<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CosmicBytez Labs</title>
    <link>https://labs.cosmicbytez.ca</link>
    <description>IT &amp; Cybersecurity Intelligence - News, Security Alerts, HOWTOs, and Project Guides</description>
    <language>en-ca</language>
    <lastBuildDate>Sat, 27 Jun 2026 17:50:04 GMT</lastBuildDate>
    <atom:link href="https://labs.cosmicbytez.ca/api/rss" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://labs.cosmicbytez.ca/images/icon.png</url>
      <title>CosmicBytez Labs</title>
      <link>https://labs.cosmicbytez.ca</link>
    </image>
    
    <item>
      <title><![CDATA[Employee Offboarding: The Security Checklist Most Northern Alberta Businesses Skip]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2027-05-01-employee-offboarding-the-security-side</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2027-05-01-employee-offboarding-the-security-side</guid>
      <description><![CDATA[Offboarding is where most SMB security postures actually fail. The technical checklist is well-known. The process discipline is what&apos;s missing in…]]></description>
      <pubDate>Sat, 01 May 2027 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>offboarding</category>
      <category>identity management</category>
      <category>access management</category>
      <category>smb</category>
      <category>Operations</category>
      <category>Compliance</category>
    </item>
    <item>
      <title><![CDATA[OT Security for Sawmills, Shops, and Ag Operations: The Part of Cyber That Breaks Production]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2027-04-01-ot-security-for-sawmills-and-shop-floors</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2027-04-01-ot-security-for-sawmills-and-shop-floors</guid>
      <description><![CDATA[OT — operational technology — is the side of cyber that takes a sawmill offline for a week. PLCs, telemetry, SCADA, building-management systems. Different…]]></description>
      <pubDate>Thu, 01 Apr 2027 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>OT Security</category>
      <category>ICS</category>
      <category>sawmill</category>
      <category>agriculture</category>
      <category>oilpatch</category>
      <category>segmentation</category>
      <category>smb</category>
    </item>
    <item>
      <title><![CDATA[What a vCISO Actually Does for a 30-Person Business (and When You Don&apos;t Need One Yet)]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2027-03-01-vciso-when-smb-actually-needs-one</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2027-03-01-vciso-when-smb-actually-needs-one</guid>
      <description><![CDATA[vCISO services get marketed to every SMB with a security budget. Most businesses under 20 seats don&apos;t need one yet. Most businesses 20 to 100 seats with…]]></description>
      <pubDate>Mon, 01 Mar 2027 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>vciso</category>
      <category>smb</category>
      <category>security leadership</category>
      <category>Governance</category>
      <category>Compliance</category>
    </item>
    <item>
      <title><![CDATA[Your First Cyber-Insurance Renewal: What to Expect When the Questionnaire Arrives the Second Time]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2027-02-01-first-year-cyber-insurance-renewal-review</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2027-02-01-first-year-cyber-insurance-renewal-review</guid>
      <description><![CDATA[Year-two cyber-insurance renewals are when carriers tighten the screws. The questionnaire grows. Last year&apos;s &quot;we&apos;re working on it&quot; answers…]]></description>
      <pubDate>Mon, 01 Feb 2027 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>cyber insurance</category>
      <category>renewal</category>
      <category>questionnaire</category>
      <category>smb</category>
      <category>underwriting</category>
      <category>canada</category>
    </item>
    <item>
      <title><![CDATA[Northern Alberta SMB Cyber Threat Landscape: 2027 Outlook]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2027-01-15-northern-alberta-smb-cyber-threat-landscape-2027</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2027-01-15-northern-alberta-smb-cyber-threat-landscape-2027</guid>
      <description><![CDATA[What changed in 2026, what to expect in 2027, and where the actual risk falls for Canadian small businesses operating north of Edmonton. Based on what…]]></description>
      <pubDate>Fri, 15 Jan 2027 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>Threat Landscape</category>
      <category>2027</category>
      <category>smb</category>
      <category>northern alberta</category>
      <category>canada</category>
      <category>year ahead</category>
    </item>
    <item>
      <title><![CDATA[5 Things Every 2026 Cyber-Insurance Policy Now Requires (And How to Check Yours)]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2026-12-15-5-things-cyber-insurance-now-requires</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2026-12-15-5-things-cyber-insurance-now-requires</guid>
