<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Threat-Intel on Tenu Tech Brief</title>
    <link>https://cluster-site.onrender.com/categories/threat-intel/</link>
    <description>Recent content in Threat-Intel on Tenu Tech Brief</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 26 Feb 2026 01:01:40 +0000</lastBuildDate>
    <atom:link href="https://cluster-site.onrender.com/categories/threat-intel/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Active exploitation of Cisco Catalyst SD-WAN by UAT-8616</title>
      <link>https://cluster-site.onrender.com/posts/active-exploitation-of-cisco-catalyst-sd-wan-by-uat-8616/</link>
      <pubDate>Wed, 25 Feb 2026 16:13:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/active-exploitation-of-cisco-catalyst-sd-wan-by-uat-8616/</guid>
      <description>• Active exploitation of Cisco Catalyst SD-WAN by UAT-8616 Cisco Talos is tracking the active exploitation ofCVE-2026-20127, a vulnerability in Cisco Catalyst SD-WAN Controller, fo</description>
    </item>
    <item>
      <title>Developer creates app to detect nearby smart glasses</title>
      <link>https://cluster-site.onrender.com/posts/developer-creates-app-to-detect-nearby-smart-glasses/</link>
      <pubDate>Wed, 25 Feb 2026 15:48:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/developer-creates-app-to-detect-nearby-smart-glasses/</guid>
      <description>• Developer creates app to detect nearby smart glasses An independent developer, moved after reading about the abuse ofsmart glassesto film people without their consent, decided to</description>
    </item>
    <item>
      <title>Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign</title>
      <link>https://cluster-site.onrender.com/posts/exposing-the-undercurrent-disrupting-the-gridtide-global-cyber-espionage-campaign/</link>
      <pubDate>Wed, 25 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/exposing-the-undercurrent-disrupting-the-gridtide-global-cyber-espionage-campaign/</guid>
      <description>• Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign Google Threat Intelligence Group Mandiant Google Threat Intelligence Visibility and context on</description>
    </item>
    <item>
      <title>Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files | CVE-2025-59536 | CVE-2026-21852</title>
      <link>https://cluster-site.onrender.com/posts/caught-in-the-hook-rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536-cve-2026-21852/</link>
      <pubDate>Wed, 25 Feb 2026 13:58:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/caught-in-the-hook-rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536-cve-2026-21852/</guid>
      <description>• By Aviv Donenfeld and Oded Vanunu Check Point Research has discovered critical vulnerabilities in Anthropic&amp;rsquo;s Claude Code that allow attackers to achieve remote code execution an</description>
    </item>
    <item>
      <title>mquire: Linux memory forensics without external dependencies</title>
      <link>https://cluster-site.onrender.com/posts/mquire-linux-memory-forensics-without-external-dependencies/</link>
      <pubDate>Wed, 25 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/mquire-linux-memory-forensics-without-external-dependencies/</guid>
      <description>• mquire: Linux memory forensics without external dependencies If you&amp;rsquo;ve ever done Linux memory forensics, you know the frustration: without debug symbols that match the exact kern</description>
    </item>
    <item>
      <title>ZDI-26-124: claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-124-claude-hovercraft-executeclaudecode-command-injection-remote-code-execution-vulnerability/</link>
      <pubDate>Wed, 25 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-124-claude-hovercraft-executeclaudecode-command-injection-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability ZDI-26-124ZDI-CAN-27785 This vulnerability allows remote attackers to e</description>
    </item>
    <item>
      <title>ZDI-26-127: (Pwn2Own) Ubiquiti Networks AI Pro Cleartext Transmission Information Disclosure Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-127-pwn2own-ubiquiti-networks-ai-pro-cleartext-transmission-information-disclosure-vulnerability/</link>
      <pubDate>Wed, 25 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-127-pwn2own-ubiquiti-networks-ai-pro-cleartext-transmission-information-disclosure-vulnerability/</guid>
      <description>• Advisory Details (Pwn2Own) Ubiquiti Networks AI Pro Cleartext Transmission Information Disclosure Vulnerability ZDI-26-127ZDI-CAN-28474 This vulnerability allows network-adjacent</description>
    </item>
    <item>
      <title>ZDI-26-128: (Pwn2Own) Ubiquiti Networks AI Pro Uncaught Exception Denial-of-Service Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-128-pwn2own-ubiquiti-networks-ai-pro-uncaught-exception-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 25 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-128-pwn2own-ubiquiti-networks-ai-pro-uncaught-exception-denial-of-service-vulnerability/</guid>
      <description>• Advisory Details (Pwn2Own) Ubiquiti Networks AI Pro Uncaught Exception Denial-of-Service Vulnerability ZDI-26-128ZDI-CAN-28824 This vulnerability allows network-adjacent attacker</description>
    </item>
    <item>
      <title>ZDI-26-129: Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-129-socomec-diris-a-40-http-api-authentication-bypass-vulnerability/</link>
      <pubDate>Wed, 25 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-129-socomec-diris-a-40-http-api-authentication-bypass-vulnerability/</guid>
      <description>• CVE ID | CVE-2026-2491 | CVSS SCORE | 6 • 3, AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | AFFECTED VENDORS | Socomec | AFFECTED PRODUCTS | DIRIS A-40 | VULNERABILITY DETAILS | This vuln</description>
    </item>
    <item>
      <title>ZDI-26-130: IceWarp collaboration Directory Traversal Information Disclosure Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-130-icewarp-collaboration-directory-traversal-information-disclosure-vulnerability/</link>
      <pubDate>Wed, 25 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-130-icewarp-collaboration-directory-traversal-information-disclosure-vulnerability/</guid>
      <description>• Advisory Details IceWarp collaboration Directory Traversal Information Disclosure Vulnerability ZDI-26-130ZDI-CAN-25440 This vulnerability allows remote attackers to disclose sen</description>
    </item>
    <item>
      <title>ZDI-26-132: Siemens SINEC NMS Uncontrolled Search Path Element Local Privilege Escalation Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-132-siemens-sinec-nms-uncontrolled-search-path-element-local-privilege-escalation-vulnerability/</link>
      <pubDate>Wed, 25 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-132-siemens-sinec-nms-uncontrolled-search-path-element-local-privilege-escalation-vulnerability/</guid>
      <description>• Advisory Details Siemens SINEC NMS Uncontrolled Search Path Element Local Privilege Escalation Vulnerability ZDI-26-132ZDI-CAN-28108 This vulnerability allows local attackers to</description>
    </item>
    <item>
      <title>Reddit, porn sites fined by UK regulators over children&#39;s safety and privacy</title>
      <link>https://cluster-site.onrender.com/posts/reddit-porn-sites-fined-by-uk-regulators-over-childrens-safety-and-privacy/</link>
      <pubDate>Tue, 24 Feb 2026 15:48:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/reddit-porn-sites-fined-by-uk-regulators-over-childrens-safety-and-privacy/</guid>
      <description>• Reddit, porn sites fined by UK regulators over children&amp;rsquo;s safety and privacy The UK&amp;rsquo;s online safety and privacy regulators are targeting companies that violate new age verificati</description>
    </item>
    <item>
      <title>Roblox gives predators &amp;#8220;powerful tools&amp;#8221; to target children, says LA County</title>
      <link>https://cluster-site.onrender.com/posts/roblox-gives-predators-%238220powerful-tools%238221-to-target-children-says-la-county/</link>
      <pubDate>Tue, 24 Feb 2026 15:22:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/roblox-gives-predators-%238220powerful-tools%238221-to-target-children-says-la-county/</guid>
      <description>• Roblox gives predators &amp;lsquo;powerful tools&amp;rsquo; to target children, says LA County Los Angeles County has sued online gaming company Roblox, adding to a series of suits that accuse the v</description>
    </item>
    <item>
      <title>Fake Zoom meeting &amp;#8220;update&amp;#8221; silently installs rogue version of monitoring tool abused by cybercriminals to spy on victims</title>
      <link>https://cluster-site.onrender.com/posts/fake-zoom-meeting-%238220update%238221-silently-installs-rogue-version-of-monitoring-tool-abused-by-cybercriminals-to-spy-on-victims/</link>
      <pubDate>Tue, 24 Feb 2026 09:47:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-zoom-meeting-%238220update%238221-silently-installs-rogue-version-of-monitoring-tool-abused-by-cybercriminals-to-spy-on-victims/</guid>
      <description>• Fake Zoom meeting &amp;lsquo;update&amp;rsquo; silently installs rogue version of monitoring tool abused by cybercriminals to spy on victims UPDATE (February 25, 2026): Teramind has stated that it i</description>
    </item>
    <item>
      <title>Fake Zoom meeting &amp;#8220;update&amp;#8221; silently installs surveillance software</title>
      <link>https://cluster-site.onrender.com/posts/fake-zoom-meeting-%238220update%238221-silently-installs-surveillance-software/</link>
      <pubDate>Tue, 24 Feb 2026 09:47:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-zoom-meeting-%238220update%238221-silently-installs-surveillance-software/</guid>
      <description>• Fake Zoom meeting &amp;lsquo;update&amp;rsquo; silently installs surveillance software A fake Zoom meeting website is silently pushing surveillance software onto Windows machines. • Visitors land on</description>
    </item>
    <item>
      <title>Refund scam impersonates Avast to harvest credit card details</title>
      <link>https://cluster-site.onrender.com/posts/refund-scam-impersonates-avast-to-harvest-credit-card-details/</link>
      <pubDate>Tue, 24 Feb 2026 08:28:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/refund-scam-impersonates-avast-to-harvest-credit-card-details/</guid>
      <description>• Refund scam impersonates Avast to harvest credit card details A fraudulent website dressed in Avast&amp;rsquo;s brand is tricking French-speaking users into handing over their full credit</description>
    </item>
    <item>
      <title>OpenClaw: What is it and can you use it safely?</title>
      <link>https://cluster-site.onrender.com/posts/openclaw-what-is-it-and-can-you-use-it-safely/</link>
      <pubDate>Mon, 23 Feb 2026 21:10:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/openclaw-what-is-it-and-can-you-use-it-safely/</guid>
      <description>• OpenClaw: What is it and can you use it safely? • An AI tool with a funny name has caused quite a commotion as of late-including some allegations ofmachine consciousness-so here</description>
    </item>
    <item>
      <title>2025: The Untold Stories of Check Point Research</title>
      <link>https://cluster-site.onrender.com/posts/2025-the-untold-stories-of-check-point-research/</link>
      <pubDate>Mon, 23 Feb 2026 15:27:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/2025-the-untold-stories-of-check-point-research/</guid>
      <description>• Check Point Research (CPR) continuously tracks threats, following the clues that lead to major players and incidents in the threat landscape. • Whether it&amp;rsquo;s high-end financially-</description>
    </item>
    <item>
      <title>Password managers keep your passwords safe, unless...</title>
      <link>https://cluster-site.onrender.com/posts/password-managers-keep-your-passwords-safe-unless.../</link>
      <pubDate>Mon, 23 Feb 2026 12:45:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/password-managers-keep-your-passwords-safe-unless.../</guid>
      <description>• Password managers keep your passwords safe, unless&amp;hellip; I&amp;rsquo;m a big advocate of password managers. • Granted, there are better alternatives for passwords likepasskeys, but if a provi</description>
    </item>
    <item>
      <title>Fake Huorong security site infects users with ValleyRAT</title>
      <link>https://cluster-site.onrender.com/posts/fake-huorong-security-site-infects-users-with-valleyrat/</link>
      <pubDate>Mon, 23 Feb 2026 12:18:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-huorong-security-site-infects-users-with-valleyrat/</guid>
      <description>• A convincing lookalike of the popular Huorong Security antivirus has been used to deliver ValleyRAT, a sophisticated Remote Access Trojan (RAT) built on the Winos4.0 framework, t</description>
    </item>
    <item>
      <title>A week in security (February 16 &amp;#8211; February 22)</title>
      <link>https://cluster-site.onrender.com/posts/a-week-in-security-february-16-%238211-february-22/</link>
