<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Hive Security</title><description>Offensive thinking. Defensive expertise.</description><link>https://hivesecurity.gitlab.io/</link><language>en-gb</language><item><title>DEF CON 34: The Hacker Party That Became the World&apos;s Biggest Hacking Conference</title><link>https://hivesecurity.gitlab.io/blog/defcon-34-history-culture-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/defcon-34-history-culture-2026/</guid><description>DEF CON started as a farewell party for a BBS sysop who never showed up. 33 years later it draws more than 30,000 people, shapes election security policy, and lets autonomous AI agents hunt flags.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>TrojPix: Stealing Data from an Air-Gapped Computer Through Its Display Cable</title><link>https://hivesecurity.gitlab.io/blog/trojpix-air-gap-hdmi-em-covert-channel/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/trojpix-air-gap-hdmi-em-covert-channel/</guid><description>USENIX Security 2026 research shows how imperceptible pixel changes can turn a digital display cable into an electromagnetic covert channel. The result is real, but so are its prerequisites.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate></item><item><title>NGINX&apos;s Configuration-Dependent Vulnerabilities: Why Version Scanning Is Not Enough</title><link>https://hivesecurity.gitlab.io/blog/nginx-configuration-dependent-vulnerabilities-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/nginx-configuration-dependent-vulnerabilities-2026/</guid><description>NGINX 1.30.4 and 1.31.3 fixed three new memory-safety flaws, but exposure depends on map, slice, SSI, proxy, and buffering configuration. Here is how to audit the real path.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Your UniFi Console Is a Server: What Security Bulletin 066 Actually Requires</title><link>https://hivesecurity.gitlab.io/blog/unifi-security-bulletin-066-attack-surface/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/unifi-security-bulletin-066-attack-surface/</guid><description>Ubiquiti disclosed 25 vulnerabilities across UniFi applications and devices. The critical issue is not the headline CVSS score, but which management services an attacker can reach.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate></item><item><title>One Email Preview Is Enough: Russia&apos;s Half-Click Webmail Exploits</title><link>https://hivesecurity.gitlab.io/blog/half-click-webmail-exploits-zimbra-roundpress-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/half-click-webmail-exploits-zimbra-roundpress-2026/</guid><description>Russian-aligned espionage groups exploited stored XSS flaws in Zimbra, SOGo, Roundcube, MDaemon, and Kerio. Opening a message was enough to lose credentials, email, and persistent access.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-48282: A Perfect 10 in Adobe ColdFusion, Exploited Within Two Hours</title><link>https://hivesecurity.gitlab.io/blog/adobe-coldfusion-cve-2026-48282-mass-exploitation/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/adobe-coldfusion-cve-2026-48282-mass-exploitation/</guid><description>A CVSS 10.0 path traversal in Adobe ColdFusion&apos;s Remote Development Services lets unauthenticated attackers write a webshell straight into the web root. Attackers were probing it before most admins finished reading the advisory.</description><pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI Voice Cloning: The $25.6 Million Phone Call That Wasn&apos;t Real</title><link>https://hivesecurity.gitlab.io/blog/ai-voice-cloning-vishing-deepfake-fraud/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ai-voice-cloning-vishing-deepfake-fraud/</guid><description>A finance employee wired $25.6 million after a video call with the CFO and colleagues — all AI-generated deepfakes. Short public audio clips can now seed convincing voice clones. Here&apos;s how vishing changed and what actually stops it.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The KDDI Breach: One Vulnerable Component, Six ISPs, 12 Million Exposed Inboxes</title><link>https://hivesecurity.gitlab.io/blog/kddi-data-breach-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/kddi-data-breach-2026/</guid><description>A zero-day in unnamed third-party software let attackers sit inside KDDI&apos;s shared ISP email platform for a month, exposing email addresses and passwords used by @nifty, BIGLOBE, J:COM, and three other providers. Here&apos;s what&apos;s confirmed and what isn&apos;t.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ICS/OT Security Basics: Why Your Office Network Rules Don&apos;t Apply to a PLC</title><link>https://hivesecurity.gitlab.io/blog/ics-ot-security-fundamentals-purdue-model/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ics-ot-security-fundamentals-purdue-model/</guid><description>A wiper attack bricked remote terminal units across 30 Polish energy sites. An Iranian APT tampered with US water utility PLCs using legitimate engineering software. Here&apos;s the OT security model IT teams keep getting wrong.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate></item><item><title>DuneSlide: How a Prompt Injection Became Full RCE in Cursor IDE</title><link>https://hivesecurity.gitlab.io/blog/duneslide-cursor-ide-prompt-injection-rce/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/duneslide-cursor-ide-prompt-injection-rce/</guid><description>Cato AI Labs found two 9.8 CVSS flaws in Cursor&apos;s terminal sandbox — CVE-2026-50548 and CVE-2026-50549 — that let a poisoned MCP response or search result silently escape to full remote code execution. Neither requires a click.</description><pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate></item><item><title>DNS Tunneling: The C2 Channel Hiding in the One Protocol You Can&apos;t Block</title><link>https://hivesecurity.gitlab.io/blog/dns-tunneling-covert-c2-detection/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/dns-tunneling-covert-c2-detection/</guid><description>SUNBURST used it. DNSMessenger lived inside it. Decoy Dog delivered payloads through it. DNS tunneling turns routine name resolution into a covert command channel — here&apos;s how it works and how to catch it.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>JADEPUFFER: Inside the First Documented Agentic Ransomware Attack</title><link>https://hivesecurity.gitlab.io/blog/jadepuffer-agentic-ai-ransomware-langflow/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/jadepuffer-agentic-ai-ransomware-langflow/</guid><description>Sysdig caught an LLM agent breaking into a Langflow server, pivoting to a production database, and extorting the victim — with no human at the keyboard between steps. Here&apos;s what actually happened, and what&apos;s still unproven.</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate></item><item><title>STRIDE Threat Modeling: A Practical Guide Nobody Needs a Tool to Start</title><link>https://hivesecurity.gitlab.io/blog/stride-threat-modeling-practical-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/stride-threat-modeling-practical-guide/</guid><description>STRIDE has been Microsoft&apos;s threat modeling framework since 1999 and still works. Here&apos;s how to run a real session with a whiteboard, a data flow diagram, and 30 minutes — no expensive tooling required.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FortiBleed&apos;s Ransomware Pipeline: What SOCRadar&apos;s INC Ransom and Lynx Attribution Actually Proves</title><link>https://hivesecurity.gitlab.io/blog/fortibleed-lynx-inc-ransomware-attribution/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/fortibleed-lynx-inc-ransomware-attribution/</guid><description>SOCRadar says the FortiBleed credential campaign feeds directly into INC Ransom and Lynx ransomware operations, with 430,000 FortiGate devices targeted. Here&apos;s what&apos;s confirmed, what&apos;s one vendor&apos;s assessment, and what it means for your firewall.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SIM Swapping: How Attackers Steal Your Phone Number to Steal Everything Else</title><link>https://hivesecurity.gitlab.io/blog/sim-swapping-number-porting-mfa-bypass/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/sim-swapping-number-porting-mfa-bypass/</guid><description>SIM swapping redirects SMS and voice verification to an attacker-controlled device. Here&apos;s how number-porting fraud works, why SMS MFA fails, and what actually stops it.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Exploited Before the PoC Existed: CVE-2026-46817 in Oracle Payments</title><link>https://hivesecurity.gitlab.io/blog/oracle-ebs-payments-cve-2026-46817-exploitation/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/oracle-ebs-payments-cve-2026-46817-exploitation/</guid><description>A critical, unauthenticated flaw in Oracle E-Business Suite&apos;s Payments module was hit in the wild on June 27, 2026 — six weeks after the patch, with no public exploit code anywhere. Here&apos;s what&apos;s confirmed, what&apos;s still speculation, and how to check if you&apos;re exposed.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Dependency Confusion: Your Internal Package Name Is a Public Attack Surface</title><link>https://hivesecurity.gitlab.io/blog/dependency-confusion-attacks-internal-package-hijacking/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/dependency-confusion-attacks-internal-package-hijacking/</guid><description>Publish a package with the same name as a company&apos;s private one, give it a higher version number, and package managers will happily install the attacker&apos;s code instead. Here&apos;s how it still works in 2026.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-48558: A Perfect 10 in SimpleHelp Opens the Door for Djinn Stealer</title><link>https://hivesecurity.gitlab.io/blog/simplehelp-auth-bypass-cve-2026-48558-djinn-stealer/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/simplehelp-auth-bypass-cve-2026-48558-djinn-stealer/</guid><description>An unsigned OIDC token is all it takes to become a fully authenticated technician on a SimpleHelp RMM server. Attackers are already using that shortcut to push a cross-platform infostealer built for the AI era.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Business Email Compromise: The $3 Billion Scam With No Malware</title><link>https://hivesecurity.gitlab.io/blog/business-email-compromise-vendor-invoice-fraud/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/business-email-compromise-vendor-invoice-fraud/</guid><description>BEC caused $3.05 billion in reported US losses in 2025 alone — without a single exploit. Here&apos;s the full attack chain from mailbox compromise to wire fraud, and the controls that actually stop it.</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-58644: The SharePoint Patch That Arrived With an Incident-Response Deadline</title><link>https://hivesecurity.gitlab.io/blog/cve-2026-58644-sharepoint-rce-incident-response/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cve-2026-58644-sharepoint-rce-incident-response/</guid><description>CISA says attackers are exploiting a critical SharePoint deserialization flaw. Patching closes the bug, but exposed servers also need a focused compromise assessment.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Cloud Concentration Risk: A Single Point of Failure</title><link>https://hivesecurity.gitlab.io/blog/cloud-concentration-risk-single-point-of-failure-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cloud-concentration-risk-single-point-of-failure-2026/</guid><description>Recent AWS and Cloudflare disruptions show how shared cloud, identity, and network dependencies turn localized faults into widespread outages. Here is how to find and reduce that hidden blast radius.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Forgotten Shims: How 11 Old Microsoft-Signed Files Break Secure Boot</title><link>https://hivesecurity.gitlab.io/blog/forgotten-uefi-shims-secure-boot-bypass/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/forgotten-uefi-shims-secure-boot-bypass/</guid><description>ESET Research found 11 old UEFI shim bootloaders, all validly signed by Microsoft, that bypass Secure Boot on any system trusting Microsoft&apos;s third-party CA. CVE-2026-8863 and CVE-2026-10797 — no exploit chain required.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Grok Build Uploaded Entire Git Repositories: What the Wire Capture Proved</title><link>https://hivesecurity.gitlab.io/blog/grok-build-repository-upload-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/grok-build-repository-upload-2026/</guid><description>A wire-level analysis found Grok Build 0.2.93 uploading tracked source code and full Git history independently of what the agent read. Here is what was proven, what changed, and how developers should respond.