<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Nanorisk Insights</title>
    <link>https://www.nanorisk.co.uk/content.html</link>
    <atom:link href="https://www.nanorisk.co.uk/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Vulnerability analysis, threat intelligence and security commentary from the Nanorisk testing team.</description>
    <language>en-gb</language>
    <lastBuildDate>Thu, 10 Sep 2026 14:59:49 +0000</lastBuildDate>
    <item>
      <title>Magento zero-day patch urgent warning</title>
      <link>https://www.nanorisk.co.uk/content/magento-zero-day-patch-urgent-warning.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/magento-zero-day-patch-urgent-warning.html</guid>
      <description>Adobe has patched CVE-2026-75650, a CVSS 10.0 zero-day affecting Magento Open Source and Adobe Commerce, following confirmed exploitation in the wild…</description>
      <pubDate>Wed, 09 Sep 2026 10:30:43 +0000</pubDate>
    </item>
    <item>
      <title>Data egress and removable media controls</title>
      <link>https://www.nanorisk.co.uk/content/data-egress-and-removable-media-controls.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/data-egress-and-removable-media-controls.html</guid>
      <description>A breach isn&#x27;t always required for data to leave your organisation. In many cases, it just walks out through gaps that nobody has formally assessed. Three…</description>
      <pubDate>Fri, 04 Sep 2026 14:00:46 +0000</pubDate>
    </item>
    <item>
      <title>Hardcoded secrets in mobile apps</title>
      <link>https://www.nanorisk.co.uk/content/hardcoded-secrets-in-mobile-apps.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/hardcoded-secrets-in-mobile-apps.html</guid>
      <description>Shipping a mobile app or frontend bundle with hardcoded credentials is not a calculated risk. It is handing every user who downloads the app the keys to…</description>
      <pubDate>Wed, 02 Sep 2026 10:00:39 +0000</pubDate>
    </item>
    <item>
      <title>NASA AIT-GUI spacecraft command vulnerability disclosure</title>
      <link>https://www.nanorisk.co.uk/content/nasa-ait-gui-spacecraft-command-vulnerability-disclosure.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/nasa-ait-gui-spacecraft-command-vulnerability-disclosure.html</guid>
      <description>Cycode have disclosed a vulnerability chain in AIT-GUI, the browser-based operator console for NASA/JPL&#x27;s open-source AMMOS Instrument Toolkit, tracked as…</description>
      <pubDate>Tue, 01 Sep 2026 12:00:43 +0000</pubDate>
    </item>
    <item>
      <title>Bank holiday security awareness reminder</title>
      <link>https://www.nanorisk.co.uk/content/bank-holiday-security-awareness-reminder.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/bank-holiday-security-awareness-reminder.html</guid>
      <description>Bank holidays are a reliable opportunity for attackers, and the reason is straightforward: staffing drops, response times slow, and security alerts sit…</description>
      <pubDate>Fri, 28 Aug 2026 13:00:44 +0000</pubDate>
    </item>
    <item>
      <title>Nanorisk achieves CREST accreditation milestone</title>
      <link>https://www.nanorisk.co.uk/content/nanorisk-achieves-crest-accreditation-milestone.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/nanorisk-achieves-crest-accreditation-milestone.html</guid>
      <description>We&#x27;re pleased to confirm that Nanorisk is now a CREST accredited organisation. CREST accreditation is an independently assessed standard covering the…</description>
      <pubDate>Thu, 27 Aug 2026 10:55:23 +0000</pubDate>
    </item>
    <item>
      <title>Free vulnerability retesting offer</title>
      <link>https://www.nanorisk.co.uk/content/free-vulnerability-retesting-offer.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/free-vulnerability-retesting-offer.html</guid>
      <description>A penetration test produces a report. What happens after that report is where most engagements fall short. Remediation takes time and resource, and it&#x27;s…</description>
      <pubDate>Wed, 26 Aug 2026 10:45:23 +0000</pubDate>
    </item>
    <item>
      <title>ADCS ESC1 privilege escalation explained</title>
      <link>https://www.nanorisk.co.uk/content/adcs-esc1-privilege-escalation-explained.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/adcs-esc1-privilege-escalation-explained.html</guid>
      <description>Active Directory Certificate Services is present in the vast majority of enterprise Windows environments, and ESC1 is one of the most consistently…</description>
      <pubDate>Mon, 24 Aug 2026 09:00:22 +0000</pubDate>
    </item>
    <item>
      <title>Explaining our scoping call process</title>
      <link>https://www.nanorisk.co.uk/content/explaining-our-scoping-call-process.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/explaining-our-scoping-call-process.html</guid>
