<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>CMD+CTRL Security Blog</title>
    <link>https://blog.cmdnctrlsecurity.com</link>
    <description>Insights on all things related to secure coding, cybersecurity challenges, and updates to our CMD+CTRL training platform.</description>
    <language>en</language>
    <pubDate>Tue, 12 May 2026 18:58:45 GMT</pubDate>
    <dc:date>2026-05-12T18:58:45Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Securing the Digital Connective Tissue: Best Practices for API Security</title>
      <link>https://blog.cmdnctrlsecurity.com/best-practices-for-api-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/best-practices-for-api-security" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-tron-lines.jpg" alt="Securing the Digital Connective Tissue: Best Practices for API Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;What Is API Security?&lt;/h2&gt; 
&lt;p&gt;API security is the practice of protecting Application Programming Interfaces from unauthorized access, data exposure, misuse, and exploitation.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/best-practices-for-api-security" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-tron-lines.jpg" alt="Securing the Digital Connective Tissue: Best Practices for API Security" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;What Is API Security?&lt;/h2&gt; 
&lt;p&gt;API security is the practice of protecting Application Programming Interfaces from unauthorized access, data exposure, misuse, and exploitation.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fbest-practices-for-api-security&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cybersecurity training</category>
      <category>API</category>
      <category>developer security training</category>
      <category>API security training</category>
      <category>API security best practices</category>
      <pubDate>Tue, 12 May 2026 13:30:00 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/best-practices-for-api-security</guid>
      <dc:date>2026-05-12T13:30:00Z</dc:date>
      <dc:creator>CMD+CTRL Security</dc:creator>
    </item>
    <item>
      <title>Building a Secure Foundation: Core Cybersecurity Practices for Developers</title>
      <link>https://blog.cmdnctrlsecurity.com/core-cybersecurity-practices-for-developers</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/core-cybersecurity-practices-for-developers" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-blue-cyber-shapes.jpg" alt="Building a Secure Foundation: Core Cybersecurity Practices for Developers" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Security is not a final checklist item. It is a mindset that must be integrated into every step of the development process.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/core-cybersecurity-practices-for-developers" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-blue-cyber-shapes.jpg" alt="Building a Secure Foundation: Core Cybersecurity Practices for Developers" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Security is not a final checklist item. It is a mindset that must be integrated into every step of the development process.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fcore-cybersecurity-practices-for-developers&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cybersecurity training</category>
      <category>application security</category>
      <category>proactive security</category>
      <pubDate>Tue, 07 Apr 2026 13:00:05 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/core-cybersecurity-practices-for-developers</guid>
      <dc:date>2026-04-07T13:00:05Z</dc:date>
      <dc:creator>CMD+CTRL Security</dc:creator>
    </item>
    <item>
      <title>Turning MITRE ATT&amp;CK v18 into Behavior-Driven Defense</title>
      <link>https://blog.cmdnctrlsecurity.com/mitre-attck-v18</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/mitre-attck-v18" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-data-layer-waves.jpg" alt="Turning MITRE ATT&amp;amp;CK v18 into Behavior-Driven Defense" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The MITRE ATT&amp;amp;CK&lt;sup&gt;®&lt;/sup&gt; framework remains one of the most influential tools for understanding real-world adversary behavior. With the release of &lt;strong&gt;ATT&amp;amp;CK v18&lt;/strong&gt;, MITRE has introduced some of the most consequential changes in the framework’s history—changes that directly impact how organizations design detections, instrument applications, and align security strategy across teams.&lt;/p&gt; 
&lt;p&gt;For AppSec leaders, developers, and CISOs, this update is less about learning a new matrix and more about adapting to a &lt;strong&gt;behavior-driven security model&lt;/strong&gt; that better reflects modern attack paths.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/mitre-attck-v18" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-data-layer-waves.jpg" alt="Turning MITRE ATT&amp;amp;CK v18 into Behavior-Driven Defense" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The MITRE ATT&amp;amp;CK&lt;sup&gt;®&lt;/sup&gt; framework remains one of the most influential tools for understanding real-world adversary behavior. With the release of &lt;strong&gt;ATT&amp;amp;CK v18&lt;/strong&gt;, MITRE has introduced some of the most consequential changes in the framework’s history—changes that directly impact how organizations design detections, instrument applications, and align security strategy across teams.&lt;/p&gt; 
