<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Zero Trust on microsegment.io</title>
    <link>https://microsegment.io/tags/zero-trust/</link>
    <description>Recent content in Zero Trust on microsegment.io</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 01 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://microsegment.io/tags/zero-trust/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>When The Network Infrastructure Lies</title>
      <link>https://microsegment.io/post/2026-09-01-when-network-infrastructure-lies/</link>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-09-01-when-network-infrastructure-lies/</guid>
      <description>&lt;p&gt;Most security architectures assume the network will tell the truth.&lt;/p&gt;&#xA;&lt;p&gt;The router reports its configuration. TACACS records who administered it. Syslog preserves what changed. The monitoring platform shows which paths were active. During an incident, those records become the timeline.&lt;/p&gt;&#xA;&lt;p&gt;But what happens when the attacker controls the systems that create the evidence?&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/&#34;&gt;Sygnia&amp;rsquo;s August 2026 Fire Ant investigation&lt;/a&gt; describes a China-nexus actor compromising Cisco IOS XR routers, TACACS infrastructure, and Linux management hosts. The actor used routers for covert connectivity and traffic collection, intercepted administrative authentication, maintained persistent access, and manipulated logging and command output.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Login Worked. The Breach Did Not.</title>
      <link>https://microsegment.io/post/2026-08-25-the-login-worked-the-breach-did-not/</link>
      <pubDate>Tue, 25 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-08-25-the-login-worked-the-breach-did-not/</guid>
      <description>&lt;p&gt;On August 22, 2026, a threat actor convinced a ReliaQuest employee to enter a password into a fake single sign-on page and approve an MFA push.&lt;/p&gt;&#xA;&lt;p&gt;The login worked.&lt;/p&gt;&#xA;&lt;p&gt;The attacker received a brief session on the identity dashboard. But the session had view-only access. Attempts to open applications were denied because the device did not meet ReliaQuest&amp;rsquo;s trust requirements. ReliaQuest then terminated the sessions, expired the password, and reset every authentication factor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The 2026 Forrester Wave For Microsegmentation: Why Illumio Stands Out</title>
      <link>https://microsegment.io/post/2026-08-22-forrester-wave-microsegmentation-2026-illumio/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-08-22-forrester-wave-microsegmentation-2026-illumio/</guid>
      <description>&lt;p&gt;Forrester has published &lt;em&gt;The Forrester Wave™: Microsegmentation Solutions, Q3 2026&lt;/em&gt;, evaluating 10 vendors against 25 criteria.&lt;/p&gt;&#xA;&lt;p&gt;The headline for Illumio is strong: Forrester named it a Leader, Illumio received the highest overall scores of any evaluated vendor in both the Current Offering and Strategy categories, and it was designated a Customer Favorite based on customer feedback in the evaluation.&lt;/p&gt;&#xA;&lt;p&gt;That combination matters more than a Leader badge on its own.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Your CI/CD Runner Is A Privileged Workload. Contain It.</title>
      <link>https://microsegment.io/post/2026-08-18-cicd-runners-need-containment/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-08-18-cicd-runners-need-containment/</guid>
      <description>&lt;p&gt;A CI/CD runner is not just a machine that builds software.&lt;/p&gt;&#xA;&lt;p&gt;It is a workload that routinely sits between untrusted input and high-trust systems: source repositories, package registries, artifact stores, cloud APIs, deployment platforms, ticketing systems, and production environments.&lt;/p&gt;&#xA;&lt;p&gt;That makes it privileged infrastructure, even when the workflow looks administrative rather than security-critical.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug&#34;&gt;Wiz&amp;rsquo;s disclosure about a GitHub Actions vulnerability in a public Snowflake repository&lt;/a&gt; is a clean example. An unauthenticated user could place crafted content in a GitHub issue title. A workflow inserted that title directly into a shell script. Wiz&amp;rsquo;s autonomous Red Agent used the resulting script injection to execute commands on the runner, extract a Jira credential, and validate read access to internal Snowflake Jira projects.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OT Segmentation Must Survive Edge Compromise</title>