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>EU Chat Control 2026: The Vote That Passed and Failed at the Same Time</title><link>https://hivesecurity.gitlab.io/blog/eu-chat-control-2026-vote-against-majority/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/eu-chat-control-2026-vote-against-majority/</guid><description>On July 9, 2026, more MEPs voted to kill the EU&apos;s message-scanning rules than to keep them — and the rules still aren&apos;t back in force. Here&apos;s what actually happened, what it means for Gmail, Proton Mail, and everything in between, and why it isn&apos;t over.</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Instagram @-Mentions Are Now an AI Impersonation Surface</title><link>https://hivesecurity.gitlab.io/blog/instagram-muse-image-ai-impersonation-risk/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/instagram-muse-image-ai-impersonation-risk/</guid><description>Meta&apos;s Muse Image turns public Instagram content into promptable visual context. The security issue is not novelty; it is lower-friction impersonation at social-media scale.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Jolla Phone in 2026: Privacy Phone or Threat Model Correction?</title><link>https://hivesecurity.gitlab.io/blog/jolla-phone-privacy-threat-model-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/jolla-phone-privacy-threat-model-2026/</guid><description>Jolla&apos;s new Finnish phone is a useful reminder that mobile privacy is not one feature. It is an architecture, an app ecosystem, a supply chain, and a set of user tradeoffs.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>WhatsApp Usernames: A Privacy Win That Opens a New Impersonation Surface</title><link>https://hivesecurity.gitlab.io/blog/whatsapp-usernames-impersonation-namespace-risk/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/whatsapp-usernames-impersonation-namespace-risk/</guid><description>WhatsApp usernames reduce phone-number exposure, but they also create a new global namespace where brands, public bodies, and lookalike handles can become fraud infrastructure.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The VPN Was Never the Problem: How a Windows Telemetry ID Unmasked a Scattered Spider Suspect</title><link>https://hivesecurity.gitlab.io/blog/gdid-windows-telemetry-scattered-spider-arrest/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/gdid-windows-telemetry-scattered-spider-arrest/</guid><description>A 19-year-old allegedly hid behind a VPN and ngrok during an $8M jewelry-retailer extortion case. Windows&apos; Global Device Identifier (GDID) gave investigators a device-level pivot.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AI-Built Browser Ransomware Abuses Chrome File Access</title><link>https://hivesecurity.gitlab.io/blog/browser-only-ransomware-file-system-access-api/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/browser-only-ransomware-file-system-access-api/</guid><description>Check Point analyzed a DeepSeek-attributed ransomware sample that should not work from a browser tab. Most of it was fiction — except for one detail that mapped to a real Chromium API. No malware install required.</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Minimum Package Age: The Supply Chain Control That Buys Defenders Time</title><link>https://hivesecurity.gitlab.io/blog/minimum-package-age-supply-chain-defense/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/minimum-package-age-supply-chain-defense/</guid><description>Fast takedowns do not protect systems that auto-install malicious packages or extensions in the first minutes after release. Minimum package age turns time into a practical supply chain defense.</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Watchdog Got Bitten: Pegasus Spyware Hit the EU Committee Investigating It</title><link>https://hivesecurity.gitlab.io/blog/pegasus-mercenary-spyware-forensics-pega-committee/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/pegasus-mercenary-spyware-forensics-pega-committee/</guid><description>A member of the EU committee investigating Pegasus abuse was hacked with Pegasus himself. Here is how forensic researchers proved it — and how to run the same detection process yourself.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Your Headphones Have Firmware: FOTA Is the IoT Attack Surface Nobody Patches</title><link>https://hivesecurity.gitlab.io/blog/headphones-fota-iot-firmware-attack-surface/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/headphones-fota-iot-firmware-attack-surface/</guid><description>Bluetooth earbuds, speakers, and IoT devices now ship with firmware update paths, microphones, pairing protocols, and cloud-adjacent features. That does not make every headset a network foothold, but it does make the accessory worth threat-modeling.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>RFC 10008: The New HTTP QUERY Method and the Attack Surface Still Catching Up</title><link>https://hivesecurity.gitlab.io/blog/http-query-method-rfc-10008-attack-surface/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/http-query-method-rfc-10008-attack-surface/</guid><description>IETF published RFC 10008 in June 2026, standardizing the HTTP QUERY method. Here is where WAFs, caches, CORS handling, and CSRF assumptions need review.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>IPV6_FRAG_ESCAPE: The Linux Container Escape Your CVE Scanner May Miss</title><link>https://hivesecurity.gitlab.io/blog/ipv6-frag-escape-linux-container-escape/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ipv6-frag-escape-linux-container-escape/</guid><description>IPV6_FRAG_ESCAPE is a Linux kernel 6.12 privilege escalation with public PoC code, no CVE at disclosure time, and a practical path from container user to host root.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>FBI Seizes NetNut: How a 2-Million-Device Proxy Botnet Hid Inside Smart TVs</title><link>https://hivesecurity.gitlab.io/blog/netnut-popa-botnet-fbi-seizure-residential-proxy/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/netnut-popa-botnet-fbi-seizure-residential-proxy/</guid><description>The FBI seized hundreds of domains tied to NetNut after Google and security researchers linked the residential proxy network to Popa, a 2-million-device botnet of smart TVs and streaming boxes.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ChocoPoC: The Exploit You Cloned Is the Attack</title><link>https://hivesecurity.gitlab.io/blog/chocopoc-trojanized-poc-exploits-researchers-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/chocopoc-trojanized-poc-exploits-researchers-2026/</guid><description>ChocoPoC hides a remote access trojan inside trojanized CVE proof-of-concept repositories on GitHub, using a malicious PyPI dependency chain to compromise the researchers who clone them.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>LSHIY Password Spray: ROPC and MFA Gaps in Microsoft 365</title><link>https://hivesecurity.gitlab.io/blog/lshiy-password-spray-ropc-mfa-bypass-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/lshiy-password-spray-ropc-mfa-bypass-2026/</guid><description>A June 2026 password spray from LSHIY LLC&apos;s IPv6 range compromised 78 Microsoft accounts across 64 organizations by abusing Azure CLI ROPC sign-ins that MFA policies did not cover.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Clean Repo Trap: AI Coding Agents and the Trust Boundary Problem</title><link>https://hivesecurity.gitlab.io/blog/claude-code-clean-repo-trap/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/claude-code-clean-repo-trap/</guid><description>A 0DIN proof of concept against Claude Code demonstrates how a clean-looking repository can lead to runtime command execution. The structural risk behind the attack applies to any AI coding agent with shell access.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Your Favicon Is Leaking Your Entire Infrastructure</title><link>https://hivesecurity.gitlab.io/blog/favicon-hash-shodan-infrastructure-fingerprinting/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/favicon-hash-shodan-infrastructure-fingerprinting/</guid><description>A single 16x16 icon file can expose hundreds of servers, bypass WAF protections, and map your entire attack surface — here&apos;s how attackers use favicon hashing with Shodan, and how defenders can stop it.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Google&apos;s Audio Memory: What If the Promises Don&apos;t Hold?</title><link>https://hivesecurity.gitlab.io/blog/google-pixel-audio-memory-privacy-questions/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/google-pixel-audio-memory-privacy-questions/</guid><description>Google&apos;s new Pixel feature listens to your day and remembers it. The company says everything stays on your device. But what if it doesn&apos;t — and does it matter either way?</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate></item><item><title>pedit COW &amp; DirtyClone: Two New Linux Root Exploits That Bypass On-Disk Integrity Checks</title><link>https://hivesecurity.gitlab.io/blog/linux-lpe-pedit-cow-dirtyclone-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/linux-lpe-pedit-cow-dirtyclone-2026/</guid><description>CVE-2026-46331 and CVE-2026-43503 both corrupt the Linux page cache via network subsystems to grant root — bypassing file integrity tools like AIDE and Tripwire without touching files on disk.</description><pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Trump Died of Rabies — And What That Means for Your Package Manager</title><link>https://hivesecurity.gitlab.io/blog/slopsquatting-ai-hallucination-package-supply-chain-attack/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/slopsquatting-ai-hallucination-package-supply-chain-attack/</guid><description>When DuckDuckGo&apos;s AI killed Trump with rabies, the world laughed. When AI coding assistants invent package names, attackers register them. Nobody&apos;s laughing then.</description><pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate></item><item><title>One HTTP Header, Full Admin Access: Gitea&apos;s June 2026 Security Release Explained</title><link>https://hivesecurity.gitlab.io/blog/gitea-forgejo-nine-cves-1263-security-release-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/gitea-forgejo-nine-cves-1263-security-release-2026/</guid><description>Gitea 1.26.3 and 1.26.4 addressed a dense security release window, including a 9.8 CRITICAL auth bypass exploitable with a single HTTP header. Here&apos;s what broke and how to fix it.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate></item><item><title>AI Cyber Sovereignty: What Happens When Your Best Defender Can Be Switched Off?</title><link>https://hivesecurity.gitlab.io/blog/ai-cyber-sovereignty-defense-risk-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ai-cyber-sovereignty-defense-risk-2026/</guid><description>Frontier cyber AI is becoming controlled infrastructure. The security risk is not only that attackers get stronger models, but that defenders become dependent on capabilities a vendor or government can withdraw.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Cordyceps and GitHub Actions: When CI/CD Trust Boundaries Become the Supply Chain Attack</title><link>https://hivesecurity.gitlab.io/blog/cordyceps-github-actions-supply-chain-attack/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cordyceps-github-actions-supply-chain-attack/</guid><description>Novee&apos;s Cordyceps research is a reminder that GitHub Actions workflows are executable attack surface, not harmless YAML. Here is how to audit the trust boundary before an outside pull request borrows maintainer authority.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>FortiBleed: Treat Exposed FortiGate Credentials as an Incident, Not a Patch Ticket</title><link>https://hivesecurity.gitlab.io/blog/fortibleed-fortigate-credential-exposure-incident-response/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/fortibleed-fortigate-credential-exposure-incident-response/</guid><description>A reported FortiGate credential-harvesting campaign is a reminder that patched edge appliances can still be compromised. Here is how to verify exposure, contain access, and hunt for follow-on activity.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Prinz Eugen Ransomware Encrypts Your Newest Files First</title><link>https://hivesecurity.gitlab.io/blog/prinz-eugen-ransomware-newest-files-first-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/prinz-eugen-ransomware-newest-files-first-2026/</guid><description>A new Go-based ransomware family prioritizes recently modified files, uses RDP and legitimate remote-management tooling, and leaves no ransom note on disk. Here&apos;s what to hunt and harden.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate></item><item><title>47-Day Certificates Will Make Every Website Look Like a Phishing Site</title><link>https://hivesecurity.gitlab.io/blog/47-day-certificates-attack-surface/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/47-day-certificates-attack-surface/</guid><description>The CA/Browser Forum is cutting TLS certificate lifespans from 398 to 47 days by 2029 to reduce the value of stolen certificates. The fix creates a bigger target: the automation that now issues every certificate on the internet.