<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Kuboid - Agency Automation &amp; AI Systems Blog</title>
    <description>Operational playbooks and technical guides on agency workflow automation, client onboarding, Friday KPI reporting, and production AI systems.</description>
    <link>https://www.kuboid.in/blog</link>
    <atom:link href="https://www.kuboid.in/rss.xml" rel="self" type="application/rss+xml"/>
    <language>en-us</language>
    <lastBuildDate>Mon, 28 Sep 2026 12:50:52 GMT</lastBuildDate>
    <item>
      <title>Speed to Lead: Why the 60-Second Rule Is Not the Real Problem</title>
      <link>https://www.kuboid.in/blog/speed-to-lead-60-second-rule</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/speed-to-lead-60-second-rule</guid>
      <description>The famous speed-to-lead statistics are older and narrower than most suggest. The real problem is simpler: leads arrive, nobody owns them, and they vanish.</description>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
      <category>Speed to Lead</category>
      <category>Lead Response Time</category>
      <category>Sales Automation</category>
      <category>AI Automation</category>
      <category>Agency Operations</category>
      <category>Lead Management</category>
    </item>
    <item>
      <title>How to Automate Agency Client Onboarding in Under 3 Minutes</title>
      <link>https://www.kuboid.in/blog/how-to-automate-agency-client-onboarding</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/how-to-automate-agency-client-onboarding</guid>
      <description>Stop wasting hours per client on manual folder provisioning and intake forms. Discover the exact production pipeline to automate agency client onboarding.</description>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
      <category>Agency Automation</category>
      <category>Client Onboarding</category>
      <category>Operations</category>
      <category>n8n</category>
    </item>
    <item>
      <title>AI Automation vs Zapier: When Simple Workflows Stop Working</title>
      <link>https://www.kuboid.in/blog/ai-automation-vs-zapier-when-simple-workflows-break</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/ai-automation-vs-zapier-when-simple-workflows-break</guid>
      <description>Zapier and Make are great for prototypes, but relying on them for agency deliverables causes silent failures that eat margins. Learn how to upgrade.</description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>AI Automation</category>
      <category>System Architecture</category>
      <category>Agency Operations</category>
      <category>Zapier</category>
    </item>
    <item>
      <title>How Agencies Can Automate Weekly Client KPI Reporting</title>
      <link>https://www.kuboid.in/blog/how-agencies-can-automate-weekly-client-reporting</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/how-agencies-can-automate-weekly-client-reporting</guid>
      <description>Account managers waste hours every Friday pulling ad data into manual spreadsheets. Learn how to build an automated reporting engine with AI summaries.</description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <category>Agency Automation</category>
      <category>Client Reporting</category>
      <category>Claude API</category>
      <category>Operations</category>
    </item>
    <item>
      <title>How to Calculate ROI Before Building an AI Automation</title>
      <link>https://www.kuboid.in/blog/how-to-calculate-roi-before-building-ai-automation</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/how-to-calculate-roi-before-building-ai-automation</guid>
      <description>Never build an automation without knowing its commercial payback period. Discover the exact mathematical model to evaluate automation ROI for your agency.</description>
      <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
      <category>Agency Operations</category>
      <category>ROI Calculator</category>
      <category>AI Automation</category>
      <category>Operations</category>
    </item>
    <item>
      <title>15 Agency Tasks You Should Never Do Manually</title>
      <link>https://www.kuboid.in/blog/15-agency-tasks-you-should-never-do-manually</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/15-agency-tasks-you-should-never-do-manually</guid>
      <description>If your team is manually copying data and writing prospect dossiers, your profit margins are leaking. Here are 15 agency tasks to automate immediately.</description>
      <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
      <category>Agency Operations</category>
      <category>Productivity</category>
      <category>Workflow Automation</category>
    </item>
    <item>
      <title>When Should a Growing Company Hire a Fractional CTO?</title>
      <link>https://www.kuboid.in/blog/when-should-a-growing-company-hire-a-fractional-cto</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/when-should-a-growing-company-hire-a-fractional-cto</guid>
      <description>When your tech stack and engineering team need leadership, a $300K full-time executive is often overkill. Learn when to bring on a Fractional AI CTO.</description>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <category>Fractional CTO</category>
      <category>Engineering Leadership</category>
      <category>System Architecture</category>
    </item>
    <item>
      <title>Business Logic Vulnerabilities: What They Are and Why Automated Tools Can&apos;t Find Them</title>
      <link>https://www.kuboid.in/blog/business-logic-vulnerabilities-what-they-are-why-automation-cant-find-them</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/business-logic-vulnerabilities-what-they-are-why-automation-cant-find-them</guid>
      <description>Business logic vulnerabilities are the most financially damaging class of web security flaw  and completely invisible to automated scanning. Here&apos;s what they are, real examples, and how to test for them.</description>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <category>Business Logic Vulnerabilities</category>
      <category>Web App Security</category>
      <category>Penetration Testing</category>
      <category>Manual Testing</category>
      <category>Application Security</category>
    </item>
    <item>
      <title>Internal Tools Security: Why Your Admin Portals Are Your Biggest Vulnerability</title>
