<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>sn1per pro - Sn1perSecurity</title>
	<atom:link href="https://sn1persecurity.com/wordpress/tag/sn1per-pro/feed/" rel="self" type="application/rss+xml" />
	<link>https://sn1persecurity.com/wordpress</link>
	<description>Get an attacker&#039;s view of your organization with our all-in-one offensive security platform</description>
	<lastBuildDate>Mon, 03 Aug 2026 17:36:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://sn1persecurity.com/wordpress/wp-content/uploads/2023/03/favoriteiconsniper.png</url>
	<title>sn1per pro - Sn1perSecurity</title>
	<link>https://sn1persecurity.com/wordpress</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">197797428</site>	<item>
		<title>CVE-2026-42533: NGINX map Directive Heap Buffer Overflow &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/cve-2026-42533-nginx-map-heap-overflow-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cve-2026-42533-nginx-map-heap-overflow-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 17:08:57 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[aslr-bypass]]></category>
		<category><![CDATA[cve-2026-42533]]></category>
		<category><![CDATA[heap-buffer-overflow]]></category>
		<category><![CDATA[memory-corruption]]></category>
		<category><![CDATA[nginx-map-directive]]></category>
		<category><![CDATA[nginx-security]]></category>
		<category><![CDATA[nginx-vulnerability]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[web-server-security]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/cve-2026-42533-nginx-map-heap-overflow-detection-with-sn1per/</guid>

					<description><![CDATA[<p>CVE-2026-42533 is a critical heap buffer overflow in the NGINX script engine reached through the map directive, with weaponized public exploit code that defeats ASLR. A plain-English advisory, a tested non-destructive Nuclei detection template, and the two-window version trap that makes naive scanners clear every mainline 1.31.x host as patched.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/cve-2026-42533-nginx-map-heap-overflow-detection-with-sn1per/">CVE-2026-42533: NGINX map Directive Heap Buffer Overflow – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65605</post-id>	</item>
		<item>
		<title>CVE-2026-42945 (NGINX Rift): Heap Buffer Overflow in the Rewrite Module &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/cve-2026-42945-nginx-rift-heap-overflow-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cve-2026-42945-nginx-rift-heap-overflow-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 17:08:55 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[cve-2026-42945]]></category>
		<category><![CDATA[heap-buffer-overflow]]></category>
		<category><![CDATA[memory-corruption]]></category>
		<category><![CDATA[nginx-rift]]></category>
		<category><![CDATA[nginx-security]]></category>
		<category><![CDATA[nginx-vulnerability]]></category>
		<category><![CDATA[ngx-http-rewrite-module]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[unauthenticated-rce]]></category>
		<category><![CDATA[web-server-security]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/cve-2026-42945-nginx-rift-heap-overflow-detection-with-sn1per/</guid>

					<description><![CDATA[<p>CVE-2026-42945, known as NGINX Rift, is a critical heap buffer overflow in ngx_http_rewrite_module reachable from a single unauthenticated request, with exploitation reported in the wild. A plain-English advisory, a tested non-destructive Nuclei detection template, a configuration audit template for the pattern nginx -t will not warn you about, and why upgrading to 1.30.1 leaves you exposed.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/cve-2026-42945-nginx-rift-heap-overflow-detection-with-sn1per/">CVE-2026-42945 (NGINX Rift): Heap Buffer Overflow in the Rewrite Module – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65603</post-id>	</item>
		<item>
		<title>CVE-2026-61511: Pre-Auth Remote Code Execution in vBulletin (runMaths) &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 19:54:35 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[cve-2026-61511]]></category>
		<category><![CDATA[eval-injection]]></category>
		<category><![CDATA[forum-security]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[php-rce]]></category>
		<category><![CDATA[runmaths]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[unauthenticated-rce]]></category>
		<category><![CDATA[vbulletin-rce]]></category>
		<category><![CDATA[vbulletin-security]]></category>
		<category><![CDATA[vbulletin-vulnerability]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per/</guid>

