<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Article on Cyshield Seclab</title><link>https://seclab.cyshield.com/categories/article/</link><description>Recent content in Article on Cyshield Seclab</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Cyshield.</copyright><lastBuildDate>Mon, 05 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://seclab.cyshield.com/categories/article/index.xml" rel="self" type="application/rss+xml"/><item><title> Detection or Proof: Rethinking the Central Question Behind WAFs</title><link>https://seclab.cyshield.com/posts/detection-or-proof-rethinking-the-central-question-behind-wafs/</link><pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/detection-or-proof-rethinking-the-central-question-behind-wafs/</guid><description>This paper challenges the idea that WAFs should rely primarily on attack detection. It proposes a risk-based architecture where lower-risk endpoints use detection and anomaly analysis, while high-risk functions require validation of structure, authorization, context, and business logic. The paper concludes that effective WAF security is fundamentally a risk-routing problem.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/detection-or-proof-rethinking-the-central-question-behind-wafs/featured.webp"/></item><item><title>Securing the RAN #4: From Security Standards to Operational Defense</title><link>https://seclab.cyshield.com/posts/securing-the-ran-4-operationalizing-from-security-standards-to-operational-defense/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/securing-the-ran-4-operationalizing-from-security-standards-to-operational-defense/</guid><description>A practical guide to operationalizing RAN security through base-station hardening, secure cryptographic and key-management practices, proactive threat detection, telemetry analysis, interface protection, and Zero Trust principles across 5G and O-RAN environments.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/securing-the-ran-4-operationalizing-from-security-standards-to-operational-defense/featured.webp"/></item><item><title>Addressing Modern SOC Challenges with Agentic Approaches</title><link>https://seclab.cyshield.com/posts/addressing-modern-soc-challenges-with-agentic-approaches/</link><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/addressing-modern-soc-challenges-with-agentic-approaches/</guid><description>Modern SOCs are under increasing pressure from alert overload, fragmented investigations, scattered expertise, and complex incident coordination. This article explores how Agentic SOCs use AI agents to connect and streamline the security lifecycle, from alert triage and investigation to response and reporting, while preserving context, reducing repetitive work, and keeping human analysts focused on critical security decisions.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/addressing-modern-soc-challenges-with-agentic-approaches/featured.webp"/></item><item><title>Securing the RAN #3: Security in Standardization Evolution from 3G to 5G-Advanced</title><link>https://seclab.cyshield.com/posts/securing-the-ran-3-security-in-standardization-evolution-from-3g-to-5g-advanced/</link><pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/securing-the-ran-3-security-in-standardization-evolution-from-3g-to-5g-advanced/</guid><description>How 3GPP has systematically hardened RAN security from 3G through 5G-Advanced, from SUCI encryption defeating IMSI catchers to Zero Trust O-RAN interfaces and next-gen protections for IoT, sensing, and satellite networks.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/securing-the-ran-3-security-in-standardization-evolution-from-3g-to-5g-advanced/featured.webp"/></item><item><title>The Invisible Attack Surface: What Vulnerability Scanners Are Not Telling You!</title><link>https://seclab.cyshield.com/posts/the-invisible-attack-surface-what-vulnerability-scanners-are-not-telling-you/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/the-invisible-attack-surface-what-vulnerability-scanners-are-not-telling-you/</guid><description>Traditional vulnerability scanners only see known assets, leaving unknown systems and exposures invisible. As cloud, APIs, and third-party services expand the attack surface, continuous discovery becomes critical. This post shows how Attack Surface Management fills that gap by uncovering hidden risks before attackers do.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/the-invisible-attack-surface-what-vulnerability-scanners-are-not-telling-you/featured.webp"/></item><item><title>WAF Evasion 101: How Attackers Bypass “Security Gates”</title><link>https://seclab.cyshield.com/posts/waf-evasion-101-how-attackers-bypass-security-gates/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/waf-evasion-101-how-attackers-bypass-security-gates/</guid><description>Attackers reshape the same malicious payload just enough that the WAF no longer recognizes it, while the backend still executes it exactly as intended. This post walks through the real evasion playbook (encoding tricks, token splitting, noise injection, and reinforcement-learning-driven automated probing) and shows why the problem is structural, not a matter of sloppy engineering.