<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Protocol Report</title>
    <link>https://protocolreport.com/</link>
    <description>Security reporting, protocol comparisons, and privacy-focused software analysis.</description>
    <language>en-us</language>
    <item>
      <title>Red Hat npm Compromise Exposes Provenance Gaps</title>
      <link>https://protocolreport.com/blog/red-hat-npm-provenance-gap/</link>
      <guid isPermaLink="false">protocolreport:red-hat-npm-provenance-gap</guid>
      <description>Red Hat confirmed a supply-chain compromise in @redhat-cloud-services npm packages. The harder lesson is that signed provenance can still carry malicious code when the trusted workflow itself is abused.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Android And Linux KEV Deadline Forces Patch Triage</title>
      <link>https://protocolreport.com/blog/android-linux-kev-patch-triage/</link>
      <guid isPermaLink="false">protocolreport:android-linux-kev-patch-triage</guid>
      <description>Google's June Android bulletin and CISA's KEV additions put an Android Framework flaw and a Linux cgroups flaw into the same urgent patch window. The practical work is mobile and container exposure scoping.</description>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Dashlane Attack Shows Vault Risk Starts At Login</title>
      <link>https://protocolreport.com/blog/dashlane-brute-force-vault-risk/</link>
      <guid isPermaLink="false">protocolreport:dashlane-brute-force-vault-risk</guid>
      <description>Dashlane confirmed a brute-force campaign against user accounts, while reporting says encrypted vault data for a small number of accounts was downloaded. The practical lesson is account hardening, cryptography settings, device approval, and response planning.</description>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Storm-2949 Turns Password Reset Into Cloud Breach</title>
      <link>https://protocolreport.com/blog/storm-2949-sspr-cloud-breach/</link>
      <guid isPermaLink="false">protocolreport:storm-2949-sspr-cloud-breach</guid>
      <description>Microsoft's Storm-2949 report shows how self-service password reset abuse can become cloud-wide access across Key Vault, web apps, SQL, storage, VMs, and MFA registration.</description>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Passkeys Move Account Risk To Recovery</title>
      <link>https://protocolreport.com/blog/passkeys-account-recovery-risk/</link>
      <guid isPermaLink="false">protocolreport:passkeys-account-recovery-risk</guid>
      <description>Passkeys remove the reusable password from login, but the hard security work moves to recovery, sync, device binding, fallback methods, and privileged account policy.</description>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Post-Quantum Messaging Needs More Than New Keys</title>
      <link>https://protocolreport.com/blog/post-quantum-messaging-migration/</link>
      <guid isPermaLink="false">protocolreport:post-quantum-messaging-migration</guid>
      <description>Quantum-safe messaging is not a single algorithm swap. Teams need to understand hybrid key agreement, ratchets, group behavior, backups, identity keys, and migration transparency.</description>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Discord E2EE Calls Raise The Privacy Baseline</title>
      <link>https://protocolreport.com/blog/discord-e2ee-voice-video-default/</link>
      <guid isPermaLink="false">protocolreport:discord-e2ee-voice-video-default</guid>
      <description>Discord says every voice and video call outside Stage channels now uses end-to-end encryption by default. The practical result is stronger media confidentiality, with clear limits around text, metadata, verification, previews, and device compromise.</description>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Instagram Encrypted DM Removal Changes The Privacy Boundary</title>
      <link>https://protocolreport.com/blog/instagram-encrypted-dms-removed/</link>
      <guid isPermaLink="false">protocolreport:instagram-encrypted-dms-removed</guid>
      <description>Instagram ended support for optional end-to-end encrypted direct messages on May 8, 2026. The change does not prove misuse, but it changes what users, creators, and community operators should assume about sensitive conversations.</description>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GlobalProtect Cookie Bypass Makes VPN Edge Hygiene Urgent</title>
      <link>https://protocolreport.com/blog/globalprotect-cookie-bypass-vpn-risk/</link>
      <guid isPermaLink="false">protocolreport:globalprotect-cookie-bypass-vpn-risk</guid>
      <description>Palo Alto Networks updated CVE-2026-0257 after limited exploit attempts against unpatched GlobalProtect deployments. The practical response is configuration review, fixed PAN-OS versions, and VPN-edge incident triage.</description>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Composio Incident Shows AI Connectors Are Token Vaults</title>
      <link>https://protocolreport.com/blog/composio-ai-connector-token-incident/</link>
      <guid isPermaLink="false">protocolreport:composio-ai-connector-token-incident</guid>
      <description>Composio's May 2026 incident exposed the security reality of agent connector platforms: a single tool hub may hold GitHub, email, chat, calendar, cloud, and API-key access that must be revocable under pressure.</description>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Glassworm Shows Developer Machines Are Supply-Chain Targets</title>
      <link>https://protocolreport.com/blog/glassworm-developer-botnet-takedown/</link>
