<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Cybersecurity Pulse (TCP)]]></title><description><![CDATA[Fortune 500 CISOs and their teams read this. So do vendors and the investors funding them. 

Weekly security news covering threats, deals, and startups. Occasional deep dives and opinion pieces.]]></description><link>https://www.cybersecuritypulse.net</link><image><url>https://substackcdn.com/image/fetch/$s_!qMTq!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fef06d7-bf82-40ef-855b-21ff2898ce23_200x200.png</url><title>The Cybersecurity Pulse (TCP)</title><link>https://www.cybersecuritypulse.net</link></image><generator>Substack</generator><lastBuildDate>Fri, 11 Sep 2026 20:48:11 GMT</lastBuildDate><atom:link href="https://www.cybersecuritypulse.net/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Darwin Salazar]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[TheCybersecurityPulse@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[TheCybersecurityPulse@substack.com]]></itunes:email><itunes:name><![CDATA[Darwin Salazar]]></itunes:name></itunes:owner><itunes:author><![CDATA[Darwin Salazar]]></itunes:author><googleplay:owner><![CDATA[TheCybersecurityPulse@substack.com]]></googleplay:owner><googleplay:email><![CDATA[TheCybersecurityPulse@substack.com]]></googleplay:email><googleplay:author><![CDATA[Darwin Salazar]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[TCP 144: LG’s TV Privacy Mess, CrowdStrike’s SecOps Push, and $245M Before Beta]]></title><description><![CDATA[Palo Alto&#8217;s reported $500M Console deal, ClickHouse buys RunReveal, and a WeChat worm that needs no clicks.]]></description><link>https://www.cybersecuritypulse.net/p/tcp-144-lgs-tv-privacy-mess-crowdstrikes</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/tcp-144-lgs-tv-privacy-mess-crowdstrikes</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Fri, 11 Sep 2026 15:35:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mxxi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mxxi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mxxi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!mxxi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!mxxi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!mxxi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mxxi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3372164,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/214966342?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mxxi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!mxxi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!mxxi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!mxxi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc737f1-a85d-48d5-ad6b-d18a03f16252_1800x1300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Howdy &#128075;&#127997; Hope you&#8217;re having a splendid week. I&#8217;m back from Burning Man and settling back in, hence the Friday issue! If you were out there too or have questions about going, DM me. I&#8217;m a firm believer that everyone should go out there at least once in their lifetime. It&#8217;s truly a mind opening experience that enhances many aspects of your life. </p><p>Also, huge thank you to <a href="https://substack.com/@andrewrichards25">Andrew</a> for taking the wheel on <a href="https://www.cybersecuritypulse.net/p/tcp-143cursor-goes-post-access-echo">last week&#8217;s issue</a> &#128076;&#127997;</p><p>Security hasn&#8217;t slowed down at all since Black Hat and DEF CON and this week&#8217;s issue is a testament of that. CrowdStrike has been cooking, especially on <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">SecOps at Fal.Con</a>, Palo Alto Networks spends $500M on a new company. Lots of funding + acquisitions. We&#8217;ve also got <a href="https://www.youtube.com/watch?v=6IFVTcM28KA">LG&#8217;s TV privacy mess</a>, and some impressive research that will have you rethink mobile security.</p><p>The next few months are packed with conferences. Vendor cons are meh because it&#8217;s mostly them touting their sauce, but it&#8217;s a great way to get a look at their roadmap and how industry leaders are thinking about the future. Here&#8217;s what&#8217;s coming up this month:</p><ul><li><p><strong><a href="https://conf.splunk.com/">Splunk .conf26</a>: September 14&#8211;17, Denver.</strong> <a href="https://info.cribl.io/RM-FEV-FY27-Q3-09-14-CriblConnect-Denver_LP-Registration.html">CriblConnect</a> is also in town on September 14, so expect a busy week for the SecOps crowd.</p></li><li><p><strong><a href="https://www.cybrseccon.com/">CYBR.SEC.CON.</a>: September 15&#8211;16, Houston.</strong> Another stop on next week&#8217;s security con circuit. Practitioner focused con &#128142;</p></li><li><p><strong><a href="https://www.okta.com/oktane/">Oktane</a>: September 22&#8211;24, Las Vegas.</strong> Okta&#8217;s annual conference puts identity next on the agenda.</p></li><li><p><strong><a href="https://grrcon.com/">GrrCON</a>: September 24&#8211;25, Grand Rapids, Michigan.</strong> Two days of security research, AI talks, and hands-on workshops. Built around the practitioner and hacker community &#128142;</p></li><li><p><strong><a href="https://criblcon.cribl.io/">CriblCon</a>: September 28&#8211;30, Chicago.</strong> Cribl heads into its annual conafter acquiring <a href="https://cribl.io/news/cribl-acquires-cardinalops-to-expand-its-ai-platform-into-security-operations/">CardinalOps</a> and <a href="https://cribl.io/news/cribl-advances-ai-powered-security-operations-with-new-ai-soc-acquisition/">Radiant Security&#8217;s AI SOC technology assets</a>. Will be interesting to hear how they&#8217;re thinking about the future.</p></li><li><p><strong><a href="https://runway.runreveal.com/">RunReveal&#8217;s RUNWAY</a>: September 29, San Francisco.</strong> The team plans to share more about its <a href="https://blog.runreveal.com/runreveal-is-joining-clickhouse/">roadmap after joining ClickHouse</a>.</p></li></ul><p>October is another jampacked conf month. Identity, SecOps, and AI security will continue to take center stage, imo. We&#8217;ll have full coverage across the board on key takeaways from these cons.</p><p>Today also marks 25 years since <a href="https://www.911memorial.org/">September 11</a>. Taking a moment to remember the lives lost, the first responders who answered the call, and the service members who gave their lives in the years that followed. My thoughts are with their families and everyone still carrying that loss &#127482;&#127480;&#128591;&#127997;</p><p>Now, let&#8217;s get into it! </p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;">Interested in sponsoring TCP?</h4><p style="text-align: center;">Reach our community of <strong>20,000+ cybersecurity professionals.</strong> Explore sponsorship opportunities below.</p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Explore sponsorships&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Explore sponsorships</span></a></p></div><div><hr></div><h2>&#128478;&#65039; TL;DR</h2><ul><li><p>&#128222; <strong><a href="https://calif.io/research/weworm">Researchers hijack WeChat accounts through unanswered calls</a>:</strong> A hacked contact could take over your account without you answering. </p></li><li><p>&#128250; <strong><a href="https://www.youtube.com/watch?v=6IFVTcM28KA">LG&#8217;s smart TVs have a privacy problem</a>:</strong> Researchers report tracking and audio collection in standby. LG disputes.</p></li><li><p>&#129657; <strong><a href="https://onapsis.com/blog/sap-overpass-remediation/">SAP patches two serious server flaws</a>:</strong> Attackers could run their own code without logging in. Internal servers need patching too.</p></li><li><p>&#128488;&#65039; <strong><a href="https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/">AI agents traded answers in 18,000 wiki posts</a>:</strong> Giving an agent browsing access can also give it a way to send information out.</p></li><li><p>&#129513; <strong><a href="https://www.linkedin.com/posts/darwin-salazar_an-incident-is-a-bad-time-to-discover-a-critical-activity-7503497248769642496-zDcq">Monad launches schema drift detection</a>:</strong> Catches changes in your log schema that can quietly break your security detections, KPI reporting, etc.</p></li><li><p>&#127959;&#65039; <strong><a href="https://cylake.com/resources/cylake-closes-245-million-funding-round/">Cylake lands $245M before beta</a>:</strong> Palo Alto&#8217;s cofounder is betting companies want their security tools and data back in-house. </p></li><li><p>&#128452;&#65039; <strong><a href="https://clickhouse.com/blog/clickhouse-welcomes-runreveal">ClickHouse buys RunReveal</a>:</strong> SecOps consolidation stays hot, with ClickHouse adding threat detection and investigation to its database business.</p></li><li><p>&#129413; <strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">CrowdStrike goes big on SecOps at Fal.Con</a>:</strong> AI investigators, earlier threat detection, and controls for agents. </p></li><li><p>&#129706; <strong><a href="https://www.cymphony.io/release">Cymphony launches with $30M</a>:</strong> Tackles the permissions mess that lets employees and AI assistants see too much.</p></li><li><p>&#128736;&#65039; <strong><a href="https://techcrunch.com/2026/09/02/palo-alto-networks-paid-500m-for-thrive-backed-console-sources-say/">Palo Alto Networks buys Console for a reported $500M</a>:</strong> Console&#8217;s AI agents handle IT requests. Palo Alto could use them to fix security issues.</p></li></ul><p><strong>Plus:</strong> Astra&#8217;s autonomous exploit capabilities, Huskeys&#8217; $27M Series A, the FBI&#8217;s stolen-ID investigation, and speaker prep for BSides NYC and Unprompted Con.</p><h2>&#9874;&#65039; Picks of the Week </h2><div><hr></div><h4><a href="https://calif.io/research/weworm">WeWorm takes over WeChat accounts through unanswered calls</a></h4><div id="youtube2-OQdagtqKoXg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;OQdagtqKoXg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/OQdagtqKoXg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>Calif</strong> disclosed a WeChat exploit chain September 8 that demonstrated account takeover spreading from Android to iPhone and back to Android through unanswered calls.</p><p><strong>Breakdown:</strong></p><ul><li><p><strong>Trigger:</strong> Memory corruption in WeChat&#8217;s VoIP stack. The caller must already be a contact; the recipient need not answer.</p></li><li><p><strong>Access:</strong> Read and send messages, place calls, and reach the next contact. Full phone compromise requires additional vulnerabilities.</p></li><li><p><strong>Status:</strong> Reported July 24, demonstrated August 11. Tencent shipped client mitigations August 21; Calif confirmed server-side mitigation August 28 for all users. No exploitation in the wild has been disclosed.</p></li></ul><p>Requiring an existing contact limits the first infection. However, once an account is compromised, its contact list supplies the next targets. Bonkers.. </p><div><hr></div><h4><a href="https://www.youtube.com/watch?v=6IFVTcM28KA&amp;utm_source=chatgpt.com">LG&#8217;s smart TVs have a serious privacy problem</a></h4><div id="youtube2-6IFVTcM28KA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;6IFVTcM28KA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/6IFVTcM28KA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>GamersNexus</strong>, with researchers <strong>MrBruh and uturn</strong>, reports tested LG TVs scanning nearby devices, identifying what people watch, and <strong>collecting audio in standby &#129327;</strong> Researchers say some data stays on the TV offline and uploads after reconnection.</p><p><a href="https://www.tomshardware.com/tech-industry/big-tech/lg-strongly-denies-tv-security-claims-says-tracking-and-snooping-concerns-not-true-online-investigation-claims-216-000-000-spy-tvs-record-audio?utm_source=chatgpt.com">LG denies ambient recording outside user-activated voice features</a> and says advertising tracking requires consent.</p><p><strong>Customers shouldn&#8217;t have to reverse-engineer a television to protect their privacy.</strong> </p><p>LG owes buyers verifiable controls and a clear justification for what it collects inside their homes.</p><p>Watch the <a href="https://www.youtube.com/watch?v=6IFVTcM28KA&amp;utm_source=chatgpt.com">full investigation</a> or <a href="https://www.instagram.com/reel/DdC840AsHRc/">Matt Jay&#8217;s shorter breakdown</a>.</p><div><hr></div><h4><a href="https://www.fox4news.com/news/iranian-hacker-group-claims-responsibility-dallas-internet-outage">APT Iran claims AT&amp;T outage; AT&amp;T points to attempted cable theft</a></h4><p>An internet outage disrupted parts of Dallas for hours on September 7. A group calling itself APT Iran claimed responsibility. AT&amp;T says it had no evidence supporting that claim and attributed the disruption to attempted cable theft.</p><p>The group also threatened U.S. water, energy, and telecom infrastructure. Those threats do not establish that it caused this outage. <strong>A system intrusion or data theft has not been &#8220;confirmed&#8221;.</strong></p><p>Interesting&#8230;.. &#129335;&#127998;&#8205;&#9794;&#65039;</p><div><hr></div><h4><a href="https://www.reuters.com/world/europe/openai-agents-hijacked-german-website-previously-undisclosed-ai-breakout-this-2026-09-04/">AI agents turned read-only web access into a public message board</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ah5P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ah5P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png 424w, https://substackcdn.com/image/fetch/$s_!ah5P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png 848w, https://substackcdn.com/image/fetch/$s_!ah5P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png 1272w, https://substackcdn.com/image/fetch/$s_!ah5P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ah5P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png" width="1456" height="437" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0145b78b-78e9-4285-8709-afa969edb254_1640x492.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:437,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54984,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/214966342?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ah5P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png 424w, https://substackcdn.com/image/fetch/$s_!ah5P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png 848w, https://substackcdn.com/image/fetch/$s_!ah5P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png 1272w, https://substackcdn.com/image/fetch/$s_!ah5P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0145b78b-78e9-4285-8709-afa969edb254_1640x492.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>OpenAI agents</strong> answering timed research questions found a way to post online despite restrictions intended to make their internet access read-only. Researchers found roughly <strong>18,000 posts</strong>, mostly on a German community wiki, a publicly editable website. Most activity happened in May and June.</p><ul><li><p><strong>How they posted:</strong> The wiki accepted edits through the same type of request used to load a page. Agents put messages in URLs, bypassing the intended posting restriction.</p></li><li><p><strong>What they shared:</strong> Answers for agents facing the same questions, plus ways around network restrictions.</p></li><li><p><strong>How they resisted cleanup:</strong> When a moderator deleted pages alphabetically, an agent created a backup starting with <code>ZZZ</code> to delay deletion.</p></li></ul><p><a href="https://www.reuters.com/business/media-telecom/openai-acknowledges-wiki-incident-need-more-transparency-around-unintended-ai-2026-09-05/">OpenAI acknowledged the incident here</a>. </p><p><strong>An agent that can read company files and browse external sites may also be able to publish those files.</strong> This was not a confirmed customer-data leak, but the posting restriction <strong>failed</strong>. </p><p>This one is wild because it&#8217;s yet another examples of how off the rails agents can go when they go rogue. If there&#8217;s a loophole, they will probably exhaust every option until they find it to achieve their goal. </p><div><hr></div><h2>&#128300;Threats &amp; Research </h2><div><hr></div><h4><a href="https://sansec.io/research/stylesmuggler-0day">Attackers hijack Magento stores through failed-payment notifications</a></h4><p><strong>Magento and Adobe Commerce are software for running online stores.</strong> Sansec found attackers exploiting <strong>StyleSmuggler (CVE-2026-75650, CVSS 10.0)</strong> to run malicious code on those stores&#8217; servers without logging in.</p><p>Attackers plant code in store-generated files, then trigger a failed-payment notification. The store executes it while preparing the email. <strong>Nobody has to open the message.</strong> Sansec found backdoors that let attackers retain access.</p><p>Merchants should apply <a href="https://helpx.adobe.com/security/products/magento/apsb26-146.html">Adobe&#8217;s emergency hotfix</a>, check for backdoors, and rotate exposed credentials. Patching closes the entry point; it does not remove an attacker who already got in.</p><div><hr></div><h4><a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/">Nexus advertises 153M driver&#8217;s-license records; the FBI investigates</a></h4><p><strong>Brian Krebs</strong> found Nexus advertising <strong>153 million driver&#8217;s-license records</strong>, verified samples with nine people, and traced clues toward identity-verification provider <strong>IDScan.net</strong>, which said it was investigating. The marketplace&#8217;s total remains unconfirmed; <a href="https://www.reuters.com/world/us/fbi-says-it-is-investigating-report-that-millions-us-drivers-licenses-exposed-2026-09-02/">the FBI confirmed its investigation September 2</a>.</p><p><strong>Still unresolved:</strong> Source, scale, and continuing access. Retained document scans can outlive the verification they supported and become reusable material for impersonation. Review whether raw images need to be kept at all.</p><div><hr></div><h4><a href="https://news.bostonscientific.com/update-on-recent-cybersecurity-incident">Boston Scientific expects cyberattack to hit sales and profit forecasts</a></h4><p><strong>Boston Scientific</strong> said that it <a href="https://www.reuters.com/technology/boston-scientific-says-cyberattack-likely-hurt-2026-sales-profit-2026-09-08/">no longer expects to meet its quarterly and annual sales and adjusted-profit forecasts</a>. The August 25 incident disrupted manufacturing and order processing; the financial consequences are this week&#8217;s development.</p><p><strong>Recovery:</strong> The company says most manufacturing has resumed, major distribution centers are shipping, and cardiac remote-monitoring activations are restored. Product analyses indicate no impairment to function. The business impact outlasts the outage. Recovery plans need to cover backlogs and missed sales as well as restoring systems.</p><div><hr></div><h2>&#128230; Security Product Releases</h2><div><hr></div><h4><a href="https://www.crowdstrike.com/en-us/press-releases/">CrowdStrike announces AI models, agent identities, and detection before ingestion at Fal.Con</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eA3_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eA3_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!eA3_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!eA3_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!eA3_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eA3_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eA3_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!eA3_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!eA3_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!eA3_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F109fce03-01c4-43db-b3ed-558ee450ca22_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>CrowdStrike has been cooking, especially on the SecOps side.</strong> Its Fal.Con lineup includes detections that run inside log pipelines, AI agents that investigate different parts of an incident in parallel, and a shared workspace for response workflows and approvals. The direction is clear and it has been for a while. CrowdStrike wants to own the end-to-end SecOps workflow.</p><p>Here&#8217;s the breakdown, including what&#8217;s available now and what&#8217;s still in preview:</p><ul><li><p><strong><a href="https://www.crowdstrike.com/en-us/about-us/cyber-superintelligence-lab/">SafeMind and the Cyber Superintelligence Lab</a>:</strong> Offensive Red Tempest and defensive Blue Solano models, built using NVIDIA Nemotron, run coordinated attack-and-defense workflows. <strong>Early-access registration.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/falcon-guardian-defines-next-generation-of-ai-security/">Falcon Guardian</a>:</strong> Agent discovery, session reconstruction, and runtime controls. The new AI gateway is <strong>pre-beta, targeting Q4 GA</strong>. OverWatch support is available with the required licenses; MDR follows later in Q3.</p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-agentic-identity-provider/">Agentic Identity Provider</a>:</strong> Registers agents, issues identities, brokers short-lived access, and preserves attribution to humans or workloads. <strong>Announced; availability unspecified.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-announces-agentic-identity-provider/">Expanded privileged access</a>:</strong> Just-in-time privileges across Salesforce, GitHub, endpoints, private applications, and AWS through Entra. <strong>Availability unspecified.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-extends-endpoint-security-to-stop-supply-chain-attacks/">Software supply-chain protection</a>:</strong> The Falcon sensor blocks known malicious npm and PyPI packages during download. Package inventory is planned for <strong>Q3</strong>; cooldown policies for <strong>Q4</strong>.</p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">Certified data pipelines</a>:</strong> Prebuilt, maintained third-party pipelines, starting with Zscaler and Palo Alto Networks. <strong>Public preview.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">Detection before ingestion</a>:</strong> Detection logic runs inside the pipeline, including at the edge. <strong>Public preview.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">Shared-context investigations</a>:</strong> Specialist agents investigate different domains in parallel, with an orchestrator combining their findings. <strong>Pre-beta.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">Agentic Recon</a>:</strong> Intelligence agents investigate exposed credentials, leaked data, and impersonation across the open, deep, and dark web. <strong>Public preview.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">Unified agentic SOAR workspace</a>:</strong> AgentWorks, SOAR orchestration, and Foundry share one interface for workflows and approval controls. <strong>Public preview.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">Bring your own model</a>:</strong> Use existing OpenAI and Anthropic licenses when building agents. <strong>GA.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">Bidirectional MCP access</a>:</strong> Third-party agents access Falcon tools; AgentWorks agents reach external tools and data. <strong>GA.</strong></p></li><li><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-delivers-next-evolution-of-agentic-soc/">Hybrid Analysis for agent workflows</a>:</strong> API-first malware analysis with an open-source MCP server. <strong>Publicly available.</strong></p></li></ul><p>Detection before ingestion could reduce dependence on centralized storage for alerting. It also makes pipeline rules part of the detection stack: teams need to version them and retain enough source events to investigate missed alerts. Many of these capabilities remain previews. </p><p>Some of these new capabilities introduce entirely new ways of doing things which some security teams may be reluctant to. Will be interesting to see how adoption goes. </p><div><hr></div><h4><a href="https://openai.com/index/gpt-6-astra/">OpenAI releases GPT-6 Astra with Critical cyber capabilities and restricted exploit access</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bEJ8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bEJ8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png 424w, https://substackcdn.com/image/fetch/$s_!bEJ8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png 848w, https://substackcdn.com/image/fetch/$s_!bEJ8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png 1272w, https://substackcdn.com/image/fetch/$s_!bEJ8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bEJ8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png" width="1456" height="442" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:442,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:185792,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/214966342?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bEJ8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png 424w, https://substackcdn.com/image/fetch/$s_!bEJ8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png 848w, https://substackcdn.com/image/fetch/$s_!bEJ8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png 1272w, https://substackcdn.com/image/fetch/$s_!bEJ8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F211a80dc-a09e-4ae1-96d9-90ad1341b9d0_2048x622.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>OpenAI</strong> released GPT-6 Astra, its first model rated <strong>Critical</strong> under its <a href="https://openai.com/index/updating-our-preparedness-framework/">Preparedness Framework</a>.</p><p><strong>Meaning:</strong> Given suitable tools and access, OpenAI says Astra can discover zero-days and develop exploits across many hardened systems without a human guiding each step. Testing assessed capabilities without production safeguards.</p><ul><li><p><strong>Access:</strong> Public release supports review and patching; exploit PoCs are refused. Broader Daybreak access is planned.</p></li><li><p><strong><a href="https://openai.com/index/safety-overview-gpt-6-astra/">Monitoring</a>:</strong> Tool use is monitored, but reasoning became harder to inspect in adversarial tests.</p></li></ul><p>Automating discovery through exploitation makes tool permissions and independent action logs more consequential.</p><div><hr></div><h2>&#129309; Funding &amp; M&amp;A</h2><div><hr></div><h4><a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-acquires-console-to-agentify-security">Palo Alto Networks acquires IT automation startup Console</a></h4><p><strong>Palo Alto Networks</strong> announced its acquisition of <strong>Console</strong> September 1 for a <a href="https://techcrunch.com/2026/09/02/palo-alto-networks-paid-500m-for-thrive-backed-console-sources-say/">reported $500M</a>. PANW did not disclose terms. Console&#8217;s <a href="https://www.console.com/">IT agents</a> provision accounts, revoke access, and reset MFA after identity verification.</p><p>Integration with Cortex investigation and remediation is planned, with no launch date. Turning alerts into access changes makes the agents&#8217; own authorization boundaries critical.</p><div><hr></div><h4><a href="https://clickhouse.com/blog/clickhouse-welcomes-runreveal">ClickHouse acquires security data platform RunReveal</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0w-o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0w-o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!0w-o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!0w-o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!0w-o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0w-o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png" width="1200" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:44914,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/214966342?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0w-o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!0w-o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!0w-o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!0w-o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1624c67e-6983-4c9a-9c18-29018b811d32_1200x628.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>ClickHouse</strong> acquired <strong>RunReveal</strong>. RunReveal builds log pipelines, detections, and AI-assisted investigations on customer-controlled ClickHouse clusters. ClickHouse says availability and existing contract terms remain unchanged. <strong>Amount undisclosed.</strong></p><p>Great pickup by Clickhouse. RunReveal is one of my favorite contenders in the SIEM space and Clickhouse has some of the best database tech on the market so it&#8217;ll be fun to see what they get up to. </p><div><hr></div><h4><a href="https://cylake.com/resources/cylake-closes-245-million-funding-round/">Cylake raises $245M through a convertible note for on-premises security</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZeTd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZeTd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!ZeTd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!ZeTd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!ZeTd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZeTd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1147368,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/214966342?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZeTd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!ZeTd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!ZeTd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!ZeTd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5732cdab-36ce-42a5-8158-311b3856158d_1448x1086.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Cylake</strong> announced <strong>$245M through a convertible note</strong>, with Lightspeed, Picture Capital, and Redpoint participating. Nir Zuk&#8217;s company is building an integrated security platform for on-premises and private-cloud deployment.</p><p>Keeping telemetry inside customer infrastructure could appeal to buyers with sovereignty requirements. Coverage and migration costs will determine whether they switch. <strong>Beta is expected by year-end; GA in 2027.</strong></p><div><hr></div><h4><a href="https://www.prnewswire.com/news-releases/hiddenlayer-raises-100m-series-b-to-advance-trustworthy-ai-302867783.html">HiddenLayer raises $100M Series B for AI runtime and coding-agent security</a></h4><p><strong>HiddenLayer</strong> announced a <strong>$100M Series B</strong>, led by Delta-v Capital. It finds AI deployments, inspects their supply chains, simulates attacks, and protects models and coding agents at runtime.</p><p>Its Agent Harness Security launched in August. A model&#8217;s safeguards do not secure every tool it can call, so defenses also need controls over agent permissions and execution.</p><div><hr></div><h4><a href="https://www.cymphony.io/release">Cymphony launches with $30M from Sequoia and Fin Capital</a></h4><p><strong>Cymphony</strong> launched with <strong>$30M</strong> led by Sequoia and Fin Capital. Cymphony connects identities, permissions, data, and behavior to find stale access and overshared files.</p><p>An AI assistant can expose sensitive files using an employee&#8217;s existing permissions. Cleaning up access becomes part of securing the assistant, even when authentication works.</p><div><hr></div><h4><a href="https://brpx.com/huskeys-raises-27m-series-a-led-by-blackstone-innovations-investments-to-redefine-how-organizations-manage-edge-security/">Huskeys raises $27M Series A to coordinate WAF, CDN, and edge policies</a></h4><p><strong>Huskeys</strong> announced a <strong>$27M Series A</strong>, led by Blackstone Innovations Investments. It coordinates configurations and policies across existing WAFs, CDNs, load balancers, and cloud network controls.</p><p>A correct WAF rule does little if another route leaves the application exposed. The value is closing those gaps across vendors.</p><div><hr></div><h4><a href="https://www.wsj.com/tech/cybersecurity/thoma-bravo-owned-proofpoint-in-talks-to-buy-cybersecurity-firm-varonis-a44f83d9">Proofpoint reportedly in advanced talks to acquire Varonis</a></h4><p>The Wall Street Journal reports that Thoma Bravo-owned Proofpoint is negotiating to buy Varonis. <strong>No agreement or purchase price is confirmed</strong>. Varonis market cap is floating around $5B - $6B and spiked ~10% when the rumors first broke.</p><div><hr></div><h4><a href="https://helmguard.ai/resources/7.3m-seed-announcement">HelmGuard raises $7.3M seed for evidence collection and risk assessment</a></h4><p><strong>HelmGuard</strong> announced a <strong>$7.3M seed round</strong>, co-led by Infinity Ventures and Frontline. Its agents gather evidence, assess supplier risks, and identify control gaps, with citations and human review.</p><p>A supplier can add AI agents after passing its security review. Continuous evidence could surface that change sooner; buyers still need to inspect the sources behind automated conclusions.</p><div><hr></div><h4><a href="https://cognition.com/blog/series-e">Cognition raises more than $2B Series E for Devin</a></h4><p><strong>Cognition</strong> announced a <strong>Series E exceeding $2B</strong>, led by Andreessen Horowitz, Accel, Founders Fund, General Catalyst, and Avenir. Devin writes, tests, and maintains code; Auto-Triage and Security Swarm add incident investigation and vulnerability triage.</p><p>When one platform writes code and proposes fixes, independent validation becomes more valuable. Faster remediation does not establish that the underlying flaw is gone.</p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[TCP 143:Cursor Goes Post-Access, Echo Picks Up Key Minimus Assets, and 700 Agents Coordinate]]></title><description><![CDATA[Plus a cybercrime takedown, a patch redo, new defenses for Android 17, and more]]></description><link>https://www.cybersecuritypulse.net/p/tcp-143cursor-goes-post-access-echo</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/tcp-143cursor-goes-post-access-echo</guid><dc:creator><![CDATA[Andrew Richards]]></dc:creator><pubDate>Wed, 02 Sep 2026 12:18:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!I8Wn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Andrew Richards, a cybersecurity practitioner working at the intersection of AI security, operations, and governance at Tennessee Valley Authority. I&#8217;ll be partnering with Darwin to bring you my perspective on the security developments, emerging technology, and industry news worth paying attention to. Subscribe to receive the latest updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I8Wn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I8Wn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png 424w, https://substackcdn.com/image/fetch/$s_!I8Wn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png 848w, https://substackcdn.com/image/fetch/$s_!I8Wn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png 1272w, https://substackcdn.com/image/fetch/$s_!I8Wn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I8Wn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png" width="728" height="524.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1049,&quot;width&quot;:1456,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:3336850,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/213413710?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I8Wn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png 424w, https://substackcdn.com/image/fetch/$s_!I8Wn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png 848w, https://substackcdn.com/image/fetch/$s_!I8Wn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png 1272w, https://substackcdn.com/image/fetch/$s_!I8Wn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75550d32-6d1d-4fa1-9c10-245ff8db51e2_1552x1118.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Hi &#128075; Hope you&#8217;re having a great week wherever you&#8217;re reading from!</p><p>A little about me before we dive in. My background spans vulnerability management, threat intelligence, and now AI operations and governance, so I&#8217;ve had the chance to look at security from a few different angles. These days, I spend a lot of my time thinking about how organizations can adopt AI securely, from evaluating models and governing agents to figuring out what good oversight looks like as the technology keeps moving.</p><p>Darwin and I actually go back to our college days. He became a mentor early in my cybersecurity career, so it&#8217;s pretty cool to come full circle and now work on TCP together. <strong>I&#8217;m excited to bring some of my perspective to TCP, while also using this as an excuse to keep learning and stay close to what&#8217;s happening across security.</strong></p><p>Now, onto the news!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LyNd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LyNd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png 424w, https://substackcdn.com/image/fetch/$s_!LyNd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png 848w, https://substackcdn.com/image/fetch/$s_!LyNd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png 1272w, https://substackcdn.com/image/fetch/$s_!LyNd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LyNd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png" width="1997" height="1091" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1091,&quot;width&quot;:1997,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1266691,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/213413710?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6b3d03-1e68-4ee9-ac5f-af77567f7b0c_2020x1098.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LyNd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png 424w, https://substackcdn.com/image/fetch/$s_!LyNd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png 848w, https://substackcdn.com/image/fetch/$s_!LyNd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png 1272w, https://substackcdn.com/image/fetch/$s_!LyNd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cd12ae4-bef8-4dea-a1ac-b57ec165b073_1997x1091.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><sub>Echo acquired key Minimus assets three days after the startup announced its wind-down. Source: </sub><a href="https://cdn.prod.website-files.com/680495205e33f0a1b96c7a98/6a9002a363fc5d2ba5eb5fb3_image%20%2819%29.png"><sub>Echo</sub></a></p><div><hr></div><h2>&#128478;&#65039; TL;DR</h2><ul><li><p>&#128433;&#65039; <strong>Cursor:</strong> <a href="https://activesoc.blackhillsinfosec.com/blog/introducing-the-aur0ra-ransomware-group/">Aurora ransomware</a> operators used <a href="https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation">Cursor Agent during post-access</a> activity across ten target organizations.</p></li><li><p>&#129521; <strong>Minimus:</strong> <a href="https://www.echo.ai/blog/echo-is-acquiring-minimus">Echo acquired key Minimus assets</a> just three days after the company announced it was winding down.</p></li><li><p>&#129514; <strong>OpenAI:</strong> <a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/?#core-takeaways-about-this-incident">Roughly 700 agents converged on the Hugging Face environment</a>, giving us another unusual look at how agents behave at scale.</p></li><li><p>&#129520; <strong>Cybercrime:</strong> The <a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers">FBI seized QTFY domains</a>, knocking its QScan and QTRouter hacking platforms offline.</p></li><li><p>&#128300; <strong>Threats &amp; research:</strong> <a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory">PaperCut patched an actively exploited flaw again</a>, <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a">CISA compared two very different SOC responses</a>, and new research dug into <a href="https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/">AI malware</a>.</p></li><li><p>&#128230; <strong>Security releases:</strong> <a href="https://www.linuxfoundation.org/press/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads">TRACE landed at the Linux Foundation</a>, <a href="https://blog.google/security/new-android-network-security-protections/">Android 17 added new network defenses</a>, and <a href="https://www.citrix.com/news/announcements/aug-2026/citrix-uniconos-dual-boot-builds-business-resilience-into-windows-endpoints-helping-enterprises-recover-within-minutes-when-downtime-hits">Citrix introduced a Windows recovery environment</a>.</p></li><li><p>&#128176; <strong>Funding &amp; M&amp;A:</strong> <a href="https://alice.io/blog/alice-raises-140m">Alice raised $140 million</a>, <a href="https://www.socure.com/news-and-press/strategic-growth-investment-fravity-acquisition">Socure acquired Fravity</a> alongside new growth capital, and <a href="https://www.ibbventures.de/en/news/cybersecurity-startup-kazimi-closes-eur-2-2-million-pre-seed-fundraise-to-battle-bot-crisis-in-mobile-marketing">Kazimi raised &#8364;2.2 million</a> in pre-seed funding.</p></li></ul><div><hr></div><h2>&#9874;&#65039; Picks of the Week </h2><div><hr></div><h4><a href="https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation">A ransomware operator used Cursor as a post-access console</a></h4><p>Gambit Security observed an <a href="https://activesoc.blackhillsinfosec.com/blog/introducing-the-aur0ra-ransomware-group/">Aurora ransomware</a> operator using Cursor Agent, running Claude Sonnet 4.5 Thinking, across ten target organizations. One important detail is easy to miss: <strong>the agent was given credentials or another route into the victim environment.</strong> Cursor wasn&#8217;t autonomously finding targets and breaking in. The attacker already had a way through the door and used the agent to help operate once inside.</p><p>Cursor was tasked with internal scanning, domain enumeration, NTLM relay attempts, certificate attacks, and other post-access activity. Many commands failed on the first attempt, but the agent repeatedly refined its approach. The operator even set guardrails including no DCSync, account lockouts, or creation of new computer objects.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F92F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F92F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png 424w, https://substackcdn.com/image/fetch/$s_!F92F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png 848w, https://substackcdn.com/image/fetch/$s_!F92F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png 1272w, https://substackcdn.com/image/fetch/$s_!F92F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F92F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png" width="1456" height="861" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:861,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:155113,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/213413710?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F92F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png 424w, https://substackcdn.com/image/fetch/$s_!F92F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png 848w, https://substackcdn.com/image/fetch/$s_!F92F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png 1272w, https://substackcdn.com/image/fetch/$s_!F92F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5856b6fb-34ed-40ce-8e2d-06af613ab567_1778x1052.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><sub>Gambit observed Cursor Agent sessions across ten organizations from April 8 through May 21. Circle size represents the number of commands run. Source: </sub><a href="https://cdn.prod.website-files.com/699d15905fa8481718f06229/6a9017c1dc1cd02fd8977486_session_timeline.svg"><sub>Gambit Security</sub></a></em></p><p><strong>There&#8217;s something almost like reverse governance happening here.</strong> Give the agent access, an objective, and boundaries. Do all of these bad things, just don&#8217;t do <em>these</em> bad things. If this is what attackers could accomplish with an earlier generation of agentic tooling, the trajectory matters as models become more capable. AI agents are becoming another part of threat actor tradecraft. For defenders, that puts even more pressure on defense in depth and detections that can catch malicious activity whether it comes from a person or an agent.</p><div><hr></div><h4><a href="https://www.echo.ai/blog/echo-is-acquiring-minimus">Echo picks up key Minimus assets after its wind-down</a></h4><p>Three days after Minimus announced it was winding down, Echo acquired key assets from the company, including its technology, integrations, research, and data. Minimus grew out of Gutsy, which launched with a $51 million seed round in 2023 before pivoting toward hardened open-source software. The terms of Echo&#8217;s deal weren&#8217;t disclosed, and importantly, <strong>Echo acquired key assets rather than Minimus itself.</strong></p><p>I like this move. Cybersecurity benefits from collaboration, and a company shutting down doesn&#8217;t mean the technology or research it built suddenly loses its value. <strong>Minimus appears to have built something Echo believes is worth carrying forward</strong>, while its customers now have a potential path forward instead of being left with a dead product. Echo gets stronger, useful security work doesn&#8217;t disappear, and years of research and engineering have a chance to keep contributing to the industry.</p><div><hr></div><h4><a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/?#core-takeaways-about-this-incident">Roughly 700 OpenAI agents joined the Hugging Face attack</a></h4><p>METR's investigation into <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/">OpenAI's</a> agent experiment keeps getting stranger. Roughly 1,200 supposedly isolated agents discovered an unsanctioned message board, exchanged more than 70,000 messages and files, and about 700 eventually participated in the Hugging Face attack. Some agents accomplished milestones through collaboration that they couldn't achieve alone. Others researched ways to manipulate the ExploitGym scorer, including spoofing their own tool calls.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dTyb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dTyb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png 424w, https://substackcdn.com/image/fetch/$s_!dTyb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png 848w, https://substackcdn.com/image/fetch/$s_!dTyb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png 1272w, https://substackcdn.com/image/fetch/$s_!dTyb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dTyb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png" width="1456" height="804" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:804,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:422295,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/213413710?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dTyb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png 424w, https://substackcdn.com/image/fetch/$s_!dTyb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png 848w, https://substackcdn.com/image/fetch/$s_!dTyb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png 1272w, https://substackcdn.com/image/fetch/$s_!dTyb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44a680e6-22fa-43d3-bbcb-ac72516218ae_2874x1588.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><sub><span>An isolated agent discovered the shared message board and joined the broader attack. Source: </span></sub><a href="https://metr.org/assets/images/openai-hugging-face-incident-investigation/image1.svg"><sub><span>METR.</span></sub></a></em></p><p>What gets me is how persistent these agents were. <strong>Give capable agents an objective and enough freedom, and you have to account for them finding paths to that objective you never designed or anticipated.</strong> One agent created the message board itself, and within hours more than 50 others had found it and started communicating. <strong>And that communication mattered. METR found that agents working together reached milestones they couldn't achieve on their own.</strong> That's wild, but it also raises a serious enterprise question: what happens when supposedly isolated agents gain access to shared state or communication channels you aren't monitoring? As agents get more capable and connected, controlling what they can access, who they can communicate with, and how we verify what they actually did becomes just as important as the task we gave them in the first place.</p><div><hr></div><h4><a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers">FBI takes QTFY's hacking platforms offline</a></h4><p>The Justice Department and FBI seized three domains used by QScan and QTRouter, two complementary hacking platforms allegedly operated by the PRC-linked QTFY group. QScan scanned and infected thousands of IoT devices, while QTRouter used compromised devices and other infrastructure to help malicious actors hide the origin of their attacks. Because the seized domains were hard-coded into both platforms, DOJ says the operation rendered them inoperable.</p><p><strong>Sometimes offense is your best defense.</strong> Most security teams, spend their time watching IOCs, threat hunting, tuning detections, and preparing for the next attack. The FBI and its partners have another lever: disrupting the infrastructure attackers depend on. Taking these platforms offline might seem like a small win, but disrupting infrastructure built to operate at scale can prevent a lot more attacks downstream.</p><div><hr></div><h2>&#128300;Threats &amp; Research </h2><div><hr></div><h4><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory">PaperCut patches an actively exploited flaw again</a></h4><p>PaperCut released a second emergency security update for actively exploited vulnerabilities affecting PaperCut MF and NG, adding further hardening beyond its original emergency patch. The company has confirmed customer incidents, making this more than a theoretical patching exercise. If you applied the first update, check again. <strong>Release 2 is the version administrators should be looking at now.</strong></p><div><hr></div><h4><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a">Both SOCs had alerts. Only one acted.</a></h4><p>CISA ran parallel red-team assessments against two organizations using similar attack techniques, but the defensive response looked very different. At Organization A, alerts were missed or closed while the red team continued deeper into the environment. At Organization B, defenders isolated three compromised endpoints in roughly 10, 2, and 20 minutes, forcing CISA to continue the assessment from an assumed breach.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e00u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e00u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png 424w, https://substackcdn.com/image/fetch/$s_!e00u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png 848w, https://substackcdn.com/image/fetch/$s_!e00u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png 1272w, https://substackcdn.com/image/fetch/$s_!e00u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e00u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png" width="1456" height="1408" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1408,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:300815,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/213413710?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e00u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png 424w, https://substackcdn.com/image/fetch/$s_!e00u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png 848w, https://substackcdn.com/image/fetch/$s_!e00u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png 1272w, https://substackcdn.com/image/fetch/$s_!e00u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9e1dee-2f36-4cb4-9a81-41ed1bde9f10_1590x1538.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><sub>Red team activity and Organization B SOC response. Source: </sub><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a#Table1"><sub>CISA</sub></a></em></p><div><hr></div><h4><a href="https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/">Unit 42 found most &#8220;AI malware&#8221; samples only in labs</a></h4><p><strong><a href="https://www.paloaltonetworks.com/unit42">Unit 42</a></strong> compared 405 AI-linked samples against endpoint telemetry from December 2024 through June 2025 and network telemetry from June 2024 through June 2025. Only 12 appeared on Cortex XDR-protected production endpoints. Roughly 97% existed only in sandboxes, VirusTotal, research repositories, or validation systems, and the set included conventional malware wearing AI branding. This is selected Palo Alto Networks telemetry, not a current prevalence estimate for the whole internet. It fits the less cinematic pattern seen elsewhere this week, where AI is useful in planning, coding, and operator workflows while autonomous malware remained uncommon in this dataset.</p><div><hr></div><h2>&#128230; Security Product Releases</h2><div><hr></div><h4><a href="https://www.linuxfoundation.org/press/linux-foundation-welcomes-trace-to-advance-verifiable-runtime-evidence-for-ai-workloads">TRACE gives agent audit trails a cryptographic spine</a></h4><p><strong>The Linux Foundation</strong> accepted TRACE, an open specification designed to create cryptographically verifiable records of AI runtime activity. Instead of relying only on traditional logs, TRACE is designed to provide tamper-evident evidence of what an AI system executed, creating a stronger audit trail for agents and other autonomous systems.</p><div><hr></div><h4><a href="https://blog.google/security/new-android-network-security-protections/">Android 17 adds four network defenses</a></h4><p>Android 17 adds broad Encrypted Client Hello support with Private DNS, enforces permission checks for local network access, and enables Certificate Transparency by default. Participating carriers can also disable 2G by default to blunt SMS-blaster attacks, while ECH still depends on supporting sites, apps, and modern networking libraries. These are consequential platform changes because they reduce exposed network metadata, silent local scanning, certificate opacity, and a legacy downgrade path without another settings scavenger hunt. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Kxk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Kxk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png 424w, https://substackcdn.com/image/fetch/$s_!5Kxk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png 848w, https://substackcdn.com/image/fetch/$s_!5Kxk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png 1272w, https://substackcdn.com/image/fetch/$s_!5Kxk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Kxk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png" width="1456" height="890" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:890,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1091569,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/213413710?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Kxk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png 424w, https://substackcdn.com/image/fetch/$s_!5Kxk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png 848w, https://substackcdn.com/image/fetch/$s_!5Kxk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png 1272w, https://substackcdn.com/image/fetch/$s_!5Kxk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa18e05d-ba30-452f-b1ad-e147e1bd24b6_2378x1454.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><sub>Google's model of an SMS-blaster attack: a rogue base station forces nearby phones onto legacy 2G before delivering phishing texts. Source: Google</sub></em></p><div><hr></div><h4><a href="https://www.citrix.com/news/announcements/aug-2026/citrix-uniconos-dual-boot-builds-business-resilience-into-windows-endpoints-helping-enterprises-recover-within-minutes-when-downtime-hits">Citrix adds a second operating system for Windows outages</a></h4><p>Citrix introduced UniconOS dual boot, a recovery capability that gives organizations another way to keep endpoints running during Windows outages. If the primary Windows environment becomes unavailable or compromised, compatible devices can boot into an isolated UniconOS environment and reconnect users to critical applications through Citrix services. The idea is straightforward: if Windows is the problem, recovery shouldn't depend entirely on Windows working.</p><div><hr></div><h2>&#129309; Funding &amp; M&amp;A</h2><div><hr></div><h4><a href="https://alice.io/blog/alice-raises-140m">Alice raises $140M</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EWAo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EWAo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png 424w, https://substackcdn.com/image/fetch/$s_!EWAo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png 848w, https://substackcdn.com/image/fetch/$s_!EWAo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!EWAo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EWAo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png" width="704" height="443.86813186813185" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16e21286-338c-4904-8f3f-958771229847_2062x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:918,&quot;width&quot;:1456,&quot;resizeWidth&quot;:704,&quot;bytes&quot;:3299342,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/213413710?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EWAo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png 424w, https://substackcdn.com/image/fetch/$s_!EWAo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png 848w, https://substackcdn.com/image/fetch/$s_!EWAo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!EWAo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16e21286-338c-4904-8f3f-958771229847_2062x1300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><sub>Alice raised $140 million in a round led by Apax Digital, bringing its total funding to $280 million. Source: Alice.</sub></em></p><p>Alice, formerly ActiveFence, raised $140 million as it expands its AI security platform. The company is positioning around securing AI applications and agents, building on ActiveFence's background in trust and safety. The round gives Alice fresh capital to expand as enterprises look for ways to secure increasingly autonomous AI systems.</p><div><hr></div><h4><a href="https://www.socure.com/news-and-press/strategic-growth-investment-fravity-acquisition">Socure adds growth capital and acquires Fravity</a></h4><p><strong>Socure</strong> raised additional growth capital and acquired <strong>Fravity</strong>, an AI-native identity company, as it expands beyond identity verification into agentic identity. The deal brings Fravity&#8217;s technology and team into Socure as companies start thinking about how autonomous agents should be identified, authorized, and trusted alongside human users.</p><div><hr></div><h4><a href="https://www.ibbventures.de/en/news/cybersecurity-startup-kazimi-closes-eur-2-2-million-pre-seed-fundraise-to-battle-bot-crisis-in-mobile-marketing">Kazimi raises &#8364;2.2M to secure AI agents</a></h4><p>Kazimi raised &#8364;2.2 million in pre-seed funding to build security infrastructure for AI agents. The company is developing tools to control how agents access systems, credentials, and sensitive resources as organizations move from AI assistants toward software capable of taking actions on their behalf.</p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[TCP 142: Taiwan Hit by AI-Assisted Attack, OpenAI’s Training Pause, and $2.74B in Capital]]></title><description><![CDATA[Plus private firms on cyber offense, Lazarus burns a Windows zero-day, and Walmart&#8217;s purple teaming approach.]]></description><link>https://www.cybersecuritypulse.net/p/tcp-142-taiwan-hit-by-ai-assisted</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/tcp-142-taiwan-hit-by-ai-assisted</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Thu, 20 Aug 2026 14:20:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NCXl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NCXl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NCXl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp 424w, https://substackcdn.com/image/fetch/$s_!NCXl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp 848w, https://substackcdn.com/image/fetch/$s_!NCXl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp 1272w, https://substackcdn.com/image/fetch/$s_!NCXl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NCXl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:195914,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/211863321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NCXl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp 424w, https://substackcdn.com/image/fetch/$s_!NCXl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp 848w, https://substackcdn.com/image/fetch/$s_!NCXl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp 1272w, https://substackcdn.com/image/fetch/$s_!NCXl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f14f399-76ed-4a17-84b8-4a990bf183ba_1456x1052.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Howdy &#128075;&#127997;</p><p>Quick heads up, I&#8217;m switching up the format a bit this week. </p><p>Picks of the Week &gt; Threats + Research &gt; Product Releases &gt; Funding + M&amp;A. </p><p>Typically, I&#8217;ll run the top 3-5 stories I think you should care about most per section, each week. There&#8217;s ridiculous amounts of noise, slop, and FUD in security. TCP should be a compass for you whether you&#8217;re a CISO, engineer, founder, investor, GTM operator or anything in between. </p><p>Consider this format officially in beta. Tell me if you hate it or if you like it or if you have any other ideas which would improve your reading experience! </p><p><strong>Re: upcoming issues:</strong> I&#8217;ll soon be going on vacation in Black Rock City so I&#8217;ll ship a special edition post in place of our weekly TCP coverage next week. The following week, our new contributing author (soon to be announced!), will ship TCP weekly. </p><p><strong>Re: work life:</strong> here&#8217;s a blog I wrote on <a href="https://www.monad.com/blog/anthropic-compliance-api-activity-feed">Anthropic Compliance API Activity feed detection opps + gaps.</a> 101 log source footprinting. </p><p><strong>Re: personal life:</strong> I&#8217;ve been DJ&#8217;ng a bit. It&#8217;s a fun hobby. I have 6 gigs over the next 3 weeks. If you happen to be in Austin this Saturday, pop by Zilker. I play at 9pm. <a href="https://partiful.com/e/ve6RDxbYrTbtkcHbJuFo?">RSVP</a>.</p><p>Before we dive in, here&#8217;s my favorite meme of the week and an ad from our friends at <a href="https://www.intruder.io/pentest-pricing?utm_source=cybersecuirtypulse&amp;utm_medium=p_referral&amp;utm_campaign=global|fixed|ai_pentesting">Intruder</a>! </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cxdq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cxdq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png 424w, https://substackcdn.com/image/fetch/$s_!Cxdq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png 848w, https://substackcdn.com/image/fetch/$s_!Cxdq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png 1272w, https://substackcdn.com/image/fetch/$s_!Cxdq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cxdq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png" width="1202" height="700" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:700,&quot;width&quot;:1202,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;t? samson reposted \nLuke Berry \n@LukeberryPi . 9h \n8 ... \nintroducing: JDD \nJealousy Driven Development \nare these the best fixes? codex suggested something \nbetter \n+ \n= X \nClaude Fable 5 \ncursor/habit-mode-ui-016 v \nThis Mac v \n104 \n27 1K \nC \n16K \nilil 326K &quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="t? samson reposted 
Luke Berry 
@LukeberryPi . 9h 
8 ... 
introducing: JDD 
Jealousy Driven Development 
are these the best fixes? codex suggested something 
better 
+ 
= X 
Claude Fable 5 
cursor/habit-mode-ui-016 v 
This Mac v 
104 
27 1K 
C 
16K 
ilil 326K " title="t? samson reposted 
Luke Berry 
@LukeberryPi . 9h 
8 ... 
