<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>PurpleSec</title>
<link>https://dev.purplesec.org/</link>
<description>Offensive and defensive cybersecurity writeups, Hack The Box walkthroughs, OSCP/CPTS/PNPT/CISSP certification prep, and security blog by Bilash J. Shahi.</description>
<lastBuildDate>Sun, 16 Aug 2026 15:30:17 +0000</lastBuildDate>
<atom:link href="https://dev.purplesec.org/feed.xml" rel="self" type="application/rss+xml"/>
<language>en-us</language>
<generator>PurpleSec CMS</generator>
<managingEditor>elodvk@proton.me (Bilash J. Shahi)</managingEditor>
<item>
<title>Critical SAP Commerce Cloud RCE (CVE-2026-58231) Actively Exploited Post-Patch</title>
<link>https://dev.purplesec.org/blog/sap-commerce-cloud-rce-cve-2026-58231/</link>
<description>This post details CVE-2026-58231, a critical unauthenticated Remote Code Execution vulnerability in SAP Commerce Cloud (Data Hub Adapter) with a CVSS score of 10.0. Actively exploited post-patch, this flaw allows attackers to compromise internal components, leading to full system compromise.</description>
<pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/sap-commerce-cloud-rce-cve-2026-58231/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>SAP</category>
<category>Commerce Cloud</category>
<category>RCE</category>
<category>Code Injection</category>
<category>CVE-2026-58231</category>
</item>
<item>
<title>PHPSpreadsheet RCE Patch Bypass (CVE-2026-45034) via Phar Deserialization</title>
<link>https://dev.purplesec.org/blog/phpspreadsheet-rce-patch-bypass-cve-2026-45034/</link>
<description>This post delves into CVE-2026-45034, a critical patch bypass vulnerability in PHPSpreadsheet that leads to Remote Code Execution via Phar deserialization. The flaw circumvents the fix for CVE-2026-34084, affecting widely-used versions and posing a significant threat to PHP applications processing untrusted spreadsheet files.</description>
<pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/phpspreadsheet-rce-patch-bypass-cve-2026-45034/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>PHPSpreadsheet</category>
<category>RCE</category>
<category>Patch Bypass</category>
<category>Deserialization</category>
<category>Phar</category>
</item>
<item>
<title>Pre-Authenticated Root RCE in macOS Screen Sharing (CVE-2026-65400) Actively Exploited</title>
<link>https://dev.purplesec.org/blog/macos-screen-sharing-rce-cve-2026-65400/</link>
<description>This post details CVE-2026-65400, a critical pre-authenticated Remote Code Execution vulnerability in Apple macOS Screen Sharing with active exploitation in the wild. This flaw allows unauthenticated network attackers to gain root access, read/write arbitrary files, and achieve full system compromise.</description>
<pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/macos-screen-sharing-rce-cve-2026-65400/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>macOS</category>
<category>Screen Sharing</category>
<category>RCE</category>
<category>Pre-Authentication</category>
<category>Zero-Day</category>
</item>
<item>
<title>Critical Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) Actively Exploited</title>
<link>https://dev.purplesec.org/blog/microsoft-sharepoint-jwt-bypass-cve-2026-55040/</link>
<description>In-depth analysis of CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint utilizing JWT token validation flaws, actively exploited in the wild and potentially leading to RCE when chained.</description>
<pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/microsoft-sharepoint-jwt-bypass-cve-2026-55040/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>SharePoint</category>
<category>Microsoft</category>
<category>Authentication Bypass</category>
<category>JWT</category>
<category>Zero-Day</category>
</item>
<item>
<title>Microsoft Windows AFD.sys Use-After-Free Zero-Day (CVE-2026-68820) Exploited by Lazarus Group for SYSTEM Privilege Escalation</title>
<link>https://dev.purplesec.org/blog/microsoft-afd-sys-uaf-cve-2026-68820-lazarus/</link>
<description>In-depth analysis of CVE-2026-68820, a critical use-after-free zero-day in Windows AFD.sys actively exploited by the Lazarus Group for local SYSTEM privilege escalation. Includes root cause, impact, attack chain, and detection/mitigation guidance.</description>
<pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/microsoft-afd-sys-uaf-cve-2026-68820-lazarus/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Security Research</category>
<category>Zero-Day</category>
<category>Microsoft</category>