&lt;p&gt;For AppSec leaders, developers, and CISOs, this update is less about learning a new matrix and more about adapting to a &lt;strong&gt;behavior-driven security model&lt;/strong&gt; that better reflects modern attack paths.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fmitre-attck-v18&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>OWASP</category>
      <category>application security</category>
      <category>MITRE ATT&amp;CK</category>
      <pubDate>Mon, 09 Mar 2026 12:30:00 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/mitre-attck-v18</guid>
      <dc:date>2026-03-09T12:30:00Z</dc:date>
      <dc:creator>CMD+CTRL Security</dc:creator>
    </item>
    <item>
      <title>Agentic AI and the Next Wave of Security Risk</title>
      <link>https://blog.cmdnctrlsecurity.com/agentic-ai-and-the-next-wave-of-security-risk</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/agentic-ai-and-the-next-wave-of-security-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-data-layer-waves.jpg" alt="Agentic AI and the Next Wave of Security Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;As organizations race to integrate agentic AI into their development and operations workflows, a critical pattern is emerging. AI autonomy is outpacing security maturity. While agentic systems promise productivity and speed, they also introduce entirely new pathways for misuse and exploitation.&lt;/p&gt; 
&lt;p&gt;But here’s the real story: &lt;em&gt;agentic AI isn’t just “new.” It mirrors an old challenge in a more dangerous form.&lt;/em&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/agentic-ai-and-the-next-wave-of-security-risk" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-data-layer-waves.jpg" alt="Agentic AI and the Next Wave of Security Risk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;As organizations race to integrate agentic AI into their development and operations workflows, a critical pattern is emerging. AI autonomy is outpacing security maturity. While agentic systems promise productivity and speed, they also introduce entirely new pathways for misuse and exploitation.&lt;/p&gt; 
&lt;p&gt;But here’s the real story: &lt;em&gt;agentic AI isn’t just “new.” It mirrors an old challenge in a more dangerous form.&lt;/em&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fagentic-ai-and-the-next-wave-of-security-risk&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>AI</category>
      <category>secure software training</category>
      <category>agentic AI</category>
      <category>API</category>
      <pubDate>Tue, 06 Jan 2026 13:00:00 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/agentic-ai-and-the-next-wave-of-security-risk</guid>
      <dc:date>2026-01-06T13:00:00Z</dc:date>
      <dc:creator>CMD+CTRL Security</dc:creator>
    </item>
    <item>
      <title>Securing the Cloud: Tame the Chaos of Cloud Misconfigurations</title>
      <link>https://blog.cmdnctrlsecurity.com/tame-the-chaos-of-cloud-misconfigurations</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/tame-the-chaos-of-cloud-misconfigurations" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1g1.jpg" alt="Securing the Cloud: Tame the Chaos of Cloud Misconfigurations" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;If this year has taught us anything, it’s that cloud security isn’t just an infrastructure problem. It’s a human one.&lt;/p&gt; 
&lt;p&gt;Organizations are rapidly migrating to multi-cloud environments, but security teams are still playing catch-up with IAM complexity, policy drift, and configuration debt. That’s why we’re offering two new courses designed to tackle the problem head-on:&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/tame-the-chaos-of-cloud-misconfigurations" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1g1.jpg" alt="Securing the Cloud: Tame the Chaos of Cloud Misconfigurations" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;If this year has taught us anything, it’s that cloud security isn’t just an infrastructure problem. It’s a human one.&lt;/p&gt; 
&lt;p&gt;Organizations are rapidly migrating to multi-cloud environments, but security teams are still playing catch-up with IAM complexity, policy drift, and configuration debt. That’s why we’re offering two new courses designed to tackle the problem head-on:&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Ftame-the-chaos-of-cloud-misconfigurations&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>training updates</category>
      <category>application security</category>
      <category>product updates</category>
