<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>William OGOU Cybersecurity Blog</title><description>Expert cybersecurity insights, tutorials, and analysis by William OGOU. Covering security architecture, and the latest cybersecurity trends and best practices.</description><link>https://blog.ogwilliam.com/</link><item><title>pnpm 11.0: Why the New Supply Chain Defaults Matter</title><link>https://blog.ogwilliam.com/post/pnpm-11-supply-chain-security/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/pnpm-11-supply-chain-security/</guid><description>pnpm 11.0 is here with critical security defaults. Learn how &apos;minimumReleaseAge&apos; and &apos;blockExoticSubdeps&apos; protect your SDLC from immediate supply chain threats.</description><pubDate>Thu, 07 May 2026 09:00:00 GMT</pubDate></item><item><title>Google Cloud Next 2026: Security Announcements Recap</title><link>https://blog.ogwilliam.com/post/google-cloud-next-2026-security-recap/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-cloud-next-2026-security-recap/</guid><description>A recap of the key security announcements at Google Cloud Next 2026: agentic defense, Wiz AI protection, agent identity, Model Armor, Fraud Defense, and Trusted Cloud updates.</description><pubDate>Sat, 25 Apr 2026 10:00:00 GMT</pubDate></item><item><title>The OWASP Top 10 CI/CD Security Risks: A Practitioner’s Blueprint</title><link>https://blog.ogwilliam.com/post/owasp-top-10-cicd-security-risks-blueprint/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/owasp-top-10-cicd-security-risks-blueprint/</guid><description>Master the OWASP Top 10 CI/CD Security Risks. Concrete attacks, code examples, and battle-tested controls to harden your pipelines against supply chain threats.</description><pubDate>Sun, 19 Apr 2026 09:00:00 GMT</pubDate></item><item><title>Bridging the Gap in Supply Chain Defense: Introducing SITF</title><link>https://blog.ogwilliam.com/post/sitf-sdlc-infrastructure-threat-framework/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/sitf-sdlc-infrastructure-threat-framework/</guid><description>Traditional security frameworks don&apos;t map the modern software supply chain. Discover SITF, the new open-source SDLC Infrastructure Threat Framework by Wiz, designed to visualize, analyze, and prevent complex supply chain attacks.</description><pubDate>Fri, 17 Apr 2026 20:00:00 GMT</pubDate></item><item><title>Guide : How to Build a &quot;Mythos-Ready&quot; Security Program</title><link>https://blog.ogwilliam.com/post/guide-mythos-ready-security/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/guide-mythos-ready-security/</guid><description>Time-to-exploit has collapsed to 20 hours. Read the definitive guide to the CSA, SANS, and OWASP &apos;AI Vulnerability Storm&apos; report. Learn the 11 Priority Actions and 10 CISO questions.</description><pubDate>Wed, 15 Apr 2026 10:00:00 GMT</pubDate></item><item><title>Inside Anthropic&apos;s &quot;Project Glasswing&quot;</title><link>https://blog.ogwilliam.com/post/anthropic-project-glasswing-claude-mythos-ai-security/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/anthropic-project-glasswing-claude-mythos-ai-security/</guid><description>Anthropic unveils Project Glasswing and the &quot;Mythos&quot; frontier model an AI so proficient at finding zero-day exploits it is deemed too dangerous for public release. Learn the exact steps defenders must take today.</description><pubDate>Wed, 08 Apr 2026 11:43:00 GMT</pubDate></item><item><title>Defending the Software Supply Chain: A Verify First Playbook</title><link>https://blog.ogwilliam.com/post/defending-software-supply-chain/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/defending-software-supply-chain/</guid><description>The software supply chain is under relentless attack from campaigns like TeamPCP and the Axios hack. Learn actionable, step-by-step strategies to secure your CI/CD pipelines and developer endpoints.</description><pubDate>Mon, 06 Apr 2026 10:00:00 GMT</pubDate></item><item><title>Stop Using Service Account Keys: A Guide to Workload Identity Federation</title><link>https://blog.ogwilliam.com/post/gcp-workload-identity-federation-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-workload-identity-federation-guide/</guid><description>Leaked service account keys are a top cloud security risk. This definitive developer&apos;s guide explains how to go keyless with GCP&apos;s Workload Identity Federation.</description><pubDate>Fri, 03 Apr 2026 10:00:00 GMT</pubDate></item><item><title>Axios Compromised in Supply Chain Attack</title><link>https://blog.ogwilliam.com/post/axios-supply-chain-attack-malware/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/axios-supply-chain-attack-malware/</guid><description>A massive supply chain attack has hit the popular npm package Axios. Versions 1.14.1 and 0.30.4 deploy a stealthy Remote Access Trojan (RAT) via a fake dependency. Learn how to detect and remediate this critical threat.</description><pubDate>Tue, 31 Mar 2026 14:25:00 GMT</pubDate></item><item><title>Dissecting the Claude Code Fiasco: Anthropic 512K-Line Leak</title><link>https://blog.ogwilliam.com/post/anthropic-claude-code-source-leak/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/anthropic-claude-code-source-leak/</guid><description>Anthropic accidentally leaked 512,000 lines of Claude Code source on npm. Learn how attackers are weaponizing the source map for context poisoning and sandbox bypasses.</description><pubDate>Tue, 31 Mar 2026 10:00:00 GMT</pubDate></item><item><title>How TeamPCP Compromised (again) LiteLLM</title><link>https://blog.ogwilliam.com/post/litellm-supply-chain-attack-teampcp/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/litellm-supply-chain-attack-teampcp/</guid><description>TeamPCP strikes again. The popular Python package litellm (versions 1.82.7 and 1.82.8) was compromised on PyPI, deploying a credential harvester and Kubernetes backdoor.</description><pubDate>Tue, 24 Mar 2026 18:00:00 GMT</pubDate></item><item><title>The Second Fall of Trivy: How TeamPCP Poisoned the CI/CD Supply Chain</title><link>https://blog.ogwilliam.com/post/trivy-supply-chain-attack-teampcp/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/trivy-supply-chain-attack-teampcp/</guid><description>Aqua Security&apos;s Trivy was compromised a second time on March 19, 2026, by &quot;TeamPCP.&quot; Learn how malicious v0.69.4 and GitHub Actions were used to steal CI/CD secrets, how to detect the breach, and immediate remediation steps.</description><pubDate>Fri, 20 Mar 2026 08:00:00 GMT</pubDate></item><item><title>Google Officially Completes Wiz Acquisition for Cloud Security</title><link>https://blog.ogwilliam.com/post/google-completes-wiz-acquisition/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-completes-wiz-acquisition/</guid><description>Google has officially closed its acquisition of Wiz. Learn what this merger means for multi-cloud security, AI-driven threat detection, and platform support.</description><pubDate>Wed, 11 Mar 2026 10:40:00 GMT</pubDate></item><item><title>What is Promptfoo?</title><link>https://blog.ogwilliam.com/post/what-is-promptfoo/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/what-is-promptfoo/</guid><description>The AI security landscape is shifting rapidly. Discover Promptfoo, the LLM red-teaming and evaluation platform recently acquired by OpenAI, and how it fits into your AI security stack.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Beyond the Base Image: Docker Introduces Hardened System Packages</title><link>https://blog.ogwilliam.com/post/docker-hardened-system-packages-container-security/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/docker-hardened-system-packages-container-security/</guid><description>Docker goes beyond the base image with the release of Docker Hardened System Packages. Discover how 8,000+ secure, SLSA Level 3 certified packages for Alpine (and soon Debian) will eliminate vulnerabilities from your custom container builds.</description><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Kali Linux Meets Claude via MCP</title><link>https://blog.ogwilliam.com/post/kali-linux-claude-mcp/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/kali-linux-claude-mcp/</guid><description>Discover how Kali Linux integrates with Claude via the Model Context Protocol (MCP) to automate offensive security tasks using natural language prompts.</description><pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Deploy OpenClaw (formerly Moltbot, formerly Clawdbot) Securely on Cloudflare</title><link>https://blog.ogwilliam.com/post/secure-openclaw-moltbot-deployment-cloudflare/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/secure-openclaw-moltbot-deployment-cloudflare/</guid><description>Stop running AI agents with root access on your local machine. Learn how to deploy OpenClaw (formerly Moltbot) securely using Cloudflare Sandboxes and Zero Trust to prevent RCE risks while maintaining full autonomy.</description><pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate></item><item><title>The AI-BOM Strategy: Securing the Trust Boundaries of Your AI Stack</title><link>https://blog.ogwilliam.com/post/ai-bom-strategy-securing-trust-boundaries/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ai-bom-strategy-securing-trust-boundaries/</guid><description>AI security goes beyond the model. Explore the critical risks defined in the AI-BOM framework, from LLMjacking and trust boundaries to infrastructure vulnerabilities, and learn how to secure every layer of your AI stack.</description><pubDate>Thu, 26 Feb 2026 10:00:00 GMT</pubDate></item><item><title>Clawdbot Security: How an AI Agent Could Leave Your Front Door Unlocked</title><link>https://blog.ogwilliam.com/post/clawdbot-ai-agent-security-risks/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/clawdbot-ai-agent-security-risks/</guid><description>Clawdbot is the latest AI trend, but critical misconfigurations are exposing API keys, Signal accounts, and root shells to the public internet. Here is what you need to know.