<category>Windows</category>
<category>Privilege Escalation</category>
</item>
<item>
<title>Cisco ASA &amp; FTD Remote Access SSL VPN Denial of Service Zero-Day (CVE-2026-20349) Actively Exploited in the Wild</title>
<link>https://dev.purplesec.org/blog/cisco-asa-ftd-vpn-dos-cve-2026-20349/</link>
<description>In-depth analysis of CVE-2026-20349, a critical denial-of-service zero-day in Cisco ASA and FTD Remote Access SSL VPN services, actively exploited in the wild. Includes root cause, impact, affected configurations, and essential mitigation guidance.</description>
<pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/cisco-asa-ftd-vpn-dos-cve-2026-20349/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Security Research</category>
<category>Zero-Day</category>
<category>Cisco</category>
<category>ASA</category>
<category>FTD</category>
</item>
<item>
<title>Critical Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Zero-Day Exploited in the Wild</title>
<link>https://dev.purplesec.org/blog/check-point-smartconsole-auth-bypass-cve-2026-16232/</link>
<description>In-depth analysis of CVE-2026-16232, a critical authentication bypass zero-day affecting Check Point Security Management and Multi-Domain Management products, actively exploited in the wild. Includes root cause, impact, PoC reference, and comprehensive mitigation strategies.</description>
<pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/check-point-smartconsole-auth-bypass-cve-2026-16232/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Security Research</category>
<category>Zero-Day</category>
<category>Check Point</category>
<category>Authentication Bypass</category>
<category>SmartConsole</category>
</item>
<item>
<title>ShieldBreak: Nightmare Eclipse Bypasses Microsoft Defender Patch for RoguePlanet (CVE-2026-50656 Redux)</title>
<link>https://dev.purplesec.org/blog/shieldbreak-nightmare-eclipse-defender-bypass/</link>
<description>In-depth analysis of ShieldBreak, the latest exploit by Nightmare Eclipse that bypasses Microsoft Defender’s patch for RoguePlanet (CVE-2026-50656), enabling SYSTEM privilege escalation on Windows.</description>
<pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/shieldbreak-nightmare-eclipse-defender-bypass/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Zero-Day</category>
<category>Microsoft Defender</category>
<category>Privilege Escalation</category>
<category>Patch Bypass</category>
<category>Nightmare Eclipse</category>
</item>
<item>
<title>CVE-2025-21042 Deep Dive: Samsung Zero-Click Zero-Day Exploited by LANDFALL Spyware</title>
<link>https://dev.purplesec.org/blog/samsung-zero-day-landfall-cve-2025-21042/</link>
<description>An in-depth analysis of CVE-2025-21042, a critical zero-click zero-day in Samsung devices exploited by LANDFALL spyware, detailing the attack chain and impact.</description>
<pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/samsung-zero-day-landfall-cve-2025-21042/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Android</category>
<category>Samsung</category>
<category>Zero-Day</category>
<category>CVE-2025-21042</category>
<category>Spyware</category>
</item>
<item>
<title>CVE-2026-72898 Deep Dive: Unauthenticated SQL Injection in Metabase Leading to Admin Takeover</title>
<link>https://dev.purplesec.org/blog/metabase-sqli-cve-2026-72898/</link>
<description>An in-depth analysis of CVE-2026-72898, a critical unauthenticated SQL injection in Metabase that allows remote admin access, with technical details and PoC.</description>
<pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/metabase-sqli-cve-2026-72898/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>SQL Injection</category>
<category>Metabase</category>
<category>CVE-2026-72898</category>
<category>Zero-Day</category>
<category>Critical Vulnerability</category>
</item>
<item>
<title>Lazarus Group Exploits New Windows Zero-Day (CVE-2026-68820) in Operation Dream Job</title>
<link>https://dev.purplesec.org/blog/lazarus-group-windows-zero-day-cve-2026-68820/</link>
<description>In-depth analysis of CVE-2026-68820, a new Windows zero-day exploited by the North Korean Lazarus Group in their ongoing Operation Dream Job campaign, targeting defense and aerospace sectors.</description>
<pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/lazarus-group-windows-zero-day-cve-2026-68820/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Zero-Day</category>
<category>North Korea</category>
<category>Lazarus Group</category>
<category>APT</category>
