<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Hard2bit Cybersecurity Blog</title>
    <link>https://hard2bit.com/en/blog/</link>
    <atom:link href="https://hard2bit.com/en/rss.xml" rel="self" type="application/rss+xml" />
    <description>Technical analysis, NIS2, DORA, ENS and ISO 27001 guides and operational insights from the Hard2bit team: 24/7 SOC, pentesting, red team and incident response.</description>
    <language>en</language>
    <lastBuildDate>Thu, 24 Sep 2026 08:06:50 GMT</lastBuildDate>
    <item>
      <title>EvilTokens: the chatbot that read stolen Microsoft 365 inboxes to decide whom to defraud</title>
      <link>https://hard2bit.com/en/blog/eviltokens-takedown-chatbot-microsoft-365-inboxes-bec-fraud/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/eviltokens-takedown-chatbot-microsoft-365-inboxes-bec-fraud/</guid>
      <pubDate>Thu, 24 Sep 2026 08:06:50 GMT</pubDate>
      <description>Microsoft and a coalition of partners have dismantled EvilTokens, the device code phishing kit whose AI analysed stolen mailboxes to set up fraud. What the data shows and which controls work.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Plugin4Shell: the SHA pinning bypass in Claude Code, Codex, Copilot and Gemini CLI plugins</title>
      <link>https://hard2bit.com/en/blog/plugin4shell-commit-pinning-bypass-ai-coding-agent-plugins-claude-code-codex-copilot-gemini/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/plugin4shell-commit-pinning-bypass-ai-coding-agent-plugins-claude-code-codex-copilot-gemini/</guid>
      <pubDate>Mon, 21 Sep 2026 08:54:17 GMT</pubDate>
      <description>Four AI coding agents pinned every plugin to a reviewed commit and none of them checked where the checkout landed. What breaks, who has a patch and what to control in the enterprise.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>OWASP Top 10 2025 from the pentest side: what changed, what a web audit covers and what to add to the scope</title>
      <link>https://hard2bit.com/en/blog/owasp-top-10-2025-pentest-audit-scope/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/owasp-top-10-2025-pentest-audit-scope/</guid>
      <pubDate>Thu, 17 Sep 2026 07:41:53 GMT</pubDate>
      <description>What changed in the OWASP Top 10 2025, why two categories come from a survey rather than the data, what a pentester tests in each one and what to add to the scope of your next web audit.</description>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Honeytokens and decoy accounts in Active Directory and Entra ID: catching the attacker before they move</title>
      <link>https://hard2bit.com/en/blog/honeytokens-decoy-accounts-active-directory-entra-id/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/honeytokens-decoy-accounts-active-directory-entra-id/</guid>
      <pubDate>Wed, 16 Sep 2026 08:15:33 GMT</pubDate>
      <description>A guide to honeytokens: fake-SPN accounts, accounts that never sign in, credentials planted in SYSVOL and cloud tokens. How to build them, watch them and stop them becoming a risk.</description>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>Active Directory tiering: what Tier 0 is and how it stops a compromised laptop reaching the domain controller</title>
      <link>https://hard2bit.com/en/blog/active-directory-tiering-tier-0-privileged-access-model/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/active-directory-tiering-tier-0-privileged-access-model/</guid>
      <pubDate>Mon, 14 Sep 2026 10:10:58 GMT</pubDate>
      <description>What tiered administration is, what belongs in Tier 0, why so many organisations skip it, and which controls and evidence prove the model exists.</description>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>A flaw fixed in Chromium&apos;s code was still open in Chrome, and Chinese espionage moved in</title>
      <link>https://hard2bit.com/en/blog/patch-gap-chrome-zero-day-chinese-espionage-ai/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/patch-gap-chrome-zero-day-chinese-espionage-ai/</guid>
      <pubDate>Mon, 14 Sep 2026 08:18:59 GMT</pubDate>
      <description>Proofpoint and Volexity separately document Chinese groups exploiting three Chrome and Windows zero-days in the gap between the Chromium fix and the browser release.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Hard2bit sponsors CyberMadrid&apos;s second SME cybersecurity conference</title>
      <link>https://hard2bit.com/en/blog/hard2bit-silver-sponsor-ii-sme-cybersecurity-congress-cybermadrid/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/hard2bit-silver-sponsor-ii-sme-cybersecurity-congress-cybermadrid/</guid>