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Operation Endgame Hits SocGholish: FakeUpdates Takedown</title><link>https://hivesecurity.gitlab.io/blog/operation-endgame-socgholish-fakeupdates-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/operation-endgame-socgholish-fakeupdates-2026/</guid><description>Operation Endgame&apos;s June 2026 action against SocGholish shows why fake browser updates, compromised WordPress sites, and criminal loader infrastructure still matter to defenders.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>QUIC and HTTP/3: The Browser Traffic Your Proxy May Not Be Seeing</title><link>https://hivesecurity.gitlab.io/blog/quic-http3-casb-proxy-blind-spot/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/quic-http3-casb-proxy-blind-spot/</guid><description>QUIC and HTTP/3 can change the path browser traffic takes through enterprise controls. Here is why TCP-focused inspection can miss policy violations, how to test it, and what defenders should fix.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>ShinyHunters Were Inside Two Weeks Before Oracle Noticed</title><link>https://hivesecurity.gitlab.io/blog/oracle-peoplesoft-zero-day-shinyhunters-cve-2026-35273/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/oracle-peoplesoft-zero-day-shinyhunters-cve-2026-35273/</guid><description>A critical, unauthenticated RCE in Oracle PeopleSoft let ShinyHunters compromise universities and other organizations for weeks before Oracle&apos;s advisory caught up. Google notified 100+ potentially exposed organizations. The technical breakdown, IOCs, and what to hunt for.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Insider Threat in 2026: The Risk Is Not Who You Trust, But What They Can Reach</title><link>https://hivesecurity.gitlab.io/blog/insider-threat-trusted-access-risk-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/insider-threat-trusted-access-risk-2026/</guid><description>Insider threat is not only about malicious employees. It is about trusted access, forgotten accounts, stolen sessions, and the controls that decide how far one identity can go.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Pwnd Blaster: How a $280 Soundbar Becomes a Wireless BadUSB</title><link>https://hivesecurity.gitlab.io/blog/pwnd-blaster-katana-v2x-bluetooth-badusb/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/pwnd-blaster-katana-v2x-bluetooth-badusb/</guid><description>A Bluetooth flaw in Creative&apos;s Sound Blaster Katana V2X lets anyone within 15 meters flash malicious firmware and turn the soundbar into a keystroke-injecting keyboard — no pairing required.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>When AI Insiders Walk Away: Google&apos;s Moral Compass Problem Is a User Trust Problem</title><link>https://hivesecurity.gitlab.io/blog/google-ai-military-contracts-moral-compass-risk/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/google-ai-military-contracts-moral-compass-risk/</guid><description>A Google Android security director resigned over Pentagon AI work. The deeper question is what users should believe when people close to powerful AI systems start walking away.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Your AI Assistant Has Tools. Audit Them Before They Audit You.</title><link>https://hivesecurity.gitlab.io/blog/mcp-llm-setup-audit-home-user-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/mcp-llm-setup-audit-home-user-2026/</guid><description>A practical home-user checklist for auditing MCP servers, AI assistant tools, local permissions, and supply-chain risk before a trusted setup turns into an exposed one.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>How Europol Is Catching Cybercriminals in 2026</title><link>https://hivesecurity.gitlab.io/blog/europol-cybercrime-arrests-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/europol-cybercrime-arrests-2026/</guid><description>Europol does not usually kick down the door. It makes cybercrime investigations cross-border, evidence-rich, and harder for offenders to escape.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>SaaS Hacking: The New Internal Network Attackers Already Use</title><link>https://hivesecurity.gitlab.io/blog/saas-hacking-new-internal-network/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/saas-hacking-new-internal-network/</guid><description>Attackers no longer need malware on every endpoint. With one valid identity, token, or integration, they can move through Microsoft 365, Google Workspace, Salesforce, Slack, GitHub, and other SaaS platforms like an internal network.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate></item><item><title>GreatXML: When a Setup File Unlocks BitLocker</title><link>https://hivesecurity.gitlab.io/blog/greatxml-bitlocker-bypass-winre-defender-offline/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/greatxml-bitlocker-bypass-winre-defender-offline/</guid><description>GreatXML is a public BitLocker-bypass PoC claim involving WinRE, Defender Offline Scan state, and unattend.xml. The defensive lesson is bigger than one repository: recovery environments are security boundaries.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>RoguePlanet: Nightmare Eclipse&apos;s New Windows Defender LPE PoC After the June 2026 Patch</title><link>https://hivesecurity.gitlab.io/blog/rogueplanet-windows-defender-lpe-race-condition/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/rogueplanet-windows-defender-lpe-race-condition/</guid><description>RoguePlanet is the latest public Nightmare Eclipse proof-of-concept targeting Microsoft Defender. The code points to a race condition that turns Defender cleanup behavior into SYSTEM execution.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>N-days Are Becoming N-hours</title><link>https://hivesecurity.gitlab.io/blog/ai-n-day-exploits-patch-gap-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ai-n-day-exploits-patch-gap-2026/</guid><description>Anthropic&apos;s June 2026 N-day research shows how frontier models can turn public patches into working exploits in hours. Here&apos;s what defenders should change now.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Court Said Stop. Meta Says NSO Group Didn&apos;t Listen.</title><link>https://hivesecurity.gitlab.io/blog/nso-group-whatsapp-contempt-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/nso-group-whatsapp-contempt-2026/</guid><description>Meta says NSO Group violated a federal court&apos;s permanent injunction within months of receiving it by running new social engineering attempts against WhatsApp users. Meta is now seeking contempt of court.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Meta&apos;s Hidden NameTag: Facial Recognition Code for Smart Glasses Is Already in a 50M-Download App</title><link>https://hivesecurity.gitlab.io/blog/meta-nametag-facial-recognition-smart-glasses-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/meta-nametag-facial-recognition-smart-glasses-2026/</guid><description>Wired found dormant facial recognition code in Meta&apos;s AI app. It has not been activated for consumers, but researchers manually triggered a 2,048-dimensional faceprint pipeline.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Miasma and Mini Shai-Hulud: When npm Malware Learned to Persist in AI Coding Agents</title><link>https://hivesecurity.gitlab.io/blog/miasma-mini-shai-hulud-ai-agent-supply-chain-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/miasma-mini-shai-hulud-ai-agent-supply-chain-2026/</guid><description>Mini Shai-Hulud and Miasma show how supply chain malware can move from npm install-time execution into Claude Code hooks, VS Code tasks, and CI/CD persistence.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Post-Quantum Security: Who Is Ready?</title><link>https://hivesecurity.gitlab.io/blog/post-quantum-security-who-is-ready/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/post-quantum-security-who-is-ready/</guid><description>Some vendors have already deployed post-quantum protections. Most enterprises have not. Here is who is moving first, where the gaps remain, and what security teams should do now.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate></item><item><title>You Are Now the Minority: Bots Have Officially Taken Over the Internet</title><link>https://hivesecurity.gitlab.io/blog/bots-overtake-human-internet-traffic-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/bots-overtake-human-internet-traffic-2026/</guid><description>2026 reports confirm bots now generate 53% of all internet traffic — the second year running that automated traffic outnumbers humans. Here&apos;s what that actually means.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The AI Evasion Lab</title><link>https://hivesecurity.gitlab.io/blog/ai-edr-evasion-cursor-claude-opus-sophos-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ai-edr-evasion-cursor-claude-opus-sophos-2026/</guid><description>Sophos X-Ops uncovered a threat actor using Claude Opus 4.5 and Cursor IDE to build an automated, modular EDR evasion framework — 80 modules, 70+ techniques, tested against Sophos, CrowdStrike, and Defender.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Why Finland and Japan Consistently Top Every Cybersecurity Metric</title><link>https://hivesecurity.gitlab.io/blog/socioeconomic-factors-national-cybersecurity-finland-japan/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/socioeconomic-factors-national-cybersecurity-finland-japan/</guid><description>Finland and Japan lead global cybersecurity rankings across multiple independent measures. The explanation is not primarily technical — it is socioeconomic.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate></item><item><title>No One in the Loop: The Autonomous Weapons Race</title><link>https://hivesecurity.gitlab.io/blog/autonomous-weapons-no-one-in-the-loop-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/autonomous-weapons-no-one-in-the-loop-2026/</guid><description>China&apos;s so-called &apos;kill them all&apos; drone algorithm made headlines. But the real story is bigger: major militaries are racing to reduce human involvement in lethal decisions, and the window to regulate them is narrowing.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate></item><item><title>OAuth Consent Phishing in 2026: MFA Stops Password Theft, Not Bad App Grants</title><link>https://hivesecurity.gitlab.io/blog/oauth-consent-phishing-app-grants-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/oauth-consent-phishing-app-grants-2026/</guid><description>Attackers do not always need your password. A single OAuth consent grant can give a malicious or compromised app durable access to mail, files, calendars, and SaaS data.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Bug Hunting in Browsers: Discovery Is Becoming the Easy Part</title><link>https://hivesecurity.gitlab.io/blog/ai-browser-security-scale-mythos-future-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ai-browser-security-scale-mythos-future-2026/</guid><description>Mozilla used Claude Mythos Preview to identify and fix 271 Firefox security bugs, while Chrome shipped a separate 151-fix security update. The lesson is not that AI replaces security teams. It is that patching, triage, and verification are becoming the bottleneck.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>Poisoned AI: How Hugging Face Became a Malware Distribution Platform</title><link>https://hivesecurity.gitlab.io/blog/huggingface-ai-supply-chain-attacks-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/huggingface-ai-supply-chain-attacks-2026/</guid><description>A fake OpenAI repo hit #1 trending on Hugging Face with 244K downloads in 18 hours. Here&apos;s every attack vector targeting AI model repositories — and how to defend against them.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate></item><item><title>The IT Guy Who Wasn&apos;t: How Attackers Walk Through Your Front Door</title><link>https://hivesecurity.gitlab.io/blog/physical-social-engineering-office-threats-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/physical-social-engineering-office-threats-2026/</guid><description>Physical social engineering is back — and the attacker doesn&apos;t have to be an IT guy. Learn how anyone with the right uniform and pretext can walk through your front door, and how organizations can fight back.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>Quasar Linux QLNX: A Developer Workstation RAT Built for Supply Chain Access</title><link>https://hivesecurity.gitlab.io/blog/quasar-linux-qlnx-supply-chain-rat/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/quasar-linux-qlnx-supply-chain-rat/</guid><description>Trend Micro documented QLNX, a Linux RAT that combines credential harvesting, LD_PRELOAD persistence, PAM backdoors, and rootkit behavior. The real risk is not one infected host - it is the supply chain access behind it.