<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Threat Advisories</title>
    <link>https://24368144.hs-sites.com/threat-advisories</link>
    <description>A collection of cybersecurity threat advisories</description>
    <language>en-us</language>
    <pubDate>Wed, 16 Sep 2026 15:45:07 GMT</pubDate>
    <dc:date>2026-09-16T15:45:07Z</dc:date>
    <dc:language>en-us</dc:language>
    <item>
      <title>Vercel OAuth Supply Chain Compromise</title>
      <link>https://24368144.hs-sites.com/threat-advisories/vercel-oauth-supply-chain-compromise</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/vercel-oauth-supply-chain-compromise" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/Website%20Hero%20+%20Featured%20Images/ta-image@4x-1.png" alt="Vercel OAuth Supply Chain Compromise" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="position: relative; padding-top: max(60%,326px); height: 0; width: 100%;"&gt;  
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/vercel-oauth-supply-chain-compromise" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/Website%20Hero%20+%20Featured%20Images/ta-image@4x-1.png" alt="Vercel OAuth Supply Chain Compromise" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="position: relative; padding-top: max(60%,326px); height: 0; width: 100%;"&gt; 
 &lt;iframe style="position: absolute; inset: 0px; margin: 0px auto; display: block; border: medium none currentcolor;" src="https://e.issuu.com/embed.html?backgroundColorFullscreen=%23303434&amp;amp;d=vercel_oauth_supply_chain_compromise&amp;amp;u=flcyber" width="814" height="458" sandbox="allow-top-navigation allow-top-navigation-by-user-activation allow-downloads allow-scripts allow-same-origin allow-popups allow-modals allow-popups-to-escape-sandbox allow-forms" allowfullscreen&gt;&lt;/iframe&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Fvercel-oauth-supply-chain-compromise&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <category>supply chain attack</category>
      <pubDate>Wed, 16 Sep 2026 15:45:07 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/vercel-oauth-supply-chain-compromise</guid>
      <dc:date>2026-09-16T15:45:07Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>DragonForce Ransomware Abuses Microsoft Teams for Covert C2 Operations</title>
      <link>https://24368144.hs-sites.com/threat-advisories/dragonforce-ransomware-abuses-microsoft-teams-for-covert-c2-operations</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/dragonforce-ransomware-abuses-microsoft-teams-for-covert-c2-operations" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="DragonForce Ransomware Abuses Microsoft Teams for Covert C2 Operations" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="hs-embed-wrapper" style="position: relative; overflow: hidden; width: 100%; height: auto; padding: 0px; max-width: 560px; min-width: 256px; display: block; margin: auto;"&gt; 
 &lt;div class="hs-embed-content-wrapper"&gt; 
  &lt;div style="position: relative; overflow: hidden; max-width: 100%; padding-bottom: 56.25%; margin: 0px;"&gt;  
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/dragonforce-ransomware-abuses-microsoft-teams-for-covert-c2-operations" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="DragonForce Ransomware Abuses Microsoft Teams for Covert C2 Operations" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="hs-embed-wrapper" style="position: relative; overflow: hidden; width: 100%; height: auto; padding: 0px; max-width: 560px; min-width: 256px; display: block; margin: auto;"&gt; 
 &lt;div class="hs-embed-content-wrapper"&gt; 
  &lt;div style="position: relative; overflow: hidden; max-width: 100%; padding-bottom: 56.25%; margin: 0px;"&gt; 
   &lt;iframe style="position: absolute; top: 0px; left: 0px; width: 100%; height: 100%; border: medium;" src="https://www.canva.com/design/DAHOD-taen4/2J5NGaBjSuWxa0HcdGMr6g/view?embed" width="560" height="315" allowfullscreen&gt;&lt;/iframe&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Fdragonforce-ransomware-abuses-microsoft-teams-for-covert-c2-operations&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cybersecurity</category>
      <category>ransomware</category>
      <pubDate>Wed, 16 Sep 2026 15:44:32 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/dragonforce-ransomware-abuses-microsoft-teams-for-covert-c2-operations</guid>
      <dc:date>2026-09-16T15:44:32Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>ShinyHunters Canvas Extortion Campaign</title>
