<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anvil Secure</title>
	<atom:link href="https://www.anvilsecure.com/feed" rel="self" type="application/rss+xml" />
	<link>https://www.anvilsecure.com/</link>
	<description></description>
	<lastBuildDate>Wed, 09 Sep 2026 07:04:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.7</generator>

<image>
	<url>https://www.anvilsecure.com/wp-content/uploads/2021/04/AnvilIcon6.png</url>
	<title>Anvil Secure</title>
	<link>https://www.anvilsecure.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Introducing PQCDump: A Real Look at PQC Adoption</title>
		<link>https://www.anvilsecure.com/blog/pqcdump-pqc-adoption-tools.html</link>
					<comments>https://www.anvilsecure.com/blog/pqcdump-pqc-adoption-tools.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 01:34:23 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7806</guid>

					<description><![CDATA[<p>Senior Security Engineer Nicholas O'Shea introduces PQCDump, a passive analysis tool that parses SSH and TLS captures to show what post-quantum algorithms were actually negotiated, not just advertised, giving a fuller picture of real-world PQC adoption than active scanning alone.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/pqcdump-pqc-adoption-tools.html">Introducing PQCDump: A Real Look at PQC Adoption</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/pqcdump-pqc-adoption-tools.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Passkey Editor: a Burp Suite Extension for Attacking WebAuthn</title>
		<link>https://www.anvilsecure.com/blog/passkey-editor.html</link>
					<comments>https://www.anvilsecure.com/blog/passkey-editor.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 15:52:52 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7641</guid>

					<description><![CDATA[<p>Security Engineer Matteo Giordano introduces Passkey Editor, a Burp Suite extension that decodes and edits WebAuthn ceremonies, drives one-click attacks against them, and re-signs across eleven COSE algorithms, all inside Burp itself.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/passkey-editor.html">Passkey Editor: a Burp Suite Extension for Attacking WebAuthn</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/passkey-editor.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://github.com/anvilsecure/passkey-editor/blob/main/assets/videos/forge-manual.mp4" length="0" type="video/mp4" />
<enclosure url="https://github.com/anvilsecure/passkey-editor/blob/main/assets/videos/forge-auto.mp4" length="0" type="video/mp4" />
<enclosure url="https://github.com/anvilsecure/passkey-editor/blob/main/assets/videos/framing-1.mp4" length="0" type="video/mp4" />
<enclosure url="https://github.com/anvilsecure/passkey-editor/blob/main/assets/videos/framing-2.mp4" length="0" type="video/mp4" />
<enclosure url="https://github.com/anvilsecure/passkey-editor/blob/main/assets/videos/framing-3.mp4" length="0" type="video/mp4" />

			</item>
		<item>
		<title>Internal AI Adoption Hackathon: What We Learned</title>
		<link>https://www.anvilsecure.com/blog/ai-adoption-hackathon.html</link>
					<comments>https://www.anvilsecure.com/blog/ai-adoption-hackathon.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 06:55:43 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7619</guid>

					<description><![CDATA[<p>Anvil Secure's internal AI adoption hackathon gave engineers dedicated time to explore practical AI use cases. Technical Director Antonios Papadopoulos shares what the team learned and what comes next.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/ai-adoption-hackathon.html">Internal AI Adoption Hackathon: What We Learned</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/ai-adoption-hackathon.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Identifying and Chasing RCE in SAP&#8217;s CommonCryptoLib</title>
		<link>https://www.anvilsecure.com/blog/identifying-and-chasing-rce-in-saps-commoncryptolib.html</link>
					<comments>https://www.anvilsecure.com/blog/identifying-and-chasing-rce-in-saps-commoncryptolib.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Thu, 16 Jul 2026 07:06:42 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7581</guid>

					<description><![CDATA[<p>Director of Research Tao Sauvage shares the latest chapter in his SAP research, chasing a bug from SAP's archive tool into CommonCryptoLib, a flaw reachable before authentication on SAP HANA. He breaks down the root cause and his attempts to exploit it.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/identifying-and-chasing-rce-in-saps-commoncryptolib.html">Identifying and Chasing RCE in SAP&#8217;s CommonCryptoLib</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/identifying-and-chasing-rce-in-saps-commoncryptolib.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Finding Crown Jewels: Hunting Through 180,000 Ruby Gems</title>
		<link>https://www.anvilsecure.com/blog/finding-crown-jewels-hunting-through-180000-ruby-gems.html</link>
					<comments>https://www.anvilsecure.com/blog/finding-crown-jewels-hunting-through-180000-ruby-gems.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Wed, 17 Jun 2026 05:28:28 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7526</guid>

