<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Security Leadership Weekly]]></title><description><![CDATA[A weekly newsletter for cybersecurity leaders]]></description><link>https://markaorlando.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!-Rwz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26a83e67-6607-42e1-8f93-16dffd66a553_1000x1000.png</url><title>Security Leadership Weekly</title><link>https://markaorlando.substack.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 01 Sep 2026 14:07:01 GMT</lastBuildDate><atom:link href="/__u/markaorlando.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Mark]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[markaorlando@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[markaorlando@substack.com]]></itunes:email><itunes:name><![CDATA[Mark Orlando]]></itunes:name></itunes:owner><itunes:author><![CDATA[Mark Orlando]]></itunes:author><googleplay:owner><![CDATA[markaorlando@substack.com]]></googleplay:owner><googleplay:email><![CDATA[markaorlando@substack.com]]></googleplay:email><googleplay:author><![CDATA[Mark Orlando]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Security Leadership #63: Language!]]></title><description><![CDATA[More tools and more metrics won&#8217;t help anyone if the CISO can&#8217;t turn technical signals into a decision someone with budget authority can actually act on.]]></description><link>https://markaorlando.substack.com/p/security-leadership-63-language</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-63-language</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 12 Aug 2026 12:26:18 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b20beda2-a698-4dcd-b503-0f034f73327e_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #63 of Security Leadership Weekly. This week's issue is kind of a two-hander: a fresh nation-state campaign, targeting an old boogeyman (hotel wi-fi!), that shows how identity attacks work in 2026, and a batch of pieces on how security leaders talk about risk to their teams, their boards, and maybe themselves(?). </p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><p>A little over a week ago, <a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/">Microsoft published this report</a> on Storm-2945, a Midnight Blizzard sub-cluster (the same SVR-linked crew behind SolarWinds), which has been hijacking hotel and conference Wi-Fi captive portals since May to run what they&#8217;re calling CaptiveCrunch. The initial attack vector is exploitation of the network gear serving the captive portal, followed by a redirect into device-code phishing against Entra ID or malware delivery via ClickFix. Once on the box, it&#8217;s a Go-based RAT (CornFlake) and PowerShell infostealer (ChocoShell) which target session cookies, saved passwords, and M365 SSO tokens.</p><p>This is what identity attacks look like in 2026: no exploit, no zero-day, nothing (necessarily) written to disk. And it&#8217;s a post-authentication attack, so phishing-resistant MFA doesn&#8217;t save you. We&#8217;ve researched <a href="https://pushsecurity.com/blog/browser-threat-landscape-mid-year-update-2026">these kinds of attacks</a> a TON at my day job, and I posted <a href="https://www.linkedin.com/posts/marko16_captivecrunch-threatintel-devicecodephishing-ugcPost-7492568373868990465-_FiJ/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAACt0_gBnCWA_RbX-4u_sM3vPDdsa88beO8">a short video about this specific campaign</a> on LinkedIn explaining how best to defend against them. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!_GO7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!_GO7!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp 424w, /__u/substackcdn.com/image/fetch/$s_!_GO7!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp 848w, /__u/substackcdn.com/image/fetch/$s_!_GO7!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!_GO7!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!_GO7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp" width="1016" height="742" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:742,&quot;width&quot;:1016,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Diagram depicting an overview of the CaptiveCrunch campaign attack flow&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram depicting an overview of the CaptiveCrunch campaign attack flow" title="Diagram depicting an overview of the CaptiveCrunch campaign attack flow" srcset="/__u/substackcdn.com/image/fetch/$s_!_GO7!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp 424w, /__u/substackcdn.com/image/fetch/$s_!_GO7!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp 848w, /__u/substackcdn.com/image/fetch/$s_!_GO7!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!_GO7!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F696ae8ca-f95d-4d59-8c6f-0a1392e2f50a_1016x742.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Thu4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Thu4!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Thu4!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Thu4!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Thu4!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Thu4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Microsoft, Google, and Apple Want You to Use Passkeys&#8212;Should You?&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Microsoft, Google, and Apple Want You to Use Passkeys&#8212;Should You?" title="Microsoft, Google, and Apple Want You to Use Passkeys&#8212;Should You?" srcset="/__u/substackcdn.com/image/fetch/$s_!Thu4!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Thu4!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Thu4!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Thu4!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe431fe9d-9494-4dcd-862f-a9855177614e_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>You Get a Passkey Attack, and YOU Get a Passkey Attack, and YOU Get a Passkey Attack!</h3><p>Speaking of identity attacks, The Hacker News covered some interesting research last week around defeating passkey protections, which isn&#8217;t great news if you&#8217;re depending on passkeys to keep your users safe from phishing and other identity attacks. But not to worry; in every case, successful exploitation requires pre-existing access to/persistence on the endpoint, and/or an attack chain that has been disrupted by security updates released since disclosure. </p><p>At a high level, the attacks target how passkeys get synced/recovered/exposed by the underlying OS and cloud providers. So the implication is that if you&#8217;re using passkeys, but not hardening the surrounding infrastructure, you may still be at risk. One technique reused signed auth material exposed by Windows, another abused a cloud-synced passkey system via malware already resident on the victim&#8217;s machine (again, assumed access), and the third targeted the MFA flow itself. </p><p>This latter one is the most interesting to me. In a presentation at Black Hat on &#8220;Pass-the-Passkey,&#8221; SpectorOps researcher Michael Grafnetter shows that YubiKey signatures are stored in clear text and are readable by authenticated users. Microsoft is tracking this as <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34348">CVE-2026-34348</a>, which is technically a vuln in the Windows Event Logging Service. Exploiting it doesn&#8217;t require the attacker to extract the private key from a YubiKey - they just need to grab and reuse the generated signature retained by Windows. </p><p>No evidence of this one being exploited in the wild yet, but something to keep an eye out for - maybe also an opportunity to soften or rework language around passkeys &#8220;eliminating phishing risk&#8221; (which hopefully you aren&#8217;t using anyway). Also maybe ask your incident response team if device compromise is treated as a passkey-invalidating event. </p><p>You can check out the full rundown from The Hacker News <a href="https://thehackernews.com/2026/08/new-passkey-attacks-can-recover-synced.html">here</a>, which includes links to the research covered.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3>AI and Security Decision Fatigue</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!f8TV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!f8TV!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!f8TV!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!f8TV!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!f8TV!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!f8TV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg" width="2636" height="1236" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1236,&quot;width&quot;:2636,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:249828,&quot;alt&quot;:&quot;silhouette of road signage during golden hour&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="silhouette of road signage during golden hour" title="silhouette of road signage during golden hour" srcset="/__u/substackcdn.com/image/fetch/$s_!f8TV!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!f8TV!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!f8TV!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!f8TV!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a85363b-9b10-4923-9c25-5749a5484de6_2636x1236.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Sam Sabin at Axios published a piece on executive decision fatigue despite expanding budgets and board support for &#8220;AI attacks&#8221;. While CISOs focus on defining AI governance strategies and figuring out which shiny new widgets they might need to identify risks posed by AI-enabled threats, frontier models continue to add new capabilities, and security debt in other areas continues to build. Some good insights here from people in the field, many of which boil down to &#8220;focus on the fundamentals&#8221; and tackling agent permissions, identity, logging, and accountability. Read the full piece <a href="https://www.axios.com/2026/08/11/ai-cybersecurity-hackers-enterprise-software">here</a>.</p><div><hr></div><h3>Templates for Cybersecurity Executive Briefings by Lenny Zeltser</h3><p>Prepping for a briefing? Lenny Zeltser <a href="https://zeltser.com/cyber-brief-templates-for-decision-makers">has published four super helpful templates</a>: a Cyber Threat Intelligence brief for distilling a full CTI report or synthesizing vendor/government reporting on an emerging threat; a Vulnerability Investigation brief for evaluating a &#8220;celebrity&#8221; vulnerability against your organization&#8217;s exposure; an Incident Response brief for use during an incident, after containment, or for incidents too small to warrant a full report; and a Cybersecurity Assessment brief for distilling findings after a pen test or vulnerability assessment.</p><p>All of these are built on principles from Lenny&#8217;s SANS course <a href="https://www.sans.org/cyber-security-courses/cyber-security-writing-hack-the-reader">Cybersecurity Writing</a> - and you can have them for free! </p><div><hr></div><h3>Risk As the Language of Vulnerability Management</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!1WA0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!1WA0!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!1WA0!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!1WA0!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!1WA0!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!1WA0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg" width="1456" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Financial chart and rising graph with lines and numbers and bar diagrams that illustrate stock market behaviour. Concept of successful trading. Dark blue background. 3d rendering&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Financial chart and rising graph with lines and numbers and bar diagrams that illustrate stock market behaviour. Concept of successful trading. Dark blue background. 3d rendering" title="Financial chart and rising graph with lines and numbers and bar diagrams that illustrate stock market behaviour. Concept of successful trading. Dark blue background. 3d rendering" srcset="/__u/substackcdn.com/image/fetch/$s_!1WA0!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!1WA0!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!1WA0!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!1WA0!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfe6a6b5-55cb-45b3-8eb2-885a0214bbfb_3000x1822.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.fairinstitute.org/blog/risk-is-or-should-be-the-business-language-of-vulnerability-management?hs_amp=true">This piece by Todd Tucker at the FAIR Institute </a>caught my eye, having just listened to last week&#8217;s episode of The CISO Series Podcast, &#8220;<a href="https://cisoseries.com/why-dont-you-tell-me-which-metrics-sound-most-impressive/">Why Don&#8217;t You Tell Me Which Risk Metrics Sound Most Impressive</a>",&#8221; which covered (among other things) vanity metrics presented by CISOs. The article centers on a CISO who came up through vulnerability management and knows the discipline cold, but who is struggling to turn CVSS scores, exploitability ratings, and other signals into an actionable conversation for her CFO and Board; basically, she needs a language overhaul more than a technical one.