<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Brickell Technologies — Research Notes</title><description>Vulnerability research, patch verification and offensive security notes from a Miami security firm.</description><link>https://brickell-tech.com</link><language>en-us</language><item><title>Does SOC 2 require a penetration test?</title><link>https://brickell-tech.com/blog/does-soc-2-require-a-penetration-test</link><guid isPermaLink="true">https://brickell-tech.com/blog/does-soc-2-require-a-penetration-test</guid><description>The honest answer is no, and it does not help you much, because the reason people ask is usually a customer contract rather than the framework.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>SOC 2</category><category>compliance</category><category>penetration testing</category><author>Elias Hasas</author></item><item><title>How much does a penetration test cost?</title><link>https://brickell-tech.com/blog/how-much-does-a-penetration-test-cost</link><guid isPermaLink="true">https://brickell-tech.com/blog/how-much-does-a-penetration-test-cost</guid><description>Every vendor dodges this question. The reason is real, but you can still work out roughly what you should be paying, and spot a quote that is wrong.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>penetration testing</category><category>buying security</category><category>pricing</category><author>Elias Hasas</author></item><item><title>The gzip patch that fixed the crash and left the bug</title><link>https://brickell-tech.com/blog/gzip-incomplete-patch-cve-2026-41992</link><guid isPermaLink="true">https://brickell-tech.com/blog/gzip-incomplete-patch-cve-2026-41992</guid><description>In July we reported that the official fix for CVE-2026-41992 left the bug reachable. Upstream shipped a better one the same day. Here is what that says about trusting patches.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>vulnerability research</category><category>patch verification</category><category>CVE-2026-41992</category><category>gzip</category><author>Elias Hasas</author></item></channel></rss>