</description><pubDate>Thu, 26 Feb 2026 10:00:00 GMT</pubDate></item><item><title>Combating Model Distillation and Weaponized LLMs</title><link>https://blog.ogwilliam.com/post/ai-distillation-attacks-hydra-clusters/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ai-distillation-attacks-hydra-clusters/</guid><description>Discover how adversaries use AI distillation attacks and &quot;hydra clusters&quot; to steal frontier AI capabilities, and how cybercriminals weaponize LLMs for global operations.</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate></item><item><title>SIEM &amp; SOAR Platforms: Master Cybersecurity Defense in 2026</title><link>https://blog.ogwilliam.com/post/siem-soar-platforms-cybersecurity-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/siem-soar-platforms-cybersecurity-guide/</guid><description>Master SIEM and SOAR platforms for cybersecurity with GenAI integration. Updated Feb 23 2026 with latest Microsoft Copilot for Security GA, Google&apos;s Security Command Center with Vertex AI, and SOAR orchestration using natural language prompts.</description><pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate></item><item><title>AWS vs Azure vs Google Cloud Security: Which Provider Leads in 2026?</title><link>https://blog.ogwilliam.com/post/aws-vs-azure-vs-google-cloud-security-which-cloud-provider-reigns-supreme-in-2025/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/aws-vs-azure-vs-google-cloud-security-which-cloud-provider-reigns-supreme-in-2025/</guid><description>A comprehensive comparison of AWS, Azure, and Google Cloud security features for 2026. Updated with latest developments including Google&apos;s Vertex AI Security, Microsoft Security Copilot GA, and AWS AI-driven threat detection initiatives. Updated Feb 22 2026.</description><pubDate>Sun, 22 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Cloudflare vs. AWS Shield vs. GCP Cloud Armor</title><link>https://blog.ogwilliam.com/post/cloudflare-vs-aws-shield-vs-gcp-armor-ddos-protection/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/cloudflare-vs-aws-shield-vs-gcp-armor-ddos-protection/</guid><description>A CISO&apos;s guide to choosing your DDoS protection. A deep dive comparison of Cloudflare, AWS Shield, and Google Cloud Armor on features, cost, and use cases for 2026.</description><pubDate>Sat, 21 Feb 2026 10:00:00 GMT</pubDate></item><item><title>Critical Ingress-NGINX Vulnerabilities : Kubernetes vulnerability</title><link>https://blog.ogwilliam.com/post/critical-ingress-nginx-vulnerabilities-a-nightmare-for-kubernetes-security/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/critical-ingress-nginx-vulnerabilities-a-nightmare-for-kubernetes-security/</guid><description>Critical Ingress-NGINX vulnerabilities threaten Kubernetes security. Learn how to mitigate three of the vulnerabilities   CVE-2025-24514, CVE-2025-1097, and CVE-2025-1098 ⚡ Updated Feb 21 2026 for ingress-nginx retirement</description><pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate></item><item><title>The GCP Connectivity Triad: Decoding PSA, PSC, and PGA</title><link>https://blog.ogwilliam.com/post/gcp-psa-psc-pga-explained/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-psa-psc-pga-explained/</guid><description>Confused by GCP&apos;s networking alphabet soup? We demystify PSA, PSC, and PGA. Learn the differences, use cases, and when to use which for secure cloud architecture.</description><pubDate>Fri, 20 Feb 2026 11:00:00 GMT</pubDate></item><item><title>A Practical Guide to MCP Security</title><link>https://blog.ogwilliam.com/post/secure-model-context-protocol-mcp-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/secure-model-context-protocol-mcp-guide/</guid><description>The Model Context Protocol (MCP) connects AI agents to your data. Learn how to secure MCP servers against tool poisoning, token misuse, and prompt injection with this practical guide based on OWASP standards.</description><pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate></item><item><title>The WAF Showdown: Google Cloud Armor vs. Cloudflare (FEB 2026 Edition)</title><link>https://blog.ogwilliam.com/post/google-cloud-armor-vs-cloudflare-waf-comparison/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-cloud-armor-vs-cloudflare-waf-comparison/</guid><description>Cloudflare or Google Cloud Armor? The ultimate WAF showdown for 2026. We compare architecture (Proxy vs. Native), pricing, Adaptive Protection, and latency to help you decide.</description><pubDate>Tue, 17 Feb 2026 10:00:00 GMT</pubDate></item><item><title>What is OAuth and OAuth 2.0 ?</title><link>https://blog.ogwilliam.com/post/what-is-oauth-and-oauth-20-/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/what-is-oauth-and-oauth-20-/</guid><description>Explore OAuth and OAuth 2.0 for secure API authorization. Learn how access tokens and security protocols enable secure third-party access. Enhance your cloud security. Updated February 2026 with OAuth 2.1 finalization status, DPoP token binding, and current best practices.</description><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Privacy-First AI Coding: Local Proxy for LLMs</title><link>https://blog.ogwilliam.com/post/building-local-privacy-llm/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/building-local-privacy-llm/</guid><description>Use powerful Chinese LLMs (GLM-5, Kimi) without leaking secrets. A local proxy that redacts API keys, credentials, and PII before data leaves your machine.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Zero Trust Network Access (ZTNA): The New Secure Access</title><link>https://blog.ogwilliam.com/post/zero-trust-network-access-ztna-the-new-secure-access/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/zero-trust-network-access-ztna-the-new-secure-access/</guid><description>Explore Zero Trust Network Access (ZTNA), a modern security framework enhancing network security through least privilege and continuous verification. Learn how ZTNA secures remote access and improves your security architecture. Updated February 2026 with AI-powered ZTNA trends, ZTNA 2.0 deep inspection concepts, and current vendor comparisons.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Your Practical Guide to Building a Zero Trust Architecture</title><link>https://blog.ogwilliam.com/post/your-practical-guide-to-building-a-zero-trust-architecture/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/your-practical-guide-to-building-a-zero-trust-architecture/</guid><description>Navigate your Zero Trust Architecture journey with a practical, phased roadmap. Learn key steps for securing identity, networks, applications, and data. Updated February 2026 with agentic AI security guidance and 2026 automation best practices.</description><pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Hacking the AI Inner Voice: Understanding Chain-of-Thought Forgery</title><link>https://blog.ogwilliam.com/post/chain-of-thought-forgery-ai-security-vulnerability/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/chain-of-thought-forgery-ai-security-vulnerability/</guid><description>Chain-of-Thought (CoT) Forgery is a sophisticated attack where hackers plant fake reasoning to trick AI models into bypassing safety guardrails. Learn how &quot;Authority by Format&quot; works and how to secure your LLMs.</description><pubDate>Fri, 13 Feb 2026 00:00:00 GMT</pubDate></item><item><title>The Missing Link in AI Security: Why Agentic AI Needs SPIFFE &amp; SPIRE (Part 3)</title><link>https://blog.ogwilliam.com/post/securing-ai-agents-with-spiffe-spire/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/securing-ai-agents-with-spiffe-spire/</guid><description>AI Agents are the new &quot;Non-Human Identities&quot; (NHI). Discover how SPIFFE and SPIRE provide the critical identity layer needed to secure autonomous, agentic AI workloads and prevent rogue actions.</description><pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate></item><item><title>A Complete Guide to Best Practices &amp; Benefits for Modern Cybersecurity</title><link>https://blog.ogwilliam.com/post/zero-trust-security-a-complete-guide-to-best-practices--benefits-for-modern-cybersecurity/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/zero-trust-security-a-complete-guide-to-best-practices--benefits-for-modern-cybersecurity/</guid><description>Explore the Zero Trust security model in this comprehensive guide. Learn about its principles, benefits, use cases, and best practices for implementation in your organization&apos;s cybersecurity strategy. Updated February 2026 with latest NIST CSF 2.0 guidance, AI-era threat statistics, and 2026 best practices.</description><pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate></item><item><title>The New Triad of AI Security: Promptfoo, Strix, and CAI</title><link>https://blog.ogwilliam.com/post/promptfoo-strix-cai-ai-security-tools/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/promptfoo-strix-cai-ai-security-tools/</guid><description>Discover the new wave of open-source AI security tools: Promptfoo, Strix, and CAI. Learn how to combine them for a defense-in-depth strategy to secure your AI applications.</description><pubDate>Tue, 10 Feb 2026 10:00:00 GMT</pubDate></item><item><title>Passkeys: Passwordless and Phishing-Resistant Future</title><link>https://blog.ogwilliam.com/post/passkeys-the-dawn-of-a-truly-passwordless-and-phishing-resistant-future/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/passkeys-the-dawn-of-a-truly-passwordless-and-phishing-resistant-future/</guid><description>Passkeys are revolutionizing authentication, offering phishing resistance and convenience. Explore how this passwordless future works, its benefits, challenges, and enterprise adoption. Updated February 2026 with 15B passkey account milestone, Windows 11 &amp; Android 15 improvements, and enterprise adoption data.