<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Darius J. Davis - Blog</title>
    <link>https://dariusjdavis.com/blog/</link>
    <description>Opinionated security notes from Darius J. Davis. CVE breakdowns, supply chain analysis, and honest takes on the state of security.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 07 Jun 2026 08:10:14 GMT</lastBuildDate>
    <atom:link href="https://dariusjdavis.com/blog/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Most Breaches Aren't Hacking. They're Human Failures.</title>
      <link>https://dariusjdavis.com/blog/the-hacking-myth/</link>
      <guid isPermaLink="true">https://dariusjdavis.com/blog/the-hacking-myth/</guid>
      <pubDate>Mon, 01 Jun 2026 12:00:00 GMT</pubDate>
      <category>Opinion</category>
      <description>The world loves the word 'hack.' The reality is that the biggest threat to any organization is the people inside it. Phishing, insider threats, default passwords, leaked credentials, or just someone holding the door open for a stranger.</description>
    </item>
    <item>
      <title>Redis Has Had a CVSS 10 RCE for 13 Years</title>
      <link>https://dariusjdavis.com/blog/redis-13-year-rce/</link>
      <guid isPermaLink="true">https://dariusjdavis.com/blog/redis-13-year-rce/</guid>
      <pubDate>Sun, 31 May 2026 12:00:00 GMT</pubDate>
      <category>CVE</category>
      <description>A use-after-free in Redis's Lua scripting engine has been sitting there since 2012. CVSS 10. If you run Redis, you're probably affected. Nobody noticed for over a decade.</description>
    </item>
    <item>
      <title>CVE-2026-39987: An AI Agent Got Root on a Database</title>
      <link>https://dariusjdavis.com/blog/cve-2026-ai-agent-database/</link>
      <guid isPermaLink="true">https://dariusjdavis.com/blog/cve-2026-ai-agent-database/</guid>
      <pubDate>Fri, 29 May 2026 12:00:00 GMT</pubDate>
      <category>CVE / AI Security</category>
      <description>An LLM agent with notebook access exploited a misconfigured database in under an hour. No human attacker involved, just an agent doing what it was told.</description>
    </item>
    <item>
      <title>160 npm Packages Compromised. Auto-Update Did This.</title>
      <link>https://dariusjdavis.com/blog/npm-supply-chain-160-packages/</link>
      <guid isPermaLink="true">https://dariusjdavis.com/blog/npm-supply-chain-160-packages/</guid>
      <pubDate>Thu, 28 May 2026 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <description>Attackers hijacked a maintainer token and pushed malicious code to 160+ npm packages. Every project with auto-update pulled it in automatically. The 'hack' was npm doing what it was designed to do.</description>
    </item>
    <item>
      <title>xz Utils: A Two-Year Social Engineering Job</title>
      <link>https://dariusjdavis.com/blog/xz-utils-backdoor/</link>
      <guid isPermaLink="true">https://dariusjdavis.com/blog/xz-utils-backdoor/</guid>
      <pubDate>Fri, 29 Mar 2024 12:00:00 GMT</pubDate>
      <category>Supply Chain</category>
      <description>A maintainer spent two years earning trust in an open-source project to slip a backdoor into the build process. This wasn't a technical exploit. It was social engineering with a very long fuse.</description>
    </item>
  </channel>
</rss>