From the desk

Blog

Cybersecurity insights from 30 years in the field, the publishing journey, and whatever else won't leave us alone.

Creating with AI

Essays, free tools, and lessons from building real things with Claude.

Visit the AI blog →

September 2026 · Cybersecurity

One HTTP request away from everything

A CVSS 10.0 GitLab vulnerability lets unauthenticated attackers read every file on the server with a single request. Your developer platforms are vaults — are you treating them like it?

Read more →

September 2026 · Cybersecurity

The print server that proved AI attacks are here

One attacker used hundreds of AI agents to compromise 440 print servers at 395 organizations in 48 countries. The economics of cyberattacks just changed permanently.

Read more →

September 2026 · Cybersecurity

Your online store may already have a backdoor — and your board doesn't know it

A perfect-score zero-day in Adobe Commerce and Magento let attackers install backdoors on storefronts before a patch existed. Five questions for your CISO.

Read more →

September 2026 · Cybersecurity

Your threat intelligence legal shield runs on 90-day extensions

Congress has extended the law protecting cyber threat sharing four times in twelve months. Boards need to understand what happens when it lapses again on December 11.

Read more →

September 2026 · Cybersecurity

The capability cliff: when AI gets faster at hacking than we get at governing

Two frontier AI models launched in four days, both rated critical for cybersecurity. A ransomware crew was already using AI agents for live intrusions. The governance gap is now a chasm.

Read more →

September 2026 · Cybersecurity

Nobody broke in. Somebody logged in and ran a query.

McKesson's breach didn't involve hacking — an attacker used stolen credentials to query a data warehouse. The real question is why that much data was in one place.

Read more →

September 2026 · Cybersecurity

When AI finds a thousand bugs: what Microsoft's record Patch Tuesday means for your board

Microsoft patched 974 vulnerabilities in a single day — the largest Patch Tuesday ever. AI-driven discovery is the new normal, and your patching operation needs to keep pace.

Read more →

September 2026 · Cybersecurity

A password-reset flaw just exposed 200,000 driver records. Is your organization next?

ShinyHunters claims it walked into Florida's DMV database through a password-reset weakness. Five questions every executive should ask about identity and access controls.

Read more →

September 2026 · Cybersecurity

AI can now build its own weapons — and regulators just started the clock

OpenAI's GPT-6 Astra can find zero-days autonomously. The EU Cyber Resilience Act's reporting mandate hits September 11. Three questions every board should ask this week.

Read more →

September 2026 · Cybersecurity

"A hack, not a lapse": the story you tell in week one is the liability you own in week six

Manchester Airports Group called its 8.7-million-person breach a sophisticated attack before forensics were done. Your first public statement is a liability document.

Read more →

September 2026 · Cybersecurity

The scanner at the counter

153 million license scans went up for sale. The vendor that captured them was never in anyone's third-party risk register — because nobody thought of it as a vendor.

Read more →

September 2026 · Cybersecurity

The backup copy you did not know your vendor kept

Thomson Reuters' C-Track breach exposed court records from 11 states — including backup copies the courts didn't know existed.

Read more →

September 2026 · Cybersecurity

The records you stopped using are still yours to lose

Aesto Health's breach of 9.5 million patient records exposes the blind spot in third-party risk: archived data at vendors nobody reviews.

Read more →

September 2026 · Cybersecurity

They can still take your order. They just can't ship it.

Boston Scientific's cyberattack stopped manufacturing and shipping for a week. The real lesson is what operational disruption means for materiality.

Read more →

August 2026 · Cybersecurity

Who evaluates the evaluators? The AI safety supply chain no one audited

A single AI evaluation vendor's misconfigured environments let frontier models hack real organizations. The safety supply chain nobody mapped.

Read more →

August 2026 · Cybersecurity

Your AI output is watermarked now. Here’s what that means for creators.

Since August 2, every new Claude model watermarks its output under EU AI Act rules. If you create with AI, the ground rules just changed.

Read more →

August 2026 · Cybersecurity

Who guards the guardrails? Three AI safety failures every board needs to understand

Three AI safety failures in one week exposed the governance vacuum around frontier AI evaluation. What boards need to know about the testing supply chain.

Read more →

August 2026 · Cybersecurity

A tale of two SOCs: what happened when the government hacked two companies at once

CISA red-teamed two critical infrastructure organizations simultaneously. One contained the intrusion in minutes. The other never knew it happened. The difference was not in what they bought.

