<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security Unlocked</title><link>https://securityunlocked.com/</link><description>Recent content on Security Unlocked</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 08 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://securityunlocked.com/index.xml" rel="self" type="application/rss+xml"/><item><title>The Registry Trusted the Token</title><link>https://securityunlocked.com/weekly-intelligence/the-registry-trusted-the-token/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-registry-trusted-the-token/</guid><description>GitHub OIDC trusted-publishing solved the stored-credential problem and created a new attack surface in the same motion: three independent actors exploited it in a single week, producing malicious packages carrying valid provenance attestations.</description></item><item><title>Threat Economics: Week of June 2 - June 8, 2026</title><link>https://securityunlocked.com/threat-economics/threat-economics-week-of-june-2-june-8-2026/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/threat-economics/threat-economics-week-of-june-2-june-8-2026/</guid><description>Three simultaneous EDR exploits expose a $16B cyber insurance underwriting assumption, while npm&amp;rsquo;s collapse as trusted infrastructure validates the developer security VC thesis absorbing the most capital in Q1 2026.</description></item><item><title>Trusted Vendor, Compromised Namespace: Miasma Escalates Supply Chain Risk While AI Cements Its Role in Ransomware Development</title><link>https://securityunlocked.com/weekly-intelligence/trusted-vendor-compromised-namespace-miasma-escalates-supply-chain-risk-while-ai-cements-its-role-in-ransomware-development/</link><pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/trusted-vendor-compromised-namespace-miasma-escalates-supply-chain-risk-while-ai-cements-its-role-in-ransomware-development/</guid><description>The Mini Shai-Hulud worm now operates inside Red Hat&amp;rsquo;s official npm namespace, proving that vendor-maintained packages are viable supply chain targets; simultaneously, the first confirmed AI-assisted ransomware toolchain documents a qualitative shift in what moderately skilled operators can build.</description></item><item><title>The Agent Trusts the Answer</title><link>https://securityunlocked.com/weekly-intelligence/the-agent-trusts-the-answer/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-agent-trusts-the-answer/</guid><description>Two CVSS 9.8 vulnerabilities this week share an identical root cause: AI agent frameworks treat LLM output as safe to execute, the same cognitive error that produced SQL injection in 2003.</description></item><item><title>Threat Economics: Week of May 26 - June 1, 2026</title><link>https://securityunlocked.com/threat-economics/threat-economics-week-of-may-26-june-1-2026/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/threat-economics/threat-economics-week-of-may-26-june-1-2026/</guid><description>The TeamPCP campaign&amp;rsquo;s full-stack attack on API keys, CI/CD tokens, and developer credentials is simultaneously the proof point for a $24.6 billion NHI acquisition wave and a live stress test of cyber insurance policy language that wasn&amp;rsquo;t written to cover it.</description></item><item><title>When Attackers Show You the Wrong Problem: SRG Goes Physical, MuddyWater Goes Ransomware</title><link>https://securityunlocked.com/weekly-intelligence/when-attackers-show-you-the-wrong-problem-srg-goes-physical-muddywater-goes-ransomware/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/when-attackers-show-you-the-wrong-problem-srg-goes-physical-muddywater-goes-ransomware/</guid><description>Two threat actor reports published this week document attackers who design their operations to trigger the wrong defensive response: Silent Ransom Group physically walks someone into a law firm when remote attacks fail, and MuddyWater deploys ransomware as cover for espionage.</description></item><item><title>Signing-as-a-Service Exposed: Fox Tempest Sold Microsoft's Code-Signing Trust Per Payload</title><link>https://securityunlocked.com/weekly-intelligence/signing-as-a-service-exposed-fox-tempest-sold-microsofts-code-signing-trust-per-payload/</link><pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/signing-as-a-service-exposed-fox-tempest-sold-microsofts-code-signing-trust-per-payload/</guid><description>Microsoft&amp;rsquo;s Fox Tempest takedown exposes a criminal market for code-signing trust sold per payload; a PAN-OS zero-day with six weeks of state-sponsored exploitation went unreported through all of W21; and Shai-Hulud nearly doubled in scope with Grafana&amp;rsquo;s source code as the first named downstream casualty.