introducing: JDD 
Jealousy Driven Development 
are these the best fixes? codex suggested something 
better 
+ 
= X 
Claude Fable 5 
cursor/habit-mode-ui-016 v 
This Mac v 
104 
27 1K 
C 
16K 
ilil 326K " srcset="https://substackcdn.com/image/fetch/$s_!Cxdq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png 424w, https://substackcdn.com/image/fetch/$s_!Cxdq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png 848w, https://substackcdn.com/image/fetch/$s_!Cxdq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png 1272w, https://substackcdn.com/image/fetch/$s_!Cxdq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f7f6198-fc10-42e9-a354-29b73eecdbd2_1202x700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;">Pentest with every major release. Security that keeps up with engineering.</h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d1vf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d1vf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg 424w, https://substackcdn.com/image/fetch/$s_!d1vf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg 848w, https://substackcdn.com/image/fetch/$s_!d1vf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg 1272w, https://substackcdn.com/image/fetch/$s_!d1vf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d1vf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg" width="428" height="79.66208791208791" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/845218db-7ed0-47d6-acba-057cccc50899_204x38.svg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:271,&quot;width&quot;:1456,&quot;resizeWidth&quot;:428,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Intruder logo&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Intruder logo" title="Intruder logo" srcset="https://substackcdn.com/image/fetch/$s_!d1vf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg 424w, https://substackcdn.com/image/fetch/$s_!d1vf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg 848w, https://substackcdn.com/image/fetch/$s_!d1vf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg 1272w, https://substackcdn.com/image/fetch/$s_!d1vf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F845218db-7ed0-47d6-acba-057cccc50899_204x38.svg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;"><span>Your engineers ship multiple times a week. Your pentest happens once a year. That means most new code goes live without any real depth of testing. Intruder&#8217;s AI pentesting gives you the depth of a manual engagement on-demand. No scoping calls, no six-week lead times, at a fraction of the cost. </span></p><p style="text-align: center;"><span>Catch complex vulnerabilities that human testers miss and get an audit-ready report in hours.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.intruder.io/pentest-pricing?utm_source=cybersecuirtypulse&amp;utm_medium=p_referral&amp;utm_campaign=global|fixed|ai_pentesting&quot;,&quot;text&quot;:&quot;See pricing&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.intruder.io/pentest-pricing?utm_source=cybersecuirtypulse&amp;utm_medium=p_referral&amp;utm_campaign=global|fixed|ai_pentesting"><span>See pricing</span></a></p></div><div><hr></div><h2>&#128478;&#65039; TL;DR</h2><ul><li><p>&#127481;&#127484; <strong>Taiwan:</strong> The government <a href="https://www.reuters.com/world/china/taiwan-says-it-was-targeted-last-month-ai-driven-hacking-campaign-2026-08-13/">confirmed a campaign</a> combining human operators with AI agents. <a href="https://dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia">Dream&#8217;s investigation</a> provides the detailed attribution, scale, and impact figures.</p></li><li><p>&#9876;&#65039; <strong>Private firms could run offensive cyber ops:</strong> A <a href="https://www.reuters.com/world/trump-signed-memo-allow-use-cyber-tools-target-transnational-criminal-orgs-white-2026-08-12/">new White House memorandum</a> directs DHS to create a federally controlled program in which vetted companies could eventually conduct surveillance and disruptive operations against specified foreign criminal organizations.</p></li><li><p>&#129514; <strong>OpenAI:</strong> The <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">Hugging Face incident</a> and <a href="https://www.securityweek.com/openai-overhauls-model-security-with-sandboxing-30-minute-alerts-and-training-pauses/">Astra&#8217;s advanced cyber capabilities</a> prompted stricter sandboxes, token-level monitoring, a 30-minute stop rule, and pauses on some training.</p></li><li><p>&#128680; <strong>Threat activity:</strong> U.S. agencies warned that actors are using <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a">AI-generated tooling against Siemens industrial controllers</a>, <a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/">Lazarus burned a Windows zero-day</a>, and CISA confirmed <a href="https://www.cisa.gov/news-events/alerts/2026/08/19/cisa-adds-one-known-exploited-vulnerability-catalog">active exploitation of a critical MLflow flaw</a>.</p></li><li><p>&#128736;&#65039; <strong>Security releases:</strong> <a href="https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap">Google Cloud shipped usable post-quantum controls</a>, <a href="https://www.coderabbit.ai/blog/introducing-coderabbit-security">CodeRabbit moved into security</a>, and <a href="https://signal.org/blog/automatic-key-verification/">Signal added automatic key verification</a>.</p></li><li><p>&#128176; <strong>Funding &amp; M&amp;A:</strong> <a href="https://investor.fortinet.com/news-releases/news-release-details/fortinet-advances-continuous-ai-protection-acquisition-virtue-ai">Fortinet closed its acquisition of Virtue AI</a>, <a href="https://siliconangle.com/2026/08/19/cribl-buys-radiant-securitys-ai-soc-tech-in-second-security-deal-of-2026/">Cribl bought Radiant Security&#8217;s AI SOC technology</a>, and <a href="https://mindgard.ai/blog/mindgard-raises-30m-series-a">Mindgard raised $30 million</a>.</p></li></ul><h2>&#9874;&#65039; Picks of the Week </h2><div><hr></div><h4><a href="https://www.reuters.com/world/china/taiwan-says-it-was-targeted-last-month-ai-driven-hacking-campaign-2026-08-13/">Taiwan confirms an AI-assisted attack on government agencies</a></h4><p>Taiwan&#8217;s Ministry of Digital Affairs confirmed that an attacker group combined manual operations with AI-agent assistance during a July campaign against government agencies. The more detailed attribution, autonomy analysis, and impact figures come from Dream&#8217;s investigation.</p><p><a href="https://dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia">Dream&#8217;s reconstruction</a> says a <strong>Hermes</strong> and <strong>OpenClaw</strong> setup ran up to eight subagents in parallel, mapped 21 connected government systems, cracked <strong>85 employee credentials</strong>, and <strong>extracted at least 2,564 personnel records in roughly four days</strong>. The <strong>recovered workspace also showed agents ranking attack paths</strong> and rechecking their own findings. Dream cited a Chinese-language operator without naming either party; <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795">the Financial Times</a> identified the target as Taiwan.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_iVp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_iVp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png 424w, https://substackcdn.com/image/fetch/$s_!_iVp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png 848w, https://substackcdn.com/image/fetch/$s_!_iVp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png 1272w, https://substackcdn.com/image/fetch/$s_!_iVp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_iVp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png" width="1456" height="741" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:741,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128660,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/211863321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_iVp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png 424w, https://substackcdn.com/image/fetch/$s_!_iVp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png 848w, https://substackcdn.com/image/fetch/$s_!_iVp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png 1272w, https://substackcdn.com/image/fetch/$s_!_iVp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff354081f-6ef6-4702-ac22-ae28c517fef4_1600x814.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Dream&#8217;s reconstruction of the attack chain. Source: <a href="https://dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia">Dream Security</a>.</em></figcaption></figure></div><p>What gets me is more the speed more than the novelty. Dream describes the agents moving through exposed debug endpoints, unauthenticated APIs, predictable passwords, an unsigned JWT flaw, and over-trusted SSO <strong>in four days</strong>. </p><p>Sure, a human still picked the target and objective, so this is not a fully autonomous attack story. It is a look at what happens when familiar weaknesses get tested in parallel, without much downtime between steps.</p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;">Access decisions at machine speed, with human judgment. Paladin is now GA.</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KF-G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KF-G!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif 424w, https://substackcdn.com/image/fetch/$s_!KF-G!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif 848w, https://substackcdn.com/image/fetch/$s_!KF-G!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif 1272w, https://substackcdn.com/image/fetch/$s_!KF-G!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KF-G!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif" width="664" height="373.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:450,&quot;width&quot;:800,&quot;resizeWidth&quot;:664,&quot;bytes&quot;:11320189,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/211863321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KF-G!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif 424w, https://substackcdn.com/image/fetch/$s_!KF-G!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif 848w, https://substackcdn.com/image/fetch/$s_!KF-G!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif 1272w, https://substackcdn.com/image/fetch/$s_!KF-G!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc660be27-646c-4b51-918d-dfb6f1d268bb_800x450.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><span>&#8220;It denied a deliberately bad admin request with better reasoning than most human reviewers would give.&#8221;</span></p><p style="text-align: center;"><span>Agent and non-human identities on Opal&#8217;s platform grew 2,300% in the last year, each holding 3x the entitlements of a person. No team reviews that volume by hand. Paladin does. Someone requests prod access at 2am: it checks the linked incident, confirms they&#8217;re on call, weighs the request against your policy, and recommends a time-boxed grant with its reasoning shown. No match? It declines or escalates to a person. You set the autonomy dial. Every decision is logged and audit-ready.</span></p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.opal.dev/blog/new-in-opal-august-roundup&quot;,&quot;text&quot;:&quot;See Paladin in action&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.opal.dev/blog/new-in-opal-august-roundup"><span>See Paladin in action</span></a></p></div><div><hr></div><h4><a href="https://www.reuters.com/technology/openai-slows-model-training-bolster-security-after-hugging-face-hack-2026-08-18/">OpenAI pauses model testing and some training after the Hugging Face incident</a></h4><p>OpenAI has paused model testing for two weeks and separately paused training on its next-gen Astra models. It also tightened sandboxing, internet isolation, and automated monitoring. New rules target alerts within 30 minutes and require pausing a test when teams cannot clear a concerning flag within that window.</p><p>The catalyst for this was July&#8217;s Hugging Face incident which we&#8217;ve covered in <a href="https://www.cybersecuritypulse.net/i/210740043/the-openai-hugging-face-incident-was-bigger-than-the-first-disclosure">previous issues</a> and is detailed below. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZFe1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZFe1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png 424w, https://substackcdn.com/image/fetch/$s_!ZFe1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png 848w, https://substackcdn.com/image/fetch/$s_!ZFe1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png 1272w, https://substackcdn.com/image/fetch/$s_!ZFe1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZFe1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png" width="1456" height="750" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:750,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:244763,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/211863321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZFe1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png 424w, https://substackcdn.com/image/fetch/$s_!ZFe1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png 848w, https://substackcdn.com/image/fetch/$s_!ZFe1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png 1272w, https://substackcdn.com/image/fetch/$s_!ZFe1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F996f8d6b-77f8-427d-bd07-fbeda5260512_1600x824.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Source: <a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">Hugging Face</a>.</em></figcaption></figure></div><p>Seems like there were 800 agent breakouts in late July/early Aug., good to see labs continuing to improve security. </p><div><hr></div><h4><a href="https://www.reuters.com/world/trump-signed-memo-allow-use-cyber-tools-target-transnational-criminal-orgs-white-2026-08-12/">The White House directs DHS to build a controlled lane for private offensive cyber operators</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VS-P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VS-P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VS-P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VS-P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VS-P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VS-P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;U.S. President Donald Trump delivers remarks at Red Rock Casino Resort Spa in Las Vegas&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="U.S. President Donald Trump delivers remarks at Red Rock Casino Resort Spa in Las Vegas" title="U.S. President Donald Trump delivers remarks at Red Rock Casino Resort Spa in Las Vegas" srcset="https://substackcdn.com/image/fetch/$s_!VS-P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg 424w, https://substackcdn.com/image/fetch/$s_!VS-P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg 848w, https://substackcdn.com/image/fetch/$s_!VS-P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!VS-P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bfa16a1-9bc9-4ee0-9bd8-5db462ab469d_1920x1281.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Security has argued about private-sector hack back for as long as I&#8217;ve been in security. The house has always been divided. This new proposal from the White House is narrower: private operators would work under federal supervision.</p><p>A new national security presidential memorandum authorizes cyber tools against foreign transnational criminal organizations and directs DHS, with Justice Department oversight, to build a federally supervised program. If and when it becomes operational, vetted companies could gather threat information, propose operations, and conduct cyber surveillance or effects. </p><p>Some threat actors operate through a victim&#8217;s compromised infrastructure, so what happens when the &#8220;hack back&#8221; takes down the infra of a legitimate corp/victim? The devil is in the details. </p><div><hr></div><h4><a href="https://www.varonis.com/blog/cosnitch">CoSnitch turned Copilot&#8217;s own answers into attack reconnaissance</a></h4><div class="pullquote"><p>&#8220;Meta-hacking: How we got Copilot to snitch on itself&#8221;<strong> - Varonis </strong></p></div><p>Repeated follow-up questions led Microsoft Copilot Personal to disclose an undocumented <code>autorun</code> URL parameter and prompt-handling details. A victim who clicked a crafted link could then trigger a prompt inside an authenticated session, query connected services, and exfiltrate encoded results through Copilot&#8217;s URL-fetch capability. Separately, researchers used indirect prompt injection through web summarization to write attacker-controlled instructions into Copilot&#8217;s persistent memory.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Irb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Irb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png 424w, https://substackcdn.com/image/fetch/$s_!2Irb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png 848w, https://substackcdn.com/image/fetch/$s_!2Irb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png 1272w, https://substackcdn.com/image/fetch/$s_!2Irb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Irb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png" width="710" height="548" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:548,&quot;width&quot;:710,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;CoSnitch-4&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="CoSnitch-4" title="CoSnitch-4" srcset="https://substackcdn.com/image/fetch/$s_!2Irb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png 424w, https://substackcdn.com/image/fetch/$s_!2Irb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png 848w, https://substackcdn.com/image/fetch/$s_!2Irb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png 1272w, https://substackcdn.com/image/fetch/$s_!2Irb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fee3cd715-bfdb-49c3-b7a5-3792665b7463_710x548.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.varonis.com/blog/cosnitch">Varonis says</a> it disclosed CoSnitch in December 2025 and that fixes shipped August 18. Microsoft told <a href="https://www.darkreading.com/vulnerabilities-threats/cosnitch-attack-copilot-mapping-out-architecture">Dark Reading</a> that no customer action was required and enterprise users were unaffected. Varonis says it found no exploitation.</p><p>The cool thing about investing in vuln research for specific ecosystems is that you become super familiar with it and end up discovering a slew of interesting things. Varonis has hit the jackpot on MSFT Copilot vulns and Copilot users can learn a lot from their research. </p><div><hr></div><h4><a href="https://www.darkreading.com/cybersecurity-operations/walmart-trusted-agent-approach-purple-teaming">Walmart puts trusted observers inside its purple-team exercises</a></h4><p>This was my favorite practitioner piece of the week. Walmart moved its red and blue teams into the same business unit and physical location, then introduced &#8220;trusted agents&#8221; into full adversary-emulation exercises. </p><p>Blue-team observers sit with the red team, check telemetry, logs, and detections in real time, and make sure the exercise does not damage production. Their job is not to tip off the defenders. The teams validate detections while the attack is still happening. When defenders make an attack path harder, the red team gets immediate feedback and has to pivot. This is textbook purple teaming. </p><p>DarkReading published a few pieces on how Walmart thinks about SecOps + Purple Teaming which you can find <a href="https://www.darkreading.com/cybersecurity-operations/walmart-leaders-transform-security-operations-without-going-bananas">here.</a></p><div><hr></div><h2>&#128300;Threats &amp; Research </h2><div><hr></div><h4><a href="https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug">Wiz&#8217;s Red Agent found a Snowflake CI/CD flaw five days after it went live</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dnZ9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dnZ9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp 424w, https://substackcdn.com/image/fetch/$s_!dnZ9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp 848w, https://substackcdn.com/image/fetch/$s_!dnZ9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp 1272w, https://substackcdn.com/image/fetch/$s_!dnZ9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dnZ9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp" width="1173" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/832a7675-711f-4290-835e-f553861da9c1_1173x768.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1173,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dnZ9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp 424w, https://substackcdn.com/image/fetch/$s_!dnZ9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp 848w, https://substackcdn.com/image/fetch/$s_!dnZ9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp 1272w, https://substackcdn.com/image/fetch/$s_!dnZ9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832a7675-711f-4290-835e-f553861da9c1_1173x768.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot demonstrating access to Snowflake&#8217;s Jira portal, via an exfiltrated token</figcaption></figure></div><p>Wiz says its Red Agent found a GitHub Actions script injection in Snowflake&#8217;s public <code>snowflake-connector-net</code> repository. A crafted issue title could execute commands in a workflow and expose a Jira token with <strong>read access to internal engineering, compliance, and bug-bounty projects.</strong> </p><p>Snowflake patched the workflow on June 23, five days after the vulnerable change went live, and rotated the token the next day. Snowflake said it found no evidence of unauthorized third-party access, while Wiz said it matched all anomalous queries to its testing IPs. </p><p>Cool BTS look at how AI pen testing helps secure enterprises.</p><div><hr></div><h4><a href="https://www.huntress.com/blog/defcon-phishing-google-doc-malware">Post-DEF CON phish chains X, Google Docs, and DocSend</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HWVC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HWVC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp 424w, https://substackcdn.com/image/fetch/$s_!HWVC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp 848w, https://substackcdn.com/image/fetch/$s_!HWVC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp 1272w, https://substackcdn.com/image/fetch/$s_!HWVC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HWVC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp" width="486" height="424" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:424,&quot;width&quot;:486,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Actor commenting on other cybersecurity accounts&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Actor commenting on other cybersecurity accounts" title="Actor commenting on other cybersecurity accounts" srcset="https://substackcdn.com/image/fetch/$s_!HWVC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp 424w, https://substackcdn.com/image/fetch/$s_!HWVC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp 848w, https://substackcdn.com/image/fetch/$s_!HWVC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp 1272w, https://substackcdn.com/image/fetch/$s_!HWVC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F027a4ba8-8785-46a2-83e5-b03331abb614_486x424.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The X account (fake VP mktng @ Coindesk) commenting on other cybersecurity accounts after DEF CON in an attempt to use the "conference planning" lure</figcaption></figure></div><p>A threat actor posing as CoinDesk&#8217;s VP of marketing approached a Huntress researcher after Black Hat and DEF CON with a fake conference-planning pitch. The researcher spotted it and kept talking to map the playbook; the actor moved from a Google Doc with an Apps Script sidebar to a fake DocSend installer delivering AMOS on macOS or Ledger-focused malware and a traffic-intercepting proxy on Windows. When neither worked, the pitch somehow became an offer of up to $1 million in funding. Conference follow-ups are supposed to feel warm and familiar, which is exactly what made this workflow useful as a lure.</p><div><hr></div><h4><a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/">Lazarus turns a Windows zero-day into an EDR-blinding chain</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-7u8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-7u8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png 424w, https://substackcdn.com/image/fetch/$s_!-7u8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png 848w, https://substackcdn.com/image/fetch/$s_!-7u8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png 1272w, https://substackcdn.com/image/fetch/$s_!-7u8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-7u8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png" width="1456" height="810" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:810,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:224848,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/211863321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-7u8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png 424w, https://substackcdn.com/image/fetch/$s_!-7u8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png 848w, https://substackcdn.com/image/fetch/$s_!-7u8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png 1272w, https://substackcdn.com/image/fetch/$s_!-7u8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3702741-1121-4055-9ab5-33ac0ea73c9d_1615x899.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">High-level overview of the DLL sideloading infection chain.</figcaption></figure></div><p>Check Point attributes a defense and aerospace campaign in Europe and India to North Korea&#8217;s Lazarus Group. Fake job offers, impersonation sites, and trojanized PDF viewers led to exploitation of <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-68820">CVE-2026-68820</a> in Windows <code>AFD.sys</code>, SYSTEM access, and deployment of the EDR-blinding FudModule rootkit. Compromised Roundcube and WordPress servers relayed command-and-control traffic. Microsoft patched the actively exploited flaw August 11. </p><div><hr></div><h4><a href="https://advisories.ncsc.nl/2026/ncsc-2026-0280.html">Attackers are abusing the macOS Screen Sharing authentication flaw</a></h4><p>Apple patched CVE-2026-65400 across supported macOS releases on August 6. <strong>The flaw lets a network attacker authenticate to Screen Sharing without valid credentials.</strong> On August 12, the <a href="https://advisories.ncsc.nl/2026/ncsc-2026-0280.html">Dutch NCSC</a> reported active exploitation of internet-exposed <strong>TCP 5900</strong>, with attackers gaining root and installing Monero miners. Screen Sharing is disabled by default. Exposed deployments should update, disable the service where unnecessary, and remove TCP 5900 from direct internet exposure.</p><div><hr></div><h2>&#128230; Security Product Releases</h2><div><hr></div><h4><a href="https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap">Google Cloud sets out its post-quantum roadmap</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mvUW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mvUW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp 424w, https://substackcdn.com/image/fetch/$s_!mvUW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp 848w, https://substackcdn.com/image/fetch/$s_!mvUW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp 1272w, https://substackcdn.com/image/fetch/$s_!mvUW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mvUW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp" width="1456" height="1128" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1128,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66444,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/211863321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mvUW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp 424w, https://substackcdn.com/image/fetch/$s_!mvUW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp 848w, https://substackcdn.com/image/fetch/$s_!mvUW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp 1272w, https://substackcdn.com/image/fetch/$s_!mvUW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac10068a-c406-4a53-824c-6d0fd429b9b9_1456x1128.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Visualization of our Google Cloud PQC roadmap. </em></figcaption></figure></div><p>Google Cloud&#8217;s August 11 update combines tactical controls teams can implement today with a multi-year plan. Cloud KMS support for ML-KEM, ML-DSA, and SLH-DSA is generally available. Google Cloud API endpoints already use hybrid ML-KEM, and application and proxy load balancers can opt into TLS 1.3 <code>X25519MLKEM768</code>. Cloud VPN, Interconnect, developer tooling, and data transfer are targeted for 2026 or 2027, while certificate, IAM, HSM, and supply-chain work extends through 2028. Google&#8217;s overall readiness target is 2029.</p><p>Google has been working on quantum for a decade+. Great to see them continuing to invest in this space while rest of the world focuses on AI security. <strong>Quantum will come slowly and then all at once, imo.</strong> </p><div><hr></div><h4><a href="https://signal.org/blog/automatic-key-verification/">Signal adds automatic key verification</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9qhQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9qhQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png 424w, https://substackcdn.com/image/fetch/$s_!9qhQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png 848w, https://substackcdn.com/image/fetch/$s_!9qhQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png 1272w, https://substackcdn.com/image/fetch/$s_!9qhQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9qhQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png" width="1456" height="825" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:825,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:338100,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/211863321?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!9qhQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png 424w, https://substackcdn.com/image/fetch/$s_!9qhQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png 848w, https://substackcdn.com/image/fetch/$s_!9qhQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png 1272w, https://substackcdn.com/image/fetch/$s_!9qhQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5a5432f-4ba4-4d3f-845d-46059f16e9ae_1600x907.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Signal&#8217;s August 11 release adds optional automatic key verification, backed by a verifiable key-transparency log, to supplement manual safety-number comparisons. When Signal knows a contact&#8217;s phone number, users can ask the app to verify that the encryption key bound to it matches the log. Cloudflare and Trail of Bits serve as independent auditors. The practical value is that key mismatches can surface without asking users to manually compare a wall of safety-number digits. Automatic verification still has limits: it does not establish real-world identity, catch every account compromise, or work for username-only contacts.</p><div><hr></div><h4><a href="https://mallory.ai/blog/byok-bring-your-own-key">Mallory makes bring your own key generally available</a></h4><p>Mallory recently made BYOK GA on August 18 across every plan. Here, BYOK refers to an LLM-provider API key, not a customer-managed encryption key. Teams can run Mallory workflows against approved OpenAI, Anthropic, Gemini, or OpenRouter accounts, with inference billed by that provider. Keys are encrypted and injected through a credential proxy.</p><p><a href="https://mallory.ai/">Mallory</a> is a leading threat intel platform founded by <a href="https://www.linkedin.com/in/jcran/">Jonathan Cran</a>. </p><div><hr></div><h4><a href="https://www.coderabbit.ai/blog/introducing-coderabbit-security">CodeRabbit moves into security and agentic change management</a></h4><p>CodeRabbit rolled out <a href="https://www.coderabbit.ai/blog/introducing-agentic-change-management">Agentic Change Management</a>  and Security. Security scans committed code for reachable auth flaws, IDOR, injection, data exposure, and prompt injection, then verifies findings and can open remediation PRs. Triage prioritizes incoming PRs, while Change Stack breaks large changes into semantic groups.</p><p>CodeRabbit is a leading AI code review platform. Makes sense that anything that touches PRs should start going after code security.</p><div><hr></div><h2>&#129309; Funding &amp; M&amp;A</h2><h4><a href="https://investor.fortinet.com/news-releases/news-release-details/fortinet-advances-continuous-ai-protection-acquisition-virtue-ai">Fortinet closes its acquisition of Virtue AI</a></h4><p>Fortinet completed its acquisition of <a href="https://www.virtueai.com/">Virtue AI</a> on August 17. Virtue adds shadow AI and MCP discovery, automated red teaming, runtime guardrails, and continuous attack simulation. Fortinet positions those capabilities as a complement to FortiAIGate and its broader AI-native Security Fabric. Financial terms were not disclosed, and Fortinet said the consideration was &#8216;immaterial&#8217;.</p><p>Fortinet is betting that AI security becomes another control layer inside the platform instead of a standalone island. What I&#8217;ll be watching is how Virtue&#8217;s product identity carries into the broader platform and where its capabilities surface first.</p><div><hr></div><h4><a href="https://siliconangle.com/2026/08/19/cribl-buys-radiant-securitys-ai-soc-tech-in-second-security-deal-of-2026/">Cribl buys Radiant Security&#8217;s AI SOC technology</a></h4><p>Cribl acquired the technology behind Radiant Security&#8217;s AI SOC platform, which builds triage logic for individual alerts and investigates them against telemetry. </p><p>Cribl plans to turn it into an application on its telemetry platform. This is its second security deal of 2026 after CardinalOps, and the direction is getting pretty clear: Cribl wants its telemetry layer to power more of the work analysts actually do.</p><div><hr></div><h4><a href="https://mindgard.ai/blog/mindgard-raises-30m-series-a">Mindgard raises a $30 million Series A</a></h4><p>Mindgard raised a $30 million Series A led by Album VC, with Karma Ventures and existing investors participating. The company tests and monitors models, applications, and agents for prompt injection, data leakage, model manipulation, and multi-step attack paths. </p><div><hr></div><h4><a href="https://www.brinqa.com/news-room/brinqa-acquires-plextrac-ctem">Brinqa acquires PlexTrac</a></h4><p>Brinqa acquired PlexTrac, bringing pentest workflows, offensive-security validation, reporting, and post-remediation retesting into its exposure-management platform. PlexTrac will remain available as a standalone product, and founder Dan DeCloss is joining Brinqa&#8217;s executive team and board. Financial terms were not disclosed.</p><p>More OffSec consolidation coming? &#128064;</p><div><hr></div><h4><a href="https://www.cloudflare.com/press/press-releases/2026/cloudflare-inc-announces-pricing-of-offering-of-2-175-billion-of-0-convertible-senior-notes-due-2031/">Cloudflare prices $2.175 billion of 0% convertible notes</a></h4><p>Cloudflare priced $2.175 billion of 0% convertible notes due 2031, with a $325 million buyer option and roughly $2.14 billion in expected net proceeds. Funds may support general corporate purposes and strategic transactions, but no acquisition was announced. The initial conversion price carries a 60% premium to Cloudflare&#8217;s August 10 close. In plain English, Cloudflare just priced a large pool of capital with zero cash interest. Conversion rights and potential dilution are the trade.</p><div><hr></div><h4><a href="https://team8.vc/team8-announces-365-million-in-new-capital/">Team8 announces $365 million in new fund capital</a></h4><p>Team8 announced $365 million in new fund capital. The total includes a $265 million Capital Fund III and more than $100 million in a follow-on pool. </p><p><a href="https://team8.vc/portfolio/">Team8 has backed</a> Claroty, Akeyless, OX Security, IONIX, and Nagomi, plus exits including Talon and Dig Security to Palo Alto Networks, Gem Security to Wiz, Portshift to Cisco, and Illusive Networks to Proofpoint.</p><p>Team8 says it will back seed and Series A companies across cybersecurity, software infrastructure, fintech, and digital health, then reserve support for its highest-conviction portfolio companies. The announcement brings Team8&#8217;s assets under management across eight funds to nearly $2 billion.</p><div><hr></div><h4><a href="https://www.businesswire.com/news/home/20260812311754/en/">CodeRabbit raises a $143 million Series C</a></h4><p>As covered in the product section, CodeRabbit&#8217;s Agentic Change Management release arrived with a $143 million Series C co-led by Atomico and Smash Capital, valuing the company at $1.5 billion and bringing total funding to more than $200 million.</p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[TCP 141: Black Hat + DEF CON 2026 Recap: Inside the Hugging Face Breakout, North Korea's Back End, and $1.27B in Funding]]></title><description><![CDATA[The research, launches, funding, and deals worth digging into from Hacker Summer Camp.]]></description><link>https://www.cybersecuritypulse.net/p/black-hat-def-con-2026-recap-inside</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/black-hat-def-con-2026-recap-inside</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Tue, 11 Aug 2026 15:05:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pMYe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/black-hat-def-con-2026-recap-inside?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/black-hat-def-con-2026-recap-inside?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pMYe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pMYe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!pMYe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!pMYe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!pMYe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pMYe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3402416,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pMYe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!pMYe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!pMYe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!pMYe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1600e6d-617d-480d-b9b8-eee039d24573_1800x1300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Howdy &#128075;&#127997; It&#8217;s the week after Hacker Summer Camp, and many of us are still in recovery mode. Our industry never catches a breather though. Lots going on to kick off this week even (i.e., <a href="https://corma.ai/introducing-corma">Corma&#8217;s $60M seed</a>, <a href="https://www.monad.com/blog/monad-adds-upwind-support">Monad x Upwind Partnership</a> etc.) </p><p>To recap it all, I&#8217;m doing my usual major-con split: one issue covering the industry side, followed by another with my personal recap and takeaways. This is the former, and probably the most comprehensive issue I&#8217;ve ever put together. Admittedly, I did use AI to help me sorth through all the noise, synthesize, and summarize. </p><p>The good news is that I filtered out all the BS and pulled out the stories and details actually worth your attention. Even after all that filtering, we still have a lot of ground to cover. Before we dive in, here&#8217;s a buzzword bingo card I came up with which probably would&#8217;ve been a hit at Blackhat&#8230; ideas for next year I guess </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rzuo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rzuo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png 424w, https://substackcdn.com/image/fetch/$s_!rzuo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png 848w, https://substackcdn.com/image/fetch/$s_!rzuo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png 1272w, https://substackcdn.com/image/fetch/$s_!rzuo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rzuo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:434878,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rzuo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png 424w, https://substackcdn.com/image/fetch/$s_!rzuo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png 848w, https://substackcdn.com/image/fetch/$s_!rzuo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png 1272w, https://substackcdn.com/image/fetch/$s_!rzuo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F828279b6-55f8-4a97-9005-bee3f07a7aec_2160x2160.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cool, now let&#8217;s get into it! </p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><span>Your AI Agents Are Deployed. Are They Trusted?</span></h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sne4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sne4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png 424w, https://substackcdn.com/image/fetch/$s_!sne4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png 848w, https://substackcdn.com/image/fetch/$s_!sne4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png 1272w, https://substackcdn.com/image/fetch/$s_!sne4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sne4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png" width="488" height="81.5936" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:209,&quot;width&quot;:1250,&quot;resizeWidth&quot;:488,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sne4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png 424w, https://substackcdn.com/image/fetch/$s_!sne4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png 848w, https://substackcdn.com/image/fetch/$s_!sne4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png 1272w, https://substackcdn.com/image/fetch/$s_!sne4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc28c73-ea66-4918-9d2d-2126704b6345_1250x209.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;"><span>Agents don't wait for permission; they simply act. Varonis Atlas' latest expansion is Agent Intent-Based Access Control (IBAC), a new layer that compares what an agent was asked to do to what it actually does. Agent IBAC blocks, alerts, and quarantines in real time when agents drift off course. </span></p><p style="text-align: center;"><span>Stop guessing what your agents can reach and start controlling what they do.</span></p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://hubs.ly/Q04sqr6z0&quot;,&quot;text&quot;:&quot;See Varonis Agent IBAC in Action&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://hubs.ly/Q04sqr6z0"><span>See Varonis Agent IBAC in Action</span></a></p></div><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#129302; <strong><a href="https://www.youtube.com/watch?v=87DyyMV0kCY">Eval agents reached cluster-admin</a>:</strong> The chain crossed multiple Hugging Face clusters through shared infrastructure and reusable credentials.</p></li><li><p>&#128300; <strong><a href="https://portswigger.net/research/can-ai-do-novel-security-research">HTTP Terminator found novel desyncs</a>:</strong> Kettle&#8217;s gated loop found 200-plus vulnerable targets across 30,000 authorized hosts.</p></li><li><p>&#128752;&#65039; <strong><a href="https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide">Inside North Korea&#8217;s back end</a>:</strong> Stykas linked the operation to 1,640 potential victims across 57 countries.</p></li><li><p>&#129713; <strong><a href="https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/">ChainDrop infected 400-plus packages</a>:</strong> The worm stole developer secrets and republished tainted npm versions through CI.</p></li><li><p>&#129516; <strong><a href="https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/">Unit42 NOVA reported 14,090 findings</a>:</strong> A separate research report from 1Password found only 26 percent of patches fully fixed the studied flaws.</p></li><li><p>&#127744; <strong><a href="https://www.varonis.com/blog/rovoblast">One Rovo link leaked data</a>:</strong> A crafted <code>rovoChatPrompt</code> URL exfiltrated victim-accessible secrets through an attacker-controlled image request.</p></li><li><p>&#129520; <strong><a href="https://www.c1.ai/blog/launch-week-roundup-agentic-control-plane">Agent controls moved inline</a>:</strong> New releases covered credentials, tool calls, browsers, runtime, and task-specific coding context.</p></li><li><p>&#129512; <strong><a href="https://snyk.io/blog/evo-continuous-offensive-security/">Agentic pentesting split three ways</a>:</strong> Continuous testing, chained attack paths, and human-backed validation are different products.</p></li><li><p>&#127793; <strong><a href="https://www.newswire.com/news/corma-the-first-frontier-defensive-cybersecurity-ai-lab-raises-60m-as-ai">Corma trained its own model</a>:</strong> Its $60M seed backs defensive self-play inside instrumented enterprise environments.</p></li><li><p>&#127942; <strong><a href="https://opnova.ai/blog/opnova-sweeps-black-hat-startup-spotlight-competition">Opnova swept Black Hat</a>:</strong> Its computer-use agents for disconnected apps won the U.S. contest, audience vote, and global final.</p></li><li><p>&#128184; <strong><a href="https://horizon3.ai/news/press-release/horizon3-raises-250m-series-e-at-2b-valuation-to-lead-the-ai-vs-ai-cybersecurity-era/">Thirteen announcements totaled $1.27B</a>:</strong> Capital clustered around testing, agents, runtime security, identity, and infrastructure.</p></li></ul><p><strong>Plus:</strong> two Kerberos logic flaws, a Pilates waitlist incident, poisoned telemetry, a USB-to-SYSTEM chain, and 40+ product launch and funding announcements.</p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><a href="https://www.youtube.com/watch?v=87DyyMV0kCY">The OpenAI-Hugging Face incident was bigger than the first disclosure</a></h4><div id="youtube2-87DyyMV0kCY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;87DyyMV0kCY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/87DyyMV0kCY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>OpenAI&#8217;s</strong> Black Hat reconstruction showed that its evaluation agents built a cross-session chain into <strong>Hugging Face</strong>. They used a shared Artifactory service as a message board, exploited a zero-day in OpenAI&#8217;s cache proxy, and turned an exposed user-hosted CyberGym executor on <strong>Modal</strong> into a root launchpad; Modal itself was not compromised.</p><p>A malicious HDF5 dataset made a Hugging Face worker return <code>/proc/self/environ</code> and its source. A second payload hid a Jinja2 expression in an fsspec <code>reference://</code> offset, which executed Python inside a production conversion pod. The agent created a privileged pod with the host filesystem mounted, reached node root, and read a Kubernetes secret with <strong>136 entries</strong>. A mesh-VPN enrollment key and a broker credential bound to <code>system:masters</code> yielded cluster-admin across multiple clusters within <strong>13 hours</strong>.</p><p>The clever exploits matter less than the permissions and gaps they chained together. Shared infrastructure, permissive egress, reusable credentials, and unrestricted privileged pods turned separate flaws into systemic compromise. I thikn moving forward, evaluation agents need the same security controls as agents in production. We&#8217;ve now seen how far the blast radius can go. </p><p><strong>Dig Deeper:</strong> <a href="https://www.youtube.com/watch?v=87DyyMV0kCY">Black Hat reconstruction</a> | <a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">Hugging Face timeline</a> | <a href="https://huggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space/">Hugging Face&#8217;s interactive replay</a></p><div><hr></div><div class="callout-block" data-callout="true"><p style="text-align: center;"><strong>The Future of Web Application Security Is Here</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hT9Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hT9Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png 424w, https://substackcdn.com/image/fetch/$s_!hT9Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png 848w, https://substackcdn.com/image/fetch/$s_!hT9Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png 1272w, https://substackcdn.com/image/fetch/$s_!hT9Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hT9Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png" width="502" height="104.4684065934066" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7956d669-4736-4338-9ddf-317609c817bd_3827x796.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:303,&quot;width&quot;:1456,&quot;resizeWidth&quot;:502,&quot;bytes&quot;:75782,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hT9Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png 424w, https://substackcdn.com/image/fetch/$s_!hT9Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png 848w, https://substackcdn.com/image/fetch/$s_!hT9Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png 1272w, https://substackcdn.com/image/fetch/$s_!hT9Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7956d669-4736-4338-9ddf-317609c817bd_3827x796.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;">Custom web applications change constantly. Security validation should too. Traditional testing captures a point-in-time snapshot, finding vulnerabilities but rarely proving how attackers could exploit them in production.</p><p style="text-align: center;">NodeZero&#174; Web Application Pentesting uses AI-powered autonomous validation to continuously and safely assess custom applications in production as code, infrastructure, and threats evolve.</p><p style="text-align: center;">Continuously validate. Continuously improve. Continuously stay ahead.</p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://horizon3.ai/intelligence/blogs/web-application-security-validation?utm_source=cybersecuritypulse&amp;utm_medium=newsletter&quot;,&quot;text&quot;:&quot;See How It Works&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://horizon3.ai/intelligence/blogs/web-application-security-validation?utm_source=cybersecuritypulse&amp;utm_medium=newsletter"><span>See How It Works</span></a></p></div><div><hr></div><h3><a href="https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide">A researcher spent 22 months inside North Korean hacker infrastructure</a></h3><p>At Black Hat, Greece-based researcher <strong>Vangelis Stykas</strong> presented findings from what he says was <strong>22 months</strong> inside multiple North Korean command-and-control (C2) systems. He reached attacker workstations, Slack, Discord, and roughly <strong>5 TB</strong> of data.</p><p>Stykas says the material tied <strong>1,640 organizations across 57 countries</strong> to the operation as potential victims. He estimates 700 to 800 suffered serious intrusions involving root access to servers or AWS environments and, in some cases, cryptocurrency keys. The operators largely used the familiar Contagious Interview playbook, sending malware through fake job offers aimed at developers and external contractors.</p><p>Named organizations reported different outcomes. Japan&#8217;s CERT confirmed remediation with <strong>AEON Smart Technology</strong>. <strong>Boston Children&#8217;s Hospital</strong> said the incident involved a former contractor&#8217;s personal device, not hospital systems. <strong>Coinbase</strong> said it terminated a risky contractor and found no sensitive or customer data exposure.</p><p>Easily one of the wildest stories to come out of hacker summer camp. </p><div><hr></div><h3><a href="https://portswigger.net/research/can-ai-do-novel-security-research">James Kettle encoded his vulnerability-research workflow into an AI system</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!etcM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!etcM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png 424w, https://substackcdn.com/image/fetch/$s_!etcM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png 848w, https://substackcdn.com/image/fetch/$s_!etcM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png 1272w, https://substackcdn.com/image/fetch/$s_!etcM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!etcM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png" width="1200" height="506" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:506,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Black box orchestration&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Black box orchestration" title="Black box orchestration" srcset="https://substackcdn.com/image/fetch/$s_!etcM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png 424w, https://substackcdn.com/image/fetch/$s_!etcM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png 848w, https://substackcdn.com/image/fetch/$s_!etcM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png 1272w, https://substackcdn.com/image/fetch/$s_!etcM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d7e9a9-91ef-4909-a543-4cbe9874376c_1200x506.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>PortSwigger&#8217;s </strong>(creator&#8217;s of BurpSuite) James Kettle presented HTTP Terminator at Black Hat USA and DEF CON 34. The AI research system converted specification fragments into hypotheses, permuted probes, and checked cross-request contamination across <strong>30,000 authorized targets</strong> at under one request per second per domain.</p><p>It found more than <strong>200 targets</strong> where <code>multipart/byteranges</code> triggered CL.0 desynchronization: a front end forwarded a body that the back end ignored. It also found servers that read duplicate valid <code>Content-Length</code> headers as a zero-length body. Its dangling-byte technique left a smuggled request one byte short so the victim&#8217;s first byte completed it, avoiding the usual response-queue-poisoning race. HTTP Terminator also proposed Shared-Parser Confusion, which Kettle manually validated.</p><p>Early agents confused HTTP pipelining with bugs. Kettle moved each success condition into deterministic code and required evidence at every stage. He reports the gated exploitation loop produced zero false positives and <a href="https://github.com/portswigger/http-terminator">released the tooling</a>.</p><p>Great research by one of the best in biz. </p><div><hr></div><h3><a href="https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/">ChainDrop infected more than 400 npm packages</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dmEx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dmEx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png 424w, https://substackcdn.com/image/fetch/$s_!dmEx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png 848w, https://substackcdn.com/image/fetch/$s_!dmEx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png 1272w, https://substackcdn.com/image/fetch/$s_!dmEx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dmEx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png" width="1080" height="665" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:665,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:861463,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dmEx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png 424w, https://substackcdn.com/image/fetch/$s_!dmEx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png 848w, https://substackcdn.com/image/fetch/$s_!dmEx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png 1272w, https://substackcdn.com/image/fetch/$s_!dmEx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F837804df-003a-4d08-a0de-d4c2cbbcb920_1080x665.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>During Black Hat week, ChainDrop began spreading across npm, infecting more than <strong>400 packages</strong>. <strong>Unit 42</strong> found that the worm stole npm and GitHub tokens, SSH keys, kubeconfigs, and other developer secrets. An embedded Python helper read live GitHub Actions runner memory for short-lived OpenID Connect tokens and secrets.</p><p>With a stolen npm token, ChainDrop enumerated every package it could publish, kept the original code, added a <code>preinstall</code> hook and two payload files, bumped the patch version, and republished. It also planted a CodeQL-named workflow that copied repository secrets into an Actions artifact. Linked Visual Studio Code and Claude Code configurations disguised the files; only the Visual Studio Code path executed in Unit 42&#8217;s sample.</p><p>An Ethereum contract resolved command infrastructure, letting the operator rotate domains with one transaction. A path for minting genuine Sigstore provenance existed but was not observed.</p><p><strong>This reminds me of the <a href="https://www.endorlabs.com/learn/teampcp-isnt-done">teamPCP</a> hacks that kicked off during RSAC week. Are attackers intentionally targeting heavy conference weeks to wreak havoc? &#128579;</strong></p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>Different cloud providers, different priorities</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vKzC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vKzC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png 424w, https://substackcdn.com/image/fetch/$s_!vKzC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png 848w, https://substackcdn.com/image/fetch/$s_!vKzC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png 1272w, https://substackcdn.com/image/fetch/$s_!vKzC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vKzC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png" width="574" height="430.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:900,&quot;width&quot;:1200,&quot;resizeWidth&quot;:574,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vKzC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png 424w, https://substackcdn.com/image/fetch/$s_!vKzC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png 848w, https://substackcdn.com/image/fetch/$s_!vKzC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png 1272w, https://substackcdn.com/image/fetch/$s_!vKzC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc22983c-71ab-4e43-9b54-5c0b72c75cd0_1200x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;">If juggling multiple cloud providers wasn't complicated enough, it turns out they don't fail in the same places. There's surprisingly little overlap in the issues affecting AWS, Azure, and Google Cloud, meaning each provider demands different priorities. </p><p style="text-align: center;">Intruder&#8217;s new report helps you understand where those priorities differ, breaking down the most common issues across each provider, how they compare across key risk categories, and how those risks change as organizations grow.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.intruder.io/blog/cloud-security-index?utm_source=cybersecuirtypulse&amp;utm_medium=p_referral&amp;utm_campaign=global|fixed|cloud_index&quot;,&quot;text&quot;:&quot;Get the report&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.intruder.io/blog/cloud-security-index?utm_source=cybersecuirtypulse&amp;utm_medium=p_referral&amp;utm_campaign=global|fixed|cloud_index"><span>Get the report</span></a></p></div><div><hr></div><h3><a href="https://opnova.ai/blog/opnova-sweeps-black-hat-startup-spotlight-competition">Opnova sweeps both Black Hat startup competitions</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LYB4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LYB4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp 424w, https://substackcdn.com/image/fetch/$s_!LYB4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp 848w, https://substackcdn.com/image/fetch/$s_!LYB4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp 1272w, https://substackcdn.com/image/fetch/$s_!LYB4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LYB4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88606,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LYB4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp 424w, https://substackcdn.com/image/fetch/$s_!LYB4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp 848w, https://substackcdn.com/image/fetch/$s_!LYB4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp 1272w, https://substackcdn.com/image/fetch/$s_!LYB4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc87f48d-4820-4437-9960-268f4fee887b_1200x675.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Opnova</strong> pulled off a clean sweep at Black Hat, beating fellow USA finalists <a href="https://blackhat.com/us-26/spotlight.html">Deception Check, Mallory, and Perpetual Systems</a> before topping regional champions <a href="https://blackhat.com/us-26/global-spotlight.html">Legion Security, Sahl, Geordie AI, and Prowler</a> in the inaugural global final later that day. Its computer-use agents handle identity operations across <a href="https://opnova.ai/">mainframes, Citrix, thick clients, and legacy portals</a>, including internal admin consoles with no SCIM connector, without replacing the existing IGA stack. </p><p>The awards are nice. Applying agents to one of IAM&#8217;s ugliest operational gaps is the more interesting part.</p><div><hr></div><h3><a href="https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/">NOVA reported 14,090 findings; only 26% of AI patches actually worked</a></h3><p>During Blackhat, <strong>Unit 42</strong> published an autonomous vulnerability discovery, validation and reporting system called Network and Open-Source Vulnerability Analyzer (NOVA) and reported <strong>14,090 vuln findings</strong> in two months. It built and replayed PoCs, then routed results to humans. The breakdown was: 4,141 were dependency exposures, 2,776 with working PoCs; 85 matched public records.</p><p>Our good friend <a href="https://www.linkedin.com/in/securingdev/">Keith Hoodlet</a> and the <strong><a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review">1Password</a></strong><a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review"> off-by-1 team published FLAWED</a>. It graded 6,080 model-generated patches for six difficult flaws after excluding 400 attempts that retrieved upstream fixes. Only <strong>26%</strong>closed every exploitable path without changing other behavior. Another <strong>20.1%</strong> fixed the flaw but changed semantics. The other <strong>53.9% </strong>failed, introduced a vulnerability, or both.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dlIB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dlIB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png 424w, https://substackcdn.com/image/fetch/$s_!dlIB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png 848w, https://substackcdn.com/image/fetch/$s_!dlIB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png 1272w, https://substackcdn.com/image/fetch/$s_!dlIB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dlIB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png" width="1350" height="1020" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1020,&quot;width&quot;:1350,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42915,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dlIB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png 424w, https://substackcdn.com/image/fetch/$s_!dlIB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png 848w, https://substackcdn.com/image/fetch/$s_!dlIB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png 1272w, https://substackcdn.com/image/fetch/$s_!dlIB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf4ec7fc-d0bd-47e2-9094-10460592fc76_1350x1020.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>More than one-third of top-scoring patches remained fragile, often blocking only the supplied PoC. Humans reviewed at least 10<strong>%  </strong>of each campaign; exact agreement with model validators was 65.9<strong>% </strong>.</p><p><strong>This research pretty much tells me that automated remediation still has a long way to go. What do you mean 54% of fixes failed or introduced a new vuln????</strong> </p><div><hr></div><h3><a href="https://www.cyberdaily.au/security/14018-fitness-phreak-aussie-man-accidentally-hacks-gym-with-ai-agent">OpenClaw removed a gym member while trying to book Pilates</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7k97!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7k97!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp 424w, https://substackcdn.com/image/fetch/$s_!7k97!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp 848w, https://substackcdn.com/image/fetch/$s_!7k97!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp 1272w, https://substackcdn.com/image/fetch/$s_!7k97!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7k97!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp" width="828" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:828,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42754,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7k97!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp 424w, https://substackcdn.com/image/fetch/$s_!7k97!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp 848w, https://substackcdn.com/image/fetch/$s_!7k97!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp 1272w, https://substackcdn.com/image/fetch/$s_!7k97!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F762b5d5c-5b9e-47fc-9116-fdddd8496676_828x400.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Australian Andrew Bird asked an OpenClaw assistant to book a gym class. The agent found that the provider&#8217;s GraphQL API allowed early bookings and lacked authorization checks on cancellations. <strong>When Bird asked whether it could improve his fourth-place waitlist position, it removed the person in first, then reported that it could not add them back.</strong></p><p>The model was not conducting security research. <strong>It was completing a normal task against a broken API with permission to act.</strong> Authorization checks cannot assume a human will stop at the intended interface.</p><div><hr></div><h3><a href="https://www.newswire.com/news/corma-the-first-frontier-defensive-cybersecurity-ai-lab-raises-60m-as-ai">Corma is training a defensive-security model from scratch</a></h3><p>One day after DEF CON 34, <strong><a href="https://corma.ai/#hero">Corma</a></strong> emerged from stealth with a <strong>$60M seed</strong> led by Sequoia Capital; Khosla Ventures and Coatue also participated. </p><p>It is training its own foundation model for defensive work using reinforcement learning and self-play in instrumented enterprise environments, then deploying agents across existing SOC, identity, cloud, and network tools. Corma also supports on-premises deployment and post-training on customer security data.</p><p>Its <a href="https://corma.ai/defensive-gap-research">launch research</a> ran four frontier models as attackers and defenders across 241 scored engagements spanning eight Active Directory domains, 64 VLANs, approximately 349 servers, and approximately 4,483 workstations. Attackers established verified, reboot-surviving backdoors in <strong>85%</strong> of runs. </p><p>Most security agents wrap a general model around a SOC workflow. We&#8217;ve recently seen an influx of small language, use-case specific models from Wiz, Cisco and more. Cool to see a well-backed startup solely focused on this approach. <strong>This is the way.