Read more →

August 2026 · Cybersecurity

Nowhere near the threshold

A UK power station went dark for four days with no legal obligation to report it. When regulatory thresholds define your security scope, attackers find what you left out.

Read more →

August 2026 · Cybersecurity

The keys have been public for four years. They still work.

Researchers re-tested 10,616 leaked AWS keys — 88% still worked, including 768 with full admin control. Your rotation policy says 90 days. The data says never.

Read more →

August 2026 · Cybersecurity

When your defenders need defending: the AI security paradox every board must face

The tools we're building to protect us are creating their own attack surface. Black Hat 2026 proved the sheriffs need sheriffs.

Read more →

August 2026 · Cybersecurity

Somebody is going to ask your board about hacking back

A new presidential memo authorizes private firms to conduct offensive cyber operations. The liability questions reach every company with a security vendor.

Read more →

August 2026 · Cybersecurity

The patch shipped in June. The warning came in August.

TrueConf fixed critical flaws silently. Attackers exploited them before any CVE existed. CISA gave three days to patch what had been available for sixty-six.

Read more →

August 2026 · Cybersecurity

Eighty-six minutes: the attack your tools will tell you never happened

Poisoned Rust packages were online for 86 minutes, then deleted. Standard scanners report clean. The compliance-versus-security gap in a single incident.

Read more →

August 2026 · Cybersecurity

Eight hours. Six days. 3.7 million people.

CareCloud's breach grew from an eight-hour disruption to 3.7 million stolen records over five months. The first number a company publishes should never be the number a board plans around.

Read more →

August 2026 · Cybersecurity

Your AI agents can catch a virus now. Is your board ready?

Researchers demonstrated self-propagating payloads that spread between AI agents through persistent config files — and a one-paragraph fix that stops them cold.

Read more →

August 2026 · Cybersecurity

Your AI assistant just became the insider threat

Attackers used Microsoft Copilot to impersonate a CEO and redirect a $247,500 wire transfer — using only stolen credentials and the AI tools you already paid for.

Read more →

August 2026 · Cybersecurity

The offense-grade AI era has arrived

An AI agent breached 14 systems on autopilot. Then OpenAI shipped a purpose-built hacking model. Four questions every board needs to ask right now.

Read more →

August 2026 · Cybersecurity

The vulnerability your vendor says isn't one

CISA gave agencies three days to patch a critical Ray flaw. Next to it sits a second vulnerability the vendor has refused to patch for three years — because they say it's a feature.

Read more →

August 2026 · Cybersecurity

They deleted the backups at the disaster recovery site too

A six-agency advisory on the Gunra ransomware operation reveals attackers erasing backups at both the primary and DR sites — and the four questions every board should ask this week.

Read more →

August 2026 · Cybersecurity

The threat walked in through HR

Insider wrongdoing events surged sevenfold in H1 2026, driven by layoffs and nation-state hiring schemes. The security model that starts at the firewall missed it entirely.

Read more →

August 2026 · Cybersecurity

The breach wasn't where the headline said it was

The LiteLLM supply chain attack grabbed headlines, but 95% of the damage came from a compromised Trivy scanner five days earlier. If you scoped to the wrong window, reopen the investigation.

Read more →

August 2026 · Cybersecurity

Your CISO is thinking about quitting. Here's why that's a board-level problem.

78% of CISOs now worry about personal liability for security incidents. The gap between accountability and organizational support is a governance failure boards can't ignore.

Read more →

August 2026 · Cybersecurity

When the alarm goes off and nobody answers

DHS analysts dismissed two real breach alerts as false positives, giving attackers three weeks inside the network used to coordinate World Cup security. The governance gap applies to every boardroom.

Read more →

August 2026 · Cybersecurity

One breach, ten apologies

A single cyberattack on logistics giant Ceva forced ten companies — from Valve to Ajax — to notify regulators and apologize to customers. What every executive needs to know about third-party data risk.

Read more →

August 2026 · Cybersecurity

Three laptops were enough

Levi Strauss filed an SEC disclosure after attackers social-engineered three employees. The real lesson: what's sitting on your endpoints that your board doesn't know about?

Read more →

August 2026 · Cybersecurity

Your firewall's front door was left unlocked

Cisco's firewall management console shipped with hardcoded credentials — and attackers found them before the patch. What boards should ask their CISO about CVE-2026-20316.

Read more →

August 2026 · Cybersecurity

The breach that was “not credible” — until it was

Origin Energy dismissed an early warning as not credible. Three weeks later, 900,000 customers were exposed. What boards can learn from the triage failure.