</p><p>The article claims that security&#8217;s biggest value driver is risk reduction, <em>not</em> cost reduction. Tucket also advocates decoupling FAIR-the-mindset from FAIR-the-quantification-program. FAIR doesn&#8217;t necessarily require a large team, Monte Carlo simulations, and dedicated analysts; the most valuable part of the exercise is the structured way of thinking and shared language. </p><p>For vuln management specifically, Tucker names two payoffs: </p><ol><li><p><strong>Justifying investment</strong>: instead of walking into a budget conversation with thousands of critical findings, you frame the few that matter as a loss scenario the business already worries about - even directional framing (&#8221;high likelihood of serious loss because we run end-of-life systems&#8221;) is better than a severity count. </p></li><li><p><strong>Aligning priorities</strong>: the scenario framing translates a technical finding into a breach scenario leadership already has in mind, and forces the one question only the business can answer: how large the harm would actually be. </p></li></ol><p>The piece gets pretty deep into the weeds on FAIR, so it may not fully connect if you aren&#8217;t using the framework. But I like it as a companion to Lenny&#8217;s presentation templates and the Axios piece on analysis paralysis. Tucker is talking here about  <em>language</em>: risk expressed as probable frequency and magnitude of loss, which should inform a CISO&#8217;s analysis in light of emerging threats (say, AI-enabled attacks) as well as briefings to the CFO and Board. It&#8217;s not about more tools and data; it&#8217;s about a common vocabulary for deciding what&#8217;s worth action and investment. </p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>CaptiveCrunch and the passkey research covered in the last week+ are two sides of the same coin. These are more identity attack surface problems than they are authentication or account problems, and they require a different lens than just &#8220;how to implement stronger auth?&#8221; (although you should do that too).</p><p>The Axios piece on decision fatigue and Tucker&#8217;s article on FAIR-as-language make the point that more tools and more metrics won&#8217;t help anyone if the CISO can&#8217;t turn technical signals into a decision someone with budget authority can actually act on. CaptiveCrunch and Pass-the-Passkey are interesting for sure, but are also exactly the kind of &#8220;emerging threat&#8221; that&#8217;s easy to over-index on and miss the actual point for leadership - treat every session as potentially compromised (or compromisable), treat every network as hostile, and get your IR team thinking about what invalidates a passkey the same way they think about what invalidates a password. Fundamentals, language, and identity, allllllll the way down.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #62: Hope Isn't a Strategy]]></title><description><![CDATA[Applying SRE principles to cybersecurity, and where the approach breaks down.]]></description><link>https://markaorlando.substack.com/p/security-leadership-62-hope-isnt</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-62-hope-isnt</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 29 Jul 2026 12:18:07 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/361ea468-8fcf-4036-a814-1c773c23ff95_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #62 of Security Leadership Weekly. This week, instead of running through the usual attacks, vulnerabilities, research, policies, and management topics, I want to spend some time on a topic some people I respect have covered recently, and which I&#8217;ve written about myself in the past: applying site reliability engineering (SRE) principles to cyber defense.</p><p><span>Google Cloud published </span><a href="https://cloud.google.com/transform/how-google-does-it-applying-sre-to-cybersecurity"><span>a piece on applying Site Reliability Engineering to cybersecurity</span></a><span> earlier this year, and Phil Venables (who shows up in this newsletter more than anyone else because he&#8217;s usually right before the rest of us catch up) just posted his own version, </span><a href="https://www.philvenables.com/post/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls"><span>Control Reliability Engineering</span></a><span>. These pieces don&#8217;t reference each other, but they are in conversation.</span></p><p><span>Anyone who&#8217;s spent time in security operations knows that defense has a scaling problem, and SRE tools and methods may help. I want to cover this from three angles: what this looks like in practice, what it means for leading a team, and where the analogy doesn&#8217;t really hold up (all models are wrong, but some are useful - right?). The leadership part is the one most relevant to this newsletter, so that&#8217;s where I&#8217;m spending the most words.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><p><span>Google&#8217;s version boils down to four habits:</span></p><ul><li><p><span>Eliminate toil (repetitive actions that add no enduring value)</span></p></li><li><p><span>Alert on symptoms instead of causes</span></p></li><li><p><span>Run blameless postmortems</span></p></li><li><p><span>Roll out changes gradually and reversibly</span></p></li></ul><p><span>None of this is new to anyone who&#8217;s read the SRE book. Google basically says you can&#8217;t grow a security team linearly to match the expanding size and scope of operations, so a new approach is needed. The Google Cloud post also points out that security teams have historically alerted on system-level signals (a failed login, a specific hash - things at the bottom of the </span><a href="https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html"><span>pyramid of pain</span></a><span>) that are either too noisy or too brittle. The SRE solution is to alert on symptoms that measurably degrade confidentiality, integrity, or availability, and automate everything else. If a 3 a.m. alert doesn&#8217;t require a human response, well then, it probably shouldn&#8217;t be an alert.</span></p><p><span>Venables goes a little further with his concept of </span><em><span>Control Reliability Engineering (CRE)</span></em><span>. He observes that most breaches result from a control everyone believed was working but quietly failed, rather than attributing to attacker brilliance. There&#8217;s a great analogy in his piece for this: a radiation detector that reads zero could mean the environment is safe, or it could mean the sensor is dead, which is why real detectors carry a small harmless source so they never actually read zero. His suggested approach for CRE is essentially a working checklist:</span></p><ul><li><p><span>control ontology and cataloging</span></p></li><li><p><span>controls-as-code</span></p></li><li><p><span>control-specific SLIs/SLOs</span></p></li><li><p><span>continuous control monitoring</span></p></li><li><p><span>synthetic event injection</span></p></li><li><p><span>control readiness reviews (an adaptation of SRE&#8217;s production readiness review)</span></p></li><li><p><span>safe/canaried changes</span></p></li><li><p><span>control incident management</span></p></li><li><p><span>error budgets for controls</span></p></li></ul><p><span>If we&#8217;re worried about control failures as much as we are attacks (and we should be), we can treat &#8220;control incidents&#8221; the same way we would a security incident. Most organizations only do root-cause analysis on the thing that was exploited, but CRE says if the control was broken and got lucky, that&#8217;s still a finding.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!hU0p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!hU0p!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png 424w, /__u/substackcdn.com/image/fetch/$s_!hU0p!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png 848w, /__u/substackcdn.com/image/fetch/$s_!hU0p!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png 1272w, /__u/substackcdn.com/image/fetch/$s_!hU0p!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!hU0p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png" width="1110" height="593" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:593,&quot;width&quot;:1110,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!hU0p!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png 424w, /__u/substackcdn.com/image/fetch/$s_!hU0p!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png 848w, /__u/substackcdn.com/image/fetch/$s_!hU0p!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png 1272w, /__u/substackcdn.com/image/fetch/$s_!hU0p!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce58daf6-b5a1-44a3-90e7-433d411064a8_1110x593.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>On the ground, this is already showing up in detection engineering as </span><a href="https://andreafortuna.org/2026/06/17/detection-as-code/"><span>detection-as-code</span></a><span>: version-controlled, peer-reviewed, tested detection analytics over ad hoc alert tuning. I don&#8217;t know that the SRE-CRE-secops alignment is this clean everywhere - controls don&#8217;t necessarily have success rates the same way a service has an uptime (see: patching SLAs and proving a negative), so CRE in practice may take some tweaking and judgment.</span></p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><span>Tailoring for SecOps, and Chaos Engineering</span></h3><p><span>The source text for most of this is </span><a href="https://google.github.io/building-secure-and-reliable-systems/raw/toc.html"><span>Building Secure and Reliable Systems</span></a><span>, Google&#8217;s free 2020 book pairing SRE and security engineers to argue that reliability and security were never actually separate disciplines. If you haven&#8217;t read it, it&#8217;s aged pretty well, and it&#8217;s free. </span><a href="https://cloud.google.com/blog/products/identity-security/achieving-autonomic-security-operations-reducing-toil"><span>Anton Chuvakin&#8217;s writing on autonomic security operations</span></a><span> is also required reading to see what common-sense alignment between secops and SRE might look like.</span></p><p><span>Another resource worth checking out is Kelly Shortridge&#8217;s </span><a href="https://kellyshortridge.com/book.html"><span>Security Chaos Engineering</span></a><span>, which is conceptually aligned with CRE: deliberately injecting failure to find out what happens - the security equivalent of chaos engineering&#8217;s fault injection in production. Where CRE is more about measurement and drift detection, SCE is about experimentation; they&#8217;re compatible, but they answer different concerns. CRE tells you whether your control is still working; SCE tells you whether your system degrades gracefully when it isn&#8217;t.</span></p><p><span>SRE was built to manage </span><em><span>stochastic </span></em><span>failure - disk failure, connectivity losses, load spikes, etc. Security failure is caused by an adversary actively probing the edges of whatever control set you&#8217;ve deployed. An </span><strong><span>error budget</span></strong><span> tells you how much unreliability you&#8217;re willing to tolerate before you stop shipping features (kind of like a risk tolerance). Applied to security, &#8220;error budget&#8221; starts to sound like an acceptable rate of successful attacks, which is probably not something your leadership wants to hear. So the approach and tools are sound, but the message might need a little&#8230;translation.</span></p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><span>Blameless postmortems only work if your team believes you mean it</span></h3><p><span>The Google Cloud and Phil Venables posts lean on this staple of SRE, which means treating every incident, including a </span><em><span>control incident</span></em><span>, as a chance to improve the system rather than assign fault. I teach this in </span><a href="https://www.sans.org/cyber-security-courses/building-leading-security-operations-centers"><span>LDR551</span></a><span>. The practice is easy to describe and difficult to actually run. &#8220;Blamelessness&#8221; depends entirely on psychological safety, which is earned over time. If your team suspects that </span><em><span>blameless </span></em><span>only applies until something gets bad enough, they&#8217;ll just stop telling you about the near-misses.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D 424w, https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D 848w, https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D 1272w, https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D" width="571" height="380.6666666666667" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2000,&quot;width&quot;:3000,&quot;resizeWidth&quot;:571,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;group of people having a meeting&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="group of people having a meeting" title="group of people having a meeting" srcset="https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D 424w, https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D 848w, https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D 1272w, https://images.unsplash.com/photo-1541746972996-4e0b0f43e02a?fm=jpg&amp;q=60&amp;w=3000&amp;auto=format&amp;fit=crop&amp;ixlib=rb-4.1.0&amp;ixid=M3wxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8fA%3D%3D 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><span>Toil elimination is a retention strategy</span></h3><p><span>Pitch toil elimination as a retention strategy. About </span><a href="https://newsroom.trendmicro.com/2021-05-25-70-Of-SOC-Teams-Emotionally-Overwhelmed-By-Security-Alert-Volume"><span>70% of SOC analysts report burnout that bleeds into their home life</span></a><span>, and nearly every organization is watching alert volume climb faster than headcount. SRE&#8217;s contribution here is that any manual, repetitive operational task gets treated as a bug in the system&#8217;s design. You don&#8217;t solve analyst burnout by hiring more analysts to do the same repetitive work faster; you solve it by treating the repetitive work itself as the defect to be controlled and reduced.</span></p><h3><span>Error budgets are a negotiating tool</span></h3><p><span>Tired of the eternal, exhausting fight with the business over how much risk is acceptable given operational velocity? An error budget lets you codify that number in advance and get buy-in instead of relitigating it every release cycle.</span></p><h3><span>Changes to your staffing plan</span></h3><p><span>Controls-as-code and detection-as-code require people who can write and review code, not just tune a console. If you&#8217;re building a security program around these ideas, your next few hires look more like engineers than analysts, and your career-pathing conversations with your current team should reflect that shift now, before it&#8217;s a surprise a year from now.</span></p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>SRE-for-security is a management philosophy expressed using engineering words: measure continuously, treat failure as information rather than a verdict on a person or solution, negotiate risk tolerance once rather than every release/sprint/operational cycle. Don't buy this from anyone selling it to you as a product in a booth at Black Hat. Focus on the concepts: controls-as-code, continuous monitoring, blameless learning, error budgets as a negotiating tool.