<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>C1BAS Blog</title>
    <link>https://www.c1bas.com/blog</link>
    <description>Threat research and cybersecurity writing from the C1BAS team.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 03 Jun 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://www.c1bas.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Tracking a Suspected SilverFox APT Operation</title>
      <link>https://www.c1bas.com/blog/silverfox-apt-valleyrat-python-infostealer</link>
      <guid isPermaLink="true">https://www.c1bas.com/blog/silverfox-apt-valleyrat-python-infostealer</guid>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
      <description>WhatsApp-delivered ZIP archive, DLL-sideloaded via signed Tencent binaries, deploying ValleyRAT and a Cython-compiled Python RAT. Inside the SilverFox chain.</description>
      <category>Threat Research</category>
    </item>
    <item>
      <title>How a Routine External Pentest Uncovered an 18-Month Active Compromise on Day One</title>
      <link>https://www.c1bas.com/blog/how-a-routine-external-pentesting-uncovered-an-18-month-active-compromise-on-day-one</link>
      <guid isPermaLink="true">https://www.c1bas.com/blog/how-a-routine-external-pentesting-uncovered-an-18-month-active-compromise-on-day-one</guid>
      <pubDate>Sat, 29 Nov 2025 00:00:00 GMT</pubDate>
      <description>Routine external pentest discovered SocGholish, multiple Russian backdoors, and a SystemBC RAT actively running on a client&apos;s public website for 18 months.</description>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Zivver Phishing: How Real Secure Messages Deliver Fake Logins</title>
      <link>https://www.c1bas.com/blog/zivver-phishing-how-real-secure-messages-deliver-fake-logins</link>
      <guid isPermaLink="true">https://www.c1bas.com/blog/zivver-phishing-how-real-secure-messages-deliver-fake-logins</guid>
      <pubDate>Tue, 25 Nov 2025 00:00:00 GMT</pubDate>
      <description>Attackers used a real Zivver secure message to deliver a hidden phishing link, harvesting an M365 mailbox in under five minutes despite real-time SOC alerts.</description>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Mapping Hidden Containers in Azure Cloud Shell: A Case Study in Responsible Disclosure</title>
      <link>https://www.c1bas.com/blog/mapping-hidden-containers-in-azure-cloud-shell-a-case-study-in-responsible-disclosure</link>
      <guid isPermaLink="true">https://www.c1bas.com/blog/mapping-hidden-containers-in-azure-cloud-shell-a-case-study-in-responsible-disclosure</guid>
      <pubDate>Wed, 11 Jun 2025 00:00:00 GMT</pubDate>
      <description>An Azure Cloud Shell information-disclosure vulnerability that turned a /download API into a file-existence oracle, plus reflections on Microsoft&apos;s response.</description>
      <category>Vulnerability Research</category>
    </item>
    <item>
      <title>Breaking Down CVE-2024-30103 and More: Insights from BlueHat 2024 on Microsoft Outlook RCE</title>
      <link>https://www.c1bas.com/blog/breaking-down-cve-2024-30103-more-insights-from-bluehat-2024</link>
      <guid isPermaLink="true">https://www.c1bas.com/blog/breaking-down-cve-2024-30103-more-insights-from-bluehat-2024</guid>
      <pubDate>Tue, 19 Nov 2024 00:00:00 GMT</pubDate>
      <description>Notes from Michael Gorelik&apos;s BlueHat 2024 talk on Microsoft Outlook RCE vulnerabilities including CVE-2024-30103 and the patch landscape that followed.</description>
      <category>Vulnerability Research</category>
    </item>
    <item>
      <title>Understanding Pentesting vs. Cyber Risk Assessment</title>
      <link>https://www.c1bas.com/blog/understanding-pentesting-vs-cyber-risk-assessment</link>
      <guid isPermaLink="true">https://www.c1bas.com/blog/understanding-pentesting-vs-cyber-risk-assessment</guid>
      <pubDate>Fri, 18 Oct 2024 00:00:00 GMT</pubDate>
      <description>Why penetration testing alone doesn&apos;t equal a security program, and how a real cyber risk assessment evaluates the bigger attack surface in business context.</description>
      <category>Cybersecurity Insights</category>
    </item>
  </channel>
</rss>
