<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Suriq Blog</title><description>Deep-dives, comparisons, and incident replays from the engineers building autonomous defense.</description><link>https://suriq.io/</link><language>en-us</language><item><title>Older iPhones just got a flaw Apple can&apos;t patch, and a cable is all it takes</title><link>https://suriq.io/blog/usbliter8-apple-bootrom-unpatchable-exploit/</link><guid isPermaLink="true">https://suriq.io/blog/usbliter8-apple-bootrom-unpatchable-exploit/</guid><description>usbliter8 is an unpatchable boot-chain exploit for Apple A12 and A13 devices. Here is the real enterprise risk, why remote wipe will not help, and what to do.</description><pubDate>Mon, 22 Jun 2026 15:31:48 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>PaperCut&apos;s Windows print client can be tricked into giving a local attacker total control</title><link>https://suriq.io/blog/papercut-print-deploy-local-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/papercut-print-deploy-local-takeover/</guid><description>CVE-2026-6645 lets a local attacker plant a file that PaperCut&apos;s Print Deploy client runs with full system rights on Windows. Update to version 1.10.4178.</description><pubDate>Mon, 22 Jun 2026 04:25:17 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Run Central Dogma across servers? It may be guarding your config with a password printed in its source code</title><link>https://suriq.io/blog/central-dogma-default-secret-cluster-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/central-dogma-default-secret-cluster-takeover/</guid><description>Central Dogma before 0.84.0 silently uses a public default secret when ZooKeeper replication runs without one set, letting nearby attackers seize the cluster.</description><pubDate>Mon, 22 Jun 2026 03:10:10 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Your Squid proxy can leak other users&apos; passwords, and the 7.6 update won&apos;t fix it</title><link>https://suriq.io/blog/squidbleed-squid-proxy-credential-leak/</link><guid isPermaLink="true">https://suriq.io/blog/squidbleed-squid-proxy-credential-leak/</guid><description>Squidbleed (CVE-2026-47729) leaks memory from Squid proxies in default config, including login credentials. A public exploit is out, and 7.6 does not patch it.</description><pubDate>Mon, 22 Jun 2026 00:08:18 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>That decade-old router you forgot is now scanning networks for attackers</title><link>https://suriq.io/blog/arystinger-router-botnet-recon-scanning/</link><guid isPermaLink="true">https://suriq.io/blog/arystinger-router-botnet-recon-scanning/</guid><description>A botnet called AryStinger hijacked over 4,300 end-of-life D-Link and Linksys routers into a distributed scanning grid for reconnaissance, not DDoS. What to do.</description><pubDate>Sun, 21 Jun 2026 18:35:49 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Millions of hacked TV boxes now rent attackers a trusted home IP. Your blocklist can&apos;t see it.</title><link>https://suriq.io/blog/popa-residential-proxy-ip-reputation-account-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/popa-residential-proxy-ip-reputation-account-takeover/</guid><description>Researchers linked the Popa botnet of 2 million hacked TV boxes to a residential proxy service. Here is why IP reputation no longer stops account takeovers.</description><pubDate>Sun, 21 Jun 2026 16:52:26 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Prinz Eugen ransomware hits your newest files first and never leaves a note</title><link>https://suriq.io/blog/prinz-eugen-ransomware-no-ransom-note/</link><guid isPermaLink="true">https://suriq.io/blog/prinz-eugen-ransomware-no-ransom-note/</guid><description>Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.</description><pubDate>Sun, 21 Jun 2026 11:51:28 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>EaseUS Partition Master left a Windows driver that lets any user seize the whole PC</title><link>https://suriq.io/blog/easeus-partition-master-driver-escalation/</link><guid isPermaLink="true">https://suriq.io/blog/easeus-partition-master-driver-escalation/</guid><description>A signed driver in EaseUS Partition Master (CVE-2026-12781) lets any standard Windows user read and overwrite the whole disk to reach SYSTEM. Patch and block</description><pubDate>Sun, 21 Jun 2026 09:55:36 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Your AI agent trusts your own computer. One web page turns that into a takeover.