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/</guid>
      <description>• The era of AI is reshaping both opportunity and risk faster than any shift security leaders have seen. • Every organization is feeling the momentum; and for security teams, the q</description>
    </item>
    <item>
      <title>Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems</title>
      <link>https://cluster-site.onrender.com/posts/lazarus-campaign-plants-malicious-packages-in-npm-and-pypi-ecosystems/</link>
      <pubDate>Thu, 12 Feb 2026 16:55:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lazarus-campaign-plants-malicious-packages-in-npm-and-pypi-ecosystems/</guid>
      <description>• Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign</description>
    </item>
    <item>
      <title>3D Printer Surveillance</title>
      <link>https://cluster-site.onrender.com/posts/3d-printer-surveillance/</link>
      <pubDate>Thu, 12 Feb 2026 12:01:31 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/3d-printer-surveillance/</guid>
      <description>• NY&amp;rsquo;s 2026-27 budget bill mandates 3D printers to include blocking tech that blocks firearm designs. • The algorithm scans every print file, refusing prints flagged as potential f</description>
    </item>
    <item>
      <title>The CTEM Divide: Why 84% of Security Programs Are Falling Behind</title>
      <link>https://cluster-site.onrender.com/posts/the-ctem-divide-why-84-of-security-programs-are-falling-behind/</link>
      <pubDate>Thu, 12 Feb 2026 10:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-ctem-divide-why-84-of-security-programs-are-falling-behind/</guid>
      <description>• The CTEM Divide: Why 84% of Security Programs Are Falling Behind A new 2026 market intelligence study of 128 enterprise security decision-makers (available here) reveals a stark</description>
    </item>
    <item>
      <title>Senegalese Data Breaches Expose Lack of Security Maturity</title>
      <link>https://cluster-site.onrender.com/posts/senegalese-data-breaches-expose-lack-of-security-maturity/</link>
      <pubDate>Thu, 12 Feb 2026 09:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/senegalese-data-breaches-expose-lack-of-security-maturity/</guid>
      <description>• Cyberattacks &amp;amp; Data Breaches Cyber Risk Data Privacy Cybersecurity Operations News Breaking cybersecurity news, news analysis, commentary, and other content from around the world</description>
    </item>
    <item>
      <title>Bypassing Administrator Protection by Abusing UI Access</title>
      <link>https://cluster-site.onrender.com/posts/bypassing-administrator-protection-by-abusing-ui-access/</link>
      <pubDate>Thu, 12 Feb 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/bypassing-administrator-protection-by-abusing-ui-access/</guid>
      <description>• In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didnât exist. • I described one</description>
    </item>
    <item>
      <title>83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/83-of-ivanti-epmm-exploits-linked-to-single-ip-on-bulletproof-hosting-infrastructure/</link>
      <pubDate>Thu, 12 Feb 2026 07:32:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/83-of-ivanti-epmm-exploits-linked-to-single-ip-on-bulletproof-hosting-infrastructure/</guid>
      <description>• 83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure A significant chunk of the exploitation attempts targeting a newly disclosed security flaw i</description>
    </item>
    <item>
      <title>ISC Stormcast For Thursday, February 12th, 2026 https://isc.sans.edu/podcastdetail/9806, (Thu, Feb 12th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-thursday-february-12th-2026-https/isc.sans.edu/podcastdetail/9806-thu-feb-12th/</link>
      <pubDate>Thu, 12 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-thursday-february-12th-2026-https/isc.sans.edu/podcastdetail/9806-thu-feb-12th/</guid>
      <description>• ISC Stormcast For Thursday, February 12th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9806&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9806&lt;/a&gt;
 Handler on Duty: Guy Bruneau Threat Level: green My next class: Application Security: Secu</description>
    </item>
    <item>
      <title>Four Seconds to Botnet - Analyzing a Self Propagating SSH Worm with Cryptographically Signed C2 &amp;#x5b;Guest Diary&amp;#x5d;, (Wed, Feb 11th)</title>
      <link>https://cluster-site.onrender.com/posts/four-seconds-to-botnet-analyzing-a-self-propagating-ssh-worm-with-cryptographically-signed-c2-%23x5bguest-diary%23x5d-wed-feb-11th/</link>
      <pubDate>Thu, 12 Feb 2026 01:56:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/four-seconds-to-botnet-analyzing-a-self-propagating-ssh-worm-with-cryptographically-signed-c2-%23x5bguest-diary%23x5d-wed-feb-11th/</guid>
      <description>• SSH worm exploited weak passwords, compromising Linux systems in seconds. • Attack used credential brute force, uploading a 4.7 KB bash script via SCP. • Script established persi</description>
    </item>
    <item>
      <title>Nation-State Actors Exploit Notepad&#43;&#43; Supply Chain</title>
      <link>https://cluster-site.onrender.com/posts/nation-state-actors-exploit-notepad-supply-chain/</link>
      <pubDate>Wed, 11 Feb 2026 23:00:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nation-state-actors-exploit-notepad-supply-chain/</guid>
      <description>• Executive Summary Between June and December 2025, the official hosting infrastructure for the text editor Notepad++ was compromised by a state-sponsored threat group known as Lot</description>
    </item>
    <item>
      <title>North Korea&#39;s UNC1069 Hammers Crypto Firms With AI</title>
      <link>https://cluster-site.onrender.com/posts/north-koreas-unc1069-hammers-crypto-firms-with-ai/</link>
      <pubDate>Wed, 11 Feb 2026 21:56:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/north-koreas-unc1069-hammers-crypto-firms-with-ai/</guid>
      <description>• In moving away from traditional banks to focus on Web3 companies, the threat actor is leveraging LLMs, deepfakes, legitimate platforms, and ClickFix.</description>
    </item>
    <item>
      <title>How to Stay on Top of Future Threats With a Cutting-Edge SOC</title>
      <link>https://cluster-site.onrender.com/posts/how-to-stay-on-top-of-future-threats-with-a-cutting-edge-soc/</link>
      <pubDate>Wed, 11 Feb 2026 20:36:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-to-stay-on-top-of-future-threats-with-a-cutting-edge-soc/</guid>
