<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>DevOps Engineering on David Gomez - Technology &amp; Business Insights</title>
    <link>https://blog.itsdavidg.co/tags/devops-engineering/</link>
    <description>Recent content in DevOps Engineering on David Gomez - Technology &amp; Business Insights</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 31 Aug 2026 12:00:00 +0000</lastBuildDate>
    <atom:link href="https://blog.itsdavidg.co/tags/devops-engineering/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-31-aws-security-audit-aurora-ransomware-operators-use-cursor-ai-in-attacks-again/</link>
      <pubDate>Mon, 31 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-31-aws-security-audit-aurora-ransomware-operators-use-cursor-ai-in-attacks-again/</guid>
      <description>Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX&amp;#39;s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime gro</description>
    </item>
    <item>
      <title>Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-30-aws-security-audit-amazon-kiro-prompt-injection-can-exfiltrate-sensitive-data/</link>
      <pubDate>Sun, 30 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-30-aws-security-audit-amazon-kiro-prompt-injection-can-exfiltrate-sensitive-data/</guid>
      <description>Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, accordin</description>
    </item>
    <item>
      <title>ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-29-aws-security-audit-owncloud-flaw-exploited-to-steal-nuclear-records-from-phil/</link>
      <pubDate>Sat, 29 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-29-aws-security-audit-owncloud-flaw-exploited-to-steal-nuclear-records-from-phil/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-491</description>
    </item>
    <item>
      <title>OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-28-aws-security-audit-openai-says-reward-hacking-drove-ai-agents-to-exploit-zero/</link>
      <pubDate>Fri, 28 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-28-aws-security-audit-openai-says-reward-hacking-drove-ai-agents-to-exploit-zero/</guid>
      <description>OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by wha</description>
    </item>
    <item>
      <title>CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-27-aws-security-audit-cisa-adds-six-exploited-flaws-to-kev-including-netscaler-l/</link>
      <pubDate>Thu, 27 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-27-aws-security-audit-cisa-adds-six-exploited-flaws-to-kev-including-netscaler-l/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code</description>
    </item>
    <item>
      <title>Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-26-aws-security-audit-critical-gitea-rce-actively-exploited-as-reported-attack-d/</link>
      <pubDate>Wed, 26 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-26-aws-security-audit-critical-gitea-rce-actively-exploited-as-reported-attack-d/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute</description>
    </item>
    <item>
      <title>SageMaker MLflow now supports customer managed keys</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-25-aws-security-audit-sagemaker-mlflow-now-supports-customer-managed-keys/</link>
      <pubDate>Tue, 25 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-25-aws-security-audit-sagemaker-mlflow-now-supports-customer-managed-keys/</guid>
      <description>SageMaker MLflow now enables customers to encrypt their data using customer-managed keys (CMK) through AWS Key Management Service (KMS). This enhancement allows organizations with strict security and compliance requirements to manage their own encryption keys. With customer-managed keys, you gain enhanced security control and comprehensive audit capabilities</description>
    </item>
    <item>
      <title>Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-24-aws-security-audit-critical-keycloak-password-reset-flaw-could-let-unauthenti/</link>
      <pubDate>Mon, 24 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-24-aws-security-audit-critical-keycloak-password-reset-flaw-could-let-unauthenti/</guid>
      <description>Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963, is rated 9.1 on the CVSS scoring syste</description>
    </item>
    <item>
      <title>Why &#34;Shady AI&#34; is Security&#39;s Next Big Governance Problem</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-23-aws-security-audit-why-shady-ai-is-security-s-next-big-governance-problem/</link>
      <pubDate>Sun, 23 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-23-aws-security-audit-why-shady-ai-is-security-s-next-big-governance-problem/</guid>
      <description>In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it, but the agent posted its response publicly w</description>
    </item>
    <item>
      <title>Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-22-aws-security-audit-isolated-vm-flaw-lets-sandboxed-javascript-escape-to-host/</link>
      <pubDate>Sat, 22 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-22-aws-security-audit-isolated-vm-flaw-lets-sandboxed-javascript-escape-to-host/</guid>
      <description>Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability (&amp;#34;GHSA-864f-rcv7-6rh4&amp;#34;), which has yet to be assigned a CVE identifier, impacts all versions of the</description>
    </item>
    <item>
      <title>GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-21-aws-security-audit-gitlab-cve-2026-19478-comes-under-active-exploitation-with/</link>
      <pubDate>Fri, 21 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-21-aws-security-audit-gitlab-cve-2026-19478-comes-under-active-exploitation-with/</guid>