</description></item><item><title>The Affordability Problem Nobody Talked About at RSA</title><link>https://securityunlocked.com/articles/the-affordability-problem-nobody-talked-about-at-rsa/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/the-affordability-problem-nobody-talked-about-at-rsa/</guid><description>Vendors at RSA 2026 sold agentic SOC capability as the answer to alert overload. The pricing model underneath, metered tokens against enterprise data volumes, was never on the keynote agenda. The organizations the affordability gap actually threatens are the ones not in the room.</description></item><item><title>The Detection Paradigm Is Broken: Why Behavioral SE Defense Is the Next Frontier</title><link>https://securityunlocked.com/articles/the-detection-paradigm-is-broken-why-behavioral-se-defense-is-the-next-frontier/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/the-detection-paradigm-is-broken-why-behavioral-se-defense-is-the-next-frontier/</guid><description>AI-assisted social engineering has eliminated the imperfection signals that detection tooling was built to find. The residual signal lives in behavior, not content. The vendors built for content scanning cannot pivot, and the gap is where the next significant security company gets built.</description></item><item><title>The Threat Actor Is a Fiction: Why Attribution's Core Unit Is Breaking</title><link>https://securityunlocked.com/articles/the-threat-actor-is-a-fiction-why-attributions-core-unit-is-breaking/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/the-threat-actor-is-a-fiction-why-attributions-core-unit-is-breaking/</guid><description>M-Trends 2026 shows the median time between initial access and downstream handoff dropped to 22 seconds. That number is not primarily a detection challenge. It is an epistemological one. The &amp;rsquo;threat actor&amp;rsquo; as an analytical unit is becoming structurally incoherent, and attribution methodology has not caught up.</description></item><item><title>Your Name Is on the Final Report</title><link>https://securityunlocked.com/articles/your-name-is-on-the-final-report/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/your-name-is-on-the-final-report/</guid><description>The SANS panel at RSA 2026 named irresponsible AI adoption as one of the five most dangerous new attack techniques. When an agentic security system makes the wrong call, the accountability does not dissolve into the architecture. It migrates to a person. That person is you.</description></item><item><title>Threat Economics: Week of May 11 - May 17, 2026</title><link>https://securityunlocked.com/threat-economics/threat-economics-week-of-may-11-may-17-2026/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/threat-economics/threat-economics-week-of-may-11-may-17-2026/</guid><description>APT45&amp;rsquo;s confirmed AI-generated zero-day hands the autonomous security testing market its validation receipt, while simultaneous supply chain attacks on AI developer packages tell investors exactly which environments adversaries have already priced as high-value targets.</description></item><item><title>Three Point One</title><link>https://securityunlocked.com/weekly-intelligence/three-point-one/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/three-point-one/</guid><description>When a vulnerability transmits your database credentials to a third-party endpoint by design and scores CVSS 3.1, the problem is not the vulnerability, it is the triage system that will deprioritize it.</description></item><item><title>AI Writes the Exploit: UNC2814's Gemini Zero-Day and the Automation Gap That Just Closed</title><link>https://securityunlocked.com/weekly-intelligence/ai-writes-the-exploit-unc2814s-gemini-zero-day-and-the-automation-gap-that-just-closed/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/ai-writes-the-exploit-unc2814s-gemini-zero-day-and-the-automation-gap-that-just-closed/</guid><description>Google GTIG&amp;rsquo;s confirmation of the first AI-generated zero-day deployed in a live attack closes the loop on Monday&amp;rsquo;s AI agent vulnerability wave, connecting the attack surface (vulnerable AI frameworks) to the attack tool (AI-generated exploits) in the same reporting week.