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>GitHub Finally Puts a Human in the Loop: npm Staged Publishing Explained</title><link>https://hivesecurity.gitlab.io/blog/github-npm-staged-publishing-supply-chain-defense-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/github-npm-staged-publishing-supply-chain-defense-2026/</guid><description>npm packages no longer publish instantly. GitHub&apos;s staged publishing forces a 2FA-gated human approval before any version hits the registry — here&apos;s what it means and how to enable it.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate></item><item><title>Netherlands Seized 800 Servers: Bulletproof Hosting Is Now a Sanctions Problem</title><link>https://hivesecurity.gitlab.io/blog/netherlands-seizes-800-servers-stark-industries-hosting/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/netherlands-seizes-800-servers-stark-industries-hosting/</guid><description>Dutch investigators seized more than 800 servers in a sanctions case tied to Stark Industries. The lesson for defenders is simple: attacker infrastructure is a business ecosystem.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate></item><item><title>Trusted Email Is the New Phishing Infrastructure</title><link>https://hivesecurity.gitlab.io/blog/trusted-email-is-the-new-phishing-infrastructure/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/trusted-email-is-the-new-phishing-infrastructure/</guid><description>Scammers are abusing legitimate notification systems from Microsoft, Google, PayPal, Docusign, and other trusted platforms. The message can pass SPF, DKIM, and DMARC because the platform really sent it.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate></item><item><title>Verizon DBIR 2026: The Remediation Paradox</title><link>https://hivesecurity.gitlab.io/blog/verizon-dbir-2026-remediation-paradox/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/verizon-dbir-2026-remediation-paradox/</guid><description>Verizon&apos;s 2026 DBIR confirms vulnerability exploitation as the #1 breach vector for the first time in 19 years — while remediation rates dropped and patch times increased. Here&apos;s what the data actually says.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>SSH-keysign-pwn: The Nine-Year Linux Kernel Flaw</title><link>https://hivesecurity.gitlab.io/blog/cve-2026-46333-ssh-keysign-pwn-linux-kernel/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cve-2026-46333-ssh-keysign-pwn-linux-kernel/</guid><description>CVE-2026-46333 (ssh-keysign-pwn) is a nine-year-old Linux kernel race condition that lets an unprivileged local user steal SSH host keys and dump /etc/shadow. Root command execution is also possible on specific configurations.</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>GitHub&apos;s VS Code Extension Breach: What We Know, What We Don&apos;t, and How to Defend</title><link>https://hivesecurity.gitlab.io/blog/github-breach-vscode-extension-teampcp-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/github-breach-vscode-extension-teampcp-2026/</guid><description>GitHub says an employee device was compromised through a poisoned third-party VS Code extension and internal repositories were exfiltrated. Here is the fact-checked breakdown for defenders.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>Your Firewall Just Became Their Foothold</title><link>https://hivesecurity.gitlab.io/blog/cisco-sdwan-palo-alto-network-infrastructure-crisis-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cisco-sdwan-palo-alto-network-infrastructure-crisis-2026/</guid><description>CVE-2026-20182 (CVSS 10.0) and CVE-2026-0300 (CVSS 9.3) hit simultaneously — one owns your firewall, the other poisons your entire SD-WAN fabric.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate></item><item><title>Ransomware Doesn&apos;t Need to Encrypt Anymore — And That&apos;s the Point</title><link>https://hivesecurity.gitlab.io/blog/ransomware-evolution-2026-extortion-over-encryption/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ransomware-evolution-2026-extortion-over-encryption/</guid><description>22% of ransomware incidents in 2026 involve no encryption at all. The threat model has shifted from disruption to silent exfiltration — and most defenses haven&apos;t caught up.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-42897: Exchange Server Zero-Day Executes JavaScript Through Your Inbox</title><link>https://hivesecurity.gitlab.io/blog/cve-2026-42897-exchange-server-owa-xss-zero-day/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cve-2026-42897-exchange-server-owa-xss-zero-day/</guid><description>Microsoft&apos;s on-prem Exchange Server has an actively exploited XSS zero-day (CVSS 8.1). A single crafted email in OWA triggers arbitrary JavaScript — here&apos;s how it works and how to stop it.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate></item><item><title>$10 Million Ransom, Four Days of Peace, and Then the Login Page Changed</title><link>https://hivesecurity.gitlab.io/blog/shinyhunters-canvas-breach-ransom-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/shinyhunters-canvas-breach-ransom-2026/</guid><description>ShinyHunters breached Canvas LMS, stole 275 million students&apos; data, took the ransom — and attacked again four days later. Here&apos;s who they are and why arrests haven&apos;t stopped them.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>Unmasking TeamPCP: The Supply Chain Saboteurs and the Trails They Left Behind</title><link>https://hivesecurity.gitlab.io/blog/unmasking-teampcp-attribution-supply-chain/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/unmasking-teampcp-attribution-supply-chain/</guid><description>TeamPCP has compromised hundreds of open-source packages and stolen half a million credentials. But their OPSEC is leaking — and someone is already hunting them.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>YellowKey: The BitLocker Bypass Hidden in Windows Recovery</title><link>https://hivesecurity.gitlab.io/blog/yellowkey-bitlocker-bypass-winre-windows-11/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/yellowkey-bitlocker-bypass-winre-windows-11/</guid><description>A researcher discovered a zero-day that bypasses BitLocker encryption on Windows 11 using a USB stick and the recovery environment — and suspects the component may be intentional. CVE-2026-45585, CVSS 6.8. Microsoft released an official mitigation on May 21, 2026.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>500 Microsoft CVEs Later — We&apos;re Still Measuring Security Wrong</title><link>https://hivesecurity.gitlab.io/blog/cve-counts-dont-measure-security-ecosystem-response/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cve-counts-dont-measure-security-ecosystem-response/</guid><description>Microsoft patched 500+ vulnerabilities in five months. Linux ecosystems patched even more. So which is more secure? That&apos;s the wrong question — here&apos;s the metric that actually matters.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>Shai-Hulud: The Open-Source GitHub Actions Token Harvester That Just Went Public</title><link>https://hivesecurity.gitlab.io/blog/shai-hulud-github-actions-supply-chain-attack/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/shai-hulud-github-actions-supply-chain-attack/</guid><description>TeamPCP&apos;s Shai-Hulud is a TypeScript/Bun C2 framework targeting GitHub Actions CI/CD pipelines — it steals GitHub tokens, exfiltrates via a fake git domain, and has now been open-sourced for anyone to deploy.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate></item><item><title>The Cache That Bites Back: GitHub Actions Cache Poisoning Attacks</title><link>https://hivesecurity.gitlab.io/blog/github-actions-cache-poisoning-supply-chain/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/github-actions-cache-poisoning-supply-chain/</guid><description>How attackers turn GitHub Actions&apos; shared build cache into a supply chain weapon — real cases, attack mechanics, detection logic, and mitigations.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate></item><item><title>When the Weapon Learns: How Nation-States Weaponized AI Across the Full Attack Chain</title><link>https://hivesecurity.gitlab.io/blog/ai-weaponized-nation-state-attack-chain-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ai-weaponized-nation-state-attack-chain-2026/</guid><description>Google GTIG&apos;s May 2026 report documents a turning point: state actors now use AI to write zero-day exploits, build self-navigating backdoors, and poison the AI supply chain itself.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate></item><item><title>Europe&apos;s Digital Independence Push: EuroStack, Sovereign Cloud, and Breaking Free from US Infrastructure</title><link>https://hivesecurity.gitlab.io/blog/eu-digital-sovereignty-eurostack-payments-cloud-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/eu-digital-sovereignty-eurostack-payments-cloud-2026/</guid><description>France is migrating 2.5 million government PCs to Linux. Europe is building its own payment network to rival Visa and Mastercard. EuroStack aims to replace AWS and Azure. Here&apos;s what&apos;s happening, why it matters for security, and how realistic it is.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>Dirty Frag &amp; Copy Fail: Two New Linux Kernel Vulnerabilities Grant Root Privileges</title><link>https://hivesecurity.gitlab.io/blog/linux-dirty-frag-copy-fail-kernel-vulnerabilities-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/linux-dirty-frag-copy-fail-kernel-vulnerabilities-2026/</guid><description>Two new Linux kernel vulnerabilities — Dirty Frag (CVE-2026-43284/43500) and Copy Fail (CVE-2026-31431) — enable local privilege escalation to root on nearly all major distros. What users and admins need to know.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>CallPhantom: How 28 Fake Apps Collected Payments for Data That Never Existed</title><link>https://hivesecurity.gitlab.io/blog/callphantom-fake-call-history-apps-android-fraud/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/callphantom-fake-call-history-apps-android-fraud/</guid><description>ESET uncovered CallPhantom — 28 Android apps with 7.3M downloads that sold fabricated call histories. A deep dive into the fraud mechanics, billing bypass, and how to protect yourself.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>AD Attack Chains: From Initial Access to Domain Admin</title><link>https://hivesecurity.gitlab.io/blog/ad-attack-chains-initial-access-to-domain-admin/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ad-attack-chains-initial-access-to-domain-admin/</guid><description>A complete purple team walkthrough of Active Directory attack chains — from initial foothold through Kerberoasting, DCSync, and Golden Tickets to full domain compromise, with detection rules for every technique.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>ADCS Abuse with Certipy: From Low-Priv User to Domain Admin via Certificate Services</title><link>https://hivesecurity.gitlab.io/blog/adcs-abuse-certipy-esc1-esc8-attack-chains/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/adcs-abuse-certipy-esc1-esc8-attack-chains/</guid><description>Active Directory Certificate Services is installed in most enterprise networks — and almost always misconfigured. Here&apos;s how attackers exploit ESC1 through ESC8 with Certipy, and how to detect and stop them.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Agentic AI: The Enterprise Blind Spot That Attackers Already Found</title><link>https://hivesecurity.gitlab.io/blog/agentic-ai-enterprise-blind-spot-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/agentic-ai-enterprise-blind-spot-2026/</guid><description>Autonomous AI agents are already inside enterprise environments — and most security teams have no idea what they&apos;re doing. Here&apos;s what attackers exploit and how to defend against it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>AI Agent Traps: Six Ways Attackers Manipulate Autonomous AI — With Real Examples</title><link>https://hivesecurity.gitlab.io/blog/ai-agent-traps-manipulation-taxonomy-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ai-agent-traps-manipulation-taxonomy-2026/</guid><description>Google DeepMind published the first systematic taxonomy of AI agent manipulation techniques. Here&apos;s what each attack looks like in practice — and why most AI deployments are already vulnerable.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>AirSnitch: How Attackers Silently Break Wi-Fi Client Isolation</title><link>https://hivesecurity.gitlab.io/blog/airsnitch-wifi-client-isolation-bypass-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/airsnitch-wifi-client-isolation-bypass-2026/</guid><description>AirSnitch bypasses Wi-Fi client isolation using four attack primitives — even on WPA3. Every router tested was vulnerable. Here&apos;s how it works and how to defend against it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>AitM Phishing: How Attackers Bypass MFA and How to Stop Them</title><link>https://hivesecurity.gitlab.io/blog/aitm-phishing-mfa-bypass-evilginx/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/aitm-phishing-mfa-bypass-evilginx/</guid><description>Adversary-in-the-Middle phishing silently proxies real login pages and steals session tokens — making MFA useless. Here&apos;s how it works and how to detect it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>API Security in 2026: JWT Attacks, OAuth Abuse, and GraphQL Exploitation</title><link>https://hivesecurity.gitlab.io/blog/api-security-jwt-oauth-graphql-attacks/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/api-security-jwt-oauth-graphql-attacks/</guid><description>APIs are the most exploited attack surface in 2026. Learn how attackers abuse JWT tokens, OAuth flows, and GraphQL endpoints — and how to stop them.