<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Cybersecurity on Tenu Tech Brief</title>
    <link>https://cluster-site.onrender.com/tags/cybersecurity/</link>
    <description>Recent content in Cybersecurity on Tenu Tech Brief</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 26 Feb 2026 02:42:06 +0000</lastBuildDate>
    <atom:link href="https://cluster-site.onrender.com/tags/cybersecurity/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance &amp;#x5b;Guest Diary&amp;#x5d;, (Tue, Feb 24th)</title>
      <link>https://cluster-site.onrender.com/posts/finding-signal-in-the-noise-lessons-learned-running-a-honeypot-with-ai-assistance-%23x5bguest-diary%23x5d-tue-feb-24th/</link>
      <pubDate>Thu, 26 Feb 2026 02:11:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/finding-signal-in-the-noise-lessons-learned-running-a-honeypot-with-ai-assistance-%23x5bguest-diary%23x5d-tue-feb-24th/</guid>
      <description>• Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary] [This is a Guest Diary by Austin Bodolay, an ISC intern as part of the SANS • edu</description>
    </item>
    <item>
      <title>Chinese Police Use ChatGPT to Smear Japan PM Takaichi</title>
      <link>https://cluster-site.onrender.com/posts/chinese-police-use-chatgpt-to-smear-japan-pm-takaichi/</link>
      <pubDate>Thu, 26 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/chinese-police-use-chatgpt-to-smear-japan-pm-takaichi/</guid>
      <description>• A Chinese keyboard warrior inadvertently leaked information about politically motivated influence operations through a ChatGPT account</description>
    </item>
    <item>
      <title>Flaws in Claude Code Put Developers&#39; Machines at Risk</title>
      <link>https://cluster-site.onrender.com/posts/flaws-in-claude-code-put-developers-machines-at-risk/</link>
      <pubDate>Wed, 25 Feb 2026 22:02:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/flaws-in-claude-code-put-developers-machines-at-risk/</guid>
      <description>• The vulnerabilities highlight a big drawback to integrating AI into software development workflows and the potential impact on supply chains</description>
    </item>
    <item>
      <title>Fake Next.js job interview tests backdoor developer&#39;s devices</title>
      <link>https://cluster-site.onrender.com/posts/fake-next.js-job-interview-tests-backdoor-developers-devices/</link>
      <pubDate>Wed, 25 Feb 2026 21:47:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-next.js-job-interview-tests-backdoor-developers-devices/</guid>
      <description>• js job interview tests backdoor developer&amp;rsquo;s devices February 25, 2026 04:47 PM 0 A coordinated campaign targeting software developers with job-themed lures is using malicious rep</description>
    </item>
    <item>
      <title>RAMP Forum Seizure Fractures Ransomware Ecosystem</title>
      <link>https://cluster-site.onrender.com/posts/ramp-forum-seizure-fractures-ransomware-ecosystem/</link>
      <pubDate>Wed, 25 Feb 2026 21:14:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ramp-forum-seizure-fractures-ransomware-ecosystem/</guid>
      <description>• Researchers suggest defenders monitor how these malicious groups re-form and leverage the useful threat intel to guide their next moves</description>
    </item>
    <item>
      <title>The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies &amp;#x5b;Guest Diary&amp;#x5d;, (Wed,...</title>
      <link>https://cluster-site.onrender.com/posts/the-clair-model-a-synthesized-conceptual-framework-for-mapping-critical-infrastructure-interdependencies-%23x5bguest-diary%23x5d-wed.../</link>
      <pubDate>Wed, 25 Feb 2026 21:09:28 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-clair-model-a-synthesized-conceptual-framework-for-mapping-critical-infrastructure-interdependencies-%23x5bguest-diary%23x5d-wed.../</guid>
      <description>• The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary] [This is a guest diary contributed by Claire Perry (Linked</description>
    </item>
    <item>
      <title>PCI Council Says Threats to Payments Systems Are Speeding Up</title>
      <link>https://cluster-site.onrender.com/posts/pci-council-says-threats-to-payments-systems-are-speeding-up/</link>
      <pubDate>Wed, 25 Feb 2026 19:15:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pci-council-says-threats-to-payments-systems-are-speeding-up/</guid>
      <description>• The PCI Security Standards Council experienced a record year in many regards, but its first annual report shows it needs to work even faster to stay ahead of attackers</description>
    </item>
    <item>
      <title>Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries</title>
      <link>https://cluster-site.onrender.com/posts/google-disrupts-unc2814-gridtide-campaign-after-53-breaches-across-42-countries/</link>
      <pubDate>Wed, 25 Feb 2026 17:46:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-disrupts-unc2814-gridtide-campaign-after-53-breaches-across-42-countries/</guid>
      <description>• Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries Google on Wednesday disclosed that it worked with industry partners to disrupt the infrastructure</description>
    </item>
    <item>
      <title>Chinese cyberspies breached dozens of telecom firms, govt agencies</title>
      <link>https://cluster-site.onrender.com/posts/chinese-cyberspies-breached-dozens-of-telecom-firms-govt-agencies/</link>
      <pubDate>Wed, 25 Feb 2026 17:00:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/chinese-cyberspies-breached-dozens-of-telecom-firms-govt-agencies/</guid>
      <description>• Chinese cyberspies breached dozens of telecom firms, govt agencies February 25, 2026 12:00 PM 0 Google&amp;rsquo;s Threat Intelligence Group (GTIG), Mandiant, and partners disrupted a glob</description>
    </item>
    <item>
      <title>Malicious Next.js Repos Target Developers Via Fake Job Interviews</title>
      <link>https://cluster-site.onrender.com/posts/malicious-next.js-repos-target-developers-via-fake-job-interviews/</link>
      <pubDate>Wed, 25 Feb 2026 16:42:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-next.js-repos-target-developers-via-fake-job-interviews/</guid>
      <description>• Linked to North Korean fake job-recruitment campaigns, the poisoned repositories are aimed at establishing persistent access to infected machines</description>
    </item>
    <item>
      <title>The Blast Radius Problem: Stolen Credentials are Weaponizing Agentic AI</title>
      <link>https://cluster-site.onrender.com/posts/the-blast-radius-problem-stolen-credentials-are-weaponizing-agentic-ai/</link>
      <pubDate>Wed, 25 Feb 2026 16:16:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-blast-radius-problem-stolen-credentials-are-weaponizing-agentic-ai/</guid>
      <description>• Weak access controls, AI confusion, and the interconnection of business continue to expand Threat • More than half (56%) of the 400,000 vulnerabilities IBM X-Force tracked in 202</description>
    </item>
    <item>
      <title>Google Disrupts Chinese Cyberespionage Campaign Targeting Telecoms, Governments</title>
      <link>https://cluster-site.onrender.com/posts/google-disrupts-chinese-cyberespionage-campaign-targeting-telecoms-governments/</link>
      <pubDate>Wed, 25 Feb 2026 16:01:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-disrupts-chinese-cyberespionage-campaign-targeting-telecoms-governments/</guid>
      <description>• Google announced on Wednesday that it has disrupted a significant China-linked cyberespionage campaign targeting telecoms and government organizations worldwide • The threat acto</description>
    </item>
    <item>
      <title>Marquis sues SonicWall over backup breach that led to ransomware attack</title>
      <link>https://cluster-site.onrender.com/posts/marquis-sues-sonicwall-over-backup-breach-that-led-to-ransomware-attack/</link>
      <pubDate>Wed, 25 Feb 2026 15:54:44 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/marquis-sues-sonicwall-over-backup-breach-that-led-to-ransomware-attack/</guid>
      <description>• Marquis sues SonicWall over backup breach that led to ransomware attack February 25, 2026 10:54 AM 0 Marquis Software Solutions has filed a lawsuit against SonicWall, accusing th</description>
    </item>
    <item>
      <title>SLH Offers $500-$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks</title>
      <link>https://cluster-site.onrender.com/posts/slh-offers-500-1000-per-call-to-recruit-women-for-it-help-desk-vishing-attacks/</link>
      <pubDate>Wed, 25 Feb 2026 15:06:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/slh-offers-500-1000-per-call-to-recruit-women-for-it-help-desk-vishing-attacks/</guid>
      <description>• SLH Offers $500-$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks The notorious cybercrime collective known asScattered LAPSUS$ Hunters(SLH) has been observed off</description>
    </item>
    <item>
      <title>The OpenClaw Hype: Analysis of Chatter from Open-Source Deep and Dark Web</title>
      <link>https://cluster-site.onrender.com/posts/the-openclaw-hype-analysis-of-chatter-from-open-source-deep-and-dark-web/</link>
      <pubDate>Wed, 25 Feb 2026 15:01:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-openclaw-hype-analysis-of-chatter-from-open-source-deep-and-dark-web/</guid>
      <description>• The OpenClaw Hype: Analysis of Chatter from Open-Source Deep and Dark Web February 25, 2026 10:01 AM 0 OpenClaw started as a side project of a developer who wanted to make his (a</description>
    </item>
    <item>
      <title>Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It</title>
      <link>https://cluster-site.onrender.com/posts/top-5-ways-broken-triage-increases-business-risk-instead-of-reducing-it/</link>
      <pubDate>Wed, 25 Feb 2026 14:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/top-5-ways-broken-triage-increases-business-risk-instead-of-reducing-it/</guid>
      <description>• Triage is supposed to make things simpler • In a lot of teams, it does the opposite • When you can&amp;rsquo;t reach a confident verdict early, alerts turn into repeat checks, back-and-for</description>
    </item>
    <item>
      <title>Why &#39;Call This Number&#39; TOAD Emails Beat Gateways</title>
      <link>https://cluster-site.onrender.com/posts/why-call-this-number-toad-emails-beat-gateways/</link>
      <pubDate>Wed, 25 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/why-call-this-number-toad-emails-beat-gateways/</guid>
      <description>• Attackers are bypassing email gateways through telephone-oriented attack delivery (TOAD), in which the only email payload is a phone number</description>
    </item>
    <item>
      <title>Medical Device Maker UFP Technologies Hit by Cyberattack</title>
      <link>https://cluster-site.onrender.com/posts/medical-device-maker-ufp-technologies-hit-by-cyberattack/</link>
      <pubDate>Wed, 25 Feb 2026 13:40:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/medical-device-maker-ufp-technologies-hit-by-cyberattack/</guid>
      <description>• Medical device manufacturer UFP Technologies on Tuesday disclosed a cybersecurity incident that involved the theft of files and the disruption of some IT systems • UFP Technologi</description>
    </item>
    <item>
      <title>Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia</title>
      <link>https://cluster-site.onrender.com/posts/ex-us-defense-contractor-executive-jailed-for-selling-exploits-to-russia/</link>
      <pubDate>Wed, 25 Feb 2026 12:59:30 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ex-us-defense-contractor-executive-jailed-for-selling-exploits-to-russia/</guid>
      <description>• An Australian national was sentenced to 87 months in a US prison for stealing trade secrets from a defense contractor and selling them to a Russian cyber-exploit broker • Accordi</description>
    </item>
    <item>
      <title>Zyxel warns of critical RCE flaw affecting over a dozen routers</title>
      <link>https://cluster-site.onrender.com/posts/zyxel-warns-of-critical-rce-flaw-affecting-over-a-dozen-routers/</link>
      <pubDate>Wed, 25 Feb 2026 12:53:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/zyxel-warns-of-critical-rce-flaw-affecting-over-a-dozen-routers/</guid>
      <description>• Zyxel warns of critical RCE flaw affecting over a dozen routers February 25, 2026 07:53 AM 0 Taiwan networking provider Zyxel has released security updates to address a critical</description>
    </item>
    <item>
      <title>Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware</title>
      <link>https://cluster-site.onrender.com/posts/malicious-nuget-packages-stole-asp.net-data-npm-package-dropped-malware/</link>
      <pubDate>Wed, 25 Feb 2026 12:43:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-nuget-packages-stole-asp.net-data-npm-package-dropped-malware/</guid>
      <description>• Malicious NuGet Packages Stole ASP • NET Data; npm Package Dropped Malware Cybersecurity researchers have discovered four malicious NuGet packages that are designed to target ASP</description>
    </item>
    <item>
      <title>Over 12 Million Users Impacted by CarGurus Data Breach</title>
      <link>https://cluster-site.onrender.com/posts/over-12-million-users-impacted-by-cargurus-data-breach/</link>
      <pubDate>Wed, 25 Feb 2026 12:32:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/over-12-million-users-impacted-by-cargurus-data-breach/</guid>
      <description>• More than 12 million users have been affected by a data breach at automotive research and shopping website CarGurus.The incident was disclosed last week, when the infamous extort</description>
    </item>
    <item>
      <title>&#39;Richter Scale&#39; Model Measures Magnitude of OT Cyber Incidents</title>
      <link>https://cluster-site.onrender.com/posts/richter-scale-model-measures-magnitude-of-ot-cyber-incidents/</link>
      <pubDate>Wed, 25 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/richter-scale-model-measures-magnitude-of-ot-cyber-incidents/</guid>
      <description>• ICS/OT experts have devised a scoring system for rating the severity and effects of cybersecurity events in operational technology environments.</description>
    </item>
    <item>
      <title>Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems</title>
      <link>https://cluster-site.onrender.com/posts/immediate-action-required-cisa-issues-emergency-directive-to-secure-cisco-sd-wan-systems/</link>
      <pubDate>Wed, 25 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/immediate-action-required-cisa-issues-emergency-directive-to-secure-cisco-sd-wan-systems/</guid>
      <description>• Immediate Action Required: CISA Issues Emergency Directive to Secure Cisco SD-WAN Systems WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today issuedEme</description>
    </item>
    <item>
      <title>Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site</title>
      <link>https://cluster-site.onrender.com/posts/wynn-resorts-confirms-data-breach-after-hackers-remove-it-from-leak-site/</link>
      <pubDate>Wed, 25 Feb 2026 11:35:48 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wynn-resorts-confirms-data-breach-after-hackers-remove-it-from-leak-site/</guid>
      <description>• Las Vegas-based high-end casino and hotel operator Wynn Resorts has confirmed that hackers have stolen employee data.&amp;lsquo;We have learned that an unauthorized third party acquired ce</description>
    </item>
    <item>
      <title>Manual Processes Are Putting National Security at Risk</title>
      <link>https://cluster-site.onrender.com/posts/manual-processes-are-putting-national-security-at-risk/</link>
      <pubDate>Wed, 25 Feb 2026 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/manual-processes-are-putting-national-security-at-risk/</guid>
      <description>• Why automating sensitive data transfers is now a mission-critical priority More than half of national security organizations still rely on manual processes to transfer sensitive</description>
    </item>
    <item>
      <title>Astelia Raises $35 Million for Exposure Management</title>
      <link>https://cluster-site.onrender.com/posts/astelia-raises-35-million-for-exposure-management/</link>
      <pubDate>Wed, 25 Feb 2026 10:38:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/astelia-raises-35-million-for-exposure-management/</guid>
      <description>• Cybersecurity startup Astelia has announced raising $35 million in seed and Series A funding. • The investment was led by Index Ventures and Team8, with additional support from H</description>
    </item>
    <item>
      <title>US sanctions Russian broker for buying stolen zero-day exploits</title>
      <link>https://cluster-site.onrender.com/posts/us-sanctions-russian-broker-for-buying-stolen-zero-day-exploits/</link>
      <pubDate>Wed, 25 Feb 2026 10:31:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/us-sanctions-russian-broker-for-buying-stolen-zero-day-exploits/</guid>
      <description>• US sanctions Russian broker for buying stolen zero-day exploits February 25, 2026 05:31 AM 0 The U.S. • Treasury Department has sanctioned a Russian exploit broker who bought sto</description>
    </item>
    <item>
      <title>Reddit Hit With $20 Million UK Data Privacy Fine Over Child Safety Failings</title>
      <link>https://cluster-site.onrender.com/posts/reddit-hit-with-20-million-uk-data-privacy-fine-over-child-safety-failings/</link>
      <pubDate>Wed, 25 Feb 2026 10:04:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/reddit-hit-with-20-million-uk-data-privacy-fine-over-child-safety-failings/</guid>
      <description>• Britain&amp;rsquo;s data privacy watchdog slapped online forum Reddit on Tuesday with a fine worth nearly $20 million for failures involving children&amp;rsquo;s personal information • The Informati</description>
    </item>
    <item>
      <title>Claude&#39;s New AI Vulnerability Scanner Sends Cybersecurity Shares Plunging</title>
      <link>https://cluster-site.onrender.com/posts/claudes-new-ai-vulnerability-scanner-sends-cybersecurity-shares-plunging/</link>
      <pubDate>Wed, 25 Feb 2026 09:44:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/claudes-new-ai-vulnerability-scanner-sends-cybersecurity-shares-plunging/</guid>
      <description>• The stocks of major cybersecurity companies have fallen sharply after AI firm Anthropic unveiled a new security capability for its Claude LLM.Anthropic announced on Friday that i</description>
    </item>
    <item>
      <title>Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker</title>
      <link>https://cluster-site.onrender.com/posts/defense-contractor-employee-jailed-for-selling-8-zero-days-to-russian-broker/</link>
      <pubDate>Wed, 25 Feb 2026 08:49:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/defense-contractor-employee-jailed-for-selling-8-zero-days-to-russian-broker/</guid>
      <description>• Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker A 39-year-old Australian national who was previously employed at U.S. • defense contractor L3Harris h</description>
    </item>
    <item>
      <title>Ad Tech Company Optimizely Targeted in Cyberattack</title>
      <link>https://cluster-site.onrender.com/posts/ad-tech-company-optimizely-targeted-in-cyberattack/</link>
      <pubDate>Wed, 25 Feb 2026 08:23:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ad-tech-company-optimizely-targeted-in-cyberattack/</guid>
      <description>• Ad tech firm Optimizely has confirmed that threat actors accessed certain internal business systems through a sophisticated voice phishing (vishing) attack.The incident, the comp</description>
    </item>
    <item>
      <title>Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker</title>
      <link>https://cluster-site.onrender.com/posts/ex-l3harris-exec-jailed-for-selling-zero-days-to-russian-exploit-broker/</link>
      <pubDate>Wed, 25 Feb 2026 08:21:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ex-l3harris-exec-jailed-for-selling-zero-days-to-russian-exploit-broker/</guid>
      <description>• Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker February 25, 2026 03:21 AM 0 The former head of Trenchant, a specialized U.S. • defense contractor unit, w</description>
    </item>
    <item>
      <title>Operation Red Card 2.0 Leads to 651 Arrests in Africa</title>
      <link>https://cluster-site.onrender.com/posts/operation-red-card-2.0-leads-to-651-arrests-in-africa/</link>
      <pubDate>Wed, 25 Feb 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/operation-red-card-2.0-leads-to-651-arrests-in-africa/</guid>
      <description>• In the latest operation targeting cybercrime groups, African law enforcement agencies cooperated with Interpol and cybersecurity firms to recover more than USD 4.3 million.</description>
    </item>
    <item>
      <title>Windows 11 KB5077241 update improves BitLocker, adds Sysmon tool</title>
      <link>https://cluster-site.onrender.com/posts/windows-11-kb5077241-update-improves-bitlocker-adds-sysmon-tool/</link>
      <pubDate>Wed, 25 Feb 2026 07:51:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/windows-11-kb5077241-update-improves-bitlocker-adds-sysmon-tool/</guid>
      <description>• Windows 11 KB5077241 update improves BitLocker, adds Sysmon tool February 25, 2026 02:51 AM 0 Microsoft has released the KB5077241 optional cumulative update for Windows 11, whic</description>
    </item>
    <item>
      <title>SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution</title>
      <link>https://cluster-site.onrender.com/posts/solarwinds-patches-4-critical-serv-u-15.5-flaws-allowing-root-code-execution/</link>
      <pubDate>Wed, 25 Feb 2026 07:04:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/solarwinds-patches-4-critical-serv-u-15.5-flaws-allowing-root-code-execution/</guid>
      <description>• SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution SolarWinds hasreleased updatesto address four critical security flaws in its Serv-U file transfer sof</description>
    </item>
    <item>
      <title>Phishing campaign targets freight and logistics orgs in the US, Europe</title>
      <link>https://cluster-site.onrender.com/posts/phishing-campaign-targets-freight-and-logistics-orgs-in-the-us-europe/</link>
      <pubDate>Tue, 24 Feb 2026 23:57:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/phishing-campaign-targets-freight-and-logistics-orgs-in-the-us-europe/</guid>
      <description>• Phishing campaign targets freight and logistics orgs in the US, Europe February 24, 2026 06:57 PM 0 A financially motivated threat group dubbed &amp;lsquo;Diesel Vortex&amp;rsquo; is stealing creden</description>
    </item>
    <item>
      <title>Wynn Resorts confirms employee data breach after extortion threat</title>
      <link>https://cluster-site.onrender.com/posts/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/</link>
      <pubDate>Tue, 24 Feb 2026 21:51:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/</guid>
      <description>• Wynn Resorts confirms employee data breach after extortion threat February 24, 2026 04:51 PM 0 Wynn Resorts has confirmed that a hacker stole employee data from its systems after</description>
    </item>
    <item>
      <title>1Campaign platform helps malicious Google ads evade detection</title>
      <link>https://cluster-site.onrender.com/posts/1campaign-platform-helps-malicious-google-ads-evade-detection/</link>
      <pubDate>Tue, 24 Feb 2026 21:45:05 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/1campaign-platform-helps-malicious-google-ads-evade-detection/</guid>
      <description>• 1Campaign platform helps malicious Google ads evade detection February 24, 2026 04:45 PM 0 A newly identified cybercrime service known as 1Campaign is enabling threat actors to r</description>
    </item>
    <item>
      <title>Attackers Now Need Just 29 Minutes to Own a Network</title>
      <link>https://cluster-site.onrender.com/posts/attackers-now-need-just-29-minutes-to-own-a-network/</link>
      <pubDate>Tue, 24 Feb 2026 21:38:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/attackers-now-need-just-29-minutes-to-own-a-network/</guid>
      <description>• Credential misuse, AI tools, and security blind spots help attackers move through breached networks faster than ever, CrowdStrike finds.</description>
    </item>
    <item>
      <title>Lazarus Group Picks a New Poison: Medusa Ransomware</title>
      <link>https://cluster-site.onrender.com/posts/lazarus-group-picks-a-new-poison-medusa-ransomware/</link>
      <pubDate>Tue, 24 Feb 2026 21:18:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lazarus-group-picks-a-new-poison-medusa-ransomware/</guid>
      <description>• Cyberattacks &amp;amp; Data Breaches Cyber Risk Endpoint Security Threat Intelligence News Lazarus Group Picks a New Poison: Medusa Ransomware The North Korean threat group also leverage</description>
    </item>
    <item>
      <title>RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN</title>
      <link>https://cluster-site.onrender.com/posts/roguepilot-flaw-in-github-codespaces-enabled-copilot-to-leak-github_token/</link>
      <pubDate>Tue, 24 Feb 2026 18:52:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/roguepilot-flaw-in-github-codespaces-enabled-copilot-to-leak-github_token/</guid>
      <description>• RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN A vulnerability inGitHub Codespacescould have been exploited by bad actors to seize control of repositor</description>
    </item>
    <item>
      <title>CarGurus data breach exposes information of 12.4 million accounts</title>
      <link>https://cluster-site.onrender.com/posts/cargurus-data-breach-exposes-information-of-12.4-million-accounts/</link>
      <pubDate>Tue, 24 Feb 2026 18:08:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cargurus-data-breach-exposes-information-of-12.4-million-accounts/</guid>
      <description>• CarGurus data breach exposes information of 12.4 million accounts February 24, 2026 01:08 PM 0 The ShinyHunters extortion group has published personal information in more than 12</description>
    </item>
    <item>
      <title>Open Redirects: A Forgotten Vulnerability&amp;#x3f;, (Tue, Feb 24th)</title>
      <link>https://cluster-site.onrender.com/posts/open-redirects-a-forgotten-vulnerability%23x3f-tue-feb-24th/</link>
      <pubDate>Tue, 24 Feb 2026 18:04:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/open-redirects-a-forgotten-vulnerability%23x3f-tue-feb-24th/</guid>
      <description>• Open Redirects: A Forgotten Vulnerability? • In 2010, OWASP added &amp;lsquo;Unvalidated Redirects and Forwards&amp;rsquo; to its Top 10 list and merged it into &amp;lsquo;Sensitive Data Exposure&amp;rsquo; in 2013 [ow</description>
    </item>
    <item>
      <title>Microsoft adds Copilot data controls to all storage locations</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-adds-copilot-data-controls-to-all-storage-locations/</link>
      <pubDate>Tue, 24 Feb 2026 17:30:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-adds-copilot-data-controls-to-all-storage-locations/</guid>
      <description>• Microsoft adds Copilot data controls to all storage locations February 24, 2026 12:30 PM 0 Microsoft is expanding data loss prevention (DLP) controls to block the Microsoft 365 C</description>
    </item>
    <item>
      <title>Developer-targeting campaign using malicious Next.js repositories</title>
      <link>https://cluster-site.onrender.com/posts/developer-targeting-campaign-using-malicious-next.js-repositories/</link>
      <pubDate>Tue, 24 Feb 2026 17:28:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/developer-targeting-campaign-using-malicious-next.js-repositories/</guid>
      <description>• Microsoft Defender Experts identified a coordinated developer-targeting campaign delivered through malicious repositories disguised as legitimate Next.js projects and technical a</description>
    </item>
    <item>
      <title>&#39;Arkanix Stealer&#39; Malware Disappears Shortly After Debut</title>
      <link>https://cluster-site.onrender.com/posts/arkanix-stealer-malware-disappears-shortly-after-debut/</link>
      <pubDate>Tue, 24 Feb 2026 15:20:06 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/arkanix-stealer-malware-disappears-shortly-after-debut/</guid>
      <description>• A new infostealer named &amp;lsquo;Arkanix Stealer&amp;rsquo; operated as a malware-as-a-service (MaaS) enterprise in a one-shot campaign, Kaspersky says.Implemented in both C++ and Python, the malw</description>
    </item>
    <item>
      <title>Identity-First AI Security: Why CISOs Must Add Intent to the Equation</title>
      <link>https://cluster-site.onrender.com/posts/identity-first-ai-security-why-cisos-must-add-intent-to-the-equation/</link>
      <pubDate>Tue, 24 Feb 2026 15:02:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/identity-first-ai-security-why-cisos-must-add-intent-to-the-equation/</guid>
      <description>• Identity-First AI Security: Why CISOs Must Add Intent to the Equation February 24, 2026 10:02 AM 0 Author: Itamar Apelblat, CEO and Co-Founder, Token Security Not long ago, AI de</description>
    </item>
    <item>
      <title>UK fines Reddit $19 million for using children&#39;s data unlawfully</title>
      <link>https://cluster-site.onrender.com/posts/uk-fines-reddit-19-million-for-using-childrens-data-unlawfully/</link>
      <pubDate>Tue, 24 Feb 2026 14:54:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/uk-fines-reddit-19-million-for-using-childrens-data-unlawfully/</guid>
      <description>• UK fines Reddit $19 million for using children&amp;rsquo;s data unlawfully February 24, 2026 09:54 AM 0 The UK Information Commissioner&amp;rsquo;s Office (ICO) has fined Reddit £14.47 million (over</description>
    </item>
    <item>
      <title>VMware Aria Operations Vulnerability Could Allow Remote Code Execution</title>
      <link>https://cluster-site.onrender.com/posts/vmware-aria-operations-vulnerability-could-allow-remote-code-execution/</link>
      <pubDate>Tue, 24 Feb 2026 14:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vmware-aria-operations-vulnerability-could-allow-remote-code-execution/</guid>
      <description>• Broadcom has released patches for several vulnerabilities affecting VMware Aria Operations, including high-severity flaws.The most important of the newly patched vulnerabilities</description>
    </item>
    <item>
      <title>UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware</title>
      <link>https://cluster-site.onrender.com/posts/uac-0050-targets-european-financial-institution-with-spoofed-domain-and-rms-malware/</link>
      <pubDate>Tue, 24 Feb 2026 14:21:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/uac-0050-targets-european-financial-institution-with-spoofed-domain-and-rms-malware/</guid>
      <description>• UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware A Russia-aligned threat actor has been observed targeting a European financial institution as</description>
    </item>
    <item>
      <title>Bring the Fight to the Edge: Turning Time Into an Advantage in OT Security</title>
      <link>https://cluster-site.onrender.com/posts/bring-the-fight-to-the-edge-turning-time-into-an-advantage-in-ot-security/</link>
      <pubDate>Tue, 24 Feb 2026 14:00:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/bring-the-fight-to-the-edge-turning-time-into-an-advantage-in-ot-security/</guid>
      <description>• Why OT Defenses Often Start Too Late Industrial organizations are facing a growing paradox in cybersecurity. • While operational technology (OT) environments are increasingly con</description>
    </item>
    <item>
      <title>CISO Conversations: Timothy Youngblood; 4x Fortune 500 CISO/CSO</title>
      <link>https://cluster-site.onrender.com/posts/ciso-conversations-timothy-youngblood-4x-fortune-500-ciso/cso/</link>
      <pubDate>Tue, 24 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ciso-conversations-timothy-youngblood-4x-fortune-500-ciso/cso/</guid>
      <description>• Timothy Youngblood didn&amp;rsquo;t set out to be a CISO, but he became CISO at four major enterprises, took on angel investing and won the Most Valued Member award at the Summer Investor</description>
    </item>
    <item>
      <title>Australia Releases Azul Open-Source Malware Analysis Platform</title>
      <link>https://cluster-site.onrender.com/posts/australia-releases-azul-open-source-malware-analysis-platform/</link>
      <pubDate>Tue, 24 Feb 2026 13:41:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/australia-releases-azul-open-source-malware-analysis-platform/</guid>
      <description>• The Australian Signals Directorate launched Azul, a free malware analysis tool. • Azul is designed for reverse engineers and incident responders. • The platform runs on Kubernete</description>
    </item>
    <item>
      <title>New &#39;Sandworm_Mode&#39; Supply Chain Attack Hits NPM</title>
      <link>https://cluster-site.onrender.com/posts/new-sandworm_mode-supply-chain-attack-hits-npm/</link>
      <pubDate>Tue, 24 Feb 2026 13:40:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-sandworm_mode-supply-chain-attack-hits-npm/</guid>
      <description>• Security researchers have uncovered a new supply chain attack targeting the NPM registry with malicious code that exhibits worm-like propagation capabilities.DubbedSandworm_Mode,</description>
    </item>
    <item>
      <title>As Cybersecurity Firms Chase AI, VC Market Skyrockets</title>
      <link>https://cluster-site.onrender.com/posts/as-cybersecurity-firms-chase-ai-vc-market-skyrockets/</link>
      <pubDate>Tue, 24 Feb 2026 13:04:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/as-cybersecurity-firms-chase-ai-vc-market-skyrockets/</guid>
      <description>• Investments in cybersecurity startups took off in 2025, as venture capital firms focused not just on AI-native tech, but talent as well.</description>
    </item>
    <item>
      <title>From Factory Floor to Cisco Cybersecurity, a Career Transformation Story</title>
      <link>https://cluster-site.onrender.com/posts/from-factory-floor-to-cisco-cybersecurity-a-career-transformation-story/</link>
      <pubDate>Tue, 24 Feb 2026 13:00:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/from-factory-floor-to-cisco-cybersecurity-a-career-transformation-story/</guid>
      <description>• Cisco career story transitions from factory floor to cybersecurity leadership. • Host shares personal journey and challenges faced during career shift. • Story highlights importa</description>
    </item>
    <item>
      <title>Full-Session Encryption Essential for TACACS&#43; Deployments</title>