      <pubDate>Mon, 29 Dec 2025 13:00:03 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/tame-the-chaos-of-cloud-misconfigurations</guid>
      <dc:date>2025-12-29T13:00:03Z</dc:date>
      <dc:creator>Jose Lazu</dc:creator>
    </item>
    <item>
      <title>How the CMD+CTRL Data API and Smart Catalog Power Smarter Secure Code Training</title>
      <link>https://blog.cmdnctrlsecurity.com/powering-smarter-secure-code-training</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/powering-smarter-secure-code-training" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1f.jpg" alt="How the CMD+CTRL Data API and Smart Catalog Power Smarter Secure Code Training" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Turning Training Insight into Action with the CMD+CTRL Data API&lt;/h2&gt; 
&lt;p&gt;If you’ve ever tried to get real clarity from training data, you know the feeling: multiple spreadsheets and reports that tell you &lt;em&gt;“Who took what,” but not “what it means.”&lt;/em&gt; That’s about to change.&lt;/p&gt; 
&lt;p&gt;The new CMD+CTRL Data API gives teams the power to unlock learning insights in real-time directly in your own dashboards, analytics platforms, and compliance systems. Whether you live in Power BI, Tableau, or a custom compliance portal, your data now moves with you, not against you.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/powering-smarter-secure-code-training" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1f.jpg" alt="How the CMD+CTRL Data API and Smart Catalog Power Smarter Secure Code Training" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Turning Training Insight into Action with the CMD+CTRL Data API&lt;/h2&gt; 
&lt;p&gt;If you’ve ever tried to get real clarity from training data, you know the feeling: multiple spreadsheets and reports that tell you &lt;em&gt;“Who took what,” but not “what it means.”&lt;/em&gt; That’s about to change.&lt;/p&gt; 
&lt;p&gt;The new CMD+CTRL Data API gives teams the power to unlock learning insights in real-time directly in your own dashboards, analytics platforms, and compliance systems. Whether you live in Power BI, Tableau, or a custom compliance portal, your data now moves with you, not against you.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fpowering-smarter-secure-code-training&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>training updates</category>
      <category>cybersecurity training</category>
      <category>product updates</category>
      <category>API</category>
      <category>smart catalog</category>
      <pubDate>Mon, 22 Dec 2025 18:27:43 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/powering-smarter-secure-code-training</guid>
      <dc:date>2025-12-22T18:27:43Z</dc:date>
      <dc:creator>Jose Lazu</dc:creator>
    </item>
    <item>
      <title>The New Age of API Security Training</title>
      <link>https://blog.cmdnctrlsecurity.com/the-new-age-of-api-security-training</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/the-new-age-of-api-security-training" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1a.jpg" alt="The New Age of API Security Training" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;APIs are everywhere, and so are attackers. If your API strategy hasn’t evolved since the OWASP 2017 era, the fact of the matter is that you are behind.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/the-new-age-of-api-security-training" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1a.jpg" alt="The New Age of API Security Training" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;APIs are everywhere, and so are attackers. If your API strategy hasn’t evolved since the OWASP 2017 era, the fact of the matter is that you are behind.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fthe-new-age-of-api-security-training&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>training updates</category>
      <category>cybersecurity training</category>
      <category>product updates</category>
      <category>API</category>
      <pubDate>Thu, 18 Dec 2025 15:13:10 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/the-new-age-of-api-security-training</guid>
      <dc:date>2025-12-18T15:13:10Z</dc:date>
      <dc:creator>Jose Lazu</dc:creator>
    </item>
    <item>
      <title>OWASP Top 10 2025: A Product Leader's Guide for CISOs, GRC, and Training Owners</title>
      <link>https://blog.cmdnctrlsecurity.com/owasp-top-10-2025-a-product-leaders-guide</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/owasp-top-10-2025-a-product-leaders-guide" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-data-layer-waves.jpg" alt="OWASP Top 10 2025: A Product Leader's Guide for CISOs, GRC, and Training Owners" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Last month, the OWASP Foundation announced the release of the 8th installment of the OWASP Top 10, as it typically does every few years. This release forces folks in AppSec, Product, and GRC roles to pause and assess whether they are training people on what causes breaches today.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/owasp-top-10-2025-a-product-leaders-guide" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/cmdctrl-data-layer-waves.jpg" alt="OWASP Top 10 2025: A Product Leader's Guide for CISOs, GRC, and Training Owners" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Last month, the OWASP Foundation announced the release of the 8th installment of the OWASP Top 10, as it typically does every few years. This release forces folks in AppSec, Product, and GRC roles to pause and assess whether they are training people on what causes breaches today.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fowasp-top-10-2025-a-product-leaders-guide&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>OWASP</category>
