<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Blue INK Security, LLC]]></title><description><![CDATA[Blue INK Security helps small and medium businesses operate securely and prevent costly cyber attacks.]]></description><link>https://luzsicza.wixsite.com/new-site/weekly-ink</link><generator>RSS for Node</generator><lastBuildDate>Sat, 10 Oct 2026 06:47:58 GMT</lastBuildDate><atom:link href="https://luzsicza.wixsite.com/new-site/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[Issue #218 - September 28, 2026]]></title><description><![CDATA[Automated AI agent used to breach cybersecurity nonprofit DIVD Source: BleepingComputer Dutch nonprofit DIVD said an attacker exploited a technical vulnerability and then used an autonomous AI agent for post-exploitation. Investigators observed rapid, self-directed actions, password spraying, and verbose comments that exposed the agent’s reasoning. The incident was reported to police, the Dutch privacy authority, and the national cybersecurity center. Link to article South Africa Seeks Help...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-218-september-28-2026</link><guid isPermaLink="false">6abefbd77333c9a7b0d0f0e4</guid><pubDate>Mon, 28 Sep 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #217 - September 21, 2026]]></title><description><![CDATA[Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign Source: Dark Reading Researchers identified “Dark Sourcery,” a campaign that seeds the web with optimized fake support pages, fraudulent contact details, and phishing links so ChatGPT, Gemini, and Google AI Overview may repeat them as trusted answers. At least 374 brands were affected, underscoring the need to verify AI-provided contact and payment information. Link to article New Check Point flaw lets hackers execute...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-217-september-21-2026</link><guid isPermaLink="false">6ab5c54d0f6358bffa049dcb</guid><pubDate>Mon, 21 Sep 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #216 - September 14, 2026]]></title><description><![CDATA[CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot Source: SecurityWeek CISA will retire its weekly vulnerability bulletin on September 28 as it shifts federal vulnerability management toward real-world risk. The agency says BOD 26-04 emphasizes active exploitation, exposure, and the Known Exploited Vulnerabilities catalog, helping defenders prioritize urgent fixes instead of sorting thousands of entries primarily by severity. Link to article Cyber Op Targets South Korean Media &#38;...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-216-september-14-2026</link><guid isPermaLink="false">6aac819cc277db7715a84eb9</guid><pubDate>Mon, 14 Sep 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #215 - September 7, 2026]]></title><description><![CDATA[Critical NetScaler Vulnerability Exploited in Attacks Source: SecurityWeek CISA warned that attackers are exploiting CVE-2026-19490, a critical authentication-bypass vulnerability affecting NetScaler ADC and Gateway appliances configured as gateways or AAA virtual servers. Citrix patched the flaw in August, but observed exploitation began shortly after public exploit code appeared. Organizations should treat remediation as an emergency priority. Link to article OpenAI Agents Took Over Wiki...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-215-september-7-2026</link><guid isPermaLink="false">6aa350215462f0629b9a954a</guid><pubDate>Mon, 07 Sep 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #214 - August 31, 2026]]></title><description><![CDATA[Hackers push malicious Virtualizor update in BGP hijacking attack Source: BleepingComputer Attackers diverted Virtualizor update traffic by hijacking BGP routes associated with Softaculous infrastructure, then delivered a malicious package to a small number of servers. The vendor restored routing, released a security analyzer, and advised administrators to check for a suspicious service, rotate credentials, and audit systems for unauthorized access. Link to article Attackers Turn Trusted...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-214-august-31-2026</link><guid isPermaLink="false">6a99a712a6d208e94870096f</guid><pubDate>Mon, 31 Aug 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #213 - August 24, 2026]]></title><description><![CDATA[New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Source: The Hacker News Researchers demonstrated GPUThor, a Rowhammer technique that produced multi-bit errors on several NVIDIA Ampere workstation GPUs and bypassed the protection expected from ECC. With unprivileged CUDA execution, the team achieved denial of service and host privilege escalation. Defenders should limit untrusted GPU workloads, avoid cross-tenant sharing, and monitor ECC errors. Link to article...