<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:media="http://search.yahoo.com/mrss/">
<channel>
    <title>Cybersecurity Tomorrow &amp; : Niche &amp;amp; Research&amp;Oriented</title>
    <link>https://cybersecuritytomorrow.com/rss/category/niche-research-oriented</link>
    <description>Cybersecurity Tomorrow &amp; : Niche &amp;amp; Research&amp;Oriented</description>
    <dc:language>en</dc:language>
    <dc:creator></dc:creator>
    <dc:rights>Copyright 2025 Cybersecurity Tomorrow &amp; All Rights Reserved.</dc:rights>
    <item>
        <title>Patch Now: Oracle&amp;apos;s Fusion Middleware Has Critical RCE Flaw</title>
        <link>https://cybersecuritytomorrow.com/patch-now-oracles-fusion-middleware-has-critical-rce-flaw</link>
        <guid>https://cybersecuritytomorrow.com/patch-now-oracles-fusion-middleware-has-critical-rce-flaw</guid>
        <description><![CDATA[ Attackers can execute arbitrary code without authentication if Oracle&#039;s Identity or Web Services Managers are exposed to the Web. ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt3966162dd76f69cb/69bd954678da062bb91c2e6a/Oracle-Jerome_Cid-Alamy.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Patch, Now:, Oracles, Fusion, Middleware, Has, Critical, RCE, Flaw</media:keywords>
    </item>
    <item>
        <title>Cyber OpSec Fail: Beast Gang Exposes Ransomware Server</title>
        <link>https://cybersecuritytomorrow.com/cyber-opsec-fail-beast-gang-exposes-ransomware-server</link>
        <guid>https://cybersecuritytomorrow.com/cyber-opsec-fail-beast-gang-exposes-ransomware-server</guid>
        <description><![CDATA[ Files on a central cloud server used by the ransomware group highlight a systematic, aggressive attack on network backups as a key TTP. ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt37940faf94d51576/69bd782de800671de0dc9622/beast-masks-at-hungarian-spring-carnival-Zsolt_Biczo-shutterstock.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Cyber, OpSec, Fail:, Beast, Gang, Exposes, Ransomware, Server</media:keywords>
    </item>
    <item>
        <title>Interlock Ransomware Targets Cisco Enterprise Firewalls</title>
        <link>https://cybersecuritytomorrow.com/interlock-ransomware-targets-cisco-enterprise-firewalls</link>
        <guid>https://cybersecuritytomorrow.com/interlock-ransomware-targets-cisco-enterprise-firewalls</guid>
        <description><![CDATA[ The ransomware gang, known for double-extortion attacks, had access to a critical Cisco firewall vulnerability weeks before it was publicly disclosed. ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc20a31ce918ced0e/69bc51ca221466202f29a950/Interlocking_Gears_Zoonar_GmbH_Alamy.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Interlock, Ransomware, Targets, Cisco, Enterprise, Firewalls</media:keywords>
    </item>
    <item>
        <title>AI Conundrum: Why MCP Security Can&amp;apos;t Be Patched Away</title>
        <link>https://cybersecuritytomorrow.com/ai-conundrum-why-mcp-security-cant-be-patched-away</link>
        <guid>https://cybersecuritytomorrow.com/ai-conundrum-why-mcp-security-cant-be-patched-away</guid>
        <description><![CDATA[ RSAC Conference Preview: MCP introduces security risks into LLM environments that are architectural and not easily fixable, researcher says. ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt1b349661d49e33aa/69bc6456139466076c16011f/mcp_Umut_Hasanoglu_shutterstock.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Conundrum:, Why, MCP, Security, Cant, Patched, Away</media:keywords>
    </item>
    <item>
        <title>With Government&amp;apos;s Role Uncertain, Businesses Unite to Combat Fraud</title>
        <link>https://cybersecuritytomorrow.com/with-governments-role-uncertain-businesses-unite-to-combat-fraud</link>
        <guid>https://cybersecuritytomorrow.com/with-governments-role-uncertain-businesses-unite-to-combat-fraud</guid>
        <description><![CDATA[ Major industry leaders agree to share information and collaborate to boost defenses in the wake of distressing online scams. ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt852374154dc9b41e/680964f6901a150e471ede06/Cyber_fraud_(1800)_Olekcii_Mach_Alamy.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>With, Governments, Role, Uncertain, Businesses, Unite, Combat, Fraud</media:keywords>
    </item>
    <item>
        <title>South Korean Police Accidentally Post Cryptocurrency Wallet Password</title>
        <link>https://cybersecuritytomorrow.com/south-korean-police-accidentally-post-cryptocurrency-wallet-password</link>
        <guid>https://cybersecuritytomorrow.com/south-korean-police-accidentally-post-cryptocurrency-wallet-password</guid>
        <description><![CDATA[ An expensive mistake:

Someone jumped at the opportunity to steal $4.4 million in crypto assets after South Korea’s National Tax Service exposed publicly the mnemonic recovery phrase of a seized cryptocurrency wallet.
