<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>CyberSec Insights</title>
        <link>https://cyber.murati.net/</link>
        <description>Cybersecurity news and analysis: vulnerabilities, threat intelligence, ransomware, AI and cloud security.</description>
        <language>en-us</language>
        <lastBuildDate>Sun, 19 Jul 2026 12:00:00 GMT</lastBuildDate>
        <atom:link href="https://cyber.murati.net/feed.xml" rel="self" type="application/rss+xml"/>
        <item>
            <title>Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes</title>
            <link>https://cyber.murati.net/posts/records-are-made-to-be-broken-patch-tuesday-raises-triage-stakes</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/records-are-made-to-be-broken-patch-tuesday-raises-triage-stakes</guid>
            <pubDate>Sun, 19 Jul 2026 12:00:00 GMT</pubDate>
            <category>AI Security</category>
            <description>Microsoft's July 2026 Patch Tuesday shattered every previous record, delivering fixes for 622 unique CVEs — including three zero-days, two of them under active exploitation — and more than 60 critical</description>
        </item>
        <item>
            <title>Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days</title>
            <link>https://cyber.murati.net/posts/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days</guid>
            <pubDate>Sun, 19 Jul 2026 12:00:00 GMT</pubDate>
            <category>AI Security</category>
            <description>Microsoft has shipped its July 2026 Patch Tuesday updates, closing a record-setting 570 security flaws across its product line — the largest monthly batch the company has ever released. The rollup inc</description>
        </item>
        <item>
            <title>Armored Likho APT Targeting Government, Electric Power Entities</title>
            <link>https://cyber.murati.net/posts/armored-likho-apt-targeting-government-electric-power-entities</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/armored-likho-apt-targeting-government-electric-power-entities</guid>
            <pubDate>Sun, 12 Jul 2026 12:00:00 GMT</pubDate>
            <category>Threat Intelligence</category>
            <description>Kaspersky has detailed a newly identified advanced persistent threat group it calls Armored Likho, which is running a mix of financially motivated and espionage operations against government bodies, e</description>
        </item>
        <item>
            <title>Accenture admits to 'isolated matter' after crook tries to flog alleged 35GB haul</title>
            <link>https://cyber.murati.net/posts/accenture-admits-to-isolated-matter-after-crook-tries-to-flog-alleged-35gb-haul</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/accenture-admits-to-isolated-matter-after-crook-tries-to-flog-alleged-35gb-haul</guid>
            <pubDate>Sun, 12 Jul 2026 12:00:00 GMT</pubDate>
            <category>Data Breach</category>
            <description>Accenture has acknowledged what it calls an "isolated matter" after a criminal advertised roughly 35GB of data allegedly lifted from the consulting firm's internal systems — a trove said to include so</description>
        </item>
        <item>
            <title>Microsoft patches RoguePlanet Defender zero-day vulnerability</title>
            <link>https://cyber.murati.net/posts/microsoft-patches-rogueplanet-defender-zero-day-vulnerability</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/microsoft-patches-rogueplanet-defender-zero-day-vulnerability</guid>
            <pubDate>Sun, 12 Jul 2026 12:00:00 GMT</pubDate>
            <category>Vulnerabilities</category>
            <description>Microsoft has shipped a fix for a Microsoft Defender zero-day dubbed "RoguePlanet," tracked as [CVE-2026-50656](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656), which lets a loc</description>
        </item>
        <item>
            <title>Agentic AI Used to Conduct Ransomware Attack via Langflow</title>
            <link>https://cyber.murati.net/posts/agentic-ai-used-to-conduct-ransomware-attack-via-langflow</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/agentic-ai-used-to-conduct-ransomware-attack-via-langflow</guid>
            <pubDate>Mon, 06 Jul 2026 12:00:00 GMT</pubDate>
            <category>Ransomware</category>
            <description>Cloud security firm Sysdig has documented what it describes as the first fully agentic, AI-driven ransomware operation: a threat actor tracked as JadePuffer used a large language model to autonomously</description>
        </item>
        <item>
            <title>Hackers target misconfigured proxies to access paid LLM services</title>
