<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PatchVex — Security for Developers</title>
    <link>https://patchvex.com</link>
    <description>Security research, CVE breakdowns, and engineering articles from PatchVex.</description>
    <language>en-us</language>
    <managingEditor>hello@patchvex.com (PatchVex)</managingEditor>
    <webMaster>hello@patchvex.com (PatchVex)</webMaster>
    <lastBuildDate>Fri, 02 Oct 2026 21:28:56 GMT</lastBuildDate>
    <atom:link href="https://patchvex.com/feed" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://patchvex.com/og-default.png</url>
      <title>PatchVex</title>
      <link>https://patchvex.com</link>
    </image>
    <item>
      <title>DPDP Act vs DPDP Rules: What Changed and What Developers Need to Know</title>
      <link>https://patchvex.com/blog/dpdp-act-vs-dpdp-rules</link>
      <guid isPermaLink="true">https://patchvex.com/blog/dpdp-act-vs-dpdp-rules</guid>
      <description>The Digital Personal Data Protection Act, 2023 is the law. The Digital Personal Data Protection Rules, 2025 tell you how to actually implement it. Here&#39;s the difference, the real enforcement timeline, and what it means for engineering teams.</description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>DPDP</category><category>India</category><category>Data Protection</category><category>Compliance</category><category>Privacy</category>
    </item>
    <item>
      <title>How to Find Personal Data in Your Codebase</title>
      <link>https://patchvex.com/blog/how-to-find-pii-in-your-codebase</link>
      <guid isPermaLink="true">https://patchvex.com/blog/how-to-find-pii-in-your-codebase</guid>
      <description>You can&#39;t secure or govern personal data you don&#39;t know you have. A practical guide to finding email addresses, phone numbers, ID numbers, and embedded credentials hiding in your source code and config — before a compliance deadline or a breach forces the question.</description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>PII Detection</category><category>Data Discovery</category><category>Privacy</category><category>DPDP</category><category>Secrets Detection</category>
    </item>
    <item>
      <title>Privacy-as-Code: What It Means and Why Developers Need It</title>
      <link>https://patchvex.com/blog/privacy-as-code-explained</link>
      <guid isPermaLink="true">https://patchvex.com/blog/privacy-as-code-explained</guid>
      <description>Privacy policy as a deterministic, version-controlled check that runs in CI — not a questionnaire, not a quarterly audit. What Privacy-as-Code actually is, what it can and can&#39;t verify, and why that honesty matters.</description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>Privacy-as-Code</category><category>Privacy</category><category>DPDP</category><category>CI/CD</category><category>PII Detection</category>
    </item>
    <item>
      <title>CVSS vs EPSS vs CISA KEV: A Practical Comparison</title>
      <link>https://patchvex.com/blog/cvss-vs-epss-vs-cisa-kev</link>
      <guid isPermaLink="true">https://patchvex.com/blog/cvss-vs-epss-vs-cisa-kev</guid>
      <description>Three vulnerability signals, three different questions. A practical guide to what CVSS, EPSS, and CISA KEV each measure, how they disagree, and how to combine them into a real prioritization workflow.</description>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>CVSS</category><category>EPSS</category><category>CISA KEV</category><category>Vulnerability Management</category><category>VulnPilot</category><category>Vulnerability Prioritization</category>
    </item>
    <item>
      <title>What Is CISA KEV and Why Does It Matter?</title>
      <link>https://patchvex.com/blog/what-is-cisa-kev</link>
      <guid isPermaLink="true">https://patchvex.com/blog/what-is-cisa-kev</guid>
      <description>CISA&#39;s Known Exploited Vulnerabilities catalog tracks CVEs with confirmed active exploitation. Here&#39;s what it is, why it&#39;s the strongest remediation signal available, and how to use it alongside CVSS.</description>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>CISA KEV</category><category>CVSS</category><category>Vulnerability Management</category><category>VulnPilot</category>
    </item>
    <item>
      <title>What Is an EPSS Score? A Plain-English Explanation</title>
      <link>https://patchvex.com/blog/what-is-epss-score</link>
      <guid isPermaLink="true">https://patchvex.com/blog/what-is-epss-score</guid>
      <description>EPSS predicts the probability a CVE will be exploited in the next 30 days. Here&#39;s what the score actually represents, how it differs from CVSS, its limitations, and how to use it in prioritization.</description>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>EPSS</category><category>CVSS</category><category>CISA KEV</category><category>Vulnerability Management</category><category>VulnPilot</category>
    </item>
    <item>
      <title>Security Checks Every AI-Built App Needs Before Launch</title>
      <link>https://patchvex.com/blog/security-checks-for-ai-built-apps</link>
      <guid isPermaLink="true">https://patchvex.com/blog/security-checks-for-ai-built-apps</guid>
      <description>LLMs write functional code fast. They also reproduce the same security gaps consistently. Here&#39;s what to check before you ship an app built with Cursor, Claude, or Copilot.</description>
      <pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>AI Coding</category><category>Cursor</category><category>Claude Code</category><category>Security Headers</category><category>API Keys</category><category>Launch Checklist</category>
    </item>
    <item>
      <title>Why CVSS Alone Is Not Enough to Prioritize Vulnerabilities</title>
      <link>https://patchvex.com/blog/why-cvss-alone-is-not-enough</link>
      <guid isPermaLink="true">https://patchvex.com/blog/why-cvss-alone-is-not-enough</guid>
      <description>CVSS scores severity if exploited — not whether anyone is. Here&#39;s how CISA KEV and EPSS close that gap, with a practical composite scoring model.</description>
      <pubDate>Sat, 15 Nov 2025 00:00:00 GMT</pubDate>
      <author>PatchVex Engineering</author>
      <category>CVSS</category><category>EPSS</category><category>CISA KEV</category><category>Vulnerability Management</category><category>VulnPilot</category>
    </item>
  </channel>
</rss>