<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>LevelBlue SpiderLabs Blog</title>
    <link>https://www.levelblue.com/blogs/spiderlabs-blog</link>
    <description>The security community's go-to destination for technical breakdowns of the latest threats, critical vulnerability disclosures and cutting-edge research.</description>
    <language>en</language>
    <pubDate>Tue, 21 Apr 2026 14:00:03 GMT</pubDate>
    <dc:date>2026-04-21T14:00:03Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>A Closer Look at the Novel and Stealthy KarstoRAT Malware</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/a-closer-look-at-the-novel-and-stealthy-karstorat-malware</link>
      <description>&lt;p&gt;For almost three decades now, threat actors have used remote access trojans (RATs) to monitor user activity and steal sensitive information and credentials. The RAT’s surreptitious nature has cemented its spot in malicious actors’ malware arsenal, and over the years, it has evolved to include advanced functionalities, including remote code execution, browser decryption, C2 communication, and reconnaissance.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For almost three decades now, threat actors have used remote access trojans (RATs) to monitor user activity and steal sensitive information and credentials. The RAT’s surreptitious nature has cemented its spot in malicious actors’ malware arsenal, and over the years, it has evolved to include advanced functionalities, including remote code execution, browser decryption, C2 communication, and reconnaissance.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Fa-closer-look-at-the-novel-and-stealthy-karstorat-malware&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Reports</category>
      <category>Emerging Threats</category>
      <pubDate>Tue, 21 Apr 2026 14:00:03 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/a-closer-look-at-the-novel-and-stealthy-karstorat-malware</guid>
      <dc:date>2026-04-21T14:00:03Z</dc:date>
      <dc:creator>Chen Aviani</dc:creator>
    </item>
    <item>
      <title>Go With the Flow: Abusing OAuth Device Code Flow</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/go-with-the-flow-abusing-oauth-device-code-flow</link>
      <description>&lt;p&gt;In early 2026, phishing attacks are still among the top contributors to the true positive detections in &lt;a href="https://www.levelblue.com/services/co-managed-soc"&gt;security operation centers (SOCs)&lt;/a&gt;. Adversaries constantly come up with new ways of luring users into traps, concealing their actual intents and stacking anti-detection features. LevelBlue’s&lt;span&gt; &lt;/span&gt;&lt;a href="https://www.levelblue.com/services/managed-detection-and-response"&gt;Global Threat Operations (GTO) team&lt;span&gt; &lt;/span&gt;&lt;/a&gt;continuously tracks those behaviors and analyzes how the attacks evolve over months. One of the most recent investigations led to the identification of a previously unseen, niche attack vector that can lead to user account compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In early 2026, phishing attacks are still among the top contributors to the true positive detections in &lt;a href="https://www.levelblue.com/services/co-managed-soc"&gt;security operation centers (SOCs)&lt;/a&gt;. Adversaries constantly come up with new ways of luring users into traps, concealing their actual intents and stacking anti-detection features. LevelBlue’s&lt;span&gt; &lt;/span&gt;&lt;a href="https://www.levelblue.com/services/managed-detection-and-response"&gt;Global Threat Operations (GTO) team&lt;span&gt; &lt;/span&gt;&lt;/a&gt;continuously tracks those behaviors and analyzes how the attacks evolve over months. One of the most recent investigations led to the identification of a previously unseen, niche attack vector that can lead to user account compromise.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Fgo-with-the-flow-abusing-oauth-device-code-flow&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Emerging Threats</category>
      <category>Vulnerabilities</category>
      <category>Threat Intelligence</category>
      <pubDate>Mon, 20 Apr 2026 14:00:01 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/go-with-the-flow-abusing-oauth-device-code-flow</guid>
      <dc:date>2026-04-20T14:00:01Z</dc:date>
      <dc:creator>Jakub Wiewiorski</dc:creator>
    </item>
    <item>
      <title>RedSun and the Expanding Risk Window: Why Microsoft Defender Patching Can’t Wait</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/redsun-and-the-expanding-risk-window-why-microsoft-defender-patching-cant-wait</link>