					<description><![CDATA[<p>CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a tested non-destructive Nuclei detection template, the 6.x patch-level trap that hides unpatched hosts, and how to find vulnerable vBulletin at scale with Sn1per.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per/">CVE-2026-61511: Pre-Auth Remote Code Execution in vBulletin (runMaths) – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65542</post-id>	</item>
		<item>
		<title>CVE-2026-50522: Unauthenticated Deserialization RCE in Microsoft SharePoint Server &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/cve-2026-50522-sharepoint-rce-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cve-2026-50522-sharepoint-rce-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 20:50:20 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[cve-2026-50522]]></category>
		<category><![CDATA[deserialization]]></category>
		<category><![CDATA[machine-key-theft]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[sharepoint-deserialization]]></category>
		<category><![CDATA[sharepoint-rce]]></category>
		<category><![CDATA[sharepoint-security]]></category>
		<category><![CDATA[sharepoint-vulnerability]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[unauthenticated-rce]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/cve-2026-50522-sharepoint-rce-detection-with-sn1per/</guid>

					<description><![CDATA[<p>CVE-2026-50522 is a critical, actively-exploited unauthenticated RCE in on-prem Microsoft SharePoint Server (2016, 2019, Subscription Edition). A plain-English advisory, a ready-to-run non-destructive Nuclei detection template, remediation with machine-key rotation, and how to detect vulnerable SharePoint at scale with Sn1per.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/cve-2026-50522-sharepoint-rce-detection-with-sn1per/">CVE-2026-50522: Unauthenticated Deserialization RCE in Microsoft SharePoint Server – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65475</post-id>	</item>
		<item>
		<title>wp2shell (CVE-2026-63030): Unauthenticated Pre-Auth RCE in WordPress Core &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/wp2shell-cve-2026-63030-wordpress-rce-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=wp2shell-cve-2026-63030-wordpress-rce-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Sat, 18 Jul 2026 19:00:36 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[cve-2026-60137]]></category>
		<category><![CDATA[cve-2026-63030]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[unauthenticated-rce]]></category>
		<category><![CDATA[wordpress-rce]]></category>
		<category><![CDATA[wordpress-security]]></category>
		<category><![CDATA[wordpress-vulnerability]]></category>
		<category><![CDATA[wp2shell]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/wp2shell-cve-2026-63030-wordpress-rce-detection-with-sn1per/</guid>

					<description><![CDATA[<p>wp2shell (CVE-2026-63030) is an unauthenticated pre-auth RCE in WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1. A plain-English advisory, a ready-to-run Nuclei detection template, remediation, and how to detect affected WordPress at scale with Sn1per.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/wp2shell-cve-2026-63030-wordpress-rce-detection-with-sn1per/">wp2shell (CVE-2026-63030): Unauthenticated Pre-Auth RCE in WordPress Core – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65281</post-id>	</item>
		<item>
		<title>Network and Subnet Discovery: Map Your Internal Attack Surface with Sn1per Pro 2026</title>
		<link>https://sn1persecurity.com/wordpress/network-subnet-discovery/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=network-subnet-discovery</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Sun, 12 Jul 2026 13:33:26 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[asset-discovery]]></category>
		<category><![CDATA[attack-surface-management]]></category>
		<category><![CDATA[connected-devices]]></category>
		<category><![CDATA[internal-attack-surface]]></category>
		<category><![CDATA[network-discovery]]></category>
		<category><![CDATA[network-subnet-discovery]]></category>
		<category><![CDATA[self-hosted]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[subnet-scanning]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/network-subnet-discovery/</guid>

