<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Recon Main Blog</title>
    <link>https://blog.reconinfosec.com</link>
    <description />
    <language>en</language>
    <pubDate>Wed, 10 Jun 2026 04:36:31 GMT</pubDate>
    <dc:date>2026-06-10T04:36:31Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Case Study: A County’s Journey from Chasing Alerts to Stopping Threats</title>
      <link>https://blog.reconinfosec.com/case-study-a-countys-journey-from-chasing-alerts-to-stopping-threats</link>
      <description>&lt;h2 style="font-weight: normal;"&gt;&lt;img src="https://blog.reconinfosec.com/hs-fs/hubfs/city-flag-cropped.jpg?width=1920&amp;amp;height=1080&amp;amp;name=city-flag-cropped.jpg" width="1920" height="1080" alt="city-flag-cropped" style="height: auto; max-width: 100%; width: 1920px;"&gt;&lt;/h2&gt; 
&lt;h2 style="font-weight: normal;"&gt;Lean Team, Big Responsibility&lt;/h2&gt; 
&lt;p&gt;A mid-sized Texas county government was managing its entire technology operation with a lean IT team who were responsible for everything from daily work orders and access control to security camera networks and call management. When a new IT Director stepped into his role, cybersecurity had never had a dedicated owner. That was about to change.&lt;/p&gt;</description>
      <content:encoded>&lt;h2 style="font-weight: normal;"&gt;&lt;img src="https://blog.reconinfosec.com/hs-fs/hubfs/city-flag-cropped.jpg?width=1920&amp;amp;height=1080&amp;amp;name=city-flag-cropped.jpg" width="1920" height="1080" alt="city-flag-cropped" style="height: auto; max-width: 100%; width: 1920px;"&gt;&lt;/h2&gt; 
&lt;h2 style="font-weight: normal;"&gt;Lean Team, Big Responsibility&lt;/h2&gt; 
&lt;p&gt;A mid-sized Texas county government was managing its entire technology operation with a lean IT team who were responsible for everything from daily work orders and access control to security camera networks and call management. When a new IT Director stepped into his role, cybersecurity had never had a dedicated owner. That was about to change.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fcase-study-a-countys-journey-from-chasing-alerts-to-stopping-threats&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 10 Jun 2026 04:36:31 GMT</pubDate>
      <guid>https://blog.reconinfosec.com/case-study-a-countys-journey-from-chasing-alerts-to-stopping-threats</guid>
      <dc:date>2026-06-10T04:36:31Z</dc:date>
      <dc:creator>Recon Team</dc:creator>
    </item>
    <item>
      <title>Cross-Org Visibility for LimaCharlie</title>
      <link>https://blog.reconinfosec.com/cross-org-visibility-for-limacharlie</link>
      <description>&lt;p&gt;At Recon InfoSec we run many aspects of our security operations on &lt;a href="https://limacharlie.io/"&gt;LimaCharlie&lt;/a&gt;. It's an API-first EDR platform that gives us total control over how we build and run our security stack. We can deploy sensors across any environment, and from there we have complete flexibility. We bring in telemetry from virtually any source and process it at wire speed with detection and response actions that we write and tune, plus we have infinite knobs and dials to adjust everything from what telemetry we’re surfacing, to how it is transformed through the system, and what we finally pass on for post processing. Instead of working around a vendor's assumptions about how security operations should look, we build the exact platform we need to best serve our customers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;At Recon InfoSec we run many aspects of our security operations on &lt;a href="https://limacharlie.io/"&gt;LimaCharlie&lt;/a&gt;. It's an API-first EDR platform that gives us total control over how we build and run our security stack. We can deploy sensors across any environment, and from there we have complete flexibility. We bring in telemetry from virtually any source and process it at wire speed with detection and response actions that we write and tune, plus we have infinite knobs and dials to adjust everything from what telemetry we’re surfacing, to how it is transformed through the system, and what we finally pass on for post processing. Instead of working around a vendor's assumptions about how security operations should look, we build the exact platform we need to best serve our customers.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fcross-org-visibility-for-limacharlie&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Open Source</category>
      <category>LimaCharlie</category>
      <pubDate>Wed, 03 Jun 2026 04:48:36 GMT</pubDate>
      <guid>https://blog.reconinfosec.com/cross-org-visibility-for-limacharlie</guid>
      <dc:date>2026-06-03T04:48:36Z</dc:date>
      <dc:creator>Ben Webb</dc:creator>
    </item>
    <item>
      <title>What's Actually Hitting Organizations Right Now: ClickFix, Identity Compromise, and AI-Powered Risk</title>