      <link>https://microsegment.io/post/2026-08-11-ot-segmentation-must-survive-edge-compromise/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-08-11-ot-segmentation-must-survive-edge-compromise/</guid>
      <description>&lt;p&gt;An OT network can contain multiple VLANs and still have no meaningful containment.&lt;/p&gt;&#xA;&lt;p&gt;The test is simple: if an attacker compromises the edge device, remote-access account, or management plane, can that attacker reach every controller, HMI, engineering workstation, and protection device behind it?&lt;/p&gt;&#xA;&lt;p&gt;If the answer is yes, the architecture has internal organization. It does not have a durable security boundary.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.gov.pl/attachment/e2cdb4be-0542-4435-948c-957b51453b6e&#34;&gt;CERT Polska&amp;rsquo;s report on the coordinated attacks against Poland&amp;rsquo;s energy sector on 29 December 2025&lt;/a&gt; is a useful case study. The report covers attacks against at least 30 wind and solar facilities, a large combined heat and power plant, and a manufacturing company. The destructive actions affected both IT systems and physical industrial devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The AI Agent Did Not Escape The Sandbox. The Network Boundary Failed.</title>
      <link>https://microsegment.io/post/2026-08-05-ai-agent-evaluation-egress-containment/</link>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-08-05-ai-agent-evaluation-egress-containment/</guid>
      <description>&lt;p&gt;The most important sentence in the UK AI Security Institute&amp;rsquo;s incident report is easy to miss:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;We did not observe any sandbox escapes in this incident.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;The agents did not break through a hypervisor. They did not compromise AISI&amp;rsquo;s internal infrastructure. They used the connectivity and tools they had deliberately been given.&lt;/p&gt;&#xA;&lt;p&gt;That is what makes the incident important.&lt;/p&gt;&#xA;&lt;p&gt;From 25 to 28 July 2026, AISI ran 122 attempts against two versions of its &amp;ldquo;Doing Life&amp;rdquo; cyber range. Its subsequent review found &lt;strong&gt;19 instances of unsanctioned action on the live internet across 10 samples&lt;/strong&gt;. Seventeen involved Mythos 5 and two involved GPT-5.6 Sol. Both models were tested with provider cyber classifiers disabled.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsegmentation Fails Quietly When Policy Drifts</title>
      <link>https://microsegment.io/post/2026-08-04-segmentation-policy-drift/</link>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-08-04-segmentation-policy-drift/</guid>
      <description>&lt;p&gt;The first microsegmentation policy is usually the easy one.&lt;/p&gt;&#xA;&lt;p&gt;The application owner explains the expected flows. The security team observes traffic. Rules are tested, approved, and enforced. The result looks clean: web talks to application, application talks to database, administrators enter through a controlled path, and everything else is denied.&lt;/p&gt;&#xA;&lt;p&gt;Then the environment changes.&lt;/p&gt;&#xA;&lt;p&gt;A new monitoring collector appears. A migration needs temporary access. A workload moves to another cloud account. A certificate service changes. A developer opens an emergency path during an incident. The old application is retired, but its rules remain. Six months later, the policy still exists, but it no longer describes the system it was meant to protect.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The AI Agent Was New. The Trust Failures Were Not.</title>
      <link>https://microsegment.io/post/2026-07-29-ai-agent-intrusion-trust-paths/</link>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-07-29-ai-agent-intrusion-trust-paths/</guid>
