<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    
    <title>DevSecOpsDadAttack</title>
    
    
    <description>Threat intelligence and detection engineering output from DevSecOpsDadAttack automation pipelines.</description>
    
    <link>https://devsecopsdadattack.com/</link>
    <atom:link href="https://devsecopsdadattack.com/feed.xml" rel="self" type="application/rss+xml" />
    
    
      <item>
        <title>Threat Intelligence Brief - Friday, September 11, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar JFrog Artifactory actively exploited: Attackers chained two flaws to achieve admin control and plant backdoors in self-hosted build servers — confirmed active exploitation from August 15 through September 8. Software supply chains are directly at risk. Check Point VPN RCE:...
        </description>
        <pubDate>Fri, 11 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-11-threat-intelligence-brief-friday-september-11-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-11-threat-intelligence-brief-friday-september-11-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Friday, September 11, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 5 detection candidates. 2 production candidates, 1 hunting-only, 2 require environment mapping, and 0 rejected. 5 detections include KQL. 5 include ATT&amp;amp;CK mappings. 5 include triage guidance. Search metadata extracted for this run includes: Microsoft Graph,...
        </description>
        <pubDate>Fri, 11 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-11-detection-engineering-brief-friday-september-11-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-11-detection-engineering-brief-friday-september-11-2026/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Thursday, September 10, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar CISA added actively exploited vulnerabilities in Cisco, Citrix, and Fortinet to the KEV catalog with a September 12 federal patch deadline — non-federal enterprises should treat this as an equally urgent signal. Cisco Secure FMC (CVE-2026-20079) is under active exploitation;...
        </description>
        <pubDate>Thu, 10 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-10-threat-intelligence-brief-thursday-september-10-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-10-threat-intelligence-brief-thursday-september-10-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Thursday, September 10, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 5 detection candidates. 3 production candidates, 2 hunting-only, 0 require environment mapping, and 0 rejected. 5 detections include KQL. 5 include ATT&amp;amp;CK mappings. 5 include triage guidance. Search metadata extracted for this run includes: Microsoft Entra...
        </description>
        <pubDate>Thu, 10 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-10-detection-engineering-brief-thursday-september-10-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-10-detection-engineering-brief-thursday-september-10-2026/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Wednesday, September 9, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar Chrome zero-day #7 of 2026 is actively exploited — Google Chrome 153 patches a confirmed in-the-wild vulnerability across Windows, macOS, and Linux; enterprise browser fleets require immediate forced updates. ICS Patch Tuesday hits four major OT vendors simultaneously — Schneider...
        </description>
        <pubDate>Wed, 09 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-09-threat-intelligence-brief-wednesday-september-9-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-09-threat-intelligence-brief-wednesday-september-9-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Wednesday, September 9, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 5 detection candidates. 1 production candidate, 2 hunting-only, 2 require environment mapping, and 0 rejected. 5 detections include KQL. 5 include ATT&amp;amp;CK mappings. 5 include triage guidance. Search metadata extracted for this run includes: MikroTik, T1136,...
        </description>
        <pubDate>Wed, 09 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-09-detection-engineering-brief-wednesday-september-9-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-09-detection-engineering-brief-wednesday-september-9-2026/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Tuesday, September 8, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar Adobe’s Magento zero-day (CVE-2026-75650, CVSS 10.0) is under active exploitation — attackers are deploying Rust backdoors and PHP web shells against e-commerce storefronts; patch immediately. MikroTik RouterOS is being actively compromised via chained authentication bypass flaws (MikroTrick), enabling full device...
        </description>
        <pubDate>Tue, 08 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-08-threat-intelligence-brief-tuesday-september-8-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-08-threat-intelligence-brief-tuesday-september-8-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Tuesday, September 8, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 5 detection candidates. 0 production candidates, 0 hunting-only, 4 require environment mapping, and 1 rejected. 4 detections include KQL. 4 include ATT&amp;amp;CK mappings. 4 include triage guidance. Search metadata extracted for this run includes: T1059, Linux,...
        </description>
        <pubDate>Tue, 08 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-08-detection-engineering-brief-tuesday-september-8-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-08-detection-engineering-brief-tuesday-september-8-2026/</guid>
      </item>
    
