<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
 xmlns:content="http://purl.org/rss/1.0/modules/content/"
 xmlns:wfw="http://wellformedweb.org/CommentAPI/"
 xmlns:dc="http://purl.org/dc/elements/1.1/"
 xmlns:atom="http://www.w3.org/2005/Atom"
 xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
 xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
 >

<channel>
 <title>7ASecurity Blog</title>
 <atom:link href="https://7asecurity.com/blog/feed/" rel="self" type="application/rss+xml" />
 <link>https://7asecurity.com/blog/</link>
 <description>7ASecurity Blog With Cybersecurity Tips and Tools</description>
 <lastBuildDate>Fri, 28 Aug 2026 06:50:42 +0000</lastBuildDate>
 <language>en-US</language>
 <sy:updatePeriod>
 hourly </sy:updatePeriod>
 <sy:updateFrequency>
 1 </sy:updateFrequency>


<image>
 <url>https://7asecurity.com/blog/contents/uploads/2019/06/favicon.ico</url>
 <title>7ASecurity Blog</title>
 <link>https://7asecurity.com/blog/</link>
 <width>32</width>
 <height>32</height>
</image> 
 <item>
  <title>Cloud Penetration Testing: Validating AWS, Azure, and GCP Security</title>
  <link>https://7asecurity.com/blog/2026/08/cloud-penetration-testing/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 28 Aug 2026 06:50:39 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[AWS Security]]></category>
  <category><![CDATA[Azure Security]]></category>
  <category><![CDATA[Cloud Misconfigurations]]></category>
  <category><![CDATA[Cloud Penetration Testing]]></category>
  <category><![CDATA[Cloud Security Assessment]]></category>
  <category><![CDATA[GCP Pentesting]]></category>
  <category><![CDATA[IAM Security]]></category>
  <category><![CDATA[Serverless Security]]></category>
  <category><![CDATA[Shared Responsibility Model]]></category>
  <category><![CDATA[SSRF Vulnerabilities]]></category>


     <description><![CDATA[<p>Cloud penetration testing looks different from a standard network test. The risk sits in identity and access management, not firewalls. AWS, Microsoft Azure, and Google Cloud all let you test your resources without asking first. However, you just must stay inside their published rules. Cloud penetration testing exists because of a split some teams only &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/08/cloud-penetration-testing/">Cloud Penetration Testing: Validating AWS, Azure, and GCP Security</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>LLM Pentesting Checklist: Prompt Injection, Data Leakage, and Tool Abuse</title>
  <link>https://7asecurity.com/blog/2026/08/llm-pentesting-checklist/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 21 Aug 2026 06:19:44 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Agent Security]]></category>
  <category><![CDATA[AI Red Teaming]]></category>
  <category><![CDATA[AI security]]></category>
  <category><![CDATA[AI Threat Modeling]]></category>
  <category><![CDATA[Data Leakage]]></category>
  <category><![CDATA[LLM Pentesting]]></category>
  <category><![CDATA[Machine Learning Security]]></category>
  <category><![CDATA[MITRE ATLAS]]></category>
  <category><![CDATA[OWASP LLM Top 10]]></category>
  <category><![CDATA[Prompt Injection]]></category>


     <description><![CDATA[<p>LLM pentesting needs to cover more than the model's text output. A proper test scopes the model, its plugins, and its data sources. Then, it works through known risk categories, including prompt injection, data leakage, and tool abuse. Shipping an AI feature moves faster than most security processes were built to handle. A chatbot goes &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/08/llm-pentesting-checklist/">LLM Pentesting Checklist: Prompt Injection, Data Leakage, and Tool Abuse</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>How to Interview a Penetration Testing Company Like a Pro (&#038; Our Answers)</title>
  <link>https://7asecurity.com/blog/2026/08/how-to-interview-a-penetration-testing-company/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 14 Aug 2026 07:30:30 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Cybersecurity Compliance]]></category>
  <category><![CDATA[Cybersecurity Vendor]]></category>
  <category><![CDATA[ISO 27001]]></category>
  <category><![CDATA[penetration testing company]]></category>
  <category><![CDATA[Pentest Provider]]></category>
  <category><![CDATA[Pentest Quality Guarantee]]></category>
  <category><![CDATA[Pentest Scoping]]></category>
  <category><![CDATA[Security Certifications]]></category>
  <category><![CDATA[SOC 2]]></category>
  <category><![CDATA[Vendor Selection]]></category>