      <description>• CISOs should focus on harnessing and securing AI and building new skills among their people. • Vision and change management can transform security.</description>
    </item>
    <item>
      <title>Apple Patches Everything: February 2026, (Wed, Feb 11th)</title>
      <link>https://cluster-site.onrender.com/posts/apple-patches-everything-february-2026-wed-feb-11th/</link>
      <pubDate>Wed, 11 Feb 2026 19:36:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/apple-patches-everything-february-2026-wed-feb-11th/</guid>
      <description>• Apple Patches Everything: February 2026 Today, Apple released updates for all of its operating systems (iOS, iPadOS, macOS, tvOS, watchOS, and visionOS). • The update fixes 71 di</description>
    </item>
    <item>
      <title>Automaker Secures the Supply Chain With Developer-Friendly Platform</title>
      <link>https://cluster-site.onrender.com/posts/automaker-secures-the-supply-chain-with-developer-friendly-platform/</link>
      <pubDate>Wed, 11 Feb 2026 19:35:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/automaker-secures-the-supply-chain-with-developer-friendly-platform/</guid>
      <description>• How a platform engineering team embeds supply chain security into infrastructure without slowing developers.</description>
    </item>
    <item>
      <title>The strategic SIEM buyer&#39;s guide: Choosing an AI-ready platform for the agentic era</title>
      <link>https://cluster-site.onrender.com/posts/the-strategic-siem-buyers-guide-choosing-an-ai-ready-platform-for-the-agentic-era/</link>
      <pubDate>Wed, 11 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-strategic-siem-buyers-guide-choosing-an-ai-ready-platform-for-the-agentic-era/</guid>
      <description>• Share Link copied to clipboard! • Content types Best practices Topics AI and agents Security operations SIEM and XDR As the agentic era reshapes security operations, leaders face</description>
    </item>
    <item>
      <title>Kimwolf Botnet Swamps Anonymity Network I2P</title>
      <link>https://cluster-site.onrender.com/posts/kimwolf-botnet-swamps-anonymity-network-i2p/</link>
      <pubDate>Wed, 11 Feb 2026 16:08:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/kimwolf-botnet-swamps-anonymity-network-i2p/</guid>
      <description>• Kimwolf botnet infected millions of IoT devices, turning them into relays for malicious traffic. • In late 2025, the botnet began targeting I2P to hide control servers from taked</description>
    </item>
    <item>
      <title>AI Rising: Do We Know Enough About the Data Populating It?</title>
      <link>https://cluster-site.onrender.com/posts/ai-rising-do-we-know-enough-about-the-data-populating-it/</link>
      <pubDate>Wed, 11 Feb 2026 14:31:47 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-rising-do-we-know-enough-about-the-data-populating-it/</guid>
      <description>• Organizations remain reluctant to address the fact that AI can dangerously expose business operations as well as personal data.</description>
    </item>
    <item>
      <title>The game is over: when &#39;free&#39; comes at too high a price. What we know about RenEngine</title>
      <link>https://cluster-site.onrender.com/posts/the-game-is-over-when-free-comes-at-too-high-a-price.-what-we-know-about-renengine/</link>
      <pubDate>Wed, 11 Feb 2026 14:00:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-game-is-over-when-free-comes-at-too-high-a-price.-what-we-know-about-renengine/</guid>
      <description>• Table of Contents Incident analysis Disguise as a visual novel &amp;lsquo;Game&amp;rsquo; source files analysis HijackLoader Not only games Distribution Recommendations for protection Indicators of</description>
    </item>
    <item>
      <title>Top Cyber Industry Defenses Spike CO2 Emissions</title>
      <link>https://cluster-site.onrender.com/posts/top-cyber-industry-defenses-spike-co2-emissions/</link>
      <pubDate>Wed, 11 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/top-cyber-industry-defenses-spike-co2-emissions/</guid>
      <description>• Organizations can improve their climate footprints by optimizing two specific cybersecurity protections, without incurring added risks.</description>
    </item>
    <item>
      <title>WSL in the Malware Ecosystem, (Wed, Feb 11th)</title>
      <link>https://cluster-site.onrender.com/posts/wsl-in-the-malware-ecosystem-wed-feb-11th/</link>
      <pubDate>Wed, 11 Feb 2026 13:28:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wsl-in-the-malware-ecosystem-wed-feb-11th/</guid>
      <description>• WSL lets users run a full Linux environment inside Windows, eliminating need for VMs or dual boot. • WSL2&amp;rsquo;s lightweight virtualized kernel boosts compatibility and performance fo</description>
    </item>
    <item>
      <title>Prompt Injection Via Road Signs</title>
      <link>https://cluster-site.onrender.com/posts/prompt-injection-via-road-signs/</link>
      <pubDate>Wed, 11 Feb 2026 12:03:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/prompt-injection-via-road-signs/</guid>
      <description>• Prompt Injection Via Road Signs Interesting research: &amp;lsquo;CHAI: Command Hijacking Against Embodied AI.&amp;rsquo; Abstract: Embodied Artificial Intelligence (AI) promises to handle edge cases</description>
    </item>
    <item>
      <title>CISA&#39;s 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/cisas-2025-year-in-review-driving-security-and-resilience-across-critical-infrastructure/</link>
      <pubDate>Wed, 11 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisas-2025-year-in-review-driving-security-and-resilience-across-critical-infrastructure/</guid>
      <description>• CISA&amp;rsquo;s 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) unveiled its20</description>
    </item>
    <item>
      <title>Spam and phishing in 2025</title>
      <link>https://cluster-site.onrender.com/posts/spam-and-phishing-in-2025/</link>
      <pubDate>Wed, 11 Feb 2026 10:00:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spam-and-phishing-in-2025/</guid>
      <description>• The year in figures - 44.99% of all emails sent worldwide and 43.27% of all emails sent in the Russian web segment were spam - 32.50% of all spam emails were sent from Russia - K</description>
    </item>
    <item>
      <title>Asia Fumbles With Throttling Back Telnet Traffic in Region</title>
      <link>https://cluster-site.onrender.com/posts/asia-fumbles-with-throttling-back-telnet-traffic-in-region/</link>
      <pubDate>Wed, 11 Feb 2026 02:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/asia-fumbles-with-throttling-back-telnet-traffic-in-region/</guid>