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #61: Agents Without Adults]]></title><description><![CDATA[Standing access, no guardrails, no owner...this week's issue on the identity debt AI agents are racking up]]></description><link>https://markaorlando.substack.com/p/security-leadership-61-agents-without</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-61-agents-without</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 22 Jul 2026 12:28:09 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/06089ba8-bff4-4707-a073-b69f068da0d5_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #61 of Security Leadership Weekly. We&#8217;re back to our normal schedule after a short break, with minor changes in length and content to improve relevance/readability (I hope)! </p><p>This week: the industry&#8217;s rush to instrument AI agents with standing access - sometimes purposely, sometimes unknowingly - is basically repeating every identity and trust mistake enterprise IT teams spent the last decade fixing, only faster, with less visibility, and in many cases with no one assigned to own the solution.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3>AI agents don&#8217;t have the controls that govern other privileged identity classes</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ijyx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ijyx!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png 424w, /__u/substackcdn.com/image/fetch/$s_!ijyx!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png 848w, /__u/substackcdn.com/image/fetch/$s_!ijyx!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ijyx!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ijyx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png" width="581" height="481.6394230769231" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1207,&quot;width&quot;:1456,&quot;resizeWidth&quot;:581,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Illustrative example of SaaS OAuth sprawl. AI apps are highlighted orange.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustrative example of SaaS OAuth sprawl. AI apps are highlighted orange." title="Illustrative example of SaaS OAuth sprawl. AI apps are highlighted orange." srcset="/__u/substackcdn.com/image/fetch/$s_!ijyx!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png 424w, /__u/substackcdn.com/image/fetch/$s_!ijyx!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png 848w, /__u/substackcdn.com/image/fetch/$s_!ijyx!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ijyx!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7542cbb5-08ef-43fc-91ae-db8a4d65ca0c_2516x2086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Enterprises are granting AI agents access to databases, APIs, file stores, and other data. Unfortunately, the OAuth token model used to grant this access has no way to express which human (if any) an agent is acting <em>for</em>, what scope it&#8217;s authorized to use, or whether one agent invoking another should inherit or narrow that authority. </p><p><a href="https://www.crowdstrike.com/en-us/blog/the-identity-problem-hiding-in-ai-agent-deployments/">According to CrowdStrike</a>, the MCP spec&#8217;s recommendation to use OAuth 2.1 for agent tokens doesn&#8217;t account for <em>who</em> a token actually represents when agents act autonomously. We know this gap is exploitable; see the <a href="https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html">recently reported AWS Kiro flaw</a>, which allows rewriting of the IDE config via hidden text on a webpage. There are plenty of other examples like this out there, and <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-uncovers-new-prompt-injection-techniques/">CrowdStrike&#8217;s prompt injection taxonomy update</a> reflects the growing volume and evolution of these techniques.</p><p>If your organization has deployed or is piloting AI agents, ask who owns the identity architecture for those agents - not who owns &#8220;AI governance,&#8221; but who is <em>accountable</em> for scoping, audit trails, and revocation when an agent is compromised or acts unpredictably.  Don&#8217;t let &#8220;we have an AI governance policy&#8221; substitute for verifying agents can&#8217;t rewrite their own config or execute code from untrusted input, which is what happened to Kiro.</p><p><em><strong>(Note: We wrote about OAuth sprawl <a href="https://pushsecurity.com/blog/unpacking-the-vercel-breach">on the Push Security blog</a>, which is where I borrowed the graphic above)</strong></em></p><div><hr></div><h3>Human challenges in AI-enabled SOCs</h3><p><a href="https://www.csoonline.com/article/4198016/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats.html">Cynthia Brumfield's CSO Online feature</a> posits that AI's biggest strain on the SOC may be human rather than technical. Futurum's Fernando Montenegro describes analysts drowning in machine-generated reports and alerts that <em>still</em> require human judgment for validation; we&#8217;ve brought down the cost of generating more signal without addressing the analysis bottleneck. My SANS colleagues (and secops experts) Chris Crowley and John Hubbard share some insights in the piece, which basically concludes that mature SOCs will absorb the load while understaffed ones burn out. In short: "Buy engineers, not tokens.&#8221;</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3>What "no AI guardrails&#8221; looks like in practice</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!fFs7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!fFs7!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png 424w, /__u/substackcdn.com/image/fetch/$s_!fFs7!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png 848w, /__u/substackcdn.com/image/fetch/$s_!fFs7!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png 1272w, /__u/substackcdn.com/image/fetch/$s_!fFs7!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!fFs7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png" width="645" height="424.72641509433964" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:698,&quot;width&quot;:1060,&quot;resizeWidth&quot;:645,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!fFs7!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png 424w, /__u/substackcdn.com/image/fetch/$s_!fFs7!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png 848w, /__u/substackcdn.com/image/fetch/$s_!fFs7!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png 1272w, /__u/substackcdn.com/image/fetch/$s_!fFs7!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F537c8d72-0ac4-499e-8a8e-859370af503a_1060x698.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A governance policy that says &#8220;agents must operate within approved scopes&#8221; means absolutely nothing if the underlying system has no approval step capable of <em>blocking</em> an agent from acting on hidden instructions. The gap between AI governance documentation and enforcement is where some recent incidents have occurred, and we can&#8217;t keep papering over it with policy language alone.</p><p><a href="https://www.crowdstrike.com/en-us/blog/why-ai-governance-without-guardrails-is-theater/">CrowdStrike&#8217;s framing - &#8220;AI governance without guardrails is theater&#8221;</a> - is catchy and maybe a bit trite, but it&#8217;s also true given what happened at AWS: its Kiro IDE could rewrite its own configuration and execute attacker code from a webpage summary request, with no approval gate to intervene. <a href="https://arxiv.org/abs/2607.00333">A research paper published last week</a> on third-party mobile agents powered by Vision-Language Models (VLMs) makes the same point from a different angle: screen-reading agents trusted invisible text as legitimate instruction, because nothing in the architecture distinguished &#8220;content to summarize&#8221; from &#8220;commands to execute&#8221; (covered by The Hacker News <a href="https://thehackernews.com/2026/07/open-source-android-ai-agents-could-let.html">here</a>).</p><p><strong>CISOs, BISOs, and security managers out there</strong> - in your next AI governance policy review, ask for a live demonstration that an agent in your environment cannot act on instructions embedded in content it&#8217;s asked to process (e.g., a webpage, a document, a calendar invite). If no one can produce that demonstration, the policy is aspirational, not operational, and your board-level AI risk reporting should say so explicitly rather than citing policy adoption as evidence of control. </p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3>A must-read for SOC teams and managers: FinOps for SecOps</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!vCST!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!vCST!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!vCST!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!vCST!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!vCST!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!vCST!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg" width="663" height="439.41964285714283" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:965,&quot;width&quot;:1456,&quot;resizeWidth&quot;:663,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;https://storage.googleapis.com/gweb-cloudblog-publish/images/agentic_soc_finops_matrix_1.max-1700x1700.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/agentic_soc_finops_matrix_1.max-1700x1700.jpg" title="https://storage.googleapis.com/gweb-cloudblog-publish/images/agentic_soc_finops_matrix_1.max-1700x1700.jpg" srcset="/__u/substackcdn.com/image/fetch/$s_!vCST!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!vCST!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!vCST!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!vCST!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5d040cf-3f2c-4d2a-b34b-bb2e46bde5a5_1700x1127.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://cloud.google.com/transform/finops-for-secops-how-to-optimize-the-agentic-soc-for-value">This post by Usman Chaudhary and Nikita Jagadeesh</a> argues that agentic SOCs are now operationally necessary, but that blind AI adoption creates financial risk. </p><p>Their proposed solution is a &#8220;FinOps for SecOps&#8221; framework that starts by plotting each SOC workload on a value-versus-compute-cost matrix:</p><ul><li><p>High-value/low-compute work (Tier 1 triage, detection engineering, investigation summaries) should be automated</p></li><li><p>High-value/high-compute work (open-ended threat hunting, multi-source correlation) deserves selective, async investment</p></li><li><p>Low-value work already handled well by the SIEM (dedup, ticket routing, IOC matching) shouldn&#8217;t be handed to agents at all</p></li><li><p>Low-value/high-compute work (i.e. agents re-normalizing raw data on every query instead of leaning on the SIEM) is the &#8220;token trap&#8221; to avoid entirely </p></li></ul><p>The second half of the piece lays out a six-step rollout: </p><ol><li><p>Aggregate telemetry efficiently, using MCP servers to query external data instead of migrating everything</p></li><li><p>Throttle agent autonomy by priority/telemetry source/target before enterprise-wide deployment</p></li><li><p>Run a 2-4 week parallel POV against manual ops to prove ROI</p></li><li><p>Require verifiable/auditable reasoning rather than black-box confidence scores</p></li><li><p>Shift success metrics beyond MTTD/MTTR toward toil reduction and junior-analyst enablement </p></li><li><p>Deliberately preserve manual triage skills in new hires (via CTF labs) to avoid &#8220;rubber stamping&#8221; and skill atrophy as agents absorb top-tier work</p></li></ol><p>I really like the focus on ongoing skill development and cost justification in this framework. CISOs should make agents justify their token spend rather than chase easy automation, and we already know the <a href="https://www.forbes.com/sites/jemmagreen/2026/07/02/ai-costs-more-than-the-people-it-replaced/">AI token gravy train is coming to an end</a>.</p><div><hr></div><h2><strong>&#127758;Notable News and Research This Week:</strong></h2><p>CVE-2026-50522, a critical SharePoint deserialization RCE (CVSS 9.8), <a href="https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html">is being actively exploited</a> following a public PoC; patch confirmation should be on this week&#8217;s agenda if you run on-prem SharePoint! </p><p><a href="https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html">Arctic Wolf Labs observed Qilin ransomware affiliates</a> using a patched PAN-OS authentication bypass (CVE-2026-0257) for initial access across multiple June intrusions; a reminder that &#8220;patched&#8221; doesn&#8217;t mean &#8220;remediated&#8221; if scanning lags (womp womp).</p><p><a href="https://www.securityweek.com/new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication/">HollowGraph malware</a> is using a compromised Microsoft 365 account&#8217;s calendar as a two-way C2 dead-drop, another entry in the growing list of SaaS-native LOTL techniques that blend into normal traffic.</p><p><a href="https://therecord.media/spain-fines-23andme-3-million-cyber-failings-data-breach">Spain&#8217;s AEPD fined 23andMe nearly $3 million</a> for cybersecurity failings tied to the 2023 breach.</p><div><hr></div><h2>&#128161;<strong>Actions for this Week</strong></h2><ol><li><p>Confirm CVE-2026-50522 (SharePoint RCE, CVSS 9.8) is patched on all internet-facing instances and check for indicators of prior exploitation, given active PoC-driven attacks.</p></li><li><p>Ask whoever owns your AI agent pilots whether any deployed agent can execute instructions embedded in content it processes (webpages, documents, emails) without a human approval gate.</p></li><li><p>(Next 30 days): Inventory every AI agent in production or pilot with access to sensitive systems and document who owns token scoping, audit logging, and revocation for each.</p></li><li><p>(Next 30 days): Re-scan environments for the patched PAN-OS auth bypass (CVE-2026-0257) even if the patch is confirmed applied; Arctic Wolf&#8217;s Qilin findings suggest exploitation windows persisted post-patch.