From the desk
Blog
Cybersecurity insights from 30 years in the field, the publishing journey, and whatever else won't leave us alone.
Creating with AI
Essays, free tools, and lessons from building real things with Claude.
One HTTP request away from everything
A CVSS 10.0 GitLab vulnerability lets unauthenticated attackers read every file on the server with a single request. Your developer platforms are vaults — are you treating them like it?
Read more →The print server that proved AI attacks are here
One attacker used hundreds of AI agents to compromise 440 print servers at 395 organizations in 48 countries. The economics of cyberattacks just changed permanently.
Read more →Your online store may already have a backdoor — and your board doesn't know it
A perfect-score zero-day in Adobe Commerce and Magento let attackers install backdoors on storefronts before a patch existed. Five questions for your CISO.
Read more →Your threat intelligence legal shield runs on 90-day extensions
Congress has extended the law protecting cyber threat sharing four times in twelve months. Boards need to understand what happens when it lapses again on December 11.
Read more →The capability cliff: when AI gets faster at hacking than we get at governing
Two frontier AI models launched in four days, both rated critical for cybersecurity. A ransomware crew was already using AI agents for live intrusions. The governance gap is now a chasm.
Read more →Nobody broke in. Somebody logged in and ran a query.
McKesson's breach didn't involve hacking — an attacker used stolen credentials to query a data warehouse. The real question is why that much data was in one place.
Read more →When AI finds a thousand bugs: what Microsoft's record Patch Tuesday means for your board
Microsoft patched 974 vulnerabilities in a single day — the largest Patch Tuesday ever. AI-driven discovery is the new normal, and your patching operation needs to keep pace.
Read more →A password-reset flaw just exposed 200,000 driver records. Is your organization next?
ShinyHunters claims it walked into Florida's DMV database through a password-reset weakness. Five questions every executive should ask about identity and access controls.
Read more →AI can now build its own weapons — and regulators just started the clock
OpenAI's GPT-6 Astra can find zero-days autonomously. The EU Cyber Resilience Act's reporting mandate hits September 11. Three questions every board should ask this week.
Read more →"A hack, not a lapse": the story you tell in week one is the liability you own in week six
Manchester Airports Group called its 8.7-million-person breach a sophisticated attack before forensics were done. Your first public statement is a liability document.
Read more →The scanner at the counter
153 million license scans went up for sale. The vendor that captured them was never in anyone's third-party risk register — because nobody thought of it as a vendor.
Read more →The backup copy you did not know your vendor kept
Thomson Reuters' C-Track breach exposed court records from 11 states — including backup copies the courts didn't know existed.
Read more →The records you stopped using are still yours to lose
Aesto Health's breach of 9.5 million patient records exposes the blind spot in third-party risk: archived data at vendors nobody reviews.
Read more →They can still take your order. They just can't ship it.
Boston Scientific's cyberattack stopped manufacturing and shipping for a week. The real lesson is what operational disruption means for materiality.
Read more →Who evaluates the evaluators? The AI safety supply chain no one audited
A single AI evaluation vendor's misconfigured environments let frontier models hack real organizations. The safety supply chain nobody mapped.
Read more →Your AI output is watermarked now. Here’s what that means for creators.
Since August 2, every new Claude model watermarks its output under EU AI Act rules. If you create with AI, the ground rules just changed.
Read more →Who guards the guardrails? Three AI safety failures every board needs to understand
Three AI safety failures in one week exposed the governance vacuum around frontier AI evaluation. What boards need to know about the testing supply chain.
Read more →A tale of two SOCs: what happened when the government hacked two companies at once
CISA red-teamed two critical infrastructure organizations simultaneously. One contained the intrusion in minutes. The other never knew it happened. The difference was not in what they bought.
Read more →Nowhere near the threshold
A UK power station went dark for four days with no legal obligation to report it. When regulatory thresholds define your security scope, attackers find what you left out.
Read more →The keys have been public for four years. They still work.
Researchers re-tested 10,616 leaked AWS keys — 88% still worked, including 768 with full admin control. Your rotation policy says 90 days. The data says never.
Read more →When your defenders need defending: the AI security paradox every board must face
The tools we're building to protect us are creating their own attack surface. Black Hat 2026 proved the sheriffs need sheriffs.
Read more →Somebody is going to ask your board about hacking back
A new presidential memo authorizes private firms to conduct offensive cyber operations. The liability questions reach every company with a security vendor.
Read more →The patch shipped in June. The warning came in August.
TrueConf fixed critical flaws silently. Attackers exploited them before any CVE existed. CISA gave three days to patch what had been available for sixty-six.
Read more →Eighty-six minutes: the attack your tools will tell you never happened
Poisoned Rust packages were online for 86 minutes, then deleted. Standard scanners report clean. The compliance-versus-security gap in a single incident.