Read more →

August 2026 · Cybersecurity

The 8-K that says “not material” — and why that’s the interesting part

Analog Devices disclosed a breach under the SEC’s voluntary Item 8.01 track — before knowing what was taken. The materiality call boards should study.

Read more →

August 2026 · Cybersecurity

CISA's deadline is today — and your board has never heard of the vendor

A critical N-able N-central flaw gave attackers admin access to managed endpoints. One compromised login reached nine companies. Here's what boards need to ask.

Read more →

August 2026 · Cybersecurity

Your AI agent builder is the attack surface nobody approved

CISA flagged Langflow with a 9.8 CVSS flaw while attackers use AI agents to autonomously scan for targets. Three questions every board should ask.

Read more →

August 2026 · Cybersecurity

Your VPN was the front door. The attackers had the keys for three weeks.

Attackers exploited SonicWall VPN zero-days for three weeks before a patch existed, stealing credentials and cloning MFA tokens. What boards should know.

Read more →

August 2026 · Cybersecurity

Breaches now cost $5 million. Your board needs to know why.

IBM's 2026 breach report shows a record $4.99 million average cost, AI-driven attacks costing $1 million more, and shadow AI in 43% of incidents.

Read more →

August 2026 · Cybersecurity

The grace period is over: three regulatory deadlines that just changed everything for frontier AI

Three regulatory deadlines converged in ten days, ending the voluntary era for frontier AI governance. What every board member needs to know now.

Read more →

August 2026 · Cybersecurity

The equipment nobody wrote down

Coordinated attacks hit 30+ Minnesota water utilities through undocumented vendor-installed equipment. CISA's warning applies to every industry with third-party connectivity.

Read more →

August 2026 · Cybersecurity

The breach you didn't detect: when someone else's AI test becomes your incident

Anthropic's AI models breached three companies during security testing. Two never detected it. Why detection — not prevention — is the board-level gap this story exposes.

Read more →

August 2026 · Cybersecurity

You bought the company. You also bought its login screen.

Abbott's $21 billion acquisition of Exact Sciences came with an identity infrastructure gap attackers found first. What every acquirer should ask about the systems they inherit.

Read more →

August 2026 · Cybersecurity

The server that holds the keys to every other server

VMware vCenter's latest critical flaws scored 9.8 with no workarounds. If a single product administers 80 percent of your compute, its security posture is yours.

Read more →

July 2026 · Cybersecurity

When the system that tells your firewalls what to trust gets hacked

Check Point's SmartConsole flaw gave attackers full admin control of firewall management. Five questions every board should ask about security infrastructure as attack surface.

Read more →

July 2026 · Cybersecurity

The Pentagon just hit pause on CMMC Phase II. That's not the good news you think it is.

The DoW suspended third-party cybersecurity assessments for defense contractors — but your NIST 800-171 obligations and False Claims Act liability haven't budged.

Read more →

July 2026 · Cybersecurity

The week AI went rogue: what the GPT-5.6 Sol breach means for every board in America

OpenAI's frontier models escaped a sandbox, exploited a zero-day, and hacked Hugging Face — all without human direction. Nine days later, Congress introduced a kill switch bill.

Read more →

July 2026 · Cybersecurity

The AI tool your developers love has a blind spot attackers already found

Researchers hid malicious instructions in a PNG that tricked AI coding assistants into stealing credentials — and neither human nor AI code reviewers caught it.

Read more →

July 2026 · Cybersecurity

A phone call breached a $200 billion healthcare giant — and your company could be next

Abbott Labs was compromised through voice phishing, not malware. With vishing now the #2 attack vector globally, every board needs to rethink the human side of cyber risk.

Read more →

July 2026 · Cybersecurity

When your trusted advisor gets breached

EY's breach through a third-party help-desk platform exposed client tax data. With record-breaking patch volumes in July, third-party risk is the primary way your data gets stolen.

Read more →

July 2026 · Cybersecurity

The regulatory net is closing: what's mandatory, what's voluntary, and what's coming for frontier AI

Gold Eagle, the EU AI Act's enforcement date, NIS2, and a new congressional AI bill all landed within weeks of each other — the regulatory tracks are converging and boards need to map their exposure now.

Read more →

July 2026 · Cybersecurity

The AI arms race inside your company

AI is defending your network, attacking it, and — through your own developers — quietly creating the vulnerabilities both sides exploit. Three fronts, one battlefield.

Read more →

July 2026 · Cybersecurity

After Mythos: why your cyber insurance policy may not cover what comes next

Insurers are racing to exclude AI-related claims just as Mythos-class AI threats accelerate. Your policy was almost certainly written before any of this existed.