      <link>https://cluster-site.onrender.com/posts/full-session-encryption-essential-for-tacacs-deployments/</link>
      <pubDate>Tue, 24 Feb 2026 13:00:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/full-session-encryption-essential-for-tacacs-deployments/</guid>
      <description>• Full‑session encryption critical for modern TACACS+ security. • Attackers use stolen credentials and protocol weaknesses to breach infrastructure. • Cisco Talos reports highlight</description>
    </item>
    <item>
      <title>Scaling security operations with Microsoft Defender autonomous defense and expert-led services</title>
      <link>https://cluster-site.onrender.com/posts/scaling-security-operations-with-microsoft-defender-autonomous-defense-and-expert-led-services/</link>
      <pubDate>Tue, 24 Feb 2026 13:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scaling-security-operations-with-microsoft-defender-autonomous-defense-and-expert-led-services/</guid>
      <description>• Share Link copied to clipboard! • Content types Best practices Products and services Microsoft Defender Microsoft Security Experts Topics AI and agents Security management Securi</description>
    </item>
    <item>
      <title>Choosing IT Hiring Service Requires Deep Background Checks</title>
      <link>https://cluster-site.onrender.com/posts/choosing-it-hiring-service-requires-deep-background-checks/</link>
      <pubDate>Tue, 24 Feb 2026 12:54:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/choosing-it-hiring-service-requires-deep-background-checks/</guid>
      <description>• IT hiring services require deeper background checks for privileged access. • AI era demands more thorough verification of IT professionals. • Podcast discusses criteria for selec</description>
    </item>
    <item>
      <title>GitHub Issues Abused in Copilot Attack Leading to Repository Takeover</title>
      <link>https://cluster-site.onrender.com/posts/github-issues-abused-in-copilot-attack-leading-to-repository-takeover/</link>
      <pubDate>Tue, 24 Feb 2026 12:26:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/github-issues-abused-in-copilot-attack-leading-to-repository-takeover/</guid>
      <description>• A vulnerability in GitHub Codespaces could have allowed attackers to take over repositories by injecting malicious Copilot instructions in a GitHub issue.The attack, Orca Securit</description>
    </item>
    <item>
      <title>Is AI Good for Democracy?</title>
      <link>https://cluster-site.onrender.com/posts/is-ai-good-for-democracy/</link>
      <pubDate>Tue, 24 Feb 2026 12:06:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/is-ai-good-for-democracy/</guid>
      <description>• Is AI Good for Democracy? • Politicians fixate on the global race for technological supremacy between US and China. • They debate geopolitical implications of chip exports, lates</description>
    </item>
    <item>
      <title>Taiwan Security Firm Confirms Flaw Flagged by CISA Likely Exploited by Chinese APTs</title>
      <link>https://cluster-site.onrender.com/posts/taiwan-security-firm-confirms-flaw-flagged-by-cisa-likely-exploited-by-chinese-apts/</link>
      <pubDate>Tue, 24 Feb 2026 12:00:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/taiwan-security-firm-confirms-flaw-flagged-by-cisa-likely-exploited-by-chinese-apts/</guid>
      <description>• The Taiwan-based cybersecurity firm TeamT5 has confirmed that the vulnerability added recently by CISA to its Known Exploited Vulnerabilities (KEV) catalog was likely exploited b</description>
    </item>
    <item>
      <title>Identity Prioritization isn&#39;t a Backlog Problem - It&#39;s a Risk Math Problem</title>
      <link>https://cluster-site.onrender.com/posts/identity-prioritization-isnt-a-backlog-problem-its-a-risk-math-problem/</link>
      <pubDate>Tue, 24 Feb 2026 11:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/identity-prioritization-isnt-a-backlog-problem-its-a-risk-math-problem/</guid>
      <description>• Most identity programs still prioritize work the way they prioritize IT tickets: by volume, loudness, or &amp;lsquo;what failed a control check.&amp;rsquo; That approach breaks the moment your envir</description>
    </item>
    <item>
      <title>Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks</title>
      <link>https://cluster-site.onrender.com/posts/lazarus-group-uses-medusa-ransomware-in-middle-east-and-u.s.-healthcare-attacks/</link>
      <pubDate>Tue, 24 Feb 2026 11:52:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lazarus-group-uses-medusa-ransomware-in-middle-east-and-u.s.-healthcare-attacks/</guid>
      <description>• Lazarus Group Uses Medusa Ransomware in Middle East and U.S. • Healthcare Attacks The North Korea-linkedLazarus Group(aka Diamond Sleet and Pompilus) has been observed using Medu</description>
    </item>
    <item>
      <title>ShinyHunters extortion gang claims Odido breach affecting millions</title>
      <link>https://cluster-site.onrender.com/posts/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/</link>
      <pubDate>Tue, 24 Feb 2026 11:40:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/</guid>
      <description>• ShinyHunters extortion gang claims Odido breach affecting millions February 24, 2026 06:40 AM 0 The ShinyHunters extortion gang has claimed responsibility for breaching Dutch tel</description>
    </item>
    <item>
      <title>Telegram CEO faces Russia probe over allegations of terrorism facilitation</title>
      <link>https://cluster-site.onrender.com/posts/telegram-ceo-faces-russia-probe-over-allegations-of-terrorism-facilitation/</link>
      <pubDate>Tue, 24 Feb 2026 11:36:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/telegram-ceo-faces-russia-probe-over-allegations-of-terrorism-facilitation/</guid>
      <description>• Russian authorities investigate Telegram co‑founder Pavel Durov for terrorism facilitation. • Allegations stem from 155,000 channels flagged for illegal content. • Investigation</description>
    </item>
    <item>
      <title>North Korean Lazarus group linked to Medusa ransomware attacks</title>
      <link>https://cluster-site.onrender.com/posts/north-korean-lazarus-group-linked-to-medusa-ransomware-attacks/</link>
      <pubDate>Tue, 24 Feb 2026 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/north-korean-lazarus-group-linked-to-medusa-ransomware-attacks/</guid>
      <description>• North Korean Lazarus group linked to Medusa ransomware attacks February 24, 2026 06:00 AM 0 North Korean state-backed hackers associated with the Lazarus threat group are targeti</description>
    </item>
    <item>
      <title>Anonymous Fénix Members Arrested in Spain</title>
      <link>https://cluster-site.onrender.com/posts/anonymous-f%C3%A9nix-members-arrested-in-spain/</link>
      <pubDate>Tue, 24 Feb 2026 10:05:57 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anonymous-f%C3%A9nix-members-arrested-in-spain/</guid>
      <description>• Spanish authorities this week announced the arrest of four members of the Anonymous Fénix group for their involvement in distributed denial-of-service (DDoS) attacks.The suspects</description>
    </item>
    <item>
      <title>UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors</title>
      <link>https://cluster-site.onrender.com/posts/unsolicitedbooker-targets-central-asian-telecoms-with-lucidoor-and-marssnake-backdoors/</link>
      <pubDate>Tue, 24 Feb 2026 09:54:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/unsolicitedbooker-targets-central-asian-telecoms-with-lucidoor-and-marssnake-backdoors/</guid>
      <description>• UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors The threat activity cluster known asUnsolicitedBookerhas been observed targeting telecommun</description>
    </item>
    <item>
      <title>CrowdStrike 2026 Global Threat Report AI Evasive Adversary</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-2026-global-threat-report-ai-evasive-adversary/</link>
      <pubDate>Tue, 24 Feb 2026 08:32:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-2026-global-threat-report-ai-evasive-adversary/</guid>
      <description>• 2026 Global Threat Report highlights AI‑driven adversaries employing evasive tactics across industries. • Report identifies 59 zero‑day CVEs patched in February, underscoring rap</description>
    </item>
    <item>
      <title>Anthropic&#39;s Claude Code Security Shakes Cybersecurity Stocks</title>
      <link>https://cluster-site.onrender.com/posts/anthropics-claude-code-security-shakes-cybersecurity-stocks/</link>
      <pubDate>Tue, 24 Feb 2026 06:21:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anthropics-claude-code-security-shakes-cybersecurity-stocks/</guid>
      <description>• Anthropic launches Claude Code Security, an AI code vulnerability scanner. • Tool scans entire codebase, flags vulnerabilities, suggests patches. • Market reaction: cybersecurity</description>
    </item>
    <item>
      <title>Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model</title>
      <link>https://cluster-site.onrender.com/posts/anthropic-says-chinese-ai-firms-used-16-million-claude-queries-to-copy-model/</link>
      <pubDate>Tue, 24 Feb 2026 06:04:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anthropic-says-chinese-ai-firms-used-16-million-claude-queries-to-copy-model/</guid>
      <description>• Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model Anthropic on Monday said it identified &amp;lsquo;industrial-scale campaigns&amp;rsquo; mounted by three artificial intel</description>
    </item>
    <item>
      <title>ISC Stormcast For Tuesday, February 24th, 2026 https://isc.sans.edu/podcastdetail/9822, (Tue, Feb 24th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-tuesday-february-24th-2026-https/isc.sans.edu/podcastdetail/9822-tue-feb-24th/</link>
      <pubDate>Tue, 24 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-tuesday-february-24th-2026-https/isc.sans.edu/podcastdetail/9822-tue-feb-24th/</guid>
      <description>• ISC Stormcast For Tuesday, February 24th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9822&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9822&lt;/a&gt;
 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security:</description>
    </item>
    <item>
      <title>The risks of cybersecurity tool sprawl: Why consolidation is a strategic priority</title>
      <link>https://cluster-site.onrender.com/posts/the-risks-of-cybersecurity-tool-sprawl-why-consolidation-is-a-strategic-priority/</link>
      <pubDate>Tue, 24 Feb 2026 00:31:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-risks-of-cybersecurity-tool-sprawl-why-consolidation-is-a-strategic-priority/</guid>
      <description>• The risks of cybersecurity tool sprawl: Why consolidation is a strategic priority Jackson Connell, Mitch Pronschinske Optimize operations Risk &amp;amp; compliance Culture &amp;amp; collaboratio</description>
    </item>
    <item>
      <title>GyroidOS virtualization solution aims to secure embedded devices, ease cybersecurity certification</title>
      <link>https://cluster-site.onrender.com/posts/gyroidos-virtualization-solution-aims-to-secure-embedded-devices-ease-cybersecurity-certification/</link>
      <pubDate>Tue, 24 Feb 2026 00:00:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/gyroidos-virtualization-solution-aims-to-secure-embedded-devices-ease-cybersecurity-certification/</guid>
      <description>• Maintained by Fraunhofer AISEC, GyroidOS is an open-source, multi-arch OS-level virtualization solution designed for embedded devices with hardware security features, and aiming</description>
    </item>
    <item>
      <title>Android mental health apps with 14.7M installs filled with security flaws</title>
      <link>https://cluster-site.onrender.com/posts/android-mental-health-apps-with-14.7m-installs-filled-with-security-flaws/</link>
      <pubDate>Mon, 23 Feb 2026 22:59:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/android-mental-health-apps-with-14.7m-installs-filled-with-security-flaws/</guid>
      <description>• Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users&amp;rsquo; sensitive medical information. • In one of t</description>
    </item>
    <item>
      <title>Spitting Cash: ATM Jackpotting Attacks Surged in 2025</title>
      <link>https://cluster-site.onrender.com/posts/spitting-cash-atm-jackpotting-attacks-surged-in-2025/</link>
      <pubDate>Mon, 23 Feb 2026 22:20:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spitting-cash-atm-jackpotting-attacks-surged-in-2025/</guid>
      <description>• The attacks cost banks more than $20 million in losses last year, as criminals used many of the same tools and tactics they have wielded for more than a decade. • The attacks cos</description>
    </item>
    <item>
      <title>More Than Dashboards: AI Decisions Must Be Provable</title>
      <link>https://cluster-site.onrender.com/posts/more-than-dashboards-ai-decisions-must-be-provable/</link>
      <pubDate>Mon, 23 Feb 2026 22:18:18 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/more-than-dashboards-ai-decisions-must-be-provable/</guid>
      <description>• AI systems have to be able to show a record of what happened and how.</description>
    </item>
    <item>
      <title>Spain arrests suspected hacktivists for DDoSing govt sites</title>
      <link>https://cluster-site.onrender.com/posts/spain-arrests-suspected-hacktivists-for-ddosing-govt-sites/</link>
      <pubDate>Mon, 23 Feb 2026 21:59:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spain-arrests-suspected-hacktivists-for-ddosing-govt-sites/</guid>
      <description>• Spain arrests suspected hacktivists for DDoSing govt sites February 23, 2026 04:59 PM 0 Spanish authorities have arrested four alleged members of a hacktivist group believed to h</description>
    </item>
    <item>
      <title>Iran&#39;s MuddyWater Targets Orgs With Fresh Malware as Tensions Mount</title>
      <link>https://cluster-site.onrender.com/posts/irans-muddywater-targets-orgs-with-fresh-malware-as-tensions-mount/</link>
      <pubDate>Mon, 23 Feb 2026 20:35:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/irans-muddywater-targets-orgs-with-fresh-malware-as-tensions-mount/</guid>
      <description>• Threat Intelligence Cyberattacks &amp;amp; Data Breaches Endpoint Security Remote Workforce News Breaking cybersecurity news, news analysis, commentary, and other content from around the</description>
    </item>
    <item>
      <title>Enigma Cipher Device Still Holds Secrets for Cyber Pros</title>
      <link>https://cluster-site.onrender.com/posts/enigma-cipher-device-still-holds-secrets-for-cyber-pros/</link>
      <pubDate>Mon, 23 Feb 2026 20:11:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/enigma-cipher-device-still-holds-secrets-for-cyber-pros/</guid>
      <description>• The Nazi relic&amp;rsquo;s history is riddled with resilience errors, and those lessons still apply to defending against modern cyber threats. • The Nazi relic&amp;rsquo;s history is riddled with re</description>
    </item>
    <item>
      <title>APT28 Targeted European Entities Using Webhook-Based Macro Malware</title>
      <link>https://cluster-site.onrender.com/posts/apt28-targeted-european-entities-using-webhook-based-macro-malware/</link>
      <pubDate>Mon, 23 Feb 2026 19:41:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/apt28-targeted-european-entities-using-webhook-based-macro-malware/</guid>
      <description>• APT28 Targeted European Entities Using Webhook-Based Macro Malware The Russia-linkedstate-sponsored threat actortracked asAPT28has been attributed to a new campaign targeting spe</description>
    </item>
    <item>
      <title>Microsoft says bug in classic Outlook hides the mouse pointer</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-says-bug-in-classic-outlook-hides-the-mouse-pointer/</link>
      <pubDate>Mon, 23 Feb 2026 19:40:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-says-bug-in-classic-outlook-hides-the-mouse-pointer/</guid>
      <description>• Microsoft says bug in classic Outlook hides the mouse pointer February 23, 2026 02:40 PM 1 Microsoft is investigating a known issue that causes the mouse pointer to disappear in</description>
    </item>
    <item>
      <title>600&#43; FortiGate Devices Hacked by AI-Armed Amateur</title>
      <link>https://cluster-site.onrender.com/posts/600-fortigate-devices-hacked-by-ai-armed-amateur/</link>
      <pubDate>Mon, 23 Feb 2026 19:37:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/600-fortigate-devices-hacked-by-ai-armed-amateur/</guid>
      <description>• A Russian-speaking hacker used generative AI to compromise the FortiGate firewalls, targeting credentials and backups for possible follow-on ransomware attacks. • A Russian-speak</description>
    </item>
    <item>
      <title>Claude Code Security Causes A SaaS-pocalypse In Cybersecurity</title>
      <link>https://cluster-site.onrender.com/posts/claude-code-security-causes-a-saas-pocalypse-in-cybersecurity/</link>
      <pubDate>Mon, 23 Feb 2026 18:49:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/claude-code-security-causes-a-saas-pocalypse-in-cybersecurity/</guid>
      <description>• Claude Code Security Causes A SaaS-pocalypse In Cybersecurity We have seen this pattern before, even if the specifics look different. • Think back to the day AWS introduced Guard</description>
    </item>
    <item>
      <title>Ad tech firm Optimizely confirms data breach after vishing attack</title>
      <link>https://cluster-site.onrender.com/posts/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/</link>
      <pubDate>Mon, 23 Feb 2026 18:04:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/</guid>
      <description>• Ad tech firm Optimizely confirms data breach after vishing attack February 23, 2026 01:04 PM 0 New York-based ad tech company Optimizely has notified an undisclosed number of cus</description>
    </item>
    <item>
      <title>Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb</title>
      <link>https://cluster-site.onrender.com/posts/wormable-xmrig-campaign-uses-byovd-exploit-and-time-based-logic-bomb/</link>
      <pubDate>Mon, 23 Feb 2026 17:59:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wormable-xmrig-campaign-uses-byovd-exploit-and-time-based-logic-bomb/</guid>
      <description>• Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures to deploy a bespoke XMRig miner program on compromise</description>
    </item>
    <item>
      <title>The Art of Deception: How Threat Actors Master Typosquatting Campaigns to Bypass Detection</title>
      <link>https://cluster-site.onrender.com/posts/the-art-of-deception-how-threat-actors-master-typosquatting-campaigns-to-bypass-detection/</link>
      <pubDate>Mon, 23 Feb 2026 16:30:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-art-of-deception-how-threat-actors-master-typosquatting-campaigns-to-bypass-detection/</guid>
      <description>• FeaturedThe Art of Deception: How Threat Actors Master Typosquatting Campaigns to Bypass DetectionFeb 23, 2026Introducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interact</description>
    </item>
    <item>
      <title>US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach</title>
      <link>https://cluster-site.onrender.com/posts/us-healthcare-diagnostic-firm-says-140000-affected-by-data-breach/</link>
      <pubDate>Mon, 23 Feb 2026 15:35:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/us-healthcare-diagnostic-firm-says-140000-affected-by-data-breach/</guid>
      <description>• Nearly 140,000 people are affected by a data breach disclosed by healthcare diagnostic company Vikor Scientific.The number of affected individuals came to light in recent days on</description>
    </item>
    <item>
      <title>When identity isn&#39;t the weak link, access still is</title>
      <link>https://cluster-site.onrender.com/posts/when-identity-isnt-the-weak-link-access-still-is/</link>
      <pubDate>Mon, 23 Feb 2026 15:00:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/when-identity-isnt-the-weak-link-access-still-is/</guid>
      <description>• For years, identity has been treated as the foundation of workforce security. • If an organization could reliably confirm who a user was, the assumption followed that access coul</description>
    </item>
    <item>
      <title>Another day, another malicious JPEG, (Mon, Feb 23rd)</title>
      <link>https://cluster-site.onrender.com/posts/another-day-another-malicious-jpeg-mon-feb-23rd/</link>
      <pubDate>Mon, 23 Feb 2026 14:26:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/another-day-another-malicious-jpeg-mon-feb-23rd/</guid>
      <description>• Another day, another malicious JPEG In his last two diaries, Xavier discussed recent malware campaigns that download JPEG files with embedded malicious payload[1,2]. • At that po</description>
    </item>
    <item>
      <title>Ukrainian Gets 5 Years in US Prison for Aiding North Korean IT Fraud</title>
      <link>https://cluster-site.onrender.com/posts/ukrainian-gets-5-years-in-us-prison-for-aiding-north-korean-it-fraud/</link>
      <pubDate>Mon, 23 Feb 2026 13:38:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ukrainian-gets-5-years-in-us-prison-for-aiding-north-korean-it-fraud/</guid>
      <description>• A Ukrainian national was sentenced to five years in a US prison for selling stolen identities to fraudulent North Korean workers and for facilitating the operation of laptop farm</description>
    </item>
    <item>
      <title>⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware &amp; More</title>
      <link>https://cluster-site.onrender.com/posts/weekly-recap-double-tap-skimmers-promptspy-ai-30tbps-ddos-docker-malware-more/</link>
      <pubDate>Mon, 23 Feb 2026 13:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/weekly-recap-double-tap-skimmers-promptspy-ai-30tbps-ddos-docker-malware-more/</guid>
      <description>• Security news rarely moves in a straight line. • This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public vie</description>
    </item>
    <item>
      <title>Autonomous AI Agents Provide New Class of Supply Chain Attack</title>
      <link>https://cluster-site.onrender.com/posts/autonomous-ai-agents-provide-new-class-of-supply-chain-attack/</link>
      <pubDate>Mon, 23 Feb 2026 12:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/autonomous-ai-agents-provide-new-class-of-supply-chain-attack/</guid>
      <description>• Found in Clawhub, promoted on Moltbook, Bob-ptp is an ongoing active agent-based crypto scam.It&amp;rsquo;s ironic that new technology often defies the fundamental security rule of zero tr</description>
    </item>
    <item>
      <title>On the Security of Password Managers</title>
      <link>https://cluster-site.onrender.com/posts/on-the-security-of-password-managers/</link>
      <pubDate>Mon, 23 Feb 2026 12:03:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/on-the-security-of-password-managers/</guid>
      <description>• On the Security of Password Managers Good article on password managers that secretly have a backdoor. • New research shows that these claims aren&amp;rsquo;t true in all cases, particularl</description>
    </item>
    <item>
      <title>How Exposed Endpoints Increase Risk Across LLM Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/how-exposed-endpoints-increase-risk-across-llm-infrastructure/</link>
      <pubDate>Mon, 23 Feb 2026 11:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-exposed-endpoints-increase-risk-across-llm-infrastructure/</guid>
      <description>• How Exposed Endpoints Increase Risk Across LLM Infrastructure As more organizations run their own Large Language Models (LLMs), they are also deploying more internal services and</description>
    </item>
    <item>
      <title>Romanian Hacker Pleads Guilty to Selling Access to US State Network</title>
      <link>https://cluster-site.onrender.com/posts/romanian-hacker-pleads-guilty-to-selling-access-to-us-state-network/</link>
      <pubDate>Mon, 23 Feb 2026 11:53:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/romanian-hacker-pleads-guilty-to-selling-access-to-us-state-network/</guid>
      <description>• A Romanian national pleaded guilty in a US court to selling unauthorized access to an Oregon state government office&amp;rsquo;s network.The man, Catalin Dragomir, 45, of Constanta, Romani</description>
    </item>
    <item>
      <title>Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS</title>
      <link>https://cluster-site.onrender.com/posts/hundreds-of-fortigate-firewalls-hacked-in-ai-powered-attacks-aws/</link>
      <pubDate>Mon, 23 Feb 2026 11:34:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hundreds-of-fortigate-firewalls-hacked-in-ai-powered-attacks-aws/</guid>
      <description>• Over 600 Fortinet FortiGate firewall instances have been hacked in an AI-powered campaign that exploits exposed ports and weak credentials, AWS reports.The attacks, observed betw</description>
    </item>
    <item>
      <title>AI for Cybersecurity: Promise, Practice, and Pitfalls</title>
      <link>https://cluster-site.onrender.com/posts/ai-for-cybersecurity-promise-practice-and-pitfalls/</link>
      <pubDate>Mon, 23 Feb 2026 11:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-for-cybersecurity-promise-practice-and-pitfalls/</guid>
      <description>• AI for Cybersecurity: Promise, Practice, and Pitfalls Free Virtual EventNovember 19, 2025 | 11:00 AM EDT About The Event AI is revolutionizing the cybersecurity landscape. • From</description>
    </item>
    <item>
      <title>Mississippi Hospital System Closes All Clinics After Ransomware Attack</title>
      <link>https://cluster-site.onrender.com/posts/mississippi-hospital-system-closes-all-clinics-after-ransomware-attack/</link>
      <pubDate>Mon, 23 Feb 2026 10:29:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/mississippi-hospital-system-closes-all-clinics-after-ransomware-attack/</guid>
      <description>• A ransomware attack forced the University of Mississippi Medical Center to close all of its roughly three dozen clinics around the state and cancel elective procedures for a seco</description>
    </item>
    <item>
      <title>CrowdStrike Named a Customers&amp;rsquo; Choice in 2026 Gartner Peer Insights&amp;trade; Voice of the Customer for Application Security Posture Management Tools</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-a-customersrsquo-choice-in-2026-gartner-peer-insightstrade-voice-of-the-customer-for-application-security-posture-management-tools/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-a-customersrsquo-choice-in-2026-gartner-peer-insightstrade-voice-of-the-customer-for-application-security-posture-management-tools/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>What Security Teams Need to Know About OpenClaw, the AI Super Agent</title>
      <link>https://cluster-site.onrender.com/posts/what-security-teams-need-to-know-about-openclaw-the-ai-super-agent/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-security-teams-need-to-know-about-openclaw-the-ai-super-agent/</guid>
      <description>• OpenClaw is CrowdStrike&amp;rsquo;s AI super agent for automated threat hunting. • It orchestrates data from multiple sensors to identify suspicious activity. • AI models continuously lear</description>
    </item>
    <item>
      <title>Advanced Web Shell Detection and Prevention: A Deep Dive into CrowdStrike&#39;s Linux Sensor Capabilities</title>
      <link>https://cluster-site.onrender.com/posts/advanced-web-shell-detection-and-prevention-a-deep-dive-into-crowdstrikes-linux-sensor-capabilities/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/advanced-web-shell-detection-and-prevention-a-deep-dive-into-crowdstrikes-linux-sensor-capabilities/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>CrowdStrike Named Customers&#39; Choice Attack Surface Management</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-attack-surface-management/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-attack-surface-management/</guid>
      <description>• Gartner named CrowdStrike the sole Customers&amp;rsquo; Choice for External Attack Surface Management. • Falcon X provides continuous visibility into cloud, on‑prem, and SaaS attack surfac</description>
    </item>
    <item>
      <title>Human‑AI Feedback Loop Powering CrowdStrike Agentic Security</title>
      <link>https://cluster-site.onrender.com/posts/humanai-feedback-loop-powering-crowdstrike-agentic-security/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/humanai-feedback-loop-powering-crowdstrike-agentic-security/</guid>
      <description>• Human‑AI feedback loop enhances threat detection by combining analyst intuition with machine learning insights. • CrowdStrike&amp;rsquo;s Agentic Security framework empowers analysts to gu</description>
    </item>
    <item>
      <title>Scale SOC Automation Falcon Fusion SOAR</title>
      <link>https://cluster-site.onrender.com/posts/scale-soc-automation-falcon-fusion-soar/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scale-soc-automation-falcon-fusion-soar/</guid>
      <description>• Falcon Fusion SOAR automates SOC workflows across security tools. • Low‑code platform accelerates incident response times. • AI‑powered playbooks prioritize high‑impact alerts. •</description>
    </item>
    <item>
      <title>CrowdStrike Named Customers&#39; Choice 2026 Gartner Peer Insights Voice User Authentication</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-2026-gartner-peer-insights-voice-user-authentication/</link>
      <pubDate>Mon, 23 Feb 2026 10:24:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-2026-gartner-peer-insights-voice-user-authentication/</guid>
      <description>• CrowdStrike awarded Customers&amp;rsquo; Choice for user authentication in 2026. • Recognition reflects high customer satisfaction and product reliability. • Falcon platform offers multi‑f</description>
    </item>
    <item>
      <title>Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens</title>
      <link>https://cluster-site.onrender.com/posts/malicious-npm-packages-harvest-crypto-keys-ci-secrets-and-api-tokens/</link>
      <pubDate>Mon, 23 Feb 2026 10:20:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-npm-packages-harvest-crypto-keys-ci-secrets-and-api-tokens/</guid>
      <description>• Cybersecurity researchers have disclosed what they say is an active &amp;lsquo;Shai-Hulud-like&amp;rsquo; supply chain worm campaign that has leveraged a cluster of at least 19 malicious npm package</description>
    </item>
    <item>
      <title>PayPal Data Breach Led to Fraudulent Transactions</title>
      <link>https://cluster-site.onrender.com/posts/paypal-data-breach-led-to-fraudulent-transactions/</link>
      <pubDate>Mon, 23 Feb 2026 09:13:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/paypal-data-breach-led-to-fraudulent-transactions/</guid>
      <description>• PayPal disclosed a data breach affecting personal info of ~100 customers. • Breach caused by coding error in PayPal Working Capital loan application. • Exposed data included name</description>
    </item>
    <item>
      <title>MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP</title>
      <link>https://cluster-site.onrender.com/posts/muddywater-targets-mena-organizations-with-ghostfetch-char-and-http_vip/</link>
      <pubDate>Mon, 23 Feb 2026 07:25:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/muddywater-targets-mena-organizations-with-ghostfetch-char-and-http_vip/</guid>
      <description>• MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP The Iranian hacking group known asMuddyWater(aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targ</description>
    </item>
    <item>
      <title>ISC Stormcast For Monday, February 23rd, 2026 https://isc.sans.edu/podcastdetail/9820, (Mon, Feb 23rd)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-monday-february-23rd-2026-https/isc.sans.edu/podcastdetail/9820-mon-feb-23rd/</link>
      <pubDate>Mon, 23 Feb 2026 02:45:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-monday-february-23rd-2026-https/isc.sans.edu/podcastdetail/9820-mon-feb-23rd/</guid>
      <description>• ISC Stormcast For Monday, February 23rd, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9820&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9820&lt;/a&gt;
 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security: S</description>
    </item>
    <item>
      <title>Arkanix Stealer pops up as short-lived AI info-stealer experiment</title>
      <link>https://cluster-site.onrender.com/posts/arkanix-stealer-pops-up-as-short-lived-ai-info-stealer-experiment/</link>
      <pubDate>Sun, 22 Feb 2026 15:33:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/arkanix-stealer-pops-up-as-short-lived-ai-info-stealer-experiment/</guid>
      <description>• Arkanix Stealer pops up as short-lived AI info-stealer experiment February 22, 2026 10:33 AM 0 An information-stealing malware operation named Arkanix Stealer, promoted on multip</description>
    </item>
    <item>
      <title>Predator spyware hooks iOS SpringBoard to hide mic, camera activity</title>
      <link>https://cluster-site.onrender.com/posts/predator-spyware-hooks-ios-springboard-to-hide-mic-camera-activity/</link>
      <pubDate>Sat, 21 Feb 2026 16:13:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/predator-spyware-hooks-ios-springboard-to-hide-mic-camera-activity/</guid>
      <description>• Intellexa&amp;rsquo;s Predator spyware can hide iOS recording indicators while secretly streaming camera and microphone feeds to its operators. • The malware does not exploit any iOS vulne</description>
    </item>
    <item>
      <title>AI-Assisted Threat Actor Compromises 600&#43; FortiGate Devices in 55 Countries</title>
      <link>https://cluster-site.onrender.com/posts/ai-assisted-threat-actor-compromises-600-fortigate-devices-in-55-countries/</link>
      <pubDate>Sat, 21 Feb 2026 14:49:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-assisted-threat-actor-compromises-600-fortigate-devices-in-55-countries/</guid>
      <description>• AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries A Russian-speaking, financially motivated threat actor has been observed taking advantage of commercia</description>
    </item>
    <item>
      <title>Amazon: AI-assisted hacker breached 600 FortiGate firewalls in 5 weeks</title>
      <link>https://cluster-site.onrender.com/posts/amazon-ai-assisted-hacker-breached-600-fortigate-firewalls-in-5-weeks/</link>
      <pubDate>Sat, 21 Feb 2026 13:50:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/amazon-ai-assisted-hacker-breached-600-fortigate-firewalls-in-5-weeks/</guid>