     <description><![CDATA[<p>Finding the right penetration testing company requires asking difficult questions. To show you what a strong answer looks like, we put these questions to ourselves. However, this is a mock interview with 7ASecurity, so answers will vary by provider. Use this as a guide for your conversations and what to listen for. Ask five different &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/08/how-to-interview-a-penetration-testing-company/">How to Interview a Penetration Testing Company Like a Pro (&#038; Our Answers)</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>Know What to Expect From a Penetration Test Before You Book</title>
  <link>https://7asecurity.com/blog/2026/08/what-to-expect-from-a-penetration-test/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 07 Aug 2026 08:25:09 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Cybersecurity Testing]]></category>
  <category><![CDATA[NIST SP 800-115]]></category>
  <category><![CDATA[Penetration Test Retesting]]></category>
  <category><![CDATA[Penetration Testing Process]]></category>
  <category><![CDATA[Pentest Reporting]]></category>
  <category><![CDATA[Pentest Scoping]]></category>
  <category><![CDATA[Pentest Timeline]]></category>
  <category><![CDATA[Security Auditing]]></category>
  <category><![CDATA[Vulnerability Assessment]]></category>
  <category><![CDATA[Vulnerability Remediation]]></category>


     <description><![CDATA[<p>What to Expect From a Penetration Test, From Scoping to Retest What to expect from a penetration test goes well beyond the final report. At least, that’s how we do it at 7ASecurity. Before testing starts, you'll agree on scope and hand over access. During testing, you're expected to stay reachable. Afterwards, you get a &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/08/what-to-expect-from-a-penetration-test/">Know What to Expect From a Penetration Test Before You Book</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>Pentest Services 101: Match the Test to Your Business Risk</title>
  <link>https://7asecurity.com/blog/2026/07/pentest-services-business-risk/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 31 Jul 2026 09:28:50 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[AI security testing]]></category>
  <category><![CDATA[Cloud Security Audit]]></category>
  <category><![CDATA[Code Audit]]></category>
  <category><![CDATA[Cybersecurity Compliance]]></category>
  <category><![CDATA[Mobile App Security]]></category>
  <category><![CDATA[network penetration testing]]></category>
  <category><![CDATA[penetration testing services]]></category>
  <category><![CDATA[Security Testing]]></category>
  <category><![CDATA[Vulnerability Assessment]]></category>
  <category><![CDATA[Web App Pentesting]]></category>


     <description><![CDATA[<p>Pentest Services Explained: Matching the Test to Your Situation Pentest services aren't one and all the same. This guide matches your situation, a new web app, a cloud migration, an AI feature, or a suspected internal risk, to the test or combination that fits. Scan the trigger table, read the scope notes for each service, &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/07/pentest-services-business-risk/">Pentest Services 101: Match the Test to Your Business Risk</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>14 Security Compliance Standards Every Business Owner Should Understand</title>
  <link>https://7asecurity.com/blog/2026/07/security-compliance-standards-for-business-owners/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 24 Jul 2026 09:05:52 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Business Compliance]]></category>
  <category><![CDATA[Business owners guide]]></category>
  <category><![CDATA[FISMA]]></category>
  <category><![CDATA[GDPR]]></category>
  <category><![CDATA[HIPAA]]></category>
  <category><![CDATA[ISO 27001]]></category>
  <category><![CDATA[PCI DSS]]></category>
  <category><![CDATA[security compliance]]></category>
  <category><![CDATA[Security Standards]]></category>
  <category><![CDATA[SOC 2]]></category>
  <category><![CDATA[SOX]]></category>
  <category><![CDATA[SWIFT CSP]]></category>


     <description><![CDATA[<p>Security compliance standards help businesses protect sensitive data, meet regulatory requirements, and build customer trust. This guide explains 14 essential frameworks, including ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, and more. Learn which standards apply to your business, avoid compliance risks, and create a stronger security foundation for long-term growth.</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/07/security-compliance-standards-for-business-owners/">14 Security Compliance Standards Every Business Owner Should Understand</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>How WPA3 Personal Transition Affects Internal Security Risk</title>
  <link>https://7asecurity.com/blog/2026/07/wpa3-transition-security-risk/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 17 Jul 2026 07:39:10 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[internal penetration testing]]></category>
  <category><![CDATA[IoT Security]]></category>
  <category><![CDATA[Network Security]]></category>
  <category><![CDATA[Network Segmentation]]></category>
  <category><![CDATA[offensive security]]></category>
  <category><![CDATA[Wi-Fi Security]]></category>
  <category><![CDATA[Wireless Security]]></category>
  <category><![CDATA[WPA2]]></category>
  <category><![CDATA[WPA3]]></category>
  <category><![CDATA[WPA3 Transition Mode]]></category>