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-213-august-24-2026</link><guid isPermaLink="false">6a90a6aab26be70df890a31c</guid><pubDate>Mon, 24 Aug 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #212 - August 17, 2026]]></title><description><![CDATA['Grandoreiro' Malware Resurfaces With Mexico Campaign Source: Dark Reading The Grandoreiro banking Trojan has returned in a campaign aimed primarily at Mexican users. Operators disguise malicious archives as invoices, abuse a legitimate file-management application for DLL sideloading, and deploy a heavily protected loader with extensive sandbox, security-tool, and analysis checks before downloading the credential-stealing payload. Link to article New Cryptographic Context Injection Attack...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-212-august-17-2026</link><guid isPermaLink="false">6a874cc929da61b144a9e30a</guid><pubDate>Mon, 17 Aug 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #211 - August 10, 2026]]></title><description><![CDATA[Plug and Pwn attack uses fake USB devices for Windows SYSTEM access Source: BleepingComputer Researchers demonstrated that Windows Plug and Play can install exploitable vendor packages as SYSTEM when presented with emulated USB hardware. Some chains required no user interaction, while another worked through RDP USB redirection without physical hardware. Recommended protections include restricting device installation and disabling unnecessary Plug and Play redirection. Link to article DDoS...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-211-august-10-2026</link><guid isPermaLink="false">6a7de6f7d791ff6850b4f6e3</guid><pubDate>Mon, 10 Aug 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #210 - August 3, 2026]]></title><description><![CDATA[AI Sends Global Crime Syndicates Into Fraud Nirvana Source: Dark Reading Organized crime groups are industrializing fraud with AI-powered voice cloning, real-time deepfake video, synthetic identities, automated translation, and persona-management tools. These capabilities help gangs defeat identity verification and scale convincing scams across borders, increasing pressure on financial institutions to strengthen identity proofing, liveness checks, behavioral defenses, and intelligence...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-210-august-3-2026</link><guid isPermaLink="false">6a74f5f12dc76a37da3bc3c4</guid><pubDate>Mon, 03 Aug 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #209 - July 27, 2026]]></title><description><![CDATA[SE Asian Cybercriminal Syndicates Become a Global Power Source: Dark Reading Dark Reading reports that Southeast Asian cyber-fraud syndicates have evolved into global service-based crime networks, enabled by cryptocurrency, secure messaging, AI, satellite connectivity, trafficking, and corruption. The story highlights how enforcement pressure has displaced operations rather than dismantled them, creating a resilient ecosystem with major regional economic impact. Link to article Russian...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-209-july-27-2026</link><guid isPermaLink="false">6a6b95e55cf1d22b8d7303d7</guid><pubDate>Mon, 27 Jul 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #208 - July 20, 2026]]></title><description><![CDATA['WP2Shell' Opens Millions of WordPress Sites to Remote Takeover Source: Dark Reading Attackers are exploiting two critical WordPress flaws chained as WP2Shell to achieve unauthenticated remote code execution on default installations. The article reports widespread exploit attempts, public proof-of-concept activity, forced security updates, and guidance to inspect sites for backdoor accounts, malicious plugins, and suspicious files even after patching. Link to article Critical ServiceNow code...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-208-july-20-2026</link><guid isPermaLink="false">6a625d7d21af5c246d0221fd</guid><pubDate>Mon, 20 Jul 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #207 - July 13, 2026]]></title><description><![CDATA[2-Click Cursor Exploit Enables Dev Environment Takeover Source: Dark Reading Researchers found that Cursor AI could be abused through disguised links that install malicious MCP servers inside a developer environment. The attack chain relies on ordinary-looking clicks and limited warning visibility, creating a path to steal source code, secrets, or run commands with the developer’s privileges. Link to article GigaWiper Lets Threat Actors Choose Their Own Destructive Attack Source: Dark Reading...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-207-july-13-2026</link><guid isPermaLink="false">6a594c76d03244312ce52e37</guid><pubDate>Mon, 13 Jul 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #206 - July 6, 2026]]></title><description><![CDATA['GitLost' Flaw Leaks Private Data From GitHub's Agentic Workflows Source: Dark Reading Researchers disclosed GitLost, a prompt-injection weakness in GitHub agentic workflows that could let unauthenticated attackers use a public GitHub issue to pull private repository data. The story highlights a fast-growing risk: AI agents with broad access can be manipulated by ordinary text if trust boundaries are weak. Link to article Fake IT support calls on Microsoft Teams push EtherRAT malware Source:...