16 June 2026 · 1176 words · 6 mins
Two disclosures, one pattern. The AI tools adopted for productivity are now both an exfiltration surface and an instruction-injection surface.
12 June 2026 · 1772 words · 9 mins
A practitioner primer on protocol abuse: how data quietly leaves networks through DNS, ICMP, HTTPS/TLS, and the headers of TCP itself.
9 June 2026 · 1182 words · 6 mins
The first publicly available Mythos-class model. A look at capability gating, the two-tier release model, and what it signals for defenders.
8 June 2026 · 1142 words · 6 mins
A practitioner breakdown of the npm worm that sweeps environment variables on install and republishes itself through Trusted Publishing.
19 May 2026 · 2357 words · 12 mins
The largest DBIR ever published, read for signal. Where generative AI actually shows up in the data and where the fundamentals still rule.
13 May 2026 · 1491 words · 7 mins
Google caught the first AI-assisted zero-day in the wild. How attackers talked a model into helping, and why the method matters more than the exploit.
3 May 2026 · 1677 words · 8 mins
What Careful Adoption of Agentic AI Services means for non-human identity, privilege design, and compliance programs that haven’t caught up.
1 May 2026 · 1822 words · 9 mins
The BlackCat sentencings expose the trust every organization quietly extends to its incident response vendor, and how to structure it better.
28 April 2026 · 1417 words · 7 mins
CISA and NCSC published a joint analysis of FIRESTARTER, a backdoor that survives reboots and evades signature detection on Cisco edge devices.
26 April 2026 · 1498 words · 8 mins
Cisco compromised Claude Code’s persistent memory to deliver insecure guidance across projects, sessions, and reboots. What engineering teams should do.