</description><pubDate>Tue, 10 Feb 2026 00:00:00 GMT</pubDate></item><item><title>SPIFFE and SPIRE : Benefits, Examples, and Use Cases (Part 2)</title><link>https://blog.ogwilliam.com/post/spiffe-spire-benefits-examples-and-use-cases/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/spiffe-spire-benefits-examples-and-use-cases/</guid><description>Why are companies like Uber and Netflix adopting SPIFFE/SPIRE? In Part 2, we explore real-world benefits over traditional IAM, multi-cloud use cases, and Zero Trust at scale.</description><pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Setup Google Model Armor with Terraform</title><link>https://blog.ogwilliam.com/post/google-model-armor-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-model-armor-guide/</guid><description>Secure your LLMs with Google Model Armor. Learn how it works, deploy reusable Terraform modules for templates, and enforce organization-wide safety floors to prevent prompt injections.</description><pubDate>Sun, 08 Feb 2026 15:57:00 GMT</pubDate></item><item><title>SPIFFE and SPIRE Explained: The Foundation of Zero Trust for Machines (Part 1)</title><link>https://blog.ogwilliam.com/post/spiffe-spire-explained/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/spiffe-spire-explained/</guid><description>Confused by SPIFFE and SPIRE? Dive into the definitive guide on Workload Identity. Learn how these open-source standards solve the Secret Zero problem, automate mTLS, and eliminate static credentials in cloud-native infrastructure.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Critical Alert: High-Severity Vulnerabilities in Kubernetes Ingress-NGINX</title><link>https://blog.ogwilliam.com/post/critical-kubernetes-ingress-nginx-vulnerability-cve-2026-24512/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/critical-kubernetes-ingress-nginx-vulnerability-cve-2026-24512/</guid><description>Critical vulnerabilities (CVE-2026-24512 &amp; others) discovered in Kubernetes Ingress-NGINX allow arbitrary code execution. Upgrade to v1.13.7 or v1.14.3 immediately to secure your cluster.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Concrete Technical Steps for Post-Quantum TLS, SSH, and IPsec</title><link>https://blog.ogwilliam.com/post/post-quantum-guide-tls-ssh-ipsec/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/post-quantum-guide-tls-ssh-ipsec/</guid><description>The quantum threat is real. Based on ANSSI&apos;s technical guidance, here are the concrete steps to secure TLS, SSH, and IPsec against &apos;Store-Now-Decrypt-Later&apos; attacks using Hybridization.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate></item><item><title>The Moltbook Hack: When &quot;Vibe Coding&quot; Leaks 1.5M API Keys</title><link>https://blog.ogwilliam.com/post/moltbook-hack-supabase-vibe-coding/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/moltbook-hack-supabase-vibe-coding/</guid><description>A massive breach at Moltbook exposed 1.5M API keys and 35,000 user emails due to a simple Supabase misconfiguration. Learn how &quot;vibe coding&quot; led to this critical security failure.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>How a Calendar Invite Tricked Google Gemini</title><link>https://blog.ogwilliam.com/post/google-gemini-calendar-prompt-injection/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-gemini-calendar-prompt-injection/</guid><description>A new prompt injection flaw in Google Gemini allowed attackers to steal private data via malicious Calendar invites. Learn how this &quot;semantic attack&quot; bypassed security controls and what it means for AI agent security.</description><pubDate>Sun, 25 Jan 2026 10:00:00 GMT</pubDate></item><item><title>Private AI Coding: Run Secure, Local LLMs with OpenCode and Docker</title><link>https://blog.ogwilliam.com/post/private-ai-coding-opencode-docker/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/private-ai-coding-opencode-docker/</guid><description>Stop leaking your code to the cloud. Learn how to build a private, secure AI coding assistant using OpenCode and Docker Model Runner. Full tutorial with code samples for local RAG and secure model serving.</description><pubDate>Sat, 17 Jan 2026 00:00:00 GMT</pubDate></item><item><title>From Reactive to Autonomous: A Guide to the AI Maturity Model for Cybersecurity</title><link>https://blog.ogwilliam.com/post/ai-maturity-model-cybersecurity-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ai-maturity-model-cybersecurity-guide/</guid><description>Is your SOC truly AI-driven? Explore the 5 levels of the AI Maturity Model for Cybersecurity, from manual operations to autonomous defense, and chart your path to resilience.</description><pubDate>Tue, 13 Jan 2026 10:00:00 GMT</pubDate></item><item><title>Cybersecurity Wrapped 2025</title><link>https://blog.ogwilliam.com/post/cybersecurity-wrapped-2025/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/cybersecurity-wrapped-2025/</guid><description>Your Cybersecurity Wrapped 2025 is here. From the $1.5B crypto heist to the rise of AI malware and the &apos;React2Shell&apos; crisis, we recap the year&apos;s wildest hacks, trends, and the Top 10 CVEs.</description><pubDate>Thu, 01 Jan 2026 10:00:00 GMT</pubDate></item><item><title>Securing Model Context Protocol (MCP) Authentication: Best Practices</title><link>https://blog.ogwilliam.com/post/mcp-authentication-security-best-practices/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mcp-authentication-security-best-practices/</guid><description>Securing the Model Context Protocol (MCP) is critical for AI agent safety. Learn the best practices for authentication, from preventing Confused Deputy attacks to implementing OAuth 2.0 and avoiding token passthrough.</description><pubDate>Wed, 31 Dec 2025 14:00:00 GMT</pubDate></item><item><title>MongoBleed: The Critical Flaw Leaking Your Database Memory (CVE-2025-14847)</title><link>https://blog.ogwilliam.com/post/mongobleed-cve-2025-14847-uninitialized-memory-leak/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mongobleed-cve-2025-14847-uninitialized-memory-leak/</guid><description>MongoBleed (CVE-2025-14847) exposes MongoDB servers to unauthenticated memory leaks due to a Zlib decompression flaw. Learn how attackers exploit uninitialized heap memory and how to patch immediately.</description><pubDate>Sun, 28 Dec 2025 19:00:00 GMT</pubDate></item><item><title>How to Build a Secure AI Platform on Google Cloud: SAIF Step-by-Step Guide (3/3)</title><link>https://blog.ogwilliam.com/post/google-saif-architecture-fortified-ai-platform-example/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-saif-architecture-fortified-ai-platform-example/</guid><description>Part 3 of the SAIF series. A deep dive into a reference architecture for a production-grade AI platform on Google Cloud, mapping controls to real-world defenses.</description><pubDate>Fri, 26 Dec 2025 10:00:00 GMT</pubDate></item><item><title>The Essential Google Cloud &amp; SAIF AI Launch Checklist for 2026 Success (2/3)</title><link>https://blog.ogwilliam.com/post/google-secure-ai-framework-saif-checklist/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-secure-ai-framework-saif-checklist/</guid><description>Start your AI project securely with this definitive &apos;Day 0&apos; checklist based on Google&apos;s Secure AI Framework (SAIF). Covers identity, data, network, and model controls for creators and consumers.</description><pubDate>Wed, 24 Dec 2025 10:00:00 GMT</pubDate></item><item><title>Critical Alert: n8n Arbitrary Code Execution (CVE-2025-68613)</title><link>https://blog.ogwilliam.com/post/n8n-rce-vulnerability-cve-2025-68613/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/n8n-rce-vulnerability-cve-2025-68613/</guid><description>A critical Arbitrary Code Execution vulnerability (CVE-2025-68613) has been discovered in n8n, allowing attackers to execute arbitrary code via workflow expressions. Upgrade to v1.122.0 immediately.</description><pubDate>Mon, 22 Dec 2025 23:00:00 GMT</pubDate></item><item><title>The Key Principles of Google SAIF Framework (1/3)</title><link>https://blog.ogwilliam.com/post/google-secure-ai-framework-saif-principles/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-secure-ai-framework-saif-principles/</guid><description>Discover the core principles of Google&apos;s Secure AI Framework (SAIF). Learn how this holistic, lifecycle-aware blueprint helps organizations build secure-by-design AI systems and combat novel threats like prompt injection and data poisoning.</description><pubDate>Mon, 22 Dec 2025 10:00:00 GMT</pubDate></item><item><title>The Ultimate Defense Strategy: Mapping MITRE ATLAS to OWASP for LLMs</title><link>https://blog.ogwilliam.com/post/mapping-mitre-atlas-mitigations-owasp-top-10-llms/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mapping-mitre-atlas-mitigations-owasp-top-10-llms/</guid><description>Bridge the gap between OWASP threats and MITRE ATLAS defenses. A strategic blueprint mapping the OWASP Top 10 for LLMs to specific, actionable MITRE ATLAS mitigations for securing Generative AI.</description><pubDate>Sat, 20 Dec 2025 00:00:00 GMT</pubDate></item><item><title>AI Security: Promptfoo, Strix, CAI, and Giskard (Updated)</title><link>https://blog.ogwilliam.com/post/giskard-promptfoo-strix-cai-ai-security-benchmark/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/giskard-promptfoo-strix-cai-ai-security-benchmark/</guid><description>Discover how Giskard joins Promptfoo, Strix, and CAI to provide continuous, compliance-ready red teaming for enterprise AI agents.</description><pubDate>Fri, 19 Dec 2025 18:00:00 GMT</pubDate></item><item><title>Docker Hardened Images Are Now Free: A Container Security Game Changer</title><link>https://blog.ogwilliam.com/post/docker-hardened-images-free-open-source/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/docker-hardened-images-free-open-source/</guid><description>Docker has officially made Docker Hardened Images (DHI) free and open source. Discover how to secure your software supply chain with near-zero CVEs, transparent SBOMs, and SLSA Level 3 provenance today.