					<description><![CDATA[<p>CTO Vincent Berg mirrored more than 180,000 Ruby gems and built a scanner to analyse them at scale. What he uncovered offers a fascinating look at the hidden risks and exposed data scattered throughout the Ruby ecosystem.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/finding-crown-jewels-hunting-through-180000-ruby-gems.html">Finding Crown Jewels: Hunting Through 180,000 Ruby Gems</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/finding-crown-jewels-hunting-through-180000-ruby-gems.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How We Use LLMs in Secure Code Review</title>
		<link>https://www.anvilsecure.com/blog/how-we-use-llms-in-secure-code-review.html</link>
					<comments>https://www.anvilsecure.com/blog/how-we-use-llms-in-secure-code-review.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 01:00:39 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7454</guid>

					<description><![CDATA[<p>Director of Research Tao Sauvage breaks down how Anvil uses LLMs during secure code review, keeping human judgment at the center. He compares two approaches across three open-source targets to show why a structured workflow catches more vulnerabilities.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/how-we-use-llms-in-secure-code-review.html">How We Use LLMs in Secure Code Review</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/how-we-use-llms-in-secure-code-review.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How We Test AI:  LLM &#038; GenAI Security Methodology at Anvil Secure</title>
		<link>https://www.anvilsecure.com/blog/llm-genai-security-methodology-at-anvil-secure.html</link>
					<comments>https://www.anvilsecure.com/blog/llm-genai-security-methodology-at-anvil-secure.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Wed, 27 May 2026 16:59:31 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7444</guid>

					<description><![CDATA[<p>From threat modeling and attack surface mapping to jailbreaks and prompt injection, Security Engineer George Damiris walks through how Anvil Secure tests LLM and GenAI systems for security vulnerabilities.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/llm-genai-security-methodology-at-anvil-secure.html">How We Test AI:  LLM &#038; GenAI Security Methodology at Anvil Secure</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/llm-genai-security-methodology-at-anvil-secure.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Demystifying Passkeys — Under the Hood: The Architecture</title>
		<link>https://www.anvilsecure.com/blog/demystifying-passkeys-under-the-hood-the-architecture.html</link>
					<comments>https://www.anvilsecure.com/blog/demystifying-passkeys-under-the-hood-the-architecture.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Wed, 13 May 2026 09:00:57 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7401</guid>

					<description><![CDATA[<p>In Part 2 of a three-part series, Security Engineer Matteo Giordano explores passkey architecture, covering origin binding, synced vs. device-bound credentials, authenticator types, and deployment quirks like key wrapping and signature counters.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/demystifying-passkeys-under-the-hood-the-architecture.html">Demystifying Passkeys — Under the Hood: The Architecture</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/demystifying-passkeys-under-the-hood-the-architecture.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Demystifying Passkeys — Under the Hood: The Protocol</title>
		<link>https://www.anvilsecure.com/blog/demystifying-passkeys-under-the-hood-the-protocol.html</link>
					<comments>https://www.anvilsecure.com/blog/demystifying-passkeys-under-the-hood-the-protocol.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Thu, 07 May 2026 01:00:22 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7247</guid>

					<description><![CDATA[<p>In Part 1 of a new series, security engineer Matteo Giordano walks through the mechanics behind passkeys, from the FIDO2 protocol stack to the raw data structures exchanged during registration and authentication.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/demystifying-passkeys-under-the-hood-the-protocol.html">Demystifying Passkeys — Under the Hood: The Protocol</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/demystifying-passkeys-under-the-hood-the-protocol.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Introducing OffTempo, Statistical Timing Side-Channel Analysis for Burp Suite</title>
		<link>https://www.anvilsecure.com/blog/introducing-offtempo-statistical-timing-side-channel-analysis-for-burp-suite.html</link>
					<comments>https://www.anvilsecure.com/blog/introducing-offtempo-statistical-timing-side-channel-analysis-for-burp-suite.html#respond</comments>
		
		<dc:creator><![CDATA[Anvil Secure]]></dc:creator>
		<pubDate>Wed, 29 Apr 2026 09:51:18 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.anvilsecure.com/?p=7211</guid>

					<description><![CDATA[<p>Senior Security Engineer Riccardo Nannini introduces OffTempo, a Burp Suite extension designed to identify timing-based information leaks by comparing request patterns and analysing subtle differences in response times.</p>
<p>The post <a href="https://www.anvilsecure.com/blog/introducing-offtempo-statistical-timing-side-channel-analysis-for-burp-suite.html">Introducing OffTempo, Statistical Timing Side-Channel Analysis for Burp Suite</a> appeared first on <a href="https://www.anvilsecure.com/">Anvil Secure</a>.</p>
]]></description>
		
					<wfw:commentRss>https://www.anvilsecure.com/blog/introducing-offtempo-statistical-timing-side-channel-analysis-for-burp-suite.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