            <link>https://cyber.murati.net/posts/hackers-target-misconfigured-proxies-to-access-paid-llm-services</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/hackers-target-misconfigured-proxies-to-access-paid-llm-services</guid>
            <pubDate>Mon, 06 Jul 2026 12:00:00 GMT</pubDate>
            <category>AI Security</category>
            <description>Attackers are scanning the internet for badly configured proxy servers that expose access to commercial large language model (LLM) platforms, according to threat intelligence firm GreyNoise. Since lat</description>
        </item>
        <item>
            <title>Dormant Iran APT is Still Alive, Spying on Dissidents</title>
            <link>https://cyber.murati.net/posts/dormant-iran-apt-is-still-alive-spying-on-dissidents</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/dormant-iran-apt-is-still-alive-spying-on-dissidents</guid>
            <pubDate>Mon, 06 Jul 2026 12:00:00 GMT</pubDate>
            <category>Data Breach</category>
            <description>Iran's oldest known state-aligned hacking crew — tracked as "Prince of Persia" or "Infy" — never actually disappeared. After roughly three years of public silence, SafeBreach researcher Tomer Bar repo</description>
        </item>
        <item>
            <title>Anonymous researcher drops 0-day 'exploitarium' repo</title>
            <link>https://cyber.murati.net/posts/anonymous-researcher-drops-0-day-exploitarium-repo</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/anonymous-researcher-drops-0-day-exploitarium-repo</guid>
            <pubDate>Mon, 06 Jul 2026 12:00:00 GMT</pubDate>
            <category>Cloud Security</category>
            <description>An anonymous researcher operating under the handle "bikini" published what they describe as working exploit code for zero-day flaws spanning 15 software products and open source projects, dropping the</description>
        </item>
        <item>
            <title>Russia's 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses</title>
            <link>https://cyber.murati.net/posts/russias-gamaredon-upgrades-its-arsenal-requiring-new-defenses</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/russias-gamaredon-upgrades-its-arsenal-requiring-new-defenses</guid>
            <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
            <category>Cloud Security</category>
            <description>Russia's long-running Gamaredon cyber-espionage group — also tracked as Aqua Blizzard, Armageddon, and BlueAlpha — has substantially modernized its toolkit and command-and-control (C2) practices, acco</description>
        </item>
        <item>
            <title>Tata Electronics confirms cyberattack as hackers leak data</title>
            <link>https://cyber.murati.net/posts/tata-electronics-confirms-cyberattack-as-hackers-leak-data</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/tata-electronics-confirms-cyberattack-as-hackers-leak-data</guid>
            <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
            <category>Ransomware</category>
            <description>Tata Electronics, the semiconductor and electronics manufacturing arm of India's Tata Group, has confirmed it was hit by a cyberattack that affected portions of its IT infrastructure. The company says</description>
        </item>
        <item>
            <title>Microsoft uses AI to link two malware operations in racketeering suit</title>
            <link>https://cyber.murati.net/posts/microsoft-uses-ai-to-link-two-malware-operations-in-racketeering-suit</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/microsoft-uses-ai-to-link-two-malware-operations-in-racketeering-suit</guid>
            <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
            <category>Ransomware</category>
            <description>Microsoft, working alongside international law enforcement and several security firms, has dismantled the infrastructure behind two prolific information-stealing and loader malware families, StealC an</description>
        </item>
        <item>
            <title>Europe Evolves Into Ransomware's Favorite Region</title>
            <link>https://cyber.murati.net/posts/europe-evolves-into-ransomwares-favorite-region</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/europe-evolves-into-ransomwares-favorite-region</guid>
            <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
            <category>Ransomware</category>
            <description>Ransomware operators are increasingly turning their attention to Europe. Security firm Black Kite logged 684 ransomware attacks across the continent in the first four months of 2026 — a 55% jump over </description>
        </item>
        <item>
            <title>Microsoft working on Defender patch for RoguePlanet zero-day</title>