      <link>https://blog.reconinfosec.com/whats-actually-hitting-organizations-right-now</link>
      <description>&lt;p&gt;Every day at Recon InfoSec we’re thinking about one thing: how are we giving bad guys headaches? To do that well, you have to stay close to what those bad guys are actually doing. So let me share what we're seeing in the field right now, because some of it is more creative than some people realize.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Every day at Recon InfoSec we’re thinking about one thing: how are we giving bad guys headaches? To do that well, you have to stay close to what those bad guys are actually doing. So let me share what we're seeing in the field right now, because some of it is more creative than some people realize.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fwhats-actually-hitting-organizations-right-now&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 08 May 2026 20:31:59 GMT</pubDate>
      <author>acook@reconinfosec.com (Andrew Cook)</author>
      <guid>https://blog.reconinfosec.com/whats-actually-hitting-organizations-right-now</guid>
      <dc:date>2026-05-08T20:31:59Z</dc:date>
    </item>
    <item>
      <title>Iranian Government Affiliated Intrusions: Documented Tradecraft</title>
      <link>https://blog.reconinfosec.com/iranian-government-affiliated-intrusions-documented-tradecraft</link>
      <description>&lt;p&gt;When geopolitical tensions rise, defenders tend to ask the same question: What does Iranian cyber activity actually look like on the wire?&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When geopolitical tensions rise, defenders tend to ask the same question: What does Iranian cyber activity actually look like on the wire?&lt;/p&gt;   
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Firanian-government-affiliated-intrusions-documented-tradecraft&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 03 Mar 2026 18:48:12 GMT</pubDate>
      <author>luke@reconinfosec.com (Luke Rusten)</author>
      <guid>https://blog.reconinfosec.com/iranian-government-affiliated-intrusions-documented-tradecraft</guid>
      <dc:date>2026-03-03T18:48:12Z</dc:date>
    </item>
    <item>
      <title>ClawHype: Making Sense of Recent AI Cybersecurity News</title>
      <link>https://blog.reconinfosec.com/clawdhype-making-sense-of-recent-ai-cybersecurity-news</link>
      <description>&lt;div&gt;  
 &lt;p&gt;&lt;strong&gt;Editor note:&lt;/strong&gt; &lt;em&gt;The sudden rise and crash of OpenClaw and Moltbook have been wild. The media will move on, but the story isn’t over for IT teams dealing with the risks posed by unauthorized AI. In this Q&amp;amp;A, Nick Lupien (Head of Recon Labs) will help make sense of the recent news and offer broader AI governance advice.&lt;/em&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;em&gt;&lt;img src="https://blog.reconinfosec.com/hs-fs/hubfs/clawdhype-banner.jpg?width=1920&amp;amp;height=1080&amp;amp;name=clawdhype-banner.jpg" width="1920" height="1080" alt="clawdhype-banner" style="height: auto; max-width: 100%; width: 1920px; margin-left: auto; margin-right: auto; display: block;"&gt;&lt;/em&gt;&lt;/p&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;What would an IT manager need to know about the OpenClaw and Moltbook security issues? What makes these security issues different from others?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;At this stage, it’s probably best to treat OpenClaw (formerly Moltbot, formerly Clawdbot) like malware. In order for OpenClaw to perform its stated function (a local personal assistant), it requires &lt;strong&gt;significant access to private data, arbitrary code execution privileges,&lt;/strong&gt; and &lt;strong&gt;absolute autonomy without human approval.&lt;/strong&gt; This combination is dangerous even without AI, but it’s particularly concerning when you consider that AI is vulnerable to &lt;strong&gt;prompt injection&lt;/strong&gt; (other people trying to trick your agent into acting against your best interests) and &lt;strong&gt;misalignment&lt;/strong&gt; (the model underneath providing inaccurate data and suggestions).&lt;/p&gt; 
   &lt;p&gt;These are both “forever problems” with large language models, and they’re the reason we put “humans in the loop” for critical functions like sending emails or texts or executing code in privileged contexts. When you hand the keys over to an agent that will automatically act on your behalf, you’re taking immeasurable risk with not only your data, but that of everyone you interact with. It’s like turning on full car automation on untested infrastructure and then going to sleep. It raises serious concerns.&lt;/p&gt; 
