<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Threat Landscape Blog</title>
    <link>https://threatlandscape.io/blog</link>
    <description>Insights, updates, and tactical analysis on the evolving threat landscape.</description>
    <language>en-us</language>
    <copyright>Copyright 2026 ThreatLandscape.io</copyright>
    <lastBuildDate>Wed, 16 Sep 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://threatlandscape.io/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Real Cost of Threat Intelligence: Why Managed CTI Beats the DIY Approach</title>
      <link>https://threatlandscape.io/blog/real-cost-of-threat-intelligence-managed-cti-vs-diy</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/real-cost-of-threat-intelligence-managed-cti-vs-diy</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate>
      <description>Open-source feeds look free, but analyst time is the real cost. See how managed CTI turns fragmented data into structured, contextual intelligence.</description>
      <category>Threat Intelligence</category>
      <category>CTI</category>
      <category>Managed CTI</category>
      <category>Threat Intelligence</category>
      <category>OSINT</category>
      <category>STIX</category>
      <category>MITRE ATT&amp;CK</category>
      <category>SOC</category>
    </item>
    <item>
      <title>Threat Landscape Intelligence Now Powers Ecliptica Replay</title>
      <link>https://threatlandscape.io/blog/threat-landscape-intelligence-now-powers-ecliptica-replay</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/threat-landscape-intelligence-now-powers-ecliptica-replay</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
      <description>Threat Landscape threat intelligence is now integrated with Ecliptica Replay, the local-first AI Detection and Response platform from Ecliptica Labs. Correlate live AI agent activity against infrastructure already known to be hostile.</description>
      <category>Product News</category>
      <category>Ecliptica Replay</category>
      <category>AIDR</category>
      <category>AI Agents</category>
      <category>Integrations</category>
      <category>Threat Intelligence</category>
      <category>STIX</category>
      <category>Product News</category>
    </item>
    <item>
      <title>CVE-2026-35029: LiteLLM Read-Only Keys Take Over the AI Gateway</title>
      <link>https://threatlandscape.io/blog/cve-2026-35029-litellm-read-only-keys-take-over-the-ai-gateway</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/cve-2026-35029-litellm-read-only-keys-take-over-the-ai-gateway</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-35029 (CVSS 8.7) lets authenticated LiteLLM users rewrite /config/update, read files via /get_image, and take over the AI gateway. Patch 1.83.0+.</description>
      <category>Threat Advisory</category>
      <category>CVE-2026-35029</category>
      <category>LiteLLM</category>
      <category>privilege escalation</category>
      <category>AI gateway</category>
      <category>broken access control</category>
      <category>zero-day</category>
      <category>CVSS</category>
      <category>threat advisory</category>
    </item>
    <item>
      <title>Dissecting RecruitTrap: Browser-in-the-Browser Phishing Adapts to Enterprise Mobile Endpoints</title>
      <link>https://threatlandscape.io/blog/dissecting-recruittrap-browser-in-the-browser-phishing-adapts-to-enterprise-mobile-endpoints</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/dissecting-recruittrap-browser-in-the-browser-phishing-adapts-to-enterprise-mobile-endpoints</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description>Analysis of the RecruitTrap campaign using Browser-in-the-Browser and mobile flows to harvest corporate credentials and bypass MFA.</description>
      <category>Threat Intelligence</category>
      <category>Phishing</category>
      <category>Browser-in-the-Browser</category>
      <category>RecruitTrap</category>
      <category>OAuth</category>
      <category>MFA Bypass</category>
      <category>Social Engineering</category>
    </item>
    <item>
      <title>Sality P2P Botnet Disruption: Peer-List Sinkholing Ends a 23-Year Operation</title>
      <link>https://threatlandscape.io/blog/sality-p2p-botnet-disruption-peer-list-sinkholing-ends-a-23-year-operation</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/sality-p2p-botnet-disruption-peer-list-sinkholing-ends-a-23-year-operation</guid>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <description>How defenders dismantled the 23-year Sality P2P botnet: peer-list poisoning, URL pack seizures, EggJagger clipjacking, and IOCs for SALTY SPIDER.</description>
      <category>Threat Intelligence</category>
      <category>Sality</category>
      <category>botnet disruption</category>
      <category>P2P botnet</category>
      <category>EggJagger</category>
      <category>SALTY SPIDER</category>
      <category>sinkhole</category>
      <category>clipjacking</category>
      <category>threat intelligence</category>
    </item>
    <item>
      <title>Fire Ant APT: Evolving from Hypervisors to Trusted Network Infrastructure</title>
