<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>defend.network – Daily Threat Briefings</title>
  <link>https://defend.network</link>
  <description>AI-powered cybersecurity threat intelligence. Daily briefings, vulnerability analysis, and security tool directory.</description>
  <language>en-us</language>
  <managingEditor>contact@defend.network (defend.network)</managingEditor>
  <webMaster>contact@defend.network (defend.network)</webMaster>
  <lastBuildDate>Sun, 19 Jul 2026 04:01:21 GMT</lastBuildDate>
  <atom:link href="https://defend.network/feed.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>WordPress, 7-Zip RCE exploited; NadMesh steals AWS keys; ACR Stealer surge</title>
    <link>https://defend.network/briefings/wordpress-7zip-nadmesh-acr-stealer-rce-2026-07-19.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/wordpress-7zip-nadmesh-acr-stealer-rce-2026-07-19.html</guid>
    <pubDate>Sun, 19 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>WordPress wp2shell RCE under active exploitation with public PoC. NadMesh botnet harvests 3,811 AWS keys from exposed AI services. 7-Zip patches critical archive RCE. Microsoft alerts on ACR Stealer surge.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">healthcare</category>
  </item>
  <item>
    <title>WordPress, OpenSSL, Fortinet zero-days: patches shipped and KEV escalations</title>
    <link>https://defend.network/briefings/wordpress-openssl-fortinet-exploits-patched-2026-07-18.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/wordpress-openssl-fortinet-exploits-patched-2026-07-18.html</guid>
    <pubDate>Sat, 18 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>WordPress 6.9/7.0 core RCE patched Friday with forced updates; OpenSSL HollowByte DoS flaw allows 11-byte memory exhaustion; two Fortinet FortiSandbox command-injection vulns in CISA KEV catalog. NadMesh botnet harvesting AWS keys from exposed AI services.</description>
    <category>high</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>Scattered Spider sentenced; Microsoft patches record 570 flaws; macOS ClickLock stealer active</title>
    <link>https://defend.network/briefings/scattered-spider-sentenced-microsoft-570-patches-clickl-2026-07-17.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/scattered-spider-sentenced-microsoft-570-patches-clickl-2026-07-17.html</guid>
    <pubDate>Fri, 17 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Two Scattered Spider members sentenced to 5.5 years for 2024 Transport for London attack. Microsoft releases record 570-CVE patch set. ClickLock macOS malware terminates apps until password stolen.</description>
    <category>high</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/industries/">government</category>
    <category domain="https://defend.network/industries/">transportation</category>
  </item>
  <item>
    <title>Microsoft SharePoint, Windows zero-days actively exploited; Zoom account takeover critical</title>
    <link>https://defend.network/briefings/microsoft-sharepoint-zoom-windows-critical-exploits-2026-07-16.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/microsoft-sharepoint-zoom-windows-critical-exploits-2026-07-16.html</guid>
    <pubDate>Thu, 16 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Microsoft SharePoint Server missing authentication flaw actively exploited; Windows User Profile Service zero-day PoC released; Zoom critical account takeover vulnerability disclosed. Microsoft patched record 570 flaws in latest Patch Tuesday.</description>
    <category>high</category>
    <category domain="https://defend.network/threats/">zero-day</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/industries/">government</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>Critical zero-days in Microsoft Active Directory, SonicWall SMA1000, GitHub malware campaign</title>
    <link>https://defend.network/briefings/microsoft-sonicwall-github-zero-day-exploits-2026-07-15.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/microsoft-sonicwall-github-zero-day-exploits-2026-07-15.html</guid>
    <pubDate>Wed, 15 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Microsoft patches record 622 flaws including two zero-days in Active Directory and SharePoint under active attack. SonicWall confirms exploitation of SMA1000 zero-days. GitHub supply-chain attack spreads 300 fake repositories with infostealer malware.</description>
    <category>critical</category>
    <category domain="https://defend.network/threats/">zero-day</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">finance</category>
  </item>
  <item>
    <title>ModHeader, CrashStealer, Joomla RCE active exploits; npm supply-chain risk</title>
    <link>https://defend.network/briefings/modheader-extension-crashstealer-joomla-rce-exploits-2026-07-14.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/modheader-extension-crashstealer-joomla-rce-exploits-2026-07-14.html</guid>
    <pubDate>Tue, 14 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Google and Microsoft remove ModHeader extension (1.6M installs) after discovering hidden tracking. CrashStealer macOS malware evades Gatekeeper using signed code. CISA warns of active Joomla extension exploitation.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">retail</category>