</description><pubDate>Wed, 17 Dec 2025 17:00:00 GMT</pubDate></item><item><title>Google Kills Dark Web Report: Shutdown Dates &amp; Alternatives</title><link>https://blog.ogwilliam.com/post/google-dark-web-report-discontinued/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-dark-web-report-discontinued/</guid><description>Google is officially discontinuing its Dark Web Report tool in early 2026. Find out why the service is shutting down, the key dates you need to know, and the best free alternatives to monitor your data security.</description><pubDate>Mon, 15 Dec 2025 18:00:00 GMT</pubDate></item><item><title>Guide: Building Secure Agentic Applications</title><link>https://blog.ogwilliam.com/post/building-secure-agentic-applications-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/building-secure-agentic-applications-guide/</guid><description>AI Agents introduce new security risks. Learn how to secure your autonomous AI systems with this architectural guide based on the OWASP Agentic Security Initiative.</description><pubDate>Mon, 15 Dec 2025 00:00:00 GMT</pubDate></item><item><title>React2Shell (Part 2): Surviving the New React DoS (CVE-2025-55184)</title><link>https://blog.ogwilliam.com/post/react-server-components-dos-vulnerability-cve-2025-55184/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/react-server-components-dos-vulnerability-cve-2025-55184/</guid><description>The React2Shell saga continues with CVE-2025-55184. A new critical DDoS vulnerability in React Server Components allows unauthenticated attackers to crash servers via infinite loops. Update immediately.</description><pubDate>Sun, 14 Dec 2025 08:17:00 GMT</pubDate></item><item><title>AI Coding Tools Are the New Attack Vector: How IDEs Enable Silent Data Theft</title><link>https://blog.ogwilliam.com/post/ide-vulnerabilities-ai-prompt-injection/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ide-vulnerabilities-ai-prompt-injection/</guid><description>New cybersecurity research uncovers how AI coding assistants like Cursor and GitHub Copilot and CI/CD agents are being exploited for data theft and remote code execution. Learn the details behind ‘IDEsaster’ and ‘PromptPwnd,’ plus essential steps to secure your development environment.</description><pubDate>Sat, 13 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Shai-Hulud 2.0: The Recursive Nightmare Eating the Software Supply Chain</title><link>https://blog.ogwilliam.com/post/shai-hulud-2-0-recursive-supply-chain-attack/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/shai-hulud-2-0-recursive-supply-chain-attack/</guid><description>The worm has returned. Shai-Hulud 2.0 has compromised over 25,000+ malicious repos across ~350 GitHub users by weaponizing the developers themselves. Discover how this recursive supply chain attack works and how to sanitize your registry.</description><pubDate>Fri, 05 Dec 2025 10:00:00 GMT</pubDate></item><item><title>React2Shell: CVE-2025-55182 CVSS 10.0</title><link>https://blog.ogwilliam.com/post/react2shell-cve-2025-55182-rce-vulnerability/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/react2shell-cve-2025-55182-rce-vulnerability/</guid><description>React2Shell (CVE-2025-55182) exposes React Server Components to a critical Remote Code Execution flaw. Dive into the technical details, the exploitation mechanics, and the urgent remediation steps required to secure your infrastructure.</description><pubDate>Thu, 04 Dec 2025 02:26:00 GMT</pubDate></item><item><title>Grafana Critical CVE-2025-41115 CVSS 10.0</title><link>https://blog.ogwilliam.com/post/grafana-enterprise-cve-2025-41115-scim/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/grafana-enterprise-cve-2025-41115-scim/</guid><description>Urgent Alert: Grafana Enterprise CVE-2025-41115 (CVSS 10.0) allows full admin takeover via SCIM. Update to version 12.3.0 immediately. See the new affected versions and fix details here.</description><pubDate>Mon, 24 Nov 2025 10:00:00 GMT</pubDate></item><item><title>Strix: The Open-Source AI Agent Redefining Automated Pentesting</title><link>https://blog.ogwilliam.com/post/strix-open-source-ai-security-agent/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/strix-open-source-ai-security-agent/</guid><description>Discover Strix, the open-source AI agent revolutionizing penetration testing. Learn how to deploy, configure, and leverage this LLM-powered tool to automate reconnaissance and vulnerability analysis with context-aware intelligence.</description><pubDate>Sat, 22 Nov 2025 13:20:00 GMT</pubDate></item><item><title>Tipping Point: Kubernetes Announces Ingress-NGINX Retirement</title><link>https://blog.ogwilliam.com/post/kubernetes-ingress-nginx-retirement/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/kubernetes-ingress-nginx-retirement/</guid><description>The community-driven Ingress-NGINX controller is retiring. Explore the reasons, its link to the critical &apos;IngressNightmare&apos; vulnerability, and what this means for your Kubernetes security and migration strategy.</description><pubDate>Thu, 20 Nov 2025 10:00:00 GMT</pubDate></item><item><title>Claude AI Weaponized for a New Breed of Cyber Espionage</title><link>https://blog.ogwilliam.com/post/claude-ai-weaponized-cyber-espionage/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/claude-ai-weaponized-cyber-espionage/</guid><description>A new era of cyber warfare has begun. Discover how Chinese state-sponsored hackers weaponized Anthropic&apos;s Claude AI for an autonomous espionage campaign, signaling a critical inflection point for AI security.</description><pubDate>Mon, 17 Nov 2025 10:00:00 GMT</pubDate></item><item><title>What is new in the MITRE ATT&amp;CK v18 Update</title><link>https://blog.ogwilliam.com/post/mitre-attck-v18-update-decoded/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mitre-attck-v18-update-decoded/</guid><description>Dive deep into the MITRE ATT&amp;CK v18 update. Discover crucial changes to detection analytics, expanded Mobile and ICS matrices, and how to leverage the latest adversary intelligence for a stronger defense.</description><pubDate>Sat, 15 Nov 2025 10:00:00 GMT</pubDate></item><item><title>Deconstructing the OWASP Top 10 2025</title><link>https://blog.ogwilliam.com/post/owasp-top-10-2025-deconstructed/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/owasp-top-10-2025-deconstructed/</guid><description>Stay ahead of emerging threats with our in-depth analysis of the OWASP Top 10 2025. Discover the new risks, including Software Supply Chain Failures, and learn how to fortify your web application security.</description><pubDate>Tue, 11 Nov 2025 10:00:00 GMT</pubDate></item><item><title>The OAuth Comparison: A Developer&apos;s Guide to Google vs. Microsoft</title><link>https://blog.ogwilliam.com/post/oauth-google-vs-microsoft/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/oauth-google-vs-microsoft/</guid><description>A deep dive into the OAuth and OIDC security philosophies of Google and Microsoft. Discover the critical differences in scopes, verification, and security features for 2025.</description><pubDate>Fri, 07 Nov 2025 10:00:00 GMT</pubDate></item><item><title>Critical WSUS RCE (CVE-2025-59287): A &apos;Code-Zombie&apos; Threat</title><link>https://blog.ogwilliam.com/post/wsus-rce-vulnerability-cve-2025-59287/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/wsus-rce-vulnerability-cve-2025-59287/</guid><description>A critical RCE vulnerability in WSUS (CVE-2025-59287) creates a &apos;Code-Zombie&apos; threat. This is your immediate action plan to patch, hunt, and harden your Windows fleet.</description><pubDate>Tue, 04 Nov 2025 10:00:00 GMT</pubDate></item><item><title>Slopsquatting: The AI Hallucination That Infects Your Codebase</title><link>https://blog.ogwilliam.com/post/ai-slopsquatting-supply-chain-attack/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ai-slopsquatting-supply-chain-attack/</guid><description>Discover AI Slopsquatting, the new supply chain attack where AI code assistants hallucinate malicious packages, tricking developers into installing malware.</description><pubDate>Fri, 31 Oct 2025 10:00:00 GMT</pubDate></item><item><title>Over $1M Awarded for 73 Zero-Days at Pwn2Own Dublin 2025</title><link>https://blog.ogwilliam.com/post/pwn2own-dublin-2025/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/pwn2own-dublin-2025/</guid><description>A recap of Pwn2Own Dublin 2025, where hackers earned over $1 million for 73 unique zero-day vulnerabilities, including a full compromise of the new Samsung Galaxy S25.</description><pubDate>Tue, 28 Oct 2025 10:00:00 GMT</pubDate></item><item><title>The AI Engine&apos;s Exposed Wires: A Practitioner&apos;s Guide to MCP Security</title><link>https://blog.ogwilliam.com/post/mcp-security-practitioners-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mcp-security-practitioners-guide/</guid><description>Master MCP security threats: RCE, injection attacks, malicious dependencies &amp; data poisoning. Complete defense-in-depth guide for securing AI agents and preventing supply chain attacks.</description><pubDate>Sat, 25 Oct 2025 10:00:00 GMT</pubDate></item><item><title>Your Cloud Won&apos;t Be Encrypted, It Will Be Deleted: Surviving Cloud Ransomware</title><link>https://blog.ogwilliam.com/post/guide-modern-cloud-ransomware/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/guide-modern-cloud-ransomware/</guid><description>Cloud ransomware is here, and it targets your control plane, not just your files. This CISO&apos;s guide explains the new threat and a cloud-native strategy to survive it.</description><pubDate>Tue, 21 Oct 2025 10:00:00 GMT</pubDate></item><item><title>The Trojan in Your IDE: Deconstructing the VS Code Marketplace Risk</title><link>https://blog.ogwilliam.com/post/vs-code-marketplace-supply-chain-risk/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/vs-code-marketplace-supply-chain-risk/</guid><description>A massive supply chain risk lurks in the VS Code Marketplace. Learn how attackers use typosquatting to impersonate popular extensions and install malware directly into your IDE.