      <link>https://threatlandscape.io/blog/fire-ant-apt-evolving-from-hypervisors-to-trusted-network-infrastructure</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/fire-ant-apt-evolving-from-hypervisors-to-trusted-network-infrastructure</guid>
      <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
      <description>Deep dive into Fire Ant&apos;s infrastructure-focused espionage tactics, compromising Cisco IOS XR routers, TACACS servers, and Linux hosts for lateral movement.</description>
      <category>Threat Advisory</category>
      <category>Fire Ant</category>
      <category>UNC3886</category>
      <category>Cisco IOS XR</category>
      <category>TACACS</category>
      <category>Medusa Rootkit</category>
      <category>APT Group</category>
      <category>Lateral Movement</category>
    </item>
    <item>
      <title>Three Perfect-10 ServiceNow Flaws: Unauthenticated Code Execution, SQL Injection, and Privilege Escalation</title>
      <link>https://threatlandscape.io/blog/servicenow-cvss-10-unauth-rce-sqli-privilege-escalation</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/servicenow-cvss-10-unauth-rce-sqli-privilege-escalation</guid>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <description>ServiceNow patches four CVEs including three CVSS 4.0 10.0 flaws, allowing unauthenticated RCE, SQL injection, and privilege escalation. Full TTP and patching guidance inside.</description>
      <category>Threat Advisory</category>
      <category>ServiceNow</category>
      <category>CVE-2026-18885</category>
      <category>CVE-2026-18886</category>
      <category>CVE-2026-74820</category>
      <category>CVE-2026-6876</category>
      <category>RCE</category>
      <category>SQL injection</category>
      <category>privilege-escalation</category>
      <category>sandbox-escape</category>
      <category>CVSS-10.0</category>
    </item>
    <item>
      <title>Supply Chain Surveillance: Unpacking the DARKLANTERN and SPEAKINGSTONE Backdoors in ZBT Routers</title>
      <link>https://threatlandscape.io/blog/supply-chain-surveillance-darklantern-speakingstone-backdoors-zbt-routers</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/supply-chain-surveillance-darklantern-speakingstone-backdoors-zbt-routers</guid>
      <pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate>
      <description>VulnCheck uncovers DARKLANTERN and SPEAKINGSTONE, unauthenticated Nim backdoors pre-installed in ZBT (Zbtlink) OEM router firmware. TTPs and IoCs inside.</description>
      <category>Threat Advisory</category>
      <category>ZBT</category>
      <category>Zbtlink</category>
      <category>backdoor</category>
      <category>supply-chain</category>
      <category>router</category>
      <category>DARKLANTERN</category>
      <category>SPEAKINGSTONE</category>
      <category>hardware</category>
      <category>ICS</category>
      <category>IoT</category>
      <category>Nim</category>
    </item>
    <item>
      <title>Threat Landscape OpenCTI Connector Is Now Officially Part of OpenCTI</title>
      <link>https://threatlandscape.io/blog/threat-landscape-opencti-connector-merged</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/threat-landscape-opencti-connector-merged</guid>
      <pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate>
      <description>Our official OpenCTI connector has been merged into the OpenCTI Platform. Streamline automated ingestion of high-fidelity Threat Landscape intelligence directly into your OpenCTI instance — no custom code required.</description>
      <category>Product News</category>
      <category>OpenCTI</category>
      <category>Integrations</category>
      <category>Connector</category>
      <category>STIX</category>
      <category>CTI</category>
      <category>Product News</category>
    </item>
    <item>
      <title>Threat Landscape Is Now Free to Explore</title>
      <link>https://threatlandscape.io/blog/threat-landscape-is-now-free-to-explore</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/threat-landscape-is-now-free-to-explore</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
      <description>Threat Landscape now offers a Free Tier — $0, no credit card required. Start exploring global OSINT and darknet-derived threat intelligence today.</description>
      <category>Threat Intelligence</category>
      <category>Threat Intelligence</category>
      <category>Free Tier</category>
      <category>OSINT</category>
      <category>Darknet Monitoring</category>
      <category>CTI</category>
    </item>
    <item>
      <title>Unpacking GigaWiper: The &apos;Frankenstein&apos; Backdoor Assembled from Multiple Malware Families</title>
      <link>https://threatlandscape.io/blog/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware</guid>
      <pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
      <description>Microsoft dissects GigaWiper, a Golang backdoor fusing Crucio ransomware, FlockWiper, and a raw-disk wiper into one implant with RabbitMQ/Redis C2.</description>
      <category>Threat Intelligence</category>
      <category>GigaWiper</category>
      <category>wiper</category>
      <category>Golang</category>
      <category>Crucio</category>
      <category>FlockWiper</category>
      <category>backdoor</category>