     <description><![CDATA[<p>WPA3 Personal Transition Mode lets WPA2 and WPA3 devices connect to the same SSID during migration. It solves a real compatibility problem, but it keeps WPA2-era risk in play. Treat it as a time-limited bridge, not the target state. Document why it exists, isolate legacy devices, use strong passphrases, review PMF behaviour, and move trusted &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/07/wpa3-transition-security-risk/">How WPA3 Personal Transition Affects Internal Security Risk</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>Don&#039;t Let jQuery 3.5.1 Vulnerabilities Panic Your Risk Team</title>
  <link>https://7asecurity.com/blog/2026/07/jquery-3-5-1-vulnerabilities/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 17 Jul 2026 07:18:30 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Application Security]]></category>
  <category><![CDATA[Code Audit]]></category>
  <category><![CDATA[Cross-Site Scripting]]></category>
  <category><![CDATA[DOM Manipulation]]></category>
  <category><![CDATA[False Positives]]></category>
  <category><![CDATA[jQuery 3.5.1]]></category>
  <category><![CDATA[jQuery Vulnerabilities]]></category>
  <category><![CDATA[Vulnerability Scanners]]></category>
  <category><![CDATA[web application penetration testing]]></category>
  <category><![CDATA[XSS]]></category>


     <description><![CDATA[<p>Searches for jQuery 3.5.1 vulnerabilities often mix up older jQuery XSS issues with scanner noise. The major 2020 DOM manipulation flaws, CVE-2020-11022 and CVE-2020-11023, affected versions before 3.5.0. jQuery 3.5.1 followed 3.5.0 and kept those fixes while addressing a regression. Teams should still check loaded versions, old bundled copies, plugins, unsafe DOM insertion, and output &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/07/jquery-3-5-1-vulnerabilities/">Don&#039;t Let jQuery 3.5.1 Vulnerabilities Panic Your Risk Team</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>BOFs Explained: Protecting Your Network From Stealthy Attacks</title>
  <link>https://7asecurity.com/blog/2026/07/bofs-explained-protecting-your-network-from-stealthy-attacks/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 10 Jul 2026 09:58:41 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Beacon Object Files]]></category>
  <category><![CDATA[BOFs]]></category>
  <category><![CDATA[Cobalt Strike]]></category>
  <category><![CDATA[Endpoint Security]]></category>
  <category><![CDATA[offensive security]]></category>
  <category><![CDATA[Penetration Testing]]></category>
  <category><![CDATA[Post-Exploitation]]></category>
  <category><![CDATA[Red Teaming]]></category>
  <category><![CDATA[Security Testing]]></category>
  <category><![CDATA[Threat Detection]]></category>


     <description><![CDATA[<p>BOFs, or Beacon Object Files, are small compiled C object files that Cobalt Strike can load and run inside an existing Beacon process. They extend Beacon with focused post-exploitation tasks without creating a separate executable for each action. For defenders, BOFs matter because they change detection trade-offs. You need to look at behaviour, memory, API &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/07/bofs-explained-protecting-your-network-from-stealthy-attacks/">BOFs Explained: Protecting Your Network From Stealthy Attacks</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
  <item>
  <title>Don&#039;t Let a Misconfigured Cache DB Ruin Your Application</title>
  <link>https://7asecurity.com/blog/2026/07/misconfigured-cache-database/</link>

  <dc:creator><![CDATA[Admin]]></dc:creator>
  <pubDate>Fri, 10 Jul 2026 09:56:06 +0000</pubDate>
    <category><![CDATA[Blog]]></category>
  <category><![CDATA[Application Security]]></category>
  <category><![CDATA[Cache DB]]></category>
  <category><![CDATA[Cache Poisoning]]></category>
  <category><![CDATA[Cache Security]]></category>
  <category><![CDATA[cloud security]]></category>
  <category><![CDATA[In-Memory Store]]></category>
  <category><![CDATA[Memcached]]></category>
  <category><![CDATA[Penetration Testing]]></category>
  <category><![CDATA[Redis]]></category>
  <category><![CDATA[Web Cache Deception]]></category>


     <description><![CDATA[<p>A cache DB is a common search term for a cache layer, cache store, or in-memory data store. It keeps frequently used data close to the application to reduce latency and load. The security risk is simple: cached data still counts. Sessions, tokens, user records, API responses, authorisation state, browser cache files, and mobile cache &#8230;</p>
<p>The post <a rel="nofollow" href="https://7asecurity.com/blog/2026/07/misconfigured-cache-database/">Don&#039;t Let a Misconfigured Cache DB Ruin Your Application</a> appeared first on <a rel="nofollow" href="https://7asecurity.com/blog/">7ASecurity Blog</a>.</p>
]]></description>



   </item>
 </channel>
</rss>