      <description>A question we get regularly: how do you scope a penetration test if you&#x27;re not sure what you need? The honest answer is that figuring out what you need is…</description>
      <pubDate>Fri, 21 Aug 2026 11:20:23 +0000</pubDate>
    </item>
    <item>
      <title>macOS Screen Sharing exploit warning</title>
      <link>https://www.nanorisk.co.uk/content/macos-screen-sharing-exploit-warning.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/macos-screen-sharing-exploit-warning.html</guid>
      <description>The Netherlands&#x27; NCSC has issued an active warning: a macOS Screen Sharing authentication bypass vulnerability is being exploited in the wild, following…</description>
      <pubDate>Thu, 20 Aug 2026 10:00:25 +0000</pubDate>
    </item>
    <item>
      <title>Office printer security risk explained</title>
      <link>https://www.nanorisk.co.uk/content/office-printer-security-risk-explained.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/office-printer-security-risk-explained.html</guid>
      <description>Tip Tuesday: the network printer is a more useful foothold than most IT teams expect. Printers running an unauthenticated web management interface -…</description>
      <pubDate>Tue, 18 Aug 2026 01:45:43 +0000</pubDate>
    </item>
    <item>
      <title>Choosing a penetration testing supplier wisely</title>
      <link>https://www.nanorisk.co.uk/content/choosing-a-penetration-testing-supplier-wisely.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/choosing-a-penetration-testing-supplier-wisely.html</guid>
      <description>Before you commission a penetration test, ask the supplier one question: can I see a sample report? Scope and day rate get most of the attention during…</description>
      <pubDate>Mon, 17 Aug 2026 10:45:23 +0000</pubDate>
    </item>
    <item>
      <title>Explaining different types of password attacks</title>
      <link>https://www.nanorisk.co.uk/content/explaining-different-types-of-password-attacks.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/explaining-different-types-of-password-attacks.html</guid>
      <description>Password attacks get discussed as though they&#x27;re a single problem. They aren&#x27;t, and treating them that way leads to defences that only address part of the…</description>
      <pubDate>Fri, 14 Aug 2026 10:30:41 +0000</pubDate>
    </item>
    <item>
      <title>Nation-state iOS exploits now widely proliferating</title>
      <link>https://www.nanorisk.co.uk/content/nation-state-ios-exploits-now-widely-proliferating.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/nation-state-ios-exploits-now-widely-proliferating.html</guid>
      <description>The Coruna and DarkSword iOS exploit chains have moved beyond nation-state use. According to reporting from Dark Reading, these sophisticated iPhone…</description>
      <pubDate>Thu, 13 Aug 2026 12:00:42 +0000</pubDate>
    </item>
    <item>
      <title>SMB share permissions misconfiguration warning</title>
      <link>https://www.nanorisk.co.uk/content/smb-share-permissions-misconfiguration-warning.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/smb-share-permissions-misconfiguration-warning.html</guid>
      <description>On internal penetration tests, misconfigured SMB shares have become one of the most consistent findings we&#x27;re documenting - and the misconfiguration isn&#x27;t…</description>
      <pubDate>Wed, 12 Aug 2026 11:40:40 +0000</pubDate>
    </item>
    <item>
      <title>Polish power plant OT network breach</title>
      <link>https://www.nanorisk.co.uk/content/polish-power-plant-ot-network-breach.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/polish-power-plant-ot-network-breach.html</guid>
      <description>Attackers shut down a steam turbine and process-water treatment system at a Polish combined heat and power plant this month. The plant supplies heat to…</description>
      <pubDate>Tue, 11 Aug 2026 10:20:23 +0000</pubDate>
    </item>
    <item>
      <title>Five interesting cybersecurity facts</title>
      <link>https://www.nanorisk.co.uk/content/five-interesting-cybersecurity-facts.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/five-interesting-cybersecurity-facts.html</guid>
      <description>A few facts worth knowing - not the usual statistics recycled from vendor whitepapers. 1. The average dwell time for an attacker inside a network before…</description>
      <pubDate>Fri, 07 Aug 2026 11:35:37 +0000</pubDate>
    </item>
    <item>
      <title>External infrastructure assessment methodology explained</title>
      <link>https://www.nanorisk.co.uk/content/external-infrastructure-assessment-methodology-explained.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/external-infrastructure-assessment-methodology-explained.html</guid>
