<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Threat-Intelligence on MEISTSEC</title><link>https://44e06765.meistsec-blog.pages.dev/tags/threat-intelligence/</link><description>Recent content in Threat-Intelligence on MEISTSEC</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://44e06765.meistsec-blog.pages.dev/tags/threat-intelligence/index.xml" rel="self" type="application/rss+xml"/><item><title>Read the Lease: From a Firewall Log to a Twelve-Membership LIR Farm</title><link>https://44e06765.meistsec-blog.pages.dev/posts/lease/</link><pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/lease/</guid><description>Eleven IPs scanned my WAN. My firewall said Iran, but the servers were in Amsterdam. Following the address space led to twelve RIPE LIR memberships sharing one company registration number, while several of my own threat-hunting heuristics failed along the way.</description></item></channel></rss>