<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cyberange — Insights</title><description>Threat intelligence, adversary emulation, DFIR, ICS/OT, and training notes from the Cyberange team.</description><link>https://cyberange.io/</link><language>en-IN</language><item><title>A cyber-physical testbed for smart-grid and digital-substation security research</title><link>https://cyberange.io/insights/cyber-physical-smart-grid-security-testbed/</link><guid isPermaLink="true">https://cyberange.io/insights/cyber-physical-smart-grid-security-testbed/</guid><description>A case study on designing and building a realistic, closed-loop smart-grid cybersecurity testbed for a research institute — the requirement, the design approach, what was delivered, and why it matters for the people who keep the grid running. Implementation specifics are deliberately withheld.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>ICS / OT</category><category>ICS</category><category>OT</category><category>smart grid</category><category>digital substation</category><category>testbed</category><category>research</category><category>energy</category><category>grid security</category><author>Cyberange Phygital Labs</author></item><item><title>Inside a 90-day red team op against a tier-1 Indian airport operator</title><link>https://cyberange.io/insights/90-day-red-team-tier-1-indian-airport/</link><guid isPermaLink="true">https://cyberange.io/insights/90-day-red-team-tier-1-indian-airport/</guid><description>A redacted case study mapping a 13-week journey from an external foothold to full Active Directory compromise. Discover how the operator adapted tactics on the fly and what forensic artifacts survived a rigorous CERT-In post-incident review.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>Adversary emulation</category><category>red team</category><category>aviation</category><category>airport</category><category>adversary emulation</category><category>India</category><category>CERT-In</category><category>field note</category><author>Cyberange Adaptive Red Team</author></item><item><title>The CERT-In six-hour window: what your DFIR runbook needs to say</title><link>https://cyberange.io/insights/cert-in-six-hour-window/</link><guid isPermaLink="true">https://cyberange.io/insights/cert-in-six-hour-window/</guid><description>CERT-In Direction 70B (April 2022) requires reporting of certain cyber incidents within six hours of detection. A practical breakdown of what the clock actually measures, what your runbook needs to include, and where most organisations get the timeline wrong.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>DFIR</category><category>CERT-In</category><category>incident response</category><category>regulatory</category><category>BFSI</category><category>India</category><author>Cyberange DFIR Consulting</author></item><item><title>Welcome to Cyberange Insights</title><link>https://cyberange.io/insights/welcome-to-insights/</link><guid isPermaLink="true">https://cyberange.io/insights/welcome-to-insights/</guid><description>The publishing home for our practice notes, engagement debriefs, and threat-landscape reads — now open for contributions from student alumni, cohorts, and the wider community.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>Community</category><category>announcement</category><category>editorial</category><author>Cyberange Editorial</author></item><item><title>Why we ship real PLCs, not software emulators</title><link>https://cyberange.io/insights/why-real-plcs-matter/</link><guid isPermaLink="true">https://cyberange.io/insights/why-real-plcs-matter/</guid><description>A short practice note on the difference between a simulator and a range, and why the difference compounds in operator training, regulator-grade demonstrations, and live red-team engagements.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>ICS / OT</category><category>phygital</category><category>practice</category><category>PLC</category><category>training</category><author>Cyberange Phygital Labs</author></item><item><title>Browser-based initial access in 2026</title><link>https://cyberange.io/insights/browser-based-initial-access-2026/</link><guid isPermaLink="true">https://cyberange.io/insights/browser-based-initial-access-2026/</guid><description>The fastest-growing initial-access surface in the engagement data is the browser session, not the credential. Reverse-proxy phishing kits, OAuth consent abuse, extension supply-chain hijacks, and infostealer-fed cookie marketplaces — what changed, why MFA and password rotation no longer cover the dominant case, and which controls actually move the curve.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>Threat intelligence</category><category>browser</category><category>initial access</category><category>SSO</category><category>threat intel</category><category>phishing</category><author>Cyberange Threat Intel</author></item><item><title>One letter off: how a look-alike domain and a stolen signature ran a 30-day invoice fraud</title><link>https://cyberange.io/insights/one-letter-off-business-email-compromise-invoice-fraud/</link><guid isPermaLink="true">https://cyberange.io/insights/one-letter-off-business-email-compromise-invoice-fraud/</guid><description>A new analyst, a trusted client, and an email that arrived at 5:45 on a Monday morning. The story of a business email compromise that turned on a single swapped character — and the forensic trail that survived a year of silence and a lawyer&apos;s denial.</description><pubDate>Sat, 14 Sep 2024 00:00:00 GMT</pubDate><category>DFIR</category><category>DFIR</category><category>BEC</category><category>business email compromise</category><category>invoice fraud</category><category>look-alike domain</category><category>phishing</category><category>financial services</category><category>investigation</category><author>Cyberange DFIR Team</author></item><item><title>Anatomy of a ransomware breach: from one exposed RDP port to domain-wide encryption in 72 hours</title><link>https://cyberange.io/insights/ransomware-dfir-exposed-rdp-to-domain-wide-encryption/</link><guid isPermaLink="true">https://cyberange.io/insights/ransomware-dfir-exposed-rdp-to-domain-wide-encryption/</guid><description>A sanitized DFIR debrief of a ransomware intrusion at a large Indian manufacturer. We reconstruct the timeline from a misconfigured firewall rule and a brute-forced RDP login through Mimikatz, AV removal, PsExec lateral movement, and full-estate encryption — and the anti-forensics that nearly erased the trail.</description><pubDate>Tue, 14 May 2024 00:00:00 GMT</pubDate><category>DFIR</category><category>DFIR</category><category>ransomware</category><category>incident response</category><category>forensics</category><category>Mimikatz</category><category>RDP</category><category>lateral movement</category><category>India</category><category>manufacturing</category><author>Cyberange DFIR Team</author></item><item><title>Just a marketing website: how a neglected WordPress site became a path to Domain Admin</title><link>https://cyberange.io/insights/marketing-website-to-domain-admin-wordpress-breach/</link><guid isPermaLink="true">https://cyberange.io/insights/marketing-website-to-domain-admin-wordpress-breach/</guid><description>It came in as a spam complaint. It ended at a forgotten brochure website wired into the company&apos;s domain controller, with the Domain Admin password sitting in a script on someone&apos;s desktop. A story about the assets nobody thinks are worth attacking.</description><pubDate>Thu, 14 Apr 2022 00:00:00 GMT</pubDate><category>DFIR</category><category>DFIR</category><category>web shell</category><category>WordPress</category><category>initial access</category><category>Active Directory</category><category>SEO spam</category><category>incident response</category><category>attack surface</category><author>Cyberange DFIR Team</author></item></channel></rss>