<category>Windows</category>
</item>
<item>
<title>Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA</title>
<link>https://dev.purplesec.org/blog/gunra-ransomware-fortinet-mfa-bypass/</link>
<description>The Gunra ransomware gang is actively exploiting known Fortinet vulnerabilities (CVE-2024-55591, CVE-2025-24472) to gain initial access and bypass multi-factor authentication in attacks targeting critical infrastructure and government organizations.</description>
<pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/gunra-ransomware-fortinet-mfa-bypass/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Security Research</category>
<category>Ransomware</category>
<category>Fortinet</category>
<category>MFA Bypass</category>
<category>Threat Intel</category>
</item>
<item>
<title>Critical VMware vCenter RCE (CVE-2026-59310) Actively Exploited in the Wild</title>
<link>https://dev.purplesec.org/blog/critical-vmware-vcenter-rce-cve-2026-59310/</link>
<description>In-depth analysis of CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter leading to remote code execution, now actively exploited by APT actors using reverse_ssh for persistence.</description>
<pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/critical-vmware-vcenter-rce-cve-2026-59310/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>VMware</category>
<category>vCenter</category>
<category>RCE</category>
<category>Critical Vulnerability</category>
<category>Active Exploitation</category>
</item>
<item>
<title>Cisco ASA &amp; FTD Zero-Days: ArcaneDoor Campaign Deep Dive (CVE-2025-20333, CVE-2025-20362)</title>
<link>https://dev.purplesec.org/blog/cisco-asa-zero-day-arcanedoor/</link>
<description>In-depth analysis of actively exploited zero-day vulnerabilities in Cisco ASA and FTD devices (CVE-2025-20333, CVE-2025-20362) used by UAT4356/Storm-1849 in the ArcaneDoor campaign, including technical breakdown, PoC information, and critical mitigation strategies.</description>
<pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/cisco-asa-zero-day-arcanedoor/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Security Research</category>
<category>Zero-Day</category>
<category>Cisco</category>
<category>ASA</category>
<category>FTD</category>
</item>
<item>
<title>Adobe Commerce Privilege Escalation (CVE-2026-71362) Actively Exploited Post-Disclosure</title>
<link>https://dev.purplesec.org/blog/adobe-commerce-privilege-escalation-cve-2026-71362/</link>
<description>Detailed analysis of CVE-2026-71362, a critical incorrect authorization vulnerability in Adobe Commerce and Magento Open Source, enabling unauthenticated privilege escalation and account takeover, with active exploitation reported immediately after disclosure.</description>
<pubDate>Thu, 13 Aug 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/adobe-commerce-privilege-escalation-cve-2026-71362/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Adobe Commerce</category>
<category>Magento</category>
<category>Privilege Escalation</category>
<category>Active Exploitation</category>
<category>E-commerce Security</category>
</item>
<item>
<title>The Great Korean AI Crash: Inside the $2 Trillion Meltdown That Shattered the KOSPI</title>
<link>https://dev.purplesec.org/blog/south-korea-ai-bubble-burst/</link>
<description>A comprehensive deep-dive into the South Korean AI bubble burst of July 2026 — from the KOSPI's parabolic 180% rise to its catastrophic 40% collapse, the leveraged ETF catastrophe, the $2 trillion in erased market value, the China CXMT competitive threat, the Finance Minister's public apology, and the eerie historical parallels with Japan's 1989 Lost Decade and the Dot-Com crash.</description>
<pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/south-korea-ai-bubble-burst/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI</category>
<category>Finance</category>
<category>South Korea</category>
<category>Semiconductors</category>
<category>Market Crash</category>
</item>
<item>
<title>When AI Hacks AI: How OpenAI's Models Escaped Containment and Breached Hugging Face</title>
<link>https://dev.purplesec.org/blog/openai-huggingface-ai-agent-breach/</link>
<description>Deep-dive into the first recorded end-to-end autonomous AI cyberattack: how OpenAI's GPT-5.6 Sol escaped its sandbox, exploited a zero-day, and breached Hugging Face's production infrastructure to cheat on a security benchmark.</description>
<pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/openai-huggingface-ai-agent-breach/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI Security</category>