      <link>https://www.kuboid.in/blog/internal-tools-security-admin-portals-biggest-vulnerability</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/internal-tools-security-admin-portals-biggest-vulnerability</guid>
      <description>A 19-year-old used compromised credentials to log into PowerSchool&apos;s support portal  no MFA, no additional verification  and walked out with data on 62 million students and teachers. Your internal tools are almost certainly your softest target. Here&apos;s what to do about it.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
      <category>Internal Tools Security</category>
      <category>Admin Portal Security</category>
      <category>MFA</category>
      <category>PowerSchool Breach</category>
      <category>Zero Trust</category>
      <category>Vendor Access</category>
    </item>
    <item>
      <title>How to Choose a Penetration Testing Provider: Red Flags, Green Flags, and the Right Questions</title>
      <link>https://www.kuboid.in/blog/how-to-choose-a-penetration-testing-provider-red-flags-green-flags</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/how-to-choose-a-penetration-testing-provider-red-flags-green-flags</guid>
      <description>Not all penetration tests are created equal. Some are scanner reports with a human signature. Here&apos;s exactly what to ask before you pay  the red flags that reveal automation masquerading as manual testing, and the green flags that show genuine expertise.</description>
      <pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate>
      <category>Penetration Testing</category>
      <category>Security Buying Guide</category>
      <category>Vendor Selection</category>
      <category>Web App Security</category>
      <category>CTO Guide</category>
    </item>
    <item>
      <title>Automated vs Manual Penetration Testing for Startups: The Right Hybrid Model in 2026</title>
      <link>https://www.kuboid.in/blog/automated-vs-manual-penetration-testing-startups-hybrid-model-2026</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/automated-vs-manual-penetration-testing-startups-hybrid-model-2026</guid>
      <description>Automated testing and manual pen testing are not competitors. Here&apos;s exactly which to use for what, when to do each, and how startups build the right security testing stack without overspending.</description>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <category>Penetration Testing</category>
      <category>Startups</category>
      <category>Security Testing</category>
      <category>Automated Scanning</category>
      <category>Hybrid Security</category>
      <category>Cyber Insurance</category>
    </item>
    <item>
      <title>Vulnerability Chaining: How Attackers Combine Low-Severity Bugs Into Critical Breaches</title>
      <link>https://www.kuboid.in/blog/vulnerability-chaining-how-attackers-combine-low-severity-bugs-into-critical-breaches</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/vulnerability-chaining-how-attackers-combine-low-severity-bugs-into-critical-breaches</guid>
      <description>Three medium and low severity findings. One complete account takeover. Here&apos;s how vulnerability chaining works  and why your automated scan report&apos;s severity ratings are misleading you.</description>
      <pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Chaining</category>
      <category>Penetration Testing</category>
      <category>Attack Paths</category>
      <category>Web App Security</category>
      <category>Manual Testing</category>
      <category>CVSS</category>
    </item>
    <item>
      <title>Why a Clean Vulnerability Scan Report Can Be Your Biggest Security Risk</title>
      <link>https://www.kuboid.in/blog/clean-vulnerability-scan-report-biggest-security-risk</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/clean-vulnerability-scan-report-biggest-security-risk</guid>
      <description>The Samsung Germany breach used 4-year-old credentials that were never rotated. The Change Healthcare breach exploited a missing MFA control. Neither would show up on a vulnerability scanner. Here&apos;s what clean reports miss.</description>
      <pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate>
      <category>Vulnerability Scanning</category>
      <category>Penetration Testing</category>
      <category>Credential Security</category>
      <category>MFA</category>
      <category>Security Posture</category>
      <category>Real World Breaches</category>
    </item>
    <item>
      <title>The Axios Supply Chain Attack Explained: How a Compromised npm Account Put 83 Million Projects at Risk</title>
      <link>https://www.kuboid.in/blog/axios-npm-supply-chain-attack-march-2026-explained</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/axios-npm-supply-chain-attack-march-2026-explained</guid>
      <description>On March 31, 2026, two malicious versions of Axios  the most widely used HTTP client in JavaScript with 83 million weekly downloads  were briefly published to npm via a compromised maintainer account. They contained a cross-platform remote access trojan. Here&apos;s exactly what happened and what you need to do.</description>
      <pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <category>npm Security</category>
      <category>Axios</category>
      <category>JavaScript Security</category>
      <category>RAT</category>
      <category>Incident Response</category>
    </item>
    <item>
      <title>Pen Testing Tools Explained: Nessus, Burp Suite, Nmap, Metasploit  What They Do and What They Miss</title>
      <link>https://www.kuboid.in/blog/pen-testing-tools-explained-nessus-burp-suite-nmap-metasploit</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/pen-testing-tools-explained-nessus-burp-suite-nmap-metasploit</guid>
      <description>Every pen tester uses Nessus, Burp Suite, Nmap, OWASP ZAP, and Metasploit. Here is an honest breakdown of what each tool actually does  and the specific limits that make manual testing irreplaceable.</description>
      <pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate>
      <category>Penetration Testing</category>
      <category>Burp Suite</category>
      <category>Nessus</category>
      <category>Nmap</category>
      <category>Metasploit</category>
      <category>Security Tools</category>
    </item>
    <item>
      <title>Why Automated Vulnerability Scanners Miss Most Real Security Vulnerabilities</title>