</p></li><li><p>(Longer term) Add a standing agenda item to your next AI governance review that requires a technical demonstration of enforcement, not just a policy citation, before governance maturity is reported to the board or auditors.</p></li></ol><p></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #60: Building Versus Firefighting]]></title><description><![CDATA[It's never been more important to strike the right balance.]]></description><link>https://markaorlando.substack.com/p/security-leadership-60-building-versus</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-60-building-versus</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 01 Jul 2026 12:23:22 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5d168f75-c1ea-4e62-b1eb-500043991377_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #60 of Security Leadership Weekly! This week: browser extensions as an underappreciated enterprise attack surface, the continued professionalization of ransomware operations, the organizational dynamics that cause security programs to succeed or fail, and what the new post-quantum EO actually means for security leaders who <em>aren't</em> in the federal government. There's also some solid reading and listening on device code phishing if you want to go deep on one of the fastest-growing attack techniques of the year. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!5hmK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!5hmK!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!5hmK!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!5hmK!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!5hmK!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!5hmK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg" width="500" height="550" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:550,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!5hmK!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!5hmK!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!5hmK!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!5hmK!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44acc771-f036-4a97-8f1e-38fe6bde1f6a_500x550.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you&#8217;re struggling to balance daily operational tasks and project work, chances are you aren&#8217;t getting <em>less </em>busy - but some structural improvements will be necessary to reduce operational load on people trying to reduce your attack surface, comply with Federal mandates, and respond to ransomware attacks.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3>The Browser Extension Attack Surface Keeps Growing</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!7shz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!7shz!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!7shz!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!7shz!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!7shz!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!7shz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg" width="900" height="470" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!7shz!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!7shz!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!7shz!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!7shz!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6425def1-386c-4b09-ac7c-90fb6b6b0dd0_900x470.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two disclosures this week highlight the risks that browser extensions can pose to enterprise networks, and maybe also that AI branding has become the most reliable social-engineering lever for getting them installed at scale.</p><p><a href="https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html">Microsoft removed 119 Edge extensions</a> this week linked to a campaign impacting up to 2.6 million users. These extensions weren&#8217;t obviously suspicious tools: ad blockers, VPNs, translators, and video downloaders. The malicious payloads were hidden inside ordinary image and font files using steganography, stayed dormant through multi-day evasion checks, and only deployed after clearing fingerprint validation to evade security review. When they did activate, the damage wasn&#8217;t limited to ad fraud; retrieved payloads included an RCE backdoor, Google credential and 2FA code theft, WordPress admin credential harvesting, and bulk cookie exfiltration for session hijacking. Microsoft links the operation to <a href="https://thehackernews.com/2025/12/darkspectre-browser-extension-campaigns.html">DarkSpectre</a>, a Chinese actor previously connected to other extension campaigns.</p><p>Separately, Microsoft&#8217;s Defender research team <a href="https://www.microsoft.com/en-us/security/blog/2026/06/29/chromium-extension-uses-airelated-branding-redirect-browser-search/">disclosed a Chrome extension impersonating Perplexity AI</a> that collected every search query (and every other input to the address bar) through an attacker-controlled intermediary before redirecting users to legitimate results. The extension shipped with server-side Node.js code that explicitly logged incoming requests with full headers, IPs, and user agents. The AI branding was an effective lure, since users tend to install AI productivity tools at unusually high rates with less scrutiny than other software.</p><p>Most enterprise security programs treat browser extension installs as a user-responsibility problem rather than a managed control, and most corporate third-party software review processes do not include extensions. We&#8217;re well past the time to start treating browser extension inventory the same way mature programs treat shadow IT: <strong>audit what&#8217;s deployed across managed endpoints, define a policy for what requires review before install, and make sure someone owns that process.</strong> </p><div><hr></div><h3><strong>Japanese telco exposes 14.2 million managed email credentials</strong></h3><p><a href="https://newsroom.kddi.com/news/assets/2026/kddi_nr_s-71_4593/kddi_nr_s-71_4593_pdf_01.pdf">Japanese telco KDDI disclosed</a> that attackers exploited a vulnerability in third-party software powering a managed email platform it operates for itself and several other Japanese ISPs, exposing up to 14.2 million email addresses and passwords. KDDI detected the unauthorized access on June 17 and says it contained the intrusion the same day, but the window was enough for credentials to be at risk across the full customer base of the shared platform.</p><p>The blast radius in this case is really something. Because KDDI operates this email infrastructure as a managed service for ISPs, including STNet, JCOM, Chubu Telecommunications, Nifty, and BIGLOBE, a single vulnerability in a shared third-party component compromised credentials across multiple providers and their respective customer bases simultaneously. It&#8217;s a good example of why third-party and managed service risk continues to punch above its weight in breach statistics: the attack surface isn&#8217;t just your own stack, it&#8217;s every customer of whoever manages your stack.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>Ransomware Syndicates&#8217; Continued Evolution</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Bv6W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Bv6W!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Bv6W!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Bv6W!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Bv6W!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Bv6W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg" width="3000" height="1726" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1726,&quot;width&quot;:3000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:432096,&quot;alt&quot;:&quot;MacBook Pro turned-on&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="MacBook Pro turned-on" title="MacBook Pro turned-on" srcset="/__u/substackcdn.com/image/fetch/$s_!Bv6W!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Bv6W!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Bv6W!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Bv6W!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F557faa1c-1737-4fac-9a9b-788c8b99ee89_3000x1726.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.intel471.com/resources/whitepapers/the-black-basta-blueprint">Intel 471&#8217;s Garrett Carstens</a> draws on analysis of Black Basta&#8217;s leaked internal chat logs to document how modern ransomware operations have adopted fully corporate structures: scheduled call teams running social engineering from 6 p.m. to 2 a.m. Moscow time, outsourced contractors for malware, spamming, and initial access, internal performance reviews tied to ransom payment distribution, and tiered pricing models calibrated to victim revenue. Black Basta collected at least $107 million from 520 victims across 39 industries before shutting down in 2025, operating, in Carstens&#8217; framing, less like a criminal gang and more like a professional services firm specializing in extortion.</p><p>It&#8217;s fascinating how attackers have turned the negotiation phase into a precision instrument. Ransomware groups now conduct data audits to assess the sensitivity and market value of what they&#8217;ve stolen, then use that valuation to set and manipulate deadlines - compressing them to force panic, or extending them when a longer runway improves payout probability. Cyber insurance policies, when discovered during reconnaissance, function as a pricing signal. Attackers use coverage details to infer the victim&#8217;s financial capacity and likely ransom ceiling. To me, the takeaway isn&#8217;t just to prepare for ransomware; it&#8217;s to treat negotiations as a scenario to be rehearsed in advance, with intelligence informing how the other side of the table actually operates. Really great read from Intel471 (with coverage via <a href="https://cyberscoop.com/ransomware-syndicates-corporate-organization-op-ed/">Cyberscoop</a>).</p><div><hr></div><h3>Device Code Phishing Twofer!</h3><p>Device code phishing attacks have risen sharply in 2026, largely due to the proliferation of new attack kits and the addition of this technique to existing kits. If you missed it, my Push Security colleague (and VP of Research) Luke Jennings did an awesome, in-depth breakdown of how device code phishing has exploded in scope and sophistication this year. Detailed timelines, TTPs, recordings of actual attacks, and mitigation strategies abound. You can see the recording <a href="https://pushsecurity.com/resources/device-code-phishing">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ULsB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ULsB!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png 424w, /__u/substackcdn.com/image/fetch/$s_!ULsB!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png 848w, /__u/substackcdn.com/image/fetch/$s_!ULsB!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ULsB!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ULsB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png" width="1191" height="658" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:658,&quot;width&quot;:1191,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:442621,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/204276132?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ULsB!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png 424w, /__u/substackcdn.com/image/fetch/$s_!ULsB!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png 848w, /__u/substackcdn.com/image/fetch/$s_!ULsB!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ULsB!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b658fd7-2bb3-4c80-bb16-1f0c837d3244_1191x658.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#8230;AND, &#8288;Selena Larson&#8288;<span>, Staff Threat Researcher and Lead, Intelligence Analysis and Strategy at </span><strong>&#8288;</strong>Proofpoint&#8288;<span>, joins host </span>&#8288;&#8288;Caleb Tolin&#8288; &#8288;<span>to detail the specific mechanics of device code phishing campaigns, revealing how adversaries exploit legitimate communication structures to capture administrative and enterprise access. You can check that one out </span><a href="https://thecyberwire.com/podcasts/data-security-decoded/57/notes"><span>here</span></a><span>.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!whhI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!whhI!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png 424w, /__u/substackcdn.com/image/fetch/$s_!whhI!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png 848w, /__u/substackcdn.com/image/fetch/$s_!whhI!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png 1272w, /__u/substackcdn.com/image/fetch/$s_!whhI!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!whhI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png" width="1008" height="501" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:501,&quot;width&quot;:1008,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:724702,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/204276132?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!whhI!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png 424w, /__u/substackcdn.com/image/fetch/$s_!whhI!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png 848w, /__u/substackcdn.com/image/fetch/$s_!whhI!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png 1272w, /__u/substackcdn.com/image/fetch/$s_!whhI!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feacdaf39-6a91-43d6-98f6-b24383b56eaf_1008x501.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3>Security Isn&#8217;t the Only Thing Saving the Company from Itself</h3><p><a href="https://www.philvenables.com/post/sorry-cyber-you-aren-t-the-only-ones-saving-the-company-from-itself">New from Phil Venables</a>: Security teams often carry an implicit sense that they&#8217;re uniquely burdened with having to be the adults in the room - the ones pushing back while the business wants to move fast and skip the guardrails. Venables pushes back on this by discussing other organizational functions that face the same pressure: financial controllers holding the line on revenue recognition, safety supervisors refusing to skip inspections, environmental compliance officers absorbing pressure to ignore runoff spikes, and HR directors asked to bury whistleblowers in restructurings. The point isn&#8217;t that security isn&#8217;t important; it&#8217;s that the tension between control functions (like security) and operational velocity is a <em>feature</em> of organizational life, not a sign that your company uniquely doesn&#8217;t &#8220;get&#8221; security. I am HUGE fan of tearing down the &#8220;security is saving the company from itself by being smarter than users&#8221; narrative, so this post really spoke to me.