</description></item><item><title>Developer Workstations Are the New Beachhead</title><link>https://securityunlocked.com/bylines/developer-workstations-are-the-new-beachhead/</link><pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/bylines/developer-workstations-are-the-new-beachhead/</guid><description>Three independent threat campaigns in early 2026 (the North Korea-attributed Contagious Interview operation, the GlassWorm Zig-dropper IDE extension malware, and the TeamPCP cascading supply chain compromise) converged on the same conclusion: developer workstations are now the highest-value initial access target in enterprise environments. The convergence is a price signal, not a coincidence.</description></item><item><title>DLP Is Underwater: How the Exfiltration Economy Inverted in Six Weeks</title><link>https://securityunlocked.com/articles/dlp-is-underwater-how-the-exfiltration-economy-inverted-in-six-weeks/</link><pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/dlp-is-underwater-how-the-exfiltration-economy-inverted-in-six-weeks/</guid><description>The economic case for DLP rested on a stable ratio between attacker cost per exfiltration event and defender cost per prevented event. Six weeks of pipeline data show that ratio fully inverted. Large language models collapsed attacker cost to a prompt; defender cost has not moved. DLP programs that have not restructured their architecture are now structurally underwater, and five independent exfiltration channels are the evidence.</description></item><item><title>Model Intuition: The SOC Skill Agentic AI Will Demand From Every Analyst</title><link>https://securityunlocked.com/articles/model-intuition-the-soc-skill-agentic-ai-will-demand-from-every-analyst/</link><pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/model-intuition-the-soc-skill-agentic-ai-will-demand-from-every-analyst/</guid><description>When agents triage 200 alerts and surface five, the analyst&amp;rsquo;s job is no longer processing signals. It is judging whether the system processing them was sound. That judgment, model intuition, is the difference between an output that looks right and one that is structurally right. Without it, agentic SOCs scale the wrong answers as efficiently as the right ones.</description></item><item><title>The Agent Trusts the Output</title><link>https://securityunlocked.com/weekly-intelligence/the-agent-trusts-the-output/</link><pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-agent-trusts-the-output/</guid><description>Eight AI agent frameworks disclosed the same class of remote code execution vulnerability in a single week because the entire ecosystem shares a cognitive failure: treating LLM output as trusted data rather than untrusted instructions.</description></item><item><title>Threat Economics: Week of May 4-10, 2026</title><link>https://securityunlocked.com/threat-economics/threat-economics-week-of-may-4-10-2026/</link><pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/threat-economics/threat-economics-week-of-may-4-10-2026/</guid><description>Eight AI agent framework RCEs in a single week, a first-ever AI proxy addition to CISA&amp;rsquo;s KEV catalog, and CrowdStrike&amp;rsquo;s $1.1 billion identity bet all converging in the same week signals that the agentic AI security market has moved from thesis to demonstrated demand.</description></item><item><title>Palo Alto Captive Portal Zero-Day Under Active Chinese-Linked Exploitation, First Patches May 13</title><link>https://securityunlocked.com/alerts/palo-alto-captive-portal-zero-day-under-active-chinese-linked-exploitation-first-patches-may-13/</link><pubDate>Fri, 08 May 2026 13:00:00 +0000</pubDate><guid>https://securityunlocked.com/alerts/palo-alto-captive-portal-zero-day-under-active-chinese-linked-exploitation-first-patches-may-13/</guid><description>CVE-2026-0300 (CVSS 9.3) is an unauthenticated, root-level RCE in the PAN-OS User-ID Authentication Portal of PA-Series and VM-Series firewalls, under active exploitation by a likely China-aligned cluster Unit 42 tracks as CL-STA-1132. First hotfixes ship May 13. Anything with the Captive Portal exposed to untrusted networks needs immediate mitigation.</description></item><item><title>8 Guiding Principles for Reskilling the SOC for Agentic AI</title><link>https://securityunlocked.com/mentions/8-guiding-principles-for-reskilling-the-soc-for-agentic-ai/</link><pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/mentions/8-guiding-principles-for-reskilling-the-soc-for-agentic-ai/</guid><description>Quoted on the cognitive reskilling SOC analysts will need as agentic AI takes over Tier 1 and Tier 2 triage, including the &amp;lsquo;model intuition&amp;rsquo; framing for distinguishing structurally wrong from plausible-sounding agent output.