<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Secorvia Blog</title>
    <link>https://www.secorvia.com/blog/</link>
    <atom:link href="https://www.secorvia.com/blog/rss.xml" rel="self" type="application/rss+xml"/>
    <description>Cloud security posture, attack paths, blast radius and identity risk, explained by the team that builds Secorvia.</description>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:00:00 GMT</lastBuildDate>
    <item>
      <title>Who can walk into your AWS account from outside?</title>
      <link>https://www.secorvia.com/blog/frontdoor-federated-trust-aws.html</link>
      <guid isPermaLink="true">https://www.secorvia.com/blog/frontdoor-federated-trust-aws.html</guid>
      <description>OIDC, SAML and cross-account trust let outsiders assume roles in your AWS account. How to find each one, plus a free open source CLI that audits them.</description>
      <author>noreply@secorvia.com (Rohaan)</author>
      <pubDate>Sat, 03 Oct 2026 09:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is an attack path in cloud security?</title>
      <link>https://www.secorvia.com/blog/what-is-an-attack-path.html</link>
      <guid isPermaLink="true">https://www.secorvia.com/blog/what-is-an-attack-path.html</guid>
      <description>An attack path is the chain of real hops from an exposed entry point to a sensitive target in your cloud. What the hops are and how tools detect them.</description>
      <author>noreply@secorvia.com (Rohaan)</author>
      <pubDate>Sat, 03 Oct 2026 09:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CVSS, EPSS and KEV: three scores, three different questions</title>
      <link>https://www.secorvia.com/blog/cvss-epss-kev.html</link>
      <guid isPermaLink="true">https://www.secorvia.com/blog/cvss-epss-kev.html</guid>
      <description>CVSS measures how bad a flaw is, EPSS how likely it is to be exploited, and KEV whether it already has been. How to combine all three in one patch queue.</description>
      <author>noreply@secorvia.com (Rohaan)</author>
      <pubDate>Sat, 05 Sep 2026 09:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CIEM: the over-permissioned identity problem</title>
      <link>https://www.secorvia.com/blog/ciem-explained.html</link>
      <guid isPermaLink="true">https://www.secorvia.com/blog/ciem-explained.html</guid>
      <description>CIEM finds cloud identities holding more access than they use, and the permission chains that lead to admin. How it works, and how it differs from IAM.</description>
      <author>noreply@secorvia.com (Rohaan)</author>
      <pubDate>Fri, 04 Sep 2026 09:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Blast radius: measuring what falls with a single asset</title>
      <link>https://www.secorvia.com/blog/blast-radius.html</link>
      <guid isPermaLink="true">https://www.secorvia.com/blog/blast-radius.html</guid>
      <description>Blast radius is what an attacker can reach after taking one cloud resource. How it is computed, how it differs from attack paths, and where it misleads.</description>
      <author>noreply@secorvia.com (Rohaan)</author>
      <pubDate>Thu, 03 Sep 2026 09:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Why a CVSS score cannot prioritise your cloud risk</title>
      <link>https://www.secorvia.com/blog/attack-paths-vs-cvss.html</link>
      <guid isPermaLink="true">https://www.secorvia.com/blog/attack-paths-vs-cvss.html</guid>
      <description>CVSS rates a flaw before anyone has seen your account. Attack paths rank risk by what an attacker can reach. Where each fits, with a side-by-side table.</description>
      <author>noreply@secorvia.com (Rohaan)</author>
      <pubDate>Wed, 02 Sep 2026 09:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What is Cloud Security Posture Management?</title>
      <link>https://www.secorvia.com/blog/what-is-cspm.html</link>
      <guid isPermaLink="true">https://www.secorvia.com/blog/what-is-cspm.html</guid>
      <description>CSPM checks cloud configuration against a secure baseline using read-only APIs. What it covers, what it misses, and how it differs from CWPP and CNAPP.</description>
      <author>noreply@secorvia.com (Rohaan)</author>
      <pubDate>Tue, 01 Sep 2026 09:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
