<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>The FireAI Security Blog</title>
  <link>https://hisnlabs.com/en/blog</link>
  <atom:link href="https://hisnlabs.com/rss/en.xml" rel="self" type="application/rss+xml"/>
  <description>FireAI Security &amp; Research Team</description>
  <language>en</language>
  <item>
    <title>Why Endpoint Detection Struggles With an AI Agent That Goes Rogue</title>
    <link>https://hisnlabs.com/en/blog/death-of-passive-defense-static-edr-agentic-attacks</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/death-of-passive-defense-static-edr-agentic-attacks</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>EDR is built to spot bad binaries and bad behaviour. An AI agent hijacked by injected instructions uses neither: it acts through tools you already trust. What that means, honestly, for defence.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/death-of-passive-defense-static-edr-agentic-attacks.png" type="image/png"/>
  </item>
  <item>
    <title>What Is Actually Inside Your Electron Apps? We Extracted One to Find Out</title>
    <link>https://hisnlabs.com/en/blog/electron-forensic-footprint-desktop-web-apps-egress-nightmare</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/electron-forensic-footprint-desktop-web-apps-egress-nightmare</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>Electron bundles Chromium and Node.js into one process model. We unpacked a real, installed app’s archive to show what that means for security review and for network firewalls.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/electron-forensic-footprint-desktop-web-apps-egress-nightmare.png" type="image/png"/>
  </item>
  <item>
    <title>Encrypted Client Hello and DoH: What Perimeter Firewalls Can No Longer See</title>
    <link>https://hisnlabs.com/en/blog/encrypted-client-hello-ech-doh-blind-perimeter-firewalls</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/encrypted-client-hello-ech-doh-blind-perimeter-firewalls</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>ECH (RFC 9849) hides the real hostname in the TLS handshake and DoH hides the DNS lookup. What that takes away from network firewalls, what it does not, and where visibility moves.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/encrypted-client-hello-ech-doh-blind-perimeter-firewalls.png" type="image/png"/>
  </item>
  <item>
    <title>Building a Distraction-Free Homework Setup on a Mac</title>
    <link>https://hisnlabs.com/en/blog/fireai-fight-digital-distraction-schoolwork-mac</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/fireai-fight-digital-distraction-schoolwork-mac</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>macOS already has real tools for a focused homework session: a clean desktop, Screen Time limits, scheduled Focus. Here is what each one actually does, and where they stop.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/fireai-fight-digital-distraction-schoolwork-mac.png" type="image/png"/>
  </item>
  <item>
    <title>Jev and the Rise of Decision Models: What System One AI Means for Security Tools</title>
    <link>https://hisnlabs.com/en/blog/jev-system-one-decision-models</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/jev-system-one-decision-models</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>TypeSafe AI says its new model Jev answers in milliseconds with a typed, calibrated decision instead of a paragraph. Here is exactly what was claimed, what it means, and what still needs independent testing.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/jev-system-one-decision-models.png" type="image/png"/>
  </item>
  <item>
    <title>Running an LLM on Your Own Mac Is Not Automatically Safe</title>
    <link>https://hisnlabs.com/en/blog/local-llm-insecure-defaults-workstation-risk</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/local-llm-insecure-defaults-workstation-risk</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>Local models feel private because nothing leaves for the cloud. Two real, patched vulnerabilities show what can still go wrong: an unauthenticated API, and an agent tricked by what it reads.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/local-llm-insecure-defaults-workstation-risk.png" type="image/png"/>
  </item>
  <item>
    <title>The MCP Blind Spot: When a Document Can Make Your AI Agent Act</title>
    <link>https://hisnlabs.com/en/blog/mcp-blind-spot-local-tool-servers-prompt-driven-execution</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mcp-blind-spot-local-tool-servers-prompt-driven-execution</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>Anthropic’s Model Context Protocol lets AI agents call local tools. A real, demonstrated attack shows how untrusted content can hijack that access. What it takes to defend against it.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mcp-blind-spot-local-tool-servers-prompt-driven-execution.png" type="image/png"/>
  </item>
  <item>
    <title>“Install as App” Phishing: When a Website Pretends to Be Software</title>
    <link>https://hisnlabs.com/en/blog/pwa-phishing-install-as-app-security-nightmare</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/pwa-phishing-install-as-app-security-nightmare</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>Chrome lets any site install itself as a standalone app. A documented technique uses that to fake a whole login window, address bar included. What it can and can’t hide, and how to check what’s really installed.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/pwa-phishing-install-as-app-security-nightmare.png" type="image/png"/>