      <description>&lt;p&gt;A newly disclosed zero-day vulnerability, dubbed RedSun, is raising fresh concerns for organizations relying on Microsoft Defender as a core layer of endpoint protection. Early indicators suggest similarities to the recently patched BlueHammer vulnerability (&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33825"&gt;CVE-2026-33825&lt;/a&gt;), reinforcing a troubling trend: attackers are increasingly targeting the very tools designed to stop them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A newly disclosed zero-day vulnerability, dubbed RedSun, is raising fresh concerns for organizations relying on Microsoft Defender as a core layer of endpoint protection. Early indicators suggest similarities to the recently patched BlueHammer vulnerability (&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33825"&gt;CVE-2026-33825&lt;/a&gt;), reinforcing a troubling trend: attackers are increasingly targeting the very tools designed to stop them.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Fredsun-and-the-expanding-risk-window-why-microsoft-defender-patching-cant-wait&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Emerging Threats</category>
      <category>Vulnerabilities</category>
      <pubDate>Fri, 17 Apr 2026 17:54:21 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/redsun-and-the-expanding-risk-window-why-microsoft-defender-patching-cant-wait</guid>
      <dc:date>2026-04-17T17:54:21Z</dc:date>
      <dc:creator />
    </item>
    <item>
      <title>Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/why-attackers-are-bypassing-phishing-emails-and-targeting-identity-instead</link>
      <description>&lt;p&gt;One of the fastest growing initial access techniques we are seeing right now is&lt;span&gt; &lt;/span&gt;&lt;span style="font-weight: normal;"&gt;Okta vishing:&lt;/span&gt;&lt;span&gt; &lt;/span&gt;voice-based social engineering designed to compromise the identity provider rather than the inbox.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;One of the fastest growing initial access techniques we are seeing right now is&lt;span&gt; &lt;/span&gt;&lt;span style="font-weight: normal;"&gt;Okta vishing:&lt;/span&gt;&lt;span&gt; &lt;/span&gt;voice-based social engineering designed to compromise the identity provider rather than the inbox.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Fwhy-attackers-are-bypassing-phishing-emails-and-targeting-identity-instead&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Emerging Threats</category>
      <category>Vulnerabilities</category>
      <category>Threat Intelligence</category>
      <pubDate>Mon, 13 Apr 2026 14:00:00 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/why-attackers-are-bypassing-phishing-emails-and-targeting-identity-instead</guid>
      <dc:date>2026-04-13T14:00:00Z</dc:date>
      <dc:creator>Jamie Mamroe</dc:creator>
    </item>
    <item>
      <title>Trojanized CPUID HWMonitor Installer Delivers Fileless .NET Payload via Obfuscated IPv6 Scriptlet</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/trojanized-cpuid-hwmonitor-installer-delivers-fileless-.net-payload-via-obfuscated-ipv6-scriptlet</link>
      <description>&lt;h3&gt;Overview&lt;/h3&gt; 
&lt;p&gt;&lt;a href="https://www.bleepingcomputer.com/news/security/supply-chain-attack-at-cpuid-pushes-malware-with-cpu-z-hwmonitor/"&gt;Recent reporting&lt;/a&gt; has identified a trojanized version of the CPUID HWMonitor installer being used to deliver a multi-stage, fileless malware chain leveraging trusted Windows binaries. Upon execution, the installer initiates a sequence involving PowerShell, MSBuild, and regsvr32, ultimately leading to the execution of malicious scriptlet files such as Clippy.sct and a secondary launcher scriptlet. These scriptlets utilize ActiveX (WScript.Shell) to silently invoke:&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;Overview&lt;/h3&gt; 
&lt;p&gt;&lt;a href="https://www.bleepingcomputer.com/news/security/supply-chain-attack-at-cpuid-pushes-malware-with-cpu-z-hwmonitor/"&gt;Recent reporting&lt;/a&gt; has identified a trojanized version of the CPUID HWMonitor installer being used to deliver a multi-stage, fileless malware chain leveraging trusted Windows binaries. Upon execution, the installer initiates a sequence involving PowerShell, MSBuild, and regsvr32, ultimately leading to the execution of malicious scriptlet files such as Clippy.sct and a secondary launcher scriptlet. These scriptlets utilize ActiveX (WScript.Shell) to silently invoke:&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Ftrojanized-cpuid-hwmonitor-installer-delivers-fileless-.net-payload-via-obfuscated-ipv6-scriptlet&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Emerging Threats</category>
      <category>Threat Intelligence</category>
      <pubDate>Fri, 10 Apr 2026 16:49:56 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/trojanized-cpuid-hwmonitor-installer-delivers-fileless-.net-payload-via-obfuscated-ipv6-scriptlet</guid>
      <dc:date>2026-04-10T16:49:56Z</dc:date>
      <dc:creator>Sean Shirley</dc:creator>
    </item>
    <item>
      <title>Axios NPM Package Supply Chain Compromise Leads to RAT Deployment</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/axios-npm-package-supply-chain-compromise-leads-to-rat-deployment</link>