      <link>https://www.kuboid.in/blog/why-automated-vulnerability-scanners-miss-most-real-vulnerabilities</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/why-automated-vulnerability-scanners-miss-most-real-vulnerabilities</guid>
      <description>Automated vulnerability scanners are essential  but they find roughly 20-30% of real security vulnerabilities. Here&apos;s exactly what they miss and why it matters for your business.</description>
      <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
      <category>Penetration Testing</category>
      <category>Vulnerability Scanning</category>
      <category>Application Security</category>
      <category>Manual Testing</category>
      <category>Web App Security</category>
    </item>
    <item>
      <title>Web Application Penetration Testing: A Complete Guide for Developers and Founders</title>
      <link>https://www.kuboid.in/blog/web-application-penetration-testing-complete-guide-developers-founders</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/web-application-penetration-testing-complete-guide-developers-founders</guid>
      <description>A complete, jargon-free guide to web application penetration testing  what it is, how it works, what gets tested, what a report looks like, and how to get started. Written by a developer turned pen tester.</description>
      <pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate>
      <category>Penetration Testing</category>
      <category>Web App Security</category>
      <category>Security Guide</category>
      <category>Startup Security</category>
      <category>AppSec</category>
      <category>Developer Security</category>
    </item>
    <item>
      <title>Web App Pen Test: What I Check in the First 10 Minutes of Every Engagement</title>
      <link>https://www.kuboid.in/blog/web-app-pen-test-first-10-minutes-checklist</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/web-app-pen-test-first-10-minutes-checklist</guid>
      <description>Before any serious testing begins, there&apos;s a 10-minute checklist I run on every web application I assess. Here&apos;s exactly what it includes  and how you can use it to check your own app right now.</description>
      <pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate>
      <category>Penetration Testing</category>
      <category>Web App Security</category>
      <category>Ethical Hacking</category>
      <category>Security Checklist</category>
      <category>AppSec</category>
    </item>
    <item>
      <title>The LiteLLM Supply Chain Attack Explained: What Happened, Who&apos;s Affected, and What to Do Now</title>
      <link>https://www.kuboid.in/blog/litellm-supply-chain-attack-march-2026-explained</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/litellm-supply-chain-attack-march-2026-explained</guid>
      <description>On March 24, 2026, two malicious versions of the LiteLLM Python package were published to PyPI. They were live for less than three hours. LiteLLM has 3 million daily downloads and sits inside 36% of cloud environments. Here&apos;s exactly what happened and what you need to do right now.</description>
      <pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <category>LiteLLM</category>
      <category>PyPI</category>
      <category>AI Security</category>
      <category>Credential Theft</category>
      <category>Incident Response</category>
    </item>
    <item>
      <title>The XZ Utils Backdoor Explained: The Supply Chain Attack That Almost Broke Linux</title>
      <link>https://www.kuboid.in/blog/xz-utils-backdoor-supply-chain-attack-linux</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/xz-utils-backdoor-supply-chain-attack-linux</guid>
      <description>In 2024, a developer spent two years contributing legitimate code to a critical open-source library  then inserted a backdoor that could have given any attacker remote access to millions of Linux servers worldwide. It was caught by one engineer who noticed SSH logins were 500 milliseconds slower than normal.</description>
      <pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate>
      <category>Supply Chain Security</category>
      <category>Open Source Security</category>
      <category>XZ Utils</category>
      <category>OWASP 2025</category>
      <category>Linux Security</category>
      <category>CVE-2024-3094</category>
    </item>
    <item>
      <title>Security Misconfiguration in 2025: Why It&apos;s Now the #2 Web App Risk</title>
      <link>https://www.kuboid.in/blog/security-misconfiguration-2025-owasp-number-2-web-app-risk</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/security-misconfiguration-2025-owasp-number-2-web-app-risk</guid>
      <description>Security Misconfiguration jumped from #5 to #2 on OWASP 2025. Here&apos;s why  with real breach examples, the most common mistakes found during real assessments, and how to fix them before an attacker finds them first.</description>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <category>Security Misconfiguration</category>
      <category>AWS Security</category>
      <category>OWASP 2025</category>
      <category>Cloud Security</category>
      <category>DevSecOps</category>
      <category>Secrets Management</category>
    </item>
    <item>
      <title>The Optus Data Breach Explained: 10 Million Records Stolen Through IDOR Vulnerability</title>
      <link>https://www.kuboid.in/blog/optus-data-breach-10-million-records-stolen-idor-vulnerability</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/optus-data-breach-10-million-records-stolen-idor-vulnerability</guid>
      <description>In 2022, nearly 10 million Optus customers had their data stolen by changing a single number in an API request. Here&apos;s exactly how it worked  and how to make sure it can&apos;t happen to you.</description>
      <pubDate>Tue, 24 Mar 2026 00:00:00 GMT</pubDate>
      <category>IDOR</category>
      <category>Broken Access Control</category>
      <category>API Security</category>
      <category>Data Breach</category>
      <category>OWASP</category>
      <category>Real World Attacks</category>
    </item>
    <item>
      <title>OWASP Top 10 2025: Everything That Changed and What It Means for Developers</title>
      <link>https://www.kuboid.in/blog/owasp-top-10-2025-everything-that-changed-and-what-it-means</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/owasp-top-10-2025-everything-that-changed-and-what-it-means</guid>