      <category>Microsoft Threat Intelligence</category>
      <category>malware</category>
      <category>disk wipe</category>
    </item>
    <item>
      <title>GitLost: Tricking GitHub&apos;s AI Agent into Leaking Private Repositories</title>
      <link>https://threatlandscape.io/blog/gitlost-tricking-github-ai-agent-leaking-private-repositories</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/gitlost-tricking-github-ai-agent-leaking-private-repositories</guid>
      <pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
      <description>Noma Security discloses GitLost, a prompt injection vulnerability that tricks GitHub&apos;s Agentic Workflows into leaking private repository data. Analysis and mitigation guidance.</description>
      <category>Threat Advisory</category>
      <category>AI</category>
      <category>Prompt Injection</category>
      <category>GitHub</category>
      <category>Agentic Workflows</category>
      <category>LLM Security</category>
      <category>Supply Chain</category>
    </item>
    <item>
      <title>Understanding CVE-2026-46331: Deep Dive into the Linux &apos;pedit COW&apos; Local Privilege Escalation Flaw</title>
      <link>https://threatlandscape.io/blog/cve-2026-46331-pedit-cow-linux-privilege-escalation</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/cve-2026-46331-pedit-cow-linux-privilege-escalation</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-46331 &apos;pedit COW&apos; grants root via the kernel&apos;s traffic control subsystem. An out-of-bounds write corrupts the shared page cache—no files touched on disk.</description>
      <category>Threat Advisory</category>
      <category>CVE-2026-46331</category>
      <category>Linux</category>
      <category>privilege-escalation</category>
      <category>kernel-security</category>
      <category>pedit-COW</category>
      <category>page-cache</category>
    </item>
    <item>
      <title>DORA Compliance for Financial Entities: Operational Resilience Through Threat Intelligence</title>
      <link>https://threatlandscape.io/blog/dora-compliance-for-financial-entities-operational-resilience-through-threat-intelligence</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/dora-compliance-for-financial-entities-operational-resilience-through-threat-intelligence</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <description>DORA requires financial entities to adopt threat-led ICT risk management. Learn how Threat Landscape enables TLPT, TIBER-EU, and third-party vendor monitoring.</description>
      <category>Industry Analysis</category>
      <category>DORA EU 2022/2554</category>
      <category>Digital Operational Resilience Act</category>
      <category>TLPT</category>
      <category>TIBER-EU</category>
      <category>ICT Risk Management</category>
      <category>Threat Intelligence</category>
      <category>financial cybersecurity</category>
    </item>
    <item>
      <title>NIS2 is Here: Securing Your Supply Chain and Incident Handling with Threat Intelligence</title>
      <link>https://threatlandscape.io/blog/nis2-is-here-securing-your-supply-chain-and-incident-handling-with-threat-intelligence</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/nis2-is-here-securing-your-supply-chain-and-incident-handling-with-threat-intelligence</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
      <description>The EU&apos;s NIS2 Directive demands proactive risk analysis and supply chain security. Discover how Threat Landscape&apos;s darknet monitoring ensures NIS2 compliance.</description>
      <category>Industry Analysis</category>
      <category>NIS2 Directive compliance</category>
      <category>EU 2022/2555</category>
      <category>Supply chain security</category>
      <category>Article 21</category>
      <category>Darknet monitoring</category>
      <category>Threat Landscape</category>
      <category>Incident Handling</category>
    </item>
    <item>
      <title>Navigating ISO/IEC 27001:2022: How to Master Annex A 5.7 (Threat Intelligence)</title>
      <link>https://threatlandscape.io/blog/navigating-iso-iec-27001-2022-master-annex-a-5-7-threat-intelligence</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/navigating-iso-iec-27001-2022-master-annex-a-5-7-threat-intelligence</guid>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <description>ISO 27001:2022 introduced Annex A 5.7, making Threat Intelligence a mandatory control. Learn how Threat Landscape helps you easily achieve and prove compliance.</description>
      <category>Industry Analysis</category>
      <category>ISO 27001:2022</category>
      <category>Annex A 5.7</category>
      <category>Threat Intelligence control</category>
      <category>Information Security Risk Assessment</category>
      <category>Threat Landscape</category>
      <category>CVSS enrichment</category>
    </item>
    <item>
      <title>Beyond the Checkbox: How Continuous Threat Intelligence Drives NIS2, DORA, and ISO 27001 Compliance</title>
      <link>https://threatlandscape.io/blog/beyond-the-checkbox-continuous-threat-intelligence-nis2-dora-iso-27001-compliance</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/beyond-the-checkbox-continuous-threat-intelligence-nis2-dora-iso-27001-compliance</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate>