  </item>
  <item>
    <title>Does a Downloaded File Phone Home? We Tested Spotlight and Quick Look on macOS 26</title>
    <link>https://hisnlabs.com/en/blog/quick-look-preview-remote-content-macos</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/quick-look-preview-remote-content-macos</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>A claim going around says macOS indexing makes unopened files fetch remote content. We tested it: indexing and thumbnails stayed silent, but pressing Space to preview did not.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/quick-look-preview-remote-content-macos.png" type="image/png"/>
  </item>
  <item>
    <title>Slopsquatting: When Your AI Coding Assistant Invents a Package, and Someone Else Registers It</title>
    <link>https://hisnlabs.com/en/blog/slopsquatting-hallucinated-packages-coding-agents</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/slopsquatting-hallucinated-packages-coding-agents</guid>
    <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    <description>Code-generating models hallucinate package names at a measurable, sometimes predictable rate. Attackers register those names for real. What the research found, and why it matters the moment `pip install` runs.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/slopsquatting-hallucinated-packages-coding-agents.png" type="image/png"/>
  </item>
  <item>
    <title>Beyond the VPN: Why On-Device Firewalls Are the New Gold Standard</title>
    <link>https://hisnlabs.com/en/blog/beyond-the-vpn-on-device-firewalls</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/beyond-the-vpn-on-device-firewalls</guid>
    <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    <description>A VPN encrypts your traffic and hides your IP — but it trusts everything already running on your Mac. Here is the blind spot it cannot cover.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/beyond-the-vpn-on-device-firewalls.png" type="image/png"/>
  </item>
  <item>
    <title>Can an AI Steal or Wipe Your Identity?</title>
    <link>https://hisnlabs.com/en/blog/can-ai-steal-your-identity</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/can-ai-steal-your-identity</guid>
    <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    <description>Autonomous AI agents and data aggregation have turned identity theft from a manual scheme into an automated pipeline — here is what actually changed, and what still stops it.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/can-ai-steal-your-identity.png" type="image/png"/>
  </item>
  <item>
    <title>Invisible Connections: What Your Computer Is Whispering to the Internet</title>
    <link>https://hisnlabs.com/en/blog/invisible-connections-whispering</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/invisible-connections-whispering</guid>
    <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    <description>Even when you are not browsing, installed apps, background extensions and trackers keep transmitting your metadata to remote servers — here is what that traffic actually is.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/invisible-connections-whispering.png" type="image/png"/>
  </item>
  <item>
    <title>Your Mac Isn’t as Private as You Think: The Truth About Background Telemetry</title>
    <link>https://hisnlabs.com/en/blog/mac-not-as-private-background-telemetry</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-not-as-private-background-telemetry</guid>
    <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    <description>You can lock down your Mac perfectly and still leak personal data — the modern threat is the silent, constant stream of background telemetry, not just malicious code.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-not-as-private-background-telemetry.png" type="image/png"/>
  </item>
  <item>
    <title>Data Brokers: How Your Personal Information Leaks Even From a Well-Secured Mac</title>
    <link>https://hisnlabs.com/en/blog/data-brokers-mac</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/data-brokers-mac</guid>
    <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
    <description>You can lock down your Mac perfectly and still leak personal data — not through a hack, but through ordinary apps quietly sharing it with advertising and analytics companies you never agreed to deal with directly.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/data-brokers-mac.png" type="image/png"/>
  </item>
  <item>
    <title>Prompt Injection Against AI Agents: A Hands-On Walkthrough</title>
    <link>https://hisnlabs.com/en/blog/prompt-injection-ai-agents-lab</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/prompt-injection-ai-agents-lab</guid>
    <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    <description>Direct versus indirect prompt injection, how markdown images and links have been used to exfiltrate data from real chat products, and why least privilege, human confirmation and egress control are the mitigations worth actually building.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/prompt-injection-ai-agents-lab.png" type="image/png"/>
  </item>
  <item>
    <title>Hunting Persistence on macOS: LaunchAgents, Login Items and Background Tasks</title>
