Security Operations Blog

Defense in Depth.

Technical articles on vulnerability management, threat detection, compliance automation, and building a security program that works.

Threat IntelligenceDevSecOps

Atomic Arch: 1,500+ AUR Packages Backdoored With an eBPF Rootkit and a Credential Stealer

Attackers claimed 1,500+ orphan Arch User Repository packages through legitimate adoption, then chained a malicious atomic-lockfile npm dependency, an eBPF rootkit, and a credential sweep. Detection gaps, MITRE mapping, and a blue-team response playbook.

Vulnerability ManagementThreat Intelligence

Oracle PeopleSoft Zero-Day CVE-2026-35273 Burned for Two Weeks: ShinyHunters Breach 100+ Organizations Through PSEMHUB

ShinyHunters spent two weeks exploiting CVE-2026-35273, a CVSS 9.8 pre-authentication RCE in Oracle PeopleSoft PSEMHUB, breaching 100+ organizations before Oracle's emergency patch landed. Detection gaps, MITRE mapping, and a blue-team response playbook.

Vulnerability ManagementThreat Intelligence

Qilin Ransomware Affiliate Is Already Through Check Point VPNs: CVE-2026-50751 Hits CISA KEV With a June 11 Deadline

An IKEv1 certificate validation flaw lets an unauthenticated attacker complete a Check Point VPN session without a valid password, and a Qilin ransomware affiliate is already inside. Detection gaps, MITRE mapping, and a blue-team response playbook.

Vulnerability ManagementThreat Intelligence

Root on the Controller, No Patch Available: Cisco SD-WAN Manager CVE-2026-20245 Is the Seventh Exploited Zero-Day of 2026

An authenticated netadmin can ride a crafted CLI input into full root on Cisco Catalyst SD-WAN Manager with no patch yet shipped. Detection gaps, MITRE mapping, and a blue-team response playbook.

Threat IntelligenceDevSecOps

Miasma Worm Republishes 96 Versions of 32 Red Hat npm Packages to Steal Cloud Credentials

A Mini Shai-Hulud variant abused GitHub Actions OIDC to republish 96 malicious versions across 32 official @redhat-cloud-services npm packages on June 1, sweeping AWS, GCP, Azure, and CI/CD secrets while self-replicating. Detection gaps, MITRE mapping, and a blue-team response playbook.

Vulnerability ManagementThreat Intelligence

Forged VPN Cookies, Real Network Access: PAN-OS CVE-2026-0257 Hits Its CISA KEV Deadline

An authentication bypass in PAN-OS GlobalProtect lets attackers forge override cookies and pull unauthorized VPN tunnels into internal networks. Active exploitation, detection gaps, MITRE mapping, and a blue-team response playbook.

Threat IntelligenceDevSecOps

Megalodon: 5,561 GitHub Repos Backdoored in Six Hours to Loot CI/CD Secrets

The Megalodon campaign pushed 5,718 malicious commits across 5,561 repositories, injecting GitHub Actions workflow files that exfiltrate CI/CD secrets with stolen tokens. CISA advisory, detection gaps, MITRE mapping, and a blue-team response playbook.

Threat IntelligenceDevSecOps

18 Minutes Live: A Poisoned Nx Console Extension Breached ~3,800 GitHub Internal Repos

A malicious Nx Console VS Code extension (nrwl.angular-console v18.95.0) ran for 18 minutes, stealing developer credentials and breaching roughly 3,800 GitHub internal repos. CVE-2026-48027 detection gaps, MITRE mapping, and a blue-team response playbook.

Threat IntelligenceDevSecOps

TrapDoor: 34 Malicious Packages Stealing Wallet Keys and Cloud Credentials Across npm, PyPI, and Crates.io

A live supply-chain campaign planted 34 credential-stealing packages and 384+ versions across three ecosystems, even poisoning AI assistant context files. Detection gaps, MITRE mapping, and a blue-team response playbook.

Threat IntelligenceDevSecOps

How a 90-Minute Git Tag Hijack Turned composer install Into a Credential Stealer

A supply-chain attacker rewrote git tags across four Composer packages to deploy a cross-platform credential stealer via autoload.files. Detection gaps, MITRE mapping, and response playbook.

BASFundamentals

What is Breach and Attack Simulation (BAS)? Complete Guide

BAS safely simulates real cyberattacks to test your defenses. How it works, BAS vs pentesting, MITRE ATT&CK mapping, and why every security team needs continuous validation.

AIFundamentals

Why Local-First Security Tools Are the Future

Cloud SaaS security tools send your most sensitive data to third-party servers. Local-first means your logs, source code, and credentials never leave your hardware.

DetectionFundamentals

Why Every Small Security Team Needs a SIEM

Enterprise SIEMs cost a fortune and small teams fly blind without log correlation. What a SIEM actually does, why it matters, and how local-first detection and BAS validation close the gap.

Threat IntelligenceFundamentals

A Practical Guide to MITRE ATT&CK for Blue Teams

What MITRE ATT&CK actually is, how to map your detections, coverage gaps most teams miss, and how to validate your coverage with BAS.

Compliance

Automating SOC 2 Compliance: From 6 Months to 6 Weeks

Manual compliance is killing small teams. How to automate evidence collection across SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST frameworks.

StrategyFundamentals

Building a Security Program From Scratch

Phase 1: Visibility. Phase 2: Protection. Phase 3: Validation. Phase 4: Governance. The complete playbook for going from zero to a working program.

Vulnerability ManagementAI

Why CVSS Is Dead: Building a Better Vulnerability Scoring Model

CVSS was designed for a world that no longer exists. Multi-layer scoring models factor in exploit maturity, business context, and threat intelligence.

Threat Intelligence

EPSS + KEV: The Scoring Stack That Actually Predicts Exploitation

Combining EPSS probability with CISA KEV binary signals produces a prioritization model that outperforms CVSS Base Score in every measurable category.

Compliance

SOC 2 Vulnerability Management Requirements: A Practical Guide

What SOC 2 actually requires for vulnerability management, how to automate evidence collection, and common audit findings to avoid.

Vulnerability ManagementFundamentals

Building a Vulnerability Management Program from Scratch

A step-by-step operational guide: asset discovery, scanning cadence, triage workflow, SLAs, and board reporting.

DevSecOps

Shift Left: Integrating SAST Into Your CI/CD Pipeline

Practical patterns for embedding static analysis into build pipelines without slowing developers down.

AIDevSecOps

AI-Powered Remediation: From Vulnerability to Fix in Seconds

How local AI models generate context-aware remediation guidance -- complete with code snippets, deployment steps, and rollback procedures.

Fundamentals

Stop Paying $40K for Vulnerability Management

The vulnerability management market charges enterprise prices for problems that can be solved with better tooling.

Vulnerability ManagementThreat Intelligence

Ransomware Triage: Prioritizing CVEs That Ransomware Gangs Actually Exploit

Cross-referencing KEV, ransomware campaign data, and EPSS to build a prioritization list focused on the CVEs ransomware operators actively weaponize.

Compliance

Compliance Mapping: ISO 27001, SOC 2, HIPAA, and NIST CSF in One View

Most organizations face multiple compliance frameworks. Cross-mapping controls reduces duplication and simplifies evidence collection.

No posts match that filter. Try a different category.