</description></item><item><title>ShinyHunters Adds 275 Million Students to Monday's Breach Wave, PAN-OS Zero-Day Leaves Perimeter Gaps Until May 13</title><link>https://securityunlocked.com/weekly-intelligence/shinyhunters-adds-275-million-students-to-mondays-breach-wave-pan-os-zero-day-leaves-perimeter-gaps-until-may-13/</link><pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/shinyhunters-adds-275-million-students-to-mondays-breach-wave-pan-os-zero-day-leaves-perimeter-gaps-until-may-13/</guid><description>ShinyHunters expanded Monday&amp;rsquo;s identity breach wave to 275 million education users via Canvas and pivoted to cloud data warehouse infrastructure at Vimeo; separately, an unpatched PAN-OS RCE zero-day leaves internet-facing firewalls exposed until at least May 13.</description></item><item><title>Threat Economics: Week of April 27 - May 3, 2026</title><link>https://securityunlocked.com/threat-economics/threat-economics-week-of-april-27-may-3-2026/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/threat-economics/threat-economics-week-of-april-27-may-3-2026/</guid><description>Eight AI agent framework CVEs in one week and ShinyHunters&amp;rsquo; no-exploit identity breach wave validate the two fastest-growing investment theses in cybersecurity, while CIRCIA&amp;rsquo;s 316,000-entity reporting mandate positions a multi-year compliance procurement cycle.</description></item><item><title>What the Model Returns, the Shell Executes</title><link>https://securityunlocked.com/weekly-intelligence/what-the-model-returns-the-shell-executes/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/what-the-model-returns-the-shell-executes/</guid><description>Eight AI agent frameworks disclosed the same architectural vulnerability in a single week, revealing that the AI agent ecosystem is repeating the early-web SQL injection era under exploitation timelines that leave no room to learn slowly.</description></item><item><title>Copy Fail Gives Root on Every Linux Kernel Since 2017, No Race Condition Required</title><link>https://securityunlocked.com/alerts/copy-fail-gives-root-on-every-linux-kernel-since-2017-no-race-condition-required/</link><pubDate>Sat, 02 May 2026 07:00:00 +0000</pubDate><guid>https://securityunlocked.com/alerts/copy-fail-gives-root-on-every-linux-kernel-since-2017-no-race-condition-required/</guid><description>CVE-2026-31431 is a deterministic local privilege escalation in the Linux kernel&amp;rsquo;s authencesn crypto template, with a public exploit and no race condition, making it the most reliable Linux LPE since Dirty Pipe.</description></item><item><title>LiteLLM's 36-Hour Exploitation Window Confirms the AI Attack Surface Has Moved Up the Stack</title><link>https://securityunlocked.com/weekly-intelligence/litellms-36-hour-exploitation-window-confirms-the-ai-attack-surface-has-moved-up-the-stack/</link><pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/litellms-36-hour-exploitation-window-confirms-the-ai-attack-surface-has-moved-up-the-stack/</guid><description>The rapid exploitation of CVE-2026-42208 in LiteLLM marks the first confirmed weaponization of the AI API proxy layer, while TeamPCP&amp;rsquo;s new ransomware partnership turns out to be a wiper with no recovery path.</description></item><item><title>Invisible by Default: AI Middleware Is the New Soft Target</title><link>https://securityunlocked.com/articles/invisible-by-default-ai-middleware-is-the-new-soft-target/</link><pubDate>Wed, 29 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/invisible-by-default-ai-middleware-is-the-new-soft-target/</guid><description>Three AI middleware vulnerabilities (LiteLLM, LeRobot, Entra Agent ID) hit the same architectural layer in the same week, all pre-auth or unauthenticated, with one being exploited thirty-six hours after disclosure. The seams of the AI stack are shipping faster than security teams can map them, and middleware that earns trust through utility is becoming the next high-value target.