<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>UMBRASEC Research</title>
    <link>https://umbrasec.dev/research/</link>
    <atom:link href="https://umbrasec.dev/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Independent defensive security research - detection engineering, threat analysis, and open-source tooling.</description>
    <language>en-us</language>
    <!-- AUTO:builddate START --><lastBuildDate>Sat, 20 Jun 2026 12:00:00 +0000</lastBuildDate><!-- AUTO:builddate END -->
    <!-- AUTO:items START -->
    <item>
      <title>SafePay Is Claiming Australian Victims - Why Real Estate SMBs Are in the Blast Radius</title>
      <link>https://umbrasec.dev/research/safepay-australian-smb.html</link>
      <guid isPermaLink="true">https://umbrasec.dev/research/safepay-australian-smb.html</guid>
      <pubDate>Sat, 20 Jun 2026 12:00:00 +0000</pubDate>
      <category>Threat Analysis</category>
      <description>SafePay is a centralized (non-RaaS) ransomware crew now claiming Australian victims, and real-estate SMBs fit its target profile almost perfectly: data-rich, cash-handling via trust accounts, thinly defended, and spread across franchise offices under one brand. The playbook stage by stage - unpatched edge devices, infostealer-harvested logins reused over RDP/VPN, PsExec/WinRM movement, rclone and FileZilla exfiltration, backup and shadow-copy deletion - mapped to the Essential Eight controls that break each link. Built entirely from public vendor reporting, naming no individual victim.</description>
    </item>
    <item>
      <title>How INC Ransom Hits Australian SMBs - and the Essential Eight That Stops It</title>
      <link>https://umbrasec.dev/research/inc-ransom-australian-smb.html</link>
      <guid isPermaLink="true">https://umbrasec.dev/research/inc-ransom-australian-smb.html</guid>
      <pubDate>Mon, 15 Jun 2026 12:00:00 +0000</pubDate>
      <category>Threat Analysis</category>
      <description>INC Ransom is a ransomware-as-a-service crew actively claiming Australian victims, and the firms it lands on look a lot like a typical SMB. The affiliate playbook stage by stage - phishing, unpatched edge devices, bought credentials, living-off-the-land movement, commodity exfiltration with rclone and MEGAsync - mapped to the Essential Eight controls that break each link in the chain. Built entirely from public reporting, including the ACSC/CERT NZ advisory.</description>
    </item>
    <item>
      <title>Securing AI Agents: A Defender's Guide to Tool-Calling LLMs</title>
      <link>https://umbrasec.dev/research/securing-ai-agents.html</link>
      <guid isPermaLink="true">https://umbrasec.dev/research/securing-ai-agents.html</guid>
      <pubDate>Sun, 14 Jun 2026 12:00:00 +0000</pubDate>
      <category>AI &amp; LLM Security</category>
      <description>A chatbot that gets prompt-injected says something wrong; an agent that gets prompt-injected does something wrong. The agent threat surface - excessive agency, indirect injection via tool output, the MCP supply chain, the confused-deputy identity problem - what to log, and the detections and containment architecture that keep one bad instruction from becoming an incident.</description>
    </item>
    <item>
      <title>Detecting the LiteLLM Command Injection (CVE-2026-42271) in Your AI Gateway</title>
      <link>https://umbrasec.dev/research/detecting-litellm-command-injection.html</link>
      <guid isPermaLink="true">https://umbrasec.dev/research/detecting-litellm-command-injection.html</guid>
      <pubDate>Sat, 13 Jun 2026 12:00:00 +0000</pubDate>
      <category>Detection Engineering</category>
      <description>CVE-2026-42271 turns LiteLLM's MCP preview endpoints into authenticated command execution on the proxy host, and chains with the Starlette "BadHost" bug (CVE-2026-48710) into unauthenticated RCE. In CISA KEV and actively exploited - the mechanism at a defender's depth, what to log, and two runnable Sigma rules with tuning notes.</description>
    </item>
    <item>
      <title>Prompt Injection and the OWASP LLM Top 10: A Field Guide for Defenders</title>
      <link>https://umbrasec.dev/research/owasp-llm-top-10-for-defenders.html</link>
      <guid isPermaLink="true">https://umbrasec.dev/research/owasp-llm-top-10-for-defenders.html</guid>
      <pubDate>Thu, 11 Jun 2026 12:00:00 +0000</pubDate>
      <category>AI &amp; LLM Security</category>
      <description>The OWASP LLM Top 10 read as a defender's checklist: why prompt injection has no patch, the "lethal trifecta" behind incidents like EchoLeak (CVE-2025-32711), what to log in LLM-integrated apps, and canary, egress, and behavioral detections you can deploy today.</description>
    </item>
    <item>
      <title>Detecting OAuth Consent Phishing in Microsoft 365</title>
      <link>https://umbrasec.dev/research/detecting-oauth-consent-phishing.html</link>
      <guid isPermaLink="true">https://umbrasec.dev/research/detecting-oauth-consent-phishing.html</guid>
      <pubDate>Thu, 11 Jun 2026 12:00:00 +0000</pubDate>
      <category>Detection Engineering</category>
      <description>The phishing class that never asks for a password and sails through MFA - illicit OAuth consent grants (MITRE ATT&amp;CK T1528) in Microsoft Entra ID, the audit-log artifacts they leave, and KQL detections with tuning notes.</description>
    </item>
    <item>
      <title>Detecting Kerberoasting: A Practical Walkthrough with Sigma</title>
      <link>https://umbrasec.dev/research/detecting-kerberoasting.html</link>
      <guid isPermaLink="true">https://umbrasec.dev/research/detecting-kerberoasting.html</guid>
      <pubDate>Wed, 10 Jun 2026 12:00:00 +0000</pubDate>
      <category>Detection Engineering</category>
      <description>How Kerberoasting (MITRE ATT&amp;CK T1558.003) works, why RC4 service tickets give it away, and three layered Sigma detections - RC4 downgrade, request fan-out, and a honeypot SPN - with tuning and false-positive notes you can run against your own logs.</description>
    </item>
  <!-- AUTO:items END -->
  </channel>
</rss>