</p><p>The more useful half of the piece applies sociologist <a href="https://sk.sagepub.com/book/mono/frameworks-of-power/chpt/circuits-power-framework-analysis#_">Stewart Clegg&#8217;s &#8220;circuits of power&#8221; framework</a> to explain why security programs succeed or fail. Clegg identifies three circuits: </p><ul><li><p>Episodic (direct face-to-face power)</p></li><li><p>Dispositional (cultural norms and policies)</p></li><li><p>Facilitative (infrastructure and systems that enforce behavior automatically) </p></li></ul><p>Venables&#8217; argument is that security teams burn out because they fight <strong>Episodic</strong> battles (e.g., an executive demanding an MFA exception) using <strong>Dispositional</strong> arguments (pointing at policy). The sustainable answer is to invest in <strong>Facilitative</strong> circuits: make the secure path the easiest path through automation and technical controls, so the argument never has to happen in the first place. It&#8217;s a framework that maps cleanly onto the maturity difference between security programs that rely on enforcement and programs that rely on design.</p><div><hr></div><h3><strong>What the post-quantum executive order demands of CISOs</strong></h3><p><a href="https://cyberscoop.com/trump-executive-order-post-quantum-encryption-deadline/">The new post-quantum cryptography executive order</a> sets two hard deadlines for federal systems: key establishment transitions to PQC by December 31, 2030, and digital signatures by December 31, 2031. <a href="https://cyberscoop.com/post-quantum-cryptography-readiness-ciso-deadlines-op-ed/">Ellen Boehm&#8217;s piece in CyberScoop</a> makes the case that CISOs outside the federal government shouldn&#8217;t treat these as someone else&#8217;s problem. The immediate concern she raises isn&#8217;t the deadline itself, but that  &#8220;Harvest Now, Decrypt Later&#8221; attacks are already underway, with nation-state adversaries collecting encrypted data today to hold until quantum capabilities can break it. Long-lived sensitive data like IP, health records, financial transactions, government communications, etc. may already be compromised in ways that won&#8217;t become visible for years.</p><p>The practical challenge Boehm identifies is less about cryptography than about visibility and program management. Most organizations don&#8217;t have an inventory of where cryptography actually lives across their environment - which algorithms, which systems, which third-party dependencies, which certificates and keys. Without that, risk assessment is guesswork. She frames the end goal as crypto-agility: not a one-time algorithm swap, but a managed, living view of the organization&#8217;s trust infrastructure that adapts as standards evolve. Do you know where your cryptographic risk lives? Do you have a funded migration plan that maps to the EO deadlines? </p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>In my security leadership course, we discuss ways to strike the right balance between operational fire fighting and improvement initiatives/project work. This is super important when there will always be tension between the two, and maybe never more than now. The through-line this week is that the gap between where attackers operate and where most security programs focus keeps widening, and it&#8217;s widening in multiple dimensions. While the tactical picture is shifting, the organizational picture is too: ransomware groups are running structured negotiation playbooks while most IR teams are still improvising; security leaders are fighting policy battles while the leverage is actually in system design; and post-quantum migration is already inside current planning horizons while most cryptographic inventories don't exist yet. </p><p>If you&#8217;ve been in security a while, you know that these problems have been visible for a while, but they&#8217;re now becoming unavoidable. The question isn&#8217;t whether to address them, it's whether your program has the organizational structure, visibility, and funded roadmap to actually move in the right direction. </p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #59: AI As An Accelerant]]></title><description><![CDATA[The bar for sophistication and scale gets lower as red and blue teams look to innovate.]]></description><link>https://markaorlando.substack.com/p/security-leadership-59-ai-as-an-accelerant</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-59-ai-as-an-accelerant</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 24 Jun 2026 12:27:24 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/13bb45fe-74d2-492c-9523-7ce237264983_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #59 of Security Leadership Weekly! This week's issue sits at the intersection of two forces: AI as an accelerant for both attackers and defenders, and the continued erosion of the traditional perimeter via trusted integrations and authorized access. Tl;dr: it&#8217;s chaos! The Five Eyes agencies issued a joint warning, framing AI-driven cyber risk as a leadership crisis measured in months, while new research reframes shadow AI as less of a data leakage problem and more of an access control gap. </p><p>Meanwhile, the Klue breach gave us a live case study in how OAuth integrations can become vectors for lateral movement, and new research is reframing shadow AI less as a data leakage problem and more as an access control gap. On the people side, Carl Froggett's dual CISO/CIO role at Deep Instinct makes one wonder what the CISO function might look like in the future, as security becomes inseparable from technology strategy and business operations.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3>Shadow AI Is An Access Control Problem</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!BDli!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!BDli!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png 424w, /__u/substackcdn.com/image/fetch/$s_!BDli!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png 848w, /__u/substackcdn.com/image/fetch/$s_!BDli!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png 1272w, /__u/substackcdn.com/image/fetch/$s_!BDli!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!BDli!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png" width="713" height="422.4736842105263" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:698,&quot;width&quot;:1178,&quot;resizeWidth&quot;:713,&quot;bytes&quot;:1373004,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/203147394?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab09f45a-9760-4f98-a11e-19dbde6f2e1c_1402x1122.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!BDli!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png 424w, /__u/substackcdn.com/image/fetch/$s_!BDli!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png 848w, /__u/substackcdn.com/image/fetch/$s_!BDli!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png 1272w, /__u/substackcdn.com/image/fetch/$s_!BDli!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82ca44fc-9afc-4a8a-8487-7d3a9dc7c52e_1178x698.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The &#8220;first generation&#8221; response to shadow AI - DLP rules, domain blocks, usage policies - was designed to prevent employees from pasting sensitive data into ChatGPT. But the risk has moved beyond that use case now that employees are connecting AI tools directly to corporate systems via OAuth integrations, granting those tools access to email, calendars, code repositories, and CRM data. The real exposure here is what permissions an unsanctioned AI application holds after that OAuth handshake completes.</p><p>The Hacker News ran <a href="https://www.token.security/lp/autonomous-but-not-controlled-ai-security-data-report-csa">a vendor-sponsored piece by Token Security</a> framing AI agents as identity and governance problems, noting that agents &#8220;access data, trigger workflows, deploy code, and interact with critical business systems, often with little oversight.&#8221; Separately, <a href="https://thehackernews.com/2026/06/forget-data-leakage-shadow-ais-real.html">The Hacker News published an analysis</a> arguing that shadow AI&#8217;s primary risk has shifted from data leakage to access control, specifically pointing to the gap between what AI integrations are authorized to do and what security teams can actually observe. The takeaway is basically that an AI tool connected to your Salesforce via OAuth looks identical to the Klue integration that compromised Huntress this week (see below).</p><p>Your DLP-era shadow AI controls are not sufficient for these kinds of risks. The question to put to your security engineering team is whether your existing OAuth review and app governance processes cover AI-category applications, or were those processes designed for conventional SaaS integrations. <strong>If you&#8217;ve got a shadow IT discovery tool, verify it enumerates AI applications with active OAuth grants, not just browser-based AI usage or domain-based discovery.</strong></p><div><hr></div><h3>Webinar: Device Code Phishing in 2026</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!WS_Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!WS_Z!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!WS_Z!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!WS_Z!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!WS_Z!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!WS_Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg" width="800" height="417" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:417,&quot;width&quot;:800,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;graphical user interface, application&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="graphical user interface, application" title="graphical user interface, application" srcset="/__u/substackcdn.com/image/fetch/$s_!WS_Z!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!WS_Z!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!WS_Z!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!WS_Z!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F468a7a50-ebe9-4701-bf72-99de408e4391_800x417.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>My Push Security colleague and VP of R&amp;D, Luke Jennings, is delivering a research-focused session that goes behind the scenes of device code phishing - including live demos, real examples from kits and campaigns in the wild, and a practical look at what security teams can do about it. </p><p>At the start of 2026, device code phishing was still a niche technique associated with Russian state-linked campaigns. Six months later, we&#8217;re tracking 18x kits in the wild, a 37x spike in detections, and it feels like every PhaaS vendor in the AiTM space has added device code phishing to their platform. Strong passwords, MFA, even passkeys: it sidesteps the standard login process altogether by targeting the authorization layer. Once an attacker has a valid token, a single phished session can quickly escalate into broad access across an organization&#8217;s connected apps and services. </p><p>The session is on June 30 at 10:00 AM BST. You can register <a href="https://pushsecurity.com/webinar/device-code-phishing">here</a>. </p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3>FortiBleed Mass Compromise Hits 86,000+ Devices</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Ay56!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Ay56!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Ay56!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Ay56!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Ay56!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Ay56!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg" width="725" height="378.6111111111111" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:900,&quot;resizeWidth&quot;:725,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;What Is FortiBleed? What It Is, What It Isn't, and How Logically Is  Responding&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="What Is FortiBleed? What It Is, What It Isn't, and How Logically Is  Responding" title="What Is FortiBleed? What It Is, What It Isn't, and How Logically Is  Responding" srcset="/__u/substackcdn.com/image/fetch/$s_!Ay56!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Ay56!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Ay56!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Ay56!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f6a95b4-6f61-4c1d-b4cc-76a062f6e822_900x470.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The &#8220;FortiBleed&#8221; campaign, <a href="https://thehackernews.com/2026/06/cisa-warns-fortinet-customers-as.html">attributed by CISA to Russian-speaking threat actors</a>,  systematically extracted credentials from roughly half of all internet-accessible Fortinet firewalls and VPNs - 86,000+ devices. So the attack surface is basically every organization that left a Fortinet appliance internet-exposed without rotating credentials after prior Fortinet vulnerabilities were disclosed over the last two years.</p><p><a href="https://www.bleepingcomputer.com/news/security/cisa-warns-fortinet-users-to-secure-devices-after-fortibleed-leak/">CISA issued an urgent advisory</a> last week urging Fortinet customers to take immediate action against the ongoing campaign. The CISA advisory and <a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/">SecurityWeek&#8217;s coverage</a> both frame this as an ongoing campaign rather than a point-in-time breach, though the precise exploitation vector hasn&#8217;t been disclosed publicly.</p><p>If your organization runs Fortinet firewalls or VPN concentrators (or inherits them through an acquisition or managed service provider), treat the credentials on those devices as compromised until proven otherwise. </p><div><hr></div><h3>The Klue Breach: A Case Study in OAuth Attacks</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!JBkX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!JBkX!