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>The World&apos;s Most Dangerous Hacking Teams: A Guide to Nation-State APT Groups</title><link>https://hivesecurity.gitlab.io/blog/apt-groups-nation-state-hackers-guide-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/apt-groups-nation-state-hackers-guide-2026/</guid><description>Meet the elite state-sponsored hacking groups that stole billions, blacked out cities, and infiltrated governments. Who they are, what they want, and how they operate in 2026.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Attack to Defend: Why the Best Security Professionals Think on Both Sides</title><link>https://hivesecurity.gitlab.io/blog/attack-to-defend-offensive-defensive-mindset/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/attack-to-defend-offensive-defensive-mindset/</guid><description>The most dangerous defenders understand how attackers think. The best red teamers understand what defenders see. Here&apos;s why the divide between offense and defense is killing your security program.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>AutoHotkey Malware Loaders: How Attackers Weaponize Automation Scripts</title><link>https://hivesecurity.gitlab.io/blog/autohotkey-malware-loader-attack-detect/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/autohotkey-malware-loader-attack-detect/</guid><description>AutoHotkey isn&apos;t just for productivity scripts — attackers use it as a stealthy malware loader. Learn how AHK-based campaigns work and how to detect them.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>AWS IAM Privilege Escalation to Data Exfil: The Full Attack Chain</title><link>https://hivesecurity.gitlab.io/blog/aws-iam-privilege-escalation-data-exfil-attack-detect/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/aws-iam-privilege-escalation-data-exfil-attack-detect/</guid><description>How attackers escalate from a low-privilege AWS IAM credential to full S3 data theft — and the CloudTrail events, GuardDuty findings, and Sigma rules that expose them.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>What It Really Takes to Become a True SOC Professional</title><link>https://hivesecurity.gitlab.io/blog/become-true-soc-professional/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/become-true-soc-professional/</guid><description>Discover the real skills, mindset, and strategies needed to become a genuine SOC professional—from technical mastery to standing out in job hunts.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>BloodHound CE: Map Active Directory Attack Paths to Domain Admin (2026)</title><link>https://hivesecurity.gitlab.io/blog/bloodhound-practical-guide-ad-attack-paths/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/bloodhound-practical-guide-ad-attack-paths/</guid><description>Run SharpHound, read attack graphs, abuse ACL misconfigurations and Kerberoastable accounts — step-by-step path to Domain Admin in Active Directory.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Browser Vendors Fail Users: Millions Infected, Zero Notifications Sent</title><link>https://hivesecurity.gitlab.io/blog/browser-extension-notification-crisis/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/browser-extension-notification-crisis/</guid><description>840,000 GhostPoster victims, 3.2M+ in GitLab campaign, 4.3M+ in ShadyPanda—browser vendors removed extensions but never told users. Self-regulation failed.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Browser-in-the-Browser: The Phishing Attack That Fakes the Browser Itself</title><link>https://hivesecurity.gitlab.io/blog/browser-in-the-browser-bitb-phishing-attack/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/browser-in-the-browser-bitb-phishing-attack/</guid><description>Browser-in-the-Browser (BitB) attacks forge convincing browser popup windows using pure HTML and CSS — making phishing pages nearly impossible to spot by eye. Here&apos;s how it works and how to defend against it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>BYOVD: How Attackers Use Legitimate Drivers to Kill Your Security Tools</title><link>https://hivesecurity.gitlab.io/blog/byovd-bring-your-own-vulnerable-driver-attacks/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/byovd-bring-your-own-vulnerable-driver-attacks/</guid><description>BYOVD (Bring Your Own Vulnerable Driver) lets attackers reach the Windows kernel using signed, legitimate drivers — and then silently kill your EDR before ransomware drops.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>C2 Without Owning C2: When Attackers Use Your Trusted Services</title><link>https://hivesecurity.gitlab.io/blog/c2-without-owning-c2/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/c2-without-owning-c2/</guid><description>Attackers no longer need their own infrastructure. Learn how Dead Drop C2, Living off Trusted Services, and reputation laundering work—and why traditional defenses fail.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Canary Tokens: Free Tripwires That Catch Attackers in the Act</title><link>https://hivesecurity.gitlab.io/blog/canary-tokens-deception-blue-team/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/canary-tokens-deception-blue-team/</guid><description>Canary tokens are digital tripwires that alert you the moment an attacker touches something they shouldn&apos;t. Free, no-install, and zero false positives.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>The Build Is the Target: CI/CD Pipeline Attacks and How to Detect Them</title><link>https://hivesecurity.gitlab.io/blog/cicd-pipeline-attacks-detect-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cicd-pipeline-attacks-detect-2026/</guid><description>Your CI/CD pipeline stores production credentials, runs code automatically, and trusts pull requests. Here&apos;s how attackers exploit that — and the detection logic to catch them.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Claude Mythos: The AI That Rewrites the Rules of Cybersecurity — For Everyone</title><link>https://hivesecurity.gitlab.io/blog/claude-mythos-what-it-means-for-everyone-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/claude-mythos-what-it-means-for-everyone-2026/</guid><description>Anthropic built an AI that autonomously discovered a 27-year-old vulnerability in widely-used code. It can build working exploits from scratch. It&apos;s too dangerous to release publicly. Here&apos;s what that means for your bank, your government, your code — and the future of digital security.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>The &apos;Fix&apos; Is the Exploit: ClickFix, FileFix, JackFix and Pastejacking Attacks Explained</title><link>https://hivesecurity.gitlab.io/blog/clickfix-filefix-pastejacking-attacks-explained/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/clickfix-filefix-pastejacking-attacks-explained/</guid><description>ClickFix attacks trick users into running malicious code disguised as legitimate troubleshooting. Learn how these social engineering tactics work and how to defend against them.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Cobalt Strike Detection &amp; Hunting: A Defender&apos;s Playbook</title><link>https://hivesecurity.gitlab.io/blog/cobalt-strike-detection-hunting/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cobalt-strike-detection-hunting/</guid><description>How to detect Cobalt Strike beacons in your environment — network fingerprints, process injection patterns, Sigma rules, and practical hunting queries for blue teams.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>CrackArmor: Nine AppArmor Flaws That Let Attackers Own the Kernel</title><link>https://hivesecurity.gitlab.io/blog/crackarmor-apparmor-vulnerabilities-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/crackarmor-apparmor-vulnerabilities-2026/</guid><description>Qualys TRU disclosed nine confused deputy vulnerabilities in Linux AppArmor — exposing 12.6 million servers to root escalation, KASLR bypass, and container isolation collapse. Technical deep dive and detection guide.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>CSRF Explained: How Attackers Trick Your Browser Into Making Requests for Them</title><link>https://hivesecurity.gitlab.io/blog/csrf-cross-site-request-forgery-complete-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/csrf-cross-site-request-forgery-complete-guide/</guid><description>CSRF (Cross-Site Request Forgery) forces authenticated users to unknowingly submit requests to a site they&apos;re logged into. Learn how it works, how to find it, and how to fix it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Cybersecurity Careers: What the Job Actually Looks Like (Not the Movie Version)</title><link>https://hivesecurity.gitlab.io/blog/cybersecurity-career-guide-real-roles-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cybersecurity-career-guide-real-roles-2026/</guid><description>A realistic guide to cybersecurity career paths in 2026 — from SOC analyst to GRC, threat intel, AppSec, cloud security, and DFIR. What each role actually does every day.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>DCSync: How Attackers Steal Every Password in Your Domain — and How to Stop Them</title><link>https://hivesecurity.gitlab.io/blog/dcsync-attack-detect-and-defend/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/dcsync-attack-detect-and-defend/</guid><description>DCSync abuses Active Directory replication to pull every password hash from a domain controller without touching it. Here&apos;s how the attack works, what it leaves in your logs, and how to build detections that catch it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>DFIR 2026: Memory Forensics, Windows Artifacts, and Incident Response</title><link>https://hivesecurity.gitlab.io/blog/dfir-incident-response-complete-guide-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/dfir-incident-response-complete-guide-2026/</guid><description>Memory forensics, Windows event artifacts, and IR methodology — from initial alert to post-incident report. Tools, commands, and playbooks included.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>The Digital Parasite: How Attacker Tradecraft Evolved in 2026</title><link>https://hivesecurity.gitlab.io/blog/digital-parasite-attacker-tradecraft-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/digital-parasite-attacker-tradecraft-2026/</guid><description>80% of top MITRE ATT&amp;CK techniques now focus on evasion and persistence. Attackers abandoned smash-and-grab for long-term parasitic operations in networks.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Entra ID Attacks in Practice: Device Code Phishing, PRT Theft, and Conditional Access Bypass</title><link>https://hivesecurity.gitlab.io/blog/entra-id-attacks-device-code-prt-conditional-access/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/entra-id-attacks-device-code-prt-conditional-access/</guid><description>MFA is no longer enough to protect Microsoft Entra ID accounts. Attackers steal tokens, register their own devices, and bypass Conditional Access — without ever touching a password. Here&apos;s the full attack chain and how to detect it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Why You Should Remove GAID From Your Android Phone Today</title><link>https://hivesecurity.gitlab.io/blog/gaid-removal-android-privacy/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/gaid-removal-android-privacy/</guid><description>Discover why removing Google Advertising ID (GAID) from your Android device is crucial for privacy. Learn the simple steps to delete GAID and protect your data in 2026.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>GitHub Secrets Management Crisis: 65% of AI Companies Leaked Credentials</title><link>https://hivesecurity.gitlab.io/blog/github-secrets-management-crisis-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/github-secrets-management-crisis-2026/</guid><description>65% of Forbes AI 50 companies leaked secrets on GitHub with 94-day median remediation time. Blue team guide to detect, prevent, and respond to repository leaks.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Hacking Prison Sentences: Real Convictions That Should Terrify You</title><link>https://hivesecurity.gitlab.io/blog/hacking-prison-sentences-real-convictions/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/hacking-prison-sentences-real-convictions/</guid><description>From 10 years to life in prison - real cybercrime convictions from Europe, USA, and Asia. DDoS, ransomware, and data theft aren&apos;t victimless crimes.