<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/blog/rss.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Stellarbridge Blog</title>
    <link>https://stellarbridge.app/blog</link>
    <description>Insights and updates from the Stellarbridge team on secure file transfer, compliance, and enterprise data protection.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 28 Jun 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://stellarbridge.app/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>PTC Windchill RCE: Why PLM Systems Need Governed Engineering Data Movement</title>
      <link>https://stellarbridge.app/blog/ptc-windchill-rce-why-plm-systems-need-governed-engineering-data-movement</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/ptc-windchill-rce-why-plm-systems-need-governed-engineering-data-movement</guid>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Security</category>
      <category>Manufacturing</category>
      <category>Incident Analysis</category>
      <description><![CDATA[CVE-2026-12569 put PTC Windchill on CISA's KEV catalog with active web-shell exploitation — a reminder that PLM platforms are engineering data-movement infrastructure, not isolated back-office tools.]]></description>
    </item>
    <item>
      <title>Klue OAuth Breach: Why Third-Party Integrations Need Governed Data Paths</title>
      <link>https://stellarbridge.app/blog/klue-oauth-breach-why-third-party-integrations-need-governed-data-paths</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/klue-oauth-breach-why-third-party-integrations-need-governed-data-paths</guid>
      <pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Security</category>
      <category>Incident Analysis</category>
      <description><![CDATA[The Klue OAuth incident shows how stolen integration tokens turn middleware into ungoverned data-movement paths — a supply chain lesson for regulated vendor sharing.]]></description>
    </item>
    <item>
      <title>Flowise MCP RCE: Why AI Agent Tool Connectors Need Governed Boundaries</title>
      <link>https://stellarbridge.app/blog/flowise-mcp-rce-why-ai-agent-tool-connectors-need-governed-boundaries</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/flowise-mcp-rce-why-ai-agent-tool-connectors-need-governed-boundaries</guid>
      <pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Security</category>
      <category>AI Governance</category>
      <category>Incident Analysis</category>
      <description><![CDATA[CVE-2026-56274 exposed blocklist bypasses in Flowise's Custom MCP Server — a reminder that AI tool connectors are privileged data-movement surfaces, not configuration convenience.]]></description>
    </item>
    <item>
      <title>Copilot SearchLeak: Why Enterprise AI Needs Governed Data Access</title>
      <link>https://stellarbridge.app/blog/copilot-searchleak-why-enterprise-ai-needs-governed-data-access</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/copilot-searchleak-why-enterprise-ai-needs-governed-data-access</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Security</category>
      <category>AI Governance</category>
      <category>Incident Analysis</category>
      <description><![CDATA[CVE-2026-42824 patched a one-click Copilot exfiltration chain — but the deeper issue is AI inheriting user permissions without policy-bound authority over sensitive data movement.]]></description>
    </item>
    <item>
      <title>Archived Health Data and the Third-Party Storage Blind Spot</title>
      <link>https://stellarbridge.app/blog/archived-health-data-and-the-third-party-storage-blind-spot</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/archived-health-data-and-the-third-party-storage-blind-spot</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Compliance</category>
      <category>Incident Analysis</category>
      <description><![CDATA[The One Medical Seniors incident shows how archived PHI in third-party storage can sit outside production governance — and why regulated teams must govern every data resting place.]]></description>
    </item>
    <item>
      <title>Forms: A Standalone Primitive for Structured Intake</title>
      <link>https://stellarbridge.app/blog/forms-a-standalone-primitive-for-structured-intake</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/forms-a-standalone-primitive-for-structured-intake</guid>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Product</category>
      <description><![CDATA[Forms gives organizations a dedicated way to define, publish, and collect structured responses with versioned schemas, immutable submissions, and public share links.]]></description>
    </item>
    <item>
      <title>Platform Tags in Drive and Settings</title>
      <link>https://stellarbridge.app/blog/platform-tags-in-drive-and-settings</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/platform-tags-in-drive-and-settings</guid>
      <pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Product</category>
      <description><![CDATA[Platform tags give organizations a shared catalog in Settings and a direct way to assign and filter tags on Drive files and folders without turning labels into ad hoc metadata.]]></description>
    </item>
    <item>
      <title>Secure Viewer: Controlled Disclosure Without Shipping Files to the Browser</title>
      <link>https://stellarbridge.app/blog/secure-viewer-controlled-disclosure-without-shipping-files-to-the-browser</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/secure-viewer-controlled-disclosure-without-shipping-files-to-the-browser</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Product</category>
      <category>Security</category>
      <description><![CDATA[Secure Viewer renders sensitive documents in a short-lived, isolated environment and streams pixels to the dashboard—so the browser does not receive the underlying file for typical preview and local caching.]]></description>
    </item>
    <item>
      <title>File Requests with Stellarbridge</title>
      <link>https://stellarbridge.app/blog/file-requests-receiving-files-without-an-account</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/file-requests-receiving-files-without-an-account</guid>
      <pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Product</category>
