<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>War Room</title>
	<atom:link href="https://warroom.rsmus.com/author/jbelton/feed/" rel="self" type="application/rss+xml" />
	<link>https://warroom.rsmus.com</link>
	<description>Shells From Above</description>
	<lastBuildDate>Thu, 15 Feb 2024 19:21:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://warroom.rsmus.com/wp-content/uploads/2018/09/cropped-favicon-32x32.png</url>
	<title>War Room</title>
	<link>https://warroom.rsmus.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Intel Insights &#8211; Phishing with QR Codes</title>
		<link>https://warroom.rsmus.com/phishing-with-qr-codes/</link>
		
		<dc:creator><![CDATA[Joel Belton]]></dc:creator>
		<pubDate>Fri, 25 Aug 2023 18:21:50 +0000</pubDate>
				<category><![CDATA[RSM Defense]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=6057</guid>

					<description><![CDATA[A large phishing campaign using QR codes has been detected targeting various industries, with the aim to acquire Microsoft credentials. Researchers from the security firm, Cofense, observed the attacks against “a major Energy company based in the US.” The reported phishing campaign also targeted organizations in other industries, including finance, insurance, manufacturing, and tech. One [&#8230;]]]></description>
		
		
		
			</item>
		<item>
		<title>Rhysida Ransomware Attack on PMH and Connections to Vice Society Ransomware</title>
		<link>https://warroom.rsmus.com/rhysida-ransomware-attack-on-pmh/</link>
		
		<dc:creator><![CDATA[Joel Belton]]></dc:creator>
		<pubDate>Fri, 11 Aug 2023 20:10:08 +0000</pubDate>
				<category><![CDATA[RSM Defense]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=6053</guid>

					<description><![CDATA[On August 4th, 2023, the parent company of Eastern Connecticut Health Network and Waterbury Health, Prospect Medical Holdings(PMH), announced that all of its facilities were facing IT complications. Prospect Medical Holdings is a parent company to over 16 hospitals, 165 outpatient clinics, in over 4 states ( California, Connecticut, Pennsylvania, Rhode Island) It was later [&#8230;]]]></description>
		
		
		
			</item>
		<item>
		<title>STORM-0558 Utilizes Acquired MSA Keys to Forge Authentication Tokens Then Attack Outlook Exchange</title>
		<link>https://warroom.rsmus.com/storm-0558-utilizes-acquired-msa-keys-to-forge-authentication-tokens-then-attack-outlook-exchange/</link>
		
		<dc:creator><![CDATA[Joel Belton]]></dc:creator>
		<pubDate>Fri, 28 Jul 2023 23:06:01 +0000</pubDate>
				<category><![CDATA[RSM Defense]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=6032</guid>

					<description><![CDATA[On July 12, 2023, The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have released a joint Cybersecurity Advisory (CSA)(aa23-193a) detailing an attack on an Federal Civilian Executive Branch (FCEB) agency in June 2023. The attack had been observed due to observing anomalous activity within the Microsoft 365 (M365) audit logs. [&#8230;]]]></description>
		
		
		
			</item>
		<item>
		<title>AI Used in Scams: Faked Kidnapping</title>
		<link>https://warroom.rsmus.com/a-i-used-in-scams/</link>
		
		<dc:creator><![CDATA[Joel Belton]]></dc:creator>
		<pubDate>Mon, 15 May 2023 19:44:04 +0000</pubDate>
				<category><![CDATA[RSM Defense]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<guid isPermaLink="false">https://warroom.rsmus.com/?p=6009</guid>

					<description><![CDATA[A mother of a 15-year-old girl, Jennifer DeStefano, received a disturbing phone call on January 20th, 2023, while taking her younger daughter, Aubrey, 13, to a dance rehearsal in Scottsdale Arizona. The call&#8217;s caller ID showed an “Unknown number”, yet a familiar voice was heard on the other end of the telephone call. The voice [&#8230;]]]></description>
		
		
		
			</item>
	</channel>
</rss>