      <description>Static compliance is dead. Learn how integrating continuous threat intelligence helps your organization meet ISO 27001:2022, NIS2, and DORA requirements.</description>
      <category>Industry Analysis</category>
      <category>Cybersecurity compliance</category>
      <category>NIS2</category>
      <category>DORA</category>
      <category>ISO 27001:2022</category>
      <category>Threat Intelligence</category>
      <category>SOC teams</category>
      <category>regulatory requirements</category>
    </item>
    <item>
      <title>NGINX Rift: Dissecting an 18-Year-Old Critical RCE Vulnerability (CVE-2026-42945)</title>
      <link>https://threatlandscape.io/blog/nginx-rift-cve-2026-42945-critical-rce-vulnerability</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/nginx-rift-cve-2026-42945-critical-rce-vulnerability</guid>
      <pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate>
      <description>Critical NGINX heap buffer overflow (CVE-2026-42945, CVSS 9.2) enables unauthenticated RCE. Technical breakdown, exploit chain analysis, and mitigation steps.</description>
      <category>Threat Advisory</category>
      <category>CVE-2026-42945</category>
      <category>NGINX</category>
      <category>RCE</category>
      <category>heap-buffer-overflow</category>
      <category>vulnerability</category>
      <category>exploit</category>
      <category>patch-now</category>
    </item>
    <item>
      <title>The Threat Intel Dilemma: Bridging the Gap Between Context and Action With Our New API</title>
      <link>https://threatlandscape.io/blog/threat-intel-dilemma-bridging-context-and-action-with-our-new-api</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/threat-intel-dilemma-bridging-context-and-action-with-our-new-api</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description>Announcing our new dual-stream API: a Context API for rich STIX 2.1 intel and a Detection API for curated, auto-expiring IOCs—delivered via REST and TAXII 2.1.</description>
      <category>Threat Intelligence</category>
      <category>Threat Intelligence</category>
      <category>CTI</category>
      <category>API</category>
      <category>TAXII</category>
      <category>STIX</category>
      <category>IOC</category>
      <category>Detection Engineering</category>
      <category>SIEM</category>
    </item>
    <item>
      <title>Zero-Day Alert: Unauthenticated RCE in Palo Alto PAN-OS Under Active Exploitation (CVE-2026-0300)</title>
      <link>https://threatlandscape.io/blog/zero-day-cve-2026-0300-palo-alto-panos-rce-active-exploitation</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/zero-day-cve-2026-0300-palo-alto-panos-rce-active-exploitation</guid>
      <pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate>
      <description>Critical PAN-OS zero-day CVE-2026-0300 enables unauthenticated RCE with root privileges. No patch yet—apply workarounds immediately.</description>
      <category>Threat Advisory</category>
      <category>CVE-2026-0300</category>
      <category>Palo Alto</category>
      <category>PAN-OS</category>
      <category>zero-day</category>
      <category>RCE</category>
      <category>firewall</category>
      <category>vulnerability</category>
      <category>active exploitation</category>
    </item>
    <item>
      <title>Bypassing Mobile Security: How CloudZ RAT &amp; Pheno Plugin Hijack Microsoft Phone Link to Steal OTPs</title>
      <link>https://threatlandscape.io/blog/cloudz-rat-pheno-plugin-microsoft-phone-link-otp-theft</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/cloudz-rat-pheno-plugin-microsoft-phone-link-otp-theft</guid>
      <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
      <description>CloudZ RAT deploys Pheno plugin to intercept OTPs by hijacking Microsoft Phone Link SQLite databases—no mobile malware required.</description>
      <category>Threat Intelligence</category>
      <category>RAT</category>
      <category>CloudZ</category>
      <category>MFA bypass</category>
      <category>OTP theft</category>
      <category>Phone Link</category>
      <category>Cisco Talos</category>
      <category>malware</category>
      <category>Windows</category>
    </item>
    <item>
      <title>Threat Landscape Alert: &quot;Copy Fail&quot; (CVE-2026-31431) Gives Root on Linux Systems With Just 732 Bytes</title>
      <link>https://threatlandscape.io/blog/copy-fail-cve-2026-31431-linux-privilege-escalation</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/copy-fail-cve-2026-31431-linux-privilege-escalation</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-31431 &apos;Copy Fail&apos; lets unprivileged users gain root on nearly every Linux distro since 2017 via a 732-byte Python script. Patch and mitigate now.</description>
      <category>Threat Advisory</category>
      <category>CVE-2026-31431</category>
      <category>Linux</category>
      <category>privilege-escalation</category>
      <category>container-escape</category>
      <category>kernel-security</category>
      <category>vulnerability</category>
    </item>
    <item>
      <title>Incident Report: The Lovable.dev Data Breach Exposes the Dark Side of Vibe Coding</title>