      <item>
        <title>KQL Detection of the Week: The Character Is Not the Payload</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Detecting ASCII Smuggling by Codepoint Range Instead of Character List, Decoding the Unicode Tag Block Back to Its Hidden ASCII, and Why &apos;MQTT Port&apos; Isn&apos;t &apos;MQTT Traffic&apos; - 
          Last week the DevSecOpsDadAttack Detection Engineering pipeline (run on a Raspberry Pi) matched the representation of an indicator instead of its meaning, and the fix was a range check where a string comparison used to be. This week’s batch runs into a...
        </description>
        <pubDate>Tue, 08 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-08-KQL-Detection-of-the-Week-The-Character-Is-Not-The-Payload/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-08-KQL-Detection-of-the-Week-The-Character-Is-Not-The-Payload/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Monday, September 7, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar N-able N-central RCE is actively exploited and requires emergency patching today — four hotfixes in five weeks signals an unstable patch cycle; every on-premises build below 2026.3.1.14 remains exposed. MikroTik RouterOS is being hijacked at scale via chained vulnerability exploitation...
        </description>
        <pubDate>Mon, 07 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-07-threat-intelligence-brief-monday-september-7-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-07-threat-intelligence-brief-monday-september-7-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Monday, September 7, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 4 detection candidates. 1 production candidate, 1 hunting-only, 2 require environment mapping, and 0 rejected. 4 detections include KQL. 4 include ATT&amp;amp;CK mappings. 4 include triage guidance. Search metadata extracted for this run includes: T1059, Linux,...
        </description>
        <pubDate>Mon, 07 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-07-detection-engineering-brief-monday-september-7-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-07-detection-engineering-brief-monday-september-7-2026/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Sunday, September 6, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar An unpatched zero-day in Magento Open Source and Adobe Commerce is being actively exploited to backdoor e-commerce servers without authentication — no patch exists yet. JetBrains Cadence was breached via an unpatched TeamCity vulnerability; AWS credentials were extracted and all...
        </description>
        <pubDate>Sun, 06 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-06-threat-intelligence-brief-sunday-september-6-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-06-threat-intelligence-brief-sunday-september-6-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Sunday, September 6, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 5 detection candidates. 0 production candidates, 1 hunting-only, 4 require environment mapping, and 0 rejected. 5 detections include KQL. 5 include ATT&amp;amp;CK mappings. 5 include triage guidance. Search metadata extracted for this run includes: T1059, HAProxy,...
        </description>
        <pubDate>Sun, 06 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-06-detection-engineering-brief-sunday-september-6-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-06-detection-engineering-brief-sunday-september-6-2026/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Saturday, September 5, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar PaperCut authentication bypass flaws are under active exploitation — threat actors are harvesting credentials from U.S. and European educational institutions now; patch or isolate exposed instances immediately. HPE AOS-CX carries nearly two dozen critical RCE vulnerabilities (CVSS 9.8) — exploitation...
        </description>
        <pubDate>Sat, 05 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-05-threat-intelligence-brief-saturday-september-5-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-05-threat-intelligence-brief-saturday-september-5-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Saturday, September 5, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 5 detection candidates. 1 production candidate, 3 hunting-only, 1 require environment mapping, and 0 rejected. 5 detections include KQL. 3 include ATT&amp;amp;CK mappings. 5 include triage guidance. Search metadata extracted for this run includes: T1059, Linux,...
        </description>
        <pubDate>Sat, 05 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-05-detection-engineering-brief-saturday-september-5-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-05-detection-engineering-brief-saturday-september-5-2026/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Friday, September 4, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar 🔴 PATCH NOW: Google Chrome’s V8 engine zero-day (CVE-2026-85046, CVSS 8.8) is under active exploitation — this is Chrome’s sixth zero-day of 2026, and every unpatched endpoint is exposed. 🔴 PATCH NOW: Over 440,000 exploit attempts are actively targeting critical...
        </description>
        <pubDate>Fri, 04 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-04-threat-intelligence-brief-friday-september-4-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-04-threat-intelligence-brief-friday-september-4-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Friday, September 4, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 5 detection candidates. 1 production candidate, 1 hunting-only, 3 require environment mapping, and 0 rejected. 5 detections include KQL. 4 include ATT&amp;amp;CK mappings. 5 include triage guidance. Search metadata extracted for this run includes: T1566, T1219,...
        </description>
        <pubDate>Fri, 04 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-04-detection-engineering-brief-friday-september-4-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-04-detection-engineering-brief-friday-september-4-2026/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Thursday, September 3, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar WordPress migration plugin CVE-2026-19949 enables unauthenticated SQL injection leading to RCE across 3+ million sites — patch immediately, exploitation status unknown but attack surface is massive. Shai-Hulud infostealer is actively harvesting credentials from 469 locations spanning CI/CD pipelines, cloud configs,...
        </description>
        <pubDate>Thu, 03 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-03-threat-intelligence-brief-thursday-september-3-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-03-threat-intelligence-brief-thursday-september-3-2026/</guid>
      </item>
    
      <item>
        <title>Detection Engineering Brief - Thursday, September 3, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Threat intelligence translated into detection engineering action. - 
          Detection Engineering Summary This brief produced 5 detection candidates. 2 production candidates, 1 hunting-only, 2 require environment mapping, and 0 rejected. 5 detections include KQL. 5 include ATT&amp;amp;CK mappings. 5 include triage guidance. Search metadata extracted for this run includes: CVE-2026-83548, CVE-2026-83549,...
        </description>
        <pubDate>Thu, 03 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-03-detection-engineering-brief-thursday-september-3-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-03-detection-engineering-brief-thursday-september-3-2026/</guid>
      </item>
    
      <item>
        <title>Threat Intelligence Brief - Wednesday, September 2, 2026</title>
        
        <dc:creator><![CDATA[ DevSecOpsDad ]]></dc:creator>
        
        <description>
          Operational threat reporting for defenders who need signal, not noise. - 
          Threat Radar SonicWall SMA 1000 zero-days are under active exploitation — two flaws confirmed in-the-wild may be chained; patch windows are effectively closed for unpatched appliances. BGP hijacking delivered trojanized Virtualizor updates — attackers paired routing manipulation with a valid TLS certificate...
        </description>
        <pubDate>Wed, 02 Sep 2026 00:00:00 -0400</pubDate>
        <link>https://devsecopsdadattack.com/2026-09-02-threat-intelligence-brief-wednesday-september-2-2026/</link>
        <guid isPermaLink="true">https://devsecopsdadattack.com/2026-09-02-threat-intelligence-brief-wednesday-september-2-2026/</guid>
      </item>
    
  </channel>
</rss>
