<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Security at Depth</title><description>Security leadership grounded in engineering.</description><link>https://securityatdepth.com/</link><item><title>EPSS v5 Changed the Queue Without Changing the Integration</title><link>https://securityatdepth.com/epss-v5-transition/</link><guid isPermaLink="true">https://securityatdepth.com/epss-v5-transition/</guid><description>EPSS v5 arrived through the same interface, but its new score distribution could materially alter vulnerability queues, thresholds, capacity assumptions, and executive reporting.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/epss-v5-transition.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>EPSS v5 Changed the Queue Without Changing the Integration</media:title></media:content><category>Govern &amp; Invest</category><category>Perspective</category><category>Vulnerability Management</category><category>EPSS</category><category>Model Risk</category><category>Governance</category><category>Leadership</category></item><item><title>A Backup That Depends on n8n Is Not an Independent Control</title><link>https://securityatdepth.com/n8n-backup-with-ansible/</link><guid isPermaLink="true">https://securityatdepth.com/n8n-backup-with-ansible/</guid><description>After an update damaged both automation workflows and their internal backup path, I moved exports outside n8n. The failure exposed gaps in separation, secret handling, and restore testing.</description><pubDate>Mon, 28 Jul 2025 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/n8n-backup-with-ansible.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>A Backup That Depends on n8n Is Not an Independent Control</media:title></media:content><category>Resilience &amp; Recovery</category><category>Operating Retrospective</category><category>Automation</category><category>n8n</category><category>Ansible</category><category>Backup</category><category>Recovery</category></item><item><title>What Executives Should Demand from Vulnerability Prioritization</title><link>https://securityatdepth.com/what-executives-should-demand-from-vulnerability-prioritization/</link><guid isPermaLink="true">https://securityatdepth.com/what-executives-should-demand-from-vulnerability-prioritization/</guid><description>A credible program must explain why an exposure matters, who owns the response, what uncertainty remains, and whether the decision reduced material risk.</description><pubDate>Wed, 02 Apr 2025 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/what-executives-should-demand-from-vulnerability-prioritization.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>What Executives Should Demand from Vulnerability Prioritization</media:title></media:content><category>Govern &amp; Invest</category><category>Executive Brief</category><category>Vulnerability Management</category><category>Risk</category><category>Leadership</category><category>Control Effectiveness</category><category>Governance</category></item><item><title>Operationalizing EPSS Without Turning Probability into Policy by Accident</title><link>https://securityatdepth.com/leveraging-epss-in-practice/</link><guid isPermaLink="true">https://securityatdepth.com/leveraging-epss-in-practice/</guid><description>EPSS becomes useful when thresholds reflect risk appetite, remediation capacity, and business context—and when the program measures what those thresholds actually capture.</description><pubDate>Thu, 20 Mar 2025 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/leveraging-epss-in-practice.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Operationalizing EPSS Without Turning Probability into Policy by Accident</media:title></media:content><category>Defend &amp; Detect</category><category>Perspective</category><category>Vulnerability Management</category><category>EPSS</category><category>CVSS</category><category>KEV</category><category>Risk</category></item><item><title>EPSS v4 Changed the Scores. The Leadership Lesson Was Model Governance</title><link>https://securityatdepth.com/diving-deep-into-epssv4-whats-new-and-why-it-matters-for-your-vulnerability-management/</link><guid isPermaLink="true">https://securityatdepth.com/diving-deep-into-epssv4-whats-new-and-why-it-matters-for-your-vulnerability-management/</guid><description>When a risk model changes, the operational question is not whether the new numbers look better. It is whether your thresholds, workflows, and executive reporting still mean what you think they mean.</description><pubDate>Wed, 19 Mar 2025 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/diving-deep-into-epssv4-whats-new-and-why-it-matters-for-your-vulnerability-management.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>EPSS v4 Changed the Scores. The Leadership Lesson Was Model Governance</media:title></media:content><category>Govern &amp; Invest</category><category>Perspective</category><category>Vulnerability Management</category><category>EPSS</category><category>Model Risk</category><category>Governance</category><category>Leadership</category></item><item><title>Vulnerability Management Is a Decision System, Not a Patch Queue</title><link>https://securityatdepth.com/stop-playing-whack-a-mole-with-vulnerabilities/</link><guid isPermaLink="true">https://securityatdepth.com/stop-playing-whack-a-mole-with-vulnerabilities/</guid><description>CVSS can describe severity, EPSS can estimate exploitation likelihood, and SSVC can structure response. Leadership still has to connect those signals to business exposure and accountable action.</description><pubDate>Sat, 15 Feb 2025 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/stop-playing-whack-a-mole-with-vulnerabilities.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Vulnerability Management Is a Decision System, Not a Patch Queue</media:title></media:content><category>Govern &amp; Invest</category><category>Perspective</category><category>Vulnerability Management</category><category>EPSS</category><category>SSVC</category><category>Risk</category><category>Leadership</category></item><item><title>Local AI on Proxmox: The Security Tradeoffs Behind GPU-Enabled LXC</title><link>https://securityatdepth.com/proxmox-lxc-ai/</link><guid isPermaLink="true">https://securityatdepth.com/proxmox-lxc-ai/</guid><description>GPU passthrough can turn older hardware into a capable local-AI environment. The useful design question is what efficiency, isolation, and operational risk you are willing to trade.