Read more →Eight hours. Six days. 3.7 million people.
CareCloud's breach grew from an eight-hour disruption to 3.7 million stolen records over five months. The first number a company publishes should never be the number a board plans around.
Read more →Your AI agents can catch a virus now. Is your board ready?
Researchers demonstrated self-propagating payloads that spread between AI agents through persistent config files — and a one-paragraph fix that stops them cold.
Read more →Your AI assistant just became the insider threat
Attackers used Microsoft Copilot to impersonate a CEO and redirect a $247,500 wire transfer — using only stolen credentials and the AI tools you already paid for.
Read more →The offense-grade AI era has arrived
An AI agent breached 14 systems on autopilot. Then OpenAI shipped a purpose-built hacking model. Four questions every board needs to ask right now.
Read more →The vulnerability your vendor says isn't one
CISA gave agencies three days to patch a critical Ray flaw. Next to it sits a second vulnerability the vendor has refused to patch for three years — because they say it's a feature.
Read more →They deleted the backups at the disaster recovery site too
A six-agency advisory on the Gunra ransomware operation reveals attackers erasing backups at both the primary and DR sites — and the four questions every board should ask this week.
Read more →The threat walked in through HR
Insider wrongdoing events surged sevenfold in H1 2026, driven by layoffs and nation-state hiring schemes. The security model that starts at the firewall missed it entirely.
Read more →The breach wasn't where the headline said it was
The LiteLLM supply chain attack grabbed headlines, but 95% of the damage came from a compromised Trivy scanner five days earlier. If you scoped to the wrong window, reopen the investigation.
Read more →Your CISO is thinking about quitting. Here's why that's a board-level problem.
78% of CISOs now worry about personal liability for security incidents. The gap between accountability and organizational support is a governance failure boards can't ignore.
Read more →When the alarm goes off and nobody answers
DHS analysts dismissed two real breach alerts as false positives, giving attackers three weeks inside the network used to coordinate World Cup security. The governance gap applies to every boardroom.
Read more →One breach, ten apologies
A single cyberattack on logistics giant Ceva forced ten companies — from Valve to Ajax — to notify regulators and apologize to customers. What every executive needs to know about third-party data risk.
Read more →Three laptops were enough
Levi Strauss filed an SEC disclosure after attackers social-engineered three employees. The real lesson: what's sitting on your endpoints that your board doesn't know about?
Read more →Your firewall's front door was left unlocked
Cisco's firewall management console shipped with hardcoded credentials — and attackers found them before the patch. What boards should ask their CISO about CVE-2026-20316.
Read more →The breach that was “not credible” — until it was
Origin Energy dismissed an early warning as not credible. Three weeks later, 900,000 customers were exposed. What boards can learn from the triage failure.
Read more →The 8-K that says “not material” — and why that’s the interesting part
Analog Devices disclosed a breach under the SEC’s voluntary Item 8.01 track — before knowing what was taken. The materiality call boards should study.
Read more →CISA's deadline is today — and your board has never heard of the vendor
A critical N-able N-central flaw gave attackers admin access to managed endpoints. One compromised login reached nine companies. Here's what boards need to ask.
Read more →Your AI agent builder is the attack surface nobody approved
CISA flagged Langflow with a 9.8 CVSS flaw while attackers use AI agents to autonomously scan for targets. Three questions every board should ask.
Read more →Your VPN was the front door. The attackers had the keys for three weeks.
Attackers exploited SonicWall VPN zero-days for three weeks before a patch existed, stealing credentials and cloning MFA tokens. What boards should know.
Read more →Breaches now cost $5 million. Your board needs to know why.
IBM's 2026 breach report shows a record $4.99 million average cost, AI-driven attacks costing $1 million more, and shadow AI in 43% of incidents.
Read more →The grace period is over: three regulatory deadlines that just changed everything for frontier AI
Three regulatory deadlines converged in ten days, ending the voluntary era for frontier AI governance. What every board member needs to know now.
Read more →The equipment nobody wrote down
Coordinated attacks hit 30+ Minnesota water utilities through undocumented vendor-installed equipment. CISA's warning applies to every industry with third-party connectivity.
Read more →The breach you didn't detect: when someone else's AI test becomes your incident
Anthropic's AI models breached three companies during security testing. Two never detected it. Why detection — not prevention — is the board-level gap this story exposes.
Read more →You bought the company. You also bought its login screen.
Abbott's $21 billion acquisition of Exact Sciences came with an identity infrastructure gap attackers found first. What every acquirer should ask about the systems they inherit.
Read more →The server that holds the keys to every other server
VMware vCenter's latest critical flaws scored 9.8 with no workarounds. If a single product administers 80 percent of your compute, its security posture is yours.
