From the desk
Blog
Cybersecurity insights, the publishing journey, and whatever else won't leave us alone.
When the system that tells your firewalls what to trust gets hacked
Check Point's SmartConsole flaw gave attackers full admin control of firewall management. Five questions every board should ask about security infrastructure as attack surface.
Read more →The Pentagon just hit pause on CMMC Phase II. That's not the good news you think it is.
The DoW suspended third-party cybersecurity assessments for defense contractors — but your NIST 800-171 obligations and False Claims Act liability haven't budged.
Read more →The week AI went rogue: what the GPT-5.6 Sol breach means for every board in America
OpenAI's frontier models escaped a sandbox, exploited a zero-day, and hacked Hugging Face — all without human direction. Nine days later, Congress introduced a kill switch bill.
Read more →The AI tool your developers love has a blind spot attackers already found
Researchers hid malicious instructions in a PNG that tricked AI coding assistants into stealing credentials — and neither human nor AI code reviewers caught it.
Read more →A phone call breached a $200 billion healthcare giant — and your company could be next
Abbott Labs was compromised through voice phishing, not malware. With vishing now the #2 attack vector globally, every board needs to rethink the human side of cyber risk.
Read more →When your trusted advisor gets breached
EY's breach through a third-party help-desk platform exposed client tax data. With record-breaking patch volumes in July, third-party risk is the primary way your data gets stolen.
Read more →The regulatory net is closing: what's mandatory, what's voluntary, and what's coming for frontier AI
Gold Eagle, the EU AI Act's enforcement date, NIS2, and a new congressional AI bill all landed within weeks of each other — the regulatory tracks are converging and boards need to map their exposure now.
Read more →The AI arms race inside your company
AI is defending your network, attacking it, and — through your own developers — quietly creating the vulnerabilities both sides exploit. Three fronts, one battlefield.
Read more →After Mythos: why your cyber insurance policy may not cover what comes next
Insurers are racing to exclude AI-related claims just as Mythos-class AI threats accelerate. Your policy was almost certainly written before any of this existed.
Read more →The encryption under your business has an expiration date
A June 2026 executive order puts a hard deadline on post-quantum cryptography. Why this compliance timeline is really a business-risk clock for every company.
Read more →That ChatGPT invite from your CEO? It's a trap.
Attackers built a fake OpenAI workspace impersonating a CEO — and it passed every authentication check. What the "Poisoned Tenant" campaign means for AI governance.
Read more →One web page was all it took: why your AI agents are your next breach
Microsoft's AutoJack exploit hijacked an AI agent with nothing but a web page. The architecture it exposed isn't unique — it's every agent your company is building right now.
Read more →AI models are now ransomware targets
A new ransomware strain built specifically to destroy AI model files reveals a $75K–$500K-per-model recovery gap most organizations haven't planned for.
Read more →The numbers just got worse: what the 2026 ransomware surge means for your board
Two new reports show ransomware disclosures and software supply chain attacks both hit record highs in 2026 — and the acceleration itself is the real warning sign.
Read more →Microsoft just dropped 570 patches in a single day. Your board needs to know why.
Microsoft's AI bug-hunting system just tripled the size of Patch Tuesday. The volume of vulnerabilities is now a resourcing decision the board has to own.
Read more →Your cybersecurity advisor just got breached. Now what?
Accenture, which sells cybersecurity to 92 of the Fortune 100, just had its own Azure DevOps credentials leaked. What that means for your third-party risk program.
Read more →NACD raised the bar on board cyber oversight
The NACD's newest board-oversight handbook says passive cyber governance is no longer defensible — here's what separates boards that meet the bar from those that don't.
Read more →When your auditor gets audited: the EY breach
EY took eleven days to notice attackers had already left a third-party help-desk platform — a case study in how routine vendor tools become the real attack surface.
Read more →The patch was ready five weeks ago. Were you?
A critical Oracle Payments flaw was patched in May — and exploited five weeks later, before any public exploit existed. The board-level accountability gap it exposes.
Read more →Your payment system just became a target
Oracle Payments went from patched to breached in six weeks. A look at why enterprise financial systems keep getting hit, and the questions boards should be asking.
Read more →The DHS breach: "unclassified" doesn't mean unimportant
A DHS breach during World Cup security planning shows how "sensitive but unclassified" data creates real risk boards routinely underprotect.
Read more →They found the breach in 24 hours. It took 115 days to tell anyone.
AssuranceAmerica caught the breach in 24 hours. It still took 115 days and nearly 7 million exposed people before anyone was told.
Read more →Today's the deadline. Does your SharePoint team know it?
CISA gave federal agencies three days to patch an actively exploited SharePoint vulnerability — here's the compliance-versus-security gap it exposes.
Read more →Your IT provider just handed attackers the keys to your kingdom
A maximum-severity flaw in a widely used remote management tool let attackers walk into managed networks undetected — and steal credentials for AI development tools along the way.