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/waf-evasion-101-how-attackers-bypass-security-gates/featured.webp"/></item><item><title>Why High Accuracy Can Still Mean Bad Security!</title><link>https://seclab.cyshield.com/posts/why-high-accuracy-can-still-mean-bad-security/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/why-high-accuracy-can-still-mean-bad-security/</guid><description>High accuracy in security does not guarantee real-world protection. Through the WAMM research study, this post examines what accuracy metrics hide, how false positives and false negatives manifest in production environments, and what a security-grade evaluation framework should actually measure.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/why-high-accuracy-can-still-mean-bad-security/featured.webp"/></item><item><title>Augmenting Security Datasets: A Technical Methodology for Modern Threat Simulation</title><link>https://seclab.cyshield.com/posts/augmenting-security-datasets-a-technical-methodology-for-modern-threat-simulation/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/augmenting-security-datasets-a-technical-methodology-for-modern-threat-simulation/</guid><description>A comprehensive enhancement of the SR-BH 2020 dataset for WAF training, combining LLM-assisted labeling, diverse benign traffic, and targeted attack injection to improve training data quality.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/augmenting-security-datasets-a-technical-methodology-for-modern-threat-simulation/featured.webp"/></item><item><title>Securing the RAN #2: Attacks on the Radio Interface</title><link>https://seclab.cyshield.com/posts/securing-the-ran-2-attacks-on-the-radio-interface/</link><pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/securing-the-ran-2-attacks-on-the-radio-interface/</guid><description>This post explores different attack surfaces, attack vectors, and attack scenarios across the RAN, explaining categories of threats and attacker TTPs supported by attack flow illustrations.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/securing-the-ran-2-attacks-on-the-radio-interface/featured.webp"/></item><item><title>Can AI Detect Web Attacks Better Than Rules?</title><link>https://seclab.cyshield.com/posts/can-ai-detect-web-attacks-better-than-rules/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/can-ai-detect-web-attacks-better-than-rules/</guid><description>The real challenge is not choosing rules or AI, but designing detection systems that can operate under uncertainty and adversarial pressure. This article examines web attack detection and WAF evasion through scientific research and real-world observations.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/can-ai-detect-web-attacks-better-than-rules/featured.webp"/></item><item><title>SBOM Demystified: A Practical Guide to Software Supply Chain Transparency</title><link>https://seclab.cyshield.com/posts/sbom-demystified-a-practical-guide-to-software-supply-chain-transparency/</link><pubDate>Tue, 12 May 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/sbom-demystified-a-practical-guide-to-software-supply-chain-transparency/</guid><description>Software is built like a layer cake full of libraries, packages, and hidden dependencies. But when a security crisis hits, do you really know what&amp;rsquo;s inside your code? This is where a Software Bill of Materials (SBOM) becomes essential.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/sbom-demystified-a-practical-guide-to-software-supply-chain-transparency/featured.webp"/></item><item><title>Remote Code Execution on SolarView Compact Firmware: A Technical Walkthrough</title><link>https://seclab.cyshield.com/posts/remote-code-execution-on-solarview-compact-firmware-a-technical-walkthrough/</link><pubDate>Mon, 27 Apr 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/remote-code-execution-on-solarview-compact-firmware-a-technical-walkthrough/</guid><description>In this post, we demonstrate how we achieved Remote Code Execution (RCE) on a web server connected to a solar system monitoring firmware: SolarView Compact. This walkthrough covers four key stages: Firmware Extraction, Reconnaissance, Code Review, and Exploitation.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/remote-code-execution-on-solarview-compact-firmware-a-technical-walkthrough/featured.webp"/></item><item><title>Securing the RAN #1: An Introduction</title><link>https://seclab.cyshield.com/posts/securing-the-ran-1-an-introduction/</link><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/securing-the-ran-1-an-introduction/</guid><description>When people talk about mobile network security, the conversation almost always gravitates toward the core network. However, there is another part of the network that quietly sits in public spaces, exposed by design: the Radio Access Network (RAN).</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/securing-the-ran-1-an-introduction/featured.webp"/></item></channel></rss>