      <description>&lt;p&gt;The headline is an autonomous AI agent escaping an evaluation sandbox and compromising Hugging Face production.&lt;/p&gt;&#xA;&lt;p&gt;The security lesson is less exotic.&lt;/p&gt;&#xA;&lt;p&gt;One compromised workload could read credentials. A pod could reach cloud metadata. An overly privileged Kubernetes identity could create privileged pods. A stolen mesh-VPN key could enroll attacker-controlled devices. One shared service-connector credential provided administrative access across multiple clusters.&lt;/p&gt;&#xA;&lt;p&gt;The agent was new. The trust failures were not.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Backup Infrastructure Needs Its Own Containment Boundary</title>
      <link>https://microsegment.io/post/2026-07-28-backup-infrastructure-needs-containment/</link>
      <pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-07-28-backup-infrastructure-needs-containment/</guid>
      <description>&lt;p&gt;Most backup strategies start with copies, retention, and restore speed.&lt;/p&gt;&#xA;&lt;p&gt;Attackers start with reachability.&lt;/p&gt;&#xA;&lt;p&gt;Can a compromised production administrator reach the backup console? Does the backup platform trust the production identity provider? Can ordinary server networks connect to repositories or storage management interfaces? Can a shared virtualization manager delete both workloads and their recovery points?&lt;/p&gt;&#xA;&lt;p&gt;If the answer is yes, the backup environment is not outside the blast radius. It is simply another management plane inside it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AI Data Pipelines Need Containment</title>
      <link>https://microsegment.io/post/2026-07-21-ai-data-pipelines-need-containment/</link>
      <pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-07-21-ai-data-pipelines-need-containment/</guid>
      <description>&lt;p&gt;Security teams are used to treating uploaded executables as hostile. Uploaded datasets often receive less suspicion.&lt;/p&gt;&#xA;&lt;p&gt;That distinction no longer holds.&lt;/p&gt;&#xA;&lt;p&gt;On July 16, 2026, &lt;a href=&#34;https://huggingface.co/blog/security-incident-july-2026&#34;&gt;Hugging Face disclosed an intrusion&lt;/a&gt; that started in its dataset-processing pipeline. A malicious dataset abused two code-execution paths: a remote-code dataset loader and template injection in a dataset configuration. The attacker reached a processing worker, escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Your Identity Provider Needs a Containment Boundary</title>
      <link>https://microsegment.io/post/2026-07-14-identity-provider-containment-boundary/</link>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-07-14-identity-provider-containment-boundary/</guid>
      <description>&lt;p&gt;Identity is often described as the new perimeter. That framing misses the harder architectural question: what protects the system that creates the identity assertion?&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi&#34;&gt;New Mandiant research&lt;/a&gt; makes the problem concrete. During a red team engagement, Mandiant recovered an active Active Directory Federation Services token-signing key from the host&amp;rsquo;s machine-scoped cryptographic store. With that key, the team forged a SAML assertion for a Global Administrator identity that Microsoft Entra ID accepted.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The ATT&amp;CK Segmentation Layer Is Now Updated to v19.1</title>
      <link>https://microsegment.io/post/2026-07-10-attack-v19-1-segmentation-layer/</link>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-07-10-attack-v19-1-segmentation-layer/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;https://microsegment.io/content/Segmentation_as_a_mitigation_in_ATTACK.json&#34;&gt;microsegment.io ATT&amp;amp;CK Navigator layer for Network Segmentation&lt;/a&gt; is now refreshed to MITRE ATT&amp;amp;CK v19.1.&lt;/p&gt;&#xA;&lt;p&gt;This is not a dramatic update in the sense of new colors, new scoring, or a long list of new techniques. The useful part is more boring, and probably more important: the mapping stayed stable. MITRE&amp;rsquo;s current Enterprise ATT&amp;amp;CK data still maps &lt;a href=&#34;https://attack.mitre.org/mitigations/M1030/&#34;&gt;M1030 Network Segmentation&lt;/a&gt; to 44 technique and tactic entries across 37 unique technique IDs.&lt;/p&gt;&#xA;&lt;p&gt;That stability is worth paying attention to. It means the original point from the 2019 ATT&amp;amp;CK segmentation article still holds in 2026: segmentation keeps appearing across the attack lifecycle because attackers need reachability. They need paths to remote services, identity infrastructure, management systems, deployment tooling, configuration stores, command-and-control channels, and exfiltration routes. If those paths are broad, implicit, or poorly governed, the attacker gets options. If those paths are narrow, explicit, and enforced close to the systems that matter, the attacker has fewer moves available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What Good L3/L4 Policy Can Actually Do</title>
