<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Simon Roses Femerling &#8211; Blog</title>
	<atom:link href="https://simonroses.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://simonroses.com</link>
	<description>CyberSpace Insecurity 3.X</description>
	<lastBuildDate>Fri, 28 Aug 2026 16:57:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>
<site xmlns="com-wordpress:feed-additions:1">13601991</site>	<item>
		<title>Information Warfare Strategies (SRF-IWS): Spyware as Statecraft — How States Blackmail States</title>
		<link>https://simonroses.com/2026/08/information-warfare-strategies-srf-iws-spyware-as-statecraft-how-states-blackmail-states/</link>
					<comments>https://simonroses.com/2026/08/information-warfare-strategies-srf-iws-spyware-as-statecraft-how-states-blackmail-states/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 16:57:22 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Economics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[SRF-IWS]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2567</guid>

					<description><![CDATA[**Read Time:** 15 minutes ## TL;DR Commercial spyware collapsed the price of the oldest move in statecraft: know what the other side knows, and hold something over the people who decide. A mid-sized state can now rent zero-click capability that &#8230; <a href="https://simonroses.com/2026/08/information-warfare-strategies-srf-iws-spyware-as-statecraft-how-states-blackmail-states/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/08/information-warfare-strategies-srf-iws-spyware-as-statecraft-how-states-blackmail-states/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2567</post-id>	</item>
		<item>
		<title>The Death of the Job: How AI and Robots Will Rewrite Work in the Next 10 Years</title>
		<link>https://simonroses.com/2026/08/the-death-of-the-job-how-ai-and-robots-will-rewrite-work-in-the-next-10-years/</link>
					<comments>https://simonroses.com/2026/08/the-death-of-the-job-how-ai-and-robots-will-rewrite-work-in-the-next-10-years/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 19:22:58 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Technology]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2558</guid>

					<description><![CDATA[**Read Time:** 16 minutes ## TL;DR Work is not disappearing. The **job** is. The salaried, 9-to-5, one-employer-for-decades package we call &#8220;a job&#8221; is an industrial-age artifact, and AI agents plus humanoid robots are dismantling it piece by piece. Over the &#8230; <a href="https://simonroses.com/2026/08/the-death-of-the-job-how-ai-and-robots-will-rewrite-work-in-the-next-10-years/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/08/the-death-of-the-job-how-ai-and-robots-will-rewrite-work-in-the-next-10-years/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2558</post-id>	</item>
		<item>
		<title>When a Missing Patch Becomes a Defective Product: The New EU Product Liability Directive</title>
		<link>https://simonroses.com/2026/08/when-a-missing-patch-becomes-a-defective-product-the-new-eu-product-liability-directive/</link>
					<comments>https://simonroses.com/2026/08/when-a-missing-patch-becomes-a-defective-product-the-new-eu-product-liability-directive/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 10:02:10 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2546</guid>

					<description><![CDATA[**Read Time:** 13 minutes ## TL;DR On **December 9, 2026** — a few months from now — the new EU Product Liability Directive ((EU) 2024/2853, &#8220;PLD&#8221;) starts applying to products placed on the EU market. For the first time, **software &#8230; <a href="https://simonroses.com/2026/08/when-a-missing-patch-becomes-a-defective-product-the-new-eu-product-liability-directive/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/08/when-a-missing-patch-becomes-a-defective-product-the-new-eu-product-liability-directive/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2546</post-id>	</item>
		<item>
		<title>The Day the AI Act Grew Teeth: GPAI Enforcement Goes Live</title>
		<link>https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/</link>
					<comments>https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 08 Aug 2026 10:53:50 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[GPAI]]></category>
		<category><![CDATA[LLM]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2536</guid>