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!JBkX!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!JBkX!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!JBkX!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!JBkX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg" width="716" height="363.9866220735786" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:304,&quot;width&quot;:598,&quot;resizeWidth&quot;:716,&quot;bytes&quot;:13277,&quot;alt&quot;:&quot;Category Leader Klue Raises $62M to Accelerate its Competitive Enablement  Platform&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Category Leader Klue Raises $62M to Accelerate its Competitive Enablement  Platform" title="Category Leader Klue Raises $62M to Accelerate its Competitive Enablement  Platform" srcset="/__u/substackcdn.com/image/fetch/$s_!JBkX!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!JBkX!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!JBkX!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!JBkX!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa05d9450-b35b-4e28-92f1-ad8951c5de63_598x304.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Klue incident, in which attackers abused OAuth tokens to exfiltrate data from the Salesforce instances of Klue&#8217;s customers (<a href="https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/">including security vendors Huntress and Recorded Future</a>), is the latest public case study of OAuth token abuse. Third-party SaaS integrations that hold persistent OAuth tokens to your core platforms are effectively trusted insiders, and most security teams have no visibility into what those tokens can reach. The Salesforce-to-Klue connection wasn&#8217;t a misconfiguration, but an authorized integration that became a lateral movement vector when Klue itself was compromised.</p><p>Salesforce confirmed it disabled the Klue Battlecards app integration after the June 11 incident, noting that customers will be unable to reconnect until further notice. <a href="https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/">SecurityWeek reported</a> that the exfiltrated data came from Klue customers&#8217; Salesforce instances, meaning the attacker&#8217;s access to Klue translated directly into access to customer data on a separate platform via OAuth token abuse. That Huntress and Recorded Future appear in the affected customer list underscores that this isn&#8217;t a hygiene failure by unsophisticated teams - it&#8217;s a problem with how OAuth-based integrations are architected and monitored.</p><p><strong>This week, ask your IAM or security engineering team to enumerate every third-party application with active OAuth tokens in your Salesforce, Microsoft 365, Google Workspace, and other core SaaS platforms</strong>. Then, ask which of those apps hold tokens with write or export permissions, and when those tokens were last reviewed. </p><div><hr></div><h3><strong>Five Eyes Cyber Security Agencies Statement</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!GXGI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!GXGI!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png 424w, /__u/substackcdn.com/image/fetch/$s_!GXGI!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png 848w, /__u/substackcdn.com/image/fetch/$s_!GXGI!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png 1272w, /__u/substackcdn.com/image/fetch/$s_!GXGI!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!GXGI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png" width="382" height="132" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:132,&quot;width&quot;:382,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Five Eyes cyber security agencies ...&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Five Eyes cyber security agencies ..." title="Five Eyes cyber security agencies ..." srcset="/__u/substackcdn.com/image/fetch/$s_!GXGI!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png 424w, /__u/substackcdn.com/image/fetch/$s_!GXGI!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png 848w, /__u/substackcdn.com/image/fetch/$s_!GXGI!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png 1272w, /__u/substackcdn.com/image/fetch/$s_!GXGI!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1ead53-4bd3-4817-87af-0333a9c1d95c_382x132.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The cybersecurity agencies of all five Five Eyes nations - the U.S. (NSA/CISA), U.K., Australia, Canada, and New Zealand - issued <a href="https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/">a joint statement</a> this week calling AI-driven cyber risk an immediate leadership crisis. The agencies warn that frontier AI models are anticipated to fundamentally transform both offensive and defensive cyber capabilities on a timeline of months, not years, and that AI is already lowering barriers for malicious actors, increasing attack speed and complexity, and shrinking the window between vulnerability discovery and exploitation. The statement is notable for its tone: this isn&#8217;t an advisory aimed at security teams. It&#8217;s addressed explicitly at boards and executives.</p><p>The practical guidance is deliberately unglamorous and probably not groundbreaking for defenders out there: reduce your attack surface, accelerate patching, address legacy systems, strengthen identity and access controls, and test your incident response plans before you need them. The agencies acknowledge none of this is new, but frame it as newly <em>urgent</em>. Cyber resilience, they argue, is no longer an IT issue; it is central to operational continuity and market trust, and leaders who delay will face growing and avoidable risk. The full statement and accompanying guidance document are worth sharing up your chain if you&#8217;re still working to get executive attention on security fundamentals.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3>CISO Perspectives with Carl Froggett, CISO &amp; CIO, Deep Instinct</h3><p><a href="https://www.securityweek.com/ciso-conversations-carl-froggett-combining-ciso-and-cio-at-deep-instinct/">An interesting entry in SecurityWeekly&#8217;s CISO Perspectives</a> series, as Carl Froggett holds both the CISO and CIO titles simultaneously. He makes a strong case that both roles ultimately serve the same purpose - supporting the business - creating natural overlap. Combining both roles would be unmanageable at a company like Citi with 200,000+ employees, but it works well at Deep Instinct with fewer than 200. The lesson isn&#8217;t that every company should merge the roles; it&#8217;s that the roles share more DNA than org charts typically reflect. </p><p>Froggett&#8217;s combined role is a live experiment on whether the CISO, as a standalone function, makes long-term sense as security becomes inseparable from technology strategy, risk management, and business operations more broadly (something I sometimes wonder). His experience suggests the roles are more complementary than competitive, and that the main cost of merging them is the loss of an independent check; something that&#8217;s manageable with the right culture, but harder to engineer at scale. Worth watching how this plays out across the industry over the next few years.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>The throughline across this week's stories is that the security perimeter has been replaced by the authorization layer, and most organizations are underinvesting in visibility there. The Klue breach shows what happens when a trusted OAuth integration becomes a supply chain vector; the shadow AI piece argues that unsanctioned AI tools present the same risk profile as the Klue-to-Salesforce connection; and the Five Eyes statement, while diplomatically restrained in its recommendations, is essentially telling boards that attackers are moving faster than defenders can patch or govern. </p><p>Device code phishing follows the same logic: bypass the credential layer entirely by targeting the token post-authentication. The FortiBleed campaign is the outlier in this kind of post-auth mechanism, but not in theme: credentials on internet-exposed appliances were treated as durable trust anchors loooong after they should have been rotated. The practical question to carry into next week is whether your identity and access governance processes - OAuth reviews, token enumeration, app governance -were designed for the threat model you had three years ago or the one you have now.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #58: The Maginot Line]]></title><description><![CDATA[A failure not of investment, but of adaptation.]]></description><link>https://markaorlando.substack.com/p/security-leadership-58-the-maginot</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-58-the-maginot</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 10 Jun 2026 12:32:14 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/99ae2191-2801-411c-ba4e-252e4bf8f956_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #58 of Security Leadership Weekly! In 1940, France had the most sophisticated fixed fortifications in the world. The Maginot Line was an engineering marvel built to stop a direct land invasion cold. It worked great, and the German army went around it in three days.</p><p>The security industry has its own Maginot Lines. Backup infrastructure to restore encrypted systems, DLP tools that monitor managed endpoints, PAM scoped to human identities, etc. Each one is a genuine (and, in many cases, still very necessary) capability, built to stop a threat that has since changed tactics.</p><p>This week&#8217;s issue is largely about that gap. The Maginot Line wasn&#8217;t a failure of investment; it was a failure of adaptation. Which of your defenses are guarding a border that the attacker has already stopped crossing?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3>Backups Out as Ransomware Defense?</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!qb2D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!qb2D!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!qb2D!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!qb2D!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!qb2D!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!qb2D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg" width="725" height="378.9326792963464" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1545,&quot;width&quot;:2956,&quot;resizeWidth&quot;:725,&quot;bytes&quot;:382106,&quot;alt&quot;:&quot;turned-on monitor displaying 12:21:33&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="turned-on monitor displaying 12:21:33" title="turned-on monitor displaying 12:21:33" srcset="/__u/substackcdn.com/image/fetch/$s_!qb2D!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!qb2D!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!qb2D!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!qb2D!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F529ca39b-7b7d-4c42-9ce6-d8af55e99304_2956x1545.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Encryptionless extortion (data theft without encryption) is now a primary attack pattern, according to <a href="https://www.blackfog.com/the-state-of-ransomware-2026/">BlackFog&#8217;s 2026 state-of-ransomware report</a>. If your ransomware response plan is organized around &#8220;restore from backup,&#8221; it probably doesn&#8217;t cover the actual leverage the attacker&#8217;s got: the data they&#8217;ve already exfil&#8217;ed. </p><p>BlackFog&#8217;s report (vendor report, so treat as directional) documents the shift toward exfiltration-only attacks as a deliberate response to improved enterprise backup practices. This tracks with <a href="https://techcrunch.com/2026/06/07/the-worst-hacks-and-breaches-of-2026-so-far/">TechCrunch&#8217;s mid-year breach roundup</a>, which independently documents ShinyHunters running simultaneous multi-target extortion campaigns against Canvas/Instructure (275M records), Charter/Spectrum (40M), and others, with 30&#8211;60 day breach-to-disclosure windows that the group uses to run parallel extortion tracks across victims before any single company can respond. We&#8217;ve written extensively about SH&#8217;s preference for identity attacks and highly automated attack chains <a href="https://pushsecurity.com/blog/analyzing-the-instructure-breach/">at my day job</a>.  </p><p><a href="https://sharkstriker.com/blog/june-2026-data-breaches/">The SharkStriker June 2026 breach roundup</a> also confirms active extortion campaigns by Qilin, Play, Abyss, Akira, LockBit, and INC_RANSOM - a crowded market that creates competitive pressure to exfiltrate rather than encrypt, since speed to leverage matters more than operational disruption. And finally, the <a href="https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf">ODNI 2026 Annual Threat Assessment</a> adds a layer: nation-states are increasingly using these criminal ransomware groups as proxies, meaning some &#8220;financially motivated&#8221; extortion is serving intelligence collection objectives, not just monetization. I wrote about this blurring of the lines between criminal groups and nation-states in <a href="/__u/markaorlando.substack.com/p/security-leadership-57-the-hard-parts">the last issue of this newsletter</a>.</p><p><strong>So, what to do?</strong> Ask your IR lead and legal team what the playbook is when an attacker has already exfiltrated sensitive data before you detect them. It isn&#8217;t time to re-write your procedures around backup restoration, but <em><strong>do</strong></em> add an explicit exfiltration-only response track. Also, review your data classification and DLP coverage to understand what an exfiltration-only attack would likely target (or where it would be most damaging), and whether you&#8217;d detect it before the 30-day window closes.</p><div><hr></div><h3>AI Agents Are a Fast-Growing Identity Governance Problem </h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!8jM2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!8jM2!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!8jM2!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!8jM2!