      <link>https://24368144.hs-sites.com/threat-advisories/shinyhunters-canvas-extortion-campaign</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/shinyhunters-canvas-extortion-campaign" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/ta-image@4x-1.png" alt="Cyber Florida Threat Advisory" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h4&gt;Jump to...&lt;/h4&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;a href="#tech-analysis"&gt;Section 2: Technical Analysis&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="#remediation"&gt;Section 3: Remediation &amp;amp; Mitigation&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="#references"&gt;Section 4: Reference&lt;/a&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h4&gt;Section 1:&amp;nbsp;Executive Summary (Current Status as of May 24, 2026)&lt;/h4&gt; 
&lt;p&gt;On April 30, 2026, the threat actor group ShinyHunters exploited a vulnerability in Instructure’s Free-For-Teacher account program to gain unauthorized access to Canvas, one of the most widely used learning management systems in the United States. The breach exposed sensitive information belonging to students, faculty, and staff across 8,809 institutions worldwide. ShinyHunters claimed to have stolen 275 million records and exfiltrated approximately 3.65 terabytes of data.&amp;nbsp;&lt;br&gt;&lt;br&gt;This incident is not ShinyHunters’ first intrusion into Instructure’s environment. In September 2025, the group breached Instructure’s Salesforce business systems through social engineering. The September 2025 Salesforce incident may have provided the actor with additional knowledge of Instructure’s environment, but no public source has confirmed that it directly enabled the April/May 2026 Canvas intrusion. Rather than negotiate following the second breach, Instructure applied security patches. ShinyHunters responded by escalating. On May 7, 2026, the group simultaneously defaced Canvas login portals across affected institutions, disrupted final examinations at multiple universities, and issued a new ransom deadline of May 12, 2026.&amp;nbsp;&lt;br&gt;&lt;br&gt;ShinyHunters operates under a pay-or-leak extortion model, applying pressure through countdown timers, dark web leak sites, and live production defacement as coercive instruments. Notably, no malware was deployed during this operation. There is currently no public indication of traditional malware deployment or ransomware encryption during the Canvas incident. Reported activity appears to have relied on abused account access, application-layer vulnerabilities, and platform/API functionality.&amp;nbsp;&lt;br&gt;&lt;br&gt;This report provides an overview of the incident, a technical analysis of the exploited attack surface and associated MITRE ATT&amp;amp;CK techniques, infrastructure, and related indicators of compromise, and recommended remediation and mitigation actions for affected institutions and their users.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/shinyhunters-canvas-extortion-campaign" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/ta-image@4x-1.png" alt="Cyber Florida Threat Advisory" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h4&gt;Jump to...&lt;/h4&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;a href="#tech-analysis"&gt;Section 2: Technical Analysis&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="#remediation"&gt;Section 3: Remediation &amp;amp; Mitigation&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="#references"&gt;Section 4: Reference&lt;/a&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h4&gt;Section 1:&amp;nbsp;Executive Summary (Current Status as of May 24, 2026)&lt;/h4&gt; 
&lt;p&gt;On April 30, 2026, the threat actor group ShinyHunters exploited a vulnerability in Instructure’s Free-For-Teacher account program to gain unauthorized access to Canvas, one of the most widely used learning management systems in the United States. The breach exposed sensitive information belonging to students, faculty, and staff across 8,809 institutions worldwide. ShinyHunters claimed to have stolen 275 million records and exfiltrated approximately 3.65 terabytes of data.&amp;nbsp;&lt;br&gt;&lt;br&gt;This incident is not ShinyHunters’ first intrusion into Instructure’s environment. In September 2025, the group breached Instructure’s Salesforce business systems through social engineering. The September 2025 Salesforce incident may have provided the actor with additional knowledge of Instructure’s environment, but no public source has confirmed that it directly enabled the April/May 2026 Canvas intrusion. Rather than negotiate following the second breach, Instructure applied security patches. ShinyHunters responded by escalating. On May 7, 2026, the group simultaneously defaced Canvas login portals across affected institutions, disrupted final examinations at multiple universities, and issued a new ransom deadline of May 12, 2026.