</title><link>https://suriq.io/blog/autojack-ai-agent-localhost-rce/</link><guid isPermaLink="true">https://suriq.io/blog/autojack-ai-agent-localhost-rce/</guid><description>Microsoft&apos;s AutoJack shows how one web page an AI browsing agent visits can run code on the host. The bug is a near miss. The architecture lesson is not.</description><pubDate>Sun, 21 Jun 2026 07:46:22 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>This login library let a stranger sign in as you with just your email</title><link>https://suriq.io/blog/ash-authentication-email-account-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/ash-authentication-email-account-takeover/</guid><description>CVE-2026-49757 (CVSS 9.2) let attackers take over accounts in Elixir apps built on ash_authentication by matching users on email instead of identity. Update</description><pubDate>Sun, 21 Jun 2026 07:24:16 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Your Fortinet password reset won&apos;t lock the FortiBleed attacker out</title><link>https://suriq.io/blog/fortibleed-cisa-alert-session-reset/</link><guid isPermaLink="true">https://suriq.io/blog/fortibleed-cisa-alert-session-reset/</guid><description>CISA declared FortiBleed an emergency on June 18 after 86,644 Fortinet devices were hit. Resetting passwords is not enough: kill live sessions and fix the</description><pubDate>Sun, 21 Jun 2026 03:18:09 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>vLLM&apos;s earlier patch only hid this AI-server bug. Re-enable embeddings and you are still exposed</title><link>https://suriq.io/blog/vllm-prompt-embeds-tensor-validation-flaw/</link><guid isPermaLink="true">https://suriq.io/blog/vllm-prompt-embeds-tensor-validation-flaw/</guid><description>CVE-2026-56340 lets a crafted tensor crash vLLM (CVSS 8.8) with a path to memory corruption. It only bites if you re-enabled prompt embeds. Fix is 0.13.0.</description><pubDate>Sun, 21 Jun 2026 02:55:23 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Gravity SMTP&apos;s &apos;medium&apos; bug leaks live email API keys to anyone. Patching alone will not save you.</title><link>https://suriq.io/blog/gravity-smtp-credential-leak-cve-2026-4020/</link><guid isPermaLink="true">https://suriq.io/blog/gravity-smtp-credential-leak-cve-2026-4020/</guid><description>Gravity SMTP&apos;s CVE-2026-4020 hands live Amazon SES, Google, and OAuth keys to unauthenticated visitors on 100,000 WordPress sites. Patching alone will not undo</description><pubDate>Sat, 20 Jun 2026 16:51:58 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Police scrubbed SocGholish from 15,000 WordPress sites. The way in is still wide open.</title><link>https://suriq.io/blog/socgholish-operation-endgame-wordpress-takedown/</link><guid isPermaLink="true">https://suriq.io/blog/socgholish-operation-endgame-wordpress-takedown/</guid><description>Operation Endgame seized 106 SocGholish servers and cleaned 14,971 WordPress sites. The takedown hit an access broker, not the entry vector. Here is what to</description><pubDate>Sat, 20 Jun 2026 12:19:16 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>One tracing header can make a LangSmith server hand over its files</title><link>https://suriq.io/blog/langsmith-tracing-header-file-read/</link><guid isPermaLink="true">https://suriq.io/blog/langsmith-tracing-header-file-read/</guid><description>LangSmith SDK before 0.8.18 lets a crafted tracing header read arbitrary files off any server running TracingMiddleware. Upgrade now; it is the second such bug.</description><pubDate>Sat, 20 Jun 2026 09:09:23 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires</title><link>https://suriq.io/blog/usb-worm-clipper-crypto-clipboard/</link><guid isPermaLink="true">https://suriq.io/blog/usb-worm-clipper-crypto-clipboard/</guid><description>Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.</description><pubDate>Sat, 20 Jun 2026 07:43:38 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>The app you&apos;re testing can hijack the AI agent testing it: Appium MCP&apos;s XSS flaw</title><link>https://suriq.io/blog/appium-mcp-locator-xss-agent-hijack/</link><guid isPermaLink="true">https://suriq.io/blog/appium-mcp-locator-xss-agent-hijack/</guid><description>An XSS flaw in Appium&apos;s official MCP server let a hostile test app hijack the AI agent driving it and call its tools. Patch appium-mcp to 1.85.10 now.</description><pubDate>Sat, 20 Jun 2026 07:10:40 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>EDR evasion is now a shipped product. Your agent&apos;s silence is the only alarm left.</title><link>https://suriq.io/blog/gentlemen-edr-killer-byovd-detection/</link><guid isPermaLink="true">https://suriq.io/blog/gentlemen-edr-killer-byovd-detection/</guid><description>The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.