<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
 xmlns:content="http://purl.org/rss/1.0/modules/content/"
 xmlns:wfw="http://wellformedweb.org/CommentAPI/"
 xmlns:dc="http://purl.org/dc/elements/1.1/"
 xmlns:atom="http://www.w3.org/2005/Atom"
 xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
 xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
 >

<channel>
 <title>7ASecurity Blog</title>
 <atom:link href="https://7asecurity.com/blog/feed/" rel="self" type="application/rss+xml" />
 <link>https://7asecurity.com/blog/</link>
 <description>7ASecurity Blog With Cybersecurity Tips and Tools</description>
 <lastBuildDate>Fri, 18 Sep 2026 09:21:22 +0000</lastBuildDate>
 <language>en-US</language>
 <sy:updatePeriod>
 hourly </sy:updatePeriod>
 <sy:updateFrequency>
 1 </sy:updateFrequency>


<image>
 <url>https://7asecurity.com/blog/contents/uploads/2019/06/favicon.ico</url>
 <title>7ASecurity Blog</title>
 <link>https://7asecurity.com/blog/</link>
 <width>32</width>
 <height>32</height>
</image> 
 <item>
  <title>Bayanat audit by 7ASecurity</title>
  <link>https://7asecurity.com/blog/2026/09/bayanat-audit-by-7asecurity/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 18 Sep 2026 08:26:18 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[API security]]></category>
  <category><![CDATA[authorization]]></category>
  <category><![CDATA[Bayanat]]></category>
  <category><![CDATA[deployment hardening]]></category>
  <category><![CDATA[evidence management]]></category>
  <category><![CDATA[Fuzzing]]></category>
  <category><![CDATA[human rights documentation]]></category>
  <category><![CDATA[import/export security]]></category>
  <category><![CDATA[Open Source Security]]></category>
  <category><![CDATA[Security Audit]]></category>
  <category><![CDATA[SJAC]]></category>
  <category><![CDATA[SLSA]]></category>
  <category><![CDATA[supply chain security]]></category>
  <category><![CDATA[Threat modeling]]></category>
  <category><![CDATA[Web Security]]></category>
  <category><![CDATA[whitebox review]]></category>


     <description><![CDATA[<p>7ASecurity shares results of a Bayanat security audit: 32 working days, 7 work packages, 22 findings, 21 hardening recommendations, supply-chain review, threat model, and fix verification.</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/09/bayanat-audit-by-7asecurity/">Bayanat audit by 7ASecurity</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>OWASP Top 10 for LLM Applications: How to Test Production AI Apps</title>
  <link>https://7asecurity.com/blog/2026/09/owasp-top-10-llm-applications/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 18 Sep 2026 08:07:43 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Agentic Workflows]]></category>
  <category><![CDATA[AI Application Security]]></category>
  <category><![CDATA[Data and Model Poisoning]]></category>
  <category><![CDATA[EU AI Act Compliance]]></category>
  <category><![CDATA[Excessive Agency]]></category>
  <category><![CDATA[LLM Pentesting]]></category>
  <category><![CDATA[MITRE ATLAS]]></category>
  <category><![CDATA[OWASP LLM Top 10]]></category>
  <category><![CDATA[Prompt Injection]]></category>
  <category><![CDATA[Vulnerability Validation]]></category>


     <description><![CDATA[<p>The OWASP LLM Top 10 names ten specific risks in LLM-powered apps: prompt injection, data leakage, excessive agency, and seven more, each with its own attack pattern. Testing against these risks means chaining a planted instruction through to real data exposure or confirming that rate limits cap costs, rather than just documenting that they should. &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/09/owasp-top-10-llm-applications/">OWASP Top 10 for LLM Applications: How to Test Production AI Apps</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>How to Choose Between AI Red Teaming and an AI Security Assessment</title>
  <link>https://7asecurity.com/blog/2026/09/ai-red-teaming-vs-ai-penetration-testing/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 11 Sep 2026 08:01:38 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Adversarial Testing]]></category>
  <category><![CDATA[AI Penetration Testing]]></category>
  <category><![CDATA[AI Red Teaming]]></category>
  <category><![CDATA[AI security]]></category>
  <category><![CDATA[autonomous agents]]></category>
  <category><![CDATA[Cyber Defense]]></category>
  <category><![CDATA[LLM Vulnerabilities]]></category>
  <category><![CDATA[MITRE ATLAS]]></category>
  <category><![CDATA[OWASP Top 10]]></category>
  <category><![CDATA[Security Assessments]]></category>