      <pubDate>Fri, 11 Sep 2026 10:05:00 GMT</pubDate>
      <description>On 29 September we will have a stand at Digitaliza Madrid and Thilina Manana joins the panel on the human factor and the supply chain.</description>
      <category>Noticias IT</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>A blank sender turns outside mail into inside mail in Microsoft 365</title>
      <link>https://hard2bit.com/en/blog/direct-send-microsoft-365-empty-sender-internal-spoofing/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/direct-send-microsoft-365-empty-sender-internal-spoofing/</guid>
      <pubDate>Tue, 08 Sep 2026 07:32:42 GMT</pubDate>
      <description>By leaving the SMTP envelope sender empty, an attacker sidesteps the RejectDirectSend control and slips external mail into Microsoft 365 as if it were internal. Detection and defence.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>A DMARC snapshot of 219 large Spanish companies: three in four block spoofing, only 38% at reject</title>
      <link>https://hard2bit.com/en/blog/dmarc-snapshot-large-spanish-companies-sectors-p-reject/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/dmarc-snapshot-large-spanish-companies-sectors-p-reject/</guid>
      <pubDate>Mon, 07 Sep 2026 09:52:11 GMT</pubDate>
      <description>We scanned SPF and DMARC across 219 large companies in 8 sectors: 73% block, 38% at reject, 22% with SPF at the edge of the limit. What RFC 9989 requires and how to reach p=reject.</description>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>Twelve years in which a PostgreSQL replication account could load code on the server (CVE-2026-6471)</title>
      <link>https://hard2bit.com/en/blog/postgreshell-cve-2026-6471-postgresql-replication-account-loads-code/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/postgreshell-cve-2026-6471-postgresql-replication-account-loads-code/</guid>
      <pubDate>Mon, 07 Sep 2026 06:01:08 GMT</pubDate>
      <description>PostGREShell (CVE-2026-6471) lets a REPLICATION account load code on the PostgreSQL server. Conditions, trail, detection, and how to patch without breaking logical replication.</description>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>CVE-2026-48710 BadHost is now on CISA&apos;s KEV catalogue, and the vulnerable library underpins LiteLLM, FastAPI and MCP </title>
      <link>https://hard2bit.com/en/blog/badhost-starlette-cve-2026-48710-cisa-kev-fastapi-litellm-mcp/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/badhost-starlette-cve-2026-48710-cisa-kev-fastapi-litellm-mcp/</guid>
      <pubDate>Sat, 05 Sep 2026 13:19:35 GMT</pubDate>
      <description>CVE-2026-48710, a CVSS 6.5 Starlette flaw, joins the KEV catalogue after being used to break into AI gateways without credentials. Who is exposed, how to detect it and how to patch.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>How to retire NTLM from your network before Windows switches it off for you</title>
      <link>https://hard2bit.com/en/blog/disable-ntlm-without-breaking-network-audit-kerberos-migration/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/disable-ntlm-without-breaking-network-audit-kerberos-migration/</guid>
      <pubDate>Fri, 04 Sep 2026 13:27:54 GMT</pubDate>
      <description>Microsoft will block NTLM by default in the next Windows release and tightens NTLMv1 in October 2026. Why it persists on your network, which events to audit and how to remove it in phases.</description>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>The C-Track breach at Thomson Reuters: four months of access to US and Canadian court data</title>
      <link>https://hard2bit.com/en/blog/troubleshooting-copy-vendor-c-track-courts-third-party-risk/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/troubleshooting-copy-vendor-c-track-courts-third-party-risk/</guid>
      <pubDate>Fri, 04 Sep 2026 08:22:58 GMT</pubDate>
      <description>US and Canadian courts handed database copies to their case management vendor to debug faults, and an intruder had them for four months. What EU rules require and what to check in your contracts.</description>
      <category>Normativa &amp; GRC</category>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>They hijacked the route, not the server: the BGP hijack that trojanised Virtualizor updates</title>
      <link>https://hard2bit.com/en/blog/bgp-hijack-virtualizor-malicious-update-root-hypervisors/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/bgp-hijack-virtualizor-malicious-update-root-hypervisors/</guid>
      <pubDate>Thu, 03 Sep 2026 08:59:01 GMT</pubDate>