      <description>• Amazon: AI-assisted hacker breached 600 FortiGate firewalls in 5 weeks February 21, 2026 08:50 AM 0 Amazon is warning that a Russian-speaking hacker used multiple generative AI s</description>
    </item>
    <item>
      <title>Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks</title>
      <link>https://cluster-site.onrender.com/posts/amazon-ai-assisted-hacker-breached-600-fortinet-firewalls-in-5-weeks/</link>
      <pubDate>Sat, 21 Feb 2026 13:50:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/amazon-ai-assisted-hacker-breached-600-fortinet-firewalls-in-5-weeks/</guid>
      <description>• Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks February 21, 2026 08:50 AM 0 Article updated at the bottom with additional technical details about this camp</description>
    </item>
    <item>
      <title>Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning</title>
      <link>https://cluster-site.onrender.com/posts/anthropic-launches-claude-code-security-for-ai-powered-vulnerability-scanning/</link>
      <pubDate>Sat, 21 Feb 2026 07:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anthropic-launches-claude-code-security-for-ai-powered-vulnerability-scanning/</guid>
      <description>• Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Clau</description>
    </item>
    <item>
      <title>CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog</title>
      <link>https://cluster-site.onrender.com/posts/cisa-adds-two-actively-exploited-roundcube-flaws-to-kev-catalog/</link>
      <pubDate>Sat, 21 Feb 2026 07:21:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-adds-two-actively-exploited-roundcube-flaws-to-kev-catalog/</guid>
      <description>• CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog The U.S. • Cybersecurity and Infrastructure Security Agency (CISA) on Fridayaddedtwo security flaws impacting Roun</description>
    </item>
    <item>
      <title>Japanese-Language Phishing Emails, (Sat, Feb 21st)</title>
      <link>https://cluster-site.onrender.com/posts/japanese-language-phishing-emails-sat-feb-21st/</link>
      <pubDate>Sat, 21 Feb 2026 06:03:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/japanese-language-phishing-emails-sat-feb-21st/</guid>
      <description>• Japanese-Language Phishing Emails Introduction For at least the past year or so, I&amp;rsquo;ve been receiving Japanese-language phishing emails to my blog email addresses at @malware-traf</description>
    </item>
    <item>
      <title>EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security</title>
      <link>https://cluster-site.onrender.com/posts/ec-council-expands-ai-certification-portfolio-to-strengthen-u.s.-ai-workforce-readiness-and-security/</link>
      <pubDate>Sat, 21 Feb 2026 04:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ec-council-expands-ai-certification-portfolio-to-strengthen-u.s.-ai-workforce-readiness-and-security/</guid>
      <description>• EC-Council Expands AI Certification Portfolio to Strengthen U.S. • AI Workforce Readiness and Security With $5.5 trillion in global AI risk exposure and 700,000 U.S. • workers ne</description>
    </item>
    <item>
      <title>Friday Squid Blogging: Squid Cartoon</title>
      <link>https://cluster-site.onrender.com/posts/friday-squid-blogging-squid-cartoon/</link>
      <pubDate>Fri, 20 Feb 2026 22:05:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/friday-squid-blogging-squid-cartoon/</guid>
      <description>• Friday Squid Blogging: Squid Cartoon I like this one. • As usual, you can also use this squid post to talk about the security stories in the news that I haven&amp;rsquo;t covered. • As usu</description>
    </item>
    <item>
      <title>Attackers Use New Tool to Scan for React2Shell Exposure</title>
      <link>https://cluster-site.onrender.com/posts/attackers-use-new-tool-to-scan-for-react2shell-exposure/</link>
      <pubDate>Fri, 20 Feb 2026 21:07:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/attackers-use-new-tool-to-scan-for-react2shell-exposure/</guid>
      <description>• Researchers say threat actors wielded the sophisticated - and unfortunately named - toolkit to target high-value networks for React2Shell exploitation • Cybersecurity researchers</description>
    </item>
    <item>
      <title>&#39;Starkiller&#39; Phishing Service Proxies Real Login Pages, MFA</title>
      <link>https://cluster-site.onrender.com/posts/starkiller-phishing-service-proxies-real-login-pages-mfa/</link>
      <pubDate>Fri, 20 Feb 2026 20:00:30 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/starkiller-phishing-service-proxies-real-login-pages-mfa/</guid>
      <description>• Most phishing websites are little more than static copies of login pages for popular online destinations, and they are often quickly taken down by anti-abuse activists and securi</description>
    </item>
    <item>
      <title>&#39;God-Like&#39; Attack Machines: AI Agents Ignore Security Policies</title>
      <link>https://cluster-site.onrender.com/posts/god-like-attack-machines-ai-agents-ignore-security-policies/</link>
      <pubDate>Fri, 20 Feb 2026 18:31:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/god-like-attack-machines-ai-agents-ignore-security-policies/</guid>
      <description>• Microsoft Copilot recently summarized and leaked user emails; but any AI agent will go above and beyond to complete assigned tasks, even breaking through their carefully designed</description>
    </item>
    <item>
      <title>Japanese tech giant Advantest hit by ransomware attack</title>
      <link>https://cluster-site.onrender.com/posts/japanese-tech-giant-advantest-hit-by-ransomware-attack/</link>
      <pubDate>Fri, 20 Feb 2026 18:30:44 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/japanese-tech-giant-advantest-hit-by-ransomware-attack/</guid>
      <description>• Japanese tech giant Advantest hit by ransomware attack February 20, 2026 01:30 PM 0 Advantest Corporation disclosed that its corporate network has been targeted in a ransomware a</description>
    </item>
    <item>
      <title>Lessons From AI Hacking: Every Model, Every Layer Is Risky</title>
      <link>https://cluster-site.onrender.com/posts/lessons-from-ai-hacking-every-model-every-layer-is-risky/</link>
      <pubDate>Fri, 20 Feb 2026 18:02:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lessons-from-ai-hacking-every-model-every-layer-is-risky/</guid>
      <description>• Application Security Cyber Risk Cybersecurity Operations Vulnerabilities &amp;amp; Threats News Lessons From AI Hacking: Every Model, Every Layer Is Risky After two years of finding flaw</description>
    </item>
    <item>
      <title>Data breach at French bank registry impacts 1.2 million accounts</title>
      <link>https://cluster-site.onrender.com/posts/data-breach-at-french-bank-registry-impacts-1.2-million-accounts/</link>
      <pubDate>Fri, 20 Feb 2026 16:20:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/data-breach-at-french-bank-registry-impacts-1.2-million-accounts/</guid>
      <description>• Data breach at French bank registry impacts 1.2 million accounts February 20, 2026 11:20 AM 0 The French Ministry of Finance has disclosed a cybersecurity incident that impacted</description>
    </item>
    <item>
      <title>NIST&#39;s Quantum Breakthrough: Single Photons Produced on a Chip</title>
      <link>https://cluster-site.onrender.com/posts/nists-quantum-breakthrough-single-photons-produced-on-a-chip/</link>
      <pubDate>Fri, 20 Feb 2026 15:48:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nists-quantum-breakthrough-single-photons-produced-on-a-chip/</guid>
      <description>• NIST has developed a chip that reliably emits a single photon on demand. • This ability will improve the efficiency of QKD (quantum key distribution) as we prepare for the arriva</description>
    </item>
    <item>
      <title>BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration</title>
      <link>https://cluster-site.onrender.com/posts/beyondtrust-flaw-used-for-web-shells-backdoors-and-data-exfiltration/</link>
      <pubDate>Fri, 20 Feb 2026 15:45:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/beyondtrust-flaw-used-for-web-shells-backdoors-and-data-exfiltration/</guid>
      <description>• BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration Threat actors have been observed exploiting a recently disclosed critical security flaw impacting BeyondTru</description>
    </item>
    <item>
      <title>In Other News: Ransomware Shuts US Clinics, ICS Vulnerability Surge, European Parliament Bans AI</title>
      <link>https://cluster-site.onrender.com/posts/in-other-news-ransomware-shuts-us-clinics-ics-vulnerability-surge-european-parliament-bans-ai/</link>
      <pubDate>Fri, 20 Feb 2026 15:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/in-other-news-ransomware-shuts-us-clinics-ics-vulnerability-surge-european-parliament-bans-ai/</guid>
      <description>• SecurityWeek&amp;rsquo;s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar.We provide a valuable summary of stories th</description>
    </item>
    <item>
      <title>Why the shift left dream has become a nightmare for security and developers</title>
      <link>https://cluster-site.onrender.com/posts/why-the-shift-left-dream-has-become-a-nightmare-for-security-and-developers/</link>
      <pubDate>Fri, 20 Feb 2026 14:45:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/why-the-shift-left-dream-has-become-a-nightmare-for-security-and-developers/</guid>
      <description>• Why the shift left dream has become a nightmare for security and developers February 20, 2026 09:45 AM 0 Written by Ivan Milenkovic, Vice President Risk Technology EMEA, Qualys F</description>
    </item>
    <item>
      <title>Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems</title>
      <link>https://cluster-site.onrender.com/posts/cline-cli-2.3.0-supply-chain-attack-installed-openclaw-on-developer-systems/</link>
      <pubDate>Fri, 20 Feb 2026 14:20:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cline-cli-2.3.0-supply-chain-attack-installed-openclaw-on-developer-systems/</guid>
      <description>• Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems In yet another software supply chain attack, the open-source, artificial intelligence (AI)-powered cod</description>
    </item>
    <item>
      <title>Age verification vendor Persona left frontend exposed</title>
      <link>https://cluster-site.onrender.com/posts/age-verification-vendor-persona-left-frontend-exposed/</link>
      <pubDate>Fri, 20 Feb 2026 14:08:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/age-verification-vendor-persona-left-frontend-exposed/</guid>
      <description>• Discord partners with Persona for age verification, requiring facial scans before full platform access. • Researchers uncovered a publicly exposed Persona frontend on a US govern</description>
    </item>
    <item>
      <title>Latin America&#39;s Cyber Maturity Lags Threat Landscape</title>
      <link>https://cluster-site.onrender.com/posts/latin-americas-cyber-maturity-lags-threat-landscape/</link>
      <pubDate>Fri, 20 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/latin-americas-cyber-maturity-lags-threat-landscape/</guid>
      <description>• Threat Intelligence Cyber Risk Cybersecurity Operations Cyberattacks &amp;amp; Data Breaches News Breaking cybersecurity news, news analysis, commentary, and other content from around th</description>
    </item>
    <item>
      <title>PayPal discloses data breach that exposed user info for 6 months</title>
      <link>https://cluster-site.onrender.com/posts/paypal-discloses-data-breach-that-exposed-user-info-for-6-months/</link>
      <pubDate>Fri, 20 Feb 2026 13:12:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/paypal-discloses-data-breach-that-exposed-user-info-for-6-months/</guid>
      <description>• PayPal disclosed a data breach affecting PPWC loan app, exposing sensitive info for 6 months. • Breach spanned July 1 to December 13, 2025, revealing names, emails, phone, busine</description>
    </item>
    <item>
      <title>Ring Cancels Its Partnership with Flock</title>
      <link>https://cluster-site.onrender.com/posts/ring-cancels-its-partnership-with-flock/</link>
      <pubDate>Fri, 20 Feb 2026 12:08:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ring-cancels-its-partnership-with-flock/</guid>
      <description>• • February 20, 2026 11:39 AM Can we read something that is not behind a paywall? • Clive Robinson • February 20, 2026 2:57 PM @ Who?, ALL, &amp;lsquo;Can we read something that is not behi</description>
    </item>
    <item>
      <title>ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware</title>
      <link>https://cluster-site.onrender.com/posts/clickfix-campaign-abuses-compromised-sites-to-deploy-mimicrat-malware/</link>
      <pubDate>Fri, 20 Feb 2026 11:55:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/clickfix-campaign-abuses-compromised-sites-to-deploy-mimicrat-malware/</guid>
      <description>• ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware Cybersecurity researchers have disclosed details of a newClickFixcampaign that abuses compromised legitimate</description>
    </item>
    <item>
      <title>Mississippi medical center closes all clinics after ransomware attack</title>
      <link>https://cluster-site.onrender.com/posts/mississippi-medical-center-closes-all-clinics-after-ransomware-attack/</link>
      <pubDate>Fri, 20 Feb 2026 11:50:14 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/mississippi-medical-center-closes-all-clinics-after-ransomware-attack/</guid>
      <description>• The University of Mississippi Medical Center (UMMC) closed all its clinic locations statewide on Thursday following a ransomware attack. • UMMC has over 10,000 employees and, as</description>
    </item>
    <item>
      <title>FBI: $20 Million Losses Caused by 700 ATM Jackpotting Attacks in 2025</title>
      <link>https://cluster-site.onrender.com/posts/fbi-20-million-losses-caused-by-700-atm-jackpotting-attacks-in-2025/</link>
      <pubDate>Fri, 20 Feb 2026 11:05:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fbi-20-million-losses-caused-by-700-atm-jackpotting-attacks-in-2025/</guid>
      <description>• A flash alert published on Thursday by the FBI warns of an increase in malware-enabled ATM jackpotting attacks in the United States.According to the agency, roughly 1,900 ATM jac</description>
    </item>
    <item>
      <title>Identity Cyber Scores: The New Metric Shaping Cyber Insurance in 2026</title>
      <link>https://cluster-site.onrender.com/posts/identity-cyber-scores-the-new-metric-shaping-cyber-insurance-in-2026/</link>
      <pubDate>Fri, 20 Feb 2026 10:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/identity-cyber-scores-the-new-metric-shaping-cyber-insurance-in-2026/</guid>
      <description>• One in three cyber-attacks now involve compromised employee accounts, driving insurers to focus on identity posture. • Password hygiene, privileged access management, and MFA cov</description>
    </item>
    <item>
      <title>FBI: Over $20 million stolen in surge of ATM malware attacks in 2025</title>
      <link>https://cluster-site.onrender.com/posts/fbi-over-20-million-stolen-in-surge-of-atm-malware-attacks-in-2025/</link>
      <pubDate>Fri, 20 Feb 2026 10:08:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fbi-over-20-million-stolen-in-surge-of-atm-malware-attacks-in-2025/</guid>
      <description>• The FBI warned that Americans lost more than $20 million last year amid a massive surge in ATM &amp;lsquo;jackpotting&amp;rsquo; attacks, in which criminals use malware to force cash machines to dis</description>
    </item>
    <item>
      <title>Ukrainian National Sentenced to 5 Years in North Korea IT Worker Fraud Case</title>
      <link>https://cluster-site.onrender.com/posts/ukrainian-national-sentenced-to-5-years-in-north-korea-it-worker-fraud-case/</link>
      <pubDate>Fri, 20 Feb 2026 09:52:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ukrainian-national-sentenced-to-5-years-in-north-korea-it-worker-fraud-case/</guid>
      <description>• Ukrainian National Sentenced to 5 Years in North Korea IT Worker Fraud Case A 29-year-old Ukrainian national has beensentenced to five years in prisonin the U.S. • for his role i</description>
    </item>
    <item>
      <title>Chip Testing Giant Advantest Hit by Ransomware</title>
      <link>https://cluster-site.onrender.com/posts/chip-testing-giant-advantest-hit-by-ransomware/</link>
      <pubDate>Fri, 20 Feb 2026 09:31:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/chip-testing-giant-advantest-hit-by-ransomware/</guid>
      <description>• Japanese chip testing giant Advantest Corporation (TSE: 6857) has been targeted in a ransomware attack.Advantest makes automatic test equipment for the semiconductor industry. •</description>
    </item>
    <item>
      <title>CrowdStrike Named a Customers&amp;rsquo; Choice in 2026 Gartner Peer Insights&amp;trade; Voice of the Customer for Application Security Posture Management Tools</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-a-customersrsquo-choice-in-2026-gartner-peer-insightstrade-voice-of-the-customer-for-application-security-posture-management-tools/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:28 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-a-customersrsquo-choice-in-2026-gartner-peer-insightstrade-voice-of-the-customer-for-application-security-posture-management-tools/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>Advanced Web Shell Detection and Prevention: A Deep Dive into CrowdStrike&#39;s Linux Sensor Capabilities</title>
      <link>https://cluster-site.onrender.com/posts/advanced-web-shell-detection-and-prevention-a-deep-dive-into-crowdstrikes-linux-sensor-capabilities/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/advanced-web-shell-detection-and-prevention-a-deep-dive-into-crowdstrikes-linux-sensor-capabilities/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>What Security Teams Need to Know About OpenClaw, the AI Super Agent</title>
      <link>https://cluster-site.onrender.com/posts/what-security-teams-need-to-know-about-openclaw-the-ai-super-agent/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-security-teams-need-to-know-about-openclaw-the-ai-super-agent/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>CrowdStrike Is the Only Vendor to Be Named a Customers&amp;rsquo; Choice in 2025 Gartner&amp;reg; Voice of the Customer for External Attack Surface Management</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-is-the-only-vendor-to-be-named-a-customersrsquo-choice-in-2025-gartnerreg-voice-of-the-customer-for-external-attack-surface-management/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-is-the-only-vendor-to-be-named-a-customersrsquo-choice-in-2025-gartnerreg-voice-of-the-customer-for-external-attack-surface-management/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>Inside the Human-AI Feedback Loop Powering CrowdStrike&amp;rsquo;s Agentic Security</title>
      <link>https://cluster-site.onrender.com/posts/inside-the-human-ai-feedback-loop-powering-crowdstrikersquos-agentic-security/</link>
      <pubDate>Fri, 20 Feb 2026 09:30:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/inside-the-human-ai-feedback-loop-powering-crowdstrikersquos-agentic-security/</guid>
      <description>• FeaturedIntroducing &amp;lsquo;AI Unlocked: Decoding Prompt Injection,&amp;rsquo; a New Interactive ChallengeFeb 18, 2026Exposing Insider Threats through Data Protection, Identity, and HR ContextFeb</description>
    </item>
    <item>
      <title>Ukrainian gets 5 years for helping North Koreans infiltrate US firms</title>
      <link>https://cluster-site.onrender.com/posts/ukrainian-gets-5-years-for-helping-north-koreans-infiltrate-us-firms/</link>
      <pubDate>Fri, 20 Feb 2026 09:00:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ukrainian-gets-5-years-for-helping-north-koreans-infiltrate-us-firms/</guid>
      <description>• Ukrainian gets 5 years for helping North Koreans infiltrate US firms February 20, 2026 04:00 AM 0 A Ukrainian national was sentenced to five years in prison for providing North K</description>
    </item>
    <item>
      <title>FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025</title>
      <link>https://cluster-site.onrender.com/posts/fbi-reports-1900-atm-jackpotting-incidents-since-2020-20m-lost-in-2025/</link>
      <pubDate>Fri, 20 Feb 2026 08:05:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fbi-reports-1900-atm-jackpotting-incidents-since-2020-20m-lost-in-2025/</guid>
      <description>• FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025 The U.S. • Federal Bureau of Investigation (FBI) has warned of an increase in ATM jackpotting incidents</description>
    </item>
    <item>
      <title>Former Google Engineers Indicted Over Trade Secret Transfers to Iran</title>
      <link>https://cluster-site.onrender.com/posts/former-google-engineers-indicted-over-trade-secret-transfers-to-iran/</link>
      <pubDate>Fri, 20 Feb 2026 05:27:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/former-google-engineers-indicted-over-trade-secret-transfers-to-iran/</guid>
      <description>• Former Google Engineers Indicted Over Trade Secret Transfers to Iran Two former Google engineers and one of their husbands have beenindictedin the U.S. • for allegedly committing</description>
    </item>
    <item>
      <title>Three Former Google Engineers Indicted Over Trade Secret Transfers to Iran</title>
      <link>https://cluster-site.onrender.com/posts/three-former-google-engineers-indicted-over-trade-secret-transfers-to-iran/</link>
      <pubDate>Fri, 20 Feb 2026 05:27:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/three-former-google-engineers-indicted-over-trade-secret-transfers-to-iran/</guid>
      <description>• Three Former Google Engineers Indicted Over Trade Secret Transfers to Iran Two former Google engineers and one of their husbands have beenindictedin the U.S. • for allegedly comm</description>
    </item>
    <item>
      <title>ISC Stormcast For Friday, February 20th, 2026 https://isc.sans.edu/podcastdetail/9818, (Fri, Feb 20th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-friday-february-20th-2026-https/isc.sans.edu/podcastdetail/9818-fri-feb-20th/</link>
      <pubDate>Fri, 20 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-friday-february-20th-2026-https/isc.sans.edu/podcastdetail/9818-fri-feb-20th/</guid>
      <description>• ISC Stormcast For Friday, February 20th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9818&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9818&lt;/a&gt;
 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security: S</description>
    </item>
    <item>
      <title>Emerging Chiplet Designs Spark Fresh Cybersecurity Challenges</title>
      <link>https://cluster-site.onrender.com/posts/emerging-chiplet-designs-spark-fresh-cybersecurity-challenges/</link>
      <pubDate>Thu, 19 Feb 2026 23:17:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/emerging-chiplet-designs-spark-fresh-cybersecurity-challenges/</guid>
      <description>• As scaled-down circuits with limited functions redefine computing for AI systems and autonomous vehicles, their flexibility demands new approaches to safeguard critical infrastru</description>
    </item>
    <item>
      <title>VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)</title>
      <link>https://cluster-site.onrender.com/posts/vshell-and-sparkrat-observed-in-exploitation-of-beyondtrust-critical-vulnerability-cve-2026-1731/</link>
      <pubDate>Thu, 19 Feb 2026 23:00:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vshell-and-sparkrat-observed-in-exploitation-of-beyondtrust-critical-vulnerability-cve-2026-1731/</guid>
      <description>• Executive Summary On Feb. • 6, 2026, BeyondTrust released a security advisory regarding CVE-2026-1731. • BeyondTrust is an identity and access management platform. • This specifi</description>
    </item>
    <item>
      <title>PromptSpy is the first known Android malware to use generative AI at runtime</title>
      <link>https://cluster-site.onrender.com/posts/promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime/</link>
      <pubDate>Thu, 19 Feb 2026 22:36:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/promptspy-is-the-first-known-android-malware-to-use-generative-ai-at-runtime/</guid>
      <description>• PromptSpy is the first known Android malware to use generative AI at runtime February 19, 2026 05:36 PM 0 Researchers have discovered the first known Android malware to use gener</description>
    </item>
    <item>
      <title>Supply Chain Attack Secretly Installs OpenClaw for Cline Users</title>
      <link>https://cluster-site.onrender.com/posts/supply-chain-attack-secretly-installs-openclaw-for-cline-users/</link>
      <pubDate>Thu, 19 Feb 2026 22:33:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/supply-chain-attack-secretly-installs-openclaw-for-cline-users/</guid>
      <description>• Application Security Cyber Risk Cyberattacks &amp;amp; Data Breaches Vulnerabilities &amp;amp; Threats News Supply Chain Attack Secretly Installs OpenClaw for Cline Users The malicious version o</description>
    </item>
    <item>
      <title>Best-in-Class &#39;Starkiller&#39; Phishing Kit Bypasses MFA</title>
      <link>https://cluster-site.onrender.com/posts/best-in-class-starkiller-phishing-kit-bypasses-mfa/</link>
      <pubDate>Thu, 19 Feb 2026 22:06:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/best-in-class-starkiller-phishing-kit-bypasses-mfa/</guid>
      <description>• A user-friendly PhaaS tool beats standard methods for detecting phishing attacks by live-proxying legitimate login sites.</description>
    </item>
    <item>
      <title>Abu Dhabi Finance Week Exposed VIP Passport Details</title>
      <link>https://cluster-site.onrender.com/posts/abu-dhabi-finance-week-exposed-vip-passport-details/</link>
      <pubDate>Thu, 19 Feb 2026 20:50:14 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/abu-dhabi-finance-week-exposed-vip-passport-details/</guid>
      <description>• Unprotected cloud data sends the wrong signal at a time when the emirate&amp;rsquo;s trying to attract investors and establish itself as a global financial center.</description>
    </item>
    <item>
      <title>Under the Hood of DynoWiper, (Thu, Feb 19th)</title>
      <link>https://cluster-site.onrender.com/posts/under-the-hood-of-dynowiper-thu-feb-19th/</link>
      <pubDate>Thu, 19 Feb 2026 19:43:30 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/under-the-hood-of-dynowiper-thu-feb-19th/</guid>
      <description>• Under the Hood of DynoWiper [This is a Guest Diary contributed by John Moutos] Overview In this post, I&amp;rsquo;m going over my analysis of DynoWiper, a wiper family that was discovered</description>
    </item>
    <item>
      <title>PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence</title>
      <link>https://cluster-site.onrender.com/posts/promptspy-android-malware-abuses-gemini-ai-to-automate-recent-apps-persistence/</link>
      <pubDate>Thu, 19 Feb 2026 17:52:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/promptspy-android-malware-abuses-gemini-ai-to-automate-recent-apps-persistence/</guid>
      <description>• PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence Cybersecurity researchers have discovered what they say is the first Android malware that abuses Ge</description>
    </item>
    <item>
      <title>INTERPOL Operation Red Card 2.0 Arrests 651 in African Cybercrime Crackdown</title>
      <link>https://cluster-site.onrender.com/posts/interpol-operation-red-card-2.0-arrests-651-in-african-cybercrime-crackdown/</link>
      <pubDate>Thu, 19 Feb 2026 17:50:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/interpol-operation-red-card-2.0-arrests-651-in-african-cybercrime-crackdown/</guid>
      <description>• INTERPOL Operation Red Card 2.0 Arrests 651 in African Cybercrime Crackdown An international cybercrime operation against online scams has led to 651 arrests and recovered more t</description>
    </item>
    <item>
      <title>Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-patches-cve-2026-26119-privilege-escalation-in-windows-admin-center/</link>
      <pubDate>Thu, 19 Feb 2026 17:40:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-patches-cve-2026-26119-privilege-escalation-in-windows-admin-center/</guid>
      <description>• Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center Microsoft has disclosed a now-patched security flaw in Windows Admin Center that could allow an atta</description>
    </item>
    <item>
      <title>Google blocked over 1.75 million Play Store app submissions in 2025</title>
      <link>https://cluster-site.onrender.com/posts/google-blocked-over-1.75-million-play-store-app-submissions-in-2025/</link>
      <pubDate>Thu, 19 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-blocked-over-1.75-million-play-store-app-submissions-in-2025/</guid>
      <description>• Google blocked over 1.75 million Play Store app submissions in 2025 February 19, 2026 12:00 PM 0 Google says that through 2025, it blocked more than 255,000 Android apps from obt</description>
    </item>
    <item>
      <title>New e-book: Establishing a proactive defense with Microsoft Security Exposure Management</title>
      <link>https://cluster-site.onrender.com/posts/new-e-book-establishing-a-proactive-defense-with-microsoft-security-exposure-management/</link>
      <pubDate>Thu, 19 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-e-book-establishing-a-proactive-defense-with-microsoft-security-exposure-management/</guid>
      <description>• Share Link copied to clipboard! • Content types Best practices Topics Data security Network security Security management Effective exposure management begins by illuminating and</description>
    </item>
    <item>
      <title>Running OpenClaw safely: identity, isolation, and runtime risk</title>
      <link>https://cluster-site.onrender.com/posts/running-openclaw-safely-identity-isolation-and-runtime-risk/</link>
      <pubDate>Thu, 19 Feb 2026 16:27:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/running-openclaw-safely-identity-isolation-and-runtime-risk/</guid>
      <description>• Self-hosted agent runtimes like OpenClaw are showing up fast in enterprise pilots, and they introduce a blunt reality: OpenClaw includes limited built-in security controls. • The</description>
    </item>
    <item>
      <title>Connected &amp;amp; Compromised: When IoT Devices Turn Into Threats</title>
      <link>https://cluster-site.onrender.com/posts/connected-amp-compromised-when-iot-devices-turn-into-threats/</link>
      <pubDate>Thu, 19 Feb 2026 15:18:23 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/connected-amp-compromised-when-iot-devices-turn-into-threats/</guid>
      <description>• Reused passwords, a lack of network segmentation, and poor sanitization processes make the Internet of Things&amp;rsquo; attack surfaces more dangerous.</description>
    </item>
    <item>
      <title>Connected and Compromised: When IoT Devices Turn Into Threats</title>
      <link>https://cluster-site.onrender.com/posts/connected-and-compromised-when-iot-devices-turn-into-threats/</link>
      <pubDate>Thu, 19 Feb 2026 15:18:23 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/connected-and-compromised-when-iot-devices-turn-into-threats/</guid>
      <description>• Reused passwords, a lack of network segmentation, and poor sanitization processes make the Internet of Things&amp;rsquo; attack surfaces more dangerous.</description>
    </item>
    <item>
      <title>How infostealers turn stolen credentials into real identities</title>
      <link>https://cluster-site.onrender.com/posts/how-infostealers-turn-stolen-credentials-into-real-identities/</link>
      <pubDate>Thu, 19 Feb 2026 15:05:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-infostealers-turn-stolen-credentials-into-real-identities/</guid>
      <description>• How infostealers turn stolen credentials into real identities February 19, 2026 10:05 AM 0 Modern infostealers have expanded credential theft far beyond usernames and passwords.</description>
    </item>
    <item>
      <title>French Government Says 1.2 Million Bank Accounts Exposed in Breach</title>
      <link>https://cluster-site.onrender.com/posts/french-government-says-1.2-million-bank-accounts-exposed-in-breach/</link>
      <pubDate>Thu, 19 Feb 2026 15:02:58 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/french-government-says-1.2-million-bank-accounts-exposed-in-breach/</guid>
      <description>• France&amp;rsquo;s Ministry of Economy on Wednesday disclosed a breach that exposed information on 1.2 million bank accounts.Investigators discovered unauthorized access to the national ba</description>
    </item>
    <item>
      <title>ThreatsDay Bulletin: OpenSSL RCE, Foxit 0-Days, Copilot Leak, AI Password Flaws &amp; 20&#43; Stories</title>
      <link>https://cluster-site.onrender.com/posts/threatsday-bulletin-openssl-rce-foxit-0-days-copilot-leak-ai-password-flaws-20-stories/</link>
      <pubDate>Thu, 19 Feb 2026 14:35:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threatsday-bulletin-openssl-rce-foxit-0-days-copilot-leak-ai-password-flaws-20-stories/</guid>
      <description>• OpenSSL RCE vulnerability threatens legacy systems, demanding urgent patching across enterprises. • Foxit PDF zero-days expose document readers to remote code execution, affectin</description>
    </item>
    <item>
      <title>Nigerian man gets eight years in prison for hacking tax firms</title>
      <link>https://cluster-site.onrender.com/posts/nigerian-man-gets-eight-years-in-prison-for-hacking-tax-firms/</link>
      <pubDate>Thu, 19 Feb 2026 13:51:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nigerian-man-gets-eight-years-in-prison-for-hacking-tax-firms/</guid>
      <description>• Nigerian man gets eight years in prison for hacking tax firms February 19, 2026 08:51 AM 0 A Nigerian national was sentenced to eight years in prison for hacking multiple tax pre</description>
    </item>
    <item>
      <title>Nearly 1 Million User Records Compromised in Figure Data Breach</title>
      <link>https://cluster-site.onrender.com/posts/nearly-1-million-user-records-compromised-in-figure-data-breach/</link>
      <pubDate>Thu, 19 Feb 2026 13:19:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nearly-1-million-user-records-compromised-in-figure-data-breach/</guid>
      <description>• Nearly 1 million user records have been compromised in a data breach at blockchain-powered lender Figure Technology Solutions.The companyconfirmedto TechCrunch that it suffered a</description>