  </item>
  <item>
    <title>npm supply-chain attacks escalate; Zimbra RCE, Android malware evolves</title>
    <link>https://defend.network/briefings/npm-supply-chain-zimbra-rce-android-malware-2026-07-13.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/npm-supply-chain-zimbra-rce-android-malware-2026-07-13.html</guid>
    <pubDate>Mon, 13 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>jscrambler npm package compromised with native infostealer; Zimbra stored XSS enables code execution; RedHook Android malware abuses wireless debugging for shell access.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>npm supply-chain attacks: jscrambler infostealer, Injective wallet theft, Zimbra RCE</title>
    <link>https://defend.network/briefings/jscrambler-zimbra-injective-npm-supply-chain-2026-07-12.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/jscrambler-zimbra-injective-npm-supply-chain-2026-07-12.html</guid>
    <pubDate>Sun, 12 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>jscrambler npm 8.14.0 compromised with Rust infostealer, Zimbra XSS flaw enables code execution</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">finance</category>
  </item>
  <item>
    <title>Progress ShareFile emergency shutdown; Injective GitHub breach; U-Boot firmware flaws</title>
    <link>https://defend.network/briefings/progress-sharefile-injective-uboot-firmware-threats-2026-07-11.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/progress-sharefile-injective-uboot-firmware-threats-2026-07-11.html</guid>
    <pubDate>Sat, 11 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Progress Software orders immediate shutdown of ShareFile Storage Zone Controllers; Injective Labs GitHub compromise distributes crypto-stealing malware; six new U-Boot bootloader vulnerabilities discovered in IoT and data-center devices.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">finance</category>
  </item>
  <item>
    <title>GitHub API enumeration campaign exposed; GigaWiper Windows backdoor combines disk wipe, spyware</title>
    <link>https://defend.network/briefings/github-api-enumeration-gigawiper-windows-backdoor-npm-s-2026-07-10.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/github-api-enumeration-gigawiper-windows-backdoor-npm-s-2026-07-10.html</guid>
    <pubDate>Fri, 10 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Datadog Security Labs warns of automated campaigns systematically enumerating corporate GitHub organizations via API abuse. Microsoft disassembles destructive GigaWiper backdoor combining disk wipe, ransomware, and spyware. npm 12 disables install scripts by default to reduce supply-chain risk.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>Ubiquiti UniFi critical patches; HalluSquatting targets AI coding assistants</title>
    <link>https://defend.network/briefings/ubiquiti-unifi-hallusquatting-ai-coding-exploits-2026-07-09.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/ubiquiti-unifi-hallusquatting-ai-coding-exploits-2026-07-09.html</guid>
    <pubDate>Thu, 09 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Ubiquiti patches critical UniFi flaws enabling privilege escalation and RCE across Connect, Talk, Access, Protect, AI coding assistants face new HalluSquatting attacks that trick them into installing botnet malware.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>GitHub, Gitea, Google Dialogflow hit by active exploits; RedWing Android malware-as-service</title>
    <link>https://defend.network/briefings/github-gitea-google-dialogflow-android-redwing-2026-07-08.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/github-gitea-google-dialogflow-android-redwing-2026-07-08.html</guid>
    <pubDate>Wed, 08 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>GitHub Agentic Workflows leak private repo data via public issues; Gitea CVE-2026-20896 authentication bypass actively exploited; RedWing Android malware rented as fraud service on Telegram.</description>
    <category>high</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">mobile-malware</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">finance</category>
  </item>
  <item>
    <title>Adobe ColdFusion RCE, Linux KVM escape, Gitea authentication bypass under active attack</title>
    <link>https://defend.network/briefings/adobe-coldfusion-linux-kvm-gitea-active-exploits-2026-07-07.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/adobe-coldfusion-linux-kvm-gitea-active-exploits-2026-07-07.html</guid>
    <pubDate>Tue, 07 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Adobe ColdFusion max-severity RCE actively exploited; Linux KVM escape (CVE-2026-53359) affects Intel/AMD hosts; Gitea Docker auth bypass (CVE-2026-20896, CVSS 9.8) probed within 13 days; Iranian MOIS-linked group deploys new Cavern C2 framework against Israeli IT providers.</description>
    <category>critical</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">apt</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">government</category>
