<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>IONSEC Resources</title><description>Real-world cyber attacks, expert analysis, and the latest security trends from the IONSEC incident response team.</description><link>https://www.ionsec.io</link><language>en-us</language><item><title>IONSEC TRACE: Leave No Model Untraced — Open-Source Forensics for the AI Harness</title><link>https://www.ionsec.io/resources/ionsec-trace-ai-harness-forensics</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-trace-ai-harness-forensics</guid><description>IONSEC TRACE is an open-source, forensically sound collector and analyzer for AI harness evidence — now shipping a Python CLI and a Go binary with near-identical capabilities, a 103-rule secret detector, and conversation secret hunting.</description><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>dfir</category><category>ai-forensics</category><category>shadow-ai</category><category>velociraptor</category><category>secret-detection</category><author>IONSEC DFIR Division</author></item><item><title>XSS2Shell: One Failed Login to PHP on the Server</title><link>https://www.ionsec.io/resources/xss2shell-wordpress-pre-auth-xss-to-rce</link><guid isPermaLink="true">https://www.ionsec.io/resources/xss2shell-wordpress-pre-auth-xss-to-rce</guid><description>CVE-2026-64638 is a reflected XSS on the WordPress login page — the finding most teams close as medium. Six gadgets sit between it and a PHP shell, and every one of them was already in core. Here is the chain, the log signatures, and what to harden after you patch.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>Article</category><category>research</category><category>threat-intelligence</category><category>wordpress</category><category>web-security</category><category>xss</category><category>incident-response</category><category>cve-2026-64638</category><author>IONSEC Team</author></item><item><title>XSS2Shell: מניסיון התחברות כושל אחד ועד PHP על השרת</title><link>https://www.ionsec.io/resources/xss2shell-wordpress-pre-auth-xss-to-rce-he</link><guid isPermaLink="true">https://www.ionsec.io/resources/xss2shell-wordpress-pre-auth-xss-to-rce-he</guid><description>CVE-2026-64638 היא חולשת XSS מוחזר בעמוד ההתחברות של וורדפרס — בדיוק הממצא שרוב הצוותים סוגרים כבינוני. בין החולשה הזו לבין הרצת PHP על השרת עומדים שישה שלבים נוספים, וכולם כבר היו בליבת המערכת. הנה השרשרת המלאה, חתימות הזיהוי בלוגים, וההקשחה שצריך לעשות אחרי העדכון.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>Article</category><category>research</category><category>threat-intelligence</category><category>israel</category><category>wordpress</category><category>web-security</category><category>xss</category><category>incident-response</category><category>cve-2026-64638</category><author>IONSEC Team</author></item><item><title>The Machine Has No Disk: Forensic Readiness for AI Agent Runtimes</title><link>https://www.ionsec.io/resources/ai-agent-runtime-forensics</link><guid isPermaLink="true">https://www.ionsec.io/resources/ai-agent-runtime-forensics</guid><description>Forensic readiness for AI agent runtimes — Cloudflare Computer, NVIDIA OpenShell, and the collapse of the endpoint as an evidence source.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>Article</category><category>dfir</category><category>agentic-ai</category><category>agent-runtimes</category><category>evidence-engineering</category><author>Nir Halfon</author></item><item><title>Coercion to krbtgt: NTLM Relay and ADCS ESC8 in 2026</title><link>https://www.ionsec.io/resources/coercion-to-krbtgt-ntlm-relay-and-adcs-esc8-in-2026</link><guid isPermaLink="true">https://www.ionsec.io/resources/coercion-to-krbtgt-ntlm-relay-and-adcs-esc8-in-2026</guid><description>A full ESC8 walkthrough against a lab domain, then the forensic reconstruction — why the certificate serial, not the source IP, is the artifact that ties the whole chain together.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>Article</category><category>adcs</category><category>esc8</category><category>ntlm-relay</category><category>active-directory</category><category>dfir</category><category>threat-intelligence</category><author>IONSEC Team</author></item><item><title>The 60-Minute Site: Phishing That Deletes Its Own Evidence</title><link>https://www.ionsec.io/resources/cloudflare-drop-60-minute-phishing</link><guid isPermaLink="true">https://www.ionsec.io/resources/cloudflare-drop-60-minute-phishing</guid><description>Cloudflare Drop publishes a site on a trusted workers.dev address with no account, then deletes it after an hour. That one-hour fuse burns your forensic evidence with it.