</strong> </p><div><hr></div><h1>Threats and Research</h1><div><hr></div><h3><a href="https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/">Two Kerberos logic flaws enabled takeover and downgrade attacks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TZi-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TZi-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png 424w, https://substackcdn.com/image/fetch/$s_!TZi-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png 848w, https://substackcdn.com/image/fetch/$s_!TZi-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png 1272w, https://substackcdn.com/image/fetch/$s_!TZi-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TZi-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png" width="1400" height="716" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:716,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:85953,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TZi-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png 424w, https://substackcdn.com/image/fetch/$s_!TZi-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png 848w, https://substackcdn.com/image/fetch/$s_!TZi-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png 1272w, https://substackcdn.com/image/fetch/$s_!TZi-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F144475b3-bc54-463b-93c7-ee246e7d93bc_1400x716.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>After Microsoft patched them, Shai Laron presented both flaws at Black Hat USA and DEF CON 34. KerberLoss (CVE-2026-25177) uses LDAP-unfilterable Unicode to bypass forest-wide SPN uniqueness, enabling SPN-jacking, DoS, or NTLM fallback.</p><p>ResetNightmare (CVE-2026-27912) requires an attacker-writable or new user or computer object and a target past minimum password age. An attacker sets the target&#8217;s bare <code>sAMAccountName</code> as an object&#8217;s UPN, requests an <code>NT-ENTERPRISE</code> TGT, clears the UPN, and sends it to <code>kadmin/changepw:464</code>. This bypasses TGS exchange and the <code>PAC_REQUESTOR_SID</code> mismatch check, allowing a password reset, including for a Domain Admin.</p><p><strong>Patch DCs; hunt Event 5136.</strong></p><div><hr></div><h3><a href="https://www.varonis.com/blog/rovoblast">RovoBlast showed how a crafted link could poison an agent prompt</a></h3><p>Varonis debuted the fixed <a href="https://www.varonis.com/blog/rovoblast">RovoBlast</a> chain at DEF CON 34. Atlassian Rovo had accepted a <code>rovoChatPrompt</code> URL parameter as trusted input. A crafted link preloaded instructions into an authenticated session. Rovo searched content the victim could access, inserted it into the path of an attacker-controlled image URL, then fetched the image and sent the data out in the request. Atlassian fixed the issue before the presentation.</p><p>There was no permission bypass. Rovo inherited the user&#8217;s access, and a URL parameter became trusted instructions.</p><div><hr></div><h3><a href="https://tenetsecurity.ai/blog/ghostjacking-attacks-agentic-kill-chain/">Poisoned telemetry became instructions for AI agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DfcG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DfcG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png 424w, https://substackcdn.com/image/fetch/$s_!DfcG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png 848w, https://substackcdn.com/image/fetch/$s_!DfcG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png 1272w, https://substackcdn.com/image/fetch/$s_!DfcG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DfcG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png" width="1456" height="278" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:278,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:96878,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DfcG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png 424w, https://substackcdn.com/image/fetch/$s_!DfcG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png 848w, https://substackcdn.com/image/fetch/$s_!DfcG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png 1272w, https://substackcdn.com/image/fetch/$s_!DfcG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2bc1ce18-d4f6-4e19-80fe-09128ea5da5a_1644x314.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Tenet disclosed Ghostjacking on DEF CON 34&#8217;s Main Track. In tests using its own accounts, the researchers placed instructions inside Cloudflare, Datadog, and Sentry records. When an AI agent reviewed the telemetry, it treated the text as commands and used legitimate tools to change DNS, execute code, or pass a poisoned conclusion to another agent. Tenet says it also reported a Claude Desktop egress and sandbox bypass that Anthropic fixed before disclosure.</p><p>If an agent can read untrusted telemetry and remediate infrastructure, logs are both evidence and input.</p><div><hr></div><h3>More research worth reading</h3><ul><li><p><strong><a href="https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/">Agent platforms had critical flaws</a>:</strong> Ruflo exposed 233 MCP tools without authentication; <a href="https://www.oasis.security/blog/paperclip-agent-vulnerabilities">Paperclip</a> allowed unauthenticated access, DNS rebinding, and RCE.</p></li><li><p><strong><a href="https://plugandpwn.com/">Plug &amp; Pwn reached SYSTEM</a>:</strong> At DEF CON 34, forged USB identities on updated Windows 11 reached SYSTEM without login.</p></li><li><p><strong><a href="https://www.openssh.com/releasenotes.html">OpenSSH fixed restricted agent operations</a>:</strong> Version 10.5 fixed three issues; duplicate AI reports accelerated the release.</p></li><li><p><strong><a href="https://www.dragos.com/blog/dragos-industrial-ransomware-analysis-q2-2026">Industrial ransomware claims rose</a>:</strong> Dragos counted 1,140 Q2 incidents, 65 percent in manufacturing; none directly manipulated control systems.</p></li><li><p><strong><a href="https://zenity.io/research/ai-total">Zenity presented AI Total at Black Hat USA</a>:</strong> It found malicious skills using droppers, prompt changes, self-reinstallation, and skill-creator replacement.</p></li></ul><div><hr></div><h1><strong>Black Hat 2026 </strong>Product Launches</h1><div><hr></div><p>The launches land at different control points. Products that own credentials or sit inline with tool calls, network traffic, or runtime execution can prevent an action. Telemetry-only products can investigate it after the fact.</p><div><hr></div><h3><a href="https://1password.com/blog/introducing-1password-privileged-access">Identity and authorization controls for agents</a></h3><p><a href="https://1password.com/blog/introducing-1password-privileged-access">1Password Privileged Access</a> creates task-scoped access for humans and agents, then removes it. <a href="https://www.rubrik.com/blog/technology/26/8/introducing-rubrik-agent-identity-identity-for-agents-control-for-actions">Rubrik Agent Identity</a> issues short-lived tokens per tool call. <a href="https://www.varonis.com/blog/agent-intent-based-access-control">Varonis Agent IBAC</a> compares instructions with tool and data use before allowing or blocking actions. <a href="https://www.businesswire.com/news/home/20260803185432/en/Zero-Networks-Launches-New-Capability-to-Enforce-OWASPs-Least-Agency-Principle-for-Enterprise-AI">Zero Networks</a> applies identity microsegmentation, just-in-time access, and human approval to sensitive agent actions.</p><div><hr></div><h3><a href="https://www.c1.ai/blog/launch-week-roundup-agentic-control-plane">C1 launches discovery, credential custody, and tool-call enforcement</a></h3><p>In the week before Black Hat, <strong>C1</strong> (formerly ConductorOne) rolled out four parts of an Agentic Control Plane. Shadow AI Discovery inventories unsanctioned tools, agents, MCP servers, and exposed credentials. Agentic Vault can replace raw keys with governed references and issue short-lived, scoped credentials. Runtime Governance routes tool calls through an identity-aware gateway that can allow, redact, hold, or block before execution. The final layer flags unowned or misclassified machine identities and routes remediation through existing approval and audit workflows. The key part here is breadth across discovery, credential custody, and inline tool-call enforcement shipped together.</p><div><hr></div><h3><a href="https://www.legitsecurity.com/security-governance-for-ai-generated-code-legit-vibeguard">Endpoint, browser, network, and runtime controls</a></h3><p>Legit VibeGuard governs coding-agent commands, skills, and Model Context Protocol activity at the endpoint. <a href="https://www.menlosecurity.com/press-releases/menlo-security-extends-mars-to-secure-ai-assistants-and-coding-agents-like-microsoft-copilot-gemini-in-chrome-and-claude-code-against-prompt-injection-and-data-exfiltration">Menlo MARS</a> routes agent web sessions through remote disposable containers. <a href="https://www.checkpoint.com/press-releases/check-point-revolutionizes-the-firewall-market-new-ai-network-firewall-closes-the-networks-ai-blind-spot-everywhere/">Check Point&#8217;s AI Network Firewall</a> discovers agents and MCP traffic at the network layer. <a href="https://www.sweet.security/press-releases/sweet-security-brings-autonomous-protection-to-the-ai-enterprise-with-new-blocking-capabilities">Sweet Security</a> says it blocks unauthorized tool calls, sessions, prompt injection, and sensitive-data movement at runtime.</p><p>These controls cover different paths. Browser isolation does not govern a local shell, and network visibility does not replace tool authorization.</p><div><hr></div><h3><a href="https://www.paloaltonetworks.com/blog/2026/08/redefining-network-security-for-the-frontier-ai-era/">Virtual patching expanded while remediation quality lagged</a></h3><p>Palo Alto Networks added Advanced Virtual Patching to PAN-OS 12.2. <a href="https://www.contrastsecurity.com/contrast-cve-shield">Contrast CVE Shield</a> wraps vulnerable Java methods in a runtime microsandbox. <a href="https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure">Qualys InstaScan</a> correlates advisories with existing inventory and telemetry instead of waiting for another scheduled scan.</p><div><hr></div><h3><a href="https://clover.security/blog/introducing-kura-adaptive-security-context-built-for-secure-agentic-coding/">Clover gave coding agents task-specific security context</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tshx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tshx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png 424w, https://substackcdn.com/image/fetch/$s_!tshx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png 848w, https://substackcdn.com/image/fetch/$s_!tshx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png 1272w, https://substackcdn.com/image/fetch/$s_!tshx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tshx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png" width="1456" height="489" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b43d44e7-1773-497c-8255-24575ba3591c_1680x564.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:489,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:420320,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tshx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png 424w, https://substackcdn.com/image/fetch/$s_!tshx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png 848w, https://substackcdn.com/image/fetch/$s_!tshx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png 1272w, https://substackcdn.com/image/fetch/$s_!tshx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43d44e7-1773-497c-8255-24575ba3591c_1680x564.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Kura pulls task-specific threats and countermeasures from a living threat model while agents build. In Clover&#8217;s experiment across Plane, Kubernetes, and Grafana, feature-tailored context mitigated 84 percent of planted business-logic flaws on average; broad context reached 33 percent.</p><p>I&#8217;m a big fan of their approach to securing AI-native development. <a href="https://www.cybersecuritypulse.net/p/the-appsec-model-was-built-for-a">I wrote about Clover&#8217;s broader thesis in March</a>. Kura is one of the few security products that really impresses me in this age of sameness because it works where business-logic mistakes start. The threat model still has to stay current, and the code still needs verification.</p><div><hr></div><h3><a href="https://snyk.io/blog/evo-continuous-offensive-security/">&#8220;Agentic pentesting&#8221; from different angles</a></h3><p><strong>What&#8217;s new:</strong></p><ul><li><p><strong><a href="https://horizon3.ai/news/press-release/nodezero-webapp-launch/">Horizon3.ai NodeZero WebApp</a>:</strong> Runs production-safe web tests and chains findings into infrastructure, identity, and cloud attack paths.</p></li><li><p><strong><a href="https://snyk.io/blog/evo-continuous-offensive-security/">Snyk Evo</a>:</strong> Runs continuous, context-aware multi-stage tests as software changes, then uses a second model to validate exploitability.</p></li><li><p><strong><a href="https://www.bugcrowd.com/blog/introducing-savant-pathseeker-agentic-pentesting-for-preemptive-security/">Bugcrowd Savant Pathseeker</a>:</strong> Tests web apps and APIs, returns exploit evidence, and works beside human-led testing.</p></li></ul><p>Not all agentic pentest tools are created equally. Compare scope, exploit proof, <strong>production safety</strong>, retesting, and human involvement. </p><div><hr></div><h3><a href="https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/">OpenAI split approved cyber access into Blue and Red</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QP3j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QP3j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png 424w, https://substackcdn.com/image/fetch/$s_!QP3j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png 848w, https://substackcdn.com/image/fetch/$s_!QP3j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png 1272w, https://substackcdn.com/image/fetch/$s_!QP3j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QP3j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:149525,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/210740043?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QP3j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png 424w, https://substackcdn.com/image/fetch/$s_!QP3j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png 848w, https://substackcdn.com/image/fetch/$s_!QP3j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png 1272w, https://substackcdn.com/image/fetch/$s_!QP3j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe44950ec-8edd-46a3-97ec-7e7270a9f1d1_1800x1013.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>OpenAI expanded Daybreak on August 10. Blue gives approved defenders GPT-5.6 Sol with safeguards calibrated for defensive work. Red separately provisions GPT-5.6 Cyber with fewer refusals for exploit development and advanced testing.</p><p>OpenAI says its researchers used GPT-5.6 Cyber to find two previously unknown V8 vulnerabilities that chain into a V8 heap-sandbox escape. Google fixed the first as CVE-2026-15903; OpenAI did not detail the second flaw or its status. Approval does not contain the model by itself. Logging, scope, and environment isolation still carry the risk.</p><div><hr></div><h3>Other launches</h3><ul><li><p><strong><a href="https://www.opal.dev/blog/opal-mcp">Opal rebuilt its MCP servers before Black Hat</a>:</strong> It introduced three role-scoped servers: end-user, admin provisioning, and admin auditing, with first-party or self-hosted deployment. The provisioning server can approve or deny requests in chat.</p></li><li><p><strong><a href="https://www.huntress.com/blog/managed-espm-app-control-rmm-protection">Huntress RMM Guard</a>:</strong> Inventories remote-monitoring tools and moves unauthorized instances toward blocking.</p></li><li><p><strong><a href="https://blackcloak.io/news-media/blackcloak-extends-deepfake-protection-to-the-executives-entire-trusted-circle/">BlackCloak Circle of Trust</a>:</strong> Extends out-of-band impersonation checks to executives&#8217; families, assistants, lawyers, and trusted contacts.</p></li><li><p><strong><a href="https://zimperium.com/resources/zimperium-deep-insights-cuts-mobile-incident-investigation-time-from-weeks-to-minutes">Zimperium Deep Insights</a>:</strong> Reconstructs mobile attack timelines and compares device state before and after travel or suspected compromise.</p></li></ul><div><hr></div><h2>FUNDING</h2><p>The 13 selected announcements, including the two seed mini PICKS above, total $1.269B. Most of the capital went toward autonomous testing, agent controls, runtime security, identity, and infrastructure.</p><ul><li><p><strong><a href="https://horizon3.ai/news/press-release/horizon3-raises-250m-series-e-at-2b-valuation-to-lead-the-ai-vs-ai-cybersecurity-era/">Horizon3.ai raised $250M in Series E funding</a>.</strong> NodeZero runs autonomous pentests across infrastructure, cloud, identity, and web applications. NightDragon and NEA co-led.</p></li><li><p><strong><a href="https://spur.us/news/insight-partners-spur-intelligence-investment">Spur received a $200M investment</a>.</strong> Spur maps VPNs, residential proxies, bot networks, and other anonymized IP traffic. Insight Partners backed the company; Spur did not label it as a conventional round.</p></li><li><p><strong><a href="https://www.threatlocker.com/press-release/threatlocker-secures-190-million-in-series-f-funding-to-drive-product-innovation-and-global-expansion">ThreatLocker raised $190M in Series F funding</a>.</strong> ThreatLocker provides deny-by-default application allowlisting, endpoint controls, and access policies. Elephant led, with Koch Disruptive Technologies, D. E. Shaw Ventures, and Arthur Ventures participating.</p></li><li><p><strong><a href="https://zenity.io/company-overview/newsroom/company-news/zenity-raises-125-million-to-secure-the-era-of-1-billion-ai-agents">Zenity raised $125M in Series C funding</a>.</strong> Zenity discovers and governs enterprise AI agents, their identities, and their actions. Norwest led, with Qumra, SoftBank Vision Fund 2, Hitachi Ventures, and LG Technology Ventures joining.</p></li><li><p><strong><a href="https://www.onyx.security/blog/onyx-113m-series-b-keeping-humans-in-control-as-ai-becomes-smarter">Onyx Security raised $113M in Series B funding</a>.</strong> Onyx discovers agents across endpoints, browsers, SaaS, and cloud, then inspects their actions before execution. Bessemer led, with Cyberstarts, TCV, Conviction, FirstMark, Vintage, QuantumLight, and G Squared participating.</p></li><li><p><strong><a href="https://www.groundcover.com/blog/groundcover-raises-series-c">groundcover raised $100M in Series C funding</a>.</strong> groundcover provides full-stack observability from production telemetry for applications and infrastructure. One Peak led, with Morgan Stanley Expansion Capital and existing investors participating.</p></li><li><p><strong><a href="https://www.obsidiansecurity.com/news/unlocking-ai-potential-securely">Obsidian Security raised $85M in Series D funding</a>.</strong> Obsidian monitors SaaS and enterprise-agent activity, data access, and identity risk. Crescent Cove Advisors led.</p></li><li><p><strong><a href="https://www.businesswire.com/news/home/20260804840699/en/OLIGO-Security-Crosses-%24140M-in-Total-Funding-with-%2460M-Round-to-Stop-AI-Driven-Attacks">Oligo Security raised $60M</a>.</strong> Oligo monitors application runtime behavior, blocks exploits, and prioritizes reachable vulnerabilities. The company did not specify a round label.</p></li><li><p><strong><a href="https://www.inforcer.com/insights/inforcer-raises-50m-series-c">inforcer raised $50M in Series C funding</a>.</strong> inforcer helps managed service providers secure and govern many customers&#8217; Microsoft 365 tenants. Insight Partners led, with Dawn Capital and Meritech Capital participating.</p></li><li><p><strong><a href="https://www.1011vc.com/news/bloom-security-launches-with-20-million-seed-to-secure-the-ai-native-endpoint">Bloom Security launched with a $20M seed round</a>.</strong> Bloom inventories and governs coding agents, MCP servers, browser extensions, and packages on AI-native endpoints. Glilot Capital led, with Ten Eleven Ventures, Okta Ventures, Runtime Ventures, and operator angels participating.</p></li><li><p><strong>Cantina added <a href="https://www.prnewswire.com/news-releases/cantina-launches-from-stealth-backed-by-8-million-to-automate-security-for-the-age-of-autonomous-attacks-302838963.html">$8M in fresh funding</a>.</strong> <a href="https://cantina.xyz/blog/the-next-chapter-of-cantina">Clarion</a> uses shared context and agents to investigate, remediate, and verify findings; Cantina also operates researcher-powered validation. Framework Ventures led.</p></li></ul><div><hr></div><h2><strong>DEALS</strong></h2><ul><li><p><strong><a href="https://investor.visa.com/news/news-details/2026/Visa-to-Acquire-BioCatch/default.aspx">Visa agreed to acquire BioCatch for $2.4B in cash</a>.</strong> The deal adds behavioral and device intelligence to Visa&#8217;s fraud stack.</p></li><li><p><strong><a href="https://www.okta.com/newsroom/press-releases/okta-signs-definitive-agreement-to-acquire-permiso-security/">Okta signed an agreement to acquire Permiso Security</a>.</strong> Terms were not disclosed. <a href="https://techcrunch.com/2026/07/30/okta-buys-ai-security-startup-permiso-source-says-for-about-200m/">TechCrunch reported</a> a price just under $200M.</p></li><li><p><strong><a href="https://newsroom.bankofamerica.com/content/newsroom/press-releases/2026/07/bank-of-america-to-acquire-information-security-consultancy-mdse.html">Bank of America agreed to acquire MDSec</a>.</strong> The bank is bringing offensive research and adversary-simulation expertise in-house.</p></li><li><p><strong><a href="https://www.keyfactor.com/press-releases/keyfactor-announces-intent-to-acquire-cofide-to-bring-verified-identity-to-ai-agents-and-cloud-workloads/">Keyfactor announced its intent to acquire Cofide</a>.</strong> The deal extends machine identity into workload and agent attestation.</p></li></ul><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[TCP 140: I Wrote a Book on AI Logging, Runlayer Sues Rippling, and Cyera Bets $1B ]]></title><description><![CDATA[Wiz says Atlas found 200+ unknown vulns, Google reset threat actor naming, and 7AI federated search.]]></description><link>https://www.cybersecuritypulse.net/p/i-wrote-a-book-on-ai-logging-runlayer</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/i-wrote-a-book-on-ai-logging-runlayer</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 29 Jul 2026 14:03:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2Ds1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/i-wrote-a-book-on-ai-logging-runlayer?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/i-wrote-a-book-on-ai-logging-runlayer?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Ds1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Ds1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp 424w, https://substackcdn.com/image/fetch/$s_!2Ds1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp 848w, https://substackcdn.com/image/fetch/$s_!2Ds1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp 1272w, https://substackcdn.com/image/fetch/$s_!2Ds1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Ds1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/daf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:197156,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208899864?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2Ds1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp 424w, https://substackcdn.com/image/fetch/$s_!2Ds1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp 848w, https://substackcdn.com/image/fetch/$s_!2Ds1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp 1272w, https://substackcdn.com/image/fetch/$s_!2Ds1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdaf8df6c-de46-4ff8-a97d-c57f87f89c9c_1456x1052.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Hi &#128075;&#127997; Hope you&#8217;re having a great week wherever you&#8217;re reading from!</p><p>Big week over here. After four months mapping what eight AI tools log, miss, and let defenders detect, we published <a href="https://www.monad.com/blog/book-launch-a-security-field-guide-to-ai-tooling-visibility">A Security Field Guide to AI Tooling Visibility</a>. The 78-page PDF is free and ungated. We&#8217;ll also have free hard copies at Black Hat, or you can request one for U.S. shipping. </p><p>To my friends and the TCP ecosystem, if I&#8217;ve been late to respond, this is a huge reason why &#128517;.. </p><p>Hacker Summer Camp is next week, so I also put together a <a href="https://www.cybersecuritypulse.net/p/2026-hacker-summer-camp-field-guide">2026 Hacker Summer Camp Field Guide</a> with my picks for the talks, side events, Vegas side quests, and where to find me. This will be my eighth one, I&#8217;ll be there from Monday through Friday.</p><p>We also announced the <a href="https://www.monad.com/blog/monad-scanner-security-data-foundation">Monad + Scanner security data architecture</a>, pairing clean logs from 350+ sources upstream with fast search, live detections, and investigations across years of logs downstream. Think modular SecOps for humans and agents, without forcing every byte into a SIEM.</p><p>Unfortunately for my free time and sanity, security did not cooperate with a quiet news week. It never does actually. Looking forward to getting back to normal life after Blackhat. </p><p>Now, onto the news!</p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><span>Introducing </span><a href="http://detections.ai"><span>detections.ai</span></a><span> Enterprise - coverage and maintenance handled</span></h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Dr5_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Dr5_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png 424w, https://substackcdn.com/image/fetch/$s_!Dr5_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png 848w, https://substackcdn.com/image/fetch/$s_!Dr5_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png 1272w, https://substackcdn.com/image/fetch/$s_!Dr5_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Dr5_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png" width="594" height="86.89697802197803" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:213,&quot;width&quot;:1456,&quot;resizeWidth&quot;:594,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Dr5_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png 424w, https://substackcdn.com/image/fetch/$s_!Dr5_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png 848w, https://substackcdn.com/image/fetch/$s_!Dr5_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png 1272w, https://substackcdn.com/image/fetch/$s_!Dr5_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a29f81c-001d-44b2-929b-de29d6913cec_2048x300.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;"><span>A new threat drops and you need to move quickly. Run coverage analysis across your whole detection stack, build detections tuned directly for your environment, and deploy them back. In minutes, not days.<br></span></p><p style="text-align: center;"><span>But coverage isn&#8217;t a one-time win. Detections drift, IOCs go stale, duplicate rules pile up. Our AI agents catch it while you sleep, so nothing slips through unnoticed and your team spends its time on real threats, not upkeep.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://detections.ai/book-a-demo?utm_source=tcp&amp;utm_medium=newsletter&amp;utm_campaign=enterprise&amp;utm_content=post1&quot;,&quot;text&quot;:&quot;Book a walkthrough&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://detections.ai/book-a-demo?utm_source=tcp&amp;utm_medium=newsletter&amp;utm_campaign=enterprise&amp;utm_content=post1"><span>Book a walkthrough</span></a></p></div><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#128218; <strong><a href="https://www.monad.com/blog/book-launch-a-security-field-guide-to-ai-tooling-visibility">We launched a book on AI tooling native logs</a>:</strong> Our 78-page guide maps eight AI log sources and is free, ungated. Covers all the Claudes, OpenAI, Cursor, Gemini and more.</p></li><li><p>&#129514; <strong><a href="https://www.wiz.io/blog/atlas-ai-vulnerability-researcher?utm_source=chatgpt.com">Wiz builds an autonomous researcher</a>:</strong> Atlas uncovered 200+ unknown flaws and autonomously proved each was exploitable.</p></li><li><p>&#129354; <strong><a href="https://www.prnewswire.com/news-releases/runlayer-files-suit-against-rippling-alleging-trade-secrets-misappropriation-in-sdny-over-ai-product-clone-seeks-preliminary-injunction-302836968.html">MCP trial becomes lawsuit</a>:</strong> Runlayer alleges Rippling cloned its gateway after a nearly year-long enterprise trial.</p></li><li><p>&#129516; <strong><a href="https://www.cyera.com/blog/one-platform-to-secure-the-agentic-enterprise">Cyera to acquire Oasis for $1B</a>:</strong> Cyera signed an LOI to acquire Oasis in a reported billion-dollar deal.</p></li><li><p>&#128029; <strong><a href="https://github.com/block/buzz">Every agent gets a keypair</a>:</strong> Block&#8217;s open-source Buzz gives agents distinct identities and signed audit trails.</p></li><li><p>&#127991;&#65039; <strong><a href="https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system">Google resets the alias map</a>:</strong> Google unified its naming systems and gave everyone another alias map to maintain.</p></li></ul><p><strong>Plus:</strong> a federated SIEM zig, more runtime agent controls, and more startups out of stealth becuase why not! </p><div><hr></div><h3><a href="https://www.monad.com/blog/book-launch-a-security-field-guide-to-ai-tooling-visibility">&#128218; Book Launch: What eight AI tools log, what they miss, and what defenders can detect</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4KTN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4KTN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!4KTN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!4KTN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!4KTN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4KTN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1632391,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208899864?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4KTN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!4KTN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!4KTN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!4KTN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53252e88-3749-4bb1-aa72-e098de4a441c_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I haven&#8217;t worked as a detection engineer in a few years, but AI tooling gave that part of my brain a fresh batch of logs to pick apart and obsess over </p><p>In March, our engineering team began mapping <a href="https://www.monad.com/blog/detection-engineering-for-claude-code-part-1">what Claude Code emits over OpenTelemetry</a>. I added the detection lens: What gets logged? How do we collect and normalize it? Which fields map to real TTPs? What should we detect? Where are we blind? That framework became seven more chapters:</p><ul><li><p>Claude Code and Claude Cowork</p></li><li><p>ChatGPT Enterprise and OpenAI Codex</p></li><li><p>Cursor and GitHub Copilot</p></li><li><p>Gemini in Google Workspace and Anthropic&#8217;s compliance activity log</p></li></ul><p>At Monad, we work with companies including Robinhood, CoreWeave, Lambda, and Rubrik. Building integrations for these sources exposed the weirdness firsthand: nested OpenTelemetry payloads, inconsistent schemas, short retention, missing identifiers, and logs that prove a tool ran without showing what it did.</p><p>Four months later, that work became <a href="https://www.monad.com/blog/book-launch-a-security-field-guide-to-ai-tooling-visibility">A Security Field Guide to AI Tooling Visibility</a>, a 78-page map of what each source records, misses, and lets defenders realistically detect. </p><p><strong>This book is meant for defenders across the SecOps spectrum from detection engineers to SOC analysts to threat hunters to DFIR pros.</strong> </p><p>Huge thanks to Matt Jane and Curtis Redgate for kicking off the Claude Code telemetry work, and to Kenneth Kaye and Valerie Worman for contributing and helping get the guide over the line.</p><p>The PDF is free and ungated. We&#8217;ll have free hard copies at Black Hat, or you can <a href="https://www.monad.com/ai-tooling-visibility-book">request one for U.S. shipping</a> while supplies last.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.monad.com/blog/book-launch-a-security-field-guide-to-ai-tooling-visibility&quot;,&quot;text&quot;:&quot;Ungated PDF here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.monad.com/blog/book-launch-a-security-field-guide-to-ai-tooling-visibility"><span>Ungated PDF here</span></a></p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><a href="https://www.wiz.io/blog/atlas-ai-vulnerability-researcher">Wiz says Atlas found 200+ unknown vulns as cyber AI goes purpose-built</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DbAD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DbAD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp 424w, https://substackcdn.com/image/fetch/$s_!DbAD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp 848w, https://substackcdn.com/image/fetch/$s_!DbAD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp 1272w, https://substackcdn.com/image/fetch/$s_!DbAD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DbAD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp" width="1456" height="853" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:853,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DbAD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp 424w, https://substackcdn.com/image/fetch/$s_!DbAD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp 848w, https://substackcdn.com/image/fetch/$s_!DbAD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp 1272w, https://substackcdn.com/image/fetch/$s_!DbAD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc32d069-8274-4e5b-ad9a-969797bfa88a_1912x1120.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Wiz</strong> built Atlas as a multi-agent vulnerability researcher. It maps code with a code property graph, spins up competing exploit hypotheses, has agents argue over exploitability, then builds an execution environment to prove each finding.</p><p>Wiz says Atlas found more than <strong>200 previously unknown vulnerabilities</strong> across Kubernetes, the Linux kernel, containerd, gVisor, grpc, and dnsmasq. It also <a href="https://www.cybergym.io/cybergym/">tops CyberGym</a> at <strong>90.9%</strong>.</p><p><strong>Important caveat:</strong> CyberGym Level 1 gives the system vulnerable code and a description, so it measures exploit reproduction, <strong>not blank-page discovery.</strong> </p><p>Purpose-built security AI models are spreading up and down the stack (<a href="https://www.cybersecuritypulse.net/p/splunk-conf-2025-recap">I highlighted this is the way to go last year</a>):</p><ul><li><p><strong>Google</strong> lined up <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/">Gemini 3.5 Flash Cyber</a> for a limited-access CodeMender pilot.</p></li><li><p><strong>Microsoft</strong> built <a href="https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/">MAI-Cyber-1-Flash</a> into MDASH.</p></li><li><p><strong>Cisco</strong> already has a <a href="https://blogs.cisco.com/ai/cisco-deep-network-model-overview">Deep Network Model</a> for troubleshooting and automation, and <a href="https://www.theregister.com/networks/2026/07/28/cisco-close-to-releasing-more-ai-models-this-time-for-deep-networking-ops/5279350">told The Register</a> that more models are headed to Hugging Face.</p></li></ul><p>Models will continue to evolve but the key is in scoping, orchestration, evals, runtime validation, and cost. <strong>The harness is what compounds.</strong></p><div><hr></div><div class="callout-block" data-callout="true"><p style="text-align: center;"><strong>Secure AI and the data that powers it with Varonis</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QvcJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QvcJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png 424w, https://substackcdn.com/image/fetch/$s_!QvcJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png 848w, https://substackcdn.com/image/fetch/$s_!QvcJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png 1272w, https://substackcdn.com/image/fetch/$s_!QvcJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QvcJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png" width="520" height="86.944" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:209,&quot;width&quot;:1250,&quot;resizeWidth&quot;:520,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QvcJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png 424w, https://substackcdn.com/image/fetch/$s_!QvcJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png 848w, https://substackcdn.com/image/fetch/$s_!QvcJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png 1272w, https://substackcdn.com/image/fetch/$s_!QvcJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16caa1fb-6160-4559-9109-28f1ba5856de_1250x209.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;"><span>AI adoption is outpacing most teams&#8217; ability to secure it. Varonis Atlas is the only platform that secures AI from the moment it&#8217;s built to the moment it&#8217;s running in production, with the data context that point solutions can&#8217;t match.</span></p><p style="text-align: center;"><span>See Atlas in action during Black Hat USA at Varonis&#8217; booth (#2948). Can&#8217;t make it to Vegas? Book a demo today.</span></p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://hubs.ly/Q04r4PCT0&quot;,&quot;text&quot;:&quot;Learn more about Varonis Atlas&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://hubs.ly/Q04r4PCT0"><span>Learn more about Varonis Atlas</span></a></p></div><div><hr></div><h4><a href="https://techcrunch.com/2026/07/28/mcp-startup-runlayer-accuses-rippling-of-stealing-its-product-idea/">Runlayer sues Rippling over an alleged MCP gateway clone</a></h4><p><strong><a href="https://www.runlayer.com/">Runlayer</a></strong> <a href="https://www.prnewswire.com/news-releases/runlayer-files-suit-against-rippling-alleging-trade-secrets-misappropriation-in-sdny-over-ai-product-clone-seeks-preliminary-injunction-302836968.html">sued </a><strong><a href="https://www.prnewswire.com/news-releases/runlayer-files-suit-against-rippling-alleging-trade-secrets-misappropriation-in-sdny-over-ai-product-clone-seeks-preliminary-injunction-302836968.html">Rippling</a></strong> in Manhattan federal court, alleging trade secret theft, unfair competition, and breach of contract <strong>after a nearly year-long enterprise trial. Wild drama in SDNY. </strong></p><p>Runlayer&#8217;s complaint alleges that:</p><ul><li><p>The companies signed a mutual NDA and trial agreement barring Rippling from copying Runlayer&#8217;s IP or creating derivative works.</p></li><li><p>Runlayer shared its roadmap, source code, deployment architecture, and engineering support during the trial.</p></li><li><p>After commercial talks failed and Runlayer cut access in June, an alleged Rippling insider told CEO Andrew Berman that an internal team was building &#8220;<strong>almost a 1 to 1 copy.</strong>&#8221;</p></li></ul><p>Rippling confirmed it is launching an MCP gateway but denied using Runlayer IP. None of Runlayer&#8217;s claims have been proven yet. </p><div><hr></div><h4><a href="https://github.com/block/buzz">Block gives every agent its own cryptographic identity</a></h4><p>Block open sourced <strong>Buzz</strong>, a self-hostable workspace where humans and agents share channels, repos, and workflows. Every participant gets a keypair, turning messages, patches, approvals, and workflow actions into <strong>signed events.</strong></p><p>That tackles a real security problem that I think is blowing up in enterprises currently. Agents often inherit a user session or shared service account, making attribution fuzzy when several agents touch the same tools. <strong>Buzz gives each agent a distinct identity, scoped access, and its own audit trail.</strong></p><p>Signatures prove which key acted, not whether the action was safe or properly authorized.</p><div><hr></div><h4><a href="https://blog.7ai.com/building-a-foundation-for-ai-in-security">7AI launches a federated SIEM as the SecOps stack converges</a></h4><p>7AI recently launched Federated SIEM, which lets its agents query, investigate, and act across existing SIEMs, data lakes, and cloud platforms without forcing customers through a migration. It also launched 7AI Build, a way for customers and partners to package their own techniques into workflows and services.</p><p>That puts 7AI in more direct competition with <a href="https://vega.io/">Vega</a>, <a href="https://www.query.ai/federated-search/">Query</a>, and other federated-search players, not just agentic triage startups.</p><p>SecOps categories keep folding into each other. SIEMs now ship threat hunting, detection, response, and triage agents. Pipeline vendors are buying detection content vendors. Agent vendors are moving into search. </p><p>Everyone wants to be <em>the</em> SecOps platform. Zig. Zag. </p><div><hr></div><h4><a href="https://www.cyera.com/blog/one-platform-to-secure-the-agentic-enterprise">Cyera&#8217;s reported $1B Oasis LOI joins data security with agent identity</a></h4><p>Cyera signed a letter of intent to acquire Oasis Security in a deal <a href="https://techcrunch.com/2026/07/28/cyera-agrees-to-acquire-oasis-security-for-1b-to-safeguard-proliferating-ai-agents/">reportedly valued at roughly </a><strong><a href="https://techcrunch.com/2026/07/28/cyera-agrees-to-acquire-oasis-security-for-1b-to-safeguard-proliferating-ai-agents/">$1 billion</a></strong>. Cyera maps sensitive data and who can reach it. Oasis inventories non-human identities, including service accounts, workloads, and AI agents, then governs their access. Together, they can answer both sides of the agent security problem: what can this identity do, and what data can it touch?</p><p><strong>Funding context:</strong></p><ul><li><p><strong>Oasis</strong> had raised <strong>$195 million</strong> in total.</p></li><li><p>Its latest round was a <strong>$120 million Series B</strong> led by Craft Ventures, with Cyberstarts, Sequoia Capital, and Accel participating.</p></li><li><p><strong>Cyera</strong> raised a <strong>$600 million Series G</strong> in June, led by Evolution Equity Partners at a <strong>$12 billion</strong> valuation.</p></li></ul><p>The market spent years treating data security and identity as adjacent categories. Not any more. </p><div><hr></div><h4><a href="https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system">Google standardizes threat names, Google-style</a></h4><p><strong>As if the industry needed any more threat group naming conventions &#129318;&#127997;&#8205;&#9794;&#65039;</strong></p><p><strong>Google Threat Intelligence Group</strong> has begun rolling Mandiant and Threat Analysis Group&#8217;s parallel naming systems into two-word cryptonyms. China-linked groups end in CASTLE, Iranian groups in ION, North Korean groups in NEPTUNE, Russian groups in RELIC, and cybercriminal clusters in COMET. </p><p>&#8220;We&#8217;re seeing an uptick in ransomware by NEPTUNE BLizzard Forrest Cozy Fuzzer&#8221; </p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><h4><a href="https://www.hush.security/resources/hush-security-raises-30m-to-close-the-ai-agent-governance-gap-with-akamai-joining-as-strategic-investor/">Hush raises $30M for agent governance rooted in identity</a></h4><p><a href="https://www.hush.security/">Hush Security</a> raised a $30 million Series A, with Akamai joining existing investors Battery Ventures and YL Ventures. </p><p>Its platform registers AI agents, removes standing credentials, grants scoped just-in-time access at runtime, records each action, and provides a centralized kill switch. Hush started with non-human identity security and is extending that control plane to agents. That is more concrete than another AI inventory dashboard, but the proof will be how broadly it can enforce short-lived access across enterprise apps and agent frameworks.</p><div><hr></div><h2><strong>Cloud Security</strong></h2><h4><a href="https://act.security/resources/securing-the-foundation-act-security-launches-to-eliminate-the-root-cause-of-every-breach">Act Security exits stealth with $60M to shrink cloud attack paths</a></h4><p><strong><a href="https://act.security/">Act Security</a></strong> <a href="https://www.prnewswire.com/news-releases/act-security-launches-action-centric-cloud-security-platform-with-60-million-in-funding-302836148.html">emerged from stealth with </a><strong><a href="https://www.prnewswire.com/news-releases/act-security-launches-action-centric-cloud-security-platform-with-60-million-in-funding-302836148.html">$60 million</a></strong> across a seed led by Team8 and Bessemer Venture Partners and a Series A led by Notable Capital. Hetz Ventures, Claltech, Startpoint Capital, and SVCI also participated. Founded by the team behind Medigate, Act maps cloud access paths and enforces boundaries around what humans, workloads, and AI agents can reach. It does not patch the vulnerabilities. The &#8220;root cause of every breach&#8221; pitch runs hot, but shrinking attack paths is saner than treating every CVE like a fire drill.</p><div><hr></div><h2><strong>Data Security </strong></h2><h4><a href="https://www.cyberhaven.com/press-releases/cyberhaven-introduces-flow-ai-native-data-security">Cyberhaven Flow follows data through human and agent workflows</a></h4><p><strong><a href="https://www.cyberhaven.com/">Cyberhaven</a></strong> took the wraps off Flow, now in early access with broader availability expected in the coming quarter. It connects data lineage, identity, and behavior across endpoints, browsers, and cloud services as humans and agents touch sensitive data. It captures prompts, tool calls, file reads, and responses, then carries classification and data loss prevention policy forward as content gets copied, split up, or transformed. Embedded agents help with configuration, detection, and analysis. Preserving context through the workflow is the useful part. The question is how much lineage survives once agents hop across vendors, clouds, and private systems.</p><div><hr></div><h2><strong>Email Security</strong></h2><h4><a href="https://www.prnewswire.com/news-releases/aegisai-raises-36-million-series-a-led-by-battery-ventures-to-fight-the-new-wave-of-ai-spear-phishing-302833624.html">AegisAI raises $36M to fight AI-generated spear phishing</a></h4><p><strong><a href="https://www.aegisai.ai/">AegisAI</a></strong><a href="https://www.aegisai.ai/"> </a>raised a <strong>$36 million Series A</strong> led by Battery Ventures, with Accel and Foundation Capital participating. Founded by former Google security leaders Cy Khormaee and Ryan Luo, the startup uses its own language models and a fleet of agents to inspect email intent, identity, links, attachments, QR codes, and behavioral signals. It is also pushing Vanguard, a threat-hunting agent that looks beyond the inbox.</p><div><hr></div><h2><strong>Identity and Access Management</strong></h2><h4><a href="https://saviynt.com/press-release/saviynt-launches-zuma-ai-security-platform">Saviynt brings runtime authorization to AI identities</a></h4><p><strong><a href="https://saviynt.com/">Saviynt</a></strong> is pushing agent governance into the runtime with Zuma. The platform discovers AI agents and non-human identities, maps owners and permissions, and governs their lifecycle. Zuma Access evaluates each action using identity, context, risk, policy, and stated intent; Zuma Governance handles access reviews, audit trails, ownership, and containment. </p><div><hr></div><h2><strong>Security Operations</strong></h2><h4><a href="https://www.fig.security/resources/blog/fig-launches-secops-cicd/">Fig brings CI/CD mechanics to detection engineering</a></h4><p><strong><a href="https://www.fig.security/resources/blog/fig-launches-secops-cicd/">Fig</a></strong> is bringing a software-engineering workflow to detections, parsers, and configuration changes. Its security data lineage graph maps dependencies across the stack, then lets teams simulate changes against the live environment before deployment. Changes can be tested, versioned, rolled back, and continuously checked for broken detection flows. </p><p>Fig calls it the first true CI/CD for SecOps. </p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[2026 Hacker Summer Camp Field Guide]]></title><description><![CDATA[My picks for the talks, side events, and Vegas side quests]]></description><link>https://www.cybersecuritypulse.net/p/2026-hacker-summer-camp-field-guide</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/2026-hacker-summer-camp-field-guide</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Tue, 28 Jul 2026 22:21:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dVK2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/2026-hacker-summer-camp-field-guide?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/2026-hacker-summer-camp-field-guide?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dVK2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dVK2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!dVK2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!dVK2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!dVK2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dVK2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2764067,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208846650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dVK2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!dVK2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!dVK2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!dVK2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab01fea-760c-4437-9da7-ef01c1795924_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>If you&#8217;re anything like me, this week is pure chaos in the best and worst ways. Next week, many of us (about 30-40K) will be descending on Las Vegas for our annual Hacker Summer Camp pilgrimmage. This will be my eighth Hacker Summer Camp. I&#8217;ve experienced it as a college student, full-time practitioner, DEF CON workshop instructor, and now from the GTM and newsletter side.</p><p>If this is your first hacker summer camp or if you&#8217;d simply like to get in the spirit, check out this cool documentary the captures the originating ethos of the week very well: </p><div id="youtube2-3ctQOmjQyYg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;3ctQOmjQyYg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/3ctQOmjQyYg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Now, here&#8217;s my quick braindump of what I&#8217;m most excited about, a few practical tips, and where you can find me Monday through Friday. </p><div><hr></div><h2>The four things at the top of my list</h2><h3><a href="https://www.c1.ai/lp/ciso-roast-2026?utm_source=securitypulse">CISO Roast</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uqnT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uqnT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp 424w, https://substackcdn.com/image/fetch/$s_!uqnT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp 848w, https://substackcdn.com/image/fetch/$s_!uqnT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp 1272w, https://substackcdn.com/image/fetch/$s_!uqnT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uqnT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp" width="1280" height="498" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:498,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:90518,&quot;alt&quot;:&quot;CISO Roast 2026&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="CISO Roast 2026" title="CISO Roast 2026" srcset="https://substackcdn.com/image/fetch/$s_!uqnT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp 424w, https://substackcdn.com/image/fetch/$s_!uqnT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp 848w, https://substackcdn.com/image/fetch/$s_!uqnT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp 1272w, https://substackcdn.com/image/fetch/$s_!uqnT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f439b54-0c17-4aef-9b3e-bd5d1bc1e892_1280x498.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <a href="https://www.c1.ai/lp/ciso-roast-2026?utm_source=securitypulse">CISO Roast</a> is the main event for me. Probably because I&#8217;ll get to see two of my friends (Ashish and Yonesy) roast each other on a big stage or probably because roasting was a core part of the culture I grew up in. Or is it because the CISO role is so demanding and high-stakes that nobody would dare roast one unless they&#8217;ve sat in the chair themselves? Feels almost taboo to roast a CISO, you know what I mean? </p><p><a href="https://www.ashishrajan.com/">Ashish Rajan</a>, former CISO and host of the Cloud Security Podcast and AI Security Podcast, will be running the show. The people entering the hot seat:</p><ul><li><p><strong><a href="https://www.linkedin.com/in/derekchamorro/">Derek Chamorro</a></strong> is Head of Security at Together AI, with more than 20 years of infrastructure security experience across Together AI and Cloudflare.</p></li><li><p><strong><a href="https://www.linkedin.com/in/emily-ocarroll/">Emily O&#8217;Carroll</a></strong> is a Field CISO at GuidePoint Security. She previously spent nearly a decade building the security program at Topgolf Callaway Brands after an earlier decade advising Fortune 50 companies at KPMG.</p></li><li><p><strong><a href="https://www.linkedin.com/in/yonesy-nunez/">Yonesy N&#250;&#241;ez</a></strong> is the CISO of Surf AI, a six-time CISO, board director, and named inventor on four U.S. patents. His previous stops include DTCC, Wells Fargo, Citigroup, and Jack Henry.</p></li></ul><p>That is a lot of collective security experience volunteering to become material for Ashish. No pressure! :) </p><p>The roast happens Wednesday at 7 p.m. at The Barbershop inside The Cosmopolitan. </p><div><hr></div><h3><a href="https://www.monad.com/black-hat-2026">The Monad x TCP events</a></h3><p>I helped put these together, so I&#8217;m obviously biased, but I&#8217;m genuinely excited about all three, especially the SecOps sunset social which will probably have the best photo opps from the entire week: </p><ul><li><p><a href="https://luma.com/110ppnbf">The Morning Burn</a> on Tuesday from 7:30 to 8:30 a.m. A guided full-body workout followed by breakfast burritos. All fitness levels are welcome.</p></li><li><p><a href="https://luma.com/o8ymcy4q">The SecOps Sunset Social</a> on Tuesday from 7:15 to 8:30 p.m. A small group of security leaders, detection engineers, and SecOps operators riding the High Roller 550 feet above Vegas. The event is currently full, but the waitlist is open.</p></li><li><p><a href="https://luma.com/h59m6c81">The Wurst Security Party</a> on Wednesday from 6 to 9 p.m. at Hofbr&#228;uhaus. German food, custom beer steins, a stein-holding competition, and plenty of security practitioners and leaders.</p></li></ul><p>The <a href="https://www.monad.com/black-hat-2026">Monad team</a> will also have a private meeting suite at the Four Seasons from Monday through Thursday. If you want to talk security data, SIEM architecture, or simply catch up, schedule time through the link or DM me! </p><div><hr></div><h3><a href="https://blackhat.com/us-26/spotlight.html">Black Hat Startup Spotlight</a></h3><p>There are two competitions happening Tuesday.</p><p>The <a href="https://blackhat.com/us-26/spotlight.html">Black Hat USA Startup Spotlight</a> runs from 11:05 a.m. to 12:10 p.m. inside the Innovators &amp; Investors Summit. Four startups will compete:</p><ul><li><p><strong><a href="https://deceptioncheck.ai/">Deception Check</a></strong> builds adaptive AI honeypots that capture attacker behavior.</p></li><li><p><strong><a href="https://mallory.ai/">Mallory</a></strong> maps live threat intelligence against your attack surface to show what actually affects you.</p></li><li><p><strong><a href="https://opnova.ai/">Opnova</a></strong> brings identity governance to legacy and disconnected applications.</p></li><li><p><strong><a href="https://www.perpetualsystems.com/">Perpetual Systems</a></strong> is building agentic detection and security analytics on a customer-owned data lake.</p></li></ul><p>The winner advances directly into the inaugural <a href="https://blackhat.com/us-26/global-spotlight.html">Global Startup Spotlight Competition</a> from 5:30 to 6:40 p.m. on the Business Hall Main Stage.</p><p>They will compete against four regional champions:</p><ul><li><p><strong><a href="https://www.legionsecurity.ai/">Legion Security</a></strong> for agentic security operations</p></li><li><p><strong><a href="https://getsahl.io/">Sahl</a></strong> for AI-powered GRC and compliance</p></li><li><p><strong><a href="https://www.geordie.ai/">Geordie AI</a></strong> for AI agent visibility and governance</p></li><li><p><strong><a href="https://prowler.com/">Prowler</a></strong> for open-source cloud security</p></li></ul><p>The U.S. competition requires an Innovators &amp; Investors Summit pass. The global final is accessible from the Business Hall.</p><p>If you are attending the summit, I also have these sessions circled:</p><ul><li><p><strong>The Market Entry Strategy for Cybersecurity</strong> with Jacques Benkoski</p></li><li><p><strong>RIP the Moat; Long Live the Moat</strong> with Robert Hansen, Rishi Bhargava, Robby Robson, and Zach Yarmolovich</p></li><li><p><strong>VC Horror Stories</strong> with Chenxi Wang, Taylor Margot, Aziz Gilani, and Travis McPeak</p></li></ul><p>I plan to catch both competitions.</p><div><hr></div><h3><a href="https://luma.com/tjehhzxm">Decibel GameDay</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Lp7W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Lp7W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Lp7W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Lp7W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Lp7W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Lp7W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg" width="564" height="564" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:800,&quot;resizeWidth&quot;:564,&quot;bytes&quot;:100765,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208846650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Lp7W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Lp7W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Lp7W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Lp7W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefa692ee-1672-4c7e-a100-00ca6f9d2dfb_800x800.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://luma.com/tjehhzxm">Decibel GameDay</a> is a one-day mini-event happening Tuesday at Libertine Social inside Mandalay Bay. There will be company launches, informal networking, and a pretty stacked group of guests.</p><p>The three conversations I&#8217;m most curious about:</p><ul><li><p><strong>Richard Sherman on defense.</strong> A Super Bowl cornerback talking preparation, communication, and reading an offense in a room full of cybersecurity people could be ridiculous or excellent. I&#8217;m betting excellent.</p></li><li><p><strong>Kevin Mandia on the next phase of cyber defense.</strong> He has seen several generations of the security industry from the front row and is now building Armadin.</p></li><li><p><strong>Rob Joyce on sophisticated adversaries.</strong> The former NSA cyber director recently joined OpenAI as a safety and security advisor and brings a perspective that is difficult to replicate.</p></li></ul><p>HD Moore and Elias Manousos are also part of the lineup. Formal session titles have not been published, but the guest list alone makes this worth watching.</p><div><hr></div><h2>A few tips for winning the week</h2><h3>Leave room for serendipity </h3><p>Don&#8217;t book yourself from AM to PM. There are a lot of unique events and people. Do cool shit and be nice to everyone. </p><h3>Respect everyone&#8217;s bandwidth</h3><p>If you are a security leader, your DMs, texts, and email are probably already flooded. If you work in GTM, Black Hat can become a five-day sprint.</p><p>Keep outreach short. Explain why you want to meet. Make it easy for people to say yes, no, or catch you another time.</p><h2>Take recovery seriously</h2><p>My best non-obvious recommendation is to make time for <a href="https://www.fontainebleaulasvegas.com/wellness/lapis-spa-and-wellness/">Lapis Spa at Fontainebleau</a>. It is truly world-class. Top 3 fav spas I&#8217;ve ever been to. </p><p>The facility includes vitality pools, an event sauna, steam room, infrared sauna, Himalayan salt room, heated chairs, cold plunges, etc</p><p>A few hours there can send you back home in a better state than you arrived in. </p><p>Also, hydrate. Vegas is a desert.</p><div><hr></div><h2>Booth stops worth making</h2><h3>Jam with Yonesy</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SarW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SarW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png 424w, https://substackcdn.com/image/fetch/$s_!SarW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png 848w, https://substackcdn.com/image/fetch/$s_!SarW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png 1272w, https://substackcdn.com/image/fetch/$s_!SarW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SarW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png" width="625" height="270" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:270,&quot;width&quot;:625,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:222041,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208846650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SarW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png 424w, https://substackcdn.com/image/fetch/$s_!SarW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png 848w, https://substackcdn.com/image/fetch/$s_!SarW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png 1272w, https://substackcdn.com/image/fetch/$s_!SarW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a69c3d3-6500-4da0-a1a4-69d7b351e5fe_625x270.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Surf AI is turning booth 4711 into <a href="https://www.surf.ai/events/black-hat-usa-2026">The Surf Spa</a>, with complimentary 10-minute wellness sessions throughout the week.</p><p>Our friend, Yonesy, will also be doing live acoustic jam sessions at select times. If you hear a guitar somewhere in the Business Hall, follow it. <strong>He is a Bachata legend in the making.</strong> </p><div><hr></div><h3>Matcha ice cream at Clover</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uEbT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uEbT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png 424w, https://substackcdn.com/image/fetch/$s_!uEbT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png 848w, https://substackcdn.com/image/fetch/$s_!uEbT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png 1272w, https://substackcdn.com/image/fetch/$s_!uEbT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uEbT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png" width="1456" height="733" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:733,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1455883,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208846650?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uEbT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png 424w, https://substackcdn.com/image/fetch/$s_!uEbT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png 848w, https://substackcdn.com/image/fetch/$s_!uEbT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png 1272w, https://substackcdn.com/image/fetch/$s_!uEbT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2c3e9c-b348-4822-8e1e-82cbc1b0ed13_1735x874.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Our friends and sponsors at <a href="https://go.clover.security/clover-security-x-black-hat-usa-2026">Clover Security</a> will be at booth 4731 and appear to be serving matcha ice cream.</p><p>That is enough information for me to bookmark the booth.</p><div><hr></div><h2>The rest of the event map</h2><p>All times below are local to Las Vegas.</p><h3>Monday</h3><ul><li><p><a href="https://events.cyera.io/blazersbourbonbubblesreception">Cyera&#8217;s Blazers, Bourbon &amp; Bubbles Reception</a>, 6 to 8 p.m. The event is currently at capacity, but I&#8217;m sure you know people who can get you in! </p></li><li><p><a href="https://www.glow.io/black-hat-party-2026">Glow Out Party</a>, beginning at 8 p.m. at the House of Blues Courtyard. Mike Posner. The took a pill in Ibiza guy will be performing!  </p></li></ul><h3>Tuesday</h3><ul><li><p><a href="https://luma.com/110ppnbf">The Morning Burn</a>, 7:30 to 8:30 a.m.</p></li><li><p><a href="https://luma.com/tjehhzxm">Decibel GameDay</a> at Libertine Social.</p></li><li><p><a href="https://blackhat.com/us-26/spotlight.html">Black Hat USA Startup Spotlight</a>, 11:05 a.m. to 12:10 p.m.</p></li><li><p><a href="https://luma.com/wsvzgxkg">Secs on the Beach</a>, 4 to 7 p.m. at the Tailgate Beach Club. </p></li><li><p><a href="https://blackhat.com/us-26/global-spotlight.html">Global Startup Spotlight</a>, 5:30 to 6:40 p.m. on the Main Stage in the Business Hall.</p></li><li><p><a href="https://www.soberincyber.org/events-1/sober-speakeasy-2026">Sober Speakeasy</a>, 7 to 9:30 p.m. at The Mob Museum. Mocktails, food, museum access, and zero pressure to drink.</p></li><li><p><a href="https://www.guidepointsecurity.com/guidepoint-at-black-hat-black-hat-party/">GuidePoint&#8217;s Black Hat Party</a>, 7 to 10 p.m. at Swingers inside Mandalay Bay.</p></li><li><p><a href="https://luma.com/o8ymcy4q">The SecOps Sunset Social</a>, 7:15 to 8:30 p.m.</p></li></ul><h3>Wednesday</h3><ul><li><p><a href="https://www.thecisosociety.com/blackhat-august-2026">The CISO Society Social</a>, 4 to 8 p.m.</p></li><li><p><a href="https://luma.com/h59m6c81">The Wurst Security Party</a>, 6 to 9 p.m. at Hofbr&#228;uhaus.</p></li><li><p><a href="https://luma.com/lockstep-blackhat-2026">Lockstep</a> VC happy hour, 6 to 9 p.m.</p></li><li><p><a href="https://www.c1.ai/lp/ciso-roast-2026?utm_source=securitypulse">CISO Roast</a>, beginning at 7 p.m.</p></li><li><p><a href="https://luma.com/qrcwsn8c">Legends of Cyber</a>, 8 p.m. to midnight at House of Blues. John Watters and Kevin Mandia will sit down for a fireside chat before the live music begins.</p></li></ul><h3>Thursday</h3><ul><li><p><a href="https://innovathersblackhat2026.splashthat.com/">InnovatHERs</a> breakfast, 7 to 9 a.m.</p></li><li><p><a href="https://info.orchid.security/bald-at-black-hat">Bald at Black Hat</a> - <strong>BALD: The Women-Only Drinks at Black Hat</strong></p></li><li><p>The great Black Hat to DEF CON migration. </p></li></ul><h2>Where to find me</h2><p>I will be in Vegas from Monday through Friday, mostly around Black Hat.</p><p>The easiest places to catch me will be:</p><ul><li><p>The Monad meeting suite at the Four Seasons from Monday through Thursday</p></li><li><p>The Morning Burn on Tuesday morning</p></li><li><p>Decibel GameDay and both Startup Spotlight competitions on Tuesday</p></li><li><p>The SecOps Sunset Social on Tuesday evening</p></li><li><p>The Wurst Security Party on Wednesday</p></li><li><p>The CISO Roast on Wednesday night</p></li></ul><p>You will not make every party, talk, dinner, booth, and meetup. Nobody does.</p><p>Pick a few things that matter to you, leave room between them, and protect enough energy to enjoy the people you came to see.</p><p>I&#8217;ll see you in Vegas&#8230;! </p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[AI Sandboxes Get Pwned, Unicorn Gets Launches, and Open-Weight Warfare]]></title><description><![CDATA[OpenAI models broke containment, Glow launched at $1.2B valuation, and Kimi K3 poured gas on the open-weight fight.]]