      <pubDate>Mon, 23 Feb 2026 08:02:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-week-in-security-february-16-%238211-february-22/</guid>
      <description>• A week in security (February 16 - February 22) Last week on Malwarebytes Labs: Age verification vendor Persona left frontend exposed, researchers say Facebook ads spread fake Win</description>
    </item>
    <item>
      <title>ZDI-26-123: Docker Desktop MCP Server Cleartext Storage of Sensitive Information Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-123-docker-desktop-mcp-server-cleartext-storage-of-sensitive-information-vulnerability/</link>
      <pubDate>Mon, 23 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-123-docker-desktop-mcp-server-cleartext-storage-of-sensitive-information-vulnerability/</guid>
      <description>• Advisory Details Docker Desktop MCP Server Cleartext Storage of Sensitive Information Vulnerability ZDI-26-123ZDI-CAN-27562 This vulnerability allows local attackers to disclose</description>
    </item>
    <item>
      <title>What can&amp;#8217;t you say on TikTok?</title>
      <link>https://cluster-site.onrender.com/posts/what-can%238217t-you-say-on-tiktok/</link>
      <pubDate>Sun, 22 Feb 2026 23:08:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-can%238217t-you-say-on-tiktok/</guid>
      <description>• What can&amp;rsquo;t you say on TikTok? • This week on the Lock and Code podcast&amp;hellip; A funny thing happened on TikTok last month, and it has brought allegations of censorship, manipulation,</description>
    </item>
    <item>
      <title>February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs Patched</title>
      <link>https://cluster-site.onrender.com/posts/february-2026-patch-tuesday-six-zero-days-among-59-cves-patched/</link>
      <pubDate>Sun, 22 Feb 2026 07:32:03 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/february-2026-patch-tuesday-six-zero-days-among-59-cves-patched/</guid>
      <description>• Actively Exploited Zero-Day Vulnerability in Windows Remote Desktop CVE-2026-21533 is an Important elevation of privilege vulnerability affecting Windows Remote Desktop Services</description>
    </item>
    <item>
      <title>Introducing &amp;quot;AI Unlocked: Decoding Prompt Injection,&amp;quot; a New Interactive Challenge</title>
      <link>https://cluster-site.onrender.com/posts/introducing-quotai-unlocked-decoding-prompt-injectionquot-a-new-interactive-challenge/</link>
      <pubDate>Sat, 21 Feb 2026 18:32:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/introducing-quotai-unlocked-decoding-prompt-injectionquot-a-new-interactive-challenge/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>Using threat modeling and prompt injection to audit Comet</title>
      <link>https://cluster-site.onrender.com/posts/using-threat-modeling-and-prompt-injection-to-audit-comet/</link>
      <pubDate>Fri, 20 Feb 2026 16:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/using-threat-modeling-and-prompt-injection-to-audit-comet/</guid>
      <description>• Using threat modeling and prompt injection to audit Comet Before launching their Comet browser, Perplexity hired us to test the security of their AI-powered browsing features. •</description>
    </item>
    <item>
      <title>Age verification vendor Persona left frontend exposed</title>
      <link>https://cluster-site.onrender.com/posts/age-verification-vendor-persona-left-frontend-exposed/</link>
      <pubDate>Fri, 20 Feb 2026 14:08:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/age-verification-vendor-persona-left-frontend-exposed/</guid>
      <description>• Discord partners with Persona for age verification, requiring facial scans before full platform access. • Researchers uncovered a publicly exposed Persona frontend on a US govern</description>
    </item>
    <item>
      <title>Age verification vendor Persona left frontend exposed, researchers say</title>
      <link>https://cluster-site.onrender.com/posts/age-verification-vendor-persona-left-frontend-exposed-researchers-say/</link>
      <pubDate>Fri, 20 Feb 2026 14:08:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/age-verification-vendor-persona-left-frontend-exposed-researchers-say/</guid>
      <description>• Age verification vendor Persona left frontend exposed, researchers say Researchers investigating Discord&amp;rsquo;s age-verification checkssay they discoveredan exposed frontend belonging</description>
    </item>
    <item>
      <title>Facebook ads spread fake Windows 11 downloads that steal passwords and crypto wallets</title>
      <link>https://cluster-site.onrender.com/posts/facebook-ads-spread-fake-windows-11-downloads-that-steal-passwords-and-crypto-wallets/</link>
      <pubDate>Fri, 20 Feb 2026 10:00:30 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/facebook-ads-spread-fake-windows-11-downloads-that-steal-passwords-and-crypto-wallets/</guid>
      <description>• Facebook ads spread fake Windows 11 downloads that steal passwords and crypto wallets Attackers are running paid Facebook ads that look like official Microsoft promotions, then d</description>
    </item>
    <item>
      <title>CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad</title>
      <link>https://cluster-site.onrender.com/posts/cve-2026-20841-arbitrary-code-execution-in-the-windows-notepad/</link>
      <pubDate>Thu, 19 Feb 2026 21:24:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cve-2026-20841-arbitrary-code-execution-in-the-windows-notepad/</guid>
      <description>• CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad In this excerpt of a TrendAI Research Services vulnerability report, Nikolai Skliarenko and Yazhi Wang of the Tren</description>
    </item>
    <item>
      <title>Using AI to defeat AI</title>
      <link>https://cluster-site.onrender.com/posts/using-ai-to-defeat-ai/</link>
      <pubDate>Thu, 19 Feb 2026 19:00:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/using-ai-to-defeat-ai/</guid>
      <description>• Using AI to defeat AI Welcome to this week&amp;rsquo;s edition of the Threat Source newsletter. • Generative AI and agentic AI are here to stay. • Although I believe that the advantages th</description>
    </item>
    <item>
      <title>AI-generated passwords are a security risk</title>
      <link>https://cluster-site.onrender.com/posts/ai-generated-passwords-are-a-security-risk/</link>
      <pubDate>Thu, 19 Feb 2026 14:46:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-generated-passwords-are-a-security-risk/</guid>
      <description>• AI-generated passwords are a security risk Using Artificial Intelligence (AI) to generate your passwords is a bad idea. • It&amp;rsquo;s likely to give that password to a criminal who can</description>
    </item>
    <item>
      <title>Intimate products maker Tenga spilled customer data</title>
      <link>https://cluster-site.onrender.com/posts/intimate-products-maker-tenga-spilled-customer-data/</link>
      <pubDate>Thu, 19 Feb 2026 11:48:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/intimate-products-maker-tenga-spilled-customer-data/</guid>
      <description>• Intimate products maker Tenga spilled customer data Tenga confirmed reports published by several outlets that the company notified customers of a data breach. • The Japanese manu</description>
    </item>
    <item>
      <title>Intimate products producer Tenga spilled customer data</title>
      <link>https://cluster-site.onrender.com/posts/intimate-products-producer-tenga-spilled-customer-data/</link>
      <pubDate>Thu, 19 Feb 2026 11:48:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/intimate-products-producer-tenga-spilled-customer-data/</guid>
      <description>• Intimate products producer Tenga spilled customer data Tenga confirmed reports published by several outlets that the company notified customers of a data breach. • The Japanese m</description>
    </item>
    <item>
      <title>Meta patents AI that could keep you posting from beyond the grave</title>
      <link>https://cluster-site.onrender.com/posts/meta-patents-ai-that-could-keep-you-posting-from-beyond-the-grave/</link>
      <pubDate>Thu, 19 Feb 2026 11:16:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/meta-patents-ai-that-could-keep-you-posting-from-beyond-the-grave/</guid>
      <description>• Meta patents AI that could keep you posting from beyond the grave Tech bros have beenwanting to become immortalfor years. • Until they get there, their fallback might be continui</description>
    </item>
    <item>
      <title>ZDI-26-110: Bosch Rexroth IndraWorks Print Settings File Parsing Deserialization Of Untrusted Data Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-110-bosch-rexroth-indraworks-print-settings-file-parsing-deserialization-of-untrusted-data-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-110-bosch-rexroth-indraworks-print-settings-file-parsing-deserialization-of-untrusted-data-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details Bosch Rexroth IndraWorks Print Settings File Parsing Deserialization Of Untrusted Data Remote Code Execution Vulnerability ZDI-26-110ZDI-CAN-28112 This vulnerabi</description>
    </item>
    <item>
      <title>ZDI-26-111: MLflow Use of Default Password Authentication Bypass Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-111-mlflow-use-of-default-password-authentication-bypass-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-111-mlflow-use-of-default-password-authentication-bypass-vulnerability/</guid>
      <description>• Advisory Details MLflow Use of Default Password Authentication Bypass Vulnerability ZDI-26-111ZDI-CAN-28256 This vulnerability allows remote attackers to bypass authentication on</description>
    </item>
    <item>
      <title>ZDI-26-112: Dassault Systèmes eDrawings Viewer EPRT File Parsing Uninitialized Variable Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-112-dassault-syst%C3%A8mes-edrawings-viewer-eprt-file-parsing-uninitialized-variable-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-112-dassault-syst%C3%A8mes-edrawings-viewer-eprt-file-parsing-uninitialized-variable-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details Dassault Systèmes eDrawings Viewer EPRT File Parsing Uninitialized Variable Remote Code Execution Vulnerability ZDI-26-112ZDI-CAN-28315 This vulnerability allows</description>
    </item>
    <item>
      <title>ZDI-26-113: Dassault Systèmes eDrawings Viewer EPRT File Parsing Memory Corruption Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-113-dassault-syst%C3%A8mes-edrawings-viewer-eprt-file-parsing-memory-corruption-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-113-dassault-syst%C3%A8mes-edrawings-viewer-eprt-file-parsing-memory-corruption-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details Dassault Systèmes eDrawings Viewer EPRT File Parsing Memory Corruption Remote Code Execution Vulnerability ZDI-26-113ZDI-CAN-28378 This vulnerability allows remo</description>
    </item>
    <item>
      <title>ZDI-26-115: Fortinet FortiClient VPN FCConfig Utility Link Following Local Privilege Escalation Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-115-fortinet-forticlient-vpn-fcconfig-utility-link-following-local-privilege-escalation-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-115-fortinet-forticlient-vpn-fcconfig-utility-link-following-local-privilege-escalation-vulnerability/</guid>
      <description>• Advisory Details Fortinet FortiClient VPN FCConfig Utility Link Following Local Privilege Escalation Vulnerability ZDI-26-115ZDI-CAN-25710 This vulnerability allows local attacke</description>
    </item>
    <item>
      <title>ZDI-26-116: TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-116-tensorflow-hdf5-library-uncontrolled-search-path-element-local-privilege-escalation-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-116-tensorflow-hdf5-library-uncontrolled-search-path-element-local-privilege-escalation-vulnerability/</guid>
      <description>• TensorFlow HDF5 library flaw lets local attackers load plugins from unsecured paths. • Exploit requires low‑privilege code execution before escalating to higher privileges. • Vul</description>
    </item>
    <item>
      <title>ZDI-26-117: RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-117-rustdesk-client-for-windows-transfer-file-link-following-information-disclosure-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-117-rustdesk-client-for-windows-transfer-file-link-following-information-disclosure-vulnerability/</guid>
      <description>• Advisory Details RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability ZDI-26-117ZDI-CAN-27909 This vulnerability allows local attackers t</description>
    </item>
    <item>
      <title>ZDI-26-118: GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-118-gimp-pgm-file-parsing-uninitialized-memory-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-118-gimp-pgm-file-parsing-uninitialized-memory-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability ZDI-26-118ZDI-CAN-28158 This vulnerability allows remote attackers to execute arbi</description>
    </item>
    <item>