      <link>https://threatlandscape.io/blog/lovable-dev-data-breach-bola-vulnerability-vibe-coding</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/lovable-dev-data-breach-bola-vulnerability-vibe-coding</guid>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
      <description>A textbook BOLA flaw in Lovable.dev exposed source code, hardcoded API keys, and AI chat histories for projects created before Nov 2025. Full incident breakdown.</description>
      <category>Threat Advisory</category>
      <category>BOLA</category>
      <category>API security</category>
      <category>data breach</category>
      <category>vibe coding</category>
      <category>AI tools</category>
      <category>supply chain</category>
      <category>credentials</category>
    </item>
    <item>
      <title>Vercel Breach April 2026: What We Know So Far (Rotate Credentials Now)</title>
      <link>https://threatlandscape.io/blog/vercel-breach-april-2026-rotate-credentials</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/vercel-breach-april-2026-rotate-credentials</guid>
      <pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate>
      <description>Vercel confirmed a security incident on April 19, 2026. The attack originated from a compromised Google Workspace OAuth app. Rotate non-sensitive environment variables now and check for the published IOC.</description>
      <category>Threat Advisory</category>
      <category>vercel</category>
      <category>breach</category>
      <category>credentials</category>
      <category>supply chain</category>
      <category>security incident</category>
      <category>ShinyHunters</category>
      <category>OAuth</category>
      <category>Google Workspace</category>
      <category>IOC</category>
    </item>
    <item>
      <title>From Consumption to Interrogation: Rethinking How We Use Threat Intelligence</title>
      <link>https://threatlandscape.io/blog/from-consumption-to-interrogation-rethinking-threat-intelligence</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/from-consumption-to-interrogation-rethinking-threat-intelligence</guid>
      <pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate>
      <description>Discover how the Threat Landscape AI Assistant, built into the Threat Landscape Platform, transforms threat data into actionable insights through conversational AI and role-specific analysis.</description>
      <category>Industry Analysis</category>
      <category>Threat Intelligence</category>
      <category>AI</category>
      <category>SecOps</category>
      <category>Tech Launch</category>
    </item>
    <item>
      <title>The 2026 Healthcare Threat Landscape: Critical Disruptions, State-Backed RaaS, and AI Poisoning</title>
      <link>https://threatlandscape.io/blog/healthcare-threat-landscape-2026-ai-poisoning-state-backed-raas</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/healthcare-threat-landscape-2026-ai-poisoning-state-backed-raas</guid>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <description>Analysis of the 2026 healthcare threat landscape, featuring the disruptive cyberattack on Signature Healthcare, state-backed ransomware trends, and memory poisoning in clinical AI.</description>
      <category>Threat Intelligence</category>
      <category>healthcare</category>
      <category>ransomware</category>
      <category>incident-response</category>
      <category>ai-security</category>
      <category>lazarus</category>
      <category>threat-intelligence</category>
    </item>
    <item>
      <title>Dissecting the Axios NPM Supply Chain Attack: A Watershed Moment in Open Source Security</title>
      <link>https://threatlandscape.io/blog/axios-npm-supply-chain-attack-open-source-security</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/axios-npm-supply-chain-attack-open-source-security</guid>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <description>Threat actors compromised the Axios npm package (40M+ weekly downloads), injecting a multi-platform RAT via stolen maintainer credentials. Full TTP breakdown inside.</description>
      <category>Threat Intelligence</category>
      <category>supply chain</category>
      <category>npm</category>
      <category>axios</category>
      <category>RAT</category>
      <category>open source security</category>
      <category>malware</category>
    </item>
    <item>
      <title>Critical Credential Stealer Discovered in LiteLLM PyPI Package</title>
      <link>https://threatlandscape.io/blog/supply-chain-attack-litellm-pypi-credential-stealer</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/supply-chain-attack-litellm-pypi-credential-stealer</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <description>Versions 1.82.7 and 1.82.8 of the litellm PyPI package contain a double base64-encoded credential stealer. Rotate all secrets immediately if affected.</description>
      <category>Threat Intelligence</category>
      <category>supply chain</category>
      <category>PyPI</category>
      <category>malware</category>
      <category>python</category>
      <category>credential theft</category>
      <category>AI security</category>
    </item>
    <item>