      <description><![CDATA[A file request lets you create a link anyone can use to upload a file directly to you through Stellarbridge — no login, no account creation required on their end.]]></description>
    </item>
    <item>
      <title>SOC 2 Type I: What It Certifies, What It Doesn&apos;t, and Why the Distinction Matters</title>
      <link>https://stellarbridge.app/blog/soc2-type-i-what-it-certifies-what-it-doesnt-and-why-the-distinction-matters</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/soc2-type-i-what-it-certifies-what-it-doesnt-and-why-the-distinction-matters</guid>
      <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Compliance</category>
      <description><![CDATA[SOC 2 Type I tells you that a vendor's security controls were designed correctly at a specific point in time. It does not tell you whether those controls operated correctly for any sustained period—that is Type II's job.]]></description>
    </item>
    <item>
      <title>FedRAMP Authorization: What It Is and How It Shapes Cloud Architecture</title>
      <link>https://stellarbridge.app/blog/fedramp-authorization-what-it-is-and-how-it-shapes-cloud-architecture</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/fedramp-authorization-what-it-is-and-how-it-shapes-cloud-architecture</guid>
      <pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Compliance</category>
      <description><![CDATA[FedRAMP defines how cloud systems must be designed, documented, and operated to reduce federal risk exposure. It does not make a system inherently secure; security remains a property of system design.]]></description>
    </item>
    <item>
      <title>HIPAA Requirements for Secure File Transfer and Regulated Data Movement</title>
      <link>https://stellarbridge.app/blog/hipaa-requirements-for-secure-file-transfer-and-regulated-data-movement</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/hipaa-requirements-for-secure-file-transfer-and-regulated-data-movement</guid>
      <pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Compliance</category>
      <description><![CDATA[HIPAA compliance for PHI transfer depends on enforceable safeguards, least-privilege controls, and immutable audit artifacts across every data movement path.]]></description>
    </item>
    <item>
      <title>Why Security Tools Keep Multiplying and Why That&apos;s a Smell</title>
      <link>https://stellarbridge.app/blog/why-security-tools-keep-multiplying-and-why-thats-a-smell</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/why-security-tools-keep-multiplying-and-why-thats-a-smell</guid>
      <pubDate>Mon, 09 Feb 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge Team</author>
      <category>Security</category>
      <description><![CDATA[When cybersecurity tools keep multiplying, it usually signals architectural risk: organizations add controls faster than they remove attack-surface exposure.]]></description>
    </item>
    <item>
      <title>Secure File Transfer</title>
      <link>https://stellarbridge.app/blog/secure-file-transfer</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/secure-file-transfer</guid>
      <pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge Team</author>
      <category>Product</category>
      <category>Compliance</category>
      <description><![CDATA[Secure file transfer has become a business imperative, requiring encryption, compliance readiness, and audit-grade visibility for regulated data.]]></description>
    </item>
    <item>
      <title>Attack Surface Is an Architectural Property, Not a Runtime Problem</title>
      <link>https://stellarbridge.app/blog/attack-surface-is-an-architectural-property-not-a-runtime-problem</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/attack-surface-is-an-architectural-property-not-a-runtime-problem</guid>
      <pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate>
      <author>David Hoenisch</author>
      <category>Security</category>
      <description><![CDATA[Security is an architectural property achieved by subtraction, not a runtime problem solved by layering tools.]]></description>
    </item>
    <item>
      <title>The Scythe Framework</title>
      <link>https://stellarbridge.app/blog/the-scythe-framework</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/the-scythe-framework</guid>
      <pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate>
      <author>David Hoenisch</author>
      <category>Security</category>
      <description><![CDATA[Scythe is a Python-based framework for security, load, and workflow testing with expected-result semantics and detailed reporting.]]></description>
    </item>
    <item>
      <title>Attack Surface at StellarBridge</title>
      <link>https://stellarbridge.app/blog/attack-surface-at-stellarbridge</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/attack-surface-at-stellarbridge</guid>
      <pubDate>Wed, 28 Jan 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge Team</author>
      <category>Security</category>
      <description><![CDATA[Reducing attack surface by design means removing entire classes of exploits through restrictive, minimal deployment architecture.]]></description>
    </item>
    <item>
      <title>Adverse Conditions Testing with Scythe</title>
      <link>https://stellarbridge.app/blog/adverse-conditions-testing-with-scythe</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/adverse-conditions-testing-with-scythe</guid>
      <pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge</author>
      <category>Security</category>
      <description><![CDATA[Scythe evolved from TTP-focused testing into a framework for validating application behavior under adverse conditions in CI.]]></description>
    </item>
    <item>
      <title>Introducing Stellarbridge: Secure File Transfer at Scale</title>
      <link>https://stellarbridge.app/blog/introducing-stellarbridge</link>
      <guid isPermaLink="true">https://stellarbridge.app/blog/introducing-stellarbridge</guid>
      <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
      <author>Stellarbridge Team</author>
      <category>Product</category>
      <description><![CDATA[Stellarbridge is a secure, auditable file transfer platform built for regulated data, large files, and cross-organization workflows.]]></description>
    </item>
  </channel>
</rss>