      <title>ZDI-26-120: GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-120-gimp-icns-file-parsing-heap-based-buffer-overflow-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-120-gimp-icns-file-parsing-heap-based-buffer-overflow-remote-code-execution-vulnerability/</guid>
      <description>• Remote attackers can execute arbitrary code via GIMP ICNS file parsing. • Exploit requires user interaction: opening malicious file or visiting malicious page. • Vulnerability du</description>
    </item>
    <item>
      <title>ZDI-26-121: GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-121-gimp-xwd-file-parsing-out-of-bounds-write-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-121-gimp-xwd-file-parsing-out-of-bounds-write-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability ZDI-26-121ZDI-CAN-28591 This vulnerability allows remote attackers to execute arbit</description>
    </item>
    <item>
      <title>ZDI-26-122: PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-122-pdf-xchange-editor-trackerupdate-uncontrolled-search-path-element-local-privilege-escalation-vulnerability/</link>
      <pubDate>Thu, 19 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-122-pdf-xchange-editor-trackerupdate-uncontrolled-search-path-element-local-privilege-escalation-vulnerability/</guid>
      <description>• Advisory Details PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability ZDI-26-122ZDI-CAN-27788 This vulnerability allows loca</description>
    </item>
    <item>
      <title>Betterment data breach might be worse than we thought</title>
      <link>https://cluster-site.onrender.com/posts/betterment-data-breach-might-be-worse-than-we-thought/</link>
      <pubDate>Wed, 18 Feb 2026 17:09:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/betterment-data-breach-might-be-worse-than-we-thought/</guid>
      <description>• Betterment data breach might be worse than we thought Betterment LLC is an investment advisor registered with US Securities and Exchange Commission (SEC). • The companydiscloseda</description>
    </item>
    <item>
      <title>Job scam uses fake Google Forms site to harvest Google logins</title>
      <link>https://cluster-site.onrender.com/posts/job-scam-uses-fake-google-forms-site-to-harvest-google-logins/</link>
      <pubDate>Wed, 18 Feb 2026 12:22:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/job-scam-uses-fake-google-forms-site-to-harvest-google-logins/</guid>
      <description>• Job scam uses fake Google Forms site to harvest Google logins As part of our investigation into a job-themed phishing campaign, we came across several suspicious URLs that all lo</description>
    </item>
    <item>
      <title>Carelessness versus craftsmanship in cryptography</title>
      <link>https://cluster-site.onrender.com/posts/carelessness-versus-craftsmanship-in-cryptography/</link>
      <pubDate>Wed, 18 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/carelessness-versus-craftsmanship-in-cryptography/</guid>
      <description>• Carelessness versus craftsmanship in cryptography Two popular AES libraries, aes-js and pyaes, &amp;lsquo;helpfully&amp;rsquo; provide a default IV in their AES-CTR API, leading to a large number of</description>
    </item>
    <item>
      <title>&#39;Good enough&#39; emulation: Fuzzing a single thread to uncover vulnerabilities</title>
      <link>https://cluster-site.onrender.com/posts/good-enough-emulation-fuzzing-a-single-thread-to-uncover-vulnerabilities/</link>
      <pubDate>Wed, 18 Feb 2026 11:00:31 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/good-enough-emulation-fuzzing-a-single-thread-to-uncover-vulnerabilities/</guid>
      <description>• - A Cisco Talos researcher worked around the limitations of hardware-level Code Read-out Protection (RDP) on the Socomec DIRIS M-70 gateway by pivoting from physical debugging to</description>
    </item>
    <item>
      <title>Scammers use fake &#39;Gemini&#39; AI chatbot to sell fake &#39;Google Coin&#39;</title>
      <link>https://cluster-site.onrender.com/posts/scammers-use-fake-gemini-ai-chatbot-to-sell-fake-google-coin/</link>
      <pubDate>Wed, 18 Feb 2026 10:10:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scammers-use-fake-gemini-ai-chatbot-to-sell-fake-google-coin/</guid>
      <description>• Scammers use fake &amp;lsquo;Gemini&amp;rsquo; AI chatbot to sell fake &amp;lsquo;Google Coin&amp;rsquo; Scammers have found a new use for AI: creating custom chatbots posing as real AI assistants to pressure victims i</description>
    </item>
    <item>
      <title>ZDI-26-106: Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-106-autodesk-autocad-catpart-file-parsing-out-of-bounds-write-remote-code-execution-vulnerability/</link>
      <pubDate>Wed, 18 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-106-autodesk-autocad-catpart-file-parsing-out-of-bounds-write-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details Autodesk AutoCAD CATPART File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability ZDI-26-106ZDI-CAN-28417 This vulnerability allows remote attackers</description>
    </item>
    <item>
      <title>ZDI-26-107: Autodesk AutoCAD MODEL File Out-Of-Bounds Write Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-107-autodesk-autocad-model-file-out-of-bounds-write-remote-code-execution-vulnerability/</link>
      <pubDate>Wed, 18 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-107-autodesk-autocad-model-file-out-of-bounds-write-remote-code-execution-vulnerability/</guid>
      <description>• Remote code execution via out-of-bounds write in AutoCAD MODEL file parsing. • Requires user to open malicious file or visit malicious page. • Exploit writes past allocated buffe</description>
    </item>
    <item>
      <title>Chrome &amp;#8220;preloading&amp;#8221; could be leaking your data and causing problems in Browser Guard</title>
      <link>https://cluster-site.onrender.com/posts/chrome-%238220preloading%238221-could-be-leaking-your-data-and-causing-problems-in-browser-guard/</link>
      <pubDate>Tue, 17 Feb 2026 18:25:47 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/chrome-%238220preloading%238221-could-be-leaking-your-data-and-causing-problems-in-browser-guard/</guid>
      <description>• Chrome &amp;lsquo;preloading&amp;rsquo; could be leaking your data and causing problems in Browser Guard This article explains why Chrome&amp;rsquo;s &amp;lsquo;preloading&amp;rsquo; feature can cause scary-looking blocks in Mal</description>
    </item>
    <item>
      <title>AI in the Middle: Turning Web-Based AI Services into C2 Proxies &amp; The Future Of AI Driven Attacks</title>
      <link>https://cluster-site.onrender.com/posts/ai-in-the-middle-turning-web-based-ai-services-into-c2-proxies-the-future-of-ai-driven-attacks/</link>
      <pubDate>Tue, 17 Feb 2026 14:12:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-in-the-middle-turning-web-based-ai-services-into-c2-proxies-the-future-of-ai-driven-attacks/</guid>
      <description>• AI is rapidly becoming embedded in day-to-day enterprise workflows, inside browsers, collaboration suites, and developer tooling. • As a result, AI service domains increasingly b</description>
    </item>
    <item>
      <title>Scam Guard for desktop: A second set of eyes for suspicious moments</title>
      <link>https://cluster-site.onrender.com/posts/scam-guard-for-desktop-a-second-set-of-eyes-for-suspicious-moments/</link>
      <pubDate>Tue, 17 Feb 2026 13:50:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scam-guard-for-desktop-a-second-set-of-eyes-for-suspicious-moments/</guid>
      <description>• Scam Guard for desktop: A second set of eyes for suspicious moments Scams aren&amp;rsquo;t so obvious anymore. • They&amp;rsquo;re well-written, have working grammar, and can lead victims to very co</description>
    </item>
    <item>
      <title>Update Chrome now: Zero-day bug allows code execution via malicious webpages</title>
      <link>https://cluster-site.onrender.com/posts/update-chrome-now-zero-day-bug-allows-code-execution-via-malicious-webpages/</link>
      <pubDate>Tue, 17 Feb 2026 12:33:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/update-chrome-now-zero-day-bug-allows-code-execution-via-malicious-webpages/</guid>
      <description>• Update Chrome now: Zero-day bug allows code execution via malicious webpages Google hasissueda patch for a high‑severity Chrome zero‑day, tracked asCVE‑2026‑2441, a memory bug in</description>
    </item>
    <item>
      <title>Hobby coder accidentally creates vacuum robot army</title>
      <link>https://cluster-site.onrender.com/posts/hobby-coder-accidentally-creates-vacuum-robot-army/</link>
      <pubDate>Tue, 17 Feb 2026 10:20:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hobby-coder-accidentally-creates-vacuum-robot-army/</guid>
      <description>• Hobby coder accidentally creates vacuum robot army Sammy Azdoufal wanted to steer his robot vacuum with a PS5 controller. • Like any good maker, he thought it would be fun to dri</description>
    </item>
    <item>
      <title>16th February - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/16th-february-threat-intelligence-report/</link>
      <pubDate>Mon, 16 Feb 2026 17:57:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/16th-february-threat-intelligence-report/</guid>
      <description>• FILTER BY YEAR 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 16th February - Threat Intelligence Report For the latest discoveries in cyber research for the week of 16th</description>
    </item>
    <item>
      <title>ClickFix added nslookup commands to its arsenal for downloading RATs</title>
      <link>https://cluster-site.onrender.com/posts/clickfix-added-nslookup-commands-to-its-arsenal-for-downloading-rats/</link>
      <pubDate>Mon, 16 Feb 2026 13:09:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/clickfix-added-nslookup-commands-to-its-arsenal-for-downloading-rats/</guid>
      <description>• ClickFix uses fake CAPTCHAs and bogus updates to trick users into executing malicious commands. • Traditional mshta and PowerShell vectors are blocked, so attackers shifted to ns</description>
    </item>
    <item>
      <title>A week in security (February 9 &amp;#8211; February 15)</title>
      <link>https://cluster-site.onrender.com/posts/a-week-in-security-february-9-%238211-february-15/</link>
      <pubDate>Mon, 16 Feb 2026 08:02:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-week-in-security-february-9-%238211-february-15/</guid>
      <description>• Credential‑stealing Chrome extensions discovered; Malwarebytes Labs offers detection and removal guide. • Fake online shops target Winter Olympics 2026 fans, phishing for payment</description>
    </item>
    <item>
      <title>How to find and remove credential-stealing Chrome extensions</title>
      <link>https://cluster-site.onrender.com/posts/how-to-find-and-remove-credential-stealing-chrome-extensions/</link>
      <pubDate>Fri, 13 Feb 2026 13:27:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-to-find-and-remove-credential-stealing-chrome-extensions/</guid>
      <description>• Researchers have found yet another family of malicious extensions in the Chrome Web Store. • This time, 30 different Chrome extensions were found stealing credentials from more t</description>
    </item>
    <item>
      <title>Fake shops target Winter Olympics 2026 fans</title>
      <link>https://cluster-site.onrender.com/posts/fake-shops-target-winter-olympics-2026-fans/</link>
      <pubDate>Fri, 13 Feb 2026 09:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-shops-target-winter-olympics-2026-fans/</guid>
      <description>• Fake shops target Winter Olympics 2026 fans If you&amp;rsquo;ve seen the two stoat siblings serving as official mascots of the Milano Cortina 2026 Winter Olympics, you already know Tina an</description>
    </item>
    <item>
      <title>ZDI-26-099: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-099-oracle-virtualbox-vmsvga-race-condition-local-privilege-escalation-vulnerability/</link>
      <pubDate>Fri, 13 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-099-oracle-virtualbox-vmsvga-race-condition-local-privilege-escalation-vulnerability/</guid>
      <description>• Oracle VirtualBox VMSVGA race condition allows local attackers to elevate privileges to hypervisor level. • Exploit requires initial high‑privileged code execution on the guest O</description>
    </item>
    <item>
      <title>ZDI-26-101: Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-101-oracle-virtualbox-buslogic-uninitialized-memory-information-disclosure-vulnerability/</link>
      <pubDate>Fri, 13 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-101-oracle-virtualbox-buslogic-uninitialized-memory-information-disclosure-vulnerability/</guid>
      <description>• Advisory Details Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability ZDI-26-101ZDI-CAN-28080 This vulnerability allows local attackers to disclos</description>
    </item>
    <item>
      <title>ZDI-26-103: Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-103-oracle-virtualbox-vmsvga-out-of-bounds-access-local-privilege-escalation-vulnerability/</link>
      <pubDate>Fri, 13 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-103-oracle-virtualbox-vmsvga-out-of-bounds-access-local-privilege-escalation-vulnerability/</guid>
