<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Roei Hadashi — research &amp; writing</title>
    <link>https://roeihadashi.com/</link>
    <description>Red team, AI security and vulnerability research by Roei Hadashi, head of red team &amp; ai security at HackersEye.</description>
    <language>en</language>
    <lastBuildDate>Thu, 13 Aug 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://roeihadashi.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Priority Portal Generator: Nine CVEs in Israel&apos;s ERP Supply Chain</title>
      <link>https://hackerseye.com/blog/priority-portal-generator-nine-cves</link>
      <guid isPermaLink="false">2026-08-13:Priority Portal Generator: Nine CVEs in Israel&apos;s ERP Supply Chain</guid>
      <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
      <dc:creator>Roei Hadashi</dc:creator>
      <source url="https://hackerseye.com/blog/priority-portal-generator-nine-cves">hackerseye.com</source>
      <description>Nine CVEs in the Portal Generator addon to Priority ERP, which served internal server addresses, an application secret, a licence key and working API credentials to every visitor before login.</description>
    </item>
    <item>
      <title>AsyncRAT, WebDAV, and Bad OpSec Walk Into an Israeli Bar</title>
      <link>https://hackerseye.com/blog/asyncrat-webdav-and-bad-opsec-walk-into-an-israeli-bar/</link>
      <guid isPermaLink="false">2025-06-19:AsyncRAT, WebDAV, and Bad OpSec Walk Into an Israeli Bar</guid>
      <pubDate>Thu, 19 Jun 2025 00:00:00 GMT</pubDate>
      <dc:creator>Roei Hadashi</dc:creator>
      <source url="https://hackerseye.com/blog/asyncrat-webdav-and-bad-opsec-walk-into-an-israeli-bar/">hackerseye.com</source>
      <description>Tracing an AsyncRAT campaign delivered over WebDAV against Israeli targets, and what the operator’s operational-security mistakes gave away about the infrastructure behind it.</description>
    </item>
    <item>
      <title>Secrets Leakage: A Rising Threat in Development Practices</title>
      <link>https://profero.io/blog/secrets-leakage-rising-threat-development-practices-to-safeguard-your-secrets</link>
      <guid isPermaLink="false">2024-07-23:Secrets Leakage: A Rising Threat in Development Practices</guid>
      <pubDate>Tue, 23 Jul 2024 00:00:00 GMT</pubDate>
      <dc:creator>Roei Hadashi</dc:creator>
      <source url="https://profero.io/blog/secrets-leakage-rising-threat-development-practices-to-safeguard-your-secrets">profero.io</source>
      <description>How credentials escape into source control, build logs and client-side bundles, and the controls that actually stop it rather than just detecting it after the fact.</description>
    </item>
    <item>
      <title>SysAid On-Prem Zero-Day — CVE-2023-47246, exploited by Lace Tempest</title>
      <link>https://profero.io/blog/sysaid-on-prem-vulnerability-disclosure</link>
      <guid isPermaLink="false">2023-11-07:SysAid On-Prem Zero-Day — CVE-2023-47246, exploited by Lace Tempest</guid>
      <pubDate>Tue, 07 Nov 2023 00:00:00 GMT</pubDate>
      <dc:creator>Roei Hadashi</dc:creator>
      <source url="https://profero.io/blog/sysaid-on-prem-vulnerability-disclosure">profero.io</source>
      <description>Disclosure of a zero-day path traversal in SysAid On-Prem, found during incident response while the threat actor Lace Tempest was actively exploiting it.</description>
    </item>
    <item>
      <title>What Are Dependency Confusion Attacks?</title>
      <link>https://open.spotify.com/episode/30V8TDInUwZQ5wHNHxOOtq</link>
      <guid isPermaLink="false">2022-06-12:What Are Dependency Confusion Attacks?</guid>
      <pubDate>Sun, 12 Jun 2022 00:00:00 GMT</pubDate>
      <dc:creator>Roei Hadashi</dc:creator>
      <source url="https://open.spotify.com/episode/30V8TDInUwZQ5wHNHxOOtq">60 Sec on AppSec</source>
      <description>A short explainer on dependency confusion: why a package manager will happily prefer an attacker’s public package over your private one, and how to pin against it.</description>
    </item>
  </channel>
</rss>