					<description><![CDATA[**Read Time:** 13 minutes ## TL;DR On **August 2, 2026**, the part of the EU AI Act everyone was quietly ignoring became enforceable: the AI Office can now fine providers of general-purpose AI models **up to 3% of global annual &#8230; <a href="https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/08/the-day-the-ai-act-grew-teeth-gpai-enforcement-goes-live/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2536</post-id>	</item>
		<item>
		<title>The Future of Vibe Coding Security (Part 10)</title>
		<link>https://simonroses.com/2026/07/the-future-of-vibe-coding-security-part-10/</link>
					<comments>https://simonroses.com/2026/07/the-future-of-vibe-coding-security-part-10/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 08:51:17 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2513</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/07/the-future-of-vibe-coding-security-part-10/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/the-future-of-vibe-coding-security-part-10/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2513</post-id>	</item>
		<item>
		<title>Do Open Weight Models Dream of Tokens?</title>
		<link>https://simonroses.com/2026/07/do-open-weight-models-dream-of-tokens/</link>
					<comments>https://simonroses.com/2026/07/do-open-weight-models-dream-of-tokens/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 25 Jul 2026 10:31:06 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Economics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[CyberSecurity]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[OpenSourceModel]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2508</guid>

					<description><![CDATA[**Read Time:** 14 minutes ## TL;DR Philip K. Dick asked whether an android could be told from a human. In 2026 the enterprise version of that question is whether you can still tell an open-weight model from a frontier commercial &#8230; <a href="https://simonroses.com/2026/07/do-open-weight-models-dream-of-tokens/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/do-open-weight-models-dream-of-tokens/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2508</post-id>	</item>
		<item>
		<title>When the Model Is the Attacker: The Hugging Face / OpenAI Model-Evaluation Incident</title>
		<link>https://simonroses.com/2026/07/when-the-model-is-the-attacker-the-hugging-face-openai-model-evaluation-incident/</link>
					<comments>https://simonroses.com/2026/07/when-the-model-is-the-attacker-the-hugging-face-openai-model-evaluation-incident/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Wed, 22 Jul 2026 16:15:09 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AgenticAI]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[BlueTeam]]></category>
		<category><![CDATA[LLM]]></category>
		<category><![CDATA[Software Security]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2491</guid>

					<description><![CDATA[**Read Time:** 12 minutes ## TL;DR On July 21, 2026, OpenAI and Hugging Face published coordinated write-ups of the same ugly weekend. In OpenAI&#8217;s telling, a pre-release model with reduced cyber refusals — run inside a cyber-capability **evaluation** — discovered &#8230; <a href="https://simonroses.com/2026/07/when-the-model-is-the-attacker-the-hugging-face-openai-model-evaluation-incident/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/when-the-model-is-the-attacker-the-hugging-face-openai-model-evaluation-incident/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2491</post-id>	</item>
		<item>
		<title>Securing the AI Coding Pipeline (Part 9)</title>
		<link>https://simonroses.com/2026/07/securing-the-ai-coding-pipeline-part-9/</link>
					<comments>https://simonroses.com/2026/07/securing-the-ai-coding-pipeline-part-9/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 09:00:28 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2470</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/07/securing-the-ai-coding-pipeline-part-9/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/securing-the-ai-coding-pipeline-part-9/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2470</post-id>	</item>
		<item>
		<title>The Founder&#8217;s Security Checklist: Shipping a Vibe-Coded MVP Without Getting Hacked (Part 8)</title>
		<link>https://simonroses.com/2026/07/the-founders-security-checklist-shipping-a-vibe-coded-mvp-without-getting-hacked-part-8/</link>
					<comments>https://simonroses.com/2026/07/the-founders-security-checklist-shipping-a-vibe-coded-mvp-without-getting-hacked-part-8/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 02 Jul 2026 08:18:07 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2446</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/07/the-founders-security-checklist-shipping-a-vibe-coded-mvp-without-getting-hacked-part-8/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/07/the-founders-security-checklist-shipping-a-vibe-coded-mvp-without-getting-hacked-part-8/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2446</post-id>	</item>
		<item>
		<title>The AI Strategy Vacuum: Why &#8220;We Use ChatGPT&#8221; Isn&#8217;t a Plan</title>
		<link>https://simonroses.com/2026/06/the-ai-strategy-vacuum-why-we-use-chatgpt-isnt-a-plan/</link>
					<comments>https://simonroses.com/2026/06/the-ai-strategy-vacuum-why-we-use-chatgpt-isnt-a-plan/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 15:05:26 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Economics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[ShadowAI]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2441</guid>