      <description>An unauthorised BGP announcement diverted Softaculous traffic for 33 hours, handed the attacker a valid certificate and served a Virtualizor update with root. What failed and what to check.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Artifactory&apos;s phantom join key CVE-2026-82329: administrators with no credentials </title>
      <link>https://hard2bit.com/en/blog/artifactory-cve-2026-82329-phantom-join-key-admin-tokens/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/artifactory-cve-2026-82329-phantom-join-key-admin-tokens/</guid>
      <pubDate>Thu, 03 Sep 2026 07:40:12 GMT</pubDate>
      <description>CVE-2026-82329 lets attackers mint Artifactory admin tokens with no credentials. Patched 28 August, exploited by 1 September, now on CISA&apos;s KEV catalogue.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>A summer of DDoS against Norway: three attacks on the gateway a whole country logs in through</title>
      <link>https://hard2bit.com/en/blog/summer-ddos-norway-id-porten-public-services/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/summer-ddos-norway-id-porten-public-services/</guid>
      <pubDate>Thu, 27 Aug 2026 09:58:51 GMT</pubDate>
      <description>Three DDoS attacks in three months struck ID-porten, Norway&apos;s digital identity gateway. What the campaign reveals, and what any organisation that depends on a shared layer should take from it.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>DDoS protection for businesses: what to contract, what to rehearse and what will not save you</title>
      <link>https://hard2bit.com/en/blog/ddos-protection-businesses-mitigation-architecture/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/ddos-protection-businesses-mitigation-architecture/</guid>
      <pubDate>Thu, 27 Aug 2026 09:55:08 GMT</pubDate>
      <description>A business guide to DDoS protection: what to contract upstream, what your architecture must do, how to rehearse the response and what NIS2 demands. With 2026 data: 5,343 attacks mitigated every hour.</description>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>Incident response plans: how to build one in 2026, the reference model has changed</title>
      <link>https://hard2bit.com/en/blog/incident-response-plan-how-to-build-one/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/incident-response-plan-how-to-build-one/</guid>
      <pubDate>Wed, 26 Aug 2026 08:40:40 GMT</pubDate>
      <description>In 2025 NIST withdrew the incident response model much Spanish-language guidance still copies. What a plan needs today, the deadlines NIS2, DORA and Spain&apos;s ENS impose, and how to test it.</description>
      <category>Ciberseguridad</category>
      <category>Normativa &amp; GRC</category>
    </item>
    <item>
      <title>GhostJacking: turning Cloudflare, Datadog and Sentry logs into commands for your AI agent</title>
      <link>https://hard2bit.com/en/blog/ghostjacking-poisoned-logs-ai-agents-cloudflare-datadog-sentry/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/ghostjacking-poisoned-logs-ai-agents-cloudflare-datadog-sentry/</guid>
      <pubDate>Tue, 25 Aug 2026 09:21:31 GMT</pubDate>
      <description>The firewall blocked the request and that log entry carried the order in: how GhostJacking hijacks AI agents through the data they trust most.</description>
      <category>Ciberamenazas</category>
      <category>Investigación</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>BOD 26-04: four questions and a three-day deadline in CISA&apos;s new patching order</title>
      <link>https://hard2bit.com/en/blog/bod-26-04-cisa-risk-based-patching-three-days/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/bod-26-04-cisa-risk-based-patching-three-days/</guid>
      <pubDate>Mon, 24 Aug 2026 17:11:47 GMT</pubDate>
      <description>CISA has replaced flat patching deadlines with a four-variable risk model. What BOD 26-04 demands, and what European organisations can borrow from it.</description>
      <category>Normativa &amp; GRC</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>LOLBins: detecting the intruder that abuses trusted Windows binaries (living off the land)</title>
      <link>https://hard2bit.com/en/blog/detecting-abuse-trusted-windows-binaries-lolbins-living-off-the-land/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/detecting-abuse-trusted-windows-binaries-lolbins-living-off-the-land/</guid>
      <pubDate>Sat, 22 Aug 2026 09:22:08 GMT</pubDate>
      <description>82% of CrowdStrike&apos;s 2025 detections brought no malware: the attacker uses the signed programs you already have. Why antivirus misses them and how to hunt them.</description>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>Three in four breach notices no longer say how the attacker got in</title>