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>Blog</category><category>phishing</category><category>cloudflare</category><category>detection-engineering</category><category>threat-hunting</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>MAES: The M365 Analyzer &amp; Extractor Suite</title><link>https://www.ionsec.io/resources/maes-the-m365-analyzer-extractor-suite</link><guid isPermaLink="true">https://www.ionsec.io/resources/maes-the-m365-analyzer-extractor-suite</guid><description>At IONSEC, we’re excited to introduce MAES: The M365 Analyzer &amp; Extractor Suite — an open-source platform purpose-built to simplify and accelerate Microsoft 365 (M365) forensic investigations.</description><pubDate>Wed, 20 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>dfir</category><category>microsoft-365</category><category>cloud-forensics</category><author>IONSEC Team</author></item><item><title>Tikun13 Checker – כלי קוד פתוח לבדיקת יישום תיקון 13</title><link>https://www.ionsec.io/resources/tikun13checker</link><guid isPermaLink="true">https://www.ionsec.io/resources/tikun13checker</guid><description>Tikun13 Checker הוא כלי קוד פתוח, מבוסס דפדפן, שפותח על ידי IONSEC כדי לסייע לארגונים בישראל ליישם את דרישות תיקון 13 לחוק הגנת הפרטיות.</description><pubDate>Sun, 17 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>compliance</category><category>privacy</category><category>tikun-13</category><category>israel</category><author>IONSEC Team</author></item><item><title>DO Audit Log Scraper v2.0</title><link>https://www.ionsec.io/resources/do-audit-log-scraper-v2-0</link><guid isPermaLink="true">https://www.ionsec.io/resources/do-audit-log-scraper-v2-0</guid><description>The DO Audit Log Scraper is a Chrome/Chromium extension that enables forensic-grade audit log extraction.</description><pubDate>Mon, 11 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>dfir</category><category>audit-logs</category><category>digitalocean</category><author>IONSEC Team</author></item><item><title>FlareInspect - Cloudflare Assessment Tool</title><link>https://www.ionsec.io/resources/flareinspect</link><guid isPermaLink="true">https://www.ionsec.io/resources/flareinspect</guid><description>FlareInspect is a CLI-based assessment framework designed to revolutionize how organizations evaluate and monitor their Cloudflare security posture.</description><pubDate>Sun, 03 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>cloudflare</category><category>cloud-security</category><category>security-assessment</category><author>IONSEC Team</author></item><item><title>Forti-DFIR: Open-Source Framework for Fortinet Forensics &amp; Incident Response</title><link>https://www.ionsec.io/resources/forti-dfir-open-source-framework-for-fortinet-forensics-incident-response</link><guid isPermaLink="true">https://www.ionsec.io/resources/forti-dfir-open-source-framework-for-fortinet-forensics-incident-response</guid><description>At IONSEC, we’re proud to introduce Forti-DFIR — an open-source initiative created to give security teams the tools they need for forensic investigations and incident response in Fortinet environments.</description><pubDate>Fri, 01 Aug 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>dfir</category><category>fortinet</category><category>network-forensics</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>When Research Meets Reality</title><link>https://www.ionsec.io/resources/when-research-meets-reality</link><guid isPermaLink="true">https://www.ionsec.io/resources/when-research-meets-reality</guid><description>How Threat-Actor Campaigns Cast a Shadow on Legitimate npm Binaries (and What IONSEC IR Sees in the wild)</description><pubDate>Sun, 06 Jul 2025 00:00:00 GMT</pubDate><category>Case Study</category><category>supply-chain</category><category>npm</category><category>threat-intelligence</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>How a Weaponized Zoom Installer Opened the Door for BlueNoroff</title><link>https://www.ionsec.io/resources/how-a-weaponized-zoom-installer-opened-the-door-for-bluenoroff</link><guid isPermaLink="true">https://www.ionsec.io/resources/how-a-weaponized-zoom-installer-opened-the-door-for-bluenoroff</guid><description>IONSEC investigates a BlueNoroff intrusion that began with a weaponized Zoom installer, combining deepfakes, social engineering and evasive scripting.