<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Zero Trust</title><description>Cybersecurity articles tagged #Zero Trust on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Securing Windows Named Pipes: Mitigating Local Privilege Escalation</title><link>https://runtimerebel.com/blog/securing-windows-named-pipes-mitigating-local-privilege-escalation</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-windows-named-pipes-mitigating-local-privilege-escalation</guid><description>Unsecured Windows named pipes pose significant local privilege escalation risks. Learn to secure IPC by verifying identity and validating input.</description><pubDate>Sun, 23 Aug 2026 00:43:54 GMT</pubDate><category>Privilege Escalation</category><category>Zero Trust</category><category>Named Pipes</category><category>Windows IPC</category><category>Confused Deputy</category></item><item><title>TP-Link Zero-Trust Provisioning Bugs: 15 Flaws Threaten Security</title><link>https://runtimerebel.com/blog/tp-link-zero-trust-provisioning-bugs-15-flaws-threaten-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/tp-link-zero-trust-provisioning-bugs-15-flaws-threaten-security</guid><description>Researchers uncover 15 TP-Link device bugs that undermine automated zero‑trust provisioning, exposing credential leakage and network compromise.</description><pubDate>Mon, 10 Aug 2026 09:10:12 GMT</pubDate><category>TP Link</category><category>Zero Trust</category><category>Provisioning</category><category>Network Devices</category><category>Credential Exposure</category></item><item><title>AI&apos;s Transformative Impact on Threat Intelligence and Defenses</title><link>https://runtimerebel.com/blog/ai-s-transformative-impact-on-threat-intelligence-and-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-s-transformative-impact-on-threat-intelligence-and-defenses</guid><description>AI is rapidly accelerating the threat landscape, enabling machine-speed attacks and increasing defender challenges. Prioritizing intelligence is key.</description><pubDate>Fri, 07 Aug 2026 02:15:12 GMT</pubDate><category>AI</category><category>Threat Intelligence</category><category>Attack Surface</category><category>Zero Trust</category><category>Software Supply Chain</category></item><item><title>AI Security Strategy: Managing the Network as a Control Plane</title><link>https://runtimerebel.com/blog/ai-security-strategy-managing-the-network-as-a-control-plane</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-security-strategy-managing-the-network-as-a-control-plane</guid><description>Analyze the transition of network firewalls into the primary control plane for securing AI workloads and preventing data exfiltration in enterprise environments.</description><pubDate>Thu, 30 Jul 2026 14:06:15 GMT</pubDate><category>AI Security</category><category>Network Firewall</category><category>LLM Security</category><category>Data Exfiltration</category><category>Zero Trust</category></item><item><title>Securing Critical Infrastructure: Closing Identity Gaps</title><link>https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-critical-infrastructure-closing-identity-gaps</guid><description>Attacks on critical infrastructure leverage identity gaps. This analysis details common vulnerabilities and how Zero Trust principles can enhance sector security.</description><pubDate>Tue, 21 Jul 2026 17:24:12 GMT</pubDate><category>Critical Infrastructure</category><category>Identity Security</category><category>Zero Trust</category><category>Credential Theft</category><category>MFA Bypass</category><category>Supply Chain Attack</category><category>Phishing</category></item><item><title>AI-Assisted Vulnerability Management: Operational Guardrails &amp; Risks</title><link>https://runtimerebel.com/blog/ai-assisted-vulnerability-management-operational-guardrails-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-vulnerability-management-operational-guardrails-risks</guid><description>Implement robust guardrails for AI-assisted vulnerability management. Learn to safely deploy LLM agents, reduce architectural risks, and prioritize human-led threat…</description><pubDate>Thu, 16 Jul 2026 17:25:07 GMT</pubDate><category>AI</category><category>LLM</category><category>Vulnerability Management</category><category>SAIF</category><category>NIST AI RMF</category><category>OWASP Top 10 for LLMs</category><category>Mandiant</category><category>Risk Based Vulnerability Management</category><category>Zero Trust</category><category>Software Supply Chain</category><category>SAST</category><category>DAST</category><category>Red Teaming</category></item><item><title>Agentic AI Identity Problem: New Attack Surface for Enterprises</title><link>https://runtimerebel.com/blog/agentic-ai-identity-problem-new-attack-surface-for-enterprises</link><guid isPermaLink="true">https://runtimerebel.com/blog/agentic-ai-identity-problem-new-attack-surface-for-enterprises</guid><description>Agentic AI systems pose novel identity and access management challenges, creating new attack vectors for data exfiltration and privilege escalation.</description><pubDate>Mon, 29 Jun 2026 17:07:07 GMT</pubDate><category>Agentic AI</category><category>AI Security</category><category>Identity Management</category><category>LLM Security</category><category>Privilege Escalation</category><category>Data Exfiltration</category><category>Zero Trust</category></item><item><title>NewCore Secures $66M for AI and Machine Identity Platform</title><link>https://runtimerebel.com/blog/newcore-secures-66m-for-ai-and-machine-identity-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/newcore-secures-66m-for-ai-and-machine-identity-platform</guid><description>NewCore emerges from stealth with $66 million to develop a security-first identity platform protecting human, machine, and AI agent access.