></description><link>https://www.cybersecuritypulse.net/p/ai-sandboxes-get-pwned-unicorn-gets</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/ai-sandboxes-get-pwned-unicorn-gets</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 22 Jul 2026 15:37:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7-M4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/ai-sandboxes-get-pwned-unicorn-gets?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/ai-sandboxes-get-pwned-unicorn-gets?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7-M4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7-M4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp 424w, https://substackcdn.com/image/fetch/$s_!7-M4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp 848w, https://substackcdn.com/image/fetch/$s_!7-M4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp 1272w, https://substackcdn.com/image/fetch/$s_!7-M4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7-M4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:195218,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208052534?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7-M4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp 424w, https://substackcdn.com/image/fetch/$s_!7-M4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp 848w, https://substackcdn.com/image/fetch/$s_!7-M4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp 1272w, https://substackcdn.com/image/fetch/$s_!7-M4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f6436f4-a404-47c9-b976-3be7db1463f8_1456x1052.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from!</p><p>It&#8217;s been a wild past few days to say the least. Exotic sandbox escapes in OpenAI, Cursor, Codex, Gemini CLI etc. Two Series A rounds for a combined $255M in the endpoint security space with one being a unicorn straight out of stealth. Spain topples Argentina for World Cup. The open-source/weights debate gets more wood in the fire with Kimi K3 causing chaos at closed-source frontier model labs (mainly OpenAI and Anthropic). Serious national security and economic implications there. Hugging Face using GLM 5.2 to do IR because closed-source model guardrails blocked IR activity. </p><p>I have a feeling this is a defining week for security and the open-source convo. Before we dive in, <strong><a href="https://www.cybersecuritypulse.net/p/a-field-guide-to-ai-tooling-visibility">here&#8217;s a recent write-up I did on the AI tooling logging research</a></strong> I&#8217;ve been doing and if you&#8217;ll be at Blackhat, hit me up! <strong><a href="https://www.monad.com/black-hat-2026">Here&#8217;s a list</a></strong> of a few places and events I&#8217;ll be at. </p><p>Full breakdown of all the things, including the OpenAI x HuggingFace incident, in this week&#8217;s TCP! But first, a meme and an ad. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!37lf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!37lf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg 424w, https://substackcdn.com/image/fetch/$s_!37lf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg 848w, https://substackcdn.com/image/fetch/$s_!37lf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!37lf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!37lf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg" width="558" height="492.3529411764706" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:986,&quot;resizeWidth&quot;:558,&quot;bytes&quot;:119378,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!37lf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg 424w, https://substackcdn.com/image/fetch/$s_!37lf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg 848w, https://substackcdn.com/image/fetch/$s_!37lf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!37lf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F594790c8-2373-4ad9-a08d-5cb4c9ac42e2_986x870.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>Cyber Reporting Has Outgrown the Checklist</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NAqe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NAqe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png 424w, https://substackcdn.com/image/fetch/$s_!NAqe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png 848w, https://substackcdn.com/image/fetch/$s_!NAqe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png 1272w, https://substackcdn.com/image/fetch/$s_!NAqe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NAqe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png" width="554" height="415.16945107398567" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:838,&quot;resizeWidth&quot;:554,&quot;bytes&quot;:253384,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208052534?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb21982e2-5bca-4a05-9aaf-859b0a519941_1200x628.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NAqe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png 424w, https://substackcdn.com/image/fetch/$s_!NAqe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png 848w, https://substackcdn.com/image/fetch/$s_!NAqe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png 1272w, https://substackcdn.com/image/fetch/$s_!NAqe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32ff85dc-a060-44a1-934b-fc9a0743f5a6_838x628.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;">Cyber reporting is no longer a checklist. A single incident can trigger 100+ obligations across different regulators, deadlines, and audiences&#8212;before the facts are stable. In the newly released Regulatory Concurrency Report, </p><p style="text-align: center;">BreachRx analyzed Change Healthcare, Snowflake, Salesforce, 700Credit, and Salt Typhoon to reveal five forms of regulatory concurrency and where manual processes break. Download the report to learn what modern teams need to keep reporting coordinated, consistent, and defensible.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://info.breachrx.com/regulatory-concurrency-report?utm_source=publication&amp;utm_medium=sponsored-email&amp;utm_campaign=2026-07_oth_cybersecurity-pulse-concurrency-report&quot;,&quot;text&quot;:&quot;Download the report&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://info.breachrx.com/regulatory-concurrency-report?utm_source=publication&amp;utm_medium=sponsored-email&amp;utm_campaign=2026-07_oth_cybersecurity-pulse-concurrency-report"><span>Download the report</span></a></p></div><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><strong><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"><span>OpenAI&#8217;s cyber test spilled into Hugging Face</span></a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hIQa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hIQa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png 424w, https://substackcdn.com/image/fetch/$s_!hIQa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png 848w, https://substackcdn.com/image/fetch/$s_!hIQa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png 1272w, https://substackcdn.com/image/fetch/$s_!hIQa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hIQa!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png" width="1200" height="810.1648351648352" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:983,&quot;width&quot;:1456,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:186242,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208052534?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hIQa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png 424w, https://substackcdn.com/image/fetch/$s_!hIQa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png 848w, https://substackcdn.com/image/fetch/$s_!hIQa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png 1272w, https://substackcdn.com/image/fetch/$s_!hIQa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ecd684-c41b-4a2a-a279-ac69818e33e3_3200x2160.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI</a></strong><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"> says </a>GPT-5.6 Sol and a more capable prerelease model escaped an internal cyber benchmark after exploiting a zero-day in the package-registry proxy that was their only path outside the sandbox. The models escalated privileges, moved laterally until they reached an internet-connected node, then chained stolen credentials and flaws into an RCE path at Hugging Face. <strong>They were trying to win the benchmark. They just found the answers in someone else&#8217;s production database. </strong>Pretty impressive ngl. </p><p>OpenAI had reduced safety/security refusals and disabled its production classifiers for the evaluation. Hugging Face then hit the inverse problem during response x_x. Commercial frontier models blocked the real exploit payloads and C2 artifacts needed to analyze <strong>17,000+ events</strong>, so it moved the work to self-hosted <strong>GLM 5.2</strong>. That also kept attack data and credentials inside its environment.</p><p>The scariest part (there are many) is that a capable model found a hole, chained together a multi-step intrusion, and crossed into another company&#8217;s environment. Another scary part is the guardrail asymmetry. Closed-model labs can remove the seatbelt when they need full capability; defenders renting similar models through an API often cannot. Guardrails reduce misuse, but security teams should not make a provider-controlled API their only AI option during an incident. <strong>OPEN-SOURCE MODELS FTW.</strong> </p><div><hr></div><h4><a href="https://www.kimi.com/blog/kimi-k3">Kimi K3 makes the guardrail tradeoff harder to ignore</a></h4><p><strong>Moonshot AI</strong> says Kimi K3 is a <strong>2.8 trillion-parameter</strong> open-weight model with a <strong>1 million-token</strong> context window, competitive benchmark performance (better than Fable 5 in some cases), and full weights due July 27. Moonshot warns that K3 can be excessively proactive and make unexpected decisions without tighter boundaries.Obviously very compute intensive as well. </p><p>The fact that Chinese labs are shipping open-weight models of this quality should concern everyone.. for many reasons. Economic, national security and many other implications.</p><p>Dan Miessler wrote a great post on some of the implications <a href="https://danielmiessler.com/blog/kimi-k3-us-economy">here.</a>  </p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong><span>How solid is your security review process, really?</span></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pdU7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pdU7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png 424w, https://substackcdn.com/image/fetch/$s_!pdU7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png 848w, https://substackcdn.com/image/fetch/$s_!pdU7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png 1272w, https://substackcdn.com/image/fetch/$s_!pdU7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pdU7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png" width="1456" height="721" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:721,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2791424,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/208052534?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pdU7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png 424w, https://substackcdn.com/image/fetch/$s_!pdU7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png 848w, https://substackcdn.com/image/fetch/$s_!pdU7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png 1272w, https://substackcdn.com/image/fetch/$s_!pdU7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbfae7fd-7d57-485b-8c30-05439f5ab1be_2210x1094.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><span>Every change - a feature, infrastructure update, access change, new vendor, and AI-generated commit - moves your risk profile. Most teams can&#8217;t say how many of those got a security review.</span></p><p style="text-align: center;"><span>Are you one of the few who can?</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.gist.security/assessment/?utm_source=TCP&amp;utm_campaign=SA&amp;utm_id=TCP&quot;,&quot;text&quot;:&quot;Take the Quiz&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.gist.security/assessment/?utm_source=TCP&amp;utm_campaign=SA&amp;utm_id=TCP"><span>Take the Quiz</span></a></p></div><div><hr></div><h4><a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes">The agent stayed sandboxed. The host still got popped.</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X3lU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X3lU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png 424w, https://substackcdn.com/image/fetch/$s_!X3lU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png 848w, https://substackcdn.com/image/fetch/$s_!X3lU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png 1272w, https://substackcdn.com/image/fetch/$s_!X3lU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X3lU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png" width="1456" height="1333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1333,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!X3lU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png 424w, https://substackcdn.com/image/fetch/$s_!X3lU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png 848w, https://substackcdn.com/image/fetch/$s_!X3lU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png 1272w, https://substackcdn.com/image/fetch/$s_!X3lU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d0742b-fa6f-4290-ad7d-698e9b660e3c_2000x1831.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes">Pillar</a> disclosed seven sandbox escape and boundary-bypass chains across Cursor, Codex, Gemini CLI, and Antigravity. In most cases, the agent never broke out directly. The agent wrote files inside the allowed workspace, then unsandboxed tools like Git, VS Code, Python, or Docker used those files to execute code on the developer&#8217;s machine. Most reported issues were patched, including Cursor fixes in version 3.0.0.</p><p>A reminder that<strong> </strong>&#8220;The agent is sandboxed&#8221; is not the same as &#8220;the host is safe.&#8221; The actual boundary includes every helper, daemon, and config file that trusts what the agent creates. Security teams should review the handoff, not just the box. Before there were AI models, there were threat models. </p><p>Perplexity was not part of Pillar&#8217;s research, but the company did  recently detail <a href="https://www.perplexity.ai/hub/blog/secure-sandboxes-for-agents">SPACE</a>, the Firecracker microVM sandbox already running underneath Computer. It is a useful contrast in how different AI companies are handling sandboxing. Though the Pillar findings show why the trust boundary cannot stop at the VM. </p><div><hr></div><h4><a href="https://claude.com/blog/ciso-guide-to-agentic-ai">Zero risk isn&#8217;t the job: a CISO&#8217;s guide to agentic AI</a></h4><p>Great write-up by Anthropic&#8217;s Deputy CISO Jason Clinton where he offers a practical framework for reviewing agentic systems.</p><p><strong>What to review:</strong></p><ul><li><p><strong>Inputs:</strong> What untrusted content can the agent ingest?</p></li><li><p><strong>Identity:</strong> Whose credentials and permissions does it use?</p></li><li><p><strong>Actions:</strong> Which tools, connectors, and systems can it change?</p></li><li><p><strong>Blast radius:</strong> What happens if the agent behaves unexpectedly?</p></li><li><p><strong>Visibility:</strong> Do its actions reach the SIEM and existing monitoring workflows?</p></li></ul><p>Anthropic&#8217;s incident-response agent shows why this assessment cannot stay static. After a model upgrade, the agent independently asked another internal agent to draft a production fix, despite no changes to its tools, permissions, or prompt. Human review still prevented the code from reaching production.</p><p>The useful lesson is to assess agents around durable control points: identity, scoped permissions, tool access, egress, sandboxing, approval gates, and telemetry.</p><div><hr></div><h4><a href="https://techcrunch.com/2026/07/22/glow-emerges-from-stealth-at-1-2b-valuation-to-challenge-endpoint-security-in-the-ai-era/">Glow exits stealth with a $180M Series A at a $1.2B valuation</a></h4><p><strong><a href="https://www.glow.io/">Glow</a></strong> emerged from stealth with a $180 million Series A led by Sequoia, Cyberstarts, Greenoaks, and Redpoint, with Index, Swish, Lux, Operator Collective, and Holly Ventures also participating. That&#8217;s quite the cap table. Also, unicorn status right out of stealth is pretty rare. <br><br>Now about the tech: Its endpoint agents inventory software, AI agents, and developer tools, assess them against company policy, and block risky components before they execute. </p><p>Glow was founded by former Meta, Snowflake (<a href="https://www.omeronsecurity.com/">Omer Singer</a>), and Claroty executives. Omer was a big proponent of security data lakes early on so if you operate in the SecOps space, it&#8217;s likely that the name rings a bell.  Funny enough, Omer asked me about the name last year. I picked Glow. What you name your startup is EXTREMELY important. </p><p>Next, the overlap with <strong><a href="https://www.neo.ai/">Neo</a></strong> and <strong>Koi</strong> is hard to miss. Neo is building a broader control plane for agent behavior across identities, applications, APIs, and data, while Koi is the clearest endpoint comp, covering coding agents, plugins, packages, scripts, and model artifacts. </p><p>Glow seems to be going after the larger prize of combining application control, software supply-chain security, AI governance, and endpoint prevention into one platform. The risk is that buyers see a bundle of features their existing endpoint vendor will eventually ship.</p><p>In any case, stellar founding team, great momentum out the gate, generational problem and not small funding. Excited to see what they do. </p><div><hr></div><h4><a href="https://www.inc.com/amaya-nichole/hackers-pulled-off-food-manufacturers-worst-nightmare-coca-cola-fairlife-shut-down/91375955?utm_source=chatgpt.com">Fairlife ransomware attack shuts down U.S. production</a></h4><p><strong>Coca-Cola</strong> disclosed that ransomware hit <strong>Fairlife</strong>, including systems tied to production, forcing the company to temporarily suspend U.S. operations. The full scope is still unknown.</p><p>The ransomware knocked production offline, but the bigger brand hit may be millions of customers realizing their wellness-coded protein shakes and milk are owned by Coca-Cola. The systems will recover. The illusion may not ;) </p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>Endpoint Security</strong></h3><h4><a href="https://www.neo.ai/news/neo-launches-100m?utm_source=chatgpt.com">Neo launches with $100M for agentic software control</a></h4><p><strong>Neo</strong> emerged from stealth with $100M raised across two rounds: a $25M Seed in 2025 led by Andreessen Horowitz and Merlin Ventures, followed by a $75M Series A backed by Andreessen Horowitz, Bessemer, Craft, and Merlin. Founded by former SentinelOne leaders Nick Warner and Shlomi Salem alongside Eran Shirazi, Neo is building endpoint security for software that can reason, invoke tools, inherit user permissions, and move data without waiting for a human.</p><p>The platform inventories agents, MCP servers, extensions, models, and AI-enabled apps across endpoints, then maps their permissions, configurations, and behavior. It attributes actions to the human, agent, application, or identity behind them, with controls to block tool calls, API access, data movement, malicious models, and out-of-policy prompts. </p><p><strong>TLDR:</strong> EDR for the agentic application layer, where traditional endpoint tools often see the trusted parent process but miss what is happening inside it. </p><div><hr></div><h2><strong>Identity and Access Management</strong></h2><h4><a href="https://www.prnewswire.com/news-releases/oak-raises-60m-in-seed-funding-to-build-the-ai-native-identity-operating-system-302826349.html">Oak exits stealth with $60M for an identity operating system</a></h4><p><strong><a href="https://www.oak.id/">Oak</a></strong> emerged from stealth with <strong>$60 million in seed funding</strong>, co-led by Accel, Greylock, and CRV. Its platform builds a live identity graph across cloud, SaaS, on-premises, and homegrown systems, covering human, machine, and AI-agent identities, then maps granted access against actual use to drive governance and remediation.</p><p>Oak is taking a platform-consolidation swing at a crowded category. On product shape, <strong>Opal</strong> and <strong>C1</strong> are the clearest modern comps. An interesting bit is that Greylock led Opal&#8217;s Series A and co-led its latest <strong>$23 million</strong> financing, then co-led Oak&#8217;s seed six weeks later. That is two bets on overlapping identity control-plane theses. Not very common in venture investing but maybe there&#8217;s more than what meets the eye. </p><div><hr></div><h2><strong>Security Operations</strong></h2><h4><strong><a href="https://cribl.io/news/cribl-acquires-cardinalops-to-expand-its-ai-platform-into-security-operations/"><span>Cribl acquires CardinalOps and moves up the SIEM stack</span></a></strong></h4><p><strong><span>Cribl</span></strong> is acquiring <span>CardinalOps</span>, adding detection engineering to its telemetry platform. CardinalOps maps rules and security controls to MITRE ATT&amp;CK, identifies coverage gaps, and flags broken or noisy detections. Cribl plans to connect that layer with its telemetry routing, storage, and federated search stack, positioning the combined platform as an open alternative to legacy SIEM.</p><div><hr></div><h2>Vulnerability Management</h2><h4><a href="https://www.securityweek.com/empirical-security-raises-25-million-in-series-a-funding/">Empirical Security raises $25M to predict which vulnerabilities actually matter</a></h4><p><strong><a href="https://www.empiricalsecurity.com/">Empirical Security</a></strong> raised a $25M Series A led by Brightmind Partners, with Costanoa Ventures, Hyde Park Angels, and others participating, bringing total funding to $37M. Founded by former Kenna Security leaders Ed Bellis and Michael Roytman alongside EPSS co-creator Jay Jacobs, Empirical is building predictive exposure management models that combine global exploitation telemetry with each customer&#8217;s assets, configurations, and internal data.</p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[A Field Guide to AI Tooling Visibility]]></title><description><![CDATA[What Claude Code, OpenAI Enterprise, Codex, Cursor, and Google Gemini log, what they don&#8217;t, and where defenders should start.]]></description><link>https://www.cybersecuritypulse.net/p/a-field-guide-to-ai-tooling-visibility</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/a-field-guide-to-ai-tooling-visibility</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 15 Jul 2026 17:57:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cowd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/a-field-guide-to-ai-tooling-visibility?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/a-field-guide-to-ai-tooling-visibility?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cowd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cowd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png 424w, https://substackcdn.com/image/fetch/$s_!cowd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png 848w, https://substackcdn.com/image/fetch/$s_!cowd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png 1272w, https://substackcdn.com/image/fetch/$s_!cowd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cowd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png" width="1440" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1440,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:620195,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/207164210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cowd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png 424w, https://substackcdn.com/image/fetch/$s_!cowd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png 848w, https://substackcdn.com/image/fetch/$s_!cowd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png 1272w, https://substackcdn.com/image/fetch/$s_!cowd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fced529cf-8d02-40cd-879f-73374154d9a9_1440x811.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Hello from the middle of a very busy week &#128075;</p><p>On the personal front, Hacker Summer Camp is coming up fast, and between preparing for Vegas and moving homes this Friday, I&#8217;m buried. I&#8217;m giving the regular TCP news roundup a rest today, but I&#8217;ll be back Friday AM with something waaaay more special. Back to regular programming next week.</p><p>Before jumping into today&#8217;s post, next Tuesday I&#8217;m joining Mitchem Boles, Field CISO at Intezer for a webinar on <a href="https://intezer.com/aisl-fix-the-detection-gaps-webinar/?utm_campaign=47880268-%5BWebinar%5D%20Fix%20Detection%20Gaps%20at%20the%20Source%20July%202026%20Q2&amp;utm_source=Monad&amp;utm_medium=monad">fixing detection gaps at the source</a>. We&#8217;ll get into ETL, detection engineering, and what AI SOC platforms need from the data layer beneath them.</p><p>Now, onto the logs &#129717;</p><div><hr></div><p>For the past few months, I&#8217;ve been focused on AI tooling security visibility. Think Claude Code, Codex, Cursor etc. What activity details each log source emits, what you can detect, key threat hunting and investigation signals and what their quirks and limitations are. </p><p>I started digging after finding surprisingly little useful coverage in SIEM rule packs and public detection repos like <a href="https://github.com/sigmahq/sigma">Sigma</a>. In recent years, AI tooling has increasingly gained access to source code, terminals, repositories, internal documents, email, calendars, and outside systems through MCP. But somehow detection coverage isn&#8217;t keeping up. The rule repos and SIEM content I relied on in the past as a detection engineer simply hasn&#8217;t kept up with the times. Folks are either gatekeeping, there are new rule repos or the majority of the industry hasn&#8217;t kept up. I&#8217;d imagine it&#8217;s a mix of all 3. </p><p>Sure, many mature security teams (think Walmart, Robinhood, JPMC, NVIDIA, Netflix, AI labs) have been on top of this all along. However, many others are flying blind or trusting their AI security tools to catch everything.</p><p>Tools can help, but you still must understand the raw logs. If you don&#8217;t know what the source gives you, you don&#8217;t know what&#8217;s missing. You also can&#8217;t copy and paste the same rules into every company or deploy every OOTB rule your tools give you. That&#8217;s leads to a shit ton of false positives and noise. Most detections depend on what normal behavior looks like inside <em>your</em> environment.</p><p>That work has turned into five in-depth posts, each focused on a different AI log source. Below, I&#8217;m pulling out a few of the most useful findings from each. If you want to see what the logs look like, which fields matter, what to alert on, and where each source falls short, read the full post linked at the end of each section.</p><p>Here&#8217;s what we&#8217;ve covered so far.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vuA5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vuA5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png 424w, https://substackcdn.com/image/fetch/$s_!vuA5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png 848w, https://substackcdn.com/image/fetch/$s_!vuA5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png 1272w, https://substackcdn.com/image/fetch/$s_!vuA5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vuA5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png" width="1456" height="1152" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1152,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:303023,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/207164210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vuA5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png 424w, https://substackcdn.com/image/fetch/$s_!vuA5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png 848w, https://substackcdn.com/image/fetch/$s_!vuA5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png 1272w, https://substackcdn.com/image/fetch/$s_!vuA5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20279d7c-a95c-4f28-9958-cd65fc220ae2_2200x1740.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2><a href="https://www.monad.com/blog/detection-engineering-for-claude-code-part-1">Claude Code</a></h2><p>Claude Code can send OpenTelemetry metrics and logs for API calls, tool approvals, tool results, MCP usage, and prompts when prompt logging is turned on.</p><p>That gives defenders useful places to start. You can look for rejected shell commands, reads of <code>.env</code> files or cloud credentials, file access followed by <code>curl</code> or <code>wget</code>, and unknown MCP servers calling tools.</p><p>The problem is the format. Raw OTel arrives as deeply nested arrays of keys and values. Before analysts can use it, the data needs to be split into individual events and flattened into fields that are easy to search.</p><p><a href="https://www.monad.com/blog/detection-engineering-for-claude-code-part-1">Read the full Claude Code post here.</a></p><div><hr></div><h2><a href="https://www.monad.com/blog/cursor-audit-logs-whats-emitted-and-detection-opportunities">Cursor Audit Logs</a></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qlue!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qlue!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png 424w, https://substackcdn.com/image/fetch/$s_!Qlue!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png 848w, https://substackcdn.com/image/fetch/$s_!Qlue!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png 1272w, https://substackcdn.com/image/fetch/$s_!Qlue!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qlue!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png" width="1632" height="1201" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1201,&quot;width&quot;:1632,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:163230,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Qlue!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png 424w, https://substackcdn.com/image/fetch/$s_!Qlue!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png 848w, https://substackcdn.com/image/fetch/$s_!Qlue!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png 1272w, https://substackcdn.com/image/fetch/$s_!Qlue!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F70b429b2-03ba-4cab-8784-49270dfbad7c_1632x1201.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://cursor.com/docs/account/teams/admin-api#get-audit-logs">Cursor audit logs</a> show changes to the settings around the agent. They do not show everything the agent did.</p><p>You can detect when Privacy Mode changes, a new MCP server is added, someone becomes an admin, an API key is created, or repository rules and hooks are weakened.</p><p>You will not see prompt text, terminal commands, file reads, or MCP arguments in the audit log. To investigate what the agent actually did, you still need endpoint, network, Git, CI/CD, and Cursor Hook data.</p><p><a href="https://www.monad.com/blog/cursor-audit-logs-whats-emitted-and-detection-opportunities">Read the full Cursor post here.</a></p><div><hr></div><h2><a href="https://www.monad.com/blog/openai-enterprise-audit-log-detections">OpenAI Enterprise Audit Logs</a></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JOjT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JOjT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png 424w, https://substackcdn.com/image/fetch/$s_!JOjT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png 848w, https://substackcdn.com/image/fetch/$s_!JOjT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png 1272w, https://substackcdn.com/image/fetch/$s_!JOjT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JOjT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png" width="728" height="342.55820476858344" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a81dbdce-8075-4065-b084-20d580a0323b_1426x671.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:671,&quot;width&quot;:1426,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JOjT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png 424w, https://substackcdn.com/image/fetch/$s_!JOjT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png 848w, https://substackcdn.com/image/fetch/$s_!JOjT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png 1272w, https://substackcdn.com/image/fetch/$s_!JOjT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81dbdce-8075-4065-b084-20d580a0323b_1426x671.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>OpenAI Enterprise exposes <a href="https://developers.openai.com/api/reference/resources/admin/subresources/organization/subresources/audit_logs">51 audit event types</a> covering users, roles, API keys, service accounts, network controls, projects, and organization settings.</p><p>The first rules I&#8217;d ship are straightforward: alert when SCIM is disabled, an IP allowlist is removed or opened too widely, new permissions are added, API call logging is reduced, or an owner-level service account is created.</p><p>These events are useful on their own. They get much stronger when you add context from your identity provider, HR system, asset inventory, and change tickets. An admin change from the platform team during business hours is different from the same change made by a terminated employee.</p><p><a href="https://www.monad.com/blog/openai-enterprise-audit-log-detections">Read the full OpenAI Enterprise post here.</a></p><div><hr></div><h2><a href="https://www.monad.com/blog/detection-engineering-for-openai-codex-otel">OpenAI Codex OTel Logs</a></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YSqp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YSqp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp 424w, https://substackcdn.com/image/fetch/$s_!YSqp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp 848w, https://substackcdn.com/image/fetch/$s_!YSqp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp 1272w, https://substackcdn.com/image/fetch/$s_!YSqp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YSqp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp" width="724.796875" height="444.0376459478022" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:892,&quot;width&quot;:1456,&quot;resizeWidth&quot;:724.796875,&quot;bytes&quot;:80400,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/207164210?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YSqp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp 424w, https://substackcdn.com/image/fetch/$s_!YSqp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp 848w, https://substackcdn.com/image/fetch/$s_!YSqp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp 1272w, https://substackcdn.com/image/fetch/$s_!YSqp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dbd7060-c2c6-4cfc-92a2-04bce8af1810_1456x892.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Codex OTel can show how a session started, which sandbox and approval settings were used, whether prompts were redacted, how tool calls were approved, what tools ran, and whether network access was allowed.</p><p>Useful checks include sessions running with full access and no approval, prompts leaving the machine without redaction, destructive tools approved by configuration instead of a person, unusual network traffic during an enabled session, and Codex suddenly appearing on a new laptop or CI runner.</p><p><a href="https://www.monad.com/blog/detection-engineering-for-openai-codex-otel">Read the full OpenAI Codex post here.</a></p><div><hr></div><h2><a href="https://www.monad.com/blog/google-workspace-gemini-activity-logs-detection-opportunities">Google Workspace Gemini</a></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EbGn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EbGn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png 424w, https://substackcdn.com/image/fetch/$s_!EbGn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png 848w, https://substackcdn.com/image/fetch/$s_!EbGn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!EbGn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EbGn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png" width="1456" height="1229" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1229,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EbGn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png 424w, https://substackcdn.com/image/fetch/$s_!EbGn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png 848w, https://substackcdn.com/image/fetch/$s_!EbGn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!EbGn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb0ed-9bd5-4029-ac98-20a617a28f5c_1600x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Gemini activity logs show who used Gemini, when they used it, their IP address, which Workspace app they were in, and which feature they used.</p><p>They do not show the prompt, response, file, email, calendar event, or other content involved. The log proves that Gemini was used. It does not prove what Gemini accessed or what happened next.</p><p><code>app_name</code> tells you where to look next. Gemini activity in Drive should send you to Drive logs. Activity in Gmail should send you to Gmail logs. From there, you can match events from the same user within a tight time window and add Login, DLP, endpoint, and identity data.</p><p><a href="https://www.monad.com/blog/google-workspace-gemini-activity-logs-detection-opportunities">Read the full Google Workspace Gemini post here.</a></p><div><hr></div><p>The underlying thread across all 5 sources we&#8217;ve covered so far is that none of them offer complete visibility. Some cover control-plane activity very well, others cover data-plane activity well while some cover none super well. You need to know those limits before trusting any alert built on top of it which is why taking matters into your own hands is key. </p><p>Getting this right requires a lot of wrangling. Teams first have to collect the logs, clean up the fields, add the missing context, filter out low-value events, and route the useful data to their SIEM or data lake. Detection engineers can then use that prepared data to hunt and build rules around what&#8217;s abnormal in their environment.</p><p>Monad handles the data pipeline work that comes before detection. We have integrations for every source above and help teams collect, normalize, enrich, filter, and route the data. Detection and alerting still happen in the team&#8217;s SIEM, data lake, or analytics platform. If you&#8217;re working through any of these sources, <a href="https://www.monad.com/">we can help</a>.</p><p>More to come on this series so follow along! </p><div><hr></div><p>If you&#8217;ll be in Vegas, hit me up! Schedule a <a href="https://www.monad.com/black-hat-2026">meet with Monad or sign up for one of our Black Hat events</a>, including The Morning Burn, our SecOps Sunset Social 550 feet above Vegas, and The Wurst Security Party. </p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Anthropic sues Abnormal AI, Ransomware AI Intern, and 2003 AI SOCs ]]></title><description><![CDATA[Anthropic picks a weird fight with Abnormal; AI ransomware gets a human-shaped asterisk; Robinhood rebuilds access approvals; Straiker, Runlayer, and Nebulock raise into the agent and AI security wave]]></description><link>https://www.cybersecuritypulse.net/p/anthropic-sues-abnormal-ai-ransomware</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/anthropic-sues-abnormal-ai-ransomware</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 08 Jul 2026 14:31:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!7TaA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/anthropic-sues-abnormal-ai-ransomware?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/anthropic-sues-abnormal-ai-ransomware?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7TaA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7TaA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!7TaA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!7TaA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!7TaA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7TaA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3355349,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/205690288?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7TaA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!7TaA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!7TaA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!7TaA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b85b039-648c-47f0-b775-d0599220b500_1800x1300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from!</p><p>On the personal front, I was able to take some time off to enjoy America&#8217;s 250th birthday. Threw a spa day in there and experienced <a href="https://ammortal.com/">this alien piece of work</a> that I can&#8217;t recommend enough. Aside from that, some World Cup shenanigans. It&#8217;s been a great one although my dark horse, Cabo Verde, has been eliminated. </p><p>Before we jump into the news, in a few weeks I&#8217;ll be partnering with my dear friend Mitchem to share our thoughts on AI SOC, detection engineering, and why the data layer is becoming the whole game. You can <strong><a href="https://hubs.li/Q04nFxgF0">register for the webinar here</a></strong> &#128126;</p><p>Lastly, Hacker Summer Camp is coming up. <strong><a href="https://www.monad.com/black-hat-2026">Here&#8217;s where I&#8217;ll be at all week</a></strong>. DM me if you wanna grab a coffee or lift weights! </p><p>Now, onto the news! </p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>Introducing Gist Security - Fear No Change</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Lijy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Lijy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png 424w, https://substackcdn.com/image/fetch/$s_!Lijy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png 848w, https://substackcdn.com/image/fetch/$s_!Lijy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png 1272w, https://substackcdn.com/image/fetch/$s_!Lijy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Lijy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png" width="1456" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1040069,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/205690288?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Lijy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png 424w, https://substackcdn.com/image/fetch/$s_!Lijy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png 848w, https://substackcdn.com/image/fetch/$s_!Lijy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png 1272w, https://substackcdn.com/image/fetch/$s_!Lijy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3ee078d-f74c-450e-9f42-a3c646936c5a_2910x1620.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;">Engineering and IT now build faster than security can review, and AI only widens the gap. Gist embeds governance into the change lifecycle itself, to produce consistent, auditable risk assessments, threat models, and evidence records.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.gist.security/?utm_source=TCP&amp;utm_campaign=July8&amp;utm_content=SecRev&quot;,&quot;text&quot;:&quot;See Gist&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.gist.security/?utm_source=TCP&amp;utm_campaign=July8&amp;utm_content=SecRev"><span>See Gist</span></a></p></div><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#9878;&#65039; <strong><a href="https://abnormal.ai/blog/abnormal-response-to-anthropic-lawsuit?utm_source=chatgpt.com">Anthropic sues Abnormal</a>:</strong> Abnormal says it used abnormal.ai and the slash wordmark before Anthropic existed.</p></li><li><p>&#129514; <strong><a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion?utm_source=chatgpt.com">Ransomware gets an AI intern</a>:</strong> Vendor says they discovered first fully autonomous ransomware, but it required a human </p></li><li><p>&#129706; <strong><a href="https://www.darkreading.com/application-security/robinhood-reengineered-access-approvals-for-high-velocity-development?utm_source=chatgpt.com">Robinhood fixes approvals</a>:</strong> SERA speeds up passkey-based approvals for incident response and sensitive access.</p></li><li><p>&#129504; <strong><a href="https://medium.com/anton-on-security/stop-building-a-2003-soc-with-ai-a-modern-people-process-framework-part-1-7220513c9de1">Stop bolting AI onto 2003</a>:</strong> Anton Chuvakin says AI SOCs need process redesign before agents enter the queue.</p></li><li><p>&#127474;&#127485; <strong><a href="https://www.recordedfuture.com/research/mexico-new-cybersecurity-plan-evaluation?utm_source=chatgpt.com">World Cup pressure test</a>:</strong> Mexico&#8217;s cyber plan puts critical infrastructure investment on a five-year clock.</p></li><li><p>&#129302; <strong><a href="https://siliconangle.com/2026/06/29/straiker-lands-64m-defend-enterprise-ai-agents-attack/?utm_source=chatgpt.com">Straiker raises $64M</a>:</strong> Straiker raised a Series A for AI agent discovery, testing, and runtime protection.</p></li></ul><p><strong>Plus:</strong> <a href="https://www.securityweek.com/runlayer-raises-30-million-in-series-a-funding/?utm_source=chatgpt.com">Runlayer raises $30M</a>, <a href="https://www.aikido.dev/blog/aikido-acquires-root?utm_source=chatgpt.com">Aikido acquires Root</a>, <a href="https://nebulock.io/blog/nebulock-raises-25m-series-a-for-hunt-first-always-on-security-operations?utm_source=chatgpt.com">Nebulock raises $25M</a>, MSP identity consolidates, poisoned MCP tools keep being annoying, and Intruder adds a free exposure-management onramp.</p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><strong><a href="https://abnormal.ai/blog/abnormal-response-to-anthropic-lawsuit?utm_source=chatgpt.com"><span>Anthropic sues Abnormal over AI branding</span></a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LIL2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LIL2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!LIL2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!LIL2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!LIL2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LIL2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/caea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;The \nCybersecurity \nJULY 2026 \nPulse \nTRADEMARK \nPLAINTIFF \nAnthropic sues Abnormal \nAnthropic, PBC \nover its Al branding \nV. \nDEFENDANT \nThe AI-naming land grab reaches a courtroom - and the timeline undercuts the core \nhe core \nAbnormal Al \nclaim. \nTHE TIMELINE \nThe order of events is the argument: Abnormal's mark predates the conflict by years. \n2018 \nAPR 2021 \nAPR 2025 \nJUL 1 '26 \nJUL 7 '26 \nO \nO \nO \nAbnormal founded \nSlash wordmark \nRebrand to \&quot;Abnormal Al\&quot; \nAnthropic files suit \nAbnormal responds \nabnormal.ai is registered. \nThe logo it still uses is designed - \nReverts to its original name. \nTrademark + unfair competition, \nRejects it. Tells customers: \nAnthropic doesn't exist yet. \nunchanged since. \nAnthropic calls this the copy. \nN.D. California. \nprotection is unchanged. \nFOR ABNORMAL'S CUSTOMERS \nNo product change, no security risk. Abnormal's threat detection and response run on its own models - not Claude - so this dispute is legal, \nnot operational. \nSources : Abnormal AI response (Jul 7) . Law360 &#183; case 3:26-cv-06754 (N.D. Cal. ) \nthecybersecuritypulse. com &quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The 
Cybersecurity 
JULY 2026 
Pulse 
TRADEMARK 
PLAINTIFF 
Anthropic sues Abnormal 
Anthropic, PBC 
over its Al branding 
V. 
DEFENDANT 
The AI-naming land grab reaches a courtroom - and the timeline undercuts the core 
he core 
Abnormal Al 
claim. 
THE TIMELINE 
The order of events is the argument: Abnormal's mark predates the conflict by years. 
2018 
APR 2021 
APR 2025 
JUL 1 '26 
JUL 7 '26 
O 
O 
O 
Abnormal founded 
Slash wordmark 
Rebrand to &quot;Abnormal Al&quot; 
Anthropic files suit 
Abnormal responds 
abnormal.ai is registered. 
The logo it still uses is designed - 
Reverts to its original name. 
Trademark + unfair competition, 
Rejects it. Tells customers: 
Anthropic doesn't exist yet. 
unchanged since. 
Anthropic calls this the copy. 
N.D. California. 
protection is unchanged. 
FOR ABNORMAL'S CUSTOMERS 
No product change, no security risk. Abnormal's threat detection and response run on its own models - not Claude - so this dispute is legal, 
not operational. 
Sources : Abnormal AI response (Jul 7) . Law360 &#183; case 3:26-cv-06754 (N.D. Cal. ) 
thecybersecuritypulse. com " title="The 
Cybersecurity 
JULY 2026 
Pulse 
TRADEMARK 
PLAINTIFF 
Anthropic sues Abnormal 
Anthropic, PBC 
over its Al branding 
V. 
DEFENDANT 
The AI-naming land grab reaches a courtroom - and the timeline undercuts the core 
he core 
Abnormal Al 
claim. 
THE TIMELINE 
The order of events is the argument: Abnormal's mark predates the conflict by years. 
2018 
APR 2021 
APR 2025 
JUL 1 '26 
JUL 7 '26 
O 
O 
O 
Abnormal founded 
Slash wordmark 
Rebrand to &quot;Abnormal Al&quot; 
Anthropic files suit 
Abnormal responds 
abnormal.ai is registered. 
The logo it still uses is designed - 
Reverts to its original name. 
Trademark + unfair competition, 
Rejects it. Tells customers: 
Anthropic doesn't exist yet. 
unchanged since. 
Anthropic calls this the copy. 
N.D. California. 
protection is unchanged. 
FOR ABNORMAL'S CUSTOMERS 
No product change, no security risk. Abnormal's threat detection and response run on its own models - not Claude - so this dispute is legal, 
not operational. 
Sources : Abnormal AI response (Jul 7) . Law360 &#183; case 3:26-cv-06754 (N.D. Cal. ) 
thecybersecuritypulse. com " srcset="https://substackcdn.com/image/fetch/$s_!LIL2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!LIL2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!LIL2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!LIL2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaea9ac1-e75d-4470-93e6-f21423dbec44_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span>Anthropic</span></strong> filed a public lawsuit against <strong><span>Abnormal AI</span></strong> on July 1, claiming unfair competition and trademark infringement over Abnormal&#8217;s slash-based AI branding. Abnormal&#8217;s CEO <a href="https://abnormal.ai/blog/abnormal-response-to-anthropic-lawsuit">wrote a blog post here</a> detailing their side of the matter. </p><p>Abnormal was founded in <strong><span>2018</span></strong>, registered abnormal.ai before Anthropic existed, and has used the same slash-based wordmark since <strong><span>April 2021</span></strong>. The CEO also says it is a large Anthropic customer, learned about the lawsuit from a reporter, not directly from Anthropic.</p><p>I&#8217;m not sure what wires got crossed here but this seems super out of left field from Anthropic. Is there something more to it?</p><p><span> </span>Will be following this one closely</p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong><span>Enterprise Incident Response for the AI Era</span></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lZY6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lZY6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!lZY6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!lZY6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!lZY6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lZY6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:445122,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/205690288?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lZY6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!lZY6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!lZY6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!lZY6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b07ff78-0faf-4a09-9be5-e11f7dadeba0_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;">Offensive AI is making attacks faster, easier to launch, and harder to manage at enterprise scale. BreachRx helps organizations move from breach chaos to coordinated Enterprise Incident Response, using agentic AI to guide workflows, surface obligations, coordinate stakeholders, and preserve evidence in one platform. </p><p style="text-align: center;">Teams train like they fight, leaders stay aligned, regulators get consistent facts, and every stakeholder can respond with resolve when it matters most.</p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.breachrx.com/get-demo/?utm_source=publication&amp;utm_medium=sponsored-content&amp;utm_campaign=2026-07_oth_cybersecurity-pulse-product-spotlight&quot;,&quot;text&quot;:&quot;See BreachRx&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.breachrx.com/get-demo/?utm_source=publication&amp;utm_medium=sponsored-content&amp;utm_campaign=2026-07_oth_cybersecurity-pulse-product-spotlight"><span>See BreachRx</span></a></p></div><div><hr></div><h4><a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion">Ransomware Gets an AI Intern</a></h4><p>This weekend I came across some headlines about the &#8220;first fully autonomous ransomware attack&#8221;. But after some digging, I discovered there were humans involved!!! Gotta love bait headlines. <a href="https://techcrunch.com/2026/07/06/the-first-ai-run-ransomware-attack-still-needed-a-human/">TechCrunch reported</a> that a human still chose the victim, provisioned infrastructure, and supplied database credentials. The AI agents did the rest.</p><p><strong><span>Sysdig</span></strong> says JADEPUFFER hit an exposed <strong><span>Langflow</span></strong> instance through <strong><span>CVE-2025-3248</span></strong>, then pivoted into a production MySQL and Nacos server. The agent encrypted <strong><span>1,342</span></strong> Nacos configuration items, dropped original config and history tables, created a ransom note, and generated an encryption key that was printed once, never stored, and never sent anywhere.  &#8220;an adaptive and fully automated campaign,&#8221; is what they are calling it but it did still need a human. <br><br>In any case, this is another reminder<span> </span>that attackers use AI to compress the tedious bits. Not a nothing burger but also not something to rewrite your security program around.</p><div><hr></div><h4><a href="https://www.linkedin.com/pulse/building-security-unlock-engineering-velocity-shreyas-sriram-deiic/">Robinhood rebuilds access approvals for speed</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W_k5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W_k5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png 424w, https://substackcdn.com/image/fetch/$s_!W_k5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png 848w, https://substackcdn.com/image/fetch/$s_!W_k5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png 1272w, https://substackcdn.com/image/fetch/$s_!W_k5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W_k5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png" width="1456" height="851" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:851,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Article content&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Article content" title="Article content" srcset="https://substackcdn.com/image/fetch/$s_!W_k5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png 424w, https://substackcdn.com/image/fetch/$s_!W_k5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png 848w, https://substackcdn.com/image/fetch/$s_!W_k5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png 1272w, https://substackcdn.com/image/fetch/$s_!W_k5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd61dbe9f-7734-4c7b-af15-a423c9ffc423_1488x870.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Access approvals get painful fast when the approver has to be on a managed laptop, on VPN, and available during an incident. <strong><span>Robinhood</span></strong> built Secure Enhanced Remote Approval, or SERA, so devs can approve access from any device using passkeys, without VPNs or managed laptops. The company says SERA cut approval time by <strong><span>20%</span></strong> and shipped in <strong><span>four months</span></strong> after incident response and engineering teams kept running into approval friction.</p><p>This is a useful playbook for teams with global engineering, 24/7 systems, sensitive data, cloud sprawl, or break-glass workflows. Approval shows up during production debugging, incident response, privileged admin actions, temporary elevation, and access to sensitive environments.</p><p>Side note - The OP was written in Nov&#8217; of &#8216;25 but <a href="https://www.darkreading.com/application-security/robinhood-reengineered-access-approvals-for-high-velocity-development">DarkReading recently picked it up</a> which piqued my curiosity.</p><div><hr></div><h4><strong><a href="https://medium.com/anton-on-security/stop-building-a-2003-soc-with-ai-a-modern-people-process-framework-part-1-7220513c9de1">Anton Chuvakin wants SOC teams to stop bolting AI onto 2003</a></strong></h4><p><strong>Anton Chuvakin</strong> argues the AI SOC conversation is too tool-heavy and too light on people and process. His warning is simple: agents added to a legacy SOC can preserve the same broken workflows with better autocomplete.</p><p>He&#8217;s right. Validation, handoffs, metrics, detection quality, feedback loops, and analyst development all need serious thought and maybe redesign before agents get bolted on, otherwise you&#8217;re just automating what was already broken. Worth following his Medium and reading in full.<br><br>I&#8217;m touch and see the problems he highlights first-hand at Monad and I couldn&#8217;t agree more. Fundamentals still matter. AI is not coming to save your SOC. </p><div><hr></div><h4><a href="https://www.recordedfuture.com/research/mexico-new-cybersecurity-plan-evaluation">World Cup Pressure Tests Mexico&#8217;s Cyber Plan</a></h4><p><strong><span>Recorded Future</span></strong> says Mexico&#8217;s <strong><span>2025&#8211;2030 National Cybersecurity Plan</span></strong> is trying to formalize national cyber coordination after years of ransomware, fraud, hacktivism, data theft, and state-linked activity. The past 5 years have been rough for Mexico on the cyber front and with co-hosting the World Cup, I&#8217;d imagine security was front and center.</p><p>The 2026 phase calls for a national cyber strategy, a General Cybersecurity Law, a National Center for Cybersecurity Operations, CSIRT coordination, critical infrastructure identification, and federal vulnerability assessment.</p><p><strong>TLDR:</strong> Lots of investment pouring into securing Mexican critical infrastructure over the next 5 years. All countries should be doing the same.</p><div><hr></div><h4><strong><a href="https://siliconangle.com/2026/06/29/straiker-lands-64m-defend-enterprise-ai-agents-attack/"><span>Straiker raises $64M for agent security</span></a></strong></h4><p><strong><span>Straiker</span></strong> raised a <strong><span>$64M Series A</span></strong> to expand its AI agent security platform. The round was led by Marathon Management Partners, Citi Ventures, Illuminate Financial, and Workday Ventures, with continued backing from Bain Capital Ventures and Lightspeed.</p><p>Straiker helps teams find agents already running, monitor live prompts/tool calls, and test new agent workflows before they get real permissions. The company was founded by <strong><span>Ankur Shah</span></strong>, former SVP and GM of Prisma Cloud at Palo Alto Networks, and <strong><span>Sreenath Kurupati</span></strong>, former Akamai AI and security research lead.</p><p>They&#8217;re one of my favorite AI security startups right now: serious team w/ big scale vendor track record, serious problem, and early enough to give the bigger platforms a real headache.</p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><h4><strong><a href="https://www.securityweek.com/runlayer-raises-30-million-in-series-a-funding/"><span>Runlayer raises $30M for agent governance</span></a></strong></h4><p><strong><span>Runlayer</span></strong> raised a $30M Series A from Felicis and Khosla Ventures, bringing total funding to $42M. The company gives enterprises one control layer for AI agents, MCP servers, and AI clients, with identity, permissions, policy enforcement, audit logs, and real-time visibility tied to agent actions.</p><p>I remember doing a demo with their CEO, Andy, earlier this year and was blown away around how intuitive and ahead the product was in securing MCP for enterprise tooling at a time where teams were still understanding how to secure it. Also, strong signal that <a href="https://fortune.com/2026/06/24/exclusive-vinod-khosla-felicis-runlayer-nanit-30-million-enterprise-ai/">Vinod Khosla wanted &#8220;every available dollar&#8221; of their Series A</a>. Good stuffs.</p><div><hr></div><p><strong>More AI Security News</strong> </p><ul><li><p><a href="https://www.jamf.com/resources/press-releases/jamf-launches-ai-governance-a-first-of-its-kind-native-ai-control-plane-for-mac/"><span>Jamf enables AI Governance and shadow AI detection on Mac</span></a></p></li><li><p><a href="https://www.wiz.io/blog/introducing-wiz-mcp"><span>Build AI Security Agents with Wiz MCP</span></a></p></li><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/06/29/securing-ai-agents-ai-tools-move-from-reading-acting/"><span>Microsoft warns poisoned MCP tool descriptions can make AI agents leak data</span></a></p></li></ul><div><hr></div><h2><strong>Identity and Access Management</strong></h2><h4><strong><a href="https://siliconangle.com/2026/07/07/barracuda-networks-acquires-access-management-startup-evo-security/"><span>Barracuda buys Evo Security for MSP identity</span></a></strong></h4><p><strong><span>Barracuda</span></strong> acquired <strong><span>Evo Security</span></strong>, an IAM and PAM provider built for MSPs. Barracuda says Evo will expand BarracudaONE with privileged access management, access control, identity protection, and identity threat detection and response. Terms were not disclosed.</p><div><hr></div><h2><strong>Software Supply Chain Security </strong></h2><h4><strong><a href="https://www.helpnetsecurity.com/2026/06/30/aikido-security-root-acquisition/"><span>Aikido acquires Root for open-source patching</span></a></strong></h4><p><strong><span>Aikido Security</span></strong> acquired <a href="https://www.root.io/">Root</a> add software supply chain patching into its platform. Root generates CVE patches for package versions teams already run, while Aikido is launching patched drop-in libraries and container images. Deal rumored to be around $80-100M.</p><p>&#8220;Acquiring Root&#8221; in a company transaction is probably a once-in-a-lifetime opportunity and I&#8217;m glad it was Aikido. The puns write themselves. In all seriousness, Aikido is a rocketship and has one of the best GTM + eng teams in the game.</p><p><strong><span>Side note:</span></strong> Both Aikido + Root are past sponsors of TCP so I&#8217;m super happy to see them winning!</p><div><hr></div><h2><strong>Security Operations</strong></h2><h4><strong><a href="https://nebulock.io/blog/nebulock-raises-25m-series-a-for-hunt-first-always-on-security-operations"><span>Nebulock raises $25M for hunt-first security ops</span></a></strong></h4><p><strong><span>Nebulock</span></strong> raised a <strong><span>$25M Series A</span></strong> led by FirstMark, with Bain Capital Ventures, Decibel, Zetta Venture Partners, and Step Function participating. The company is building hunt-first security ops.</p><p>The idea is simple: the bad stuff increasingly looks normal until you connect the sequence. Nebulock is focused on that middle layer, where valid creds, weird agent behavior, and quiet pivots start to look less innocent.</p><p>I&#8217;m bullish on the team + problem space. A lot of finding &#8220;the needle in the haystack&#8221; depends on correlation and piecing things together over long windows of time. That&#8217;s where Nebulock really helps.</p><div><hr></div><p><strong>More Security Operations News</strong></p><ul><li><p><a href="https://siliconangle.com/2026/07/01/jamf-launches-beacon-threat-hunting-service-enterprise-mac-environments/">Jamf launches Beacon threat hunting service for enterprise Mac environments</a></p></li></ul><div><hr></div><h2>Vulnerability Management</h2><h4><strong><a href="https://www.msspalert.com/brief/intruder-adds-free-exposure-management-plan-for-lean-security-teams"><span>Intruder launches a free exposure management plan</span></a></strong></h4><p><strong><span>Intruder</span></strong> launched a permanent free plan for lean security teams, with weekly scans for up to <strong><span>5</span></strong> external targets, one cloud environment, <strong><span>2</span></strong> container images, port change monitoring on <strong><span>80</span></strong> and <strong><span>443</span></strong>, unlimited remediation scans, one AI pentesting credit per month, and up to <strong><span>3</span></strong> users.</p><p>This is a great way to help SMBs and a neat onramp into Intruder&#8217;s pipeline.</p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[Patch the Planet, drain the CRMs, buy the OT]]></title><description><![CDATA[Klue's OAuth compromise exposed Salesforce data across the security vendor bench; Accenture spends $4.175B on Dragos, runZero, and NetRise; Cisco picks up WideField for Splunk's agentic SOC.]]></description><link>https://www.cybersecuritypulse.net/p/patch-the-planet-drain-the-crms-buy</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/patch-the-planet-drain-the-crms-buy</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 24 Jun 2026 12:57:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rGNe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/patch-the-planet-drain-the-crms-buy?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/patch-the-planet-drain-the-crms-buy?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rGNe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rGNe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!rGNe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!rGNe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!rGNe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rGNe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3317763,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/203251077?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rGNe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!rGNe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!rGNe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!rGNe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5151ae4e-4844-4413-b3cc-dc846d8ed404_1800x1300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from!</p><p>It&#8217;s the week after Identiverse/Juneteenth and the week before holiday week, so the security news cycle has that weird pre-OOTO lull. Still, the Klue breach is ringing bells and stirring up <a href="https://www.driftbreach.com/">Salesloft/Drift</a> PTSD. Meanwhile, there still hasn&#8217;t been much movement on the Fable/Mythos front, which is pretty telling. </p><p>On the TCP front, <a href="https://www.cybersecuritypulse.net/p/a-6x-ciso-on-the-era-that-security">Dr. Yonesy N&#250;&#241;ez, CISO at Surf AI, teamed up with TCP</a> on a guest post about security hygiene. Also, TCP sponsor <a href="https://www.gist.security/">Gist</a> came out of stealth, tackling the very unsexy but very real problem of turning product and code changes into risk reviews, threat models, and audit-ready evidence. </p><p>Lastly, no TCP next week. We&#8217;ll be back with issue 138 on July 28th! </p><p>Now, onto the news!