      <description>OWASP just updated its Top 10 Web Application Security Risks for the first time in four years  analysing 2.8 million applications and 175,000 CVE records. Two new categories. Major reshuffling. Here&apos;s exactly what changed and what every developer and CTO needs to know.</description>
      <pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate>
      <category>OWASP Top 10 2025</category>
      <category>Web Application Security</category>
      <category>Secure Coding</category>
      <category>AppSec</category>
      <category>Penetration Testing</category>
    </item>
    <item>
      <title>How to Defend Against Social Engineering: A Practical Team Guide</title>
      <link>https://www.kuboid.in/blog/how-to-defend-against-social-engineering-practical-team-guide</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/how-to-defend-against-social-engineering-practical-team-guide</guid>
      <description>A practical, jargon-free guide to building a social engineering defence for any team  without a large security budget. Five things you can implement this week.</description>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
      <category>Social Engineering Defence</category>
      <category>Security Awareness Training</category>
      <category>Phishing Simulation</category>
      <category>GoPhish</category>
      <category>Security Culture</category>
      <category>Startup Security</category>
    </item>
    <item>
      <title>The Psychology of Social Engineering: Why Smart People Get Hacked</title>
      <link>https://www.kuboid.in/blog/psychology-of-social-engineering-why-smart-people-get-hacked</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/psychology-of-social-engineering-why-smart-people-get-hacked</guid>
      <description>Social engineering doesn&apos;t target intelligence  it targets psychology. Here are the 6 psychological triggers every attacker exploits, grounded in peer-reviewed research, and how understanding them is your most effective defence.</description>
      <pubDate>Sat, 21 Mar 2026 00:00:00 GMT</pubDate>
      <category>Psychology</category>
      <category>Social Engineering</category>
      <category>Security Awareness</category>
      <category>Human Risk</category>
      <category>Phishing Psychology</category>
    </item>
    <item>
      <title>AI Phishing Attacks in 2026: How to Detect and Defend Against Them</title>
      <link>https://www.kuboid.in/blog/ai-phishing-attacks-2026-how-to-detect-and-defend</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/ai-phishing-attacks-2026-how-to-detect-and-defend</guid>
      <description>Over 80% of phishing emails now use AI-assisted content. Here&apos;s what actually changed, what AI phishing looks like up close, and the only defence framework that still works in 2026.</description>
      <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
      <category>AI Phishing</category>
      <category>Phishing 2026</category>
      <category>Email Security</category>
      <category>DMARC</category>
      <category>Security Awareness</category>
      <category>Generative AI</category>
    </item>
    <item>
      <title>Why Multi-Factor Authentication Won&apos;t Stop Social Engineering Attacks</title>
      <link>https://www.kuboid.in/blog/why-mfa-wont-stop-social-engineering-attacks</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/why-mfa-wont-stop-social-engineering-attacks</guid>
      <description>MFA is essential but not sufficient. Here&apos;s how attackers bypass MFA through social engineering  with real case studies  and what additional controls actually work.</description>
      <pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate>
      <category>MFA</category>
      <category>Multi-Factor Authentication</category>
      <category>Social Engineering</category>
      <category>Identity Security</category>
      <category>Help Desk Attack</category>
      <category>FIDO2</category>
    </item>
    <item>
      <title>The Coinbase Breach Explained: Insider Social Engineering Attack</title>
      <link>https://www.kuboid.in/blog/coinbase-breach-2025-insider-social-engineering-explained</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/coinbase-breach-2025-insider-social-engineering-explained</guid>
      <description>The 2025 Coinbase breach required zero hacking. Here&apos;s exactly how attackers used insider bribery and social engineering to steal customer data  and what any business can learn from it.</description>
      <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
      <category>Coinbase Breach</category>
      <category>Insider Threat</category>
      <category>Social Engineering</category>
      <category>Third-Party Risk</category>
      <category>Data Breach 2025</category>
    </item>
    <item>
      <title>7 Types of Social Engineering Attacks  Real Examples from 2025 and 2026</title>
      <link>https://www.kuboid.in/blog/7-types-of-social-engineering-attacks-real-examples-2025-2026</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/7-types-of-social-engineering-attacks-real-examples-2025-2026</guid>
      <description>Phishing is just the beginning. Here are all 7 social engineering attack types with real examples from 2025–2026 that show exactly how each one works.</description>
      <pubDate>Tue, 17 Mar 2026 00:00:00 GMT</pubDate>
      <category>Social Engineering</category>
      <category>Phishing</category>
      <category>Vishing</category>
      <category>Pretexting</category>
      <category>Deepfake</category>
      <category>Cybersecurity 2026</category>
    </item>
    <item>
      <title>What Is Social Engineering? Complete Guide With 2026 Examples</title>
      <link>https://www.kuboid.in/blog/what-is-social-engineering-complete-guide-2026</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/what-is-social-engineering-complete-guide-2026</guid>
      <description>Social engineering is responsible for 60% of all data breaches. This complete guide covers every technique, 2025–2026 case studies, and how to defend your team.</description>
      <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
      <category>Social Engineering</category>
      <category>Cybersecurity 2026</category>
      <category>Phishing</category>
      <category>Human Risk</category>
      <category>Security Awareness</category>
    </item>
    <item>