     <description><![CDATA[<p>AI red teaming and AI penetration testing are not the same thing. AI penetration testing looks for every possible vulnerability to build a secure baseline. AI red teaming simulates a targeted attack to test your detection and response capabilities. Choose an AI security assessment based on your current operational maturity. People use the terms "AI &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/09/ai-red-teaming-vs-ai-penetration-testing/">How to Choose Between AI Red Teaming and an AI Security Assessment</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>Incus security audit by 7ASecurity</title>
  <link>https://7asecurity.com/blog/2026/09/incus-security-audit-7asecurity/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 04 Sep 2026 10:38:33 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[7ASecurity;]]></category>
  <category><![CDATA[API security;]]></category>
  <category><![CDATA[authorization;]]></category>
  <category><![CDATA[container security;]]></category>
  <category><![CDATA[guest isolation;]]></category>
  <category><![CDATA[Incus;]]></category>
  <category><![CDATA[Linux Containers;]]></category>
  <category><![CDATA[multi-tenant security;]]></category>
  <category><![CDATA[open source security;]]></category>
  <category><![CDATA[parser fuzzing;]]></category>
  <category><![CDATA[security audit;]]></category>
  <category><![CDATA[SLSA;]]></category>
  <category><![CDATA[Sovereign Tech Agency;]]></category>
  <category><![CDATA[supply chain security;]]></category>
  <category><![CDATA[threat modeling;]]></category>
  <category><![CDATA[virtual machine security;]]></category>
  <category><![CDATA[whitebox testing;]]></category>


     <description><![CDATA[<p>7ASecurity publishes an independent Incus audit: all 14 vulnerabilities and 14 of 17 hardening recommendations were resolved and independently verified.</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/09/incus-security-audit-7asecurity/">Incus security audit by 7ASecurity</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>API Penetration Testing Methodology: How Testers Structure the Engagement</title>
  <link>https://7asecurity.com/blog/2026/09/api-pentesting-guide/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 04 Sep 2026 07:04:04 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[API Penetration Testing]]></category>
  <category><![CDATA[API Security Methodology]]></category>
  <category><![CDATA[BOLA Vulnerabilities]]></category>
  <category><![CDATA[Business Logic Flaws]]></category>
  <category><![CDATA[GraphQL Security]]></category>
  <category><![CDATA[JWT Security]]></category>
  <category><![CDATA[OAuth Pentesting]]></category>
  <category><![CDATA[OWASP API Top 10]]></category>
  <category><![CDATA[Rate Limit Bypassing]]></category>
  <category><![CDATA[Shadow APIs]]></category>


     <description><![CDATA[<p>API penetration testing methodology starts with scoping and endpoint mapping. From there, it moves through authentication, authorisation, and business logic testing. Findings then get mapped back to the OWASP API Security Top 10. This piece walks through that process from a tester's side. An API (Application Programming Interface) doesn't have a login page to click &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/09/api-pentesting-guide/">API Penetration Testing Methodology: How Testers Structure the Engagement</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>Cloud Penetration Testing: Validating AWS, Azure, and GCP Security</title>
  <link>https://7asecurity.com/blog/2026/08/cloud-penetration-testing/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 28 Aug 2026 06:50:39 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[AWS Security]]></category>
  <category><![CDATA[Azure Security]]></category>
  <category><![CDATA[Cloud Misconfigurations]]></category>
  <category><![CDATA[Cloud Penetration Testing]]></category>
  <category><![CDATA[Cloud Security Assessment]]></category>
  <category><![CDATA[GCP Pentesting]]></category>
  <category><![CDATA[IAM Security]]></category>
  <category><![CDATA[Serverless Security]]></category>
  <category><![CDATA[Shared Responsibility Model]]></category>
  <category><![CDATA[SSRF Vulnerabilities]]></category>


     <description><![CDATA[<p>Cloud penetration testing looks different from a standard network test. The risk sits in identity and access management, not firewalls. AWS, Microsoft Azure, and Google Cloud all let you test your resources without asking first. However, you just must stay inside their published rules. Cloud penetration testing exists because of a split some teams only &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/08/cloud-penetration-testing/">Cloud Penetration Testing: Validating AWS, Azure, and GCP Security</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>LLM Pentesting Checklist: Prompt Injection, Data Leakage, and Tool Abuse</title>
  <link>https://7asecurity.com/blog/2026/08/llm-pentesting-checklist/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 21 Aug 2026 06:19:44 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Agent Security]]></category>
  <category><![CDATA[AI Red Teaming]]></category>
  <category><![CDATA[AI security]]></category>
  <category><![CDATA[AI Threat Modeling]]></category>
  <category><![CDATA[Data Leakage]]></category>
  <category><![CDATA[LLM Pentesting]]></category>
  <category><![CDATA[Machine Learning Security]]></category>
  <category><![CDATA[MITRE ATLAS]]></category>
  <category><![CDATA[OWASP LLM Top 10]]></category>
  <category><![CDATA[Prompt Injection]]></category>


