From the desk

Blog

Cybersecurity insights, the publishing journey, and whatever else won't leave us alone.

July 2026 · Cybersecurity

When the system that tells your firewalls what to trust gets hacked

Check Point's SmartConsole flaw gave attackers full admin control of firewall management. Five questions every board should ask about security infrastructure as attack surface.

Read more →

July 2026 · Cybersecurity

The Pentagon just hit pause on CMMC Phase II. That's not the good news you think it is.

The DoW suspended third-party cybersecurity assessments for defense contractors — but your NIST 800-171 obligations and False Claims Act liability haven't budged.

Read more →

July 2026 · Cybersecurity

The week AI went rogue: what the GPT-5.6 Sol breach means for every board in America

OpenAI's frontier models escaped a sandbox, exploited a zero-day, and hacked Hugging Face — all without human direction. Nine days later, Congress introduced a kill switch bill.

Read more →

July 2026 · Cybersecurity

The AI tool your developers love has a blind spot attackers already found

Researchers hid malicious instructions in a PNG that tricked AI coding assistants into stealing credentials — and neither human nor AI code reviewers caught it.

Read more →

July 2026 · Cybersecurity

A phone call breached a $200 billion healthcare giant — and your company could be next

Abbott Labs was compromised through voice phishing, not malware. With vishing now the #2 attack vector globally, every board needs to rethink the human side of cyber risk.

Read more →

July 2026 · Cybersecurity

When your trusted advisor gets breached

EY's breach through a third-party help-desk platform exposed client tax data. With record-breaking patch volumes in July, third-party risk is the primary way your data gets stolen.

Read more →

July 2026 · Cybersecurity

The regulatory net is closing: what's mandatory, what's voluntary, and what's coming for frontier AI

Gold Eagle, the EU AI Act's enforcement date, NIS2, and a new congressional AI bill all landed within weeks of each other — the regulatory tracks are converging and boards need to map their exposure now.

Read more →

July 2026 · Cybersecurity

The AI arms race inside your company

AI is defending your network, attacking it, and — through your own developers — quietly creating the vulnerabilities both sides exploit. Three fronts, one battlefield.

Read more →

July 2026 · Cybersecurity

After Mythos: why your cyber insurance policy may not cover what comes next

Insurers are racing to exclude AI-related claims just as Mythos-class AI threats accelerate. Your policy was almost certainly written before any of this existed.

Read more →

July 2026 · Cybersecurity

The encryption under your business has an expiration date

A June 2026 executive order puts a hard deadline on post-quantum cryptography. Why this compliance timeline is really a business-risk clock for every company.

Read more →

July 2026 · Cybersecurity

That ChatGPT invite from your CEO? It's a trap.

Attackers built a fake OpenAI workspace impersonating a CEO — and it passed every authentication check. What the "Poisoned Tenant" campaign means for AI governance.

Read more →

July 2026 · Cybersecurity

One web page was all it took: why your AI agents are your next breach

Microsoft's AutoJack exploit hijacked an AI agent with nothing but a web page. The architecture it exposed isn't unique — it's every agent your company is building right now.

Read more →

July 2026 · Cybersecurity

AI models are now ransomware targets

A new ransomware strain built specifically to destroy AI model files reveals a $75K–$500K-per-model recovery gap most organizations haven't planned for.

Read more →

July 2026 · Cybersecurity

The numbers just got worse: what the 2026 ransomware surge means for your board

Two new reports show ransomware disclosures and software supply chain attacks both hit record highs in 2026 — and the acceleration itself is the real warning sign.

Read more →

July 2026 · Cybersecurity

Microsoft just dropped 570 patches in a single day. Your board needs to know why.

Microsoft's AI bug-hunting system just tripled the size of Patch Tuesday. The volume of vulnerabilities is now a resourcing decision the board has to own.

Read more →

July 2026 · Cybersecurity

Your cybersecurity advisor just got breached. Now what?

Accenture, which sells cybersecurity to 92 of the Fortune 100, just had its own Azure DevOps credentials leaked. What that means for your third-party risk program.

Read more →

July 2026 · Cybersecurity

NACD raised the bar on board cyber oversight

The NACD's newest board-oversight handbook says passive cyber governance is no longer defensible — here's what separates boards that meet the bar from those that don't.

Read more →

July 2026 · Cybersecurity

When your auditor gets audited: the EY breach

EY took eleven days to notice attackers had already left a third-party help-desk platform — a case study in how routine vendor tools become the real attack surface.

Read more →

July 2026 · Cybersecurity

The patch was ready five weeks ago. Were you?

A critical Oracle Payments flaw was patched in May — and exploited five weeks later, before any public exploit existed. The board-level accountability gap it exposes.

Read more →

July 2026 · Cybersecurity

Your payment system just became a target

Oracle Payments went from patched to breached in six weeks. A look at why enterprise financial systems keep getting hit, and the questions boards should be asking.

Read more →

July 2026 · Cybersecurity

The DHS breach: "unclassified" doesn't mean unimportant

A DHS breach during World Cup security planning shows how "sensitive but unclassified" data creates real risk boards routinely underprotect.

Read more →

July 2026 · Cybersecurity

They found the breach in 24 hours. It took 115 days to tell anyone.

AssuranceAmerica caught the breach in 24 hours. It still took 115 days and nearly 7 million exposed people before anyone was told.

Read more →

July 2026 · Cybersecurity

Today's the deadline. Does your SharePoint team know it?

CISA gave federal agencies three days to patch an actively exploited SharePoint vulnerability — here's the compliance-versus-security gap it exposes.

Read more →

July 2026 · Cybersecurity

Your IT provider just handed attackers the keys to your kingdom

A maximum-severity flaw in a widely used remote management tool let attackers walk into managed networks undetected — and steal credentials for AI development tools along the way.