Read more →

July 2026 · Cybersecurity

The encryption under your business has an expiration date

A June 2026 executive order puts a hard deadline on post-quantum cryptography. Why this compliance timeline is really a business-risk clock for every company.

Read more →

July 2026 · Cybersecurity

That ChatGPT invite from your CEO? It's a trap.

Attackers built a fake OpenAI workspace impersonating a CEO — and it passed every authentication check. What the "Poisoned Tenant" campaign means for AI governance.

Read more →

July 2026 · Cybersecurity

One web page was all it took: why your AI agents are your next breach

Microsoft's AutoJack exploit hijacked an AI agent with nothing but a web page. The architecture it exposed isn't unique — it's every agent your company is building right now.

Read more →

July 2026 · Cybersecurity

AI models are now ransomware targets

A new ransomware strain built specifically to destroy AI model files reveals a $75K–$500K-per-model recovery gap most organizations haven't planned for.

Read more →

July 2026 · Cybersecurity

The numbers just got worse: what the 2026 ransomware surge means for your board

Two new reports show ransomware disclosures and software supply chain attacks both hit record highs in 2026 — and the acceleration itself is the real warning sign.

Read more →

July 2026 · Cybersecurity

Microsoft just dropped 570 patches in a single day. Your board needs to know why.

Microsoft's AI bug-hunting system just tripled the size of Patch Tuesday. The volume of vulnerabilities is now a resourcing decision the board has to own.

Read more →

July 2026 · Cybersecurity

Your cybersecurity advisor just got breached. Now what?

Accenture, which sells cybersecurity to 92 of the Fortune 100, just had its own Azure DevOps credentials leaked. What that means for your third-party risk program.

Read more →

July 2026 · Cybersecurity

NACD raised the bar on board cyber oversight

The NACD's newest board-oversight handbook says passive cyber governance is no longer defensible — here's what separates boards that meet the bar from those that don't.

Read more →

July 2026 · Cybersecurity

When your auditor gets audited: the EY breach

EY took eleven days to notice attackers had already left a third-party help-desk platform — a case study in how routine vendor tools become the real attack surface.

Read more →

July 2026 · Cybersecurity

The patch was ready five weeks ago. Were you?

A critical Oracle Payments flaw was patched in May — and exploited five weeks later, before any public exploit existed. The board-level accountability gap it exposes.

Read more →

July 2026 · Cybersecurity

Your payment system just became a target

Oracle Payments went from patched to breached in six weeks. A look at why enterprise financial systems keep getting hit, and the questions boards should be asking.

Read more →

July 2026 · Cybersecurity

The DHS breach: "unclassified" doesn't mean unimportant

A DHS breach during World Cup security planning shows how "sensitive but unclassified" data creates real risk boards routinely underprotect.

Read more →

July 2026 · Cybersecurity

They found the breach in 24 hours. It took 115 days to tell anyone.

AssuranceAmerica caught the breach in 24 hours. It still took 115 days and nearly 7 million exposed people before anyone was told.

Read more →

July 2026 · Cybersecurity

Today's the deadline. Does your SharePoint team know it?

CISA gave federal agencies three days to patch an actively exploited SharePoint vulnerability — here's the compliance-versus-security gap it exposes.

Read more →

July 2026 · Cybersecurity

Your IT provider just handed attackers the keys to your kingdom

A maximum-severity flaw in a widely used remote management tool let attackers walk into managed networks undetected — and steal credentials for AI development tools along the way.

Read more →

July 2026 · Cybersecurity

When AI attacks AI: the Hugging Face breach and what every board needs to understand

An autonomous AI agent breached Hugging Face's production infrastructure over a weekend. The incident reveals a structural asymmetry between AI-powered attackers and defenders.

Read more →

July 2026 · Cybersecurity

When the negotiator works for the other side

A ransomware negotiator was secretly feeding clients' positions to BlackCat. The DOJ case is a wake-up call for how organizations vet crisis response vendors.

Read more →

July 2026 · Cybersecurity

The first ransomware attack run by a machine — and why your board should care

Sysdig documented an AI agent that ran a full ransomware operation end to end — recon, credential theft, lateral movement, encryption. The skill floor for attacks just dropped to the cost of an API call.

Read more →

July 2026 · Cybersecurity

When your shield becomes the sword: what the BlueHammer vulnerability means for your board

Microsoft Defender's BlueHammer flaw lets attackers hijack the cleanup process to gain SYSTEM access. 84 days after the patch, many organizations are still exposed.