  </item>
  <item>
    <title>North Korea PolinRider expands to 108 packages; Avalon ransomware framework emerges</title>
    <link>https://defend.network/briefings/north-korea-malware-packages-avalon-framework-ransomwar-2026-07-06.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/north-korea-malware-packages-avalon-framework-ransomwar-2026-07-06.html</guid>
    <pubDate>Mon, 06 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>North Korean actors publish 108 malicious packages across npm, Packagist, Go, Chrome; Avalon modular framework combines credential theft with CrownX ransomware. U.S. government paid $1M extortion to Kairos group.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/threats/">ransomware</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">government</category>
  </item>
  <item>
    <title>North Korea targets npm, Linux kernel RCE, AI-driven ransomware surge</title>
    <link>https://defend.network/briefings/north-korea-malware-linux-kernel-ransomware-ai-2026-07-05.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/north-korea-malware-linux-kernel-ransomware-ai-2026-07-05.html</guid>
    <pubDate>Sun, 05 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>North Korean actors published 108 malicious packages across npm and other ecosystems; Linux kernel RCE affects Android; first documented LLM-automated ransomware attack observed.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/threats/">ransomware</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>Linux kernel RCE, FatFs firmware flaws, North Korea npm malware</title>
    <link>https://defend.network/briefings/linux-kernel-fatfs-npm-supply-chain-threats-2026-07-04.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/linux-kernel-fatfs-npm-supply-chain-threats-2026-07-04.html</guid>
    <pubDate>Sat, 04 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>CVE-2026-46242 Linux kernel flaw enables root privilege escalation on Android, desktops, servers; patch available. Seven unpatched FatFs vulnerabilities in millions of embedded devices. North Korea-linked malicious npm packages target developer credentials.</description>
    <category>low</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>NetNut seized; Citrix Bleed 2 exploited; ToddyCat hijacks Gmail via OAuth</title>
    <link>https://defend.network/briefings/netnut-citrix-bleed-toddycat-oauth-gmail-2026-07-03.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/netnut-citrix-bleed-toddycat-oauth-gmail-2026-07-03.html</guid>
    <pubDate>Fri, 03 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Google and FBI disrupt 2M-device NetNut proxy network; Anubis ransomware actively exploits Citrix Bleed 2 (CVE-2025-5777); ToddyCat malware abuses Google APIs to hijack Gmail accounts; Microsoft 365 OAuth bypass attacks steal tokens in seconds.</description>
    <category>high</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">malware</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>Unpatched Argo CD RCE, ChocoPoC researcher targeting, Scattered Spider extraditions</title>
    <link>https://defend.network/briefings/argo-cd-kubernetes-chocopoc-github-scattered-spider-2026-07-02.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/argo-cd-kubernetes-chocopoc-github-scattered-spider-2026-07-02.html</guid>
    <pubDate>Thu, 02 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Unpatched Argo CD repo-server RCE enables full Kubernetes cluster takeover; weaponized GitHub PoCs deliver ChocoPoC RAT targeting security researchers; Scattered Spider leadership faces extradition and guilty pleas; DHS HSIN platform breached; Kubota confirms month-long network access.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/industries/">technology</category>
    <category domain="https://defend.network/industries/">government</category>
  </item>
  <item>
    <title>AI agent poisoning, Langflow RCE exploited: Microsoft warns data theft risks</title>
    <link>https://defend.network/briefings/ai-agent-poisoning-microsoft-langflow-rce-cryptojacking-2026-07-01.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/ai-agent-poisoning-microsoft-langflow-rce-cryptojacking-2026-07-01.html</guid>
    <pubDate>Wed, 01 Jul 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Microsoft research exposes AI agent manipulation via poisoned tool descriptions; Langflow RCE (CVE-2026-33017) actively exploited for Monero mining; six critical shell-injection bypasses discovered in open-source AI coding agents.</description>
    <category>high</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">credential-theft</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>Oracle PeopleSoft breaches widen; malicious Chrome extension steals searches; Mustang Panda targets India</title>
    <link>https://defend.network/briefings/oracle-peoplesoft-microsoft-chrome-credential-theft-2026-06-30.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/oracle-peoplesoft-microsoft-chrome-credential-theft-2026-06-30.html</guid>