      <description><![CDATA[The policy language changed materially between 2024 and 2026, and most policies now contain conditions, sub-limits, and exclusions that did not exist three…]]></description>
      <pubDate>Tue, 15 Dec 2026 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>cyber insurance</category>
      <category>policy review</category>
      <category>smb</category>
      <category>canada</category>
      <category>underwriting</category>
      <category>claims</category>
    </item>
    <item>
      <title><![CDATA[Peace Country Cyber is Open for Business]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2026-12-01-peace-country-cyber-public-launch</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2026-12-01-peace-country-cyber-public-launch</guid>
      <description><![CDATA[Public launch day. After a year of writing, six months of planning, and a quiet soft-launch in November, Peace Country Cyber is officially open. Here&apos;s…]]></description>
      <pubDate>Tue, 01 Dec 2026 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>announcement</category>
      <category>peace country cyber</category>
      <category>launch</category>
      <category>northern alberta</category>
    </item>
    <item>
      <title><![CDATA[The Cyber-Insurance Compliance Checklist — Now Available]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2026-11-15-compliance-checklist-released</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2026-11-15-compliance-checklist-released</guid>
      <description><![CDATA[A free 30-item self-assessment covering the controls Canadian cyber-insurance carriers actually ask about in 2026. Designed to be filled out by a business…]]></description>
      <pubDate>Sun, 15 Nov 2026 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>cyber insurance</category>
      <category>checklist</category>
      <category>Compliance</category>
      <category>smb</category>
      <category>lead magnet</category>
      <category>canada</category>
    </item>
    <item>
      <title><![CDATA[Introducing Peace Country Cyber]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2026-11-01-peace-country-cyber-soft-launch</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2026-11-01-peace-country-cyber-soft-launch</guid>
      <description><![CDATA[After a year of writing about Canadian SMB cybersecurity, we&apos;re building the firm we wished existed for northern Alberta. Quiet launch today, full launch…]]></description>
      <pubDate>Sun, 01 Nov 2026 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>announcement</category>
      <category>peace country cyber</category>
      <category>northern alberta</category>
      <category>MSP</category>
    </item>
    <item>
      <title><![CDATA[29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-29-year-old-squid-proxy-bug-squidbleed-can-leak-cleartext-http-requests</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-29-year-old-squid-proxy-bug-squidbleed-can-leak-cleartext-http-requests</guid>
      <description><![CDATA[A heap over-read vulnerability introduced in a 1997 FTP parser change allows a malicious co-user of a shared Squid proxy to read other users' cleartext HTTP requests, including authorization headers and session tokens.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>vulnerability</category>
      <category>squid-proxy</category>
      <category>cve</category>
      <category>memory-disclosure</category>
      <category>enterprise-security</category>
      <category>patch</category>
    </item>
    <item>
      <title><![CDATA[Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-data-exposure-flaws-threaten-dify-ai-platform-used-by-1-million-apps</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-data-exposure-flaws-threaten-dify-ai-platform-used-by-1-million-apps</guid>
      <description><![CDATA[Security researchers discovered multi-tenant isolation failures in the Dify AI platform that allowed attackers to read private conversations from other tenants, preview their uploaded documents, and reach internal APIs — threatening the privacy of over one million applications built on the platform.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI Security</category>
      <category>Cloud Security</category>
      <category>Dify</category>
      <category>Data Exposure</category>
      <category>Multi-Tenant</category>
      <category>IDOR</category>
    </item>
    <item>
      <title><![CDATA[Eight-Year-Old Samsung KNOX Flaw Exposed Millions of Galaxy Devices to Kernel Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-eight-year-old-samsung-knox-flaw-exposed-millions-of-galaxy-devices-to-kernel-at</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-eight-year-old-samsung-knox-flaw-exposed-millions-of-galaxy-devices-to-kernel-at</guid>
      <description><![CDATA[A high-severity use-after-free vulnerability lurking in Samsung's KNOX security framework for eight years left Galaxy devices from the S9 through S25 series vulnerable to kernel-level attacks. The flaw has now been patched, but its longevity raises serious questions about security review processes in flagship device platforms.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Samsung</category>
