<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>AWS Security Audit on David Gomez - Technology &amp; Business Insights</title>
    <link>https://blog.itsdavidg.co/categories/aws-security-audit/</link>
    <description>Recent content in AWS Security Audit on David Gomez - Technology &amp; Business Insights</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 11 Sep 2026 12:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.itsdavidg.co/categories/aws-security-audit/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-11-aws-security-audit-cisco-fmc-flaws-exploited-to-steal-credentials-and-deploy/</link>
      <pubDate>Fri, 11 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-11-aws-security-audit-cisco-fmc-flaws-exploited-to-steal-credentials-and-deploy/</guid>
      <description>Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unaut</description>
    </item>
    <item>
      <title>Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-10-aws-security-audit-researcher-drops-new-microsoft-defender-poc-showing-shield/</link>
      <pubDate>Thu, 10 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-10-aws-security-audit-researcher-drops-new-microsoft-defender-poc-showing-shield/</guid>
      <description>The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. &amp;#34;Microsoft has failed to properly patch Shield</description>
    </item>
    <item>
      <title>Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-09-aws-security-audit-webinar-learn-how-to-answer-are-we-exposed-faster-after-a/</link>
      <pubDate>Wed, 09 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-09-aws-security-audit-webinar-learn-how-to-answer-are-we-exposed-faster-after-a/</guid>
      <description>A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery a</description>
    </item>
    <item>
      <title>Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-08-aws-security-audit-adobe-patches-magento-zero-day-exploited-to-deploy-rust-ba/</link>
      <pubDate>Tue, 08 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-08-aws-security-audit-adobe-patches-magento-zero-day-exploited-to-deploy-rust-ba/</guid>
      <description>Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. &amp;#34;</description>
    </item>
    <item>
      <title>Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-07-aws-security-audit-rogue-screenconnect-clients-spread-four-stage-vbscript-cha/</link>
      <pubDate>Mon, 07 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-07-aws-security-audit-rogue-screenconnect-clients-spread-four-stage-vbscript-cha/</guid>
      <description>Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-de</description>
    </item>
    <item>
      <title>Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-06-aws-security-audit-attackers-breached-jetbrains-cadence-via-unpatched-teamcit/</link>
      <pubDate>Sun, 06 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-06-aws-security-audit-attackers-breached-jetbrains-cadence-via-unpatched-teamcit/</guid>
      <description>JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. &amp;#34;Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their</description>
    </item>
    <item>
      <title>Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-05-aws-security-audit-critical-cisco-nexus-9000-flaw-lets-unauthenticated-remote/</link>
      <pubDate>Sat, 05 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-05-aws-security-audit-critical-cisco-nexus-9000-flaw-lets-unauthenticated-remote/</guid>
      <description>Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as</description>
    </item>
    <item>
      <title>Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-04-aws-security-audit-google-releases-chrome-update-to-patch-actively-exploited/</link>
      <pubDate>Fri, 04 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-04-aws-security-audit-google-releases-chrome-update-to-patch-actively-exploited/</guid>
      <description>Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome&amp;#39;s JavaScript and WebAssembly engine. &amp;#34;Type confusion in V8 in Google Chrome prior to</description>
    </item>
    <item>
      <title>CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-03-aws-security-audit-cisa-adds-seven-exploited-flaws-as-attackers-deploy-revers/</link>
      <pubDate>Thu, 03 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-03-aws-security-audit-cisa-adds-seven-exploited-flaws-as-attackers-deploy-revers/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers&amp;#39; crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that cou</description>
    </item>
    <item>
      <title>Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-02-aws-security-audit-attackers-exploit-two-sonicwall-sma-1000-zero-days-that-ma/</link>
      <pubDate>Wed, 02 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-02-aws-security-audit-attackers-exploit-two-sonicwall-sma-1000-zero-days-that-ma/</guid>
      <description>SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall&amp;#39;s William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnera</description>
    </item>
    <item>
      <title>Amazon Redshift now supports AWS IAM Identity Center authentication with enhanced VPC routing</title>
      <link>https://blog.itsdavidg.co/posts/2026-09-01-aws-security-audit-amazon-redshift-now-supports-aws-iam-identity-center-authe/</link>
      <pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-09-01-aws-security-audit-amazon-redshift-now-supports-aws-iam-identity-center-authe/</guid>
      <description>Amazon Redshift now supports AWS IAM Identity Center authentication for provisioned clusters and serverless workgroups configured with enhanced VPC routing (EVR). You can access Amazon Redshift with single sign-on with your corporate credentials, and the traffic traverses Amazon Virtual Private Cloud (Amazon VPC) and stays on the AWS network. This is valuabl</description>
    </item>
  </channel>
</rss>