      <title>How to Security Test an AI-Powered Application  Complete Guide 2026</title>
      <link>https://www.kuboid.in/blog/how-to-security-test-your-ai-powered-application</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/how-to-security-test-your-ai-powered-application</guid>
      <description>Security testing an AI-powered application is not the same as testing a traditional web app. It starts the same way  then it goes somewhere entirely new. Here is the full methodology, the tools that actually work, and what a proper AI security assessment looks like.</description>
      <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
      <category>AI Security Testing</category>
      <category>LLM Penetration Testing</category>
      <category>AI Red Teaming</category>
      <category>Application Security</category>
      <category>OWASP LLM</category>
      <category>Security Assessment</category>
    </item>
    <item>
      <title>OWASP Top 10 for LLM Applications 2025  Plain English Explanation with Real Examples</title>
      <link>https://www.kuboid.in/blog/owasp-top-10-for-llm-applications-explained-simply</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/owasp-top-10-for-llm-applications-explained-simply</guid>
      <description>Three years ago &apos;OWASP Top 10 for LLM Applications&apos; would have been a meaningless phrase. Today it&apos;s the most important document in AI application security. Here is what every item means  in the language of someone who builds and ships products, not a security academic.</description>
      <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
      <category>OWASP</category>
      <category>LLM Security</category>
      <category>AI Security</category>
      <category>OWASP LLM Top 10</category>
      <category>Application Security</category>
      <category>AI Vulnerabilities</category>
    </item>
    <item>
      <title>RAG Security  How Attackers Poison AI Knowledge Bases and What to Do About It</title>
      <link>https://www.kuboid.in/blog/rag-security-how-attackers-poison-your-ais-knowledge-base</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/rag-security-how-attackers-poison-your-ais-knowledge-base</guid>
      <description>You built a RAG system to make your AI accurate and grounded. You fed it your documentation, your product data, your knowledge base. But did you consider what happens when an attacker plants something in that knowledge base before your users query it? Five documents in a database of millions is all it takes.</description>
      <pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
      <category>RAG Security</category>
      <category>RAG Poisoning</category>
      <category>Vector Database Security</category>
      <category>AI Security</category>
      <category>LLM Security</category>
      <category>Knowledge Base</category>
    </item>
    <item>
      <title>LLMjacking  How AI API Key Theft Works and How to Prevent It</title>
      <link>https://www.kuboid.in/blog/llmjacking-how-attackers-steal-your-openai-api-key-and-run-up-dollar100k-bills</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/llmjacking-how-attackers-steal-your-openai-api-key-and-run-up-dollar100k-bills</guid>
      <description>A startup&apos;s OpenAI bill jumped from $400 to $67,000 in a month. Their API key had been sitting in a public GitHub repository for 11 days. Automated bots found it within minutes. This is LLMjacking  and Microsoft has already filed lawsuits over it.</description>
      <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
      <category>LLMjacking</category>
      <category>API Security</category>
      <category>AI Security</category>
      <category>OpenAI</category>
      <category>Credential Theft</category>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Indirect Prompt Injection  How Attacks Hide in Documents Your AI Reads</title>
      <link>https://www.kuboid.in/blog/indirect-prompt-injection-when-the-document-attacks-you</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/indirect-prompt-injection-when-the-document-attacks-you</guid>
      <description>The attacker never touched the chat interface. They sent an email. The AI read it, followed the hidden instructions inside, and silently exfiltrated data from files the attacker had no access to. This is indirect prompt injection  and it&apos;s the most dangerous AI vulnerability most organisations haven&apos;t heard of.</description>
      <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
      <category>Prompt Injection</category>
      <category>Indirect Prompt Injection</category>
      <category>AI Security</category>
      <category>LLM Security</category>
      <category>RAG Security</category>
      <category>Microsoft Copilot</category>
    </item>
    <item>
      <title>What Is Prompt Injection? The Most Critical AI Vulnerability Explained</title>
      <link>https://www.kuboid.in/blog/prompt-injection-the-sql-injection-of-the-ai-era</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/prompt-injection-the-sql-injection-of-the-ai-era</guid>
      <description>Prompt injection is to AI applications what SQL injection was to web apps in the early 2000s  a fundamental confusion between instructions and data that attackers know exactly how to exploit. Here&apos;s how it works, why it&apos;s so hard to fix, and what real-world breaches look like.</description>
      <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
      <category>Prompt Injection</category>
      <category>AI Security</category>
      <category>LLM Security</category>
      <category>OWASP</category>
      <category>Application Security</category>
    </item>
    <item>
      <title>AI-Powered App Security  The New Attack Surface Startups Are Ignoring</title>
      <link>https://www.kuboid.in/blog/ai-powered-apps-the-attack-surface-no-one-is-testing</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/ai-powered-apps-the-attack-surface-no-one-is-testing</guid>
      <description>Your team shipped an AI feature last sprint. You tested it for bugs. You tested it for accuracy. Did anyone test it for security? AI features introduce a class of vulnerabilities that traditional security tools simply don&apos;t look for.</description>
      <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
      <category>AI Security</category>
      <category>LLM Security</category>
      <category>Prompt Injection</category>