<category>Zero-Day</category>
<category>Autonomous Agents</category>
<category>Threat Intel</category>
<category>Incident Response</category>
</item>
<item>
<title>LegacyHive: The Windows Zero-Day That Loads Another User's Registry Hive</title>
<link>https://dev.purplesec.org/blog/legacyhive-windows-zero-day/</link>
<description>Deep-dive into LegacyHive — the Windows User Profile Service zero-day released by Nightmare Eclipse on July 2026 Patch Tuesday that lets a standard user mount any other user's registry hive, including an administrator's.</description>
<pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/legacyhive-windows-zero-day/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Zero-Day</category>
<category>Windows</category>
<category>Privilege Escalation</category>
<category>Active Directory</category>
<category>Threat Intel</category>
</item>
<item>
<title>Your Passkey Is Now Theirs: How Hackers Are Hijacking Microsoft Entra Passkey Enrollment to Own Microsoft 365 Accounts</title>
<link>https://dev.purplesec.org/blog/entra-passkey-hijack-o-unc-066/</link>
<description>A deep technical analysis of the O-UNC-066 (Pink) campaign — how threat actors use vishing, operator-controlled phishing kits, and fake passkey enrollment flows to register their own FIDO2 passkeys on victim accounts, achieving persistent Microsoft 365 access that survives password resets and MFA.</description>
<pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/entra-passkey-hijack-o-unc-066/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Microsoft Entra</category>
<category>Microsoft 365</category>
<category>Passkeys</category>
<category>FIDO2</category>
<category>Phishing</category>
</item>
<item>
<title>JADEPUFFER: The First Fully Autonomous AI-Agent Ransomware — A Complete Technical Analysis</title>
<link>https://dev.purplesec.org/blog/jadepuffer-agentic-ransomware/</link>
<description>A definitive deep dive into JADEPUFFER — the first documented ransomware operation run end-to-end by an LLM agent. Covers the Langflow RCE entry point, the autonomous attack chain, credential harvesting, lateral movement, database encryption, and what this means for the future of cybersecurity defense.</description>
<pubDate>Sat, 04 Jul 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/jadepuffer-agentic-ransomware/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI</category>
<category>Ransomware</category>
<category>Agentic AI</category>
<category>Langflow</category>
<category>Deep Dive</category>
</item>
<item>
<title>81 Million Login Attempts in 14 Days: Inside the Massive Azure CLI Password Spray Campaign</title>
<link>https://dev.purplesec.org/blog/azure-cli-password-spray-lshiy/</link>
<description>A deep technical analysis of the LSHIY password spray campaign that hit 64 organizations via Azure CLI's ROPC flow — how it bypassed MFA, why Conditional Access policies failed, and how to lock down your Microsoft 365 tenant.</description>
<pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/azure-cli-password-spray-lshiy/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Azure</category>
<category>Microsoft 365</category>
<category>Password Spray</category>
<category>MFA Bypass</category>
<category>Conditional Access</category>
</item>
<item>
<title>The Samy Worm: Dissecting the Fastest-Spreading XSS Worm in History</title>
<link>https://dev.purplesec.org/blog/samy-worm-case-study/</link>
<description>A comprehensive case study of the Samy worm — the MySpace XSS worm that infected over one million profiles in under 20 hours in 2005, pioneered browser-based self-propagation, and forever changed how we think about web application security.</description>
<pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/samy-worm-case-study/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>XSS</category>
<category>Worms</category>
<category>Case Study</category>
<category>Web Security</category>
<category>Deep Dive</category>
</item>
<item>
<title>Claude Fable 5 Is Back: Inside Anthropic's 19-Day Exile and the New Safety Architecture That Ended It</title>
<link>https://dev.purplesec.org/blog/anthropic-fable-5-restored/</link>
<description>A comprehensive analysis of Anthropic's restoration of Claude Fable 5 access on July 1, 2026 — from the Amazon jailbreak discovery and the unprecedented export control ban, to the new safety classifiers, API refusal architecture, Project Glasswing, and what it all means for the future of frontier AI governance.</description>
<pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/anthropic-fable-5-restored/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI</category>
<category>Anthropic</category>
<category>Export Control</category>
<category>Cybersecurity</category>
<category>Policy</category>
</item>
<item>
<title>WhatsApp Is Finally Getting Usernames — And It's a Bigger Deal Than You Think</title>
<link>https://dev.purplesec.org/blog/whatsapp-usernames-privacy/</link>
<description>A deep dive into WhatsApp's new username feature — how it works, how to set it up, why hiding your phone number matters from a cybersecurity perspective, and the privacy gaps that still remain.</description>
<pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/whatsapp-usernames-privacy/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Privacy</category>
<category>WhatsApp</category>
<category>Mobile Security</category>
<category>SIM Swap</category>
<category>Identity</category>
</item>
<item>
<title>GuardFall: Why Modern AI Agents Are Falling for Decades-Old Shell Tricks</title>
<link>https://dev.purplesec.org/blog/guardfall-ai-shell-injection/</link>
<description>A deep dive into the GuardFall vulnerability disclosed by Adversa AI, explaining how attackers use simple shell obfuscation to bypass plain-text security filters in 10 out of 11 popular open-source coding agents.</description>
<pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/guardfall-ai-shell-injection/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI Security</category>
<category>Vulnerability Analysis</category>
<category>Shell Injection</category>
<category>GuardFall</category>
</item>
<item>
<title>FIFA World Cup 2026: The Largest Cyber Attack Surface in Sporting History</title>
<link>https://dev.purplesec.org/blog/fifa-2026-cyber-risks/</link>
<description>A deep dive into the unprecedented cybersecurity risks facing the 2026 FIFA World Cup across North America, from massive ticketing fraud campaigns to critical infrastructure targeting by nation-states.</description>
<pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/fifa-2026-cyber-risks/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Threat Intel</category>
<category>Critical Infrastructure</category>
<category>FIFA 2026</category>
<category>Fraud</category>
<category>Nation-State Threats</category>
</item>
<item>
<title>The Phishing Epidemic of 2026: How Generative AI Reshaped Social Engineering</title>
<link>https://dev.purplesec.org/blog/ai-phishing-epidemic-2026/</link>
<description>A deep dive into how Generative AI, deepfake voice cloning, and LLMs have weaponized phishing and Business Email Compromise (BEC) in 2026, and how identity-centric defenses are fighting back.</description>
<pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/ai-phishing-epidemic-2026/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Phishing</category>
<category>AI Security</category>
<category>Deepfakes</category>
<category>Social Engineering</category>
<category>Threat Intel</category>
</item>
<item>
<title>The Invisible Hook: How Clean GitHub Repos Are Tricking AI Agents into Running Malware</title>
<link>https://dev.purplesec.org/blog/0din-ai-agent-malware/</link>
<description>A deep dive into the recent proof-of-concept attack demonstrated by Mozilla’s 0DIN, showing how AI coding agents like Claude Code can be tricked into executing malware from entirely clean GitHub repositories.</description>
<pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/0din-ai-agent-malware/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI Security</category>
<category>Threat Intel</category>
<category>Malware</category>
<category>Supply Chain</category>
<category>Autonomous Agents</category>
</item>
<item>
<title>Windows 11 26H2: Everything You Need to Know — Features, AI Integration, Security, and the Great Architecture Split</title>
<link>https://dev.purplesec.org/blog/windows-11-26h2-complete-guide/</link>
<description>A massively detailed guide to Windows 11 version 26H2 — the fall 2026 annual update. Covers the enablement package delivery model, AI-powered features like Copilot Vision and Click to Do, the 26H1 vs 26H2 architecture split, security hardening with hotpatching, Smart App Control, and Pluton, enterprise migration strategies from Windows 10, and what it all means for IT professionals.</description>
<pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/windows-11-26h2-complete-guide/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Windows 11</category>