      <description>• Only Taiwan made the top 10 list of governments, effectively blocking the threat-ridden protocol, but overall, the region lagged in curbing Telnet traffic.</description>
    </item>
    <item>
      <title>A Peek Into Muddled Libra&#39;s Operational Playbook</title>
      <link>https://cluster-site.onrender.com/posts/a-peek-into-muddled-libras-operational-playbook/</link>
      <pubDate>Tue, 10 Feb 2026 23:00:41 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-peek-into-muddled-libras-operational-playbook/</guid>
      <description>• Executive Summary During a September 2025 incident response investigation, Unit 42 discovered a rogue virtual machine (VM) which we believe with high confidence to be used by the</description>
    </item>
    <item>
      <title>SolarWinds WHD Attacks Highlight Risks of Exposed Apps</title>
      <link>https://cluster-site.onrender.com/posts/solarwinds-whd-attacks-highlight-risks-of-exposed-apps/</link>
      <pubDate>Tue, 10 Feb 2026 22:00:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/solarwinds-whd-attacks-highlight-risks-of-exposed-apps/</guid>
      <description>• Organizations that have exposed their instances of Web Help Desk to the public Internet have inadvertently made them prime targets for attackers.</description>
    </item>
    <item>
      <title>In Bypassing MFA, ZeroDayRAT Is &#39;Textbook Stalkerware&#39;</title>
      <link>https://cluster-site.onrender.com/posts/in-bypassing-mfa-zerodayrat-is-textbook-stalkerware/</link>
      <pubDate>Tue, 10 Feb 2026 21:37:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/in-bypassing-mfa-zerodayrat-is-textbook-stalkerware/</guid>
      <description>• With access to SIM, location data, and a preview of recent SMSes, attackers have everything they need for account takeover or targeted social engineering.</description>
    </item>
    <item>
      <title>80% of Fortune 500 use active AI Agents: Observability, governance, and security shape the new frontier</title>
      <link>https://cluster-site.onrender.com/posts/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/</link>
      <pubDate>Tue, 10 Feb 2026 16:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/</guid>
      <description>• Today, Microsoft is releasing the new Cyber Pulse report to provide leaders with straightforward, practical insights and guidance on new cybersecurity risks. • One of today&amp;rsquo;s mos</description>
    </item>
    <item>
      <title>Manipulating AI memory for profit: The rise of AI Recommendation Poisoning</title>
      <link>https://cluster-site.onrender.com/posts/manipulating-ai-memory-for-profit-the-rise-of-ai-recommendation-poisoning/</link>
      <pubDate>Tue, 10 Feb 2026 14:56:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/manipulating-ai-memory-for-profit-the-rise-of-ai-recommendation-poisoning/</guid>
      <description>• That helpful &amp;lsquo;Summarize with AI&amp;rsquo; button? • It might be secretly manipulating what your AI recommends. • Microsoft security researchers have discovered a growing trend of AI memor</description>
    </item>
    <item>
      <title>AI-Generated Text and the Detection Arms Race</title>
      <link>https://cluster-site.onrender.com/posts/ai-generated-text-and-the-detection-arms-race/</link>
      <pubDate>Tue, 10 Feb 2026 12:03:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-generated-text-and-the-detection-arms-race/</guid>
      <description>• AI-Generated Text and the Detection Arms Race In 2023, the science fiction literary magazine Clarkesworld stopped accepting new submissions because so many were generated by arti</description>
    </item>
    <item>
      <title>CISA Releases Guide to Help Critical Infrastructure Users Adopt More Secure Communication</title>
      <link>https://cluster-site.onrender.com/posts/cisa-releases-guide-to-help-critical-infrastructure-users-adopt-more-secure-communication/</link>
      <pubDate>Tue, 10 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-releases-guide-to-help-critical-infrastructure-users-adopt-more-secure-communication/</guid>
      <description>• CISA Releases Guide to Help Critical Infrastructure Users Adopt More Secure Communication WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today released</description>
    </item>
    <item>
      <title>A one-prompt attack that breaks LLM safety alignment</title>
      <link>https://cluster-site.onrender.com/posts/a-one-prompt-attack-that-breaks-llm-safety-alignment/</link>
      <pubDate>Mon, 09 Feb 2026 17:12:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-one-prompt-attack-that-breaks-llm-safety-alignment/</guid>
      <description>• Share Link copied to clipboard! • Content types Research Topics Actionable threat insights AI and agents Security management Large language models (LLMs) and diffusion models now</description>
    </item>
    <item>
      <title>LLMs are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days</title>
      <link>https://cluster-site.onrender.com/posts/llms-are-getting-a-lot-better-and-faster-at-finding-and-exploiting-zero-days/</link>
      <pubDate>Mon, 09 Feb 2026 12:04:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/llms-are-getting-a-lot-better-and-faster-at-finding-and-exploiting-zero-days/</guid>
      <description>• LLMs are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days This is amazing: Opus 4.6 is notably better at finding high-severity vulnerabilities than previous mo</description>
    </item>
    <item>
      <title>Analysis of active exploitation of SolarWinds Web Help Desk</title>
      <link>https://cluster-site.onrender.com/posts/analysis-of-active-exploitation-of-solarwinds-web-help-desk/</link>
      <pubDate>Sat, 07 Feb 2026 01:08:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/analysis-of-active-exploitation-of-solarwinds-web-help-desk/</guid>
      <description>• The Microsoft Defender Research Team observed a multi‑stage intrusion where threat actors exploited internet‑exposed SolarWinds Web Help Desk (WHD) instances to get an initial fo</description>
    </item>
    <item>
      <title>Novel Technique to Detect Cloud Threat Actor Operations</title>
      <link>https://cluster-site.onrender.com/posts/novel-technique-to-detect-cloud-threat-actor-operations/</link>
      <pubDate>Fri, 06 Feb 2026 23:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/novel-technique-to-detect-cloud-threat-actor-operations/</guid>
      <description>• Executive Summary Cloud-based alerting systems often struggle to distinguish between normal cloud activity and targeted malicious operations by known threat actors. • The difficu</description>