      <description>• Advisory Details Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability ZDI-26-103ZDI-CAN-27923 This vulnerability allows local attackers to escal</description>
    </item>
    <item>
      <title>ZDI-26-104: Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-104-sante-dicom-viewer-pro-dcm-file-parsing-buffer-overflow-remote-code-execution-vulnerability/</link>
      <pubDate>Fri, 13 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-104-sante-dicom-viewer-pro-dcm-file-parsing-buffer-overflow-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability ZDI-26-104ZDI-CAN-28129 This vulnerability allows remote attackers to</description>
    </item>
    <item>
      <title>ZDI-26-105: MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-105-mlflow-tracking-server-artifact-handler-directory-traversal-remote-code-execution-vulnerability/</link>
      <pubDate>Fri, 13 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-105-mlflow-tracking-server-artifact-handler-directory-traversal-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability ZDI-26-105ZDI-CAN-26649 This vulnerability allows remote attacker</description>
    </item>
    <item>
      <title>Hand over the keys for Shannon&#39;s shenanigans</title>
      <link>https://cluster-site.onrender.com/posts/hand-over-the-keys-for-shannons-shenanigans/</link>
      <pubDate>Thu, 12 Feb 2026 19:00:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hand-over-the-keys-for-shannons-shenanigans/</guid>
      <description>• Hand over the keys for Shannon&amp;rsquo;s shenanigans Welcome to this week&amp;rsquo;s edition of the Threat Source newsletter. • Last week, yet another security AI tool made the rounds on social m</description>
    </item>
    <item>
      <title>Outlook add-in goes rogue and steals 4,000 credentials and payment data</title>
      <link>https://cluster-site.onrender.com/posts/outlook-add-in-goes-rogue-and-steals-4000-credentials-and-payment-data/</link>
      <pubDate>Thu, 12 Feb 2026 14:35:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/outlook-add-in-goes-rogue-and-steals-4000-credentials-and-payment-data/</guid>
      <description>• Outlook add-in goes rogue and steals 4,000 credentials and payment data Researchersfound a malicious Microsoft Outlook add-in which was able to steal 4,000 stolen Microsoft accou</description>
    </item>
    <item>
      <title>GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use</title>
      <link>https://cluster-site.onrender.com/posts/gtig-ai-threat-tracker-distillation-experimentation-and-continued-integration-of-ai-for-adversarial-use/</link>
      <pubDate>Thu, 12 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/gtig-ai-threat-tracker-distillation-experimentation-and-continued-integration-of-ai-for-adversarial-use/</guid>
      <description>• GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use Google Threat Intelligence Group Google Threat Intelligence Visibilit</description>
    </item>
    <item>
      <title>Child exploitation, grooming, and social media addiction claims put Meta on trial</title>
      <link>https://cluster-site.onrender.com/posts/child-exploitation-grooming-and-social-media-addiction-claims-put-meta-on-trial/</link>
      <pubDate>Thu, 12 Feb 2026 12:35:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/child-exploitation-grooming-and-social-media-addiction-claims-put-meta-on-trial/</guid>
      <description>• Child exploitation, grooming, and social media addiction claims put Meta on trial Meta is facing two trials over child safety allegations in California and New Mexico. • The laws</description>
    </item>
    <item>
      <title>Ryan Liles, master of technical diplomacy</title>
      <link>https://cluster-site.onrender.com/posts/ryan-liles-master-of-technical-diplomacy/</link>
      <pubDate>Thu, 12 Feb 2026 11:00:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ryan-liles-master-of-technical-diplomacy/</guid>
      <description>• Ryan Liles, master of technical diplomacy Cisco Talos is back with another inside look at the people who keep the internet safe. • This time, Amy chats with Ryan Liles, who bridg</description>
    </item>
    <item>
      <title>Criminals are using AI website builders to clone major brands</title>
      <link>https://cluster-site.onrender.com/posts/criminals-are-using-ai-website-builders-to-clone-major-brands/</link>
      <pubDate>Thu, 12 Feb 2026 08:03:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/criminals-are-using-ai-website-builders-to-clone-major-brands/</guid>
      <description>• Cybercriminals use AI website builders like Vercel to clone trusted brands in minutes. • Cheap, fast domain registration lets attackers register plausible brand‑lookalike names w</description>
    </item>
    <item>
      <title>Bypassing Administrator Protection by Abusing UI Access</title>
      <link>https://cluster-site.onrender.com/posts/bypassing-administrator-protection-by-abusing-ui-access/</link>
      <pubDate>Thu, 12 Feb 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/bypassing-administrator-protection-by-abusing-ui-access/</guid>
      <description>• In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didnât exist. • I described one</description>
    </item>
    <item>
      <title>ZDI-26-094: Schneider Electric EcoStruxure Power Build SSD File Parsing Use-After-Free Remote Code Execution Vulnerability</title>
      <link>https://cluster-site.onrender.com/posts/zdi-26-094-schneider-electric-ecostruxure-power-build-ssd-file-parsing-use-after-free-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 12 Feb 2026 06:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zdi-26-094-schneider-electric-ecostruxure-power-build-ssd-file-parsing-use-after-free-remote-code-execution-vulnerability/</guid>
      <description>• Advisory Details Schneider Electric EcoStruxure Power Build SSD File Parsing Use-After-Free Remote Code Execution Vulnerability ZDI-26-094ZDI-CAN-27478 This vulnerability allows</description>
    </item>
    <item>
      <title>Malwarebytes earns PCMag Best Tech Brand spot, scores 100% with MRG Effitas</title>
      <link>https://cluster-site.onrender.com/posts/malwarebytes-earns-pcmag-best-tech-brand-spot-scores-100-with-mrg-effitas/</link>
      <pubDate>Wed, 11 Feb 2026 10:09:52 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malwarebytes-earns-pcmag-best-tech-brand-spot-scores-100-with-mrg-effitas/</guid>
      <description>• Malwarebytes earns PCMag Best Tech Brand spot, scores 100% with MRG Effitas Malwarebytes is on a roll. • Recently named one of PCMag&amp;rsquo;s &amp;lsquo;Best Tech Brands for 2026,&amp;rsquo; Malwarebytes a</description>
    </item>
    <item>
      <title>New threat actor, UAT-9921, leverages VoidLink framework in campaigns</title>
      <link>https://cluster-site.onrender.com/posts/new-threat-actor-uat-9921-leverages-voidlink-framework-in-campaigns/</link>
      <pubDate>Wed, 11 Feb 2026 00:00:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-threat-actor-uat-9921-leverages-voidlink-framework-in-campaigns/</guid>
      <description>• - Cisco Talos recently discovered a new threat actor, UAT-9921, leveraging VoidLink in campaigns. • Their activities may go as far back as 2019, even without VoidLink. • - The Vo</description>
    </item>
    <item>
      <title>The February 2026 Security Update Review</title>
      <link>https://cluster-site.onrender.com/posts/the-february-2026-security-update-review/</link>
      <pubDate>Tue, 10 Feb 2026 18:30:28 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-february-2026-security-update-review/</guid>
      <description>• I have survived the biggest Pwn2Own ever, but I&amp;rsquo;m back in Tokyo for the second Patch Tuesday of 2026. • My location never stops Patch Tuesday from coming, so let&amp;rsquo;s take a look at</description>
    </item>
    <item>
      <title>Discord will limit profiles to teen-appropriate mode until you verify your age</title>
      <link>https://cluster-site.onrender.com/posts/discord-will-limit-profiles-to-teen-appropriate-mode-until-you-verify-your-age/</link>
      <pubDate>Tue, 10 Feb 2026 15:29:52 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/discord-will-limit-profiles-to-teen-appropriate-mode-until-you-verify-your-age/</guid>
      <description>• Discord will limit profiles to teen-appropriate mode until you verify your age Discordannouncedit will put all existing and new profiles in teen-appropriate mode by default in ea</description>
    </item>
    <item>
      <title>Beyond the Battlefield: Threats to the Defense Industrial Base</title>
      <link>https://cluster-site.onrender.com/posts/beyond-the-battlefield-threats-to-the-defense-industrial-base/</link>
      <pubDate>Tue, 10 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/beyond-the-battlefield-threats-to-the-defense-industrial-base/</guid>
      <description>• Beyond the Battlefield: Threats to the Defense Industrial Base Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.</description>
    </item>
    <item>
      <title>How safe are kids using social media? We did the groundwork</title>
      <link>https://cluster-site.onrender.com/posts/how-safe-are-kids-using-social-media-we-did-the-groundwork/</link>
      <pubDate>Tue, 10 Feb 2026 13:50:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-safe-are-kids-using-social-media-we-did-the-groundwork/</guid>
      <description>• When researchers created an account for a child under 13 on Roblox, they expected heavy guardrails. • Instead, they found that the platform&amp;rsquo;s search features still allowed kids t</description>
    </item>
    <item>
      <title>Man tricked hundreds of women into handing over Snapchat security codes</title>
      <link>https://cluster-site.onrender.com/posts/man-tricked-hundreds-of-women-into-handing-over-snapchat-security-codes/</link>
      <pubDate>Tue, 10 Feb 2026 13:28:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/man-tricked-hundreds-of-women-into-handing-over-snapchat-security-codes/</guid>
      <description>• Man tricked hundreds of women into handing over Snapchat security codes Fresh off a breathless Super Bowl Sunday, we&amp;rsquo;re less thrilled to bring you this week&amp;rsquo;s Weirdo Wednesday. •</description>
    </item>
    <item>
      <title>UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering</title>
      <link>https://cluster-site.onrender.com/posts/unc1069-targets-cryptocurrency-sector-with-new-tooling-and-ai-enabled-social-engineering/</link>
      <pubDate>Mon, 09 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/unc1069-targets-cryptocurrency-sector-with-new-tooling-and-ai-enabled-social-engineering/</guid>
      <description>• UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering Mandiant Written by: Ross Inman, Adrian Hernandez Introduction North Korean threat actors</description>
    </item>
    <item>
      <title>9th February - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/9th-february-threat-intelligence-report/</link>
      <pubDate>Mon, 09 Feb 2026 12:50:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/9th-february-threat-intelligence-report/</guid>
      <description>• Conpet pipeline attack disrupted IT but not operations. • Qilin ransomware group claimed responsibility. • Check Point Harmony protects against this threat. • Report covers recen</description>
    </item>
    <item>
      <title>All gas, no brakes: Time to come to AI church</title>
      <link>https://cluster-site.onrender.com/posts/all-gas-no-brakes-time-to-come-to-ai-church/</link>
      <pubDate>Thu, 05 Feb 2026 19:00:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/all-gas-no-brakes-time-to-come-to-ai-church/</guid>
      <description>• All gas, no brakes: Time to come to AI church Welcome to this week&amp;rsquo;s edition of the Threat Source newsletter. • Brothers and sisters, gather close for a moment. • We are all secu</description>
    </item>
    <item>
      <title>CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall</title>
      <link>https://cluster-site.onrender.com/posts/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall/</link>
      <pubDate>Thu, 05 Feb 2026 16:45:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cve-2025-6978-arbitrary-code-execution-in-the-arista-ng-firewall/</guid>
      <description>• CVE-2025-6978 exposes command injection in Arista NG Firewall&amp;rsquo;s diagnostics component. • Remote authenticated attackers can craft HTTP requests to execute arbitrary commands as r</description>
    </item>
    <item>
      <title>Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework</title>
      <link>https://cluster-site.onrender.com/posts/knife-cutting-the-edge-disclosing-a-china-nexus-gateway-monitoring-aitm-framework/</link>
      <pubDate>Thu, 05 Feb 2026 11:00:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/knife-cutting-the-edge-disclosing-a-china-nexus-gateway-monitoring-aitm-framework/</guid>
      <description>• - Cisco Talos uncovered &amp;lsquo;DKnife,&amp;rsquo; a fully featured gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants that perform deep-packet</description>