					<description><![CDATA[<p>Discover live hosts, open ports, services, and connected devices across your internal subnets with Sn1per Professional 2026 - a self-hosted, automated network and subnet discovery tool you run from the CLI or a web dashboard.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/network-subnet-discovery/">Network and Subnet Discovery: Map Your Internal Attack Surface with Sn1per Pro 2026</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65161</post-id>	</item>
		<item>
		<title>Continuous Penetration Testing (PTaaS): Beyond the Once-a-Year Pentest</title>
		<link>https://sn1persecurity.com/wordpress/continuous-penetration-testing/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=continuous-penetration-testing</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Thu, 18 Jun 2026 16:18:20 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[automated penetration testing]]></category>
		<category><![CDATA[continuous-penetration-testing]]></category>
		<category><![CDATA[continuous-testing]]></category>
		<category><![CDATA[managed-penetration-testing]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[ptaas]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/continuous-penetration-testing/</guid>

					<description><![CDATA[<p>The annual pentest is stale within weeks. A 2026 guide to continuous penetration testing and PTaaS - how it differs from point-in-time testing and from continuous ASM, and how to run it with Sn1per.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/continuous-penetration-testing/">Continuous Penetration Testing (PTaaS): Beyond the Once-a-Year Pentest</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">64650</post-id>	</item>
		<item>
		<title>Automated Penetration Testing: What It Is, How It Works, and Where It Needs Humans (2026)</title>
		<link>https://sn1persecurity.com/wordpress/automated-penetration-testing/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=automated-penetration-testing</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Thu, 18 Jun 2026 16:18:10 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[automated penetration testing]]></category>
		<category><![CDATA[automated-pentesting]]></category>
		<category><![CDATA[automated-vs-manual]]></category>
		<category><![CDATA[offensive-security]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[pentest-automation]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/automated-penetration-testing/</guid>

					<description><![CDATA[<p>Automated penetration testing, explained without the hype. What it is, automated vs manual (and why you need both), what automation can and cannot do, the workflow, and where Sn1per fits.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/automated-penetration-testing/">Automated Penetration Testing: What It Is, How It Works, and Where It Needs Humans (2026)</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">64646</post-id>	</item>
		<item>
		<title>Continuous Attack Surface Testing: From Periodic Red Team Engagements to Always-On Validation</title>
		<link>https://sn1persecurity.com/wordpress/continuous-attack-surface-testing/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=continuous-attack-surface-testing</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Wed, 17 Jun 2026 18:18:00 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Red Team]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[attack-surface-management]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[continuous-attack-surface-testing]]></category>
		<category><![CDATA[continuous-monitoring]]></category>
		<category><![CDATA[continuous-penetration-testing]]></category>
		<category><![CDATA[ctem]]></category>
		<category><![CDATA[red-team]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/continuous-attack-surface-testing/</guid>

					<description><![CDATA[<p>The annual pentest is a photograph of a moving target. A 2026 guide to continuous attack surface testing, the CTEM framework, and building an always-on red team loop with Sn1per - scheduled scans, drift detection, and validation.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/continuous-attack-surface-testing/">Continuous Attack Surface Testing: From Periodic Red Team Engagements to Always-On Validation</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">64628</post-id>	</item>
		<item>
		<title>Red Team Attack Surface Management: How Offensive Teams Map and Validate the External Attack Surface (2026)</title>
		<link>https://sn1persecurity.com/wordpress/red-team-attack-surface-management/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=red-team-attack-surface-management</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Wed, 17 Jun 2026 18:17:58 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Red Team]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[attack-surface-management]]></category>
		<category><![CDATA[ctem]]></category>
		<category><![CDATA[easm]]></category>
		<category><![CDATA[external-attack-surface-management]]></category>
		<category><![CDATA[offensive-security]]></category>
		<category><![CDATA[reconnaissance]]></category>
		<category><![CDATA[red-team]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[sn1per-enterprise]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/red-team-attack-surface-management/</guid>

					<description><![CDATA[<p>A red team sees your organization from the outside in. A 2026 guide to red team attack surface management - the offensive ASM workflow, why an inventory is not an attack surface, and what to look for in an attack surface management platform.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/red-team-attack-surface-management/">Red Team Attack Surface Management: How Offensive Teams Map and Validate the External Attack Surface (2026)</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">64626</post-id>	</item>
	</channel>
</rss>