    </item>
    <item>
      <title>Texas sues TP-Link over Chinese hacking risks, user deception</title>
      <link>https://cluster-site.onrender.com/posts/texas-sues-tp-link-over-chinese-hacking-risks-user-deception/</link>
      <pubDate>Thu, 19 Feb 2026 12:36:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/texas-sues-tp-link-over-chinese-hacking-risks-user-deception/</guid>
      <description>• Texas sued networking giant TP-Link Systems, accusing the company of deceptively marketing its routers as secure while allowing Chinese state-backed hackers to exploit firmware v</description>
    </item>
    <item>
      <title>Hackers target Microsoft Entra accounts in device code vishing attacks</title>
      <link>https://cluster-site.onrender.com/posts/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/</link>
      <pubDate>Thu, 19 Feb 2026 12:30:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/</guid>
      <description>• Hackers target Microsoft Entra accounts via device code vishing, exploiting OAuth 2.0 flow. • Attack uses legitimate OAuth client IDs, bypassing phishing sites and standard login</description>
    </item>
    <item>
      <title>Venice Security Emerges From Stealth With $33M Funding for Privileged Access Management</title>
      <link>https://cluster-site.onrender.com/posts/venice-security-emerges-from-stealth-with-33m-funding-for-privileged-access-management/</link>
      <pubDate>Thu, 19 Feb 2026 12:23:41 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/venice-security-emerges-from-stealth-with-33m-funding-for-privileged-access-management/</guid>
      <description>• Venice Security on Wednesday emerged from stealth mode with $33 million in funding for its adaptive enterprise privileged access management platform.The company, formerly named V</description>
    </item>
    <item>
      <title>Malicious AI</title>
      <link>https://cluster-site.onrender.com/posts/malicious-ai/</link>
      <pubDate>Thu, 19 Feb 2026 12:05:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-ai/</guid>
      <description>• Malicious AI Summary: An AI agent of unknown ownership autonomously wrote and published a personalized hit piece about me after I rejected its code, attempting to damage my reput</description>
    </item>
    <item>
      <title>From Exposure to Exploitation: How AI Collapses Your Response Window</title>
      <link>https://cluster-site.onrender.com/posts/from-exposure-to-exploitation-how-ai-collapses-your-response-window/</link>
      <pubDate>Thu, 19 Feb 2026 11:55:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/from-exposure-to-exploitation-how-ai-collapses-your-response-window/</guid>
      <description>• From Exposure to Exploitation: How AI Collapses Your Response Window We&amp;rsquo;ve all seen this before: a developer deploys a new cloud workload and grants overly broad permissions just</description>
    </item>
    <item>
      <title>Police arrests 651 suspects in African cybercrime crackdown</title>
      <link>https://cluster-site.onrender.com/posts/police-arrests-651-suspects-in-african-cybercrime-crackdown/</link>
      <pubDate>Thu, 19 Feb 2026 11:24:17 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/police-arrests-651-suspects-in-african-cybercrime-crackdown/</guid>
      <description>• Police arrests 651 suspects in African cybercrime crackdown February 19, 2026 06:24 AM 0 African law enforcement agencies arrested 651 suspects and recovered over $4.3 million in</description>
    </item>
    <item>
      <title>Arkanix Stealer: a C&#43;&#43; &amp; Python infostealer</title>
      <link>https://cluster-site.onrender.com/posts/arkanix-stealer-a-c-python-infostealer/</link>
      <pubDate>Thu, 19 Feb 2026 11:00:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/arkanix-stealer-a-c-python-infostealer/</guid>
      <description>• Introduction In October 2025, we discovered a series of forum posts advertising a previously unknown stealer, dubbed &amp;lsquo;Arkanix Stealer&amp;rsquo; by its authors. • It operated under a MaaS</description>
    </item>
    <item>
      <title>OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts</title>
      <link>https://cluster-site.onrender.com/posts/openclaw-security-issues-continue-as-secureclaw-open-source-tool-debuts/</link>
      <pubDate>Thu, 19 Feb 2026 11:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/openclaw-security-issues-continue-as-secureclaw-open-source-tool-debuts/</guid>
      <description>• OpenClaw is rarely out of the news, but not necessarily under that name. • This &amp;lsquo;autonomous personal assistant&amp;rsquo; started life as Clawdbot, changed its name to Moltbot, and is now</description>
    </item>
    <item>
      <title>Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users</title>
      <link>https://cluster-site.onrender.com/posts/fake-iptv-apps-spread-massiv-android-malware-targeting-mobile-banking-users/</link>
      <pubDate>Thu, 19 Feb 2026 10:24:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-iptv-apps-spread-massiv-android-malware-targeting-mobile-banking-users/</guid>
      <description>• Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users Cybersecurity researchers have disclosed details of a new Android trojan calledMassivthat&amp;rsquo;s designed t</description>
    </item>
    <item>
      <title>New &#39;Massiv&#39; Android banking malware poses as an IPTV app</title>
      <link>https://cluster-site.onrender.com/posts/new-massiv-android-banking-malware-poses-as-an-iptv-app/</link>
      <pubDate>Thu, 19 Feb 2026 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-massiv-android-banking-malware-poses-as-an-iptv-app/</guid>
      <description>• New &amp;lsquo;Massiv&amp;rsquo; Android banking malware poses as an IPTV app February 19, 2026 05:00 AM 0 A new Android banking malware, which researchers named Massiv, is posing as an IPTV app to</description>
    </item>
    <item>
      <title>German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack</title>
      <link>https://cluster-site.onrender.com/posts/german-rail-giant-deutsche-bahn-hit-by-large-scale-ddos-attack/</link>
      <pubDate>Thu, 19 Feb 2026 09:16:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/german-rail-giant-deutsche-bahn-hit-by-large-scale-ddos-attack/</guid>
      <description>• Deutsche Bahn, Germany&amp;rsquo;s national rail operator, has been dealing with a large-scale distributed denial-of-service (DDoS) attack that has disrupted some of its IT systems.Regular</description>
    </item>
    <item>
      <title>CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware</title>
      <link>https://cluster-site.onrender.com/posts/crescentharvest-campaign-targets-iran-protest-supporters-with-rat-malware/</link>
      <pubDate>Thu, 19 Feb 2026 08:13:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crescentharvest-campaign-targets-iran-protest-supporters-with-rat-malware/</guid>
      <description>• CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware Cybersecurity researchers have disclosed details of a new campaign dubbedCRESCENTHARVEST, likely targeti</description>
    </item>
    <item>
      <title>February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs Patched</title>
      <link>https://cluster-site.onrender.com/posts/february-2026-patch-tuesday-six-zero-days-among-59-cves-patched/</link>
      <pubDate>Thu, 19 Feb 2026 07:30:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/february-2026-patch-tuesday-six-zero-days-among-59-cves-patched/</guid>
      <description>• Patch Tuesday 2026 fixed 59 CVEs, including six critical zero‑days. • CVE‑2026‑21533: Windows Remote Desktop elevation of privilege, CVSS 7.8. • Exploit modifies service config k</description>
    </item>
    <item>
      <title>More Than 40% of South Africans Were Scammed in 2025</title>
      <link>https://cluster-site.onrender.com/posts/more-than-40-of-south-africans-were-scammed-in-2025/</link>
      <pubDate>Thu, 19 Feb 2026 07:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/more-than-40-of-south-africans-were-scammed-in-2025/</guid>
      <description>• Survey underscores the reality that scammers follow &amp;lsquo;scalable opportunities and low friction,&amp;rsquo; rather than rich targets that tend to be better protected.</description>
    </item>
    <item>
      <title>ISC Stormcast For Thursday, February 19th, 2026 https://isc.sans.edu/podcastdetail/9816, (Thu, Feb 19th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-thursday-february-19th-2026-https/isc.sans.edu/podcastdetail/9816-thu-feb-19th/</link>
      <pubDate>Thu, 19 Feb 2026 02:00:03 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-thursday-february-19th-2026-https/isc.sans.edu/podcastdetail/9816-thu-feb-19th/</guid>
      <description>• ISC Stormcast For Thursday, February 19th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9816&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9816&lt;/a&gt;
 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security:</description>
    </item>
    <item>
      <title>How to start consolidating your cybersecurity tools</title>
      <link>https://cluster-site.onrender.com/posts/how-to-start-consolidating-your-cybersecurity-tools/</link>
      <pubDate>Thu, 19 Feb 2026 00:46:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-to-start-consolidating-your-cybersecurity-tools/</guid>
      <description>• How to start consolidating your cybersecurity tools Jackson Connell, Mitch Pronschinske Optimize operations Risk &amp;amp; compliance Culture &amp;amp; collaboration Jan 12, 2026 Jackson Connell</description>
    </item>
    <item>
      <title>The risks of cybersecurity tool sprawl: Why consolidation is a strategic priority</title>
      <link>https://cluster-site.onrender.com/posts/the-risks-of-cybersecurity-tool-sprawl-why-consolidation-is-a-strategic-priority/</link>
      <pubDate>Thu, 19 Feb 2026 00:46:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-risks-of-cybersecurity-tool-sprawl-why-consolidation-is-a-strategic-priority/</guid>
      <description>• The risks of cybersecurity tool sprawl: Why consolidation is a strategic priority Jackson Connell, Mitch Pronschinske Optimize operations Risk &amp;amp; compliance Culture &amp;amp; collaboratio</description>
    </item>
    <item>
      <title>Exposing Insider Threats through Data Protection, Identity, and HR Context</title>
      <link>https://cluster-site.onrender.com/posts/exposing-insider-threats-through-data-protection-identity-and-hr-context/</link>
      <pubDate>Wed, 18 Feb 2026 22:30:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/exposing-insider-threats-through-data-protection-identity-and-hr-context/</guid>
      <description>• Insider threats pose a growing risk to organizations. • Whether insiders take malicious actions, exhibit negligent behavior, or make accidental errors, they have the potential to</description>
    </item>
    <item>
      <title>Scam Abuses Gemini Chatbots to Convince People to Buy Fake Crypto</title>
      <link>https://cluster-site.onrender.com/posts/scam-abuses-gemini-chatbots-to-convince-people-to-buy-fake-crypto/</link>
      <pubDate>Wed, 18 Feb 2026 21:47:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scam-abuses-gemini-chatbots-to-convince-people-to-buy-fake-crypto/</guid>
      <description>• A convincing presale site for phony &amp;lsquo;Google Coin&amp;rsquo; features an AI assistant that engages victims with a slick sales pitch, funneling payment to attackers.</description>
    </item>
    <item>
      <title>Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot</title>
      <link>https://cluster-site.onrender.com/posts/critical-grandstream-voip-bug-highlights-smb-security-blind-spot/</link>
      <pubDate>Wed, 18 Feb 2026 21:15:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/critical-grandstream-voip-bug-highlights-smb-security-blind-spot/</guid>
      <description>• CVE-2026-2329 allows unauthenticated root-level access to SMB phone infrastructure, so attackers can intercept calls, commit toll fraud, and impersonate users.</description>
    </item>
    <item>
      <title>Critical infra Honeywell CCTVs vulnerable to auth bypass flaw</title>
      <link>https://cluster-site.onrender.com/posts/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/</link>
      <pubDate>Wed, 18 Feb 2026 20:58:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/</guid>
      <description>• Critical infra Honeywell CCTVs vulnerable to auth bypass flaw February 18, 2026 03:58 PM 0 The U.S. • Cybersecurity and Infrastructure Security Agency (CISA) is warning of a crit</description>
    </item>
    <item>
      <title>Threat Intelligence Has a Human-Shaped Blind Spot</title>
      <link>https://cluster-site.onrender.com/posts/threat-intelligence-has-a-human-shaped-blind-spot/</link>
      <pubDate>Wed, 18 Feb 2026 20:56:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-intelligence-has-a-human-shaped-blind-spot/</guid>
      <description>• How I realized what I was taught to about threat intelligence was missing something crucial.</description>
    </item>
    <item>
      <title>Dell&#39;s Hard-Coded Flaw: A Nation-State Goldmine</title>
      <link>https://cluster-site.onrender.com/posts/dells-hard-coded-flaw-a-nation-state-goldmine/</link>
      <pubDate>Wed, 18 Feb 2026 20:49:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dells-hard-coded-flaw-a-nation-state-goldmine/</guid>
      <description>• A China-related attacker has exploited the vendor flaw since mid-2024, allowing it to move laterally, maintain persistent access, and deploy malware.</description>
    </item>
    <item>
      <title>AI platforms can be abused for stealthy malware communication</title>
      <link>https://cluster-site.onrender.com/posts/ai-platforms-can-be-abused-for-stealthy-malware-communication/</link>
      <pubDate>Wed, 18 Feb 2026 20:18:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-platforms-can-be-abused-for-stealthy-malware-communication/</guid>
      <description>• AI platforms can be abused for stealthy malware communication February 18, 2026 03:18 PM 0 AI assistants like Grok and Microsoft Copilot with web browsing and URL-fetching capabi</description>
    </item>
    <item>
      <title>A CISO&#39;s Playbook for Defending Data Assets Against AI Scraping</title>
      <link>https://cluster-site.onrender.com/posts/a-cisos-playbook-for-defending-data-assets-against-ai-scraping/</link>
      <pubDate>Wed, 18 Feb 2026 19:13:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-cisos-playbook-for-defending-data-assets-against-ai-scraping/</guid>
      <description>• Cyber Risk Commentary Cybersecurity In-Depth: Getting answers to questions about IT security threats and best practices from trusted cybersecurity professionals and industry expe</description>
    </item>
    <item>
      <title>AI Unlocked Decoding Prompt Injection Interactive Challenge</title>
      <link>https://cluster-site.onrender.com/posts/ai-unlocked-decoding-prompt-injection-interactive-challenge/</link>
      <pubDate>Wed, 18 Feb 2026 18:30:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-unlocked-decoding-prompt-injection-interactive-challenge/</guid>
      <description>• AI Unlocked challenge focuses on detecting and mitigating prompt injection attacks. • Participants learn to craft prompts that resist malicious manipulation by LLMs. • Interactiv</description>
    </item>
    <item>
      <title>Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist&#39;s Phone in Police Custody</title>
      <link>https://cluster-site.onrender.com/posts/citizen-lab-finds-cellebrite-tool-used-on-kenyan-activists-phone-in-police-custody/</link>
      <pubDate>Wed, 18 Feb 2026 17:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/citizen-lab-finds-cellebrite-tool-used-on-kenyan-activists-phone-in-police-custody/</guid>
      <description>• Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist&amp;rsquo;s Phone in Police Custody New research from the Citizen Lab has found signs that Kenyan authorities used a commercialfor</description>
    </item>
    <item>
      <title>Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution</title>
      <link>https://cluster-site.onrender.com/posts/grandstream-gxp1600-voip-phones-exposed-to-unauthenticated-remote-code-execution/</link>
      <pubDate>Wed, 18 Feb 2026 16:35:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/grandstream-gxp1600-voip-phones-exposed-to-unauthenticated-remote-code-execution/</guid>
      <description>• Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution Cybersecurity researchers have disclosed a critical security flaw in the Grandstream GXP1600 seri</description>
    </item>
    <item>
      <title>Telegram channels expose rapid weaponization of SmarterMail flaws</title>
      <link>https://cluster-site.onrender.com/posts/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/</link>
      <pubDate>Wed, 18 Feb 2026 16:27:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/</guid>
      <description>• SmarterMail CVE-2026-24423 and CVE-2026-23760 enable remote code execution and auth bypass. • Attackers weaponized these flaws within days of disclosure, sharing exploits on Tele</description>
    </item>
    <item>
      <title>Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-anti-phishing-rules-mistakenly-blocked-emails-teams-messages/</link>
      <pubDate>Wed, 18 Feb 2026 16:26:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-anti-phishing-rules-mistakenly-blocked-emails-teams-messages/</guid>
      <description>• Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages February 18, 2026 11:26 AM 0 Microsoft says an Exchange Online issue that mistakenly quarantined legitima</description>
    </item>
    <item>
      <title>New Keenadu Android Malware Found on Thousands of Devices</title>
      <link>https://cluster-site.onrender.com/posts/new-keenadu-android-malware-found-on-thousands-of-devices/</link>
      <pubDate>Wed, 18 Feb 2026 15:41:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-keenadu-android-malware-found-on-thousands-of-devices/</guid>
      <description>• Researchers at Kaspersky have analyzed a recently discovered Android malware that enables its operators to remotely control compromised devices.DubbedKeenadu, the backdoor has be</description>
    </item>
    <item>
      <title>Cogent Security Raises $42 Million for AI-Driven Vulnerability Management</title>
      <link>https://cluster-site.onrender.com/posts/cogent-security-raises-42-million-for-ai-driven-vulnerability-management/</link>
      <pubDate>Wed, 18 Feb 2026 14:47:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cogent-security-raises-42-million-for-ai-driven-vulnerability-management/</guid>
      <description>• Cogent Security raises $42M Series A, total funding now $53M. • Funding led by Bain Capital Ventures, joined by Greylock, OpenAI execs, Datadog. • Company develops autonomous AI</description>
    </item>
    <item>
      <title>Data breach at fintech firm Figure affects nearly 1 million accounts</title>
      <link>https://cluster-site.onrender.com/posts/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/</link>
      <pubDate>Wed, 18 Feb 2026 14:01:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/</guid>
      <description>• Hackers breached Figure Technology Solutions, stealing personal data of nearly 1 million accounts. • Attack was a social‑engineering phishing that tricked an employee into giving</description>
    </item>
    <item>
      <title>Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration</title>
      <link>https://cluster-site.onrender.com/posts/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/</link>
      <pubDate>Wed, 18 Feb 2026 13:16:19 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/</guid>
      <description>• 16 critical, high, and medium‑severity vulnerabilities found in Foxit and Apryse PDF platforms. • Flaws include DOM XSS, SSRF, path traversal, and OS command injection. • Attacke</description>
    </item>
    <item>
      <title>Lenovo denies allegations of transferring data to China - class action lawsuit alleges company uses trackers to expose American behavioral data to &#39;foreign adversaries&#39;</title>
      <link>https://cluster-site.onrender.com/posts/lenovo-denies-allegations-of-transferring-data-to-china-class-action-lawsuit-alleges-company-uses-trackers-to-expose-american-behavioral-data-to-foreign-adversaries/</link>
      <pubDate>Wed, 18 Feb 2026 13:06:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lenovo-denies-allegations-of-transferring-data-to-china-class-action-lawsuit-alleges-company-uses-trackers-to-expose-american-behavioral-data-to-foreign-adversaries/</guid>
      <description>• Lenovo sued by Almeida Law Group for alleged data transfer to China. • Lawsuit claims violation of DOJ Data Security Program, preventing large data exports to &amp;lsquo;countries of conce</description>
    </item>
    <item>
      <title>AI Found Twelve New Vulnerabilities in OpenSSL</title>
      <link>https://cluster-site.onrender.com/posts/ai-found-twelve-new-vulnerabilities-in-openssl/</link>
      <pubDate>Wed, 18 Feb 2026 12:03:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-found-twelve-new-vulnerabilities-in-openssl/</guid>
      <description>• AI Found Twelve New Vulnerabilities in OpenSSL The title of the post is&amp;rsquo;What AI Security Research Looks Like When It Works,&amp;rsquo; and I agree: In the latest OpenSSL security release&amp;gt;</description>
    </item>
    <item>
      <title>Microsoft says bug causes Copilot to summarize confidential emails</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/</link>
      <pubDate>Wed, 18 Feb 2026 12:03:05 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/</guid>
      <description>• Microsoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies th</description>
    </item>
    <item>
      <title>Cybersecurity Tech Predictions for 2026: Operating in a World of Permanent Instability</title>
      <link>https://cluster-site.onrender.com/posts/cybersecurity-tech-predictions-for-2026-operating-in-a-world-of-permanent-instability/</link>
      <pubDate>Wed, 18 Feb 2026 11:58:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cybersecurity-tech-predictions-for-2026-operating-in-a-world-of-permanent-instability/</guid>
      <description>• In 2025, navigating the digital seas still felt like a matter of direction. • Organizations charted routes, watched the horizon, and adjusted course to reach safe harbors of resi</description>
    </item>
    <item>
      <title>Glendale man gets 5 years in prison for role in darknet drug ring</title>
      <link>https://cluster-site.onrender.com/posts/glendale-man-gets-5-years-in-prison-for-role-in-darknet-drug-ring/</link>
      <pubDate>Wed, 18 Feb 2026 10:50:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/glendale-man-gets-5-years-in-prison-for-role-in-darknet-drug-ring/</guid>
      <description>• Glendale man gets 5 years in prison for role in darknet drug ring February 18, 2026 05:50 AM 0 ​A Glendale man was sentenced to nearly five years in federal prison for his role i</description>
    </item>
    <item>
      <title>3 Ways to Start Your Intelligent Workflow Program</title>
      <link>https://cluster-site.onrender.com/posts/3-ways-to-start-your-intelligent-workflow-program/</link>
      <pubDate>Wed, 18 Feb 2026 10:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/3-ways-to-start-your-intelligent-workflow-program/</guid>
      <description>• 3 Ways to Start Your Intelligent Workflow Program Security, IT, and engineering teams today are under relentless pressure to accelerate outcomes, cut operational drag, and unlock</description>
    </item>
    <item>
      <title>Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction</title>
      <link>https://cluster-site.onrender.com/posts/palo-alto-networks-to-acquire-koi-in-reported-400-million-transaction/</link>
      <pubDate>Wed, 18 Feb 2026 08:24:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/palo-alto-networks-to-acquire-koi-in-reported-400-million-transaction/</guid>
      <description>• Palo Alto Networks announced on Tuesday that it has entered into a definitive agreement to acquire endpoint security company Koi.Financial details have not been disclosed by the</description>
    </item>
    <item>
      <title>Tracking Malware Campaigns With Reused Material, (Wed, Feb 18th)</title>
      <link>https://cluster-site.onrender.com/posts/tracking-malware-campaigns-with-reused-material-wed-feb-18th/</link>
      <pubDate>Wed, 18 Feb 2026 08:19:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/tracking-malware-campaigns-with-reused-material-wed-feb-18th/</guid>
      <description>• Tracking Malware Campaigns With Reused Material A few days ago I wrote a diary called &amp;lsquo;Malicious Script Delivering More Maliciousness&amp;rsquo;[1]. • In the malware infection chain, there</description>
    </item>
    <item>
      <title>Notepad&#43;&#43; Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware</title>
      <link>https://cluster-site.onrender.com/posts/notepad-fixes-hijacked-update-mechanism-used-to-deliver-targeted-malware/</link>
      <pubDate>Wed, 18 Feb 2026 07:40:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/notepad-fixes-hijacked-update-mechanism-used-to-deliver-targeted-malware/</guid>
      <description>• Notepad++ released 8.9.2 patch to fix hijacked update mechanism exploited by Chinese threat actor. • Introduces &amp;lsquo;double lock&amp;rsquo; design, verifying signed installer and XML from upda</description>
    </item>
    <item>
      <title>What Aristotle and Socrates can teach us about using generative AI</title>
      <link>https://cluster-site.onrender.com/posts/what-aristotle-and-socrates-can-teach-us-about-using-generative-ai/</link>
      <pubDate>Wed, 18 Feb 2026 01:12:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-aristotle-and-socrates-can-teach-us-about-using-generative-ai/</guid>
      <description>• AI language models can erode our creative capacity, making original idea generation harder. • Other AI types enhance critical thinking, providing analytical tools for better deci</description>
    </item>
    <item>
      <title>Singapore &amp;amp; Its 4 Major Telcos Fend Off Chinese Hackers</title>
      <link>https://cluster-site.onrender.com/posts/singapore-amp-its-4-major-telcos-fend-off-chinese-hackers/</link>
      <pubDate>Wed, 18 Feb 2026 01:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/singapore-amp-its-4-major-telcos-fend-off-chinese-hackers/</guid>
      <description>• Singapore&amp;rsquo;s CSA and four telcos launched &amp;lsquo;Cyber Guardian&amp;rsquo; to counter China-linked UNC3886.\n• 100+ incident responders coordinated across government and M1, Singtel, StarHub, Sim</description>
    </item>
    <item>
      <title>Spain orders NordVPN and ProtonVPN to block LaLiga stream piracy</title>
      <link>https://cluster-site.onrender.com/posts/spain-orders-nordvpn-and-protonvpn-to-block-laliga-stream-piracy/</link>
      <pubDate>Tue, 17 Feb 2026 23:15:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spain-orders-nordvpn-and-protonvpn-to-block-laliga-stream-piracy/</guid>
      <description>• Spanish court orders NordVPN and ProtonVPN to block 16 sites facilitating LaLiga match piracy. • Restrictions apply to a dynamic IP list in Spain, with no appeal rights for VPNs.</description>
    </item>
    <item>
      <title>Supply Chain Attack Embeds Malware in Android Devices</title>
      <link>https://cluster-site.onrender.com/posts/supply-chain-attack-embeds-malware-in-android-devices/</link>
      <pubDate>Tue, 17 Feb 2026 22:06:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/supply-chain-attack-embeds-malware-in-android-devices/</guid>
      <description>• Keenadu downloads payloads that hijack browser searches, commit ad fraud, and execute other actions without user knowledge.</description>
    </item>
    <item>
      <title>Poland Energy Survives Attack on Wind, Solar Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/poland-energy-survives-attack-on-wind-solar-infrastructure/</link>
      <pubDate>Tue, 17 Feb 2026 21:31:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/poland-energy-survives-attack-on-wind-solar-infrastructure/</guid>
      <description>• Russia-aligned groups are probable culprits behind the wiper attacks against renewable energy farms, a manufacturer, and a heating and power plant.</description>
    </item>
    <item>
      <title>Flaws in popular VSCode extensions expose developers to attacks</title>
      <link>https://cluster-site.onrender.com/posts/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/</link>
      <pubDate>Tue, 17 Feb 2026 21:27:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/</guid>
      <description>• Flaws in popular VSCode extensions expose developers to attacks February 17, 2026 04:27 PM 0 Vulnerabilities with high to critical severity ratings affecting popular Visual Studi</description>
    </item>
    <item>
      <title>RMM Abuse Explodes as Hackers Ditch Malware</title>
      <link>https://cluster-site.onrender.com/posts/rmm-abuse-explodes-as-hackers-ditch-malware/</link>
      <pubDate>Tue, 17 Feb 2026 21:01:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/rmm-abuse-explodes-as-hackers-ditch-malware/</guid>
      <description>• RMM tools are increasingly used as primary attack vectors, replacing traditional malware. • Attackers leverage RMM&amp;rsquo;s remote access to maintain stealth and persistence. • RMM&amp;rsquo;s bu</description>
    </item>
    <item>
      <title>ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT</title>
      <link>https://cluster-site.onrender.com/posts/clickfix-attacks-abuses-dns-lookup-command-to-deliver-modelorat/</link>
      <pubDate>Tue, 17 Feb 2026 21:01:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/clickfix-attacks-abuses-dns-lookup-command-to-deliver-modelorat/</guid>
      <description>• ClickFix campaigns have adapted to the latest defenses with a new technique to trick users into infecting their own machines with malware.</description>
    </item>
    <item>
      <title>Critical Vulnerabilities in Ivanti EPMM Exploited</title>
      <link>https://cluster-site.onrender.com/posts/critical-vulnerabilities-in-ivanti-epmm-exploited/</link>
      <pubDate>Tue, 17 Feb 2026 20:35:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/critical-vulnerabilities-in-ivanti-epmm-exploited/</guid>
      <description>• Executive Summary Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild</description>
    </item>
    <item>
      <title>Resilience in the AI era: Google at MSC 2026</title>
      <link>https://cluster-site.onrender.com/posts/resilience-in-the-ai-era-google-at-msc-2026/</link>
      <pubDate>Tue, 17 Feb 2026 19:10:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/resilience-in-the-ai-era-google-at-msc-2026/</guid>
      <description>• Google highlighted MSC 2026&amp;rsquo;s focus on integrated security amid multi-front cyber threats. • AI-driven attacks now automate reconnaissance, phishing, and supply‑chain sabotage. •</description>
    </item>
    <item>
      <title>Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster</title>
      <link>https://cluster-site.onrender.com/posts/webinar-how-modern-soc-teams-use-ai-and-context-to-investigate-cloud-breaches-faster/</link>
      <pubDate>Tue, 17 Feb 2026 19:08:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/webinar-how-modern-soc-teams-use-ai-and-context-to-investigate-cloud-breaches-faster/</guid>
      <description>• Cloud attacks outpace traditional incident response, infrastructure vanishes in minutes. • Manual log stitching gives attackers advantage; automated, context-aware forensics need</description>
    </item>
    <item>
      <title>Notepad&#43;&#43; boosts update security with &#39;double-lock&#39; mechanism</title>
      <link>https://cluster-site.onrender.com/posts/notepad-boosts-update-security-with-double-lock-mechanism/</link>
      <pubDate>Tue, 17 Feb 2026 18:29:18 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/notepad-boosts-update-security-with-double-lock-mechanism/</guid>
      <description>• Notepad++ introduces a double‑lock update system, verifying signed installers from GitHub and XML from its domain. • The new design eliminates DLL side‑loading by removing libcur</description>
    </item>
    <item>
      <title>Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies</title>
      <link>https://cluster-site.onrender.com/posts/researchers-show-copilot-and-grok-can-be-abused-as-malware-c2-proxies/</link>
      <pubDate>Tue, 17 Feb 2026 18:08:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/researchers-show-copilot-and-grok-can-be-abused-as-malware-c2-proxies/</guid>
      <description>• AI assistants like Copilot and Grok can be hijacked as stealthy C2 proxies, blending into legitimate traffic. • Check Point researchers demonstrated the technique using anonymous</description>
    </item>
    <item>
      <title>Unify now or pay later: New research exposes the operational cost of a fragmented SOC</title>
      <link>https://cluster-site.onrender.com/posts/unify-now-or-pay-later-new-research-exposes-the-operational-cost-of-a-fragmented-soc/</link>
      <pubDate>Tue, 17 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/unify-now-or-pay-later-new-research-exposes-the-operational-cost-of-a-fragmented-soc/</guid>
      <description>• Share Link copied to clipboard! • Content types Industry trends Topics AI and agents Defending against advanced tactics Security management Security operations SIEM and XDR Secur</description>
    </item>
    <item>
      <title>Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates</title>
      <link>https://cluster-site.onrender.com/posts/keenadu-firmware-backdoor-infects-android-tablets-via-signed-ota-updates/</link>
      <pubDate>Tue, 17 Feb 2026 16:41:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/keenadu-firmware-backdoor-infects-android-tablets-via-signed-ota-updates/</guid>
      <description>• Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates A new Android backdoor that&amp;rsquo;s embedded deep into the device firmware can silently harvest data and remote</description>
    </item>
    <item>
      <title>VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence</title>
      <link>https://cluster-site.onrender.com/posts/vulncheck-raises-25-million-in-series-b-funding-to-scale-vulnerability-intelligence/</link>
      <pubDate>Tue, 17 Feb 2026 16:00:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vulncheck-raises-25-million-in-series-b-funding-to-scale-vulnerability-intelligence/</guid>
