<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>jankesec</title><description>Pentest notes, vulnerability research, and practical web security analysis.</description><link>https://jankesec.com/</link><item><title>GitHub Issue to Supply Chain Compromise: How Prompt Injection Turned AI Agents into the New CI/CD Kill Chain</title><link>https://jankesec.com/blog/ai-agent-prompt-injection-supply-chain/</link><guid isPermaLink="true">https://jankesec.com/blog/ai-agent-prompt-injection-supply-chain/</guid><description>When a single GitHub issue can poison an AI agent, steal pipeline credentials, and publish malicious packages to production registries — all without a single binary payload.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weaponizing Secure Email Gateways: When the Sandbox Clicks for the Attacker</title><link>https://jankesec.com/blog/weaponizing-secure-email-gateways/</link><guid isPermaLink="true">https://jankesec.com/blog/weaponizing-secure-email-gateways/</guid><description>When the SEG&apos;s sandbox click triggers real actions, the defender becomes the attacker&apos;s proxy.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>From Zero to Root: Automating the Logsign Pre-Auth RCE Chain in Metasploit</title><link>https://jankesec.com/blog/logsign-pre-auth-rce-metasploit/</link><guid isPermaLink="true">https://jankesec.com/blog/logsign-pre-auth-rce-metasploit/</guid><description>Chaining CVE-2024-5716 and CVE-2024-5717 into a Metasploit module for root RCE on Logsign.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The Convergence: How Supply Chain Attacks Became Ransomware&apos;s Favorite Delivery Vehicle</title><link>https://jankesec.com/blog/supply-chain-ransomware-2025/</link><guid isPermaLink="true">https://jankesec.com/blog/supply-chain-ransomware-2025/</guid><description>How modern ransomware weaponizes supply chain trust, and where to break the kill chain.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Inside the Machine: A Technical Anatomy of the 2025 Ransomware Ecosystem</title><link>https://jankesec.com/blog/ransomware-ecosystem-2025/</link><guid isPermaLink="true">https://jankesec.com/blog/ransomware-ecosystem-2025/</guid><description>Affiliate infrastructure, negotiation backends, and the TTPs that define modern RaaS operations.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Mapping the Adversary: A Technical Profile of the 2025 APT Landscape</title><link>https://jankesec.com/blog/apt-landscape-2025/</link><guid isPermaLink="true">https://jankesec.com/blog/apt-landscape-2025/</guid><description>Operational TTPs, infrastructure patterns, and detection strategies for the APT groups shaping 2025.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The Evolution of Modern Ransomware: How They Became This Powerful</title><link>https://jankesec.com/blog/modern-ransomware-evolution/</link><guid isPermaLink="true">https://jankesec.com/blog/modern-ransomware-evolution/</guid><description>From script-kiddie lockers to billion-dollar enterprises — the technical leaps that made ransomware unstoppable.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The Treasure of Finding Vulnerabilities: A Researcher&apos;s Guide to Secure Code Review</title><link>https://jankesec.com/blog/secure-code-review-methodology/</link><guid isPermaLink="true">https://jankesec.com/blog/secure-code-review-methodology/</guid><description>A risk-based methodology for finding the vulnerabilities that scanners and pentests miss.</description><pubDate>Mon, 04 Aug 2025 00:00:00 GMT</pubDate></item><item><title>Anatomy of a Supply Chain Kill Chain: The xz Utils Backdoor (CVE-2024-3094)</title><link>https://jankesec.com/blog/xz-utils-backdoor-technical-breakdown/</link><guid isPermaLink="true">https://jankesec.com/blog/xz-utils-backdoor-technical-breakdown/</guid><description>How build-system manipulation and IFUNC hijacking turned a compression library into an SSH implant.</description><pubDate>Mon, 09 Sep 2024 00:00:00 GMT</pubDate></item><item><title>The Human Firewall: Why Decision Hygiene Is Your Best Security ROI</title><link>https://jankesec.com/blog/human-firewall-decision-hygiene/</link><guid isPermaLink="true">https://jankesec.com/blog/human-firewall-decision-hygiene/</guid><description>Why security awareness must evolve from compliance theater to decision hygiene.</description><pubDate>Sat, 22 Jun 2024 00:00:00 GMT</pubDate></item><item><title>Mapping the Digital Metropolis: A Practitioner&apos;s Guide to Attack Surface Management</title><link>https://jankesec.com/blog/attack-surface-management/</link><guid isPermaLink="true">https://jankesec.com/blog/attack-surface-management/</guid><description>Mapping the digital, human, supply chain, and physical attack surfaces with risk-based prioritization.</description><pubDate>Fri, 21 Jun 2024 00:00:00 GMT</pubDate></item></channel></rss>