<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>lwst.io</title>
    <link>https://lwst.io/en/</link>
    <description>Recent content on lwst.io</description>
    <image>
      <title>lwst.io</title>
      <url>https://lwst.io/images/profile-crop.jpg</url>
      <link>https://lwst.io/images/profile-crop.jpg</link>
    </image>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sun, 26 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://lwst.io/en/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Device Code Phishing: Why Even Passkeys Won&#39;t Save Your Microsoft Tenant</title>
      <link>https://lwst.io/en/posts/microsoft-entra-device-code-phishing/</link>
      <pubDate>Sun, 26 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://lwst.io/en/posts/microsoft-entra-device-code-phishing/</guid>
      <description>A phishing wave against Microsoft 365 bypasses MFA and even phishing-resistant passkeys without faking a single pixel of Microsoft. What attackers do, why it works, and the conditional access policy that stops it.</description>
    </item>
    <item>
      <title>Eleven Characters, No Authentication</title>
      <link>https://lwst.io/en/posts/sms-phishing-alphanumeric-senderids/</link>
      <pubDate>Sun, 26 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://lwst.io/en/posts/sms-phishing-alphanumeric-senderids/</guid>
      <description>An SMS lands in the real Trade Republic chat — and costs a 63-year-old his retirement savings. What makes alphanumeric sender IDs so phishable, and why the UK and Singapore are ahead of Germany.</description>
    </item>
    <item>
      <title>Hello World</title>
      <link>https://lwst.io/en/posts/hallo-welt/</link>
      <pubDate>Sat, 25 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://lwst.io/en/posts/hallo-welt/</guid>
      <description>The first post on lwst.io — what this blog is and who&amp;#39;s behind it. No marketing language, no tool reviews — just notes from working in the field and studying.</description>
    </item>
    <item>
      <title>About</title>
      <link>https://lwst.io/en/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://lwst.io/en/about/</guid>
      <description>About David Leeuwestein</description>
    </item>
    <item>
      <title>Imprint</title>
      <link>https://lwst.io/en/imprint/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://lwst.io/en/imprint/</guid>
      <description>&lt;p&gt;Information according to § 5 TMG (German Telemedia Act):&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;David Leeuwestein&lt;/strong&gt;&lt;br&gt;
c/o Block Services&lt;br&gt;
Stuttgarter Str. 106&lt;br&gt;
70736 Fellbach&lt;br&gt;
Germany&lt;/p&gt;
&lt;h2 id=&#34;contact&#34;&gt;Contact&lt;/h2&gt;
&lt;p&gt;Email: &lt;a href=&#34;mailto:blog@lwst.io&#34;&gt;blog@lwst.io&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&#34;responsible-for-the-content-according-to--18-2-mstv&#34;&gt;Responsible for the content according to § 18 (2) MStV&lt;/h2&gt;
&lt;p&gt;David Leeuwestein&lt;br&gt;
c/o Block Services&lt;br&gt;
Stuttgarter Str. 106&lt;br&gt;
70736 Fellbach&lt;br&gt;
Germany&lt;/p&gt;
&lt;h2 id=&#34;liability-for-content&#34;&gt;Liability for content&lt;/h2&gt;
&lt;p&gt;The contents of these pages have been created with the utmost care. However, no guarantee can be given for the accuracy, completeness, or timeliness of the content. As a service provider, I am responsible for my own content on these pages in accordance with general laws under § 7 (1) TMG. According to §§ 8 to 10 TMG, however, I am not obligated as a service provider to monitor transmitted or stored third-party information or to investigate circumstances that indicate illegal activity. Obligations to remove or block the use of information under general laws remain unaffected. Liability in this respect is only possible from the time at which a specific legal violation becomes known. Should I become aware of any such violations, I will remove the relevant content without delay.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Privacy Policy</title>
      <link>https://lwst.io/en/privacy/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://lwst.io/en/privacy/</guid>
      <description>&lt;h2 id=&#34;data-controller&#34;&gt;Data controller&lt;/h2&gt;
&lt;p&gt;The controller within the meaning of the General Data Protection Regulation (GDPR) is:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;David Leeuwestein&lt;/strong&gt;&lt;br&gt;
c/o Block Services&lt;br&gt;
Stuttgarter Str. 106&lt;br&gt;
70736 Fellbach&lt;br&gt;
Germany&lt;br&gt;
Email: &lt;a href=&#34;mailto:blog@lwst.io&#34;&gt;blog@lwst.io&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&#34;overview&#34;&gt;Overview&lt;/h2&gt;
&lt;p&gt;This site processes personal data only to the extent technically necessary to operate the offering. There is &lt;strong&gt;no tracking&lt;/strong&gt;, no advertising, no analytics cookies, and no newsletter sign-up.&lt;/p&gt;
&lt;h2 id=&#34;hosting-and-connection-data&#34;&gt;Hosting and connection data&lt;/h2&gt;
&lt;p&gt;This site is hosted on &lt;strong&gt;Cloudflare Pages&lt;/strong&gt;, a service of &lt;strong&gt;Cloudflare, Inc.&lt;/strong&gt;, 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare operates a global content-delivery network and handles delivery of this site&amp;rsquo;s content as well as protection against abusive use (e.g. DDoS attacks).&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