      <description>A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain</description>
    </item>
    <item>
      <title>Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-20-aws-security-audit-elementor-pro-flaw-could-let-unauthenticated-attackers-upl/</link>
      <pubDate>Thu, 20 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-20-aws-security-audit-elementor-pro-flaw-could-let-unauthenticated-attackers-upl/</guid>
      <description>Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. &amp;#34;The flaw</description>
    </item>
    <item>
      <title>AWS IAM identity federation to external services is now available in AWS European Sovereign...</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-19-aws-security-audit-aws-iam-identity-federation-to-external-services-is-now-av/</link>
      <pubDate>Wed, 19 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-19-aws-security-audit-aws-iam-identity-federation-to-external-services-is-now-av/</guid>
      <description>AWS Identity and Access Management (IAM) now enables AWS workloads in the AWS European Sovereign Cloud (Germany) Region to securely authenticate with external services using short-lived JSON Web Tokens (JWTs). The AWS European Sovereign Cloud is an independent cloud for Europe entirely located within the European Union (EU), designed to help customers meet t</description>
    </item>
    <item>
      <title>Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-18-aws-security-audit-apple-macos-screen-sharing-flaw-exploited-on-internet-expo/</link>
      <pubDate>Tue, 18 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-18-aws-security-audit-apple-macos-screen-sharing-flaw-exploited-on-internet-expo/</guid>
      <description>A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an atta</description>
    </item>
    <item>
      <title>Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-17-aws-security-audit-suspected-china-nexus-actor-exploits-vmware-vcenter-flaw-d/</link>
      <pubDate>Mon, 17 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-17-aws-security-audit-suspected-china-nexus-actor-exploits-vmware-vcenter-flaw-d/</guid>
      <description>Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a mali</description>
    </item>
    <item>
      <title>Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-16-aws-security-audit-attackers-exploit-vmware-vcenter-vulnerability-to-gain-per/</link>
      <pubDate>Sun, 16 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-16-aws-security-audit-attackers-exploit-vmware-vcenter-vulnerability-to-gain-per/</guid>
      <description>Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrar</description>
    </item>
    <item>
      <title>Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-15-aws-security-audit-adobe-patches-three-cvss-10-0-coldfusion-and-campaign-clas/</link>
      <pubDate>Sat, 15 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-15-aws-security-audit-adobe-patches-three-cvss-10-0-coldfusion-and-campaign-clas/</guid>
      <description>Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulne</description>
    </item>
    <item>
      <title>Attackers Exploit SharePoint Authentication Bypass After Public PoC Release</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-14-aws-security-audit-attackers-exploit-sharepoint-authentication-bypass-after-p/</link>
      <pubDate>Fri, 14 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-14-aws-security-audit-attackers-exploit-sharepoint-authentication-bypass-after-p/</guid>
      <description>Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch T</description>
    </item>
    <item>
      <title>OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-13-aws-security-audit-openai-launches-gpt-5-6-cyber-with-reduced-safeguards-for/</link>
      <pubDate>Thu, 13 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-13-aws-security-audit-openai-launches-gpt-5-6-cyber-with-reduced-safeguards-for/</guid>
      <description>OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. &amp;#34;Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to re</description>
    </item>
    <item>
      <title>ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-12-aws-security-audit-shieldbreak-zero-day-poc-claims-microsoft-defender-patch-b/</link>
      <pubDate>Wed, 12 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-12-aws-security-audit-shieldbreak-zero-day-poc-claims-microsoft-defender-patch-b/</guid>
      <description>The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePla</description>
    </item>
    <item>
      <title>Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-11-aws-security-audit-gunra-ransomware-exploits-fortinet-and-schneider-electric/</link>
      <pubDate>Tue, 11 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-11-aws-security-audit-gunra-ransomware-exploits-fortinet-and-schneider-electric/</guid>
      <description>Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. &amp;#34;Gunra is another</description>
    </item>
    <item>
      <title>New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-10-aws-security-audit-new-passkey-attacks-can-recover-synced-private-keys-or-byp/</link>
      <pubDate>Mon, 10 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-10-aws-security-audit-new-passkey-attacks-can-recover-synced-private-keys-or-byp/</guid>
      <description>Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the</description>
    </item>
    <item>
      <title>Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-09-aws-security-audit-progress-kemp-loadmaster-flaw-hits-cisa-kev-after-792-repo/</link>