&amp;nbsp;&lt;br&gt;&lt;br&gt;ShinyHunters operates under a pay-or-leak extortion model, applying pressure through countdown timers, dark web leak sites, and live production defacement as coercive instruments. Notably, no malware was deployed during this operation. There is currently no public indication of traditional malware deployment or ransomware encryption during the Canvas incident. Reported activity appears to have relied on abused account access, application-layer vulnerabilities, and platform/API functionality.&amp;nbsp;&lt;br&gt;&lt;br&gt;This report provides an overview of the incident, a technical analysis of the exploited attack surface and associated MITRE ATT&amp;amp;CK techniques, infrastructure, and related indicators of compromise, and recommended remediation and mitigation actions for affected institutions and their users.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Fshinyhunters-canvas-extortion-campaign&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <category>exploit</category>
      <category>canvas</category>
      <pubDate>Wed, 16 Sep 2026 15:30:21 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/shinyhunters-canvas-extortion-campaign</guid>
      <dc:date>2026-09-16T15:30:21Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>RDP Exploitation and AI-Enhanced Token Theft</title>
      <link>https://24368144.hs-sites.com/threat-advisories/rdp-exploitation-and-ai-enhanced-token-theft</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/rdp-exploitation-and-ai-enhanced-token-theft" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="RDP Exploitation and AI-Enhanced Token Theft" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="position: relative; width: 100%; height: 0; padding-top: 129.4118%; padding-bottom: 0; box-shadow: 0 2px 8px 0 rgba(63,69,81,0.16); margin-top: 1.6em; margin-bottom: 0.9em; overflow: hidden; border-radius: 8px; will-change: transform;"&gt;  
 &lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Authors&lt;/strong&gt;: &lt;span class="a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none"&gt;Kevin Wong, Aarav&amp;nbsp;Jain&lt;/span&gt;&lt;/span&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/rdp-exploitation-and-ai-enhanced-token-theft" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="RDP Exploitation and AI-Enhanced Token Theft" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="position: relative; width: 100%; height: 0; padding-top: 129.4118%; padding-bottom: 0; box-shadow: 0 2px 8px 0 rgba(63,69,81,0.16); margin-top: 1.6em; margin-bottom: 0.9em; overflow: hidden; border-radius: 8px; will-change: transform;"&gt; 
 &lt;iframe style="position: absolute; top: 0px; left: 0px; padding: 0px; margin: 0px; display: block; border: medium none currentcolor;" src="https://www.canva.com/design/DAHLD-JZeH4/tra2Ae_FTgehsttOWfgCow/view?embed" width="773" height="435" allowfullscreen&gt;&lt;/iframe&gt; 
 &lt;span style="color: #ffffff;"&gt;&lt;strong&gt;Authors&lt;/strong&gt;: &lt;span class="a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none"&gt;Kevin Wong, Aarav&amp;nbsp;Jain&lt;/span&gt;&lt;/span&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Frdp-exploitation-and-ai-enhanced-token-theft&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <category>ai</category>
      <category>exploit</category>
      <pubDate>Wed, 16 Sep 2026 15:25:05 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/rdp-exploitation-and-ai-enhanced-token-theft</guid>
      <dc:date>2026-09-16T15:25:05Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>GitHub Internals Breach via Poisoned VS Code Extension</title>
      <link>https://24368144.hs-sites.com/threat-advisories/github-internals-breach-via-poisoned-vs-code-extension</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/github-internals-breach-via-poisoned-vs-code-extension" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/Website%20Hero%20+%20Featured%20Images/ta-image@4x-1.png" alt="GitHub Internals Breach via Poisoned VS Code Extension" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="hs-embed-wrapper" style="position: relative; overflow: hidden; width: 100%; height: auto; padding: 0px; max-width: 560px; min-width: 256px; display: block; margin: auto;"&gt; 
 &lt;div class="hs-embed-content-wrapper"&gt; 
  &lt;div style="position: relative; overflow: hidden; max-width: 100%; padding-bottom: 56.25%; margin: 0px;"&gt;  
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt; 
