<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>SecOpsNomad — Breach analysis</title><description>Cybersecurity breaches explained through security impact, team responsibilities, and practical hunting. Independent analysis in English and Japanese.</description><link>https://secopsnomad.si/</link><language>en</language><item><title>Shadow AI on .si domains: when “AI” became “SI”.</title><link>https://secopsnomad.si/blog/shadow-ai-si-domains/</link><guid isPermaLink="true">https://secopsnomad.si/blog/shadow-ai-si-domains/</guid><description>A US rename and a .si registration rush give unvetted AI tools a new name that word-based proxy, DLP and policy controls may not catch.</description><pubDate>Fri, 02 Oct 2026 00:00:00 GMT</pubDate></item><item><title>DIVD’s Zammad breach: the help desk belongs in the trust map.</title><link>https://secopsnomad.si/blog/divd-zammad-boundaries/</link><guid isPermaLink="true">https://secopsnomad.si/blog/divd-zammad-boundaries/</guid><description>A support platform can connect sensitive conversations, privileged workflows, and the rest of the environment.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate></item><item><title>Pentagon personnel-data exposure: patching does not close the data question.</title><link>https://secopsnomad.si/blog/dmdc-data-exposure/</link><guid isPermaLink="true">https://secopsnomad.si/blog/dmdc-data-exposure/</guid><description>A long reported exposure window shifts the review toward retention, historical evidence, data ownership, and targeted impersonation.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate></item><item><title>JAEA: count the people, not just the downloaded files.</title><link>https://secopsnomad.si/blog/jaea-cloud-files/</link><guid isPermaLink="true">https://secopsnomad.si/blog/jaea-cloud-files/</guid><description>JAEA’s cloud-service disclosure highlights sensitive uploads, supplier evidence, and the limits of an endpoint-only investigation.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate></item><item><title>MetaMask: an infrastructure incident needs a precise boundary.</title><link>https://secopsnomad.si/blog/metamask-validator-incident/</link><guid isPermaLink="true">https://secopsnomad.si/blog/metamask-validator-incident/</guid><description>What an infrastructure incident means for service owners, key custody, partner assurance, and follow-on impersonation.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate></item><item><title>NetScaler: investigate the appliance after closing the vulnerability.</title><link>https://secopsnomad.si/blog/netscaler-post-exploitation/</link><guid isPermaLink="true">https://secopsnomad.si/blog/netscaler-post-exploitation/</guid><description>New post-exploitation reporting offers leads for appliance logs, configuration exposure, and privileged changes.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate></item><item><title>Zimbra: email security also needs visibility into the mail server.</title><link>https://secopsnomad.si/blog/zimbra-mail-server-hunt/</link><guid isPermaLink="true">https://secopsnomad.si/blog/zimbra-mail-server-hunt/</guid><description>Microsoft’s exploitation report connects a mail-server weakness to host activity and published network indicators.</description><pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate></item></channel></rss>