</description><pubDate>Sat, 20 Jun 2026 04:42:29 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>Branda fixed this WordPress account takeover in January. It is back, and a public exploit is circulating.</title><link>https://suriq.io/blog/branda-wordpress-account-takeover-cve-2026-11551/</link><guid isPermaLink="true">https://suriq.io/blog/branda-wordpress-account-takeover-cve-2026-11551/</guid><description>CVE-2026-11551 is a CVSS 9.8 unauthenticated account takeover in the Branda WordPress plugin (versions up to 3.4.29). A public exploit is out. Update to 3.4.31</description><pubDate>Sat, 20 Jun 2026 03:56:36 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A WordPress form plugin lets a stranger delete your site, the moment an admin looks</title><link>https://suriq.io/blog/wordpress-form-entries-file-deletion-rce/</link><guid isPermaLink="true">https://suriq.io/blog/wordpress-form-entries-file-deletion-rce/</guid><description>CVE-2026-9843 lets an unauthenticated visitor plant a form entry that deletes WordPress files when an admin opens it. Update the CRM Perks entries plugin to</description><pubDate>Sat, 20 Jun 2026 02:40:19 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A single rigged document can turn Langflow&apos;s file reader into full server takeover</title><link>https://suriq.io/blog/langflow-rag-file-read-rce/</link><guid isPermaLink="true">https://suriq.io/blog/langflow-rag-file-read-rce/</guid><description>A crafted document in a Langflow RAG pipeline (CVE-2026-55447, CVSS 9.6) reads any file, forges a login token, then runs code. Upgrade to 1.9.2 or later.</description><pubDate>Sat, 20 Jun 2026 01:25:41 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>One Langflow account can now run every other user&apos;s AI workflow</title><link>https://suriq.io/blog/langflow-idor-cross-user-flow-execution/</link><guid isPermaLink="true">https://suriq.io/blog/langflow-idor-cross-user-flow-execution/</guid><description>A critical IDOR in Langflow (CVE-2026-55255, CVSS 9.9) lets any logged-in user run another user&apos;s AI flow. Upgrade to 1.9.1. The real problem is the pattern.</description><pubDate>Fri, 19 Jun 2026 23:53:51 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Mastra&apos;s npm packages passed inspection, then turned hostile a day later</title><link>https://suriq.io/blog/mastra-npm-supply-chain-compromise/</link><guid isPermaLink="true">https://suriq.io/blog/mastra-npm-supply-chain-compromise/</guid><description>Attackers hijacked a dormant maintainer account to poison 140+ Mastra npm packages with a wallet-stealing payload. Here is who is exposed and what to rotate</description><pubDate>Fri, 19 Jun 2026 22:55:50 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>CoreWCF&apos;s SAML check trusted a forged identity as your admin. There is no workaround, only the patch.</title><link>https://suriq.io/blog/corewcf-saml-signature-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/corewcf-saml-signature-bypass/</guid><description>CVE-2026-54782 lets an attacker forge a SAML token and impersonate anyone, admins included, on CoreWCF federation services. No workaround. Patch to 1.8.1 or</description><pubDate>Fri, 19 Jun 2026 21:55:54 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Quarkus fixed a semicolon auth bypass in May. Its encoded cousin just reopened it.</title><link>https://suriq.io/blog/quarkus-encoded-path-auth-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/quarkus-encoded-path-auth-bypass/</guid><description>Quarkus fixed a semicolon authorization bypass in May, but CVE-2026-50559 reopens it with URL-encoded characters. What to patch now and how to detect abuse.</description><pubDate>Fri, 19 Jun 2026 20:56:09 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.</title><link>https://suriq.io/blog/dragonforce-teams-relay-c2-backdoor-turn/</link><guid isPermaLink="true">https://suriq.io/blog/dragonforce-teams-relay-c2-backdoor-turn/</guid><description>DragonForce&apos;s Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft. Here is where the detectable seam actually</description><pubDate>Fri, 19 Jun 2026 19:34:51 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Your Salesforce wasn&apos;t breached. A connected app handed over the data.</title><link>https://suriq.io/blog/klue-oauth-salesforce-connected-app-breach/</link><guid isPermaLink="true">https://suriq.io/blog/klue-oauth-salesforce-connected-app-breach/</guid><description>The Icarus group stole Salesforce CRM data through Klue&apos;s connected app, not a Salesforce flaw. Why OAuth integration tokens are the unmonitored attack surface.