      <guid isPermaLink="false">protocolreport:glassworm-developer-botnet-takedown</guid>
      <description>CrowdStrike's May 2026 Glassworm takedown cut off a developer-targeting botnet, but teams still need to treat infected workstations, tokens, packages, and repositories as an active supply-chain risk.</description>
      <pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Google Workspace DBSC Makes Stolen Cookies Less Portable</title>
      <link>https://protocolreport.com/blog/google-workspace-dbsc-session-cookie-theft/</link>
      <guid isPermaLink="false">protocolreport:google-workspace-dbsc-session-cookie-theft</guid>
      <description>Google made Device Bound Session Credentials generally available for Workspace users in Chrome on Windows. The useful change is narrower than passwordless login: it targets session theft after authentication.</description>
      <pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GitHub's GHES Signing-Key Rotation Is a Supply-Chain Warning</title>
      <link>https://protocolreport.com/blog/github-enterprise-signing-key-rotation/</link>
      <guid isPermaLink="false">protocolreport:github-enterprise-signing-key-rotation</guid>
      <description>GitHub's May 2026 Enterprise Server signing-key rotation shows how a poisoned developer tool can force enterprise software verification, release, and secret-rotation decisions.</description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Texas's WhatsApp Lawsuit Tests What Encryption Claims Mean</title>
      <link>https://protocolreport.com/blog/whatsapp-encryption-lawsuit-privacy-claims/</link>
      <guid isPermaLink="false">protocolreport:whatsapp-encryption-lawsuit-privacy-claims</guid>
      <description>Texas sued Meta and WhatsApp over end-to-end encryption claims. The useful question is where personal chats, business chats, backups, reports, AI features, and metadata actually sit.</description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Kali365 Turns Microsoft 365 MFA Into a Token Problem</title>
      <link>https://protocolreport.com/blog/kali365-microsoft-365-oauth-token-phishing/</link>
      <guid isPermaLink="false">protocolreport:kali365-oauth-token-phishing</guid>
      <description>The FBI's May 2026 Kali365 alert shows why Microsoft 365 teams need to treat device-code OAuth flows, refresh tokens, and session revocation as first-class controls.</description>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Privage vs. Discord: Privacy, Communities, and Control</title>
      <link>https://protocolreport.com/blog/privage-vs-discord-security-privacy-comparison/</link>
      <guid isPermaLink="false">protocolreport:privage-discord-comparison</guid>
      <description>A practical comparison of Privage and Discord for private communities, paid groups, gaming teams, and crypto-native teams deciding where their conversations should live.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>End-to-End Encryption Is Failing the UX Test</title>
      <link>https://protocolreport.com/blog/end-to-end-encryption-failing-ux-test/</link>
      <guid isPermaLink="false">protocolreport:e2ee-ux-test</guid>
      <description>A rigorous technical teardown of top-tier messaging protocols and how cryptographic certainty can collapse under poor product design.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Slack vs. Signal: Enterprise Security Deep Dive</title>
      <link>https://protocolreport.com/blog/slack-vs-signal-enterprise-security-review/</link>
      <guid isPermaLink="false">protocolreport:slack-signal-enterprise-review</guid>
      <description>A security review comparing Slack and Signal across encryption, metadata retention, open source posture, and enterprise risk.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Best Discord Alternatives for Communities, Teams, and Private Groups</title>
      <link>https://protocolreport.com/blog/best-discord-alternatives-communities-teams-private-groups/</link>
      <guid isPermaLink="false">protocolreport:discord-alternatives-guide</guid>
      <description>A security-first evaluation of chat platforms that can replace Discord when moderation controls, data ownership, privacy, or professional workflows matter more than gaming-native defaults.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Zero-Log Claims Under Pressure: The 2024 Server Seizure Report</title>
      <link>https://protocolreport.com/blog/zero-log-claims-under-pressure-2024-server-seizure-report/</link>
      <guid isPermaLink="false">protocolreport:zero-log-claims-report</guid>
      <description>Analyzing the technical infrastructure of leading VPN providers after international law enforcement audits.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Misconfigured S3 Buckets: An Automated Exploitation Crisis</title>
      <link>https://protocolreport.com/blog/misconfigured-s3-buckets-automated-exploitation-crisis/</link>
      <guid isPermaLink="false">protocolreport:s3-bucket-exposure-analysis</guid>
      <description>How simple policy errors in AWS environments are leading to sophisticated, automated data exfiltration pipelines.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Bypassing Biometrics: The Rise of Synthetic Identity Injections</title>
      <link>https://protocolreport.com/blog/bypassing-biometrics-synthetic-identity-injections/</link>
      <guid isPermaLink="false">protocolreport:biometric-injection-analysis</guid>
      <description>Exploring vulnerabilities in mobile trusted execution environments and sensor spoofing methodologies.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