   &lt;p&gt;Moltbook is a public “Reddit-like” social media site that OpenClaw agents interact with autonomously. There have already been &lt;a href="https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys"&gt;reports of massive data loss&lt;/a&gt; due to an improperly configured database. Though this and other vulnerabilities have been addressed, it’s the clearest example yet of the threats posed by OpenClaw, and it’s likely not the last.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;Employees have always used unauthorized apps at work. How is that problem different now with AI tools?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Unauthorized/unvetted apps are still a big problem and contribute to significant losses for companies every year. The type of risk is the same: loss of confidentiality and integrity when the application misbehaves, whether through malicious activity or accidental misuse. The addition of AI significantly increases the &lt;strong&gt;magnitude&lt;/strong&gt; of the threat: they are &lt;strong&gt;more likely to be exploited&lt;/strong&gt;, and the effects of misuse are &lt;strong&gt;significantly more damaging&lt;/strong&gt; to you, your organization, and everyone you interact with.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;How do I decide whether to allow AI tools at our company? What safety measures must I put in place to protect our data and systems?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Stepping back, I wouldn’t conflate OpenClaw with most “AI tools.” There are many AI tools like Claude, Gemini, and ChatGPT that have mechanisms to control human-in-the-loop and that encourage good security practices. The best safety measures we’ve seen are proactive ones: provide people with vetted tools, and train them on best practices for interacting with confidential data. All of the large providers have a “no training on customer data” option for paid subscribers, and some have zero data retention policies available. Research and understand these features before deciding on a platform. Search for “Trust Center” with the products you’re considering to fully understand their compliance environments. For enterprise deployments, look for features like audit logs, admin controls, and SSO integration.&lt;/p&gt; 
   &lt;p&gt;Deciding whether to allow AI tools at your company is a risk/benefit discussion. The risks of a trained workforce using vetted tools can be controlled but are never completely mitigated. Apps change quickly, and new features may introduce new risks that require significant, ongoing attention. If you decide to embrace AI, commit to one or two products at first, and create a plan to keep up with changes to those products. Even vetted tools require good policy around integrations and human approvals.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;If employees are already using unauthorized AI tools, how do I find out and what should I do about it?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Prevention is really the first step. Decide on a path that satisfies employee and company needs, create a policy, communicate it, and enforce it.&lt;/p&gt; 
   &lt;p&gt;Surveying / Enforcing: if you have a managed security provider or security operations center, have a conversation with them about detecting unauthorized software installations or visits to unauthorized sites. They will have a number of tools at their disposal to detect and surface unauthorized use.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;What are the most important security rules IT leaders should follow when dealing with AI? What security basics stay the same even as technology changes?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Never grant an AI agent “modify” or “execute” permissions against a system that processes confidential data without a human approver.&lt;/p&gt; 
   &lt;p&gt;The concept of &lt;strong&gt;“least privilege”&lt;/strong&gt; underscores this entire conversation. Would you allow an intern to commit code to your production codebase without a senior engineer’s review and approval? Would you allow them to send emails to the CEOs of your customers without reviewing or approving them? Least privilege isn’t new, but people placing total trust in LLM agents is. Generally, you can’t have both.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;Where can IT managers go to keep learning about AI security threats and how to handle them?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;The Center for AI Safety (&lt;a href="https://safe.ai/"&gt;https://safe.ai/&lt;/a&gt;) is a non-profit dedicated to reducing societal-scale risk from AI. Their newsletter addresses current events pertaining to AI risk, including cyber risks.&lt;/p&gt; 
   &lt;p&gt;Anthropic Academy has several great courses around AI fluency and technical expertise: &lt;a href="https://anthropic.skilljar.com/"&gt;https://anthropic.skilljar.com/&lt;/a&gt;&lt;/p&gt; 