      <description>• Vulnerability intelligence company VulnCheck announced on Tuesday that it has raised $25 million to meet demand for its solutions.The Series B funding round, which brings the tot</description>
    </item>
    <item>
      <title>Microsoft Teams outage affects users in United States, Europe</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-teams-outage-affects-users-in-united-states-europe/</link>
      <pubDate>Tue, 17 Feb 2026 15:37:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-teams-outage-affects-users-in-united-states-europe/</guid>
      <description>• Microsoft Teams experiencing widespread outage across US and Europe, disrupting meetings and chat functionality. • Users report delays and failures when sending or receiving inli</description>
    </item>
    <item>
      <title>What 5 Million Apps Revealed About Secrets in JavaScript</title>
      <link>https://cluster-site.onrender.com/posts/what-5-million-apps-revealed-about-secrets-in-javascript/</link>
      <pubDate>Tue, 17 Feb 2026 14:40:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-5-million-apps-revealed-about-secrets-in-javascript/</guid>
      <description>• What 5 Million Apps Revealed About Secrets in JavaScript February 17, 2026 09:40 AM 0 Leaked API keys are nothing new, but the scale of the problem in front-end code has been lar</description>
    </item>
    <item>
      <title>New Keenadu backdoor found in Android firmware, Google Play apps</title>
      <link>https://cluster-site.onrender.com/posts/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/</link>
      <pubDate>Tue, 17 Feb 2026 14:05:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/</guid>
      <description>• Keenadu: sophisticated Android malware embedded in firmware across multiple device brands. • Distributes via OTA firmware, system apps, unofficial sources, and Google Play apps.</description>
    </item>
    <item>
      <title>API Threats Grow in Scale as AI Expands the Blast Radius</title>
      <link>https://cluster-site.onrender.com/posts/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/</link>
      <pubDate>Tue, 17 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/</guid>
      <description>• Application Programming Interfaces (APIs) remain an attacker-favored exploit route. • Aggressors continuously target common failures in identity, access control and exposed inter</description>
    </item>
    <item>
      <title>Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems</title>
      <link>https://cluster-site.onrender.com/posts/cyber-insights-2026-the-ongoing-fight-to-secure-industrial-control-systems/</link>
      <pubDate>Tue, 17 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cyber-insights-2026-the-ongoing-fight-to-secure-industrial-control-systems/</guid>
      <description>• SecurityWeek&amp;rsquo;s Cyber Insights 2026 examines expert opinions on the expected evolution of more than a dozen areas of cybersecurity interest over the next 12 months. • We spoke to</description>
    </item>
    <item>
      <title>Man Linked to Phobos Ransomware Arrested in Poland</title>
      <link>https://cluster-site.onrender.com/posts/man-linked-to-phobos-ransomware-arrested-in-poland/</link>
      <pubDate>Tue, 17 Feb 2026 12:54:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/man-linked-to-phobos-ransomware-arrested-in-poland/</guid>
      <description>• A 47-year-old man arrested by police in Poland for allegedly being involved in cybercriminal activities has been linked to the Phobos ransomware operation.According to Poland&amp;rsquo;s C</description>
    </item>
    <item>
      <title>SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer</title>
      <link>https://cluster-site.onrender.com/posts/smartloader-attack-uses-trojanized-oura-mcp-server-to-deploy-stealc-infostealer/</link>
      <pubDate>Tue, 17 Feb 2026 12:42:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/smartloader-attack-uses-trojanized-oura-mcp-server-to-deploy-stealc-infostealer/</guid>
      <description>• SmartLoader uses a trojanized Oura MCP server to deliver the StealC infostealer. • Threat actors cloned legitimate Oura MCP, creating fake forks to build credibility. • StealC st</description>
    </item>
    <item>
      <title>Side-Channel Attacks Against LLMs</title>
      <link>https://cluster-site.onrender.com/posts/side-channel-attacks-against-llms/</link>
      <pubDate>Tue, 17 Feb 2026 12:01:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/side-channel-attacks-against-llms/</guid>
      <description>• Side-Channel Attacks Against LLMs Here are three papers describing different side-channel attacks against LLMs. • &amp;lsquo;Remote Timing Attacks on Efficient Language Model Inference&amp;rsquo;: A</description>
    </item>
    <item>
      <title>SATA SSD cheated death from failed attempt at data destruction with a drill - drive emerges victorious in face-off against IT worker</title>
      <link>https://cluster-site.onrender.com/posts/sata-ssd-cheated-death-from-failed-attempt-at-data-destruction-with-a-drill-drive-emerges-victorious-in-face-off-against-it-worker/</link>
      <pubDate>Tue, 17 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/sata-ssd-cheated-death-from-failed-attempt-at-data-destruction-with-a-drill-drive-emerges-victorious-in-face-off-against-it-worker/</guid>
      <description>• IT worker tried to destroy SATA SSD with a drill, but missed the PCB. • The drive remained intact, data still accessible, posing a security risk. • SSDs have shorter PCBs; drilli</description>
    </item>
    <item>
      <title>Poland arrests suspect linked to Phobos ransomware operation</title>
      <link>https://cluster-site.onrender.com/posts/poland-arrests-suspect-linked-to-phobos-ransomware-operation/</link>
      <pubDate>Tue, 17 Feb 2026 11:31:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/poland-arrests-suspect-linked-to-phobos-ransomware-operation/</guid>
      <description>• Poland arrests suspect linked to Phobos ransomware operation February 17, 2026 06:31 AM 0 Polish police have detained a 47-year-old man suspected of ties to the Phobos ransomware</description>
    </item>
    <item>
      <title>My Day Getting My Hands Dirty with an NDR System</title>
      <link>https://cluster-site.onrender.com/posts/my-day-getting-my-hands-dirty-with-an-ndr-system/</link>
      <pubDate>Tue, 17 Feb 2026 11:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/my-day-getting-my-hands-dirty-with-an-ndr-system/</guid>
      <description>• My objective As someone relatively inexperienced with network threat hunting, I wanted to get some hands-on experience using a network detection and response (NDR) system. • My g</description>
    </item>
    <item>
      <title>3 Threat Groups Started Targeting ICS/OT in 2025: Dragos</title>
      <link>https://cluster-site.onrender.com/posts/3-threat-groups-started-targeting-ics/ot-in-2025-dragos/</link>
      <pubDate>Tue, 17 Feb 2026 11:05:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/3-threat-groups-started-targeting-ics/ot-in-2025-dragos/</guid>
      <description>• Dragos 9th Annual Report reveals three new OT/ICS threat groups active in 2025. • Sylvanite rapidly weaponizes n‑day vulnerabilities, enabling Voltzite to infiltrate critical inf</description>
    </item>
    <item>
      <title>Ireland now also investigating X over Grok-made sexual images</title>
      <link>https://cluster-site.onrender.com/posts/ireland-now-also-investigating-x-over-grok-made-sexual-images/</link>
      <pubDate>Tue, 17 Feb 2026 10:02:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ireland-now-also-investigating-x-over-grok-made-sexual-images/</guid>
      <description>• Ireland&amp;rsquo;s Data Protection Commission (DPC), the country&amp;rsquo;s data protection authority, has opened a formal investigation into X over the use of the platform&amp;rsquo;s Grok artificial intel</description>
    </item>
    <item>
      <title>Microsoft Finds &#39;Summarize with AI&#39; Prompts Manipulating Chatbot Recommendations</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-finds-summarize-with-ai-prompts-manipulating-chatbot-recommendations/</link>
      <pubDate>Tue, 17 Feb 2026 09:31:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-finds-summarize-with-ai-prompts-manipulating-chatbot-recommendations/</guid>
      <description>• Microsoft Finds &amp;lsquo;Summarize with AI&amp;rsquo; Prompts Manipulating Chatbot Recommendations New research from Microsoft has revealed that legitimate businesses are gaming artificial intelli</description>
    </item>
    <item>
      <title>Password Managers Vulnerable to Vault Compromise Under Malicious Server</title>
      <link>https://cluster-site.onrender.com/posts/password-managers-vulnerable-to-vault-compromise-under-malicious-server/</link>
      <pubDate>Tue, 17 Feb 2026 09:30:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/password-managers-vulnerable-to-vault-compromise-under-malicious-server/</guid>
      <description>• ETH Zurich researchers tested zero‑knowledge password managers against fully malicious servers. • Bitwarden, Dashlane, LastPass, and 1Password were evaluated. • Attacks targeted</description>
    </item>
    <item>
      <title>Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets</title>
      <link>https://cluster-site.onrender.com/posts/divide-and-conquer-how-the-new-keenadu-backdoor-exposed-links-between-major-android-botnets/</link>
      <pubDate>Tue, 17 Feb 2026 09:00:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/divide-and-conquer-how-the-new-keenadu-backdoor-exposed-links-between-major-android-botnets/</guid>
      <description>• In April 2025, we reported on a then-new iteration of the Triada backdoor that had compromised the firmware of counterfeit Android devices sold across major marketplaces. • The m</description>
    </item>
    <item>
      <title>CrowdStrike Falcon Scores Perfect 100% in SE Labs&amp;rsquo; Most Challenging Ransomware Test</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-falcon-scores-perfect-100-in-se-labsrsquo-most-challenging-ransomware-test/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:17 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-falcon-scores-perfect-100-in-se-labsrsquo-most-challenging-ransomware-test/</guid>
      <description>• FeaturedCrowdStrike Named a Customers&amp;rsquo; Choice in 2026 Gartner® Peer Insights™ Voice of the Customer for User AuthenticationFeb 12, 2026How to Scale SOC Automation with Falcon Fus</description>
    </item>
    <item>
      <title>Secure AI with CrowdStrike: Real-World Stories of Protecting AI Workloads and Data</title>
      <link>https://cluster-site.onrender.com/posts/secure-ai-with-crowdstrike-real-world-stories-of-protecting-ai-workloads-and-data/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:17 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/secure-ai-with-crowdstrike-real-world-stories-of-protecting-ai-workloads-and-data/</guid>
      <description>• FeaturedCrowdStrike Named a Customers&amp;rsquo; Choice in 2026 Gartner® Peer Insights™ Voice of the Customer for User AuthenticationFeb 12, 2026How to Scale SOC Automation with Falcon Fus</description>
    </item>
    <item>
      <title>CrowdStrike Enhances Linux Sensor for Web Shell Detection</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-enhances-linux-sensor-for-web-shell-detection/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-enhances-linux-sensor-for-web-shell-detection/</guid>
      <description>• CrowdStrike expands Linux sensor to detect malicious web shells in real time. • New detection engine uses behavioral analytics and signature matching for zero‑day threats. • Prev</description>
    </item>
    <item>
      <title>CrowdStrike Wins 2026 Gartner Peer Insights Customer Choice</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-wins-2026-gartner-peer-insights-customer-choice/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-wins-2026-gartner-peer-insights-customer-choice/</guid>
      <description>• CrowdStrike awarded Customer&amp;rsquo;s Choice in 2026 Gartner Peer Insights for user authentication. • Recognition reflects strong customer satisfaction and product performance across se</description>
    </item>
    <item>
      <title>OpenClaw AI Super Agent: Key Insights for Security Teams</title>
      <link>https://cluster-site.onrender.com/posts/openclaw-ai-super-agent-key-insights-for-security-teams/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/openclaw-ai-super-agent-key-insights-for-security-teams/</guid>
      <description>• OpenClaw automates threat detection and response across enterprise environments. • Seamless integration with CrowdStrike Falcon boosts SOC efficiency. • Human‑AI feedback loops r</description>
    </item>
    <item>
      <title>CrowdStrike Named Customers&#39; Choice in 2026 Gartner Voice</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-in-2026-gartner-voice/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-in-2026-gartner-voice/</guid>
      <description>• CrowdStrike earns Customers&amp;rsquo; Choice award in 2026 Gartner Peer Insights Voice of the Customer for User Authentication. • The accolade reflects strong customer satisfaction and pr</description>
    </item>
    <item>
      <title>CrowdStrike&#39;s Agentic Security Powered by Human‑AI Feedback Loop</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrikes-agentic-security-powered-by-humanai-feedback-loop/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:08 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrikes-agentic-security-powered-by-humanai-feedback-loop/</guid>
      <description>• CrowdStrike&amp;rsquo;s new Agentic Security framework blends human oversight with AI‑driven threat detection. • The system uses a continuous feedback loop where analysts refine AI models</description>
    </item>
    <item>
      <title>CrowdStrike Named Customers&#39; Choice User Authentication</title>
      <link>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-user-authentication/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crowdstrike-named-customers-choice-user-authentication/</guid>
      <description>• CrowdStrike recognized as Customers&amp;rsquo; Choice for User Authentication in Gartner Peer Insights. • Falcon Identity Security delivers zero‑trust authentication across web, mobile, an</description>
    </item>
    <item>
      <title>Scale SOC Automation with Falcon Fusion SOAR</title>
      <link>https://cluster-site.onrender.com/posts/scale-soc-automation-with-falcon-fusion-soar/</link>
      <pubDate>Tue, 17 Feb 2026 08:33:07 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/scale-soc-automation-with-falcon-fusion-soar/</guid>
      <description>• Falcon Fusion SOAR scales SOC automation by integrating AI‑driven playbooks and real‑time incident response. • The platform supports multi‑cloud environments, enabling consistent</description>
    </item>
    <item>
      <title>Fake Incident Report Used in Phishing Campaign, (Tue, Feb 17th)</title>
      <link>https://cluster-site.onrender.com/posts/fake-incident-report-used-in-phishing-campaign-tue-feb-17th/</link>
      <pubDate>Tue, 17 Feb 2026 07:41:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-incident-report-used-in-phishing-campaign-tue-feb-17th/</guid>
      <description>• Fake Incident Report Used in Phishing Campaign This morning, I received an interesting phishing email. • I&amp;rsquo;ve a &amp;rsquo;love &amp;amp; hate&amp;rsquo; relation with such emails because I always have the</description>
    </item>
    <item>
      <title>Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta</title>
      <link>https://cluster-site.onrender.com/posts/apple-tests-end-to-end-encrypted-rcs-messaging-in-ios-26.4-developer-beta/</link>
      <pubDate>Tue, 17 Feb 2026 06:44:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/apple-tests-end-to-end-encrypted-rcs-messaging-in-ios-26.4-developer-beta/</guid>
      <description>• Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta Apple on Monday released a new developer beta of iOS and iPadOS with support for end-to-end encryption (</description>
    </item>
    <item>
      <title>ISC Stormcast For Tuesday, February 17th, 2026 https://isc.sans.edu/podcastdetail/9812, (Tue, Feb 17th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-tuesday-february-17th-2026-https/isc.sans.edu/podcastdetail/9812-tue-feb-17th/</link>
      <pubDate>Tue, 17 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-tuesday-february-17th-2026-https/isc.sans.edu/podcastdetail/9812-tue-feb-17th/</guid>
      <description>• ISC Stormcast For Tuesday, February 17th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9812&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9812&lt;/a&gt;
 Handler on Duty: Jan Kopriva Threat Level: green My next class: Application Security: Secur</description>
    </item>
    <item>
      <title>Washington Hotel in Japan discloses ransomware infection incident</title>
      <link>https://cluster-site.onrender.com/posts/washington-hotel-in-japan-discloses-ransomware-infection-incident/</link>
      <pubDate>Mon, 16 Feb 2026 21:10:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/washington-hotel-in-japan-discloses-ransomware-infection-incident/</guid>
      <description>• Washington Hotel in Japan discloses ransomware infection incident February 16, 2026 04:10 PM 0 The Washington Hotel brand in Japan has announced that that its servers were compro</description>
    </item>
    <item>
      <title>Man arrested for demanding reward after accidental police data leak</title>
      <link>https://cluster-site.onrender.com/posts/man-arrested-for-demanding-reward-after-accidental-police-data-leak/</link>
      <pubDate>Mon, 16 Feb 2026 19:13:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/man-arrested-for-demanding-reward-after-accidental-police-data-leak/</guid>
      <description>• Man arrested for demanding reward after accidental police data leak February 16, 2026 02:13 PM 1 Dutch authorities arrested a 40-year-old man after he downloaded confidential doc</description>
    </item>
    <item>
      <title>Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens</title>
      <link>https://cluster-site.onrender.com/posts/infostealer-steals-openclaw-ai-agent-configuration-files-and-gateway-tokens/</link>
      <pubDate>Mon, 16 Feb 2026 18:43:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/infostealer-steals-openclaw-ai-agent-configuration-files-and-gateway-tokens/</guid>
      <description>• Infostealer variant of Vidar exfiltrated OpenClaw AI agent config files. • Stolen files include openclaw.json, device.json, soul.md with tokens, keys, operational principles. • T</description>
    </item>
    <item>
      <title>Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers</title>
      <link>https://cluster-site.onrender.com/posts/study-uncovers-25-password-recovery-attacks-in-major-cloud-password-managers/</link>
      <pubDate>Mon, 16 Feb 2026 18:06:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/study-uncovers-25-password-recovery-attacks-in-major-cloud-password-managers/</guid>
      <description>• A new study has found that multiple cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks under certain conditi</description>
    </item>
    <item>
      <title>Operation DoppelBrand: Weaponizing Fortune 500 Brands</title>
      <link>https://cluster-site.onrender.com/posts/operation-doppelbrand-weaponizing-fortune-500-brands/</link>
      <pubDate>Mon, 16 Feb 2026 18:05:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/operation-doppelbrand-weaponizing-fortune-500-brands/</guid>
      <description>• GS7 group exploits Fortune 500 brand trust, creating near‑perfect corporate portal replicas. • Targeted U.S. financial institutions, luring employees into credential theft. • Att</description>
    </item>
    <item>
      <title>Infostealer malware found stealing OpenClaw secrets for first time</title>
      <link>https://cluster-site.onrender.com/posts/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/</link>
      <pubDate>Mon, 16 Feb 2026 17:32:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/infostealer-malware-found-stealing-openclaw-secrets-for-first-time/</guid>
      <description>• Infostealer malware found stealing OpenClaw secrets for first time February 16, 2026 12:32 PM 0 With the massive adoption of the OpenClaw agentic AI assistant, information-steali</description>
    </item>
    <item>
      <title>Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches</title>
      <link>https://cluster-site.onrender.com/posts/dior-louis-vuitton-tiffany-fined-25-million-in-south-korea-after-data-breaches/</link>
      <pubDate>Mon, 16 Feb 2026 15:09:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dior-louis-vuitton-tiffany-fined-25-million-in-south-korea-after-data-breaches/</guid>
      <description>• South Korea&amp;rsquo;s Personal Information Protection Commission (PIPC) announced last week that it has issued significant fines to several major luxury brands over a recent hacker attac</description>
    </item>
    <item>
      <title>Passwords to passkeys: Staying ISO 27001 compliant in a passwordless era</title>
      <link>https://cluster-site.onrender.com/posts/passwords-to-passkeys-staying-iso-27001-compliant-in-a-passwordless-era/</link>
      <pubDate>Mon, 16 Feb 2026 15:02:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/passwords-to-passkeys-staying-iso-27001-compliant-in-a-passwordless-era/</guid>
      <description>• One morning, you wake up and realize that your business has grown to the point where you can no longer afford to get into that old, worn-out diesel subcompact. • Instead, you sch</description>
    </item>
    <item>
      <title>260K&#43; Chrome Users Duped by Fake AI Browser Extensions</title>
      <link>https://cluster-site.onrender.com/posts/260k-chrome-users-duped-by-fake-ai-browser-extensions/</link>
      <pubDate>Mon, 16 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/260k-chrome-users-duped-by-fake-ai-browser-extensions/</guid>
      <description>• 30 copycat apps tricked users, and Google itself, into thinking they&amp;rsquo;re legitimate AI tools.</description>
    </item>
    <item>
      <title>Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security</title>
      <link>https://cluster-site.onrender.com/posts/android-17-beta-strengthens-secure-by-default-design-for-privacy-and-app-security/</link>
      <pubDate>Mon, 16 Feb 2026 13:50:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/android-17-beta-strengthens-secure-by-default-design-for-privacy-and-app-security/</guid>
      <description>• Google announced the first beta version of Android 17, which includes several privacy and security enhancements.Android developers have described several improvements related to</description>
    </item>
    <item>
      <title>CISA Navigates DHS Shutdown With Reduced Staff</title>
      <link>https://cluster-site.onrender.com/posts/cisa-navigates-dhs-shutdown-with-reduced-staff/</link>
      <pubDate>Mon, 16 Feb 2026 13:49:03 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-navigates-dhs-shutdown-with-reduced-staff/</guid>
      <description>• CISAwill remain operational during the DHS shutdown that commenced at 12:01 a.m. • on Saturday, February 14, 2026, although at a reduced capacity. • KEV is one area that remains.</description>
    </item>
    <item>
      <title>ClickFix added nslookup commands to its arsenal for downloading RATs</title>
      <link>https://cluster-site.onrender.com/posts/clickfix-added-nslookup-commands-to-its-arsenal-for-downloading-rats/</link>
      <pubDate>Mon, 16 Feb 2026 13:09:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/clickfix-added-nslookup-commands-to-its-arsenal-for-downloading-rats/</guid>
      <description>• ClickFix uses fake CAPTCHAs and bogus updates to trick users into executing malicious commands. • Traditional mshta and PowerShell vectors are blocked, so attackers shifted to ns</description>
    </item>
    <item>
      <title>CISA gives feds 3 days to patch actively exploited BeyondTrust flaw</title>
      <link>https://cluster-site.onrender.com/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-beyondtrust-flaw/</link>
      <pubDate>Mon, 16 Feb 2026 12:33:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-beyondtrust-flaw/</guid>
      <description>• CISA gives feds 3 days to patch actively exploited BeyondTrust flaw February 16, 2026 07:33 AM 1 The U.S. • Cybersecurity and Infrastructure Security Agency (CISA) ordered federa</description>
    </item>
    <item>
      <title>The Promptware Kill Chain</title>
      <link>https://cluster-site.onrender.com/posts/the-promptware-kill-chain/</link>
      <pubDate>Mon, 16 Feb 2026 12:04:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-promptware-kill-chain/</guid>
      <description>• The Promptware Kill Chain Attacks against modern generative artificial intelligence (AI) large language models (LLMs) pose a real threat. • Yet discussions around these attacks a</description>
    </item>
    <item>
      <title>Microsoft Warns of ClickFix Attack Abusing DNS Lookups</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-warns-of-clickfix-attack-abusing-dns-lookups/</link>
      <pubDate>Mon, 16 Feb 2026 11:56:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-warns-of-clickfix-attack-abusing-dns-lookups/</guid>
      <description>• Microsoft has warned users that threat actors are leveraging a new variant of the ClickFix technique to deliver malware.TheClickFixattack method has been increasingly used in the</description>
    </item>
    <item>
      <title>Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud</title>
      <link>https://cluster-site.onrender.com/posts/safe-and-inclusive-esociety-how-lithuania-is-bracing-for-aidriven-cyber-fraud/</link>
      <pubDate>Mon, 16 Feb 2026 11:55:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/safe-and-inclusive-esociety-how-lithuania-is-bracing-for-aidriven-cyber-fraud/</guid>
      <description>• Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud Technologies are evolving fast, reshaping economies, governance, and daily life. • Yet, as innova</description>
    </item>
    <item>
      <title>Amazon Scraps Partnership With Surveillance Company After Super Bowl Ad Backlash</title>
      <link>https://cluster-site.onrender.com/posts/amazon-scraps-partnership-with-surveillance-company-after-super-bowl-ad-backlash/</link>
      <pubDate>Mon, 16 Feb 2026 11:40:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/amazon-scraps-partnership-with-surveillance-company-after-super-bowl-ad-backlash/</guid>
      <description>• Amazon&amp;rsquo;s Ring ends partnership with police surveillance firm Flock Safety amid public backlash. • The decision follows a 30‑second Super Bowl ad featuring a lost dog and camera n</description>
    </item>
    <item>
      <title>New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft</title>
      <link>https://cluster-site.onrender.com/posts/new-zerodayrat-mobile-spyware-enables-real-time-surveillance-and-data-theft/</link>
      <pubDate>Mon, 16 Feb 2026 10:24:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-zerodayrat-mobile-spyware-enables-real-time-surveillance-and-data-theft/</guid>
      <description>• Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that&amp;rsquo;s being advertised on Telegram as a way to grab sensitive data and facili</description>
    </item>
    <item>
      <title>A week in security (February 9 &amp;#8211; February 15)</title>
      <link>https://cluster-site.onrender.com/posts/a-week-in-security-february-9-%238211-february-15/</link>
      <pubDate>Mon, 16 Feb 2026 08:02:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-week-in-security-february-9-%238211-february-15/</guid>
      <description>• Credential‑stealing Chrome extensions discovered; Malwarebytes Labs offers detection and removal guide. • Fake online shops target Winter Olympics 2026 fans, phishing for payment</description>
    </item>
    <item>
      <title>2026 64-Bits Malware Trend, (Mon, Feb 16th)</title>
      <link>https://cluster-site.onrender.com/posts/2026-64-bits-malware-trend-mon-feb-16th/</link>
      <pubDate>Mon, 16 Feb 2026 07:46:36 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/2026-64-bits-malware-trend-mon-feb-16th/</guid>
      <description>• 2026 64-Bits Malware Trend In 2022 (time flies!), I wrote a diary about the 32-bits VS. • 64-bits malware landscape[1]. • It demonstrated that, despite the growing number of 64-b</description>
    </item>
    <item>
      <title>New Chrome Zero-Day (CVE-2026-2441) Under Active Attack - Patch Released</title>
      <link>https://cluster-site.onrender.com/posts/new-chrome-zero-day-cve-2026-2441-under-active-attack-patch-released/</link>
      <pubDate>Mon, 16 Feb 2026 06:38:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-chrome-zero-day-cve-2026-2441-under-active-attack-patch-released/</guid>
      <description>• New Chrome Zero-Day (CVE-2026-2441) Under Active Attack - Patch Released Google on Friday released security updates for its Chrome browser to address a security flaw that it said</description>
    </item>
    <item>
      <title>Canada Goose investigating as hackers leak 600K customer records</title>
      <link>https://cluster-site.onrender.com/posts/canada-goose-investigating-as-hackers-leak-600k-customer-records/</link>
      <pubDate>Mon, 16 Feb 2026 04:45:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/canada-goose-investigating-as-hackers-leak-600k-customer-records/</guid>
      <description>• Canada Goose investigating as hackers leak 600K customer records February 15, 2026 11:45 PM 0 ShinyHunters, a well-known data extortion group, claims to have stolen more than 600</description>
    </item>
    <item>
      <title>ISC Stormcast For Monday, February 16th, 2026 https://isc.sans.edu/podcastdetail/9810, (Mon, Feb 16th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-monday-february-16th-2026-https/isc.sans.edu/podcastdetail/9810-mon-feb-16th/</link>
      <pubDate>Mon, 16 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-monday-february-16th-2026-https/isc.sans.edu/podcastdetail/9810-mon-feb-16th/</guid>
      <description>• ISC Stormcast For Monday, February 16th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9810&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9810&lt;/a&gt;
 Handler on Duty: Jan Kopriva Threat Level: green My next class: Application Security: Securi</description>
    </item>
    <item>
      <title>New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS</title>
      <link>https://cluster-site.onrender.com/posts/new-clickfix-attack-abuses-nslookup-to-retrieve-powershell-payload-via-dns/</link>
      <pubDate>Mon, 16 Feb 2026 00:29:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-clickfix-attack-abuses-nslookup-to-retrieve-powershell-payload-via-dns/</guid>
      <description>• Threat actors are now abusing DNS queries as part of ClickFix social engineering attacks to deliver malware, making this the first known use of DNS as a channel in these campaign</description>
    </item>
    <item>
      <title>Windows 11 KB5077181 fixes boot failures linked to failed updates</title>
      <link>https://cluster-site.onrender.com/posts/windows-11-kb5077181-fixes-boot-failures-linked-to-failed-updates/</link>
      <pubDate>Sun, 15 Feb 2026 22:08:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/windows-11-kb5077181-fixes-boot-failures-linked-to-failed-updates/</guid>
      <description>• Windows 11 KB5077181 fixes boot failures linked to failed updates February 15, 2026 05:08 PM 0 Microsoft says it has resolved a Windows 11 bug that caused some commercial systems</description>
    </item>
    <item>
      <title>CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups</title>
      <link>https://cluster-site.onrender.com/posts/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups/</link>
      <pubDate>Sun, 15 Feb 2026 16:30:41 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups/</guid>
      <description>• CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups February 15, 2026 11:30 AM 0 CTM360 reports that more than 4,000 malicious Google Groups and 3,500</description>
    </item>
    <item>
      <title>Pastebin comments push ClickFix JavaScript attack to hijack crypto swaps</title>
      <link>https://cluster-site.onrender.com/posts/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/</link>
      <pubDate>Sun, 15 Feb 2026 15:17:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pastebin-comments-push-clickfix-javascript-attack-to-hijack-crypto-swaps/</guid>
      <description>• Pastebin comments push ClickFix JavaScript attack to hijack crypto swaps February 15, 2026 10:17 AM 0 Threat actors are abusing Pastebin comments to distribute a new ClickFix-sty</description>
    </item>
    <item>
      <title>Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-discloses-dns-based-clickfix-attack-using-nslookup-for-malware-staging/</link>
      <pubDate>Sun, 15 Feb 2026 14:10:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-discloses-dns-based-clickfix-attack-using-nslookup-for-malware-staging/</guid>
      <description>• Microsoft has disclosed details of a new version of the ClickFix social engineering tactic in which the attackers trick unsuspecting users into running commands that carry out a</description>
    </item>
    <item>
      <title>Upcoming Speaking Engagements</title>
      <link>https://cluster-site.onrender.com/posts/upcoming-speaking-engagements/</link>
      <pubDate>Sat, 14 Feb 2026 17:04:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/upcoming-speaking-engagements/</guid>
      <description>• Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I&amp;rsquo;m speaking atOntario Tech Universityin Oshawa, Ontario, Canada, at 2 PM ET on Th</description>
    </item>
    <item>
      <title>One threat actor responsible for 83% of recent Ivanti RCE attacks</title>
      <link>https://cluster-site.onrender.com/posts/one-threat-actor-responsible-for-83-of-recent-ivanti-rce-attacks/</link>
      <pubDate>Sat, 14 Feb 2026 16:02:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/one-threat-actor-responsible-for-83-of-recent-ivanti-rce-attacks/</guid>
      <description>• One threat actor responsible for 83% of recent Ivanti RCE attacks February 14, 2026 11:02 AM 0 Update: The article initially listed the wrong CVEs. • This has now been corrected</description>
    </item>
    <item>
      <title>Snail mail letters target Trezor and Ledger users in crypto-theft attacks</title>