      <pubDate>Sun, 09 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-09-aws-security-audit-progress-kemp-loadmaster-flaw-hits-cisa-kev-after-792-repo/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could</description>
    </item>
    <item>
      <title>Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-08-aws-security-audit-metabase-zero-day-exploited-in-wild-allows-admin-access-wi/</link>
      <pubDate>Sat, 08 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-08-aws-security-audit-metabase-zero-day-exploited-in-wild-allows-admin-access-wi/</guid>
      <description>Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application databas</description>
    </item>
    <item>
      <title>New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-07-aws-security-audit-new-zapscape-kvm-flaw-could-let-privileged-l1-guest-code-e/</link>
      <pubDate>Fri, 07 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-07-aws-security-audit-new-zapscape-kvm-flaw-could-let-privileged-l1-guest-code-e/</guid>
      <description>Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86&amp;#39;s shadow memory management unit (MMU), wh</description>
    </item>
    <item>
      <title>CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-06-aws-security-audit-cisa-flags-teamcity-cve-2026-63077-rce-flaw-under-active-e/</link>
      <pubDate>Thu, 06 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-06-aws-security-audit-cisa-flags-teamcity-cve-2026-63077-rce-flaw-under-active-e/</guid>
      <description>A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated atta</description>
    </item>
    <item>
      <title>New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-05-aws-security-audit-new-ovswrap-linux-kernel-flaw-lets-local-users-gain-root-v/</link>
      <pubDate>Wed, 05 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-05-aws-security-audit-new-ovswrap-linux-kernel-flaw-lets-local-users-gain-root-v/</guid>
      <description>A memory corruption flaw in the Linux kernel&amp;#39;s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclose</description>
    </item>
    <item>
      <title>CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-04-aws-security-audit-cisa-adds-exploited-n-able-n-central-flaw-to-kev-after-cus/</link>
      <pubDate>Tue, 04 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-04-aws-security-audit-cisa-adds-exploited-n-able-n-central-flaw-to-kev-after-cus/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556</description>
    </item>
    <item>
      <title>PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-03-aws-security-audit-pnld-breach-exposes-u-k-police-and-government-contact-deta/</link>
      <pubDate>Mon, 03 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-03-aws-security-audit-pnld-breach-exposes-u-k-police-and-government-contact-deta/</guid>
      <description>The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified</description>
    </item>
    <item>
      <title>Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-02-aws-security-audit-ruflo-mcp-flaw-lets-unauthenticated-attackers-run-commands/</link>
      <pubDate>Sun, 02 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-02-aws-security-audit-ruflo-mcp-flaw-lets-unauthenticated-attackers-run-commands/</guid>
      <description>Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been code</description>
    </item>
    <item>
      <title>Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction</title>
      <link>https://blog.itsdavidg.co/posts/2026-08-01-aws-security-audit-adobe-campaign-classic-cvss-10-0-flaw-could-run-code-witho/</link>
      <pubDate>Sat, 01 Aug 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-08-01-aws-security-audit-adobe-campaign-classic-cvss-10-0-flaw-could-run-code-witho/</guid>
      <description>Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect</description>
    </item>
    <item>
      <title>Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-31-aws-security-audit-anthropic-says-claude-mistook-the-open-internet-for-a-ctf/</link>
      <pubDate>Fri, 31 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-31-aws-security-audit-anthropic-says-claude-mistook-the-open-internet-for-a-ctf/</guid>
      <description>Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the di</description>
    </item>
    <item>
      <title>Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-30-aws-security-audit-cisco-fmc-zero-day-actively-exploited-static-credentials-c/</link>
      <pubDate>Thu, 30 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-30-aws-security-audit-cisco-fmc-zero-day-actively-exploited-static-credentials-c/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an una</description>
    </item>
    <item>
      <title>OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-29-aws-security-audit-openai-agent-used-exposed-credentials-across-four-services/</link>
      <pubDate>Wed, 29 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-29-aws-security-audit-openai-agent-used-exposed-credentials-across-four-services/</guid>
      <description>OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face&amp;#39;s production environment also hacked multiple third-party accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was more</description>
    </item>
    <item>
      <title>Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-28-aws-security-audit-critical-teamcity-flaw-could-let-attackers-run-os-commands/</link>
      <pubDate>Tue, 28 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-28-aws-security-audit-critical-teamcity-flaw-could-let-attackers-run-os-commands/</guid>
      <description>JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3.</description>