   &lt;p&gt;As always, monitor vendor security advisories and CVE databases for AI-related vulnerabilities.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;What's one thing an IT manager can do this week to immediately improve AI security?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Create a policy that provides a governable path to individuals using AI safely and responsibly, and commit to supporting and enforcing it.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;  
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt;  
 &lt;p&gt;&lt;strong&gt;Editor note:&lt;/strong&gt; &lt;em&gt;The sudden rise and crash of OpenClaw and Moltbook have been wild. The media will move on, but the story isn’t over for IT teams dealing with the risks posed by unauthorized AI. In this Q&amp;amp;A, Nick Lupien (Head of Recon Labs) will help make sense of the recent news and offer broader AI governance advice.&lt;/em&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;em&gt;&lt;img src="https://blog.reconinfosec.com/hs-fs/hubfs/clawdhype-banner.jpg?width=1920&amp;amp;height=1080&amp;amp;name=clawdhype-banner.jpg" width="1920" height="1080" alt="clawdhype-banner" style="height: auto; max-width: 100%; width: 1920px; margin-left: auto; margin-right: auto; display: block;"&gt;&lt;/em&gt;&lt;/p&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;What would an IT manager need to know about the OpenClaw and Moltbook security issues? What makes these security issues different from others?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;At this stage, it’s probably best to treat OpenClaw (formerly Moltbot, formerly Clawdbot) like malware. In order for OpenClaw to perform its stated function (a local personal assistant), it requires &lt;strong&gt;significant access to private data, arbitrary code execution privileges,&lt;/strong&gt; and &lt;strong&gt;absolute autonomy without human approval.&lt;/strong&gt; This combination is dangerous even without AI, but it’s particularly concerning when you consider that AI is vulnerable to &lt;strong&gt;prompt injection&lt;/strong&gt; (other people trying to trick your agent into acting against your best interests) and &lt;strong&gt;misalignment&lt;/strong&gt; (the model underneath providing inaccurate data and suggestions).&lt;/p&gt; 
   &lt;p&gt;These are both “forever problems” with large language models, and they’re the reason we put “humans in the loop” for critical functions like sending emails or texts or executing code in privileged contexts. When you hand the keys over to an agent that will automatically act on your behalf, you’re taking immeasurable risk with not only your data, but that of everyone you interact with. It’s like turning on full car automation on untested infrastructure and then going to sleep. It raises serious concerns.&lt;/p&gt; 
   &lt;p&gt;Moltbook is a public “Reddit-like” social media site that OpenClaw agents interact with autonomously. There have already been &lt;a href="https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys"&gt;reports of massive data loss&lt;/a&gt; due to an improperly configured database. Though this and other vulnerabilities have been addressed, it’s the clearest example yet of the threats posed by OpenClaw, and it’s likely not the last.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;Employees have always used unauthorized apps at work. How is that problem different now with AI tools?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Unauthorized/unvetted apps are still a big problem and contribute to significant losses for companies every year. The type of risk is the same: loss of confidentiality and integrity when the application misbehaves, whether through malicious activity or accidental misuse. The addition of AI significantly increases the &lt;strong&gt;magnitude&lt;/strong&gt; of the threat: they are &lt;strong&gt;more likely to be exploited&lt;/strong&gt;, and the effects of misuse are &lt;strong&gt;significantly more damaging&lt;/strong&gt; to you, your organization, and everyone you interact with.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;How do I decide whether to allow AI tools at our company? What safety measures must I put in place to protect our data and systems?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Stepping back, I wouldn’t conflate OpenClaw with most “AI tools.” There are many AI tools like Claude, Gemini, and ChatGPT that have mechanisms to control human-in-the-loop and that encourage good security practices. The best safety measures we’ve seen are proactive ones: provide people with vetted tools, and train them on best practices for interacting with confidential data. All of the large providers have a “no training on customer data” option for paid subscribers, and some have zero data retention policies available. Research and understand these features before deciding on a platform. Search for “Trust Center” with the products you’re considering to fully understand their compliance environments. For enterprise deployments, look for features like audit logs, admin controls, and SSO integration.&lt;/p&gt; 