      <description>&lt;h3&gt;&lt;span style="color: #9cef69;"&gt;KEY OBSERVATIONS&lt;/span&gt;&lt;/h3&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;span&gt;Malicious Package Versions Identified: &lt;/span&gt;&lt;/strong&gt;&lt;span&gt;Malicious versions of the Axios npm package (axios@1.14.1 and axios@0.30.4) were observed within a customer’s environment, indicating exposure to the supply chain compromise.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;span&gt;Suspicious Dependency Execution: &lt;/span&gt;&lt;/strong&gt;&lt;span&gt;The presence of an unauthorized dependency was identified, which executed a postinstall script during npm installation, triggering the initial stage of the infection.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;span&gt;Abnormal Process Execution Chain: &lt;/span&gt;&lt;/strong&gt;&lt;span&gt;Multiple systems exhibited suspicious parent-child process relationships where npm or node spawned command interpreters such as cmd.exe, powershell.exe, followed by execution of network utilities like curl or wget.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;span&gt;Post-exploitation activities detected by LevelBlue: &lt;/span&gt;&lt;/strong&gt;&lt;span&gt;LevelBlue’s&lt;strong&gt; &lt;/strong&gt;Cybereason Defense Platform generated detections associated with post-install script execution, abnormal process (renamed PowerShell) spawning, and suspicious outbound network communication, indicating successful exploitation and potential remote access trojan (RAT) deployment on affected systems.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;br&gt; 
&lt;p&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;h3&gt;&lt;span style="color: #9cef69;"&gt;KEY OBSERVATIONS&lt;/span&gt;&lt;/h3&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;span&gt;Malicious Package Versions Identified: &lt;/span&gt;&lt;/strong&gt;&lt;span&gt;Malicious versions of the Axios npm package (axios@1.14.1 and axios@0.30.4) were observed within a customer’s environment, indicating exposure to the supply chain compromise.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;span&gt;Suspicious Dependency Execution: &lt;/span&gt;&lt;/strong&gt;&lt;span&gt;The presence of an unauthorized dependency was identified, which executed a postinstall script during npm installation, triggering the initial stage of the infection.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;span&gt;Abnormal Process Execution Chain: &lt;/span&gt;&lt;/strong&gt;&lt;span&gt;Multiple systems exhibited suspicious parent-child process relationships where npm or node spawned command interpreters such as cmd.exe, powershell.exe, followed by execution of network utilities like curl or wget.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;&lt;span&gt;Post-exploitation activities detected by LevelBlue: &lt;/span&gt;&lt;/strong&gt;&lt;span&gt;LevelBlue’s&lt;strong&gt; &lt;/strong&gt;Cybereason Defense Platform generated detections associated with post-install script execution, abnormal process (renamed PowerShell) spawning, and suspicious outbound network communication, indicating successful exploitation and potential remote access trojan (RAT) deployment on affected systems.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;br&gt; 
&lt;p&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Faxios-npm-package-supply-chain-compromise-leads-to-rat-deployment&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Emerging Threats</category>
      <pubDate>Thu, 09 Apr 2026 20:16:36 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/axios-npm-package-supply-chain-compromise-leads-to-rat-deployment</guid>
      <dc:date>2026-04-09T20:16:36Z</dc:date>
      <dc:creator>Mahadev Joshi and Sho Kishimoto</dc:creator>
    </item>
    <item>
      <title>Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/err-hiding-and-seek-how-errtraffic-v3-leverages-etherhiding-in-clickfix-campaign</link>
      <description>&lt;p&gt;The LevelBlue &lt;a href="https://www.levelblue.com/spiderlabs"&gt;SpiderLabs&lt;/a&gt; team&amp;nbsp;examined&lt;a href="https://www.levelblue.com/blogs/spiderlabs-blog/file:///C:/Users/pauli/Downloads/Err-Hiding%20and%20Seek%20-%20How%20ErrTraffic%20v3%20Leverages%20EtherHiding%20in%20ClickFix%20Campaign.docx#_msocom_1"&gt;&lt;span&gt;&lt;/span&gt;&lt;/a&gt;&amp;nbsp;the latest version of ErrTraffic, which emerged in early 2026. In a recently observed campaign, the team found that ErrTraffic primarily targets WordPress websites by deploying a PHP backdoor script in the must-use plugin (mu-plugin) that captures administrator credentials and ensures persistence on compromised sites. On the infected website, the backdoor injects malicious inline scripts that leverage both XOR and Base64 obfuscation to evade detection. ErrTraffic utilizes the Traffic Distribution System (TDS) to filter site visitors and redirect them to ClickFix lures.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The LevelBlue &lt;a href="https://www.levelblue.com/spiderlabs"&gt;SpiderLabs&lt;/a&gt; team&amp;nbsp;examined&lt;a href="https://www.levelblue.com/blogs/spiderlabs-blog/file:///C:/Users/pauli/Downloads/Err-Hiding%20and%20Seek%20-%20How%20ErrTraffic%20v3%20Leverages%20EtherHiding%20in%20ClickFix%20Campaign.docx#_msocom_1"&gt;&lt;span&gt;&lt;/span&gt;&lt;/a&gt;&amp;nbsp;the latest version of ErrTraffic, which emerged in early 2026. In a recently observed campaign, the team found that ErrTraffic primarily targets WordPress websites by deploying a PHP backdoor script in the must-use plugin (mu-plugin) that captures administrator credentials and ensures persistence on compromised sites. On the infected website, the backdoor injects malicious inline scripts that leverage both XOR and Base64 obfuscation to evade detection. ErrTraffic utilizes the Traffic Distribution System (TDS) to filter site visitors and redirect them to ClickFix lures.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Ferr-hiding-and-seek-how-errtraffic-v3-leverages-etherhiding-in-clickfix-campaign&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Emerging Threats</category>
