<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title>SOC Minute</title>
<description>Cybersecurity signal, minus the noise.</description>
<link>https://socminute.example/</link>
<language>en</language>
<item>
<title>Microsoft Explores Risks Targeting AI Memory and Defense Strategies</title>
<link>https://socminute.example/articulos/microsoft-explores-risks-targeting-ai-memory-and-defense-strategies/</link>
<guid isPermaLink="true">https://socminute.example/articulos/microsoft-explores-risks-targeting-ai-memory-and-defense-strategies/</guid>
<description>Microsoft Security Blog discusses the implications when threat actors attempt to manipulate what AI systems remember and the emerging defenses against these attacks. Understanding these risks is crucial for securing AI-driven technologies.</description>
<pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
<category>AI Security</category>
<category>Microsoft AI memory attack</category>
<category>AI memory manipulation risks</category>
<category>defense strategies for AI security</category>
<category>Cybersecurity</category>
<category>AI</category>
</item>
<item>
<title>Microsoft Links Mastra AI Supply Chain Attack to North Korean Hackers</title>
<link>https://socminute.example/articulos/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/</link>
<guid isPermaLink="true">https://socminute.example/articulos/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/</guid>
<description>Microsoft has attributed the recent Mastra AI supply chain attack, compromising over 140 npm packages, to the North Korean group Sapphire Sleet, aka BlueNoroff. This highlights ongoing state-sponsored supply chain risks affecting open source ecosystems.</description>
<pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
<category>Threat Actor</category>
<category>Mastra AI supply chain attack</category>
<category>North Korean hackers npm packages</category>
<category>Sapphire Sleet cyberattack</category>
<category>Cybersecurity</category>
<category>SupplyChainAttack</category>
</item>
<item>
<title>ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack</title>
<link>https://socminute.example/articulos/shapedplugin-wordpress-pro-plugins-backdoored-in-supply-chain-attack/</link>
<guid isPermaLink="true">https://socminute.example/articulos/shapedplugin-wordpress-pro-plugins-backdoored-in-supply-chain-attack/</guid>
<description>Attackers compromised ShapedPlugin&apos;s build pipeline to inject backdoor code into Pro plugins via official update channels. This supply chain attack puts thousands of WordPress sites at risk of remote exploitation.</description>
<pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
<category>Malware</category>
<category>ShapedPlugin supply chain attack</category>
<category>WordPress Pro plugin backdoor</category>
<category>WordPress plugin security breach</category>
<category>Cybersecurity</category>
<category>WordPress</category>
</item>
<item>
<title>FortiBleed: what a SOC should validate in Fortinet environments</title>
<link>https://socminute.example/articulos/fortibleed-fortinet/</link>
<guid isPermaLink="true">https://socminute.example/articulos/fortibleed-fortinet/</guid>
<description>Exposure of perimeter Fortinet devices puts the focus back on external asset inventory, patching speed, and hunting for anomalous access.</description>
<pubDate>Tue, 16 Dec 2025 00:00:00 GMT</pubDate>
<category>Vulnerabilities</category>
<category>Fortinet</category>
<category>FortiOS</category>
<category>edge-security</category>
</item>
<item>
<title>Splunk Enterprise: an actively exploited flaw demands a look beyond the SIEM</title>
<link>https://socminute.example/articulos/splunk-enterprise-actively-exploited-flaw/</link>
<guid isPermaLink="true">https://socminute.example/articulos/splunk-enterprise-actively-exploited-flaw/</guid>
<description>When the platform at the center of detection is exposed, teams must patch quickly and verify the integrity of searches, alerts, accounts, and data.</description>
<pubDate>Fri, 28 Nov 2025 00:00:00 GMT</pubDate>
<category>Active exploitation</category>
<category>Splunk</category>
<category>SIEM</category>
<category>CISA-KEV</category>
</item>
<item>
<title>AutoJack: when an AI agent turns instructions into control</title>
<link>https://socminute.example/articulos/autojack-ai-agent-hijack/</link>
<guid isPermaLink="true">https://socminute.example/articulos/autojack-ai-agent-hijack/</guid>
<description>Agent hijacking shows how untrusted content can redirect automation with tools, memory, and permissions toward actions the user never authorized.</description>
<pubDate>Thu, 09 Oct 2025 00:00:00 GMT</pubDate>
<category>AI Security</category>
<category>AI-agents</category>
<category>prompt-injection</category>
<category>identity</category>
</item>
</channel>
</rss>