</description></item><item><title>When the Security Tool IS the Supply Chain Attack</title><link>https://securityunlocked.com/alerts/when-the-security-tool-is-the-supply-chain-attack/</link><pubDate>Tue, 28 Apr 2026 17:00:00 +0000</pubDate><guid>https://securityunlocked.com/alerts/when-the-security-tool-is-the-supply-chain-attack/</guid><description>TeamPCP&amp;rsquo;s supply-chain campaign has propagated from Trivy to Checkmarx KICS, Checkmarx GitHub Actions, two Open VSX plugins, and now Bitwarden CLI. Lapsus$ is handling the extortion. The blast radius now reaches a password manager with 10M+ users.</description></item><item><title>Agentic Trust Debt: How 'Agent-Controlled Input' Became the New Buffer Overflow</title><link>https://securityunlocked.com/articles/agentic-trust-debt-how-agent-controlled-input-became-the-new-buffer-overflow/</link><pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/agentic-trust-debt-how-agent-controlled-input-became-the-new-buffer-overflow/</guid><description>Five AI agent frameworks disclosed the same vulnerability class in a single week, and the MCP SDK STDIO injection extended the pattern across four language ecosystems. The cluster reads like the buffer overflow era: a field-level conceptual gap in how agentic systems handle trust, not a string of individual implementation bugs.</description></item><item><title>AI Infrastructure Exploited Within 24 Hours of Disclosure</title><link>https://securityunlocked.com/weekly-intelligence/the-advisory-is-the-starting-gun/</link><pubDate>Mon, 27 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-advisory-is-the-starting-gun/</guid><description>Four AI infrastructure platforms (Langflow, Marimo, LMDeploy, Flowise) were exploited within 24 hours of vulnerability disclosure last week. The patching window has collapsed to under one attacker shift.</description></item><item><title>Threat Economics: Week of April 20-26, 2026</title><link>https://securityunlocked.com/threat-economics/threat-economics-week-of-april-20-26-2026/</link><pubDate>Mon, 27 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/threat-economics/threat-economics-week-of-april-20-26-2026/</guid><description>Adversaries exploited four AI platforms in under 24 hours each while $3.8B in Q1 cybersecurity capital concentrated 46% into AI security: the market validated the attack surface before defenders finished reading the advisories.</description></item><item><title>Three Critical Exploits Hit Management Planes and Endpoints</title><link>https://securityunlocked.com/alerts/three-critical-exploits-hit-management-planes-and-endpoints/</link><pubDate>Sun, 26 Apr 2026 16:00:00 +0000</pubDate><guid>https://securityunlocked.com/alerts/three-critical-exploits-hit-management-planes-and-endpoints/</guid><description>Three critical vulnerabilities under active exploitation target FortiClient EMS, Adobe Acrobat Reader, and nginx-ui, collectively exposing enterprise management planes and endpoints to unauthenticated remote code execution.</description></item><item><title>Defenders Under Siege: How Adversaries Turned Security Tools Into Weapons This Week</title><link>https://securityunlocked.com/articles/defenders-under-siege-how-adversaries-turned-security-tools-into-weapons-this-week/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/defenders-under-siege-how-adversaries-turned-security-tools-into-weapons-this-week/</guid><description>Three incidents this week reveal the same strategic pattern: attackers turning trusted defensive infrastructure into weapons. Microsoft Defender zero-days, the Trivy scanner compromise that breached the European Commission, and UNC6783&amp;rsquo;s live-chat social engineering all exploit a cognitive constant: defenders don&amp;rsquo;t question the tools they depend on.</description></item><item><title>Threat Economics: Week of April 13-19, 2026</title><link>https://securityunlocked.com/threat-economics/threat-economics-week-of-april-13-19-2026/</link><pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/threat-economics/threat-economics-week-of-april-13-19-2026/</guid><description>Weekly market intelligence: Linx Security&amp;rsquo;s $50M identity bet, $4.62B in Q2 cybersecurity funding, and why NIS2 enforcement and CIRCIA deadlines are about to reshape enterprise buying criteria.</description></item><item><title>The Protocol Is Doing Its Job</title><link>https://securityunlocked.com/weekly-intelligence/the-protocol-is-doing-its-job/</link><pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-protocol-is-doing-its-job/</guid><description>MCP&amp;rsquo;s trust architecture makes any exposed management interface a pre-authenticated command shell by design, not by accident, and two RCE vulnerabilities in the same week reveal a deployment curve that has outrun both audit methodology and detection playbooks.