    </item>
    <item>
      <title>Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-27-aws-security-audit-adobe-acrobat-extension-flaw-let-malicious-sites-read-what/</link>
      <pubDate>Mon, 27 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-27-aws-security-audit-adobe-acrobat-extension-flaw-let-malicious-sites-read-what/</guid>
      <description>Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user&amp;#39;s WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs. It&amp;#39;s officially tracked as CVE-2026-48294 (CVSS score:</description>
    </item>
    <item>
      <title>Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-26-aws-security-audit-fastjson-1-x-rce-vulnerability-targeted-in-attacks-with-no/</link>
      <pubDate>Sun, 26 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-26-aws-security-audit-fastjson-1-x-rce-vulnerability-targeted-in-attacks-with-no/</guid>
      <description>Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba&amp;#39;s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of</description>
    </item>
    <item>
      <title>Opus 4.8, Sonnet 5, and User Activity Monitoring now available on Kiro in AWS GovCloud (US)</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-25-aws-security-audit-opus-4-8-sonnet-5-and-user-activity-monitoring-now-availab/</link>
      <pubDate>Sat, 25 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-25-aws-security-audit-opus-4-8-sonnet-5-and-user-activity-monitoring-now-availab/</guid>
      <description>Two new models are now available in the Kiro IDE and CLI for the AWS GovCloud (US) Regions. Claude Opus 4.8 is the most intelligent Opus model, delivering stronger self-verification, more efficient tool calling, and better follow-through on long-horizon projects. It plans before it edits, catches its own mistakes, and finds creative paths around obstacles in</description>
    </item>
    <item>
      <title>ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-24-aws-security-audit-chatgpt-agentforger-flaw-could-deploy-rogue-workspace-agen/</link>
      <pubDate>Fri, 24 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-24-aws-security-audit-chatgpt-agentforger-flaw-could-deploy-rogue-workspace-agen/</guid>
      <description>Cybersecurity researchers have disclosed a critical vulnerability in OpenAI&amp;#39;s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim&amp;#39;s organization. The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since b</description>
    </item>
    <item>
      <title>Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-23-aws-security-audit-ubuntu-snap-confine-flaw-could-give-local-users-root-on-de/</link>
      <pubDate>Thu, 23 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-23-aws-security-audit-ubuntu-snap-confine-flaw-could-give-local-users-root-on-de/</guid>
      <description>Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10</description>
    </item>
    <item>
      <title>Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-22-aws-security-audit-qilin-ransomware-attackers-exploit-pan-os-authentication-b/</link>
      <pubDate>Wed, 22 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-22-aws-security-audit-qilin-ransomware-attackers-exploit-pan-os-authentication-b/</guid>
      <description>Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass f</description>
    </item>
    <item>
      <title>Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-21-aws-security-audit-critical-servicenow-ai-platform-flaw-exploited-for-unauthe/</link>
      <pubDate>Tue, 21 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-21-aws-security-audit-critical-servicenow-ai-platform-flaw-exploited-for-unauthe/</guid>
      <description>Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it&amp;#39;s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary</description>
    </item>
    <item>
      <title>SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-20-aws-security-audit-sonicwall-sma-zero-days-exploited-before-disclosure-to-gai/</link>
      <pubDate>Mon, 20 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-20-aws-security-audit-sonicwall-sma-zero-days-exploited-before-disclosure-to-gai/</guid>
      <description>A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident res</description>
    </item>
    <item>
      <title>AWS IAM Identity Center achieves FedRAMP Class C Certification</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-19-aws-security-audit-aws-iam-identity-center-achieves-fedramp-class-c-certifica/</link>
      <pubDate>Sun, 19 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-19-aws-security-audit-aws-iam-identity-center-achieves-fedramp-class-c-certifica/</guid>
      <description>AWS IAM Identity Center is now in scope for FedRAMP Class C in the US East (Ohio), US East (N. Virginia), US West (N. California), and US West (Oregon) Regions. You can now use IAM Identity Center to enable workforce access to AWS accounts and applications that are subject to FedRAMP Class C compliance. The Federal Risk and Authorization Management Program (</description>
    </item>
    <item>
      <title>GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-18-aws-security-audit-goldeneyedog-subgroup-linked-to-digicert-breach-and-code-s/</link>
      <pubDate>Sat, 18 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-18-aws-security-audit-goldeneyedog-subgroup-linked-to-digicert-breach-and-code-s/</guid>
      <description>Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gamb</description>
    </item>
    <item>
      <title>CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-17-aws-security-audit-cisa-adds-exploited-sharepoint-rce-zero-day-cve-2026-58644/</link>
