<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cybersecurity on Sammy Farida</title><link>https://me.itsecurity.network/tags/cybersecurity/</link><description>Recent content in Cybersecurity on Sammy Farida</description><generator>Hugo -- 0.147.3</generator><language>en</language><lastBuildDate>Sun, 01 Mar 2026 00:00:00 -0500</lastBuildDate><atom:link href="https://me.itsecurity.network/tags/cybersecurity/index.xml" rel="self" type="application/rss+xml"/><item><title>Agent Skills: The New Supply Chain Attack Vector</title><link>https://me.itsecurity.network/blog/agent-skills-the-new-supply-chain-attack-vector/</link><pubDate>Sun, 01 Mar 2026 00:00:00 -0500</pubDate><guid>https://me.itsecurity.network/blog/agent-skills-the-new-supply-chain-attack-vector/</guid><description>AI agent skills marketplaces like ClawHub and OpenClaw promise productivity magic but hide malware risks. These ecosystems bypass traditional supply chain defenses, enabling prompt injection, credential theft, and silent data exfiltration.</description></item><item><title>Sigma Rules Decoded: Building Effective Threat Detection at Scale</title><link>https://me.itsecurity.network/blog/sigma-rules-decoded/</link><pubDate>Sun, 21 Sep 2025 07:01:23 -0400</pubDate><guid>https://me.itsecurity.network/blog/sigma-rules-decoded/</guid><description>A practical guide to implementing Sigma rules for vendor-agnostic threat detection that actually works, with strategies to overcome common challenges and build a mature detection engineering practice.</description></item><item><title>From Blind Spots to Insights: The CDM Revolution</title><link>https://me.itsecurity.network/blog/from-blind-spots-to-insights-the-cdm-revolution/</link><pubDate>Fri, 19 Sep 2025 07:00:46 -0400</pubDate><guid>https://me.itsecurity.network/blog/from-blind-spots-to-insights-the-cdm-revolution/</guid><description>How Continuous Diagnostics and Mitigation (CDM) is transforming security assessment by replacing inadequate point-in-time testing with real-time visibility, reducing breach detection times by 76% and eliminating critical security blind spots.</description></item><item><title>SolarWinds: Supply Chain Trust Betrayal</title><link>https://me.itsecurity.network/blog/solarwinds-supply-chain-trust-betrayal/</link><pubDate>Tue, 26 Aug 2025 07:00:41 -0400</pubDate><guid>https://me.itsecurity.network/blog/solarwinds-supply-chain-trust-betrayal/</guid><description>A technical deep dive into the SolarWinds attack, examining how attackers compromised the software supply chain and providing actionable security architecture principles to prevent similar attacks.</description></item><item><title>From Engineer to Business Security Partner: Bridging the Technical to Business Gap</title><link>https://me.itsecurity.network/blog/from-engineer-to-business-security-partner/</link><pubDate>Mon, 25 Aug 2025 07:00:32 -0400</pubDate><guid>https://me.itsecurity.network/blog/from-engineer-to-business-security-partner/</guid><description>How security professionals evolve beyond technical excellence to become strategic business partners by speaking the language of outcomes, quantifying risk, and aligning to revenue and growth.</description></item><item><title>The 15-Minute Incident Response Playbook (Based on NIST)</title><link>https://me.itsecurity.network/blog/the-15-minute-incident-response-playbook/</link><pubDate>Wed, 20 Aug 2025 07:01:12 -0400</pubDate><guid>https://me.itsecurity.network/blog/the-15-minute-incident-response-playbook/</guid><description>A concise, action-oriented incident response playbook based on the NIST framework. Learn how security teams can respond confidently to ransomware, data breaches, and insider threats in just 15 minutes.