<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Savount by APOLLOSEC</title><link>https://www.apollo-sec.com/savount</link><description>Research and analysis on cyber conflict, AI and the powers behind them.</description><language>en-gb</language><item><title>AI agents are powerful. Are they secure?</title><link>https://www.apollo-sec.com/savount/dont-give-your-ai-agent-the-keys-to-the-kingdom</link><guid>https://www.apollo-sec.com/savount/dont-give-your-ai-agent-the-keys-to-the-kingdom</guid><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><description>Securing agentic AI before it becomes your biggest attack surface: prompt injection, memory poisoning, tool misuse and the defences that work.</description></item><item><title>Securing New Agentic Workers</title><link>https://www.apollo-sec.com/savount/securing-new-agentic-workers</link><guid>https://www.apollo-sec.com/savount/securing-new-agentic-workers</guid><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><description>A practical hardening guide for desktop AI agents: sandboxing, allow-lists, secrets, logging, and keeping work and personal contexts apart.</description></item><item><title>How to Secure Your DevOps Pipeline: Risks, Tools, and Best Practices</title><link>https://www.apollo-sec.com/savount/how-to-secure-your-devops-pipeline-risks-tools-and-best-practices</link><guid>https://www.apollo-sec.com/savount/how-to-secure-your-devops-pipeline-risks-tools-and-best-practices</guid><pubDate>Sun, 25 May 2025 00:00:00 +0000</pubDate><description>The risks in modern CI/CD pipelines, the tools that help, and the practices that keep secrets, dependencies and build systems away from attackers.</description></item><item><title>Lessons From Recent Cyberattacks</title><link>https://www.apollo-sec.com/savount/lessons-from-recent-cyberattacks</link><guid>https://www.apollo-sec.com/savount/lessons-from-recent-cyberattacks</guid><pubDate>Sun, 25 May 2025 00:00:00 +0000</pubDate><description>M&amp;S, Co-op and Harrods, Cartier and Coinbase: what recent attacks have in common, the techniques used, and what defenders should take from them.</description></item><item><title>Emulating the Enemy – How Adversary Emulation is Elevating Offensive Security</title><link>https://www.apollo-sec.com/savount/emulating-the-enemy-how-adversary-emulation-is-elevating-offensive-security</link><guid>https://www.apollo-sec.com/savount/emulating-the-enemy-how-adversary-emulation-is-elevating-offensive-security</guid><pubDate>Fri, 25 Apr 2025 00:00:00 +0000</pubDate><description>How adversary emulation moved offensive security beyond the annual penetration test, and how to use real attacker behaviour to test your defences.</description></item><item><title>Replacing Annual Penetration Testing with Continuous Pen Testing</title><link>https://www.apollo-sec.com/savount/replacing-annual-penetration-testing-with-continuous-pen-testing</link><guid>https://www.apollo-sec.com/savount/replacing-annual-penetration-testing-with-continuous-pen-testing</guid><pubDate>Fri, 25 Apr 2025 00:00:00 +0000</pubDate><description>Why a yearly penetration test describes a system that no longer exists, and how continuous penetration testing closes the gap.</description></item><item><title>Critical Vulnerabilities Keep Coming: The Urgency of Proactive Security</title><link>https://www.apollo-sec.com/savount/critical-vulnerabilities-keep-coming-the-urgency-of-proactive-security</link><guid>https://www.apollo-sec.com/savount/critical-vulnerabilities-keep-coming-the-urgency-of-proactive-security</guid><pubDate>Sun, 30 Mar 2025 00:00:00 +0000</pubDate><description>The gap between disclosure and exploitation keeps shrinking. Why critical vulnerabilities demand continuous, proactive security, not a yearly test.</description></item><item><title>Lessons from Hellcat’s Jira breaches</title><link>https://www.apollo-sec.com/savount/lessons-from-hellcats-jira-breaches-identity-based-attacks-on-the-rise-in-2025</link><guid>https://www.apollo-sec.com/savount/lessons-from-hellcats-jira-breaches-identity-based-attacks-on-the-rise-in-2025</guid><pubDate>Sun, 30 Mar 2025 00:00:00 +0000</pubDate><description>No zero-days and no novel malware: how the Hellcat crew breached enterprise Jira with stolen credentials, and the identity defences that stop it.</description></item><item><title>From Perimeter to Identity: The New SaaS Attack Frontier</title><link>https://www.apollo-sec.com/savount/from-perimeter-to-identity-the-new-saas-attack-frontier</link><guid>https://www.apollo-sec.com/savount/from-perimeter-to-identity-the-new-saas-attack-frontier</guid><pubDate>Wed, 05 Mar 2025 00:00:00 +0000</pubDate><description>Single sign-on, session tokens and MFA fatigue: why identity is now the main attack surface for SaaS, and how to defend it.</description></item><item><title>The Costly Reality of Cybersecurity Gaps for SMBs</title><link>https://www.apollo-sec.com/savount/the-costly-reality-of-cybersecurity-gaps-for-smbs</link><guid>https://www.apollo-sec.com/savount/the-costly-reality-of-cybersecurity-gaps-for-smbs</guid><pubDate>Wed, 05 Mar 2025 00:00:00 +0000</pubDate><description>What security gaps really cost small and mid-sized businesses, from breaches and downtime to ransomware and fines, and how to build resilience on a budget.