<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>AN3 Security · Intel Brief</title>
    <link>https://an3.io/blog</link>
    <description>AN3 provides cybersecurity testing, audits and continuous defence across cloud, applications, infrastructure and onchain systems.</description>
    <language>en</language>
    <lastBuildDate>Tue, 11 Aug 2026 15:23:49 GMT</lastBuildDate>
    <atom:link href="https://an3.io/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Cross-chain message verification beyond the bridge contract</title>
      <link>https://an3.io/blog/cross-chain-message-verification-beyond-the-bridge-contract</link>
      <guid isPermaLink="true">https://an3.io/blog/cross-chain-message-verification-beyond-the-bridge-contract</guid>
      <pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate>
      <description>Where proof checks end and trust assumptions begin on the receiving chain — a field guide to what bridge audits miss once the message leaves the contract.</description>
      <author>AN3 · Offensive Research</author>
      <category>Onchain · Bridges</category>
    </item>
    <item>
      <title>Where VASP testing falls short of the VARA Rulebook</title>
      <link>https://an3.io/blog/where-vasp-testing-falls-short-of-the-vara-rulebook</link>
      <guid isPermaLink="true">https://an3.io/blog/where-vasp-testing-falls-short-of-the-vara-rulebook</guid>
      <pubDate>Thu, 06 Aug 2026 12:00:00 GMT</pubDate>
      <description>A practical reading of Dubai's Technology &amp; Information Rulebook on annual testing, cryptographic keys, and the live systems that still decide outcomes.</description>
      <author>AN3 · Offensive Research</author>
      <category>Regulatory · Dubai</category>
    </item>
    <item>
      <title>Signer ops beat signature schemes</title>
      <link>https://an3.io/blog/signer-ops-beat-signature-schemes</link>
      <guid isPermaLink="true">https://an3.io/blog/signer-ops-beat-signature-schemes</guid>
      <pubDate>Wed, 05 Aug 2026 12:00:00 GMT</pubDate>
      <description>In 2026 the expensive failures still land on humans approving the wrong thing. Here is how we scope signer operations the way we scope contracts.</description>
      <author>AN3 · Offensive Research</author>
      <category>Onchain · Operations</category>
    </item>
    <item>
      <title>Upgradeability is where protocols quietly die</title>
      <link>https://an3.io/blog/upgradeability-is-where-protocols-quietly-die</link>
      <guid isPermaLink="true">https://an3.io/blog/upgradeability-is-where-protocols-quietly-die</guid>
      <pubDate>Wed, 05 Aug 2026 12:00:00 GMT</pubDate>
      <description>Immutable code is rare. Upgrade paths are common—and under-reviewed. A 2026 field guide to where proxy, governor, and timelock designs actually fail.</description>
      <author>AN3 · Offensive Research</author>
      <category>Onchain · Architecture</category>
    </item>
    <item>
      <title>Reentrancy in 2026: the bugs that refuse to die</title>
      <link>https://an3.io/blog/reentrancy-2026</link>
      <guid isPermaLink="true">https://an3.io/blog/reentrancy-2026</guid>
      <pubDate>Mon, 15 Jun 2026 12:00:00 GMT</pubDate>
      <description>A modern field guide to reentrancy variants and the patterns that still slip past automated tooling.</description>
      <author>AN3 Security</author>
      <category>Onchain · Audit</category>
    </item>
    <item>
      <title>Anatomy of the Bybit hack: when the UI is the exploit</title>
      <link>https://an3.io/blog/bybit-hack-anatomy</link>
      <guid isPermaLink="true">https://an3.io/blog/bybit-hack-anatomy</guid>
      <pubDate>Mon, 01 Jun 2026 12:00:00 GMT</pubDate>
      <description>How attackers manipulated a signing interface to drain a $1.5B cold wallet — and why the same human-layer class threatens exchanges and enterprises alike.</description>
      <author>AN3 · Offensive Research</author>
      <category>Featured · Threat research</category>
    </item>
    <item>
      <title>Your IAM is your perimeter now</title>
      <link>https://an3.io/blog/iam-perimeter</link>
      <guid isPermaLink="true">https://an3.io/blog/iam-perimeter</guid>
      <pubDate>Wed, 20 May 2026 12:00:00 GMT</pubDate>
      <description>Why cloud breaches keep tracing back to identity — and a practical hardening checklist for AWS, Azure, and GCP.</description>
      <author>AN3 Security</author>
      <category>Enterprise · Cloud</category>
    </item>
    <item>
      <title>Phishing still wins. Here's the data.</title>
      <link>https://an3.io/blog/phishing-data</link>
      <guid isPermaLink="true">https://an3.io/blog/phishing-data</guid>
      <pubDate>Sun, 10 May 2026 12:00:00 GMT</pubDate>
      <description>What 50 simulated campaigns taught us about human-layer risk and how to actually move the needle.</description>
      <author>AN3 Security</author>
      <category>Enterprise · Red team</category>
    </item>
    <item>
      <title>Auditing consensus: beyond the smart contract</title>
      <link>https://an3.io/blog/consensus-audit</link>
      <guid isPermaLink="true">https://an3.io/blog/consensus-audit</guid>
      <pubDate>Sat, 18 Apr 2026 12:00:00 GMT</pubDate>
      <description>Validator logic, networking, and timing assumptions — where L1 risk really lives.</description>
      <author>AN3 Security</author>
      <category>Onchain · Protocol</category>
    </item>
    <item>
      <title>SOC 2 without the theater</title>
      <link>https://an3.io/blog/soc2-theater</link>
      <guid isPermaLink="true">https://an3.io/blog/soc2-theater</guid>
      <pubDate>Sun, 05 Apr 2026 12:00:00 GMT</pubDate>
      <description>How to build controls your engineers respect and an auditor signs off on, minus the busywork.</description>
      <author>AN3 Security</author>
      <category>Enterprise · GRC</category>
    </item>
    <item>
      <title>Tokenomics as an attack surface</title>
      <link>https://an3.io/blog/tokenomics-attack-surface</link>
      <guid isPermaLink="true">https://an3.io/blog/tokenomics-attack-surface</guid>
      <pubDate>Sun, 22 Mar 2026 12:00:00 GMT</pubDate>
      <description>Supply schedules, vesting, and incentives are code too. We break down the economic exploits.</description>
      <author>AN3 Security</author>
      <category>Onchain · DeFi</category>
    </item>
  </channel>
</rss>
