Penetration Testing and AppSec XXE: XML parser security in practice
How external entities turn an XML parser into a file reader and HTTP client. Where XML sneaks in, how to disable DTDs, and how to test and detect XXE.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Penetration Testing and AppSec How external entities turn an XML parser into a file reader and HTTP client. Where XML sneaks in, how to disable DTDs, and how to test and detect XXE.
Vulnerabilities and CVEs CVE-2026-48294 (HermeticReader) in Adobe's Acrobat Chrome extension let any site read WhatsApp Web data across origins. Check that you are on the patched build.
AI Security Qualys found the RefluXFS Linux kernel flaw with help from an Anthropic model. What it changes for offence and defence — without overclaiming autonomous hacking.
Threats and Incidents Dolphin X steals data from over 300 applications and advertises AI victim profiling. We separate the confirmed analysis from the criminals' marketing.
Threats and Incidents Group-IB detailed a China-nexus operation, JadeProx, and the TriBack loader, exposed via a misconfigured cloud server. Targets, techniques and defensive lessons.
AI Security Late July 2026 brings a record wave of open models: stable DeepSeek V4 and Kimi K3 weights. How to approach adoption from a security and provenance standpoint.
AI Security OpenAI announced Project Camellia — a 3.2 GW data center campus in Georgia costing over $30 billion. We sum up the facts and what they say about AI's bottleneck.
Vulnerabilities and CVEs CVE-2026-8933 is a race condition in snap-confine that gives a local user root on default Ubuntu Desktop 24.04, 25.10 and 26.04. How to patch it, and why.
AI Security The US is finalising a voluntary framework giving agencies up to 30 days to review frontier models before release. We explain what is confirmed and what is still in progress.
AI Security At Advancing AI 2026 AMD unveiled Instinct MI400, EPYC 9006 and the Helios platform. We sum up the confirmed facts and what they mean for enterprises and sovereign AI.
Threats and Incidents Cisco Talos detailed msaRAT — a Chaos-group trojan that runs C2 through Chrome/Edge and WebRTC to evade network detection. We explain the mechanism and defence.
Vulnerabilities and CVEs CVE-2026-16232 (CVSS 9.1) lets an unauthenticated attacker take over SmartConsole with admin rights. It is in CISA KEV and actively exploited — patch now.
AI Security Researchers detailed SharedRoot (CVE-2026-46331) — a Claude Cowork agent escaping its local sandbox to files on the Mac. What it means for agent security.
Careers and Certifications Learn penetration testing from zero. The free Pentester Path at BreachRoad Academy: 13 modules, Kali Linux, knowledge tests, XP and ranks. Watch the video.
AI Security The OSTP director accused Moonshot AI of distilling Anthropic's model to build Kimi K3. We separate fact from claim and explain what it means for companies.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.