    </item>
    <item>
      <title>Amaranth-Dragon: Weaponizing CVE-2025-8088 for Targeted Espionage in the Southeast Asia</title>
      <link>https://cluster-site.onrender.com/posts/amaranth-dragon-weaponizing-cve-2025-8088-for-targeted-espionage-in-the-southeast-asia/</link>
      <pubDate>Wed, 04 Feb 2026 13:57:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/amaranth-dragon-weaponizing-cve-2025-8088-for-targeted-espionage-in-the-southeast-asia/</guid>
      <description>• Check Point Research has identified several campaigns targeting multiple countries in the Southeast Asian region. • These related activities have been collectively categorized un</description>
    </item>
    <item>
      <title>2nd February - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/2nd-february-threat-intelligence-report/</link>
      <pubDate>Mon, 02 Feb 2026 13:35:05 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/2nd-february-threat-intelligence-report/</guid>
      <description>• FILTER BY YEAR 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 2nd February - Threat Intelligence Report For the latest discoveries in cyber research for the week of 2nd F</description>
    </item>
    <item>
      <title>Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS</title>
      <link>https://cluster-site.onrender.com/posts/guidance-from-the-frontlines-proactive-defense-against-shinyhunters-branded-data-theft-targeting-saas/</link>
      <pubDate>Fri, 30 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/guidance-from-the-frontlines-proactive-defense-against-shinyhunters-branded-data-theft-targeting-saas/</guid>
      <description>• Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS Mandiant Introduction Mandiant is tracking a significant expansion and esca</description>
    </item>
    <item>
      <title>Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft</title>
      <link>https://cluster-site.onrender.com/posts/vishing-for-access-tracking-the-expansion-of-shinyhunters-branded-saas-data-theft/</link>
      <pubDate>Fri, 30 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vishing-for-access-tracking-the-expansion-of-shinyhunters-branded-saas-data-theft/</guid>
      <description>• Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft Mandiant Google Threat Intelligence Visibility and context on the threats that matter most. • C</description>
    </item>
    <item>
      <title>Celebrating our 2025 open-source contributions</title>
      <link>https://cluster-site.onrender.com/posts/celebrating-our-2025-open-source-contributions/</link>
      <pubDate>Fri, 30 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/celebrating-our-2025-open-source-contributions/</guid>
      <description>• Celebrating our 2025 open-source contributions Last year, our engineers submitted over 375 pull requests that were merged into non-Trail of Bits repositories, touching more than</description>
    </item>
    <item>
      <title>Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529</title>
      <link>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</link>
      <pubDate>Fri, 30 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</guid>
      <description>• CVE-2024-54529: type confusion in CoreAudio&amp;rsquo;s com.apple.audio.audiohald Mach service, causing crashes. • Exploitation involved manipulating Mach messages to fetch wrong HALS_Obje</description>
    </item>
    <item>
      <title>I&#39;m locked in!</title>
      <link>https://cluster-site.onrender.com/posts/im-locked-in/</link>
      <pubDate>Thu, 29 Jan 2026 19:00:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/im-locked-in/</guid>
      <description>• Welcome to this week&amp;rsquo;s edition of the Threat Source newsletter. • I&amp;rsquo;ve struggled a lot over the last few years with balance. • I want to follow the news closely, but at the same</description>
    </item>
    <item>
      <title>Microsoft releases update to address zero-day vulnerability in Microsoft Office</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-releases-update-to-address-zero-day-vulnerability-in-microsoft-office/</link>
      <pubDate>Thu, 29 Jan 2026 14:43:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-releases-update-to-address-zero-day-vulnerability-in-microsoft-office/</guid>
      <description>• Microsoft releases update to address zero-day vulnerability in Microsoft Office Microsoft has published three out-of-band (OOB) updates so far in January 2026. • One of these upd</description>
    </item>
    <item>
      <title>Building cryptographic agility into Sigstore</title>
      <link>https://cluster-site.onrender.com/posts/building-cryptographic-agility-into-sigstore/</link>
      <pubDate>Thu, 29 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/building-cryptographic-agility-into-sigstore/</guid>
      <description>• Sigstore&amp;rsquo;s original hard-coded ECDSA P-256 + SHA-256 limited future cryptographic flexibility. • Trail of Bits collaborated to create centralized algorithm registry in Protobuf s</description>
    </item>
    <item>
      <title>Dissecting UAT-8099: New persistence mechanisms and regional focus</title>
      <link>https://cluster-site.onrender.com/posts/dissecting-uat-8099-new-persistence-mechanisms-and-regional-focus/</link>
      <pubDate>Thu, 29 Jan 2026 11:00:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dissecting-uat-8099-new-persistence-mechanisms-and-regional-focus/</guid>
      <description>• - Cisco Talos has identified a new campaign by UAT-8099, active from late 2025 to early 2026, that is targeting vulnerable Internet Information Services (IIS) servers across Asia</description>
    </item>
    <item>
      <title>IR Trends Q4 2025: Exploitation remains dominant, phishing campaign targets Native American tribal organizations</title>
      <link>https://cluster-site.onrender.com/posts/ir-trends-q4-2025-exploitation-remains-dominant-phishing-campaign-targets-native-american-tribal-organizations/</link>
      <pubDate>Thu, 29 Jan 2026 11:00:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ir-trends-q4-2025-exploitation-remains-dominant-phishing-campaign-targets-native-american-tribal-organizations/</guid>
      <description>• Threat actors predominately exploited public-facing applications for the second quarter in a row, with this tactic appearing in nearly 40 percent of Cisco Talos Incident Response</description>
    </item>
    <item>
      <title>Cyber Security Report 2026</title>
      <link>https://cluster-site.onrender.com/posts/cyber-security-report-2026/</link>
      <pubDate>Wed, 28 Jan 2026 16:34:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cyber-security-report-2026/</guid>
      <description>• CATEGORIES Android Malware23 Artificial Intelligence4 ChatGPT3 Check Point Research Publications443 Cloud Security1 CPRadio44 Crypto2 Data &amp;amp; Threat Intelligence1 Data Analysis0 D</description>
    </item>
    <item>
      <title>No Place Like Home Network: Disrupting the World&#39;s Largest Residential Proxy Network</title>
      <link>https://cluster-site.onrender.com/posts/no-place-like-home-network-disrupting-the-worlds-largest-residential-proxy-network/</link>
      <pubDate>Wed, 28 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/no-place-like-home-network-disrupting-the-worlds-largest-residential-proxy-network/</guid>
      <description>• No Place Like Home Network: Disrupting the World&amp;rsquo;s Largest Residential Proxy Network Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the thr</description>
    </item>
    <item>
      <title>Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088</title>
      <link>https://cluster-site.onrender.com/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088/</link>
      <pubDate>Tue, 27 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088/</guid>
      <description>• CVE-2025-8088: critical path traversal flaw in WinRAR allows arbitrary file writes via ADS. • Exploited by state-backed actors from Russia, China and financially motivated groups</description>
    </item>
    <item>
      <title>26th January - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/26th-january-threat-intelligence-report/</link>
      <pubDate>Mon, 26 Jan 2026 13:35:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/26th-january-threat-intelligence-report/</guid>
      <description>• Article inaccessible; requires JavaScript to load content. • Unable to verify authenticity of threat intel data. • No actionable insights provided due to technical barrier. • Sug</description>
    </item>
    <item>
      <title>Bypassing Windows Administrator Protection</title>
      <link>https://cluster-site.onrender.com/posts/bypassing-windows-administrator-protection/</link>
      <pubDate>Mon, 26 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/bypassing-windows-administrator-protection/</guid>
      <description>• Windows 11 25H2 introduces Administrator Protection, replacing UAC with a stricter privilege model. • Feature grants admin rights only when necessary, isolating limited and admin</description>
    </item>
    <item>
      <title>I scan, you scan, we all scan for... knowledge?</title>
      <link>https://cluster-site.onrender.com/posts/i-scan-you-scan-we-all-scan-for...-knowledge/</link>
      <pubDate>Thu, 22 Jan 2026 19:00:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/i-scan-you-scan-we-all-scan-for...-knowledge/</guid>
      <description>• Reconnaissance is often ignored, yet it&amp;rsquo;s essential for protecting networks. • Know your environment: attackers excel at mapping assets, from Windows 7 machines to smart fridges.</description>
    </item>
    <item>
      <title>Foxit, Epic Games Store, MedDreams vulnerabilities</title>
      <link>https://cluster-site.onrender.com/posts/foxit-epic-games-store-meddreams-vulnerabilities/</link>
      <pubDate>Thu, 22 Jan 2026 13:54:57 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/foxit-epic-games-store-meddreams-vulnerabilities/</guid>
      <description>• Cisco Talos uncovered 25 critical vulnerabilities across Foxit PDF Editor, Epic Games Store, and MedDreams PACS. • Foxit PDF Editor had privilege escalation via Microsoft Store i</description>
    </item>
    <item>
      <title>KONNI Adopts AI to Generate PowerShell Backdoors</title>
      <link>https://cluster-site.onrender.com/posts/konni-adopts-ai-to-generate-powershell-backdoors/</link>
      <pubDate>Thu, 22 Jan 2026 13:54:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/konni-adopts-ai-to-generate-powershell-backdoors/</guid>
      <description>• KONNI leverages AI to auto-generate PowerShell backdoor scripts, streamlining malware development. • AI models produce obfuscated code, enhancing stealth against signature-based</description>
    </item>
    <item>
      <title>Pwn2Own Automotive 2026 - Day One Results</title>
      <link>https://cluster-site.onrender.com/posts/pwn2own-automotive-2026-day-one-results/</link>
      <pubDate>Wed, 21 Jan 2026 04:03:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pwn2own-automotive-2026-day-one-results/</guid>
      <description>• 76 unique 0‑day vulnerabilities discovered across three days, totaling $1,047,000 in rewards. • Fuzzware.io clinched Master of Pwn with 28 points, outperforming rivals like Team</description>
    </item>
    <item>
      <title>Pwn2Own Automotive 2026 - The Full Schedule</title>
      <link>https://cluster-site.onrender.com/posts/pwn2own-automotive-2026-the-full-schedule/</link>
      <pubDate>Tue, 20 Jan 2026 10:25:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pwn2own-automotive-2026-the-full-schedule/</guid>
      <description>• Pwn2Own Automotive 2026 returns to Tokyo, featuring record 73 entries. • Competition spans real‑world automotive components, testing IVI and Level‑2 EV chargers. • Random draw se</description>
    </item>
    <item>
      <title>VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun</title>
      <link>https://cluster-site.onrender.com/posts/voidlink-evidence-that-the-era-of-advanced-ai-generated-malware-has-begun/</link>
      <pubDate>Tue, 20 Jan 2026 09:27:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/voidlink-evidence-that-the-era-of-advanced-ai-generated-malware-has-begun/</guid>
      <description>• VoidLink showcases AI-generated malware capable of crafting polymorphic code. • The malware leverages generative models to evade traditional signature-based detection. • Checkpoi</description>
    </item>
    <item>
      <title>19th January - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/19th-january-threat-intelligence-report/</link>
      <pubDate>Mon, 19 Jan 2026 08:55:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/19th-january-threat-intelligence-report/</guid>
      <description>• Unable to access threat intel report due to JavaScript requirement, preventing data retrieval. • Checkpoint Research site blocked without JavaScript, limiting threat intelligence</description>
    </item>
    <item>
      <title>Predicting 2026</title>
      <link>https://cluster-site.onrender.com/posts/predicting-2026/</link>
      <pubDate>Thu, 15 Jan 2026 19:00:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/predicting-2026/</guid>