      <category>application security</category>
      <category>OWASP Top 10</category>
      <pubDate>Tue, 16 Dec 2025 13:00:00 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/owasp-top-10-2025-a-product-leaders-guide</guid>
      <dc:date>2025-12-16T13:00:00Z</dc:date>
      <dc:creator>Jose Lazu</dc:creator>
    </item>
    <item>
      <title>Stop Relying on Quantum Fixes: Build Secure Realities from the Start with Proactive Training</title>
      <link>https://blog.cmdnctrlsecurity.com/stop-relying-on-quantum-fixes-part3</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/stop-relying-on-quantum-fixes-part3" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1g2.jpg" alt="Stop Relying on Quantum Fixes: Build Secure Realities from the Start with Proactive Training" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Security in cloud-native, high-velocity development environments is about more than avoiding failure. In today’s threat landscape, it’s about preventing avoidable mistakes from cascading into costly incidents.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/stop-relying-on-quantum-fixes-part3" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1g2.jpg" alt="Stop Relying on Quantum Fixes: Build Secure Realities from the Start with Proactive Training" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Security in cloud-native, high-velocity development environments is about more than avoiding failure. In today’s threat landscape, it’s about preventing avoidable mistakes from cascading into costly incidents.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fstop-relying-on-quantum-fixes-part3&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cybersecurity training</category>
      <category>secure coding</category>
      <category>SDLC training</category>
      <category>proactive security</category>
      <pubDate>Fri, 12 Dec 2025 13:00:01 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/stop-relying-on-quantum-fixes-part3</guid>
      <dc:date>2025-12-12T13:00:01Z</dc:date>
      <dc:creator>CMD+CTRL Security</dc:creator>
    </item>
    <item>
      <title>Beyond Developers: Why Proactive Security Training Must Reach the Entire SDLC</title>
      <link>https://blog.cmdnctrlsecurity.com/why-proactive-security-training-must-reach-the-entire-sdlc-part2</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/why-proactive-security-training-must-reach-the-entire-sdlc-part2" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1d.jpg" alt="Beyond Developers: Why Proactive Security Training Must Reach the Entire SDLC" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;One of the most persistent misconceptions in AppSec is that secure development is a problem exclusive to developers. However, vulnerabilities don’t originate solely from code; decisions, trade-offs, and misalignments across the entire lifecycle also contribute to errors and exposure.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.cmdnctrlsecurity.com/why-proactive-security-training-must-reach-the-entire-sdlc-part2" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.cmdnctrlsecurity.com/hubfs/blog-images/CnC_Website_Blog_Headers_v1d.jpg" alt="Beyond Developers: Why Proactive Security Training Must Reach the Entire SDLC" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;One of the most persistent misconceptions in AppSec is that secure development is a problem exclusive to developers. However, vulnerabilities don’t originate solely from code; decisions, trade-offs, and misalignments across the entire lifecycle also contribute to errors and exposure.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=46779874&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.cmdnctrlsecurity.com%2Fwhy-proactive-security-training-must-reach-the-entire-sdlc-part2&amp;amp;bu=https%253A%252F%252Fblog.cmdnctrlsecurity.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>cybersecurity training</category>
      <category>secure coding</category>
      <category>SDLC training</category>
      <category>proactive security</category>
      <pubDate>Tue, 09 Dec 2025 19:12:32 GMT</pubDate>
      <guid>https://blog.cmdnctrlsecurity.com/why-proactive-security-training-must-reach-the-entire-sdlc-part2</guid>
      <dc:date>2025-12-09T19:12:32Z</dc:date>
      <dc:creator>CMD+CTRL Security</dc:creator>
    </item>
  </channel>
</rss>