					<description><![CDATA[**Read Time:** 18 minutes ## TL;DR A CEO tells the board the company is &#8220;all in on AI.&#8221; Three floors down, here&#8217;s what that actually means: marketing is running a chatbot nobody in security has heard of, finance just pasted &#8230; <a href="https://simonroses.com/2026/06/the-ai-strategy-vacuum-why-we-use-chatgpt-isnt-a-plan/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/06/the-ai-strategy-vacuum-why-we-use-chatgpt-isnt-a-plan/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2441</post-id>	</item>
		<item>
		<title>Prompt Engineering for Secure Code (Part 7)</title>
		<link>https://simonroses.com/2026/06/prompt-engineering-for-secure-code-part-7/</link>
					<comments>https://simonroses.com/2026/06/prompt-engineering-for-secure-code-part-7/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Sat, 20 Jun 2026 10:00:53 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2422</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/06/prompt-engineering-for-secure-code-part-7/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/06/prompt-engineering-for-secure-code-part-7/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2422</post-id>	</item>
		<item>
		<title>Information Warfare Strategies (SRF-IWS): Offensive Operations Against a Papal Visit — Pope Leo XIV in Madrid 2026</title>
		<link>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/</link>
					<comments>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Fri, 05 Jun 2026 07:52:00 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[BlueTeam]]></category>
		<category><![CDATA[Information Warfare]]></category>
		<category><![CDATA[RedTeam]]></category>
		<category><![CDATA[SRF-IWS]]></category>
		<category><![CDATA[SRFIWS]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2394</guid>

					<description><![CDATA[> **Disclaimer:** Everything described here is pure imagination and any resemblance to reality is coincidental. This document is intended for security professionals to develop defensive countermeasures. The author is not responsible for the consequences of any action taken based on &#8230; <a href="https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/06/information-warfare-strategies-srf-iws-offensive-operations-against-a-papal-visit-pope-leo-xiv-in-madrid-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2394</post-id>	</item>
		<item>
		<title>Scanning Vibe-Coded Apps: Why Traditional SAST/DAST Falls Short (part 6)</title>
		<link>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/</link>
					<comments>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/#respond</comments>
		
		<dc:creator><![CDATA[Simon Roses]]></dc:creator>
		<pubDate>Thu, 28 May 2026 07:20:50 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[VibeCoding]]></category>
		<category><![CDATA[VibeCodingSecurity]]></category>
		<guid isPermaLink="false">https://simonroses.com/?p=2379</guid>

					<description><![CDATA[> **Vibe Coding Security Series** > 1. [What Is Vibe Coding Security? A Field Guide for 2026](https://simonroses.com/2026/04/what-is-vibe-coding-security-a-field-guide-for-2026-part-1/) > 2. [The OWASP Top 10 for Vibe-Coded Applications](https://simonroses.com/2026/04/the-owasp-top-10-for-vibe-coded-applications-part-2/) > 3. [Anatomy of a Vibe Coding Breach: Lessons from 2026&#8217;s Worst Incidents](https://simonroses.com/2026/04/anatomy-of-a-vibe-coding-breach-part-3/) > &#8230; <a href="https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		
					<wfw:commentRss>https://simonroses.com/2026/05/scanning-vibe-coded-apps-why-traditional-sast-dast-falls-short-part-6/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2379</post-id>	</item>
	</channel>
</rss>