</description><pubDate>Fri, 19 Jun 2026 14:50:51 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Your JetBrains Hub 2FA protected nothing. The recovery codes were predictable.</title><link>https://suriq.io/blog/jetbrains-hub-predictable-recovery-codes/</link><guid isPermaLink="true">https://suriq.io/blog/jetbrains-hub-predictable-recovery-codes/</guid><description>JetBrains Hub generated predictable 2FA recovery codes (CVE-2026-56141, CVSS 9.8), allowing pre-auth account takeover. Patch self-hosted Hub now and reset the</description><pubDate>Fri, 19 Jun 2026 13:37:56 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Perry&apos;s stdlib turned off JWT expiry checks. Logout stopped meaning anything.</title><link>https://suriq.io/blog/perry-jwt-expiration-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/perry-jwt-expiration-bypass/</guid><description>CVE-2026-53776: Perry&apos;s bundled JWT helper hard-codes validate_exp = false, so expired and revoked tokens stay valid. Patch to 0.5.1166 and rotate signing keys.</description><pubDate>Fri, 19 Jun 2026 10:59:11 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Your Splunk box runs a database sidecar you never configured. Attackers use it for root.</title><link>https://suriq.io/blog/splunk-postgres-sidecar-preauth-rce/</link><guid isPermaLink="true">https://suriq.io/blog/splunk-postgres-sidecar-preauth-rce/</guid><description>CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.</description><pubDate>Fri, 19 Jun 2026 07:42:37 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Two NGINX bugs scored 9.2. On a default server you get a crash, not a shell.</title><link>https://suriq.io/blog/nginx-critical-rce-config-triage/</link><guid isPermaLink="true">https://suriq.io/blog/nginx-critical-rce-config-triage/</guid><description>F5&apos;s two critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) score 9.2, but RCE needs ASLR off and a non-default config. Here is what to actually triage.</description><pubDate>Fri, 19 Jun 2026 03:45:04 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>INC ransomware never used a zero-day. It used your patch backlog.</title><link>https://suriq.io/blog/inc-ransomware-patch-backlog-edge-devices/</link><guid isPermaLink="true">https://suriq.io/blog/inc-ransomware-patch-backlog-edge-devices/</guid><description>INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.</description><pubDate>Thu, 18 Jun 2026 16:56:17 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect</title><link>https://suriq.io/blog/clickfix-shared-delivery-detection/</link><guid isPermaLink="true">https://suriq.io/blog/clickfix-shared-delivery-detection/</guid><description>Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.</description><pubDate>Thu, 18 Jun 2026 12:10:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.</title><link>https://suriq.io/blog/cisco-sd-wan-manager-cve-2026-20262/</link><guid isPermaLink="true">https://suriq.io/blog/cisco-sd-wan-manager-cve-2026-20262/</guid><description>CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root. Federal patch deadline is June 29, and why 6.5</description><pubDate>Thu, 18 Jun 2026 08:11:51 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>RoguePlanet turns Microsoft Defender into a SYSTEM shell, and switching it off won&apos;t save you</title><link>https://suriq.io/blog/rogueplanet-defender-system-zero-day/</link><guid isPermaLink="true">https://suriq.io/blog/rogueplanet-defender-system-zero-day/</guid><description>RoguePlanet (CVE-2026-50656) is a public-exploit privilege escalation in Microsoft Defender&apos;s engine. It hands a local attacker SYSTEM, and disabling Defender</description><pubDate>Thu, 18 Jun 2026 05:50:21 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>FortiBleed isn&apos;t a Fortinet bug. It&apos;s every password you never rotated.</title><link>https://suriq.io/blog/fortibleed-fortinet-no-cve-to-patch/</link><guid isPermaLink="true">https://suriq.io/blog/fortibleed-fortinet-no-cve-to-patch/</guid><description>FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.