    </item>
    <item>
      <title>New Clickfix variant &#39;CrashFix&#39; deploying Python Remote Access Trojan</title>
      <link>https://cluster-site.onrender.com/posts/new-clickfix-variant-crashfix-deploying-python-remote-access-trojan/</link>
      <pubDate>Thu, 05 Feb 2026 18:51:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-clickfix-variant-crashfix-deploying-python-remote-access-trojan/</guid>
      <description>• In January 2026, Microsoft Defender Experts identified a new evolution in the ongoing ClickFix campaign. • This updated tactic deliberately crashes victims&amp;rsquo; browsers and then att</description>
    </item>
    <item>
      <title>The security implementation gap: Why Microsoft is supporting Operation Winter SHIELD</title>
      <link>https://cluster-site.onrender.com/posts/the-security-implementation-gap-why-microsoft-is-supporting-operation-winter-shield/</link>
      <pubDate>Thu, 05 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-security-implementation-gap-why-microsoft-is-supporting-operation-winter-shield/</guid>
      <description>• Share Link copied to clipboard! • Content types News Topics Office of the CISO Security management Security operations Every conversation I have with information security leaders</description>
    </item>
    <item>
      <title>CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats</title>
      <link>https://cluster-site.onrender.com/posts/cisa-orders-federal-agencies-to-strengthen-edge-device-security-amid-rising-cyber-threats/</link>
      <pubDate>Thu, 05 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-orders-federal-agencies-to-strengthen-edge-device-security-amid-rising-cyber-threats/</guid>
      <description>• CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today issuedBin</description>
    </item>
    <item>
      <title>The Shadow Campaigns: Uncovering Global Espionage</title>
      <link>https://cluster-site.onrender.com/posts/the-shadow-campaigns-uncovering-global-espionage/</link>
      <pubDate>Thu, 05 Feb 2026 11:00:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-shadow-campaigns-uncovering-global-espionage/</guid>
      <description>• Executive Summary This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. • We refer to the group&amp;rsquo;s activity as the Shadow Campaigns. • We asse</description>
    </item>
    <item>
      <title>Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT</title>
      <link>https://cluster-site.onrender.com/posts/stan-ghouls-targeting-russia-and-uzbekistan-with-netsupport-rat/</link>
      <pubDate>Thu, 05 Feb 2026 09:00:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/stan-ghouls-targeting-russia-and-uzbekistan-with-netsupport-rat/</guid>
      <description>• Introduction Stan Ghouls (also known as Bloody Wolf) is an cybercriminal group that has been launching targeted attacks against organizations in Russia, Kyrgyzstan, Kazakhstan, a</description>
    </item>
    <item>
      <title>Detecting backdoored language models at scale</title>
      <link>https://cluster-site.onrender.com/posts/detecting-backdoored-language-models-at-scale/</link>
      <pubDate>Wed, 04 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/detecting-backdoored-language-models-at-scale/</guid>
      <description>• Today, we are releasing new research on detecting backdoors in open-weight language models. • Our research highlights several key properties of language model backdoors, laying t</description>
    </item>
    <item>
      <title>Why Smart People Fall For Phishing Attacks</title>
      <link>https://cluster-site.onrender.com/posts/why-smart-people-fall-for-phishing-attacks/</link>
      <pubDate>Wed, 04 Feb 2026 00:00:43 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/why-smart-people-fall-for-phishing-attacks/</guid>
      <description>• Threat Research Center Insights Opinions Why Smart People Fall For Phishing Attacks By:Ria Bhatia Ria Bhatia Published:February 3, 2026 Categories:Business Email CompromiseCyberc</description>
    </item>
    <item>
      <title>The Notepad&#43;&#43; supply chain attack - unnoticed execution chains and new IoCs</title>
      <link>https://cluster-site.onrender.com/posts/the-notepad-supply-chain-attack-unnoticed-execution-chains-and-new-iocs/</link>
      <pubDate>Tue, 03 Feb 2026 08:10:06 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-notepad-supply-chain-attack-unnoticed-execution-chains-and-new-iocs/</guid>
      <description>• UPD 11.02.2026: added recommendations on how to use the Notepad++ supply chain attack rules package in our SIEM system. • Introduction On February 2, 2026, the developers of Note</description>
    </item>
    <item>
      <title>Please Don&#39;t Feed the Scattered Lapsus ShinyHunters</title>
      <link>https://cluster-site.onrender.com/posts/please-dont-feed-the-scattered-lapsus-shinyhunters/</link>
      <pubDate>Mon, 02 Feb 2026 16:15:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/please-dont-feed-the-scattered-lapsus-shinyhunters/</guid>
      <description>• Scattered Lapsus ShinyHunters (SLSH) uses harassment, threats, even swatting to extort firms. • They notify journalists and regulators, amplifying pressure beyond typical ransomw</description>
    </item>
    <item>
      <title>Privileged File System Vulnerability Present in a SCADA System</title>
      <link>https://cluster-site.onrender.com/posts/privileged-file-system-vulnerability-present-in-a-scada-system/</link>
      <pubDate>Fri, 30 Jan 2026 23:00:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/privileged-file-system-vulnerability-present-in-a-scada-system/</guid>
      <description>• Iconics Suite SCADA system vulnerable (CVE-2025-0921) allows privilege escalation via unnecessary file system operations. • Exploitation can corrupt critical binaries, leading to</description>
    </item>
    <item>
      <title>Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529</title>
      <link>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</link>
      <pubDate>Fri, 30 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</guid>
      <description>• In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-f</description>
    </item>
    <item>
      <title>Understanding the Russian Cyberthreat to the 2026 Winter Olympics</title>
      <link>https://cluster-site.onrender.com/posts/understanding-the-russian-cyberthreat-to-the-2026-winter-olympics/</link>
      <pubDate>Thu, 29 Jan 2026 21:30:47 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/understanding-the-russian-cyberthreat-to-the-2026-winter-olympics/</guid>