      <description>• Predicting 2026 Welcome to this week&amp;rsquo;s edition of the Threat Source newsletter. • It&amp;rsquo;s become traditional at this time of year to make predictions about cybersecurity for the com</description>
    </item>
    <item>
      <title>Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation</title>
      <link>https://cluster-site.onrender.com/posts/closing-the-door-on-net-ntlmv1-releasing-rainbow-tables-to-accelerate-protocol-deprecation/</link>
      <pubDate>Thu, 15 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/closing-the-door-on-net-ntlmv1-releasing-rainbow-tables-to-accelerate-protocol-deprecation/</guid>
      <description>• Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation Stop attacks, reduce risk, and advance your security. • Written by: Nic Losby Introduc</description>
    </item>
    <item>
      <title>UAT-8837 targets critical infrastructure sectors in North America</title>
      <link>https://cluster-site.onrender.com/posts/uat-8837-targets-critical-infrastructure-sectors-in-north-america/</link>
      <pubDate>Thu, 15 Jan 2026 11:00:47 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/uat-8837-targets-critical-infrastructure-sectors-in-north-america/</guid>
      <description>• - Cisco Talos is closely tracking UAT-8837, a threat actor we assess with medium confidence is a China-nexus advanced persistent threat (APT) actor based on overlaps in tactics,</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</link>
      <pubDate>Wed, 14 Jan 2026 18:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</guid>
      <description>• With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland conte</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</link>
      <pubDate>Wed, 14 Jan 2026 17:59:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</guid>
      <description>• Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. • One effect of this change</description>
    </item>
    <item>
      <title>Sicarii Ransomware: Truth vs Myth</title>
      <link>https://cluster-site.onrender.com/posts/sicarii-ransomware-truth-vs-myth/</link>
      <pubDate>Wed, 14 Jan 2026 14:24:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/sicarii-ransomware-truth-vs-myth/</guid>
      <description>• JavaScript is disabled In order to continue, we need to verify that you&amp;rsquo;re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.</description>
    </item>
    <item>
      <title>The January 2026 Security Update Review</title>
      <link>https://cluster-site.onrender.com/posts/the-january-2026-security-update-review/</link>
      <pubDate>Tue, 13 Jan 2026 19:01:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-january-2026-security-update-review/</guid>
      <description>• I may be in Tokyo preparing for Pwn2Own Automotive, but that doesn&amp;rsquo;t stop patch Tuesday from coming. • Put aside your broken New Year&amp;rsquo;s resolutions for just a moment as we review</description>
    </item>
    <item>
      <title>Lack of isolation in agentic browsers resurfaces old vulnerabilities</title>
      <link>https://cluster-site.onrender.com/posts/lack-of-isolation-in-agentic-browsers-resurfaces-old-vulnerabilities/</link>
      <pubDate>Tue, 13 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lack-of-isolation-in-agentic-browsers-resurfaces-old-vulnerabilities/</guid>
      <description>• Lack of isolation in agentic browsers resurfaces old vulnerabilities With browser-embedded AI agents, we&amp;rsquo;re essentially starting the security journey over again. • We exploited a</description>
    </item>
    <item>
      <title>Unveiling VoidLink - A Stealthy, Cloud-Native Linux Malware Framework</title>
      <link>https://cluster-site.onrender.com/posts/unveiling-voidlink-a-stealthy-cloud-native-linux-malware-framework/</link>
      <pubDate>Tue, 13 Jan 2026 06:31:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/unveiling-voidlink-a-stealthy-cloud-native-linux-malware-framework/</guid>
      <description>• JavaScript is disabled In order to continue, we need to verify that you&amp;rsquo;re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.</description>
    </item>
    <item>
      <title>AuraInspector: Auditing Salesforce Aura for Data Exposure</title>
      <link>https://cluster-site.onrender.com/posts/aurainspector-auditing-salesforce-aura-for-data-exposure/</link>
      <pubDate>Mon, 12 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/aurainspector-auditing-salesforce-aura-for-data-exposure/</guid>
      <description>• AuraInspector: Auditing Salesforce Aura for Data Exposure Mandiant Written by: Amine Ismail, Anirudha Kanodia Introduction Mandiant is releasing AuraInspector, a new open-source</description>
    </item>
    <item>
      <title>12th January - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/12th-january-threat-intelligence-report/</link>
      <pubDate>Mon, 12 Jan 2026 10:07:05 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/12th-january-threat-intelligence-report/</guid>
      <description>• JavaScript is disabled In order to continue, we need to verify that you&amp;rsquo;re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.</description>
    </item>
    <item>
      <title>Breaking Down the Attack Surface of the Kenwood DNR1007XR - Part One</title>
      <link>https://cluster-site.onrender.com/posts/breaking-down-the-attack-surface-of-the-kenwood-dnr1007xr-part-one/</link>
      <pubDate>Wed, 07 Jan 2026 19:09:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/breaking-down-the-attack-surface-of-the-kenwood-dnr1007xr-part-one/</guid>
      <description>• Breaking Down the Attack Surface of the Kenwood DNR1007XR - Part One For the upcoming Pwn2Own Automotive contest, a total of 3 head units have been selected. • One of these is th</description>
    </item>
    <item>
      <title>Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns</title>
      <link>https://cluster-site.onrender.com/posts/inside-gobruteforcer-ai-generated-server-defaults-weak-passwords-and-crypto-focused-campaigns/</link>
      <pubDate>Wed, 07 Jan 2026 13:07:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/inside-gobruteforcer-ai-generated-server-defaults-weak-passwords-and-crypto-focused-campaigns/</guid>
      <description>• JavaScript is disabled In order to continue, we need to verify that you&amp;rsquo;re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.</description>
    </item>
    <item>
      <title>5th January - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/5th-january-threat-intelligence-report/</link>
      <pubDate>Mon, 05 Jan 2026 12:34:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/5th-january-threat-intelligence-report/</guid>
      <description>• JavaScript is disabled In order to continue, we need to verify that you&amp;rsquo;re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.</description>
    </item>
    <item>
      <title>Detect Go&#39;s silent arithmetic bugs with go-panikint</title>
      <link>https://cluster-site.onrender.com/posts/detect-gos-silent-arithmetic-bugs-with-go-panikint/</link>
      <pubDate>Wed, 31 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/detect-gos-silent-arithmetic-bugs-with-go-panikint/</guid>
      <description>• Go&amp;rsquo;s arithmetic operations on standard integer types are silent by default, meaning overflows &amp;lsquo;wrap around&amp;rsquo; without panicking. • This behavior has hidden an entire class of secur</description>
    </item>
    <item>
      <title>Can chatbots craft correct code?</title>
      <link>https://cluster-site.onrender.com/posts/can-chatbots-craft-correct-code/</link>
      <pubDate>Fri, 19 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/can-chatbots-craft-correct-code/</guid>
      <description>• Can chatbots craft correct code? • I recently attended the AI Engineer Code Summit in New York, an invite-only gathering of AI leaders and engineers. • One theme emerged repeated</description>
    </item>
    <item>
      <title>Use GWP-ASan to detect exploits in production environments</title>
      <link>https://cluster-site.onrender.com/posts/use-gwp-asan-to-detect-exploits-in-production-environments/</link>
      <pubDate>Tue, 16 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/use-gwp-asan-to-detect-exploits-in-production-environments/</guid>
      <description>• Use GWP-ASan to detect exploits in production environments Memory safety bugs like use-after-free and buffer overflows remain among the most exploited vulnerability classes in pr</description>
    </item>
    <item>
      <title>Welcome to the new Project Zero Blog</title>
      <link>https://cluster-site.onrender.com/posts/welcome-to-the-new-project-zero-blog/</link>
      <pubDate>Tue, 16 Dec 2025 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/welcome-to-the-new-project-zero-blog/</guid>
      <description>• While on Project Zero, we aim for our research to be leading-edge, our blog design was â¦ not so much. • We welcome readers to our shiny new blog! • For the occasion, we asked me</description>
    </item>
    <item>
      <title>Thinking Outside The Box [dusted off draft from 2017]</title>
      <link>https://cluster-site.onrender.com/posts/thinking-outside-the-box-dusted-off-draft-from-2017/</link>
      <pubDate>Tue, 16 Dec 2025 09:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/thinking-outside-the-box-dusted-off-draft-from-2017/</guid>
      <description>• Preface Hello from the future! • This is a blogpost I originally drafted in early 2017. • I wrote what I intended to be the first half of this post (about escaping from the VM to</description>
    </item>
    <item>
      <title>Windows Exploitation Techniques: Winning Race Conditions with Path Lookups</title>
      <link>https://cluster-site.onrender.com/posts/windows-exploitation-techniques-winning-race-conditions-with-path-lookups/</link>
      <pubDate>Tue, 16 Dec 2025 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/windows-exploitation-techniques-winning-race-conditions-with-path-lookups/</guid>
      <description>• This post was originally written in 2016 for the Project Zero blog. • However, in the end it was published separately in the journal PoC||GTFO issue #13 as well as in the second</description>
    </item>
    <item>
      <title>Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)</title>
      <link>https://cluster-site.onrender.com/posts/multiple-threat-actors-exploit-react2shell-cve-2025-55182/</link>
      <pubDate>Fri, 12 Dec 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/multiple-threat-actors-exploit-react2shell-cve-2025-55182/</guid>
      <description>• Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most. •</description>
    </item>
    <item>
      <title>Catching malicious package releases using a transparency log</title>
      <link>https://cluster-site.onrender.com/posts/catching-malicious-package-releases-using-a-transparency-log/</link>
      <pubDate>Fri, 12 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/catching-malicious-package-releases-using-a-transparency-log/</guid>
      <description>• Catching malicious package releases using a transparency log We&amp;rsquo;re getting Sigstore&amp;rsquo;s rekor-monitor ready for production use, making it easier for developers to detect tampering</description>
    </item>
    <item>
      <title>A look at an Android ITW DNG exploit</title>
      <link>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</link>
      <pubDate>Fri, 12 Dec 2025 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</guid>
      <description>• Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. • Thanks to a lead from Meta, these samples came to the attention of Googl</description>
    </item>
    <item>
      <title>Introducing mrva, a terminal-first approach to CodeQL multi-repo variant analysis</title>
      <link>https://cluster-site.onrender.com/posts/introducing-mrva-a-terminal-first-approach-to-codeql-multi-repo-variant-analysis/</link>
      <pubDate>Thu, 11 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/introducing-mrva-a-terminal-first-approach-to-codeql-multi-repo-variant-analysis/</guid>
      <description>• Introducing mrva, a terminal-first approach to CodeQL multi-repo variant analysis In 2023 GitHub introduced CodeQL multi-repository variant analysis (MRVA). • This functionality</description>
    </item>
    <item>
      <title>The December 2025 Security Update Review</title>
      <link>https://cluster-site.onrender.com/posts/the-december-2025-security-update-review/</link>
      <pubDate>Tue, 09 Dec 2025 18:29:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-december-2025-security-update-review/</guid>
      <description>• It&amp;rsquo;s the final patch Tuesday of 2025, but that doesn&amp;rsquo;t make it any less exciting. • Put aside your holiday planning for just a moment as we review the latest security offering fr</description>
    </item>
    <item>
      <title>A method to assess &#39;forgivable&#39; vs &#39;unforgivable&#39; vulnerabilities</title>
      <link>https://cluster-site.onrender.com/posts/a-method-to-assess-forgivable-vs-unforgivable-vulnerabilities/</link>
