<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Wiz Blog: CIRT | RSS feed</title>
        <link>https://www.wiz.io</link>
        <description>Guides, announcements, and articles about Cloud Security and the Wiz platform.</description>
        <lastBuildDate>Wed, 09 Sep 2026 14:58:50 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>de-DE</language>
        <image>
            <title>Wiz Blog: CIRT | RSS feed</title>
            <url>https://www.wiz.io/rss_feed_logo.jpg</url>
            <link>https://www.wiz.io</link>
        </image>
        <copyright>All rights reserved 2026, Wiz Inc.</copyright>
        <atom:link href="https://www.wiz.io/feed/tag/cirt/rss.xml" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps]]></title>
            <link>https://www.wiz.io/blog/vcs-dfir-threat-hunting-github-gitlab-azure-devops</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/vcs-dfir-threat-hunting-github-gitlab-azure-devops</guid>
            <pubDate>Thu, 27 Aug 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.]]></description>
            <content:encoded><![CDATA[A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.]]></content:encoded>
            <author>Shira Ayal</author>
            <author>Sean Johnstone</author>
            <enclosure url="https://www.datocms-assets.com/75231/1787767961-vcs-2x-1.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign]]></title>
            <link>https://www.wiz.io/blog/investigating-github-pat-compromise</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/investigating-github-pat-compromise</guid>
            <pubDate>Thu, 13 Aug 2026 15:04:28 GMT</pubDate>
            <description><![CDATA[A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.]]></description>
            <content:encoded><![CDATA[A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRT's response to a coordinated multi-organization campaign.]]></content:encoded>
            <author>Eden Abergil</author>
            <enclosure url="https://www.datocms-assets.com/75231/1786570602-github-pat-compromise-2.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure]]></title>
            <link>https://www.wiz.io/blog/threat-actors-target-crypto-orgs</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/threat-actors-target-crypto-orgs</guid>
            <pubDate>Wed, 27 May 2026 13:52:45 GMT</pubDate>
            <description><![CDATA[Wiz CIRT and Wiz Research detail JINX-0164, a threat actor using LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target cryptocurrency organizations.]]></description>
            <content:encoded><![CDATA[Wiz CIRT and Wiz Research detail JINX-0164, a threat actor using LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target cryptocurrency organizations.]]></content:encoded>
            <author>Shira Ayal</author>
            <author>Eden Abergil</author>
            <author>Andre Maccarone</author>
            <author>Yuval Dan</author>
            <author>Benjamin Read</author>
            <enclosure url="https://www.datocms-assets.com/75231/1779831567-dprk-2x.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild]]></title>
            <link>https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild</guid>
            <pubDate>Mon, 30 Mar 2026 23:54:14 GMT</pubDate>
            <description><![CDATA[How TeamPCP are leveraging stolen secrets from the recent supply chain attacks to compromise cloud environments]]></description>
            <content:encoded><![CDATA[How TeamPCP are leveraging stolen secrets from the recent supply chain attacks to compromise cloud environments]]></content:encoded>
            <author>Eden Abergil</author>
            <author>Sean Johnstone</author>
            <author>Zoe Rabi</author>
            <author>Hila Ramati</author>
            <enclosure url="https://www.datocms-assets.com/75231/1774960503-tracking-teampcp.png" length="0" type="image/png"/>
        </item>
        <item>
            <title><![CDATA[Code to Cloud Attacks: From Github PAT to Cloud Control Plane]]></title>
            <link>https://www.wiz.io/blog/github-attacks-pat-control-plane</link>
            <guid isPermaLink="false">https://www.wiz.io/blog/github-attacks-pat-control-plane</guid>
            <pubDate>Tue, 09 Dec 2025 13:00:02 GMT</pubDate>
            <description><![CDATA[How attackers are leveraging compromised employee GitHub Personal Access Tokens to compromise cloud environments.]]></description>
            <content:encoded><![CDATA[How attackers are leveraging compromised employee GitHub Personal Access Tokens to compromise cloud environments.]]></content:encoded>
            <author>Shira Ayal</author>
            <enclosure url="https://www.datocms-assets.com/75231/1765223281-github-pats-2x.png" length="0" type="image/png"/>
        </item>
    </channel>
</rss>