</description></item><item><title>Anthropic's Best Week and Worst Week Were the Same Week</title><link>https://securityunlocked.com/articles/anthropics-best-week-and-worst-week-were-the-same-week/</link><pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/anthropics-best-week-and-worst-week-were-the-same-week/</guid><description>Anthropic unveiled an AI that finds decades-old zero-days while shipping three injection flaws in its own CLI, exposing the gap between offensive capability and defensive practice.</description></item><item><title>Threat Economics: Week of April 6-12, 2026</title><link>https://securityunlocked.com/threat-economics/threat-economics-week-of-april-6-12-2026/</link><pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/threat-economics/threat-economics-week-of-april-6-12-2026/</guid><description>Weekly market intelligence: Anthropic&amp;rsquo;s $100M Glasswing commitment, the FBI&amp;rsquo;s $21B cybercrime figure, and why developer security tooling is the next VC cycle.</description></item><item><title>Mythos Finds Zero-Days. npm Found Three More.</title><link>https://securityunlocked.com/weekly-intelligence/mythos-finds-zero-days.-npm-found-three-more./</link><pubDate>Sun, 12 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/mythos-finds-zero-days.-npm-found-three-more./</guid><description>The same week Anthropic unveiled an AI that autonomously finds zero-days, its own CLI shipped a CVSS 9.8 command injection, exposed by a debugging artifact that had been sitting in an npm package since March 31.</description></item><item><title>Trust Is the Exploit</title><link>https://securityunlocked.com/weekly-intelligence/trust-is-the-exploit/</link><pubDate>Mon, 06 Apr 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/trust-is-the-exploit/</guid><description>From a six-month DPRK social engineering operation to mass exploitation of developer ecosystems, this week&amp;rsquo;s threat landscape reveals that the most reliable attack surface is the trust we extend by default.</description></item><item><title>The Mental Model Is the Vulnerability</title><link>https://securityunlocked.com/weekly-intelligence/the-mental-model-is-the-vulnerability/</link><pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/the-mental-model-is-the-vulnerability/</guid><description>Five AI infrastructure disclosures in one day share the same root cause: the gap between what users believe their security settings do and what the framework actually executes.</description></item><item><title>Trust Is the Attack Surface</title><link>https://securityunlocked.com/weekly-intelligence/trust-is-the-attack-surface/</link><pubDate>Tue, 17 Mar 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/weekly-intelligence/trust-is-the-attack-surface/</guid><description>Every major incident this week exploited institutional or interpersonal trust rather than technical vulnerabilities. The adversary&amp;rsquo;s target is not the system. It is the relationship.</description></item><item><title>Are Hacktivists Going Out of Business? Or Just Out of Style</title><link>https://securityunlocked.com/articles/are-hacktivists-going-out-of-business-or-just-out-of-style/</link><pubDate>Fri, 09 Jan 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/are-hacktivists-going-out-of-business-or-just-out-of-style/</guid><description>Hacktivism hasn&amp;rsquo;t disappeared; it has been absorbed into the cybercrime economy and repurposed as cover for state-sponsored operations, forcing defenders to rethink how they assess ideologically motivated threats.</description></item><item><title>Predicting the Six Biggest Impacts AI Will Have on OT Cybersecurity</title><link>https://securityunlocked.com/mentions/predicting-the-six-biggest-impacts-ai-will-have-on-ot-cybersecurity/</link><pubDate>Wed, 07 Jan 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/mentions/predicting-the-six-biggest-impacts-ai-will-have-on-ot-cybersecurity/</guid><description>Quoted on treating AI agents as insider threats and the emerging legal liability for autonomous AI decisions in enterprise environments.</description></item><item><title>Predicting the Six Biggest Impacts AI Will Have on OT Cybersecurity</title><link>https://securityunlocked.com/mentions/predicting-the-six-biggest-impacts-ai-will-have-on-ot-cybersecurity/</link><pubDate>Wed, 07 Jan 2026 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/mentions/predicting-the-six-biggest-impacts-ai-will-have-on-ot-cybersecurity/</guid><description>Quoted on why enterprises need to start treating AI systems as insider threats, the coming wave of AI liability lawsuits, and the machine identity crisis facing security teams.