            <link>https://cyber.murati.net/posts/microsoft-working-on-defender-patch-for-rogueplanet-zero-day</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/microsoft-working-on-defender-patch-for-rogueplanet-zero-day</guid>
            <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
            <category>Cloud Security</category>
            <description>Microsoft has acknowledged a zero-day elevation-of-privilege flaw in Microsoft Defender, publicly nicknamed "RoguePlanet," and says it is building a security update to fix it. Now tracked as CVE-2026-</description>
        </item>
        <item>
            <title>Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges</title>
            <link>https://cyber.murati.net/posts/microsoft-defender-rogueplanet-zero-day-grants-system-privileges</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/microsoft-defender-rogueplanet-zero-day-grants-system-privileges</guid>
            <pubDate>Sun, 28 Jun 2026 12:00:00 GMT</pubDate>
            <category>Cloud Security</category>
            <description>A researcher operating under the handle Nightmare Eclipse has published a proof-of-concept exploit dubbed "RoguePlanet" that abuses a race condition in Microsoft Defender to launch a SYSTEM-level comm</description>
        </item>
        <item>
            <title>6-Year Ransomware Campaign Targets Turkish Homes &amp; SMBs</title>
            <link>https://cyber.murati.net/posts/6-year-ransomware-campaign-targets-turkish-homes-smbs</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/6-year-ransomware-campaign-targets-turkish-homes-smbs</guid>
            <pubDate>Mon, 15 Jun 2026 12:00:00 GMT</pubDate>
            <category>Ransomware</category>
            <description>A newly published report from Acronis describes a ransomware operation that has likely been running since at least 2020, targeting home users and small or medium-sized businesses (SMBs) across Turkey.</description>
        </item>
        <item>
            <title>ServiceNow discloses security incident exposing customer data</title>
            <link>https://cyber.murati.net/posts/servicenow-discloses-security-incident-exposing-customer-data</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/servicenow-discloses-security-incident-exposing-customer-data</guid>
            <pubDate>Mon, 15 Jun 2026 12:00:00 GMT</pubDate>
            <category>Vulnerabilities</category>
            <description>ServiceNow has notified customers of a security incident in which a flaw in a vulnerable API endpoint allowed unauthenticated access to data inside hosted customer instances. The company says it pushe</description>
        </item>
        <item>
            <title>Microsoft patches Exchange Server zero-day exploited in attacks</title>
            <link>https://cyber.murati.net/posts/microsoft-patches-exchange-server-zero-day-exploited-in-attacks</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/microsoft-patches-exchange-server-zero-day-exploited-in-attacks</guid>
            <pubDate>Mon, 15 Jun 2026 12:00:00 GMT</pubDate>
            <category>Ransomware</category>
            <description>Microsoft has shipped a fix for an actively exploited Exchange Server flaw that lets attackers run arbitrary JavaScript in the browsers of Outlook Web Access users. Tracked as CVE-2026-42897, the high</description>
        </item>
        <item>
            <title>Max-Severity Ivanti Sentry Flaw Exploited Within 24 Hours</title>
            <link>https://cyber.murati.net/posts/max-severity-ivanti-sentry-flaw-exploited-within-24-hours</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/max-severity-ivanti-sentry-flaw-exploited-within-24-hours</guid>
            <pubDate>Mon, 15 Jun 2026 12:00:00 GMT</pubDate>
            <category>Vulnerabilities</category>
            <description>A maximum-severity flaw in Ivanti Sentry was being exploited in the wild within a day of becoming public, with attackers leaning on a freely available proof-of-concept to break in. Tracked as CVE-2026</description>
        </item>
        <item>
            <title>Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters</title>
            <link>https://cyber.murati.net/posts/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters</link>
            <guid isPermaLink="true">https://cyber.murati.net/posts/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters</guid>
            <pubDate>Mon, 15 Jun 2026 12:00:00 GMT</pubDate>
            <category>Data Breach</category>
            <description>Google says a critical flaw in Oracle's PeopleSoft software has been exploited as a zero-day by the cybercrime group ShinyHunters to steal data from organizations, with the education sector bearing th</description>
        </item>
    </channel>
</rss>
