<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Vulnerability Management on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
    <link>https://www.msbiro.net/tags/vulnerability-management/</link>
    <description>Recent content in Vulnerability Management on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</description>
    <image>
      <title>Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
      <url>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 09 Aug 2026 09:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.msbiro.net/tags/vulnerability-management/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SCTPhantom (CVE-2026-64564): Threat-Modeling a High-Impact SCTP Kernel Flaw Without Panic</title>
      <link>https://www.msbiro.net/posts/sctphantom-cve-2026-64564-threat-modeling/</link>
      <pubDate>Sun, 09 Aug 2026 09:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/sctphantom-cve-2026-64564-threat-modeling/</guid>
      <description>CVE-2026-64564 (SCTPhantom) is a critical Linux kernel use-after-free in SCTP ASCONF with a high CVSS score and a demonstrated container escape. A DevSecOps threat-modeling walkthrough of when to care, who is actually at risk, and how to prioritize patching without panic, accounting for attacker-creatable SCTP associations.</description>
    </item>
    <item>
      <title>OWASP GenAI LLM Top 10 2026: What the New Rankings Mean for Security Teams</title>
      <link>https://www.msbiro.net/posts/owasp-genai-llm-top-10-2026/</link>
      <pubDate>Wed, 05 Aug 2026 07:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/owasp-genai-llm-top-10-2026/</guid>
      <description>OWASP released the GenAI LLM Top 10 2026, the first edition grounded in 7,714 real AI security incidents. Prompt Injection stays at number one. Excessive Agency climbs. Misinformation is the widest gap between what practitioners fear and what the evidence shows.</description>
    </item>
    <item>
      <title>ECB on AI-Enabled Cybersecurity Threats: What Banks Must Do by October 2026</title>
      <link>https://www.msbiro.net/posts/ecb-ai-enabled-cybersecurity-threats-letter/</link>
      <pubDate>Fri, 10 Jul 2026 08:30:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/ecb-ai-enabled-cybersecurity-threats-letter/</guid>
      <description>ECB letter on AI-enabled cybersecurity threats: action plan due October 2026, ITRQ deadline extension, CNAPP, hardened images, SBOMs and DORA resilience.</description>
    </item>
    <item>
      <title>2025 CWE Top 25: Mitre&#39;s Critical Software Weakness Rankings and Trends</title>
      <link>https://www.msbiro.net/posts/top25mitre2025/</link>
      <pubDate>Wed, 17 Dec 2025 05:19:07 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/top25mitre2025/</guid>
      <description>Mitre&amp;#39;s 2025 CWE Top 25 reveals persistent threats like XSS and SQL Injection atop the list, with rising authorization flaws and memory bugs signaling DevSecOps priorities for cloud-native apps. Explore the top 10 changes from 2024, key trends, and how CWE root causes differ from CVEs.</description>
    </item>
    <item>
      <title>Understanding the Power of SBOMs: Insights from OpenSSF&#39;s White Paper</title>
      <link>https://www.msbiro.net/posts/openssf-sbom-whitepaper/</link>
      <pubDate>Fri, 03 Oct 2025 16:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/openssf-sbom-whitepaper/</guid>
      <description>This article explores the OpenSSF white paper &amp;#39;Improving Risk Management Decisions with SBOM Data,&amp;#39; highlighting how Software Bill of Materials (SBOMs) provide critical visibility into software components, vulnerabilities, and licensing. It covers 13 practical SBOM use cases, the SBOM lifecycle from creation to consumption, and key OpenSSF tooling for managing SBOMs in cloud-native environments to enhance security, compliance, and supply chain risk management.</description>
    </item>
    <item>
      <title>Urgent: Zero-Day CVEs Found in Two Major Secrets Managers — Have You Updated Yet?</title>
      <link>https://www.msbiro.net/posts/0day-cves-secrets-manager/</link>
      <pubDate>Mon, 11 Aug 2025 12:39:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/0day-cves-secrets-manager/</guid>
      <description>This article highlights recent zero-day vulnerabilities discovered in CyberArk and HashiCorp secrets managers, emphasizes the importance of timely software updates, and offers practical advice for staying proactive about security patches.</description>
    </item>
    <item>
      <title>The Critical Trio: Secrets Manager, Zero-CVE Images, and CNAPP are Needed (Not Only) for DORA Compliance!</title>
      <link>https://www.msbiro.net/posts/secrets-cnapp-0cve-dora/</link>
      <pubDate>Thu, 07 Aug 2025 06:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/secrets-cnapp-0cve-dora/</guid>
      <description>Why Secrets Manager, Zero-CVE container images, and CNAPPs are essential for cybersecurity resilience and DORA compliance</description>
    </item>
    <item>
      <title>SIGHUP Secure Containers: how do you choose the oci base image for your workload?</title>
      <link>https://www.msbiro.net/posts/sighup-secure-container-how-choose-base-image-security/</link>
      <pubDate>Thu, 13 Apr 2023 12:30:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/sighup-secure-container-how-choose-base-image-security/</guid>
      <description>This post discusses how to choose the right OCI base image for your workloads, emphasizing the importance of security, vulnerability management, and timely updates. It showcases SIGHUP’s Secure Containers service, which offers a curated, proactively patched container catalog with support, SLAs, and automation benefits to help teams maintain secure, compliant container supply chains.</description>
    </item>
    <item>
      <title>How Is It Possible to Make Both Developers and Security Officers Happy? Try Snyk!</title>
      <link>https://www.msbiro.net/posts/how-make-developers-and-security-officers-happy-with-snyk/</link>
      <pubDate>Fri, 13 Jan 2023 16:23:03 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/how-make-developers-and-security-officers-happy-with-snyk/</guid>
      <description>Snyk is a powerful security platform offering tools for static analysis (SAST), software composition analysis (SCA), container security, infrastructure as code, and cloud security. This post explains how Snyk helps developers maintain secure codebases while enabling security officers to oversee vulnerabilities without slowing development. Learn about Snyk’s integrations in IDEs, CI/CD, and Git workflows, customizable dashboards for security teams, and its open-source vulnerability database. A free plan makes testing easy for anyone interested in improving software security.</description>
    </item>
  </channel>
</rss>