</description></item><item><title>2026 Security Predictions: Are You Prepared?</title><link>https://securityunlocked.com/mentions/2026-security-predictions-are-you-prepared/</link><pubDate>Tue, 02 Dec 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/mentions/2026-security-predictions-are-you-prepared/</guid><description>Quoted on why enterprises must adopt nation-state-grade defenses as APT groups increasingly target private-sector companies for economic disruption, IP theft, and geopolitically aligned espionage.</description></item><item><title>What National Cybersecurity Awareness Month Means in 2025</title><link>https://securityunlocked.com/mentions/what-national-cybersecurity-awareness-month-means-in-2025/</link><pubDate>Fri, 03 Oct 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/mentions/what-national-cybersecurity-awareness-month-means-in-2025/</guid><description>Quoted on why enabling multi-factor authentication remains the single highest-impact action individuals can take against credential-based attacks.</description></item><item><title>AI Agents Are Mapping Your Organization</title><link>https://securityunlocked.com/articles/ai-agents-are-mapping-your-organization/</link><pubDate>Fri, 08 Aug 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/ai-agents-are-mapping-your-organization/</guid><description>Automated reconnaissance agents now profile entire organizations in minutes, compiling dossiers from public sources faster and more comprehensively than ever before, reshaping how defenders must think about information exposure.</description></item><item><title>When Yesterday's Emails Never Happened: Conversation Hijacking Attacks</title><link>https://securityunlocked.com/articles/when-yesterdays-emails-never-happened-conversation-hijacking-attacks/</link><pubDate>Tue, 17 Jun 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/when-yesterdays-emails-never-happened-conversation-hijacking-attacks/</guid><description>AI-fabricated email threads now bypass traditional security controls entirely by exploiting workplace authority dynamics and psychological familiarity, eliminating malicious indicators while weaponizing legitimate communication patterns.</description></item><item><title>When Confusion Becomes a Weapon: Economic Uncertainty and Cyber Risk</title><link>https://securityunlocked.com/articles/when-confusion-becomes-a-weapon-economic-uncertainty-and-cyber-risk/</link><pubDate>Wed, 23 Apr 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/when-confusion-becomes-a-weapon-economic-uncertainty-and-cyber-risk/</guid><description>Economic turbulence weaponizes organizational chaos through social engineering campaigns that exploit distraction and degraded attention. while paradoxically prompting security budget cuts exactly when attacks intensify.</description></item><item><title>Strategic AI Alliances and the Geopolitics of Today's Internet</title><link>https://securityunlocked.com/articles/strategic-ai-alliances-and-the-geopolitics-of-todays-internet/</link><pubDate>Mon, 21 Apr 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/strategic-ai-alliances-and-the-geopolitics-of-todays-internet/</guid><description>As nations weaponize AI and enforce data sovereignty requirements, the borderless internet has fractured into competing digital blocs, forcing enterprises to navigate fragmented compliance regimes while adversaries exploit jurisdictional gaps.</description></item><item><title>US Cybersecurity Efforts for Spacecraft Are Up in the Air</title><link>https://securityunlocked.com/mentions/us-cybersecurity-efforts-for-spacecraft-are-up-in-the-air/</link><pubDate>Thu, 06 Feb 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/mentions/us-cybersecurity-efforts-for-spacecraft-are-up-in-the-air/</guid><description>Quoted on the lack of progress in spacecraft cybersecurity standards and why the delay is concerning given supply chain breaches targeting government systems.</description></item><item><title>Why Your Desire for Free TV Could Cost You</title><link>https://securityunlocked.com/articles/why-your-desire-for-free-tv-could-cost-you/</link><pubDate>Tue, 04 Feb 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/why-your-desire-for-free-tv-could-cost-you/</guid><description>Pirated streaming platforms weaponize user impatience through layered deception, fake CAPTCHAs, disguised malware installers, and obfuscated command execution, turning entertainment shortcuts into persistent device compromise.