    <pubDate>Tue, 30 Jun 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Oracle PeopleSoft zero-day exploited at Nissan and NAIC; malicious Chrome extension intercepted searches and address bar input; Mustang Panda uses Zoho WorkDrive in Indian government campaigns.</description>
    <category>critical</category>
    <category domain="https://defend.network/threats/">data-breach</category>
    <category domain="https://defend.network/threats/">credential-theft</category>
    <category domain="https://defend.network/industries/">finance</category>
    <category domain="https://defend.network/industries/">government</category>
  </item>
  <item>
    <title>Russian intel evolves Signal phishing; Cisco actively exploited; KDDI breach hits 14.2M</title>
    <link>https://defend.network/briefings/russian-phishing-signal-cisco-breach-2026-06-29.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/russian-phishing-signal-cisco-breach-2026-06-29.html</guid>
    <pubDate>Mon, 29 Jun 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Russian intelligence phishing campaign now targets Signal backup recovery keys; Cisco vulnerability under active exploitation with CISA emergency deadline; KDDI email breach exposes 14.2M credentials across six ISPs.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">phishing</category>
    <category domain="https://defend.network/threats/">apt</category>
    <category domain="https://defend.network/industries/">government</category>
    <category domain="https://defend.network/industries/">telecom</category>
  </item>
  <item>
    <title>Russian phishing escalates; Turla malware evolves; GitHub AI agents at risk</title>
    <link>https://defend.network/briefings/russian-signal-phishing-turla-malware-github-ai-2026-06-28.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/russian-signal-phishing-turla-malware-github-ai-2026-06-28.html</guid>
    <pubDate>Sun, 28 Jun 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Russian intelligence expanding Signal phishing to steal backup keys; Turla deploys StockStay malware against Ukraine; AI coding agents tricked into executing malware via GitHub repositories.</description>
    <category>medium</category>
    <category domain="https://defend.network/threats/">phishing</category>
    <category domain="https://defend.network/threats/">apt</category>
    <category domain="https://defend.network/industries/">government</category>
  </item>
  <item>
    <title>Signal backup keys targeted; Linux kernel RCE; AWS Q credential theft</title>
    <link>https://defend.network/briefings/signal-phishing-linux-kernel-aws-credential-theft-2026-06-27.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/signal-phishing-linux-kernel-aws-credential-theft-2026-06-27.html</guid>
    <pubDate>Sat, 27 Jun 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Russian intelligence phishing now targets Signal Backup Recovery Keys. Linux kernel privilege escalation (CVE-2026-46331) has working exploit. AWS Q flaw (CVE-2026-12957, CVSS 8.5) allows malicious repos to steal cloud credentials.</description>
    <category>low</category>
    <category domain="https://defend.network/threats/">phishing</category>
    <category domain="https://defend.network/threats/">credential-theft</category>
    <category domain="https://defend.network/industries/">government</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>Critical Lantronix flaw actively exploited; Cisco SD-WAN zero-day; 27M credentials recovered</title>
    <link>https://defend.network/briefings/lantronix-eds5000-cisco-sd-wan-cordyceps-github-2026-06-25.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/lantronix-eds5000-cisco-sd-wan-cordyceps-github-2026-06-25.html</guid>
    <pubDate>Thu, 25 Jun 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>Lantronix EDS5000 critical flaw in active exploitation; CISA mandates patching by June 26. Amadey/StealC malware networks dismantled, 27M credentials recovered. Cordyceps CI/CD weakness affects 300+ GitHub repositories.</description>
    <category>high</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/threats/">supply-chain</category>
    <category domain="https://defend.network/industries/">government</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
  <item>
    <title>FortiBleed harvests 110M credentials; Cisco SSRF actively exploited; GitHub patches CI/CD attacks</title>
    <link>https://defend.network/briefings/fortibleed-cisco-github-ai-credential-theft-2026-06-24.html</link>
    <guid isPermaLink="true">https://defend.network/briefings/fortibleed-cisco-github-ai-credential-theft-2026-06-24.html</guid>
    <pubDate>Wed, 24 Jun 2026 06:30:00 GMT</pubDate>
    <dc:creator>defend.network</dc:creator>
    <description>FortiBleed credential-harvesting campaign collected 110 million credentials from 430</description>
    <category>high</category>
    <category domain="https://defend.network/threats/">credential-theft</category>
    <category domain="https://defend.network/threats/">vulnerability-exploit</category>
    <category domain="https://defend.network/industries/">technology</category>
  </item>
</channel>
</rss>