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Identity-First Attacks in Cloud: How Permissions Become the New Perimeter</title><link>https://hivesecurity.gitlab.io/blog/identity-first-attacks-cloud/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/identity-first-attacks-cloud/</guid><description>Cloud attackers exploit IAM permissions, not vulnerabilities. Learn the 4-phase attack chain from initial access to data exfiltration and detection strategies.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>IDOR Explained: How Attackers Access Anyone&apos;s Data by Changing a Number</title><link>https://hivesecurity.gitlab.io/blog/idor-insecure-direct-object-reference-complete-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/idor-insecure-direct-object-reference-complete-guide/</guid><description>IDOR (Insecure Direct Object Reference) is one of the most common and most impactful web vulnerabilities. Learn how it works, how to find it, and how to fix it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Invisible Characters as an Attack Vector</title><link>https://hivesecurity.gitlab.io/blog/invisible-characters-attack-vector/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/invisible-characters-attack-vector/</guid><description>Unicode&apos;s invisible characters are being weaponized — hiding malicious code in repositories, hijacking AI agents, and bypassing security reviews without leaving a trace visible to human eyes.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>The EDR Dead Zone: How Attackers Pivot Through Cameras and NAS Devices</title><link>https://hivesecurity.gitlab.io/blog/iot-pivot-cameras-nas-edr-dead-zone/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/iot-pivot-cameras-nas-edr-dead-zone/</guid><description>IoT devices like IP cameras and NAS boxes sit on your network but outside your EDR coverage. Here&apos;s how attackers exploit them to pivot — and how defenders can detect it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Kimwolf Botnet: 2 Million Hijacked Devices Reshaping Threat Landscape</title><link>https://hivesecurity.gitlab.io/blog/kimwolf-botnet-threat-intelligence-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/kimwolf-botnet-threat-intelligence-2026/</guid><description>The Kimwolf botnet has compromised over 2 million devices worldwide by exploiting residential proxy networks and unsecured Android TV boxes. Here&apos;s what threat intelligence reveals about its infrastructure, tactics, and how to defend against it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>The Linux Server Attack Surface You Didn&apos;t Install: Default Services That Open Your System</title><link>https://hivesecurity.gitlab.io/blog/linux-default-attack-surface/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/linux-default-attack-surface/</guid><description>Every major Linux distro ships services you never asked for. From snapd to CUPS to rpcbind — a practical audit guide covering Ubuntu, Debian, RHEL, Rocky, Fedora, and openSUSE.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Linux Lateral Movement: Attack Techniques and How to Detect Them</title><link>https://hivesecurity.gitlab.io/blog/linux-lateral-movement-attack-detect-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/linux-lateral-movement-attack-detect-2026/</guid><description>A complete guide to Linux lateral movement — SSH pivoting, ssh-agent hijacking, credential harvesting, port forwarding, and NFS abuse. Includes auditd rules, Sigma, Wazuh, and Sentinel KQL detections.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Linux Privilege Escalation: Attack Techniques and How to Detect Them</title><link>https://hivesecurity.gitlab.io/blog/linux-privilege-escalation-attack-detect-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/linux-privilege-escalation-attack-detect-2026/</guid><description>A complete guide to Linux privilege escalation — SUID abuse, sudo misconfig, cron hijacking, capabilities, and kernel exploits. Includes auditd rules, Sigma, Wazuh, and Sentinel KQL detections.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Trust Me, I&apos;m a Shortcut: How LNK Files Lie to Windows Explorer</title><link>https://hivesecurity.gitlab.io/blog/lnk-shortcut-spoofing-windows-cve-2025-9491/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/lnk-shortcut-spoofing-windows-cve-2025-9491/</guid><description>Windows .lnk shortcut files can show one target while silently executing another. Discover five spoofing techniques including CVE-2025-9491, how attackers exploit them, and how to detect them.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Your Local AI Is Listening — And So Is Everyone Else on Your Network</title><link>https://hivesecurity.gitlab.io/blog/local-ai-tools-open-ports-security-risk/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/local-ai-tools-open-ports-security-risk/</guid><description>Ollama, LM Studio, Jupyter Notebook — you installed them for privacy, but they may be broadcasting your data to your entire network. Here&apos;s what&apos;s actually happening and how to fix it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>LOLBins in 2026: How Attackers Use Windows Against Itself</title><link>https://hivesecurity.gitlab.io/blog/lolbins-living-off-the-land-windows-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/lolbins-living-off-the-land-windows-2026/</guid><description>79% of attacks in 2024 used no malware. Certutil, mshta, rundll32 — execution, persistence, and evasion via Windows built-ins. Detection rules included.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>macOS Offensive Security: How Attackers Exploit Apple&apos;s Unique Attack Surface</title><link>https://hivesecurity.gitlab.io/blog/macos-offensive-security-attack-detect-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/macos-offensive-security-attack-detect-2026/</guid><description>TCC bypass, Keychain theft, Launch Agent persistence, dylib hijacking — how attackers target macOS and how defenders detect them. Attack→Detect with real commands.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>MCP Servers Through an Attacker&apos;s Eyes: What Happens When You Plug In Without Thinking</title><link>https://hivesecurity.gitlab.io/blog/mcp-server-security-risks-attackers-perspective/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/mcp-server-security-risks-attackers-perspective/</guid><description>MCP servers let AI assistants control your tools — but most users install them without understanding the attack surface. Here&apos;s what attackers already know.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>MDR in Plain English: What It Solves That Tools Alone Can&apos;t</title><link>https://hivesecurity.gitlab.io/blog/mdr-and-what-it-is/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/mdr-and-what-it-is/</guid><description>Managed Detection and Response (MDR) delivers 24/7 expert-led threat hunting and active remediation that tools alone can&apos;t provide — and solves the SOC talent shortage at a fraction of the cost.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Mobile Pentesting: How to Attack Android and iOS Apps Like a Professional</title><link>https://hivesecurity.gitlab.io/blog/mobile-pentesting-android-ios-complete-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/mobile-pentesting-android-ios-complete-guide/</guid><description>A practical guide to mobile application penetration testing on Android and iOS — static analysis, dynamic analysis, traffic interception, and the most common vulnerabilities found in real engagements.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Network Penetration Testing: From Nmap Scan to Pivoting Deep Into the Network</title><link>https://hivesecurity.gitlab.io/blog/network-penetration-testing-complete-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/network-penetration-testing-complete-guide/</guid><description>A practical guide to network penetration testing — host discovery, service enumeration, vulnerability exploitation, credential attacks, and pivoting through segmented networks.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Non-Human Identities: The Attack Surface Your Security Team Isn&apos;t Managing</title><link>https://hivesecurity.gitlab.io/blog/non-human-identity-security-biggest-blind-spot-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/non-human-identity-security-biggest-blind-spot-2026/</guid><description>Service accounts, API keys, OAuth tokens and machine credentials now outnumber human identities 144 to 1. Most organizations have zero visibility into them. Attackers do.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>The Package You Trusted: How the Axios Supply Chain Attack Happened</title><link>https://hivesecurity.gitlab.io/blog/npm-supply-chain-attack-axios-teamcp-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/npm-supply-chain-attack-axios-teamcp-2026/</guid><description>On March 31, 2026, a trusted npm package with 400 million monthly downloads was backdoored for three hours. Here&apos;s how it worked and why it keeps happening.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>NTFS Alternate Data Streams: How Attackers Hide in Plain Sight</title><link>https://hivesecurity.gitlab.io/blog/ntfs-alternate-data-streams-ads-hiding-payloads/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ntfs-alternate-data-streams-ads-hiding-payloads/</guid><description>NTFS Alternate Data Streams let attackers hide executables inside innocent-looking files. Learn how ADS works, how malware uses it, and how to detect it with PowerShell, Sysinternals, and Sysmon.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>NTLM Relay in 2026: Microsoft Declared It Dead. Attackers Didn&apos;t Get the Memo.</title><link>https://hivesecurity.gitlab.io/blog/ntlm-relay-attack-detect-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ntlm-relay-attack-detect-2026/</guid><description>Microsoft is officially deprecating NTLM — yet CVE-2025-24054 was actively exploited days after patching, and the Coercion → Relay → ADCS → Domain Admin chain still works in most enterprise environments. Here&apos;s the full 2026 kill chain and how to detect it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>OpenClaw: How the Viral AI Agent Became 2026&apos;s First Major Security Crisis</title><link>https://hivesecurity.gitlab.io/blog/openclaw-ai-agent-security-crisis-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/openclaw-ai-agent-security-crisis-2026/</guid><description>OpenClaw went from 0 to 180,000 GitHub stars in weeks — and then came the RCE, 30,000 exposed instances, and a supply chain attack poisoning its entire skill marketplace.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Pass-the-Hash &amp; Pass-the-Ticket: How Attackers Move Laterally — and How to Catch Them</title><link>https://hivesecurity.gitlab.io/blog/pass-the-hash-pass-the-ticket-attack-and-detect/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/pass-the-hash-pass-the-ticket-attack-and-detect/</guid><description>A practitioner&apos;s guide to PtH and PtT attacks: how they work, what tools attackers use, what evidence they leave behind, and how to build detections with Sigma and Wazuh.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Post-Quantum Cryptography: Prepare Before Your Encryption Breaks</title><link>https://hivesecurity.gitlab.io/blog/post-quantum-cryptography-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/post-quantum-cryptography-guide/</guid><description>Quantum computers will crack today&apos;s encryption — and attackers are already stealing encrypted data to decrypt later. Here&apos;s what post-quantum cryptography means for everyone.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Project Glasswing: Anthropic&apos;s AI That Finds Zero-Days Better Than Humans</title><link>https://hivesecurity.gitlab.io/blog/project-glasswing-anthropic-claude-mythos-cybersecurity/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/project-glasswing-anthropic-claude-mythos-cybersecurity/</guid><description>Anthropic just unveiled Claude Mythos Preview — an AI model too dangerous to release publicly, but powerful enough to find vulnerabilities that evaded detection for decades. Here&apos;s what it means and how to get involved.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Prompt Injection in 2026: From Research Toy to Real CVEs, Agent Hijacking, and Zero-Click Exfiltration</title><link>https://hivesecurity.gitlab.io/blog/prompt-injection-attack-detect-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/prompt-injection-attack-detect-2026/</guid><description>CVE-2025-32711 (EchoLeak) exfiltrated M365 data with zero user interaction. The Anthropic MCP server had three exploitable injection CVEs. OpenAI says AI browsers may never be fully fixed. Here&apos;s the full attack chain — and how to detect it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Purple Teaming on a Budget: Free Tools and Frameworks That Actually Work</title><link>https://hivesecurity.gitlab.io/blog/purple-teaming-budget-free-tools-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/purple-teaming-budget-free-tools-2026/</guid><description>A practical guide to building a purple team program using only free, open-source tools. Covers Atomic Red Team, MITRE Caldera, Sigma rules, Wazuh, and VECTR with real setup examples.