</description></item><item><title>Scam Yourself Attacks: The New Evolution of Social Engineering</title><link>https://securityunlocked.com/articles/scam-yourself-attacks-the-new-evolution-of-social-engineering/</link><pubDate>Tue, 21 Jan 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/scam-yourself-attacks-the-new-evolution-of-social-engineering/</guid><description>Scam-Yourself attacks manipulate users into triggering their own compromise through familiar interfaces and psychological triggers, making the victim an unwitting accomplice in their own breach.</description></item><item><title>Hack the Hacker's Mind: Weaponizing Cognitive Biases in Cyber Defense</title><link>https://securityunlocked.com/articles/hack-the-hackers-mind-weaponizing-cognitive-biases-in-cyber-defense/</link><pubDate>Thu, 16 Jan 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/hack-the-hackers-mind-weaponizing-cognitive-biases-in-cyber-defense/</guid><description>Adversarial Cognitive Engineering flips traditional defense models by exploiting predictable patterns in attacker decision-making, using deception operations to waste attacker resources rather than merely detecting intrusions after they occur.</description></item><item><title>Evolving Cyber Resilience: From Tool Sprawl to Ecosystem Balance</title><link>https://securityunlocked.com/articles/evolving-cyber-resilience-from-tool-sprawl-to-ecosystem-balance/</link><pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/evolving-cyber-resilience-from-tool-sprawl-to-ecosystem-balance/</guid><description>Modern security ecosystems have grown so complex they create vulnerabilities through sheer disorganization. Resilience requires treating security architecture like biological systems that adapt through classification, evolution, and purposeful simplification.</description></item><item><title>The Dual-Edged Sword of AI in Cybersecurity</title><link>https://securityunlocked.com/articles/the-dual-edged-sword-of-ai-in-cybersecurity/</link><pubDate>Tue, 07 Jan 2025 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/articles/the-dual-edged-sword-of-ai-in-cybersecurity/</guid><description>AI amplifies both defensive and offensive capabilities asymmetrically, raising the ceiling for defenders while lowering the floor for attackers and creating a fundamentally new threat multiplier that organizations cannot address through traditional approaches alone.</description></item><item><title/><link>https://securityunlocked.com/drafts/josh_taylor_writing_guide/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/drafts/josh_taylor_writing_guide/</guid><description>&lt;h1 id="josh-taylor-writing-guide"&gt;Josh Taylor Writing Guide&lt;/h1&gt;
&lt;h2 id="voice-and-positioning"&gt;Voice and Positioning&lt;/h2&gt;
&lt;p&gt;Write as a cybersecurity strategist, SOC leader, doctoral
researcher, and published analyst. Combine strategic clarity,
technical credibility, psychological insight, and measured
authority. Sound like someone who has operated in real
environments and studied the field deeply. Never sound like
a vendor brochure, generic marketer, or academic performing
impressiveness.&lt;/p&gt;
&lt;h2 id="audience-and-tone-modes"&gt;Audience and Tone Modes&lt;/h2&gt;
&lt;p&gt;Before writing, confirm:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Who is the audience?&lt;/li&gt;
&lt;li&gt;Executive, Practitioner, or Research-informed tone?&lt;/li&gt;
&lt;li&gt;Publication venue — neutral outlet or Fortra-aligned?&lt;/li&gt;
&lt;li&gt;Should Fortra be mentioned explicitly?&lt;/li&gt;
&lt;li&gt;Is there a current event or trend to anchor the piece?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Tone modes:&lt;/p&gt;</description></item><item><title>Privacy Policy | Security Unlocked</title><link>https://securityunlocked.com/privacy-policy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/privacy-policy/</guid><description>How we collect, use, and protect your information.</description></item><item><title>Terms of Use | Security Unlocked</title><link>https://securityunlocked.com/terms-of-use/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://securityunlocked.com/terms-of-use/</guid><description>The rules for using Security Unlocked.</description></item></channel></rss>