<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://c-zhong.github.io/feed.xml" rel="self" type="application/atom+xml" /><link href="https://c-zhong.github.io/" rel="alternate" type="text/html" /><updated>2026-05-20T10:06:56-04:00</updated><id>https://c-zhong.github.io/feed.xml</id><title type="html">Chen Zhong / Personal Website</title><subtitle>Associate Professor of Cybersecurity</subtitle><author><name>Chen Zhong</name><email>czhong at ut dot edu</email></author><entry><title type="html">Future Blog Post</title><link href="https://c-zhong.github.io/posts/2012/08/blog-post-4/" rel="alternate" type="text/html" title="Future Blog Post" /><published>2199-01-01T00:00:00-05:00</published><updated>2199-01-01T00:00:00-05:00</updated><id>https://c-zhong.github.io/posts/2012/08/future-post</id><content type="html" xml:base="https://c-zhong.github.io/posts/2012/08/blog-post-4/"><![CDATA[<p>This post will show up by default. To disable scheduling of future posts, edit <code class="language-plaintext highlighter-rouge">config.yml</code> and set <code class="language-plaintext highlighter-rouge">future: false</code>.</p>]]></content><author><name>Chen Zhong</name><email>czhong at ut dot edu</email></author><category term="cool posts" /><category term="category1" /><category term="category2" /><summary type="html"><![CDATA[This post will show up by default. To disable scheduling of future posts, edit config.yml and set future: false.]]></summary></entry><entry><title type="html">Daily Cybersecurity Updates - May 19, 2026</title><link href="https://c-zhong.github.io/daily-cybersecurity-updates/daily-cybersecurity-updates/" rel="alternate" type="text/html" title="Daily Cybersecurity Updates - May 19, 2026" /><published>2026-05-19T00:00:00-04:00</published><updated>2026-05-19T00:00:00-04:00</updated><id>https://c-zhong.github.io/daily-cybersecurity-updates/daily-cybersecurity-updates</id><content type="html" xml:base="https://c-zhong.github.io/daily-cybersecurity-updates/daily-cybersecurity-updates/"><![CDATA[<h2 id="top-3-5-updates">Top 3-5 Updates</h2>

<ul>
  <li><a href="https://www.darkreading.com/vulnerabilities-threats/microsoft-exchange-zero-day-no-patch">Dark Reading</a>: Microsoft Exchange OWA zero-day <code class="language-plaintext highlighter-rouge">CVE-2026-42897</code> remained under active exploitation on May 18 with no patch yet, which matters because mailbox compromise still creates a clean path to BEC, token theft, and downstream ransomware.</li>
  <li><a href="https://www.darkreading.com/application-security/claw-chain-vulnerabilities-threaten-openclaw">Dark Reading</a>: Four patched OpenClaw flaws (<code class="language-plaintext highlighter-rouge">CVE-2026-44112</code>, <code class="language-plaintext highlighter-rouge">CVE-2026-44115</code>, <code class="language-plaintext highlighter-rouge">CVE-2026-44118</code>, <code class="language-plaintext highlighter-rouge">CVE-2026-44113</code>) show how AI agent platforms can turn normal tool use into stealthy persistence and credential theft.</li>
  <li><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">Google Threat Intelligence Group</a>: GTIG’s latest AI threat tracker remains the highest-signal AI-cyber item in scope, documenting AI-assisted zero-day discovery, malware obfuscation, and autonomous Android backdoor behavior relevant to defender planning.</li>
</ul>

<h2 id="research-watch">Research Watch</h2>

<ul>
  <li>No high-signal new <a href="https://www.usenix.org/conference/usenixsecurity26">USENIX Security accepted-paper</a> or <a href="https://arxiv.org/list/cs.CR/recent">arXiv cs.CR</a> items stood out in the past 24 hours.</li>
</ul>

<h2 id="threat-and-advisory-watch">Threat and Advisory Watch</h2>

<ul>
  <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA KEV Catalog</a>: <code class="language-plaintext highlighter-rouge">CVE-2026-42897</code> is now in KEV, so Exchange OWA exposure should be treated as a live-priority remediation and mitigation problem.</li>
  <li><a href="https://unit42.paloaltonetworks.com/threat-bulletin/may-2026/">Unit 42 Threat Bulletin - May 2026</a>: Unit 42’s current bulletin argues that identity abuse, trusted software paths, and AI-assisted discovery are converging into a lower-noise attack model that bypasses many exploit-centric detections.</li>
</ul>

<h2 id="practitioner-discussions">Practitioner Discussions</h2>

<ul>
  <li>No technically meaningful new r/cybersecurity or r/netsec discussion in the past 24 hours added enough verified signal to include.</li>
</ul>