</description><pubDate>Mon, 15 Jun 2026 14:24:20 GMT</pubDate><category>NewCore</category><category>Identity Management</category><category>AI Security</category><category>Machine Identity</category><category>Zero Trust</category><category>Security Funding</category></item><item><title>Onboarding Password Risk: Securing First-Day Account Access</title><link>https://runtimerebel.com/blog/onboarding-password-risk-securing-first-day-account-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/onboarding-password-risk-securing-first-day-account-access</guid><description>Temporary onboarding passwords, often sent insecurely and reused, pose significant risk. Learn how to secure initial employee access and mitigate threats.</description><pubDate>Mon, 15 Jun 2026 14:21:06 GMT</pubDate><category>Onboarding Security</category><category>Password Policy</category><category>Identity Management</category><category>Initial Access</category><category>Employee Risk</category><category>Zero Trust</category></item><item><title>ABB B&amp;R Automation Studio &lt;6.5: Multiple Critical SQLite Vulnerabilities</title><link>https://runtimerebel.com/blog/abb-b-r-automation-studio-6-5-multiple-critical-sqlite-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/abb-b-r-automation-studio-6-5-multiple-critical-sqlite-vulnerabilities</guid><description>Critical SQLite vulnerabilities in ABB B&amp;R Automation Studio &lt;6.5 expose ICS to RCE, data exposure, and unauthorized access. Update to version 6.5 immediately.</description><pubDate>Sat, 23 May 2026 00:56:27 GMT</pubDate><category>ABB</category><category>B R Automation Studio</category><category>SQLite</category><category>ICS</category><category>OT</category><category>CVE-2025-6965</category><category>CVE-2025-3277</category><category>CVE-2019-19646</category><category>CVE-2019-8457</category><category>CVE-2017-10989</category><category>RCE</category><category>Buffer Overflow</category><category>Memory Corruption</category><category>Zero Trust</category></item><item><title>Zero Trust: Why Device Security is Essential Beyond Identity</title><link>https://runtimerebel.com/blog/zero-trust-why-device-security-is-essential-beyond-identity</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-trust-why-device-security-is-essential-beyond-identity</guid><description>Identity-only security fails against stolen tokens and compromised devices. Learn why robust device security is critical for effective Zero Trust strategies.</description><pubDate>Wed, 20 May 2026 17:12:24 GMT</pubDate><category>Zero Trust</category><category>Device Security</category><category>Identity and Access Management</category><category>Session Hijacking</category><category>Endpoint Security</category></item><item><title>20 Years of Cybersecurity: Strategic Insights from Industry Pioneers</title><link>https://runtimerebel.com/blog/20-years-of-cybersecurity-strategic-insights-from-industry-pioneers</link><guid isPermaLink="true">https://runtimerebel.com/blog/20-years-of-cybersecurity-strategic-insights-from-industry-pioneers</guid><description>Leading cybersecurity experts reflect on two decades of evolving threats, bug bounties, and the critical transition toward identity-centric security models.</description><pubDate>Fri, 15 May 2026 12:48:32 GMT</pubDate><category>Vulnerability Management</category><category>Bug Bounty</category><category>Zero Trust</category><category>Industry Analysis</category></item><item><title>Scattered Spider Arrest and NSA Emissary CVE-2024-34543 Analysis</title><link>https://runtimerebel.com/blog/scattered-spider-arrest-and-nsa-emissary-cve-2024-34543-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/scattered-spider-arrest-and-nsa-emissary-cve-2024-34543-analysis</guid><description>Analysis of the Scattered Spider arrest, the NSA Emissary XXE vulnerability (CVE-2024-34543), and CISA&apos;s new Zero Trust guidance for OT environments.</description><pubDate>Fri, 01 May 2026 16:27:10 GMT</pubDate><category>Scattered Spider</category><category>CVE-2024-34543</category><category>NSA Emissary</category><category>Zero Trust</category><category>XXE</category></item><item><title>Zero Trust Adoption for Operational Technology Security</title><link>https://runtimerebel.com/blog/zero-trust-adoption-for-operational-technology-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-trust-adoption-for-operational-technology-security</guid><description>CISA guidance details adapting Zero Trust principles to Operational Technology (OT) to mitigate IT-OT convergence risks for critical infrastructure.