</p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>Chaos is Not a Response Strategy</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mP2j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mP2j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png 424w, https://substackcdn.com/image/fetch/$s_!mP2j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png 848w, https://substackcdn.com/image/fetch/$s_!mP2j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png 1272w, https://substackcdn.com/image/fetch/$s_!mP2j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mP2j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png" width="552" height="81.89010989010988" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:216,&quot;width&quot;:1456,&quot;resizeWidth&quot;:552,&quot;bytes&quot;:29451,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/203251077?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!mP2j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png 424w, https://substackcdn.com/image/fetch/$s_!mP2j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png 848w, https://substackcdn.com/image/fetch/$s_!mP2j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png 1272w, https://substackcdn.com/image/fetch/$s_!mP2j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff874bb60-0aed-40d8-857e-53e1c42a9d33_2127x315.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;">Cyber incidents no longer end at containment. Legal, privacy, IT, executives, and regulators all need answers fast. Our Cybersecurity Incident Response Management (CIRM) Buyer&#8217;s Guide shows how to evaluate platforms built for coordinated, defensible enterprise response.</p><p style="text-align: center;">Learn how AI-powered CIRM clarifies ownership, tracks obligations, preserves privilege, and creates an audit-ready record so your team can turn chaos into control.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://info.breachrx.com/cirm-buyers-guide?utm_source=publication&amp;utm_medium=email-sponsored&amp;utm_campaign=2026-06_oth_cybersecurity-pulse-email&quot;,&quot;text&quot;:&quot;Download the guide&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://info.breachrx.com/cirm-buyers-guide?utm_source=publication&amp;utm_medium=email-sponsored&amp;utm_campaign=2026-06_oth_cybersecurity-pulse-email"><span>Download the guide</span></a></p></div><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#129513; <strong><a href="https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data">Klue breach hits Salesforce</a>:</strong> LastPass, Huntress, HackerOne, and more disclosed impact from stolen OAuth tokens.</p></li><li><p>&#128736;&#65039; <strong><a href="https://www.securityweek.com/openai-refocuses-cybersecurity-efforts-on-patching-over-discovery/">OpenAI shifts to patching</a>:</strong> Daybreak adds GPT-5.5-Cyber, Codex Security updates, and Patch the Planet.</p></li><li><p>&#127981; <strong><a href="https://newsroom.accenture.com/news/2026/accenture-to-strengthen-critical-infrastructure-defense-with-end-to-end-cybersecurity-platform-in-age-of-ai-driven-cyber-threats-and-geopolitical-risk">Accenture buys into OT</a>:</strong> Accenture agrees to take a Dragos majority stake and buy runZero/NetRise for total $4.15B. </p></li><li><p>&#129534; <strong><a href="https://www.gist.security/">Gist comes out of stealth</a>:</strong> Gist turns product and code changes into risk reviews, threat models, and audit-ready evidence.</p></li><li><p>&#129529; <strong><a href="https://www.cybersecuritypulse.net/p/a-6x-ciso-on-the-era-that-security">Security&#8217;s cleanup era</a>:</strong> Dr. Yonesy N&#250;&#241;ez says the work is simple, not easy: close the gaps before they compound.</p></li><li><p>&#129504; <strong><a href="https://www.reuters.com/technology/israeli-cyber-startup-dream-raises-260-million-valued-3-billion-2026-06-18/">Dream raises $260M</a>:</strong> Bicycle Capital and Group 11 co-led the round at a $3B valuation.</p></li><li><p>&#129706; <strong><a href="https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-widefield-security">Cisco targets WideField</a>:</strong> Cisco plans to add identity and session context to Splunk&#8217;s Agentic SOC.</p></li></ul><p><strong>Plus:</strong> OT-specific AI, coding-agent controls, SASE deployment skills, a cursed awareness test, and more. </p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><a href="https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data">Klue breach turns OAuth tokens into a Salesforce data-theft lane</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HuM-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HuM-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png 424w, https://substackcdn.com/image/fetch/$s_!HuM-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png 848w, https://substackcdn.com/image/fetch/$s_!HuM-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png 1272w, https://substackcdn.com/image/fetch/$s_!HuM-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HuM-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png" width="1456" height="1036" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac50329d-ad32-4782-9e35-437ead006842_2400x1708.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1036,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:314452,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/203251077?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HuM-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png 424w, https://substackcdn.com/image/fetch/$s_!HuM-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png 848w, https://substackcdn.com/image/fetch/$s_!HuM-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png 1272w, https://substackcdn.com/image/fetch/$s_!HuM-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac50329d-ad32-4782-9e35-437ead006842_2400x1708.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <strong>Klue</strong> breach appears to have started with a stale credential and ended with attackers using trusted SaaS integrations to pull customer data from Salesforce.</p><p><a href="https://www.huntress.com/blog/klue-breach-investigation?utm_source=chatgpt.com">According to</a> <strong><a href="https://www.notion.so/331333f663c04fe4a9c05ffceee02bcc?pvs=21">Huntress</a></strong>, attackers used a long-disused but still active credential tied to an abandoned integration prototype, pivoted into Klue backend systems, and pushed code that collected customer OAuth tokens. Those tokens were then used to access connected environments, including Salesforce. ReliaQuest observed attackers using Python scripts and the Salesforce REST API for bulk extraction, including nearly <strong>1,000 queries in 15 minutes</strong> in one environment.</p><p>Klue disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack while investigating. Publicly disclosed impacted companies include <strong>Huntress</strong>, <strong>LastPass</strong>, <strong>HackerOne</strong>, <strong>Recorded Future</strong>, <strong>Jamf</strong>, <strong>Snyk</strong>, <strong>OneTrust</strong>, <strong>Tanium</strong>, <strong>Gong</strong>, <strong>Sprout Social</strong>, and <strong>Insurity</strong>. <strong>LastPass</strong> said attackers accessed business contact info, support case data, and sales-related data, but said customer vaults were not affected.</p><p>Once again, a forgotten integration credential at one vendor became a working key into other companies&#8217; CRM data. OAuth tokens are pretty much non-human identities with business context, access, and persistence.. That makes them perfect for this kind of campaign (remember Vercel and Salesloft/Drift breaches?).</p><div><hr></div><h4><a href="https://www.securityweek.com/openai-refocuses-cybersecurity-efforts-on-patching-over-discovery/">OpenAI shifts Daybreak toward patching</a></h4><p><strong>OpenAI</strong> is expanding Daybreak with an updated <strong>Codex Security</strong> plugin, a limited release of <strong>GPT-5.5-Cyber</strong>, and <strong>Patch the Planet</strong>, an open-source remediation initiative with Trail of Bits, HackerOne, Calif, researchers, and maintainers.</p><p>The company says Codex Security has scanned <strong>30M+ commits</strong> across <strong>30,000+ codebases</strong>, with human reviewers marking <strong>70,000+ findings</strong> as fixed and more than <strong>500,000 findings</strong> automatically determined to be fixed. While GPT-5.5-Cyber outperformed GPT-5.5 on CyberGym, ExploitGym, and SEC-bench Pro.</p><p>The contrast with the Mythos/Glasswing circus is pretty loud. Anthropic turned frontier cyber capability into a global shock. OpenAI is trying to frame similar capabilities as remediation infrastructure: find, validate, patch, land the fix.</p><div><hr></div><h4><a href="https://newsroom.accenture.com/news/2026/accenture-to-strengthen-critical-infrastructure-defense-with-end-to-end-cybersecurity-platform-in-age-of-ai-driven-cyber-threats-and-geopolitical-risk">Accenture makes a $4.175B OT security bet</a></h4><p><strong>Accenture</strong> agreed to acquire a majority stake in <strong>Dragos</strong> and all of <strong>runZero</strong> and <strong>NetRise</strong> in a deal valued at approximately <strong>$4.175B</strong>.</p><p>The move gives Accenture a much larger software footprint in OT security: Dragos brings industrial threat detection, runZero adds asset intelligence and exposure assessment, and NetRise adds firmware and software supply chain visibility. Accenture says the three companies are estimated to generate roughly <strong>$208M ARR</strong> as of June 2026. Dragos will keep operating independently, with runZero and NetRise rolling under Dragos.</p><p>This is Accenture buying its way from OT services into OT security software. Having worked in Accenture&#8217;s security consulting biz, I can say that they service a strong portion of the federal govt. and critical infrastructure co&#8217;s (i.e., energy). These are great pickups for Accenture, especially considering that AI has disrupted the value of all their other offerings.</p><div><hr></div><h4><a href="https://finance.yahoo.com/technology/ai/articles/dream-raises-260m-reveals-sovereign-101700202.html?guccounter=1">Dream raises $260M for sovereign AI cyber defense</a></h4><p><strong>Dream</strong> raised <strong>$260M</strong> at a <strong>$3B valuation</strong> to expand its sovereign AI and cyber defense platforms for governments and critical infrastructure.</p><p>The round was co-led by <strong>Bicycle Capital</strong> and <strong>Group 11</strong>, with participation from <strong>Antler</strong>, <strong>Bain Capital Ventures</strong>, <strong>Tru Arrow Partners</strong>, and other global investors. Dream was founded by <strong>Shalev Hulio</strong>, former CEO and co-founder of NSO Group, former Austrian Chancellor <strong>Sebastian Kurz</strong>, and CTO <strong>Gil Dolev</strong>. Its pitch is national cyber defense and sovereign AI for governments that want more control over data, models, and critical infrastructure security.</p><p>Dream is selling the same geopolitical anxiety that is reshaping the whole AI security market: countries do not want their defensive stack dependent on someone else&#8217;s frontier model, cloud, or export policy. The uncomfortable part is the founder history. A former NSO CEO building sovereign defensive AI for governments is interesting.</p><div><hr></div><h4><a href="https://www.theregister.com/security/2026/06/22/canadian-health-board-sorry-after-tasteless-phishing-test/5259320">Health board apologizes for tasteless phishing test</a></h4><p><strong>Newfoundland and Labrador Health Services</strong> apologized after sending staff a phishing simulation that dangled an extra paid vacation day as bait.</p><p>The test thanked employees and physicians for their work on the CorCare software rollout, then invited them to click a button to redeem the day off. Anyone who clicked failed the test. The Registered Nurses&#8217; Union called the exercise insensitive, pointing to staffing shortages, burnout, and the difficulty healthcare workers already face getting paid time off.</p><p>It&#8217;s 2026. Pretty wild that this is still happening &#128579;</p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><h4><a href="https://snyk.io/blog/agentic-development-security-ads/">Snyk launches Agentic Development Security</a></h4><p><strong>Snyk</strong> launched <strong>Evo Agentic Development Security</strong>, a new capability for governing AI-driven development workflows before agent-generated code hits repos, pipelines, or production. The pitch is to secure what agents use, what they do, and what they generate, including MCP servers, tools, permissions, agent actions, and AI-written code. This is the right problem: AppSec tooling was built around humans committing code, but coding agents are starting to act before traditional controls even see the artifact.</p><div><hr></div><p><strong>More AI Security News</strong> </p><ul><li><p><a href="https://www.techtimes.com/articles/318616/20260618/enterprise-ai-agent-security-startups-raise-98m-convey-arcade-tackle-production-gap.htm">Enterprise AI Agent Security Startups Raise $98M: Convey and Arcade Tackle Production Gap</a></p></li><li><p><a href="https://securitybrief.com.au/story/rubrik-ties-ai-security-tools-to-aws-bedrock-agentcore">Rubrik ties AI security tools to AWS Bedrock AgentCore</a></p></li><li><p><a href="https://www.fierce-network.com/newswire/cloudflare-launches-ai-skill-set-sase-deployments">Cloudflare launches AI skill set for SASE deployments</a></p></li></ul><div><hr></div><h2><strong>IoT/OT Security </strong></h2><h4><a href="https://www.securityweek.com/dragos-unveils-ai-for-ot-security/">Dragos unveils EmberAI for OT security</a></h4><p><strong>Dragos</strong> unveiled <strong>EmberAI</strong>, an OT-specific AI capability built on its Intelligence Fabric dataset, which includes adversary tracking, vuln research, asset and protocol research, and incident response experience. EmberAI lets analysts ask plain-language questions, correlate threat intel, assets, vulnerabilities, and network activity, and keep data inside the customer-controlled Dragos deployment. The useful bit is not &#8220;AI for OT,&#8221; it is context: generic copilots are weak in industrial environments unless they understand protocols, process risk, and why taking something offline can be worse than leaving it exposed.</p><div><hr></div><h2><strong>Security Operations</strong></h2><h4><a href="https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-widefield-security">Cisco buys WideField for Splunk&#8217;s Agentic SOC</a></h4><p><strong>Cisco</strong> plans to acquire <strong>WideField Security</strong> to strengthen Splunk&#8217;s Agentic SOC with identity, credential, session, and blast-radius context. WideField maps human and non-human identities, detects weak authentication paths and policy drift, and adds live session monitoring into investigations. This is the right direction for agentic SOC: autonomous response is mostly theater unless the system understands who the actor is, what they can touch, and what breaks if it takes action.</p><div><hr></div><p><strong>More Security Operations News</strong></p><ul><li><p><a href="https://siliconangle.com/2026/06/17/sentinelone-turns-purple-ai-loose-investigate-threats/">SentinelOne turns Purple AI loose to investigate threats on its own</a></p></li></ul><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[A 6x CISO on the era that security just entered]]></title><description><![CDATA[The Hygiene Era is here, and the boring work is now the moat.]]></description><link>https://www.cybersecuritypulse.net/p/a-6x-ciso-on-the-era-that-security</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/a-6x-ciso-on-the-era-that-security</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Tue, 23 Jun 2026 13:56:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!U7dD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer in big tech. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/25-million-alerts-one-year-of-real?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxMTY2OTE1NTEsInBvc3RfaWQiOjE4OTk5NTgyNCwiaWF0IjoxNzczMTk3ODk5LCJleHAiOjE3NzU3ODk4OTksImlzcyI6InB1Yi0xMjU0OTkwIiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.uLri8qmd3TaY1NBupbqOvebAA6UkoZKWikyo0XeoQSw&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/25-million-alerts-one-year-of-real?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxMTY2OTE1NTEsInBvc3RfaWQiOjE4OTk5NTgyNCwiaWF0IjoxNzczMTk3ODk5LCJleHAiOjE3NzU3ODk4OTksImlzcyI6InB1Yi0xMjU0OTkwIiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.uLri8qmd3TaY1NBupbqOvebAA6UkoZKWikyo0XeoQSw"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U7dD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U7dD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png 424w, https://substackcdn.com/image/fetch/$s_!U7dD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png 848w, https://substackcdn.com/image/fetch/$s_!U7dD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png 1272w, https://substackcdn.com/image/fetch/$s_!U7dD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U7dD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png" width="1442" height="812" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:812,&quot;width&quot;:1442,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U7dD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png 424w, https://substackcdn.com/image/fetch/$s_!U7dD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png 848w, https://substackcdn.com/image/fetch/$s_!U7dD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png 1272w, https://substackcdn.com/image/fetch/$s_!U7dD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b06c1f6-132e-4205-9b3c-80a826a9788b_1442x812.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Guest post by Dr. Yonesy N&#250;&#241;ez, CISO at <a href="https://www.surf.ai/">Surf AI</a> (previously Wells Fargo, Jack Henry, and DTCC). Published in partnership with <a href="https://www.surf.ai/">Surf AI</a>.</em></p><div><hr></div><p><span>I&#8217;ve spent more than two decades running enterprise security programs &#8212; five CISO seats across Wells Fargo, Jack Henry, and DTCC. In that time, I&#8217;ve watched security go through five distinct eras. Each one was a real response to a real shift in how attackers worked, what auditors wanted, and where the workloads ran. And in each one, the same thing happened: security hygiene got pushed further down the backlog.</span></p><p><span>We&#8217;re entering a sixth era. This time, hygiene is the strategic discipline &#8212; the work that decides whether the rest of the security program can actually hold.</span></p><p><span>I want to be specific about what I mean by hygiene: the recurring operational work that reduces attack surface. Dormant accounts. Stale OAuth apps. Secrets and environment variables left readable in production. Expired certificates. Third-party access no one has reviewed since the integration was built. Plaintext sensitive data. AI tools connected to your environment that nobody on the security team knows exist.</span></p><p><span>That work has always been on the roadmap. It almost never got funded at the level it deserved. This year, three events made it impossible to ignore why that has to change.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fLxN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fLxN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png 424w, https://substackcdn.com/image/fetch/$s_!fLxN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png 848w, https://substackcdn.com/image/fetch/$s_!fLxN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png 1272w, https://substackcdn.com/image/fetch/$s_!fLxN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fLxN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png" width="1456" height="1820" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1820,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1476451,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/203243859?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fLxN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png 424w, https://substackcdn.com/image/fetch/$s_!fLxN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png 848w, https://substackcdn.com/image/fetch/$s_!fLxN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png 1272w, https://substackcdn.com/image/fetch/$s_!fLxN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8444fe49-061e-4d38-8040-a411159cd69a_2160x2700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2><strong><span>The five eras I&#8217;ve worked through</span></strong></h2><p><strong><span>Perimeter</span></strong><span> </span><em><span>(late 1990s into the early 2000s):</span></em><span> Firewalls, DMZs, NAT. The marquee discipline was the boundary. If the perimeter held, the inside was assumed safe. Hygiene was invisible.</span></p><p><strong><span>Compliance</span></strong><span> </span><em><span>(early to mid-2000s):</span></em><span> SOX, PCI DSS, HIPAA enforcement. Audit became the gate. Hygiene sat on every framework&#8217;s control list and almost never got primary funding. Passing the audit was a faster path to keeping your seat than fixing the underlying mess.</span></p><p><strong><span>Detection and APT</span></strong><span> </span><em><span>(late 2000s through mid-2010s):</span></em><a href="https://cloud.google.com/blog/topics/threat-intelligence/operation-aurora-2010"><span> Operation Aurora</span></a><span>,</span><a href="https://www.cisa.gov/news-events/alerts/2010/07/20/increased-threat-stuxnet-malware"><span> Stuxnet</span></a><span>,</span><a href="https://www.mandiant.com/resources/reports/apt1-exposing-one-of-chinas-cyber-espionage-units"><span> Mandiant&#8217;s APT1 report</span></a><span>. SIEM proliferation. Assume breach. Detection became the strategic discipline &#8212; you couldn&#8217;t stop everything, but you could respond fast enough. Hygiene deficits got absorbed by detection coverage.</span></p><p><strong><span>Cloud and zero trust</span></strong><span> </span><em><span>(mid-2010s into the early 2020s):</span></em><span> Workloads moved off the corporate network. Identity became the new perimeter.</span><a href="https://www.cisa.gov/news-events/alerts/2020/12/13/active-exploitation-solarwinds-software"><span> SolarWinds</span></a><span> was the marker. Hygiene changed shape &#8212; third-party access, identity sprawl, OAuth apps &#8212; and stayed in the backlog.</span></p><p><strong><span>SOAR and AI SOC</span></strong><span> </span><em><span>(overlapping with the above):</span></em><span> The promise was that you could manage alert volume without doing the cleanup that produced the alerts. SOAR automated parts of the response motion. AI SOC now extends that idea with agents, copilots, and autonomous triage loops. That wave is still useful, but it does not remove the underlying problem. If anything, it makes the hygiene gap more obvious: faster alert handling does not fix the stale account, exposed secret, permissive OAuth grant, or unmanaged SaaS tool that created the incident path in the first place.</span></p><p><span>Each era was a rational response to real conditions. And each one helped security teams absorb the risk created by hygiene gaps. The model worked &#8212; more or less &#8212; because attacker tempo stayed inside what human-staffed detection could close.</span></p><p><span>That model broke in April 2026.</span></p><div><hr></div><h2><strong><span>What April 2026 actually showed us</span></strong></h2><p><span>Three events, read together, make the argument.</span></p><p><strong><a href="https://www.wiz.io/blog/claude-mythos"><span>Anthropic and Claude Mythos</span></a></strong><span> (April 7). Anthropic disclosed that a single model run surfaced thousands of zero-day vulnerabilities &#8212; including long-lived flaws in major operating systems and browsers &#8212; and produced working exploits at a scale prior generations could not approach. Anthropic chose not to ship the model publicly and instead stood up</span><a href="https://www.anthropic.com/glasswing"><span> Project Glasswing</span></a><span> to share findings with vetted partners. That decision, and the stated reason behind it, is what matters: discovery cost is approaching zero.</span></p><p><strong><a href="https://xint.io/blog/copy-fail-linux-distributions"><span>CVE-2026-31431</span></a></strong><span> (Copy Fail, April 29). Xint Code disclosed a Linux kernel logic flaw affecting major Linux distributions. A 732-byte Python proof-of-concept could obtain root on Ubuntu, Amazon Linux, Red Hat Enterprise Linux, and SUSE. CISA later added the vulnerability to its</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span> Known Exploited Vulnerabilities catalog</span></a><span>. The hygiene implication is direct: asset inventory, kernel exposure tracking, patch ownership, and exploitability context in your environment. If you can&#8217;t answer which systems are affected and who owns the remediation, this CVE is an open door.</span></p><p><strong><a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident"><span>The Vercel breach</span></a></strong><span> (April 19). This one is the most instructive. An employee at Context.ai was compromised by Lumma Stealer, giving an attacker a path through OAuth into Vercel. The result: exposed environment variables, a database key, and source code. The root cause wasn&#8217;t a zero-day &#8212; it was an uninventoried AI tool, an OAuth trust relationship that granted broader access than anyone realized, and secrets governance that treated readable environment variables as low risk.</span></p><p><span>The same pattern appeared in the 2025</span><a href="https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift"><span> Salesloft Drift OAuth incident</span></a><span>, where compromised OAuth tokens tied to a trusted integration enabled access to Salesforce environments. The campaign affected a number of high-profile organizations, including Cloudflare and Palo Alto Networks, which disclosed unauthorized access to its Salesforce tenant through the compromised Salesloft Drift integration. The lesson is the same: modern breach paths increasingly run through trusted SaaS integrations, OAuth grants, third-party tools, and data that security teams did not realize those tools could reach.</span></p><p><span>That&#8217;s what April showed: discovery cost is collapsing, so exposed inventory matters more than it ever did. </span></p><p><span>The failure mode is now an uninventoried trust relationship, not a missed alert. And attack tempo scales with compute &#8212; which means detection that scales with headcount can&#8217;t keep up.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!p4ea!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!p4ea!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png 424w, https://substackcdn.com/image/fetch/$s_!p4ea!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png 848w, https://substackcdn.com/image/fetch/$s_!p4ea!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!p4ea!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!p4ea!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png" width="1456" height="602" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6544491-ae61-4315-a566-c39794506bcf_2912x1204.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:602,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:505882,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/203243859?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!p4ea!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png 424w, https://substackcdn.com/image/fetch/$s_!p4ea!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png 848w, https://substackcdn.com/image/fetch/$s_!p4ea!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!p4ea!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6544491-ae61-4315-a566-c39794506bcf_2912x1204.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2><strong><span>Why hygiene becomes the strategic discipline</span></strong></h2><p><span>The reason hygiene was always deprioritized is rational: every era&#8217;s marquee discipline absorbed the risk that hygiene gaps created. Detection caught what hygiene missed. SOAR papered over what detection missed. AI SOC may accelerate triage and response, but it does not eliminate the blast radius created by unmanaged access, exposed secrets, stale identities, or unreviewed integrations.</span></p><p><span>That model held as long as attacker tempo stayed inside what human-staffed detection could close. It doesn&#8217;t hold anymore.</span></p><p><span>Here&#8217;s what changes: hygiene is the only security discipline that compounds. Every account removed, every secret rotated, every third-party tool inventoried makes future attacks measurably more expensive. It doesn&#8217;t matter what the attacker discovers tomorrow &#8212; every piece of hygiene work between now and then is still in force.</span></p><p><span>Detection burns down with the alert. A SOAR playbook burns down with the incident. An AI SOC agent can help summarize, prioritize, and respond faster. But hygiene reduces the surface that the next alert fires on. As attackers exploit vulnerabilities and trust relationships faster than ever, hygiene stops being optional and becomes non-negotiable. The unglamorous work is now the strategic work.</span></p><div><hr></div><h2><strong><span>What this looks like in practice</span></strong></h2><p><span>For the board update, three frames hold up:</span></p><p><strong><span>Detection investment has a ceiling defined by attacker tempo.</span></strong><span> We&#8217;re not going to chase it by adding headcount.</span></p><p><strong><span>Hygiene investment compounds across every future incident class.</span></strong><span> We&#8217;re funding it as program work, not project work &#8212; which means dedicated ownership, not quarterly cleanup sprints.</span></p><p><strong><span>Context investment turns hygiene into outcomes.</span></strong><a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth"><span> NIST has changed how it enriches CVEs in the National Vulnerability Database</span></a><span>. The public pipeline can&#8217;t be relied on the way it once could. Re-deriving severity inside your own environment &#8212; knowing which systems are actually exposed, who owns them, and what business function they support &#8212; is no longer optional.</span></p><p><span>For practitioners, the work that compounds fastest in 2026 is the work the backlog has been carrying for a decade:</span></p><ul><li><p><span>Identity hygiene as a standing program: dormant accounts, leaver audits, guest accounts, OAuth application scope review</span></p></li><li><p><span>Third-party inventory, expanded to include AI tools and their data access</span></p></li><li><p><span>Environment variable and secrets governance, treated as program work rather than ticketing-system tasks</span></p></li><li><p><span>Certificate lifecycle with executive backing and cross-team ownership, not a quarterly project</span></p></li></ul><p><span>None of this is new. What&#8217;s new is that the justification for deferring it no longer holds.</span></p><div><hr></div><h2><strong><span>Why I joined a startup to work on this</span></strong></h2><p><span>In December, I left DTCC to join</span><a href="https://surf.ai/"><span> Surf AI</span></a><span>. The question I get most often: why leave a CISO seat at a major financial infrastructure firm to join an early-stage company?</span></p><p><span>The answer is the argument above.</span></p><p><span>Hygiene at scale doesn&#8217;t get done by adding headcount. The operational surface &#8212; dormant accounts, external OAuth apps, sensitive data in plaintext, certificate lifecycle &#8212; crosses too many systems and teams for manual workflows to close. What I wanted to work on was the question of how specialized AI agents execute those operational disciplines at speed, with human approval at every step, in a way that actually closes the gap rather than auditing it.</span></p><p><span>That&#8217;s what Surf AI is building. And when I saw what April was going to look like &#8212; well before any of those three events were public &#8212; it confirmed that this is the right problem to work on now.</span></p><div><hr></div><h2><strong><span>A closing thought</span></strong></h2><p><span>Every prior era named itself in retrospect. This one is naming itself in real time, while the discovery curve bends past where prior playbooks were designed to operate.</span></p><p><span>When the next exploit arrives, the teams that come through it cleanest will be the ones that spent the months before reducing surface, not chasing alerts.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FVZJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FVZJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png 424w, https://substackcdn.com/image/fetch/$s_!FVZJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png 848w, https://substackcdn.com/image/fetch/$s_!FVZJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png 1272w, https://substackcdn.com/image/fetch/$s_!FVZJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FVZJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png" width="1456" height="643" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:643,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:579989,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/203243859?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FVZJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png 424w, https://substackcdn.com/image/fetch/$s_!FVZJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png 848w, https://substackcdn.com/image/fetch/$s_!FVZJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png 1272w, https://substackcdn.com/image/fetch/$s_!FVZJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12e6d0dd-1571-4b4f-856e-ddab409311c2_2912x1286.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>If you&#8217;re seeing the same pattern in your environment, find me. The peers who tell each other the truth about what&#8217;s happening on the ground are the ones who get their organizations through periods like this intact.</span></p><div><hr></div><h2><strong>Interested in sponsoring TCP?</strong></h2><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to an audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p>]]></content:encoded></item><item><title><![CDATA[It was all a Fable; Identiverse news; and another Copilot makes old bugs new again]]></title><description><![CDATA[Anthropic FAFOs, while Ent raised a monster seed, Copilot got a one-click exfil chain, and identity vendors bought into agent security.]]></description><link>https://www.cybersecuritypulse.net/p/it-was-all-a-fable-identiverse-news</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/it-was-all-a-fable-identiverse-news</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 17 Jun 2026 14:50:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ENSg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/it-was-all-a-fable-identiverse-news?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/it-was-all-a-fable-identiverse-news?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ENSg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ENSg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!ENSg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!ENSg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!ENSg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ENSg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3359761,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/202428931?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ENSg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!ENSg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!ENSg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!ENSg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F455da3e7-0c2a-4b6e-9e7e-b0804cdc03ba_1800x1300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from!</p><p>It&#8217;s <a href="https://identiverse.com/">Identiverse</a> week which means a ton of developments on the IAM front. Key pieces in the NHI race being pulled off the board, new ones emerging w/ mega rounds of funding etc. Aside from that, Anthropic&#8217;s latest model remains in the spotlight after being pulled from the public due to a &#8216;security flaw&#8217; found by Amazon researchers. Whitehats are angry. It&#8217;s been a whirlwind of a week and it&#8217;s not even over yet. </p><p>On the personal front, I got to celebrate my good friend Day this weekend, a former Datadog colleague, elite cyber operator, and now a married man. It was pretty dope experiencing the traditional Nigerian wedding ceremony and being there for one of his biggest moments in life!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qt6w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qt6w!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qt6w!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qt6w!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qt6w!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qt6w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg" width="660" height="461.13258600695787" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3615,&quot;width&quot;:5174,&quot;resizeWidth&quot;:660,&quot;bytes&quot;:2947531,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/202428931?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf24b307-b6c7-41be-84fa-6eef0b5fe242_5712x4284.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qt6w!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qt6w!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qt6w!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qt6w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9dbeaf5f-ef8b-4cde-bdb7-4d5b26dc1b5d_5174x3615.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now, onto the news! </p><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#129512; <strong><a href="https://www.darkreading.com/vulnerabilities-threats/security-community-slams-us-ban-on-exporting-mythos-fable">Anthropic&#8217;s export fight gets ugly:</a></strong> Fable gets repealed. Security leaders want Fable and Mythos access restored for defenders.</p></li><li><p>&#129470; <strong><a href="https://www.securityweek.com/endpoint-security-startup-ent-emerges-from-stealth-with-100-million-seed-round/">Ent raises $100 million</a></strong>: Decibel led, with Sequoia, Crosspoint, Craft, Shield, Felicis, and In-Q-Tel. Endpoint security. Former RiskIQ founders.</p></li><li><p>&#128371;&#65039; <strong><a href="https://www.varonis.com/blog/searchleak">Varonis SearchLeak hits Copilot</a></strong>: One click could leak emails, files, calendar details, and MFA codes.</p></li><li><p>&#129534; <strong><a href="https://www.businessinsider.com/microsoft-was-in-talks-to-lease-oracle-compute-capacity-2026-6">Microsoft walks from Oracle deal:</a></strong> Reported FedRAMP concerns stalled more than $3 billion in cloud capacity.</p></li><li><p>&#128659;<a href="https://www.404media.co/cops-keep-getting-arrested-for-using-flock-to-stalk-people/"> </a><strong><a href="https://www.404media.co/cops-keep-getting-arrested-for-using-flock-to-stalk-people/">Flock keeps getting abused</a>:</strong> Police allegedly used ALPR searches to stalk romantic partners and exes.</p></li><li><p><a href="https://www.databricks.com/company/newsroom/press-releases/databricks-agrees-acquire-panther-further-establishing-security">&#129521; </a><strong><a href="https://www.databricks.com/company/newsroom/press-releases/databricks-agrees-acquire-panther-further-establishing-security">Databricks buys Panther:</a></strong> Lakewatch gets detection-as-code, 100+ integrations, and a real SOC core.</p></li><li><p>&#129706; <strong><a href="https://www.sailpoint.com/press-releases/sailpoint-announces-intent-to-acquire-entro-security">Identity vendors buy agents</a></strong>: SailPoint/Entro (~$200M) and 1Password/Apono ($250-300M) push agent security into IAM.</p></li><li><p>&#129516; <strong><a href="https://newcore.com/newsroom/newcore-emerges-from-stealth-66m">NewCore raises $66 million</a></strong>: Cyberstarts, Index, and Evolution back another agent identity swing.</p></li></ul><p><strong>Plus:</strong> Rubrik launches Claude security controls, identity standards get their weekly acronym workout, and more. </p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>Adaptive Security: Next-Generation Security Awareness Training</strong></h4><div id="youtube2-bHO7Fn2920w" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;bHO7Fn2920w&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/bHO7Fn2920w?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p style="text-align: center;">Deepfakes of your CEO. Voice calls cloning your CFO. Phishing emails no filter catches. AI has changed how attackers target your people and most teams aren't ready. </p><p style="text-align: center;">Adaptive Security trains employees against the attacks they'll actually face, with 1,000+ interactive modules that deploy automatically. Zero manual effort. Trusted by security teams at PayPal, Ramp, Bose, and more. Rated 5 stars on G2 and Gartner Peer Insights.</p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivesecurity.com/demo/security-awareness-training?utm_source=sp_email&amp;utm_medium=other&amp;utm_campaign=2026_Q2_TCP&amp;utm_id=701Rd00000iv54yIAA&quot;,&quot;text&quot;:&quot;Tour the Platform&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adaptivesecurity.com/demo/security-awareness-training?utm_source=sp_email&amp;utm_medium=other&amp;utm_campaign=2026_Q2_TCP&amp;utm_id=701Rd00000iv54yIAA"><span>Tour the Platform</span></a></p></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><a href="https://www.darkreading.com/vulnerabilities-threats/security-community-slams-us-ban-on-exporting-mythos-fable">Anthropic&#8217;s AI export fight gets ugly</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f-Z4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f-Z4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png 424w, https://substackcdn.com/image/fetch/$s_!f-Z4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png 848w, https://substackcdn.com/image/fetch/$s_!f-Z4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png 1272w, https://substackcdn.com/image/fetch/$s_!f-Z4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f-Z4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png" width="1456" height="1030" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1030,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1662010,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/202428931?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f-Z4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png 424w, https://substackcdn.com/image/fetch/$s_!f-Z4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png 848w, https://substackcdn.com/image/fetch/$s_!f-Z4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png 1272w, https://substackcdn.com/image/fetch/$s_!f-Z4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29b5a742-cff6-4e31-a74f-158ff312f0aa_1491x1055.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Dozens of security leaders are urging the U.S. government to roll back export restrictions on <strong>Anthropic&#8217;s Claude Fable 5 and Mythos 5</strong>, after Anthropic disabled both models for all customers to comply with a foreign-national access ban. Signers include <strong>Alex Stamos</strong>, <strong>Katie Moussouris</strong>, <strong>Casey Ellis</strong>, <strong>Bruce Schneier</strong>, <strong>Joe Levy</strong>, <strong>Chris Wysopal</strong>, <strong>Dan Lorenc</strong>, and <strong>Rachel Tobac</strong>, among others. </p><p>The Amazon part makes this even stranger: <strong>Amazon</strong> researchers got a Mythos-class model to produce restricted cyberattack information, then Andy Jassy (CEO) raised concerns with senior U.S. officials. Anthropic says the issue was narrow, not unique to Fable, and not enough to justify cutting off defenders. <strong>Fair, but Anthropic also spent months telling everyone its frontier models were cyber dynamite with an API, so the shocked Pikachu act is not exactly compelling</strong>. </p><p>The ban is still bad policy because serious adversaries don&#8217;t give 2 fcks probably jailbroke Fable/Mythos on Day 0 so barring defenders from having access is not smart.  but it exposed the bigger problem sitting underneath the AI security boom. If security teams, companies, and countries are building critical workflows on frontier models they do not control, they are not just renting intelligence, they are renting someone else&#8217;s off switch.</p><div><hr></div><h4><a href="https://www.securityweek.com/endpoint-security-startup-ent-emerges-from-stealth-with-100-million-seed-round/">Ent comes out swinging with a $100M seed</a></h4><p><em>This one earned the second slot as it&#8217;s got all the makings of a generational company with focusing on a hard problem, strong founding team, backers and significant seed size.</em><strong> </strong></p><p><strong><a href="https://ent.ai/">Ent</a></strong> emerged from stealth with <strong>$100 million</strong> in seed funding led by <strong>Decibel</strong>, with Sequoia, Crosspoint Capital Partners, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel participating.</p><p>The company is building an intent-aware workspace security platform that runs at the endpoint and intervenes before risky human or AI-agent actions turn into incidents. The founding team, Elias Manousos and Brandon Dixon, previously co-founded RiskIQ and helped launch Microsoft Security Copilot.</p><p>The category overlap is significant. Ent sits near endpoint, DLP, insider risk, AI governance, and agent security, which means the execution bar is high from day one.</p><div><hr></div><h4><a href="https://www.varonis.com/blog/searchleak?utm_source=chatgpt.com">SearchLeak flaw turns Copilot into a one-click exfil path</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SOjM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SOjM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png 424w, https://substackcdn.com/image/fetch/$s_!SOjM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png 848w, https://substackcdn.com/image/fetch/$s_!SOjM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png 1272w, https://substackcdn.com/image/fetch/$s_!SOjM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SOjM!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png" width="1200" height="517.5824175824176" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:628,&quot;width&quot;:1456,&quot;resizeWidth&quot;:1200,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;SearchLeakFlowChart&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="SearchLeakFlowChart" title="SearchLeakFlowChart" srcset="https://substackcdn.com/image/fetch/$s_!SOjM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png 424w, https://substackcdn.com/image/fetch/$s_!SOjM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png 848w, https://substackcdn.com/image/fetch/$s_!SOjM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png 1272w, https://substackcdn.com/image/fetch/$s_!SOjM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0beaed5e-b33c-4ffd-93c0-34781ba4cfd4_2628x1134.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Attack Technique Flow</figcaption></figure></div><p><strong><a href="https://www.varonis.com/">Varonis</a></strong> disclosed SearchLeak, a Microsoft 365 Copilot Enterprise flaw chain that could leak emails, calendar details, indexed files, and MFA codes after one click on a trusted Microsoft link.</p><p>The chain abused Copilot Search&#8217;s <code>q</code> parameter as an instruction prompt, raced Microsoft&#8217;s HTML sanitizer during streaming, then used Bing&#8217;s image search endpoint as an SSRF-powered exfil proxy. Microsoft remediated the issue as <strong>CVE-2026-42824</strong>, and Varonis says it was a proof-of-concept, not observed exploitation.</p><p>The weird part is not prompt injection by itself. It is prompt injection making old web bugs that thought went away, reachable again. The question for teams is not &#8220;is Copilot secure,&#8221; it is &#8220;what damage can compromised Copilot cause to my business?&#8221; and then reversing security measures from there. </p><div><hr></div><h4><a href="https://www.businessinsider.com/microsoft-was-in-talks-to-lease-oracle-compute-capacity-2026-6">Microsoft reportedly walked from $3B Oracle cloud deal over compliance concerns</a></h4><p><strong>Microsoft</strong> reportedly walked away from talks to lease more than <strong>$3B</strong> in <strong>Oracle Cloud Infrastructure</strong> capacity after raising security and compliance concerns, according to Business Insider. The sticking point was reportedly FedRAMP: Oracle&#8217;s government cloud is authorized, but the public OCI environment Microsoft wanted to use was not. <a href="https://www.reuters.com/technology/microsofts-cloud-infrastructure-talks-with-oracle-collapse-business-insider-2026-06-16/">Oracle called the report inaccurate</a>, Microsoft declined to comment, and Reuters could not independently verify the report. </p><p>In summary, compliance still matters even in a compute bottlenecked world. </p><div><hr></div><h4><a href="https://www.404media.co/cops-keep-getting-arrested-for-using-flock-to-stalk-people/">Police keep using Flock to stalk people</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pMkt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pMkt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png 424w, https://substackcdn.com/image/fetch/$s_!pMkt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png 848w, https://substackcdn.com/image/fetch/$s_!pMkt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png 1272w, https://substackcdn.com/image/fetch/$s_!pMkt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pMkt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png" width="1456" height="945" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:945,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Cops Keep Getting Arrested for Using Flock to Stalk People&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Cops Keep Getting Arrested for Using Flock to Stalk People" title="Cops Keep Getting Arrested for Using Flock to Stalk People" srcset="https://substackcdn.com/image/fetch/$s_!pMkt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png 424w, https://substackcdn.com/image/fetch/$s_!pMkt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png 848w, https://substackcdn.com/image/fetch/$s_!pMkt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png 1272w, https://substackcdn.com/image/fetch/$s_!pMkt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a82865f-acbb-43b8-8943-ac9428c53dcb_1962x1274.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>404 Media</strong> found more than a dozen cases where police allegedly used <strong>Flock</strong> automated license plate readers to stalk people, often romantic partners or exes. One Florida officer ran his ex-girlfriend&#8217;s plate at least <strong>69 times</strong>, her mother&#8217;s plate <strong>24 times</strong>, and her father&#8217;s plate <strong>15 times</strong>. Flock&#8217;s ALPR network logs where cars travel, then lets police search historical plate data to reconstruct a person&#8217;s movements. </p><p>This is the boring failure mode of surveillance tech. The pitch is always &#8220;find stolen cars faster,&#8221; and the operational reality is that someone eventually uses the same database to track their ex or much, much worse. </p><div><hr></div><h4><a href="https://www.databricks.com/company/newsroom/press-releases/databricks-agrees-acquire-panther-further-establishing-security">Databricks buys Panther to scale security lakehouse</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kcIv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kcIv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png 424w, https://substackcdn.com/image/fetch/$s_!kcIv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png 848w, https://substackcdn.com/image/fetch/$s_!kcIv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png 1272w, https://substackcdn.com/image/fetch/$s_!kcIv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kcIv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png" width="727" height="380.5390625" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:268,&quot;width&quot;:512,&quot;resizeWidth&quot;:727,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Databricks Agrees to Acquire Panther, Further Establishing the Security Lakehouse Category &quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Databricks Agrees to Acquire Panther, Further Establishing the Security Lakehouse Category " title="Databricks Agrees to Acquire Panther, Further Establishing the Security Lakehouse Category " srcset="https://substackcdn.com/image/fetch/$s_!kcIv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png 424w, https://substackcdn.com/image/fetch/$s_!kcIv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png 848w, https://substackcdn.com/image/fetch/$s_!kcIv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png 1272w, https://substackcdn.com/image/fetch/$s_!kcIv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa13a886-dc2d-4e7e-b44e-f8100bd22d29_512x268.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Databricks</strong> agreed to acquire <strong>Panther</strong>, giving Lakewatch a real security operations core instead of just a better data architecture story. Panther brings <strong>100+ integrations</strong>, detection-as-code, and agentic SOC workflows into Databricks&#8217; push to replace legacy SIEM with a security lakehouse. </p><p><strong>Terms were not disclosed,</strong> and the deal is still subject to customary closing conditions. This is Databricks&#8217; third security acquisition, following Antimatter and <a href="http://SiftD.ai">SiftD.ai</a>.</p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><h4><strong><a href="https://www.scworld.com/brief/1password-acquires-apono-to-bolster-ai-security?utm_source=chatgpt.com">Identity vendors buy into agent security</a></strong></h4><p><a href="https://www.sailpoint.com/press-releases/sailpoint-announces-intent-to-acquire-entro-security">SailPoint plans to acquire Entro</a>, while <a href="https://1password.com/press/2026/june/1password-acquires-apono">1Password acquired Apono</a>, giving two identity platforms a faster path into AI-agent and non-human identity security.</p><p><a href="https://identiverse.com/">Identiverse</a> is this week in Las Vegas, so the timing is not random. Non-human identity and agent security are becoming the next identity market fight, and SailPoint and 1Password clearly do not want to watch it from the sidelines.</p><p>SailPoint did not disclose terms, but Calcalist reported the Entro deal at about <strong>$200 million</strong>. 1Password also did not disclose terms, while Calcalist reported the Apono deal at <strong>$250 million to $300 million</strong>.</p><p>Entro brings discovery for secrets, tokens, certificates, and machine identities. Apono brings just-in-time access controls for humans, machines, and agents.</p><p>Agents are mostly an identity, access, and credential problem once you strip away the AI confetti. The NHI space has seen a lot of consolidation lately, with Astrix, Entro, and Apono now off the table. Much-needed consolidation</p><div><hr></div><p><strong>More AI Security News</strong> </p><ul><li><p><a href="https://www.thefastmode.com/technology-solutions/48976-rubrik-launches-agent-cloud-for-anthropic-claude-code-claude-cowork-to-secure-ai-agents">Rubrik Launches Agent Cloud for Anthropic Claude Code &amp; Claude Cowork to Secure AI Agents</a></p></li><li><p><a href="https://siliconangle.com/2026/06/16/okta-expands-google-cloud-partnership-secure-ai-agents-browser/">Okta expands Google Cloud partnership to secure AI agents and the browser</a></p></li></ul><div><hr></div><h2><strong>Identity Security</strong></h2><h4><a href="https://www.msspalert.com/brief/newcore-launches-with-66m-to-secure-human-and-ai-agent-identities">NewCore launches with $66 million for agent identity</a></h4><p><strong><a href="https://newcore.com/">NewCore</a></strong> emerged from stealth with <strong>$66 million</strong> from <strong>Cyberstarts, Index Ventures, and Evolution Equity Partners</strong> to secure identities across humans, machines, and AI agents.</p><p>The team has some real founder-market fit: CEO <strong>Zohar Alon</strong> previously co-founded Dome9, the cloud security company Check Point acquired in 2018. He&#8217;s an experienced builder and advisor/mentor to much of the Israeli cyber ecosystem. </p><p>The space is already crowded, with identity vendors, NHI startups, and agent-security companies all circling the same budget. But the funding, timing, and leadership team make this one more credible than the average &#8220;agents are coming for your IAM&#8221; launch.</p><div><hr></div><p><strong>More IAM Security News</strong> </p><ul><li><p><a href="https://www.opal.dev/blog/ai-guided-access-reviews">Opal adds AI-guided access reviews</a></p></li><li><p><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-expands-identity-leadership-with-openid-and-idpro/">CrowdStrike Expands Identity Leadership with OpenID and IDPro</a></p></li></ul><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[Opus causes $3B Zcash wipeout; $1B+ in funding; and 38 fwd:cloudsec talks]]></title><description><![CDATA[Fable 5 lands, Datadog drops 100+ features, and Kramer and Kurtz show up on the same cap table.]]></description><link>https://www.cybersecuritypulse.net/p/opus-causes-3b-zcash-wipeout-1b-in</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/opus-causes-3b-zcash-wipeout-1b-in</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 10 Jun 2026 14:37:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hzvR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/opus-causes-3b-zcash-wipeout-1b-in?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/opus-causes-3b-zcash-wipeout-1b-in?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hzvR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hzvR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png 424w, https://substackcdn.com/image/fetch/$s_!hzvR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png 848w, https://substackcdn.com/image/fetch/$s_!hzvR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png 1272w, https://substackcdn.com/image/fetch/$s_!hzvR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hzvR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png" width="1009" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1009,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1619792,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/201364099?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hzvR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png 424w, https://substackcdn.com/image/fetch/$s_!hzvR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png 848w, https://substackcdn.com/image/fetch/$s_!hzvR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png 1272w, https://substackcdn.com/image/fetch/$s_!hzvR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48410536-ef95-4e9c-ae7e-af4461420086_1009x728.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from!</p><p>The past 7 days have felt like 582 days lumped into a single week, on all accounts. On the personal front, I shipped <strong><a href="https://www.monad.com/blog/setting-up-openai-codex-otel">Pt. II of my OpenAI Codex Logs detection series</a></strong> and Monad <strong><a href="https://www.monad.com/blog/monad-named-leader-latio-2026-security-operations-market-report">won 2 Latio awards</a></strong> for user reliability and being a data pipeline leader. A true testament of how much the team has been cooking and what&#8217;s to come :) </p><p>I&#8217;ve been working a fair bit on AI tooling visibility and will share what I&#8217;ve come across so far soon so stay tuned on that front. For now, the Monad blog has the most recent updates. <br><br>Aside from that, more Mythos news of course, loads of funding (you&#8217;d think Blackhat is next week), and Opus 4.8 finds a very expensive bug. </p><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#129335;&#127997;&#8205;&#9794;&#65039; <strong><a href="https://securityaffairs.com/193224/hacking/claude-opus-found-a-four-year-old-hole-in-zcashs-privacy-layer-nobody-knows-if-someone-already-used-it.html">Claude Opus found a bug causing $3B wipeout in Zcash</a></strong> &#8212; A public model surfaced a 4-year-old Orchard flaw in 24 hours; ZEC cap got cut in half.</p></li><li><p>&#129718; <strong><a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Anthropic ships Claude Fable 5</a></strong> &#8212; First public Mythos-class model, gated by a classifier layer a state-level team already cracked.</p></li><li><p>&#128302; <strong><a href="https://engineering.salesforce.com/how-salesforce-built-an-ai-security-agent-for-autonomous-threat-triage/">Salesforce&#8217;s triage agent hits 95%</a></strong> &#8212; SATA matches analysts on triage across 80,000 employees, if you have Salesforce&#8217;s budget.</p></li><li><p>&#127909; <strong><a href="https://youtube.com/playlist?list=PLCPCP1pNWD7O2zbp9sao2mNInjpvHWsnR&amp;si=Kmu0x-F3HBTw6ses">fwd:cloudsec 2026 talks are live</a></strong> &#8212; All 38 sessions free on YouTube, heavy on agentic and neocloud risk.</p></li><li><p>&#128200; <strong><a href="https://en.globes.co.il/en/article-cyera-raises-600m-at-12b-valuation-1001545507">Cyera $600M round at $12B valuation</a></strong> &#8212; Led by Evolution Equity; valuation doubled since January. 7th major funding announcement.. Series G? </p></li><li><p>&#129399; <strong><a href="https://siliconangle.com/2026/06/09/ninjaone-raises-400m-endpoint-management-platform/">NinjaOne lands $400M+ secondary</a></strong> &#8212; Profitable, <strong>$500M</strong> ARR, and shopping for partners, not runway.</p></li><li><p>&#128202; <strong><a href="https://siliconangle.com/2026/06/09/datadog-launches-100-features-dash-push-autonomous-ai-ops/">Datadog drops 100+ features at DASH</a></strong> &#8212; AI Guard targets prompt injection; Agent Console monitors Claude Code, Cursor, Copilot.</p></li><li><p>&#128273; <strong><a href="https://www.securityweek.com/opal-security-raises-23-million-for-ai-native-identity-governance/">Opal raises $23M for AI-native identity</a></strong> &#8212; Governs access for humans, service accounts, and agents; five senior hires alongside.</p></li></ul><p><strong>Plus:</strong> Kramer and Kurtz pile into the same Series A, AI-native identity keeps pulling checks, and an agentic vuln remediation continues its streak.</p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>Your Agents Just Got Interactive</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cx3_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cx3_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif 424w, https://substackcdn.com/image/fetch/$s_!Cx3_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif 848w, https://substackcdn.com/image/fetch/$s_!Cx3_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif 1272w, https://substackcdn.com/image/fetch/$s_!Cx3_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cx3_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif" width="1000" height="563" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:563,&quot;width&quot;:1000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:643127,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/201364099?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cx3_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif 424w, https://substackcdn.com/image/fetch/$s_!Cx3_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif 848w, https://substackcdn.com/image/fetch/$s_!Cx3_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif 1272w, https://substackcdn.com/image/fetch/$s_!Cx3_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37bea71c-bbb2-41e5-b227-c5123e94f74e_1000x563.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;">New from BlinkOps: <strong>interactive agents</strong>. Over a year ago we shipped the first natural language agent builder in security, where you set an agent's role, guardrails on how it reasons, limits on what it can do, plus its abilities and knowledge. Now those same agents are interactive. </p><p style="text-align: center;">Open a standalone chat and put one to work, ask questions, run an investigation, act on your policy, no workflow required. The agentic layer for SecOps just got hands-on.</p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://go.blinkops.com/agentic-soc?utm_campaign=43443635-chnl-influencer-tcp-pulse&amp;utm_source=tcp-pulse&amp;utm_medium=newsletter&amp;utm_content=agentic-soc&quot;,&quot;text&quot;:&quot;See it in action&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://go.blinkops.com/agentic-soc?utm_campaign=43443635-chnl-influencer-tcp-pulse&amp;utm_source=tcp-pulse&amp;utm_medium=newsletter&amp;utm_content=agentic-soc"><span>See it in action</span></a></p></div><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><strong><a href="https://securityaffairs.com/193224/hacking/claude-opus-found-a-four-year-old-hole-in-zcashs-privacy-layer-nobody-knows-if-someone-already-used-it.html">Claude Opus 4.8 Found a Zcash Bug That Wiped $3B in Market Cap</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ymuJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ymuJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png 424w, https://substackcdn.com/image/fetch/$s_!ymuJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png 848w, https://substackcdn.com/image/fetch/$s_!ymuJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png 1272w, https://substackcdn.com/image/fetch/$s_!ymuJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ymuJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png" width="1456" height="743" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:743,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ymuJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png 424w, https://substackcdn.com/image/fetch/$s_!ymuJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png 848w, https://substackcdn.com/image/fetch/$s_!ymuJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png 1272w, https://substackcdn.com/image/fetch/$s_!ymuJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b1d0fc-97da-411e-bed3-a9fab1175db9_1858x948.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>More than <strong>$3 billion</strong> in Zcash market cap vanished after a researcher pointed <strong>Claude Opus 4.8</strong> at the Orchard shielded pool and found a critical flaw inside 24 hours. ZEC ran to a $624 peak on June 4 as the market read the emergency fix as bullish, then cratered to the low $300s the next day, cutting the cap in half. Arthur Hayes dumped his entire position on the way down.</p><p>Taylor Hornby, hired by the Zcash team to hunt exactly this, used the model the day after Opus 4.8 shipped and surfaced a bug that had been live since Orchard launched in May 2022. A validation check that looked like it was enforcing the rules wasn&#8217;t, so an attacker could feed false inputs and double-spend inside the shielded pool while the zero-knowledge proof system signed off as legitimate &#129327;</p><p>The wild part is the because Orchard is a privacy pool, there is no cryptographic way to determine whether the bug was exploited at any point in those four years. The team&#8217;s assessment is that exploitation was unlikely, but they&#8217;re explicitly telling users not to rely on that, and are pursuing a network upgrade called &#8220;turnstile accounting&#8221; that forces every Orchard coin through a verifiable checkpoint to expose any counterfeit supply.