      <title>Telnet&apos;s Undead Threat: CVE-2026-32746 — A Critical Pre-Auth Buffer Overflow in GNU Inetutils</title>
      <link>https://threatlandscape.io/blog/telnet-cve-2026-32746-gnu-inetutils-preauth-buffer-overflow</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/telnet-cve-2026-32746-gnu-inetutils-preauth-buffer-overflow</guid>
      <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
      <description>CVE-2026-32746: A critical pre-authentication buffer overflow in GNU Inetutils telnetd enables unauthenticated RCE on OT, ICS, and legacy devices. Patch and mitigate now.</description>
      <category>Threat Advisory</category>
      <category>CVE-2026-32746</category>
      <category>GNU Inetutils</category>
      <category>telnet</category>
      <category>buffer-overflow</category>
      <category>RCE</category>
      <category>OT</category>
      <category>ICS</category>
      <category>pre-auth</category>
    </item>
    <item>
      <title>ClickFix Evolves Again: Three Fresh Campaigns Deliver MacSync macOS Infostealer via Fake AI Tools &amp; Malvertising</title>
      <link>https://threatlandscape.io/blog/clickfix-evolves-macsync-macos-infostealer-fake-ai-tools-malvertising</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/clickfix-evolves-macsync-macos-infostealer-fake-ai-tools-malvertising</guid>
      <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
      <description>Three ClickFix campaigns push MacSync infostealer to macOS users via Google ads, fake AI tools, and ChatGPT lures. No exploits, pure social engineering.</description>
      <category>Threat Intelligence</category>
      <category>macOS</category>
      <category>infostealer</category>
      <category>ClickFix</category>
      <category>MacSync</category>
      <category>malvertising</category>
      <category>social-engineering</category>
    </item>
    <item>
      <title>Critical: Sweden&apos;s E-Government Source Code Leaked — CGI Sverige AB Infrastructure Compromised</title>
      <link>https://threatlandscape.io/blog/sweden-egovernment-source-code-leak-cgi-sverige-bytetobreach</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/sweden-egovernment-source-code-leak-cgi-sverige-bytetobreach</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
      <description>ByteToBreach leaks Sweden&apos;s E-Gov source code after compromising CGI Sverige AB via Jenkins misconfiguration and Docker escape. Citizen PII for sale.</description>
      <category>Threat Advisory</category>
      <category>data breach</category>
      <category>e-government</category>
      <category>supply chain</category>
      <category>Sweden</category>
      <category>CGI</category>
      <category>Jenkins</category>
      <category>insider threat</category>
      <category>threat intelligence</category>
    </item>
    <item>
      <title>Your SOC Has a Threat Intelligence Problem. It&apos;s Not a Lack of Data.</title>
      <link>https://threatlandscape.io/blog/your-soc-has-a-threat-intelligence-problem-its-not-a-lack-of-data</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/your-soc-has-a-threat-intelligence-problem-its-not-a-lack-of-data</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
      <description>Discover how the purpose-built Threat Landscape AI Assistant — part of the Threat Landscape Platform — queries live STIX 2.1 data to give SOC analysts fast, accurate, role-aware answers — not AI guesswork.</description>
      <category>Threat Intelligence</category>
      <category>AI</category>
      <category>Threat Intelligence</category>
      <category>SOC</category>
      <category>STIX 2.1</category>
      <category>MITRE ATT&amp;CK</category>
      <category>AI Assistant</category>
      <category>CTI</category>
    </item>
    <item>
      <title>Darknet Monitoring for Modern Threat Intelligence Programs</title>
      <link>https://threatlandscape.io/blog/darknet-monitoring-for-modern-threat-intelligence-programs</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/darknet-monitoring-for-modern-threat-intelligence-programs</guid>
      <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
      <description>Why darknet monitoring belongs in modern CTI workflows, what teams should watch first, and how structured analysis turns underground signals into action.</description>
      <category>Product &amp; Strategy</category>
      <category>darknet monitoring</category>
      <category>threat intelligence</category>
      <category>ransomware</category>
      <category>exposure monitoring</category>
      <category>cti</category>
    </item>
    <item>
      <title>Why Your Threat Intelligence Platform Is Giving You Data — Not Intelligence</title>
      <link>https://threatlandscape.io/blog/why-your-threat-intelligence-platform-is-giving-you-data-not-intelligence</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/why-your-threat-intelligence-platform-is-giving-you-data-not-intelligence</guid>
      <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
      <description>Discover how automated threat intelligence platforms convert OSINT into structured STIX 2.1 intelligence, cutting analyst research time by 50–70%.</description>
      <category>Industry Analysis</category>