&lt;a href="https://www.canva.com/design/DAHK-5vkAX4/Z-84E4QPm2gYabiL5myTNw/view?utm_content=DAHK-5vkAX4&amp;amp;utm_campaign=designshare&amp;amp;utm_medium=embeds&amp;amp;utm_source=link"&gt;&lt;br&gt; &lt;p&gt;On May 19, 2026, GitHub announced via X (formerly Twitter) an ongoing investigation into unauthorized access to its internal repositories. In a follow-up statement hours later, GitHub confirmed it had experienced a breach and assessed that threat actors had stolen&amp;nbsp;source files and other sensitive data from around 3,800 of its internal repositories.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Authors&lt;/strong&gt;: &lt;span class="a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none"&gt;Taylor Alvarez, Isaac Ward &lt;span style="font-weight: bold;"&gt;Published:&lt;/span&gt; 05/29/2026&lt;/span&gt;&lt;/p&gt; &lt;/a&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/github-internals-breach-via-poisoned-vs-code-extension" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/Website%20Hero%20+%20Featured%20Images/ta-image@4x-1.png" alt="GitHub Internals Breach via Poisoned VS Code Extension" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div class="hs-embed-wrapper" style="position: relative; overflow: hidden; width: 100%; height: auto; padding: 0px; max-width: 560px; min-width: 256px; display: block; margin: auto;"&gt; 
 &lt;div class="hs-embed-content-wrapper"&gt; 
  &lt;div style="position: relative; overflow: hidden; max-width: 100%; padding-bottom: 56.25%; margin: 0px;"&gt; 
   &lt;iframe style="position: absolute; top: 0px; left: 0px; width: 100%; height: 100%; border: medium;" src="https://www.canva.com/design/DAHK-5vkAX4/Z-84E4QPm2gYabiL5myTNw/view?embed" width="560" height="315" allowfullscreen&gt;&lt;/iframe&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt; 
&lt;a href="https://www.canva.com/design/DAHK-5vkAX4/Z-84E4QPm2gYabiL5myTNw/view?utm_content=DAHK-5vkAX4&amp;amp;utm_campaign=designshare&amp;amp;utm_medium=embeds&amp;amp;utm_source=link"&gt;&lt;br&gt; &lt;p&gt;On May 19, 2026, GitHub announced via X (formerly Twitter) an ongoing investigation into unauthorized access to its internal repositories. In a follow-up statement hours later, GitHub confirmed it had experienced a breach and assessed that threat actors had stolen&amp;nbsp;source files and other sensitive data from around 3,800 of its internal repositories.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Authors&lt;/strong&gt;: &lt;span class="a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none"&gt;Taylor Alvarez, Isaac Ward &lt;span style="font-weight: bold;"&gt;Published:&lt;/span&gt; 05/29/2026&lt;/span&gt;&lt;/p&gt; &lt;/a&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Fgithub-internals-breach-via-poisoned-vs-code-extension&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <category>supply chain attack</category>
      <pubDate>Wed, 16 Sep 2026 15:00:43 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/github-internals-breach-via-poisoned-vs-code-extension</guid>
      <dc:date>2026-09-16T15:00:43Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>Technical Threat Advisory | CVE-2026-45675</title>
      <link>https://24368144.hs-sites.com/threat-advisories/technical-threat-advisory-cve-2026-45675</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/technical-threat-advisory-cve-2026-45675" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="Technical Threat Advisory | CVE-2026-45675" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Originally Published May 20, 2026&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/technical-threat-advisory-cve-2026-45675" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="Technical Threat Advisory | CVE-2026-45675" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Originally Published May 20, 2026&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Ftechnical-threat-advisory-cve-2026-45675&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <category>cybersecurity</category>
      <category>Florida</category>
      <category>USF</category>
      <pubDate>Wed, 16 Sep 2026 14:57:33 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/technical-threat-advisory-cve-2026-45675</guid>
      <dc:date>2026-09-16T14:57:33Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>Chrome Zero-Days Threat Advisory</title>
      <link>https://24368144.hs-sites.com/threat-advisories/chrome-zero-days-threat-advisory</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/chrome-zero-days-threat-advisory" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="Chrome Zero-Days Threat Advisory" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Originally Published April 1, 2026&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/chrome-zero-days-threat-advisory" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="Chrome Zero-Days Threat Advisory" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Originally Published April 1, 2026&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Fchrome-zero-days-threat-advisory&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <category>zero day</category>
      <pubDate>Wed, 16 Sep 2026 14:49:48 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/chrome-zero-days-threat-advisory</guid>