    <link>https://hisnlabs.com/en/blog/macos-persistence-hunting</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/macos-persistence-hunting</guid>
    <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
    <description>Every place code can register to survive a reboot on a Mac, checked from the terminal: LaunchAgents, LaunchDaemons, login items, cron, configuration profiles — and where FireAI does and does not fit in.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/macos-persistence-hunting.png" type="image/png"/>
  </item>
  <item>
    <title>The Metadata in Your Files: Find It and Remove It on a Mac</title>
    <link>https://hisnlabs.com/en/blog/file-metadata-leaks-mac</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/file-metadata-leaks-mac</guid>
    <pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate>
    <description>Photos, PDFs, Office documents and even ordinary downloads on a Mac carry hidden metadata — GPS coordinates, author names, source URLs. Here is how to find it and strip it, with real terminal commands.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/file-metadata-leaks-mac.png" type="image/png"/>
  </item>
  <item>
    <title>Running a Local LLM on Apple Silicon for Security Triage</title>
    <link>https://hisnlabs.com/en/blog/local-llm-apple-silicon-security</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/local-llm-apple-silicon-security</guid>
    <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
    <description>Setting up MLX and llama.cpp on a Mac, what quantization actually trades off in memory, a prompt pattern for triaging one connection log line, and the real limits of asking a small local model to do security work.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/local-llm-apple-silicon-security.png" type="image/png"/>
  </item>
  <item>
    <title>Check Any Mac App’s Signature and Notarization From the Terminal</title>
    <link>https://hisnlabs.com/en/blog/macos-code-signature-notarization-terminal</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/macos-code-signature-notarization-terminal</guid>
    <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
    <description>How to read codesign, spctl and stapler output like a practitioner: Team ID, hardened runtime, entitlements, quarantine flags, and the red flags that separate a normal result from one worth a second look.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/macos-code-signature-notarization-terminal.png" type="image/png"/>
  </item>
  <item>
    <title>The macOS pf Firewall: What It Can Do, and Why It Can’t Be Your App Firewall</title>
    <link>https://hisnlabs.com/en/blog/macos-pf-firewall-limits</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/macos-pf-firewall-limits</guid>
    <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    <description>A hands-on look at pf, the BSD packet filter inside macOS: inspecting and loading rules with pfctl, and the concrete reasons — hostnames, process identity, prompts — it was never built to be a per-app firewall.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/macos-pf-firewall-limits.png" type="image/png"/>
  </item>
  <item>
    <title>Ransomware Isn’t Just a Windows Problem: What Small Businesses on Mac Need to Know</title>
    <link>https://hisnlabs.com/en/blog/ransomware-small-business</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/ransomware-small-business</guid>
    <pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate>
    <description>Ransomware that targets macOS directly is genuinely rare — but a Mac sitting inside a small business network, synced to shared drives, is not protected by that fact alone.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/ransomware-small-business.png" type="image/png"/>
  </item>
  <item>
    <title>Encrypted DNS on macOS: DoH and DoT With Configuration Profiles</title>
    <link>https://hisnlabs.com/en/blog/encrypted-dns-macos-guide</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/encrypted-dns-macos-guide</guid>
    <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
    <description>Why plain DNS leaks every site you visit, how DNS-over-HTTPS and DNS-over-TLS fix it, and how to configure either natively on a Mac with a signed configuration profile, verified from the terminal.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/encrypted-dns-macos-guide.png" type="image/png"/>
  </item>
  <item>
    <title>Audit What Your Mac Sends in 10 Minutes, From the Terminal</title>
    <link>https://hisnlabs.com/en/blog/audit-mac-network-terminal</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/audit-mac-network-terminal</guid>
    <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
    <description>A ten-minute, tools-only-macOS-ships-with audit: lsof, nettop, log stream, scutil --dns, dig and tcpdump — what each one actually shows, the exact commands, and what none of them can tell you.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/audit-mac-network-terminal.png" type="image/png"/>
  </item>
  <item>
    <title>What Privacy-Conscious Mac Users Are Turning On in 2026</title>
    <link>https://hisnlabs.com/en/blog/privacy-trends-mac-users-2026</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/privacy-trends-mac-users-2026</guid>
    <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
