Real-World Cyber Insights

No vendor fluff. No recycled frameworks. Just honest, experience-driven perspectives on what actually matters in cybersecurity today.

31 articles

Aurora Ransomware Used an AI Coding Assistant to Plan Your Breach

The Aurora ransomware group used Cursor AI to plan attacks against 33 victims across the US and Europe — including a full AD CS exploitation plan written in Russian. The same tool your developers use. The detection implications are significant.

9 min read · September 2, 2026

800 Malicious npm Packages. Your SCA Tool Probably Missed Them.

Nearly 800 malicious npm packages flooded the registry using AI-generated typosquatting names. The WEL1DROPPER campaign delivers a cross-platform RAT on Windows and Mac, and Sliver C2 on Linux. Standard SCA tools miss this because the packages had no prior malicious history.

8 min read · August 12, 2026

Google Passkeys Can Be Hijacked. Not the Cryptography. The Cloud Sync.

Unit 42 published three attacks, called Pass-ta-key, that allow unprivileged malware to hijack Google Password Manager's cloud-synced passkeys in Chrome. No admin rights. No user interaction. The passkey cryptography is not broken. The cloud sync trust model is.

9 min read · August 5, 2026

Your Hotel Is PCI-DSS Certified. APT29 Targeted It Anyway.

Microsoft confirmed APT29 (Midnight Blizzard) has been running CaptiveCrunch, a global campaign targeting hotel and conference Wi-Fi since May 2026. The attack steals M365 session tokens through compromised captive portal hardware. PCI-DSS certification did not stop it.

9 min read · August 4, 2026

DORA Didn't Account for an AI Agent Running in YOLO Mode

An open-source AI agent breached Thailand's Finance Ministry this week in fully autonomous mode. No human in the loop. Here is what that means for DORA ICT risk management and financial sector detection capabilities.

9 min read · July 29, 2026

EU AI Act: Your CISO Checklist for August 2

On August 2, 2026, EU AI Act high-risk obligations become enforceable. Fines reach 35M EUR or 7% of global revenue. 78% of organizations are not ready. Here is the 5-step CISO action plan.

8 min read · July 15, 2026

Shadow AI: The Insider Threat Your Security Stack Can't See

Employees are pasting sensitive data into unapproved AI tools every day. This is not a future risk - it is a data breach unfolding in slow motion, and most organizations have no visibility into it.

9 min read · June 27, 2026

Your Collaboration Tools Are Now the Attack Surface

MuddyWater used Microsoft Teams to steal credentials and deploy false-flag ransomware. If your attack surface map does not include Teams, Slack, and Zoom, you have a blind spot.

8 min read · May 6, 2026

The Three Doors Ransomware Crews Walk Through

Frost Bank and Citizens Bank both lost data to Everest ransomware in the same week. No zero-days - just three doors every CISO can lock this week.

10 min read · April 22, 2026

The CISO's Guide to Board Communication

Boards don't speak 'cyber.' They speak risk, cost, and reputation. Learn how to translate your security program into language that drives action.

8 min read · April 19, 2026

Continue the conversation on LinkedIn

Join the conversation on LinkedIn - where I post daily insights on cybersecurity, risk management, and the CISO mindset.

Follow on LinkedIn