</description><pubDate>Mon, 03 Feb 2025 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/proxmox-lxc-ai.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Local AI on Proxmox: The Security Tradeoffs Behind GPU-Enabled LXC</media:title></media:content><category>Architect &amp; Build</category><category>Implementation Guide</category><category>AI</category><category>Proxmox</category><category>Containers</category><category>NVIDIA</category><category>Security Architecture</category></item><item><title>Upgrading AWX on MicroK8s Without Treating the Operator as a Rollback Plan</title><link>https://securityatdepth.com/upgrade-awx-microk8s-ubuntu/</link><guid isPermaLink="true">https://securityatdepth.com/upgrade-awx-microk8s-ubuntu/</guid><description>An operator can automate an AWX upgrade, but it cannot decide whether your backups, capacity, compatibility, and recovery path are good enough.</description><pubDate>Sat, 08 Apr 2023 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/upgrade-awx-microk8s-ubuntu.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Upgrading AWX on MicroK8s Without Treating the Operator as a Rollback Plan</media:title></media:content><category>Resilience &amp; Recovery</category><category>Implementation Guide</category><category>AWX</category><category>Kubernetes</category><category>Automation</category><category>Reliability</category><category>Recovery</category></item><item><title>Running AWX on MicroK8s: What a Small Automation Platform Still Requires</title><link>https://securityatdepth.com/linux-awx-microk8s-ubuntu/</link><guid isPermaLink="true">https://securityatdepth.com/linux-awx-microk8s-ubuntu/</guid><description>A lab-sized AWX deployment is easy to start and surprisingly instructive to operate. The important work begins with state, access, upgrades, and recovery.</description><pubDate>Fri, 07 Apr 2023 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/linux-awx-microk8s-ubuntu.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Running AWX on MicroK8s: What a Small Automation Platform Still Requires</media:title></media:content><category>Architect &amp; Build</category><category>Implementation Guide</category><category>AWX</category><category>Ansible</category><category>Kubernetes</category><category>Automation</category><category>Security Architecture</category></item><item><title>Patching Standalone ESXi: A Lab Runbook Built Around Recovery</title><link>https://securityatdepth.com/how-to-esxi-update/</link><guid isPermaLink="true">https://securityatdepth.com/how-to-esxi-update/</guid><description>The ESXi command is the smallest part of a safe update. Maintenance mode, rollback planning, compatibility review, and post-change evidence are the real controls.</description><pubDate>Mon, 27 Sep 2021 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/how-to-esxi-update.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Patching Standalone ESXi: A Lab Runbook Built Around Recovery</media:title></media:content><category>Resilience &amp; Recovery</category><category>Implementation Guide</category><category>VMware</category><category>ESXi</category><category>Patching</category><category>Recovery</category><category>Infrastructure</category></item><item><title>Recovering Ubuntu Boot Space Without Removing Your Recovery Path</title><link>https://securityatdepth.com/linux-uninstall-kernel/</link><guid isPermaLink="true">https://securityatdepth.com/linux-uninstall-kernel/</guid><description>Old kernels can fill a small boot volume, but cleanup should preserve a known-good fallback and use the package manager’s own dependency decisions.</description><pubDate>Mon, 27 Sep 2021 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/linux-uninstall-kernel.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Recovering Ubuntu Boot Space Without Removing Your Recovery Path</media:title></media:content><category>Resilience &amp; Recovery</category><category>Implementation Guide</category><category>Linux</category><category>Ubuntu</category><category>Operations</category><category>Reliability</category><category>Recovery</category></item><item><title>Random Passwords from the Shell: A Small Tool with Security Boundaries</title><link>https://securityatdepth.com/bash-randompass/</link><guid isPermaLink="true">https://securityatdepth.com/bash-randompass/</guid><description>A secure random string is useful in a lab, but generation is only one part of credential security. Here is a practical shell pattern and the limits that matter.</description><pubDate>Mon, 22 Apr 2019 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/bash-randompass.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Random Passwords from the Shell: A Small Tool with Security Boundaries</media:title></media:content><category>Architect &amp; Build</category><category>Field Note</category><category>Linux</category><category>Bash</category><category>Shell</category><category>Password Security</category></item><item><title>Bash History Is Operational Memory—and Sometimes Sensitive Data</title><link>https://securityatdepth.com/how-to-bash-history/</link><guid isPermaLink="true">https://securityatdepth.com/how-to-bash-history/</guid><description>A cleaner shell history improves retrieval, but the more important design question is what should be retained, synchronized, or removed in the first place.</description><pubDate>Mon, 22 Apr 2019 00:00:00 GMT</pubDate><media:content url="https://securityatdepth.com/generated/social/how-to-bash-history.jpg" type="image/jpeg" medium="image" width="1200" height="630"><media:title>Bash History Is Operational Memory—and Sometimes Sensitive Data</media:title></media:content><category>Defend &amp; Detect</category><category>Field Note</category><category>Linux</category><category>Bash</category><category>Shell</category><category>Operations</category></item></channel></rss>