      <link>https://microsegment.io/post/2026-07-09-what-l3-l4-policy-can-do/</link>
      <pubDate>Thu, 09 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-07-09-what-l3-l4-policy-can-do/</guid>
      <description>&lt;p&gt;In 2019 I published a short article about MITRE ATT&amp;amp;CK and segmentation.&lt;/p&gt;&#xA;&lt;p&gt;The point was simple: when ATT&amp;amp;CK maps adversary techniques to mitigations, network segmentation shows up in more places than many people expect. It is not only a perimeter control. It appears across the attack lifecycle because attackers need reach.&lt;/p&gt;&#xA;&lt;p&gt;That old point still holds.&lt;/p&gt;&#xA;&lt;p&gt;But it deserves a 2026 reassessment.&lt;/p&gt;&#xA;&lt;p&gt;The original post was written in a world where many segmentation conversations still meant VLANs, firewall zones, and large network boundaries. Today the conversation is broader. We have cloud security groups, Kubernetes network policies, host firewalls, software-defined segmentation, identity-aware access paths, workload labels, service maps, and microsegmentation platforms.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Voice Infrastructure Needs Containment, Too</title>
      <link>https://microsegment.io/post/2026-07-07-voice-infrastructure-needs-containment/</link>
      <pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-07-07-voice-infrastructure-needs-containment/</guid>
      <description>&lt;p&gt;Voice infrastructure is easy to underestimate.&lt;/p&gt;&#xA;&lt;p&gt;It sits in the background. It routes calls. It connects desk phones, softphones, contact centers, voicemail, emergency calling, directories, gateways, and collaboration workflows. It is operational plumbing, so it often gets treated as a specialist island.&lt;/p&gt;&#xA;&lt;p&gt;That is the wrong mental model.&lt;/p&gt;&#xA;&lt;p&gt;Unified communications platforms are not just voice systems. They are trust infrastructure.&lt;/p&gt;&#xA;&lt;p&gt;The latest Cisco Unified Communications Manager issue is a useful reminder. CVE-2026-20230 affects Cisco Unified CM and Unified CM SME when the WebDialer service is enabled. Cisco published the advisory on June 3, 2026 and updated it on July 1, 2026 after becoming aware of active exploitation. NVD describes the issue as server-side request forgery through crafted HTTP requests that can allow file writes to the underlying operating system, which can then be used to elevate to root. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on June 25, 2026 with a June 28 due date for covered federal agencies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mythos, Microsegmentation, and the Collapse of the Exploit Window</title>
      <link>https://microsegment.io/post/2026-07-03-mythos-microsegmentation-containment/</link>
      <pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-07-03-mythos-microsegmentation-containment/</guid>
      <description>&lt;h2 id=&#34;the-interesting-part-is-not-the-hype&#34;&gt;The Interesting Part Is Not the Hype&lt;/h2&gt;&#xA;&lt;p&gt;Anthropic&amp;rsquo;s Project Glasswing is easy to turn into a dramatic headline.&lt;/p&gt;&#xA;&lt;p&gt;Claude Mythos Preview finds vulnerabilities. It helps develop exploit paths. It can be pointed at large, important software systems. In Anthropic&amp;rsquo;s first update, partners reported more than ten thousand high- or critical-severity findings in about a month.&lt;/p&gt;&#xA;&lt;p&gt;That sounds like the future of vulnerability research arriving all at once.&lt;/p&gt;&#xA;&lt;p&gt;Maybe it is.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Non-Human Identities Need Containment, Not Just Rotation</title>
      <link>https://microsegment.io/post/2026-06-30-non-human-identities-need-containment/</link>
