<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>RDN Security</title>
  <link>https://rdnsec.info/</link>
  <description>Malware and hardware security research by Radek Zdonczyk</description>
  <language>en</language>
  <atom:link href="https://rdnsec.info/feed.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>Honeypot Recon: New Variant of SkidMap Targeting Redis</title>
    <link>https://rdnsec.info/articles/skidmap-redis-honeypot/</link>
    <guid>https://rdnsec.info/articles/skidmap-redis-honeypot/</guid>
    <pubDate>Sun, 30 Jul 2023 00:00:00 +0000</pubDate>
    <description>An unauthenticated Redis instance, a base64 cron job, and a rootkit-equipped cryptominer that ClamAV walked straight past.</description>
  </item>
  <item>
    <title>Honeypot Recon: Global Database Threat Landscape</title>
    <link>https://rdnsec.info/articles/global-database-threat-landscape/</link>
    <guid>https://rdnsec.info/articles/global-database-threat-landscape/</guid>
    <pubDate>Tue, 13 Jun 2023 00:00:00 +0000</pubDate>
    <description>Six countries, nine database engines, four months of data — and one engine absorbing over 93% of every login attempt.</description>
  </item>
  <item>
    <title>Typosquatting in Python Repositories</title>
    <link>https://rdnsec.info/articles/typosquatting-python-repositories/</link>
    <guid>https://rdnsec.info/articles/typosquatting-python-repositories/</guid>
    <pubDate>Fri, 13 Dec 2019 00:00:00 +0000</pubDate>
    <description>Two PyPI packages impersonated python-dateutil and jellyfish with lookalike names, then quietly harvested SSH and GPG keys from developer machines.</description>
  </item>
</channel>
</rss>