      <description>Most external infrastructure assessments follow the same pattern: run a scan, map the output to CVEs, produce a report. That process has value, but it…</description>
      <pubDate>Thu, 06 Aug 2026 11:05:43 +0000</pubDate>
    </item>
    <item>
      <title>Russian APT targeting public Wi-Fi networks</title>
      <link>https://www.nanorisk.co.uk/content/russian-apt-targeting-public-wi-fi-networks.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/russian-apt-targeting-public-wi-fi-networks.html</guid>
      <description>Midnight Blizzard, the Russian state-sponsored threat group previously linked to the SolarWinds compromise, has been operating a credential theft campaign…</description>
      <pubDate>Wed, 05 Aug 2026 14:00:39 +0000</pubDate>
    </item>
    <item>
      <title>Introducing Nanorisk client security portal</title>
      <link>https://www.nanorisk.co.uk/content/introducing-nanorisk-client-security-portal.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/introducing-nanorisk-client-security-portal.html</guid>
      <description>One of the less glamorous but genuinely important parts of running a structured assessment service is what happens after the test - how findings are…</description>
      <pubDate>Tue, 04 Aug 2026 11:16:38 +0000</pubDate>
    </item>
    <item>
      <title>Explaining scan vs pentest vs red team</title>
      <link>https://www.nanorisk.co.uk/content/explaining-scan-vs-pentest-vs-red-team.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/explaining-scan-vs-pentest-vs-red-team.html</guid>
      <description>These three terms get used interchangeably far too often, and it leads to organisations paying for the wrong thing. A vulnerability scan is automated. It…</description>
      <pubDate>Mon, 03 Aug 2026 11:45:30 +0000</pubDate>
    </item>
    <item>
      <title>OpenAI Astra AI capability milestone</title>
      <link>https://www.nanorisk.co.uk/content/openai-astra-ai-capability-milestone.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/openai-astra-ai-capability-milestone.html</guid>
      <description>OpenAI has revealed Astra, an as-yet unreleased model that has already produced ten significant advances in mathematics and theoretical computer science…</description>
      <pubDate>Mon, 03 Aug 2026 09:45:22 +0000</pubDate>
    </item>
    <item>
      <title>Sysadmin Appreciation Day shoutout</title>
      <link>https://www.nanorisk.co.uk/content/sysadmin-appreciation-day-shoutout.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/sysadmin-appreciation-day-shoutout.html</guid>
      <description>Today is Sysadmin Appreciation Day, and it&#x27;s one we&#x27;re genuinely happy to mark. Penetration testing doesn&#x27;t happen in isolation. Behind almost every…</description>
      <pubDate>Fri, 31 Jul 2026 10:45:39 +0000</pubDate>
    </item>
    <item>
      <title>Promoting Nanorisk key selling points</title>
      <link>https://www.nanorisk.co.uk/content/promoting-nanorisk-key-selling-points.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/promoting-nanorisk-key-selling-points.html</guid>
      <description>If you&#x27;re evaluating penetration testing providers, here&#x27;s what we think you should be asking for - and what we deliver as standard. Every Nanorisk…</description>
      <pubDate>Wed, 29 Jul 2026 11:00:25 +0000</pubDate>
    </item>
    <item>
      <title>WordPress RCE chain mass exploitation explained</title>
      <link>https://www.nanorisk.co.uk/content/wordpress-rce-chain-mass-exploitation-explained.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/wordpress-rce-chain-mass-exploitation-explained.html</guid>
      <description>The wp2shell exploitation campaign is a useful case study in why chained vulnerabilities are disproportionately dangerous compared to isolated findings…</description>
      <pubDate>Tue, 28 Jul 2026 10:00:24 +0000</pubDate>
    </item>
    <item>
      <title>Coca-Cola Fairlife ransomware data theft</title>
      <link>https://www.nanorisk.co.uk/content/coca-cola-fairlife-ransomware-data-theft.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/coca-cola-fairlife-ransomware-data-theft.html</guid>
      <description>Coca-Cola has confirmed that data was stolen from Fairlife, its dairy subsidiary, as part of a ransomware attack earlier this month. The detail worth…</description>
      <pubDate>Mon, 27 Jul 2026 16:30:22 +0000</pubDate>
    </item>
    <item>
      <title>New Nanorisk website launch</title>
      <link>https://www.nanorisk.co.uk/content/new-nanorisk-website-launch.html</link>
      <guid isPermaLink="true">https://www.nanorisk.co.uk/content/new-nanorisk-website-launch.html</guid>
      <description>We&#x27;ve launched our new website at nanorisk.co.uk, and we&#x27;d genuinely encourage you to take a look - not because it&#x27;s new, but because it sets out clearly…</description>
      <pubDate>Mon, 27 Jul 2026 14:35:33 +0000</pubDate>
    </item>
  </channel>
</rss>