      <category>KNOX</category>
      <category>Android</category>
      <category>Kernel</category>
      <category>Use-After-Free</category>
      <category>Vulnerability</category>
      <category>Mobile Security</category>
    </item>
    <item>
      <title><![CDATA[FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-fortibleed-attackers-turn-firewalls-into-credential-stealers-as-heists-persist</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-fortibleed-attackers-turn-firewalls-into-credential-stealers-as-heists-persist</guid>
      <description><![CDATA[The FortiBleed campaign's operators weaponize Fortinet's own built-in diagnostic command to run a custom Golang sniffer that intercepts 24 authentication protocols — turning compromised FortiGate devices into self-sustaining credential harvesting platforms feeding 650+ parallel pipelines.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Threat Intelligence</category>
      <category>Fortinet</category>
      <category>FortiBleed</category>
      <category>Credential Theft</category>
      <category>Malware</category>
    </item>
    <item>
      <title><![CDATA[FortiBleed: Russian IAB Harvested 110 Million Credentials from 430,000 FortiGate Firewalls]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-fortibleed-targeted-fortigate-firewalls-in-110-million-credential-harvesting-ope</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-fortibleed-targeted-fortigate-firewalls-in-110-million-credential-harvesting-ope</guid>
      <description><![CDATA[A financially motivated Russian-speaking initial access broker behind the FortiBleed campaign has been systematically harvesting credentials from over 430,000 FortiGate firewalls worldwide since February 2026, amassing more than 110 million stolen credentials for sale on criminal markets.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Fortinet</category>
      <category>FortiGate</category>
      <category>Russia</category>
      <category>Credential Theft</category>
      <category>Initial Access Broker</category>
      <category>Firewall</category>
    </item>
    <item>
      <title><![CDATA[GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-github-updates-actionscheckout-to-block-common-pwn-request-attack-patterns</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-github-updates-actionscheckout-to-block-common-pwn-request-attack-patterns</guid>
      <description><![CDATA[GitHub released actions/checkout v7 on June 18, 2026, adding default protections that refuse to fetch fork PR code inside pull_request_target workflows — closing a widely misused CI/CD privilege escalation vector responsible for secrets theft at Nx, PostHog, TanStack, and others.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Supply Chain</category>
      <category>GitHub Actions</category>
      <category>CI/CD</category>
      <category>Security Updates</category>
    </item>
    <item>
      <title><![CDATA[LastPass Confirms Data Breach in Klue Supply Chain Attack]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-lastpass-confirms-data-breach-in-klue-supply-chain-attack</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-lastpass-confirms-data-breach-in-klue-supply-chain-attack</guid>
      <description><![CDATA[The Icarus extortion group compromised Klue, an AI-powered competitive intelligence platform, harvesting OAuth tokens to drain CRM data from hundreds of enterprise Salesforce environments — including LastPass, Huntress, HackerOne, and Recorded Future.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Supply Chain</category>
      <category>Salesforce</category>
      <category>Extortion</category>
    </item>
    <item>
      <title><![CDATA[New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-new-oxloader-loader-uses-malicious-google-ads-to-deliver-castlestealer</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-new-oxloader-loader-uses-malicious-google-ads-to-deliver-castlestealer</guid>
      <description><![CDATA[Elastic Security Labs has uncovered OXLOADER, a sophisticated new malware loader using malvertising via Google Ads to target developers searching for Node.js, ultimately deploying the CastleStealer information stealer with heavy obfuscation and anti-analysis techniques.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>malware</category>
      <category>infostealer</category>
      <category>malvertising</category>
      <category>google-ads</category>
      <category>castlestealer</category>
      <category>oxloader</category>
      <category>elastic-security</category>
    </item>
    <item>
      <title><![CDATA[OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-openai-expands-daybreak-with-gpt-55-cyber-to-help-defenders-patch-security-flaws</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-openai-expands-daybreak-with-gpt-55-cyber-to-help-defenders-patch-security-flaws</guid>