</description><pubDate>Thu, 03 Jul 2025 00:00:00 GMT</pubDate><category>Case Study</category><category>bluenoroff</category><category>apt</category><category>social-engineering</category><category>incident-response</category><category>macos</category><author>IONSEC Team</author></item><item><title>Iranian Threat Actor Hijacks DNS</title><link>https://www.ionsec.io/resources/iranian-threat-actor-hijacks-dns</link><guid isPermaLink="true">https://www.ionsec.io/resources/iranian-threat-actor-hijacks-dns</guid><description>קבוצת התקיפה האיראנית פתח אלקודס פרצה לרשם דומיינים ישראלי ושינתה רשומות DNS ו-MX של יותר מ-1,000 דומיינים, והפנתה אותם לשרת זדוני ולדף תעמולה.</description><pubDate>Wed, 02 Jul 2025 00:00:00 GMT</pubDate><category>Case Study</category><category>dns-hijacking</category><category>iran</category><category>apt</category><category>incident-response</category><category>israel</category><author>IONSEC Team</author></item><item><title>RansomProtect – Open-Source Defense Against Ransomware &amp; Wipers</title><link>https://www.ionsec.io/resources/ransomprotect---open-source-defense-against-ransomware-wipers</link><guid isPermaLink="true">https://www.ionsec.io/resources/ransomprotect---open-source-defense-against-ransomware-wipers</guid><description>RansomProtect is our open-source tool that detects and blocks ransomware and wipers early in the infection chain, where built-in OS defenses fall short.</description><pubDate>Tue, 01 Jul 2025 00:00:00 GMT</pubDate><category>Tools</category><category>open-source</category><category>ransomware</category><category>wiper</category><category>endpoint-security</category><author>IONSEC Team</author></item><item><title>IONSEC at the IMPROVATE CISO Summit</title><link>https://www.ionsec.io/resources/ionsec-at-the-improvate-ciso-summit</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-at-the-improvate-ciso-summit</guid><description>Two months ago, IONSEC had the privilege of participating in the CISO Summit by IMPROVATE — a premier platform for connecting with Israel’s leading cybersecurity executives and security professionals.</description><pubDate>Mon, 30 Jun 2025 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>conference</category><category>ciso</category><author>IONSEC Team</author></item><item><title>LIVE from GISEC Global 2025 – Israeli Pavilion</title><link>https://www.ionsec.io/resources/gisec-2025</link><guid isPermaLink="true">https://www.ionsec.io/resources/gisec-2025</guid><description>IONSEC is proud to showcase an exclusive preview of our next-generation Digital Forensics and Incident Response (DFIR) platform at GISEC Global 2025, one of the world’s premier cybersecurity events in Dubai.</description><pubDate>Tue, 06 May 2025 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>gisec</category><category>conference</category><author>IONSEC Team</author></item><item><title>Why Malware Analysis Training is Vital: Lessons from Real-World Cyber Attacks</title><link>https://www.ionsec.io/resources/why-malware-analysis-training-is-vital-lessons-from-real-world-cyber-attacks</link><guid isPermaLink="true">https://www.ionsec.io/resources/why-malware-analysis-training-is-vital-lessons-from-real-world-cyber-attacks</guid><description>Picture this: airport metal detectors efficiently catch large, obvious weapons, but small components slip through unnoticed. Once inside, attackers assemble them into a complete weapon.</description><pubDate>Wed, 11 Dec 2024 00:00:00 GMT</pubDate><category>Article</category><category>malware-analysis</category><category>training</category><category>awareness</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>IONSEC at HackExpo 2024 – Breach at the Frontline</title><link>https://www.ionsec.io/resources/ionsec-at-hackexpo-2024---breach-at-the-frontline</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-at-hackexpo-2024---breach-at-the-frontline</guid><description>At HackExpo 2024, IONSEC CEO Nir Halfon shared practical strategies for responding to exploits in fintech first-party applications under live pressure.</description><pubDate>Thu, 28 Nov 2024 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>conference</category><category>incident-response</category><category>fintech</category><author>IONSEC Team</author></item><item><title>Reverse Engineering GodPotato (MSASCui.exe)</title><link>https://www.ionsec.io/resources/reverse-engineering-godpotato-msascui-exe</link><guid isPermaLink="true">https://www.ionsec.io/resources/reverse-engineering-godpotato-msascui-exe</guid><description>Privilege escalation is a critical technique employed by attackers to gain unauthorized access to higher system privileges, often leading to significant security breaches.