      <category>Threat Intelligence</category>
      <category>STIX 2.1</category>
      <category>MITRE ATT&amp;CK</category>
      <category>SOC</category>
      <category>Automation</category>
      <category>CTI</category>
    </item>
    <item>
      <title>An AI Bot Just Hijacked GitHub Repos with a Simple Pull Request</title>
      <link>https://threatlandscape.io/blog/hackerbot-claw-ai-bot-github-actions-supply-chain-attack</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/hackerbot-claw-ai-bot-github-actions-supply-chain-attack</guid>
      <pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate>
      <description>An AI-powered bot exploited GitHub Actions misconfigurations to compromise Microsoft, DataDog, Trivy and others. No zero-day needed—just a pull request.</description>
      <category>Threat Intelligence</category>
      <category>supply chain</category>
      <category>github actions</category>
      <category>ci/cd</category>
      <category>AI threats</category>
      <category>open source security</category>
    </item>
    <item>
      <title>Critical Advisory: Active Exploitation of CVE-2026-20127 in Cisco Catalyst SD-WAN</title>
      <link>https://threatlandscape.io/blog/critical-cve-2026-20127-cisco-sd-wan-active-exploitation</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/critical-cve-2026-20127-cisco-sd-wan-active-exploitation</guid>
      <pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate>
      <description>Critical alert: UAT-8616 actively exploiting CVE-2026-20127 in Cisco Catalyst SD-WAN for authentication bypass and root escalation. Mitigation steps inside.</description>
      <category>Threat Advisory</category>
      <category>CVE-2026-20127</category>
      <category>Cisco</category>
      <category>SD-WAN</category>
      <category>authentication-bypass</category>
      <category>privilege-escalation</category>
      <category>threat-actor</category>
      <category>FCEB</category>
    </item>
    <item>
      <title>Supply Chain via Agent Configuration: Analyzing CVE-2025-59536 &amp; CVE-2026-21852</title>
      <link>https://threatlandscape.io/blog/analyzing-cve-2025-59536-cve-2026-21852-agent-configuration-risks</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/analyzing-cve-2025-59536-cve-2026-21852-agent-configuration-risks</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
      <description>Deep dive into the recent RCE and credential exfiltration vulnerabilities (CVE-2025-59536 &amp; CVE-2026-21852) affecting Claude Code agentic CLI tools.</description>
      <category>Threat Advisory</category>
      <category>CVE-2025-59536</category>
      <category>CVE-2026-21852</category>
      <category>Claude Code</category>
      <category>Agentic AI</category>
      <category>Supply Chain Security</category>
    </item>
    <item>
      <title>The Barrier Has Fallen: What the Mexican Government Breach Tells Us About Agentic Cyber Threats</title>
      <link>https://threatlandscape.io/blog/the-barrier-has-fallen-what-the-mexican-government-breach-tells-us-about-agentic-cyber-threats</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/the-barrier-has-fallen-what-the-mexican-government-breach-tells-us-about-agentic-cyber-threats</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
      <description>Analysis of the Mexican government data breach and what it reveals about AI-orchestrated cyberattacks, kill-chain compression, and modern defense priorities.</description>
      <category>Threat Intelligence</category>
      <category>threat-intelligence</category>
      <category>ai-security</category>
      <category>government-breach</category>
      <category>agentic-ai</category>
    </item>
    <item>
      <title>Supply Chain Fragility: Lessons from the Conduent/SafePay Ransomware Crisis</title>
      <link>https://threatlandscape.io/blog/supply-chain-fragility-conduent-safepay-ransomware-crisis</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/supply-chain-fragility-conduent-safepay-ransomware-crisis</guid>
      <pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate>
      <description>8.5 TB exfiltrated, 26M+ victims, 90-day dwell time. A deep-dive into the Conduent/SafePay breach and strategic takeaways for security executives.</description>
      <category>Threat Advisory</category>
      <category>ransomware</category>
      <category>supply chain</category>
      <category>third-party risk</category>
      <category>SafePay</category>
      <category>Conduent</category>
      <category>data breach</category>
      <category>PHI</category>
    </item>
    <item>
      <title>Analyst Advisory: Critical Zero-Day CVE-2026-22769 Exploited in Dell RecoverPoint for VMs</title>
      <link>https://threatlandscape.io/blog/analyst-advisory-critical-zero-day-cve-2026-22769-dell-recoverpoint</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/analyst-advisory-critical-zero-day-cve-2026-22769-dell-recoverpoint</guid>
      <pubDate>Wed, 18 Feb 2026 00:00:00 GMT</pubDate>
      <description>Critical unauthenticated hardcoded-credential vulnerability in Dell RecoverPoint is under active exploitation. CVE-2026-22769 Immediate patching and network isolation recommended.</description>