      <description><![CDATA[OpenAI has released GPT-5.5-Cyber, its most capable security model yet, as part of the Daybreak initiative — targeting real-world vulnerabilities in Chrome V8, Safari, Firefox, and critical open-source infrastructure like cURL and Python.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>ai</category>
      <category>openai</category>
      <category>vulnerability-research</category>
      <category>patch-management</category>
      <category>open-source-security</category>
      <category>daybreak</category>
    </item>
    <item>
      <title><![CDATA[Russian Initial Access Broker Behind FortiBleed Campaign]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-russian-initial-access-broker-behind-fortibleed-campaign</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-russian-initial-access-broker-behind-fortibleed-campaign</guid>
      <description><![CDATA[A Russian-speaking initial access broker has compromised 86,644 verified credentials from over 430,000 internet-facing Fortinet FortiGate devices across 194 countries, deploying a custom Golang sniffer tool and a 45-GPU cracking infrastructure in a campaign active since February 2026.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>APT</category>
      <category>Russia</category>
      <category>Nation-State</category>
      <category>Fortinet</category>
      <category>FortiBleed</category>
    </item>
    <item>
      <title><![CDATA[Scope of Salesforce Attacks Expands as Icarus Leaks Stolen Data]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-scope-of-salesforce-attacks-expands-as-icarus-leaks-data</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-scope-of-salesforce-attacks-expands-as-icarus-leaks-data</guid>
      <description><![CDATA[More victims have surfaced after attackers breached application vendor Klue and abused its OAuth tokens to access customers' Salesforce environments. The Icarus threat actor is now publicly leaking the harvested data.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Salesforce</category>
      <category>OAuth</category>
      <category>Supply Chain</category>
      <category>Klue</category>
      <category>Icarus</category>
      <category>Threat Intelligence</category>
    </item>
    <item>
      <title><![CDATA[WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-23-whatsapp-vbscript-campaign-uses-fake-documents-to-install-manageengine-rmm-tool</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-23-whatsapp-vbscript-campaign-uses-fake-documents-to-install-manageengine-rmm-tool</guid>
      <description><![CDATA[Attackers are abusing compromised WhatsApp accounts to distribute malicious VBScript files disguised as financial documents, ultimately deploying a legitimate RMM tool as a persistent backdoor.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>malware</category>
      <category>social-engineering</category>
      <category>whatsapp</category>
      <category>vbscript</category>
      <category>rmm</category>
      <category>living-off-the-land</category>
      <category>kaspersky</category>
    </item>
    <item>
      <title><![CDATA[CVE-2025-67038: Lantronix EDS5000 OS Command Injection Vulnerability]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2025-67038-lantronix-eds5000-code-injection-vulnerability</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2025-67038-lantronix-eds5000-code-injection-vulnerability</guid>
      <description><![CDATA[A critical OS command injection flaw in the Lantronix EDS5000 serial device server allows unauthenticated attackers to inject arbitrary commands via the username parameter, executing them with root privileges. Added to CISA's Known Exploited Vulnerabilities catalog.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>CISA KEV</category>
      <category>Command Injection</category>
      <category>Lantronix</category>
      <category>Industrial</category>
      <category>IoT</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-11374: ManageEngine SSO Ticket Prediction Enables Unauthenticated Account Takeover]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-11374</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-11374</guid>
      <description><![CDATA[A critical authentication vulnerability in four ManageEngine products allows unauthenticated attackers to predict SSO session tickets and take over accounts. ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus are all affected. Patches are available.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-11374</category>
      <category>ManageEngine</category>
      <category>SSO</category>
      <category>Authentication Bypass</category>
      <category>Account Takeover</category>
      <category>Active Directory</category>
      <category>CWE-330</category>
      <category>Windows</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-12866: expr-eval npm Package Enables Arbitrary Code Execution via toJSFunction()]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-12866</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-12866</guid>
      <description><![CDATA[All versions of the expr-eval JavaScript package are vulnerable to remote code execution through the toJSFunction() API. Crafted expressions escape the sandbox via new Function(), enabling attackers to run arbitrary Node.js code.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-12866</category>