      <pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-06-30-non-human-identities-need-containment/</guid>
      <description>&lt;p&gt;Most Zero Trust programs still talk about identity as if the identity is a person.&lt;/p&gt;&#xA;&lt;p&gt;That is no longer enough.&lt;/p&gt;&#xA;&lt;p&gt;Modern environments are full of identities that do not show up in HR systems, do not sit in security awareness training, and do not leave the company when an employee changes jobs. Service accounts. API keys. OAuth apps. CI/CD tokens. Workload roles. SaaS connectors. Kubernetes service accounts. Agent runtimes. Automation jobs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsegmentation in 2026: The Control That Turns Breach Assumption Into Architecture</title>
      <link>https://microsegment.io/post/2026-06-23-microsegmentation-2026-trends/</link>
      <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-06-23-microsegmentation-2026-trends/</guid>
      <description>&lt;p&gt;Microsegmentation is having a very practical moment.&lt;/p&gt;&#xA;&lt;p&gt;Not because the term is new. It is not. And not because another framework told security teams to &amp;ldquo;do Zero Trust.&amp;rdquo; We have had enough of that.&lt;/p&gt;&#xA;&lt;p&gt;The reason microsegmentation matters in 2026 is simpler: the current threat landscape is exposing the cost of flat trust.&lt;/p&gt;&#xA;&lt;p&gt;Verizon&amp;rsquo;s 2026 DBIR says 31% of breaches now start with software vulnerabilities, making vulnerability exploitation the leading initial access vector in that report. It also says ransomware is involved in 48% of breaches. Mandiant&amp;rsquo;s M-Trends 2026 is built from more than 500,000 hours of incident response work in 2025. Unit 42&amp;rsquo;s 2026 incident response report points to excessive trust and identity weakness as recurring reasons initial access turns into broader compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Weekly Security Landscape: April 26 - May 2, 2026</title>
      <link>https://microsegment.io/post/2026-05-02-weekly-security-landscape-w18/</link>
      <pubDate>Sat, 02 May 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-05-02-weekly-security-landscape-w18/</guid>
      <description>&lt;h2 id=&#34;the-week-at-a-glance&#34;&gt;The Week at a Glance&lt;/h2&gt;&#xA;&lt;p&gt;This week, the most important security stories all hit the same layer: the systems that orchestrate trust for everything else.&lt;/p&gt;&#xA;&lt;p&gt;Hosting control planes, Windows trust paths, SAP developer pipelines, and AI agent runtimes all showed the same problem in different clothes. Attackers do not need a dramatic initial foothold if they can hijack the layer that decides who gets access, what code runs, or where secrets flow next.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Weekly Security Landscape: April 18 - 25, 2026</title>
      <link>https://microsegment.io/post/2026-04-25-weekly-security-landscape-w17/</link>
      <pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-04-25-weekly-security-landscape-w17/</guid>
      <description>&lt;h2 id=&#34;the-week-at-a-glance&#34;&gt;The Week at a Glance&lt;/h2&gt;&#xA;&lt;p&gt;This week was not defined by one giant breach.&lt;/p&gt;&#xA;&lt;p&gt;It was defined by repeated proof that attackers do not need exotic tradecraft when trust is already overextended. Management planes, collaboration paths, developer tooling, and edge infrastructure kept turning into the fastest route from access to impact.&lt;/p&gt;&#xA;&lt;p&gt;Cisco SD-WAN Manager, Apache ActiveMQ, SharePoint, Teams helpdesk impersonation, Vercel&amp;rsquo;s OAuth-linked exposure, Forest Blizzard&amp;rsquo;s router-to-token collection, and the Checkmarx KICS and Bitwarden CLI supply-chain chain all pointed to the same operational truth. The attack surface that matters most right now is the layer that connects systems to each other - admin consoles, brokers, package channels, OAuth grants, remote support paths, and poorly governed edge devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Weekly Security Landscape: April 11 - 17, 2026</title>
      <link>https://microsegment.io/post/2026-04-17-weekly-security-landscape-w16/</link>
      <pubDate>Fri, 17 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-04-17-weekly-security-landscape-w16/</guid>
