<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Threat Research on Juan Carlos Munera</title><link>https://cybersecpro.me/categories/threat-research/</link><description>Recent content in Threat Research on Juan Carlos Munera</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Juan Carlos Munera</copyright><lastBuildDate>Thu, 16 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://cybersecpro.me/categories/threat-research/index.xml" rel="self" type="application/rss+xml"/><item><title>Your Streaming Box Is Someone Else's Exit Node: SOCKS5 Proxies and the Traffic Laundering Economy</title><link>https://cybersecpro.me/posts/iptv-streaming-security/</link><pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/iptv-streaming-security/</guid><description>How the traffic laundering economy turns jailbroken FireSticks into residential proxies, and what defenders can actually do about it.</description></item><item><title>IronWorm: A Self-Propagating npm Worm Built to Steal Machine Identities</title><link>https://cybersecpro.me/posts/ironworm-npm-worm/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/ironworm-npm-worm/</guid><description>A practitioner breakdown of the npm worm that sweeps environment variables on install and republishes itself through Trusted Publishing.</description></item><item><title>Reading the 2026 Verizon DBIR: AI Is the Catalyst, Not the Threat Actor</title><link>https://cybersecpro.me/posts/2026-dbir-ai-as-catalyst/</link><pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/2026-dbir-ai-as-catalyst/</guid><description>The largest DBIR ever published, read for signal. Where generative AI actually shows up in the data and where the fundamentals still rule.</description></item><item><title>How Hackers Talked an AI Into Helping Them Build a Zero-Day</title><link>https://cybersecpro.me/posts/ai-jailbreak-zero-day-google-gtig/</link><pubDate>Wed, 13 May 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/ai-jailbreak-zero-day-google-gtig/</guid><description>Google caught the first AI-assisted zero-day in the wild. How attackers talked a model into helping, and why the method matters more than the exploit.</description></item><item><title>FIRESTARTER and the Detection Gap CISA Just Made Official</title><link>https://cybersecpro.me/posts/firestarter-cisco-backdoor-detection-gap/</link><pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/firestarter-cisco-backdoor-detection-gap/</guid><description>CISA and NCSC published a joint analysis of FIRESTARTER, a backdoor that survives reboots and evades signature detection on Cisco edge devices.</description></item><item><title>Operation Masquerade: FBI Disrupts APT28 Campaign Across 18,000 Hijacked Routers</title><link>https://cybersecpro.me/posts/operation-masquerade-fbi-apt28-router-dns-hijacking/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/operation-masquerade-fbi-apt28-router-dns-hijacking/</guid><description>How the DNS hijacking attack chain worked across 120+ countries, and what practitioners should be checking in their own environments.</description></item><item><title>CPU-Z and HWMonitor Hijacked: Inside the CPUID Supply Chain Attack</title><link>https://cybersecpro.me/posts/cpuid-cpu-z-hwmonitor-supply-chain-attack/</link><pubDate>Sun, 12 Apr 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/cpuid-cpu-z-hwmonitor-supply-chain-attack/</guid><description>How the April 2026 compromise of CPUID&amp;rsquo;s site turned CPU-Z and HWMonitor downloads into a multi-stage malware delivery chain.</description></item><item><title>Two FortiClient EMS Zero-Days in Two Weeks: Why Your Endpoint Management Server Is the Target</title><link>https://cybersecpro.me/posts/forticlient-ems-double-zero-day/</link><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/forticlient-ems-double-zero-day/</guid><description>Why endpoint management servers are a high-value target, how both flaws were exploited, and the actions practitioners should take today.</description></item><item><title>IBM X-Force 2026: AI Is Speeding Up Attacks, But Basic Hygiene Failures Are Still the Real Problem</title><link>https://cybersecpro.me/posts/ibm-xforce-threat-intelligence-index-2026/</link><pubDate>Wed, 11 Mar 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/ibm-xforce-threat-intelligence-index-2026/</guid><description>What the IBM X-Force Threat Intelligence Index 2026 says about AI-accelerated attacks, and why basic hygiene failures still cause the damage.</description></item><item><title>ATM Jackpotting: The Emerging Threat Draining U.S. Cash Machines</title><link>https://cybersecpro.me/posts/atm-jackpotting/</link><pubDate>Sun, 22 Feb 2026 00:00:00 +0000</pubDate><guid>https://cybersecpro.me/posts/atm-jackpotting/</guid><description>A threat that matured abroad has found a home in the US. How ATM jackpotting works, why it keeps working, and what the industry guidance says.</description></item></channel></rss>