      <category>expr-eval</category>
      <category>npm</category>
      <category>JavaScript</category>
      <category>Node.js</category>
      <category>Code Injection</category>
      <category>RCE</category>
      <category>Sandbox Escape</category>
      <category>CWE-94</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-9733: Mojolicious OAuth2 Weak PRNG Enables CSRF Session Hijacking]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-9733</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-9733</guid>
      <description><![CDATA[A critical flaw in the Mojolicious::Plugin::Web::Auth::OAuth2 Perl module uses a predictable SHA-1 state derived from epoch time and rand(), allowing attackers to hijack OAuth sessions via CSRF with no privileges required.]]></description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-9733</category>
      <category>OAuth2</category>
      <category>CSRF</category>
      <category>Perl</category>
      <category>CPAN</category>
      <category>Session Hijacking</category>
      <category>CWE-338</category>
      <category>Weak PRNG</category>
    </item>
    <item>
      <title><![CDATA[AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-arystinger-malware-infects-4300-legacy-routers-proxy-network</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-arystinger-malware-infects-4300-legacy-routers-proxy-network</guid>
      <description><![CDATA[Researchers at QiAnXin's XLab have identified AryStinger, a novel malware targeting end-of-life D-Link routers and QNAP NAS devices to build a distributed proxy network used for pre-breach reconnaissance rather than traditional DDoS botnet activity.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Malware</category>
      <category>Botnet</category>
      <category>Router Security</category>
      <category>QNAP</category>
      <category>D-Link</category>
    </item>
    <item>
      <title><![CDATA[FFmpeg Fixes PixelSmash Flaw in Widely Used Video Decoder]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-ffmpeg-fixes-pixelsmash-flaw-in-widely-used-video-decoder</guid>
      <description><![CDATA[FFmpeg has patched a critical vulnerability dubbed PixelSmash that could enable remote code execution on Jellyfin servers and denial-of-service conditions in Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>FFmpeg</category>
      <category>Vulnerability</category>
      <category>CVE</category>
      <category>Security Update</category>
      <category>Cloud Security</category>
    </item>
    <item>
      <title><![CDATA[FortiBleed Campaign Used Custom FortiGate Sniffer to Steal Credentials]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-fortibleed-campaign-used-custom-fortigate-sniffer-to-steal-credentials</guid>
      <description><![CDATA[The large-scale FortiBleed campaign targeting Fortinet FortiGate devices deployed custom packet sniffers to harvest authentication secrets from compromised firewalls, systematically stealing credentials at scale.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Fortinet</category>
      <category>FortiGate</category>
      <category>Credential Theft</category>
      <category>Threat Campaign</category>
    </item>
    <item>
      <title><![CDATA[INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-interpol-warns-phishing-ransomware-ai-scams-asia-pacific</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-interpol-warns-phishing-ransomware-ai-scams-asia-pacific</guid>
      <description><![CDATA[A new INTERPOL report reveals a dramatic surge in Asia-Pacific cybercrime, with phishing rates nearly double the global average, ransomware attacks exceeding 135,000 in 2024, and AI-powered scams fueling an estimated $37 billion in regional losses.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Phishing</category>
      <category>AI</category>
      <category>Cybercrime</category>
      <category>INTERPOL</category>
    </item>
    <item>
      <title><![CDATA[JaredFromSubway MEV Bot Hacked in $15 Million Crypto Theft]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-jaredfromsubway-mev-bot-hacked-in-15-million-crypto-theft</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-jaredfromsubway-mev-bot-hacked-in-15-million-crypto-theft</guid>
      <description><![CDATA[The JaredFromSubway Ethereum MEV bot lost $15 million after an attacker exploited its opportunity-detection logic by creating fake trading setups, draining funds in a sophisticated on-chain manipulation attack.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Cryptocurrency</category>
      <category>DeFi Security</category>
      <category>MEV</category>
      <category>Blockchain</category>
      <category>Exploit</category>
    </item>
    <item>
      <title><![CDATA[Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-microsoft-fixes-autogen-studio-flaw-that-enabled-code-execution</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-microsoft-fixes-autogen-studio-flaw-that-enabled-code-execution</guid>