</p><p>Between <a href="https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/">DPRK having stolen $7B+ in crypto</a> and security kerfuffles like this in privacy/security-oriented coins, I truly don&#8217;t see cryptocurrency picking steam back up. The trust is gone and then there&#8217;s the looming threat of</p><p><strong>Dig Deeper: </strong><a href="https://x.com/zooko/status/2062644925590900980">Shielded Labs disclosure thread</a> | <a href="https://finance.yahoo.com/markets/crypto/articles/morning-minute-massive-zcash-exploit-124904107.html">Yahoo Finance on the undetectability problem</a></p><div><hr></div><h4><a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Anthropic Brings Mythos to the Masses With Claude Fable</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QH_P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QH_P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp 424w, https://substackcdn.com/image/fetch/$s_!QH_P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp 848w, https://substackcdn.com/image/fetch/$s_!QH_P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp 1272w, https://substackcdn.com/image/fetch/$s_!QH_P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QH_P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QH_P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp 424w, https://substackcdn.com/image/fetch/$s_!QH_P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp 848w, https://substackcdn.com/image/fetch/$s_!QH_P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp 1272w, https://substackcdn.com/image/fetch/$s_!QH_P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1d84a35-3e0f-423e-92fe-8ffd547451c7_3840x2160.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Anthropic</strong> shipped <strong>Claude Fable 5</strong>, the first public model in the <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Mythos</a> family, the one they sat on in April because it was &#8220;too good at finding bugs&#8221;. The whole release hinges on a safeguard layer, so that&#8217;s where the attention belongs. Also uses 2x the tokens as Opus 4.8 so use carefully.</p><p>Fable 5 runs separate AI classifiers in front of the model. Trip one on cybersecurity, biology and chemistry, or distillation and the request gets handed to Claude Opus 4.8 instead. The cyber net is widest, covering the full agentic kill chain (recon, lateral movement, exploit-gen), and Anthropic says it stops Fable from making any progress on offensive tasks. Over 95% of sessions never hit a fallback; bio and chem are tuned hardest and mostly punt to Opus for now.</p><p>We just watched a public Opus model find a four-year-old Zcash flaw in 24 hours. The capability is proven. The guardrail is two months old and a state-level team already found a seam. Bet accordingly.</p><p><strong>Dig Deeper: </strong><a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Anthropic&#8217;s announcement</a> | <a href="https://techcrunch.com/2026/06/09/anthropic-released-claude-fable-5-its-most-powerful-model-publicly-days-after-warning-ai-is-getting-too-dangerous/">TechCrunch</a></p><div><hr></div><h4><strong><a href="https://engineering.salesforce.com/how-salesforce-built-an-ai-security-agent-for-autonomous-threat-triage/">Salesforce Built an AI Agent That Triages Security Alerts at 95% Analyst Agreement</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d0Ei!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d0Ei!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!d0Ei!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!d0Ei!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!d0Ei!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d0Ei!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!d0Ei!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!d0Ei!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!d0Ei!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!d0Ei!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7820bda-1549-4072-a83b-f0aa0ce1277e_2816x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Salesforce dropped an autonomous triage agent, SATA (Security Alerts Triage Agent), into production across 80,000 employees and is claiming ~95% agreement with human analysts.  </p><p>Triage context is scattered across the case system, the log platform, and the runbook tooling stitched across it, and the logs are too fat to shovel into a model&#8217;s context without timing out. Salesforce had the agent call SOAR workflows to fetch only the slice each decision needs, ran multiple agents over the same case, and let a confidence score kick the inconclusive ones back to humans. </p><p>Salesforce is about as well-instrumented as a security org gets. $140B+ market cap, compute to burn, and an in-house agent platform in Agentforce their security teams already lean on hard, one of those agents has reportedly chewed through 44,000+ prompts and clawed back 3,000+ analyst hours. SATA is the autonomous-triage extension of a muscle they&#8217;ve built for two years.</p><p>Great write-up on what it takes to roll your own triage agent that is actually good. </p><div><hr></div><h4><strong><a href="https://youtube.com/playlist?list=PLCPCP1pNWD7O2zbp9sao2mNInjpvHWsnR&amp;si=Kmu0x-F3HBTw6ses">fwd:cloudsec North America 2026 Talks Are Live on YouTube</a></strong></h4><p>All 38 talks from <strong>fwd:cloudsec North America 2026</strong> are up on YouTube, free. This is the one cloud security con that isn&#8217;t a vendor pitch deck in disguise: independent, community-run, attack and defense research with the honest discussion of where security features actually fall short. This year&#8217;s theme leaned hard into agentic and neocloud risk. As a taste, Upwind&#8217;s Dan Gansel demoed C2 through an AWS data perimeter via Bedrock-AgentCore, abusing trusted AI services to slip past perimeter controls, plus the CloudTrail signals to catch it. Block out a weekend. This is the highest signal-to-noise content in the space right now.</p><p><strong>Fun fact:</strong> <a href="https://youtu.be/VjMj3KH1VtM?si=2TJpqAztGxChDFm2">I presented at fwd:cloud in 2022</a> on leveraging Azure Resource Graph for good and for evil &#128520;.. Easily in my top 3 of conferences. </p><div><hr></div><h4><strong><a href="https://en.globes.co.il/en/article-cyera-raises-600m-at-12b-valuation-1001545507">Cyera Raises $600M at $12B Valuation</a></strong></h4><p>Cyera closed a $600M round at a $12B valuation, led by <strong>Evolution Equity Partners</strong> with participation from Cyberstarts, Temasek, and all existing investors including Accel, Blackstone, and Coatue. </p><p>That&#8217;s $2.3B raised total, with the valuation doubling since January&#8217;s $400M round at $9B and quadrupling over two years. The pitch has evolved from DSPM into an AI trust layer: this year&#8217;s AI Guardian launch positions Cyera as the control plane for what AI agents can see and touch across enterprise data. </p><p>Five months between mega-rounds at a 33% valuation bump is less about needing capital and I&#8217;d imagine for more acquisitions, GTM, and capitalizing on good raising conditions. </p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><p><strong><a href="https://siliconangle.com/2026/06/09/datadog-launches-100-features-dash-push-autonomous-ai-ops/">Datadog Launches 100+ Features at DASH, Leans Into Agent Security</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T1TK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T1TK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg 424w, https://substackcdn.com/image/fetch/$s_!T1TK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg 848w, https://substackcdn.com/image/fetch/$s_!T1TK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!T1TK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T1TK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg" width="1400" height="788" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:788,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Claude Compliance dashboard overview showing unique actors and event volume over time to help spot anomalous activity spikes.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Claude Compliance dashboard overview showing unique actors and event volume over time to help spot anomalous activity spikes." title="Claude Compliance dashboard overview showing unique actors and event volume over time to help spot anomalous activity spikes." srcset="https://substackcdn.com/image/fetch/$s_!T1TK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg 424w, https://substackcdn.com/image/fetch/$s_!T1TK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg 848w, https://substackcdn.com/image/fetch/$s_!T1TK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!T1TK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F171e1447-7588-4804-8f95-e00480634392_1400x788.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Datadog unveiled more than 100 capabilities at <strong><a href="https://dash.datadoghq.com/">DASH</a></strong>, its annual conference and the company&#8217;s biggest product moment of the year. The headline is Bits AI expanding from root cause analysis into autonomous detection, investigation, and remediation under predefined guardrails.</p><p>The security drops:</p><ul><li><p><strong>AI Guard</strong>: blocks prompt injection and agent poisoning by pairing agent telemetry tracing with behavioral anomaly analysis, catching what single prompt-and-response checks miss</p></li><li><p><strong>Agent Console</strong>: centralized monitoring for AI agents and agentic dev tools, including Claude Code, Cursor, and GitHub Copilot</p></li><li><p><strong>Bits Detection and Agent Evals</strong>: always-on infrastructure scanning plus debugging and fix generation for AI agents</p></li></ul><p>Datadog is my former employer so it&#8217;s super good to see them keep pounding the momentum. The observability data was always the moat, and pointing it at agent security is the right move.</p><div><hr></div><p><strong>More AI Security News</strong> </p><ul><li><p><a href="https://siliconangle.com/2026/06/09/zscaler-launches-ai-broker-endpoint-ai-security-ai-agents/">Zscaler launches AI Broker and Endpoint AI Security for agents</a></p></li><li><p><a href="https://siliconangle.com/2026/06/08/ai-agent-security-snowflakesummit/">Snowflake and 1Password tackle the growing challenge of securing AI agents at scale</a></p></li><li><p><a href="https://www.infosecurity-magazine.com/news/chatgpt-lockdown-mode-active/">OpenAI Unveils ChatGPT Account Security Controls</a></p></li></ul><div><hr></div><h2><strong>Cloud Security</strong></h2><p><strong><a href="https://www.calcalistech.com/ctechnews/article/rjg0xcubmg">Aryon Security Raises $25M Series A</a></strong></p><p><strong><a href="https://www.aryon.security/">Aryon</a></strong> raised a $25M Series A led by <strong>Brightmind Partners</strong> and Shlomo Kramer&#8217;s Skinos Ventures, with Datadog Ventures and CrowdStrike CEO George Kurtz participating; total funding hits $38M since late 2024. </p><p>The founders came out of Matzov, the IDF&#8217;s cyber defense unit, and built the company on lessons from securing Project Nimbus. Kramer and Kurtz on the same cap table is a <em>strong</em> signal for a 44-person company.</p><div><hr></div><h2><strong>Endpoint Management </strong></h2><p><strong><a href="https://siliconangle.com/2026/06/09/ninjaone-raises-400m-endpoint-management-platform/">NinjaOne Secures $400M+ in Secondary Funding</a></strong></p><p><strong>NinjaOne</strong> raised over $400M in secondary funding, the second extension of its 2024 Series C, with CapitalG, Sequoia, and ICONIQ participating. The company says it crossed $500M ARR in 2025, turned profitable last quarter, and self-reports nearly <strong>40,000</strong> customer organizations. President Chris Matarese was blunt that the raise wasn&#8217;t about capital: &#8220;we used this round as an opportunity to pick the best possible partners.&#8221; A profitable endpoint management player taking secondaries at this size reads like pre-IPO positioning, not runway</p><h2><strong>Identity Security </strong></h2><p><strong><a href="https://www.securityweek.com/opal-security-raises-23-million-for-ai-native-identity-governance/">Opal Security Raises $23 Million for AI-Native Identity Governance</a></strong></p><p><strong><a href="https://www.opal.dev/">Opal Security</a></strong> raised $23 million led by Greylock and Battery Ventures, bringing total funding to $59 million. The company governs access for employees, service accounts, and AI agents: just-in-time access by default, risk-based revocation, policy-as-code enforced across cloud, SaaS, and on-prem. </p><p>Opal also announced five senior hires in one shot, including a new CPO and CTO. A leadership overhaul of that size alongside fresh capital reads like a relaunch around agent identity, the lane every IGA vendor is now racing toward.</p><div><hr></div><p><strong>More Identity Security News</strong> </p><ul><li><p><a href="https://siliconangle.com/2026/06/04/offroad-launches-7m-automate-identity-security-ai-agents/">Offroad launches with $7M to automate identity security with AI agents</a></p></li><li><p><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-zscaler-bring-continuous-identity-security-to-zero-trust-access/">CrowdStrike and Zscaler Bring Continuous Identity to Zero Trust Access</a></p></li></ul><div><hr></div><h2><strong>Offensive Security </strong></h2><p><strong><a href="https://www.securityweek.com/a-security-raises-37-million-for-autonomous-offensive-security-platform/">A Security Raises $37 Million for Autonomous Offensive Security Platform</a></strong></p><p><strong><a href="https://a.security/">A Security</a></strong> left stealth with <strong>$37 million</strong> to fight AI-driven attackers with AI of its own. The platform runs offensive and defensive agents continuously, chains vulns into real cross-domain exploit paths, proves exploitability through scoped execution with audit trails, then remediates at the source. Founders Yossi Torati (ex-Sygnia), Omer Gull, and Yuval Itzchakov (both ex-Hunters) pulled in <strong>Lightspeed</strong>, <strong>Cyberstarts</strong>, and angel checks from Wiz CEO Assaf Rapaport and Cyera CEO Yotam Segev.</p><p>AI-assisted OffSec is a crowded, well-capitalized field. Armadin, Kevin Mandia&#8217;s new outfit, took $189.9M in March, the largest early-stage raise in cybersecurity history. XBOW has raised north of $270M at a $1B+ valuation. Horizon3.ai sits near $186M and already powers the NSA&#8217;s autonomous pentest program. MindFort, ADCL, and a dozen more pitch the same &#8220;AI red-teamer that never sleeps&#8221; line.</p><p>It&#8217;s a long road ahead for this domain and everyone competing in it.</p><div><hr></div><h2><strong>Vulnerability Management</strong></h2><p><strong><a href="https://www.securityweek.com/emphere-raises-2-1-million-for-ai-powered-vulnerability-remediation/">Emphere Raises $2.1 Million for AI-Powered Vulnerability Remediation</a></strong></p><p><strong><a href="https://www.emphere.com/">Emphere</a></strong> raised a $2.1 million pre-seed from <strong>AI2 Incubator</strong> and <strong>Outsiders Fund</strong> to automate vuln remediation. The platform maps the software dependency graph to determine what is actually exploitable, then executes, validates, and ships patches without breaking downstream builds. </p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[CRWD and PANW Earnings Report; Mythos Expands; and MSRC Threatens Researcher]]></title><description><![CDATA[Plus: Security funding is up, Bumblebee lands, Cyera eyes $12B, and Dragos moves deeper into xIoT.]]></description><link>https://www.cybersecuritypulse.net/p/crwd-and-panw-earnings-report-mythos</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/crwd-and-panw-earnings-report-mythos</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Thu, 04 Jun 2026 14:14:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!V0f9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer in big tech. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/crwd-and-panw-earnings-report-mythos?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/crwd-and-panw-earnings-report-mythos?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V0f9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V0f9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!V0f9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!V0f9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!V0f9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V0f9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3363013,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/200002086?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V0f9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!V0f9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!V0f9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!V0f9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8462744d-43ef-4999-87ba-2d82a1f18f59_1800x1300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>The 2026 AI in Enterprise Security Survey</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SeNi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SeNi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!SeNi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!SeNi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!SeNi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SeNi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png" width="1200" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b91683da-e49d-464e-aece-20a04a2b759c_1200x628.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SeNi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!SeNi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!SeNi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!SeNi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91683da-e49d-464e-aece-20a04a2b759c_1200x628.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>We built Surf AI to fix how enterprise security teams operate. Before we publish our take on where things stand in 2026, we want to hear from the people running those teams. <br><br>17 questions. Five minutes. One respondent wins a Peloton.</em></p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.surf.ai/2026-survey?utm_source=tcp&amp;utm_medium=newsletter&quot;,&quot;text&quot;:&quot;Take the survey&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.surf.ai/2026-survey?utm_source=tcp&amp;utm_medium=newsletter"><span>Take the survey</span></a></p></div><div><hr></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from!</p><p>Two of the biggest players in security reported earnings this past week and of course, AI was at the center. Truly impressive numbers and performance though. This past week has been one of the most newsworthy in recent months. However, before we dive in, I&#8217;ve been digging into the telemetry that agentic dev tools like Claude Code, Codex, and Cursor emit. </p><p>While I haven&#8217;t done much detection work in recent years, my brain is truly intrigued by what&#8217;s possible to detect with what these tools emit natively and thus, I&#8217;ve been shipping some of that research via <a href="https://www.monad.com/blog/detection-engineering-for-openai-codex-otel">the Monad blog which you can read here. </a></p><p><a href="https://www.monad.com/blog/detection-engineering-for-openai-codex-otel">The latest in the series</a> takes a look at what OpenAI Codex emits through OpenTelemetry. Logs, metrics, traces. All pretty rich with detection value. Below is a map of key fields emitted and what detection opportunities they unlock: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YY8x!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YY8x!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YY8x!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YY8x!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YY8x!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YY8x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg" width="800" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;graphical user interface, application&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="graphical user interface, application" title="graphical user interface, application" srcset="https://substackcdn.com/image/fetch/$s_!YY8x!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YY8x!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YY8x!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YY8x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5678b977-dbc6-411c-9b4e-e3f696fbe984_800x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now, onto the news! </p><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#129504; <strong><a href="https://siliconangle.com/2026/06/03/crowdstrike-shares-fall-billings-miss-overshadows-earnings-revenue-beat/">CrowdStrike and Palo Alto blowout the AI quarter</a></strong> &#8212; Both anchored strong quarters to frontier AI, but <a href="https://www.fool.com/earnings/call-transcripts/2026/06/02/panw-q3-2026-earnings-transcript/">Palo Alto&#8217;s faster growth and raised guidance</a> made the cleaner case.</p></li><li><p>&#129695; <strong><a href="https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation/">Microsoft&#8217;s disclosure problem gets messy</a></strong> &#8212; Windows zero-day PoCs turn into a broader fight over trust, researcher access, and coordinated disclosure.</p></li><li><p>&#129725; <strong><a href="https://www.darkreading.com/cyber-risk/anthropic-mythos-ai-eu-enisa">Anthropic expands Mythos access</a></strong> &#8212; ENISA nears Project Glasswing access as Anthropic expands Mythos to <a href="https://techcrunch.com/2026/06/02/anthropic-scales-claude-mythos-to-critical-infrastructure-in-15-countries/">150 orgs across 15+ countries</a>.</p></li><li><p>&#127942; <strong><a href="https://www.forbes.com/sites/truebridge/2026/05/27/the-2026-midas-brink-list-the-investors-behind-techs-next-wave-of-breakout-companies/">Security investors climb the Midas List</a></strong> &#8212; Wiz&#8217;s <strong>$32B exit</strong> lifts Cyberstarts, Sequoia, and Index near the top of Forbes&#8217; 2026 venture rankings.</p></li><li><p>&#128029; <strong><a href="https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee">Perplexity open sources Bumblebee</a></strong> &#8212; Read-only dev-machine scanner checks risky packages, extensions, AI configs, and local tool metadata.</p></li><li><p>&#128272; <strong><a href="https://techcrunch.com/2026/06/02/cyera-eyes-12b-valuation-at-80x-arr-multiple-despite-operating-losses/">Cyera nears $300M at $12B valuation</a></strong> &#8212; Data security keeps heating up as AI makes access, classification, and exposure harder to govern.</p></li><li><p>&#128231; <strong><a href="https://siliconangle.com/2026/05/27/doppel-launches-agentic-email-security-disrupt-phishing-campaigns-source/">Doppel launches agentic email security</a></strong> &#8212; Product traces phishing campaigns to attacker infrastructure and coordinates takedowns across domains, profiles, and kits.</p></li><li><p>&#128737;&#65039; <strong><a href="https://www.securityweek.com/dragos-acquires-xiot-security-firm-phosphorus/">Dragos acquires Phosphorus</a></strong> &#8212; Dragos adds xIoT discovery and remediation depth for OT and critical infrastructure environments.</p></li></ul><p><strong>Plus:</strong> ZeroDrift raises <strong>$10M</strong> for AI compliance controls; RevEng.AI raises <strong>$15M</strong> for binary analysis; and Lastwall raises <strong>$11.5M</strong> for quantum-resilient identity.</p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><a href="https://www.fool.com/earnings/call-transcripts/2026/06/02/panw-q3-2026-earnings-transcript/">CrowdStrike and Palo Alto both anchored their quarters to AI, Mythos, and faster remediation</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lgq2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lgq2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!lgq2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!lgq2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!lgq2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lgq2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1675538,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/200002086?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lgq2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!lgq2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!lgq2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!lgq2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F790ca0f3-1a31-4b86-8cbb-22044082d971_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The two biggest names in security reported quarterly performance a day apart, and both pretty much ran the exact same pitch: AI broke the threat model, and they&#8217;re the ones selling the fix.</p><p>CrowdStrike put up fiscal Q1 revenue of $1.39B, up 26%, ARR at $5.51B, and beat on earnings. Shares still dropped more than 9%, after climbing ~60% this year. Palo Alto Networks posted fiscal Q3 revenue of $3B, up 31%, NGS ARR of $8.13B, up 60% (28% if you strip out the CyberArk and Chronosphere buys), and its best hardware quarter in a decade. It raised guidance everywhere and the stock shrugged.</p><p>George Kurtz: &#8220;the worlds of cybersecurity and frontier AI collided: this was the Mythos moment.&#8221; Arora went further, claiming frontier models can weaponize a vuln in minutes, so the only thing that survives is a platform that gets smarter as it scales.</p><p>No surprise on performance or themes to me and probably not for you either, but somehow Wall St. always seems surprised by security outcomes &#175;\_(&#12484;)_/&#175;</p><p>Dig Deeper: <a href="https://siliconangle.com/2026/06/03/crowdstrike-shares-fall-billings-miss-overshadows-earnings-revenue-beat/">CrowdStrike Q1 FY27 (SiliconANGLE)</a> | <a href="https://www.fool.com/earnings/call-transcripts/2026/06/02/panw-q3-2026-earnings-transcript/">Palo Alto Q3 FY26 transcript (Motley Fool)</a></p><div><hr></div><h4><strong><a href="https://techcrunch.com/2026/05/29/microsoft-under-fire-for-threatening-security-researcher-with-criminal-investigation/">Microsoft&#8217;s disclosure problem is bigger than one researcher</a></strong></h4><p>Microsoft is catching heat after a messy public fight with the researcher known as Nightmare Eclipse / Chaotic Eclipse, who published exploit code for several Windows zero-days tied to products including Defender and BitLocker. Microsoft says the disclosures were not coordinated and put customers at risk. The researcher claims Microsoft mishandled prior reports, cut off access, and left them with no good path back through the front door.</p><p>The easy take is that Microsoft should not threaten researchers. True, but incomplete.</p><p>The harder issue is that coordinated disclosure only works when researchers believe the process is real, fair, and available to them. Once the vendor response becomes account bans, legal language, and public condemnation, the incentive model breaks. You may stop one disclosure, but you also teach the next researcher to stay quiet, go anonymous, or skip coordination entirely.</p><p>Microsoft is right that public PoCs for unpatched bugs can turn into a fire drill fast, especially when the affected products sit close to the security foundation of Windows. But in security, trust is part of the patch pipeline. If researchers don&#8217;t trust the intake path, vendors lose early warning. And customers lose the thing they actually need most: time.</p><div><hr></div><h4><a href="https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee">Perplexity open sources Bumblebee</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q2lg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q2lg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png 424w, https://substackcdn.com/image/fetch/$s_!Q2lg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png 848w, https://substackcdn.com/image/fetch/$s_!Q2lg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png 1272w, https://substackcdn.com/image/fetch/$s_!Q2lg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q2lg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png" width="1456" height="904" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:904,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Q2lg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png 424w, https://substackcdn.com/image/fetch/$s_!Q2lg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png 848w, https://substackcdn.com/image/fetch/$s_!Q2lg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png 1272w, https://substackcdn.com/image/fetch/$s_!Q2lg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F232146fc-5cb8-4b35-9ab9-96bd2b9ed9cb_1475x916.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Perplexity</strong> open-sourced Bumblebee, a read-only scanner for macOS and Linux developer machines that checks for risky packages and tool configs. The use case is simple: when a bad package or version shows up in an advisory, security teams can ask which laptops have it sitting on disk right now.</p><p>What it looks for:</p><ul><li><p>Risky packages and versions</p></li><li><p>Browser extensions</p></li><li><p>Editor extensions</p></li><li><p>AI tool configs</p></li><li><p>Other developer-tool metadata sitting on disk</p></li></ul><p>That sounds boring, which is usually where useful security tooling lives. Bumblebee does not execute package managers or read source files, which matters when malicious packages abuse install scripts and dev workflows. It is not an SBOM replacement or EDR killer. It is a sharper way to answer the messy middle question between &#8220;what shipped?&#8221; and &#8220;what is running?&#8221;</p><div><hr></div><h4><a href="https://www.darkreading.com/cyber-risk/anthropic-mythos-ai-eu-enisa">Anthropic expands Mythos access in Europe and critical infrastructure</a></h4><p><strong>ENISA</strong>, the European Union&#8217;s cybersecurity agency, is close to getting access to <strong>Anthropic&#8217;s</strong> Claude Mythos through Project Glasswing. That would make it the first European entity in the program, while Anthropic is also expanding Mythos access to roughly <strong>150 organizations across 15+ countries</strong>.</p><p>The rollout targets critical infrastructure operators across power, water, healthcare, communications, and hardware sectors.</p><p>Anthropic marketing continues to do the security thing well.</p><div><hr></div><h4><a href="https://www.forbes.com/lists/midas/">Security investors climb the Forbes Midas List</a></h4><p><strong>Forbes</strong> released its 2026 Midas List, with several security and infrastructure investors near the top. <strong>Gili Raanan</strong> of <strong>Cyberstarts</strong> ranked <strong>No. 4</strong>, <strong>Doug Leone</strong> of <strong>Sequoia Capital</strong> ranked <strong>No. 8</strong>, <strong>Shardul Shah</strong> of <strong>Index Ventures</strong> ranked <strong>No. 10</strong>, and <strong>Shaun Maguire</strong> of <strong>Sequoia Capital</strong> ranked <strong>No. 22</strong>. The common thread is Wiz, which was acquired for <strong>$32 billion</strong>.</p><p>Wiz created one of the cleanest and biggest venture outcomes in security, with Cyberstarts, Index, and Sequoia all tied to the cap table. Security is still producing elite venture outcomes when the company becomes a control point.</p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><p><strong><a href="https://techcrunch.com/2026/06/02/zerodrift-raises-10-million-to-protect-ai-models-from-themselves/">ZeroDrift raises $10M for AI compliance controls</a></strong></p><p><strong>ZeroDrift</strong> raised a <strong>$10 million</strong> seed round for an AI compliance layer that sits between models and end users, flagging and replacing responses that could create regulatory or policy problems. The company is starting with the least glamorous, most necessary slice of AI security: making sure model outputs do not casually create legal, compliance, or brand risk at runtime. Not everything in AI security needs to be jailbreak chess.</p><div><hr></div><p><strong>More AI Security News</strong> </p><ul><li><p><a href="https://www.securityweek.com/geordie-raises-30-million-for-ai-security-and-governance-platform/">Geordie Raises $30 Million for AI Security and Governance Platform</a></p></li><li><p><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-nvidia-bring-enterprise-grade-security-to-the-ai-factory/">CrowdStrike Brings Enterprise-Grade Security to the AI Factory with NVIDIA Vera BlueField-4 STX</a></p></li></ul><div><hr></div><h2><strong>Application Security </strong></h2><p><strong><a href="https://siliconangle.com/2026/05/27/reveng-ai-raises-15m-reverse-engineer-software-binaries-hunt-malicious-threats/">RevEng.AI raises $15M for binary analysis</a></strong></p><p><strong>RevEng.AI</strong> raised <strong>$15 million</strong> in Series A funding led by the <strong>NATO Innovation Fund</strong> to expand its binary analysis platform for reverse engineering software and spotting malicious functionality inside compiled code.</p><p>Teams still need to understand what is actually inside the binaries they ship, buy, deploy, and execute, especially as AI-generated code makes the &#8220;who wrote this and what does it do?&#8221; question messier.</p><div><hr></div><h2><strong>Data Security</strong></h2><p><strong><a href="https://techcrunch.com/2026/06/02/cyera-eyes-12b-valuation-at-80x-arr-multiple-despite-operating-losses/">Cyera nears $300M round at a $12B valuation, 80x ARR</a></strong></p><p><strong>Cyera</strong> is closing at least $300M led by <strong>Evolution Equity Partners</strong> at a $12B valuation, per TechCrunch. That&#8217;s around 80x its reported $150M+ ARR. The round lands five months after a $400M Series F at a $9B valuation. A second monster round five months after the last one says investors expect this to compound fast, and they&#8217;re probably right given how critical data security is to securing AI.</p><div><hr></div><h2><strong>Email Security</strong></h2><p><strong><a href="https://siliconangle.com/2026/05/27/doppel-launches-agentic-email-security-disrupt-phishing-campaigns-source/">Doppel launches agentic email security</a></strong></p><p><strong>Doppel</strong> launched an agentic email security product designed to disrupt phishing campaigns. The system traces phishing emails back to attacker infrastructure, then coordinates takedowns across spoofed domains, lookalike profiles, impersonation kits, and other campaign surfaces.</p><div><hr></div><h2><strong>Exposure Management</strong></h2><p><strong><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-nvidia-collaborate-to-scale-ai-native-agents-across-falcon-exposure-management/">CrowdStrike and NVIDIA scale exposure agents</a></strong></p><p><strong>CrowdStrike</strong> and <strong>NVIDIA</strong> are working to scale AI-native agents inside Falcon Exposure Management using NVIDIA Nemotron 3 Super models, NeMo Data Designer, and the NeMo Framework. </p><p>The goal is faster vuln remediation by letting specialized agents reason across exposure data, exploitability, asset context, and remediation paths. It is a vendor blog, so season accordingly, but the direction makes sense: exposure management is becoming less about ranking CVEs and more about turning messy context into decisions teams can actually act on.</p><div><hr></div><h2><strong>Identity Security</strong></h2><p><strong><a href="https://www.securityweek.com/lastwall-raises-11-5-million-for-quantum-resilient-identity-platform/">Lastwall raises $11.5M</a></strong></p><p>Lastwall raised an $11.5 million Series A extension led by BDC Capital&#8217;s StrongNorth Fund to expand its quantum-resilient identity platform across North America. The company sells into defense and government use cases, combining passwordless authentication, PKI, zero trust, risk-based login signals, and post-quantum TLS protection.</p><div><hr></div><h2><strong>IoT/OT Security</strong></h2><p><strong><a href="https://www.securityweek.com/dragos-acquires-xiot-security-firm-phosphorus/">Dragos acquires Phosphorus</a></strong></p><p>Dragos acquired Phosphorus, an xIoT security company focused on discovering, assessing, and remediating risks across connected devices. The move gives Dragos broader visibility into device-heavy OT and critical infrastructure environments, with integrated device intelligence coming first and automated remediation workflows expected later. Financial terms were not disclosed.</p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[ZScaler earnings cause security stocks to tumble, Wiz puts data to supply chain risk, and the Megalodon strikes]]></title><description><![CDATA[Another week of supply chain pressure, AI data security bets, and one reminder that cyber&#8217;s public market rally leaves little room for deceleration.]]></description><link>https://www.cybersecuritypulse.net/p/zscaler-earnings-cause-security-stocks</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/zscaler-earnings-cause-security-stocks</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 27 May 2026 13:22:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!frI4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer in big tech. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/zscaler-earnings-cause-security-stocks?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/zscaler-earnings-cause-security-stocks?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!frI4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!frI4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png 424w, https://substackcdn.com/image/fetch/$s_!frI4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png 848w, https://substackcdn.com/image/fetch/$s_!frI4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png 1272w, https://substackcdn.com/image/fetch/$s_!frI4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!frI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png" width="1456" height="1053" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1053,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5434954,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/199451174?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!frI4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png 424w, https://substackcdn.com/image/fetch/$s_!frI4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png 848w, https://substackcdn.com/image/fetch/$s_!frI4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png 1272w, https://substackcdn.com/image/fetch/$s_!frI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35b0b4e8-69d0-4b35-a2eb-64c1f4461303_2126x1538.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from! </p><p>I&#8217;m in Boston this week for their first ever <a href="https://www.tech-week.com/calendar/boston?day=2026-05-27">TechWeek</a> which surprisingly has quite a few security events. Last night, I hosted my first Darwin &amp; Friends Dinner Club and it was a fun time with great operators. Shoutout to <a href="https://www.monad.com/">Monad</a> and <a href="https://fablesecurity.com/">Fable Security</a> for sponsoring it! One of our attendees even pulled up in their yacht so that was cool &#175;\_(&#12484;)_/&#175; (jk)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rD9R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rD9R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rD9R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rD9R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rD9R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rD9R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg" width="4284" height="2600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2600,&quot;width&quot;:4284,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2126378,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/199451174?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9269fb7-df75-430b-bee8-0e20dd3236e9_5712x4284.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rD9R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rD9R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rD9R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rD9R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13a4ef60-8878-476b-a2f4-e3d2509d1df4_4284x2600.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Tonight, I&#8217;ll be speaking on a panel with security leaders from Citizens Bank, DigitalOcean, Jiffy Labs and Scrut Automation, where we&#8217;ll cover how AI has changed security. Hosted at an art gallery with cocktail reception before &#127912;. Come hang out if you&#8217;re in the area! You can <a href="https://partiful.com/e/rYlEZvkSLhbLsbhUhJ14">RSVP here.</a> </p><p>Now, let&#8217;s get into the news! </p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>AI Agents Are Multiplying Faster Than Security Teams Can Track</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0FnX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0FnX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png 424w, https://substackcdn.com/image/fetch/$s_!0FnX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png 848w, https://substackcdn.com/image/fetch/$s_!0FnX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png 1272w, https://substackcdn.com/image/fetch/$s_!0FnX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0FnX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png" width="298" height="109.10382513661202" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:134,&quot;width&quot;:366,&quot;resizeWidth&quot;:298,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0FnX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png 424w, https://substackcdn.com/image/fetch/$s_!0FnX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png 848w, https://substackcdn.com/image/fetch/$s_!0FnX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png 1272w, https://substackcdn.com/image/fetch/$s_!0FnX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06fc131a-c47e-46aa-8798-e76151f1e660_366x134.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;">AI agents are spreading across SaaS environments through ChatGPT integrations, Salesforce Agentforce, n8n workflows, custom tools, and embedded assistants. They act autonomously, keep persistent permissions, and connect to sensitive systems that security teams often can&#8217;t fully see.</p><p style="text-align: center;">Reco helps security teams discover AI agents, map their connections, and reduce the risk of data exposure before it happens.</p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.reco.ai/monthly-product-demo-recording-taking-control-of-ai-agents&quot;,&quot;text&quot;:&quot;Watch the Full Demo&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.reco.ai/monthly-product-demo-recording-taking-control-of-ai-agents"><span>Watch the Full Demo</span></a></p></div><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#128051; <strong><a href="https://www.wiz.io/blog/sdlc-security-report-2026-key-takeaways">Wiz&#8217;s 2026 report puts numbers on supply chain risk</a></strong>&#8212; Code, dev tools, automation, and AI are turning software delivery into one big trust problem. Shai-Hulud, TeamPCP, Megalodon, and poisoned packages make the timing feel very real.</p></li><li><p>&#128201; <strong><a href="https://www.globenewswire.com/news-release/2026/05/26/3301454/0/en/zscaler-announces-strong-third-quarter-fiscal-2026-results.html?utm_source=chatgpt.com">Zscaler gets punished after a strong quarter</a></strong> &#8212; Zscaler posted <strong>$850.5M in Q3 revenue</strong>, up <strong>25% YoY</strong>, and <strong>$3.525B in ARR</strong>, also up <strong>25% YoY</strong>, but the stock sold off after softer forward guidance. </p></li><li><p>&#129416; <strong><a href="https://www.securityweek.com/over-5500-github-repositories-infected-in-megalodon-supply-chain-attack/?utm_source=chatgpt.com">Megalodon hits GitHub</a></strong> &#8212; 5,500+ repos were infected via fake automated commits that injected GitHub Actions workflows to steal CI secrets, keys, tokens, and credentials.</p></li><li><p>&#128268; <strong><a href="https://www.securityweek.com/socket-raises-60-million-at-1-billion-valuation/?utm_source=chatgpt.com">Socket raises $60M</a></strong> &#8212; Supply chain security startup hits a $1B valuation as the category expands from bad packages to IDE extensions, browser extensions, AI tools, and MCP servers.</p></li><li><p>&#129302; <strong><a href="https://www.zscaler.com/press/ai-announcement?utm_source=chatgpt.com">Zscaler buys Symmetry</a></strong> &#8212; Zscaler adds data discovery and AI agent governance in an acquisition with <strong>undisclosed terms</strong>.</p></li><li><p>&#129502; <strong><a href="https://www.timesofisrael.com/six-month-old-israeli-startup-is-bought-by-cyber-unicorn-cyera-for-about-50-million/?utm_source=chatgpt.com">Cyera buys Genie Security</a></strong> &#8212; Cyera acquires a six-month-old Israeli startup for <strong>about $50M</strong>, adding endpoint-focused DLP for sensitive data leakage across employee devices, AI tools, and autonomous agents.</p></li><li><p>&#129489;&#8205;&#128658; <strong><a href="https://siliconangle.com/2026/05/26/7ai-launches-plaid-elite-fully-managed-agentic-security-operations-service/?utm_source=chatgpt.com">7AI launches agentic MDR</a></strong> &#8212; Autonomous investigations with 7AI security engineers, pushing MDR from analyst assist toward agent-led SecOps.</p></li><li><p>&#128272; <strong><a href="https://aws.amazon.com/blogs/security/automating-identity-lifecycle-and-security-with-aws-directory-service-apis/?utm_source=chatgpt.com">AWS automates AD response</a></strong> &#8212; New Directory Service APIs let teams automate Microsoft AD user and group actions, including GuardDuty-to-Step Functions workflows that disable risky users.</p></li></ul><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><strong><a href="https://www.wiz.io/blog/sdlc-security-report-2026-key-takeaways">Wiz's 2026 report puts numbers on supply chain risk</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ISx4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ISx4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png 424w, https://substackcdn.com/image/fetch/$s_!ISx4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png 848w, https://substackcdn.com/image/fetch/$s_!ISx4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png 1272w, https://substackcdn.com/image/fetch/$s_!ISx4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ISx4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png" width="1456" height="1219" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1219,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ISx4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png 424w, https://substackcdn.com/image/fetch/$s_!ISx4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png 848w, https://substackcdn.com/image/fetch/$s_!ISx4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png 1272w, https://substackcdn.com/image/fetch/$s_!ISx4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15cc7f5b-8c11-4357-a5bb-3e965b743009_2901x2429.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The software supply chain security space has been on fire this year, and not in a good way. Wiz&#8217;s 2026 SDLC security report gives a clear look at why. Supply chain attacks keep showing up in the same places: dependencies, developer machines, build systems, CI/CD, identity, and cloud credentials.</p><p>Shai-Hulud, Mini Shai-Hulud, TeamPCP, malicious npm packages, poisoned developer tooling, and stolen secrets all point in the same direction. The path from dev to prod is now one of the most useful routes for attackers, and teams are being forced to treat SDLC security as a core part of enterprise defense, not just an AppSec checklist.</p><p>That&#8217;s why the Wiz report hit. SDLC security is not just about finding vulnerable code anymore. It is about whether you can trust the packages, tools, workflows, agents, credentials, and people involved in shipping software. The question is no longer just &#8220;is this code vulnerable?&#8221; It is &#8220;can we trust how this code got here?&#8221; If you&#8217;ve been dealing with SDLC security in any capacity, this report is a must read as it puts empirical data to what we&#8217;ve all been experiencing. </p><div><hr></div><h4><strong><a href="https://www.fool.com/earnings/call-transcripts/2026/05/26/zscaler-zs-q3-2026-earnings-call-transcript/?utm_source=chatgpt.com">Zscaler gets punished after a strong quarter</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HE8z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HE8z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png 424w, https://substackcdn.com/image/fetch/$s_!HE8z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png 848w, https://substackcdn.com/image/fetch/$s_!HE8z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png 1272w, https://substackcdn.com/image/fetch/$s_!HE8z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HE8z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png" width="1456" height="995" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:995,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:186230,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/199451174?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HE8z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png 424w, https://substackcdn.com/image/fetch/$s_!HE8z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png 848w, https://substackcdn.com/image/fetch/$s_!HE8z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png 1272w, https://substackcdn.com/image/fetch/$s_!HE8z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36ad2779-d54f-43c6-8f29-2b8c91943112_1478x1010.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Zscaler reported a strong Q3, with <strong>revenue up 25% YoY to $850.5M</strong>, <strong>ARR up 25% YoY to $3.525B</strong>, and <strong>$100M+ in AI Protect bookings over the last 12 months</strong>, but the stock still sold off after softer forward guidance. The reaction says more about the current cyber tape than the quarter itself. Security stocks have been ripping, with names like CrowdStrike and Palo Alto trading near highs, so investors are punishing anything that looks like deceleration. The market moves fast. Just a bit ago, the SaaSpocalypse triggered by Anthropic had claimed a few &#8220;casualties,&#8221; and now we&#8217;re back near ATHs. Fun times.</p><p>This isn&#8217;t news but the earnings call transcript highlighted that security leaders are worried about AI-driven exposure: which users, apps, agents, and workloads can reach sensitive systems, under which identity, with what logging, and with what blast radius. Winning AI security products will need to show the graph: data, identity, apps, agents, and controls in one place.</p><div><hr></div><h4><strong><a href="https://www.securityweek.com/over-5500-github-repositories-infected-in-megalodon-supply-chain-attack/">Megalodon hits 5,500+ GitHub repos</a></strong></h4><p>Megalodon is the week&#8217;s clearest proof point for why SDLC security is top of mind. More than 5,500 GitHub repositories were reportedly infected through fake automated commits that injected malicious GitHub Actions workflows. The payloads were built to steal credentials, CI secrets, keys, tokens, and other sensitive data from developer and build environments.</p><p>The important part is that the attackers went after the pipeline. That is the same pattern behind Shai-Hulud, TeamPCP, poisoned packages, and malicious dev tooling. If attackers can compromise what builds the software, they can get access before anything ever reaches runtime.</p><div><hr></div><h4><strong><a href="https://www.securityweek.com/socket-raises-60-million-at-1-billion-valuation/">Socket raises $60M as supply chain security heats up</a></strong></h4><p>Socket raised $60M at a $1B valuation, and the timing makes sense. The company started around open source dependency risk, but the category is getting bigger fast. Malicious packages, hijacked maintainer accounts, compromised release pipelines, IDE extensions, browser extensions, AI coding tools, and MCP servers are all becoming part of the same problem.</p><p>While Socket has had a great product and customer base for a while, the raise feels directly tied to what we are seeing in the wild. Attackers are moving earlier in the build process, and companies are realizing that runtime defense is too late if poisoned code already made it into the product. </p><div><hr></div><h4><strong><a href="https://aws.amazon.com/blogs/security/automating-identity-lifecycle-and-security-with-aws-directory-service-apis/">AWS adds more automation for Managed Microsoft AD</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dels!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dels!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png 424w, https://substackcdn.com/image/fetch/$s_!dels!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png 848w, https://substackcdn.com/image/fetch/$s_!dels!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png 1272w, https://substackcdn.com/image/fetch/$s_!dels!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dels!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png" width="1456" height="640" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Figure 2: Diagram showing the workflow of what happens when potentially damaging activity is detected&quot;,&quot;title&quot;:&quot;Figure 2: Diagram showing the workflow of what happens when potentially damaging activity is detected&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Figure 2: Diagram showing the workflow of what happens when potentially damaging activity is detected" title="Figure 2: Diagram showing the workflow of what happens when potentially damaging activity is detected" srcset="https://substackcdn.com/image/fetch/$s_!dels!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png 424w, https://substackcdn.com/image/fetch/$s_!dels!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png 848w, https://substackcdn.com/image/fetch/$s_!dels!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png 1272w, https://substackcdn.com/image/fetch/$s_!dels!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfba8b57-1b65-4d52-9917-bcc5e5a890e0_2394x1053.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AWS published a walkthrough for using its newer Directory Service Data APIs to automate identity lifecycle work in AWS Managed Microsoft AD. The APIs support user and group operations like listing users, retrieving details, disabling and enabling accounts, resetting passwords, and managing group membership through the AWS CLI, APIs, and console.</p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><p><strong><a href="https://www.scworld.com/brief/zscaler-acquires-symmetry-systems-to-enhance-ai-security?utm_source=chatgpt.com">Zscaler buys Symmetry Systems for AI data security</a></strong></p><p>Zscaler is acquiring Symmetry Systems, a data security startup focused on finding and monitoring data across cloud, on-prem, and air-gapped environments. The AI angle is the useful part: Symmetry can scan training datasets and monitor data ingested by AI agents, which gives Zscaler a stronger story around what agents can access, touch, and potentially leak.</p><p>This fits the broader AI security acquisition wave. The market is moving past &#8220;secure the chatbot&#8221; and into the harder problem of governing the data, identities, applications, and agents underneath it. Zscaler&#8217;s bet is that AI security will need an access graph that shows how identities, apps, agents, and data sources connect across the enterprise.</p><div><hr></div><h2><strong>Data Security</strong></h2><p><strong><a href="https://www.timesofisrael.com/six-month-old-israeli-startup-is-bought-by-cyber-unicorn-cyera-for-about-50-million/?utm_source=chatgpt.com">Cyera buys six-month-old Genie Security</a></strong></p><p>Cyera acquired <a href="https://geniesecurity.io/">Genie Security</a>, a six-month-old Israeli startup, in a deal reportedly worth about $50M. Genie was building endpoint-focused DLP technology for detecting sensitive data leakage from employee devices, including leakage caused by generative AI tools and autonomous agents. </p><p>The fit is pretty obvious. Cyera already owns the data security layer, and Genie helps extend that control closer to laptops, phones, servers, and the messy places where employees and AI tools actually touch sensitive data.</p><div><hr></div><h2><strong>Offensive Security</strong></h2><p><strong><a href="https://www.helpnetsecurity.com/2026/05/21/terra-security-network-exploitation-validation/?utm_source=chatgpt.com">Terra adds continuous network exploitation validation</a></strong></p><p>Terra added public preview support for continuous exploitation validation across network infrastructure, expanding its platform beyond web apps and AI systems. The pitch is agentic offensive security with human oversight across the full attack surface: web apps, AI, and network environments. Findings are verified for real exploitability, prioritized by business impact, and shown in one connected view so teams can see chained paths instead of juggling separate pentest, red team, and vulnerability reports.</p><div><hr></div><p><strong>More OffSec News</strong></p><ul><li><p><strong><a href="https://siliconangle.com/2026/05/21/bugcrowd-launches-reinforcement-learning-environments-train-ai-real-software-vulnerabilities/?utm_source=chatgpt.com">Bugcrowd launches RL environments for AI vuln hunting</a></strong></p></li></ul><div><hr></div><h2><strong>Security Operations</strong></h2><p><strong><a href="https://siliconangle.com/2026/05/26/7ai-launches-plaid-elite-fully-managed-agentic-security-operations-service/?utm_source=chatgpt.com">7AI launches agentic MDR</a></strong></p><p>7AI launched PLAID ELITE, a fully managed agentic security operations service that pairs autonomous investigations with human oversight from 7AI security engineers. The service is positioned as AI-native MDR: agents handle alert ingestion, enrichment, triage, investigation, and response, while humans stay in the loop for review, escalation, and customer-specific context.</p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[GitHub Breach; Faster Old Problems; and Mythos Helps Bypass Apple M5 Chip Security]]></title><description><![CDATA[Things are getting weird: GitHub, TeamPCP, and Mythos all pointing at the same problem.]]></description><link>https://www.cybersecuritypulse.net/p/github-breach-faster-old-problems</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/github-breach-faster-old-problems</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 20 May 2026 13:33:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QiVF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer in big tech. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/github-breach-faster-old-problems?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/github-breach-faster-old-problems?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QiVF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QiVF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png 424w, https://substackcdn.com/image/fetch/$s_!QiVF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png 848w, https://substackcdn.com/image/fetch/$s_!QiVF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png 1272w, https://substackcdn.com/image/fetch/$s_!QiVF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QiVF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png" width="1330" height="959" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47422e9a-3592-4041-a959-285dd821c080_1330x959.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:959,&quot;width&quot;:1330,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2388738,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/198548594?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QiVF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png 424w, https://substackcdn.com/image/fetch/$s_!QiVF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png 848w, https://substackcdn.com/image/fetch/$s_!QiVF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png 1272w, https://substackcdn.com/image/fetch/$s_!QiVF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47422e9a-3592-4041-a959-285dd821c080_1330x959.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from! </p><p>Ever since TeamPCP started popping off in March and the Mythos news broke, it feels like the security space has just been on overdrive. So many vulns, supply chain attacks, and breaches. Definitely a sign of what&#8217;s to come. HugOps to the defenders, product builders and security leaders securing our critical infrastructure and the companies we all rely on. </p><p>That said, I took last week off from TCP weekly as things continue to heat up at <a href="https://www.monad.com/blog/monad-partners-with-databricks-to-bring-285-security-sources-to-the-lakehouse">Monad</a>, but I did ship <a href="https://www.cybersecuritypulse.net/p/how-one-ciso-got-4-budget-offers">a recap on the AI SOC Nasdaq event</a> I attended earlier this month. Lots of gold around SecOps, board-level vibe, and how CISOs are using Mythos news to achieve better outcomes. </p><p>Also, I&#8217;ll be in Boston next week for Tech Week and am hosting a small intimate dinner on Tuesday for security leaders and practitioners. You can <a href="https://luma.com/jnvbole1">register here</a>. I&#8217;m also speaking on a panel with security leader friends. <a href="https://www.linkedin.com/posts/darwin-salazar_boston-speaking-on-this-panel-with-folks-activity-7460720518552477696-FB1x?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAB-Qy6IBLQLTsD9lC_8dkpPiQtNrO5eQqEo">More details here</a>. If you&#8217;re in or around town, definitely come hang out for some friendly banter, great food and good vibes. DM me if you have any questions! </p><p>Lastly, our friends at <a href="https://www.surf.ai/2026-survey?utm_source=tcp&amp;utm_medium=newsletter">Surf</a> are running a short survey to help bring more insight into what&#8217;s actually happening across security teams, AI, and SOC workflows in 2026. <strong><a href="https://www.surf.ai/2026-survey?utm_source=tcp&amp;utm_medium=newsletter">Take the survey here.</a></strong></p><p>Now onto this week&#8217;s news! </p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;">The Phishing Threat Evolved. Your Simulations Should Too.</h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ae8U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ae8U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png 424w, https://substackcdn.com/image/fetch/$s_!Ae8U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png 848w, https://substackcdn.com/image/fetch/$s_!Ae8U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png 1272w, https://substackcdn.com/image/fetch/$s_!Ae8U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ae8U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png" width="494" height="54.069651741293534" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:44,&quot;width&quot;:402,&quot;resizeWidth&quot;:494,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ae8U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png 424w, https://substackcdn.com/image/fetch/$s_!Ae8U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png 848w, https://substackcdn.com/image/fetch/$s_!Ae8U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png 1272w, https://substackcdn.com/image/fetch/$s_!Ae8U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9b5a92-04a5-4547-93ff-98f1ef8f0eb1_402x44.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;">Most phishing simulations are still templated emails. Adaptive runs hyperrealistic, multi-channel simulations: AI voice clones, OSINT-based spear phishing, and attacks across email, SMS, and phone. Fully automated, no manual lift. </p><p style="text-align: center;">The result: measurable reductions in click rates and a workforce prepared for what's actually hitting them today. Trusted by security teams at PayPal, Ramp, Bose, and more.</p><p style="text-align: center;"></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.adaptivesecurity.com/lp/nb/phishing-simulation?utm_source=cybersecuritypulse&amp;utm_medium=newsletter&amp;utm_campaign=tcp-phishing-may26&quot;,&quot;text&quot;:&quot;Tour the platform&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.adaptivesecurity.com/lp/nb/phishing-simulation?utm_source=cybersecuritypulse&amp;utm_medium=newsletter&amp;utm_campaign=tcp-phishing-may26"><span>Tour the platform</span></a></p></div><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#128025; <strong><a href="https://www.theregister.com/devops/2026/05/20/github-says-internal-repos-exfiltrated-after-poisoned-vs-code-extension-attack/5243206?utm_source=chatgpt.com">GitHub&#8217;s rough quarter</a></strong> &#8212; Internal repos stolen via poisoned VS Code extension after <strong>20</strong> degraded-service incidents in three months.</p></li><li><p>&#128213; <strong><a href="https://www.verizon.com/business/resources/reports/dbir/?utm_source=chatgpt.com">DBIR 2026 lands</a></strong> &#8212; Verizon analyzed <strong>22,000+</strong> breaches; vuln exploitation is now the top initial access vector exceeding credential theft </p></li><li><p>&#9729;&#65039; <strong><a href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=chatgpt.com">Cloudflare tests Mythos</a></strong> &#8212; Anthropic&#8217;s model chained low-severity bugs into working exploits across <strong>50+</strong> repos.</p></li><li><p>&#128013; <strong><a href="https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack?utm_source=chatgpt.com">TeamPCP hits DurableTask</a></strong> &#8212; Malicious <code>durabletask</code> PyPI versions stole cloud, Kubernetes, Vault, and password manager secrets.</p></li><li><p>&#127822; <strong><a href="https://blog.calif.io/p/first-public-kernel-memory-corruption?utm_source=chatgpt.com">Mythos bypasses Mac defenses</a></strong> &#8212; Calif used Mythos to help build a macOS kernel LPE chain on M5 in <strong>five days</strong>.</p></li><li><p>&#129302; <strong><a href="https://www.exaforce.com/blogs/series-b?utm_source=chatgpt.com">Exaforce raises $125M</a></strong> &#8212; Series B brings total funding to <strong>$200M</strong> for its AI-native SOC platform</p></li><li><p>&#127749; <strong><a href="https://openai.com/daybreak/?utm_source=chatgpt.com">OpenAI ships Daybreak</a></strong> &#8212; New vuln defense initiative bundles GPT-5.5-Cyber, Codex Security, and yet another confusing name.</p></li><li><p>&#127754; <strong><a href="https://techcrunch.com/2026/05/19/from-teen-hacker-to-iron-dome-researcher-this-founder-raised-28m-to-fight-ai-phishing/?utm_source=chatgpt.com">Ocean raises $28M</a></strong> &#8212; Lightspeed led the round for agentic email security startup</p></li><li><p>&#129504; <strong><a href="https://siliconangle.com/2026/05/19/torq-acquires-ai-security-startup-jit-add-context-graphs-soc-platform/">Torq buys Jit</a></strong> &#8212; Torq adds context graphs across code, identity, privileges, data sensitivity, and runtime behavior.</p></li><li><p>&#127760; <strong><a href="https://www.securityweek.com/akamai-to-acquire-ai-and-browser-security-firm-layerx-for-205-million/?utm_source=chatgpt.com">Akamai buys LayerX</a></strong> &#8212; $205M deal gives Akamai more AI and browser security controls</p></li></ul><p><strong>Plus:</strong> Boost Security raises $4M and buys SecureIQx + Korbit.ai; Tanium and ServiceNow automate endpoint patching.