<category>Microsoft</category>
<category>26H2</category>
<category>Copilot</category>
<category>AI</category>
</item>
<item>
<title>Wi-Fi Snitching: How Microsoft Teams' New Auto-Detect Feature Works (And How to Opt-Out)</title>
<link>https://dev.purplesec.org/blog/teams-wifi-tracking/</link>
<description>A deep dive into Microsoft Teams' new 'Workplace check-in' feature, the privacy concerns around Wi-Fi tracking, and how to opt-out of corporate surveillance.</description>
<pubDate>Sun, 21 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/teams-wifi-tracking/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Microsoft Teams</category>
<category>Privacy</category>
<category>Surveillance</category>
<category>Enterprise Security</category>
<category>Cybersecurity</category>
</item>
<item>
<title>RoguePlanet: Deep Dive into the Microsoft Defender TOCTOU Zero-Day (CVE-2026-50656)</title>
<link>https://dev.purplesec.org/blog/rogueplanet/</link>
<description>A comprehensive technical analysis of RoguePlanet (CVE-2026-50656), a critical Time-of-Check to Time-of-Use (TOCTOU) local privilege escalation vulnerability in Microsoft Defender, released by researcher Nightmare Eclipse.</description>
<pubDate>Sun, 21 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/rogueplanet/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Zero-Day</category>
<category>Microsoft Defender</category>
<category>Vulnerability Analysis</category>
<category>Nightmare Eclipse</category>
<category>CVE-2026-50656</category>
</item>
<item>
<title>The Anatomy of a Botnet: History, Architecture, and the Botnet Economy</title>
<link>https://dev.purplesec.org/blog/botnets-history-and-mechanics/</link>
<description>A massively detailed deep dive into the evolution of botnets, from benign 1980s IRC automation to the modern, sophisticated global networks fueling Botnet-as-a-Service (BaaS).</description>
<pubDate>Sun, 21 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/botnets-history-and-mechanics/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Botnets</category>
<category>Architecture</category>
<category>Mirai</category>
<category>Emotet</category>
<category>Deep Dive</category>
</item>
<item>
<title>An AI Agent Is an Identity — and Most Organizations Don't Treat Them That Way</title>
<link>https://dev.purplesec.org/blog/ai-agents-are-identities/</link>
<description>A deep, practical examination of why autonomous AI agents are full-fledged identities — not glorified service accounts — and why human-centric IAM is failing to govern them. Covers the non-human identity explosion (the 144:1 ratio), the confused deputy and lethal trifecta problems, the Salesloft Drift OAuth breach, the OWASP NHI and LLM Top 10s, the identity implications of local LLMs vs Claude/Gemini/OpenAI SaaS models, Microsoft Entra Agent ID and Google Agent Identity, and a concrete framework for treating agents as first-class governed identities.</description>
<pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/ai-agents-are-identities/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI Security</category>
<category>Identity and Access Management</category>
<category>Non-Human Identity</category>
<category>AI Agents</category>
<category>Zero Trust</category>
</item>
<item>
<title>The Great Telegram Lockdown: Exam Leaks, Timestamp Forgery, and the Global War on Moderation</title>
<link>https://dev.purplesec.org/blog/telegram-ban-india-global-moderation/</link>
<description>An in-depth investigation into India's recent temporary ban on Telegram, the technical exploit of timestamp forgery used by exam paper leaking rackets, and the global legal struggles of Pavel Durov.</description>
<pubDate>Wed, 17 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/telegram-ban-india-global-moderation/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Telegram</category>
<category>Government Bans</category>
<category>Cybersecurity</category>
<category>Privacy</category>
</item>
<item>
<title>Deep Dive: CVE-2025-57819 - Critical RCE in Sangoma FreePBX</title>
<link>https://dev.purplesec.org/blog/cve-2025-57819/</link>
<description>A detailed technical breakdown of CVE-2025-57819, an unauthenticated SQL injection and remote code execution vulnerability in Sangoma FreePBX Endpoint Manager.</description>
<pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/cve-2025-57819/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>CVE-2025-57819</category>
<category>FreePBX</category>