      <link>https://hard2bit.com/en/blog/breach-notices-hidden-root-cause-third-party-risk/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/breach-notices-hidden-root-cause-third-party-risk/</guid>
      <pubDate>Fri, 21 Aug 2026 08:09:14 GMT</pubDate>
      <description>Only 24% of breach notices now disclose the attack vector. What that does to supplier assessment in Europe, and what can still be demanded by contract.</description>
      <category>Normativa &amp; GRC</category>
      <category>Ciberamenazas</category>
    </item>
    <item>
      <title>TLPT under DORA in Spain: what the regulation demands and what the TIBER-ES guide still omits</title>
      <link>https://hard2bit.com/en/blog/tlpt-under-dora-spain-tiber-es-what-the-regulation-demands/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/tlpt-under-dora-spain-tiber-es-what-the-regulation-demands/</guid>
      <pubDate>Thu, 20 Aug 2026 18:32:48 GMT</pubDate>
      <description>The TIBER-ES guide dates from January 2022 and never mentions DORA. Since 2025 the same procedure has been mandatory for designated entities, and several of its parts have changed.</description>
      <category>Normativa &amp; GRC</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Detection engineering: coverage counts rules, robustness counts what survives an evasive adversary</title>
      <link>https://hard2bit.com/en/blog/detection-engineering-attack-coverage-versus-analytic-robustness/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/detection-engineering-attack-coverage-versus-analytic-robustness/</guid>
      <pubDate>Thu, 20 Aug 2026 09:22:45 GMT</pubDate>
      <description>MITRE retired ATT&amp;CK&apos;s detection fields and replaced them with 697 strategies and 1,758 analytics. That change explains why a coverage percentage measures the map rather than the ground.</description>
      <category>Ciberseguridad</category>
      <category>Investigación</category>
    </item>
    <item>
      <title>Which logs to send to your SIEM and which to leave out: priority sources, retention and cost</title>
      <link>https://hard2bit.com/en/blog/which-logs-to-send-to-siem-priority-sources-retention-cost/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/which-logs-to-send-to-siem-priority-sources-retention-cost/</guid>
      <pubDate>Wed, 19 Aug 2026 16:39:02 GMT</pubDate>
      <description>Production SIEMs ingest enough data to cover 90% of MITRE ATT&amp;CK and detect 22%. Which sources to prioritise, which fields to demand and how long to keep them.</description>
      <category>Ciberseguridad</category>
      <category>Ciberamenazas</category>
      <category>Normativa &amp; GRC</category>
    </item>
    <item>
      <title>Screen Sharing left on, port 5900 open: the macOS flaw that hands out root without a password</title>
      <link>https://hard2bit.com/en/blog/macos-screen-sharing-cve-2026-65400-root-without-credentials/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/macos-screen-sharing-cve-2026-65400-root-without-credentials/</guid>
      <pubDate>Sun, 16 Aug 2026 17:25:27 GMT</pubDate>
      <description>A macOS Screen Sharing flaw hands root to anyone who can reach port 5900. Exploitation is active with Monero miners, and the usual hardening offers no protection.</description>
      <category>Ciberamenazas</category>
      <category>Noticias IT</category>
    </item>
    <item>
      <title>The recruiter answered every email: how Lazarus planted a kernel rootkit inside European defence firms</title>
      <link>https://hard2bit.com/en/blog/lazarus-dream-job-zero-day-afd-fudmodule-defence/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/lazarus-dream-job-zero-day-afd-fudmodule-defence/</guid>
      <pubDate>Sun, 16 Aug 2026 10:49:37 GMT</pubDate>
      <description>Lazarus paired fake job offers and DLL side-loading in a PDF viewer with zero-day CVE-2026-68820 in afd.sys to plant the FudModule rootkit inside European defence firms.</description>
      <category>Ciberamenazas</category>
      <category>Noticias IT</category>
    </item>
    <item>
      <title>Three research teams bypassed passkey sign-in in a week, on already-compromised machines</title>
      <link>https://hard2bit.com/en/blog/passkey-attacks-compromised-endpoint-synced-keys/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/passkey-attacks-compromised-endpoint-synced-keys/</guid>
      <pubDate>Sat, 15 Aug 2026 10:13:41 GMT</pubDate>