      <category>OWASP</category>
      <category>Application Security</category>
      <category>Secure AI</category>
    </item>
    <item>
      <title>Cloud Security for SaaS Startups  Complete Guide 2026</title>
      <link>https://www.kuboid.in/blog/complete-guide-to-cloud-security-for-saas-startups-2026-edition</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/complete-guide-to-cloud-security-for-saas-startups-2026-edition</guid>
      <description>Everything a SaaS startup needs to know about cloud security  the risks, the mistakes, the tools, and the step-by-step process for securing your AWS or GCP environment. A permanent reference, updated for 2026.</description>
      <pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <category>SaaS Security</category>
      <category>AWS Security</category>
      <category>Startup Security</category>
      <category>Cloud Guide 2026</category>
      <category>GCP Security</category>
    </item>
    <item>
      <title>AWS Security Checklist 2025  10 Critical Settings Every Startup Must Configure</title>
      <link>https://www.kuboid.in/blog/cloud-security-checklist-10-things-to-fix-in-your-aws-account-today</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/cloud-security-checklist-10-things-to-fix-in-your-aws-account-today</guid>
      <description>Ten AWS security settings that take under 2 hours to configure and protect against the most common cloud attack vectors. These are the first things I check  and the first things you should fix.</description>
      <pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate>
      <category>AWS Security</category>
      <category>Cloud Security Checklist</category>
      <category>Startup Security</category>
      <category>AWS Best Practices</category>
      <category>Cloud Configuration</category>
    </item>
    <item>
      <title>Cloud Shared Responsibility Model Explained  What AWS, Azure, and GCP Are NOT Responsible For</title>
      <link>https://www.kuboid.in/blog/the-cloud-shared-responsibility-model-every-founder-must-understand</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/the-cloud-shared-responsibility-model-every-founder-must-understand</guid>
      <description>&quot;But we&apos;re on AWS  aren&apos;t they responsible for keeping our data safe?&quot; I&apos;ve heard this from almost every startup founder I&apos;ve worked with. The answer is yes and no  and understanding the difference is the most important thing you can learn about cloud security.</description>
      <pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <category>Shared Responsibility Model</category>
      <category>AWS Security</category>
      <category>Azure Security</category>
      <category>GCP Security</category>
      <category>Cloud Compliance</category>
    </item>
    <item>
      <title>API Keys in GitHub  How Leaked Credentials Cause Cloud Breaches</title>
      <link>https://www.kuboid.in/blog/secrets-in-code-how-one-git-commit-cost-a-startup-dollar-80000</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/secrets-in-code-how-one-git-commit-cost-a-startup-dollar-80000</guid>
      <description>The commit was pushed at 11:47 PM. By 12:03 AM  16 minutes later  an automated bot had found the AWS access key and began spinning up EC2 instances. By morning, 340 instances were running across 6 regions. The bill: $80,000 over 36 hours. Here&apos;s exactly how it happens  and how to make sure it doesn&apos;t happen to you.</description>
      <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
      <category>Secrets Management</category>
      <category>AWS Security</category>
      <category>GitHub Security</category>
      <category>API Key Security</category>
      <category>Cloud Security</category>
      <category>DevSecOps</category>
    </item>
    <item>
      <title>AWS S3 Bucket Security  How Misconfigurations Cause Breaches and How to Fix Them</title>
      <link>https://www.kuboid.in/blog/s3-bucket-misconfigurations-the-breach-that-keeps-happening</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/s3-bucket-misconfigurations-the-breach-that-keeps-happening</guid>
      <description>Customer invoices for hundreds of thousands of users  indexed by Google, sitting in a public S3 bucket set to public during a dev sprint and never changed back. Discovered by a security researcher who typed &apos;site:s3.amazonaws.com invoice&apos; into a search bar. Here&apos;s how it keeps happening  and how to make sure it doesn&apos;t happen to you.</description>
      <pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate>
      <category>S3 Security</category>
      <category>AWS Security</category>
      <category>Cloud Misconfiguration</category>
      <category>Data Breach</category>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>AWS IAM Security Best Practices  Why Over-Permissive Access Is Your Biggest Cloud Risk</title>
      <link>https://www.kuboid.in/blog/iam-permissions-why-admin-access-for-everyone-is-a-disaster-waiting-to-happen</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/iam-permissions-why-admin-access-for-everyone-is-a-disaster-waiting-to-happen</guid>
      <description>Seven developers with AdministratorAccess. Three inactive accounts from ex-employees still enabled. Root account with no MFA. No API key rotation in 18 months. This is what I find in almost every startup AWS account I audit  and it&apos;s your single biggest cloud security risk.</description>
      <pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate>
      <category>AWS IAM</category>
      <category>Cloud Security</category>
      <category>IAM Security</category>
      <category>Least Privilege</category>
      <category>Access Management</category>
      <category>Startup Security</category>
    </item>
    <item>
      <title>Why Cloud Security Is Your Responsibility  Not Amazon&apos;s or Google&apos;s</title>
      <link>https://www.kuboid.in/blog/why-cloud-security-is-your-problem-not-aws</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/why-cloud-security-is-your-problem-not-aws</guid>
      <description>A founder received an AWS bill for $74,000. They&apos;d been paying $800 a month. In 48 hours, someone had spun up hundreds of EC2 instances for crypto mining. &apos;Why didn&apos;t AWS stop this?&apos; The answer changed how they thought about cloud security permanently.</description>
      <pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate>