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Ransomware Backup Strategy: Why 93% Who Pay Still Lose Data</title><link>https://hivesecurity.gitlab.io/blog/ransomware-backup-strategy-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ransomware-backup-strategy-2026/</guid><description>93% of ransomware victims who pay still discover data theft. Only 29% use multi-layer backup protection. Learn immutability, validation, and org readiness strategies.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Rapid Compromise Triage: First 10 Minutes on Linux and Windows</title><link>https://hivesecurity.gitlab.io/blog/rapid-compromise-triage-linux-windows/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/rapid-compromise-triage-linux-windows/</guid><description>A practical workflow for the first 10 minutes after a suspected breach — commands with explanations for Linux and Windows triage, red flags, and when to escalate.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>72 Hours to Domain Admin: A Red Team Engagement Debrief</title><link>https://hivesecurity.gitlab.io/blog/red-team-engagement-debrief-72-hours-domain-admin/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/red-team-engagement-debrief-72-hours-domain-admin/</guid><description>A step-by-step debrief of a real-world red team engagement — from passive OSINT through AiTM phishing, EDR evasion, and ADCS exploitation to full domain compromise. What worked, what didn&apos;t, and what would have stopped us.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Shadow Credentials: Account Takeover Without a Password</title><link>https://hivesecurity.gitlab.io/blog/shadow-credentials-attack-ad-takeover/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/shadow-credentials-attack-ad-takeover/</guid><description>Shadow Credentials abuse msDS-KeyCredentialLink via DACL misconfiguration to add a rogue certificate, authenticate via PKINIT, and extract NT hashes — no password required.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>SQL Injection 2026: Blind, Time-Based, ORM Bypass, and WAF Evasion</title><link>https://hivesecurity.gitlab.io/blog/sql-injection-complete-guide-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/sql-injection-complete-guide-2026/</guid><description>Still powering major breaches in 2026 — blind injection, time-based attacks, ORM bypasses, WAF evasion. Real payloads and detection queries.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>SSRF Explained: How Attackers Make Servers Fetch Secrets for Them</title><link>https://hivesecurity.gitlab.io/blog/ssrf-server-side-request-forgery-complete-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/ssrf-server-side-request-forgery-complete-guide/</guid><description>Server-Side Request Forgery (SSRF) lets attackers trick a server into making requests on their behalf — reaching internal systems, cloud credentials, and more.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Starkiller: Inside Empire&apos;s C2 GUI — Red Team Playbook and Blue Team Detection</title><link>https://hivesecurity.gitlab.io/blog/starkiller-empire-red-blue-guide-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/starkiller-empire-red-blue-guide-2026/</guid><description>A technical deep dive into Starkiller and PowerShell Empire — how red teams deploy and operate it, and exactly how defenders can detect and disrupt it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>State-Sponsored Threat Actors 2026: Who They Are and What They Do</title><link>https://hivesecurity.gitlab.io/blog/state-sponsored-threat-actors-2026-deep-dive/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/state-sponsored-threat-actors-2026-deep-dive/</guid><description>A threat intelligence deep-dive into the world&apos;s most dangerous state-sponsored APT groups — their identities, motivations, campaigns, and tradecraft in 2026.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>UEFI Bootkits: The Malware That Lives Below Your Operating System</title><link>https://hivesecurity.gitlab.io/blog/uefi-bootkit-firmware-attacks-explained/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/uefi-bootkit-firmware-attacks-explained/</guid><description>UEFI bootkits survive OS reinstalls, hide from every AV and EDR tool, and can bypass Secure Boot on fully-patched systems. Here&apos;s how they work and what you can do about it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Web Application Penetration Testing 2026: Beyond OWASP Top 10</title><link>https://hivesecurity.gitlab.io/blog/web-pentesting-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/web-pentesting-2026/</guid><description>Advanced web application security testing techniques covering modern frameworks, API exploitation, authentication bypass, and real-world attack scenarios for 2026</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>When Trusted Agents Turn Rogue: The Rise of the Double Agent in Modern AI Systems</title><link>https://hivesecurity.gitlab.io/blog/when-trusted-agents-turn-rogue-double-agent-ai-systems/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/when-trusted-agents-turn-rogue-double-agent-ai-systems/</guid><description>AI agents are trusted to act on your behalf — but that trust is exactly what attackers exploit. Here&apos;s how AI agents get turned against you, and why you won&apos;t see it coming.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Why Changing Your DNS Is One of the Best Privacy Decisions You&apos;ll Make</title><link>https://hivesecurity.gitlab.io/blog/why-change-dns-privacy-security/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/why-change-dns-privacy-security/</guid><description>Your ISP tracks every website you visit through DNS. Learn why changing to privacy-focused DNS providers like Mullvad, Quad9, or DNS4EU is essential for online privacy.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Why Enterprise VPN and Gateway Products Are Perpetually Broken</title><link>https://hivesecurity.gitlab.io/blog/why-enterprise-vpn-gateways-always-vulnerable/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/why-enterprise-vpn-gateways-always-vulnerable/</guid><description>Ivanti, Fortinet, Palo Alto — the names change but the pattern doesn&apos;t. Here&apos;s the structural reason why enterprise edge devices are permanently on fire and what you can do about it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Windows Event Logs for Security Analysts: Read, Hunt, Automate</title><link>https://hivesecurity.gitlab.io/blog/windows-event-log-security-analysis/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/windows-event-log-security-analysis/</guid><description>A practical guide to Windows Event Log analysis for blue teams — key Event IDs, PowerShell automation, cross-version differences, and structured exports for SIEM tools.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>When Your Defender Becomes the Attacker: How Trusted Windows Processes Get Weaponized</title><link>https://hivesecurity.gitlab.io/blog/windows-trusted-process-abuse-defender-attack-surface/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/windows-trusted-process-abuse-defender-attack-surface/</guid><description>Windows Defender and other high-privilege system processes are increasingly targeted by attackers. Learn how security tools become attack surfaces — and what you can do about it.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Wireshark for Threat Detection: A Practical Guide for 2026</title><link>https://hivesecurity.gitlab.io/blog/wireshark-packet-analysis-practical-guide-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/wireshark-packet-analysis-practical-guide-2026/</guid><description>How to find real threats with Wireshark in 2026 — encrypted traffic analysis, JA3 fingerprinting, ransomware patterns, C2 beaconing, and DNS tunneling explained step by step.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Xanthorox AI: When the Attacker&apos;s AI Goes Dark</title><link>https://hivesecurity.gitlab.io/blog/xanthorox-ai-offline-malicious-platform-2025/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/xanthorox-ai-offline-malicious-platform-2025/</guid><description>Xanthorox is an offline, modular AI attack platform with five specialized models — and it needs no cloud, no API, and leaves no traditional IoCs. Here&apos;s what defenders need to know.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>XDR Explained Clearly — What Does It Do That EDR Doesn&apos;t?</title><link>https://hivesecurity.gitlab.io/blog/xdr-vs-edr/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/xdr-vs-edr/</guid><description>Discover the critical differences between XDR and EDR security solutions. Learn why XDR provides cross-domain threat detection that EDR can&apos;t match, and which solution fits your organization in 2026.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>XSS Explained: How Attackers Inject Code Into Your Browser</title><link>https://hivesecurity.gitlab.io/blog/xss-cross-site-scripting-complete-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/xss-cross-site-scripting-complete-guide/</guid><description>Cross-Site Scripting (XSS) lets attackers inject malicious JavaScript into web pages viewed by other users — stealing sessions, redirecting victims, and taking over accounts.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Your Data on the Dark Web: How to Find It Without Ever Opening Tor</title><link>https://hivesecurity.gitlab.io/blog/your-data-on-the-dark-web-how-to-find-it/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/your-data-on-the-dark-web-how-to-find-it/</guid><description>Your email and password are probably already on the dark web. Here&apos;s how to check using real tools — no Tor browser, no .onion sites, no technical expertise needed.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Zero Trust vs. Real Attacks: Which Threats Does It Actually Stop?</title><link>https://hivesecurity.gitlab.io/blog/zerotrust-vs-real-attacks/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/zerotrust-vs-real-attacks/</guid><description>Discover which real-world cyberattacks Zero Trust prevents—and which ones it doesn&apos;t. Analyzed through 2025-2026 breach data including ransomware campaigns, insider threats, supply chain compromises, and social engineering attacks.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Zombie ZIP: How a Malformed Archive Header Blinds 98% of Antivirus Engines</title><link>https://hivesecurity.gitlab.io/blog/zombie-zip-cve-2026-0866-antivirus-bypass/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/zombie-zip-cve-2026-0866-antivirus-bypass/</guid><description>CVE-2026-0866 — a single two-byte header manipulation causes 50 of 51 AV engines to scan compressed noise instead of the actual payload. Technical breakdown, attack scenarios, and detection.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>The Notebook That Stole Your Credentials: Google Colab&apos;s Hidden Security Risks</title><link>https://hivesecurity.gitlab.io/blog/google-colab-security-risks-shared-notebooks/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/google-colab-security-risks-shared-notebooks/</guid><description>Millions run shared Colab notebooks without reading them. Here&apos;s what that actually costs you — from Google Drive exfiltration to OAuth token theft and supply chain attacks.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate></item><item><title>Memory Forensics with Volatility 3: What Attackers Leave Behind</title><link>https://hivesecurity.gitlab.io/blog/memory-forensics-volatility-attack-detect/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/memory-forensics-volatility-attack-detect/</guid><description>How attackers hide in RAM using fileless malware and process injection — and how defenders use Volatility 3 to find them. Practical DFIR workflow with real commands.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Violence-as-a-Service: How Organized Crime Borrowed the Cybercrime Playbook</title><link>https://hivesecurity.gitlab.io/blog/violence-as-a-service-otf-grimm-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/violence-as-a-service-otf-grimm-2026/</guid><description>Europol&apos;s OTF GRIMM has made 280 arrests in one year targeting criminal networks that outsource violence like a SaaS product. The model mirrors ransomware-as-a-service — and it&apos;s recruiting teenagers through Discord and encrypted apps.