The funds were stored in a Ledger cold wallet seized in law enforcement raids at 124 high-value tax evaders that resulted in confiscating digital assets worth 8.1 billion won (currently approximately $5.6 million).
When announcing the success of the operation, the agency released photos of a Ledger device, a popular hardware wallet for crypto storage and management... ]]></description>
        <enclosure url="http://www.schneier.com/wp-content/uploads/2019/10/rss-32px.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:14 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>South, Korean, Police, Accidentally, Post, Cryptocurrency, Wallet, Password</media:keywords>
    </item>
    <item>
        <title>Meta’s AI Glasses and Privacy</title>
        <link>https://cybersecuritytomorrow.com/metas-ai-glasses-and-privacy</link>
        <guid>https://cybersecuritytomorrow.com/metas-ai-glasses-and-privacy</guid>
        <description><![CDATA[ Surprising no one, Meta’s new AI glasses are a privacy disaster.
I’m not sure what can be done here. This is a technology that will exist, whether we like it or not.
Meanwhile, there is a new Android app that detects when there are smart glasses nearby. ]]></description>
        <enclosure url="http://www.schneier.com/wp-content/uploads/2019/10/rss-32px.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:13 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Meta’s, Glasses, and, Privacy</media:keywords>
    </item>
    <item>
        <title>Hacking a Robot Vacuum</title>
        <link>https://cybersecuritytomorrow.com/hacking-a-robot-vacuum</link>
        <guid>https://cybersecuritytomorrow.com/hacking-a-robot-vacuum</guid>
        <description><![CDATA[ Someone tries to remote control his own DJI Romo vacuum, and ends up controlling 7,000 of them from all around the world.
The IoT is horribly insecure, but we already knew that. ]]></description>
        <enclosure url="http://www.schneier.com/wp-content/uploads/2019/10/rss-32px.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:11 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Hacking, Robot, Vacuum</media:keywords>
    </item>
    <item>
        <title>Proton Mail Shared User Information with the Police</title>
        <link>https://cybersecuritytomorrow.com/proton-mail-shared-user-information-with-the-police</link>
        <guid>https://cybersecuritytomorrow.com/proton-mail-shared-user-information-with-the-police</guid>
        <description><![CDATA[ 404 Media has a story about Proton Mail giving subscriber data to the Swiss government, who passed the information to the FBI.
