<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTO-GENERATED by script/generate-rss.ts; do not edit by hand. -->
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Strix Blog</title>
    <link>https://www.strix.ai/blog</link>
    <description>Security research, product updates, and insights from the Strix team on autonomous pentesting, application security, and vulnerability management.</description>
    <language>en</language>
    <atom:link href="https://www.strix.ai/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8n</title>
      <link>https://www.strix.ai/blog/n8n-cross-issuer-account-takeover</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/n8n-cross-issuer-account-takeover</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <description>Strix pointed itself at n8n&apos;s token-exchange flow and found an identity-binding bug: two trusted issuers emitting the same sub map to the same local account. One trusted token could log you in as someone else.</description>
    </item>
    <item>
      <title>One Click Account Takeover in Granola: How a Notification Link Broke Out of Electron</title>
      <link>https://www.strix.ai/blog/granola</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/granola</guid>
      <pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate>
      <description>Strix found a one-click account takeover in Granola&apos;s Electron app: a notification link could navigate a trusted renderer to an attacker&apos;s page while keeping Granola&apos;s privileged bridge.</description>
    </item>
    <item>
      <title>Training Specialized Pentesting Models with Reinforcement Learning</title>
      <link>https://www.strix.ai/blog/training-pentesting-models-with-rl-on-strix-harness</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/training-pentesting-models-with-rl-on-strix-harness</guid>
      <pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate>
      <description>How we post-train smaller specialized models for specific vulnerability classes using RL inside the Strix harness.</description>
    </item>
    <item>
      <title>Securing a DoD Contractor: Finding a Multi-Tenant Authorization Vulnerability</title>
      <link>https://www.strix.ai/blog/how-strix-found-zero-auth-vulnerability-dod-backed-startup</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/how-strix-found-zero-auth-vulnerability-dod-backed-startup</guid>
      <pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate>
      <description>Zero tenant isolation, exposed military training data, and a five-month responsible disclosure timeline.</description>
    </item>
    <item>
      <title>Autonomous Pentesting for Internal Infrastructure</title>
      <link>https://www.strix.ai/blog/autonomous-pentesting-for-internal-infrastructure</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/autonomous-pentesting-for-internal-infrastructure</guid>
      <pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate>
      <description>Strix now runs inside your network, continuously pentesting the internal systems where real security failures usually happen.</description>
    </item>
    <item>
      <title>Context-Aware Pentesting</title>
      <link>https://www.strix.ai/blog/context-aware-pentesting</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/context-aware-pentesting</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate>
      <description>Strix now builds a living threat model of your organization and learns from every finding, so each pentest picks up where the last one left off.</description>
    </item>
    <item>
      <title>Introducing Strix API: Pentesting, Agent-Native</title>
      <link>https://www.strix.ai/blog/introducing-strix-api</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/introducing-strix-api</guid>
      <pubDate>Wed, 15 Apr 2026 19:00:00 GMT</pubDate>
      <description>Run Strix pentests from CI, scripts, and coding agents, with HTTP APIs for pentests, vulnerabilities, schedules, and webhooks.</description>
    </item>
    <item>
      <title>Open Source Isn&apos;t Dead.</title>
      <link>https://www.strix.ai/blog/cal-com-is-closing-its-code-due-to-ai-threats</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/cal-com-is-closing-its-code-due-to-ai-threats</guid>
      <pubDate>Wed, 15 Apr 2026 16:00:00 GMT</pubDate>
      <description>AI has changed vulnerability discovery, but closing source code does not remove the attack surface. Continuous AI defense is the better response.</description>
    </item>
    <item>
      <title>Pentesting Every Pull Request</title>
      <link>https://www.strix.ai/blog/pentesting-every-pull-request</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/pentesting-every-pull-request</guid>
      <pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate>
      <description>Strix now pentests every pull request, blocking vulnerabilities before they reach production, so you can ship with confidence.</description>
    </item>
    <item>
      <title>Introducing the New Strix Platform</title>
      <link>https://www.strix.ai/blog/introducing-the-new-strix-platform</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/introducing-the-new-strix-platform</guid>
      <pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate>
      <description>Strix is now a full-stack security platform for continuously pentesting, validating, and fixing vulnerabilities across your apps.</description>
    </item>
    <item>
      <title>Uncovering a hidden BOLA in Appsmith&apos;s snapshot logic</title>
      <link>https://www.strix.ai/blog/where-others-missed-it-appsmith-bola</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/where-others-missed-it-appsmith-bola</guid>
      <pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate>
      <description>Strix autonomously discovered and reported a BOLA/IDOR vulnerability in Appsmith&apos;s snapshot deletion path.</description>
    </item>
    <item>
      <title>How Strix found a critical auth bypass in etcd</title>
      <link>https://www.strix.ai/blog/where-others-missed-it-etcd-auth-bypass</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/where-others-missed-it-etcd-auth-bypass</guid>
      <pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate>
      <description>Strix autonomously discovered and reported a critical authentication bypass in etcd, later designated as CVE-2026-33413.</description>
    </item>
    <item>
      <title>Where Cybersecurity Goes From Here</title>
      <link>https://www.strix.ai/blog/your-first-visitors-arent-users-theyre-bots</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/your-first-visitors-arent-users-theyre-bots</guid>
      <pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate>
      <description>Why continuous AI-driven scanning has made periodic pentesting obsolete, and what teams need to change now.</description>
    </item>
    <item>
      <title>Best AI Pentesting Tools in 2026: 8 Platforms Compared</title>
      <link>https://www.strix.ai/blog/best-ai-pentesting-tools</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/best-ai-pentesting-tools</guid>
      <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
      <description>Compare the best AI pentesting tools in 2026, including Strix, XBOW, NodeZero, RunSybil, Pentera, Strobes, pwn.ai, and Prancer.</description>
    </item>
    <item>
      <title>Partnering with Caido to Bring Precision &amp; Control to Agentic Pentesting</title>
      <link>https://www.strix.ai/blog/partnering-with-caido</link>
      <guid isPermaLink="true">https://www.strix.ai/blog/partnering-with-caido</guid>
      <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
      <description>Security teams shouldn&apos;t have to choose between speed and control.</description>
    </item>
  </channel>
</rss>