      <pubDate>Fri, 17 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-17-aws-security-audit-cisa-adds-exploited-sharepoint-rce-zero-day-cve-2026-58644/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS scor</description>
    </item>
    <item>
      <title>Zoom Patches Critical Windows Flaw That Could Enable Account Takeover</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-16-aws-security-audit-zoom-patches-critical-windows-flaw-that-could-enable-accou/</link>
      <pubDate>Thu, 16 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-16-aws-security-audit-zoom-patches-critical-windows-flaw-that-could-enable-accou/</guid>
      <description>Zoom has released security updates for a critical security flaw impacting Zoom Workplace for Windows that could facilitate account takeover. The vulnerability, tracked as CVE-2026-53412 (CVSS score: 9.8), affects Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. &amp;#34;Improper Input Validation in Zoom Desktop Client f</description>
    </item>
    <item>
      <title>Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-15-aws-security-audit-microsoft-patches-record-622-flaws-including-two-zero-days/</link>
      <pubDate>Wed, 15 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-15-aws-security-audit-microsoft-patches-record-622-flaws-including-two-zero-days/</guid>
      <description>Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft&amp;#39;s own CVEs by its Security Update Guide count, more than triple June&amp;#39;s previous high of around 200. Those two live bugs are the ones to grab first. Microsoft credits incident responders for b</description>
    </item>
    <item>
      <title>Apple says former employee exploited ‘rare’ bug to download confidential files after leaving...</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-14-aws-security-audit-apple-says-former-employee-exploited-rare-bug-to-download/</link>
      <pubDate>Tue, 14 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-14-aws-security-audit-apple-says-former-employee-exploited-rare-bug-to-download/</guid>
      <description>Apple would not comment on the &amp;#34;security breach,&amp;#34; which allegedly allowed a former employee to download sensitive files from Apple&amp;#39;s network long after he departed the company for rival OpenAI.</description>
    </item>
    <item>
      <title>iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-13-aws-security-audit-icagenda-and-balbooa-forms-joomla-flaws-reportedly-exploit/</link>
      <pubDate>Mon, 13 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-13-aws-security-audit-icagenda-and-balbooa-forms-joomla-flaws-reportedly-exploit/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below - CVE-2026-</description>
    </item>
    <item>
      <title>US cybersecurity agency CISA had to build its incident playbook during the incident, agency...</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-12-aws-security-audit-us-cybersecurity-agency-cisa-had-to-build-its-incident-pla/</link>
      <pubDate>Sun, 12 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-12-aws-security-audit-us-cybersecurity-agency-cisa-had-to-build-its-incident-pla/</guid>
      <description>Independent cybersecurity journalist Brian Krebs reported in May that a security researcher with cyber firm GitGuardian alerted him to reams of exposed passwords stored in a publicly accessible GitHub repository, which an employee of a CISA contractor had uploaded.</description>
    </item>
    <item>
      <title>Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-11-aws-security-audit-critical-zimbra-flaw-could-let-crafted-emails-run-maliciou/</link>
      <pubDate>Sat, 11 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-11-aws-security-audit-critical-zimbra-flaw-could-let-crafted-emails-run-maliciou/</guid>
      <description>Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user&amp;#39;s session. It has yet to b</description>
    </item>
    <item>
      <title>Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-10-aws-security-audit-ubiquiti-patches-critical-unifi-flaws-across-connect-talk/</link>
      <pubDate>Fri, 10 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-10-aws-security-audit-ubiquiti-patches-critical-unifi-flaws-across-connect-talk/</guid>
      <description>Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-50746 (CVSS score: 10.0) - An improper access control vulnerability in UniFi Con</description>
    </item>
    <item>
      <title>Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-09-aws-security-audit-microsoft-patches-rogueplanet-defender-flaw-that-can-grant/</link>
      <pubDate>Thu, 09 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-09-aws-security-audit-microsoft-patches-rogueplanet-defender-flaw-that-can-grant/</guid>
      <description>Microsoft has released security updates for a Defender vulnerability known as RoguePlanet, nearly a month after details of the flaw became public. The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine (&amp;#34;mpengine.dll&amp;#34;), which provides scanning, detection, and cleaning capabil</description>
    </item>
    <item>
      <title>Hacked, leaked, and held for ransom: The worst breaches of 2026 so far</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-08-aws-security-audit-hacked-leaked-and-held-for-ransom-the-worst-breaches-of-20/</link>
      <pubDate>Wed, 08 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-08-aws-security-audit-hacked-leaked-and-held-for-ransom-the-worst-breaches-of-20/</guid>