</description><pubDate>Wed, 17 Jun 2026 19:12:55 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>JetBrains Plugins Are Stealing AI API Keys, and You Find Out From the Bill</title><link>https://suriq.io/blog/jetbrains-plugins-steal-ai-api-keys/</link><guid isPermaLink="true">https://suriq.io/blog/jetbrains-plugins-steal-ai-api-keys/</guid><description>Aikido found 15 JetBrains Marketplace plugins stealing AI API keys across 70,000 installs. Why a stolen metered key shows up as a bill, not an alert, and what</description><pubDate>Wed, 17 Jun 2026 15:04:54 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In</title><link>https://suriq.io/blog/fortisandbox-flaws-actively-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/fortisandbox-flaws-actively-exploited/</guid><description>Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago. Why a compromised malware sandbox blinds your</description><pubDate>Wed, 17 Jun 2026 11:08:44 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Three requests, no password, a webshell: the JCE flaw hitting Joomla hosts now</title><link>https://suriq.io/blog/joomla-jce-unauthenticated-rce/</link><guid isPermaLink="true">https://suriq.io/blog/joomla-jce-unauthenticated-rce/</guid><description>Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.</description><pubDate>Wed, 17 Jun 2026 05:20:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Linux backdoor moved into the Windows kernel, and the detection window closes at driver load</title><link>https://suriq.io/blog/sprysocks-windows-kernel-driver/</link><guid isPermaLink="true">https://suriq.io/blog/sprysocks-windows-kernel-driver/</guid><description>SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.</description><pubDate>Tue, 16 Jun 2026 19:40:47 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>LiteSpeed&apos;s cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn&apos;t help.</title><link>https://suriq.io/blog/litespeed-cpanel-plugin-root-escalation/</link><guid isPermaLink="true">https://suriq.io/blog/litespeed-cpanel-plugin-root-escalation/</guid><description>CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.</description><pubDate>Tue, 16 Jun 2026 07:13:38 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>Awesome Motive&apos;s WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.</title><link>https://suriq.io/blog/awesome-motive-wordpress-cdn-backdoor/</link><guid isPermaLink="true">https://suriq.io/blog/awesome-motive-wordpress-cdn-backdoor/</guid><description>OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.</description><pubDate>Mon, 15 Jun 2026 20:32:28 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>SearchLeak in Microsoft 365 Copilot: prompt injection as a new door to old bugs</title><link>https://suriq.io/blog/searchleak-copilot-prompt-injection/</link><guid isPermaLink="true">https://suriq.io/blog/searchleak-copilot-prompt-injection/</guid><description>SearchLeak chained prompt injection, an HTML render race, and Bing SSRF to steal Microsoft 365 Copilot data in one click. What it means for detection.</description><pubDate>Mon, 15 Jun 2026 19:25:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Why we built Suriq on Wazuh instead of writing our own detection engine</title><link>https://suriq.io/blog/why-suriq-built-on-wazuh/</link><guid isPermaLink="true">https://suriq.io/blog/why-suriq-built-on-wazuh/</guid><description>Suriq runs on Wazuh because a detection engine is a decade of decoders, CVE feeds, and agents you should never rebuild. Here is the reasoning behind the bet.</description><pubDate>Mon, 15 Jun 2026 07:42:14 GMT</pubDate><category>Thought leadership</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Ivanti Sentry&apos;s CVE-2026-10520: patch the gateway, then hunt for the breach</title><link>https://suriq.io/blog/ivanti-sentry-patched-still-breached/</link><guid isPermaLink="true">https://suriq.io/blog/ivanti-sentry-patched-still-breached/</guid><description>Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA&apos;s new 3-day patch rule applies; patched gateways were already breached.</description><pubDate>Sun, 14 Jun 2026 07:06:06 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>PeopleSoft&apos;s PSEMHUB zero-day turns the patch service into the breach</title><link>https://suriq.io/blog/peoplesoft-psemhub-zero-day/</link><guid isPermaLink="true">https://suriq.io/blog/peoplesoft-psemhub-zero-day/</guid><description>CVE-2026-35273 sits in PeopleSoft&apos;s Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.</description><pubDate>Sat, 13 Jun 2026 18:38:12 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Velvet Ant&apos;s PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug</title><link>https://suriq.io/blog/velvet-ant-auth-stack-blind-spot/</link><guid isPermaLink="true">https://suriq.io/blog/velvet-ant-auth-stack-blind-spot/</guid><description>Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.</description><pubDate>Sat, 13 Jun 2026 17:01:32 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item></channel></rss>