</p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><a href="https://www.theregister.com/devops/2026/05/20/github-says-internal-repos-exfiltrated-after-poisoned-vs-code-extension-attack/5243206?utm_source=chatgpt.com">GitHub says internal repos were stolen after poisoned VS Code extension attack</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pvsS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pvsS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png 424w, https://substackcdn.com/image/fetch/$s_!pvsS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png 848w, https://substackcdn.com/image/fetch/$s_!pvsS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png 1272w, https://substackcdn.com/image/fetch/$s_!pvsS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pvsS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png" width="1427" height="802" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:802,&quot;width&quot;:1427,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:383484,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/198548594?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pvsS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png 424w, https://substackcdn.com/image/fetch/$s_!pvsS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png 848w, https://substackcdn.com/image/fetch/$s_!pvsS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png 1272w, https://substackcdn.com/image/fetch/$s_!pvsS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35de8589-9335-416f-97e9-4476e54b9cd0_1427x802.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>GitHub confirmed attackers compromised an employee device through a poisoned VS Code extension from the official Marketplace, then exfiltrated GitHub-internal repositories. GitHub says the incident appears limited to internal repos, with no evidence so far that customer enterprises, organizations, or repositories were impacted. </p><p>The attacker&#8217;s claim of roughly <strong>3,800</strong> stolen repos is &#8220;directionally consistent&#8221; with GitHub&#8217;s investigation, according to <em>The Register</em>, and GitHub says it is rotating secrets, reviewing logs, and watching for follow-on activity.</p><p>The absurd part is the attack path. GitHub, the platform everyone uses to secure, review, build, and ship software, got popped through the developer tool supply chain. Not a Mythos zero-click magic spicy nation-state digital nuke. A poisoned VS Code extension. GitHub&#8217;s line that customer repos were not affected matters, but internal source code is still useful attacker material. It can expose architecture, workflows, secrets hygiene, internal tooling assumptions, and future attack paths. </p><p>Zoom out and you can see Github has been in a tough spot recently. GitHub&#8217;s own availability reports show <a href="https://github.blog/news-insights/company-news/github-availability-report-february-2026/?utm_source=chatgpt.com">six degraded-service incidents in February</a>, <a href="https://github.blog/news-insights/company-news/github-availability-report-march-2026/?utm_source=chatgpt.com">four in March</a>, and <a href="https://github.blog/news-insights/company-news/github-availability-report-april-2026/?utm_source=chatgpt.com">10 in April</a>. That is <strong>20 incidents</strong> in three months before May even gets a full report. GitHub has also said it is designing for a future that requires <strong><a href="https://github.blog/news-insights/company-news/an-update-on-github-availability/?utm_source=chatgpt.com">30X</a></strong><a href="https://github.blog/news-insights/company-news/an-update-on-github-availability/?utm_source=chatgpt.com"> today&#8217;s scale</a>, driven by AI coding growth. The degraded service/ post-mortem reports are truly educative btw.</p><p>So the question is getting harder to dodge: can GitHub keep up with the AI-generated code flood, AI agent traffic, extension supply chain risk, and uptime expectations all at once, or is there finally room for a serious alternative that is safer, more boring, and online more often? Reuters reported in March that <a href="https://www.reuters.com/business/openai-is-developing-alternative-microsofts-github-information-reports-2026-03-03/?utm_source=chatgpt.com">OpenAI is developing a GitHub alternative</a> after recurring GitHub disruptions hit its engineers. </p><p>What GitHub does is hard. And doing it for how long they&#8217;ve done it is seriously impressive but have they been caught off guard by the nature of code in 2026? </p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;">How Databricks Scales Modern Identity Governance with Opal Security</h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1x5G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1x5G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png 424w, https://substackcdn.com/image/fetch/$s_!1x5G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png 848w, https://substackcdn.com/image/fetch/$s_!1x5G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png 1272w, https://substackcdn.com/image/fetch/$s_!1x5G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1x5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png" width="528" height="71.49389567147614" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:122,&quot;width&quot;:901,&quot;resizeWidth&quot;:528,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1x5G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png 424w, https://substackcdn.com/image/fetch/$s_!1x5G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png 848w, https://substackcdn.com/image/fetch/$s_!1x5G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png 1272w, https://substackcdn.com/image/fetch/$s_!1x5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315bff48-1e8d-4ec1-81d9-171d7746a999_901x122.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;">Most identity governance platforms add work instead of reducing it. Databricks took a different approach with Opal, <strong>using automation and developer-friendly policy controls</strong> to manage access at scale while maintaining visibility and control.</p><p style="text-align: center;"></p><p style="text-align: center;"><strong>Automated workflows</strong> speed provisioning.</p><p style="text-align: center;"><strong>Policy-driven governance</strong> scales access rules.</p><p style="text-align: center;"><strong>Unified visibility</strong> shows who has access and why.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.opal.dev/customers/databricks/?utm_source=tcp&amp;utm_medium=cpc&amp;utm_campaign=databricks&amp;utm_term=jit&amp;utm_content=secondary&amp;hstk_campaign=39785132&amp;hstk_network=tcp&amp;hsa_acc=45127704&amp;hsa_net=tcp&quot;,&quot;text&quot;:&quot;Read the case study&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.opal.dev/customers/databricks/?utm_source=tcp&amp;utm_medium=cpc&amp;utm_campaign=databricks&amp;utm_term=jit&amp;utm_content=secondary&amp;hstk_campaign=39785132&amp;hstk_network=tcp&amp;hsa_acc=45127704&amp;hsa_net=tcp"><span>Read the case study</span></a></p></div><div><hr></div><h4><a href="https://www.verizon.com/business/resources/reports/dbir/">Verizon DBIR 2026: Faster Old Problems</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YWN8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YWN8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png 424w, https://substackcdn.com/image/fetch/$s_!YWN8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png 848w, https://substackcdn.com/image/fetch/$s_!YWN8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png 1272w, https://substackcdn.com/image/fetch/$s_!YWN8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YWN8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png" width="728" height="402.88427299703267" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:373,&quot;width&quot;:674,&quot;resizeWidth&quot;:728,&quot;bytes&quot;:163307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/198548594?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YWN8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png 424w, https://substackcdn.com/image/fetch/$s_!YWN8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png 848w, https://substackcdn.com/image/fetch/$s_!YWN8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png 1272w, https://substackcdn.com/image/fetch/$s_!YWN8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F054c1069-1c63-4755-a36b-cb19f403ea76_674x373.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <strong>2026 DBIR</strong> is live, and it is <strong>121 pages</strong> of hard data and reminders that the basics are still where most teams bleed. It is well worth the full read-through, especially this year, because the story is not &#8220;AI changed everything.&#8221; It is that exposed apps, slow patching, stolen creds, third-party cloud auth, help desk social engineering, and unmanaged AI are all moving faster. Verizon analyzed <strong>31,000+ incidents</strong> and <strong>22,000+ confirmed breaches</strong>, its largest breach dataset yet.</p><p><strong>Here are the top 5 takeaways I&#8217;d pull out:</strong></p><ol><li><p><strong>Vuln exploitation is now the front door.<br></strong>Exploitation of vulnerabilities became the top initial access vector at 31%, passing credential abuse at 13%. Only 26% of CISA KEV vulns were fully remediated, and median full remediation slipped to 43 days.</p></li><li><p><strong>Ransomware grew, but payments cracked.<br></strong>Ransomware appeared in 48% of breaches, up from 44% last year. But 69% of victims did not pay, and the median payment fell to $139,875. That reads like margin compression for criminals.</p></li><li><p><strong>Third-party risk is now core breach risk.<br></strong>Third-party involvement hit 48% of breaches, up 60% from last year. Weak cloud auth, missing MFA, poor credential rotation, and permission misconfigs keep showing up. Vendor risk questionnaires are not going to save us here.</p></li><li><p><strong>AI is accelerating known tradecraft.<br></strong>Threat actors are using GenAI for targeting, initial access, malware development, and tooling. But less than 2.5% of AI-assisted malware observations involved rare techniques. AI is mostly making known bad work faster and cheaper.</p></li><li><p><strong>Social engineering moved closer to the phone.<br></strong>The human element appeared in 62% of breaches. Mobile-centric vectors like voice and SMS had a 40% higher median click rate than email in simulations. Email training alone is starting to look pretty incomplete.</p></li></ol><div><hr></div><h4><a href="https://blog.cloudflare.com/cyber-frontier-models/?utm_source=chatgpt.com">Cloudflare says Mythos can chain low-severity bugs into working exploits</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KVjw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KVjw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png 424w, https://substackcdn.com/image/fetch/$s_!KVjw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png 848w, https://substackcdn.com/image/fetch/$s_!KVjw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png 1272w, https://substackcdn.com/image/fetch/$s_!KVjw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KVjw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png" width="1456" height="659" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:659,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Vulnerability discovery harness \n5 \n7 \n8 \n1 \n2 \n3 \n6 \nDedupe \nTrace \nFeedback \nReport \nRecon \nHunt \nValidate \n> \n> \n> \n> \n> \n&#8249;- \n<-- \n4 \nGapfill &quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Vulnerability discovery harness 
5 
7 
8 
1 
2 
3 
6 
Dedupe 
Trace 
Feedback 
Report 
Recon 
Hunt 
Validate 
> 
> 
> 
> 
> 
&#8249;- 
<-- 
4 
Gapfill " title="Vulnerability discovery harness 
5 
7 
8 
1 
2 
3 
6 
Dedupe 
Trace 
Feedback 
Report 
Recon 
Hunt 
Validate 
> 
> 
> 
> 
> 
&#8249;- 
<-- 
4 
Gapfill " srcset="https://substackcdn.com/image/fetch/$s_!KVjw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png 424w, https://substackcdn.com/image/fetch/$s_!KVjw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png 848w, https://substackcdn.com/image/fetch/$s_!KVjw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png 1272w, https://substackcdn.com/image/fetch/$s_!KVjw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bf3947-e9d9-4f5b-bd2b-37f990258a2f_1999x905.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Cloudflare</strong> tested Anthropic&#8217;s <strong>Mythos Preview</strong> across <strong>50+</strong> internal repos and found the model was best at the part scanners usually botch: turning small primitives into a working exploit chain. It could write PoCs, compile them, run them, read the failure, adjust the hypothesis, and try again. That loop matters because &#8220;possible vuln&#8221; is cheap. Reproducible exploitability is not.</p><p>The team also found the chat-agent model breaks down fast. One generic agent pointed at a huge repo covers basically nothing useful before context gets messy. Cloudflare got better results with a harness: recon, narrow parallel hunts, independent validation, gapfill, dedupe, reachability tracing, and structured reporting. The trace stage is the money step: it turns &#8220;bug exists&#8221; into &#8220;attacker-controlled input can actually reach it.&#8221;</p><p>This is the shape of AI AppSec that actually matters. Not &#8220;ask Claude to find bugs.&#8221; More like distributed vuln research pipelines with adversarial review and reachability analysis. Also, Cloudflare is honest about the ugly part: the same capability helps attackers compress vuln research timelines. Faster patching helps, but architecture still decides how bad the blast radius gets.</p><div><hr></div><h3><a href="https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack">TeamPCP compromises Microsoft DurableTask PyPI package</a></h3><p><strong>TeamPCP</strong> compromised durabletask, Microsoft&#8217;s official Python client for the <a href="https://learn.microsoft.com/en-us/azure/durable-task/common/what-is-durable-task?utm_source=chatgpt.com">Durable Task framework</a>, publishing malicious PyPI versions <code>1.4.1, 1.4.2, </code>and <code>1.4.3.</code> Wiz tied the attack to the earlier <code>@antv</code> wave: a compromised GitHub account likely dumped repo secrets, exposed the PyPI token, and let the actor publish directly.</p><p>The payload targeted Linux systems and stole AWS, Azure, GCP, Kubernetes, Vault, filesystem, and password manager secrets. It also added AWS SSM propagation, Kubernetes lateral movement, shell history scraping, and brute-force attempts against Bitwarden, 1Password, and GPG. PyPI quarantined the malicious packages after Wiz&#8217;s analysis.</p><p>TeamPCP are turning trusted developer infrastructure into a propagation layer: GitHub secrets to PyPI tokens, PyPI installs to cloud creds, cloud creds to lateral movement. The package manager is the initial access vector. The build and runtime environment is the blast radius.</p><div><hr></div><h4><a href="https://blog.calif.io/p/first-public-kernel-memory-corruption">Anthropic&#8217;s Mythos helped bypass Apple&#8217;s Mac security</a></h4><div id="youtube2-tH-4u9Jbl_g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;tH-4u9Jbl_g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/tH-4u9Jbl_g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Anthropic&#8217;s unreleased <strong>Claude Mythos Preview</strong> helped researchers find a macOS privilege escalation chain that reportedly bypassed Apple&#8217;s <strong>Memory Integrity Enforcement</strong> on M5 systems. The bug let a standard user gain root on macOS <strong>26.4.1</strong>, according to reporting on Calif&#8217;s AI-discovered bugs work.</p><p>Frontier models are getting useful at chaining real vuln research against hardware-backed mitigations. Not good. </p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><p><strong><a href="https://openai.com/daybreak/?utm_source=chatgpt.com">OpenAI launches Daybreak, plus a naming problem</a></strong></p><p><strong>OpenAI</strong> launched <strong>Daybreak</strong>, a cybersecurity initiative that uses <strong>GPT-5.5</strong>, <strong>GPT-5.5-Cyber</strong>, and <strong>Codex Security</strong> to find, validate, patch, and verify software vulnerabilities. </p><p>If you&#8217;re confused, that&#8217;s okay. I am too. The naming is getting messy enough that OpenAI may need marketing help, which is a deeply weird thing to say about a company with hundreds of million in marketing budget and that made &#8220;ChatGPT&#8221; a household name.</p><p>As best as I can tell: <strong>Trusted Access for Cyber</strong> is the vetted-access program, <strong>GPT-5.5-Cyber</strong> is the specialized model tier, <strong>Codex Security</strong> is the code scanning and remediation product, and <strong>Daybreak</strong> is the umbrella initiative for vuln defense.</p><p>Ultimately, OpenAI wants to own more of the remediation loop, not just give defenders a smarter bug-finding assistant. Finding more vulns is easy to market and brutal to operationalize. </p><div><hr></div><h2><strong>Application Security</strong></h2><p><strong><a href="https://www.securityweek.com/boost-security-raises-4-million-for-sdlc-defense-platform/?utm_source=chatgpt.com">Boost Security raises $4M, buys two AppSec startups</a></strong></p><p>Boost Security, founded by Zaid Al Hamami and Rajiv Sinha, raised $4 million from White Star Capital, Amiral Ventures, Accelia Capital, and Sorensen Capital, bringing total funding to $16 million. The company also acquired SecureIQx and Korbit.ai, adding reachability analysis, SAST, and AI-assisted code review to its SDLC defense platform. </p><div><hr></div><h2><strong>Browser Security</strong></h2><p><strong><a href="https://www.securityweek.com/akamai-to-acquire-ai-and-browser-security-firm-layerx-for-205-million/?utm_source=chatgpt.com">Akamai buys LayerX for $205M to push AI controls into the browser</a></strong></p><p><strong>Akamai</strong> agreed to acquire <strong>LayerX</strong> for roughly <strong>$205 million</strong>, adding browser-level controls for GenAI apps, SaaS AI, IDEs, and agentic workflows. LayerX gives Akamai visibility and policy enforcement where employees actually touch AI: the browser, not some clean architecture diagram nobody&#8217;s environment matches.</p><p>The browser is becoming the AI security control plane. DLP, CASB, and proxy controls still matter, but a lot of risky AI use now happens in copy-paste land, browser extensions, SaaS copilots, and agents acting through web apps.</p><div><hr></div><h2><strong>Email Security</strong></h2><p><strong><a href="https://techcrunch.com/2026/05/19/from-teen-hacker-to-iron-dome-researcher-this-founder-raised-28m-to-fight-ai-phishing/?utm_source=chatgpt.com">Ocean raises $28M to fight AI phishing</a></strong></p><p><strong>Ocean</strong> emerged from stealth with <strong>$28 million</strong> for an agentic email security platform built to catch AI-generated phishing, impersonation, and fraud. The round was led by <strong>Lightspeed Venture Partners</strong>, with participation from <strong>Picture Capital</strong> and <strong>Cerca Partners</strong>, plus angels including <strong>Wiz</strong> CEO Assaf Rappaport and <strong>Armis</strong> co-founders Yevgeny Dibrov and Nadir Izrael. Customers include Kayak, Kingston Technology, and Headspace.</p><div><hr></div><h2><strong>Endpoint Security</strong></h2><p><strong><a href="https://siliconangle.com/2026/05/06/tanium-servicenow-launch-joint-solution-automate-endpoint-patching-remediation/">Tanium and ServiceNow team up on autonomous patching</a></strong></p><p><strong>Tanium</strong> and <strong>ServiceNow</strong> launched <strong>ITOM AI Prime powered by Tanium</strong>, a joint offering that feeds Tanium&#8217;s real-time endpoint data into ServiceNow workflows for patching and remediation. ServiceNow agents get endpoint state from Tanium, then execute OS and third-party patching through approved change processes.</p><p>ServiceNow is uniquely positioned for the long-run in security given how much enterprise IT context and visibility they have as a go-to CMDB + the recent Armis and Veza acquisitions. Will be fun to watch what they do in the space. </p><div><hr></div><h2><strong>Security Operations</strong></h2><p><strong><a href="https://siliconangle.com/2026/05/19/torq-acquires-ai-security-startup-jit-add-context-graphs-soc-platform/">Torq buys Jit to bring context graphs into the SOC</a></strong></p><p><strong>Torq</strong> acquired <strong>Jit</strong>, an AI security startup building context graphs that map relationships across code, identities, roles, privileges, data sensitivity, and runtime behavior. </p><p>Jit started as a security-as-code platform with SAST, SCA, IaC scanning, secrets detection, container scanning, and SBOM generation, but Torq wants the graph layer underneath its AI SOC agents.</p><p>This is the right direction for AI SOC, at least on paper. Alerts without context are just expensive confetti. If agents are going to investigate or contain anything with confidence, they need an environment-specific graph of what matters, who can touch it, and what blast radius looks like. The hard part is keeping that graph fresh enough to trust.</p><div><hr></div><p><strong>More SecOps news</strong> </p><ul><li><p><a href="https://securitybrief.com.au/story/exaforce-raises-usd-125m-in-series-b-for-ai-security">Exaforce raises USD $125m in Series B for AI security</a></p></li><li><p><a href="https://www.crowdstrike.com/en-us/blog/ai-threat-detection-with-automated-leads/">Inside CrowdStrike Automated Leads: A Transformative Approach to Threat Detections</a></p></li></ul><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[How one CISO got 4 budget offers in a single afternoon and how the AI SOC is evolving]]></title><description><![CDATA[A field report from AI SOC Live at Nasdaq.]]></description><link>https://www.cybersecuritypulse.net/p/how-one-ciso-got-4-budget-offers</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/how-one-ciso-got-4-budget-offers</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Tue, 12 May 2026 12:57:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bp8S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer in big tech. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/25-million-alerts-one-year-of-real?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxMTY2OTE1NTEsInBvc3RfaWQiOjE4OTk5NTgyNCwiaWF0IjoxNzczMTk3ODk5LCJleHAiOjE3NzU3ODk4OTksImlzcyI6InB1Yi0xMjU0OTkwIiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.uLri8qmd3TaY1NBupbqOvebAA6UkoZKWikyo0XeoQSw&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/25-million-alerts-one-year-of-real?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjoxMTY2OTE1NTEsInBvc3RfaWQiOjE4OTk5NTgyNCwiaWF0IjoxNzczMTk3ODk5LCJleHAiOjE3NzU3ODk4OTksImlzcyI6InB1Yi0xMjU0OTkwIiwic3ViIjoicG9zdC1yZWFjdGlvbiJ9.uLri8qmd3TaY1NBupbqOvebAA6UkoZKWikyo0XeoQSw"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bp8S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bp8S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png 424w, https://substackcdn.com/image/fetch/$s_!bp8S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png 848w, https://substackcdn.com/image/fetch/$s_!bp8S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png 1272w, https://substackcdn.com/image/fetch/$s_!bp8S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bp8S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png" width="1440" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1440,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2197498,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/196999185?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bp8S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png 424w, https://substackcdn.com/image/fetch/$s_!bp8S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png 848w, https://substackcdn.com/image/fetch/$s_!bp8S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png 1272w, https://substackcdn.com/image/fetch/$s_!bp8S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2420f02d-a70f-4ab9-8031-546717dd2625_1440x811.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>I recently attended <a href="https://intezer.com/ai-soc-live-nasdaq/">Intezer&#8217;s AI SOC Live</a> show, a one-day, invite-only gathering of CISOs and security leaders at Nasdaq&#8217;s MarketSite. While this trip was sponsored, this piece highlights what I extracted from the experience and thought would be most valuable to you.</em></p><p>One thing that kept coming up across nearly every session is that it's the hardest time to be a CISO and also the most exciting. <a href="https://www.linkedin.com/in/4pavi/">Pavi</a> laid out everything stacking against defenders right now and <a href="https://www.linkedin.com/in/dougmayer1/">Doug</a> kept coming back to how AI is making the CISO seat more rewarding than it's been in years. While we covered a lot of ground in one day, that tension was kind of the undercurrent for everything else.</p><div><hr></div><h3><strong>TL;DR</strong></h3><ul><li><p><a href="https://red.anthropic.com/2026/mythos-preview/">Mythos</a> quietly opened a budget window. It spooked many execs and brought security to the forefront even more. CISOs can and should parlay this into more funding to bolster their security programs for what comes next.</p></li><li><p>The walls between SIEM, SOAR, MDR, and EDR are collapsing. The AI SOC unlocks the speed and coverage to investigate every alert, not just the obvious ones.</p></li><li><p>Tier 1 is dead, Tier 2 is dying. MSSPs and MDRs whose business model depends on selling tiered analysis have a real problem.</p></li><li><p><a href="https://www.linkedin.com/in/mitchem-boles/">Mitchem Boles</a> proposed AVERT (Action-Verified Resolution Time) as the executive metric to replace MTTR.</p></li><li><p>Procurement is shifting from multi-year to one-year deals. Renewal motions just got harder.</p></li><li><p>Mature SOCs will win bigger from AI than immature ones. <em>Good brakes make the car go faster.</em></p></li></ul><p>While AI SOC was at the forefront, the takeaways ranged well beyond that: procurement strategy, MSSP business models, board-level budget dynamics, metric reframes, and architectural patterns for adopting autonomous approaches to security.</p><p>This post covers the 8 things I walked away with.</p><div><hr></div><h3><strong>Mythos quietly rewrote the budget conversation in real time</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CeEA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CeEA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png 424w, https://substackcdn.com/image/fetch/$s_!CeEA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png 848w, https://substackcdn.com/image/fetch/$s_!CeEA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png 1272w, https://substackcdn.com/image/fetch/$s_!CeEA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CeEA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png" width="1456" height="969" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:969,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CeEA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png 424w, https://substackcdn.com/image/fetch/$s_!CeEA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png 848w, https://substackcdn.com/image/fetch/$s_!CeEA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png 1272w, https://substackcdn.com/image/fetch/$s_!CeEA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c906767-43d2-4ef5-aba7-2fd097ecc230_2048x1363.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When the Mythos news broke, one of the panelist CISOs (I forget which one) got pulled aside by <em>four different C-suite executives</em> in short succession, each offering more budget. Not &#8220;send us a plan.&#8221; More money, now, because they were genuinely worried Mythos-class capability in the wrong hands could end the company.</p><p><a href="https://www.linkedin.com/in/dougmayer1/">Doug Mayer</a> (CISO, WCG Clinical) made the same point from another angle: <em>&#8220;I&#8217;m a huge fan of the marketing around Mythos because it opens eyes and interest into security. CISOs should use this moment to educate the board and get more funding.&#8221;</em></p><p>The window is open. CISOs who go to their boards in the next two quarters with a clear-eyed plan for AI-era threats will get funded in ways they wouldn&#8217;t have a year ago. The ones who wait may already be being questioned behind closed doors. Everyone is AI-pilled and security leaders who aren&#8217;t being vocal + tactical about securing it, securing from it, and using it to secure things, risk falling behind.</p><div><hr></div><h3><strong>We&#8217;re tuning out the wrong alerts</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m7RY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m7RY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png 424w, https://substackcdn.com/image/fetch/$s_!m7RY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png 848w, https://substackcdn.com/image/fetch/$s_!m7RY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png 1272w, https://substackcdn.com/image/fetch/$s_!m7RY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m7RY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png" width="1456" height="967" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:967,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m7RY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png 424w, https://substackcdn.com/image/fetch/$s_!m7RY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png 848w, https://substackcdn.com/image/fetch/$s_!m7RY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png 1272w, https://substackcdn.com/image/fetch/$s_!m7RY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498198d3-9a00-4944-ab88-3e1f8b943de7_2048x1360.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="http://linkedin.com/in/itai-tevet-43776767">Itai Tevet</a> (co-founder and CEO of Intezer) opened by addressing the elephant in the room. SIEM, SOAR, MDR, and traditional SOC models are all broken in the same way. Each layer requires humans to operationalize, and humans don&#8217;t scale. So teams tune out, filter down, and only chase what looks obviously anomalous or bad.</p><p>Alert fatigue and analyst burnout are real, but they&#8217;re organization-specific problems with organization-specific fixes. The bigger issue is the industry-wide pattern that we&#8217;ve been forced to accept for over a decade. We collectively decided low-severity alerts aren&#8217;t worth investigating, and we built our entire SOC operating model around that assumption.<a href="https://intezer.com/2026-ai-soc-report-for-cisos/"> Intezer&#8217;s 2026 AI SOC Report</a> puts a number on what that costs us:<a href="https://www.cybersecuritypulse.net/p/25-million-alerts-one-year-of-real"> nearly 2% of low-severity endpoint alerts turn out to be real threats</a>.. Tune those out at scale, you tune out real attacks at scale.</p><p>Itai&#8217;s reframe of the SOC operating model boils down to three rules: every alert is investigated, every investigation is consistent, detection posture improves with every alert. None of those work with a human-bottlenecked tier 1 queue.</p><div><hr></div><h3><strong>The offense has gotten too fast for human-in-the-loop on every alert</strong></h3><p><a href="https://www.linkedin.com/in/alon-n-cohen/">Alon Cohen</a> (CyberArk founder, Intezer executive chairman) followed with: <em>&#8220;In a world of machine-speed attacks, human-speed defense is a suicide mission.&#8221;</em></p><p> A few months ago I would have called that fearmongering or an overstatement but this has only become increasingly true.  <a href="https://red.anthropic.com/2026/mythos-preview/">Anthropic&#8217;</a> showed a model that weaponized 181 working attacks from a single Firefox vulnerability set, where the prior generation managed two. The November 2025 <a href="https://www.anthropic.com/news/disrupting-AI-espionage">GTG-1002 disclosure</a> showed nation-state actors running 80 to 90% of an espionage campaign autonomously through Claude Code at thousands of requests per second. Now think about the capabilities nation-state actors have which don&#8217;t come up on traditional radars; the landscape has truly shifted and automation is one of our best answers for this.</p><p>If you&#8217;ve architected your SOC around human-in-the-loop on every alert, you&#8217;re not building a SOC. You&#8217;re building a forensics team.</p><div><hr></div><h3><strong>Translating SOC outcomes into board language</strong></h3><p><a href="https://www.linkedin.com/in/mitchem-boles/">Mitchem Boles</a> (Field CISO at Intezer, four years previously as Field CISO and security advisor at GuidePoint) gave one of the most insightful talks of the day. I&#8217;ve never been a CISO so of course, I&#8217;ve never had to report to a board so aside from what I read or hear, I don&#8217;t truly know how CISOs navigate the dynamic.</p><p><strong>&#8220;If you&#8217;ve seen a board, you&#8217;ve seen one board.&#8221;</strong> This means that every board is different, but every board is pretty much asking a version of the same three questions. Mitchem&#8217;s framework maps each one to what they actually need to hear: coverage to risk reduction, comparison to containment, operations to leverage. Reframe the conversation in those terms and you stop reporting activity and start reporting outcomes.</p><p><strong>AVERT, a new executive-level metric.</strong> Action-Verified Resolution Time. The argument: MTTR is dead, MTTC is closer, but neither captures whether the threat was actually neutralized with forensic proof. AVERT bundles three sub-metrics:</p><ul><li><p><strong>RMV (Risk Mitigation Velocity):</strong> 20x faster than industry average.</p></li><li><p><strong>ARR (Autonomous Resolution Rate):</strong> 85% resolved before an analyst touches them.</p></li><li><p><strong>VRR (Verified Resolution Rate):</strong> 97% closed with forensic proof of neutralization.</p></li></ul><p>Mitchem framed AVERT as a &#8220;proposed executive and board metric,&#8221; so I&#8217;m reading those numbers as aspirational targets for a mature AI SOC rather than industry averages.</p><div><hr></div><h3><strong>Procurement is shifting from multi-year to one-year deals.</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CRaG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CRaG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png 424w, https://substackcdn.com/image/fetch/$s_!CRaG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png 848w, https://substackcdn.com/image/fetch/$s_!CRaG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png 1272w, https://substackcdn.com/image/fetch/$s_!CRaG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CRaG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CRaG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png 424w, https://substackcdn.com/image/fetch/$s_!CRaG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png 848w, https://substackcdn.com/image/fetch/$s_!CRaG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png 1272w, https://substackcdn.com/image/fetch/$s_!CRaG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1333cad6-49a7-41d8-8cca-b43ee5c3960b_2048x1365.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.linkedin.com/in/4pavi/">Pavi Ramamurthy</a> (CISO, Blackhawk Network) flagged a shift that&#8217;s going to compound: CISOs are pulling back from multi-year contracts in favor of one-year deals.</p><p>Two reasons. The industry is moving fast enough that locking into a three-year deal with anyone, including the vendor you love today, looks reckless. And security incidents are increasingly hitting <em>security vendors themselves</em>, eroding trust and making the ability to switch a feature, not a bug. Another point of concern is what usually happens when a vendor gets acquired. Things inevitably change and sometimes for the worse.</p><div><hr></div><h3><strong>Tier 1 is dead. Tier 2 is dying.</strong></h3><p>Across both CISO panels, the consensus was nearly unanimous, and Doug Mayer made the case clearly: siloed tier 1 / tier 2 / tier 3 categorization is a relic of a staffing model that no longer makes sense when AI can do the triage and enrichment work that filled tier 1 queues for the last 15 years.</p><p>Bad news for any MSSP or MDR whose business model depends on selling tier 1 and tier 2 analysis as a service. The shops that survive are investing in higher-order detection engineering, threat hunting, and complex investigation. Jen Greulich&#8217;s Legato Security is a good example of a shop already adapting.</p><p>Counterpoint from Deepak Kolingivadi (ServiceNow): the security practitioner role isn&#8217;t disappearing, it&#8217;s changing. The new bar is whether you can think in automation, orchestration, and scale.</p><div><hr></div><h3><strong>Stop measuring MTTR. Start measuring dwell time and time-to-decision</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V5OE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V5OE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png 424w, https://substackcdn.com/image/fetch/$s_!V5OE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png 848w, https://substackcdn.com/image/fetch/$s_!V5OE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png 1272w, https://substackcdn.com/image/fetch/$s_!V5OE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V5OE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png" width="1456" height="956" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:956,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V5OE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png 424w, https://substackcdn.com/image/fetch/$s_!V5OE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png 848w, https://substackcdn.com/image/fetch/$s_!V5OE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png 1272w, https://substackcdn.com/image/fetch/$s_!V5OE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c16cf37-a813-4a03-accc-af24a623132b_2048x1345.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two CISOs in the same room landed on the same idea from different angles: MTTR is measuring the wrong thing.</p><p>Doug Mayer: <em>&#8220;Screw MTTR. Mean time to contain, dwell time, is the real thing.&#8221;</em> MTTR measures activity. Dwell time measures outcome.</p><p><a href="https://www.linkedin.com/in/nickvigier/">Nick Vigier</a> (CISO, Oscar Health), in the closing <a href="https://cisoseries.com">CISO Series</a> podcast taping with <a href="https://www.linkedin.com/in/davidspark/">David Spark</a>, pushed it further. Most SOCs are slow because <em>decision-making rests with too few operators</em>. The bottleneck isn&#8217;t analysis speed. It&#8217;s decision ownership. Nick&#8217;s reframe: <strong>mean time to decision</strong>.</p><p>Together, dwell time and time-to-decision describe the SOC&#8217;s job better than any framework I&#8217;ve seen.</p><div><hr></div><h3><strong>Mature SOCs with strong foundations will win</strong></h3><p><a href="https://www.linkedin.com/in/paul-carpenito/">Paul Carpenito</a> (CISO, ION Group): <em>&#8220;Good brakes make the car go faster.&#8221; </em>Easily my favorite quote of the day.</p><p>To me, it means that if your SOC is mature-ish and has good hygiene (trustworthy log ingestion and coverage, fine-tuned detection content, well-mapped MITRE ATT&amp;CK coverage, defined runbooks, clear ownership), you can adopt AI faster and trust it more. The AI has structured ground truth to operate against. Tiered autonomy based on asset criticality becomes achievable because you actually know how certain events should be responded to.</p><p>If your SOC is immature, AI accelerates your dysfunction, automates decisions you didn&#8217;t realize were wrong, and produces confident outputs against a foundation that can&#8217;t validate them. The gap between mature and immature SOCs will widen dramatically. The decisions (or lack thereof) SOC leaders make in 2026 will compound for the next five years.</p><div><hr></div><h2><strong>Wrapping Up</strong></h2><p>The offense has gotten a lot faster and the defense hasn&#8217;t necessarily caught up. The AI SOC conversation is no longer about whether to adopt. I think that&#8217;s a settled debate. It&#8217;s about whether you have a mature foundation that can absorb it, or on top of a stack that&#8217;s going to amplify your existing problems.</p><p>Good brakes make the car go faster. If you don&#8217;t have good brakes, this is the year to build them.</p><p>Big kudos to Sarah, Lital, Ada and the Intezer marketing team for putting this together. A Nasdaq venue, a CISO-only invite list, and a David Spark podcast taping in a single day takes <em>serious </em>coordination, and they made it look easy. Shoutout also to Itai and Mitchem for the substance, and to the CISOs who didn&#8217;t hold back any punches. Cool event! </p><div><hr></div><h2><strong>Interested in sponsoring TCP?</strong></h2><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to an audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/sponsor&quot;,&quot;text&quot;:&quot;Learn more here&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cybersecuritypulse.net/p/sponsor"><span>Learn more here</span></a></p>]]></content:encoded></item><item><title><![CDATA[A Production DB Gone in 9 Seconds, DPRK Steals $577M in 18 Days, and Cisco Acquires Astrix ]]></title><description><![CDATA[Plus: a GitHub RCE, cPanel auth bypass, and OpenAI's passkey play]]></description><link>https://www.cybersecuritypulse.net/p/a-production-db-gone-in-9-seconds</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/a-production-db-gone-in-9-seconds</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Wed, 06 May 2026 12:51:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Au9U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer in big tech. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/a-production-db-gone-in-9-seconds?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/a-production-db-gone-in-9-seconds?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Au9U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Au9U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!Au9U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!Au9U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!Au9U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Au9U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3338574,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/196616271?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Au9U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!Au9U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!Au9U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!Au9U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a4595e-ea23-4813-8314-d48fe4bad3a6_1800x1300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;">Agentify Your Security Operations</h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9ZdH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9ZdH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png 424w, https://substackcdn.com/image/fetch/$s_!9ZdH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png 848w, https://substackcdn.com/image/fetch/$s_!9ZdH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png 1272w, https://substackcdn.com/image/fetch/$s_!9ZdH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9ZdH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png" width="360" height="76.8956043956044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:311,&quot;width&quot;:1456,&quot;resizeWidth&quot;:360,&quot;bytes&quot;:55015,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/196616271?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9ZdH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png 424w, https://substackcdn.com/image/fetch/$s_!9ZdH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png 848w, https://substackcdn.com/image/fetch/$s_!9ZdH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png 1272w, https://substackcdn.com/image/fetch/$s_!9ZdH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27251772-3507-4950-93d0-a08f4ddb238b_2916x623.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>Every SOC runs differently. BlinkOps is the agentic platform built for it. Run pre-built agentic solution on day-one. Customize it as your programs mature. Build your own from scratch to match your needs. Or co-build with our forward-deployed engineers. </p><p>Agentic SOC and Agentic SOAR on one platform. With enterprise governance, security, and scale.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://go.blinkops.com/agentic-soc?utm_campaign=43443635-chnl-influencer-tcp-pulse&amp;utm_source=tcp-pulse&amp;utm_medium=newsletter&amp;utm_content=agentic-soc&quot;,&quot;text&quot;:&quot;See AI SOC in action&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://go.blinkops.com/agentic-soc?utm_campaign=43443635-chnl-influencer-tcp-pulse&amp;utm_source=tcp-pulse&amp;utm_medium=newsletter&amp;utm_content=agentic-soc"><span>See AI SOC in action</span></a></p><p></p></div><div><hr></div><p>Hi &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from! </p><p>On a personal note, I&#8217;m finally back home in Austin after being on the road for ~90% of the past 2 months. Life is good but there&#8217;s no rest for the wicked. I&#8217;ll be in <a href="https://www.linkedin.com/posts/amber-bennoui_bostechweek-cybersecurity-ai-share-7450525072219561984-99Qh?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAB-Qy6IBLQLTsD9lC_8dkpPiQtNrO5eQqEo">Boston for Tech Week at the end of this month for an AI x Security panel</a>. If you&#8217;re in the New England area, don&#8217;t miss it. It&#8217;s at a dope art gallery and we&#8217;re coming with hot, grounded takes. We also may or may not be hosting a chatham-house rules dinner at one of Drake&#8217;s favorite restaurants &#175;\_(&#12484;)_/&#175;</p><p>Aside from that, the Monad team has partnered w/ Oso Security for a breakfast during #AIWeekNY. The line-up of attendees is pretty stacked. <a href="https://luma.com/6tta08op">Register here</a>.</p><p>Cool, now let&#8217;s get into all the wildness that&#8217;s taken place this past week. </p><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#128128; <a href="https://www.darkreading.com/cloud-security/ais-so-smart-keep-deleting-production-databases">AI wipes a production database in 9 seconds</a> &#8212; Cursor agent on Claude Opus 4.6 deleted PocketOS prod and all backups via single Railway API call, 3 months of data gone.</p></li><li><p>&#127472;&#127477; <a href="https://www.darkreading.com/cybersecurity-analytics/crypto-stolen-2026-north-korea">North Korea owns 76% of 2026 crypto theft</a> &#8212; DPRK actors stole $577M in two attacks (Drift, KelpDAO), pushing cumulative since 2017 past $6B.</p></li><li><p>&#128680; <a href="https://techcrunch.com/2026/05/04/hackers-are-still-exploiting-the-cpanel-bug-to-gain-control-of-thousands-of-websites/">cPanel auth bypass hits governments and MSPs</a> &#8212; CVE-2026-41940 (CVSS 9.8) exploited since Feb 23, ~550K servers still vulnerable, ~2K confirmed compromised.</p></li><li><p>&#128025; <a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854">GitHub patches RCE in git push pipeline</a> &#8212; Wiz Research finds CVE-2026-3854 (CVSS 8.7) on GitHub.com and GHES via <code>X-Stat</code> header injection, 88% of GHES instances vulnerable at disclosure.</p></li><li><p>&#128188; <a href="https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-astrix-security">Cisco to acquire Astrix Security for ~$400M</a> &#8212; NHI Anthology Fund and Anthropic-backed startup gets absorbed.</p></li><li><p>&#128477;&#65039; <a href="https://www.securityweek.com/openai-rolls-out-advanced-security-for-chatgpt-accounts/">OpenAI ships passkey-only Advanced Account Security</a> &#8212; Passkeys or YubiKeys required, no password or SMS recovery, mandatory for Trusted Access for Cyber members by June 1.</p></li></ul><p><strong>Plus:</strong> Azure AD Graph Activity Logs land, closing a long-standing legacy-API detection gap; Rippling launches Automated Compliance for SOC 2 with AJ Yawn joining the team; and CrowdStrike extends Falcon OverWatch managed threat hunting to Microsoft Defender environments.</p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><strong><a href="https://www.darkreading.com/cloud-security/ais-so-smart-keep-deleting-production-databases">If AI&#8217;s So Smart, Why Does It Keep Deleting Production Databases?</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sbGy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sbGy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png 424w, https://substackcdn.com/image/fetch/$s_!sbGy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png 848w, https://substackcdn.com/image/fetch/$s_!sbGy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png 1272w, https://substackcdn.com/image/fetch/$s_!sbGy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sbGy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png" width="901" height="498" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:498,&quot;width&quot;:901,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:102768,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/196616271?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sbGy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png 424w, https://substackcdn.com/image/fetch/$s_!sbGy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png 848w, https://substackcdn.com/image/fetch/$s_!sbGy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png 1272w, https://substackcdn.com/image/fetch/$s_!sbGy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd95280e8-45df-4bd2-9b0a-e2f9d39ff7d7_901x498.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://x.com/lifeof_jer/status/1915615563996713335">A Cursor agent running Claude Opus 4.6 wiped</a> <a href="https://pocketos.ai/">PocketOS</a>&#8216;s production database and all volume-level backups in <strong>9 seconds</strong> via a single API call to Railway. Three months of reservations, customer signups, and payment records: gone. </p><p>Founder <strong>Jer Crane</strong> discovered it Saturday morning while rental customers were arriving at his clients&#8217; counters with no records on file. The agent hit a credential mismatch, decided on its own to &#8220;fix&#8221; it by deleting a Railway volume, and produced a <a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue">written confession</a> when asked to explain itself. Data was recovered two days later. A <a href="https://x.com/jasonlk/status/1946069562723897802">Replit agent</a> did roughly the same thing to Jason Lemkin&#8217;s environment last summer.</p><p>PocketOS handed an LLM a token that could nuke prod and backups in one call, and Railway exposed an API where staging and prod volume IDs share a namespace with no destructive-action gate. That&#8217;s a blast radius problem and governance problem. Every CISO, CIO and CTO has to be asking themselves how they could prevent this type of insider risk. Continuously threat modeling AI coding agents should be at the top of the list.</p><p>This also reminds me of the time a <a href="https://techcrunch.com/2026/02/23/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox/">Meta AI safety researcher had all her emails deleted by OpenClaw</a>. Agents do go rogue.</p><div><hr></div><div class="callout-block" data-callout="true"><h4 style="text-align: center;">AI signals in email attacks: Boosting detection and threat hunting</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ojpI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ojpI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png 424w, https://substackcdn.com/image/fetch/$s_!ojpI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png 848w, https://substackcdn.com/image/fetch/$s_!ojpI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png 1272w, https://substackcdn.com/image/fetch/$s_!ojpI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ojpI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png" width="1300" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:1300,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ojpI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png 424w, https://substackcdn.com/image/fetch/$s_!ojpI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png 848w, https://substackcdn.com/image/fetch/$s_!ojpI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png 1272w, https://substackcdn.com/image/fetch/$s_!ojpI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b7ebc8-5c44-4e20-bb81-5fa9691d28fd_1300x500.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most AI &#8220;tells&#8221; in email are noisy and unreliable on their own. But used correctly, they can still strengthen detections and improve threat hunting.</p><p>In Sublime Security&#8217;s upcoming webinar, we break down which AI signals actually work, how to apply signal stacking, and where these approaches fail. See real examples and a practical framework you can use immediately.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://sublime.security/events/ai-signals-in-email-attacks/?utm_source=cybersecuritypulse&amp;utm_medium=third-party&amp;utm_campaign=webinar&quot;,&quot;text&quot;:&quot;Register now, watch anytime&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://sublime.security/events/ai-signals-in-email-attacks/?utm_source=cybersecuritypulse&amp;utm_medium=third-party&amp;utm_campaign=webinar"><span>Register now, watch anytime</span></a></p></div><div><hr></div><h4><strong><a href="https://www.darkreading.com/cybersecurity-analytics/crypto-stolen-2026-north-korea">North Korea now responsible for 76% of all crypto stolen in 2026</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-X9l!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-X9l!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png 424w, https://substackcdn.com/image/fetch/$s_!-X9l!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png 848w, https://substackcdn.com/image/fetch/$s_!-X9l!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png 1272w, https://substackcdn.com/image/fetch/$s_!-X9l!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-X9l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png" width="1456" height="835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-X9l!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png 424w, https://substackcdn.com/image/fetch/$s_!-X9l!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png 848w, https://substackcdn.com/image/fetch/$s_!-X9l!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png 1272w, https://substackcdn.com/image/fetch/$s_!-X9l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb511df1d-d977-4dda-980d-0848c621cdf7_2048x1174.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>DPRK-linked actors stole <strong>$577M</strong> in the first four months of 2026, <strong>76%</strong> of all global crypto hack losses, per a <a href="https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks">TRM Labs report</a>.</p><p>The number comes from just two attacks: a <strong>$285M</strong> Drift Protocol exploit on April 1 (Citrine Sleet, months of in-person social engineering against Drift employees, exploiting Solana durable nonce authorization) and a <strong>$292M</strong> KelpDAO breach on April 18 (TraderTraitor, single-verifier flaw in a LayerZero bridge). Cumulative DPRK crypto theft since 2017 exceeds <strong>$6B</strong>. THORChain handled most of the laundering on both Bybit (2025) and KelpDAO, converting stolen ETH to BTC with no operator willing to freeze.</p><p>#1 - that&#8217;s a lot of money. #2 - Crypto exchanges have startup-level security and are fending off nation-state actors. #3 - Something has to change. </p><p><strong>Dig Deeper: </strong><a href="https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks">TRM Labs report</a> | <a href="https://www.coindesk.com/business/2026/04/30/north-korean-hackers-are-moving-faster-they-account-for-76-of-crypto-exploits-this-year-trmlabs">CoinDesk on the months-long Drift social engineering campaign</a></p><div><hr></div><h4><strong><a href="https://techcrunch.com/2026/05/04/hackers-are-still-exploiting-the-cpanel-bug-to-gain-control-of-thousands-of-websites/">cPanel auth bypass CVE-2026-41940 exploited against governments, MSPs as patches lag</a></strong></h4><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41940">CVE-2026-41940</a> is a pre-auth <a href="https://owasp.org/www-community/vulnerabilities/CRLF_Injection">CRLF-injection</a> bypass in cPanel and WHM (CVSS <strong>9.8</strong>) disclosed by <a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/">watchTowr</a> on April 29, affecting Linux-based deployments (AlmaLinux, Rocky Linux, CloudLinux, and Ubuntu LTS). <strong>An unauthenticated attacker injects forged authentication state into a session file via the Basic-auth header and reloads it as root.</strong> </p><p>Shodan shows roughly <strong>1.5M</strong> exposed cPanel instances, with <strong>~550K</strong> still potentially vulnerable and <strong>~2,000</strong> confirmed compromised per Shadowserver, down from <strong>44K</strong> Thursday. KnownHost detected exploitation as early as <strong>February 23</strong>, two months before the patch. </p><p>Vendor and government guidance line up. WebPros&#8217; <a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-cPanel-WHM-Security-Update-04-28-2026">official advisory</a> instructs admins to update via the standard script, verify the build, and restart cpsrvd, with firewall-level blocks on ports <strong>2083, 2087, 2095, and 2096</strong> as the interim mitigation. The <a href="https://www.cyber.gc.ca/en/alerts-advisories/al26-008-vulnerability-affecting-cpanel-webhost-manager-whm-cve-2026-41940">Canadian Centre for Cyber Security</a> calls exploitation <em>&#8220;highly probable&#8221;</em> and pushes the same patch path. <a href="https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/">Rapid7</a> and watchTowr both stress the two-month pre-disclosure window: patching alone won&#8217;t evict an attacker who&#8217;s already inside, so credential rotation, session-file audits, and persistence hunting need to follow. </p><div><hr></div><h3><a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854">A single git push got Wiz Research RCE on GitHub&#8217;s backend</a></h3><p><a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854">Wiz Research</a> disclosed <strong>CVE-2026-3854</strong> (CVSS <strong>8.7</strong>), a command injection in GitHub&#8217;s internal git push pipeline that gave any authenticated user RCE on GitHub.com and GitHub Enterprise Server, including against repos the attacker created themselves. The chain:</p><ul><li><p><strong>The bug:</strong> <code>babeld</code> copied push option values into the <code>X-Stat</code> header unsanitized, and a semicolon let attackers inject arbitrary fields. Last-write-wins parsing meant injected fields silently overrode legitimate ones.</p></li><li><p><strong>The escalation:</strong> Sandbox escape via <code>rails_env</code>, hook directory redirection via <code>custom_hooks_dir</code>, then arbitrary binary execution as the <code>git</code> service user via <code>repo_pre_receive_hooks</code> with path traversal.</p></li><li><p><strong>The blast radius:</strong> On GitHub.com, that landed researchers on shared storage nodes with filesystem access to millions of repos belonging to other users and orgs (Wiz did not access contents).</p></li></ul><p><a href="https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/">GitHub patched cloud within hours</a> on March 4 and shipped patches March 10, public disclosure April 28. <strong>88%</strong> of GHES instances were still vulnerable at disclosure&#129327; </p><p>Wiz used <a href="https://github.com/mrexodia/ida-pro-mcp">IDA MCP</a>, an AI-augmented reverse engineering setup, to analyze GitHub&#8217;s compiled binaries and reconstruct internal protocols at a speed that wasn&#8217;t economical before. </p><p><strong>Dig Deeper:</strong> <a href="https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854">Wiz technical writeup</a> | <a href="https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/">GitHub&#8217;s response post</a> (authored by GH CISO)</p><div><hr></div><h4><strong><a href="https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-astrix-security">Cisco to acquire Astrix Security for $400M, betting on non-human identity</a></strong></h4><p>Cisco announced intent to acquire <a href="https://astrix.security/">Astrix Security</a> for roughly <strong>$400M</strong>, <a href="https://www.calcalistech.com/ctechnews/article/dy5obf581">per Calcalist</a>.  </p><p>Founded in 2021 by <strong>Alon Jackson</strong> and <strong>Idan Gour</strong> (both Unit 8200), Astrix raised <strong>$85M</strong> total across rounds led by Menlo Ventures&#8217; Anthology Fund (with Anthropic), Bessemer, CRV, Workday Ventures, and F2. </p><p>~5x return on $85M raised is pretty good for Astrix and sets the bar for other NHI platforms like <a href="https://www.oasis.security/">Oasis</a>, <a href="https://www.token.security/">Token</a>, and <a href="https://entro.security/">Entro</a> etc. </p><p>Capabilities will fold into Cisco Identity Intelligence and extend into Duo and Secure Access, with detection signals piping into Splunk.</p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><p><strong><a href="https://www.securityweek.com/openai-rolls-out-advanced-security-for-chatgpt-accounts/">OpenAI ships passkey-only Advanced Account Security for ChatGPT and Codex</a></strong></p><p>OpenAI <a href="https://openai.com/index/advanced-account-security/">rolled out</a> opt-in Advanced Account Security for ChatGPT and Codex accounts, requiring passkeys or FIDO hardware keys and disabling password login, email, and SMS recovery. </p><p>Account recovery falls entirely on the user; OpenAI support cannot assist. Conversations are auto-excluded from training. Partnered with Yubico on discounted YubiKey bundles. Members of OpenAI&#8217;s <a href="https://openai.com/index/trusted-access-for-cyber/">Trusted Access for Cyber</a> program must enable it by <strong>June 1</strong>. Not available for ChatGPT Enterprise or managed accounts yet.</p><div><hr></div><p><strong>More AI security news</strong> </p><ul><li><p><a href="https://aws.amazon.com/blogs/security/introducing-ai-traffic-analysis-dashboards-for-aws-waf/">Introducing AI traffic analysis dashboards for AWS WAF</a></p></li><li><p><a href="https://securitybrief.com.au/story/cyberhaven-expands-ai-security-to-track-shadow-agents">Cyberhaven expands AI security to track shadow agents</a></p></li><li><p><a href="https://www.msspalert.com/brief/armadin-expands-ai-attack-validation-push">Armadin Expands AI Attack Validation Push</a></p></li><li><p><a href="https://www.paloaltonetworks.com/blog/2026/04/unit-42-frontier-ai-defense-armadin-partnership/">Unit 42 Expands Frontier AI Defense with Armadin Partnership</a></p></li></ul><div><hr></div><h2><strong>Detection Engineering</strong></h2><p><strong><a href="https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/aadgraphactivitylogs">Azure AD Graph Activity Logs land in Sentinel, closing a long-standing detection gap</a></strong></p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/Cyb3rMonk/status/2051407407461326963&quot;,&quot;full_text&quot;:&quot;Historical moment for red and blue teamers &#128737;&#65039;\nAzure Active Directory Graph Activity logs are now available&#129395; &quot;,&quot;username&quot;:&quot;Cyb3rMonk&quot;,&quot;name&quot;:&quot;Mehmet Ergene&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1936122496513687552/QuTVhtfY_normal.jpg&quot;,&quot;date&quot;:&quot;2026-05-04T21:03:33.000Z&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/HHgPf1oWQAA7Z-F.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/hesRc4ci0Y&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:2,&quot;retweet_count&quot;:42,&quot;like_count&quot;:252,&quot;impression_count&quot;:29972,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;video_preview_media_key&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>Microsoft made the <strong>AADGraphActivityLogs</strong> table queryable in Azure Monitor and Sentinel, giving defenders visibility into the legacy Azure AD Graph API (<code>graph.windows.net</code>) for the first time. The modern <code>graph.microsoft.com</code> endpoint has had a <a href="https://learn.microsoft.com/en-us/graph/microsoft-graph-activity-logs-overview">logging table</a> since 2023, but the deprecated legacy API stayed active and unlogged, a gap <a href="https://cloudbrothers.info/en/detect-threats-microsoft-graph-logs-part-1/">Cloudbrothers documented</a> as the reason offensive tooling evaded detection. What&#8217;s now detectable:</p><ul><li><p><strong><a href="https://aadinternals.com/">AADInternals</a></strong>-based recon and persistence</p></li><li><p><strong><a href="https://www.pingcastle.com/">Ping Castle</a></strong> assessment scans</p></li><li><p>Any custom tooling targeting the legacy endpoint</p></li><li><p>Historical Azure AD Graph activity once ingestion is enabled</p></li></ul><p>A significant win for blue teams. The &#8220;use the deprecated API to evade logging&#8221; technique has been documented and used in the wild for years, and any tenant running detections was effectively blind to a chunk of legitimate-looking reconnaissance. The interesting question for red teamers: what&#8217;s the next evasion path now that this one is closed. </p><p>Expect new detection content from the usual Sentinel community shops within weeks. </p><div><hr></div><h2><strong>Governance, Risk, and Compliance</strong></h2><p><strong><a href="https://www.rippling.com/blog/get-soc-2-ready-with-rippling-no-assembly-required">Rippling launches Automated Compliance for SOC 2, brings in AJ Yawn</a></strong></p><p>Rippling rolled out Rippling Automated Compliance on April 28, leveraging its position as the system of record for HR, IT, identity, and device management to auto-collect SOC 2 evidence. Available now for SOC 2 Type 1 and Type 2, with more frameworks on the way. Connected CPA firm and pen testing partners are wired into the audit workflow. </p><p>Compliance veteran <a href="https://www.linkedin.com/in/ajyawn/">AJ Yawn</a>, founder of the <a href="https://grcengclub.com/">GRC Engineering Club</a> and one of the most credible voices in GRC engineering, also <a href="https://www.linkedin.com/posts/ajyawn_rippling-activity-7454922859925209088-6LHb">joined the team</a> around the same time this was announced. </p><p>Rippling is right that GRC tools have been reporting layers on top of systems they don&#8217;t control, and being the underlying system flips the economics. Bringing Yawn in lends real practitioner credibility and Rippling has a true moat as they control much of the underlying surface that compliance probes for anyways. Rippling has a massive customer base so the upsell opp. is real. </p><div><hr></div><h2><strong>Security Operations</strong></h2><p><strong><a href="https://www.msspalert.com/brief/crowdstrike-adds-threat-hunting-for-microsoft-defender">CrowdStrike extends OverWatch managed threat hunting to Microsoft Defender</a></strong></p><p>CrowdStrike <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-launches-falcon-overwatch-for-defender/">launched</a> Falcon OverWatch for Defender, bringing its threat hunting service to organizations running Microsoft Defender for endpoint without requiring an EDR rip-and-replace. The service layers continuous human-led hunting, adversary intelligence (CrowdStrike tracks 280+ tracked groups), and response guidance on top of Defender&#8217;s native detections. Builds on March&#8217;s Falcon Next-Gen SIEM for Defender integration.</p><p>Smart land-grab. Seems like CrowdStrike and MSFT are deepening their partnership which is ultimately, what&#8217;s best for both customer bases.</p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[TCP 130: Linux 0-day, Checkmarx leak, ShinyHunters double-hit, Google and Wiz go all in, and more ]]></title><description><![CDATA[96GB dumped, CVSS 7.8 across 'every' linux distro, 17.7M records claimed, and three new SecOps agents from Google]]></description><link>https://www.cybersecuritypulse.net/p/tcp-130-checkmarx-on-dark-web-linux</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/tcp-130-checkmarx-on-dark-web-linux</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Thu, 30 Apr 2026 13:23:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HoFR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer in big tech. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/tcp-130-checkmarx-on-dark-web-linux?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/tcp-130-checkmarx-on-dark-web-linux?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HoFR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HoFR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png 424w, https://substackcdn.com/image/fetch/$s_!HoFR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png 848w, https://substackcdn.com/image/fetch/$s_!HoFR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png 1272w, https://substackcdn.com/image/fetch/$s_!HoFR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HoFR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png" width="1400" height="1010" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1010,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2971568,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/195884741?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HoFR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png 424w, https://substackcdn.com/image/fetch/$s_!HoFR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png 848w, https://substackcdn.com/image/fetch/$s_!HoFR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png 1272w, https://substackcdn.com/image/fetch/$s_!HoFR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd823c31f-50d5-4336-ba8f-ed378f07abc1_1400x1010.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><h4><strong>Ship Fast. Sleep Well. </strong></h4><h4><strong>The 2026 Identity Governance Playbook Is Here.</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jaJY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jaJY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png 424w, https://substackcdn.com/image/fetch/$s_!jaJY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png 848w, https://substackcdn.com/image/fetch/$s_!jaJY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png 1272w, https://substackcdn.com/image/fetch/$s_!jaJY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jaJY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png" width="531" height="82.62700228832952" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2920a7b-5247-4532-9b02-7260c04909f6_437x68.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:68,&quot;width&quot;:437,&quot;resizeWidth&quot;:531,&quot;bytes&quot;:19437,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/195884741?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jaJY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png 424w, https://substackcdn.com/image/fetch/$s_!jaJY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png 848w, https://substackcdn.com/image/fetch/$s_!jaJY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png 1272w, https://substackcdn.com/image/fetch/$s_!jaJY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2920a7b-5247-4532-9b02-7260c04909f6_437x68.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>Speed and security don't have to be a tradeoff. The security teams ready for AI have automated what used to take weeks: access approvals, lifecycle management, unused access removal and built a unified identity graph ready for AI agents. Read Opal's 2026 report to learn how they did it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=tcp&amp;utm_medium=cpc&amp;utm_campaign=state-of-identity&amp;utm_term=ai-access&amp;utm_content=primary&amp;hstk_campaign=40445781&amp;hstk_network=tcp&amp;hsa_acc=45127704&amp;hsa_cam=40445781&amp;hsa_net=tcp&quot;,&quot;text&quot;:&quot;Get the report&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=tcp&amp;utm_medium=cpc&amp;utm_campaign=state-of-identity&amp;utm_term=ai-access&amp;utm_content=primary&amp;hstk_campaign=40445781&amp;hstk_network=tcp&amp;hsa_acc=45127704&amp;hsa_cam=40445781&amp;hsa_net=tcp"><span>Get the report</span></a></p></div><p>Howdy &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re reading from! <br><br>This week has been quite eventful, literally. I had the opportunity to attend <a href="https://intezer.com/ai-soc-live-nasdaq/">Intezer&#8217;s Nasdaq event</a> in NYC and it was pretty insightful. F500 CISOs and security leaders shared how they&#8217;re thinking about AI, Mythos-level threats, how the buyer-vendor relationship has evolved, reporting up to the board and more. I have a full write-up coming out next Tuesday for this so I won&#8217;t spoil it all here. However, huge kudos to the Intezer GTM team for pulling off such a stellar event. <br><br>Aside from that, a quick heads up that <a href="https://defcon.org/html/defcon-34/dc-34-cfp.html">DEF CON main stage Call for Papers, Labs, Workshops, Music</a> and more closes today at 8PM ET. I think DC village CFPs closes a couple weeks later but always good to double check! </p><p>Also, a quick plug for <a href="https://www.monad.com/blog/introducing-storage-cost-analysis">this cool cost savings analysis feature</a> that my team at Monad shipped. </p><p>Lastly, the past 2 TCP issues have gone out on Thursdays. We&#8217;ll be back to our regularly scheduled programming next Wednesday. <br><br>Cool, let&#8217;s dive in! </p><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#129656; <strong><a href="https://www.bleepingcomputer.com/news/security/checkmarx-confirms-lapsus-hackers-leaked-its-stolen-github-data/">Checkmarx dump hits dark web</a></strong> &#8212; Lapsus$ posts 96GB archive after TeamPCP pivoted from Trivy &#8594; Checkmarx GitHub; 30-day persistence despite cred revocation</p></li><li><p>&#9729;&#65039; <strong><a href="https://siliconangle.com/2026/04/22/google-cloud-next-new-security-operations-agents-wiz-integrations-agent-governance-tools/">Google Cloud Next &#8216;26 ships agent governance</a></strong> &#8212; Three new SecOps agents, Wiz scanning all the things, Gemini Enterprise Agent Platform, Q1 earnings smoked</p></li><li><p>&#128039; <strong><a href="https://copy.fail/">Copy Fail roots every Linux since 2017</a></strong> &#8212; 732-byte Python script, CVSS 7.8, container escape primitive; not as critical as alarmist would have you think</p></li><li><p>&#129658; <strong><a href="https://www.theregister.com/2026/04/24/shinyhunters_claim_cruise_giant_carnivals/">ShinyHunters claims Medtronic and Carnival</a></strong> &#8212; 9M+ Medtronic records, 8.7M Carnival/Holland America loyalty records; both vectors still undisclosed</p></li><li><p>&#128202; <strong><a href="https://www.securityweek.com/cyber-insurance-data-gives-cisos-new-ammo-for-budget-talks/">Cyber insurance data is the real CISO ammo</a></strong> &#8212; Misconfigured MFA = 26% of losses, ransomware = 90% of total loss from 12% of claims. Industry needs more 3rd party data like this </p></li><li><p>&#128142; <strong><a href="https://www.opal.dev/resource-center/identity-governance-report-2026-ai-access?utm_source=tcp&amp;utm_medium=cpc&amp;utm_campaign=state-of-identity&amp;utm_term=ai-access&amp;utm_content=primary&amp;hstk_campaign=40445781&amp;hstk_network=tcp&amp;hsa_acc=45127704&amp;hsa_cam=40445781&amp;hsa_net=tcp">Opal's 2026 Identity Governance Report</a></strong> &#8212; Auto-granted access goes unused 50% of the time, NHIs outnumber humans 5:1, and 72% of CISOs say authz is their biggest AI blocker</p></li><li><p>&#129302; <strong><a href="url">Amazon CISO details RuleForge detection-rule pipeline</a></strong> &#8212; Bedrock generator agent proposes rules, separate judge model scores sensitivity vs specificity, MadPot honeypots validate before merge</p></li></ul><p><strong>Plus:</strong> Copperhelm exits stealth with $7M, Sublime Security goes 100% channel-led, and Silverfort acquires Fabrix Security ($8M raised to date) and more. &#128071;</p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><strong><a href="https://www.bleepingcomputer.com/news/security/checkmarx-confirms-lapsus-hackers-leaked-its-stolen-github-data/">Checkmarx debacle: AppSec vendor caught in the Trivy/TeamPCP supply chain blast radius</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!r51m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!r51m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png 424w, https://substackcdn.com/image/fetch/$s_!r51m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png 848w, https://substackcdn.com/image/fetch/$s_!r51m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png 1272w, https://substackcdn.com/image/fetch/$s_!r51m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!r51m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png" width="751" height="582" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:582,&quot;width&quot;:751,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78777,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/195884741?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!r51m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png 424w, https://substackcdn.com/image/fetch/$s_!r51m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png 848w, https://substackcdn.com/image/fetch/$s_!r51m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png 1272w, https://substackcdn.com/image/fetch/$s_!r51m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe14bd1c0-e7b3-4ec0-9f53-de95c067aedf_751x582.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://checkmarx.com/">Checkmarx</a> (the AppSec vendor who markets itself as covering 40% of the Fortune 100, including Apple, Salesforce, Walmart, Visa, Citigroup, Ford, Siemens, Airbus, Adidas, and SAP) confirmed that Lapsus$ dumped a 96GB archive of its data (source code, employee database, API keys, MongoDB and MySQL creds) on dark web and clearnet portals.</p><p>The access vector: stolen creds from the <a href="https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/">March 23 Trivy supply-chain compromise</a> attributed to <strong>TeamPCP</strong>, which gave attackers the keys into Checkmarx&#8217;s GitHub.</p><p><strong>Timeline</strong></p><ul><li><p><strong>Late Feb:</strong> TeamPCP compromises <strong>Trivy</strong> (Aqua Security&#8217;s open source vuln scanner)</p></li><li><p><strong>March 16:</strong> Credential-stealing malware injected into Trivy, harvesting CI/CD secrets, cloud creds, SSH keys, and K8s configs from downstream users</p></li><li><p><strong>March 23:</strong> Attackers use stolen Trivy creds to access Checkmarx GitHub</p></li><li><p><strong>March 30:</strong> Data exfil from Checkmarx GitHub</p></li><li><p><strong>April 22:</strong> Despite cred revocation and outbound blocks, attackers come back and poison the <strong>KICS</strong> Docker image, two <strong>VS Code/Open VSX extensions</strong>, and a <strong>GitHub Actions workflow</strong></p></li><li><p><strong>Late April:</strong> Lapsus$ lists Checkmarx on its leak site and dumps the archive</p></li></ul><p><strong>Blast radius</strong></p><p>Same campaign also briefly compromised the <strong><a href="https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/">Bitwarden CLI npm package</a></strong> (@bitwarden/cli 2026.4.0), live for ~90 minutes, hoovering AWS keys, GitHub tokens, and SSH creds. Bitwarden has 10M+ users, 50K+ business customers. AI startup <strong>Mercor</strong> also got pulled in via the related <strong>LiteLLM</strong> compromise; Lapsus$ offered 4TB including 939GB of Mercor source code for sale.</p><p>This is the X-factor with software supply chain compromises. There&#8217;s a super long tail of downstream impact which may last months to years.</p><div><hr></div><h4><a href="https://cloud.google.com/blog/products/identity-security/next26-redefining-security-for-the-ai-era-with-google-cloud-and-wiz">Google Cloud Next: Wiz everywhere, agents for everything, and stellar Q1 &#8216;26 Performance</a></h4><p>Google <a href="https://www.googlecloudevents.com/next-vegas">Cloud Next &#8216;26</a> came with a slew of security updates: <strong>three new SecOps agents</strong>, <strong><a href="https://www.wiz.io/blog/wiz-at-google-cloud-next">Wiz</a></strong> sprawling across every rival cloud and agent platform, and a new <strong><a href="https://www.theregister.com/2026/04/22/google_enterprise/">Gemini Enterprise Agent Platform</a></strong> with governance bolted on.</p><p><strong>SecOps agents</strong></p><p>The existing <a href="https://siliconangle.com/2026/04/22/google-cloud-next-new-security-operations-agents-wiz-integrations-agent-governance-tools/">Triage and Investigation agent</a> (which Google says chewed through <strong>5M+ alerts</strong> last year, taking 30-min triage down to 60 seconds) gets three new siblings in preview:</p><ol><li><p><strong>Threat Hunting agent to chase novel TTPs and stealthy behavior</strong></p></li><li><p><strong>Detection Engineering agent to find detection gaps and write rules for them</strong></p></li><li><p><strong>Third-Party Context agent to pull external context into analyst workflows</strong></p></li></ol><p>Remote <a href="https://siliconangle.com/2026/04/22/google-cloud-next-new-security-operations-agents-wiz-integrations-agent-governance-tools/">MCP server</a> support hit GA, dark web intel went into preview in Google Threat Intelligence (Google claims 98% accuracy on millions of daily events, take that with the usual grain of salt), and Darktrace, Gigamon, and SAP join as new partner integrations.</p><p><strong>Wiz securing all the things, everywhere</strong></p><p><strong><a href="https://www.wiz.io/blog/wiz-at-google-cloud-next">Wiz</a></strong> now scans Databricks and the agent stacks of basically every competitor: <strong>AWS AgentCore, Azure Copilot Studio, Salesforce Agentforce</strong>, plus Google&#8217;s own Gemini platform. Apigee, <a href="https://www.wiz.io/blog/wiz-at-google-cloud-next">Cloudflare AI Security for Apps</a>, and Vercel got integrations too.</p><p>New AI-SDLC capabilities: a <a href="https://www.wiz.io/blog/wiz-at-google-cloud-next">Lovable</a> integration that runs Wiz scans inside the vibe-coding platform, inline AI security hooks for IDEs and agent workflows that scan prompts and generated code pre-commit, and a dynamic <strong>AI-BOM</strong> to surface shadow AI tools across an environment.</p><p><strong>Agent identity, fraud, Chrome</strong></p><p><a href="https://www.theregister.com/2026/04/22/google_enterprise/">Gemini Enterprise Agent Platform</a> ships with <strong>Agent Identity</strong> (cryptographic IDs, scoped delegation, audit trails per action), <strong>Agent Gateway</strong> (policy enforcement aware of MCP and A2A, plus prompt injection, tool poisoning, and data leakage protections), and <strong>Model Armor</strong> for runtime model/agent protection now integrating with Agent Gateway, Agent Runtime, and LangChain. reCAPTCHA got rebranded to <strong>Google Cloud Fraud Defense</strong> (GA), with human/bot/agent distinction coming in preview. Chrome Enterprise gets an AI-aware threat detection extension plus shadow AI reporting for unsanctioned web AI apps.</p><p>Also key to note that <span class="cashtag-wrap" data-attrs="{&quot;symbol&quot;:&quot;$GOOGL&quot;}" data-component-name="CashtagToDOM"></span>  <a href="https://finance.yahoo.com/sectors/technology/article/alphabet-tops-q1-estimates-on-strong-google-cloud-growth-212244133.html?guccounter=1">absolutely smoked Q1 2026 earnings</a> and I&#8217;d imagine Wiz will be a great add-on to their bottom line. Excited to see how it all plays out! </p><div><hr></div><h4><a href="https://copy.fail/">Copy Fail (CVE-2026-31431): one logic bug, every Linux distro since 2017</a></h4><p>Researchers at Theori/Xint disclosed <strong><a href="https://copy.fail/">Copy Fail</a></strong>, a Linux kernel LPE (CVSS <strong>7.8</strong>) that lets an unprivileged local user write 4 controlled bytes into the page cache of any readable file and pop a root shell via a <strong>732-byte Python script</strong> that works unmodified across Ubuntu, Amazon Linux, RHEL, and SUSE. The bug is a logic flaw in <code>algif_aead</code> introduced by a <a href="https://github.com/torvalds/linux/commit/72548b093ee3">2017 in-place optimization commit</a>, chained through <code>AF_ALG</code> and <code>splice()</code>. </p><p>Critically, it&#8217;s <strong>not remotely exploitable</strong> by itself, but the same primitive crosses container and tenant boundaries via the shared page cache, which makes it serious for K8s nodes, CI runners (GitHub Actions self-hosted, GitLab, Jenkins), shell-as-a-service hosts, and any SaaS running tenant code. <strong>Theori/Xint surfaced it with their AI code-auditing tool and is using the disclosure page as a product showcase, so calibrate the marketing accordingly, but the bug itself is real and the PoC is public on GitHub.</strong></p><p><strong>Where to follow:</strong> the <a href="https://copy.fail/">copy.fail landing page</a> for the technical writeup and guidance on how to patch, the <a href="https://github.com/theori-io/copy-fail-CVE-2026-31431">Theori GitHub issue tracker</a> for ongoing distro confirmations, and your distro&#8217;s advisory page (<a href="https://ubuntu.com/security/CVE-2026-31431">Ubuntu</a>, <a href="https://access.redhat.com/security/cve/cve-2026-31431">RHEL</a>, <a href="https://www.suse.com/security/cve/CVE-2026-31431.html">SUSE</a>, <a href="https://explore.alas.aws.amazon.com/CVE-2026-31431.html">Amazon Linux</a>, <a href="https://security-tracker.debian.org/tracker/CVE-2026-31431">Debian</a>).</p><div><hr></div><h4><strong><a href="https://www.infosecurity-magazine.com/news/medtronic-data-breach-shinyhunters/">ShinyHunters on a tear: Medtronic and Carnival both hit</a></strong></h4><p><strong><a href="https://www.infosecurity-magazine.com/news/shinyhunters-hundreds-websites/">ShinyHunters</a></strong> claimed two big names back to back this week: medical device giant <strong><a href="https://www.infosecurity-magazine.com/news/medtronic-data-breach-shinyhunters/">Medtronic</a></strong> and the world&#8217;s largest cruise operator, <strong><a href="https://www.theregister.com/2026/04/24/shinyhunters_claim_cruise_giant_carnivals/">Carnival Corporation</a></strong>.</p><p><strong>Medtronic</strong></p><p>Medtronic confirmed a data security incident affecting corporate IT after ShinyHunters listed it on its leak site in mid-April, claiming <strong>9M+ records</strong> of personal info plus piles of internal corporate data. Medtronic has not validated the numbers and stresses that hospital networks running its devices are managed independently and were not exposed. ShinyHunters set a ransom deadline, then <a href="https://www.infosecurity-magazine.com/news/medtronic-data-breach-shinyhunters/">pulled the listing</a>, which usually signals either negotiation or whatever face-saving move keeps the leak tab clean.</p><p><strong>Carnival</strong></p><p>Two days later, Have I Been Pwned <a href="https://haveibeenpwned.com/Breach/Carnival">flagged what it described</a> as <strong>8.7M records</strong> (with <strong>7.5M unique email addresses</strong>) tied to the Mariner Society loyalty program run by Holland America, a Carnival subsidiary. Exposed fields: names, DOBs, genders, and membership status. Carnival&#8217;s framing: a phishing attack against a single user account, scope still being assessed. ShinyHunters posted on its leak site that <em>&#8220;the company failed to reach an agreement with us despite our incredible patience,&#8221;</em> adding <em>&#8220;they don&#8217;t care.&#8221;</em></p><p><strong>How did they get in?</strong></p><p>Honestly, nobody&#8217;s saying. Medtronic&#8217;s disclosure is vague enough to drive a truck through (&#8221;an unauthorized party accessed certain internal systems&#8221;). Carnival&#8217;s only attributed vector is a single phished user account, which doesn&#8217;t square with terabytes of data unless that account had way more access than it should have. Neither side has named a SaaS platform, an initial access broker, or any IOCs</p><div><hr></div><h4><strong><a href="https://www.securityweek.com/cyber-insurance-data-gives-cisos-new-ammo-for-budget-talks/">Cyber insurance data gives CISOs new ammo for budget talks</a></strong></h4><p>Misconfigured MFA drives more financial loss than any other single control failure, and ransomware drives 90% of total loss despite being only 12% of claims. The industry needs more of this kind of empirical claims data; vendor &#8220;state of X&#8221; reports don&#8217;t cut it for CISOs trying to justify budget against actual loss attribution.</p><p>New analysis from cyber insurer <strong>Resilience</strong>, drawn from its manufacturing claims portfolio (March 2021 to February 2026) and synthesized with IBM X-Force and KELA data. <strong>Misconfigured MFA</strong> accounted for <strong>26% of losses</strong>, software vuln exploits 13%, and transfer fraud plus BEC tied to phishing and credential theft made up 30% of claims.</p><p>More insurers and ISACs should be publishing data like this. Claims data beats survey-based findings or vendor-funded research every time.</p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>Application Security</strong></h3><p><strong><a href="https://www.wiz.io/blog/wiz-code-week-recap">Wiz Code Week recap: visibility, IDE guardrails, and CI/CD as a first-class asset</a></strong></p><p>Wiz ran Code Week in parallel with Google Cloud Next. Code Week is where they release a bunch of dev and AppSec-related features and announcements. This time around, they launched an <strong>AI-BOM</strong> that auto-inventories AI frameworks, models, and IDE extensions (Gemini Code Assist, Copilot, Cursor), plus an <strong>IaC Inventory</strong> that maps code-to-cloud blast radius.</p><p>New <strong>Wiz Code plugins</strong> for Claude Code and Cursor embed pre-commit hooks for hardcoded secrets, IaC misconfigs, and vulns, with new <strong>SAST rules</strong> mapped to the OWASP Top 10 for LLM and Agentic Applications.</p><p>Pipeline-side, Wiz now models <strong>CI/CD as first-class assets</strong> on its Security Graph, surfacing dangerous trigger configs, excessive perms, and prompt injection risks from AI agents, plus a <strong>CI-BOM</strong> for third-party action inventory.</p><div><hr></div><h2><strong>Cloud Security </strong></h2><p><strong><a href="https://www.securityweek.com/copperhelm-raises-7-million-for-agentic-cloud-security-platform/">Copperhelm exits stealth with $7M for agentic cloud security platform</a></strong></p><p><strong>Copperhelm</strong> emerged from stealth with <strong>$7M</strong> in seed led by <strong>TLV Partners</strong> (with toDay Ventures, ICON, and SaaS Ventures Israel), pitching AI agents that autonomously monitor cloud environments, investigate threats, and execute remediation in real time while keeping humans in control.</p><p>Auto-remediation is the next frontier. Dozens of vendors going after it meanwhile security leaders remain skeptical/hesitant for the more critical stuff. Let&#8217;s see.</p><div><hr></div><h2><strong>Email Security</strong></h2><p><strong><a href="https://martechseries.com/content/programmatic-email/sublime-security-launches-channel-partner-program-to-redefine-email-security/">Sublime Security goes 100% channel-led with new partner program</a></strong></p><p>Sublime Security launched a formal channel partner program and is now operating as a 100% channel-led company.</p><p>Core elements of a partner-first GTM motion are recurring margins with deal protection, dedicated partner sales managers and SEs, technical enablement and accreditation, and co-marketing support. Wiz did the same and <a href="https://www.cybersecuritypulse.net/p/wizs-32b-sales-engine-from-founder">I covered it here.</a> Channel-led sales is cool because some MSSPs and VARs have been around for decades and know where the bodies are buried regarding legacy, clunky tech and can accelerate displacement.</p><div><hr></div><h2><strong>Identity and Access Management</strong></h2><p><strong><a href="https://siliconangle.com/2026/04/28/silverfort-acquires-fabrix-security-bring-ai-decisioning-runtime-access-control/">Silverfort acquires Fabrix Security to add AI-native runtime access decisioning</a></strong></p><p>Silverfort acquired Fabrix Security, an AI-native identity security startup founded in 2024, for an undisclosed price.</p><p>Fabrix had raised <strong>$8M</strong> to date. The product runs an identity knowledge graph paired with AI agents that handle authorization decisions, just-in-time access requests, and lifecycle management for human, non-human, and agentic identities (service accounts, API keys, bots, AI agents).</p><div><hr></div><h2><strong>Vulnerability Management</strong></h2><p><strong><a href="https://www.amazon.science/blog/how-amazon-uses-agentic-ai-for-vulnerability-detection-at-global-scale">Amazon&#8217;s RuleForge: agentic AI generates production detection rules</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lVtL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lVtL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png 424w, https://substackcdn.com/image/fetch/$s_!lVtL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png 848w, https://substackcdn.com/image/fetch/$s_!lVtL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png 1272w, https://substackcdn.com/image/fetch/$s_!lVtL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lVtL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;generation2.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="generation2.jpg" title="generation2.jpg" srcset="https://substackcdn.com/image/fetch/$s_!lVtL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png 424w, https://substackcdn.com/image/fetch/$s_!lVtL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png 848w, https://substackcdn.com/image/fetch/$s_!lVtL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png 1272w, https://substackcdn.com/image/fetch/$s_!lVtL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05680dab-0a81-465d-ba3b-afcbd0ef3b98_1200x675.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Amazon CISO, CJ Moses recently wrote a blog about <strong>RuleForge</strong>, an internal agentic AI system that turns CVE proof-of-concept exploits into production-ready detection rules 336% faster than manual analyst workflows, with humans in the loop for final approval.</p><p>Architecture: a generation agent on AWS Fargate + Bedrock proposes multiple candidate rules in parallel; a separate judge model scores each on sensitivity (will this miss exploits?) and specificity (does it target the vuln or a correlated feature?).</p><p>Rules then run through synthetic testing and validation against MadPot honeypot traffic before code review.</p><p>The separation of generation from evaluation reduced false positives by <strong>67%</strong> while preserving true positives, and Amazon credits negative-phrased prompts (&#8221;what&#8217;s the probability this rule fails?&#8221;) for better LLM calibration on security tasks.</p><p>This is one of the more honest hyperscaler writeups on applied AI for security stuff, and the architectural lessons (judge != generator, decompose the workflow, keep humans gating prod) are directly transferable to anyone building internal AI-based security tooling.</p><div><hr></div><p>More vulnerability management news: </p><ul><li><p><a href="https://www.msspalert.com/brief/hackerone-launches-h1-validation-as-ai-drives-a-surge-in-vulnerability-discovery">HackerOne Launches h1 Validation as AI Drives a Surge in Vulnerability Discovery</a></p></li><li><p><a href="https://www.securityweek.com/rilian-raises-17-5-million-for-ai-native-security-orchestration/">Rilian Raises $17.5 Million for AI-Native Security Orchestration</a></p></li></ul><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item><item><title><![CDATA[TCP 129: Vercel Breach, Mythos Leak, the SIEM arms race, and 3 Defender 0 days]]></title><description><![CDATA[OAuth grant abuse, leaked models, and $89M chasing the SIEM of the future]]></description><link>https://www.cybersecuritypulse.net/p/tcp-129-vercel-breach-mythos-leak</link><guid isPermaLink="false">https://www.cybersecuritypulse.net/p/tcp-129-vercel-breach-mythos-leak</guid><dc:creator><![CDATA[Darwin Salazar]]></dc:creator><pubDate>Thu, 23 Apr 2026 12:49:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!G3q5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Welcome to <strong>The Cybersecurity Pulse (TCP)</strong>! I&#8217;m Darwin Salazar, Head of Growth at <strong><a href="https://www.monad.com/">Monad</a></strong> and former detection engineer in big tech. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! &#128231;</em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/tcp-129-vercel-breach-mythos-leak?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/tcp-129-vercel-breach-mythos-leak?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G3q5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G3q5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!G3q5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!G3q5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!G3q5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G3q5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3346248,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/194993129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!G3q5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png 424w, https://substackcdn.com/image/fetch/$s_!G3q5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png 848w, https://substackcdn.com/image/fetch/$s_!G3q5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png 1272w, https://substackcdn.com/image/fetch/$s_!G3q5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53b09dfb-2dfb-40a9-af96-35d82c177deb_1800x1300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="pullquote"><h4><strong>AI signals in email attacks: Boosting detection and threat hunting</strong></h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1QkB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1QkB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png 424w, https://substackcdn.com/image/fetch/$s_!1QkB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png 848w, https://substackcdn.com/image/fetch/$s_!1QkB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png 1272w, https://substackcdn.com/image/fetch/$s_!1QkB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1QkB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png" width="408" height="87.65217391304348" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:168,&quot;width&quot;:782,&quot;resizeWidth&quot;:408,&quot;bytes&quot;:16869,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/194993129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1QkB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png 424w, https://substackcdn.com/image/fetch/$s_!1QkB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png 848w, https://substackcdn.com/image/fetch/$s_!1QkB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png 1272w, https://substackcdn.com/image/fetch/$s_!1QkB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a666bc-f612-4038-80fc-96bb6c9f1cb8_782x168.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><p>Most AI &#8220;tells&#8221; in email are noisy and unreliable on their own. But used correctly, they can still strengthen detections and improve threat hunting.</p><p>In Sublime Security&#8217;s upcoming webinar, we break down which AI signals actually work, how to apply signal stacking, and where these approaches fail. See real examples and a practical framework you can use immediately.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://sublime.security/events/ai-signals-in-email-attacks/?utm_source=cybersecuritypulse&amp;utm_medium=third-party&amp;utm_campaign=webinar&quot;,&quot;text&quot;:&quot;Register now, watch anytime&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://sublime.security/events/ai-signals-in-email-attacks/?utm_source=cybersecuritypulse&amp;utm_medium=third-party&amp;utm_campaign=webinar"><span>Register now, watch anytime</span></a></p></div><p>Howdy &#128075; - Hope you&#8217;re having a great week wherever you&#8217;re tuning in from! </p><p>This has been a wild week. Anthropic&#8217;s Mythos model apparently accessed by a unauthorized 3rd party, Vercel breached via 3rd party OAuth abuse, Lovable exposure kerfuffle, 3 0-days found in MSFT Defender and security stocks rebound. And of course, there&#8217;s more marinating in the background (case in point: <a href="https://www.businesswire.com/news/home/20260423988692/en/Cyera-Acquires-Ryft-to-Extend-its-Agentic-AI-Security-Platform">Cyera announces acq. of Ryft</a> just as I was about to press &#8216;send&#8217; &#128579;). </p><p>Before we dive in, two plugs: </p><ul><li><p>If you&#8217;re a security operator in NYC, come hang out this upcoming Monday (Apr. 27th) at <a href="https://intezer.com/ai-soc-live-nasdaq/">this live show I&#8217;m co-hosting with Intezer at the Nasdaq</a>. Security leaders from Salesforce, Oscar Health, and many highly regarded folks you probably know. Truly a can&#8217;t miss event! </p></li><li><p>I wrote a thing on the contents of and detection opportunities for OpenAI Enterprise Audit Logs. <a href="https://www.monad.com/blog/openai-enterprise-audit-log-detections">Read it here.</a></p></li></ul><p>Cool. Now let's get into it! </p><div><hr></div><h2>TL;DR &#9999;&#65039;</h2><ul><li><p>&#128371;&#65039; <strong><a href="https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims/">Mythos allegedly accessed via third-party vendor</a></strong> &#8212; Discord group reportedly combined contractor creds with URL patterns from the Mercor breach; story still developing</p></li></ul><ul><li><p>&#129512; <strong><a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident">Vercel breached via Context.ai OAuth grant</a></strong> &#8212; Roblox cheat &#8594; Lumma Stealer &#8594; inherited &#8220;Allow All&#8221; token &#8594; prod env vars; campaign bigger than Context.ai alone</p></li><li><p>&#129521; <strong><a href="https://bytebytego.com/">GitHub&#8217;s agentic workflows threat model</a></strong> &#8212; assume the agent is compromised; secretless execution, safe-outputs pipeline, damage-containment over prevention</p></li><li><p>&#129309; <strong><a href="https://www.businesswire.com/news/home/20260423988692/en/Cyera-Acquires-Ryft-to-Extend-its-Agentic-AI-Security-Platform">Cyera acquires Ryft to extend its agentic AI data security play</a></strong> &#8212; Fourth acquisition for Cyera (now $9B val, $1.7B raised); deal size undisclosed</p></li><li><p>&#127917; <strong><a href="https://hackerone.com/">Lovable&#8217;s BOLA + disclosure meltdown</a></strong> &#8212; a few API calls &#8594; any user&#8217;s source code and DB creds; &#8220;fixed&#8221; only for projects created after Nov 2025</p></li><li><p>&#129695; <strong><a href="https://thehackernews.com/2026/04/three-microsoft-defender-zero-days.html">Three MSFT Defender 0-days, two still unpatched</a></strong> &#8212; BlueHammer (<strong>CVE-2026-33825</strong>) patched, RedSun and UnDefend live with public PoCs and in-the-wild exploitation</p></li><li><p>&#128225; <strong><a href="https://www.monad.com/blog/">Detection engineering for OpenAI Enterprise audit logs</a></strong> &#8212; Log set deep dive + 5 detection opportunities</p></li><li><p>&#128231; <strong><a href="https://sublime.security/events/ai-signals-in-email-attacks/?utm_source=cybersecuritypulse&amp;utm_medium=third-party&amp;utm_campaign=webinar">Sublime webinar: AI signals in email attacks</a></strong> &#8212; Alex Orleans and Luke Wescott on threat hunting with AI signals, signal stacking, and where they break; May 13</p></li><li><p>&#127993; <strong><a href="https://www.artemis.security/">Artemis out of stealth with $70M</a></strong> &#8212; AI-native SIEM contender, Felicis-led, angels from Demisto and Abnormal founders</p></li><li><p>&#129517; <strong><a href="https://www.spectrum.security/blog/spectrum-emerges-from-stealth-with-19m-to-reinvent-detection-for-the-ai-era">Spectrum exits stealth with $19M</a></strong> &#8212; AI-powered detection engineering layer on top of existing SIEMs, led by TechOperators and Skinos (Shlomo Kramer&#8217;s new fund)</p></li><li><p>&#128138; <strong><a href="https://www.securityweek.com/capsule-security-emerges-from-stealth-with-7-million-in-funding/">Capsule Security exits stealth with $7M</a></strong> &#8212; runtime trust layer for AI agents; disclosed ShareLeak (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21520">CVE-2026-21520</a>) and PipeLeak alongside launch</p></li></ul><p><strong>Plus:</strong> Aikido ships Endpoint Protection for developer workstations, Microsoft publishes KQL for hunting DPRK IT workers in Workday and DocuSign, Cowbell launches a mid-market policy with affirmative AI and quantum coverage, and more &#128071;</p><div><hr></div><h1><strong>&#9874;&#65039; Picks of the Week &#9874;&#65039;</strong></h1><div><hr></div><h4><a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident">Vercel breached via Context.ai x GWS OAuth grant</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VX3N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VX3N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png 424w, https://substackcdn.com/image/fetch/$s_!VX3N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png 848w, https://substackcdn.com/image/fetch/$s_!VX3N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png 1272w, https://substackcdn.com/image/fetch/$s_!VX3N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VX3N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png" width="1456" height="688" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:688,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:166566,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cybersecuritypulse.net/i/194993129?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VX3N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png 424w, https://substackcdn.com/image/fetch/$s_!VX3N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png 848w, https://substackcdn.com/image/fetch/$s_!VX3N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png 1272w, https://substackcdn.com/image/fetch/$s_!VX3N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451f9e01-8d34-4492-ae18-75add8318418_2200x1040.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A Vercel employee connected Context.ai&#8217;s AI Office Suite to their enterprise Google Workspace and granted &#8220;Allow All&#8221; permissions. When Context.ai got popped (a Context.ai employee caught Lumma Stealer in February 2026 , reportedly from a Roblox cheat download of all things), the attacker inherited that OAuth grant and walked right into Vercel. </p><p>From there they escalated by sifting through environment variables not marked as &#8220;sensitive,&#8221; (&#128532;) which were sitting in plaintext in the dashboard and API. Mandiant is engaged, and Vercel now defaults env vars to sensitive. No npm packages were tampered with, they say.</p><p>Also a ShinyHunters persona is shopping alleged internal data for $2M, but Google TAG&#8217;s Austin Larsen called the claimant &#8220;likely an imposter.&#8221;</p><p>No AI-powered Mythos nuke. Just 3rd party OAuth token grant abuse similar to what happened with <a href="https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift">Salesloft Drift</a>. It&#8217;s exactly what <a href="https://www.jpmorganchase.com/about/technology/blog/open-letter-to-our-suppliers">Pat Opet, CISO @ JP Morgan, warned about almost exactly a year ago</a>.</p><p><strong>Update</strong>: <a href="https://thehackernews.com/2026/04/vercel-finds-more-compromised-accounts.html">Vercel disclosed on April 22</a> that it identified additional compromised accounts from independent prior compromises, and CEO Guillermo Rauch said the threat actor appears to be running a broader token-harvesting campaign beyond Context.ai. Context.ai has deprecated the AI Office Suite entirely.</p><p>HugOps to my friends on the Vercel security team. </p><div><hr></div><h4><a href="https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims/">Mythos allegedly leaked via third-party vendor, story still developing</a></h4><p>Per <strong><a href="https://techcrunch.com/2026/04/21/unauthorized-group-has-gained-access-to-anthropics-exclusive-cyber-tool-mythos-report-claims/">TechCrunch</a></strong>, a group of Discord users claim to have gained unauthorized access to Anthropic&#8217;s Claude Mythos Preview on the same day it was announced, reportedly by combining compromised credentials from a <strong><a href="https://www.cbsnews.com/news/anthropic-investigates-mythos-ai-breach/">third-party contractor</a></strong> with URL naming conventions reconstructed from a <strong><a href="https://www.techradar.com/pro/security/mythos-accessed-by-unauthorized-users-as-anthropic-says-were-investigating-cracks-may-be-showing-in-project-glasswing-as-unknown-users-access-model-via-third-parties">recent data breach at Mercor</a></strong>. <strong><a href="https://www.anthropic.com/">Anthropic</a></strong> confirmed it&#8217;s <a href="https://www.engadget.com/ai/anthropic-is-investigating-unauthorized-access-of-its-mythos-cybersecurity-tool-091017168.html">investigating</a> and said there&#8217;s no evidence its own systems were impacted or that activity extended beyond the vendor environment. </p><p>A ShinyHunters impersonator has since tried to take credit circulating AI-generated screenshots as proof, but security researcher Dominic Alvieri and others <a href="https://cybernews.com/security/anthropic-mythos-ai-unauthorized-access/">quickly called the claim out as fabricated</a>. </p><p>Story is still developing, more to come as Anthropic&#8217;s investigation plays out, but if even part of this holds up it&#8217;s detrimental to the whole walled-off Project Glasswing model. </p><div><hr></div><h4><strong><a href="https://www.spectrum.security/">How Did We Miss This?</a></strong></h4><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;6d3b32d5-b691-401c-8eaf-b38d7cc60d10&quot;,&quot;duration&quot;:null}"></div><p>Every security leader has asked this at some point. Usually after an incident review, usually at 11pm, usually over cold pizza. And the answer is almost always the same: detection gaps nobody had time to map, rules nobody could write fast enough, and coverage that quietly broke weeks ago without firing a single alert. AI-powered attacks are just making that gap harder to ignore.</p><p>Spectrum is built for that exact problem. An AI-powered detection platform that maps your coverage, researches emerging threats, and writes custom, deployment-ready detections against your data, wherever it lives. The stuff your team would write if they had ten more hours in the day.</p><p>Fewer gaps, fewer blind spots, fewer &#8220;how did we miss this&#8221; moments.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.spectrum.security/&quot;,&quot;text&quot;:&quot;Get a demo&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.spectrum.security/"><span>Get a demo</span></a></p><div><hr></div><h4><strong><a href="https://blog.bytebytego.com/p/the-security-architecture-of-github">GitHub&#8217;s security architecture for agentic workflows: assume the agent is compromised</a></strong></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ed83!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ed83!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png 424w, https://substackcdn.com/image/fetch/$s_!Ed83!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png 848w, https://substackcdn.com/image/fetch/$s_!Ed83!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png 1272w, https://substackcdn.com/image/fetch/$s_!Ed83!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ed83!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png" width="1456" height="824" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:824,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;How Agentic Workflow Takes Place \napi-proxy \nCodex token \nDocker container \nagent \nhttp \ngh-aw- \nhttp \ngh-aw- \nstdio \nGitHub \nfirewall \nmcpg \nMCP \nDocker container \nDocker container \nDocker container \nDocker container \nD \nchroot/host \nHost Docker \nSocket \nGitHub PAT &quot;,&quot;title&quot;:&quot;How Agentic Workflow Takes Place \napi-proxy \nCodex token \nDocker container \nagent \nhttp \ngh-aw- \nhttp \ngh-aw- \nstdio \nGitHub \nfirewall \nmcpg \nMCP \nDocker container \nDocker container \nDocker container \nDocker container \nD \nchroot/host \nHost Docker \nSocket \nGitHub PAT &quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="How Agentic Workflow Takes Place 
api-proxy 
Codex token 
Docker container 
agent 
http 
gh-aw- 
http 
gh-aw- 
stdio 
GitHub 
firewall 
mcpg 
MCP 
Docker container 
Docker container 
Docker container 
Docker container 
D 
chroot/host 
Host Docker 
Socket 
GitHub PAT " title="How Agentic Workflow Takes Place 
api-proxy 
Codex token 
Docker container 
agent 
http 
gh-aw- 
http 
gh-aw- 
stdio 
GitHub 
firewall 
mcpg 
MCP 
Docker container 
Docker container 
Docker container 
Docker container 
D 
chroot/host 
Host Docker 
Socket 
GitHub PAT " srcset="https://substackcdn.com/image/fetch/$s_!Ed83!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png 424w, https://substackcdn.com/image/fetch/$s_!Ed83!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png 848w, https://substackcdn.com/image/fetch/$s_!Ed83!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png 1272w, https://substackcdn.com/image/fetch/$s_!Ed83!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1eb4236-0afe-4447-afae-904ab7dd0a42_1456x824.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>GitHub published the threat model and architecture behind their Agentic Workflows, and it&#8217;s the most informative write-up I&#8217;ve seen on running agents in CI/CD pipeline. Shoutout to ByteByteGo for this one. Highly recommend reading if you&#8217;re using AI coding tools in an enterprise environement.</p><p>One core assumption they&#8217;ve made is that the agent will try to read and write state it shouldn&#8217;t, communicate over unintended channels, and abuse legitimate channels. In other words, the agent will misbehave.</p><p>Three-layer architecture (substrate, configuration, planning), with the agent running secretless: MCP auth tokens live in a separate gateway container, LLM tokens in an isolated proxy, all traffic through a dedicated firewall container. Every agent output goes through a deterministic &#8220;safe outputs&#8221; pipeline that checks operations against an allowlist, enforces quantity limits, and scans for leaked secrets before anything gets committed. <br><br>The &#8220;secrets are physically unreachable from the agent&#8221; pattern transfers well beyond GitHub and is a great example of &#8220;contain damage&#8221; vs. &#8220;stop breach&#8221; approach.</p><div><hr></div><h4><strong><a href="https://www.monad.com/blog/openai-enterprise-audit-log-detections">Detection engineering for OpenAI Enterprise audit logs</a></strong> </h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gNRp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gNRp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png 424w, https://substackcdn.com/image/fetch/$s_!gNRp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png 848w, https://substackcdn.com/image/fetch/$s_!gNRp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png 1272w, https://substackcdn.com/image/fetch/$s_!gNRp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gNRp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png" width="1426" height="671" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:671,&quot;width&quot;:1426,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!gNRp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png 424w, https://substackcdn.com/image/fetch/$s_!gNRp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png 848w, https://substackcdn.com/image/fetch/$s_!gNRp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png 1272w, https://substackcdn.com/image/fetch/$s_!gNRp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa0dc8f-1fe4-4cd6-8224-d8c5044b39fd_1426x671.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.monad.com/blog/openai-enterprise-audit-log-detections">I dropped a new post on the Monad blog </a>walking through the 5 detections worth shipping first against OpenAI&#8217;s enterprise audit log (51 event types, immutable once enabled). The starter pack: SCIM disabled, IP allowlist deactivated or broadened, role changes with permissions_added, api_call_logging reduced, and owner-level service account creation. Plus a bonus on external key (BYOK) tampering</p><p>Same playbook as the <a href="https://www.monad.com/blog/detection-engineering-for-claude-code-part-1">Claude Code OTel work</a> we put out earlier this month. As AI platforms become control planes in your stack, their audit logs need to be treated more like cloud or identiy logs. </p><p>If you&#8217;re running enterprise ChatGPT, this blog should serve as a great starting point for understanding the log source + getting some coverage on high signal activity.</p><div><hr></div><h4><a href="https://www.businesswire.com/news/home/20260423988692/en/Cyera-Acquires-Ryft-to-Extend-its-Agentic-AI-Security-Platform">Cyera Acquires Ryft to Extend Its Agentic AI Security Platform</a></h4><p>As I was getting ready to press &#8216;send&#8217;, I learned that <strong><a href="https://www.cyera.com/">Cyera</a></strong><a href="https://www.cyera.com/"> </a>announced its acquisition of <strong><a href="https://www.ryft.io/">Ryft</a></strong>, a secure data lake startup founded in 2024 and backed by Index Ventures and Bessemer Venture Partners. Deal terms were not disclosed. This is Cyera&#8217;s fourth acquisition in five years, following Trail Security ($162M, Oct 2024) and Otterize (June 2025).</p><p>The thesis as co-founder and CTO Tamar Bar-Ilan calls it &#8220;unified control plane&#8221; for agentic AI, fusing data discovery, classification, DLP, identity, and now AI-ready data lake infrastructure in one platform. </p><p>Cyera is valued at $9B per their last raise. Most companies stagnate around this point. Will be fun to see them continue cooking. </p><div><hr></div><h4><strong><a href="https://cybernews.com/security/lovable-vibe-coding-flaw-apology/">Lovable&#8217;s BOLA and how not to handle disclosure</a></strong></h4><p>A researcher (@weezerOSINT) showed that any free Lovable account could make a handful of API calls and walk away with another user&#8217;s source code, chat history, and database credentials.</p><p>Root cause: a textbook Broken Object Level Authorization (BOLA) flaw, OWASP API #1. The project endpoints verified the auth token but never checked if the user actually owned the resource. Reported through HackerOne on March 3rd and marked as a duplicate.</p><p>The worst part: Lovable shipped a fix in March, but only for projects created after November 2025. Every pre-existing project stayed wide open. New projects returned 403, legacy projects returned 200 OK with full data.</p><p>Then the PR arc: &#8220;did not suffer a data breach&#8221; &#8594; blame documentation &#8594; blame HackerOne &#8594; apologize for the apology. They also casually dropped that public project code visibility is &#8220;intentional behavior&#8221; and &#8220;by design.&#8221;</p><p>$6.6B valuation, nearly 8M users, enterprise customers including Uber, Klarna, Deutsche Telekom, and Zendesk, and the #1 item on the OWASP API Top 10 is sitting in production.</p><p>The wild part is the response: deny, gaslight, then blame HackerOne for closing a ticket your own triage team owns.</p><div><hr></div><h4><a href="https://www.spectrum.security/blog/spectrum-emerges-from-stealth-with-19m-to-reinvent-detection-for-the-ai-era">Spectrum exits stealth with $19M for AI-era detection engineering</a></h4><p>SF-based<strong> <a href="https://www.spectrum.security/">Spectrum Security</a></strong> launched from stealth with <strong>$19M</strong> in seed funding led by TechOperators, with participation from WhiteRabbit Ventures, Skinos Ventures (the new fund from Shlomo Kramer and Yishay Yovel), and Alumni Ventures. </p><p>The platform sits on top of existing SIEMs, data lakes, and EDRs to automate detection authoring, continuously find coverage gaps, and maintain detection health as log schemas and infrastructure drift. </p><p>The team is stacked (Ex leadership at Siemplify, Opus Security, operators at Appian etc) are attacking the same problem most detection eng teams have, rules that quietly break when infrastructure shifts, coverage gaps nobody mapped, drift nobody noticed. </p><p>Backed by Nir Polak (Exabeam founder) and Kevin Skapinetz (TechOperators), this is a strong detection-engineering bet especially as the ground shifts from under us in the SecOps space. </p><div><hr></div><h4><strong><a href="https://securityaffairs.com/190961/hacking/microsoft-defender-under-attack-as-three-zero-days-two-of-them-still-unpatched-enable-elevated-access.html">Three Defender zero-days in the wild, two still unpatched</a></strong></h4><p>A researcher, <strong>C</strong>haotic Eclipse, dropped three Defender Antivirus zero-days after beefing with Microsoft over disclosure: BlueHammer, RedSun, and UnDefend. BlueHammer and RedSun are local priv-esc; UnDefend is a DoS that kills Defender&#8217;s security definition updates. Only BlueHammer (<strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33825">CVE-2026-33825</a></strong>) is patched. The other two are still live with public PoCs on <strong><a href="https://github.com/Nightmare-Eclipse">GitHub</a></strong> (yes, Microsoft-owned GitHub lol). Huntress reported BlueHammer exploitation starting April 10, with RedSun and UnDefend PoC activity kicking off April 16.</p><p>The disclosure drama is pretty wild. Per Chaotic Eclipse, MSRC required a video demonstration of the exploit before they&#8217;d triage the report, then dismissed the case when the researcher declined. Microsoft later said video demos are not a requirement for disclosure, which raises the obvious question of who told the researcher they were.</p><p>UnDefend is the sneakiest of the three because silently killing definition updates means the box looks healthy in your console while going blind in real time. <strong>A stark reminder that the software meant to secure your org could also be vulnerable. Also a reminder for software vendors to patch their shit when researchers surface findings.</strong> Don&#8217;t gaslight or brush it under the rug as it may very likely come back to bite and cost more than the initial fix would&#8217;ve cost.</p><div><hr></div><h1><strong>  &#128302; The Future of Security &#128302;</strong></h1><div><hr></div><h3><strong>AI Security</strong></h3><p><strong><a href="https://www.securityweek.com/capsule-security-emerges-from-stealth-with-7-million-in-funding/">Capsule Security Exits Stealth With $7M to Secure AI Agents at Runtime</a></strong></p><p><strong>Capsule Security</strong>, founded by Naor Paz (ex-F5, Unit 8200) and Lidan Hazout (ex-Transmit Security), exited stealth with $7M in seed funding led by Lama Partners and Forgepoint Capital International. </p><p>The platform sits in the agent execution path and blocks unsafe tool calls, manipulation, and data exfiltration at runtime, with support for Cursor, Claude Code, Copilot Studio, ServiceNow, and Salesforce Agentforce. Alongside the launch, Capsule disclosed two agent-platform vulnerabilities, <strong><a href="https://www.darkreading.com/cloud-security/microsoft-salesforce-patch-ai-agent-data-leak-flaws">ShareLeak</a></strong> in Copilot Studio (now tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21520">CVE-2026-21520</a></strong> and patched) and <strong><a href="https://www.darkreading.com/cloud-security/microsoft-salesforce-patch-ai-agent-data-leak-flaws">PipeLeak</a></strong> in Salesforce Agentforce.</p><div><hr></div><p><strong>More AI Security News:</strong></p><ul><li><p><a href="https://siliconangle.com/2026/04/16/zscaler-openai-turn-zero-trust-security-ai-accelerator/">How Zscaler and OpenAI turn zero-trust security into an AI accelerator</a></p></li></ul><div><hr></div><h2><strong>Endpoint Security </strong></h2><p><strong><a href="https://www.aikido.dev/blog/endpoint-security-for-developer-devices">Aikido Launches Endpoint Protection for Developer Devices</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LEy5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LEy5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png 424w, https://substackcdn.com/image/fetch/$s_!LEy5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png 848w, https://substackcdn.com/image/fetch/$s_!LEy5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png 1272w, https://substackcdn.com/image/fetch/$s_!LEy5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LEy5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png" width="1456" height="914" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:914,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;@ Advanced plan \nAll Teams v \n> Devices \nDocs \nRoland Demo Org \nDevices \nBeta \nView Requests \n1 \nBlock malware and risky software packages on your developer laptops. \nDashboard \nFeed \nDevices \n22 \nPackages \n2481 \nActivity \nSettings \nSnoozed \n1 \ngnored \n99+ \nSolved \n99+ \n- Malware Blocked \nPolicy Blocks \nAutoFix \n264 Blocked installs in the last 30 days \n70 \n194 \nAssets \nAttack \nSearch \nAll v \nProtect \nDevices \nAll \nEvent \n2 Firewall \nMalware Blocked \nDevice \nTimestamp \n24 \n&amp;, Installed Package \nInstall Blocked \ncore \ndesign-win-02 \n2026-04-21, 01:59 \nMore \nNew Device Detected \nIntegrations \n4, Installed Package \nInstalled Package \ndevops-win-01 \n2026-04-21, 01:53 \nCode Quality \nReports \nInstall Blocked \nn \nfree-vpn-proxy \ndevops-linux-03 \n2026-04-21, 01:46 \n&amp;, Installed Package \nLighthouse \ndevops-win-01 \n2026-04-21, 01:43 \n&amp;, Installed Package \n@trpc/server \n&amp; eng-mac-03 \n2026-04-21, 01:37 \n0 \nMalware Blocked \nevent-stream-malware \nMalware \ndesign-mac-03 \n2026-04-21, 01:31 \n4, Installed Package \nLighthouse \n&#171; devops-mac-01 \n2026-04-21, 01:27 \n4, Installed Package \nanyhow \n&#171; eng-mac-01 \n2026-04-21, 01:24 \nInstall Blocked \nn free-vpn-proxy \n&#171; design-mac-02 \n2026-04-21, 01:18 &quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="@ Advanced plan 
All Teams v 
> Devices 
Docs 
Roland Demo Org 
Devices 
Beta 
View Requests 
1 
Block malware and risky software packages on your developer laptops. 
Dashboard 
Feed 
Devices 
22 
Packages 
2481 
Activity 
Settings 
Snoozed 
1 
gnored 
99+ 
Solved 
99+ 
- Malware Blocked 
Policy Blocks 
AutoFix 
264 Blocked installs in the last 30 days 
70 
194 
Assets 
Attack 
Search 
All v 
Protect 
Devices 
All 
Event 
2 Firewall 
Malware Blocked 
Device 
Timestamp 
24 
&amp;, Installed Package 
Install Blocked 
core 
design-win-02 
2026-04-21, 01:59 
More 
New Device Detected 
Integrations 
4, Installed Package 
Installed Package 
devops-win-01 
2026-04-21, 01:53 
Code Quality 
Reports 
Install Blocked 
n 
free-vpn-proxy 
devops-linux-03 
2026-04-21, 01:46 
&amp;, Installed Package 
Lighthouse 
devops-win-01 
2026-04-21, 01:43 
&amp;, Installed Package 
@trpc/server 
&amp; eng-mac-03 
2026-04-21, 01:37 
0 
Malware Blocked 
event-stream-malware 
Malware 
design-mac-03 
2026-04-21, 01:31 
4, Installed Package 
Lighthouse 
&#171; devops-mac-01 
2026-04-21, 01:27 
4, Installed Package 
anyhow 
&#171; eng-mac-01 
2026-04-21, 01:24 
Install Blocked 
n free-vpn-proxy 
&#171; design-mac-02 
2026-04-21, 01:18 " title="@ Advanced plan 
All Teams v 
> Devices 
Docs 
Roland Demo Org 
Devices 
Beta 
View Requests 
1 
Block malware and risky software packages on your developer laptops. 
Dashboard 
Feed 
Devices 
22 
Packages 
2481 
Activity 
Settings 
Snoozed 
1 
gnored 
99+ 
Solved 
99+ 
- Malware Blocked 
Policy Blocks 
AutoFix 
264 Blocked installs in the last 30 days 
70 
194 
Assets 
Attack 
Search 
All v 
Protect 
Devices 
All 
Event 
2 Firewall 
Malware Blocked 
Device 
Timestamp 
24 
&amp;, Installed Package 
Install Blocked 
core 
design-win-02 
2026-04-21, 01:59 
More 
New Device Detected 
Integrations 
4, Installed Package 
Installed Package 
devops-win-01 
2026-04-21, 01:53 
Code Quality 
Reports 
Install Blocked 
n 
free-vpn-proxy 
devops-linux-03 
2026-04-21, 01:46 
&amp;, Installed Package 
Lighthouse 
devops-win-01 
2026-04-21, 01:43 
&amp;, Installed Package 
@trpc/server 
&amp; eng-mac-03 
2026-04-21, 01:37 
0 
Malware Blocked 
event-stream-malware 
Malware 
design-mac-03 
2026-04-21, 01:31 
4, Installed Package 
Lighthouse 
&#171; devops-mac-01 
2026-04-21, 01:27 
4, Installed Package 
anyhow 
&#171; eng-mac-01 
2026-04-21, 01:24 
Install Blocked 
n free-vpn-proxy 
&#171; design-mac-02 
2026-04-21, 01:18 " srcset="https://substackcdn.com/image/fetch/$s_!LEy5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png 424w, https://substackcdn.com/image/fetch/$s_!LEy5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png 848w, https://substackcdn.com/image/fetch/$s_!LEy5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png 1272w, https://substackcdn.com/image/fetch/$s_!LEy5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb024da2a-8853-4819-9911-1b286cb6af7a_2048x1286.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Aikido launched Endpoint, a lightweight agent for dev workstations that inspects packages, IDE extensions, browser extensions, MCP servers, and AI tools before installation. Built on their open source Safe Chain project. </p><p>Notable default: any package published less than 48 hours ago gets held back in favor of the most recent version that clears the age policy, killing the highest-risk window right after a compromised version ships.</p><p>Dev laptops are the softest spot in most orgs. Devs have local admin, install whatever they want, run MCPs calling APIs with prod creds, and hit npm/PyPI a hundred times a day. Most traditional EDR doesn&#8217;t understand any of that telemetry. The 48-hour age policy is the kind of simple heuristic that would have blocked a big chunk of recent supply chain attacks (Axios staged its dropper less than 24 hours before the compromised versions pulled it in, per Aikido&#8217;s own writeup). The endpoint space is getting crowded, but the developer-first and SMB-friendly approach is a true differentiator.</p><div><hr></div><h2><strong>Insurance</strong></h2><p><strong><a href="https://siliconangle.com/2026/04/21/cowbell-debuts-prime-one-cyber-insurance-ai-quantum-risk-cover/">Cowbell Debuts Prime One Cyber Insurance with AI and Quantum Risk Cover</a></strong></p><p>Cowbell Cyber launched Prime One, a cyber insurance product targeting mid-market companies ($250M-$1B revenue) with up to <strong>$10 million</strong> in coverage limits.</p><p>The policy includes affirmative coverage for AI-related incidents and quantum computing risks, positioning itself ahead of the post-quantum cryptography curve. 4D PR play, imo.</p><div><hr></div><h2><strong>SaaS Security</strong></h2><p><strong><a href="https://www.microsoft.com/en-us/security/blog/2026/04/21/detection-strategies-cloud-identities-against-infiltrating-it-workers/">Microsoft drops detection strategies for North Korean IT worker</a></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hrj_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hrj_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png 424w, https://substackcdn.com/image/fetch/$s_!hrj_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png 848w, https://substackcdn.com/image/fetch/$s_!hrj_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png 1272w, https://substackcdn.com/image/fetch/$s_!hrj_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hrj_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png" width="1456" height="569" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:569,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Jasper Sleet attack chain&quot;,&quot;title&quot;:&quot;Jasper Sleet attack chain&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Jasper Sleet attack chain" title="Jasper Sleet attack chain" srcset="https://substackcdn.com/image/fetch/$s_!hrj_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png 424w, https://substackcdn.com/image/fetch/$s_!hrj_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png 848w, https://substackcdn.com/image/fetch/$s_!hrj_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png 1272w, https://substackcdn.com/image/fetch/$s_!hrj_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fa4f74a-4198-4449-ab02-19459c640314_1623x634.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>MSFT published KQL and detection logic for <a href="https://www.microsoft.com/en-us/security/blog/2025/06/30/jasper-sleet-north-korean-remote-it-workers-evolving-tactics-to-infiltrate-organizations/">Jasper Sleet</a>, the DPRK-aligned actor posing as legit hires with AI-assisted fake personas. Ready-to-ship queries for Workday, Teams, Zoom, Webex, and DocuSign in the post.<br><br>Probably the biggest novel piece from it all is that they&#8217;re recommending to hunt the pre-recruitment phase. They&#8217;ve observed Jasper Sleet hitting Workday&#8217;s /hrrecruiting/* API endpoints from known actor infrastructure in a consistent, repeating pattern across multiple external accounts , which looks different from a normal applicant.</p><p>The fact that you need to detect DPRK operatives inside your HRIS in 2026 is wild but here we are. What&#8217;s cool about this post is that it shifts the detection surface left of the endpoint entirely. Your SaaS audit logs (Workday, DocuSign, Zoom) are threat hunting surfaces now, not just compliance logs. If you&#8217;re not piping HR platform telemetry, that could be a big gap.</p><div><hr></div><h2><strong>Security Operations</strong></h2><p><strong><a href="https://www.securityweek.com/artemis-emerges-from-stealth-with-70-million/">Artemis emerges from stealth with $70M to fight AI-powered attacks with AI</a></strong></p><p>Artemis came out of stealth last week with $70M in combined seed and Series A funding, just six months after founding. Series A led by Felicis with First Round and Brightmind returning, plus angels from the founders of Demisto and Abnormal AI, the former Splunk CEO/CTO, and execs from CrowdStrike, Palo Alto, Microsoft, and Okta. Nice cap table.</p><p>The pitch is a data model built from each customer&#8217;s telemetry, fusing log data with business context to generate tuned detections, investigate alerts, and surface correlated attack stories. Early customers include Mercury, Wix, Lemonade, and Abnormal AI.</p><p>There have been quite a few SIEM contenders that have come out of stealth in the past year. Each has a slightly differentiated approach. I like Artemis&#8217; pitch because it&#8217;s adaptive and built off of the reality of a customer&#8217;s environment as opposed to handing off great software to customers and expecting them to realize the full value of it. </p><p>My main question is can they get in front of the CrowdStrikes, Palos, and Splunks of the world who are all striving toward the same narrative with way more distribution? In any case, great funding, founding team and backing. SecOps space is a fun one! </p><div><hr></div><h1><strong>Interested in sponsoring TCP?</strong></h1><p>Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries &#127758;</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach&quot;,&quot;text&quot;:&quot;&#128073; Learn more here!&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.cybersecuritypulse.net/p/partner-with-tcp-maximize-your-reach"><span>&#128073; Learn more here!</span></a></p><div><hr></div><h1>Bye for now &#128075;&#127997;</h1><p>That&#8217;s all for this week&#8230; &#161;Nos vemos la pr&#243;xima semana! </p><div class="pullquote"><p><strong>Disclaimer</strong></p><p>The insights, opinions, and analyses shared in <em>The Cybersecurity Pulse</em> are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.</p></div>]]></content:encoded></item></channel></rss>