      <link>https://cluster-site.onrender.com/posts/snail-mail-letters-target-trezor-and-ledger-users-in-crypto-theft-attacks/</link>
      <pubDate>Sat, 14 Feb 2026 15:15:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/snail-mail-letters-target-trezor-and-ledger-users-in-crypto-theft-attacks/</guid>
      <description>• Snail mail letters target Trezor and Ledger users in crypto-theft attacks February 14, 2026 10:15 AM 1 Threat actors are sending physical letters pretending to be from Trezor and</description>
    </item>
    <item>
      <title>Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data</title>
      <link>https://cluster-site.onrender.com/posts/over-300-malicious-chrome-extensions-caught-leaking-or-stealing-user-data/</link>
      <pubDate>Sat, 14 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/over-300-malicious-chrome-extensions-caught-leaking-or-stealing-user-data/</guid>
      <description>• Security researchers have discovered more than 300 Chrome extensions that leak browser data, spy on their users, or outright steal users&amp;rsquo; data.Research focused on the analysis of</description>
    </item>
    <item>
      <title>Phishing on the Edge of the Web and Mobile Using QR Codes</title>
      <link>https://cluster-site.onrender.com/posts/phishing-on-the-edge-of-the-web-and-mobile-using-qr-codes/</link>
      <pubDate>Fri, 13 Feb 2026 23:00:48 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/phishing-on-the-edge-of-the-web-and-mobile-using-qr-codes/</guid>
      <description>• Executive Summary This article explores the misuse of QR codes in today&amp;rsquo;s threat landscape, covering three areas of concern: - QR codes using URL shorteners to disguise malicious</description>
    </item>
    <item>
      <title>Fake job recruiters hide malware in developer coding challenges</title>
      <link>https://cluster-site.onrender.com/posts/fake-job-recruiters-hide-malware-in-developer-coding-challenges/</link>
      <pubDate>Fri, 13 Feb 2026 22:35:37 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fake-job-recruiters-hide-malware-in-developer-coding-challenges/</guid>
      <description>• Fake job recruiters hide malware in developer coding challenges February 13, 2026 05:35 PM 0 A new variation of the fake recruiter campaign from North Korean threat actors is tar</description>
    </item>
    <item>
      <title>Friday Squid Blogging: Do Squid Dream?</title>
      <link>https://cluster-site.onrender.com/posts/friday-squid-blogging-do-squid-dream/</link>
      <pubDate>Fri, 13 Feb 2026 22:08:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/friday-squid-blogging-do-squid-dream/</guid>
      <description>• Friday Squid Blogging: Do Squid Dream? • An exploration of the interesting question. • An exploration of the interesting question. • Clive Robinson • February 14, 2026 2:08 AM @</description>
    </item>
    <item>
      <title>Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs</title>
      <link>https://cluster-site.onrender.com/posts/google-ties-suspected-russian-actor-to-canfail-malware-attacks-on-ukrainian-orgs/</link>
      <pubDate>Fri, 13 Feb 2026 17:27:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-ties-suspected-russian-actor-to-canfail-malware-attacks-on-ukrainian-orgs/</guid>
      <description>• Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs A previously undocumented threat actor has been attributed to attacks targeting Ukrainian organiz</description>
    </item>
    <item>
      <title>Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-under-pressure-to-bolster-defenses-for-byovd-attacks/</link>
      <pubDate>Fri, 13 Feb 2026 17:08:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-under-pressure-to-bolster-defenses-for-byovd-attacks/</guid>
      <description>• Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks Threat actors are exploiting security gaps to weaponize Windows drivers and terminate security processes in targete</description>
    </item>
    <item>
      <title>Nation-State Hackers Put Defense Industrial Base Under Siege</title>
      <link>https://cluster-site.onrender.com/posts/nation-state-hackers-put-defense-industrial-base-under-siege/</link>
      <pubDate>Fri, 13 Feb 2026 17:07:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nation-state-hackers-put-defense-industrial-base-under-siege/</guid>
      <description>• Espionage groups from China, Russia and other nations burned at least two dozen zero-days in edge devices in attempts to infiltrate defense contractors&amp;rsquo; networks.</description>
    </item>
    <item>
      <title>AI Agents &#39;Swarm,&#39; Security Complexity Follows Suit</title>
      <link>https://cluster-site.onrender.com/posts/ai-agents-swarm-security-complexity-follows-suit/</link>
      <pubDate>Fri, 13 Feb 2026 16:49:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-agents-swarm-security-complexity-follows-suit/</guid>
      <description>• As AI deployments scale and start to include packs of agents autonomously working in concert, organizations face a naturally amplified attack surface.</description>
    </item>
    <item>
      <title>Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations</title>
      <link>https://cluster-site.onrender.com/posts/google-links-china-iran-russia-north-korea-to-coordinated-defense-sector-cyber-operations/</link>
      <pubDate>Fri, 13 Feb 2026 16:23:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-links-china-iran-russia-north-korea-to-coordinated-defense-sector-cyber-operations/</guid>
      <description>• Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations Several state-sponsored actors, hacktivist entities, and criminal groups from China,</description>
    </item>
    <item>
      <title>UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors</title>
      <link>https://cluster-site.onrender.com/posts/uat-9921-deploys-voidlink-malware-to-target-technology-and-financial-sectors/</link>
      <pubDate>Fri, 13 Feb 2026 15:23:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/uat-9921-deploys-voidlink-malware-to-target-technology-and-financial-sectors/</guid>
      <description>• UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors A previously unknown threat actor tracked asUAT-9921has been observed leveraging a new modular framew</description>
    </item>
    <item>
      <title>In Other News: Google Looks at AI Abuse, Trump Pauses China Bans, Disney&#39;s $2.7M Fine</title>
      <link>https://cluster-site.onrender.com/posts/in-other-news-google-looks-at-ai-abuse-trump-pauses-china-bans-disneys-2.7m-fine/</link>
      <pubDate>Fri, 13 Feb 2026 15:01:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/in-other-news-google-looks-at-ai-abuse-trump-pauses-china-bans-disneys-2.7m-fine/</guid>
      <description>• SecurityWeek&amp;rsquo;s cybersecurity news roundup provides a concise compilation of noteworthy stories that might have slipped under the radar.We provide a valuable summary of stories th</description>
    </item>
    <item>
      <title>Check Point Announces Trio of Acquisitions Amid Solid 2025 Earnings Beat</title>
      <link>https://cluster-site.onrender.com/posts/check-point-announces-trio-of-acquisitions-amid-solid-2025-earnings-beat/</link>
      <pubDate>Fri, 13 Feb 2026 12:35:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/check-point-announces-trio-of-acquisitions-amid-solid-2025-earnings-beat/</guid>
      <description>• Israeli cybersecurity firm Check Point Software Technologies (NASDAQ: CHKP) reported strong fourth-quarter and full-year 2025 financial performance while announcing three strateg</description>
    </item>
    <item>
      <title>Dutch Carrier Odido Discloses Data Breach Impacting 6 Million</title>
      <link>https://cluster-site.onrender.com/posts/dutch-carrier-odido-discloses-data-breach-impacting-6-million/</link>
      <pubDate>Fri, 13 Feb 2026 12:02:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dutch-carrier-odido-discloses-data-breach-impacting-6-million/</guid>
      <description>• Dutch mobile phone carrier Odido has disclosed a data breach impacting the personal information of over 6 million customers.The incident, the company said in anotice, occurred on</description>
    </item>
    <item>
      <title>CISA Announces New Town Halls to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/cisa-announces-new-town-halls-to-engage-with-stakeholders-on-cyber-incident-reporting-for-critical-infrastructure/</link>
      <pubDate>Fri, 13 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-announces-new-town-halls-to-engage-with-stakeholders-on-cyber-incident-reporting-for-critical-infrastructure/</guid>
      <description>• CISA Announces New Town Halls to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure WASHINGTON - The Cybersecurity and Infrastructure Security Agenc</description>
    </item>
    <item>
      <title>Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History</title>
      <link>https://cluster-site.onrender.com/posts/malicious-chrome-extensions-caught-stealing-business-data-emails-and-browsing-history/</link>
      <pubDate>Fri, 13 Feb 2026 11:25:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/malicious-chrome-extensions-caught-stealing-business-data-emails-and-browsing-history/</guid>
      <description>• Cybersecurity researchers have discovered a malicious Google Chrome extension that&amp;rsquo;s designed to steal data associated with Meta Business Suite and Facebook Business Manager. • T</description>
    </item>
    <item>
      <title>npm&#39;s Update to Harden Their Supply Chain, and Points to Consider</title>
      <link>https://cluster-site.onrender.com/posts/npms-update-to-harden-their-supply-chain-and-points-to-consider/</link>
      <pubDate>Fri, 13 Feb 2026 10:45:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/npms-update-to-harden-their-supply-chain-and-points-to-consider/</guid>
      <description>• npm&amp;rsquo;s Update to Harden Their Supply Chain, and Points to Consider In December 2025, in response to the Sha1-Hulud incident, npm completed amajor authentication overhaulintended t</description>
    </item>
    <item>
      <title>Cybersecurity founders: Apply now for the Google for Startups Gemini Startup Forum.</title>
      <link>https://cluster-site.onrender.com/posts/cybersecurity-founders-apply-now-for-the-google-for-startups-gemini-startup-forum./</link>
      <pubDate>Fri, 13 Feb 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cybersecurity-founders-apply-now-for-the-google-for-startups-gemini-startup-forum./</guid>
      <description>• Appy now for our two-day, London-based forum supporting innovative cyber defenders. • Building on the success of previous cybersecurity programs (alumni of which includeBforeAI,P</description>
    </item>
    <item>
      <title>&amp;#x26;#xa;AI-Powered Knowledge Graph Generator &amp;#x26; APTs, (Thu, Feb 12th)</title>
      <link>https://cluster-site.onrender.com/posts/%23x26%23xaai-powered-knowledge-graph-generator-%23x26-apts-thu-feb-12th/</link>
      <pubDate>Fri, 13 Feb 2026 03:04:48 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/%23x26%23xaai-powered-knowledge-graph-generator-%23x26-apts-thu-feb-12th/</guid>
      <description>• AI-Powered Knowledge Graph Generator &amp;amp; APTs Unstructured text to interactive knowledge graph via LLM &amp;amp; SPO triplet extraction Courtesy of TLDR InfoSec Launches &amp;amp; Tools again, ano</description>
    </item>
    <item>
      <title>Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again</title>
      <link>https://cluster-site.onrender.com/posts/ivanti-epmm-zero-day-bugs-spark-exploit-frenzy-again/</link>
      <pubDate>Thu, 12 Feb 2026 22:05:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ivanti-epmm-zero-day-bugs-spark-exploit-frenzy-again/</guid>
      <description>• Endpoint Security Cyberattacks &amp;amp; Data Breaches Vulnerabilities &amp;amp; Threats Perimeter News Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again It&amp;rsquo;s time to phase out the &amp;lsquo;patch a</description>
    </item>
    <item>
      <title>Booz Allen Announces General Availability of Vellox Reverser to Automate Malware Defense</title>
      <link>https://cluster-site.onrender.com/posts/booz-allen-announces-general-availability-of-vellox-reverser-to-automate-malware-defense/</link>
      <pubDate>Thu, 12 Feb 2026 21:23:06 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/booz-allen-announces-general-availability-of-vellox-reverser-to-automate-malware-defense/</guid>
      <description>• The AI-powered product delivers expert-grade malware analysis and reverse engineering in minutes.</description>
    </item>
    <item>
      <title>SpecterOps Launches BloodHound Scentry to Accelerate the Practice of Identity Attack Path Management</title>
      <link>https://cluster-site.onrender.com/posts/specterops-launches-bloodhound-scentry-to-accelerate-the-practice-of-identity-attack-path-management/</link>
      <pubDate>Thu, 12 Feb 2026 21:11:52 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/specterops-launches-bloodhound-scentry-to-accelerate-the-practice-of-identity-attack-path-management/</guid>
      <description>• Drawing on years of adversary tradecraft, SpecterOps experts work alongside customers to analyze and eliminate attack paths, protect critical assets, and stay ahead of emerging t</description>
    </item>
    <item>
      <title>Gone With the Shame: One in Two Americans Are Reluctant to Talk About Romance Scam Incidents</title>
      <link>https://cluster-site.onrender.com/posts/gone-with-the-shame-one-in-two-americans-are-reluctant-to-talk-about-romance-scam-incidents/</link>
      <pubDate>Thu, 12 Feb 2026 21:04:25 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/gone-with-the-shame-one-in-two-americans-are-reluctant-to-talk-about-romance-scam-incidents/</guid>
      <description>• Men should take extra care on Valentine&amp;rsquo;s Day because they are nearly twice as likely as women to fall victim to romance scams.</description>
    </item>
    <item>
      <title>Those &#39;Summarize With AI&#39; Buttons May Be Lying to You</title>
      <link>https://cluster-site.onrender.com/posts/those-summarize-with-ai-buttons-may-be-lying-to-you/</link>
      <pubDate>Thu, 12 Feb 2026 20:47:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/those-summarize-with-ai-buttons-may-be-lying-to-you/</guid>
      <description>• Microsoft uncovered AI recommendation poisoning in 31 companies across 14 industries, and turnkey tools make it trivially easy to pull off.</description>
    </item>
    <item>
      <title>Copilot Studio agent security: Top 10 risks you can detect and prevent</title>
      <link>https://cluster-site.onrender.com/posts/copilot-studio-agent-security-top-10-risks-you-can-detect-and-prevent/</link>
      <pubDate>Thu, 12 Feb 2026 20:38:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/copilot-studio-agent-security-top-10-risks-you-can-detect-and-prevent/</guid>
      <description>• Organizations are rapidly adopting Copilot Studio agents, but threat actors are equally fast at exploiting misconfigured AI workflows. • Mis-sharing, unsafe orchestration, and we</description>
    </item>
    <item>
      <title>Detecting and mitigating common agent misconfigurations</title>
      <link>https://cluster-site.onrender.com/posts/detecting-and-mitigating-common-agent-misconfigurations/</link>
      <pubDate>Thu, 12 Feb 2026 20:38:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/detecting-and-mitigating-common-agent-misconfigurations/</guid>
      <description>• Organizations are rapidly adopting agents, but attackers are equally fast at exploiting misconfigured AI workflows. • Mis-sharing, unsafe orchestration, and weak authentication c</description>
    </item>
    <item>
      <title>Top 10 actions to build agents securely with Microsoft Copilot Studio</title>
      <link>https://cluster-site.onrender.com/posts/top-10-actions-to-build-agents-securely-with-microsoft-copilot-studio/</link>
      <pubDate>Thu, 12 Feb 2026 20:38:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/top-10-actions-to-build-agents-securely-with-microsoft-copilot-studio/</guid>
      <description>• Organizations are rapidly adopting Copilot Studio agents, but threat actors are equally fast at exploiting misconfigured AI workflows. • Mis-sharing, unsafe orchestration, and we</description>
    </item>
    <item>
      <title>Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support</title>
      <link>https://cluster-site.onrender.com/posts/google-reports-state-backed-hackers-using-gemini-ai-for-recon-and-attack-support/</link>
      <pubDate>Thu, 12 Feb 2026 17:57:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/google-reports-state-backed-hackers-using-gemini-ai-for-recon-and-attack-support/</guid>
      <description>• Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support Google on Thursday said it observed the North Korea-linked threat actor known asUNC2970using its</description>
    </item>
    <item>
      <title>Fleet cybersecurity funding to see &#39;increased investment&#39; in FY27 budget request: Navy official</title>
      <link>https://cluster-site.onrender.com/posts/fleet-cybersecurity-funding-to-see-increased-investment-in-fy27-budget-request-navy-official/</link>
      <pubDate>Thu, 12 Feb 2026 17:39:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fleet-cybersecurity-funding-to-see-increased-investment-in-fy27-budget-request-navy-official/</guid>
      <description>• WEST 2026 - The Navy&amp;rsquo;s upcoming budget request will include a focused pot of money to increase cybersecurity aboard the fleet, the department&amp;rsquo;s principal cyber adviser told Break</description>
    </item>
    <item>
      <title>Your complete guide to Microsoft experiences at RSAC™ 2026 Conference</title>
      <link>https://cluster-site.onrender.com/posts/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/</link>
      <pubDate>Thu, 12 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/</guid>
      <description>• The era of AI is reshaping both opportunity and risk faster than any shift security leaders have seen. • Every organization is feeling the momentum; and for security teams, the q</description>
    </item>
    <item>
      <title>Your complete guide to Microsoft experiences at RSAC™ 2026 Conference</title>
      <link>https://cluster-site.onrender.com/posts/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/</link>
      <pubDate>Thu, 12 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/</guid>
      <description>• The era of AI is reshaping both opportunity and risk faster than any shift security leaders have seen. • Every organization is feeling the momentum; and for security teams, the q</description>
    </item>
    <item>
      <title>Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems</title>
      <link>https://cluster-site.onrender.com/posts/lazarus-campaign-plants-malicious-packages-in-npm-and-pypi-ecosystems/</link>
      <pubDate>Thu, 12 Feb 2026 16:55:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/lazarus-campaign-plants-malicious-packages-in-npm-and-pypi-ecosystems/</guid>
      <description>• Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign</description>
    </item>
    <item>
      <title>3D Printer Surveillance</title>
      <link>https://cluster-site.onrender.com/posts/3d-printer-surveillance/</link>
      <pubDate>Thu, 12 Feb 2026 12:01:31 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/3d-printer-surveillance/</guid>
      <description>• NY&amp;rsquo;s 2026-27 budget bill mandates 3D printers to include blocking tech that blocks firearm designs. • The algorithm scans every print file, refusing prints flagged as potential f</description>
    </item>
    <item>
      <title>The CTEM Divide: Why 84% of Security Programs Are Falling Behind</title>
      <link>https://cluster-site.onrender.com/posts/the-ctem-divide-why-84-of-security-programs-are-falling-behind/</link>
      <pubDate>Thu, 12 Feb 2026 10:30:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-ctem-divide-why-84-of-security-programs-are-falling-behind/</guid>
      <description>• The CTEM Divide: Why 84% of Security Programs Are Falling Behind A new 2026 market intelligence study of 128 enterprise security decision-makers (available here) reveals a stark</description>
    </item>
    <item>
      <title>Senegalese Data Breaches Expose Lack of Security Maturity</title>
      <link>https://cluster-site.onrender.com/posts/senegalese-data-breaches-expose-lack-of-security-maturity/</link>
      <pubDate>Thu, 12 Feb 2026 09:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/senegalese-data-breaches-expose-lack-of-security-maturity/</guid>
      <description>• Cyberattacks &amp;amp; Data Breaches Cyber Risk Data Privacy Cybersecurity Operations News Breaking cybersecurity news, news analysis, commentary, and other content from around the world</description>
    </item>
    <item>
      <title>Criminals are using AI website builders to clone major brands</title>
      <link>https://cluster-site.onrender.com/posts/criminals-are-using-ai-website-builders-to-clone-major-brands/</link>
      <pubDate>Thu, 12 Feb 2026 08:03:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/criminals-are-using-ai-website-builders-to-clone-major-brands/</guid>
      <description>• Cybercriminals use AI website builders like Vercel to clone trusted brands in minutes. • Cheap, fast domain registration lets attackers register plausible brand‑lookalike names w</description>
    </item>
    <item>
      <title>Bypassing Administrator Protection by Abusing UI Access</title>
      <link>https://cluster-site.onrender.com/posts/bypassing-administrator-protection-by-abusing-ui-access/</link>
      <pubDate>Thu, 12 Feb 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/bypassing-administrator-protection-by-abusing-ui-access/</guid>
      <description>• In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didnât exist. • I described one</description>
    </item>
    <item>
      <title>83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/83-of-ivanti-epmm-exploits-linked-to-single-ip-on-bulletproof-hosting-infrastructure/</link>
      <pubDate>Thu, 12 Feb 2026 07:32:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/83-of-ivanti-epmm-exploits-linked-to-single-ip-on-bulletproof-hosting-infrastructure/</guid>
      <description>• 83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure A significant chunk of the exploitation attempts targeting a newly disclosed security flaw i</description>
    </item>
    <item>
      <title>ISC Stormcast For Thursday, February 12th, 2026 https://isc.sans.edu/podcastdetail/9806, (Thu, Feb 12th)</title>
      <link>https://cluster-site.onrender.com/posts/isc-stormcast-for-thursday-february-12th-2026-https/isc.sans.edu/podcastdetail/9806-thu-feb-12th/</link>
      <pubDate>Thu, 12 Feb 2026 02:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/isc-stormcast-for-thursday-february-12th-2026-https/isc.sans.edu/podcastdetail/9806-thu-feb-12th/</guid>
      <description>• ISC Stormcast For Thursday, February 12th, 2026 &lt;a href=&#34;https://isc.sans.edu/podcastdetail/9806&#34; target=&#34;_blank&#34; rel=&#34;nofollow noopener noreferrer&#34;&gt;https://isc.sans.edu/podcastdetail/9806&lt;/a&gt;
 Handler on Duty: Guy Bruneau Threat Level: green My next class: Application Security: Secu</description>
    </item>
    <item>
      <title>Four Seconds to Botnet - Analyzing a Self Propagating SSH Worm with Cryptographically Signed C2 &amp;#x5b;Guest Diary&amp;#x5d;, (Wed, Feb 11th)</title>
      <link>https://cluster-site.onrender.com/posts/four-seconds-to-botnet-analyzing-a-self-propagating-ssh-worm-with-cryptographically-signed-c2-%23x5bguest-diary%23x5d-wed-feb-11th/</link>
      <pubDate>Thu, 12 Feb 2026 01:56:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/four-seconds-to-botnet-analyzing-a-self-propagating-ssh-worm-with-cryptographically-signed-c2-%23x5bguest-diary%23x5d-wed-feb-11th/</guid>
      <description>• SSH worm exploited weak passwords, compromising Linux systems in seconds. • Attack used credential brute force, uploading a 4.7 KB bash script via SCP. • Script established persi</description>
    </item>
    <item>
      <title>Nation-State Actors Exploit Notepad&#43;&#43; Supply Chain</title>
      <link>https://cluster-site.onrender.com/posts/nation-state-actors-exploit-notepad-supply-chain/</link>
      <pubDate>Wed, 11 Feb 2026 23:00:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nation-state-actors-exploit-notepad-supply-chain/</guid>
      <description>• Executive Summary Between June and December 2025, the official hosting infrastructure for the text editor Notepad++ was compromised by a state-sponsored threat group known as Lot</description>
    </item>
    <item>
      <title>North Korea&#39;s UNC1069 Hammers Crypto Firms With AI</title>
      <link>https://cluster-site.onrender.com/posts/north-koreas-unc1069-hammers-crypto-firms-with-ai/</link>
      <pubDate>Wed, 11 Feb 2026 21:56:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/north-koreas-unc1069-hammers-crypto-firms-with-ai/</guid>
      <description>• In moving away from traditional banks to focus on Web3 companies, the threat actor is leveraging LLMs, deepfakes, legitimate platforms, and ClickFix.</description>
    </item>
    <item>
      <title>How to Stay on Top of Future Threats With a Cutting-Edge SOC</title>
      <link>https://cluster-site.onrender.com/posts/how-to-stay-on-top-of-future-threats-with-a-cutting-edge-soc/</link>
      <pubDate>Wed, 11 Feb 2026 20:36:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-to-stay-on-top-of-future-threats-with-a-cutting-edge-soc/</guid>
      <description>• CISOs should focus on harnessing and securing AI and building new skills among their people. • Vision and change management can transform security.</description>
    </item>
    <item>
      <title>Apple Patches Everything: February 2026, (Wed, Feb 11th)</title>
      <link>https://cluster-site.onrender.com/posts/apple-patches-everything-february-2026-wed-feb-11th/</link>
      <pubDate>Wed, 11 Feb 2026 19:36:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/apple-patches-everything-february-2026-wed-feb-11th/</guid>
      <description>• Apple Patches Everything: February 2026 Today, Apple released updates for all of its operating systems (iOS, iPadOS, macOS, tvOS, watchOS, and visionOS). • The update fixes 71 di</description>
    </item>
    <item>
      <title>Automaker Secures the Supply Chain With Developer-Friendly Platform</title>
      <link>https://cluster-site.onrender.com/posts/automaker-secures-the-supply-chain-with-developer-friendly-platform/</link>
      <pubDate>Wed, 11 Feb 2026 19:35:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/automaker-secures-the-supply-chain-with-developer-friendly-platform/</guid>
      <description>• How a platform engineering team embeds supply chain security into infrastructure without slowing developers.</description>
    </item>
    <item>
      <title>The strategic SIEM buyer&#39;s guide: Choosing an AI-ready platform for the agentic era</title>
      <link>https://cluster-site.onrender.com/posts/the-strategic-siem-buyers-guide-choosing-an-ai-ready-platform-for-the-agentic-era/</link>
      <pubDate>Wed, 11 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-strategic-siem-buyers-guide-choosing-an-ai-ready-platform-for-the-agentic-era/</guid>
      <description>• Share Link copied to clipboard! • Content types Best practices Topics AI and agents Security operations SIEM and XDR As the agentic era reshapes security operations, leaders face</description>
    </item>
    <item>
      <title>Kimwolf Botnet Swamps Anonymity Network I2P</title>
      <link>https://cluster-site.onrender.com/posts/kimwolf-botnet-swamps-anonymity-network-i2p/</link>
      <pubDate>Wed, 11 Feb 2026 16:08:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/kimwolf-botnet-swamps-anonymity-network-i2p/</guid>
      <description>• Kimwolf botnet infected millions of IoT devices, turning them into relays for malicious traffic. • In late 2025, the botnet began targeting I2P to hide control servers from taked</description>
    </item>
    <item>
      <title>AI Rising: Do We Know Enough About the Data Populating It?</title>
      <link>https://cluster-site.onrender.com/posts/ai-rising-do-we-know-enough-about-the-data-populating-it/</link>
      <pubDate>Wed, 11 Feb 2026 14:31:47 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-rising-do-we-know-enough-about-the-data-populating-it/</guid>
      <description>• Organizations remain reluctant to address the fact that AI can dangerously expose business operations as well as personal data.</description>
    </item>
    <item>
      <title>The game is over: when &#39;free&#39; comes at too high a price. What we know about RenEngine</title>
      <link>https://cluster-site.onrender.com/posts/the-game-is-over-when-free-comes-at-too-high-a-price.-what-we-know-about-renengine/</link>
      <pubDate>Wed, 11 Feb 2026 14:00:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-game-is-over-when-free-comes-at-too-high-a-price.-what-we-know-about-renengine/</guid>
      <description>• Table of Contents Incident analysis Disguise as a visual novel &amp;lsquo;Game&amp;rsquo; source files analysis HijackLoader Not only games Distribution Recommendations for protection Indicators of</description>
    </item>
    <item>
      <title>Top Cyber Industry Defenses Spike CO2 Emissions</title>
      <link>https://cluster-site.onrender.com/posts/top-cyber-industry-defenses-spike-co2-emissions/</link>
      <pubDate>Wed, 11 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/top-cyber-industry-defenses-spike-co2-emissions/</guid>
      <description>• Organizations can improve their climate footprints by optimizing two specific cybersecurity protections, without incurring added risks.</description>
    </item>
    <item>
      <title>WSL in the Malware Ecosystem, (Wed, Feb 11th)</title>
      <link>https://cluster-site.onrender.com/posts/wsl-in-the-malware-ecosystem-wed-feb-11th/</link>
      <pubDate>Wed, 11 Feb 2026 13:28:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wsl-in-the-malware-ecosystem-wed-feb-11th/</guid>
      <description>• WSL lets users run a full Linux environment inside Windows, eliminating need for VMs or dual boot. • WSL2&amp;rsquo;s lightweight virtualized kernel boosts compatibility and performance fo</description>
    </item>
    <item>
      <title>Prompt Injection Via Road Signs</title>
      <link>https://cluster-site.onrender.com/posts/prompt-injection-via-road-signs/</link>
      <pubDate>Wed, 11 Feb 2026 12:03:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/prompt-injection-via-road-signs/</guid>
      <description>• Prompt Injection Via Road Signs Interesting research: &amp;lsquo;CHAI: Command Hijacking Against Embodied AI.&amp;rsquo; Abstract: Embodied Artificial Intelligence (AI) promises to handle edge cases</description>
    </item>
    <item>
      <title>CISA&#39;s 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/cisas-2025-year-in-review-driving-security-and-resilience-across-critical-infrastructure/</link>
      <pubDate>Wed, 11 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisas-2025-year-in-review-driving-security-and-resilience-across-critical-infrastructure/</guid>
      <description>• CISA&amp;rsquo;s 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) unveiled its20</description>
    </item>
    <item>
      <title>Spam and phishing in 2025</title>
      <link>https://cluster-site.onrender.com/posts/spam-and-phishing-in-2025/</link>
      <pubDate>Wed, 11 Feb 2026 10:00:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spam-and-phishing-in-2025/</guid>
      <description>• The year in figures - 44.99% of all emails sent worldwide and 43.27% of all emails sent in the Russian web segment were spam - 32.50% of all spam emails were sent from Russia - K</description>
    </item>
    <item>
      <title>Asia Fumbles With Throttling Back Telnet Traffic in Region</title>
      <link>https://cluster-site.onrender.com/posts/asia-fumbles-with-throttling-back-telnet-traffic-in-region/</link>
      <pubDate>Wed, 11 Feb 2026 02:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/asia-fumbles-with-throttling-back-telnet-traffic-in-region/</guid>
      <description>• Only Taiwan made the top 10 list of governments, effectively blocking the threat-ridden protocol, but overall, the region lagged in curbing Telnet traffic.</description>
    </item>
    <item>
      <title>A Peek Into Muddled Libra&#39;s Operational Playbook</title>
      <link>https://cluster-site.onrender.com/posts/a-peek-into-muddled-libras-operational-playbook/</link>
      <pubDate>Tue, 10 Feb 2026 23:00:41 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-peek-into-muddled-libras-operational-playbook/</guid>
      <description>• Executive Summary During a September 2025 incident response investigation, Unit 42 discovered a rogue virtual machine (VM) which we believe with high confidence to be used by the</description>
    </item>
    <item>
      <title>SolarWinds WHD Attacks Highlight Risks of Exposed Apps</title>
      <link>https://cluster-site.onrender.com/posts/solarwinds-whd-attacks-highlight-risks-of-exposed-apps/</link>
      <pubDate>Tue, 10 Feb 2026 22:00:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/solarwinds-whd-attacks-highlight-risks-of-exposed-apps/</guid>
      <description>• Organizations that have exposed their instances of Web Help Desk to the public Internet have inadvertently made them prime targets for attackers.</description>
    </item>
    <item>
      <title>In Bypassing MFA, ZeroDayRAT Is &#39;Textbook Stalkerware&#39;</title>
      <link>https://cluster-site.onrender.com/posts/in-bypassing-mfa-zerodayrat-is-textbook-stalkerware/</link>
      <pubDate>Tue, 10 Feb 2026 21:37:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/in-bypassing-mfa-zerodayrat-is-textbook-stalkerware/</guid>
      <description>• With access to SIM, location data, and a preview of recent SMSes, attackers have everything they need for account takeover or targeted social engineering.</description>
    </item>
    <item>
      <title>80% of Fortune 500 use active AI Agents: Observability, governance, and security shape the new frontier</title>
      <link>https://cluster-site.onrender.com/posts/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/</link>
      <pubDate>Tue, 10 Feb 2026 16:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier/</guid>