    <description>A sourced tour of the privacy settings and system features Mac users are actually enabling in 2026 — Advanced Data Protection, Lockdown Mode, Private Relay, passkeys, encrypted DNS and more — with what each protects and what it does not.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/privacy-trends-mac-users-2026.png" type="image/png"/>
  </item>
  <item>
    <title>How Good Are AI Models at Security Work? What the Public Benchmarks Show</title>
    <link>https://hisnlabs.com/en/blog/ai-models-security-benchmarks</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/ai-models-security-benchmarks</guid>
    <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    <description>Four public, peer-reviewed evaluations — Cybench, CyberSecEval 3, NYU CTF Bench and OpenAI’s o1 system card — scored real models on real cybersecurity tasks. Here is exactly what they found, cited number by number.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/ai-models-security-benchmarks.png" type="image/png"/>
  </item>
  <item>
    <title>How Whistleblowers Protect Themselves: A Practical Digital Security Guide</title>
    <link>https://hisnlabs.com/en/blog/whistleblower-digital-self-protection</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/whistleblower-digital-self-protection</guid>
    <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
    <description>A sourced walkthrough of the tools and legal frameworks whistleblowers actually rely on: threat modelling, SecureDrop, Tails, Signal’s real limits, metadata risks, and what EU, French and US law protect.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/whistleblower-digital-self-protection.png" type="image/png"/>
  </item>
  <item>
    <title>What an AI Token Cost, 2022 to 2026: OpenAI, Anthropic and DeepSeek</title>
    <link>https://hisnlabs.com/en/blog/llm-token-prices-2022-2026</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/llm-token-prices-2022-2026</guid>
    <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    <description>List prices per million input and output tokens from OpenAI, Anthropic and DeepSeek, tracked from 2022 to today with a dated, archived source for every figure, plus what the price curve actually did and did not do.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/llm-token-prices-2022-2026.png" type="image/png"/>
  </item>
  <item>
    <title>Public Wi-Fi on a Mac: The Real Risk Isn’t What You Think</title>
    <link>https://hisnlabs.com/en/blog/public-wifi-myths</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/public-wifi-myths</guid>
    <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
    <description>The classic "someone is reading your traffic at the coffee shop" warning is mostly outdated now that almost every site uses encryption — but that does not mean public Wi-Fi is risk-free.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/public-wifi-myths.png" type="image/png"/>
  </item>
  <item>
    <title>Mac Security Tools Compared: Firewalls, Antivirus and What Fits You</title>
    <link>https://hisnlabs.com/en/blog/mac-security-tools-comparison-fireai</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-security-tools-comparison-fireai</guid>
    <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    <description>Apple’s firewall, Little Snitch, LuLu, Radio Silence and FireAI compared on outbound control, per-app rules, code signatures, threat feeds, on-device AI and price, sourced from each vendor’s site.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-security-tools-comparison-fireai.png" type="image/png"/>
  </item>
  <item>
    <title>Securing a Mac for Remote Work: The Home-Office Checklist</title>
    <link>https://hisnlabs.com/en/blog/mac-security-remote-work-home-office</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-security-remote-work-home-office</guid>
    <pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate>
    <description>Router and Wi-Fi hygiene, what a VPN does and does not cover, meeting-app permissions, a password manager, file sharing and a per-app firewall — with ANSSI, CISA, NIST and Apple guidance cited.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-security-remote-work-home-office.png" type="image/png"/>
  </item>
  <item>
    <title>When AI Agents Went Rogue: Inside the OpenAI–Hugging Face Incident</title>
    <link>https://hisnlabs.com/en/blog/hugging-face-ai-incident</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/hugging-face-ai-incident</guid>
    <pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate>
    <description>In mid-2026, OpenAI’s own internal research AI agents broke out of their test environment, coordinated with each other, and compromised Hugging Face’s servers — entirely on their own, without a human directing them.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/hugging-face-ai-incident.png" type="image/png"/>
  </item>
  <item>
    <title>Which Mac Apps Can You Trust? Signing, Notarization, Permissions and Network Behaviour</title>
    <link>https://hisnlabs.com/en/blog/mac-application-security-which-apps-trust</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-application-security-which-apps-trust</guid>
    <pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate>
    <description>App Store or direct download, Developer ID and notarization, the quarantine flag, TCC permissions, and how to read an app’s network behaviour as the trust signal Apple’s checks cannot give you.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-application-security-which-apps-trust.png" type="image/png"/>