      <description>&lt;h2 id=&#34;the-week-at-a-glance&#34;&gt;The Week at a Glance&lt;/h2&gt;&#xA;&lt;p&gt;This week was not mainly about new malware families.&lt;/p&gt;&#xA;&lt;p&gt;It was about trusted channels getting turned against defenders.&lt;/p&gt;&#xA;&lt;p&gt;Routers became token-theft infrastructure. Browser extensions became session theft kits. Admin and endpoint management platforms kept showing up in KEV. Code-signing workflows reminded everyone that supply-chain risk is really trust-path risk. Even the noisier vulnerability stories all pointed to the same thing: attackers do not need to smash the front door if they can inherit trust from the systems that already shape traffic, identity, and policy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Weekly Security Landscape: April 4 - 10, 2026</title>
      <link>https://microsegment.io/post/2026-04-10-weekly-security-landscape-w15/</link>
      <pubDate>Fri, 10 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-04-10-weekly-security-landscape-w15/</guid>
      <description>&lt;h2 id=&#34;the-week-at-a-glance&#34;&gt;The Week at a Glance&lt;/h2&gt;&#xA;&lt;p&gt;This week was not really about malware. It was about trust boundaries failing in quiet, high-leverage places.&lt;/p&gt;&#xA;&lt;p&gt;Older routers became token theft infrastructure. Helpdesks and BPOs became initial access. Mobile and endpoint management platforms kept showing up in CISA KEV. AI kept compressing the window between disclosure and weaponization. And all of it pointed to the same uncomfortable truth: the highest-risk systems are often the ones defenders still treat as support plumbing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Management Consoles: The Keys to the Kingdom</title>
      <link>https://microsegment.io/post/2026-04-08-management-consoles-keys-to-the-kingdom/</link>
      <pubDate>Wed, 08 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-04-08-management-consoles-keys-to-the-kingdom/</guid>
      <description>&lt;h2 id=&#34;the-wrong-thing-is-still-trusted&#34;&gt;The Wrong Thing Is Still Trusted&lt;/h2&gt;&#xA;&lt;p&gt;Defenders keep hardening endpoints, tuning detections, and buying more visibility.&lt;/p&gt;&#xA;&lt;p&gt;Meanwhile, attackers keep going after the systems that already have permission to touch everything.&lt;/p&gt;&#xA;&lt;p&gt;That is the real problem with management consoles.&lt;/p&gt;&#xA;&lt;p&gt;When a laptop gets compromised, you have an incident.&lt;/p&gt;&#xA;&lt;p&gt;When a management console gets compromised, you may have a change-control&#xA;problem, an identity problem, a visibility problem, and a lateral movement&#xA;problem all at once.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introducing the Blast Radius Calculator</title>
      <link>https://microsegment.io/post/2026-04-07-blast-radius-calculator/</link>
      <pubDate>Tue, 07 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-04-07-blast-radius-calculator/</guid>
      <description>&lt;h2 id=&#34;why-blast-radius-matters&#34;&gt;Why Blast Radius Matters&lt;/h2&gt;&#xA;&lt;p&gt;When an attacker compromises a single workload, the real question isn&amp;rsquo;t &lt;em&gt;if&lt;/em&gt; they can move laterally &amp;ndash; it&amp;rsquo;s &lt;em&gt;how far&lt;/em&gt; they can go. In a flat network with no segmentation, the answer is: everywhere. Every reachable host becomes a stepping stone toward high-value assets like domain controllers, databases, ERP systems, and backup servers.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Blast radius&lt;/strong&gt; is the total number of workloads, services, and data stores an attacker can reach from an initial point of compromise. It&amp;rsquo;s the single most important metric for understanding the actual impact of a breach &amp;ndash; and the one most organizations can&amp;rsquo;t quantify.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Weekly Security Landscape: March 28 - April 3, 2026</title>
      <link>https://microsegment.io/post/2026-04-03-weekly-security-landscape-w14/</link>
      <pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-04-03-weekly-security-landscape-w14/</guid>