<category>Vulnerability</category>
<category>Security</category>
</item>
<item>
<title>Deep Dive: BadSuccessor (CVE-2025-53779) — The Windows Server 2025 dMSA Exploit That Shook Active Directory</title>
<link>https://dev.purplesec.org/blog/badsuccessor-cve-2025-53779/</link>
<description>The definitive technical analysis of BadSuccessor (CVE-2025-53779). Covers the full history of dMSA, Akamai's discovery, Kerberos PAC mechanics, Microsoft's controversial response, public PoC tools, the Ouroboros persistence technique, SIEM detection rules, and enterprise mitigations.</description>
<pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/badsuccessor-cve-2025-53779/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Active Directory</category>
<category>CVE-2025-53779</category>
<category>BadSuccessor</category>
<category>Windows Server 2025</category>
<category>Privilege Escalation</category>
</item>
<item>
<title>The Ban on "Foreign Nationals": US Government's Unprecedented Move Against Anthropic's Fable and Mythos Models</title>
<link>https://dev.purplesec.org/blog/anthropic-fable-mythos-export-control/</link>
<description>A deep dive into the recent U.S. government export control directive targeting Anthropic's Fable 5 and Mythos 5 models, the global shutdown, and the jailbreak controversy.</description>
<pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/anthropic-fable-mythos-export-control/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI</category>
<category>Export Control</category>
<category>Anthropic</category>
<category>Cybersecurity</category>
<category>Policy</category>
</item>
<item>
<title>Quantum Computing and PKI: The Looming Cryptographic Apocalypse and How to Survive It</title>
<link>https://dev.purplesec.org/blog/quantum-computing-and-pki/</link>
<description>A comprehensive deep dive into how quantum computing threatens to dismantle Public Key Infrastructure (PKI), the backbone of internet security. Covers Shor's and Grover's algorithms, the Harvest Now Decrypt Later threat, NIST's post-quantum standards (ML-KEM, ML-DSA, SLH-DSA), real-world hybrid TLS deployments by Google and Cloudflare, Quantum Key Distribution vs PQC, cryptographic agility, and a practical enterprise migration checklist.</description>
<pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/quantum-computing-and-pki/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Quantum Computing</category>
<category>PKI</category>
<category>Post-Quantum Cryptography</category>
<category>Cryptography</category>
<category>TLS</category>
</item>
<item>
<title>NVIDIA RTX Spark &amp; DGX Spark: The Dawn of Personal AI Supercomputers and What It Means for Local LLM Enthusiasts</title>
<link>https://dev.purplesec.org/blog/nvidia-rtx-dgx-spark/</link>
<description>An in-depth look at NVIDIA RTX Spark and DGX Spark — the new personal AI supercomputers powered by Grace Blackwell silicon. From the 128GB unified memory architecture to running 200B-parameter models locally, we explore what these machines mean for developers, researchers, and the local LLM community.</description>
<pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/nvidia-rtx-dgx-spark/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>NVIDIA</category>
<category>AI</category>
<category>LLM</category>
<category>DGX Spark</category>
<category>RTX Spark</category>
</item>
<item>
<title>How GitHub and npm Are Fighting Back Against Supply Chain Attacks — And What You Need to Do Before July 2026</title>
<link>https://dev.purplesec.org/blog/npm-supply-chain-security/</link>
<description>A deep dive into the npm v12 security overhaul arriving July 2026, the supply chain attacks that forced it, and a practical guide to preparing your projects — covering lifecycle script lockdown, Trusted Publishing, provenance attestations, and lessons from event-stream, colors.js, Shai-Hulud, and the chalk/debug compromise.</description>
<pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/npm-supply-chain-security/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>npm</category>
<category>GitHub</category>
<category>Supply Chain Security</category>
<category>Software Security</category>
<category>DevSecOps</category>
</item>
<item>
<title>June 2026 Patch Tuesday: A Record-Breaking 206 CVEs, Three Zero-Days &amp; Two BitLocker Bypasses</title>
<link>https://dev.purplesec.org/blog/june-2026-patch-tuesday/</link>