     <description><![CDATA[<p>LLM pentesting needs to cover more than the model's text output. A proper test scopes the model, its plugins, and its data sources. Then, it works through known risk categories, including prompt injection, data leakage, and tool abuse. Shipping an AI feature moves faster than most security processes were built to handle. A chatbot goes &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/08/llm-pentesting-checklist/">LLM Pentesting Checklist: Prompt Injection, Data Leakage, and Tool Abuse</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>How to Interview a Penetration Testing Company Like a Pro (&#038; Our Answers)</title>
  <link>https://7asecurity.com/blog/2026/08/how-to-interview-a-penetration-testing-company/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 14 Aug 2026 07:30:30 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Cybersecurity Compliance]]></category>
  <category><![CDATA[Cybersecurity Vendor]]></category>
  <category><![CDATA[ISO 27001]]></category>
  <category><![CDATA[penetration testing company]]></category>
  <category><![CDATA[Pentest Provider]]></category>
  <category><![CDATA[Pentest Quality Guarantee]]></category>
  <category><![CDATA[Pentest Scoping]]></category>
  <category><![CDATA[Security Certifications]]></category>
  <category><![CDATA[SOC 2]]></category>
  <category><![CDATA[Vendor Selection]]></category>


     <description><![CDATA[<p>Finding the right penetration testing company requires asking difficult questions. To show you what a strong answer looks like, we put these questions to ourselves. However, this is a mock interview with 7ASecurity, so answers will vary by provider. Use this as a guide for your conversations and what to listen for. Ask five different &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/08/how-to-interview-a-penetration-testing-company/">How to Interview a Penetration Testing Company Like a Pro (&#038; Our Answers)</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>Know What to Expect From a Penetration Test Before You Book</title>
  <link>https://7asecurity.com/blog/2026/08/what-to-expect-from-a-penetration-test/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 07 Aug 2026 08:25:09 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Cybersecurity Testing]]></category>
  <category><![CDATA[NIST SP 800-115]]></category>
  <category><![CDATA[Penetration Test Retesting]]></category>
  <category><![CDATA[Penetration Testing Process]]></category>
  <category><![CDATA[Pentest Reporting]]></category>
  <category><![CDATA[Pentest Scoping]]></category>
  <category><![CDATA[Pentest Timeline]]></category>
  <category><![CDATA[Security Auditing]]></category>
  <category><![CDATA[Vulnerability Assessment]]></category>
  <category><![CDATA[Vulnerability Remediation]]></category>


     <description><![CDATA[<p>What to Expect From a Penetration Test, From Scoping to Retest What to expect from a penetration test goes well beyond the final report. At least, that’s how we do it at 7ASecurity. Before testing starts, you'll agree on scope and hand over access. During testing, you're expected to stay reachable. Afterwards, you get a &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/08/what-to-expect-from-a-penetration-test/">Know What to Expect From a Penetration Test Before You Book</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>Pentest Services 101: Match the Test to Your Business Risk</title>
  <link>https://7asecurity.com/blog/2026/07/pentest-services-business-risk/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 31 Jul 2026 09:28:50 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[AI security testing]]></category>
  <category><![CDATA[Cloud Security Audit]]></category>
  <category><![CDATA[Code Audit]]></category>
  <category><![CDATA[Cybersecurity Compliance]]></category>
  <category><![CDATA[Mobile App Security]]></category>
  <category><![CDATA[network penetration testing]]></category>
  <category><![CDATA[penetration testing services]]></category>
  <category><![CDATA[Security Testing]]></category>
  <category><![CDATA[Vulnerability Assessment]]></category>
  <category><![CDATA[Web App Pentesting]]></category>


     <description><![CDATA[<p>Pentest Services Explained: Matching the Test to Your Situation Pentest services aren't one and all the same. This guide matches your situation, a new web app, a cloud migration, an AI feature, or a suspected internal risk, to the test or combination that fits. Scan the trigger table, read the scope notes for each service, &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/07/pentest-services-business-risk/">Pentest Services 101: Match the Test to Your Business Risk</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
 </channel>
</rss>