</description><pubDate>Thu, 16 Oct 2025 10:00:00 GMT</pubDate></item><item><title>Critical Redis RCE (CVE-2025-49844): Technical Breakdown &amp; Action Plan</title><link>https://blog.ogwilliam.com/post/redis-rce-vulnerability-cve-2025-49844/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/redis-rce-vulnerability-cve-2025-49844/</guid><description>A critical RCE vulnerability (CVE-2025-49844) in Redis allows for a full server takeover. This is a technical breakdown and your immediate action plan to mitigate the threat.</description><pubDate>Wed, 08 Oct 2025 10:00:00 GMT</pubDate></item><item><title>Critical Oracle WebLogic RCE (CVE-2025-61882): Your Immediate Action Plan</title><link>https://blog.ogwilliam.com/post/oracle-weblogic-rce-cve-2025-61882-action-plan/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/oracle-weblogic-rce-cve-2025-61882-action-plan/</guid><description>A critical, unauthenticated RCE vulnerability (CVE-2025-61882) in Oracle WebLogic Server is being actively exploited. Here is your immediate action plan.</description><pubDate>Tue, 07 Oct 2025 10:00:00 GMT</pubDate></item><item><title>The Knock at the Door: Deconstructing the Clop Extortion Campaign</title><link>https://blog.ogwilliam.com/post/clop-extortion-oracle-ebs-zero-day/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/clop-extortion-oracle-ebs-zero-day/</guid><description>Clop extortion campaign targeting a new Oracle E-Business Suite zero-day. Understand the threat, the attack, and the immediate action plan you need.</description><pubDate>Sat, 04 Oct 2025 10:00:00 GMT</pubDate></item><item><title>The Prompt That Turns Your AI Coder into a Security Expert</title><link>https://blog.ogwilliam.com/post/secure-ai-code-assistant-prompts/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/secure-ai-code-assistant-prompts/</guid><description>Your AI code assistant is a brilliant, eager, and dangerously naive intern. It&apos;s time to give it a security promotion by mastering the art of the secure prompt.</description><pubDate>Wed, 01 Oct 2025 10:00:00 GMT</pubDate></item><item><title>Microsoft AI Red Teaming Tool</title><link>https://blog.ogwilliam.com/post/microsoft-ai-red-teaming-agent-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/microsoft-ai-red-teaming-agent-guide/</guid><description>Microsoft&apos;s new AI Red Team tool automates the discovery of risks in LLMs. Learn how this agentic system finds vulnerabilities like jailbreaking and prompt injection before attackers do.</description><pubDate>Mon, 29 Sep 2025 10:00:00 GMT</pubDate></item><item><title>Securing Remote MCP Servers with Google Cloud</title><link>https://blog.ogwilliam.com/post/gcp-securing-remote-mcp-servers/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-securing-remote-mcp-servers/</guid><description>Secure remote MCP servers on Google Cloud using a defense-in-depth architecture with IAP, Cloud Armor, and IAM.</description><pubDate>Thu, 25 Sep 2025 10:00:00 GMT</pubDate></item><item><title>Critical Entra ID Impersonation Flaw - CVE-2025-55241</title><link>https://blog.ogwilliam.com/post/entra-id-actor-token-vulnerability-cve-2025-55241/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/entra-id-actor-token-vulnerability-cve-2025-55241/</guid><description>A critical flaw in Entra ID (CVE-2025-55241) allowed attackers to impersonate anyone. This is a CISO&apos;s guide to the &apos;Actor Token&apos; vulnerability, the attack chain, and how to hunt for compromise.</description><pubDate>Wed, 24 Sep 2025 10:00:00 GMT</pubDate></item><item><title>Kubernetes Security: Top 10 Actions to Take Now</title><link>https://blog.ogwilliam.com/post/ciso-blueprint-kubernetes-security-hardening/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ciso-blueprint-kubernetes-security-hardening/</guid><description>A CISO&apos;s guide to Kubernetes security, based on authoritative guidance from the NSA and CISA. Discover the top 10 critical, high-impact actions you must take to harden your clusters.</description><pubDate>Sat, 20 Sep 2025 10:00:00 GMT</pubDate></item><item><title>ANSSI Guide to Implementing Zero Trust</title><link>https://blog.ogwilliam.com/post/implementing-zero-trust/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/implementing-zero-trust/</guid><description>Beyond the buzzword, this is a CISO&apos;s practical guide to implementing a real Zero Trust strategy, based on authoritative guidance from agencies like ANSSI.</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate></item><item><title>Forging Cyber Defenders in Student-Run SOCs</title><link>https://blog.ogwilliam.com/post/student-run-socs-forging-next-gen-cyber-defenders/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/student-run-socs-forging-next-gen-cyber-defenders/</guid><description>Student-run SOCs are a powerful solution to the cybersecurity skills gap. This CISO&apos;s guide explains the model, the benefits, and how to build a program that forges the next generation of defenders.</description><pubDate>Sat, 13 Sep 2025 10:00:00 GMT</pubDate></item><item><title>The Mass NPM Hijack Explained</title><link>https://blog.ogwilliam.com/post/anatomy-of-npm-hijack-supply-chain/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/anatomy-of-npm-hijack-supply-chain/</guid><description>Anatomy of the mass NPM hijack that breached the internet&apos;s core. This CISO&apos;s guide details the attack, its impact, and the immediate action plan you must execute now.</description><pubDate>Wed, 10 Sep 2025 10:00:00 GMT</pubDate></item><item><title>IAM Is Dead. Long Live IAM for the Agentic Era</title><link>https://blog.ogwilliam.com/post/iam-for-the-agentic-era/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/iam-for-the-agentic-era/</guid><description>Traditional IAM is broken. Discover the new paradigm of Agentic IAM, from DIDs and VCs to dynamic, real-time access control. A CISO&apos;s guide to governing your AI workforce.</description><pubDate>Fri, 05 Sep 2025 10:00:00 GMT</pubDate></item><item><title>Salesforce Supply Chain Nightmare: Breach at Salesloft &amp; Drift</title><link>https://blog.ogwilliam.com/post/salesforce-supply-chain-attack-salesloft-drift/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/salesforce-supply-chain-attack-salesloft-drift/</guid><description>A major supply chain attack via Salesloft and Drift has breached top companies. This guides you to the threat, the impact on Salesforce, and the immediate action plan you need.</description><pubDate>Thu, 04 Sep 2025 10:00:00 GMT</pubDate></item><item><title>CISA New Tool Solves Your Software Supply Chain Problem</title><link>https://blog.ogwilliam.com/post/cisa-guide-software-supply-chain-security/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/cisa-guide-software-supply-chain-security/</guid><description>CISA new tool translates security needs into ironclad contract language, solving the biggest problem in software supply chain security. A CISO guide to secure procurement.</description><pubDate>Tue, 02 Sep 2025 10:00:00 GMT</pubDate></item><item><title>The Clock is Ticking: AI Weaponizes Vulnerabilities in 15 Minutes</title><link>https://blog.ogwilliam.com/post/ai-weaponized-vulnerability-exploit-timeline/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ai-weaponized-vulnerability-exploit-timeline/</guid><description>Modern AI can turn a vulnerability disclosure into a weaponized exploit in 15 minutes. This CISO&apos;s guide unveils the critical risks and provides a blueprint for secure AI adoption.</description><pubDate>Sun, 31 Aug 2025 10:00:00 GMT</pubDate></item><item><title>OAuth 2.1 vs OpenID Connect in 2025: What&apos;s Changing &amp; Why It Matters</title><link>https://blog.ogwilliam.com/post/oauth-2-1-vs-openid-connect-2025/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/oauth-2-1-vs-openid-connect-2025/</guid><description>OAuth 2.1 is here. Discover the critical security upgrades that deprecate insecure parts of OAuth 2.0, how it strengthens OpenID Connect, and why it&apos;s essential for your applications in 2025.</description><pubDate>Tue, 19 Aug 2025 10:00:00 GMT</pubDate></item><item><title>Guide to the NIST CSF</title><link>https://blog.ogwilliam.com/post/nist-cybersecurity-framework-ciso-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/nist-cybersecurity-framework-ciso-guide/</guid><description>The NIST Cybersecurity Framework is more than a checklist; it&apos;s a strategic tool. This CISO&apos;s guide explains how to use the CSF to manage risk, communicate with the board, and build a resilient security program.</description><pubDate>Sat, 16 Aug 2025 10:00:00 GMT</pubDate></item><item><title>GCP Security Solution to the Top 11 Cloud Vulnerabilities</title><link>https://blog.ogwilliam.com/post/gcp-solutions-to-top-cloud-vulnerabilities/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-solutions-to-top-cloud-vulnerabilities/</guid><description>A practical CISO&apos;s guide to defeating the top 11 cloud vulnerabilities using Google Cloud&apos;s security arsenal. Map threats to specific GCP tools for a robust defense-in-depth strategy.</description><pubDate>Thu, 14 Aug 2025 14:00:00 GMT</pubDate></item><item><title>The AI Security Arsenal: AI Security New Tools</title><link>https://blog.ogwilliam.com/post/ai-security-arsenal-ciso-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ai-security-arsenal-ciso-guide/</guid><description>Your traditional security stack is blind to AI. This guide, based on industry research, unveils the new arsenal of tools needed to secure your AI ecosystem, from posture management to runtime defense.</description><pubDate>Tue, 12 Aug 2025 10:00:00 GMT</pubDate></item><item><title>GCP Storage Security: Guide to Preventing Silent Takeovers</title><link>https://blog.ogwilliam.com/post/gcp-storage-security-preventing-takeovers/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-storage-security-preventing-takeovers/</guid><description>A CISO&apos;s blueprint for Google Cloud Storage security. Learn about the risks, from public buckets to dangling bucket takeovers, and how to build a defense-in-depth strategy.