      <description>From a massive DOGE data breach and the hacking of critical energy and water systems to the hack of an FBI surveillance system, here are the most damaging security incidents and data breaches of 2026.</description>
    </item>
    <item>
      <title>BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-07-aws-security-audit-beyondtrust-patches-critical-auth-bypass-flaws-in-remote-s/</link>
      <pubDate>Tue, 07 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-07-aws-security-audit-beyondtrust-patches-critical-auth-bypass-flaws-in-remote-s/</guid>
      <description>BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices. The vulnerabilities are listed below - CVE-2026-40138 (CVSS score: 9.2) - A pre-authentication vulnerab</description>
    </item>
    <item>
      <title>U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-06-aws-security-audit-u-s-government-entity-paid-kairos-1-million-in-data-theft/</link>
      <pubDate>Mon, 06 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-06-aws-security-audit-u-s-government-entity-paid-kairos-1-million-in-data-theft/</guid>
      <description>A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money calls itself Kairos, but it may not be a ransomware gang at all. Krishnan found no si</description>
    </item>
    <item>
      <title>SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-05-aws-security-audit-sharepoint-rce-cve-2026-45659-added-to-cisa-kev-after-acti/</link>
      <pubDate>Sun, 05 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-05-aws-security-audit-sharepoint-rce-cve-2026-45659-added-to-cisa-kev-after-acti/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deseria</description>
    </item>
    <item>
      <title>New Avalon Malware Framework Packs CrownX Ransomware Capabilities</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-04-aws-security-audit-new-avalon-malware-framework-packs-crownx-ransomware-capab/</link>
      <pubDate>Sat, 04 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-04-aws-security-audit-new-avalon-malware-framework-packs-crownx-ransomware-capab/</guid>
      <description>Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that&amp;#39;s distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together</description>
    </item>
    <item>
      <title>Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-03-aws-security-audit-ransomware-groups-turn-to-citrix-bleed-2-byovd-and-supply/</link>
      <pubDate>Fri, 03 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-03-aws-security-audit-ransomware-groups-turn-to-citrix-bleed-2-byovd-and-supply/</guid>
      <description>Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. &amp;#34;Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyb</description>
    </item>
    <item>
      <title>AWS Artifact now includes Assurance Assistant for compliance inquiries</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-02-aws-security-audit-aws-artifact-now-includes-assurance-assistant-for-complian/</link>
      <pubDate>Thu, 02 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-02-aws-security-audit-aws-artifact-now-includes-assurance-assistant-for-complian/</guid>
      <description>AWS Artifact now includes Assurance Assistant, an AI-powered capability that generates citation-backed responses to security and compliance questions about AWS services. AWS Artifact is the service through which AWS provides compliance reports, certifications, and agreements to customers. Assurance Assistant helps third-party risk managers, compliance office</description>
    </item>
    <item>
      <title>Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints</title>
      <link>https://blog.itsdavidg.co/posts/2026-07-01-aws-security-audit-langflow-rce-exploited-to-deploy-monero-miner-on-exposed-a/</link>
      <pubDate>Wed, 01 Jul 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-07-01-aws-security-audit-langflow-rce-exploited-to-deploy-monero-miner-on-exposed-a/</guid>
      <description>Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed a</description>
    </item>
    <item>
      <title>Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-30-aws-security-audit-attackers-exploit-simplehelp-cve-2026-48558-to-deploy-task/</link>
      <pubDate>Tue, 30 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-30-aws-security-audit-attackers-exploit-simplehelp-cve-2026-48558-to-deploy-task/</guid>
      <description>An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (O</description>
    </item>
    <item>
      <title>Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-29-aws-security-audit-gamaredon-expands-ukraine-attacks-with-new-malware-and-clo/</link>
      <pubDate>Mon, 29 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-29-aws-security-audit-gamaredon-expands-ukraine-attacks-with-new-malware-and-clo/</guid>
      <description>A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025. Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Gamaredon against new targets, with most of them taking place in the second half o</description>
    </item>
    <item>
      <title>New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-28-aws-security-audit-new-dirtyclone-linux-kernel-flaw-lets-local-users-gain-roo/</link>
      <pubDate>Sun, 28 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-28-aws-security-audit-new-dirtyclone-linux-kernel-flaw-lets-local-users-gain-roo/</guid>
      <description>DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user corrupt file-backed memory through a cloned network packet and gain root. The patch</description>
    </item>
    <item>
      <title>CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-27-aws-security-audit-cisa-adds-exploited-ptc-windchill-rce-flaw-to-kev-as-web-s/</link>
