<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Omar Babba — CTI Monthly</title>
<link>https://omarbabba.co/blog/</link>
<atom:link href="https://omarbabba.co/blog/feed.xml" rel="self" type="application/rss+xml"/>
<description>Monthly cyber threat intelligence: vulnerabilities, ransomware, nation-state activity and supply-chain attacks — evidence-graded, sources cited.</description>
<language>en</language>
<lastBuildDate>Fri, 04 Sep 2026 00:00:00 +0000</lastBuildDate>
<item>
<title>CTI Report — August 2026: The Compression of the Exploitation Window</title>
<link>https://omarbabba.co/blog/cti-report-august-2026.html</link>
<guid isPermaLink="true">https://omarbabba.co/blog/cti-report-august-2026.html</guid>
<pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate>
<description>Monthly cyber threat intelligence report for August 2026: RansomHub&#x27;s 90/10 economics and the fission of the ransomware ecosystem, a China-nexus espionage campaign through VMware vCenter (CVE-2026-59310), the JFrog Artifactory supply-chain crisis (CVE-2026-82329), Iranian attacks on UK power and US water utilities, the Morocco CNSS data breach, and the first fully autonomous AI-driven cyberattack.</description>
</item>
<item>
<title>CTI Report — July 2026: SharePoint Exploitation Wave, Agentic AI Intrusion, and Iranian PLC Targeting</title>
<link>https://omarbabba.co/blog/cti-report-july-2026.html</link>
<guid isPermaLink="true">https://omarbabba.co/blog/cti-report-july-2026.html</guid>
<pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate>
<description>Monthly cyber threat intelligence report for 1–23 July 2026: 14 CISA KEV additions, four exploited SharePoint CVEs, the first documented agentic-AI intrusion of a major AI platform, Iranian PLC attacks on US critical infrastructure, ransomware and law-enforcement developments. Evidence-graded, with confidence levels and full source register.</description>
</item>
</channel>
</rss>