      <dc:date>2026-09-16T14:49:48Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>Qilin Ransomware – A Double Extortion Campaign</title>
      <link>https://24368144.hs-sites.com/threat-advisories/qilin-ransomware-a-double-extortion-campaign</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/qilin-ransomware-a-double-extortion-campaign" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="Qilin Ransomware – A Double Extortion Campaign" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Originally Published December 8, 2025&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/qilin-ransomware-a-double-extortion-campaign" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="Qilin Ransomware – A Double Extortion Campaign" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Originally Published December 8, 2025&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Fqilin-ransomware-a-double-extortion-campaign&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <pubDate>Wed, 16 Sep 2026 14:35:24 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/qilin-ransomware-a-double-extortion-campaign</guid>
      <dc:date>2026-09-16T14:35:24Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>BRICKSTORM APT Intrusion Campaign</title>
      <link>https://24368144.hs-sites.com/threat-advisories/big-ip-integrity-vulnerability-threat-report-2</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/big-ip-integrity-vulnerability-threat-report-2" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="BRICKSTORM APT Intrusion Campaign" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Originally Published December 3, 2025&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/big-ip-integrity-vulnerability-threat-report-2" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/threat-advisory_SOC_GREEN.jpg.webp" alt="BRICKSTORM APT Intrusion Campaign" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Originally Published December 3, 2025&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Fbig-ip-integrity-vulnerability-threat-report-2&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <category>malware</category>
      <category>brickstorm</category>
      <pubDate>Wed, 16 Sep 2026 14:23:02 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/big-ip-integrity-vulnerability-threat-report-2</guid>
      <dc:date>2026-09-16T14:23:02Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
    <item>
      <title>BIG-IP Integrity Vulnerability Threat Report</title>
      <link>https://24368144.hs-sites.com/threat-advisories/big-ip-integrity-vulnerability-threat-report</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/big-ip-integrity-vulnerability-threat-report" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/Website%20Hero%20+%20Featured%20Images/ta-image@4x-1.png" alt="BIG-IP Integrity Vulnerability Threat Report" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h3&gt;I. Introduction&lt;/h3&gt; 
&lt;p&gt;Application Delivery Controllers (ADCs) are essential to modern networks because they optimize, secure, and manage client-server traffic. F5’s BIG-IP, a critical Application Delivery Controller used across enterprises and government networks, plays a key role in traffic management, SSL/TLS termination, and application delivery. [1]&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://24368144.hs-sites.com/threat-advisories/big-ip-integrity-vulnerability-threat-report" title="" class="hs-featured-image-link"&gt; &lt;img src="https://24368144.hs-sites.com/hubfs/Website%20Hero%20+%20Featured%20Images/ta-image@4x-1.png" alt="BIG-IP Integrity Vulnerability Threat Report" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h3&gt;I. Introduction&lt;/h3&gt; 
&lt;p&gt;Application Delivery Controllers (ADCs) are essential to modern networks because they optimize, secure, and manage client-server traffic. F5’s BIG-IP, a critical Application Delivery Controller used across enterprises and government networks, plays a key role in traffic management, SSL/TLS termination, and application delivery. [1]&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=24368144&amp;amp;k=14&amp;amp;r=https%3A%2F%2F24368144.hs-sites.com%2Fthreat-advisories%2Fbig-ip-integrity-vulnerability-threat-report&amp;amp;bu=https%253A%252F%252F24368144.hs-sites.com%252Fthreat-advisories&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>threat advisory</category>
      <category>cyber florida</category>
      <category>cybersecurity</category>
      <category>application discovery controllers</category>
      <pubDate>Wed, 16 Sep 2026 14:14:29 GMT</pubDate>
      <guid>https://24368144.hs-sites.com/threat-advisories/big-ip-integrity-vulnerability-threat-report</guid>
      <dc:date>2026-09-16T14:14:29Z</dc:date>
      <dc:creator>Cyber Florida SOCAP Team</dc:creator>
    </item>
  </channel>
</rss>