      <description>• Today, Microsoft is releasing the new Cyber Pulse report to provide leaders with straightforward, practical insights and guidance on new cybersecurity risks. • One of today&amp;rsquo;s mos</description>
    </item>
    <item>
      <title>Manipulating AI memory for profit: The rise of AI Recommendation Poisoning</title>
      <link>https://cluster-site.onrender.com/posts/manipulating-ai-memory-for-profit-the-rise-of-ai-recommendation-poisoning/</link>
      <pubDate>Tue, 10 Feb 2026 14:56:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/manipulating-ai-memory-for-profit-the-rise-of-ai-recommendation-poisoning/</guid>
      <description>• That helpful &amp;lsquo;Summarize with AI&amp;rsquo; button? • It might be secretly manipulating what your AI recommends. • Microsoft security researchers have discovered a growing trend of AI memor</description>
    </item>
    <item>
      <title>AI-Generated Text and the Detection Arms Race</title>
      <link>https://cluster-site.onrender.com/posts/ai-generated-text-and-the-detection-arms-race/</link>
      <pubDate>Tue, 10 Feb 2026 12:03:50 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ai-generated-text-and-the-detection-arms-race/</guid>
      <description>• AI-Generated Text and the Detection Arms Race In 2023, the science fiction literary magazine Clarkesworld stopped accepting new submissions because so many were generated by arti</description>
    </item>
    <item>
      <title>CISA Releases Guide to Help Critical Infrastructure Users Adopt More Secure Communication</title>
      <link>https://cluster-site.onrender.com/posts/cisa-releases-guide-to-help-critical-infrastructure-users-adopt-more-secure-communication/</link>
      <pubDate>Tue, 10 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-releases-guide-to-help-critical-infrastructure-users-adopt-more-secure-communication/</guid>
      <description>• CISA Releases Guide to Help Critical Infrastructure Users Adopt More Secure Communication WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today released</description>
    </item>
    <item>
      <title>A one-prompt attack that breaks LLM safety alignment</title>
      <link>https://cluster-site.onrender.com/posts/a-one-prompt-attack-that-breaks-llm-safety-alignment/</link>
      <pubDate>Mon, 09 Feb 2026 17:12:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-one-prompt-attack-that-breaks-llm-safety-alignment/</guid>
      <description>• Share Link copied to clipboard! • Content types Research Topics Actionable threat insights AI and agents Security management Large language models (LLMs) and diffusion models now</description>
    </item>
    <item>
      <title>9th February - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/9th-february-threat-intelligence-report/</link>
      <pubDate>Mon, 09 Feb 2026 12:50:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/9th-february-threat-intelligence-report/</guid>
      <description>• Conpet pipeline attack disrupted IT but not operations. • Qilin ransomware group claimed responsibility. • Check Point Harmony protects against this threat. • Report covers recen</description>
    </item>
    <item>
      <title>LLMs are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days</title>
      <link>https://cluster-site.onrender.com/posts/llms-are-getting-a-lot-better-and-faster-at-finding-and-exploiting-zero-days/</link>
      <pubDate>Mon, 09 Feb 2026 12:04:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/llms-are-getting-a-lot-better-and-faster-at-finding-and-exploiting-zero-days/</guid>
      <description>• LLMs are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days This is amazing: Opus 4.6 is notably better at finding high-severity vulnerabilities than previous mo</description>
    </item>
    <item>
      <title>Analysis of active exploitation of SolarWinds Web Help Desk</title>
      <link>https://cluster-site.onrender.com/posts/analysis-of-active-exploitation-of-solarwinds-web-help-desk/</link>
      <pubDate>Sat, 07 Feb 2026 01:08:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/analysis-of-active-exploitation-of-solarwinds-web-help-desk/</guid>
      <description>• The Microsoft Defender Research Team observed a multi‑stage intrusion where threat actors exploited internet‑exposed SolarWinds Web Help Desk (WHD) instances to get an initial fo</description>
    </item>
    <item>
      <title>Novel Technique to Detect Cloud Threat Actor Operations</title>
      <link>https://cluster-site.onrender.com/posts/novel-technique-to-detect-cloud-threat-actor-operations/</link>
      <pubDate>Fri, 06 Feb 2026 23:00:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/novel-technique-to-detect-cloud-threat-actor-operations/</guid>
      <description>• Executive Summary Cloud-based alerting systems often struggle to distinguish between normal cloud activity and targeted malicious operations by known threat actors. • The difficu</description>
    </item>
    <item>
      <title>New Clickfix variant &#39;CrashFix&#39; deploying Python Remote Access Trojan</title>
      <link>https://cluster-site.onrender.com/posts/new-clickfix-variant-crashfix-deploying-python-remote-access-trojan/</link>
      <pubDate>Thu, 05 Feb 2026 18:51:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/new-clickfix-variant-crashfix-deploying-python-remote-access-trojan/</guid>
      <description>• In January 2026, Microsoft Defender Experts identified a new evolution in the ongoing ClickFix campaign. • This updated tactic deliberately crashes victims&amp;rsquo; browsers and then att</description>
    </item>
    <item>
      <title>The security implementation gap: Why Microsoft is supporting Operation Winter SHIELD</title>
      <link>https://cluster-site.onrender.com/posts/the-security-implementation-gap-why-microsoft-is-supporting-operation-winter-shield/</link>
      <pubDate>Thu, 05 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-security-implementation-gap-why-microsoft-is-supporting-operation-winter-shield/</guid>
      <description>• Share Link copied to clipboard! • Content types News Topics Office of the CISO Security management Security operations Every conversation I have with information security leaders</description>
    </item>
    <item>
      <title>2025 Q4 DDoS threat report: A record-setting 31.4 Tbps attack caps a year of massive DDoS assaults</title>
      <link>https://cluster-site.onrender.com/posts/2025-q4-ddos-threat-report-a-record-setting-31.4-tbps-attack-caps-a-year-of-massive-ddos-assaults/</link>
      <pubDate>Thu, 05 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/2025-q4-ddos-threat-report-a-record-setting-31.4-tbps-attack-caps-a-year-of-massive-ddos-assaults/</guid>
      <description>• 2025 saw 47.1 million DDoS attacks, a 236% rise since 2023. • Cloudflare mitigated 5,376 attacks per hour, 3,925 network‑layer, 1,451 HTTP. • Network‑layer attacks tripled to 34.</description>
    </item>
    <item>
      <title>CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats</title>
      <link>https://cluster-site.onrender.com/posts/cisa-orders-federal-agencies-to-strengthen-edge-device-security-amid-rising-cyber-threats/</link>
      <pubDate>Thu, 05 Feb 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-orders-federal-agencies-to-strengthen-edge-device-security-amid-rising-cyber-threats/</guid>
      <description>• CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today issuedBin</description>
    </item>
    <item>
      <title>The Shadow Campaigns: Uncovering Global Espionage</title>
      <link>https://cluster-site.onrender.com/posts/the-shadow-campaigns-uncovering-global-espionage/</link>
      <pubDate>Thu, 05 Feb 2026 11:00:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-shadow-campaigns-uncovering-global-espionage/</guid>
      <description>• Executive Summary This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. • We refer to the group&amp;rsquo;s activity as the Shadow Campaigns. • We asse</description>
    </item>
    <item>
      <title>Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT</title>
      <link>https://cluster-site.onrender.com/posts/stan-ghouls-targeting-russia-and-uzbekistan-with-netsupport-rat/</link>
      <pubDate>Thu, 05 Feb 2026 09:00:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/stan-ghouls-targeting-russia-and-uzbekistan-with-netsupport-rat/</guid>
      <description>• Introduction Stan Ghouls (also known as Bloody Wolf) is an cybercriminal group that has been launching targeted attacks against organizations in Russia, Kyrgyzstan, Kazakhstan, a</description>
    </item>
    <item>
      <title>Detecting backdoored language models at scale</title>
      <link>https://cluster-site.onrender.com/posts/detecting-backdoored-language-models-at-scale/</link>
      <pubDate>Wed, 04 Feb 2026 17:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/detecting-backdoored-language-models-at-scale/</guid>
      <description>• Today, we are releasing new research on detecting backdoors in open-weight language models. • Our research highlights several key properties of language model backdoors, laying t</description>
    </item>
    <item>
      <title>From guardrails to governance: A CEO&#39;s guide for securing agentic systems</title>
      <link>https://cluster-site.onrender.com/posts/from-guardrails-to-governance-a-ceos-guide-for-securing-agentic-systems/</link>
      <pubDate>Wed, 04 Feb 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/from-guardrails-to-governance-a-ceos-guide-for-securing-agentic-systems/</guid>
      <description>• Treat AI agents as semi‑autonomous users, enforcing rules at identity, tool, data, and output boundaries. • Assign narrow job scopes and run agents under user‑level identities, l</description>
    </item>
    <item>
      <title>Why Smart People Fall For Phishing Attacks</title>
      <link>https://cluster-site.onrender.com/posts/why-smart-people-fall-for-phishing-attacks/</link>
      <pubDate>Wed, 04 Feb 2026 00:00:43 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/why-smart-people-fall-for-phishing-attacks/</guid>
      <description>• Threat Research Center Insights Opinions Why Smart People Fall For Phishing Attacks By:Ria Bhatia Ria Bhatia Published:February 3, 2026 Categories:Business Email CompromiseCyberc</description>
    </item>
    <item>
      <title>PP095: OT and ICS - Where Digital and Physical Risks Meet</title>
      <link>https://cluster-site.onrender.com/posts/pp095-ot-and-ics-where-digital-and-physical-risks-meet/</link>
      <pubDate>Tue, 03 Feb 2026 19:04:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pp095-ot-and-ics-where-digital-and-physical-risks-meet/</guid>
      <description>• OT &amp;amp; ICs bridge digital and physical, powering critical infrastructure like nuclear plants and water systems. • Rising attacks target OT/ICS, demanding robust threat awareness an</description>
    </item>
    <item>
      <title>The Notepad&#43;&#43; supply chain attack - unnoticed execution chains and new IoCs</title>
      <link>https://cluster-site.onrender.com/posts/the-notepad-supply-chain-attack-unnoticed-execution-chains-and-new-iocs/</link>
      <pubDate>Tue, 03 Feb 2026 08:10:06 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-notepad-supply-chain-attack-unnoticed-execution-chains-and-new-iocs/</guid>
      <description>• UPD 11.02.2026: added recommendations on how to use the Notepad++ supply chain attack rules package in our SIEM system. • Introduction On February 2, 2026, the developers of Note</description>
    </item>
    <item>
      <title>Please Don&#39;t Feed the Scattered Lapsus ShinyHunters</title>
      <link>https://cluster-site.onrender.com/posts/please-dont-feed-the-scattered-lapsus-shinyhunters/</link>
      <pubDate>Mon, 02 Feb 2026 16:15:16 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/please-dont-feed-the-scattered-lapsus-shinyhunters/</guid>
      <description>• Scattered Lapsus ShinyHunters (SLSH) uses harassment, threats, even swatting to extort firms. • They notify journalists and regulators, amplifying pressure beyond typical ransomw</description>
    </item>
    <item>
      <title>Privileged File System Vulnerability Present in a SCADA System</title>
      <link>https://cluster-site.onrender.com/posts/privileged-file-system-vulnerability-present-in-a-scada-system/</link>
      <pubDate>Fri, 30 Jan 2026 23:00:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/privileged-file-system-vulnerability-present-in-a-scada-system/</guid>
      <description>• Iconics Suite SCADA system vulnerable (CVE-2025-0921) allows privilege escalation via unnecessary file system operations. • Exploitation can corrupt critical binaries, leading to</description>
    </item>
    <item>
      <title>Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529</title>
      <link>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</link>
      <pubDate>Fri, 30 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</guid>
      <description>• CVE-2024-54529: type confusion in CoreAudio&amp;rsquo;s com.apple.audio.audiohald Mach service, causing crashes. • Exploitation involved manipulating Mach messages to fetch wrong HALS_Obje</description>
    </item>
    <item>
      <title>Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529</title>
      <link>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</link>
      <pubDate>Fri, 30 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</guid>
      <description>• In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-f</description>
    </item>
    <item>
      <title>Understanding the Russian Cyberthreat to the 2026 Winter Olympics</title>
      <link>https://cluster-site.onrender.com/posts/understanding-the-russian-cyberthreat-to-the-2026-winter-olympics/</link>
      <pubDate>Thu, 29 Jan 2026 21:30:47 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/understanding-the-russian-cyberthreat-to-the-2026-winter-olympics/</guid>
      <description>• Threat Research Center Insights Opinions Understanding the Russian Cyberthreat to the 2026 Winter Olympics By:Justin Moore Justin Moore Published:January 29, 2026 Categories:Cybe</description>
    </item>
    <item>
      <title>Supply chain attack on eScan antivirus: detecting and remediating malicious updates</title>
      <link>https://cluster-site.onrender.com/posts/supply-chain-attack-on-escan-antivirus-detecting-and-remediating-malicious-updates/</link>
      <pubDate>Thu, 29 Jan 2026 15:07:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/supply-chain-attack-on-escan-antivirus-detecting-and-remediating-malicious-updates/</guid>
      <description>• UPD 30.01.2026: Added technical details about the attack chain and more IoCs. • On January 20, a supply chain attack has occurred, with the infected software being the eScan anti</description>
    </item>
    <item>
      <title>CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats</title>
      <link>https://cluster-site.onrender.com/posts/cisa-urges-critical-infrastructure-organizations-to-take-action-against-insider-threats/</link>
      <pubDate>Wed, 28 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-urges-critical-infrastructure-organizations-to-take-action-against-insider-threats/</guid>
      <description>• CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) is calling on cri</description>
    </item>
    <item>
      <title>Rust at Scale: An Added Layer of Security for WhatsApp</title>
      <link>https://cluster-site.onrender.com/posts/rust-at-scale-an-added-layer-of-security-for-whatsapp/</link>
      <pubDate>Tue, 27 Jan 2026 15:00:09 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/rust-at-scale-an-added-layer-of-security-for-whatsapp/</guid>
      <description>• WhatsApp introduces Rust-based security layer to protect billions of users from malware threats. • The new media consistency library, written in Rust, runs on devices and browser</description>
    </item>
    <item>
      <title>Building a serverless, post-quantum Matrix homeserver</title>
      <link>https://cluster-site.onrender.com/posts/building-a-serverless-post-quantum-matrix-homeserver/</link>
      <pubDate>Tue, 27 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/building-a-serverless-post-quantum-matrix-homeserver/</guid>
      <description>• Ported Synapse Matrix homeserver to Cloudflare Workers, creating a fully serverless architecture. • Eliminated heavy operational costs: no VPS, PostgreSQL tuning, Redis, reverse</description>
    </item>
    <item>
      <title>Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088</title>
      <link>https://cluster-site.onrender.com/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088/</link>
      <pubDate>Tue, 27 Jan 2026 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/diverse-threat-actors-exploiting-critical-winrar-vulnerability-cve-2025-8088/</guid>
      <description>• CVE-2025-8088: critical path traversal flaw in WinRAR allows arbitrary file writes via ADS. • Exploited by state-backed actors from Russia, China and financially motivated groups</description>
    </item>
    <item>
      <title>Celebrating Data Privacy Week with NIST&#39;s Privacy Engineering Program</title>
      <link>https://cluster-site.onrender.com/posts/celebrating-data-privacy-week-with-nists-privacy-engineering-program/</link>
      <pubDate>Tue, 27 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/celebrating-data-privacy-week-with-nists-privacy-engineering-program/</guid>
      <description>• Data Privacy Week celebrates global awareness, led by the National Cybersecurity Alliance. • NIST&amp;rsquo;s Privacy Engineering Program plans 2026 privacy risk management guidelines. • P</description>
    </item>
    <item>
      <title>Spy vs spy at scale</title>
      <link>https://cluster-site.onrender.com/posts/spy-vs-spy-at-scale/</link>
      <pubDate>Tue, 27 Jan 2026 08:40:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/spy-vs-spy-at-scale/</guid>
      <description>• AI reshapes espionage, intensifying global intelligence rivalry and prompting new defensive strategies. • China&amp;rsquo;s tech surge fuels new espionage tactics and countermeasures, resh</description>
    </item>
    <item>
      <title>HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns</title>
      <link>https://cluster-site.onrender.com/posts/honeymyte-updates-coolclient-and-deploys-multiple-stealers-in-recent-campaigns/</link>
      <pubDate>Tue, 27 Jan 2026 08:00:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/honeymyte-updates-coolclient-and-deploys-multiple-stealers-in-recent-campaigns/</guid>
      <description>• HoneyMyte upgraded CoolClient backdoor with new features, enhancing persistence and stealth. • The group deployed multiple browser login data stealers across recent campaigns. •</description>
    </item>
    <item>
      <title>Who Operates the Badbox 2.0 Botnet?</title>
      <link>https://cluster-site.onrender.com/posts/who-operates-the-badbox-2.0-botnet/</link>
      <pubDate>Mon, 26 Jan 2026 16:11:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/who-operates-the-badbox-2.0-botnet/</guid>
      <description>• Kimwolf botnet, 2M infected devices, compromised Badbox 2.0 control panel screenshot. • Badbox 2.0: China-based botnet on Android TV streaming boxes, over ten million devices, us</description>
    </item>
    <item>
      <title>26th January - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/26th-january-threat-intelligence-report/</link>
      <pubDate>Mon, 26 Jan 2026 13:35:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/26th-january-threat-intelligence-report/</guid>
      <description>• Article inaccessible; requires JavaScript to load content. • Unable to verify authenticity of threat intel data. • No actionable insights provided due to technical barrier. • Sug</description>
    </item>
    <item>
      <title>Open Source Software, Public Policy, and the Stakes of Getting It Right</title>
      <link>https://cluster-site.onrender.com/posts/open-source-software-public-policy-and-the-stakes-of-getting-it-right/</link>
      <pubDate>Mon, 26 Jan 2026 12:12:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/open-source-software-public-policy-and-the-stakes-of-getting-it-right/</guid>
      <description>• Open Source software drives global innovation, research, and economic growth, worth $8.8 trillion. • Without Open Source, companies would spend 3.5× more on software, highlightin</description>
    </item>
    <item>
      <title>Bypassing Windows Administrator Protection</title>
      <link>https://cluster-site.onrender.com/posts/bypassing-windows-administrator-protection/</link>
      <pubDate>Mon, 26 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/bypassing-windows-administrator-protection/</guid>
      <description>• A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. • The goal of this feature is to replace User Account Control (UAC) with a mo</description>
    </item>
    <item>
      <title>Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense</title>
      <link>https://cluster-site.onrender.com/posts/happy-9th-anniversary-cta-a-celebration-of-collaboration-in-cyber-defense/</link>
      <pubDate>Sat, 24 Jan 2026 00:00:53 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/happy-9th-anniversary-cta-a-celebration-of-collaboration-in-cyber-defense/</guid>
      <description>• CTA founded in 2014, uniting Palo Alto, Fortinet, McAfee, and Symantec for shared threat intelligence. • Shifted industry from proprietary intel to collaborative defense, raising</description>
    </item>
    <item>
      <title>CISA Releases Product Categories List to Propel Post-Quantum Cryptography Adoption Pursuant to President Trump&#39;s Executive Order 14306</title>
      <link>https://cluster-site.onrender.com/posts/cisa-releases-product-categories-list-to-propel-post-quantum-cryptography-adoption-pursuant-to-president-trumps-executive-order-14306/</link>
      <pubDate>Fri, 23 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-releases-product-categories-list-to-propel-post-quantum-cryptography-adoption-pursuant-to-president-trumps-executive-order-14306/</guid>
      <description>• CISA releases first product categories list for post‑quantum cryptography (PQC) adoption. • List identifies hardware and software that support or will support PQC standards. • De</description>
    </item>
    <item>
      <title>I scan, you scan, we all scan for... knowledge?</title>
      <link>https://cluster-site.onrender.com/posts/i-scan-you-scan-we-all-scan-for...-knowledge/</link>
      <pubDate>Thu, 22 Jan 2026 19:00:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/i-scan-you-scan-we-all-scan-for...-knowledge/</guid>
      <description>• Reconnaissance is often ignored, yet it&amp;rsquo;s essential for protecting networks. • Know your environment: attackers excel at mapping assets, from Windows 7 machines to smart fridges.</description>
    </item>
    <item>
      <title>The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time</title>
      <link>https://cluster-site.onrender.com/posts/the-next-frontier-of-runtime-assembly-attacks-leveraging-llms-to-generate-phishing-javascript-in-real-time/</link>
      <pubDate>Thu, 22 Jan 2026 11:00:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-next-frontier-of-runtime-assembly-attacks-leveraging-llms-to-generate-phishing-javascript-in-real-time/</guid>
      <description>• Attackers embed a benign page that calls an LLM API to generate malicious JavaScript in real time. • Prompt engineering bypasses AI safety guardrails, producing polymorphic phish</description>
    </item>
    <item>
      <title>Pwn2Own Automotive 2026 - Day One Results</title>
      <link>https://cluster-site.onrender.com/posts/pwn2own-automotive-2026-day-one-results/</link>
      <pubDate>Wed, 21 Jan 2026 04:03:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pwn2own-automotive-2026-day-one-results/</guid>
      <description>• 76 unique 0‑day vulnerabilities discovered across three days, totaling $1,047,000 in rewards. • Fuzzware.io clinched Master of Pwn with 28 points, outperforming rivals like Team</description>
    </item>
    <item>
      <title>Kimwolf Botnet Lurking in Corporate, Govt. Networks</title>
      <link>https://cluster-site.onrender.com/posts/kimwolf-botnet-lurking-in-corporate-govt.-networks/</link>
      <pubDate>Tue, 20 Jan 2026 18:19:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/kimwolf-botnet-lurking-in-corporate-govt.-networks/</guid>
      <description>• Kimwolf botnet has infected over 2 million IoT devices, enabling massive DDoS attacks. • It scans local networks of compromised systems to spread to additional vulnerable devices</description>
    </item>
    <item>
      <title>DNS OverDoS: Are Private Endpoints Too Private?</title>
      <link>https://cluster-site.onrender.com/posts/dns-overdos-are-private-endpoints-too-private/</link>
      <pubDate>Tue, 20 Jan 2026 17:23:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dns-overdos-are-private-endpoints-too-private/</guid>
      <description>Azure Private Endpoints can unintentionally expose resources to DoS attacks. Attack vectors include accidental admin deployments, vendor setups, and malicious actors. Over 5% of Az</description>
    </item>
    <item>
      <title>VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun</title>
      <link>https://cluster-site.onrender.com/posts/voidlink-evidence-that-the-era-of-advanced-ai-generated-malware-has-begun/</link>
      <pubDate>Tue, 20 Jan 2026 09:27:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/voidlink-evidence-that-the-era-of-advanced-ai-generated-malware-has-begun/</guid>
      <description>• VoidLink showcases AI-generated malware capable of crafting polymorphic code. • The malware leverages generative models to evade traditional signature-based detection. • Checkpoi</description>
    </item>
    <item>
      <title>19th January - Threat Intelligence Report</title>
      <link>https://cluster-site.onrender.com/posts/19th-january-threat-intelligence-report/</link>
      <pubDate>Mon, 19 Jan 2026 08:55:27 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/19th-january-threat-intelligence-report/</guid>
      <description>• Unable to access threat intel report due to JavaScript requirement, preventing data retrieval. • Checkpoint Research site blocked without JavaScript, limiting threat intelligence</description>
    </item>
    <item>
      <title>Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering</title>
      <link>https://cluster-site.onrender.com/posts/anatomy-of-an-attack-the-payroll-pirates-and-the-power-of-social-engineering/</link>
      <pubDate>Sat, 17 Jan 2026 00:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/anatomy-of-an-attack-the-payroll-pirates-and-the-power-of-social-engineering/</guid>
      <description>• Threat Research Center Insights Anatomy of an Attack Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering By:Randy Stone Randy Stone Published:January 16</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</link>
      <pubDate>Wed, 14 Jan 2026 18:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</guid>
      <description>• With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland conte</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</link>
      <pubDate>Wed, 14 Jan 2026 17:59:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</guid>
      <description>• Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. • One effect of this change</description>
    </item>
    <item>
      <title>CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT</title>
      <link>https://cluster-site.onrender.com/posts/cisa-uk-ncsc-fbi-unveil-principles-to-combat-cyber-risks-in-ot/</link>
      <pubDate>Wed, 14 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-uk-ncsc-fbi-unveil-principles-to-combat-cyber-risks-in-ot/</guid>
      <description>• CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA), United Kingdom&amp;rsquo;s National Cyber</description>
    </item>
    <item>
      <title>Patch Tuesday, January 2026 Edition</title>
      <link>https://cluster-site.onrender.com/posts/patch-tuesday-january-2026-edition/</link>
      <pubDate>Wed, 14 Jan 2026 00:47:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/patch-tuesday-january-2026-edition/</guid>
      <description>• Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. • Eight of the vulnerabilities earned Microsof</description>
    </item>
    <item>
      <title>Threat Brief: MongoDB Vulnerability (CVE-2025-14847)</title>
      <link>https://cluster-site.onrender.com/posts/threat-brief-mongodb-vulnerability-cve-2025-14847/</link>
      <pubDate>Tue, 13 Jan 2026 20:30:02 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-brief-mongodb-vulnerability-cve-2025-14847/</guid>
      <description>• Executive Summary On Dec. • 19, 2025, MongoDB publicly disclosed MongoBleed, a security vulnerability (CVE-2025-14847) that allows unauthenticated attackers to leak sensitive hea</description>
    </item>
    <item>
      <title>Remote Code Execution With Modern AI/ML Formats and Libraries</title>
      <link>https://cluster-site.onrender.com/posts/remote-code-execution-with-modern-ai/ml-formats-and-libraries/</link>
      <pubDate>Tue, 13 Jan 2026 11:00:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/remote-code-execution-with-modern-ai/ml-formats-and-libraries/</guid>
      <description>• Executive Summary We identified vulnerabilities in three open-source artificial intelligence/machine learning (AI/ML) Python libraries published by Apple, Salesforce and NVIDIA o</description>
    </item>
    <item>
      <title>Who Benefited from the Aisuru and Kimwolf Botnets?</title>
      <link>https://cluster-site.onrender.com/posts/who-benefited-from-the-aisuru-and-kimwolf-botnets/</link>
      <pubDate>Thu, 08 Jan 2026 23:23:43 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/who-benefited-from-the-aisuru-and-kimwolf-botnets/</guid>
      <description>• Our first story of 2026 revealed how a destructive new botnet called Kimwolf has infected more than two million devices by mass-compromising a vast number of unofficial Android T</description>
    </item>
    <item>
      <title>CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity</title>
      <link>https://cluster-site.onrender.com/posts/cisa-retires-ten-emergency-directives-marking-an-era-in-federal-cybersecurity/</link>
      <pubDate>Thu, 08 Jan 2026 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-retires-ten-emergency-directives-marking-an-era-in-federal-cybersecurity/</guid>
      <description>• CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA) announced the succe</description>
    </item>
    <item>
      <title>Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk</title>
      <link>https://cluster-site.onrender.com/posts/securing-vibe-coding-tools-scaling-productivity-without-scaling-risk/</link>
      <pubDate>Thu, 08 Jan 2026 11:00:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/securing-vibe-coding-tools-scaling-productivity-without-scaling-risk/</guid>
      <description>• Threat Research Center Insights General Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk By:Kate MiddaghMichael Spisak Kate Middagh Michael Spisak Published:</description>
    </item>
    <item>
      <title>The Kimwolf Botnet is Stalking Your Local Network</title>
      <link>https://cluster-site.onrender.com/posts/the-kimwolf-botnet-is-stalking-your-local-network/</link>
      <pubDate>Fri, 02 Jan 2026 14:20:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-kimwolf-botnet-is-stalking-your-local-network/</guid>
      <description>• The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. • The vulnerability at issue has been exploited for months alrea</description>
    </item>
    <item>
      <title>Happy 16th Birthday, KrebsOnSecurity.com!</title>
      <link>https://cluster-site.onrender.com/posts/happy-16th-birthday-krebsonsecurity.com/</link>
      <pubDate>Mon, 29 Dec 2025 20:23:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/happy-16th-birthday-krebsonsecurity.com/</guid>
      <description>• KrebsOnSecurity.com celebrates its 16th anniversary today! • A huge &amp;rsquo;thank you&amp;rsquo; to all of our readers - newcomers, long-timers and drive-by critics alike. • Your engagement this</description>
    </item>
    <item>
      <title>The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor</title>
      <link>https://cluster-site.onrender.com/posts/the-honeymyte-apt-evolves-with-a-kernel-mode-rootkit-and-a-toneshell-backdoor/</link>
      <pubDate>Mon, 29 Dec 2025 10:00:35 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-honeymyte-apt-evolves-with-a-kernel-mode-rootkit-and-a-toneshell-backdoor/</guid>
      <description>• Overview of the attacks In mid-2025, we identified a malicious driver file on computer systems in Asia. • The driver file is signed with an old, stolen, or leaked digital certifi</description>
    </item>
    <item>
      <title>Threat landscape for industrial automation systems in Q3 2025</title>
      <link>https://cluster-site.onrender.com/posts/threat-landscape-for-industrial-automation-systems-in-q3-2025/</link>
      <pubDate>Thu, 25 Dec 2025 10:00:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-landscape-for-industrial-automation-systems-in-q3-2025/</guid>
      <description>• Table of Contents Statistics across all threats Selected industries Diversity of detected malicious objects Main threat sources Threat categories Malicious objects used for initi</description>
    </item>
    <item>
      <title>Evasive Panda APT poisons DNS requests to deliver MgBot</title>
      <link>https://cluster-site.onrender.com/posts/evasive-panda-apt-poisons-dns-requests-to-deliver-mgbot/</link>
      <pubDate>Wed, 24 Dec 2025 07:00:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/evasive-panda-apt-poisons-dns-requests-to-deliver-mgbot/</guid>
      <description>• Introduction The Evasive Panda APT group (also known as Bronze Highland, Daggerfly, and StormBamboo) has been active since 2012, targeting multiple industries with sophisticated,</description>
    </item>
    <item>
      <title>Assessing SIEM effectiveness</title>
      <link>https://cluster-site.onrender.com/posts/assessing-siem-effectiveness/</link>
      <pubDate>Tue, 23 Dec 2025 12:00:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/assessing-siem-effectiveness/</guid>
      <description>• A SIEM is a complex system offering broad and flexible threat detection capabilities. • Due to its complexity, its effectiveness heavily depends on how it is configured and what</description>
    </item>
    <item>
      <title>Dismantling Defenses: Trump 2.0 Cyber Year in Review</title>
      <link>https://cluster-site.onrender.com/posts/dismantling-defenses-trump-2.0-cyber-year-in-review/</link>
