<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>farksecurity.com</title>
    <link>https://farksecurity.com/</link>
    <atom:link href="https://farksecurity.com/feed.xml" rel="self" type="application/rss+xml" />
    <description>Research writeups and blog posts from Fark Consulting.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 24 Aug 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>The Week Phish-Signals Stopped Being a Mirror</title>
      <link>https://farksecurity.com/blog/phish-signals-goes-standalone</link>
      <guid isPermaLink="true">https://farksecurity.com/blog/phish-signals-goes-standalone</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>The mirror setup from last week&apos;s post is gone. In its place: a full Python port that has to agree with the TypeScript original signal for signal, a patched supply-chain vulnerability, and docs restructured so they stop duplicating the same explanation twice.</description>
      <category>security</category>
      <category>phishing</category>
      <category>detection-engineering</category>
      <category>typescript</category>
      <category>python</category>
      <category>tooling</category>
    </item>
    <item>
      <title>Cutting the Detection Engine Loose</title>
      <link>https://farksecurity.com/blog/open-sourcing-the-detection-engine</link>
      <guid isPermaLink="true">https://farksecurity.com/blog/open-sourcing-the-detection-engine</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>The heuristic engine behind /phish-report is now its own open-source npm package with a real release pipeline behind it, and a local indicator database is next.</description>
      <category>security</category>
      <category>phishing</category>
      <category>tooling</category>
      <category>detection-engineering</category>
      <category>typescript</category>
    </item>
    <item>
      <title>Third Pass: Trusting a Header Less, and a CSS Fix That Wasn&apos;t</title>
      <link>https://farksecurity.com/blog/phish-analyzer-round-three</link>
      <guid isPermaLink="true">https://farksecurity.com/blog/phish-analyzer-round-three</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Cross-checking the authentication header against the delivery path itself, catching links with no domain at all, closing an evasion gap in my own keyword matching, and a print bug where the obvious fix quietly did nothing.</description>
      <category>security</category>
      <category>phishing</category>
      <category>detection-engineering</category>
      <category>meta</category>
    </item>
    <item>
      <title>Second Pass on the Phish Analyzer: Hashing, Thread Hijacking, and a Bug I Introduced Myself</title>
      <link>https://farksecurity.com/blog/phish-analyzer-round-two</link>
      <guid isPermaLink="true">https://farksecurity.com/blog/phish-analyzer-round-two</guid>
      <pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate>
      <description>Adding attachment hashing, reply-thread hijack detection, and a Sigma rule that actually uses the hash, then finding a real bug on the way that had nothing to do with any of it.</description>
      <category>security</category>
      <category>phishing</category>
      <category>detection-engineering</category>
      <category>meta</category>
    </item>
    <item>
      <title>Phish-Report: Sender Typosquatting, QR Decoding, and a Decompression Bomb in Review</title>
      <link>https://farksecurity.com/research/phish-report-detection-expansion-2026</link>
      <guid isPermaLink="true">https://farksecurity.com/research/phish-report-detection-expansion-2026</guid>
      <pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate>
      <description>Six new detections shipped to the phish-report pipeline this round, and the security review that ran against the diff before merge caught a real memory-exhaustion bug along with four other verified issues.</description>
      <category>phishing</category>
      <category>detection-engineering</category>
      <category>tooling</category>
      <category>secure-coding</category>
    </item>
    <item>
      <title>Rebuilding the Phish Analyzer, and the Bugs I Found Doing It</title>
      <link>https://farksecurity.com/blog/rebuilding-the-phish-analyzer</link>
      <guid isPermaLink="true">https://farksecurity.com/blog/rebuilding-the-phish-analyzer</guid>
      <pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate>
      <description>A review of my own site turned up three live bugs in the phishing analyzer, then a scoring model that was quietly wrong, then a tool that could list indicators but not reason about them.</description>
      <category>security</category>
      <category>phishing</category>
      <category>detection-engineering</category>
      <category>meta</category>
    </item>
    <item>
      <title>Migrating This Site to TypeScript</title>
      <link>https://farksecurity.com/blog/migrating-to-typescript</link>
      <guid isPermaLink="true">https://farksecurity.com/blog/migrating-to-typescript</guid>
      <pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate>
      <description>Converting the whole Express app from plain JS to TypeScript, and the handful of sharp edges that came with it.</description>
      <category>typescript</category>
      <category>express</category>
      <category>meta</category>
    </item>
    <item>
      <title>A Week of Fixing and Building on This Site</title>
      <link>https://farksecurity.com/blog/recent-site-improvements</link>
      <guid isPermaLink="true">https://farksecurity.com/blog/recent-site-improvements</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>What started as a broken deploy turned into a security audit, a new Blog section, and a pile of infrastructure cleanup.</description>
      <category>meta</category>
    </item>
    <item>
      <title>Starting a Blog Section</title>
      <link>https://farksecurity.com/blog/starting-a-blog</link>
      <guid isPermaLink="true">https://farksecurity.com/blog/starting-a-blog</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <description>Why this section exists separately from Research, and what&apos;s actually going to end up here.</description>
      <category>meta</category>
    </item>
    <item>
      <title>Farksecurity.com Security Audit, August 2026</title>
      <link>https://farksecurity.com/research/farksecurity-security-audit-2026</link>
      <guid isPermaLink="true">https://farksecurity.com/research/farksecurity-security-audit-2026</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
      <description>A self-audit of this site&apos;s infrastructure covering OSINT recon, HTTP header hygiene, and exposed service scanning, plus the fixes that came out of it.</description>
      <category>audit</category>
      <category>web-security</category>
      <category>dns</category>
      <category>tls</category>
    </item>
    <item>
      <title>Welcome to the Research Hub</title>
      <link>https://farksecurity.com/research/welcome-to-the-research-hub</link>
      <guid isPermaLink="true">https://farksecurity.com/research/welcome-to-the-research-hub</guid>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <description>How writeups get published here, and what to expect from this section.</description>
      <category>meta</category>
    </item>
  </channel>
</rss>