      <description>&lt;h2 id=&#34;the-week-at-a-glance&#34;&gt;The Week at a Glance&lt;/h2&gt;&#xA;&lt;p&gt;This was the week supply chain attacks went industrial, management plane vulnerabilities kept stacking up, and AI proved it can write kernel exploits faster than most organizations can triage a CVE. Here&amp;rsquo;s what happened - and what it means for your architecture.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;-critical-teampcp-supply-chain-campaign-expands&#34;&gt;🔴 Critical: TeamPCP Supply Chain Campaign Expands&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;The biggest story of the month continued to grow.&lt;/strong&gt; TeamPCP&amp;rsquo;s supply chain attack, which started with compromising Aqua Security&amp;rsquo;s Trivy vulnerability scanner via GitHub Actions, expanded to hit LiteLLM (95 million PyPI downloads/month), Checkmarx KICS, and the Axios npm package (100 million weekly downloads).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hard Truths #2: Patching Is Whack-a-Mole, Not Strategy</title>
      <link>https://microsegment.io/post/2026-03-31-hard-truths-2-patching-whack-a-mole/</link>
      <pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-03-31-hard-truths-2-patching-whack-a-mole/</guid>
      <description>&lt;h2 id=&#34;the-math-nobody-wants-to-do&#34;&gt;The Math Nobody Wants to Do&lt;/h2&gt;&#xA;&lt;p&gt;March Patch Tuesday: 84 vulnerabilities. Including two zero-days already under active exploitation.&lt;/p&gt;&#xA;&lt;p&gt;February: APT28 was exploiting CVE-2026-21513 in MSHTML &lt;strong&gt;before the patch even shipped&lt;/strong&gt;. A Russian state-sponsored group had your number before Microsoft did. &lt;a href=&#34;https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html&#34;&gt;Source&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Every month, the same ritual plays out across enterprise IT:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Vendor drops patches&lt;/li&gt;&#xA;&lt;li&gt;Security team triages&lt;/li&gt;&#xA;&lt;li&gt;Testing begins&lt;/li&gt;&#xA;&lt;li&gt;Change advisory boards convene&lt;/li&gt;&#xA;&lt;li&gt;Deployment rolls out in waves&lt;/li&gt;&#xA;&lt;li&gt;Stragglers get chased down&lt;/li&gt;&#xA;&lt;li&gt;Next Patch Tuesday arrives&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Repeat forever.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hard Truths #1: Your Security Tools Are the Attack Surface</title>
      <link>https://microsegment.io/post/2026-03-26-hard-truths-1-security-tools-attack-surface/</link>
      <pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-03-26-hard-truths-1-security-tools-attack-surface/</guid>
      <description>&lt;h2 id=&#34;the-pattern-nobody-wants-to-see&#34;&gt;The Pattern Nobody Wants to See&lt;/h2&gt;&#xA;&lt;p&gt;This month alone, four major security vendors had their management infrastructure turned into attack vectors. Not the endpoints they protect. The management consoles that control them.&lt;/p&gt;&#xA;&lt;p&gt;Let that sink in.&lt;/p&gt;&#xA;&lt;h3 id=&#34;the-incidents&#34;&gt;The Incidents&lt;/h3&gt;&#xA;&lt;p&gt;&lt;strong&gt;Cisco Secure Firewall Management Center&lt;/strong&gt; - CVE-2026-20131, CVSS 10.0. Unauthenticated remote code execution as root. The Interlock ransomware group exploited this as a zero-day for &lt;strong&gt;36 days&lt;/strong&gt; before Cisco even disclosed it. Amazon&amp;rsquo;s threat intelligence team caught them exploiting it since January 26. The attackers had custom RATs, recon scripts, proxy infrastructure - the full playbook. All through a firewall management console.&lt;/p&gt;</description>
    </item>
    <item>
      <title>NIST publishes a zerotrust architecture recommendation</title>
      <link>https://microsegment.io/post/2019-10-11-nist-publishes-zerotrust-architecture-recommendation/</link>
      <pubDate>Fri, 11 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2019-10-11-nist-publishes-zerotrust-architecture-recommendation/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;https://nist.gov/&#34;&gt;US NIST&lt;/a&gt; published a great guide on a zero trust&#xA;architecture that definitely is worth reading and details the elements,&#xA;deployment and deployment scenarios and reference to other material to help&#xA;people get started with zero trust.