      <category>Cloud Security</category>
      <category>AWS Security</category>
      <category>Shared Responsibility Model</category>
      <category>Startup Security</category>
      <category>Cloud Misconfiguration</category>
    </item>
    <item>
      <title>Web Application Penetration Testing Checklist  What Gets Tested and Why</title>
      <link>https://www.kuboid.in/blog/the-complete-web-app-pen-test-checklist-what-i-test-on-every-engagement</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/the-complete-web-app-pen-test-checklist-what-i-test-on-every-engagement</guid>
      <description>What exactly gets tested during a web application penetration test? Here&apos;s the complete checklist I use on every engagement  organised by category, with a plain-English explanation of what each item looks for and why it matters.</description>
      <pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
      <category>Penetration Testing</category>
      <category>Web App Security</category>
      <category>Pen Test Checklist</category>
      <category>Security Methodology</category>
      <category>Application Security</category>
    </item>
    <item>
      <title>Secure Coding Practices for Web Developers  Quick Wins That Actually Work</title>
      <link>https://www.kuboid.in/blog/secure-coding-habits-that-take-5-minutes-and-prevent-80percent-of-web-vulnerabilities</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/secure-coding-habits-that-take-5-minutes-and-prevent-80percent-of-web-vulnerabilities</guid>
      <description>Most vulnerabilities I find in web applications would have been prevented by a handful of habits that add less than 30 minutes to a developer&apos;s week. Here&apos;s the list  specific, framework-agnostic, and immediately actionable.</description>
      <pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate>
      <category>Secure Coding</category>
      <category>Developer Security</category>
      <category>Web Security</category>
      <category>Best Practices</category>
      <category>Security Habits</category>
    </item>
    <item>
      <title>Cross-Site Scripting (XSS) Explained  Why It&apos;s Still Dangerous in 2026</title>
      <link>https://www.kuboid.in/blog/xss-in-2026-why-cross-site-scripting-is-still-dangerous-and-still-everywhere</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/xss-in-2026-why-cross-site-scripting-is-still-dangerous-and-still-everywhere</guid>
      <description>XSS has been in the OWASP Top 10 for over two decades. A comment field with unencoded output silently harvested 2,400 session cookies over 6 days. Here&apos;s how it still works in 2026, what attackers do with it, and why modern frameworks don&apos;t fully protect you.</description>
      <pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate>
      <category>XSS</category>
      <category>Cross-Site Scripting</category>
      <category>Web App Security</category>
      <category>OWASP</category>
      <category>JavaScript Security</category>
      <category>Penetration Testing</category>
    </item>
    <item>
      <title>Broken Authentication in Web Apps  What It Is and How to Test for It</title>
      <link>https://www.kuboid.in/blog/broken-authentication-what-it-is-what-i-test-and-why-it-keeps-getting-exploited</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/broken-authentication-what-it-is-what-i-test-and-why-it-keeps-getting-exploited</guid>
      <description>Broken authentication isn&apos;t just weak passwords. It&apos;s non-expiring reset links, sessions that survive logout, MFA that can be bypassed, and remember-me tokens that last forever. Here&apos;s exactly what I test in every authentication implementation  and what I keep finding.</description>
      <pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate>
      <category>Broken Authentication</category>
      <category>Session Management</category>
      <category>OWASP</category>
      <category>Web App Security</category>
      <category>Authentication Testing</category>
    </item>
    <item>
      <title>API Security for Startups  The Vulnerabilities No One Is Testing</title>
      <link>https://www.kuboid.in/blog/api-security-the-blind-spot-of-every-early-stage-startup</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/api-security-the-blind-spot-of-every-early-stage-startup</guid>
      <description>The startup had a beautiful frontend. Strong passwords. HTTPS. A WAF. Their API had no authentication on three endpoints, no rate limiting, and returned fields the frontend never displayed. The frontend was a fortress. The API was a screen door.</description>
      <pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate>
      <category>API Security</category>
      <category>REST API</category>
      <category>Startup Security</category>
      <category>Web App Security</category>
      <category>Penetration Testing</category>
      <category>API Vulnerabilities</category>
    </item>
    <item>
      <title>What Is IDOR? The Web Vulnerability That Exposes Your Users&apos; Data</title>
      <link>https://www.kuboid.in/blog/idor-the-vulnerability-developers-keep-writing-and-how-to-stop</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/idor-the-vulnerability-developers-keep-writing-and-how-to-stop</guid>
      <description>IDOR lets attackers access other users&apos; data by changing a number in a URL. It&apos;s one of the most common vulnerabilities I find  and one of the easiest to miss during development. Here&apos;s exactly how it works and how to stop it.</description>
      <pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate>
      <category>IDOR</category>
      <category>Web Application Security</category>
      <category>Access Control</category>
      <category>OWASP</category>
      <category>Bug Bounty</category>
      <category>Secure Development</category>
    </item>
    <item>
      <title>Why Web Applications Get Hacked in 2025  And How to Protect Yours</title>
      <link>https://www.kuboid.in/blog/why-web-applications-get-hacked-and-why-yours-might-be-next</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/why-web-applications-get-hacked-and-why-yours-might-be-next</guid>
      <description>80% of cyberattacks target web applications. You used a modern framework. You implemented HTTPS. You think you&apos;re covered. Here&apos;s what you almost certainly missed  and why most web app breaches are entirely preventable.</description>