   &lt;p&gt;Deciding whether to allow AI tools at your company is a risk/benefit discussion. The risks of a trained workforce using vetted tools can be controlled but are never completely mitigated. Apps change quickly, and new features may introduce new risks that require significant, ongoing attention. If you decide to embrace AI, commit to one or two products at first, and create a plan to keep up with changes to those products. Even vetted tools require good policy around integrations and human approvals.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;If employees are already using unauthorized AI tools, how do I find out and what should I do about it?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Prevention is really the first step. Decide on a path that satisfies employee and company needs, create a policy, communicate it, and enforce it.&lt;/p&gt; 
   &lt;p&gt;Surveying / Enforcing: if you have a managed security provider or security operations center, have a conversation with them about detecting unauthorized software installations or visits to unauthorized sites. They will have a number of tools at their disposal to detect and surface unauthorized use.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;What are the most important security rules IT leaders should follow when dealing with AI? What security basics stay the same even as technology changes?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Never grant an AI agent “modify” or “execute” permissions against a system that processes confidential data without a human approver.&lt;/p&gt; 
   &lt;p&gt;The concept of &lt;strong&gt;“least privilege”&lt;/strong&gt; underscores this entire conversation. Would you allow an intern to commit code to your production codebase without a senior engineer’s review and approval? Would you allow them to send emails to the CEOs of your customers without reviewing or approving them? Least privilege isn’t new, but people placing total trust in LLM agents is. Generally, you can’t have both.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;Where can IT managers go to keep learning about AI security threats and how to handle them?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;The Center for AI Safety (&lt;a href="https://safe.ai/"&gt;https://safe.ai/&lt;/a&gt;) is a non-profit dedicated to reducing societal-scale risk from AI. Their newsletter addresses current events pertaining to AI risk, including cyber risks.&lt;/p&gt; 
   &lt;p&gt;Anthropic Academy has several great courses around AI fluency and technical expertise: &lt;a href="https://anthropic.skilljar.com/"&gt;https://anthropic.skilljar.com/&lt;/a&gt;&lt;/p&gt; 
   &lt;p&gt;As always, monitor vendor security advisories and CVE databases for AI-related vulnerabilities.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;   
 &lt;h2 style="font-size: 24px; font-weight: normal;"&gt;What's one thing an IT manager can do this week to immediately improve AI security?&lt;/h2&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;p&gt;Create a policy that provides a governable path to individuals using AI safely and responsibly, and commit to supporting and enforcing it.&lt;/p&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;  
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fclawdhype-making-sense-of-recent-ai-cybersecurity-news&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI Security</category>
      <pubDate>Fri, 06 Feb 2026 00:09:37 GMT</pubDate>
      <guid>https://blog.reconinfosec.com/clawdhype-making-sense-of-recent-ai-cybersecurity-news</guid>
      <dc:date>2026-02-06T00:09:37Z</dc:date>
      <dc:creator>Nicholas Lupien</dc:creator>
    </item>
    <item>
      <title>Planning for the Worst: Making IR, BC, and DR Plans Work</title>
      <link>https://blog.reconinfosec.com/planning-for-the-worst-making-ir-bc-and-dr-plans-work</link>
      <description>&lt;p&gt;Organizations know they should have plans for cyber incidents, but too often those plans are outdated, incomplete, or untested. Incident Response (IR), Business Continuity Plans (BCP), and Disaster Recovery (DR) plans are frequently treated as check-the-box documents instead of living, operational playbooks. The real cost of that mindset becomes painfully clear during a major cyber incident.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Organizations know they should have plans for cyber incidents, but too often those plans are outdated, incomplete, or untested. Incident Response (IR), Business Continuity Plans (BCP), and Disaster Recovery (DR) plans are frequently treated as check-the-box documents instead of living, operational playbooks. The real cost of that mindset becomes painfully clear during a major cyber incident.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fplanning-for-the-worst-making-ir-bc-and-dr-plans-work&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Incident Response</category>