      <description>• Threat Research Center Insights Opinions Understanding the Russian Cyberthreat to the 2026 Winter Olympics By:Justin Moore Justin Moore Published:January 29, 2026 Categories:Cybe</description>
    </item>
    <item>
      <title>Supply chain attack on eScan antivirus: detecting and remediating malicious updates</title>
      <link>https://cluster-site.onrender.com/posts/supply-chain-attack-on-escan-antivirus-detecting-and-remediating-malicious-updates/</link>
      <pubDate>Thu, 29 Jan 2026 15:07:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/supply-chain-attack-on-escan-antivirus-detecting-and-remediating-malicious-updates/</guid>
      <description>• UPD 30.01.2026: Added technical details about the attack chain and more IoCs. • On January 20, a supply chain attack has occurred, with the infected software being the eScan anti</description>
    </item>
    <item>
      <title>CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats</title>
      <link>https://cluster-site.onrender.com/posts/cisa-urges-critical-infrastructure-organizations-to-take-action-against-insider-threats/</link>
      <pubDate>Wed, 28 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-urges-critical-infrastructure-organizations-to-take-action-against-insider-threats/</guid>
      <description>• CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) is calling on cri</description>
    </item>
    <item>
      <title>HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns</title>
      <link>https://cluster-site.onrender.com/posts/honeymyte-updates-coolclient-and-deploys-multiple-stealers-in-recent-campaigns/</link>
      <pubDate>Tue, 27 Jan 2026 08:00:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/honeymyte-updates-coolclient-and-deploys-multiple-stealers-in-recent-campaigns/</guid>
      <description>• HoneyMyte upgraded CoolClient backdoor with new features, enhancing persistence and stealth. • The group deployed multiple browser login data stealers across recent campaigns. •</description>
    </item>
    <item>
      <title>Who Operates the Badbox 2.0 Botnet?</title>
      <link>https://cluster-site.onrender.com/posts/who-operates-the-badbox-2.0-botnet/</link>
      <pubDate>Mon, 26 Jan 2026 16:11:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/who-operates-the-badbox-2.0-botnet/</guid>
      <description>• Kimwolf botnet, 2M infected devices, compromised Badbox 2.0 control panel screenshot. • Badbox 2.0: China-based botnet on Android TV streaming boxes, over ten million devices, us</description>
    </item>
    <item>
      <title>Bypassing Windows Administrator Protection</title>
      <link>https://cluster-site.onrender.com/posts/bypassing-windows-administrator-protection/</link>
      <pubDate>Mon, 26 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/bypassing-windows-administrator-protection/</guid>
      <description>• A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. • The goal of this feature is to replace User Account Control (UAC) with a mo</description>
    </item>
    <item>
      <title>Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense</title>
      <link>https://cluster-site.onrender.com/posts/happy-9th-anniversary-cta-a-celebration-of-collaboration-in-cyber-defense/</link>
      <pubDate>Sat, 24 Jan 2026 00:00:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/happy-9th-anniversary-cta-a-celebration-of-collaboration-in-cyber-defense/</guid>
      <description>• CTA founded in 2014, uniting Palo Alto, Fortinet, McAfee, and Symantec for shared threat intelligence. • Shifted industry from proprietary intel to collaborative defense, raising</description>
    </item>
    <item>
      <title>CISA Releases Product Categories List to Propel Post-Quantum Cryptography Adoption Pursuant to President Trump&#39;s Executive Order 14306</title>
      <link>https://cluster-site.onrender.com/posts/cisa-releases-product-categories-list-to-propel-post-quantum-cryptography-adoption-pursuant-to-president-trumps-executive-order-14306/</link>
      <pubDate>Fri, 23 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-releases-product-categories-list-to-propel-post-quantum-cryptography-adoption-pursuant-to-president-trumps-executive-order-14306/</guid>
      <description>• CISA releases first product categories list for post‑quantum cryptography (PQC) adoption. • List identifies hardware and software that support or will support PQC standards. • De</description>
    </item>
    <item>
      <title>The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time</title>
      <link>https://cluster-site.onrender.com/posts/the-next-frontier-of-runtime-assembly-attacks-leveraging-llms-to-generate-phishing-javascript-in-real-time/</link>
      <pubDate>Thu, 22 Jan 2026 11:00:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-next-frontier-of-runtime-assembly-attacks-leveraging-llms-to-generate-phishing-javascript-in-real-time/</guid>
      <description>• Attackers embed a benign page that calls an LLM API to generate malicious JavaScript in real time. • Prompt engineering bypasses AI safety guardrails, producing polymorphic phish</description>
    </item>
    <item>
      <title>Kimwolf Botnet Lurking in Corporate, Govt. Networks</title>
      <link>https://cluster-site.onrender.com/posts/kimwolf-botnet-lurking-in-corporate-govt.-networks/</link>
      <pubDate>Tue, 20 Jan 2026 18:19:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/kimwolf-botnet-lurking-in-corporate-govt.-networks/</guid>
      <description>• Kimwolf botnet has infected over 2 million IoT devices, enabling massive DDoS attacks. • It scans local networks of compromised systems to spread to additional vulnerable devices</description>
    </item>
    <item>
      <title>DNS OverDoS: Are Private Endpoints Too Private?</title>
      <link>https://cluster-site.onrender.com/posts/dns-overdos-are-private-endpoints-too-private/</link>
      <pubDate>Tue, 20 Jan 2026 17:23:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dns-overdos-are-private-endpoints-too-private/</guid>
      <description>Azure Private Endpoints can unintentionally expose resources to DoS attacks. Attack vectors include accidental admin deployments, vendor setups, and malicious actors. Over 5% of Az</description>
    </item>
    <item>
      <title>Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering</title>
      <link>https://cluster-site.onrender.com/posts/anatomy-of-an-attack-the-payroll-pirates-and-the-power-of-social-engineering/</link>