      <description><![CDATA[Microsoft has patched the AutoJack vulnerability chain in AutoGen Studio, its AI agent prototyping interface, which allowed attackers to manipulate agents into executing arbitrary commands simply by having a user visit a malicious webpage.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Microsoft</category>
      <category>AI Security</category>
      <category>Vulnerability</category>
      <category>Code Execution</category>
      <category>Security Update</category>
    </item>
    <item>
      <title><![CDATA[Microsoft Says Windows 11 26H2 Is Coming Soon, Details Upgrade Process]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-microsoft-says-windows-11-26h2-is-coming-soon-details-upgrade-process</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-microsoft-says-windows-11-26h2-is-coming-soon-details-upgrade-process</guid>
      <description><![CDATA[Microsoft has confirmed Windows 11 version 26H2 as the next feature update, with devices running 24H2 and 25H2 able to upgrade via a lightweight enablement package rather than a full OS reinstall.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Microsoft</category>
      <category>Windows</category>
      <category>Security Updates</category>
      <category>Patch Management</category>
    </item>
    <item>
      <title><![CDATA[New Exploit Bypasses Apple's Boot Defenses, Affects Millions of iPhones]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-new-exploit-bypasses-apple-boot-defenses-millions-iphones</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-new-exploit-bypasses-apple-boot-defenses-millions-iphones</guid>
      <description><![CDATA[The Usbliter8 exploit targets a hardware-level flaw in Apple A12 and A13 SecureROM boot chains that cannot be patched via software updates, leaving millions of older iPhones permanently vulnerable to bootchain bypass and persistent spyware deployment.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Vulnerability</category>
      <category>Apple</category>
      <category>Security Updates</category>
    </item>
    <item>
      <title><![CDATA[A Record-Breaking Patch Tuesday for June 2026]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-record-breaking-patch-tuesday-june-2026</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-record-breaking-patch-tuesday-june-2026</guid>
      <description><![CDATA[Microsoft's June 2026 Patch Tuesday addressed nearly 200 security vulnerabilities — the highest single-month patch count in the company's history — including roughly 30 Critical-rated flaws across Windows, IIS, Visual Studio Code, and Azure.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Microsoft</category>
      <category>Windows</category>
      <category>Patch Tuesday</category>
      <category>Security Updates</category>
      <category>CVE</category>
    </item>
    <item>
      <title><![CDATA[Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-researchers-detail-difytap-flaws-in-dify-that-could-expose-ai-chats-across-tenan</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-researchers-detail-difytap-flaws-in-dify-that-could-expose-ai-chats-across-tenan</guid>
      <description><![CDATA[Four vulnerabilities dubbed DifyTap were disclosed in the open-source AI workflow platform Dify, enabling attackers to silently read AI conversations from other customers' applications without requiring authentication.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI Security</category>
      <category>Cloud Security</category>
      <category>Vulnerability</category>
      <category>Multi-Tenant</category>
    </item>
    <item>
      <title><![CDATA[A Glimpse into the 'Search Your Target' Market for Stolen Credentials]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-search-your-target-stolen-credentials-market</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-search-your-target-stolen-credentials-market</guid>
      <description><![CDATA[An emerging underground market lets attackers pay to search specific domains and companies within massive stolen credential databases — eliminating the need to sift through billions of records and dramatically lowering the barrier to targeted credential-based attacks.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>BleepingComputer</category>
      <category>General</category>
    </item>
    <item>
      <title><![CDATA[ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-shapedplugin-wordpress-pro-plugins-backdoored-in-supply-chain-attack</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-shapedplugin-wordpress-pro-plugins-backdoored-in-supply-chain-attack</guid>
      <description><![CDATA[Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack, with attackers injecting backdoor code into Pro plugin releases distributed through official channels.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Supply Chain</category>
      <category>WordPress</category>
      <category>Malware</category>
      <category>Threat Intelligence</category>
    </item>
    <item>
