<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>basicsecurity.net — editorial</title>
  <subtitle>Cited, lab-proven stories from the known-exploited record.</subtitle>
  <link rel="self" href="https://basicsecurity.net/feed.xml"/>
  <link rel="alternate" href="https://basicsecurity.net/"/>
  <id>tag:basicsecurity.net,2026:/feed</id>
  <updated>2026-08-05T16:30:30Z</updated>
  <author><name>basicsecurity.net</name></author>
  <entry>
    <title>A leak in the front door: how Citrix Bleed became a ransomware crew’s favorite way in</title>
    <link rel="alternate" href="https://basicsecurity.net/outcomes/story/cve-2023-4966/"/>
    <id>https://basicsecurity.net/outcomes/story/cve-2023-4966/</id>
    <updated>2026-08-05T16:30:30Z</updated>
    <published>2026-08-05T16:30:30Z</published>
    <category term="CVE-2023-4966"/>
    <summary>An unauthenticated attacker reads valid session tokens straight out of a NetScaler appliance’s memory — then logs in as your users, MFA and all. A named ransomware group industrialized it. Here is the whole path, with a source for every claim.</summary>
  </entry>
  <entry>
    <title>Known, weaponised, and off the list: the 208 days CVE-2024-23897 waited for CISA's KEV</title>
    <link rel="alternate" href="https://basicsecurity.net/outcomes/story/cve-2024-23897/"/>
    <id>https://basicsecurity.net/outcomes/story/cve-2024-23897/</id>
    <updated>2026-08-04T02:07:12Z</updated>
    <published>2026-08-04T02:07:12Z</published>
    <category term="CVE-2024-23897"/>
    <summary>A maximum-severity Jenkins flaw was public, exploited, and rated 'actively exploited' by CISA's own triage — yet it took 208 days to reach the government's authoritative Known Exploited Vulnerabilities catalog. A post-2021 measurement of a system its own maintainers say is behind.</summary>
  </entry>
</feed>