</description><pubDate>Sun, 10 Nov 2024 00:00:00 GMT</pubDate><category>Blog</category><category>reverse-engineering</category><category>privilege-escalation</category><category>windows</category><category>malware-analysis</category><author>IONSEC Team</author></item><item><title>Clearing the Mist: Unveiling Fog Ransomware</title><link>https://www.ionsec.io/resources/clearing-the-mist-unveiling-fog-ransomware</link><guid isPermaLink="true">https://www.ionsec.io/resources/clearing-the-mist-unveiling-fog-ransomware</guid><description>A full analysis of the Fog Ransomware Group: the malware it deploys, the TTPs it relies on to infiltrate high-tech firms, and how defenders can disrupt it.</description><pubDate>Sun, 25 Aug 2024 00:00:00 GMT</pubDate><category>Blog</category><category>ransomware</category><category>malware-analysis</category><category>threat-intelligence</category><category>ttps</category><author>IONSEC Team</author></item><item><title>IONSEC Joins the 3rd MIRROR Forum with INCD</title><link>https://www.ionsec.io/resources/ionsec-joins-the-3rd-mirror-forum-with-incd</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-joins-the-3rd-mirror-forum-with-incd</guid><description>On June 28, IONSEC proudly participated in the third MIRROR Forum — a unique gathering of 15 Incident Response (IR) companies across Israel, convened by the Israel National Cyber Directorate (INCD).</description><pubDate>Fri, 28 Jun 2024 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>incd</category><category>collaboration</category><author>IONSEC Team</author></item><item><title>IONSEC Shares Wiper Malware Research with Czech Delegation in Israel</title><link>https://www.ionsec.io/resources/ionsec-shares-wiper-malware-research-with-czech-delegation-in-israel</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-shares-wiper-malware-research-with-czech-delegation-in-israel</guid><description>IONSEC hosted a Czech delegation in Israel to present our Wiper malware research, including the campaign we track as Operation HANDALA.</description><pubDate>Sun, 02 Jun 2024 00:00:00 GMT</pubDate><category>News</category><category>wiper</category><category>malware-analysis</category><category>operation-handala</category><category>threat-intelligence</category><category>events</category><author>IONSEC Team</author></item><item><title>IONSEC at GPEC 2024 – Showcasing APT Research on the Global Stage</title><link>https://www.ionsec.io/resources/ionsec-at-gpec-2024---showcasing-apt-research-on-the-global-stage-98do0-brms0</link><guid isPermaLink="true">https://www.ionsec.io/resources/ionsec-at-gpec-2024---showcasing-apt-research-on-the-global-stage-98do0-brms0</guid><description>Wow — what a journey GPEC (General Police Equipment Exhibition &amp; Conference) was this year. Standing among 471 exhibitors from 32 different countries was nothing short of inspiring. The scale, the diversity, and the energy of the event made it a true highlight of 2024.</description><pubDate>Wed, 08 May 2024 00:00:00 GMT</pubDate><category>News</category><category>events</category><category>conference</category><category>apt</category><category>threat-intelligence</category><author>IONSEC Team</author></item><item><title>SovaTeam - New State-Sponsored APT</title><link>https://www.ionsec.io/resources/sovateam---new-state-sponsored-apt</link><guid isPermaLink="true">https://www.ionsec.io/resources/sovateam---new-state-sponsored-apt</guid><description>How IONSEC and White-Hat traced the Sova Team threat actor through a ransom note to uncover a state-sponsored APT operating past strict security controls.</description><pubDate>Sun, 31 Mar 2024 00:00:00 GMT</pubDate><category>Blog</category><category>apt</category><category>ransomware</category><category>threat-intelligence</category><category>incident-response</category><author>IONSEC Team</author></item><item><title>סקירה מודיעינית 2024 #OpIsrael</title><link>https://www.ionsec.io/resources/sqyrh-mvdy-ynyt-2024-opisrael</link><guid isPermaLink="true">https://www.ionsec.io/resources/sqyrh-mvdy-ynyt-2024-opisrael</guid><description>IONSEC הינה חברת בוטיק לשירותי אבטחת מידע ותגובה לאירועי סייבר (24/7) העוסקת במחקר ותגובה לאיומים מתקדמים ומספקת פתרונות אבטחה מותאמים אישית לחברות ברחבי העולם.</description><pubDate>Sun, 24 Mar 2024 00:00:00 GMT</pubDate><category>Blog</category><category>opisrael</category><category>threat-intelligence</category><category>hacktivism</category><category>israel</category><author>IONSEC Team</author></item></channel></rss>