<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security Operations on Juan Carlos Munera</title><link>https://cybersecpro.me/categories/security-operations/</link><description>Recent content in Security Operations on Juan Carlos Munera</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Juan Carlos Munera</copyright><lastBuildDate>Wed, 05 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cybersecpro.me/categories/security-operations/index.xml" rel="self" type="application/rss+xml"/><item><title>When a Public Exploit Lands in Two Days, Severity Ratings Aren't Enough</title><link>https://cybersecpro.me/posts/public-exploit-window-patch-priority/</link><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/public-exploit-window-patch-priority/</guid><description>A threat-hunting report puts the gap between a public proof-of-concept and active exploitation at about 48 hours. Here is what that does to patch scheduling, why severity scores are the wrong primary signal, and a few adjustments worth making.</description></item><item><title>Covert Channels and Protocol Abuse: How Data Quietly Leaves Networks</title><link>https://cybersecpro.me/posts/covert-data-exfil/</link><pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/covert-data-exfil/</guid><description>A practitioner primer on protocol abuse: how data quietly leaves networks through DNS, ICMP, HTTPS/TLS, and the headers of TCP itself.</description></item><item><title>When the Negotiator Is on Both Sides of the Table: Rethinking IR Trust After the BlackCat Sentencings</title><link>https://cybersecpro.me/posts/ir-firm-insider-threat-trust-architecture/</link><pubDate>Fri, 01 May 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/ir-firm-insider-threat-trust-architecture/</guid><description>The BlackCat sentencings expose the trust every organization quietly extends to its incident response vendor, and how to structure it better.</description></item><item><title>MFA Won't Save You: How Device Code Phishing Bypasses Your Strongest Authentication</title><link>https://cybersecpro.me/posts/device-code-phishing-mfa-bypass/</link><pubDate>Mon, 06 Apr 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/device-code-phishing-mfa-bypass/</guid><description>At least 11 phishing kits now abuse the OAuth device flow to bypass MFA entirely. How the attack works and how to shut it down.</description></item><item><title>The FCC Just Banned Foreign-Made Routers. It Should Have Happened Years Ago.</title><link>https://cybersecpro.me/posts/device-security-fcc/</link><pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/device-security-fcc/</guid><description>Every consumer router made outside the US is now on the FCC Covered List. Why firmware verification matters more than the import ban.</description></item><item><title>Non-Human Identities Are the Top Emerging Threat, and It's Privileged Service Accounts All Over Again</title><link>https://cybersecpro.me/posts/nhi-emerging-threat/</link><pubDate>Tue, 17 Mar 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/nhi-emerging-threat/</guid><description>If your IAM program doesn&amp;rsquo;t treat non-human identities with the same rigor as human accounts, you have a problem that&amp;rsquo;s already being exploited.</description></item><item><title>Intel Hub</title><link>https://cybersecpro.me/projects/intel-hub/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/projects/intel-hub/</guid><description>Monitors 170+ cybersecurity, geopolitical, OSINT, and dark web feeds with severity classification, credibility scoring, and bias tagging. No API keys.</description></item><item><title>Quantum Won't Kill Encryption. It Never Has.</title><link>https://cybersecpro.me/posts/quantum-wont-kill-encryption/</link><pubDate>Thu, 19 Feb 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/quantum-wont-kill-encryption/</guid><description>Why the cryptographic doomsday framing misleads, and what practitioners should actually be doing about post-quantum migration in 2026.</description></item><item><title>Understanding Zero Trust Security Architecture</title><link>https://cybersecpro.me/posts/zero-trust-security/</link><pubDate>Thu, 22 Jan 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/zero-trust-security/</guid><description>Zero Trust assumes no implicit trust based on network location. What that means in practice and how to build toward it incrementally.</description></item></channel></rss>