      <pubDate>Sat, 27 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-27-aws-security-audit-cisa-adds-exploited-ptc-windchill-rce-flaw-to-kev-as-web-s/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.</description>
    </item>
    <item>
      <title>CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-26-aws-security-audit-cisa-warns-critical-lantronix-eds5000-flaw-is-being-active/</link>
      <pubDate>Fri, 26 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-26-aws-security-audit-cisa-warns-critical-lantronix-eds5000-flaw-is-being-active/</guid>
      <description>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026. The vulnerability in question is CVE-2025-67038 (CVSS score: 9.8), a code injection flaw</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-25-aws-security-audit-cisco-catalyst-sd-wan-zero-day-cve-2026-20245-exploited-to/</link>
      <pubDate>Thu, 25 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-25-aws-security-audit-cisco-catalyst-sd-wan-zero-day-cve-2026-20245-exploited-to/</guid>
      <description>An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrar</description>
    </item>
    <item>
      <title>Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-24-aws-security-audit-cisco-unified-cm-flaw-exploited-after-poc-reveals-file-wri/</link>
      <pubDate>Wed, 24 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-24-aws-security-audit-cisco-unified-cm-flaw-exploited-after-poc-reveals-file-wri/</guid>
      <description>Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could</description>
    </item>
    <item>
      <title>Shareholders sue Uber’s board over sexual assaults, other incidents</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-23-aws-security-audit-shareholders-sue-uber-s-board-over-sexual-assaults-other-i/</link>
      <pubDate>Tue, 23 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-23-aws-security-audit-shareholders-sue-uber-s-board-over-sexual-assaults-other-i/</guid>
      <description>The lawsuit, led by a Detroit pension fund, alleges Uber&amp;#39;s board and management has cut too many compliance corners, resulting in thousands of lawsuits.</description>
    </item>
    <item>
      <title>INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-22-aws-security-audit-interpol-warns-phishing-ransomware-and-ai-scams-are-rising/</link>
      <pubDate>Mon, 22 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-22-aws-security-audit-interpol-warns-phishing-ransomware-and-ai-scams-are-rising/</guid>
      <description>A new report from INTERPOL has revealed a &amp;#34;dramatic increase&amp;#34; in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity. According to INTERPOL&amp;#39;s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report, phishing has emerged</description>
    </item>
    <item>
      <title>F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-21-aws-security-audit-f5-patches-two-critical-nginx-open-source-flaws-enabling-r/</link>
      <pubDate>Sun, 21 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-21-aws-security-audit-f5-patches-two-critical-nginx-open-source-flaws-enabling-r/</guid>
      <description>F5 has released security updates to address two critical security flaws in NGINX Open Source that could be exploited to achieve code execution on affected systems. The vulnerabilities are listed below - CVE-2026-42530 (CVSS v4 score: 9.2) - A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker w</description>
    </item>
    <item>
      <title>Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-20-aws-security-audit-hackers-exploit-gravity-smtp-wordpress-plugin-bug-to-expos/</link>
      <pubDate>Sat, 20 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-20-aws-security-audit-hackers-exploit-gravity-smtp-wordpress-plugin-bug-to-expos/</guid>
      <description>Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that&amp;#39;s installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API ke</description>
    </item>
    <item>
      <title>Amazon EKS now supports customer-routed control plane egress</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-19-aws-security-audit-amazon-eks-now-supports-customer-routed-control-plane-egre/</link>
      <pubDate>Fri, 19 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-19-aws-security-audit-amazon-eks-now-supports-customer-routed-control-plane-egre/</guid>
      <description>Today, Amazon Elastic Kubernetes Service (Amazon EKS) introduces customer-routed control plane egress, a capability that lets you route outbound Kubernetes API server traffic through your own Amazon VPC. This includes admission webhook callbacks, OpenID Connect (OIDC) provider lookups, and aggregate API server requests. With customer-routed control plane egr</description>
    </item>
    <item>
      <title>Announcing Web Search on Amazon Bedrock AgentCore for Agentic Web Retrieval</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-18-aws-security-audit-announcing-web-search-on-amazon-bedrock-agentcore-for-agen/</link>
      <pubDate>Thu, 18 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-18-aws-security-audit-announcing-web-search-on-amazon-bedrock-agentcore-for-agen/</guid>
      <description>As AI agents become more capable, they need access to information beyond a model&amp;#39;s training data - to answer questions, retrieve latest facts, and take action grounded in current developments. Today, we&amp;#39;re making that easy with the general availability of Web Search on AgentCore. Web Search is a fully managed tool that enables agents to ground responses in c</description>
    </item>
    <item>
