<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>SurfaceLoop Blog</title><description>Security insights, guides, and analysis covering attack surface management, vulnerability scanning, and infrastructure security.</description><link>https://surfaceloop.com/</link><item><title>What Is a CVE? Vulnerability Identifiers and Scoring</title><link>https://surfaceloop.com/blog/what-is-a-cve/</link><guid isPermaLink="true">https://surfaceloop.com/blog/what-is-a-cve/</guid><description>CVE identifiers explained for IT and security teams. Learn how CVEs are assigned, how CVSS scoring works, and how to use the NVD to assess risk.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>How to Scan External Assets for Known Vulnerabilities</title><link>https://surfaceloop.com/blog/vulnerability-scanning-external-assets/</link><guid isPermaLink="true">https://surfaceloop.com/blog/vulnerability-scanning-external-assets/</guid><description>A practical guide to scanning internet-facing assets for CVEs. Covers tools, techniques, and how to interpret and act on scan results.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Critical CVEs Targeting Internet-Facing Services</title><link>https://surfaceloop.com/blog/critical-cves-internet-facing-services/</link><guid isPermaLink="true">https://surfaceloop.com/blog/critical-cves-internet-facing-services/</guid><description>Recent high-impact CVEs in VPN gateways, web servers, and network devices. Learn which vulnerabilities attackers are actively exploiting.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>The Most Dangerous Open Ports and How Attackers Use Them</title><link>https://surfaceloop.com/blog/most-dangerous-open-ports/</link><guid isPermaLink="true">https://surfaceloop.com/blog/most-dangerous-open-ports/</guid><description>Which open ports pose the greatest security risk. Covers SSH, RDP, databases, SMB, and other commonly exploited services with attack scenarios.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>How to Audit Open Ports on Your External Attack Surface</title><link>https://surfaceloop.com/blog/how-to-audit-open-ports/</link><guid isPermaLink="true">https://surfaceloop.com/blog/how-to-audit-open-ports/</guid><description>A practical guide to discovering and auditing open ports across your internet-facing infrastructure using Nmap, Masscan, and EASM tools.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Securing SSH, RDP, and VPN Ports Against Attack</title><link>https://surfaceloop.com/blog/securing-remote-access-ports/</link><guid isPermaLink="true">https://surfaceloop.com/blog/securing-remote-access-ports/</guid><description>How to harden remote access services exposed to the internet. Covers SSH key authentication, RDP security, VPN hardening, and zero-trust alternatives.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Preventing TLS Certificate Expiry with Automation</title><link>https://surfaceloop.com/blog/preventing-tls-certificate-expiry/</link><guid isPermaLink="true">https://surfaceloop.com/blog/preventing-tls-certificate-expiry/</guid><description>How to prevent TLS certificate expiry using ACME automation, monitoring, and certificate lifecycle management. Avoid outages before they happen.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Weak Cipher Suites: What They Are and How to Fix Them</title><link>https://surfaceloop.com/blog/weak-cipher-suites-explained/</link><guid isPermaLink="true">https://surfaceloop.com/blog/weak-cipher-suites-explained/</guid><description>Which TLS cipher suites are insecure and why. Learn how to identify weak ciphers on your servers and configure modern, secure cipher suites.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Content Security Policy: A Practical Implementation Guide</title><link>https://surfaceloop.com/blog/content-security-policy-guide/</link><guid isPermaLink="true">https://surfaceloop.com/blog/content-security-policy-guide/</guid><description>How to implement Content-Security-Policy from scratch. Covers report-only mode, nonce-based scripts, common directives, and deployment strategies.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>HSTS Preloading: How to Enforce HTTPS Permanently</title><link>https://surfaceloop.com/blog/hsts-preloading-guide/</link><guid isPermaLink="true">https://surfaceloop.com/blog/hsts-preloading-guide/</guid><description>How to deploy HSTS and submit your domain to browser preload lists. Covers max-age, includeSubDomains, the preload directive, and common pitfalls.