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-206-july-6-2026</link><guid isPermaLink="false">6a501d1bcb673b1177c71ce3</guid><pubDate>Mon, 06 Jul 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #205 - June 29, 2026]]></title><description><![CDATA[FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks Source: SecurityWeek Researchers linked the FortiBleed credential-harvesting campaign to INC and Lynx ransomware activity. SOCRadar reported scanning against thousands of FortiGate portals, hundreds of successful administrative compromises, and at least 12 ransomware deployments, showing how stolen edge-device credentials can quickly become enterprise-wide extortion access. Link to article China-Linked Group Targets Southeast Asia...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-205-june-29-2026</link><guid isPermaLink="false">6a46abe9316fbd62aff79f50</guid><pubDate>Mon, 29 Jun 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #204 - June 22, 2026]]></title><description><![CDATA[CISA warns of max severity Ubiquiti flaws exploited in attacks Source: BleepingComputer CISA warned that attackers are actively exploiting critical Ubiquiti UniFi OS flaws and Lantronix serial-to-ethernet server vulnerabilities. The directive gives federal agencies only three days to apply fixes or mitigations, underscoring how exposed edge and network management systems remain high-value targets for fast-moving exploitation. Link to article More Malicious OpenClaw Skills Threaten AI Supply...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-204-june-22-2026</link><guid isPermaLink="false">6a3d4c9e40b34fdeb1ef876c</guid><pubDate>Mon, 22 Jun 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #203 - June 15, 2026]]></title><description><![CDATA[INC Ransomware Thrives by Mastering the Basics Source: Dark Reading INC ransomware has grown by focusing on practical, repeatable intrusion methods rather than novel tooling. Researchers said the group targets high-pressure sectors, uses familiar techniques such as stolen credentials, phishing, and unpatched remote services, and benefits from affiliate scalability as other ransomware groups decline or reorganize. Link to article Fileless Phantom Stealer Targets Browser Credentials Source:...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-203-june-15-2026</link><guid isPermaLink="false">6a341f52881c4b5f4c45fc47</guid><pubDate>Mon, 15 Jun 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #202 - June 08, 2026]]></title><description><![CDATA[Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks Source: BleepingComputer Oracle PeopleSoft servers are being targeted in ongoing data theft attacks attributed to ShinyHunters, with the group claiming data from more than 100 organizations. The report is notable because PeopleSoft often supports HR, payroll, finance, procurement, and student administration, making exposed systems a high-value business data target. Link to article Critical HVAC and UPS Vulnerabilities Could...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-202-june-08-2026</link><guid isPermaLink="false">6a2afb4016a9a8229e024bce</guid><pubDate>Mon, 08 Jun 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #201 - June 01, 2026]]></title><description><![CDATA[Cyber Insurance Rates Are Dropping, but Exclusions Widen Source: Dark Reading Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix. The good news for enterprises is that cyber insurance policies are still affordable. The bad news is that coverage exclusions are increasing, and some might catch customers by surprise. Link to article VS Code zero-day lets hackers steal GitHub tokens in one click Source:...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-201-june-01-2026</link><guid isPermaLink="false">6a21dc5f513f7725cf1fb04c</guid><pubDate>Mon, 01 Jun 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #200 - May 25, 2026]]></title><description><![CDATA[KnowledgeDeliver flaw exploited as a zero-day to install web shells Source: BleepingComputer Attackers exploited CVE-2026-5426, a deserialization flaw in the KnowledgeDeliver LMS, to gain unauthenticated remote code execution and deploy the Godzilla web shell. Mandiant said the issue stemmed from shared hardcoded ASP.NET machine keys, enabling malicious ViewState payloads and follow-on delivery of a Cobalt Strike backdoor. Link to article Feeding Frenzy: 'Megalodon' Malware Infects Thousands...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-200-may-25-2026</link><guid isPermaLink="false">6a18626a34554029974f7c05</guid><pubDate>Thu, 28 May 2026 15:45:30 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item><item><title><![CDATA[Issue #199 - May 18, 2026]]></title><description><![CDATA[On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email Source: The Hacker News Microsoft disclosed active exploitation of CVE-2026-42897, a spoofing flaw rooted in cross-site scripting on on-premises Exchange. The issue can let attackers deliver crafted emails that execute JavaScript in Outlook Web Access sessions. CISA has already added the bug to its known exploited vulnerabilities catalog, underscoring the urgency for defenders. Link to article Critical Vulnerability...]]></description><link>https://luzsicza.wixsite.com/new-site/post/issue-199-may-18-2026</link><guid isPermaLink="false">6a0f64e1a2438924d10a7aa1</guid><pubDate>Mon, 18 May 2026 05:00:00 GMT</pubDate><dc:creator>Weekly INK</dc:creator></item></channel></rss>