</description><pubDate>Mon, 11 Aug 2025 10:00:00 GMT</pubDate></item><item><title>The Quantum-Proof Handshake: Your Blueprint for Migrating to Post-Quantum TLS</title><link>https://blog.ogwilliam.com/post/post-quantum-cryptography-tls-migration/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/post-quantum-cryptography-tls-migration/</guid><description>Quantum computing threatens the TLS protocol. This is your blueprint for understanding the threat, navigating the hybrid solution, and migrating to Post-Quantum TLS to protect your data.</description><pubDate>Fri, 08 Aug 2025 10:00:00 GMT</pubDate></item><item><title>From Zero to Root: Deconstructing the NVIDIA Triton RCE Vulnerability</title><link>https://blog.ogwilliam.com/post/nvidia-triton-rce-vulnerability-chain/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/nvidia-triton-rce-vulnerability-chain/</guid><description>A critical RCE vulnerability chain in NVIDIA Triton Inference Server (CVE-2025-23319) allows unauthenticated attackers to take full control. Learn how the attack works and how to defend your AI infrastructure.</description><pubDate>Tue, 05 Aug 2025 10:00:00 GMT</pubDate></item><item><title>Passkeys Were the Start: Google&apos;s DBSC Will Make Cookie Theft Obsolete</title><link>https://blog.ogwilliam.com/post/google-dbsc-cookie-theft-obsolete/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-dbsc-cookie-theft-obsolete/</guid><description>Passkeys secured the login, but session hijacking via cookie theft remains a critical threat. Discover how Google&apos;s DBSC is set to make this attack vector a relic of the past.</description><pubDate>Fri, 01 Aug 2025 13:00:00 GMT</pubDate></item><item><title>ServiceNow &apos;Counter-Strike&apos; Flaw (CVE-2025-3648) Explained</title><link>https://blog.ogwilliam.com/post/servicenow-counter-strike-vulnerability-cve-2025-3648/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/servicenow-counter-strike-vulnerability-cve-2025-3648/</guid><description>Critical vulnerability in ServiceNow (CVE-2025-3648) allows a low-privilege user to gain full admin access. Learn how the &apos;Counter-Strike&apos; attack works and how to mitigate it.</description><pubDate>Mon, 28 Jul 2025 16:00:00 GMT</pubDate></item><item><title>Critical SharePoint Zero-Day Under Attack: Action Plan for CVE-2025-53770</title><link>https://blog.ogwilliam.com/post/sharepoint-zeroday-cve-2025-53770-toolshell/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/sharepoint-zeroday-cve-2025-53770-toolshell/</guid><description>Critical SharePoint RCE (CVE-2025-53770): What SecOps teams must do right now, from patching to hunting the &apos;ToolShell&apos; campaign. Your immediate action plan.</description><pubDate>Wed, 23 Jul 2025 22:00:00 GMT</pubDate></item><item><title>Critical SharePoint RCE (CVE-2025-53770)</title><link>https://blog.ogwilliam.com/post/sharepoint-rce-vulnerability-cve-2025-53770/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/sharepoint-rce-vulnerability-cve-2025-53770/</guid><description>Critical, actively exploited zero-day RCE vulnerability in SharePoint Server (CVE-2025-53770). This is your guide to understanding, identifying, and mitigating the threat immediately.</description><pubDate>Mon, 21 Jul 2025 15:00:00 GMT</pubDate></item><item><title>Stop Chasing Developers</title><link>https://blog.ogwilliam.com/post/scale-security-with-platform-engineering/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/scale-security-with-platform-engineering/</guid><description>Stop chasing developers. Scale security by building a secure &apos;paved road&apos; with platform engineering. A CISO&apos;s guide to a more efficient, secure, and collaborative DevSecOps model.</description><pubDate>Sat, 19 Jul 2025 10:00:00 GMT</pubDate></item><item><title>Your SIEM is Blind: The New Playbook for Cloud Threat Detection</title><link>https://blog.ogwilliam.com/post/modern-cloud-threat-detection-playbook/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/modern-cloud-threat-detection-playbook/</guid><description>Your SIEM is struggling in the cloud. Discover why modern cloud threat detection requires a radically new playbook focused on context, runtime, and identity.</description><pubDate>Fri, 18 Jul 2025 13:00:00 GMT</pubDate></item><item><title>Your AI Strategy’s Biggest Blind Spot: MCP Vulnerability Scanning</title><link>https://blog.ogwilliam.com/post/mcp-vulnerability-scanning/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mcp-vulnerability-scanning/</guid><description>Your AI strategy&apos;s biggest blind spot is the Machine Control Plane (MCP). Learn about critical threats like Tool Poisoning and how specialized MCP vulnerability scanning is essential for security.</description><pubDate>Sat, 12 Jul 2025 10:00:00 GMT</pubDate></item><item><title>The AI Revolution&apos;s Double-Edged Sword: A CISO&apos;s Guide to AI Security</title><link>https://blog.ogwilliam.com/post/ciso-guide-ai-security-risks/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ciso-guide-ai-security-risks/</guid><description>AI is your new competitive advantage and your greatest security blind spot. This CISO&apos;s guide, based on SANS, NIST, and Tenable research, unveils the critical risks and provides a blueprint for secure AI adoption.</description><pubDate>Fri, 11 Jul 2025 10:00:00 GMT</pubDate></item><item><title>RCE in mcp-remote (CVE-2025-6514)</title><link>https://blog.ogwilliam.com/post/mcp-remote-rce-vulnerability-cve-2025-6514/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mcp-remote-rce-vulnerability-cve-2025-6514/</guid><description>Critical RCE vulnerability (CVE-2025-6514) in Anthropic&apos;s mcp-remote exposes developer machines. Learn how attackers can chain exploits to take control and why securing AI agents is paramount.</description><pubDate>Wed, 09 Jul 2025 22:00:00 GMT</pubDate></item><item><title>Critical RCE in Anthropic&apos;s MCP Inspector (CVE-2025-49596)</title><link>https://blog.ogwilliam.com/post/anthropic-mcp-inspector-rce-vulnerability/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/anthropic-mcp-inspector-rce-vulnerability/</guid><description>Critical RCE vulnerability (CVE-2025-49596) in Anthropic&apos;s MCP Inspector exposes developer machines. Learn how attackers can chain exploits to take control and why securing AI agents is paramount.</description><pubDate>Sat, 05 Jul 2025 10:00:00 GMT</pubDate></item><item><title>GCP Defense-in-Depth: IAM Deny &amp; Org Policies</title><link>https://blog.ogwilliam.com/post/gcp-defense-in-depth-iam-deny-org-policies/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-defense-in-depth-iam-deny-org-policies/</guid><description>Transform your GCP security with IAM Deny and Organization Policies. This CISO&apos;s guide to defense-in-depth shows how to build unbreakable guardrails and simplify cloud security.</description><pubDate>Fri, 04 Jul 2025 13:00:00 GMT</pubDate></item><item><title>A Practical Blueprint for Zero Trust on GCP</title><link>https://blog.ogwilliam.com/post/zero-trust-gcp-implementation-blueprint/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/zero-trust-gcp-implementation-blueprint/</guid><description>The perimeter is dead. Discover the ultimate blueprint for implementing a Zero Trust security model on Google Cloud Platform (GCP). A CISO&apos;s guide to modern security.</description><pubDate>Mon, 30 Jun 2025 10:00:00 GMT</pubDate></item><item><title>Cache Me If You Can: Smuggling Malware Through Browser</title><link>https://blog.ogwilliam.com/post/browser-cache-smuggling-malware-delivery/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/browser-cache-smuggling-malware-delivery/</guid><description>Discover Browser Cache Smuggling, a stealthy attack that uses your browsers cache to deliver malware and hijacks trusted apps like Microsoft Teams. Learn how it works and how to defend against it.</description><pubDate>Sun, 29 Jun 2025 10:00:00 GMT</pubDate></item><item><title>We Replaced Our Boring ISSP with a GCP AI Agent</title><link>https://blog.ogwilliam.com/post/gcp-ai-agent-for-issp/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-ai-agent-for-issp/</guid><description>How we transformed our dense Information System Security Policy (ISSP) into an interactive GCP AI agent, improving employee adoption and reducing security risks.</description><pubDate>Fri, 27 Jun 2025 22:00:00 GMT</pubDate></item><item><title>Audit Manager: Google Cloud New Controls Feature</title><link>https://blog.ogwilliam.com/post/google-cloud-ai-controls-framework/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/google-cloud-ai-controls-framework/</guid><description>Audit smarter: Introducing Google Cloud&apos;s Recommended AI Controls Framework. Automate compliance and secure your generative AI workloads with evidence-based controls.</description><pubDate>Fri, 27 Jun 2025 10:00:00 GMT</pubDate></item><item><title>Unlocking the Kingdom: A CISO&apos;s Guide to GCP IAM Privilege Escalation</title><link>https://blog.ogwilliam.com/post/gcp-iam-privilege-escalation-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-iam-privilege-escalation-guide/</guid><description>A CISO&apos;s guide to GCP IAM privilege escalation. Uncover common attack vectors, understand misconfigurations, and learn critical mitigation strategies to secure your Google Cloud environment.</description><pubDate>Wed, 25 Jun 2025 20:00:00 GMT</pubDate></item><item><title>The CISO&apos;s Essential Guide to Security Audits: Objectives &amp; Types</title><link>https://blog.ogwilliam.com/post/ciso-guide-security-audits/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ciso-guide-security-audits/</guid><description>Master security audits: Explore objectives, types (technical, organizational, compliance), methodologies, and key pitfalls to avoid for robust cybersecurity. Your CISO&apos;s guide.