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>HTTP Security Headers Checklist for Web Applications</title><link>https://surfaceloop.com/blog/security-headers-checklist/</link><guid isPermaLink="true">https://surfaceloop.com/blog/security-headers-checklist/</guid><description>An actionable checklist of HTTP security headers every web application should set. Includes recommended values, server configuration, and common mistakes.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Certificate Transparency Logs for Subdomain Discovery</title><link>https://surfaceloop.com/blog/certificate-transparency-subdomain-discovery/</link><guid isPermaLink="true">https://surfaceloop.com/blog/certificate-transparency-subdomain-discovery/</guid><description>Certificate transparency logs are a free, passive source for discovering subdomains. Learn how CT logs work and how to use them for attack surface mapping.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>DMARC Enforcement Step by Step</title><link>https://surfaceloop.com/blog/dmarc-enforcement-step-by-step/</link><guid isPermaLink="true">https://surfaceloop.com/blog/dmarc-enforcement-step-by-step/</guid><description>Most DMARC deployments stall at p=none. This guide walks you from monitoring to full enforcement - the step where your domain actually becomes protected.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>How Attackers Spoof Your Domain for Phishing</title><link>https://surfaceloop.com/blog/how-attackers-spoof-your-domain/</link><guid isPermaLink="true">https://surfaceloop.com/blog/how-attackers-spoof-your-domain/</guid><description>Email spoofing lets attackers send messages as your domain. Learn the techniques they use and how SPF, DKIM, and DMARC stop them.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Shadow IT and Forgotten Subdomains: Your Hidden Attack Surface</title><link>https://surfaceloop.com/blog/forgotten-subdomains-shadow-it/</link><guid isPermaLink="true">https://surfaceloop.com/blog/forgotten-subdomains-shadow-it/</guid><description>Forgotten subdomains and shadow IT expand your attack surface invisibly. Learn why they appear, what risks they create, and how to discover them.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Subdomain Takeover: How It Works and How to Prevent It</title><link>https://surfaceloop.com/blog/subdomain-takeover-explained/</link><guid isPermaLink="true">https://surfaceloop.com/blog/subdomain-takeover-explained/</guid><description>Subdomain takeover lets attackers serve content on your domain. Learn how dangling DNS records create this risk and how to detect and prevent takeovers.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Exposed Admin Panels: Real-World Breaches and Lessons</title><link>https://surfaceloop.com/blog/exposed-admin-panels-breaches/</link><guid isPermaLink="true">https://surfaceloop.com/blog/exposed-admin-panels-breaches/</guid><description>Admin panels left open to the internet have caused major breaches. See real examples and learn how to prevent your organisation becoming the next case study.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>Default Credentials Are Still the Biggest Risk</title><link>https://surfaceloop.com/blog/default-credentials-risk/</link><guid isPermaLink="true">https://surfaceloop.com/blog/default-credentials-risk/</guid><description>Factory-set usernames and passwords remain one of the easiest ways into an organisation. Why default credentials persist and how to eliminate them.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>SPF, DKIM, and DMARC: The Complete Setup Guide</title><link>https://surfaceloop.com/blog/spf-dkim-dmarc-complete-guide/</link><guid isPermaLink="true">https://surfaceloop.com/blog/spf-dkim-dmarc-complete-guide/</guid><description>A step-by-step guide to configuring SPF, DKIM, and DMARC for your domain. Protect against email spoofing with correctly configured email authentication.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item><item><title>How to Find Exposed Admin Panels on Your Network</title><link>https://surfaceloop.com/blog/find-exposed-admin-panels/</link><guid isPermaLink="true">https://surfaceloop.com/blog/find-exposed-admin-panels/</guid><description>A practical guide to discovering admin panels, management consoles, and login pages exposed on your external attack surface before attackers do.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate></item></channel></rss>