      <pubDate>Sat, 17 Jan 2026 00:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anatomy-of-an-attack-the-payroll-pirates-and-the-power-of-social-engineering/</guid>
      <description>• Threat Research Center Insights Anatomy of an Attack Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering By:Randy Stone Randy Stone Published:January 16</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</link>
      <pubDate>Wed, 14 Jan 2026 18:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</guid>
      <description>• With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland conte</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</link>
      <pubDate>Wed, 14 Jan 2026 17:59:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</guid>
      <description>• Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. • One effect of this change</description>
    </item>
    <item>
      <title>CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT</title>
      <link>https://cluster-site.onrender.com/posts/cisa-uk-ncsc-fbi-unveil-principles-to-combat-cyber-risks-in-ot/</link>
      <pubDate>Wed, 14 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-uk-ncsc-fbi-unveil-principles-to-combat-cyber-risks-in-ot/</guid>
      <description>• CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA), United Kingdom&amp;rsquo;s National Cyber</description>
    </item>
    <item>
      <title>Patch Tuesday, January 2026 Edition</title>
      <link>https://cluster-site.onrender.com/posts/patch-tuesday-january-2026-edition/</link>
      <pubDate>Wed, 14 Jan 2026 00:47:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/patch-tuesday-january-2026-edition/</guid>
      <description>• Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. • Eight of the vulnerabilities earned Microsof</description>
    </item>
    <item>
      <title>Threat Brief: MongoDB Vulnerability (CVE-2025-14847)</title>
      <link>https://cluster-site.onrender.com/posts/threat-brief-mongodb-vulnerability-cve-2025-14847/</link>
      <pubDate>Tue, 13 Jan 2026 20:30:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-brief-mongodb-vulnerability-cve-2025-14847/</guid>
      <description>• Executive Summary On Dec. • 19, 2025, MongoDB publicly disclosed MongoBleed, a security vulnerability (CVE-2025-14847) that allows unauthenticated attackers to leak sensitive hea</description>
    </item>
    <item>
      <title>Remote Code Execution With Modern AI/ML Formats and Libraries</title>
      <link>https://cluster-site.onrender.com/posts/remote-code-execution-with-modern-ai/ml-formats-and-libraries/</link>
      <pubDate>Tue, 13 Jan 2026 11:00:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/remote-code-execution-with-modern-ai/ml-formats-and-libraries/</guid>
      <description>• Executive Summary We identified vulnerabilities in three open-source artificial intelligence/machine learning (AI/ML) Python libraries published by Apple, Salesforce and NVIDIA o</description>
    </item>
    <item>
      <title>Who Benefited from the Aisuru and Kimwolf Botnets?</title>
      <link>https://cluster-site.onrender.com/posts/who-benefited-from-the-aisuru-and-kimwolf-botnets/</link>
      <pubDate>Thu, 08 Jan 2026 23:23:43 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/who-benefited-from-the-aisuru-and-kimwolf-botnets/</guid>
      <description>• Our first story of 2026 revealed how a destructive new botnet called Kimwolf has infected more than two million devices by mass-compromising a vast number of unofficial Android T</description>
    </item>
    <item>
      <title>CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity</title>
      <link>https://cluster-site.onrender.com/posts/cisa-retires-ten-emergency-directives-marking-an-era-in-federal-cybersecurity/</link>
      <pubDate>Thu, 08 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-retires-ten-emergency-directives-marking-an-era-in-federal-cybersecurity/</guid>
      <description>• CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA) announced the succe</description>
    </item>
    <item>
      <title>Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk</title>
      <link>https://cluster-site.onrender.com/posts/securing-vibe-coding-tools-scaling-productivity-without-scaling-risk/</link>
      <pubDate>Thu, 08 Jan 2026 11:00:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/securing-vibe-coding-tools-scaling-productivity-without-scaling-risk/</guid>
      <description>• Threat Research Center Insights General Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk By:Kate MiddaghMichael Spisak Kate Middagh Michael Spisak Published:</description>
    </item>
    <item>
      <title>The Kimwolf Botnet is Stalking Your Local Network</title>
      <link>https://cluster-site.onrender.com/posts/the-kimwolf-botnet-is-stalking-your-local-network/</link>
      <pubDate>Fri, 02 Jan 2026 14:20:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-kimwolf-botnet-is-stalking-your-local-network/</guid>
      <description>• The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. • The vulnerability at issue has been exploited for months alrea</description>
    </item>
    <item>
      <title>Happy 16th Birthday, KrebsOnSecurity.com!</title>
      <link>https://cluster-site.onrender.com/posts/happy-16th-birthday-krebsonsecurity.com/</link>
      <pubDate>Mon, 29 Dec 2025 20:23:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/happy-16th-birthday-krebsonsecurity.com/</guid>
      <description>• KrebsOnSecurity.com celebrates its 16th anniversary today! • A huge &amp;rsquo;thank you&amp;rsquo; to all of our readers - newcomers, long-timers and drive-by critics alike. • Your engagement this</description>
    </item>
    <item>
      <title>The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor</title>
      <link>https://cluster-site.onrender.com/posts/the-honeymyte-apt-evolves-with-a-kernel-mode-rootkit-and-a-toneshell-backdoor/</link>
      <pubDate>Mon, 29 Dec 2025 10:00:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-honeymyte-apt-evolves-with-a-kernel-mode-rootkit-and-a-toneshell-backdoor/</guid>
      <description>• Overview of the attacks In mid-2025, we identified a malicious driver file on computer systems in Asia. • The driver file is signed with an old, stolen, or leaked digital certifi</description>
    </item>
    <item>
      <title>Threat landscape for industrial automation systems in Q3 2025</title>
      <link>https://cluster-site.onrender.com/posts/threat-landscape-for-industrial-automation-systems-in-q3-2025/</link>
      <pubDate>Thu, 25 Dec 2025 10:00:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-landscape-for-industrial-automation-systems-in-q3-2025/</guid>