      <pubDate>Mon, 08 Dec 2025 09:58:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-method-to-assess-forgivable-vs-unforgivable-vulnerabilities/</guid>
      <description>• You need to enable JavaScript to run this app.</description>
    </item>
    <item>
      <title>Sanctioned but Still Spying: Intellexa&#39;s Prolific Zero-Day Exploits Continue</title>
      <link>https://cluster-site.onrender.com/posts/sanctioned-but-still-spying-intellexas-prolific-zero-day-exploits-continue/</link>
      <pubDate>Wed, 03 Dec 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/sanctioned-but-still-spying-intellexas-prolific-zero-day-exploits-continue/</guid>
      <description>• Sanctioned but Still Spying: Intellexa&amp;rsquo;s Prolific Zero-Day Exploits Continue Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats tha</description>
    </item>
    <item>
      <title>Introducing constant-time support for LLVM to protect cryptographic code</title>
      <link>https://cluster-site.onrender.com/posts/introducing-constant-time-support-for-llvm-to-protect-cryptographic-code/</link>
      <pubDate>Tue, 02 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/introducing-constant-time-support-for-llvm-to-protect-cryptographic-code/</guid>
      <description>• Introducing constant-time support for LLVM to protect cryptographic code Trail of Bits has developed constant-time coding support for LLVM, providing developers with compiler-lev</description>
    </item>
    <item>
      <title>Beyond the Watering Hole: APT24&#39;s Pivot to Multi-Vector Attacks</title>
      <link>https://cluster-site.onrender.com/posts/beyond-the-watering-hole-apt24s-pivot-to-multi-vector-attacks/</link>
      <pubDate>Thu, 20 Nov 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/beyond-the-watering-hole-apt24s-pivot-to-multi-vector-attacks/</guid>
      <description>• Beyond the Watering Hole: APT24&amp;rsquo;s Pivot to Multi-Vector Attacks Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most</description>
    </item>
    <item>
      <title>We found cryptography bugs in the elliptic library using Wycheproof</title>
      <link>https://cluster-site.onrender.com/posts/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof/</link>
      <pubDate>Tue, 18 Nov 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof/</guid>
      <description>• We found cryptography bugs in the elliptic library using Wycheproof Trail of Bits is publicly disclosing two vulnerabilities in elliptic, a widely used JavaScript library for ell</description>
    </item>
    <item>
      <title>Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem</title>
      <link>https://cluster-site.onrender.com/posts/frontline-intelligence-analysis-of-unc1549-ttps-custom-tools-and-malware-targeting-the-aerospace-and-defense-ecosystem/</link>
      <pubDate>Mon, 17 Nov 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/frontline-intelligence-analysis-of-unc1549-ttps-custom-tools-and-malware-targeting-the-aerospace-and-defense-ecosystem/</guid>
      <description>• Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem Mandiant Written by: Mohamed El-Banna, Daniel Lee, Mike</description>
    </item>
    <item>
      <title>Level up your Solidity LLM tooling with Slither-MCP</title>
      <link>https://cluster-site.onrender.com/posts/level-up-your-solidity-llm-tooling-with-slither-mcp/</link>
      <pubDate>Sat, 15 Nov 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/level-up-your-solidity-llm-tooling-with-slither-mcp/</guid>
      <description>• We&amp;rsquo;re releasingSlither-MCP, a new tool that augments LLMs with Slither&amp;rsquo;s unmatched static analysis engine. • Slither-MCP benefits virtually every use case for LLMs by exposing Sl</description>
    </item>
    <item>
      <title>How we avoided side-channels in our new post-quantum Go cryptography libraries</title>
      <link>https://cluster-site.onrender.com/posts/how-we-avoided-side-channels-in-our-new-post-quantum-go-cryptography-libraries/</link>
      <pubDate>Fri, 14 Nov 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-we-avoided-side-channels-in-our-new-post-quantum-go-cryptography-libraries/</guid>
      <description>• How we avoided side-channels in our new post-quantum Go cryptography libraries The Trail of Bits cryptography team is releasing our open-source pure Go implementations of ML-DSA</description>
    </item>
    <item>
      <title>Time Travel Triage: An Introduction to Time Travel Debugging using a .NET Process Hollowing Case Study</title>
      <link>https://cluster-site.onrender.com/posts/time-travel-triage-an-introduction-to-time-travel-debugging-using-a-.net-process-hollowing-case-study/</link>
      <pubDate>Thu, 13 Nov 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/time-travel-triage-an-introduction-to-time-travel-debugging-using-a-.net-process-hollowing-case-study/</guid>
      <description>• Time Travel Triage: An Introduction to Time Travel Debugging using a .NET Process Hollowing Case Study Mandiant Google Threat Intelligence Visibility and context on the threats t</description>
    </item>
    <item>
      <title>Building checksec without boundaries with Checksec Anywhere</title>
      <link>https://cluster-site.onrender.com/posts/building-checksec-without-boundaries-with-checksec-anywhere/</link>
      <pubDate>Thu, 13 Nov 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/building-checksec-without-boundaries-with-checksec-anywhere/</guid>
      <description>• Since its original release in 2009,checksechas become widely used in the software security community, proving useful in CTF challenges, security posturing, and general binary ana</description>
    </item>
    <item>
      <title>The November 2025 Security Update Review</title>
      <link>https://cluster-site.onrender.com/posts/the-november-2025-security-update-review/</link>
      <pubDate>Tue, 11 Nov 2025 18:30:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-november-2025-security-update-review/</guid>
      <description>• I&amp;rsquo;ve made it through Pwn2Own Ireland, and while many are celebrated those who served their country in the armed services, patch Tuesday stops for no one. • So affix your poppy ac</description>
    </item>
    <item>
      <title>No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480</title>
      <link>https://cluster-site.onrender.com/posts/no-place-like-localhost-unauthenticated-remote-access-via-triofox-vulnerability-cve-2025-12480/</link>
      <pubDate>Mon, 10 Nov 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/no-place-like-localhost-unauthenticated-remote-access-via-triofox-vulnerability-cve-2025-12480/</guid>
      <description>• No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480 Mandiant Written by: Stallone D&amp;rsquo;Souza, Praveeth DSouza, Bill Glynn, Kevin O&amp;rsquo;Flynn,</description>
    </item>
    <item>
      <title>Balancer hack analysis and guidance for the DeFi ecosystem</title>
      <link>https://cluster-site.onrender.com/posts/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/</link>
      <pubDate>Fri, 07 Nov 2025 23:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/balancer-hack-analysis-and-guidance-for-the-defi-ecosystem/</guid>
      <description>• Balancer hack analysis and guidance for the DeFi ecosystem TL;DR - The root cause of the hack was a rounding direction issue that had been present in the code for many years. • -</description>
    </item>
    <item>
      <title>GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools</title>
      <link>https://cluster-site.onrender.com/posts/gtig-ai-threat-tracker-advances-in-threat-actor-usage-of-ai-tools/</link>
      <pubDate>Wed, 05 Nov 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/gtig-ai-threat-tracker-advances-in-threat-actor-usage-of-ai-tools/</guid>
      <description>• GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter m</description>
    </item>
    <item>
      <title>Preparing for Threats to Come: Cybersecurity Forecast 2026</title>
      <link>https://cluster-site.onrender.com/posts/preparing-for-threats-to-come-cybersecurity-forecast-2026/</link>
      <pubDate>Tue, 04 Nov 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/preparing-for-threats-to-come-cybersecurity-forecast-2026/</guid>
      <description>• Preparing for Threats to Come: Cybersecurity Forecast 2026 Blog and Content Manager Visibility and context on the threats that matter most. • Every November, we make it our missi</description>
    </item>
    <item>
      <title>The cryptography behind electronic passports</title>
      <link>https://cluster-site.onrender.com/posts/the-cryptography-behind-electronic-passports/</link>
      <pubDate>Fri, 31 Oct 2025 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cryptography-behind-electronic-passports/</guid>
      <description>• The cryptography behind electronic passports Did you know that most modern passports are actually embedded devices containing an entire filesystem, access controls, and support f</description>
    </item>
    <item>
      <title>Vulnerabilities in LUKS2 disk encryption for confidential VMs</title>
      <link>https://cluster-site.onrender.com/posts/vulnerabilities-in-luks2-disk-encryption-for-confidential-vms/</link>
      <pubDate>Thu, 30 Oct 2025 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vulnerabilities-in-luks2-disk-encryption-for-confidential-vms/</guid>
      <description>• Trail of Bits is disclosing vulnerabilities in eight different confidential computing systems that use Linux Unified Key Setup version 2 (LUKS2) for disk encryption. • Using thes</description>
    </item>
    <item>
      <title>Keys to the Kingdom: A Defender&#39;s Guide to Privileged Account Monitoring</title>
      <link>https://cluster-site.onrender.com/posts/keys-to-the-kingdom-a-defenders-guide-to-privileged-account-monitoring/</link>
      <pubDate>Tue, 28 Oct 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/keys-to-the-kingdom-a-defenders-guide-to-privileged-account-monitoring/</guid>
      <description>• Keys to the Kingdom: A Defender&amp;rsquo;s Guide to Privileged Account Monitoring Mandiant Written by: Bhavesh Dhake, Will Silverstone, Matthew Hitchcock, Aaron Fletcher The Criticality o</description>
    </item>
    <item>
      <title>Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials</title>
      <link>https://cluster-site.onrender.com/posts/help-wanted-vietnamese-actors-using-fake-job-posting-campaigns-to-deliver-malware-and-steal-credentials/</link>
      <pubDate>Thu, 23 Oct 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/help-wanted-vietnamese-actors-using-fake-job-posting-campaigns-to-deliver-malware-and-steal-credentials/</guid>
      <description>• Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials Visibility and context on the threats that matter most. • Google Threat I</description>
    </item>
    <item>
      <title>Pwn2Own Ireland 2025: Day Three and Master of Pwn</title>
      <link>https://cluster-site.onrender.com/posts/pwn2own-ireland-2025-day-three-and-master-of-pwn/</link>
      <pubDate>Thu, 23 Oct 2025 09:41:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pwn2own-ireland-2025-day-three-and-master-of-pwn/</guid>
      <description>• Pwn2Own Ireland 2025: Day Three and Master of Pwn Welcome to the third and final day of Pwn2Own Ireland 2025. • So far, we&amp;rsquo;ve awarded $792,750 for 56 unique 0-day bugs, and we st</description>
    </item>
    <item>
      <title>Prompt injection to RCE in AI agents</title>
      <link>https://cluster-site.onrender.com/posts/prompt-injection-to-rce-in-ai-agents/</link>
      <pubDate>Wed, 22 Oct 2025 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/prompt-injection-to-rce-in-ai-agents/</guid>
      <description>• Prompt injection to RCE in AI agents Modern AI agents increasingly execute system commands to automate filesystem operations, code analysis, and development workflows. • While so</description>
    </item>
    <item>
      <title>Pwn2Own Ireland 2025: Day One Results</title>
      <link>https://cluster-site.onrender.com/posts/pwn2own-ireland-2025-day-one-results/</link>
      <pubDate>Tue, 21 Oct 2025 09:26:57 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pwn2own-ireland-2025-day-one-results/</guid>
      <description>• Pwn2Own Ireland 2025: Day One Results Welcome to Day One of Pwn2Own Ireland 2025! • We have 17 attempts today with some exciting research on display. • We&amp;rsquo;ll be posting results h</description>
    </item>
    <item>
      <title>Pwn2Own Ireland 2025: The Full Schedule</title>
      <link>https://cluster-site.onrender.com/posts/pwn2own-ireland-2025-the-full-schedule/</link>
      <pubDate>Mon, 20 Oct 2025 17:01:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pwn2own-ireland-2025-the-full-schedule/</guid>
      <description>• Pwn2Own Ireland 2025: The Full Schedule Welcome to Pwn2Own Ireland 2025! • We have some amazing spooky entries for this year&amp;rsquo;s contest, and a potential of up to $2,000,000 - incl</description>
    </item>
    <item>
      <title>Pwn2Own Automotive Returns to Tokyo with Expanded Chargers and More!</title>