</description></item><item><title>The PAW Architecture Blueprint</title><link>https://me.itsecurity.network/blog/the-paw-architecture-blueprint/</link><pubDate>Tue, 19 Aug 2025 21:29:27 -0400</pubDate><guid>https://me.itsecurity.network/blog/the-paw-architecture-blueprint/</guid><description>A deep dive into the Privileged Access Workstation (PAW) architecture, a critical security model for protecting high-value administrator accounts from credential theft and lateral movement.</description></item><item><title>The Duolingo API Security Blunder</title><link>https://me.itsecurity.network/blog/the-duolingo-api-security-blunder/</link><pubDate>Fri, 15 Aug 2025 08:37:37 -0400</pubDate><guid>https://me.itsecurity.network/blog/the-duolingo-api-security-blunder/</guid><description>A deep dive into the 2024 Duolingo API breach, breaking down the architectural flaws that exposed 2.6 million users and providing actionable API security principles to prevent similar incidents.</description></item><item><title>Change Healthcare Ransomware Breakdown</title><link>https://me.itsecurity.network/blog/change-healthcare-ransomware-breakdown/</link><pubDate>Wed, 13 Aug 2025 22:14:31 -0400</pubDate><guid>https://me.itsecurity.network/blog/change-healthcare-ransomware-breakdown/</guid><description>The 2024 Change Healthcare ransomware attack exposed how a single missing control MFA on remote access systems led to the largest healthcare data breach in history. This post analyzes the architectural failures that allowed attackers to compromise 190 million patient records.</description></item><item><title>Microsoft's Zero Trust Transformation: A Case Study</title><link>https://me.itsecurity.network/blog/microsoft-zero-trust-transformation/</link><pubDate>Mon, 11 Aug 2025 00:56:53 -0400</pubDate><guid>https://me.itsecurity.network/blog/microsoft-zero-trust-transformation/</guid><description>A deep dive into Microsoft&amp;#39;s Zero Trust security model, breaking down their implementation into actionable phases for any organization looking to modernize its security architecture.</description></item><item><title>MITRE D3FEND: Bridging Attack &amp; Defense</title><link>https://me.itsecurity.network/blog/mitre-d3fend-bridging-attack-and-defense/</link><pubDate>Mon, 11 Aug 2025 00:24:24 -0400</pubDate><guid>https://me.itsecurity.network/blog/mitre-d3fend-bridging-attack-and-defense/</guid><description>MITRE D3FEND is the defensive complement to the popular ATT&amp;amp;CK framework. Learn how blue teams can map countermeasures directly to adversary techniques for a more effective defense.</description></item><item><title>The Silent Crypto Crisis</title><link>https://me.itsecurity.network/blog/the-silent-crypto-crisis/</link><pubDate>Sat, 09 Aug 2025 00:00:53 -0400</pubDate><guid>https://me.itsecurity.network/blog/the-silent-crypto-crisis/</guid><description>A deep dive into why cryptographic key management is a critical but often overlooked security control, examining major breaches and providing a practical framework for robust key lifecycle management.</description></item><item><title>AI Security Snake Oil: Seeing Through the Hype</title><link>https://me.itsecurity.network/blog/ai-security-snake-oil/</link><pubDate>Wed, 06 Aug 2025 00:28:54 -0400</pubDate><guid>https://me.itsecurity.network/blog/ai-security-snake-oil/</guid><description>A critical look at how vendors are overhyping AI in security, and how to distinguish genuine solutions from mere marketing buzz.</description></item><item><title>NIST CSF 2.0: An Architectural Revolution</title><link>https://me.itsecurity.network/blog/nist-csf-2-0-architectural-revolution/</link><pubDate>Wed, 06 Aug 2025 00:24:24 -0400</pubDate><guid>https://me.itsecurity.network/blog/nist-csf-2-0-architectural-revolution/</guid><description>NIST CSF 2.0 introduces the &amp;#39;Govern&amp;#39; function, fundamentally shifting security from just technical controls to a comprehensive, governance-led approach. This post explores the architectural implications for security programs.</description></item></channel></rss>