<h2 id="relevance-to-my-research">Relevance to My Research</h2>

<ul>
  <li>OpenClaw’s bug chain is a concrete example of human-AI trust failure: benign-seeming tool calls can mask privilege escalation and persistence.</li>
  <li>The Exchange case reinforces that AI-assisted defense still needs strong prioritization around identity, mail, and session-token abuse, not just endpoint malware.</li>
  <li>GTIG’s report is directly relevant to adversarial AI and human-AI collaboration because it shows both attacker automation gains and the need for defender-side AI monitoring, repair, and validation.</li>
</ul>]]></content><author><name>Chen Zhong</name><email>czhong at ut dot edu</email></author><category term="daily-cybersecurity-updates" /><category term="cybersecurity" /><category term="daily update" /><summary type="html"><![CDATA[Daily cybersecurity update summary.]]></summary></entry><entry><title type="html">Blog Post number 4</title><link href="https://c-zhong.github.io/posts/2012/08/blog-post-4/" rel="alternate" type="text/html" title="Blog Post number 4" /><published>2015-08-14T00:00:00-04:00</published><updated>2015-08-14T00:00:00-04:00</updated><id>https://c-zhong.github.io/posts/2012/08/blog-post-4</id><content type="html" xml:base="https://c-zhong.github.io/posts/2012/08/blog-post-4/"><![CDATA[<p>This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.</p>

<h1 id="headings-are-cool">Headings are cool</h1>

<h1 id="you-can-have-many-headings">You can have many headings</h1>

<h2 id="arent-headings-cool">Aren’t headings cool?</h2>]]></content><author><name>Chen Zhong</name><email>czhong at ut dot edu</email></author><category term="cool posts" /><category term="category1" /><category term="category2" /><summary type="html"><![CDATA[This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.]]></summary></entry><entry><title type="html">Blog Post number 3</title><link href="https://c-zhong.github.io/posts/2014/08/blog-post-3/" rel="alternate" type="text/html" title="Blog Post number 3" /><published>2014-08-14T00:00:00-04:00</published><updated>2014-08-14T00:00:00-04:00</updated><id>https://c-zhong.github.io/posts/2014/08/blog-post-3</id><content type="html" xml:base="https://c-zhong.github.io/posts/2014/08/blog-post-3/"><![CDATA[<p>This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.</p>

<h1 id="headings-are-cool">Headings are cool</h1>

<h1 id="you-can-have-many-headings">You can have many headings</h1>

<h2 id="arent-headings-cool">Aren’t headings cool?</h2>]]></content><author><name>Chen Zhong</name><email>czhong at ut dot edu</email></author><category term="cool posts" /><category term="category1" /><category term="category2" /><summary type="html"><![CDATA[This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.]]></summary></entry><entry><title type="html">Blog Post number 2</title><link href="https://c-zhong.github.io/posts/2013/08/blog-post-2/" rel="alternate" type="text/html" title="Blog Post number 2" /><published>2013-08-14T00:00:00-04:00</published><updated>2013-08-14T00:00:00-04:00</updated><id>https://c-zhong.github.io/posts/2013/08/blog-post-2</id><content type="html" xml:base="https://c-zhong.github.io/posts/2013/08/blog-post-2/"><![CDATA[<p>This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.</p>

<h1 id="headings-are-cool">Headings are cool</h1>

<h1 id="you-can-have-many-headings">You can have many headings</h1>

<h2 id="arent-headings-cool">Aren’t headings cool?</h2>]]></content><author><name>Chen Zhong</name><email>czhong at ut dot edu</email></author><category term="cool posts" /><category term="category1" /><category term="category2" /><summary type="html"><![CDATA[This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.]]></summary></entry><entry><title type="html">Blog Post number 1</title><link href="https://c-zhong.github.io/posts/2012/08/blog-post-1/" rel="alternate" type="text/html" title="Blog Post number 1" /><published>2012-08-14T00:00:00-04:00</published><updated>2012-08-14T00:00:00-04:00</updated><id>https://c-zhong.github.io/posts/2012/08/blog-post-1</id><content type="html" xml:base="https://c-zhong.github.io/posts/2012/08/blog-post-1/"><![CDATA[<p>This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.</p>

<h1 id="headings-are-cool">Headings are cool</h1>

<h1 id="you-can-have-many-headings">You can have many headings</h1>

<h2 id="arent-headings-cool">Aren’t headings cool?</h2>]]></content><author><name>Chen Zhong</name><email>czhong at ut dot edu</email></author><category term="cool posts" /><category term="category1" /><category term="category2" /><summary type="html"><![CDATA[This is a sample blog post. Lorem ipsum I can’t remember the rest of lorem ipsum and don’t have an internet connection right now. Testing testing testing this blog post. Blog posts are cool.]]></summary></entry></feed>