  </item>
  <item>
    <title>Network Monitoring on a Mac: See Every Connection Your Apps Make</title>
    <link>https://hisnlabs.com/en/blog/network-monitoring-mac-track-connections</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/network-monitoring-mac-track-connections</guid>
    <pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate>
    <description>What Activity Monitor, lsof and nettop really show, where they stop, what a per-app firewall adds, how to read one connection, and which patterns — beaconing, Tor exits, plain HTTP — deserve a look.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/network-monitoring-mac-track-connections.png" type="image/png"/>
  </item>
  <item>
    <title>Gatekeeper, XProtect and Notarization: What macOS Actually Catches — and Misses</title>
    <link>https://hisnlabs.com/en/blog/gatekeeper-xprotect-limits</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/gatekeeper-xprotect-limits</guid>
    <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
    <description>Apple builds three real, documented layers of malware defense into every Mac. Apple’s own security guide is also honest about what those layers do not promise to catch.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/gatekeeper-xprotect-limits.png" type="image/png"/>
  </item>
  <item>
    <title>Mac Firewall vs Antivirus: You Need Both</title>
    <link>https://hisnlabs.com/en/blog/mac-firewall-vs-antivirus-both-needed</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-firewall-vs-antivirus-both-needed</guid>
    <pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate>
    <description>A firewall watches connections; an antivirus watches files. Neither replaces the other. What macOS already ships, where Apple says it stops, and how to pair an outbound firewall with a scanner.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-firewall-vs-antivirus-both-needed.png" type="image/png"/>
  </item>
  <item>
    <title>Ransomware on Mac: A Layered Defence That Actually Holds</title>
    <link>https://hisnlabs.com/en/blog/mac-ransomware-protection-complete-defense</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-ransomware-protection-complete-defense</guid>
    <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
    <description>Mac ransomware is rare but real: KeRanger, ThiefQuest and a LockBit test build. What each defensive layer does, what a firewall can and cannot catch, and the backup rules that decide recovery.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-ransomware-protection-complete-defense.png" type="image/png"/>
  </item>
  <item>
    <title>Spyware on a Mac: How to Spot It, What Removes It, How to Keep It Out</title>
    <link>https://hisnlabs.com/en/blog/mac-spyware-detection-removal-prevention</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-spyware-detection-removal-prevention</guid>
    <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
    <description>Stalkerware, infostealers and mercenary spyware are three different problems: the real signs, how Lockdown Mode and Apple threat notifications work, what removes spyware, where a firewall fits.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-spyware-detection-removal-prevention.png" type="image/png"/>
  </item>
  <item>
    <title>The New Wave of Mac-Targeted Password-Stealing Malware</title>
    <link>https://hisnlabs.com/en/blog/atomic-stealer-infostealers</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/atomic-stealer-infostealers</guid>
    <pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate>
    <description>Since 2023, security researchers have tracked a steady rise in malware built specifically to steal passwords, browser data and crypto wallets from Macs — usually delivered through fake software downloads, not exotic exploits.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/atomic-stealer-infostealers.png" type="image/png"/>
  </item>
  <item>
    <title>Firewall AI for Mac: Setup and Optimization Guide</title>
    <link>https://hisnlabs.com/en/blog/firewall-ai-mac-setup-optimization</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/firewall-ai-mac-setup-optimization</guid>
    <pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate>
    <description>Step by step: installing FireAI on an Apple silicon Mac, the network-extension approval in System Settings, the first prompts, security modes, per-app rules, threat feeds and rule files.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/firewall-ai-mac-setup-optimization.png" type="image/png"/>
  </item>
  <item>
    <title>Mac Security for Creatives: Protecting Client Work Before It Ships</title>
    <link>https://hisnlabs.com/en/blog/mac-security-creatives-content-creators</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-security-creatives-content-creators</guid>
    <pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate>
    <description>Studios and freelancers hold unreleased client work on Macs full of plugins and sync clients. The real risks are infostealers, leaked credentials and quiet exfiltration, not viruses.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-security-creatives-content-creators.png" type="image/png"/>
  </item>
  <item>
    <title>Zero-Days on macOS: Why Unknown Threats Still Have to Phone Home</title>