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>MITRE ATT&amp;CK v19: Defense Evasion Is Dead — Meet Stealth and Impair Defenses</title><link>https://hivesecurity.gitlab.io/blog/mitre-attack-v19-defense-evasion-split-stealth-impair-defenses/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/mitre-attack-v19-defense-evasion-split-stealth-impair-defenses/</guid><description>ATT&amp;CK v19 drops April 28 and splits Defense Evasion into two tactics. Here&apos;s what changes, why it matters for detection engineering, and what you need to do before the weekend.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate></item><item><title>From CVE to RCE in Hours: The Collapse of the Exploitation Window</title><link>https://hivesecurity.gitlab.io/blog/from-cve-to-rce-in-hours-attack-timeline-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/from-cve-to-rce-in-hours-attack-timeline-2026/</guid><description>The average time from vulnerability disclosure to active exploitation has collapsed from 756 days in 2018 to mere hours in 2025. Here&apos;s what that means for defenders.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Vulnerability Exploitation Overtook Phishing — What That Means for Defenders</title><link>https://hivesecurity.gitlab.io/blog/vulnerability-exploitation-overtook-phishing-defenders-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/vulnerability-exploitation-overtook-phishing-defenders-guide/</guid><description>For the first time, vulnerability exploitation is the #1 initial access vector — not phishing. Here&apos;s what the data says and how defenders must adapt.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Active Directory Attacks: The Complete Attack Path Guide</title><link>https://hivesecurity.gitlab.io/blog/active-directory-attacks-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/active-directory-attacks-guide/</guid><description>A structured guide to Active Directory attack techniques — from BloodHound enumeration through Kerberoasting, LSASS dumping, ADCS abuse, and Shadow Credentials to Entra ID pivot. Every technique with detection coverage.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Kubernetes and Container Security: Attacks, Misconfigurations, and Defenses</title><link>https://hivesecurity.gitlab.io/blog/kubernetes-container-security-attacks-and-defenses/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/kubernetes-container-security-attacks-and-defenses/</guid><description>How attackers break out of containers, escalate privileges in Kubernetes clusters, and move into cloud infrastructure — and how defenders detect and stop them.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Windows Attack Techniques 2026: BYOVD, ClickFix, and C2 over Cloud</title><link>https://hivesecurity.gitlab.io/blog/modern-attack-techniques-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/modern-attack-techniques-2026/</guid><description>BYOVD EDR evasion, ClickFix delivery, C2 over cloud services — how modern Windows attackers operate in 2026, and the detection logic to catch them.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OSINT and Recon Methodology: A Practical Guide for Security Professionals</title><link>https://hivesecurity.gitlab.io/blog/osint-recon-methodology-security-professionals/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/osint-recon-methodology-security-professionals/</guid><description>How to systematically map an organization&apos;s attack surface using open-source intelligence — domains, infrastructure, employees, leaked credentials, and exposed secrets.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Passkeys and FIDO2: The End of Passwords — and What Attackers Do Next</title><link>https://hivesecurity.gitlab.io/blog/passkeys-fido2-passwordless-authentication-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/passkeys-fido2-passwordless-authentication-guide/</guid><description>How passkeys and FIDO2 work, why they defeat phishing and credential stuffing, and how attackers are already adapting with downgrade attacks and fallback abuse.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Cookie-Controlled PHP Webshells: A Stealthy Tradecraft in Linux Hosting Environments</title><link>https://hivesecurity.gitlab.io/blog/cookie-controlled-php-webshells-linux-hosting/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cookie-controlled-php-webshells-linux-hosting/</guid><description>Microsoft&apos;s Defender team uncovered a clever attacker technique: PHP webshells that stay completely dormant until activated by a secret HTTP cookie. Here&apos;s how it works — and how to catch it.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Telegram as a C2 Server: How It Works and How to Detect It</title><link>https://hivesecurity.gitlab.io/blog/telegram-c2-bot-api-detection-blue-team/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/telegram-c2-bot-api-detection-blue-team/</guid><description>Attackers use Telegram&apos;s Bot API as command-and-control infrastructure — no Telegram install needed on the victim machine. Here&apos;s the mechanics, real-world examples, and blue team detection strategies.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Salt Typhoon: How China Hacked the World&apos;s Largest Telecoms</title><link>https://hivesecurity.gitlab.io/blog/salt-typhoon-telecom-hack-analysis/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/salt-typhoon-telecom-hack-analysis/</guid><description>Salt Typhoon is the worst telecom breach in history. The Chinese APT stayed hidden for years inside AT&amp;T, Verizon and T-Mobile. Here&apos;s the full attack chain, the tools they used, and the detection opportunities blue teams missed.</description><pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Phishing Under the Microscope: Analyzing a Real Attack Email Step by Step</title><link>https://hivesecurity.gitlab.io/blog/phishing-email-analysis-security-decoder/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/phishing-email-analysis-security-decoder/</guid><description>We tear apart a realistic phishing email using Security Decoder — headers, URLs, JWT tokens, and obfuscated JavaScript — and show exactly what each red flag means.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Kerberoasting: A Deep Dive into Service Account Attacks</title><link>https://hivesecurity.gitlab.io/blog/kerberoasting-deep-dive/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/kerberoasting-deep-dive/</guid><description>A comprehensive analysis of Kerberoasting — how it works at the protocol level, detection opportunities, and hardening strategies for Active Directory environments.</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate></item><item><title>UPnP: The Hidden Door in Your Router That You Never Opened</title><link>https://hivesecurity.gitlab.io/blog/upnp-security-risk-disable-router-windows/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/upnp-security-risk-disable-router-windows/</guid><description>UPnP lets apps silently open ports on your router without asking. It&apos;s enabled by default on almost every home router — and it has been exploited by botnets, malware, and remote attackers for decades. Here&apos;s what it is and how to turn it off.</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate></item><item><title>LSASS Dumping: Techniques, Evasion, and Detection</title><link>https://hivesecurity.gitlab.io/blog/lsass-dumping-techniques/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/lsass-dumping-techniques/</guid><description>LSASS credential dumping is one of the most reliable post-exploitation techniques. Survey of methods from MiniDump to direct syscalls and custom loaders, with detection logic and Sysmon rules for each approach.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate></item><item><title>What 218 Million Honeypot Events Reveal About January 2026</title><link>https://hivesecurity.gitlab.io/blog/honeypot-threat-landscape-january-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/honeypot-threat-landscape-january-2026/</guid><description>Global honeypot sensors logged over 218 million malicious events in January 2026. MSSQL attacks doubled, botnet infrastructure expanded 50%, and attackers pivoted away from RDP toward database targeting.</description><pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Lock the Front Door: Mandatory Security Actions Every Home User Must Take</title><link>https://hivesecurity.gitlab.io/blog/home-computer-security-mandatory-actions/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/home-computer-security-mandatory-actions/</guid><description>A practical, no-nonsense guide to the essential security actions every home user should take to protect their computer, network, and personal data from everyday cyber threats.</description><pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate></item><item><title>PathSentry: Detecting and Preventing Windows PATH Hijacking Attacks</title><link>https://hivesecurity.gitlab.io/blog/pathsentry-windows-path-hijacking-detection/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/pathsentry-windows-path-hijacking-detection/</guid><description>Windows PATH hijacking enables attackers to execute malicious code through writable directories. PathSentry uses two-phase detection to identify vulnerable PATH entries before exploitation.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Threat Hunting with Wazuh: Building Effective Detection Rules</title><link>https://hivesecurity.gitlab.io/blog/wazuh-threat-hunting/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/wazuh-threat-hunting/</guid><description>A practical guide to writing custom Wazuh detection rules for threat hunting — covering rule anatomy, decoder chaining, MITRE ATT&amp;CK mapping, and real-world detection scenarios for enterprise environments.</description><pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Client-Side File Analysis with Directory Tool Pro</title><link>https://hivesecurity.gitlab.io/blog/directory-tool-pro-client-side-file-analysis/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/directory-tool-pro-client-side-file-analysis/</guid><description>A Chrome extension for local file scanning and secrets detection. No cloud uploads, instant analysis, useful for security audits and pentesting workflows.</description><pubDate>Mon, 19 Jan 2026 00:00:00 GMT</pubDate></item><item><title>PSO - When Printers Become the Pentester&apos;s Blindspot</title><link>https://hivesecurity.gitlab.io/blog/printers-pentest-blindspot/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/printers-pentest-blindspot/</guid><description>How we built PSO — an open-source pentesting tool exposing the forgotten attack surface in corporate networks: network printers. Covers PJL exploitation, IPP vulnerabilities, and automated printer discovery.</description><pubDate>Sat, 03 Jan 2026 00:00:00 GMT</pubDate></item><item><title>The Human Remains the Weakest Link – But Now It&apos;s AI-Assisted</title><link>https://hivesecurity.gitlab.io/blog/human-weakest-link-ai-assisted/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/human-weakest-link-ai-assisted/</guid><description>AI has transformed social engineering into an automated, scalable threat. Learn how attackers leverage AI-powered phishing, deepfakes, and voice cloning—and what defenders can do about it.</description><pubDate>Sat, 27 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Cybersecurity in 2025: Holiday Season Security Guide and Year-End Threats</title><link>https://hivesecurity.gitlab.io/blog/cybersecurity-2025-holiday-guide/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/cybersecurity-2025-holiday-guide/</guid><description>Cybersecurity threats heading into 2025: AI-powered attacks, ransomware trends, and quantum threats — with practical security measures for the holiday season and beyond.</description><pubDate>Fri, 19 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Session Messenger: Privacy Without Phone Numbers in 2026</title><link>https://hivesecurity.gitlab.io/blog/session-messenger-privacy-comparison-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/session-messenger-privacy-comparison-2026/</guid><description>Discover why Session messenger is gaining ground as the EU debates Chat Control. Compare privacy features across popular messaging apps in 2025.</description><pubDate>Mon, 15 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Should I Switch to Linux in 2026? The Honest Answer</title><link>https://hivesecurity.gitlab.io/blog/switch-to-linux-2026/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/switch-to-linux-2026/</guid><description>Linux hits 5% US market share. With Windows 10 ending support, is switching to Linux the right move? Real stats, costs, and answers.</description><pubDate>Fri, 12 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Antivirus vs EDR vs XDR — What&apos;s the real difference in 2026?</title><link>https://hivesecurity.gitlab.io/blog/av-vs-edr-vs-xdr/</link><guid isPermaLink="true">https://hivesecurity.gitlab.io/blog/av-vs-edr-vs-xdr/</guid><description>A modern breakdown of Antivirus, EDR and XDR — including features, use-cases, attack detection logic and why traditional antivirus is no longer enough.</description><pubDate>Fri, 05 Dec 2025 00:00:00 GMT</pubDate></item></channel></rss>