<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>The Compliance Brief on GetPentest</title>
    <link>https://getpentest.ca/brief</link>
    <atom:link href="https://getpentest.ca/brief/feed.xml" rel="self" type="application/rss+xml"/>
    <description>A free weekly email on the vulnerabilities being exploited this week, what they mean for your next penetration test, and what to patch first.</description>
    <language>en-CA</language>
    <item>
      <title>Eight NetScaler flaws, two already being exploited</title>
      <link>https://getpentest.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</link>
      <guid isPermaLink="true">https://getpentest.ca/brief/8-patch-netscaler-then-read-the-labcorp-terms</guid>
      <pubDate>Tue, 29 Sep 2026 13:00:00 +0000</pubDate>
      <description>Eight NetScaler flaws, two already being exploited. Citrix disclosed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, and CISA added two of them to the Known Exploited Vulnerabilities catalogue.</description>
    </item>
    <item>
      <title>Exposed Vite dev servers are being scanned for cloud keys</title>
      <link>https://getpentest.ca/brief/7-fake-government-requests-real-ai-attacks</link>
      <guid isPermaLink="true">https://getpentest.ca/brief/7-fake-government-requests-real-ai-attacks</guid>
      <pubDate>Tue, 22 Sep 2026 13:00:00 +0000</pubDate>
      <description>Exposed Vite dev servers are being scanned for cloud keys. F5 Labs described an automated mass-scanning campaign hunting internet-exposed Vite development servers.</description>
    </item>
    <item>
      <title>Artifactory auth bypasses are now on the exploited list</title>
      <link>https://getpentest.ca/brief/6-revolut-handed-data-to-a-fake-government-request</link>
      <guid isPermaLink="true">https://getpentest.ca/brief/6-revolut-handed-data-to-a-fake-government-request</guid>
      <pubDate>Tue, 15 Sep 2026 13:00:00 +0000</pubDate>
      <description>Artifactory auth bypasses are now on the exploited list. CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalogue on September 11.</description>
    </item>
    <item>
      <title>JFrog Artifactory flaw lands in the KEV catalogue</title>
      <link>https://getpentest.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</link>
      <guid isPermaLink="true">https://getpentest.ca/brief/4-what-cisas-two-red-teams-say-about-your-soc-2</guid>
      <pubDate>Tue, 01 Sep 2026 13:00:00 +0000</pubDate>
      <description>JFrog Artifactory flaw lands in the KEV catalogue. CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalogue: an ownCloud authentication flaw, an unspecified Linux kernel issue, and a path traversal issue in JFrog Artifactory. CISA red-teamed two organizations and only one saw it coming. CISA ran simultaneous red team assessments at two organizations and published the comparison.</description>
    </item>
    <item>
      <title>Microsoft patches a 10.0 in Entra ID</title>
      <link>https://getpentest.ca/brief/3-a-cvss-10-in-entra-id-and-a-breach-that-grew-tenfold</link>
      <guid isPermaLink="true">https://getpentest.ca/brief/3-a-cvss-10-in-entra-id-and-a-breach-that-grew-tenfold</guid>
      <pubDate>Tue, 25 Aug 2026 13:00:00 +0000</pubDate>
      <description>Microsoft patches a 10.0 in Entra ID. Microsoft patched CVE-2026-69836, a remote code execution flaw in Entra ID carrying a CVSS score of 10.0, which was initially reported as exploited in the wild.</description>
    </item>
    <item>
      <title>Hidden prompt injection is showing up in &quot;Ask AI&quot; buttons on marketing pages</title>
      <link>https://getpentest.ca/brief/1-a-250-000-penalty-and-a-vendor-that-went-dark</link>
      <guid isPermaLink="true">https://getpentest.ca/brief/1-a-250-000-penalty-and-a-vendor-that-went-dark</guid>
      <pubDate>Tue, 11 Aug 2026 13:00:00 +0000</pubDate>
      <description>Hidden prompt injection is showing up in &quot;Ask AI&quot; buttons on marketing pages. Researchers observed production websites embedding hidden prompt injection payloads inside pre-filled deep links behind &quot;Ask AI&quot; buttons, including on marketing and competitor comparison pages.</description>
    </item>
  </channel>
</rss>
