<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Brandefense</title>
	<atom:link href="https://brandefense.io/feed/" rel="self" type="application/rss+xml" />
	<link>https://brandefense.io</link>
	<description>Digital Risk Protection Services Platform</description>
	<lastBuildDate>Thu, 01 Oct 2026 15:13:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>The Credential You Published on Purpose: How an Exposed GitLab Email Token Becomes Push Access to Main</title>
		<link>https://brandefense.io/blog/gitlab-incoming-email-token-exposure/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[brand protection]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[easm]]></category>
		<category><![CDATA[intelligence]]></category>
		<category><![CDATA[security awareness]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36785</guid>

					<description><![CDATA[A GitLab incoming email token published in a README never expires and works at account level. Learn how the attack path works, how to reset the token, and how to audit your repositories.]]></description>
		
		
		
			</item>
		<item>
		<title>Two NetScaler Zero-Days, One Wrong Assumption: Why Patching Does Not Close the Incident</title>
		<link>https://brandefense.io/blog/netscaler-zero-day-cve-2026-88771-response/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Thu, 01 Oct 2026 12:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[brand protection]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[drps]]></category>
		<category><![CDATA[exposure management]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36720</guid>

					<description><![CDATA[Citrix fixed two actively exploited NetScaler zero-day flaws, but a patch does not remove an attacker already inside. Seven steps from patch to closure.]]></description>
		
		
		
			</item>
		<item>
		<title>CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Zero-Day Under Active Exploitation</title>
		<link>https://brandefense.io/blog/cve-2026-76461-email-gateway-sql-injection/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 07:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[dark web monitoring]]></category>
		<category><![CDATA[drps]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36584</guid>

					<description><![CDATA[A CVSS 9.8 SQL injection in Cisco Secure Email Gateway (CVE-2026-76461) lets an attacker gain root access with a single crafted email — no authentication, no workaround. Here's what's exploitable, what to check, and how to patch.]]></description>
		
		
		
			</item>
		<item>
		<title>The Leak Site Got Breached: What ShinyHunters&#8217; Takeover of Clop Means for the Companies Listed on It</title>
		<link>https://brandefense.io/blog/ransomware-leak-site-clop-shinyhunters/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 07:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[drps]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[threat intellgence]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36579</guid>

					<description><![CDATA[ShinyHunters says it breached Clop's ransomware leak site and holds the keys to its Tor onion service. Here's what that means for every organisation still listed on it.]]></description>
		
		
		
			</item>
		<item>
		<title>Your Identity Programme Was Built for People. Non-Human Identity Is Now the Leading Way In.</title>
		<link>https://brandefense.io/blog/non-human-identity-leading-entry-point/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Mon, 21 Sep 2026 07:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[brand protection]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[intelligence]]></category>
		<category><![CDATA[security awareness]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36499</guid>

					<description><![CDATA[New research shows compromised non-human identity now drives more breaches than phishing. See why service accounts, API keys, and AI agents are the entry point most identity programmes still cannot see.]]></description>
		
		
		
			</item>
		<item>
		<title>The Phishing Came From Your Real Domain: What a Marketing Platform Breach Does to Brand Trust</title>
		<link>https://brandefense.io/blog/marketing-platform-breach-trusted-sender/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 07:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[brand protection]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[drps]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing attack]]></category>
		<category><![CDATA[phishing email]]></category>
		<category><![CDATA[third party risk management]]></category>
		<category><![CDATA[third-party risk]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36492</guid>

					<description><![CDATA[An attacker breached a marketing platform and sent phishing emails from a hardware wallet maker's genuine domain to 347,000 subscribers. Every technical control that checks for forgery passed, because nothing was forged.]]></description>
		
		
		
			</item>
		<item>
		<title>Passwordless Is Not Takeover Proof: Where Passkey Attacks Actually Land</title>
		<link>https://brandefense.io/blog/passkey-attacks-account-takeover-passwordless/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 07:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[account takeover attack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[phishing]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36487</guid>

					<description><![CDATA[Passkey attacks published this year do not break the cryptography. They target the sync fabric, the recovery path, and the enrolment step instead — the parts a passwordless migration usually leaves unmonitored.]]></description>
		
		
		
			</item>
		<item>
		<title>Your Security Vendors Are Your Highest-Privilege Third Parties, and Your TPRM Program Scores Them Low</title>
		<link>https://brandefense.io/blog/security-vendor-risk-tprm/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 07:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[brand protection]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[third party risk management]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36474</guid>

					<description><![CDATA[Security vendors sit at the top of the privilege ladder, yet TPRM programs consistently score them low because certification substitution and category heuristics mask the real question: what does an attacker inherit if this vendor is compromised?]]></description>
		
		
		
			</item>
		<item>
		<title>Agentic Ransomware: What Happens When Malware Doesn&#8217;t Need a Human Operator to Decide Who to Hit Next?</title>
		<link>https://brandefense.io/blog/agentic-ransomware-autonomous-attack-defense/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 10:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[brand protection]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[drps]]></category>
		<category><![CDATA[exposure management]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36466</guid>

					<description><![CDATA[A documented ransomware operation completed reconnaissance, credential theft, lateral movement, and encryption with no human operator at any stage. This analysis breaks down the JADEPUFFER intrusion end to end: the Langflow vulnerability that opened the door, how an autonomous LLM agent adapted mid-attack, and what defense architecture needs to look like when breakout is measured in minutes.]]></description>
		
		
		
			</item>
		<item>
		<title>When Abandoned Digital Assets Become Someone Else&#8217;s Infrastructure</title>
		<link>https://brandefense.io/blog/abandoned-digital-assets-ai-infrastructure/</link>
		
		<dc:creator><![CDATA[Brandefense]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 07:00:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[attack surface management]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[easm]]></category>
		<category><![CDATA[security awareness]]></category>
		<guid isPermaLink="false">https://brandefense.io/?p=36445</guid>

					<description><![CDATA[A 25-year-old wiki sat forgotten for years, then quietly became AI agent infrastructure: 18,000 posts in 52 days, unnoticed. Abandoned digital assets stay accessible and unmonitored while still carrying your organization's name.]]></description>
		
		
		
			</item>
	</channel>
</rss>