Read more →

July 2026 · Cybersecurity

When AI attacks AI: the Hugging Face breach and what every board needs to understand

An autonomous AI agent breached Hugging Face's production infrastructure over a weekend. The incident reveals a structural asymmetry between AI-powered attackers and defenders.

Read more →

July 2026 · Cybersecurity

When the negotiator works for the other side

A ransomware negotiator was secretly feeding clients' positions to BlackCat. The DOJ case is a wake-up call for how organizations vet crisis response vendors.

Read more →

July 2026 · Cybersecurity

The first ransomware attack run by a machine — and why your board should care

Sysdig documented an AI agent that ran a full ransomware operation end to end — recon, credential theft, lateral movement, encryption. The skill floor for attacks just dropped to the cost of an API call.

Read more →

July 2026 · Cybersecurity

When your shield becomes the sword: what the BlueHammer vulnerability means for your board

Microsoft Defender's BlueHammer flaw lets attackers hijack the cleanup process to gain SYSTEM access. 84 days after the patch, many organizations are still exposed.

Read more →

July 2026 · Cybersecurity

The AI executive order's "voluntary" framework: why your board can't afford to ignore it

The White House says participation is optional. But with classified benchmarks, trusted partner status, and new enforcement priorities, opting out has a price your board needs to understand.

Read more →

July 2026 · Cybersecurity

Your company has MFA. This week we learned that may not mean much.

81 million login attempts, 64 organizations breached — many had MFA deployed. The attacker used a legacy login path their policies never covered.

Read more →

July 2026 · Cybersecurity

The 25-day window your board doesn't know about

A critical Kemp LoadMaster vulnerability sat unpatched for 25 days before attackers struck. The question isn't about the CVE — it's whether your organization can close the window in time.

Read more →

June 2026 · Cybersecurity

The $100M question: who protects the software that protects you?

AI found 10,000+ critical vulnerabilities in open-source software in a single month. Only 14% got patched. The discovery-remediation gap is a board-level risk.

Read more →

June 2026 · Cybersecurity

A phone call, a face scan, and 26 million reasons to rethink AI surveillance

The MSG breach exposed facial recognition records on millions of visitors. The liability didn't start with the hack — it started when nobody asked why they were collecting the data.

Read more →

June 2026 · Cybersecurity

The world's top spy agencies just told you to fix your cybersecurity. Are you listening?

The Five Eyes alliance warned that AI will transform cyber threats in months, not years. Here's what boards and executives need to do right now.

Read more →

June 2026 · Cybersecurity

One phone call, 26 million records: what the Madison Square Garden breach means for every board

MSG was breached twice in under a year by two different threat actors. The common thread isn't a technical failure — it's a governance failure that starts in the boardroom.

Read more →

June 2026 · Cybersecurity

When your vendor's vendor gets hacked: the Klue breach and what it means for your board

An abandoned OAuth token at a competitive intelligence platform exposed CRM data at LastPass, HackerOne, Huntress, and eight other cybersecurity firms. The supply chain question boards aren't asking.

Read more →

June 2026 · Cybersecurity

They didn't lock the doors — they took the filing cabinets

ShinyHunters breached 100+ organizations through a single Oracle PeopleSoft zero-day. What the attack reveals about third-party software risk and board oversight.

Read more →

June 2026 · Cybersecurity

The 29-year-old bug leaking your credentials right now

Squidbleed has been silently leaking usernames, passwords, and session tokens from corporate networks since 1997. A case study in infrastructure blind spots.

Read more →

June 2026 · Cybersecurity

Your developers trusted a plugin. Attackers were counting on that.

15 malicious JetBrains plugins stole AI API keys from 70,000 developers for eight months. What boards need to know about supply chain risk.

Read more →

June 2026 · Cybersecurity

86,000 Firewalls, 194 Countries, and One Uncomfortable Question For Your Board

FortiBleed exposed admin credentials for 73,000+ firewalls worldwide. It wasn't a zero-day — it was a credential hygiene failure at civilizational scale.

Read more →

June 2026 · Cybersecurity

The Compliance Deadline Passed. Now What?

The SEC's Regulation S-P went fully live on June 3. If your board hasn't confirmed compliance, you're already behind.

Read more →

June 2026 · Cybersecurity

Your Board is Spending More on Cybersecurity. It's Getting Worse at It.

HBR research shows boards are paradoxically getting worse at cybersecurity governance even as they spend more. Compliance isn't security.

Read more →

June 2026 · Cybersecurity

Your CISO Isn't The One Who Should Be Worried. You Are.

CISOs are buying personal liability insurance. That's a red flag about your governance structure, not a problem for HR.

Read more →

June 2026 · Cybersecurity

Lost in Translation: Why Security Leaders Struggle to Get The Buy-In They've Earned

The gap between what security teams measure and what executives act on isn't a technical problem. It's a translation problem.

Read more →

June 2026 · Cybersecurity

The AI Executive Order Sounds Like Protection. It Isn't — Yet.

The White House's AI executive order establishes voluntary frameworks. But the threats it's responding to are already hitting companies right now.

Read more →

April 2026 · Cybersecurity

The Wild West of AI: Why Enterprises Need A Central Authority Before The Next Crisis Hits

AI cowboys are deploying models at breakneck speed without oversight. The risks are mounting.

Read more →

April 2026 · Cybersecurity

AI Risk in Healthcare: What Every Clinician and Business Leader Should Know

AI introduces new dimensions of risk that go beyond traditional IT concerns.

Read more →

More Posts on The Way

I'm still putting pen to paper on the first few pieces. Sign up below and I'll send a note when there's something worth reading.