</description><pubDate>Sat, 21 Jun 2025 10:00:00 GMT</pubDate></item><item><title>Navigating the Storm: Unmasking Critical Cloud Security Risks in 2025</title><link>https://blog.ogwilliam.com/post/cloud-security-risks-2025-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/cloud-security-risks-2025-guide/</guid><description>Unveiling critical cloud security risks for 2025: Exposed data, insecure secrets, AI vulnerabilities, and &apos;toxic trilogies&apos; loom. Your essential guide to mitigation.</description><pubDate>Fri, 20 Jun 2025 10:00:00 GMT</pubDate></item><item><title>The Invisible Threat: Securing Open-Source Credentials in Supply Chain</title><link>https://blog.ogwilliam.com/post/open-source-credential-security-deps-dev/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/open-source-credential-security-deps-dev/</guid><description>Uncover the hidden risks of leaked credentials in your open-source dependencies. Learn how Google Cloud&apos;s deps.dev is securing the software supply chain at scale.</description><pubDate>Tue, 17 Jun 2025 17:00:00 GMT</pubDate></item><item><title>EchoLeak: Zero-Click AI Vulnerability Exposed M365 Copilot Data</title><link>https://blog.ogwilliam.com/post/echoleak-zero-click-ai-vulnerability-m365-copilot/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/echoleak-zero-click-ai-vulnerability-m365-copilot/</guid><description>Critical EchoLeak zero-click AI vulnerability in Microsoft 365 Copilot (CVE-2025-32711) allowed sensitive data exfiltration without user interaction. Learn how it worked and Microsoft&apos;s response.</description><pubDate>Mon, 16 Jun 2025 10:00:00 GMT</pubDate></item><item><title>The Quantum Horizon: Your PQC Migration Strategy Can&apos;t Wait</title><link>https://blog.ogwilliam.com/post/post-quantum-cryptography-migration-strategy/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/post-quantum-cryptography-migration-strategy/</guid><description>Quantum computers threaten current encryption. Discover Post-Quantum Cryptography (PQC), why migration is urgent, and how to build your strategic PQC roadmap now.</description><pubDate>Fri, 06 Jun 2025 20:00:00 GMT</pubDate></item><item><title>Securing AI in Multi-Cloud</title><link>https://blog.ogwilliam.com/post/ai-multi-cloud-security-guide/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ai-multi-cloud-security-guide/</guid><description>Master AI multi-cloud security. Gain visibility, manage risks, and implement behavioral threat detection. Your expert guide to securing AI across diverse cloud platforms.</description><pubDate>Thu, 05 Jun 2025 10:00:00 GMT</pubDate></item><item><title>BadSuccessor: Unmasking a Critical Privilege Escalation in Active Directory</title><link>https://blog.ogwilliam.com/post/badsuccessor-ad-privilege-escalation/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/badsuccessor-ad-privilege-escalation/</guid><description>Uncover BadSuccessor: a critical Active Directory privilege escalation vulnerability in Windows Server 2025&apos;s dMSA feature. Learn how it works, detection, and mitigation.</description><pubDate>Tue, 03 Jun 2025 10:00:00 GMT</pubDate></item><item><title>Fortifying Your Digital Fortress: Mastering DDoS Protection with GCP</title><link>https://blog.ogwilliam.com/post/gcp-armor-ddos-protection/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/gcp-armor-ddos-protection/</guid><description>Shield your GCP applications from devastating DDoS attacks with Google Cloud Armor. Explore Layer 3/4 &amp; L7 protection, WAF, and Adaptive Protection. Secure your cloud now!</description><pubDate>Sat, 31 May 2025 10:00:00 GMT</pubDate></item><item><title>Text-to-Malware: Fake AI Platforms as Cybercriminal Playgrounds</title><link>https://blog.ogwilliam.com/post/ai-themed-malware-fake-platforms/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ai-themed-malware-fake-platforms/</guid><description>Beware of AI-themed malware! Cybercriminals use fake AI video generators to spread infostealers like Noodlophile &amp; STARKVEIL. Learn how to stay safe.</description><pubDate>Wed, 28 May 2025 10:00:00 GMT</pubDate></item><item><title>Linux Foundations New Cybersecurity Skills Framework Explained</title><link>https://blog.ogwilliam.com/post/linux-foundation-cybersecurity-skills-framework/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/linux-foundation-cybersecurity-skills-framework/</guid><description>Bridge the cyber skills gap with the Linux Foundations free Cybersecurity Skills Framework. Define roles, identify needs, and build a resilient team. Learn more!</description><pubDate>Tue, 27 May 2025 09:00:00 GMT</pubDate></item><item><title>DORA Regulation: Expert Guide to EU Compliance &amp; Resilience</title><link>https://blog.ogwilliam.com/post/dora-regulation-expert-guide-compliance/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/dora-regulation-expert-guide-compliance/</guid><description>Master the EU&apos;s DORA regulation. Uncover key requirements, ICT risk management, and compliance strategies for financial entities. Your expert guide to DORA readiness.</description><pubDate>Fri, 16 May 2025 11:00:00 GMT</pubDate></item><item><title>SAML vs OAuth vs OpenID Connect: A Comprehensive Comparison</title><link>https://blog.ogwilliam.com/post/saml-oauth-openid-connect-comparison/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/saml-oauth-openid-connect-comparison/</guid><description>Discover the key differences between SAML, OAuth, and OpenID Connect. Learn how these authentication protocols work and which one is best for your needs.</description><pubDate>Thu, 15 May 2025 08:00:00 GMT</pubDate></item><item><title>Microsoft&apos;s New Email Rules for Bulk Senders: SPF, DKIM, DMARC</title><link>https://blog.ogwilliam.com/post/microsoft-new-email-rules-bulk-senders/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/microsoft-new-email-rules-bulk-senders/</guid><description>Discover Microsoft&apos;s new email security rules for bulk senders. Learn about SPF, DKIM, DMARC, and how to ensure compliance for better email deliverability.</description><pubDate>Wed, 14 May 2025 20:00:00 GMT</pubDate></item><item><title>LockBit Hacked : Leaked Data Exposes Victim Secrets &amp; Failures</title><link>https://blog.ogwilliam.com/post/lockbit-hacked-data-leak-analysis/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/lockbit-hacked-data-leak-analysis/</guid><description>The LockBit ransomware gang is hacked (again). Discover the leak exposing victim negotiations, internal data, affiliate plaintext passwords, and the blow to the top RaaS operation.</description><pubDate>Mon, 12 May 2025 20:00:00 GMT</pubDate></item><item><title>OWASP&apos;s MAESTRO: Securing Agentic AI&apos;s Next Frontier</title><link>https://blog.ogwilliam.com/post/owasp-maestro-agentic-ai-security/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/owasp-maestro-agentic-ai-security/</guid><description>OWASP unveils guide for AI Agent Security. Explore the MAESTRO framework for threat modeling Multi-Agent Systems (MAS), key agentic threats, and mitigation strategies.</description><pubDate>Wed, 07 May 2025 10:00:00 GMT</pubDate></item><item><title>SBOMs: The Key to Software Supply Chain Security or an Unachievable Fantasy?</title><link>https://blog.ogwilliam.com/post/sboms-the-key-to-software-supply-chain-security-or-an-unachievable-fantasy/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/sboms-the-key-to-software-supply-chain-security-or-an-unachievable-fantasy/</guid><description>Unlock software supply chain security with SBOMs. Explore what an SBOM is, why it&apos;s vital for vulnerability management &amp; compliance, current challenges, and future outlook.</description><pubDate>Tue, 06 May 2025 22:00:00 GMT</pubDate></item><item><title>Zero-Days Exploited in 2024: Google GTIG Report</title><link>https://blog.ogwilliam.com/post/zero-days-exploded-in-2024/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/zero-days-exploded-in-2024/</guid><description>Google&apos;s 2024 Zero-Day Report reveals 75 exploited in the wild. Discover the critical shift towards enterprise targets.</description><pubDate>Wed, 30 Apr 2025 20:00:00 GMT</pubDate></item><item><title>Critical Remote Code Execution (CVE-2025-34028) in Commvault Command Center</title><link>https://blog.ogwilliam.com/post/commvault-vulnerability-cve-2025-34028-exposes-command-center-to-remote-code-execution/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/commvault-vulnerability-cve-2025-34028-exposes-command-center-to-remote-code-execution/</guid><description>Critical Commvault vulnerability (CVE-2025-34028) allows unauthenticated RCE in Command Center. Patch immediately to prevent full system compromise.</description><pubDate>Fri, 25 Apr 2025 13:00:00 GMT</pubDate></item><item><title>Hybrid Identity Security: The Hidden Permissions Risk in Entra ID Sync</title><link>https://blog.ogwilliam.com/post/hybrid-identity-security-the-hidden-permissions-risk-in-entra-id-synchronization/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/hybrid-identity-security-the-hidden-permissions-risk-in-entra-id-synchronization/</guid><description>Unpack Hybrid Identity Security risks: Discover how Entra ID synchronization roles retain potent implicit permissions, creating exposure even after hardening. Learn to protect your hybrid environment.</description><pubDate>Fri, 25 Apr 2025 12:00:00 GMT</pubDate></item><item><title>Alert Fatigue: The Silent Killer Drowning Your Cybersecurity Team in Noise</title><link>https://blog.ogwilliam.com/post/alert-fatigue-the-silent-killer-in-cybersecurity/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/alert-fatigue-the-silent-killer-in-cybersecurity/</guid><description>Combat alert fatigue in cybersecurity. Understand causes, consequences, and proven strategies to reduce noise, prioritize threats, and boost SOC effectiveness.</description><pubDate>Thu, 24 Apr 2025 20:00:00 GMT</pubDate></item><item><title>Key Insights from the Verizon 2025 DBIR</title><link>https://blog.ogwilliam.com/post/decoding-the-digital-battlefield-verizon-2025-dbir-insights/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/decoding-the-digital-battlefield-verizon-2025-dbir-insights/</guid><description>Deep dive into the Verizon 2025 DBIR: Vulnerability exploitation surges (34% increase), edge devices targeted, third-party risk doubles. Get key findings &amp; analysis.