      <description>Unit 42, SpecterOps and Mollema got past passkey sign-in without breaking the encryption, starting from an already-compromised endpoint. The weakness is in the implementation.</description>
      <category>Investigación</category>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Payroll Pirates: the Microsoft 365 intrusion that ends on payday</title>
      <link>https://hard2bit.com/en/blog/payroll-pirates-microsoft-365-salary-diversion-aitm/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/payroll-pirates-microsoft-365-salary-diversion-aitm/</guid>
      <pubDate>Fri, 14 Aug 2026 06:12:18 GMT</pubDate>
      <description>Hundreds of organisations targeted in July 2026: Payroll Pirates steals Microsoft 365 sessions with AiTM phishing, maps HR staff via Microsoft Graph and reroutes salaries.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Gunra turns the corporate VPN into its way in and MFA into its back door</title>
      <link>https://hard2bit.com/en/blog/gunra-ransomware-joint-advisory-vpn-mfa-backdoor/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/gunra-ransomware-joint-advisory-vpn-mfa-backdoor/</guid>
      <pubDate>Thu, 13 Aug 2026 10:45:47 GMT</pubDate>
      <description>Six US and South Korean agencies detail how Gunra operates: in through firewalls and VPNs, a back door planted inside MFA, and backups wiped before encryption.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>From the wind farm to the turbine: the private-APN pivot CERT Polska saw for the first time</title>
      <link>https://hard2bit.com/en/blog/private-apn-pivot-wind-farm-chp-plant-ot/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/private-apn-pivot-wind-farm-chp-plant-ot/</guid>
      <pubDate>Wed, 12 Aug 2026 06:17:55 GMT</pubDate>
      <description>An attacker pivoted from a wind farm to a heating plant through a private APN assumed to be isolated, stopped a turbine and wiped its tracks — no malware.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>TeamCity CVE-2026-63077: unauthenticated RCE on the server that builds your software</title>
      <link>https://hard2bit.com/en/blog/teamcity-cve-2026-63077-unauthenticated-rce-build-server/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/teamcity-cve-2026-63077-unauthenticated-rce-build-server/</guid>
      <pubDate>Tue, 11 Aug 2026 15:57:11 GMT</pubDate>
      <description>A deserialization flaw (CWE-502) in JetBrains TeamCity On-Premises allows unauthenticated remote code execution (CVSS 9.8). Now on CISA&apos;s KEV: timeline, detection and CI/CD hardening.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>One crew, four extortion brands: the help-desk call that lands on your personal phone</title>
      <link>https://hard2bit.com/en/blog/voice-phishing-extortion-multi-brand-unc6671-financial-sector/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/voice-phishing-extortion-multi-brand-unc6671-financial-sector/</guid>
      <pubDate>Tue, 11 Aug 2026 09:28:16 GMT</pubDate>
      <description>UNC6671 calls employees on their personal phones, steals the MFA token with AiTM infrastructure and negotiates under four separate brands. What it reveals about defending financial firms.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Kemp LoadMaster (CVE-2026-8037): 25 days between the patch and the first exploitation attempt</title>
      <link>https://hard2bit.com/en/blog/cve-2026-8037-kemp-loadmaster-patch-to-exploitation-window/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/cve-2026-8037-kemp-loadmaster-patch-to-exploitation-window/</guid>
      <pubDate>Mon, 10 Aug 2026 06:49:28 GMT</pubDate>
      <description>Progress patched the flaw on 4 June and attacks began on the 29th, the day the analysis went public. CISA added it to KEV on 7 August. What that timeline teaches about your patching deadlines.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Not all ENS certificates are equal: why scope and the audit result decide the value</title>
      <link>https://hard2bit.com/en/blog/not-all-ens-certificates-are-equal-scope-non-conformities/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/not-all-ens-certificates-are-equal-scope-non-conformities/</guid>
      <pubDate>Sun, 09 Aug 2026 10:54:54 GMT</pubDate>
      <description>Two suppliers can both claim ENS and cover very different things. What the boundary, the category and the audit result actually tell a buying committee.</description>
      <category>Normativa &amp; GRC</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Who needs ENS: Spanish public bodies, their suppliers and the companies caught in scope</title>