      <link>https://cluster-site.onrender.com/posts/pwn2own-automotive-returns-to-tokyo-with-expanded-chargers-and-more/</link>
      <pubDate>Thu, 16 Oct 2025 15:00:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pwn2own-automotive-returns-to-tokyo-with-expanded-chargers-and-more/</guid>
      <description>• If you just want to read the rules, click here. • Updated as of November 21 to expand the Alpitronic target scope and to clarify the model of the ChargePointHome Flex model numbe</description>
    </item>
    <item>
      <title>The October 2025 Security Update Review</title>
      <link>https://cluster-site.onrender.com/posts/the-october-2025-security-update-review/</link>
      <pubDate>Tue, 14 Oct 2025 18:38:44 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-october-2025-security-update-review/</guid>
      <description>• I&amp;rsquo;m currently in Cork, Ireland as we prepare for Pwn2Own Ireland, but that doesn&amp;rsquo;t stop patch Tuesday from coming. • Take a break from your scheduled activities and let&amp;rsquo;s take a</description>
    </item>
    <item>
      <title>Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing</title>
      <link>https://cluster-site.onrender.com/posts/crafting-a-full-exploit-rce-from-a-crash-in-autodesk-revit-rfa-file-parsing/</link>
      <pubDate>Wed, 08 Oct 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crafting-a-full-exploit-rce-from-a-crash-in-autodesk-revit-rfa-file-parsing/</guid>
      <description>• In April of 2025, my colleague Mat Powell was hunting for vulnerabilities in Autodesk Revit 2025. • While fuzzing RFA files, he found the following crash (CVE-2025-5037 / ZDI-CAN</description>
    </item>
    <item>
      <title>Taming 2,500 compiler warnings with CodeQL, an OpenVPN2 case study</title>
      <link>https://cluster-site.onrender.com/posts/taming-2500-compiler-warnings-with-codeql-an-openvpn2-case-study/</link>
      <pubDate>Thu, 25 Sep 2025 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/taming-2500-compiler-warnings-with-codeql-an-openvpn2-case-study/</guid>
      <description>• Taming 2,500 compiler warnings with CodeQL, an OpenVPN2 case study Why are implicit integer conversions a problem in C? • During our security review of OpenVPN2, we faced a daunt</description>
    </item>
    <item>
      <title>CVE-2025-23298: Getting Remote Code Execution in NVIDIA Merlin</title>
      <link>https://cluster-site.onrender.com/posts/cve-2025-23298-getting-remote-code-execution-in-nvidia-merlin/</link>
      <pubDate>Wed, 24 Sep 2025 16:41:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cve-2025-23298-getting-remote-code-execution-in-nvidia-merlin/</guid>
      <description>• CVE-2025-23298: Getting Remote Code Execution in NVIDIA Merlin While investigating the security posture of various machine learning (ML) and artificial intelligence (AI) framewor</description>
    </item>
    <item>
      <title>Supply chain attacks are exploiting our assumptions</title>
      <link>https://cluster-site.onrender.com/posts/supply-chain-attacks-are-exploiting-our-assumptions/</link>
      <pubDate>Wed, 24 Sep 2025 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/supply-chain-attacks-are-exploiting-our-assumptions/</guid>
      <description>• Supply chain attacks are exploiting our assumptions Every time you run cargo add or pip install , you are taking a leap of faith. • You trust that the code you are downloading co</description>
    </item>
    <item>
      <title>The September 2025 Security Update Review</title>
      <link>https://cluster-site.onrender.com/posts/the-september-2025-security-update-review/</link>
      <pubDate>Tue, 09 Sep 2025 19:06:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-september-2025-security-update-review/</guid>
      <description>• There&amp;rsquo;s a crispness in the air - at least here in North America - and with it comes the latest security patches from Adobe and Microsoft. • Take a break from your scheduled activ</description>
    </item>
    <item>
      <title>Active Cyber Defence (ACD) - The Third Year</title>
      <link>https://cluster-site.onrender.com/posts/active-cyber-defence-acd-the-third-year/</link>
      <pubDate>Mon, 04 Aug 2025 14:24:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/active-cyber-defence-acd-the-third-year/</guid>
      <description>• You need to enable JavaScript to run this app. • You need to enable JavaScript to run this app.</description>
    </item>
    <item>
      <title>Impact of AI on cyber threat from now to 2027</title>
      <link>https://cluster-site.onrender.com/posts/impact-of-ai-on-cyber-threat-from-now-to-2027/</link>
      <pubDate>Fri, 16 May 2025 20:03:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/impact-of-ai-on-cyber-threat-from-now-to-2027/</guid>
      <description>• AI is accelerating threat sophistication, enabling attackers to craft more convincing phishing campaigns. • Machine‑learning models are used to generate polymorphic malware that</description>
    </item>
    <item>
      <title>Vendor Security Assessment</title>
      <link>https://cluster-site.onrender.com/posts/vendor-security-assessment/</link>
      <pubDate>Wed, 12 Mar 2025 11:21:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vendor-security-assessment/</guid>
      <description>• Identify vendor security posture through comprehensive risk assessment. • Evaluate compliance with industry standards and regulatory requirements. • Assess data protection, acces</description>
    </item>
    <item>
      <title>Threat report on application stores</title>
      <link>https://cluster-site.onrender.com/posts/threat-report-on-application-stores/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-report-on-application-stores/</guid>
      <description>• Malware increasingly hides in legitimate app store listings, exploiting user trust for widespread infection. • Supply‑chain attacks target third‑party libraries, enabling attacke</description>
    </item>
    <item>
      <title>The threat from commercial cyber proliferation</title>
      <link>https://cluster-site.onrender.com/posts/the-threat-from-commercial-cyber-proliferation/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-threat-from-commercial-cyber-proliferation/</guid>
      <description>• Commercial software proliferation expands attack surface, increasing vulnerability exposure across enterprises. • Open-source components in commercial stacks introduce hidden bac</description>
    </item>
    <item>
      <title>The near-term impact of AI on the cyber threat</title>
      <link>https://cluster-site.onrender.com/posts/the-near-term-impact-of-ai-on-the-cyber-threat/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-near-term-impact-of-ai-on-the-cyber-threat/</guid>
      <description>• AI accelerates threat detection, enabling faster identification of malicious activity. • Adversarial AI allows attackers to craft evasive malware that bypasses traditional defens</description>
    </item>
    <item>
      <title>The cyber threat to Universities</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-universities/</link>
      <pubDate>Wed, 12 Mar 2025 11:19:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-universities/</guid>
      <description>• Universities face rising ransomware attacks targeting research data and student records. • Phishing campaigns exploit faculty credentials to gain network access. • Supply‑chain v</description>
    </item>
    <item>
      <title>The Cyber Threat to UK Business</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-uk-business/</link>
      <pubDate>Wed, 12 Mar 2025 11:19:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-uk-business/</guid>
      <description>• Ransomware remains the top threat, targeting critical UK business data. • Phishing campaigns exploit remote working, increasing credential theft. • Supply‑chain attacks grow, com</description>
    </item>
    <item>
      <title>The cyber threat to sports organisations</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-sports-organisations/</link>
      <pubDate>Wed, 12 Mar 2025 11:18:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-sports-organisations/</guid>
      <description>• Sports organisations increasingly targeted by ransomware, phishing, and credential‑stealing attacks. • High‑profile events like the Olympics and World Cup attract sophisticated t</description>
    </item>
    <item>
      <title>Summary of the NCSC analysis of May 2020 US sanction</title>
      <link>https://cluster-site.onrender.com/posts/summary-of-the-ncsc-analysis-of-may-2020-us-sanction/</link>
      <pubDate>Wed, 12 Mar 2025 11:17:43 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/summary-of-the-ncsc-analysis-of-may-2020-us-sanction/</guid>
      <description>• US sanctions in May 2020 targeted Russian cyber actors and infrastructure. • NCSC identified increased threat actor activity following sanction announcements. • Sanctions disrupt</description>
    </item>
    <item>
      <title>Summary of NCSC&#39;s security analysis for the UK telecoms sector</title>
      <link>https://cluster-site.onrender.com/posts/summary-of-ncscs-security-analysis-for-the-uk-telecoms-sector/</link>
      <pubDate>Wed, 12 Mar 2025 11:16:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/summary-of-ncscs-security-analysis-for-the-uk-telecoms-sector/</guid>
      <description>• UK telecoms face rising cyber threats, including ransomware targeting network infrastructure. • NCSC highlights supply chain risks from overseas vendors in 5G equipment. • Vulner</description>
    </item>
    <item>
      <title>Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking</title>
      <link>https://cluster-site.onrender.com/posts/technical-report-responsible-use-of-the-border-gateway-protocol-bgp-for-isp-interworking/</link>
      <pubDate>Wed, 12 Mar 2025 11:12:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/technical-report-responsible-use-of-the-border-gateway-protocol-bgp-for-isp-interworking/</guid>
      <description>• BGP is critical for inter-ISP routing, requiring strict policy enforcement to prevent leaks and hijacks. • Implement prefix filtering and route origin validation to ensure only l</description>
    </item>
    <item>
      <title>Organisational use of Enterprise Connected Devices</title>
      <link>https://cluster-site.onrender.com/posts/organisational-use-of-enterprise-connected-devices/</link>
      <pubDate>Wed, 12 Mar 2025 11:11:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/organisational-use-of-enterprise-connected-devices/</guid>
      <description>• Enterprise connected devices expand attack surface, enabling lateral movement across corporate networks. • Insider threats amplified as employees use personal devices for work, b</description>
    </item>
    <item>
      <title>Joint report on publicly available hacking tools</title>
      <link>https://cluster-site.onrender.com/posts/joint-report-on-publicly-available-hacking-tools/</link>
      <pubDate>Wed, 12 Mar 2025 11:11:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/joint-report-on-publicly-available-hacking-tools/</guid>
      <description>• Joint report reveals surge in publicly available hacking toolkits targeting critical infrastructure. • Analysts highlight increased ease of access via dark web marketplaces and o</description>
    </item>
    <item>
      <title>Incident trends report (October 2018 - April 2019)</title>
      <link>https://cluster-site.onrender.com/posts/incident-trends-report-october-2018-april-2019/</link>
      <pubDate>Wed, 12 Mar 2025 11:10:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/incident-trends-report-october-2018-april-2019/</guid>
      <description>• Over 1,200 cyber incidents reported across 30 countries, highlighting rising ransomware activity. • Ransomware attacks surged 35%, with CryptoLocker variants targeting healthcare</description>
    </item>
    <item>
      <title>High level privacy and security design for NHS COVID-19 contact tracing app</title>
      <link>https://cluster-site.onrender.com/posts/high-level-privacy-and-security-design-for-nhs-covid-19-contact-tracing-app/</link>
      <pubDate>Wed, 12 Mar 2025 11:09:09 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/high-level-privacy-and-security-design-for-nhs-covid-19-contact-tracing-app/</guid>
      <description>• Decentralized architecture keeps contact data on device, reducing central data exposure. • Uses Bluetooth Low Energy (BLE) for proximity detection, no GPS or location tracking. •</description>
    </item>
    <item>
      <title>Decrypting diversity: Diversity and inclusion in cyber security report 2021</title>
      <link>https://cluster-site.onrender.com/posts/decrypting-diversity-diversity-and-inclusion-in-cyber-security-report-2021/</link>
      <pubDate>Wed, 12 Mar 2025 11:07:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/decrypting-diversity-diversity-and-inclusion-in-cyber-security-report-2021/</guid>
      <description>• Cybersecurity workforce remains 70% male, with women under 20% in technical roles. • Minority representation below 15%, limiting diverse threat perspective. • 2021 report links d</description>
    </item>
  </channel>
</rss>