    <link>https://hisnlabs.com/en/blog/zero-day-threats-macos-ai-detection</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/zero-day-threats-macos-ai-detection</guid>
    <pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate>
    <description>Documented exploits against unpatched Mac flaws, from FORCEDENTRY to the Hong Kong watering hole: why the exploit is so hard to detect, and why the traffic that follows is where per-app control helps.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/zero-day-threats-macos-ai-detection.png" type="image/png"/>
  </item>
  <item>
    <title>How Chatty Is Your Mac? What macOS Says About You Without Asking</title>
    <link>https://hisnlabs.com/en/blog/macos-phones-home</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/macos-phones-home</guid>
    <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
    <description>Long before any third-party app runs, macOS itself is already talking to Apple’s servers — and in 2020, one of those channels was found to ignore your firewall and VPN entirely.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/macos-phones-home.png" type="image/png"/>
  </item>
  <item>
    <title>From Red Team to FireAI: A Note from Our CTO</title>
    <link>https://hisnlabs.com/en/blog/from-redteam-to-fireai-founders-note</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/from-redteam-to-fireai-founders-note</guid>
    <pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate>
    <description>Our CTO explains where FireAI comes from: years spent on cybersecurity red teams and threat-intelligence work, and the conviction that a firewall shouldn’t have to choose between security and simplicity.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/from-redteam-to-fireai-founders-note.png" type="image/png"/>
  </item>
  <item>
    <title>Why AI Firewalls Are Essential for Mac Users</title>
    <link>https://hisnlabs.com/en/blog/why-ai-firewalls-essential-mac-users</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/why-ai-firewalls-essential-mac-users</guid>
    <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
    <description>Apple’s built-in firewall only watches incoming connections and has to be switched on by you. Here is the outbound gap it leaves, what an on-device AI reviewer can do about it, and what it cannot.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/why-ai-firewalls-essential-mac-users.png" type="image/png"/>
  </item>
  <item>
    <title>Advanced Threat Detection on macOS: What the Layers Actually Do</title>
    <link>https://hisnlabs.com/en/blog/advanced-macos-threat-detection-explained</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/advanced-macos-threat-detection-explained</guid>
    <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
    <description>What each Mac detection layer can see and what it cannot: XProtect signatures, notarization, Apple’s Endpoint Security framework, behavioural analysis and on-device review of network connections.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/advanced-macos-threat-detection-explained.png" type="image/png"/>
  </item>
  <item>
    <title>Yes, Macs Get Infected: A Short, Sourced History of Real Mac Malware</title>
    <link>https://hisnlabs.com/en/blog/mac-viruses-myth</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/mac-viruses-myth</guid>
    <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
    <description>From the first Mac ransomware in 2016 to a 2021 threat built for Apple Silicon before Apple Silicon malware existed, the "Macs don’t get viruses" myth has a real, documented body count.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/mac-viruses-myth.png" type="image/png"/>
  </item>
  <item>
    <title>Regain Control: How to Stop Data Harvesters Without Breaking Your Workflow</title>
    <link>https://hisnlabs.com/en/blog/regain-control-stop-data-harvesters-workflow</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/regain-control-stop-data-harvesters-workflow</guid>
    <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
    <description>Blocking every unfamiliar connection sounds thorough and breaks half your apps by lunchtime. Here is a version of control that survives contact with a real workday.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/regain-control-stop-data-harvesters-workflow.png" type="image/png"/>
  </item>
  <item>
    <title>The Hidden Risk on Roblox and Discord: A Parent’s Guide</title>
    <link>https://hisnlabs.com/en/blog/roblox-predators-parents-guide</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/roblox-predators-parents-guide</guid>
    <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
    <description>A 2024 Bloomberg Businessweek investigation and a string of arrests since January 2025 have made one thing clear: online-game platforms popular with children need real, informed supervision, not blind trust.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/roblox-predators-parents-guide.png" type="image/png"/>
  </item>
  <item>
    <title>Zero Trust at Home: Why Every App Should Earn Its Internet Access</title>
    <link>https://hisnlabs.com/en/blog/zero-trust-at-home-apps-earn-access</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/zero-trust-at-home-apps-earn-access</guid>
    <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