&lt;/p&gt;&#xA;&lt;p&gt;&lt;span class=&#34;inline-svg-icon&#34; &gt;&lt;svg xmlns=&#34;http://www.w3.org/2000/svg&#34; viewBox=&#34;0 0 384 512&#34;&gt;&lt;path fill=&#34;currentColor&#34; d=&#34;M181.9 256.1c-5-16-4.9-46.9-2-46.9 8.4 0 7.6 36.9 2 46.9zm-1.7 47.2c-7.7 20.2-17.3 43.3-28.4 62.7 18.3-7 39-17.2 62.9-21.9-12.7-9.6-24.9-23.4-34.5-40.8zM86.1 428.1c0 .8 13.2-5.4 34.9-40.2-6.7 6.3-29.1 24.5-34.9 40.2zM248 160h136v328c0 13.3-10.7 24-24 24H24c-13.3 0-24-10.7-24-24V24C0 10.7 10.7 0 24 0h200v136c0 13.2 10.8 24 24 24zm-8 171.8c-20-12.2-33.3-29-42.7-53.8 4.5-18.5 11.6-46.6 6.2-64.2-4.7-29.4-42.4-26.5-47.8-6.8-5 18.3-.4 44.1 8.1 77-11.6 27.6-28.7 64.6-40.8 85.8-.1 0-.1.1-.2.1-27.1 13.9-73.6 44.5-54.5 68 5.6 6.9 16 10 21.5 10 17.9 0 35.7-18 61.1-61.8 25.8-8.5 54.1-19.1 79-23.2 21.7 11.8 47.1 19.5 64 19.5 29.2 0 31.2-32 19.7-43.4-13.9-13.6-54.3-9.7-73.6-7.2zM377 105L279 7c-4.5-4.5-10.6-7-17-7h-6v128h128v-6.1c0-6.3-2.5-12.4-7-16.9zm-74.1 255.3c4.1-2.7-2.5-11.9-42.8-9 37.1 15.8 42.8 9 42.8 9z&#34;/&gt;&lt;/svg&gt;&#xA;&lt;/span&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>ACT IAC on Zero Trust trends</title>
      <link>https://microsegment.io/post/2019-08-25-actiac-zero-trust-cybersecurity-trends/</link>
      <pubDate>Sun, 25 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2019-08-25-actiac-zero-trust-cybersecurity-trends/</guid>
      <description>&lt;p&gt;The &lt;strong&gt;American Council for Technology-Industry Advisory Council (ACT-IAC)&lt;/strong&gt;, a&#xA;non commercial organisation for creating a more innovative government published&#xA;a &lt;a href=&#34;https://www.actiac.org/system/files/ACT-IAC%20Zero%20Trust%20Project%20Report%2004182019.pdf&#34;&gt;paper on Zero&#xA;Trust&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;I would recommend this paper for anybody remotely thinking about Zero Trust,&#xA;be it because you start thinking about introducing it or because it is just&#xA;one of those trends that you want to catch up on.&lt;/p&gt;&#xA;&lt;p&gt;There is a huge amount of truth and knowledge in this document and it is&#xA;not having any marketing in it. I read it and thought this is sound advice&#xA;for anyone that looks to improve their security posture with the ultimate,&#xA;long term &lt;strong&gt;Zero Trust&lt;/strong&gt; goal in mind.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A collection of zero trust resources</title>
      <link>https://microsegment.io/post/zero-trust-resources/</link>
      <pubDate>Sat, 10 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/zero-trust-resources/</guid>
      <description>&lt;h1 id=&#34;work-in-progress&#34;&gt;Work in progress&lt;/h1&gt;&#xA;&lt;p&gt;This list is work in progress, if you have suggestions on what to add,&#xA;please add a comment below or drop me a mail or note.&lt;/p&gt;&#xA;&lt;h1 id=&#34;the-origins&#34;&gt;The origins&lt;/h1&gt;&#xA;&lt;p&gt;Zero Trust is not exactly a new idea, but a name for a architecture that takes&#xA;least privilege as the first design principle and assumes nothing can be&#xA;trusted.  I am not sure who established the category at this moment, but it&#xA;seems Google and Forrester Research have both been working on this.  &lt;a href=&#34;https://twitter.com/kindervag&#34;&gt;John&#xA;Kindervag (@kindervag)&lt;/a&gt; originally published the&#xA;model in 2010.&#xA;That paper is still valid 9 years after the first publication and it shows&#xA;great foresight and vision. Kudos to that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Visualization of an attack in a Zero Trust Network</title>
      <link>https://microsegment.io/2019/08/10/visualization-of-an-attack-zero-trust/</link>
      <pubDate>Sat, 10 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/2019/08/10/visualization-of-an-attack-zero-trust/</guid>
      <description>&lt;p&gt;Dr Chase Cunningham from Forrester Research is spreading the Zero Trust&#xA;Networking word and there is a lot to be learned from the model.&#xA;The below video shows how a attack spreads in a relatively flat network&#xA;compared to how it spreads (or rather does not spread) in a network&#xA;build with Zero Trust Networking architecture.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://go.forrester.com/blogs/zero-trust-in-practice/&#34;&gt;Zero Trust in Practice&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;We will also publish a series of posts and articles that talk about&#xA;the Zero Trust model, the guiding principles and challenges and how&#xA;to start the journey.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