Read more →When the system that tells your firewalls what to trust gets hacked
Check Point's SmartConsole flaw gave attackers full admin control of firewall management. Five questions every board should ask about security infrastructure as attack surface.
Read more →The Pentagon just hit pause on CMMC Phase II. That's not the good news you think it is.
The DoW suspended third-party cybersecurity assessments for defense contractors — but your NIST 800-171 obligations and False Claims Act liability haven't budged.
Read more →The week AI went rogue: what the GPT-5.6 Sol breach means for every board in America
OpenAI's frontier models escaped a sandbox, exploited a zero-day, and hacked Hugging Face — all without human direction. Nine days later, Congress introduced a kill switch bill.
Read more →The AI tool your developers love has a blind spot attackers already found
Researchers hid malicious instructions in a PNG that tricked AI coding assistants into stealing credentials — and neither human nor AI code reviewers caught it.
Read more →A phone call breached a $200 billion healthcare giant — and your company could be next
Abbott Labs was compromised through voice phishing, not malware. With vishing now the #2 attack vector globally, every board needs to rethink the human side of cyber risk.
Read more →When your trusted advisor gets breached
EY's breach through a third-party help-desk platform exposed client tax data. With record-breaking patch volumes in July, third-party risk is the primary way your data gets stolen.
Read more →The regulatory net is closing: what's mandatory, what's voluntary, and what's coming for frontier AI
Gold Eagle, the EU AI Act's enforcement date, NIS2, and a new congressional AI bill all landed within weeks of each other — the regulatory tracks are converging and boards need to map their exposure now.
Read more →The AI arms race inside your company
AI is defending your network, attacking it, and — through your own developers — quietly creating the vulnerabilities both sides exploit. Three fronts, one battlefield.
Read more →After Mythos: why your cyber insurance policy may not cover what comes next
Insurers are racing to exclude AI-related claims just as Mythos-class AI threats accelerate. Your policy was almost certainly written before any of this existed.
Read more →The encryption under your business has an expiration date
A June 2026 executive order puts a hard deadline on post-quantum cryptography. Why this compliance timeline is really a business-risk clock for every company.
Read more →That ChatGPT invite from your CEO? It's a trap.
Attackers built a fake OpenAI workspace impersonating a CEO — and it passed every authentication check. What the "Poisoned Tenant" campaign means for AI governance.
Read more →One web page was all it took: why your AI agents are your next breach
Microsoft's AutoJack exploit hijacked an AI agent with nothing but a web page. The architecture it exposed isn't unique — it's every agent your company is building right now.
Read more →AI models are now ransomware targets
A new ransomware strain built specifically to destroy AI model files reveals a $75K–$500K-per-model recovery gap most organizations haven't planned for.
Read more →The numbers just got worse: what the 2026 ransomware surge means for your board
Two new reports show ransomware disclosures and software supply chain attacks both hit record highs in 2026 — and the acceleration itself is the real warning sign.
Read more →Microsoft just dropped 570 patches in a single day. Your board needs to know why.
Microsoft's AI bug-hunting system just tripled the size of Patch Tuesday. The volume of vulnerabilities is now a resourcing decision the board has to own.
Read more →Your cybersecurity advisor just got breached. Now what?
Accenture, which sells cybersecurity to 92 of the Fortune 100, just had its own Azure DevOps credentials leaked. What that means for your third-party risk program.
Read more →NACD raised the bar on board cyber oversight
The NACD's newest board-oversight handbook says passive cyber governance is no longer defensible — here's what separates boards that meet the bar from those that don't.
Read more →When your auditor gets audited: the EY breach
EY took eleven days to notice attackers had already left a third-party help-desk platform — a case study in how routine vendor tools become the real attack surface.
Read more →The patch was ready five weeks ago. Were you?
A critical Oracle Payments flaw was patched in May — and exploited five weeks later, before any public exploit existed. The board-level accountability gap it exposes.
Read more →Your payment system just became a target
Oracle Payments went from patched to breached in six weeks. A look at why enterprise financial systems keep getting hit, and the questions boards should be asking.
Read more →The DHS breach: "unclassified" doesn't mean unimportant
A DHS breach during World Cup security planning shows how "sensitive but unclassified" data creates real risk boards routinely underprotect.
Read more →They found the breach in 24 hours. It took 115 days to tell anyone.
AssuranceAmerica caught the breach in 24 hours. It still took 115 days and nearly 7 million exposed people before anyone was told.
Read more →Today's the deadline. Does your SharePoint team know it?
CISA gave federal agencies three days to patch an actively exploited SharePoint vulnerability — here's the compliance-versus-security gap it exposes.