</description><pubDate>Wed, 29 Apr 2026 20:32:48 GMT</pubDate><category>Zero Trust</category><category>Operational Technology</category><category>OT Security</category><category>CISA Guidance</category><category>Critical Infrastructure</category><category>IT OT Convergence</category></item><item><title>AI Agentic Threats: Countering Automated Attacks with AI-Driven Defense</title><link>https://runtimerebel.com/blog/ai-agentic-threats-countering-automated-attacks-with-ai-driven-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agentic-threats-countering-automated-attacks-with-ai-driven-defense</guid><description>The rise of AI agents introduces new attack vectors. Enterprises must adopt AI-driven agentic defenses to counter automated reconnaissance, exploitation, and evasion…</description><pubDate>Tue, 28 Apr 2026 16:43:41 GMT</pubDate><category>AI</category><category>AI Agents</category><category>Automated Attacks</category><category>Cybersecurity Strategy</category><category>XDR</category><category>EDR</category><category>Zero Trust</category></item><item><title>Zero Trust Implementation Stalled by Secure Data Movement Bottlenecks</title><link>https://runtimerebel.com/blog/zero-trust-implementation-stalled-by-secure-data-movement-bottlenecks</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-trust-implementation-stalled-by-secure-data-movement-bottlenecks</guid><description>New Cyber360 research reveals why organizations fail to achieve Zero Trust by prioritizing network connectivity over granular data movement security.</description><pubDate>Tue, 28 Apr 2026 16:41:38 GMT</pubDate><category>Zero Trust</category><category>Data Security</category><category>Cyber360 Report</category><category>Network Architecture</category><category>Access Control</category></item><item><title>Identity-First Zero Trust Strategies to Prevent Credential Theft</title><link>https://runtimerebel.com/blog/identity-first-zero-trust-strategies-to-prevent-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-first-zero-trust-strategies-to-prevent-credential-theft</guid><description>Learn how Zero Trust architecture mitigates stolen credentials and lateral movement by enforcing device trust, least privilege, and continuous verification.</description><pubDate>Tue, 14 Apr 2026 16:32:08 GMT</pubDate><category>Zero Trust</category><category>Identity Security</category><category>Credential Theft</category><category>Least Privilege</category><category>MFA</category></item><item><title>Orange Business: Enhancing Enterprise Voice with AI and Trust</title><link>https://runtimerebel.com/blog/orange-business-enhancing-enterprise-voice-with-ai-and-trust</link><guid isPermaLink="true">https://runtimerebel.com/blog/orange-business-enhancing-enterprise-voice-with-ai-and-trust</guid><description>Orange Business introduces a new enterprise voice solution integrating AI and a &apos;Zero Trust&apos; approach to enhance security and user experience for multinational…</description><pubDate>Fri, 10 Apr 2026 16:28:22 GMT</pubDate><category>Orange Business</category><category>Enterprise Voice</category><category>AI Security</category><category>Zero Trust</category><category>Communications Security</category></item><item><title>APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns</title><link>https://runtimerebel.com/blog/apt28-analysis-mitigation-strategies-against-fancy-bear-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-analysis-mitigation-strategies-against-fancy-bear-campaigns</guid><description>A technical analysis of APT28&apos;s global operations, highlighting the necessity of Zero Trust and rapid patching to counter Fancy Bear threat activity.</description><pubDate>Fri, 10 Apr 2026 08:40:01 GMT</pubDate><category>APT28</category><category>Fancy Bear</category><category>Russia</category><category>Nation State</category><category>Zero Trust</category></item><item><title>Beyond MFA: Bridging the Zero Trust Gap in Session Security</title><link>https://runtimerebel.com/blog/beyond-mfa-bridging-the-zero-trust-gap-in-session-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/beyond-mfa-bridging-the-zero-trust-gap-in-session-security</guid><description>Authentication alone does not equate to trust. Discover how session token hijacking bypasses MFA and why device health is critical for Zero Trust.</description><pubDate>Tue, 24 Mar 2026 16:29:03 GMT</pubDate><category>Zero Trust</category><category>MFA Bypass</category><category>Session Hijacking</category><category>Identity Security</category><category>Device Trust</category></item><item><title>James ‘Aaron’ Bishop Named Pentagon CISO Amid Strategic Shifts</title><link>https://runtimerebel.com/blog/james-aaron-bishop-named-pentagon-ciso-amid-strategic-shifts</link><guid isPermaLink="true">https://runtimerebel.com/blog/james-aaron-bishop-named-pentagon-ciso-amid-strategic-shifts</guid><description>James ‘Aaron’ Bishop succeeds David McKeown as Pentagon CISO, steering the Department of Defense through a major Zero Trust architecture implementation.</description><pubDate>Fri, 06 Mar 2026 12:18:48 GMT</pubDate><category>Pentagon</category><category>CISO</category><category>Department of Defense</category><category>Zero Trust</category><category>James Aaron Bishop</category><category>David McKeown</category></item><item><title>Token Theft and Session Hijacking: Mitigating Device Trust Failures</title><link>https://runtimerebel.com/blog/token-theft-and-session-hijacking-mitigating-device-trust-failures</link><guid isPermaLink="true">https://runtimerebel.com/blog/token-theft-and-session-hijacking-mitigating-device-trust-failures</guid><description>An analysis of post-authentication attack vectors involving token theft and the technical requirement for continuous device posture verification within Zero Trust…</description><pubDate>Mon, 23 Feb 2026 16:23:45 GMT</pubDate><category>Token Theft</category><category>Session Hijacking</category><category>Zero Trust</category><category>Endpoint Security</category></item></channel></rss>