Real-World Cyber Insights
No vendor fluff. No recycled frameworks. Just honest, experience-driven perspectives on what actually matters in cybersecurity today.
Google Passkeys Can Be Hijacked. Not the Cryptography. The Cloud Sync.
Unit 42 published three attacks, called Pass-ta-key, that allow unprivileged malware to hijack Google Password Manager's cloud-synced passkeys in Chrome. No admin rights. No user interaction. The passkey cryptography is not broken. The cloud sync trust model is.
Your Hotel Is PCI-DSS Certified. APT29 Targeted It Anyway.
Microsoft confirmed APT29 (Midnight Blizzard) has been running CaptiveCrunch, a global campaign targeting hotel and conference Wi-Fi since May 2026. The attack steals M365 session tokens through compromised captive portal hardware. PCI-DSS certification did not stop it.
CVE-2026-16723: The Fastjson Zero-Day Your Pen Test Probably Missed
Fastjson 1.x has a CVSS 9.0 RCE with no patch and active exploitation in financial services. A vulnerability scanner would not have caught it. A properly scoped penetration test would have.
DORA Didn't Account for an AI Agent Running in YOLO Mode
An open-source AI agent breached Thailand's Finance Ministry this week in fully autonomous mode. No human in the loop. Here is what that means for DORA ICT risk management and financial sector detection capabilities.
Half a Billion WordPress Sites. Zero Credentials Required. Found by Continuous Monitoring.
CVE-2026-63030 and CVE-2026-60137 chain to give any anonymous user remote code execution on WordPress 6.9 and 7.0. A public proof-of-concept is on GitHub. The attack surface management team that found it wasn't running a pen test.
The OpenSSL Fix That Arrived with No CVE. NIS2 Still Expects You to Patch It.
OpenSSL shipped a fix on June 9 with no CVE, no advisory, and no changelog entry. Okta's Red Team published the details 38 days later. NIS2 and DORA require patch management for known vulnerabilities. This one was deliberately invisible.
EU AI Act: Your CISO Checklist for August 2
On August 2, 2026, EU AI Act high-risk obligations become enforceable. Fines reach 35M EUR or 7% of global revenue. 78% of organizations are not ready. Here is the 5-step CISO action plan.
Your CFO Is on the Call. So Are Three Executives. None of Them Are Real.
A finance employee at Arup wired $25.6M after a deepfake video call with fake executives. The controls worked exactly as designed. The threat had already moved past them.
AI Governance Without Board Accountability Is Just a Document
The EU AI Act starts enforcing high-risk AI system rules on August 2, 2026. Most boards don't know which of their AI systems qualify. That is the governance gap nobody is talking about.
Shadow AI: The Insider Threat Your Security Stack Can't See
Employees are pasting sensitive data into unapproved AI tools every day. This is not a future risk - it is a data breach unfolding in slow motion, and most organizations have no visibility into it.
AI Is Already Being Used Against You. Here's How to Fight Back.
Deepfake video calls, AI-cloned executive voices, autonomous phishing agents - attackers are already using AI at scale. Here is the security framework every organization needs before AI becomes a liability.
Signed, Trusted, Compromised: The npm Supply Chain Attack That Fooled Every Security Gate
The Shai Hulud campaign poisoned 373–416 npm package versions - all signed, all attested, all verified. What CISOs must understand about software supply chain trust when 'signed' no longer means 'safe'.
CVSS 9.8: How a cPanel Auth Bypass Became a Mass Ransomware Campaign
CVE-2026-41940 gives attackers admin access to cPanel servers with no credentials required. It was exploited before the patch shipped. Here is what that means for your exposure.
Your Collaboration Tools Are Now the Attack Surface
MuddyWater used Microsoft Teams to steal credentials and deploy false-flag ransomware. If your attack surface map does not include Teams, Slack, and Zoom, you have a blind spot.
When Your Security Vendor Gets Breached: Third-Party Risk in the Security Stack
Trellix confirmed attackers accessed their source code repository. If your security vendor can be breached, how much scrutiny are you applying to the tools that sit inside your environment?
AI Compliance Theater: Your GRC Platform Got a Chatbot. Your Team Still Chases Evidence.
Security leaders spend 40% of their time on compliance admin. The GRC industry's answer was a chatbot on top of a 2019 dashboard. That is not AI. Here is what autonomous compliance actually looks like.
The $415M Wake-Up Call: Why Your AI Threat Model Is Outdated
One attacker. Nine Mexican government agencies. 415M records exfiltrated using Claude Code and GPT-4.1. What CISOs and boards must change this quarter.
The Three Doors Ransomware Crews Walk Through
Frost Bank and Citizens Bank both lost data to Everest ransomware in the same week. No zero-days - just three doors every CISO can lock this week.
Why Most Companies Don't Know They've Been Breached
The average company takes 194 days to detect a breach and 64 more to contain it. Here's why detection fails - and what CISOs can do to change it.
The CISO's Guide to Board Communication
Boards don't speak 'cyber.' They speak risk, cost, and reputation. Learn how to translate your security program into language that drives action.
10,000+ Followers Already Reading
Join the conversation on LinkedIn - where I post daily insights on cybersecurity, risk management, and the CISO mindset.
Follow on LinkedIn