All Posts

Join us 5-15-26 for “Hacking the Cloud Security Playbook” – Super Cyber Friday

Please join us on Friday May 15, 2026 for Super Cyber Friday. Our topic of discussion will be “Hacking the Cloud Security Playbook: An hour…

Cybersecurity News: Agent payments, Russian phishing, LeRobot RCE flaw

In today’s cybersecurity news… FIDO Alliance working on securing AI agent payments The industry association said its working with Google and Mastercard on a pair…

Step 1: Deploy New AI Tool. Step 2: Discover Security Flaws. Step 3: Repeat. (LIVE in Orlando, FL)

The rush to not fall behind with the latest AI tooling is creating a vicious cycle. Is there any way to enable teams to use…

Cybersecurity News: PhantomRPC flaw, Checkmarx GitHub dark web data, PyPI package infostealer

In today’s cybersecurity news… PhantomRPC flaw enables privilege escalation A Kaspersky researcher disclosed an unpatched Windows vulnerability dubbed “PhantomRPC” that allows privilege escalation by exploiting…

Detection vs. Prevention: Why Zero Trust Is Essential in the Age of AI

Sponsored article AI-generated cyberattacks are evolving faster than detection tools can respond. Zero Trust strengthens EDR by stopping threats before damage occurs.  Introduction AI is…

Cybersecurity News: ADT data breach, Toronto SMS blasting, pre-Stuxnet malware discovery

In today’s cybersecurity news… ADT says customer data stolen in cyberattack The home security company ADT stated that Monday’s breach resulted in a “limited set”…

April 2026 AMA – “I’m a security professional in the healthcare industry. Ask me anything about the unique challenges of working in this space.”

For this month’s edition of our AMA (Ask me anything) on Reddit, we’ve assembled a panel of security professionals from across the healthcare industry to…

The Department of Know: Vercel breach, a “Contagious Interview,” and ghost breaches

This week’s Department of Know is hosted by Rich Stroffolino, with guests Brett Conlon, CISO, American Century Investments, and Michael Bickford, former CISO, New York…

Cybersecurity News: Rituals cosmetics breach, FBI iOS flaw fixed, Teams Helpdesk malware impersonation

In today’s cybersecurity news… Cosmetics giant Rituals discloses data breach The company, based in The Netherlands, says attackers stole “personal information of an undisclosed number…

What Makes a Successful Security Vendor Demo?

Far too many vendor demos are falling short on just delivering the basics of what a security professional expects to see. Isn’t the point of…

Cybersecurity News: New OpenAI cyber product, unauthorized Mythos access, insurers to cap LLMjacking payouts

In today’s cybersecurity news… OpenAI shares cyber product with government orgs Axios reports that OpenAI has been briefing U.S. federal agencies, state governments, and Five…

What it actually takes to build a security team that works

In March 2026, six security leaders gathered on r/cybersecurity to field questions about the human side of the job: hiring, culture, team structure, and what…

Join us 5-8-26 for “Hacking the End of Compliance” – Super Cyber Friday

Please join us on Friday May 8, 2026 for Super Cyber Friday. Our topic of discussion will be “Hacking the End of Compliance: An hour…

Cybersecurity News: CISA lacks Mythos, Lovable’s leak by design, YouTube’s deepfake detection

In today’s cybersecurity news… CISA lacks Mythos access Sources tell Axios that the Cybersecurity and Infrastructure Security Agency doesn’t have access to Anthropic’s much vaunted…

Back in My Day, You Could Get a Cybersecurity Job at the Corner Store

The barrier to entry for using technology has almost completely disappeared compared to the 80s and 90s. But by smoothing out all the rough edges,…

Cybersecurity News: Vercel breach, ZionSiphon targets water infrastructure, Bluesky DDoS

In today’s cybersecurity news… Vercel confirms breach, stolen data for sale Vercel disclosed an incident involving unauthorized access to internal systems after an employee’s Google…

Security has a trust problem and it’s not what you think

Security teams spend money and time adhering to compliance frameworks, issuing SOC 2 reports, and conducting penetration tests. It’s all done to show they’ve done…

Cybersecurity News: London hospital ransomware legacy, PowerOFF takedown, Microsoft RedSun zero-day

In today’s cybersecurity news… London hospitals continue to suffer from 2024 ransomware attack A ransomware attack that occurred in June 2024 by the Qilin ransomware…

The Department of Know: Mythos Mayhem, critical infrastructure targeted, NVD changes

This week’s Department of Know is hosted by Rich Stroffolino, with guests Andrew Storms, security engineering, Kilo Code, and Eduardo Ortiz-Romeu, VP, global head of…

Cybersecurity News: Cisco Webex warning, Splunk’s Enterprise fix, Git spoof tricks Claude

In today’s cybersecurity news… Cisco posts urgent Webex Services warning Cisco has “released security updates to patch four critical vulnerabilities, including a fixed improper certificate…

Should You Use Native or 3rd Party Cloud Management Tools?

“Secure by Design” gets thrown around in the cloud a lot, but what do we actually mean by that? And is it even achievable? Check…

Cybersecurity News: OpenAI’s GPT-5.4-Cyber, McGraw Hill blames Salesforce for breach, signed adware disables antivirus

In today’s cybersecurity news… OpenAI rolls out GPT-5.4-Cyber OpenAI is rolling out GPT-5.4-Cyber to a limited group of trusted users to help identify software vulnerabilities,…

Protecting executives beyond the office

Executives are high-value targets. Attackers know that the easiest way in isn’t through the corporate firewall. It’s through the home. In this conversation, David Spark…

Join on 5-1-26 for “Hacking the Death of Entry-Level Jobs” – Super Cyber Friday

Please join us on Friday May 1, 2026 for Super Cyber Friday. Our topic of discussion will be “Hacking the Death of Entry-Level Jobs: An…