      <category>Vulnerabilities</category>
      <category>Threat Intelligence</category>
      <pubDate>Thu, 09 Apr 2026 13:00:00 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/err-hiding-and-seek-how-errtraffic-v3-leverages-etherhiding-in-clickfix-campaign</guid>
      <dc:date>2026-04-09T13:00:00Z</dc:date>
      <dc:creator>King Orande and Cris Tomboc</dc:creator>
    </item>
    <item>
      <title>Major Supply Chain Compromise in the Popular axios npm Package</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/major-supply-chain-compromise-in-the-popular-axios-npm-package</link>
      <description>&lt;p&gt;On March 30, 2026, two malicious versions of the widely used axios HTTP client library were published to npm; axios@1.14.1 and axios@0.30.4. The malicious versions inject a new dependency, plain-crypto-js@4.2.1, which, in turn, downloads a Remote Access Toolkit (RAT).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On March 30, 2026, two malicious versions of the widely used axios HTTP client library were published to npm; axios@1.14.1 and axios@0.30.4. The malicious versions inject a new dependency, plain-crypto-js@4.2.1, which, in turn, downloads a Remote Access Toolkit (RAT).&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Fmajor-supply-chain-compromise-in-the-popular-axios-npm-package&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Emerging Threats</category>
      <category>Vulnerabilities</category>
      <pubDate>Fri, 03 Apr 2026 12:28:57 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/major-supply-chain-compromise-in-the-popular-axios-npm-package</guid>
      <dc:date>2026-04-03T12:28:57Z</dc:date>
      <dc:creator>Karl Sigler</dc:creator>
    </item>
    <item>
      <title>Using RF Power Levels to Defeat MAC Address Randomization Enabling Passive Device Tracking</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/using-rf-power-levels-to-defeat-mac-address-randomization-enabling-passive-device-tracking</link>
      <description>&lt;p&gt;I came up with a theory (based on science) that it may be possible to passively track wireless devices even though they are making use of the defense that is MAC Address Randomization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;I came up with a theory (based on science) that it may be possible to passively track wireless devices even though they are making use of the defense that is MAC Address Randomization.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Fusing-rf-power-levels-to-defeat-mac-address-randomization-enabling-passive-device-tracking&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Emerging Threats</category>
      <category>Vulnerabilities</category>
      <pubDate>Tue, 31 Mar 2026 14:59:37 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/using-rf-power-levels-to-defeat-mac-address-randomization-enabling-passive-device-tracking</guid>
      <dc:date>2026-03-31T14:59:37Z</dc:date>
      <dc:creator>Tom Neaves</dc:creator>
    </item>
    <item>
      <title>The Value of Microsoft Security Copilot: SCU Billing and Why Agent Design Matters</title>
      <link>https://www.levelblue.com/blogs/spiderlabs-blog/the-value-of-microsoft-security-copilot-scu-billing-and-why-agent-design-matters</link>
      <description>&lt;p&gt;Most organizations start by using Microsoft Copilot the way it looks in demos: type a question, get an answer. That works for exploration. For repeatable operational work, it gets expensive quickly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Most organizations start by using Microsoft Copilot the way it looks in demos: type a question, get an answer. That works for exploration. For repeatable operational work, it gets expensive quickly.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=21158977&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.levelblue.com%2Fblogs%2Fspiderlabs-blog%2Fthe-value-of-microsoft-security-copilot-scu-billing-and-why-agent-design-matters&amp;amp;bu=https%253A%252F%252Fwww.levelblue.com%252Fblogs%252Fspiderlabs-blog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Tips &amp; Tricks</category>
      <category>Artificial Intelligence</category>
      <category>Microsoft Security</category>
      <pubDate>Fri, 27 Mar 2026 14:00:01 GMT</pubDate>
      <guid>https://www.levelblue.com/blogs/spiderlabs-blog/the-value-of-microsoft-security-copilot-scu-billing-and-why-agent-design-matters</guid>
      <dc:date>2026-03-27T14:00:01Z</dc:date>
      <dc:creator>David Broggy</dc:creator>
    </item>
  </channel>
</rss>