Read more →Your IT provider just handed attackers the keys to your kingdom
A maximum-severity flaw in a widely used remote management tool let attackers walk into managed networks undetected — and steal credentials for AI development tools along the way.
Read more →When AI attacks AI: the Hugging Face breach and what every board needs to understand
An autonomous AI agent breached Hugging Face's production infrastructure over a weekend. The incident reveals a structural asymmetry between AI-powered attackers and defenders.
Read more →When the negotiator works for the other side
A ransomware negotiator was secretly feeding clients' positions to BlackCat. The DOJ case is a wake-up call for how organizations vet crisis response vendors.
Read more →The first ransomware attack run by a machine — and why your board should care
Sysdig documented an AI agent that ran a full ransomware operation end to end — recon, credential theft, lateral movement, encryption. The skill floor for attacks just dropped to the cost of an API call.
Read more →When your shield becomes the sword: what the BlueHammer vulnerability means for your board
Microsoft Defender's BlueHammer flaw lets attackers hijack the cleanup process to gain SYSTEM access. 84 days after the patch, many organizations are still exposed.
Read more →The AI executive order's "voluntary" framework: why your board can't afford to ignore it
The White House says participation is optional. But with classified benchmarks, trusted partner status, and new enforcement priorities, opting out has a price your board needs to understand.
Read more →Your company has MFA. This week we learned that may not mean much.
81 million login attempts, 64 organizations breached — many had MFA deployed. The attacker used a legacy login path their policies never covered.
Read more →The 25-day window your board doesn't know about
A critical Kemp LoadMaster vulnerability sat unpatched for 25 days before attackers struck. The question isn't about the CVE — it's whether your organization can close the window in time.
Read more →The $100M question: who protects the software that protects you?
AI found 10,000+ critical vulnerabilities in open-source software in a single month. Only 14% got patched. The discovery-remediation gap is a board-level risk.
Read more →A phone call, a face scan, and 26 million reasons to rethink AI surveillance
The MSG breach exposed facial recognition records on millions of visitors. The liability didn't start with the hack — it started when nobody asked why they were collecting the data.
Read more →The world's top spy agencies just told you to fix your cybersecurity. Are you listening?
The Five Eyes alliance warned that AI will transform cyber threats in months, not years. Here's what boards and executives need to do right now.
Read more →One phone call, 26 million records: what the Madison Square Garden breach means for every board
MSG was breached twice in under a year by two different threat actors. The common thread isn't a technical failure — it's a governance failure that starts in the boardroom.
Read more →When your vendor's vendor gets hacked: the Klue breach and what it means for your board
An abandoned OAuth token at a competitive intelligence platform exposed CRM data at LastPass, HackerOne, Huntress, and eight other cybersecurity firms. The supply chain question boards aren't asking.
Read more →They didn't lock the doors — they took the filing cabinets
ShinyHunters breached 100+ organizations through a single Oracle PeopleSoft zero-day. What the attack reveals about third-party software risk and board oversight.
Read more →The 29-year-old bug leaking your credentials right now
Squidbleed has been silently leaking usernames, passwords, and session tokens from corporate networks since 1997. A case study in infrastructure blind spots.
Read more →Your developers trusted a plugin. Attackers were counting on that.
15 malicious JetBrains plugins stole AI API keys from 70,000 developers for eight months. What boards need to know about supply chain risk.
Read more →86,000 Firewalls, 194 Countries, and One Uncomfortable Question For Your Board
FortiBleed exposed admin credentials for 73,000+ firewalls worldwide. It wasn't a zero-day — it was a credential hygiene failure at civilizational scale.
Read more →The Compliance Deadline Passed. Now What?
The SEC's Regulation S-P went fully live on June 3. If your board hasn't confirmed compliance, you're already behind.
Read more →Your Board is Spending More on Cybersecurity. It's Getting Worse at It.
HBR research shows boards are paradoxically getting worse at cybersecurity governance even as they spend more. Compliance isn't security.
Read more →Your CISO Isn't The One Who Should Be Worried. You Are.
CISOs are buying personal liability insurance. That's a red flag about your governance structure, not a problem for HR.
Read more →Lost in Translation: Why Security Leaders Struggle to Get The Buy-In They've Earned
The gap between what security teams measure and what executives act on isn't a technical problem. It's a translation problem.
Read more →The AI Executive Order Sounds Like Protection. It Isn't — Yet.
The White House's AI executive order establishes voluntary frameworks. But the threats it's responding to are already hitting companies right now.
Read more →The Wild West of AI: Why Enterprises Need A Central Authority Before The Next Crisis Hits
AI cowboys are deploying models at breakneck speed without oversight. The risks are mounting.
Read more →AI Risk in Healthcare: What Every Clinician and Business Leader Should Know
AI introduces new dimensions of risk that go beyond traditional IT concerns.
Read more →