It’s metadata—payment information related to a particular account—but still important knowledge. This sort of thing happens, even to privacy-centric companies like Proton Mail. ]]></description>
        <enclosure url="http://www.schneier.com/wp-content/uploads/2019/10/rss-32px.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:10 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Proton, Mail, Shared, User, Information, with, the, Police</media:keywords>
    </item>
    <item>
        <title>Friday Squid Blogging: Jumbo Flying Squid in the South Pacific</title>
        <link>https://cybersecuritytomorrow.com/friday-squid-blogging-jumbo-flying-squid-in-the-south-pacific</link>
        <guid>https://cybersecuritytomorrow.com/friday-squid-blogging-jumbo-flying-squid-in-the-south-pacific</guid>
        <description><![CDATA[ The population needs better conservation.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Blog moderation policy. ]]></description>
        <enclosure url="http://www.schneier.com/wp-content/uploads/2019/10/rss-32px.png" length="49398" type="image/jpeg"/>
        <pubDate>Sun, 22 Mar 2026 15:33:09 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Friday, Squid, Blogging:, Jumbo, Flying, Squid, the, South, Pacific</media:keywords>
    </item>
    <item>
        <title>Upcoming Speaking Engagements</title>
        <link>https://cybersecuritytomorrow.com/upcoming-speaking-engagements</link>
        <guid>https://cybersecuritytomorrow.com/upcoming-speaking-engagements</guid>
        <description><![CDATA[ This is a current list of where and when I am scheduled to speak:

I’m giving an online talk on AI and trust for the Weizenbaum Institute on April 24, 2025 at 2:00 PM CEST (8:00 AM ET).

The list is maintained on this page.
  ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:11:19 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Upcoming, Speaking, Engagements</media:keywords>
    </item>
    <item>
        <title>Slopsquatting</title>
        <link>https://cybersecuritytomorrow.com/slopsquatting</link>
        <guid>https://cybersecuritytomorrow.com/slopsquatting</guid>
        <description><![CDATA[ As AI coding assistants invent nonexistent software libraries to download and use, enterprising attackers create and upload libraries with those names—laced with malware, of course. ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:11:18 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Slopsquatting</media:keywords>
    </item>
    <item>
        <title>CVE Program Almost Unfunded</title>
        <link>https://cybersecuritytomorrow.com/cve-program-almost-unfunded</link>
        <guid>https://cybersecuritytomorrow.com/cve-program-almost-unfunded</guid>
        <description><![CDATA[ Mitre’s CVE’s program—which provides common naming and other informational resources about cybersecurity vulnerabilities—was about to be cancelled, as the US Department of Homeland Security failed to renew the contact. It was funded for eleven more months at the last minute.
This is a big deal. The CVE program is one of those pieces of common infrastructure that everyone benefits from. Losing it will bring us back to a world where there’s no single way to talk about vulnerabilities. It’s kind of crazy to think that the US government might damage its own security in this way—but I suppose no crazier than any of the other ways the US is working against its own interests right now... ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:11:16 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>CVE, Program, Almost, Unfunded</media:keywords>
    </item>
    <item>
        <title>Age Verification Using Facial Scans</title>
        <link>https://cybersecuritytomorrow.com/age-verification-using-facial-scans</link>
        <guid>https://cybersecuritytomorrow.com/age-verification-using-facial-scans</guid>
        <description><![CDATA[ Discord is  testing the feature:
“We’re currently running tests in select regions to age-gate access to certain spaces or user settings,” a spokesperson for Discord said in a statement. “The information shared to power the age verification method is only used for the one-time age verification process and is not stored by Discord or our vendor. For Face Scan, the solution our vendor uses operates on-device, which means there is no collection of any biometric information when you scan your face. For ID verification, the scan of your ID is deleted upon verification.”... ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:11:15 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Age, Verification, Using, Facial, Scans</media:keywords>
    </item>
    <item>
        <title>Friday Squid Blogging: Live Colossal Squid Filmed</title>
        <link>https://cybersecuritytomorrow.com/friday-squid-blogging-live-colossal-squid-filmed</link>