      <link>https://hard2bit.com/en/blog/who-needs-ens-spanish-public-sector-suppliers-scope/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/who-needs-ens-spanish-public-sector-suppliers-scope/</guid>
      <pubDate>Sun, 09 Aug 2026 10:54:54 GMT</pubDate>
      <description>The ENS reaches far beyond Spanish public bodies. When a contract, a system and administrative powers line up, private suppliers&apos; systems fall inside it too.</description>
      <category>Normativa &amp; GRC</category>
    </item>
    <item>
      <title>ENS for SaaS: when you need the Medium category and how to certify without inflating it</title>
      <link>https://hard2bit.com/en/blog/ens-for-saas-medium-level-scope-certification/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/ens-for-saas-medium-level-scope-certification/</guid>
      <pubDate>Sun, 09 Aug 2026 10:54:54 GMT</pubDate>
      <description>For a SaaS provider selling to Spanish public bodies, ENS arrives as a tender clause with a deadline. Boundary and category decide the cost. How to get both right.</description>
      <category>Normativa &amp; GRC</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>The Metabase zero-day: when your BI tool leaks your entire customer database</title>
      <link>https://hard2bit.com/en/blog/metabase-zero-day-sqli-bi-data-leak-third-party-risk/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/metabase-zero-day-sqli-bi-data-leak-third-party-risk/</guid>
      <pubDate>Sun, 09 Aug 2026 08:32:55 GMT</pubDate>
      <description>An unauthenticated CVSS 10.0 flaw in Metabase, exploited since 3 August, handed attackers the credentials for connected databases. What to check, how to detect it and who to notify.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>EDR blind spots: why attacks now come through firewalls, VPNs and routers, and how to detect them</title>
      <link>https://hard2bit.com/en/blog/edr-blind-spots-network-edge-devices-agentless-detection/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/edr-blind-spots-network-edge-devices-agentless-detection/</guid>
      <pubDate>Sun, 09 Aug 2026 07:43:10 GMT</pubDate>
      <description>Edge devices went from 3% to 22% of exploitation breaches in a year. Why EDR cannot reach firewalls, VPNs and routers, and how to regain visibility without an agent.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>Cyber due diligence in M&amp;A: valuing technology risk before you buy a company</title>
      <link>https://hard2bit.com/en/blog/cyber-due-diligence-ma-technology-risk/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/cyber-due-diligence-ma-technology-risk/</guid>
      <pubDate>Sat, 08 Aug 2026 09:41:25 GMT</pubDate>
      <description>Verizon cut US$350m from the Yahoo price over two breaches; Marriott inherited Starwood&apos;s penalty. What to assess, how to price it and how to get it into the agreement.</description>
      <category>Normativa &amp; GRC</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>AI has stopped copying known attacks and started inventing its own — what defenders must change</title>
      <link>https://hard2bit.com/en/blog/ai-invents-novel-attacks-offensive-research-defence/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/ai-invents-novel-attacks-offensive-research-defence/</guid>
      <pubDate>Sat, 08 Aug 2026 09:23:10 GMT</pubDate>
      <description>At Black Hat 2026 an AI system found attack techniques no human had catalogued first. Signature and known-TTP defence now has a much shorter shelf life.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>What cybersecurity brings to a business: from cost centre to a licence to sell</title>
      <link>https://hard2bit.com/en/blog/business-value-cybersecurity-company/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/business-value-cybersecurity-company/</guid>
      <pubDate>Fri, 07 Aug 2026 07:42:22 GMT</pubDate>
      <description>What does cybersecurity really do for a business? In 2026 it has stopped being an IT cost and become a key to winning contracts, a shield against losses and an engine of trust.</description>
      <category>Normativa &amp; GRC</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>NullReceiver hides C2 on the blockchain: why domain takedowns no longer stop the malware</title>
      <link>https://hard2bit.com/en/blog/nullreceiver-hidden-c2-blockchain-ethereum-npm/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/nullreceiver-hidden-c2-blockchain-ethereum-npm/</guid>
      <pubDate>Fri, 07 Aug 2026 06:25:14 GMT</pubDate>
      <description>Two North Korea-linked npm packages resolve their command server by reading a blank Ethereum transfer. NullReceiver defeats domain takedown — here is what changes for defenders.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