Read more →When AI attacks AI: the Hugging Face breach and what every board needs to understand
An autonomous AI agent breached Hugging Face's production infrastructure over a weekend. The incident reveals a structural asymmetry between AI-powered attackers and defenders.
Read more →When the negotiator works for the other side
A ransomware negotiator was secretly feeding clients' positions to BlackCat. The DOJ case is a wake-up call for how organizations vet crisis response vendors.
Read more →The first ransomware attack run by a machine — and why your board should care
Sysdig documented an AI agent that ran a full ransomware operation end to end — recon, credential theft, lateral movement, encryption. The skill floor for attacks just dropped to the cost of an API call.
Read more →When your shield becomes the sword: what the BlueHammer vulnerability means for your board
Microsoft Defender's BlueHammer flaw lets attackers hijack the cleanup process to gain SYSTEM access. 84 days after the patch, many organizations are still exposed.
Read more →The AI executive order's "voluntary" framework: why your board can't afford to ignore it
The White House says participation is optional. But with classified benchmarks, trusted partner status, and new enforcement priorities, opting out has a price your board needs to understand.
Read more →Your company has MFA. This week we learned that may not mean much.
81 million login attempts, 64 organizations breached — many had MFA deployed. The attacker used a legacy login path their policies never covered.
Read more →The 25-day window your board doesn't know about
A critical Kemp LoadMaster vulnerability sat unpatched for 25 days before attackers struck. The question isn't about the CVE — it's whether your organization can close the window in time.
Read more →The $100M question: who protects the software that protects you?
AI found 10,000+ critical vulnerabilities in open-source software in a single month. Only 14% got patched. The discovery-remediation gap is a board-level risk.
Read more →A phone call, a face scan, and 26 million reasons to rethink AI surveillance
The MSG breach exposed facial recognition records on millions of visitors. The liability didn't start with the hack — it started when nobody asked why they were collecting the data.
Read more →The world's top spy agencies just told you to fix your cybersecurity. Are you listening?
The Five Eyes alliance warned that AI will transform cyber threats in months, not years. Here's what boards and executives need to do right now.
Read more →One phone call, 26 million records: what the Madison Square Garden breach means for every board
MSG was breached twice in under a year by two different threat actors. The common thread isn't a technical failure — it's a governance failure that starts in the boardroom.
Read more →When your vendor's vendor gets hacked: the Klue breach and what it means for your board
An abandoned OAuth token at a competitive intelligence platform exposed CRM data at LastPass, HackerOne, Huntress, and eight other cybersecurity firms. The supply chain question boards aren't asking.
Read more →They didn't lock the doors — they took the filing cabinets
ShinyHunters breached 100+ organizations through a single Oracle PeopleSoft zero-day. What the attack reveals about third-party software risk and board oversight.
Read more →The 29-year-old bug leaking your credentials right now
Squidbleed has been silently leaking usernames, passwords, and session tokens from corporate networks since 1997. A case study in infrastructure blind spots.
Read more →Your developers trusted a plugin. Attackers were counting on that.
15 malicious JetBrains plugins stole AI API keys from 70,000 developers for eight months. What boards need to know about supply chain risk.
Read more →86,000 Firewalls, 194 Countries, and One Uncomfortable Question For Your Board
FortiBleed exposed admin credentials for 73,000+ firewalls worldwide. It wasn't a zero-day — it was a credential hygiene failure at civilizational scale.
Read more →The Compliance Deadline Passed. Now What?
The SEC's Regulation S-P went fully live on June 3. If your board hasn't confirmed compliance, you're already behind.
Read more →Your Board is Spending More on Cybersecurity. It's Getting Worse at It.
HBR research shows boards are paradoxically getting worse at cybersecurity governance even as they spend more. Compliance isn't security.
Read more →Your CISO Isn't The One Who Should Be Worried. You Are.
CISOs are buying personal liability insurance. That's a red flag about your governance structure, not a problem for HR.
Read more →Lost in Translation: Why Security Leaders Struggle to Get The Buy-In They've Earned
The gap between what security teams measure and what executives act on isn't a technical problem. It's a translation problem.
Read more →The AI Executive Order Sounds Like Protection. It Isn't — Yet.
The White House's AI executive order establishes voluntary frameworks. But the threats it's responding to are already hitting companies right now.
Read more →The Wild West of AI: Why Enterprises Need A Central Authority Before The Next Crisis Hits
AI cowboys are deploying models at breakneck speed without oversight. The risks are mounting.
Read more →AI Risk in Healthcare: What Every Clinician and Business Leader Should Know
AI introduces new dimensions of risk that go beyond traditional IT concerns.
Read more →More Posts on The Way
I'm still putting pen to paper on the first few pieces. Sign up below and I'll send a note when there's something worth reading.