Saying something positive about certifications now means arguing against the room. Here is that argument, followed by where to start, what each credential is actually good for, and what changed this year.
A preprint published on 10 August 2026 demonstrated instructions propagating between AI agents through ordinary messages. The propagation is interesting. Which file the payload had to land in is more useful.
Two August KEV additions put CISA’s most aggressive remediation tier into practice for the first time. The operational shift isn’t the calendar, it’s the requirement to determine whether an attacker got there first.
A three month investigation into a December 2025 attack on a Polish combined heat and power plant found something no one had documented before: attackers reaching an operational technology network through a private cellular APN. There was no exploited CVE and no malware. Every destructive step used a supported device function.
A threat-hunting report puts the gap between a public proof-of-concept and active exploitation at about 48 hours. Here is what that does to patch scheduling, why severity scores are the wrong primary signal, and a few adjustments worth making.