      <pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate>
      <category>Web Application Security</category>
      <category>Web App Vulnerabilities</category>
      <category>Startup Security</category>
      <category>Security 2025</category>
      <category>Application Security</category>
    </item>
    <item>
      <title>Startup Security Checklist  10 Security Steps Before You Launch</title>
      <link>https://www.kuboid.in/blog/startup-security-checklist-10-things-to-do-before-you-launch</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/startup-security-checklist-10-things-to-do-before-you-launch</guid>
      <description>Launching without a security baseline isn&apos;t a calculated risk  it&apos;s an open invitation. Here are 10 things every startup should verify before going live, explained without the jargon.</description>
      <pubDate>Sun, 22 Feb 2026 00:00:00 GMT</pubDate>
      <category>Startup Security</category>
      <category>Web App Security</category>
      <category>Security Checklist</category>
      <category>Pre-Launch</category>
      <category>Secure Development</category>
    </item>
    <item>
      <title>From Developer to Penetration Tester  My Journey and What I Learned</title>
      <link>https://www.kuboid.in/blog/from-developer-to-pen-tester-my-honest-journey</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/from-developer-to-pen-tester-my-honest-journey</guid>
      <description>Ten years of writing code. Then one CTF changed everything. Here&apos;s my honest account of moving from software development into penetration testing  what transferred, what didn&apos;t, and why I eventually built Kuboid.</description>
      <pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate>
      <category>Career</category>
      <category>Penetration Testing</category>
      <category>Developer Journey</category>
      <category>Cybersecurity Career</category>
      <category>Kuboid</category>
    </item>
    <item>
      <title>What Is Social Engineering in Cybersecurity? A Plain-English Guide</title>
      <link>https://www.kuboid.in/blog/social-engineering-cybersecurity-plain-english-guide</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/social-engineering-cybersecurity-plain-english-guide</guid>
      <description>Your firewall can block malware. Your antivirus can catch ransomware. But neither can stop an attacker who simply asks your employee for the password  and gets it. Here&apos;s what social engineering really is, and what you can actually do about it.</description>
      <pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate>
      <category>Social Engineering</category>
      <category>Cybersecurity Awareness</category>
      <category>Phishing</category>
      <category>Security Training</category>
      <category>Human Risk</category>
    </item>
    <item>
      <title>Why Developers Write Insecure Code  And How to Fix It</title>
      <link>https://www.kuboid.in/blog/developers-write-insecure-code-and-how-to-fix-it</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/developers-write-insecure-code-and-how-to-fix-it</guid>
      <description>Insecure code isn&apos;t a talent problem. It&apos;s a systems problem  bad deadlines, missing security education, and unclear requirements. Here&apos;s what&apos;s actually happening inside engineering teams, and what leaders can do about it.</description>
      <pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate>
      <category>Secure Coding</category>
      <category>Application Security</category>
      <category>Developer Security</category>
      <category>Penetration Testing</category>
      <category>Code Review</category>
    </item>
    <item>
      <title>How Phishing Attacks Work in 2026  Techniques, Examples &amp; Defense</title>
      <link>https://www.kuboid.in/blog/phishing-attacks-work-2026-techniques-examples-defense</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/phishing-attacks-work-2026-techniques-examples-defense</guid>
      <description>Phishing isn&apos;t a relic of the early internet. It&apos;s the single most common entry point for cyberattacks worldwide  and in 2026, AI has made it frighteningly more convincing. Here&apos;s how it actually works, why smart people still fall for it, and what your team needs to know.</description>
      <pubDate>Wed, 18 Feb 2026 00:00:00 GMT</pubDate>
      <category>Phishing</category>
      <category>Spear Phishing</category>
      <category>Email Security</category>
      <category>Security Awareness</category>
      <category>AI Threats</category>
      <category>Cybersecurity 2026</category>
    </item>
    <item>
      <title>OWASP Top 10 Explained Simply  With Real Examples</title>
      <link>https://www.kuboid.in/blog/owasp-top-10-explained-without-the-jargon</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/owasp-top-10-explained-without-the-jargon</guid>
      <description>The OWASP Top 10 is the industry&apos;s most referenced list of web application vulnerabilities. Here&apos;s what each one actually means  in plain English, with real examples  and why your development team should care.</description>
      <pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate>
      <category>OWASP Top 10</category>
      <category>Web Application Security</category>
      <category>Application Security</category>
      <category>Secure Development</category>
      <category>Vulnerabilities</category>
    </item>
    <item>
      <title>What Is a Penetration Test? Complete Guide for Founders and CTOs</title>
      <link>https://www.kuboid.in/blog/what-is-a-penetration-test-everything-you-need-to-know-before-booking-one</link>
      <guid isPermaLink="true">https://www.kuboid.in/blog/what-is-a-penetration-test-everything-you-need-to-know-before-booking-one</guid>
      <description>What actually happens during a penetration test, how much it costs, what the report should look like, and the red flags to watch for when hiring someone to do one. Everything you need to know before booking.</description>
      <pubDate>Mon, 16 Feb 2026 00:00:00 GMT</pubDate>
      <category>Penetration Testing</category>
      <category>Pen Test Guide</category>
      <category>Startup Security</category>
      <category>Web App Security</category>
      <category>Security Assessment</category>
    </item>
  </channel>
</rss>