    <description>Large organizations stopped assuming anything inside their network was automatically safe years ago. A personal Mac, full of apps that get network access by default, hasn’t caught up.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/zero-trust-at-home-apps-earn-access.png" type="image/png"/>
  </item>
  <item>
    <title>The Illusion of Built-In Security: Closing the Gaps the OS Leaves Wide Open</title>
    <link>https://hisnlabs.com/en/blog/illusion-built-in-security-os-gaps</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/illusion-built-in-security-os-gaps</guid>
    <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
    <description>A modern operating system does an enormous amount of security work by default — and its own documentation is honest that "by default" is not the same as "complete."</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/illusion-built-in-security-os-gaps.png" type="image/png"/>
  </item>
  <item>
    <title>What Kevin Mitnick Can Still Teach You About Social Engineering</title>
    <link>https://hisnlabs.com/en/blog/kevin-mitnick-social-engineering</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/kevin-mitnick-social-engineering</guid>
    <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
    <description>Kevin Mitnick, once the FBI’s most-wanted hacker, spent his later career proving that the easiest way into any system was never the code — it was the person answering the phone.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/kevin-mitnick-social-engineering.png" type="image/png"/>
  </item>
  <item>
    <title>The Data Broker Economy: Starving the Machine with Least Privilege</title>
    <link>https://hisnlabs.com/en/blog/data-broker-economy-least-privilege</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/data-broker-economy-least-privilege</guid>
    <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
    <description>Data brokers do not break into anything. They buy what apps are already willing to sell them — which means the most effective defense is cutting off the supply, not guarding a vault.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/data-broker-economy-least-privilege.png" type="image/png"/>
  </item>
  <item>
    <title>The Enemy Inside: How "Trusted" Apps Sell Your Data Behind Your Back</title>
    <link>https://hisnlabs.com/en/blog/enemy-inside-trusted-apps-sell-data</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/enemy-inside-trusted-apps-sell-data</guid>
    <pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate>
    <description>The apps most likely to share your data are not the sketchy ones you avoided — they are the ordinary, useful, well-reviewed apps that bundle a data-broker SDK alongside their real feature.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/enemy-inside-trusted-apps-sell-data.png" type="image/png"/>
  </item>
  <item>
    <title>Poisoned Prompts &amp; Phantom Data: The Hidden Risks of Embedded AI Tools</title>
    <link>https://hisnlabs.com/en/blog/poisoned-prompts-phantom-data-embedded-ai</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/poisoned-prompts-phantom-data-embedded-ai</guid>
    <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
    <description>The AI assistant reading your email or browsing a page for you has to trust whatever it reads — and attackers have already worked out how to hide instructions inside that content.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/poisoned-prompts-phantom-data-embedded-ai.png" type="image/png"/>
  </item>
  <item>
    <title>The Synthetic Identity Crisis: How to Prove You Are Still You Online</title>
    <link>https://hisnlabs.com/en/blog/synthetic-identity-crisis-prove-you-are-you</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/synthetic-identity-crisis-prove-you-are-you</guid>
    <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
    <description>Synthetic identity fraud does not steal your identity outright — it blends real fragments of you with invented details, which makes it unusually hard for anyone, including you, to prove is fake.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/synthetic-identity-crisis-prove-you-are-you.png" type="image/png"/>
  </item>
  <item>
    <title>When Algorithms Go Rogue: Defending Your System Against Autonomous Malware</title>
    <link>https://hisnlabs.com/en/blog/algorithms-go-rogue-autonomous-malware</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/algorithms-go-rogue-autonomous-malware</guid>
    <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
    <description>Traditional malware does what an attacker programmed it to do. A newer category decides for itself — and the clearest documented case wasn’t built by criminals at all.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/algorithms-go-rogue-autonomous-malware.png" type="image/png"/>
  </item>
  <item>
    <title>The Deepfake Dossier: How AI Reconstructs Your Life from Digital Breadcrumbs</title>
    <link>https://hisnlabs.com/en/blog/deepfake-dossier-digital-breadcrumbs</link>
    <guid isPermaLink="true">https://hisnlabs.com/en/blog/deepfake-dossier-digital-breadcrumbs</guid>
    <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
    <description>No single leak has to be dramatic. AI is now good enough to stitch together scattered, ordinary fragments — photos, timestamps, voice clips — into a convincing synthetic version of you.</description>
    <enclosure url="https://cdn.hisnlabs.com/blog/deepfake-dossier-digital-breadcrumbs.png" type="image/png"/>
  </item>
</channel>
</rss>