        <guid>https://cybersecuritytomorrow.com/friday-squid-blogging-live-colossal-squid-filmed</guid>
        <description><![CDATA[ A live colossal squid was filmed for the first time in the ocean. It’s only a juvenile: a foot long.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. ]]></description>
        <enclosure url="http://cybersecuritytomorrow.com" length="4096" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:11:13 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Friday, Squid, Blogging:, Live, Colossal, Squid, Filmed</media:keywords>
    </item>
    <item>
        <title>Could Ransomware Survive Without Cryptocurrency?</title>
        <link>https://cybersecuritytomorrow.com/could-ransomware-survive-without-cryptocurrency</link>
        <guid>https://cybersecuritytomorrow.com/could-ransomware-survive-without-cryptocurrency</guid>
        <description><![CDATA[ Threat actors would be at least temporarily derailed, experts say. But the real issue ladders back to organizations’ weak cyber hygiene. ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt121d9e06e00992e3/66e1a2cd23ab25574e44ad14/Ransomware(1800)_Andreas_Prott_Alamy.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:10:51 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Could, Ransomware, Survive, Without, Cryptocurrency</media:keywords>
    </item>
    <item>
        <title>AWWA Supports Introduction of Collaborative Cybersecurity Legislation</title>
        <link>https://cybersecuritytomorrow.com/awwa-supports-introduction-of-collaborative-cybersecurity-legislation</link>
        <guid>https://cybersecuritytomorrow.com/awwa-supports-introduction-of-collaborative-cybersecurity-legislation</guid>
        <description><![CDATA[  ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt850556f866500627/654a5a8e05eb4d040a046894/325351_DR23_Graphics_General_Large_Text_v1.png" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:10:51 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>AWWA, Supports, Introduction, Collaborative, Cybersecurity, Legislation</media:keywords>
    </item>
    <item>
        <title>Organizations Fix Less Than Half of All Exploitable Vulnerabilities, With Just 21% of GenAI App Flaws Resolved</title>
        <link>https://cybersecuritytomorrow.com/organizations-fix-less-than-half-of-all-exploitable-vulnerabilities-with-just-21-of-genai-app-flaws-resolved</link>
        <guid>https://cybersecuritytomorrow.com/organizations-fix-less-than-half-of-all-exploitable-vulnerabilities-with-just-21-of-genai-app-flaws-resolved</guid>
        <description><![CDATA[  ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt850556f866500627/654a5a8e05eb4d040a046894/325351_DR23_Graphics_General_Large_Text_v1.png" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:10:51 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Organizations, Fix, Less, Than, Half, All, Exploitable, Vulnerabilities, With, Just, 21, GenAI, App, Flaws, Resolved</media:keywords>
    </item>
    <item>
        <title>Attackers and Defenders Lean on AI in Identity Fraud Battle</title>
        <link>https://cybersecuritytomorrow.com/attackers-and-defenders-lean-on-ai-in-identity-fraud-battle</link>
        <guid>https://cybersecuritytomorrow.com/attackers-and-defenders-lean-on-ai-in-identity-fraud-battle</guid>
        <description><![CDATA[ Identity verification, insurance claims, and financial services are all seeing surges in AI-enabled fraud, but organizations are taking advantage of AI systems to fight fire with fire. ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltad54be6b01576633/67ffbc8f590d24262f8594d5/fingerprint-identity-verification-ART_STOCK_CREATIVE-shutterstock.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:10:51 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Attackers, and, Defenders, Lean, Identity, Fraud, Battle</media:keywords>
    </item>
    <item>
        <title>Chinese APT Mustang Panda Debuts 4 New Attack Tools</title>
        <link>https://cybersecuritytomorrow.com/chinese-apt-mustang-panda-debuts-4-new-attack-tools</link>
        <guid>https://cybersecuritytomorrow.com/chinese-apt-mustang-panda-debuts-4-new-attack-tools</guid>
        <description><![CDATA[ The notorious nation-state-backed threat actor has added two new keyloggers, a lateral movement tool, and an endpoint detection and response (EDR) evasion driver to its arsenal. ]]></description>
        <enclosure url="http://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt61e68617764cdb10/680277d35ded1a8c1efc56d7/Mustang_Panda-Dan_Herrick-Alamy.jpg" length="49398" type="image/jpeg"/>
        <pubDate>Sat, 19 Apr 2025 16:10:51 -0400</pubDate>
        <dc:creator>Darpan Neupane</dc:creator>
        <media:keywords>Chinese, APT, Mustang, Panda, Debuts, New, Attack, Tools</media:keywords>
    </item>
    </channel>
</rss>