<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cyberange — Insights</title><description>Threat intelligence, adversary emulation, DFIR, ICS/OT, and training notes from the Cyberange team.</description><link>https://cyberange.io/</link><language>en-IN</language><item><title>Inside a 90-day red team op against a tier-1 Indian airport operator</title><link>https://cyberange.io/insights/90-day-red-team-tier-1-indian-airport/</link><guid isPermaLink="true">https://cyberange.io/insights/90-day-red-team-tier-1-indian-airport/</guid><description>A redacted case study mapping a 13-week journey from an external foothold to full Active Directory compromise. Discover how the operator adapted tactics on the fly and what forensic artifacts survived a rigorous CERT-In post-incident review.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>Adversary emulation</category><category>red team</category><category>aviation</category><category>airport</category><category>adversary emulation</category><category>India</category><category>CERT-In</category><category>field note</category><author>Cyberange Adaptive Red Team</author></item><item><title>The CERT-In six-hour window: what your DFIR runbook needs to say</title><link>https://cyberange.io/insights/cert-in-six-hour-window/</link><guid isPermaLink="true">https://cyberange.io/insights/cert-in-six-hour-window/</guid><description>CERT-In Direction 70B (April 2022) requires reporting of certain cyber incidents within six hours of detection. A practical breakdown of what the clock actually measures, what your runbook needs to include, and where most organisations get the timeline wrong.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>DFIR</category><category>CERT-In</category><category>incident response</category><category>regulatory</category><category>BFSI</category><category>India</category><author>Cyberange DFIR Consulting</author></item><item><title>Welcome to Cyberange Insights</title><link>https://cyberange.io/insights/welcome-to-insights/</link><guid isPermaLink="true">https://cyberange.io/insights/welcome-to-insights/</guid><description>The publishing home for our practice notes, engagement debriefs, and threat-landscape reads — now open for contributions from student alumni, cohorts, and the wider community.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>Practice</category><category>announcement</category><category>editorial</category><author>Cyberange Editorial</author></item><item><title>Why we ship real PLCs, not software emulators</title><link>https://cyberange.io/insights/why-real-plcs-matter/</link><guid isPermaLink="true">https://cyberange.io/insights/why-real-plcs-matter/</guid><description>A short practice note on the difference between a simulator and a range, and why the difference compounds in operator training, regulator-grade demonstrations, and live red-team engagements.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>ICS / OT</category><category>phygital</category><category>practice</category><category>PLC</category><category>training</category><author>Cyberange Phygital Labs</author></item><item><title>Browser-based initial access in 2026</title><link>https://cyberange.io/insights/browser-based-initial-access-2026/</link><guid isPermaLink="true">https://cyberange.io/insights/browser-based-initial-access-2026/</guid><description>The fastest-growing initial-access surface in the engagement data is the browser session, not the credential. Reverse-proxy phishing kits, OAuth consent abuse, extension supply-chain hijacks, and infostealer-fed cookie marketplaces — what changed, why MFA and password rotation no longer cover the dominant case, and which controls actually move the curve.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>Threat intelligence</category><category>browser</category><category>initial access</category><category>SSO</category><category>threat intel</category><category>phishing</category><author>Cyberange Threat Intel</author></item></channel></rss>