</description><pubDate>Wed, 23 Apr 2025 22:00:00 GMT</pubDate></item><item><title>ConfusedComposer: GCP Cloud Build vunerability via PyPI Packages</title><link>https://blog.ogwilliam.com/post/confusedcomposer-vulnerability-explained/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/confusedcomposer-vulnerability-explained/</guid><description>Unpacking ConfusedComposer: Discover how Tenable found a GCP vulnerability allowing privilege escalation via malicious PyPI packages in Cloud Composer &amp; Cloud Build.</description><pubDate>Tue, 22 Apr 2025 22:00:00 GMT</pubDate></item><item><title>Unmasking the Enemy - Understanding and Mitigating Insider Threats</title><link>https://blog.ogwilliam.com/post/unmasking-the-enemy-within-understanding-and-mitigating-insider-threats/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/unmasking-the-enemy-within-understanding-and-mitigating-insider-threats/</guid><description>Unmask insider threats: malicious vs. accidental. Learn detection indicators (behavioral, technical), prevention strategies (access control, Zero Trust), &amp; mitigation.</description><pubDate>Fri, 18 Apr 2025 14:00:00 GMT</pubDate></item><item><title>SSL/TLS Certificate Lifespan Reduction to 47 Days by 2029: Are You Ready?</title><link>https://blog.ogwilliam.com/post/ssl-tls-certificate-lifespan-reduction-2029/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/ssl-tls-certificate-lifespan-reduction-2029/</guid><description>SSL/TLS certificate lifespan reduction to 47 days by 2029. Understand the impact, timelines, and why automation is now critical.</description><pubDate>Thu, 17 Apr 2025 01:00:00 GMT</pubDate></item><item><title>Google Cloud Bridges SSE and Cloud WAN with New NCC Gateway</title><link>https://blog.ogwilliam.com/post/sse-cloud-wan/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/sse-cloud-wan/</guid><description>Google Cloud introduces NCC Gateway, integrating third-party SSE solutions with Cloud WAN for unified, high-performance secure access for hybrid workforces.</description><pubDate>Thu, 17 Apr 2025 00:00:00 GMT</pubDate></item><item><title>MCP Security (Part 2)</title><link>https://blog.ogwilliam.com/post/mcp-security-part-2/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mcp-security-part-2/</guid><description>Explore critical MCP Security Threats (Part 2): Deep dive into lifecycle risks (name collision, sandbox escape) &amp; Tool Poisoning Attacks. Learn vital mitigation steps.</description><pubDate>Mon, 14 Apr 2025 22:00:00 GMT</pubDate></item><item><title>MCP Security (Part 1)</title><link>https://blog.ogwilliam.com/post/mcp-security-part-1/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/mcp-security-part-1/</guid><description>Unpacking MCP Security (Part 1): Explore the Model Context Protocol connecting LLMs to data/tools and uncover the inherent security risks developers must address now.</description><pubDate>Sun, 13 Apr 2025 22:00:00 GMT</pubDate></item><item><title>Containers vs Virtual Machines (VMs)</title><link>https://blog.ogwilliam.com/post/unpacking-the-differences-for-optimal-application-deployment/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/unpacking-the-differences-for-optimal-application-deployment/</guid><description>Containers vs Virtual Machines (VMs): Explore the key differences in isolation, performance, security, and use cases to choose the right technology for your apps.</description><pubDate>Thu, 10 Apr 2025 22:00:00 GMT</pubDate></item><item><title>Data Exfiltration: The Threats Siphoning Your Most Valuable Assets</title><link>https://blog.ogwilliam.com/post/data-exfiltration-the-threats-siphoning-your-most-valuable-assets/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/data-exfiltration-the-threats-siphoning-your-most-valuable-assets/</guid><description>Uncover data exfiltration techniques targeting your sensitive cloud data. Learn expert prevention strategies, detection signs, and incident response steps.</description><pubDate>Wed, 09 Apr 2025 22:00:00 GMT</pubDate></item><item><title>OpenSSL 3.5 LTS Arrives: Fortifying the Future with PQC and QUIC</title><link>https://blog.ogwilliam.com/post/openssl-35-lts-arrives-fortifying-the-future-with-pqc-and-quic/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/openssl-35-lts-arrives-fortifying-the-future-with-pqc-and-quic/</guid><description>Explore OpenSSL 3.5 LTS: Future-proof your security with Post-Quantum Cryptography (PQC), server-side QUIC, and vital TLS updates. Migrate today!</description><pubDate>Tue, 08 Apr 2025 22:00:00 GMT</pubDate></item><item><title>Understanding Data Sovereignty in a Borderless Digital World</title><link>https://blog.ogwilliam.com/post/understanding-data-sovereignty-in-a-borderless-digital-world/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/understanding-data-sovereignty-in-a-borderless-digital-world/</guid><description>Navigate Data Sovereignty complexities in the cloud era. Understand GDPR, digital sovereignty, trusted tech &amp; ensure compliance across borders</description><pubDate>Wed, 02 Apr 2025 22:00:00 GMT</pubDate></item><item><title>ImageRunner Vulnerability: Privilege Escalation in GCP Cloud Run</title><link>https://blog.ogwilliam.com/post/imagerunner-vulnerability-privilege-escalation-in-gcp-cloud-run/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/imagerunner-vulnerability-privilege-escalation-in-gcp-cloud-run/</guid><description>Explore the ImageRunner vulnerability: A patched GCP Cloud Run privilege escalation flaw. See how IAM permissions allowed unauthorized image access via service agents.</description><pubDate>Tue, 01 Apr 2025 22:00:00 GMT</pubDate></item><item><title>Firewall that Annoys Hackers into Giving Up</title><link>https://blog.ogwilliam.com/post/cybersecurity-breakthrough-new-firewall-uses-aggressive-pop-up-ads-to-annoy-hackers-into-giving-up/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/cybersecurity-breakthrough-new-firewall-uses-aggressive-pop-up-ads-to-annoy-hackers-into-giving-up/</guid><description>Discover Annoyance-Based Threat Mitigation! The AdNauseam Firewall 5000 uses pop-up ads to frustrate hackers. A revolutionary cyber defense approach.</description><pubDate>Mon, 31 Mar 2025 22:00:00 GMT</pubDate></item><item><title>Embracing Zero Trust Security for Resilient Defense</title><link>https://blog.ogwilliam.com/post/embracing-zero-trust-security-for-resilient-defense/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/embracing-zero-trust-security-for-resilient-defense/</guid><description>Unlock robust defense with Zero Trust Security. Move beyond outdated perimeters, verify everything, enforce least privilege, and stop breaches. Learn how</description><pubDate>Sun, 30 Mar 2025 22:00:00 GMT</pubDate></item><item><title>What is the Principle of Least Privilege ?</title><link>https://blog.ogwilliam.com/post/what-is-the-principle-of-least-privilege-/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/what-is-the-principle-of-least-privilege-/</guid><description>Follow the Principle of Least Privilege (PoLP) for robust cybersecurity. Implement Zero Trust, RBAC, &amp; PAM for secure access management. Elevate your data security today.</description><pubDate>Sat, 29 Mar 2025 23:00:00 GMT</pubDate></item><item><title>Next-generation firewall (NGFW) vs. firewall-as-a-service (FWaaS)</title><link>https://blog.ogwilliam.com/post/next-generation-firewall-ngfw-vs-firewall-as-a-service-fwaas/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/next-generation-firewall-ngfw-vs-firewall-as-a-service-fwaas/</guid><description>Navigate the evolving world of network security with our detailed guide on NGFW vs. FWaaS. Discover the differences, benefits, and which solution best suits your business needs</description><pubDate>Tue, 25 Mar 2025 23:00:00 GMT</pubDate></item><item><title>Secure Access Service Edge (SASE): Advancing Modern Network Security​</title><link>https://blog.ogwilliam.com/post/secure-access-service-edge-sase-enhancing-network-security-in-the-modern-era/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/secure-access-service-edge-sase-enhancing-network-security-in-the-modern-era/</guid><description>Explore Secure Access Service Edge (SASE), a unified cloud-based model combining network connectivity with security services like ZTNA, CASB, DLP, SD-WAN, and FWaaS to enhance cybersecurity</description><pubDate>Tue, 25 Mar 2025 23:00:00 GMT</pubDate></item><item><title>What is Data Loss Prevention (DLP) in the Context of SASE ?</title><link>https://blog.ogwilliam.com/post/what-is-data-loss-prevention-dlp-in-the-context-of-sase/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/what-is-data-loss-prevention-dlp-in-the-context-of-sase/</guid><description>Discover Data Loss Prevention (DLP) definition to safeguard sensitive data. Learn how DLP prevents data breaches, ensures compliance, and mitigates insider threats. Protect your data today.</description><pubDate>Tue, 25 Mar 2025 23:00:00 GMT</pubDate></item><item><title>What is a CASB (Cloud Access Security Broker) ?</title><link>https://blog.ogwilliam.com/post/what-is-a-casb-cloud-access-security-broker-/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/what-is-a-casb-cloud-access-security-broker-/</guid><description>Explore CASB (Cloud Access Security Broker) solutions for robust cloud security. Learn how CASBs prevent data loss, control Shadow IT, and ensure SaaS compliance. Secure your cloud today.</description><pubDate>Mon, 24 Mar 2025 23:00:00 GMT</pubDate></item><item><title>A Deep Dive into Passwordless Authentication</title><link>https://blog.ogwilliam.com/post/a-deep-dive-into-passwordless-authentication/</link><guid isPermaLink="true">https://blog.ogwilliam.com/post/a-deep-dive-into-passwordless-authentication/</guid><description>Explore passwordless authentication methods, benefits, security aspects, implementation strategies, and future trends in cybersecurity.</description><pubDate>Wed, 12 Feb 2025 00:00:00 GMT</pubDate></item></channel></rss>