<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Suriq Blog</title><description>Deep-dives, comparisons, and incident replays from the engineers building autonomous defense.</description><link>https://suriq.io/</link><language>en-us</language><item><title>Three requests, no password, a webshell: the JCE flaw hitting Joomla hosts now</title><link>https://suriq.io/blog/joomla-jce-unauthenticated-rce/</link><guid isPermaLink="true">https://suriq.io/blog/joomla-jce-unauthenticated-rce/</guid><description>Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.</description><pubDate>Wed, 17 Jun 2026 05:20:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Linux backdoor moved into the Windows kernel, and the detection window closes at driver load</title><link>https://suriq.io/blog/sprysocks-windows-kernel-driver/</link><guid isPermaLink="true">https://suriq.io/blog/sprysocks-windows-kernel-driver/</guid><description>SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.</description><pubDate>Tue, 16 Jun 2026 19:40:47 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>LiteSpeed&apos;s cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn&apos;t help.</title><link>https://suriq.io/blog/litespeed-cpanel-plugin-root-escalation/</link><guid isPermaLink="true">https://suriq.io/blog/litespeed-cpanel-plugin-root-escalation/</guid><description>CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.</description><pubDate>Tue, 16 Jun 2026 07:13:38 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>Awesome Motive&apos;s WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.</title><link>https://suriq.io/blog/awesome-motive-wordpress-cdn-backdoor/</link><guid isPermaLink="true">https://suriq.io/blog/awesome-motive-wordpress-cdn-backdoor/</guid><description>OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.</description><pubDate>Mon, 15 Jun 2026 20:32:28 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>SearchLeak in Microsoft 365 Copilot: prompt injection as a new door to old bugs</title><link>https://suriq.io/blog/searchleak-copilot-prompt-injection/</link><guid isPermaLink="true">https://suriq.io/blog/searchleak-copilot-prompt-injection/</guid><description>SearchLeak chained prompt injection, an HTML render race, and Bing SSRF to steal Microsoft 365 Copilot data in one click. What it means for detection.</description><pubDate>Mon, 15 Jun 2026 19:25:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Why we built Suriq on Wazuh instead of writing our own detection engine</title><link>https://suriq.io/blog/why-suriq-built-on-wazuh/</link><guid isPermaLink="true">https://suriq.io/blog/why-suriq-built-on-wazuh/</guid><description>Suriq runs on Wazuh because a detection engine is a decade of decoders, CVE feeds, and agents you should never rebuild. Here is the reasoning behind the bet.</description><pubDate>Mon, 15 Jun 2026 07:42:14 GMT</pubDate><category>Thought leadership</category><category>Deep dive</category><author>Jack of Suriq</author></item><item><title>Ivanti Sentry&apos;s CVE-2026-10520: patch the gateway, then hunt for the breach</title><link>https://suriq.io/blog/ivanti-sentry-patched-still-breached/</link><guid isPermaLink="true">https://suriq.io/blog/ivanti-sentry-patched-still-breached/</guid><description>Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA&apos;s new 3-day patch rule applies; patched gateways were already breached.</description><pubDate>Sun, 14 Jun 2026 07:06:06 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Jack of Suriq</author></item><item><title>PeopleSoft&apos;s PSEMHUB zero-day turns the patch service into the breach</title><link>https://suriq.io/blog/peoplesoft-psemhub-zero-day/</link><guid isPermaLink="true">https://suriq.io/blog/peoplesoft-psemhub-zero-day/</guid><description>CVE-2026-35273 sits in PeopleSoft&apos;s Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.</description><pubDate>Sat, 13 Jun 2026 18:38:12 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Jack of Suriq</author></item><item><title>Velvet Ant&apos;s PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug</title><link>https://suriq.io/blog/velvet-ant-auth-stack-blind-spot/</link><guid isPermaLink="true">https://suriq.io/blog/velvet-ant-auth-stack-blind-spot/</guid><description>Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.</description><pubDate>Sat, 13 Jun 2026 17:01:32 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Jack of Suriq</author></item></channel></rss>