<description>A deep-dive into June 2026 Patch Tuesday — the largest in Microsoft history, patching 206 CVEs including 3 zero-days, a wormable Windows Kernel RCE (CVSS 9.8), an actively exploited Defender EoP, and two separate BitLocker bypasses (YellowKey &amp; Bitskrieg).</description>
<pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/june-2026-patch-tuesday/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Patch Tuesday</category>
<category>Microsoft</category>
<category>CVE</category>
<category>Windows</category>
<category>BitLocker</category>
</item>
<item>
<title>To Err is Algorithm: Case Studies Where AI Messed Up Big Time</title>
<link>https://dev.purplesec.org/blog/when_ai_messes_up/</link>
<description>A deep dive into three major incidents where artificial intelligence systems failed spectacularly, resulting in financial loss, legal liability, and public relations nightmares.</description>
<pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/when_ai_messes_up/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI</category>
<category>Machine Learning</category>
<category>Case Studies</category>
<category>Incident Response</category>
<category>Cybersecurity</category>
</item>
<item>
<title>The Nightmare Eclipse Zero-Day Campaign: A Complete Technical Analysis of the 2026 Microsoft Vendetta</title>
<link>https://dev.purplesec.org/blog/nightmare_eclipse_zero_days/</link>
<description>The definitive case study on the Nightmare Eclipse zero-day campaign against Microsoft. Covers all 8+ exploits (YellowKey, BlueHammer, RedSun, UnDefend, RoguePlanet, GreatXML), the researcher's identity and motivations, CVE details, patch status, CISA KEV entries, detection strategies, and the broader vulnerability disclosure debate.</description>
<pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/nightmare_eclipse_zero_days/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Zero-Day</category>
<category>Microsoft</category>
<category>Vulnerability Disclosure</category>
<category>Nightmare Eclipse</category>
<category>Case Study</category>
</item>
<item>
<title>A Comprehensive Guide to Modern AI: Concepts, Architecture, and Local Deployment</title>
<link>https://dev.purplesec.org/blog/comprehensive_ai_guide/</link>
<description>A comprehensive guide to modern AI, explaining core concepts like LLMs, RAG, embeddings, local deployment, and practical cybersecurity risks.</description>
<pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/comprehensive_ai_guide/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>AI</category>
<category>Machine Learning</category>
<category>Large Language Models</category>
<category>RAG</category>
<category>Local AI</category>
</item>
<item>
<title>The Anatomy of the Meta AI Support Hack: Why AI Should Never Reset Passwords</title>
<link>https://dev.purplesec.org/blog/Meta_AI_Support_Hack_Blog/</link>
<description>A deep dive into the 2026 Meta AI support hack, exploring how attackers socially engineered an AI chatbot to bypass IAM and reset Instagram passwords.</description>
<pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/Meta_AI_Support_Hack_Blog/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>Meta</category>
<category>AI</category>
<category>Security</category>
<category>Social Engineering</category>
</item>
<item>
<title>The Golden Skeleton Key: A Deep Dive into CVE-2026-45585 (YellowKey) BitLocker Bypass</title>
<link>https://dev.purplesec.org/blog/CVE-2026-45585_YellowKey_DeepDive/</link>
<description>A comprehensive technical deep dive into CVE-2026-45585 (YellowKey), a critical physical access vulnerability that completely bypasses Microsoft BitLocker encryption.</description>
<pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/CVE-2026-45585_YellowKey_DeepDive/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>CVE-2026-45585</category>
<category>BitLocker</category>
<category>YellowKey</category>
<category>Windows</category>
<category>Physical Security</category>
</item>
<item>
<title>How I Conquered the PNPT: A Wild Ride Through Cyber Shenanigans</title>
<link>https://dev.purplesec.org/blog/pnpt-review/</link>
<description>A candid review of the Practical Network Penetration Tester (PNPT) exam, featuring tips, lessons learned, and active directory exploitation strategies.</description>
<pubDate>Wed, 22 Oct 2025 00:00:00 +0000</pubDate>
<guid isPermaLink="true">https://dev.purplesec.org/blog/pnpt-review/</guid>
<author>elodvk@proton.me (Bilash J. Shahi)</author>
<category>TCM Security</category>
<category>PNPT</category>
<category>Practical Network Penetration Tester</category>
<category>Active Directory</category>
</item>
</channel>
</rss>