<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>almamy.net | Security Write-ups</title><description>Curated incident analyses and vulnerability deep dives from almamy.net.</description><link>https://almamy.net/</link><language>en-gb</language><item><title>XZ Utils Backdoor — CVE-2024-3094 Deep Dive</title><link>https://almamy.net/security/2025-03-xz-backdoor/</link><guid isPermaLink="true">https://almamy.net/security/2025-03-xz-backdoor/</guid><description>How a supply chain attacker spent two years building trust before planting a backdoor in a critical compression library.</description><pubDate>Sat, 29 Mar 2025 00:00:00 GMT</pubDate><category>supply-chain</category><category>linux</category><category>backdoor</category></item><item><title>Ivanti Connect Secure Zero-Days — CVE-2025-0282 &amp; CVE-2025-0283</title><link>https://almamy.net/security/2024-12-ivanti-zero-day/</link><guid isPermaLink="true">https://almamy.net/security/2024-12-ivanti-zero-day/</guid><description>Two zero-day vulnerabilities in Ivanti Connect Secure allowed unauthenticated remote code execution before patches were available.</description><pubDate>Wed, 08 Jan 2025 00:00:00 GMT</pubDate><category>vpn</category><category>zero-day</category><category>rce</category><category>ivanti</category></item></channel></rss>