      <title>The Top 10 Attack Surface Exposures in 2026</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-17-aws-security-audit-the-top-10-attack-surface-exposures-in-2026/</link>
      <pubDate>Wed, 17 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-17-aws-security-audit-the-top-10-attack-surface-exposures-in-2026/</guid>
      <description>Breaches don&amp;#39;t always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk. Wit</description>
    </item>
    <item>
      <title>Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-16-aws-security-audit-attackers-exploit-three-fortinet-fortisandbox-flaws-one-pa/</link>
      <pubDate>Tue, 16 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-16-aws-security-audit-attackers-exploit-three-fortinet-fortisandbox-flaws-one-pa/</guid>
      <description>Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability</description>
    </item>
    <item>
      <title>Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-15-aws-security-audit-palo-alto-warns-of-active-exploitation-of-pan-os-globalpro/</link>
      <pubDate>Mon, 15 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-15-aws-security-audit-palo-alto-warns-of-active-exploitation-of-pan-os-globalpro/</guid>
      <description>Palo Alto Networks has revealed that it has observed &amp;#34;active exploitation&amp;#34; of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS softwar</description>
    </item>
    <item>
      <title>Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-14-aws-security-audit-critical-splunk-enterprise-flaw-lets-attackers-run-code-wi/</link>
      <pubDate>Sun, 14 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-14-aws-security-audit-critical-splunk-enterprise-flaw-lets-attackers-run-code-wi/</guid>
      <description>Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. &amp;#34;In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user</description>
    </item>
    <item>
      <title>Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-13-aws-security-audit-langflow-vulnerability-cve-2026-5027-exploited-for-unauthe/</link>
      <pubDate>Sat, 13 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-13-aws-security-audit-langflow-vulnerability-cve-2026-5027-exploited-for-unauthe/</guid>
      <description>A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of path traversal that could allow an attacker to write files to arbitrar</description>
    </item>
    <item>
      <title>ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-12-aws-security-audit-shinyhunters-exploits-oracle-peoplesoft-zero-day-cve-2026/</link>
      <pubDate>Fri, 12 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-12-aws-security-audit-shinyhunters-exploits-oracle-peoplesoft-zero-day-cve-2026/</guid>
      <description>The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google&amp;#39;s Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory un</description>
    </item>
    <item>
      <title>Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-11-aws-security-audit-ivanti-fortinet-and-sap-release-patches-for-multiple-criti/</link>
      <pubDate>Thu, 11 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-11-aws-security-audit-ivanti-fortinet-and-sap-release-patches-for-multiple-criti/</guid>
      <description>Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It&amp;#39;s tracked as CVE-2026-</description>
    </item>
    <item>
      <title>Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-10-aws-security-audit-chrome-v8-zero-day-cve-2026-11645-exploited-in-the-wild-pa/</link>
      <pubDate>Wed, 10 Jun 2026 12:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-10-aws-security-audit-chrome-v8-zero-day-cve-2026-11645-exploited-in-the-wild-pa/</guid>
      <description>Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Chrome&amp;#39;s JavaScript and WebAssembly engine. &amp;#34;Out-of-bounds read and write in V8 in Goog</description>
    </item>
    <item>
      <title>How to Reduce Your AWS Bill: A Practical Cost-Optimization Guide</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-10-how-to-reduce-aws-bill-cost-optimization-guide/</link>
      <pubDate>Wed, 10 Jun 2026 09:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-10-how-to-reduce-aws-bill-cost-optimization-guide/</guid>
      <description>A practical guide to AWS cost optimization - the highest-leverage ways to reduce your AWS bill without breaking production, from killing waste to commitment-based discounts.</description>
    </item>
    <item>
      <title>Fractional CTO Cost in 2026: What You Actually Pay (vs a Full-Time Hire)</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-10-fractional-cto-cost-pricing-guide/</link>
      <pubDate>Wed, 10 Jun 2026 08:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-10-fractional-cto-cost-pricing-guide/</guid>
      <description>A clear breakdown of fractional CTO cost and pricing models in 2026 - retainers, hourly, and pay-per-outcome - and how it compares to the fully loaded cost of a full-time CTO hire.</description>
    </item>
    <item>
      <title>AWS Security Audit Checklist: 30 Things to Check in 2026</title>
      <link>https://blog.itsdavidg.co/posts/2026-06-10-aws-security-audit-checklist-30-point-guide/</link>
      <pubDate>Wed, 10 Jun 2026 08:00:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/posts/2026-06-10-aws-security-audit-checklist-30-point-guide/</guid>
      <description>A practical, 30-point AWS security audit checklist covering IAM, network exposure, data protection, logging, and incident readiness - the same list used on real client accounts before findings worth more than the audit itself.</description>
    </item>
  </channel>
</rss>