      <category>Threat Advisory</category>
      <category>cve-2026-22769</category>
      <category>dell</category>
      <category>recoverpoint</category>
      <category>zero-day</category>
      <category>intrusion</category>
      <category>unc6201</category>
    </item>
    <item>
      <title>Vulnerability Spotlight: CVE-2026-20841 – Remote Code Execution via Notepad Markdown Handling</title>
      <link>https://threatlandscape.io/blog/vulnerability-spotlight-cve-2026-20841</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/vulnerability-spotlight-cve-2026-20841</guid>
      <pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate>
      <description>Discover the details of CVE-2026-20841, a remote code execution flaw in Notepad&apos;s Markdown handling, and learn how to protect your systems.</description>
      <category>Threat Advisory</category>
      <category>CVE-2026-20841</category>
      <category>Windows Notepad</category>
      <category>Remote Code Execution</category>
      <category>Markdown</category>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Abuse of CVE-2025-8088 Enables Stealthy Loader Deployment in Targeted Intrusions</title>
      <link>https://threatlandscape.io/blog/abuse-of-cve-2025-8088-enables-stealthy-loader-deployment-in-targeted-intrusions</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/abuse-of-cve-2025-8088-enables-stealthy-loader-deployment-in-targeted-intrusions</guid>
      <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
      <description>Analysis of active CVE-2025-8088 exploitation campaigns leveraging malicious RAR archives, custom loaders, and evasive C2 infrastructure.</description>
      <category>Threat Intelligence</category>
      <category>CVE-2025-8088</category>
      <category>Amaranth Dragon</category>
      <category>Loader Malware</category>
      <category>WinRAR</category>
    </item>
    <item>
      <title>Critical n8n Vulnerabilities: CVE-2025-68613 and CVE-2026-25049 Analysis</title>
      <link>https://threatlandscape.io/blog/critical-n8n-vulnerabilities-cve-2025-68613-and-cve-2026-25049-analysis</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/critical-n8n-vulnerabilities-cve-2025-68613-and-cve-2026-25049-analysis</guid>
      <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
      <description>Detailed analysis of n8n workflow automation platform vulnerabilities allowing remote code execution and credential theft.</description>
      <category>Threat Intelligence</category>
      <category>n8n</category>
      <category>CVE-2025-68613</category>
      <category>CVE-2026-25049</category>
      <category>RCE</category>
      <category>workflow automation</category>
    </item>
    <item>
      <title>Manufacturing Sector Threat Landscape: Ransomware and Supply Chain Risks in 2026</title>
      <link>https://threatlandscape.io/blog/manufacturing-sector-threat-landscape-ransomware-and-supply-chain-risks-in-2026</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/manufacturing-sector-threat-landscape-ransomware-and-supply-chain-risks-in-2026</guid>
      <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
      <description>Latest threat intelligence on manufacturing sector risks, including RaaS, supply chain pre-positioning, and critical CVEs.</description>
      <category>Threat Intelligence</category>
      <category>ransomware</category>
      <category>manufacturing</category>
      <category>supply chain</category>
      <category>CVE</category>
      <category>threat intelligence</category>
    </item>
    <item>
      <title>Beyond the Feed: Why Analysts Are Seeking a Feedly Threat Intelligence Alternative</title>
      <link>https://threatlandscape.io/blog/beyond-the-feed-feedly-threat-intelligence-alternative</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/beyond-the-feed-feedly-threat-intelligence-alternative</guid>
      <pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate>
      <description>Looking for a Feedly threat intelligence alternative? Discover how switching from RSS aggregation to structured threat monitoring saves analysts hours per week.</description>
      <category>Industry Analysis</category>
      <category>Threat Intelligence</category>
      <category>CTI</category>
      <category>Feedly Alternative</category>
      <category>Security Operations</category>
      <category>Workflow</category>
    </item>
    <item>
      <title>What active or emerging threats are targeting European banking in January 2026</title>
      <link>https://threatlandscape.io/blog/active-emerging-threats-targeting-european-banking-january-2026</link>
      <guid isPermaLink="true">https://threatlandscape.io/blog/active-emerging-threats-targeting-european-banking-january-2026</guid>
      <pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate>
      <description>Discover the latest active and emerging threats targeting European banking institutions in January 2026.</description>
      <category>Threat Intelligence</category>
      <category>threat intelligence</category>
      <category>banking</category>
      <category>malware</category>
      <category>Europe</category>
      <category>Klopatra</category>
    </item>
  </channel>
</rss>