      <category>Operations</category>
      <pubDate>Fri, 09 Jan 2026 17:32:15 GMT</pubDate>
      <author>mthompson@reconinfosec.com (Macie Thompson)</author>
      <guid>https://blog.reconinfosec.com/planning-for-the-worst-making-ir-bc-and-dr-plans-work</guid>
      <dc:date>2026-01-09T17:32:15Z</dc:date>
    </item>
    <item>
      <title>Case Study: From Running Blind to Active Defense</title>
      <link>https://blog.reconinfosec.com/case-study-from-running-blind-to-active-defense</link>
      <description>&lt;p style="font-weight: bold;"&gt;&lt;em&gt;How a Mid-Size Energy Infrastructure Company Achieved 95%+ Security Score and Peace of Mind&lt;/em&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: bold;"&gt;&lt;em&gt;How a Mid-Size Energy Infrastructure Company Achieved 95%+ Security Score and Peace of Mind&lt;/em&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fcase-study-from-running-blind-to-active-defense&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Thu, 04 Dec 2025 19:44:26 GMT</pubDate>
      <guid>https://blog.reconinfosec.com/case-study-from-running-blind-to-active-defense</guid>
      <dc:date>2025-12-04T19:44:26Z</dc:date>
      <dc:creator>Recon Team</dc:creator>
    </item>
    <item>
      <title>A Pragmatic Approach to Vulnerability Management</title>
      <link>https://blog.reconinfosec.com/a-pragmatic-approach-to-vulnerability-management</link>
      <description />
      <content:encoded>&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fa-pragmatic-approach-to-vulnerability-management&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Operations</category>
      <category>InfoSec</category>
      <category>Monitoring</category>
      <category>Infrastructure</category>
      <category>Vulnerability</category>
      <category>Risk Management</category>
      <pubDate>Mon, 10 Nov 2025 13:23:04 GMT</pubDate>
      <guid>https://blog.reconinfosec.com/a-pragmatic-approach-to-vulnerability-management</guid>
      <dc:date>2025-11-10T13:23:04Z</dc:date>
      <dc:creator>Ben Webb</dc:creator>
    </item>
    <item>
      <title>Every Pentest Makes us Better</title>
      <link>https://blog.reconinfosec.com/closing-the-loop-how-recon-infosec-uses-pentests</link>
      <description>&lt;p&gt;Penetration tests reveal the true strength of your organization’s security posture. Approached correctly, they also serve an important role in continuously improving your ability to find and stop real threats quickly. At Recon InfoSec, we view our customers’ penetration tests as invaluable opportunities to test and improve our detection capabilities against skilled attackers in a controlled environment.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Penetration tests reveal the true strength of your organization’s security posture. Approached correctly, they also serve an important role in continuously improving your ability to find and stop real threats quickly. At Recon InfoSec, we view our customers’ penetration tests as invaluable opportunities to test and improve our detection capabilities against skilled attackers in a controlled environment.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fclosing-the-loop-how-recon-infosec-uses-pentests&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>SecOps</category>
      <category>SOC</category>
      <category>MSO</category>
      <pubDate>Wed, 08 Oct 2025 18:06:26 GMT</pubDate>
      <author>acook@reconinfosec.com (Andrew Cook)</author>
      <guid>https://blog.reconinfosec.com/closing-the-loop-how-recon-infosec-uses-pentests</guid>
      <dc:date>2025-10-08T18:06:26Z</dc:date>
    </item>
    <item>
      <title>Delivering AI Superpowers to Security Teams: Introducing Recon Labs</title>
      <link>https://blog.reconinfosec.com/introducing-recon-labs</link>
      <description>&lt;p&gt;Recon InfoSec, a leader in managed security operations, is proud to announce the creation of &lt;span style="font-weight: bold;"&gt;Recon Labs&lt;/span&gt;, our internal R&amp;amp;D organization that delivers superpowers to your security teams.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recon InfoSec, a leader in managed security operations, is proud to announce the creation of &lt;span style="font-weight: bold;"&gt;Recon Labs&lt;/span&gt;, our internal R&amp;amp;D organization that delivers superpowers to your security teams.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=7101814&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.reconinfosec.com%2Fintroducing-recon-labs&amp;amp;bu=https%253A%252F%252Fblog.reconinfosec.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 22 Sep 2025 21:39:15 GMT</pubDate>
      <guid>https://blog.reconinfosec.com/introducing-recon-labs</guid>
      <dc:date>2025-09-22T21:39:15Z</dc:date>
      <dc:creator>Nicholas Lupien</dc:creator>
    </item>
  </channel>
</rss>