      <description>• Table of Contents Statistics across all threats Selected industries Diversity of detected malicious objects Main threat sources Threat categories Malicious objects used for initi</description>
    </item>
    <item>
      <title>Evasive Panda APT poisons DNS requests to deliver MgBot</title>
      <link>https://cluster-site.onrender.com/posts/evasive-panda-apt-poisons-dns-requests-to-deliver-mgbot/</link>
      <pubDate>Wed, 24 Dec 2025 07:00:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/evasive-panda-apt-poisons-dns-requests-to-deliver-mgbot/</guid>
      <description>• Introduction The Evasive Panda APT group (also known as Bronze Highland, Daggerfly, and StormBamboo) has been active since 2012, targeting multiple industries with sophisticated,</description>
    </item>
    <item>
      <title>Assessing SIEM effectiveness</title>
      <link>https://cluster-site.onrender.com/posts/assessing-siem-effectiveness/</link>
      <pubDate>Tue, 23 Dec 2025 12:00:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/assessing-siem-effectiveness/</guid>
      <description>• A SIEM is a complex system offering broad and flexible threat detection capabilities. • Due to its complexity, its effectiveness heavily depends on how it is configured and what</description>
    </item>
    <item>
      <title>Dismantling Defenses: Trump 2.0 Cyber Year in Review</title>
      <link>https://cluster-site.onrender.com/posts/dismantling-defenses-trump-2.0-cyber-year-in-review/</link>
      <pubDate>Fri, 19 Dec 2025 15:14:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dismantling-defenses-trump-2.0-cyber-year-in-review/</guid>
      <description>• The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation&amp;rsquo;s ability and willingness to address a broad spectrum o</description>
    </item>
    <item>
      <title>CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness</title>
      <link>https://cluster-site.onrender.com/posts/cisa-releases-dynamic-new-guide-for-stadium-and-arena-owners-to-fortify-operations-mitigate-vulnerabilities-and-elevate-emergency-preparedness/</link>
      <pubDate>Wed, 17 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-releases-dynamic-new-guide-for-stadium-and-arena-owners-to-fortify-operations-mitigate-vulnerabilities-and-elevate-emergency-preparedness/</guid>
      <description>• CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness WASHINGTON - Today, the Cybersecur</description>
    </item>
    <item>
      <title>Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS)</title>
      <link>https://cluster-site.onrender.com/posts/opening-doors-to-the-future-cisa-announces-participation-in-the-cybercorps-scholarship-for-service-sfs/</link>
      <pubDate>Wed, 17 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/opening-doors-to-the-future-cisa-announces-participation-in-the-cybercorps-scholarship-for-service-sfs/</guid>
      <description>• Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS) WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agenc</description>
    </item>
    <item>
      <title>Most Parked Domains Now Serving Malicious Content</title>
      <link>https://cluster-site.onrender.com/posts/most-parked-domains-now-serving-malicious-content/</link>
      <pubDate>Tue, 16 Dec 2025 14:14:48 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/most-parked-domains-now-serving-malicious-content/</guid>
      <description>• Direct navigation - the act of visiting a website by manually typing a domain name in a web browser - has never been riskier: A new study finds the vast majority of &amp;lsquo;parked&amp;rsquo; doma</description>
    </item>
    <item>
      <title>Welcome to the new Project Zero Blog</title>
      <link>https://cluster-site.onrender.com/posts/welcome-to-the-new-project-zero-blog/</link>
      <pubDate>Tue, 16 Dec 2025 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/welcome-to-the-new-project-zero-blog/</guid>
      <description>• While on Project Zero, we aim for our research to be leading-edge, our blog design was â¦ not so much. • We welcome readers to our shiny new blog! • For the occasion, we asked me</description>
    </item>
    <item>
      <title>Thinking Outside The Box [dusted off draft from 2017]</title>
      <link>https://cluster-site.onrender.com/posts/thinking-outside-the-box-dusted-off-draft-from-2017/</link>
      <pubDate>Tue, 16 Dec 2025 09:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/thinking-outside-the-box-dusted-off-draft-from-2017/</guid>
      <description>• Preface Hello from the future! • This is a blogpost I originally drafted in early 2017. • I wrote what I intended to be the first half of this post (about escaping from the VM to</description>
    </item>
    <item>
      <title>Windows Exploitation Techniques: Winning Race Conditions with Path Lookups</title>
      <link>https://cluster-site.onrender.com/posts/windows-exploitation-techniques-winning-race-conditions-with-path-lookups/</link>
      <pubDate>Tue, 16 Dec 2025 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/windows-exploitation-techniques-winning-race-conditions-with-path-lookups/</guid>
      <description>• This post was originally written in 2016 for the Project Zero blog. • However, in the end it was published separately in the journal PoC||GTFO issue #13 as well as in the second</description>
    </item>
    <item>
      <title>A look at an Android ITW DNG exploit</title>
      <link>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</link>
      <pubDate>Fri, 12 Dec 2025 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</guid>
      <description>• Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. • Thanks to a lead from Meta, these samples came to the attention of Googl</description>
    </item>
    <item>
      <title>Microsoft Patch Tuesday, December 2025 Edition</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-patch-tuesday-december-2025-edition/</link>
      <pubDate>Tue, 09 Dec 2025 23:18:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-patch-tuesday-december-2025-edition/</guid>
      <description>• Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. • This final Patch Tuesday of 2025 tackles one zero-day</description>
    </item>
    <item>
      <title>Drones to Diplomas: How Russia&#39;s Largest Private University is Linked to a $25M Essay Mill</title>
      <link>https://cluster-site.onrender.com/posts/drones-to-diplomas-how-russias-largest-private-university-is-linked-to-a-25m-essay-mill/</link>