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!8jM2!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!8jM2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg" width="2841" height="1296" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1296,&quot;width&quot;:2841,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:651026,&quot;alt&quot;:&quot;blue and black robot figurine&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="blue and black robot figurine" title="blue and black robot figurine" srcset="/__u/substackcdn.com/image/fetch/$s_!8jM2!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!8jM2!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!8jM2!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!8jM2!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3a08bcd-eb2b-4a86-90f5-ed419cddd14b_2841x1296.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Agents that autonomously file tickets, execute scripts, provision resources, and interact with production environments have created an identity problem that existing PAM, UEBA, and IAM tooling are not built to handle. The sprawl is happening because, in many cases, AI agents are granted access rights under identity models designed for humans. <strong>Most enterprises don&#8217;t have an accurate inventory of agents currently in production</strong>, which means they can&#8217;t scope the problem, let alone govern it.</p><p><a href="https://investor.cisco.com/news/news-details/2026/Splunk-Report-Agentic-AI-Takes-Center-Stage-in-CISOs-Path-to-Digital-Resilience/default.aspx">The Cisco/Splunk 2026 CISO report</a> says agentic AI has moved from experimental to operational in most enterprise security programs, and flags AI agents with over-provisioned service accounts as an identity risk that PAM and UEBA programs won&#8217;t catch. <a href="https://www.bvp.com/atlas/securing-ai-agents-the-defining-cybersecurity-challenge-of-2026">Bessemer Venture Partners&#8217; analysis</a> found that 48% of cybersecurity professionals identify agentic AI as the single most dangerous attack vector, which would seem to support the assertion that most enterprises lack an agent inventory. Though I&#8217;m not aware of any real-world breaches achieved through compromised AI agent identities, this is probably something to revisit against other vulnerability management/threat modeling priorities. </p><p>A concrete starting point is to enumerate AI agents currently in production, identify the service accounts they operate under, and assess whether those accounts are in PAM scope - maybe check OAuth permission grants? The longer-term question to answer is whether your identity governance program covers non-human identities at all.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3>AI Eats the World by Benedict Evans</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!A2Re!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!A2Re!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!A2Re!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!A2Re!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!A2Re!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!A2Re!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg" width="1456" height="835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;No alternative text description for this image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="No alternative text description for this image" title="No alternative text description for this image" srcset="/__u/substackcdn.com/image/fetch/$s_!A2Re!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!A2Re!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!A2Re!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!A2Re!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff21edfd5-110e-4ae5-83b4-70229688d352_2048x1174.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Via Phil Venables, you do not want to sleep on <a href="https://www.ben-evans.com/presentations">this excellent presentation</a> (content-wise, but also, that design!) by independent analyst Benedict Evans, covering capital, deployment, institutional/operational change, and an analysis of AI as a transformative tech compared to previous generations.</p><div><hr></div><h3>CCCS Publishes Threat Bulletin on FIFA-themed Attacks</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!goGp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!goGp!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!goGp!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!goGp!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!goGp!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!goGp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg" width="2555" height="1181" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1181,&quot;width&quot;:2555,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:498955,&quot;alt&quot;:&quot;Houston Welcomes the World for the 2026 FIFA World Cup | Houston.org&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Houston Welcomes the World for the 2026 FIFA World Cup | Houston.org" title="Houston Welcomes the World for the 2026 FIFA World Cup | Houston.org" srcset="/__u/substackcdn.com/image/fetch/$s_!goGp!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!goGp!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!goGp!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!goGp!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F587a546c-a954-423b-a8da-8d0073a50679_2555x1181.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Canadian Centre for Cyber Security (CCCS) issued <a href="https://www.cyber.gc.ca/en/guidance/cyber-threat-bulletin-fifa-world-cup-2026tm">a formal FIFA 2026 threat bulletin</a> flagging phishing, fake streaming apps carrying banking malware, and AI-generated credential harvesting pages targeting employees. The CCCS assesses a high risk of targeting in the travel and hospitality, event management, infrastructure owners and operators, and services and sponsors tied to the tournament. It isn&#8217;t unusual to see topical lures and increased targeting around events like this, but given the expanding scale and sophistication of phishing and other social engineering attacks, it&#8217;s definitely worth looking out for.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3>CIRCIA&#8217;s 72-hour Clock is Running</h3><p>I wrote about CISA's final <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia">Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA</a>) rule in the last issue - the final rule is now enforceable, covering 300,000+ critical infrastructure entities across 16 sectors with a 72-hour reporting requirement for covered incidents and a 24-hour window for ransomware payments. What will probably bite most orgs is making a legally defensible &#8220;covered incident&#8221; determination before the investigation is complete, while the response team is still scoping the incident.</p><p>NIS2 requires a 24-hour initial notification to EU national authorities, so if you&#8217;re operating in both jurisdictions, a single incident could trigger three or four distinct reporting workflows with different deadlines and different content requirements.</p><div><hr></div><h3><strong>AI Compliance Is Now a Browser Problem</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ShVd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ShVd!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png 424w, /__u/substackcdn.com/image/fetch/$s_!ShVd!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png 848w, /__u/substackcdn.com/image/fetch/$s_!ShVd!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ShVd!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ShVd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png" width="1456" height="1031" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1031,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;ai regulation matrix&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ai regulation matrix" title="ai regulation matrix" srcset="/__u/substackcdn.com/image/fetch/$s_!ShVd!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png 424w, /__u/substackcdn.com/image/fetch/$s_!ShVd!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png 848w, /__u/substackcdn.com/image/fetch/$s_!ShVd!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ShVd!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ee7c6ac-112b-4ff3-a652-1bb3262a3356_2550x1806.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI regulations across the US, EU, and UK are converging on obligations related to how employees use AI tools. <a href="https://pushsecurity.com/blog/browser-visibility-and-control-can-achieve-ai-compliance/">This blog post</a> by Push Security&#8217;s Head of Legal, John Creaton, maps out five common obligation categories emerging across frameworks like the EU AI Act, DORA, NYDFS, and HIPAA: </p><ul><li><p>AI inventory and classification</p></li><li><p>Employee literacy and guidance</p></li><li><p>Data governance and exposure control</p></li><li><p>AI-resistant authentication</p></li><li><p>Third-party/supply chain risk</p></li></ul><p>The common failure across all five obligation categories is basically the same: organizations have policies but can&#8217;t demonstrate enforcement, because their tooling operates at the wrong layer. Some key takeaways:</p><ul><li><p><strong>Shadow AI is a compliance liability, not just a risk.</strong> You need a real-time inventory of AI apps, extensions, and OAuth integrations, not a spreadsheet.</p></li><li><p><strong>Policy isn&#8217;t enough; you need auditable evidence.</strong> Regulators want proof that employees received guidance <em>at the point of AI interaction</em>, not just in annual training.</p></li><li><p><strong>Browser-layer DLP closes a gap most platforms miss.</strong> Traditional DLP tools lack visibility into what users paste or upload directly into AI tools.</p></li><li><p><strong>Phishing-resistant MFA is becoming mandatory.</strong> Multiple frameworks now explicitly require it, and AI is making phishing attacks more convincing and harder to detect through traditional means.</p></li></ul><p>Of course, the browser is an excellent place to gain this kind of visibility and evidence which happens to be where Push operates :). But if you&#8217;re concerned about regulatory responsibilities related to AI, this is a great summary by a true expert.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>Three of this week&#8217;s stories are about a control that works, deployed against a threat that has moved on. Backups don&#8217;t stop exfiltration-only ransomware, PAM and UEBA weren&#8217;t built for non-human identities, and browser-blind DLP misses what employees paste into AI tools. In each case, the investment was sound, but attackers are starting to change the route.</p><p>CIRCIA&#8217;s 72-hour clock, 30-day breach-to-disclosure windows, and AI agents operating at machine speed all compress the window between something happening and you needing to have already responded. Adaptation matters, but so does the speed at which you adapt.</p><p>Some questions for your next team discussion: Do you have an exfiltration-only response track? An agent identity inventory? Auditable evidence of AI policy enforcement &#8212; not just the policy itself? If the answer to any of those is no, you&#8217;re defending a border the attacker stopped crossing a while ago.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #57: The Hard Part(s) of Being a CISO]]></title><description><![CDATA[The hardest part of being a CISO isn't technical.]]></description><link>https://markaorlando.substack.com/p/security-leadership-57-the-hard-parts</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-57-the-hard-parts</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 27 May 2026 12:29:50 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/0eac8298-ca03-45c3-b710-dcc7881d510d_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!B8rG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!B8rG!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!B8rG!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!B8rG!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!B8rG!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!B8rG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg" width="699" height="393.1875" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:450,&quot;width&quot;:800,&quot;resizeWidth&quot;:699,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!B8rG!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!B8rG!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!B8rG!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!B8rG!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F747faede-be7f-4eff-9834-27ee629a0169_800x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Welcome to Issue #57 of Security Leadership Weekly! This week's content has less to do with CVEs, MITRE ATT&amp;CK techniques, or attack campaigns (though there&#8217;s still some of that). Being a CISO right now means making consequential decisions in domains where process, policies, or frameworks may not yet exist - where nation-states borrow criminal playbooks to confuse attribution, regulatory deadlines arrive before compliance frameworks mature, and where the supply chain you're responsible for securing extends into code repositories you've never audited and/or don&#8217;t control. The technical problems are <em>really </em>hard. The leadership problems, such as governing in ambiguity, framing risk for audiences who want certainty, and building institutional readiness for scenarios that haven't happened yet, may be harder. This week, we&#8217;ve got a bit of both.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3>Nation-State Actors Are Blurring the Line Between Criminal and State Operations</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!8DA9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!8DA9!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!8DA9!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!8DA9!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!8DA9!