      <title><![CDATA[Texas Parks & Wildlife Data Breach Affects 3 Million Individuals]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-texas-parks-wildlife-data-breach-3-million</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-texas-parks-wildlife-data-breach-3-million</guid>
      <description><![CDATA[Hackers stole personal information including driver's license and passport numbers after breaching a third-party license vendor serving the Texas Parks and Wildlife Department.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Supply Chain</category>
      <category>PII</category>
      <category>Texas</category>
    </item>
    <item>
      <title><![CDATA[Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-weekly-recap-browser-bugs-edr-killers-tv-botnet-openbsd-flaw-android-trojan</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-weekly-recap-browser-bugs-edr-killers-tv-botnet-openbsd-flaw-android-trojan</guid>
      <description><![CDATA[This week's threat roundup covers the Usbliter8 iPhone boot exploit, NarwhalRAT spread via fake Microsoft alerts, The Gentlemen ransomware's GentleKiller EDR framework, a smart TV ad-fraud botnet, and an OpenBSD kernel flaw — plus the week's other notable security stories.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Ransomware</category>
      <category>Malware</category>
      <category>Android</category>
      <category>The Hacker News</category>
      <category>Cybercrime</category>
    </item>
    <item>
      <title><![CDATA[What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-what-the-latest-shinyhunters-breaches-reveal-about-modern-cyberattacks</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-what-the-latest-shinyhunters-breaches-reveal-about-modern-cyberattacks</guid>
      <description><![CDATA[Groups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage — identity-based attacks and supply chain compromises are now the dominant playbook.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Malware</category>
      <category>Zero-Day</category>
      <category>Data Breach</category>
    </item>
    <item>
      <title><![CDATA[WhatsApp Phishing Attack Uses Fake Business Docs to Hack PCs]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-22-whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-22-whatsapp-phishing-attack-uses-fake-business-docs-to-hack-pcs</guid>
      <description><![CDATA[An active malware campaign is targeting WhatsApp users across multiple countries with deceptive messages pushing VBScript-based droppers disguised as business documents, leading to remote system compromise.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Phishing</category>
      <category>Malware</category>
      <category>WhatsApp</category>
      <category>Social Engineering</category>
      <category>VBScript</category>
    </item>
    <item>
      <title><![CDATA[Deploy OpenCanary to Catch Attackers Inside Your Network]]></title>
      <link>https://labs.cosmicbytez.ca/howtos/2026-06-22-opencanary-honeypot-deployment</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/howtos/2026-06-22-opencanary-honeypot-deployment</guid>
      <description><![CDATA[Set up OpenCanary honeypot services on a Raspberry Pi or VM to detect lateral movement, credential stuffing, and unauthorized access before attackers reach real systems.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
      <category>howto</category>
      <category>honeypot</category>
      <category>deception</category>
      <category>intrusion-detection</category>
      <category>opencanary</category>
      <category>blue-team</category>
      <category>network-security</category>
      <category>threat-detection</category>
    </item>
    <item>
      <title><![CDATA[Accenture to Acquire Majority Stake in Dragos, runZero, and NetRise in $4.1 Billion OT Cybersecurity Push]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-21-accenture-acquires-dragos-runzero-netrise-41-billion</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-21-accenture-acquires-dragos-runzero-netrise-41-billion</guid>
      <description><![CDATA[Accenture's $4.1 billion acquisition of Dragos (valued at $3.25B), runZero, and NetRise marks the largest consolidation in operational technology cybersecurity history.]]></description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>OT Security</category>
      <category>M&amp;A</category>
      <category>Dragos</category>
      <category>Accenture</category>
      <category>Industrial Security</category>
      <category>Critical Infrastructure</category>
      <category>ICS</category>
    </item>
    <item>
      <title><![CDATA[Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-21-ai-agents-identity-governance-challenge</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-21-ai-agents-identity-governance-challenge</guid>
      <description><![CDATA[AI agents can access databases, trigger workflows, deploy code, and interact with critical business systems — often with little oversight. Token Security breaks down why AI agent identity governance is the next major security frontier.]]></description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI Security</category>