      <pubDate>Sat, 06 Dec 2025 14:45:03 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/drones-to-diplomas-how-russias-largest-private-university-is-linked-to-a-25m-essay-mill/</guid>
      <description>• A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian u</description>
    </item>
    <item>
      <title>Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/pro-russia-hacktivists-conduct-opportunistic-attacks-against-us-and-global-critical-infrastructure/</link>
      <pubDate>Fri, 05 Dec 2025 19:35:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pro-russia-hacktivists-conduct-opportunistic-attacks-against-us-and-global-critical-infrastructure/</guid>
      <description>• Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure Actions for Operational Technology Owners and Operators to Take Today to Mitiga</description>
    </item>
    <item>
      <title>SMS Phishers Pivot to Points, Taxes, Fake Retailers</title>
      <link>https://cluster-site.onrender.com/posts/sms-phishers-pivot-to-points-taxes-fake-retailers/</link>
      <pubDate>Thu, 04 Dec 2025 23:02:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/sms-phishers-pivot-to-points-taxes-fake-retailers/</guid>
      <description>• China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday s</description>
    </item>
    <item>
      <title>CISA Shares Lessons Learned from an Incident Response Engagement</title>
      <link>https://cluster-site.onrender.com/posts/cisa-shares-lessons-learned-from-an-incident-response-engagement/</link>
      <pubDate>Mon, 22 Sep 2025 15:12:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-shares-lessons-learned-from-an-incident-response-engagement/</guid>
      <description>• CISA Shares Lessons Learned from an Incident Response Engagement Advisory at a Glance Executive Summary | CISA began incident response efforts at a U.S. • federal civilian execut</description>
    </item>
    <item>
      <title>Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System</title>
      <link>https://cluster-site.onrender.com/posts/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system/</link>
      <pubDate>Mon, 25 Aug 2025 13:36:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system/</guid>
      <description>• Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System Executive summary People&amp;rsquo;s Republic of China (PRC) state-sponsored cybe</description>
    </item>
    <item>
      <title>CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization</title>
      <link>https://cluster-site.onrender.com/posts/cisa-and-uscg-identify-areas-for-cyber-hygiene-improvement-after-conducting-proactive-threat-hunt-at-us-critical-infrastructure-organization/</link>
      <pubDate>Tue, 29 Jul 2025 17:53:52 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-and-uscg-identify-areas-for-cyber-hygiene-improvement-after-conducting-proactive-threat-hunt-at-us-critical-infrastructure-organization/</guid>
      <description>• CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization Summary The Cybersecurity and Infrast</description>
    </item>
    <item>
      <title>#StopRansomware: Interlock</title>
      <link>https://cluster-site.onrender.com/posts/%23stopransomware-interlock/</link>
      <pubDate>Mon, 21 Jul 2025 14:11:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/%23stopransomware-interlock/</guid>
      <description>• #StopRansomware: Interlock Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Ransomware Activity Prevent initial access by implementing domai</description>
    </item>
    <item>
      <title>Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider</title>
      <link>https://cluster-site.onrender.com/posts/ransomware-actors-exploit-unpatched-simplehelp-remote-monitoring-and-management-to-compromise-utility-billing-software-provider/</link>
      <pubDate>Thu, 12 Jun 2025 14:29:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ransomware-actors-exploit-unpatched-simplehelp-remote-monitoring-and-management-to-compromise-utility-billing-software-provider/</guid>
      <description>• Ransomware actors target unpatched SimpleHelp RMM to breach utility billing software provider customers. • Vulnerability CVE-2024-57727, a path traversal flaw, exploited in Simpl</description>
    </item>
    <item>
      <title>Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations</title>
      <link>https://cluster-site.onrender.com/posts/threat-actors-deploy-lummac2-malware-to-exfiltrate-sensitive-data-from-organizations/</link>
      <pubDate>Tue, 20 May 2025 19:20:23 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-actors-deploy-lummac2-malware-to-exfiltrate-sensitive-data-from-organizations/</guid>
      <description>• FBI &amp;amp; CISA issue joint advisory on LummaC2 infostealer targeting critical infrastructure. • Malware infiltrates networks, exfiltrates sensitive data via spearphishing links and a</description>
    </item>
    <item>
      <title>Russian GRU Targeting Western Logistics Entities and Technology Companies</title>
      <link>https://cluster-site.onrender.com/posts/russian-gru-targeting-western-logistics-entities-and-technology-companies/</link>
      <pubDate>Mon, 12 May 2025 16:49:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/russian-gru-targeting-western-logistics-entities-and-technology-companies/</guid>
      <description>• Russian GRU&amp;rsquo;s 85th GTsSS unit 26165 targets Western logistics and tech firms. • Campaign focuses on coordination, transport, delivery of foreign aid to Ukraine. • Uses known TTPs</description>
    </item>
    <item>
      <title>Fast Flux: A National Security Threat</title>
      <link>https://cluster-site.onrender.com/posts/fast-flux-a-national-security-threat/</link>
      <pubDate>Tue, 01 Apr 2025 19:00:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fast-flux-a-national-security-threat/</guid>
      <description>• Fast flux hides malicious server locations by rapidly changing DNS records. • Enables cybercriminals and nation-state actors to evade detection and maintain C2. • Resilient, high</description>
    </item>
    <item>
      <title>#StopRansomware: Medusa Ransomware</title>
      <link>https://cluster-site.onrender.com/posts/%23stopransomware-medusa-ransomware/</link>
      <pubDate>Tue, 11 Mar 2025 14:52:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/%23stopransomware-medusa-ransomware/</guid>
      <description>• Patch OS, software, firmware promptly to close known vulnerabilities across all systems. • Segment networks to limit lateral movement from infected devices and protect critical a</description>
    </item>
  </channel>
</rss>