Read more →

July 2026 · Cybersecurity

The AI executive order's "voluntary" framework: why your board can't afford to ignore it

The White House says participation is optional. But with classified benchmarks, trusted partner status, and new enforcement priorities, opting out has a price your board needs to understand.

Read more →

July 2026 · Cybersecurity

Your company has MFA. This week we learned that may not mean much.

81 million login attempts, 64 organizations breached — many had MFA deployed. The attacker used a legacy login path their policies never covered.

Read more →

July 2026 · Cybersecurity

The 25-day window your board doesn't know about

A critical Kemp LoadMaster vulnerability sat unpatched for 25 days before attackers struck. The question isn't about the CVE — it's whether your organization can close the window in time.

Read more →

June 2026 · Cybersecurity

The $100M question: who protects the software that protects you?

AI found 10,000+ critical vulnerabilities in open-source software in a single month. Only 14% got patched. The discovery-remediation gap is a board-level risk.

Read more →

June 2026 · Cybersecurity

A phone call, a face scan, and 26 million reasons to rethink AI surveillance

The MSG breach exposed facial recognition records on millions of visitors. The liability didn't start with the hack — it started when nobody asked why they were collecting the data.

Read more →

June 2026 · Cybersecurity

The world's top spy agencies just told you to fix your cybersecurity. Are you listening?

The Five Eyes alliance warned that AI will transform cyber threats in months, not years. Here's what boards and executives need to do right now.

Read more →

June 2026 · Cybersecurity

One phone call, 26 million records: what the Madison Square Garden breach means for every board

MSG was breached twice in under a year by two different threat actors. The common thread isn't a technical failure — it's a governance failure that starts in the boardroom.

Read more →

June 2026 · Cybersecurity

When your vendor's vendor gets hacked: the Klue breach and what it means for your board

An abandoned OAuth token at a competitive intelligence platform exposed CRM data at LastPass, HackerOne, Huntress, and eight other cybersecurity firms. The supply chain question boards aren't asking.

Read more →

June 2026 · Cybersecurity

They didn't lock the doors — they took the filing cabinets

ShinyHunters breached 100+ organizations through a single Oracle PeopleSoft zero-day. What the attack reveals about third-party software risk and board oversight.

Read more →

June 2026 · Cybersecurity

The 29-year-old bug leaking your credentials right now

Squidbleed has been silently leaking usernames, passwords, and session tokens from corporate networks since 1997. A case study in infrastructure blind spots.

Read more →

June 2026 · Cybersecurity

Your developers trusted a plugin. Attackers were counting on that.

15 malicious JetBrains plugins stole AI API keys from 70,000 developers for eight months. What boards need to know about supply chain risk.

Read more →

June 2026 · Cybersecurity

86,000 Firewalls, 194 Countries, and One Uncomfortable Question For Your Board

FortiBleed exposed admin credentials for 73,000+ firewalls worldwide. It wasn't a zero-day — it was a credential hygiene failure at civilizational scale.

Read more →

June 2026 · Cybersecurity

The Compliance Deadline Passed. Now What?

The SEC's Regulation S-P went fully live on June 3. If your board hasn't confirmed compliance, you're already behind.

Read more →

June 2026 · Cybersecurity

Your Board is Spending More on Cybersecurity. It's Getting Worse at It.

HBR research shows boards are paradoxically getting worse at cybersecurity governance even as they spend more. Compliance isn't security.

Read more →

June 2026 · Cybersecurity

Your CISO Isn't The One Who Should Be Worried. You Are.

CISOs are buying personal liability insurance. That's a red flag about your governance structure, not a problem for HR.

Read more →

June 2026 · Cybersecurity

Lost in Translation: Why Security Leaders Struggle to Get The Buy-In They've Earned

The gap between what security teams measure and what executives act on isn't a technical problem. It's a translation problem.

Read more →

June 2026 · Cybersecurity

The AI Executive Order Sounds Like Protection. It Isn't — Yet.

The White House's AI executive order establishes voluntary frameworks. But the threats it's responding to are already hitting companies right now.

Read more →

April 2026 · Cybersecurity

The Wild West of AI: Why Enterprises Need A Central Authority Before The Next Crisis Hits

AI cowboys are deploying models at breakneck speed without oversight. The risks are mounting.

Read more →

April 2026 · Cybersecurity

AI Risk in Healthcare: What Every Clinician and Business Leader Should Know

AI introduces new dimensions of risk that go beyond traditional IT concerns.

Read more →