      <category>Investigación</category>
    </item>
    <item>
      <title>A DeepSeek-driven AI agent attacked 460 servers with barely a human in the loop</title>
      <link>https://hard2bit.com/en/blog/deepseek-ai-agent-autonomous-attacks-hermes-agent/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/deepseek-ai-agent-autonomous-attacks-hermes-agent/</guid>
      <pubDate>Thu, 06 Aug 2026 06:56:28 GMT</pubDate>
      <description>Unit 42 documented an actor who wired DeepSeek into an agent and automated a 460-target exploitation campaign. What it really showed, and how to defend against it.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>The self-replicating npm worm that plants Claude Code and VS Code hooks</title>
      <link>https://hard2bit.com/en/blog/npm-worm-keyv-mini-shai-hulud-hooks-claude-code-vscode/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/npm-worm-keyv-mini-shai-hulud-hooks-claude-code-vscode/</guid>
      <pubDate>Wed, 05 Aug 2026 07:54:02 GMT</pubDate>
      <description>A worm started in keyv@6.0.0 and spread on its own to hundreds of npm packages in half an hour: it steals dev and CI secrets and plants hooks that run when the project opens in Claude Code or VS Code.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>From 11 September the Cyber Resilience Act gives product makers 24 hours to report exploited flaws</title>
      <link>https://hard2bit.com/en/blog/cyber-resilience-act-24-hour-reporting-exploited-vulnerabilities/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/cyber-resilience-act-24-hour-reporting-exploited-vulnerabilities/</guid>
      <pubDate>Tue, 04 Aug 2026 07:11:45 GMT</pubDate>
      <description>The Cyber Resilience Act switches on its reporting regime on 11 September: 24 hours to flag an exploited vulnerability. It binds product makers, not only NIS2 operators.</description>
      <category>Normativa &amp; GRC</category>
    </item>
    <item>
      <title>Three critical VMware vCenter and ESXi flaws to patch now</title>
      <link>https://hard2bit.com/en/blog/vmware-vcenter-esxi-vmsa-2026-0006-critical-flaws-patch/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/vmware-vcenter-esxi-vmsa-2026-0006-critical-flaws-patch/</guid>
      <pubDate>Mon, 03 Aug 2026 08:47:43 GMT</pubDate>
      <description>Broadcom patches three critical VMware vCenter and ESXi flaws (CVSS up to 9.8): auth bypass, RCE and a VM escape. What to prioritise, no workaround.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>How a support phone call gets the attacker&apos;s passkey enrolled in your Microsoft 365</title>
      <link>https://hard2bit.com/en/blog/pink-vishing-passkey-enrolment-hijack-microsoft-365/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/pink-vishing-passkey-enrolment-hijack-microsoft-365/</guid>
      <pubDate>Mon, 03 Aug 2026 07:20:29 GMT</pubDate>
      <description>The Pink campaign phones employees posing as IT support, walks them through a fake passkey page and registers its own credential in the real Microsoft 365 account. What breaks and how to close it.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
    <item>
      <title>From 2 August your chatbot must say it is AI: what Article 50 of the AI Act requires</title>
      <link>https://hard2bit.com/en/blog/ai-act-article-50-ai-transparency-chatbots-deepfakes/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/ai-act-article-50-ai-transparency-chatbots-deepfakes/</guid>
      <pubDate>Fri, 31 Jul 2026 06:47:26 GMT</pubDate>
      <description>On 2 August 2026 Article 50 of the EU AI Act starts to apply. It is not only about big tech: if you run a chatbot or publish AI-generated content, the transparency duty is yours too.</description>
      <category>Normativa &amp; GRC</category>
      <category>Noticias IT</category>
    </item>
    <item>
      <title>Salesforce data theft without a single exploit: how ShinyHunters abuses OAuth and connected apps</title>
      <link>https://hard2bit.com/en/blog/salesforce-oauth-abuse-shinyhunters-connected-apps/</link>
      <guid isPermaLink="true">https://hard2bit.com/en/blog/salesforce-oauth-abuse-shinyhunters-connected-apps/</guid>
      <pubDate>Thu, 30 Jul 2026 15:50:42 GMT</pubDate>
      <description>Microsoft maps a year of ShinyHunters attacks on Salesforce: no platform exploit, just OAuth abuse, connected apps and stolen vendor tokens. What to review in your SaaS.</description>
      <category>Ciberamenazas</category>
      <category>Ciberseguridad</category>
    </item>
  </channel>
</rss>