      <pubDate>Fri, 19 Dec 2025 15:14:55 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/dismantling-defenses-trump-2.0-cyber-year-in-review/</guid>
      <description>• The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation&amp;rsquo;s ability and willingness to address a broad spectrum o</description>
    </item>
    <item>
      <title>CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness</title>
      <link>https://cluster-site.onrender.com/posts/cisa-releases-dynamic-new-guide-for-stadium-and-arena-owners-to-fortify-operations-mitigate-vulnerabilities-and-elevate-emergency-preparedness/</link>
      <pubDate>Wed, 17 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-releases-dynamic-new-guide-for-stadium-and-arena-owners-to-fortify-operations-mitigate-vulnerabilities-and-elevate-emergency-preparedness/</guid>
      <description>• CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness WASHINGTON - Today, the Cybersecur</description>
    </item>
    <item>
      <title>Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS)</title>
      <link>https://cluster-site.onrender.com/posts/opening-doors-to-the-future-cisa-announces-participation-in-the-cybercorps-scholarship-for-service-sfs/</link>
      <pubDate>Wed, 17 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/opening-doors-to-the-future-cisa-announces-participation-in-the-cybercorps-scholarship-for-service-sfs/</guid>
      <description>• Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS) WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agenc</description>
    </item>
    <item>
      <title>Most Parked Domains Now Serving Malicious Content</title>
      <link>https://cluster-site.onrender.com/posts/most-parked-domains-now-serving-malicious-content/</link>
      <pubDate>Tue, 16 Dec 2025 14:14:48 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/most-parked-domains-now-serving-malicious-content/</guid>
      <description>• Direct navigation - the act of visiting a website by manually typing a domain name in a web browser - has never been riskier: A new study finds the vast majority of &amp;lsquo;parked&amp;rsquo; doma</description>
    </item>
    <item>
      <title>Draft NIST Guidelines Rethink Cybersecurity for the AI Era</title>
      <link>https://cluster-site.onrender.com/posts/draft-nist-guidelines-rethink-cybersecurity-for-the-ai-era/</link>
      <pubDate>Tue, 16 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/draft-nist-guidelines-rethink-cybersecurity-for-the-ai-era/</guid>
      <description>• Official websites use .govA.govwebsite belongs to an official government organization in the United States. • Secure .gov websites use HTTPSAlock(LockA locked padlock) orhttps://</description>
    </item>
    <item>
      <title>Welcome to the new Project Zero Blog</title>
      <link>https://cluster-site.onrender.com/posts/welcome-to-the-new-project-zero-blog/</link>
      <pubDate>Tue, 16 Dec 2025 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/welcome-to-the-new-project-zero-blog/</guid>
      <description>• While on Project Zero, we aim for our research to be leading-edge, our blog design was â¦ not so much. • We welcome readers to our shiny new blog! • For the occasion, we asked me</description>
    </item>
    <item>
      <title>Thinking Outside The Box [dusted off draft from 2017]</title>
      <link>https://cluster-site.onrender.com/posts/thinking-outside-the-box-dusted-off-draft-from-2017/</link>
      <pubDate>Tue, 16 Dec 2025 09:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/thinking-outside-the-box-dusted-off-draft-from-2017/</guid>
      <description>• Preface Hello from the future! • This is a blogpost I originally drafted in early 2017. • I wrote what I intended to be the first half of this post (about escaping from the VM to</description>
    </item>
    <item>
      <title>Windows Exploitation Techniques: Winning Race Conditions with Path Lookups</title>
      <link>https://cluster-site.onrender.com/posts/windows-exploitation-techniques-winning-race-conditions-with-path-lookups/</link>
      <pubDate>Tue, 16 Dec 2025 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/windows-exploitation-techniques-winning-race-conditions-with-path-lookups/</guid>
      <description>• This post was originally written in 2016 for the Project Zero blog. • However, in the end it was published separately in the journal PoC||GTFO issue #13 as well as in the second</description>
    </item>
    <item>
      <title>A look at an Android ITW DNG exploit</title>
      <link>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</link>
      <pubDate>Fri, 12 Dec 2025 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</guid>
      <description>• Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. • Thanks to a lead from Meta, these samples came to the attention of Googl</description>
    </item>
    <item>
      <title>Microsoft Patch Tuesday, December 2025 Edition</title>
      <link>https://cluster-site.onrender.com/posts/microsoft-patch-tuesday-december-2025-edition/</link>
      <pubDate>Tue, 09 Dec 2025 23:18:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/microsoft-patch-tuesday-december-2025-edition/</guid>
      <description>• Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. • This final Patch Tuesday of 2025 tackles one zero-day</description>
    </item>
    <item>
      <title>Drones to Diplomas: How Russia&#39;s Largest Private University is Linked to a $25M Essay Mill</title>
      <link>https://cluster-site.onrender.com/posts/drones-to-diplomas-how-russias-largest-private-university-is-linked-to-a-25m-essay-mill/</link>
      <pubDate>Sat, 06 Dec 2025 14:45:03 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/drones-to-diplomas-how-russias-largest-private-university-is-linked-to-a-25m-essay-mill/</guid>
      <description>• A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian u</description>
    </item>
    <item>
      <title>Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure</title>
      <link>https://cluster-site.onrender.com/posts/pro-russia-hacktivists-conduct-opportunistic-attacks-against-us-and-global-critical-infrastructure/</link>
      <pubDate>Fri, 05 Dec 2025 19:35:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/pro-russia-hacktivists-conduct-opportunistic-attacks-against-us-and-global-critical-infrastructure/</guid>
      <description>• Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure Actions for Operational Technology Owners and Operators to Take Today to Mitiga</description>
    </item>
    <item>
      <title>SMS Phishers Pivot to Points, Taxes, Fake Retailers</title>
      <link>https://cluster-site.onrender.com/posts/sms-phishers-pivot-to-points-taxes-fake-retailers/</link>
      <pubDate>Thu, 04 Dec 2025 23:02:34 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/sms-phishers-pivot-to-points-taxes-fake-retailers/</guid>
      <description>• China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday s</description>
    </item>
    <item>
      <title>A NICE Retrospective on Shaping Cybersecurity&#39;s Future</title>
      <link>https://cluster-site.onrender.com/posts/a-nice-retrospective-on-shaping-cybersecuritys-future/</link>
      <pubDate>Tue, 02 Dec 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-nice-retrospective-on-shaping-cybersecuritys-future/</guid>
      <description>• a NIST blog Rodney Petersen has served as the Director of NICE at the National Institute for Standards and Technology (NIST) for the past eleven years where his focus has been on</description>
    </item>
    <item>
      <title>Beware of double agents: How AI can fortify - or fracture - your cybersecurity</title>
      <link>https://cluster-site.onrender.com/posts/beware-of-double-agents-how-ai-can-fortify-or-fracture-your-cybersecurity/</link>
      <pubDate>Wed, 05 Nov 2025 14:00:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/beware-of-double-agents-how-ai-can-fortify-or-fracture-your-cybersecurity/</guid>
      <description>• AI is rapidly becoming the backbone of our world, promising unprecedented productivity and innovation. • But as organizations deploy AI agents to unlock new opportunities and dri</description>
    </item>
    <item>
      <title>Preparing for Threats to Come: Cybersecurity Forecast 2026</title>
      <link>https://cluster-site.onrender.com/posts/preparing-for-threats-to-come-cybersecurity-forecast-2026/</link>
      <pubDate>Tue, 04 Nov 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/preparing-for-threats-to-come-cybersecurity-forecast-2026/</guid>
      <description>• Preparing for Threats to Come: Cybersecurity Forecast 2026 Blog and Content Manager Visibility and context on the threats that matter most. • Every November, we make it our missi</description>
    </item>
    <item>
      <title>Space is the new cybersecurity frontier: Here are the startups leading the race</title>
      <link>https://cluster-site.onrender.com/posts/space-is-the-new-cybersecurity-frontier-here-are-the-startups-leading-the-race/</link>
      <pubDate>Wed, 29 Oct 2025 22:32:47 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/space-is-the-new-cybersecurity-frontier-here-are-the-startups-leading-the-race/</guid>
      <description>• Space infrastructure is evolving from exclusive government and military operations into critical commercial applications - includingnavigation systems,satellite internet, andgeos</description>
    </item>
    <item>
      <title>Sharpening the Focus on Product Requirements and Cybersecurity Risks: Updating Foundational Activities for IoT Product Manufacturers</title>
      <link>https://cluster-site.onrender.com/posts/sharpening-the-focus-on-product-requirements-and-cybersecurity-risks-updating-foundational-activities-for-iot-product-manufacturers/</link>
      <pubDate>Tue, 30 Sep 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/sharpening-the-focus-on-product-requirements-and-cybersecurity-risks-updating-foundational-activities-for-iot-product-manufacturers/</guid>
      <description>• a NIST blog Update: The comment period for your feedback on the second public draft of NIST IR 8259 has been extended through December 10, 2025. • Over the past few months, NIST</description>
    </item>
    <item>
      <title>CISA Shares Lessons Learned from an Incident Response Engagement</title>
      <link>https://cluster-site.onrender.com/posts/cisa-shares-lessons-learned-from-an-incident-response-engagement/</link>
      <pubDate>Mon, 22 Sep 2025 15:12:49 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-shares-lessons-learned-from-an-incident-response-engagement/</guid>
      <description>• CISA Shares Lessons Learned from an Incident Response Engagement Advisory at a Glance Executive Summary | CISA began incident response efforts at a U.S. • federal civilian execut</description>
    </item>
    <item>
      <title>NIST Awards More Than $3 Million to Support Cybersecurity Workforce Development Across 13 States</title>
      <link>https://cluster-site.onrender.com/posts/nist-awards-more-than-3-million-to-support-cybersecurity-workforce-development-across-13-states/</link>
      <pubDate>Wed, 17 Sep 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nist-awards-more-than-3-million-to-support-cybersecurity-workforce-development-across-13-states/</guid>
      <description>• Official websites use .govA.govwebsite belongs to an official government organization in the United States. • Secure .gov websites use HTTPSAlock(LockA locked padlock) orhttps://</description>
    </item>
    <item>
      <title>Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System</title>
      <link>https://cluster-site.onrender.com/posts/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system/</link>
      <pubDate>Mon, 25 Aug 2025 13:36:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system/</guid>
      <description>• Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System Executive summary People&amp;rsquo;s Republic of China (PRC) state-sponsored cybe</description>
    </item>
    <item>
      <title>Powering AI-Driven Security with the Open Cybersecurity Schema Framework</title>
      <link>https://cluster-site.onrender.com/posts/powering-ai-driven-security-with-the-open-cybersecurity-schema-framework/</link>
      <pubDate>Mon, 04 Aug 2025 22:17:23 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/powering-ai-driven-security-with-the-open-cybersecurity-schema-framework/</guid>
      <description>• AWS Open Source Blog Powering AI-Driven Security with the Open Cybersecurity Schema Framework As organizations continue to innovate and scale their operations, security teams fac</description>
    </item>
    <item>
      <title>CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization</title>
      <link>https://cluster-site.onrender.com/posts/cisa-and-uscg-identify-areas-for-cyber-hygiene-improvement-after-conducting-proactive-threat-hunt-at-us-critical-infrastructure-organization/</link>
      <pubDate>Tue, 29 Jul 2025 17:53:52 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cisa-and-uscg-identify-areas-for-cyber-hygiene-improvement-after-conducting-proactive-threat-hunt-at-us-critical-infrastructure-organization/</guid>
      <description>• CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization Summary The Cybersecurity and Infrast</description>
    </item>
    <item>
      <title>#StopRansomware: Interlock</title>
      <link>https://cluster-site.onrender.com/posts/%23stopransomware-interlock/</link>
      <pubDate>Mon, 21 Jul 2025 14:11:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/%23stopransomware-interlock/</guid>
      <description>• #StopRansomware: Interlock Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Ransomware Activity Prevent initial access by implementing domai</description>
    </item>
    <item>
      <title>Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider</title>
      <link>https://cluster-site.onrender.com/posts/ransomware-actors-exploit-unpatched-simplehelp-remote-monitoring-and-management-to-compromise-utility-billing-software-provider/</link>
      <pubDate>Thu, 12 Jun 2025 14:29:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ransomware-actors-exploit-unpatched-simplehelp-remote-monitoring-and-management-to-compromise-utility-billing-software-provider/</guid>
      <description>• Ransomware actors target unpatched SimpleHelp RMM to breach utility billing software provider customers. • Vulnerability CVE-2024-57727, a path traversal flaw, exploited in Simpl</description>
    </item>
    <item>
      <title>The Impact of Artificial Intelligence on the Cybersecurity Workforce</title>
      <link>https://cluster-site.onrender.com/posts/the-impact-of-artificial-intelligence-on-the-cybersecurity-workforce/</link>
      <pubDate>Thu, 12 Jun 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-impact-of-artificial-intelligence-on-the-cybersecurity-workforce/</guid>
      <description>• NICE Framework updated in 2020 to integrate emerging tech, especially AI, into cybersecurity workforce planning. • Stakeholder dialogues span federal agencies, industry, academia</description>
    </item>
    <item>
      <title>Cybersecurity and AI: Integrating and Building on Existing NIST Guidelines</title>
      <link>https://cluster-site.onrender.com/posts/cybersecurity-and-ai-integrating-and-building-on-existing-nist-guidelines/</link>
      <pubDate>Thu, 22 May 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/cybersecurity-and-ai-integrating-and-building-on-existing-nist-guidelines/</guid>
      <description>• NIST held Cybersecurity &amp;amp; AI Profile Workshop to gather feedback on CSF and AI RMF profiles. • Profiles aim to guide adoption of AI in cybersecurity and defend against AI-enabled</description>
    </item>
    <item>
      <title>Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations</title>
      <link>https://cluster-site.onrender.com/posts/threat-actors-deploy-lummac2-malware-to-exfiltrate-sensitive-data-from-organizations/</link>
      <pubDate>Tue, 20 May 2025 19:20:23 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-actors-deploy-lummac2-malware-to-exfiltrate-sensitive-data-from-organizations/</guid>
      <description>• FBI &amp;amp; CISA issue joint advisory on LummaC2 infostealer targeting critical infrastructure. • Malware infiltrates networks, exfiltrates sensitive data via spearphishing links and a</description>
    </item>
    <item>
      <title>Impact of AI on cyber threat from now to 2027</title>
      <link>https://cluster-site.onrender.com/posts/impact-of-ai-on-cyber-threat-from-now-to-2027/</link>
      <pubDate>Fri, 16 May 2025 20:03:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/impact-of-ai-on-cyber-threat-from-now-to-2027/</guid>
      <description>• AI is accelerating threat sophistication, enabling attackers to craft more convincing phishing campaigns. • Machine‑learning models are used to generate polymorphic malware that</description>
    </item>
    <item>
      <title>Five Years Later: Evolving IoT Cybersecurity Guidelines</title>
      <link>https://cluster-site.onrender.com/posts/five-years-later-evolving-iot-cybersecurity-guidelines/</link>
      <pubDate>Tue, 13 May 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/five-years-later-evolving-iot-cybersecurity-guidelines/</guid>
      <description>• NIST&amp;rsquo;s 2020 IoT Cybersecurity Improvement Act mandated five‑year guideline reviews. • IR 8259 set foundational cybersecurity activities for IoT manufacturers. • IR 8259A/B expand</description>
    </item>
    <item>
      <title>Russian GRU Targeting Western Logistics Entities and Technology Companies</title>
      <link>https://cluster-site.onrender.com/posts/russian-gru-targeting-western-logistics-entities-and-technology-companies/</link>
      <pubDate>Mon, 12 May 2025 16:49:12 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/russian-gru-targeting-western-logistics-entities-and-technology-companies/</guid>
      <description>• Russian GRU&amp;rsquo;s 85th GTsSS unit 26165 targets Western logistics and tech firms. • Campaign focuses on coordination, transport, delivery of foreign aid to Ukraine. • Uses known TTPs</description>
    </item>
    <item>
      <title>Small Businesses Create Big Impact: NIST Celebrates 2025 National Small Business Week</title>
      <link>https://cluster-site.onrender.com/posts/small-businesses-create-big-impact-nist-celebrates-2025-national-small-business-week/</link>
      <pubDate>Mon, 05 May 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/small-businesses-create-big-impact-nist-celebrates-2025-national-small-business-week/</guid>
      <description>• NIST celebrates National Small Business Week, spotlighting SMBs&amp;rsquo; vital role in U.S. economy and cybersecurity. • 34.8 million SMBs, 99% of U.S. businesses, 81.7% having no paid e</description>
    </item>
    <item>
      <title>Journey to Zero Trust Access</title>
      <link>https://cluster-site.onrender.com/posts/journey-to-zero-trust-access/</link>
      <pubDate>Tue, 15 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/journey-to-zero-trust-access/</guid>
      <description>• Yelp transitioned to fully remote, requiring secure, consistent access for a globally distributed workforce. • Existing VPN (Ivanti Pulse Secure) was unreliable, prompting a sear</description>
    </item>
    <item>
      <title>Fast Flux: A National Security Threat</title>
      <link>https://cluster-site.onrender.com/posts/fast-flux-a-national-security-threat/</link>
      <pubDate>Tue, 01 Apr 2025 19:00:21 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/fast-flux-a-national-security-threat/</guid>
      <description>• Fast flux hides malicious server locations by rapidly changing DNS records. • Enables cybercriminals and nation-state actors to evade detection and maintain C2. • Resilient, high</description>
    </item>
    <item>
      <title>Vendor Security Assessment</title>
      <link>https://cluster-site.onrender.com/posts/vendor-security-assessment/</link>
      <pubDate>Wed, 12 Mar 2025 11:21:29 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/vendor-security-assessment/</guid>
      <description>• Identify vendor security posture through comprehensive risk assessment. • Evaluate compliance with industry standards and regulatory requirements. • Assess data protection, acces</description>
    </item>
    <item>
      <title>Threat report on application stores</title>
      <link>https://cluster-site.onrender.com/posts/threat-report-on-application-stores/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:59 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/threat-report-on-application-stores/</guid>
      <description>• Malware increasingly hides in legitimate app store listings, exploiting user trust for widespread infection. • Supply‑chain attacks target third‑party libraries, enabling attacke</description>
    </item>
    <item>
      <title>The threat from commercial cyber proliferation</title>
      <link>https://cluster-site.onrender.com/posts/the-threat-from-commercial-cyber-proliferation/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:26 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-threat-from-commercial-cyber-proliferation/</guid>
      <description>• Commercial software proliferation expands attack surface, increasing vulnerability exposure across enterprises. • Open-source components in commercial stacks introduce hidden bac</description>
    </item>
    <item>
      <title>The near-term impact of AI on the cyber threat</title>
      <link>https://cluster-site.onrender.com/posts/the-near-term-impact-of-ai-on-the-cyber-threat/</link>
      <pubDate>Wed, 12 Mar 2025 11:20:01 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-near-term-impact-of-ai-on-the-cyber-threat/</guid>
      <description>• AI accelerates threat detection, enabling faster identification of malicious activity. • Adversarial AI allows attackers to craft evasive malware that bypasses traditional defens</description>
    </item>
    <item>
      <title>The cyber threat to Universities</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-universities/</link>
      <pubDate>Wed, 12 Mar 2025 11:19:33 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-universities/</guid>
      <description>• Universities face rising ransomware attacks targeting research data and student records. • Phishing campaigns exploit faculty credentials to gain network access. • Supply‑chain v</description>
    </item>
    <item>
      <title>The Cyber Threat to UK Business</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-uk-business/</link>
      <pubDate>Wed, 12 Mar 2025 11:19:11 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-uk-business/</guid>
      <description>• Ransomware remains the top threat, targeting critical UK business data. • Phishing campaigns exploit remote working, increasing credential theft. • Supply‑chain attacks grow, com</description>
    </item>
    <item>
      <title>The cyber threat to sports organisations</title>
      <link>https://cluster-site.onrender.com/posts/the-cyber-threat-to-sports-organisations/</link>
      <pubDate>Wed, 12 Mar 2025 11:18:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-cyber-threat-to-sports-organisations/</guid>
      <description>• Sports organisations increasingly targeted by ransomware, phishing, and credential‑stealing attacks. • High‑profile events like the Olympics and World Cup attract sophisticated t</description>
    </item>
    <item>
      <title>Summary of the NCSC analysis of May 2020 US sanction</title>
      <link>https://cluster-site.onrender.com/posts/summary-of-the-ncsc-analysis-of-may-2020-us-sanction/</link>
      <pubDate>Wed, 12 Mar 2025 11:17:43 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/summary-of-the-ncsc-analysis-of-may-2020-us-sanction/</guid>
      <description>• US sanctions in May 2020 targeted Russian cyber actors and infrastructure. • NCSC identified increased threat actor activity following sanction announcements. • Sanctions disrupt</description>
    </item>
    <item>
      <title>Summary of NCSC&#39;s security analysis for the UK telecoms sector</title>
      <link>https://cluster-site.onrender.com/posts/summary-of-ncscs-security-analysis-for-the-uk-telecoms-sector/</link>
      <pubDate>Wed, 12 Mar 2025 11:16:51 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/summary-of-ncscs-security-analysis-for-the-uk-telecoms-sector/</guid>
      <description>• UK telecoms face rising cyber threats, including ransomware targeting network infrastructure. • NCSC highlights supply chain risks from overseas vendors in 5G equipment. • Vulner</description>
    </item>
    <item>
      <title>Technical report: Responsible use of the Border Gateway Protocol (BGP) for ISP interworking</title>
      <link>https://cluster-site.onrender.com/posts/technical-report-responsible-use-of-the-border-gateway-protocol-bgp-for-isp-interworking/</link>
      <pubDate>Wed, 12 Mar 2025 11:12:10 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/technical-report-responsible-use-of-the-border-gateway-protocol-bgp-for-isp-interworking/</guid>
      <description>• BGP is critical for inter-ISP routing, requiring strict policy enforcement to prevent leaks and hijacks. • Implement prefix filtering and route origin validation to ensure only l</description>
    </item>
    <item>
      <title>Organisational use of Enterprise Connected Devices</title>
      <link>https://cluster-site.onrender.com/posts/organisational-use-of-enterprise-connected-devices/</link>
      <pubDate>Wed, 12 Mar 2025 11:11:45 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/organisational-use-of-enterprise-connected-devices/</guid>
      <description>• Enterprise connected devices expand attack surface, enabling lateral movement across corporate networks. • Insider threats amplified as employees use personal devices for work, b</description>
    </item>
    <item>
      <title>Joint report on publicly available hacking tools</title>
      <link>https://cluster-site.onrender.com/posts/joint-report-on-publicly-available-hacking-tools/</link>
      <pubDate>Wed, 12 Mar 2025 11:11:20 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/joint-report-on-publicly-available-hacking-tools/</guid>
      <description>• Joint report reveals surge in publicly available hacking toolkits targeting critical infrastructure. • Analysts highlight increased ease of access via dark web marketplaces and o</description>
    </item>
    <item>
      <title>Incident trends report (October 2018 - April 2019)</title>
      <link>https://cluster-site.onrender.com/posts/incident-trends-report-october-2018-april-2019/</link>
      <pubDate>Wed, 12 Mar 2025 11:10:04 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/incident-trends-report-october-2018-april-2019/</guid>
      <description>• Over 1,200 cyber incidents reported across 30 countries, highlighting rising ransomware activity. • Ransomware attacks surged 35%, with CryptoLocker variants targeting healthcare</description>
    </item>
    <item>
      <title>Decrypting diversity: Diversity and inclusion in cyber security report 2021</title>
      <link>https://cluster-site.onrender.com/posts/decrypting-diversity-diversity-and-inclusion-in-cyber-security-report-2021/</link>
      <pubDate>Wed, 12 Mar 2025 11:07:13 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/decrypting-diversity-diversity-and-inclusion-in-cyber-security-report-2021/</guid>
      <description>• Cybersecurity workforce remains 70% male, with women under 20% in technical roles. • Minority representation below 15%, limiting diverse threat perspective. • 2021 report links d</description>
    </item>
    <item>
      <title>#StopRansomware: Medusa Ransomware</title>
      <link>https://cluster-site.onrender.com/posts/%23stopransomware-medusa-ransomware/</link>
      <pubDate>Tue, 11 Mar 2025 14:52:42 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/%23stopransomware-medusa-ransomware/</guid>
      <description>• Patch OS, software, firmware promptly to close known vulnerabilities across all systems. • Segment networks to limit lateral movement from infected devices and protect critical a</description>
    </item>
    <item>
      <title>Celebrating 1 Year of CSF 2.0</title>
      <link>https://cluster-site.onrender.com/posts/celebrating-1-year-of-csf-2.0/</link>
      <pubDate>Wed, 26 Feb 2025 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/celebrating-1-year-of-csf-2.0/</guid>
      <description>• One year since NIST released Cybersecurity Framework 2.0, boosting enterprise security readiness. • New 2025 resources offer tailored pathways for diverse audiences to implement</description>
    </item>
    <item>
      <title>NIST&#39;s International Cybersecurity and Privacy Engagement Update - New Translations</title>
      <link>https://cluster-site.onrender.com/posts/nists-international-cybersecurity-and-privacy-engagement-update-new-translations/</link>
      <pubDate>Thu, 19 Dec 2024 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nists-international-cybersecurity-and-privacy-engagement-update-new-translations/</guid>
      <description>• NIST released 10+ new cybersecurity translations across six languages for global stakeholders. • International partners engaged through travel, sharing key NIST projects worldwid</description>
    </item>
    <item>
      <title>Kicking-Off with a December 4th Workshop, NIST is Revisiting and Revising Foundational Cybersecurity Activities for IoT Device Manufacturers, NIST IR 8259!</title>
      <link>https://cluster-site.onrender.com/posts/kicking-off-with-a-december-4th-workshop-nist-is-revisiting-and-revising-foundational-cybersecurity-activities-for-iot-device-manufacturers-nist-ir-8259/</link>
      <pubDate>Thu, 21 Nov 2024 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/kicking-off-with-a-december-4th-workshop-nist-is-revisiting-and-revising-foundational-cybersecurity-activities-for-iot-device-manufacturers-nist-ir-8259/</guid>
      <description>• NIST&amp;rsquo;s 2020 IR 8259 outlines foundational cybersecurity activities for IoT device manufacturers. • The guide has 40,000+ downloads and is available in English, Spanish, and Portu</description>
    </item>
    <item>
      <title>Unlocking Cybersecurity Talent: The Power of Apprenticeships</title>
      <link>https://cluster-site.onrender.com/posts/unlocking-cybersecurity-talent-the-power-of-apprenticeships/</link>
      <pubDate>Mon, 18 Nov 2024 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/unlocking-cybersecurity-talent-the-power-of-apprenticeships/</guid>
      <description>• Cybersecurity demand surges, yet no standardized entry path for professionals. • Registered apprenticeships offer paid, on‑the‑job training with real‑world experience. • Apprenti</description>
    </item>
    <item>
      <title>Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem</title>
      <link>https://cluster-site.onrender.com/posts/digital-identities-getting-to-know-the-verifiable-digital-credential-ecosystem/</link>
      <pubDate>Wed, 13 Nov 2024 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/digital-identities-getting-to-know-the-verifiable-digital-credential-ecosystem/</guid>
      <description>• Verifiable digital credentials turn physical IDs into cryptographically verifiable digital tokens stored on smartphones. • Common buzzwords include &amp;lsquo;digital wallet,&amp;rsquo; &amp;lsquo;mobile driv</description>
    </item>
    <item>
      <title>Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024</title>
      <link>https://cluster-site.onrender.com/posts/staff-stories-spotlight-series-cybersecurity-awareness-month-2024/</link>
      <pubDate>Mon, 28 Oct 2024 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/staff-stories-spotlight-series-cybersecurity-awareness-month-2024/</guid>
      <description>• NIST launches Staff Stories Spotlight series during Cybersecurity Awareness Month to highlight diverse staff backgrounds. • Theme &amp;lsquo;Secure our World&amp;rsquo; emphasizes global collaborati</description>
    </item>
    <item>
      <title>Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024</title>
      <link>https://cluster-site.onrender.com/posts/staff-stories-spotlight-series-cybersecurity-awareness-month-2024/</link>
      <pubDate>Wed, 23 Oct 2024 12:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/staff-stories-spotlight-series-cybersecurity-awareness-month-2024/</guid>
      <description>• NIST launches Staff Stories Spotlight series for Cybersecurity Awareness Month, featuring Q&amp;amp;A with staff. • Theme &amp;lsquo;Secure our World&amp;rsquo; underscores collective duty to protect digita</description>
    </item>
    <item>
      <title>Integrate Elastic AI Assistant for Security via API to advance SOC workflows</title>
      <link>https://cluster-site.onrender.com/posts/integrate-elastic-ai-assistant-for-security-via-api-to-advance-soc-workflows/</link>
      <pubDate>Thu, 08 Aug 2024 07:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/integrate-elastic-ai-assistant-for-security-via-api-to-advance-soc-workflows/</guid>
      <description>• Elastic AI Assistant for Security now offers chat and management APIs in Elastic Security 8.15. • APIs enable automated threat identification and data enrichment directly within</description>
    </item>
    <item>
      <title>Building a next-gen SOC at Pinewood, a leading MSSP, underpinned by Elastic SIEM</title>
      <link>https://cluster-site.onrender.com/posts/building-a-next-gen-soc-at-pinewood-a-leading-mssp-underpinned-by-elastic-siem/</link>
      <pubDate>Thu, 06 Jun 2024 07:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/building-a-next-gen-soc-at-pinewood-a-leading-mssp-underpinned-by-elastic-siem/</guid>
      <description>• Pinewood, a leading MSSP, deployed Elastic SIEM to centralize threat detection across finance, healthcare, retail, and government clients. • The platform aggregates logs, network</description>
    </item>
    <item>
      <title>What you need to know about Process Ghosting, a new executable image tampering attack</title>
      <link>https://cluster-site.onrender.com/posts/what-you-need-to-know-about-process-ghosting-a-new-executable-image-tampering-attack/</link>
      <pubDate>Tue, 15 Jun 2021 07:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/what-you-need-to-know-about-process-ghosting-a-new-executable-image-tampering-attack/</guid>
      <description>• Process Ghosting exploits the delay between process creation and thread notification, enabling pre‑scan tampering. • Attack writes malware to disk, deletes it, yet execution cont</description>
    </item>
  </channel>
</rss>