      <category>Identity</category>
      <category>Governance</category>
      <category>Zero Trust</category>
      <category>Shadow AI</category>
      <category>Agentic AI</category>
      <category>DevSecOps</category>
    </item>
    <item>
      <title><![CDATA[AryStinger Botnet Infected Thousands of D-Link Routers Worldwide]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-21-arystinger-botnet-infected-thousands-of-d-link-routers-worldwide</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-21-arystinger-botnet-infected-thousands-of-d-link-routers-worldwide</guid>
      <description><![CDATA[A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated D-Link routers, converting them into malicious proxy nodes used to anonymize threat actor traffic.]]></description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Malware</category>
      <category>Botnet</category>
      <category>D-Link</category>
      <category>Routers</category>
      <category>BleepingComputer</category>
    </item>
    <item>
      <title><![CDATA[China-Nexus Actor Spies on US Researchers Undetected for a Year]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-21-china-nexus-actor-spies-on-us-researchers-undetected-for-a-year</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-21-china-nexus-actor-spies-on-us-researchers-undetected-for-a-year</guid>
      <description><![CDATA[Google's Threat Intelligence Group discovered and disrupted a sprawling China-nexus espionage campaign that stole RedCAP credentials to silently breach research institutions and exfiltrate sensitive data for over a year.]]></description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Espionage</category>
      <category>China</category>
      <category>Google</category>
      <category>Threat Intelligence</category>
      <category>Nation-State</category>
    </item>
    <item>
      <title><![CDATA[French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-21-french-president-urges-us-to-share-cutting-edge-ai-and-democracies-to-cooperate</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-21-french-president-urges-us-to-share-cutting-edge-ai-and-democracies-to-cooperate</guid>
      <description><![CDATA[At the G7 summit in France, President Macron called on the US to share frontier AI technology with allied democracies and pushed for coordinated...]]></description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>AI Policy</category>
      <category>Geopolitics</category>
      <category>Regulation</category>
      <category>AI Governance</category>
      <category>G7</category>
    </item>
    <item>
      <title><![CDATA[Google Exposes China Espionage Group UNC6508 Lurking in Networks Since 2023]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-21-google-exposes-unc6508-china-espionage-group</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-21-google-exposes-unc6508-china-espionage-group</guid>
      <description><![CDATA[Google's Threat Intelligence Group has unmasked UNC6508, a China-linked espionage actor that silently maintained access to critical infrastructure and research networks for over three years before detection.]]></description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>China</category>
      <category>Espionage</category>
      <category>UNC6508</category>
      <category>APT</category>
      <category>Critical Infrastructure</category>
      <category>Google</category>
      <category>Threat Intelligence</category>
      <category>Nation-State</category>
    </item>
    <item>
      <title><![CDATA[Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-21-hackers-exploit-gravity-smtp-wordpress-plugin-bug-to-expose-api-keys</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-21-hackers-exploit-gravity-smtp-wordpress-plugin-bug-to-expose-api-keys</guid>
      <description><![CDATA[Active exploitation of CVE-2026-4020 in the Gravity SMTP WordPress plugin has generated over 17 million malicious requests, allowing unauthenticated...]]></description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>WordPress</category>
      <category>CVE</category>
      <category>Vulnerability</category>
      <category>API Keys</category>
      <category>Web Security</category>
    </item>
    <item>
      <title><![CDATA[In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-06-21-in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrik</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-06-21-in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrik</guid>
      <description><![CDATA[This week's security roundup covers Apple's patch for a Beats headphones eavesdropping vulnerability, the DOT closing its investigation into Delta's CrowdStrike outage response, AWS Continuum's launch, and new details on the Android TV botnet Popa.]]></description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Apple</category>
      <category>Android</category>
      <category>AWS</category>
      <category>Security Updates</category>
      <category>SecurityWeek</category>
      <category>Roundup</category>
    </item>
  </channel>
</rss>