</description></item><item><title>Threat Actors TTPs You Need to Watch in 2025</title><link>https://www.apollo-sec.com/savount/threat-actors-ttps-you-need-to-watch-in-2025</link><guid>https://www.apollo-sec.com/savount/threat-actors-ttps-you-need-to-watch-in-2025</guid><pubDate>Sun, 09 Feb 2025 00:00:00 +0000</pubDate><description>Five attacker techniques to watch: non-human identity attacks, pass-the-hash, supply chain compromise, Golden SAML and stolen remote access credentials.</description></item><item><title>Navigating Supply Chain Risks</title><link>https://www.apollo-sec.com/savount/navigating-supply-chain-risks</link><guid>https://www.apollo-sec.com/savount/navigating-supply-chain-risks</guid><pubDate>Fri, 06 Dec 2024 00:00:00 +0000</pubDate><description>Why a supplier’s weakness becomes yours: lessons from SolarWinds, Log4Shell and Okta, and how to protect your organisation from supply chain attacks.</description></item><item><title>Cyber Breach Survey Insight: The Need to Know for UK Businesses and Charities</title><link>https://www.apollo-sec.com/savount/cyber-breach-survey-insights-the-need-to-know-for-uk-businesses-and-charities</link><guid>https://www.apollo-sec.com/savount/cyber-breach-survey-insights-the-need-to-know-for-uk-businesses-and-charities</guid><pubDate>Fri, 01 Nov 2024 00:00:00 +0000</pubDate><description>Key findings from the UK Cyber Security Breaches Survey 2024: what breaches cost, why phishing leads, and where boards stand on cyber risk.</description></item><item><title>Preparing for the Digital Operational Resilience Act (DORA): How Financial Services Can Comply with New EU IT Resilience Legislation</title><link>https://www.apollo-sec.com/savount/preparing-for-the-digital-operational-resilience-act-dora-how-financial-services-can-comply-with-new-eu-it-resilience-legislation</link><guid>https://www.apollo-sec.com/savount/preparing-for-the-digital-operational-resilience-act-dora-how-financial-services-can-comply-with-new-eu-it-resilience-legislation</guid><pubDate>Fri, 01 Nov 2024 00:00:00 +0000</pubDate><description>Who the EU Digital Operational Resilience Act applies to, what it asks of financial services firms, and how to prepare for it.</description></item><item><title>Enhancing Cloud Security: A Multi-Layered Approach</title><link>https://www.apollo-sec.com/savount/enhancing-cloud-security-a-multi-layered-approach</link><guid>https://www.apollo-sec.com/savount/enhancing-cloud-security-a-multi-layered-approach</guid><pubDate>Wed, 07 Aug 2024 00:00:00 +0000</pubDate><description>How attackers exploit cloud storage, web applications and deployments, and a layered approach to securing them, from zero trust to data security.</description></item><item><title>Living on the Edge: An Adversary Playground</title><link>https://www.apollo-sec.com/savount/living-on-the-edge-an-adversary-playground</link><guid>https://www.apollo-sec.com/savount/living-on-the-edge-an-adversary-playground</guid><pubDate>Sat, 01 Jun 2024 00:00:00 +0000</pubDate><description>A walk through an engagement: how edge devices, leaked cloud keys and an open Trello board gave an attacker a path in, one step at a time.</description></item><item><title>Offense is The Best Form of Defense</title><link>https://www.apollo-sec.com/savount/offense-is-the-best-defense</link><guid>https://www.apollo-sec.com/savount/offense-is-the-best-defense</guid><pubDate>Thu, 23 May 2024 00:00:00 +0000</pubDate><description>Why thinking like an attacker is the most effective way to defend, and the case for offensive security over checkbox compliance.</description></item><item><title>The Essential Guide to Penetration Testing for SMBs</title><link>https://www.apollo-sec.com/savount/the-essential-guide-to-penetration-testing-for-smbs</link><guid>https://www.apollo-sec.com/savount/the-essential-guide-to-penetration-testing-for-smbs</guid><pubDate>Thu, 23 May 2024 00:00:00 +0000</pubDate><description>What penetration testing is, why small and mid-sized businesses are targeted, what testing gives you, and how often to do it.</description></item><item><title>The 2024 Cyber Landscape: Insights and Strategies</title><link>https://www.apollo-sec.com/savount/rising-tide-of-cyber-threats</link><guid>https://www.apollo-sec.com/savount/rising-tide-of-cyber-threats</guid><pubDate>Thu, 09 May 2024 00:00:00 +0000</pubDate><description>The 2024 threat landscape in brief: the attack trends that shaped the year and the strategies organisations can use to respond.</description></item><item><title>SBOMs: Essential for Modern Software Security</title><link>https://www.apollo-sec.com/savount/sbom</link><guid>https://www.apollo-sec.com/savount/sbom</guid><pubDate>Tue, 30 Apr 2024 00:00:00 +0000</pubDate><description>What a software bill of materials is, why transparency in software matters, and how SBOMs help secure the software supply chain.</description></item><item><title>The Key to Robust IT Security</title><link>https://www.apollo-sec.com/savount/the-key-to-robust-security</link><guid>https://www.apollo-sec.com/savount/the-key-to-robust-security</guid><pubDate>Tue, 30 Apr 2024 00:00:00 +0000</pubDate><description>The basics that stop most attacks: least privilege, password hygiene, patching, email controls and training, and why regular testing matters.</description></item></channel></rss>