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!8DA9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg" width="725" height="379.11211129296237" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1278,&quot;width&quot;:2444,&quot;resizeWidth&quot;:725,&quot;bytes&quot;:670569,&quot;alt&quot;:&quot;Chinese Telecom Hack: How to Protect Your Messages - National Cybersecurity  Alliance&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Chinese Telecom Hack: How to Protect Your Messages - National Cybersecurity  Alliance" title="Chinese Telecom Hack: How to Protect Your Messages - National Cybersecurity  Alliance" srcset="/__u/substackcdn.com/image/fetch/$s_!8DA9!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!8DA9!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!8DA9!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!8DA9!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e756a9e-e7b4-4da5-8bcd-1c8a6fd06eb1_2444x1278.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two threat intelligence reports this week describe how nation-states are increasingly using criminal ransomware and hacktivist groups as operational proxies, with similar goals: persistent access to critical infrastructure, intelligence collection, and disruption. If your threat model still differentiates between &#8220;financially motivated cybercrime&#8221; and&#8220;nation-state APT,&#8221; you&#8217;re using distinctions that are dissolving quickly.</p><p><a href="https://industrialcyber.co/reports/waterfall-threat-report-2026-finds-ransomware-slowdown-masks-deeper-shift-toward-nation-state-attacks-on-critical-infrastructure/">Waterfall&#8217;s 2026 threat report</a> tracks a drop in cyber incidents with physical consequences (25% in 2025), but a 100% increase in nation-state and hacktivist attacks, with MuddyWater&#8217;s use of the Qilin ransomware ecosystem as an example of state actors operating through criminal infrastructure. <a href="https://www.cyfirma.com/news/weekly-intelligence-report-22-may-2026/">CYFIRMA&#8217;s weekly intelligence report</a> flags China-linked group <a href="https://malpedia.caad.fkie.fraunhofer.de/actor/dagger_panda">UAT-7290</a> targeting U.S. and allied telecom providers through edge device vulnerabilities - access that serves intelligence collection, not ransomware monetization. Both are vendor-produced/unverified reports, but the pattern is well-documented public reporting on Russian and Iranian proxies using similar structures.</p><p>For most security leaders, the practical implication isn&#8217;t that you need to change up your defensive controls, but rather to change how you frame risk to boards and triage incident investigations. <strong>A ransomware intrusion that doesn&#8217;t proceed to encryption, or that targets operational technology networks rather than data, should trigger an APT hypothesis alongside the criminal one</strong>. Ask your threat intelligence function (or your IR retainer) whether your current escalation criteria would detect a nation-state actor using criminal tooling. </p><div><hr></div><h3>The AI-Driven SOC Revisited, by Rob Van Os</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!cNVQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!cNVQ!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png 424w, /__u/substackcdn.com/image/fetch/$s_!cNVQ!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png 848w, /__u/substackcdn.com/image/fetch/$s_!cNVQ!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cNVQ!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!cNVQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png" width="726" height="407.8078125" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:719,&quot;width&quot;:1280,&quot;resizeWidth&quot;:726,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Rob van Os&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Rob van Os" title="Rob van Os" srcset="/__u/substackcdn.com/image/fetch/$s_!cNVQ!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png 424w, /__u/substackcdn.com/image/fetch/$s_!cNVQ!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png 848w, /__u/substackcdn.com/image/fetch/$s_!cNVQ!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cNVQ!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F116d4cbc-3660-4a7f-9485-4250d43fcb50_1280x719.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you&#8217;re an operations leader who isn&#8217;t familiar with <a href="https://soc-cmm.com/">Rob&#8217;s SOC-CMM model</a>, it&#8217;s worth your time to get up to speed. Rob just dropped <a href="https://www.linkedin.com/pulse/ai-driven-soc-revisited-moving-beyond-alert-centric-security-van-os-jyjqe">this article on LinkedIn</a> describing a new operating model for an AI-driven SOC, with the following key principles:</p><ul><li><p>The operational relevance of zero-days is increasing due to faster exploitation cycles</p></li><li><p>SOCs are still dealing with ever-increasing event flows</p></li><li><p>The bottleneck for many SOCs is the number of alerts that can be processed </p></li><li><p>AIs are being embedded in SOC tooling, but value realization is still uneven and often limited to efficiency gains</p></li></ul><p>I value Rob&#8217;s practical approach to these models and, to that end, his basic assertion that SOC functions aren&#8217;t fundamentally changing. A great addition to the SOC-CMM library of resources, especially if you&#8217;re incorporating AI capabilities into your SOC functions.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3>Attackers Target Developer Credentials In CI/CD Pipelines (and other things we already knew)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!_Gym!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!_Gym!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!_Gym!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!_Gym!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!_Gym!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!_Gym!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg" width="719" height="361.6831983805668" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:497,&quot;width&quot;:988,&quot;resizeWidth&quot;:719,&quot;bytes&quot;:103683,&quot;alt&quot;:&quot;A MacBook with lines of code on its screen on a busy desk&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A MacBook with lines of code on its screen on a busy desk" title="A MacBook with lines of code on its screen on a busy desk" srcset="/__u/substackcdn.com/image/fetch/$s_!_Gym!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!_Gym!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!_Gym!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!_Gym!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b198ee4-d0e8-4fd2-bed3-c747cd09bbec_988x497.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@cgower">Christopher Gower</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>Multiple independent supply chain campaigns landed this week, with a common goal of harvesting cloud credentials, GitHub tokens, and deployment secrets from build systems. Most security leaders are aware, on some level, that secrets are often scattered throughout developer environments; attackers know this too, and have realized that these environments are less well-defended than the identity perimeter that most security programs have invested in hardening.</p><p><a href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/">According to Unit 42</a>, the &#8220;Mini Shai-Hulud&#8221; campaign embedded malware in four SAP npm packages with roughly 570,000 weekly downloads, explicitly targeting enterprise CI/CD pipelines for cloud credentials and deployment secrets. Separately, <a href="https://techcrunch.com/2026/05/19/hackers-have-compromised-dozens-of-popular-open-source-packages-in-an-ongoing-supply-chain-attack/">TechCrunch reports</a> that a single compromised developer account was used to push over 630 malicious package versions across 317 packages in approximately 20 minutes; a manual review process just isn&#8217;t going to work at this scale.</p><p>And the list goes on, including t<a href="https://thehackernews.com/2026/05/tanstack-supply-chain-attack-hits-two.html">he TanStack compromise</a> targeting OpenAI employees&#8217; devices and <a href="https://www.esecurityplanet.com/weekly-roundup/supply-chain-attacks-ai-security-and-major-breaches-define-this-week-in-cybersecurity-in-may-2026/">the Laravel-Lang/PHP campaign</a>, which added more than 700 compromised package versions. </p><p>This week, ask your AppSec or DevSecOps lead two questions: </p><ol><li><p>Do you have integrity verification (checksums, signed packages, lockfile enforcement) on every package your CI/CD pipelines pull at build time (not just production dependencies, but dev and build tooling as well)? </p></li><li><p>Are the credentials your build systems use scoped to least privilege and rotated on a schedule shorter than your MTTD? </p></li></ol><p>If either answer is unclear, prioritize clarity and filling the gaps. Also, be sure to check out <a href="https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/">this Wired piece on TeamPCP&#8217;s mass software supply chain exploitation</a> by Andy Greenberg and Lily Hay Newman (behind a pay wall).</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3>Most Security Programs Aren&#8217;t Ready for CIRCIA</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!lOSs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!lOSs!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!lOSs!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!lOSs!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!lOSs!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!lOSs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg" width="725" height="407.8125" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:725,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;CISA proposes new security requirements to protect govt, personal data&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="CISA proposes new security requirements to protect govt, personal data" title="CISA proposes new security requirements to protect govt, personal data" srcset="/__u/substackcdn.com/image/fetch/$s_!lOSs!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!lOSs!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!lOSs!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!lOSs!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda058b44-2ee3-4538-94eb-5b365d1823fc_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>CISA's final <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia">Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA</a>) rule - 72-hour incident reporting for about 300,000 entities across 16 critical infrastructure sectors, 24-hour reporting for ransomware payments - is expected to be finalized soon after the current lapse in Federal funding for CISA is resolved. The hard problem isn't the notification itself; it's making a confident, defensible determination within 72 hours that an incident is "covered" under CIRCIA's definition - most organizations still treat breach disclosure as an ad hoc task during incident response. Institutionalizing these disclosures will require documented triage criteria, logs sufficient to reconstruct a timeline, and <a href="https://www.fisherphillips.com/en/insights/insights/new-federal-cybersecurity-reporting-rules-are-on-their-way">pre-cleared legal counsel</a>. </p><p>At the same time, the SEC is elevating cybersecurity above cryptocurrency on its 2026 examination priority list, which means the appetite for regulatory enforcement (read: fines) is increasing even as implementation timelines slip. The bottom line is that time is running short for organizations to build out these compliance programs. </p><p>Two things most IR teams don't have documented: </p><ol><li><p>A sector-specific determination checklist defining what qualifies as a covered cyber incident under your CIRCIA designation</p></li><li><p>A logging architecture sufficient to establish the incident onset independently </p></li></ol><p>If you're in critical infrastructure and haven't done a CIRCIA readiness gap assessment, assign it to your GRC function as a Q3 priority. The rule can be implemented at any time, and the ramp-up period will likely be short.</p><div><hr></div><h2><strong>&#127897;&#65039;Media Roundup</strong></h2><h3>AI-Driven Hunting in Browser Telemetry with Jacques Louw</h3><p><strong><a href="https://au.linkedin.com/in/jwcto">James Wilson</a></strong> of the <a href="https://risky.biz/RBNEWSSI128/">Risky Bulletin Podcast</a> chats with Push Security Co-Founder and Chief Research Officer, <strong><a href="https://za.linkedin.com/in/jacques-louw-o-62608594">Jacques Louw</a></strong>, about how we&#8217;ve integrated AI agents into our threat detection platform, our careful approach to introducing agentic capabilities over time, and how it has helped our threat research team scale analysis and detection engineering functions. Great conversation on striking the right balance between human expertise and automation, with examples!</p><div><hr></div><h3>Ethics in Cybersecurity with Ed Skoudis and Paul J. Maurer</h3><p><strong><a href="https://www.linkedin.com/in/paul-j-maurer-346bb49/">&#8288;Paul J. Maurer&#8288;</a></strong> and <strong><a href="https://www.linkedin.com/in/edskoudis/">&#8288;Ed Skoudis&#8288;</a></strong> joined the <strong><a href="https://thecyberwire.com/podcasts/caveat">&#8288;Caveat&#8288;</a></strong> podcast with <strong><a href="https://www.linkedin.com/in/benjamin-yelin-5b14114b/">&#8288;Ben Yelin&#8288;</a></strong> this week to talk about their new book, "The Code of Honor: Embracing Ethics in Cybersecurity." The book lays out a code of ethics for cybersecurity, providing a decision framework that transcends cyber law. This is immensely useful since technology trends move so quickly that policy just can&#8217;t keep up (Ed mentions AI as an example). Ed&#8217;s perspective, based on decades of experience as a practitioner and instructor, and Paul&#8217;s legal expertise, make for an interesting episode and a must-read; I will definitely be checking this one out. You can hear the <a href="https://thecyberwire.com/podcasts/special-edition/97/notes">N2K Cyberwire episode here</a>.</p><div><hr></div><h3>Holding the Line: Episode One | Why the Hell Would Anyone Want to Be a CISO</h3><p>Great first episode of a web series from Nagomi Security and Hacker Valley Media, featuring interviews with experienced CISOs. This one covers the evolution of the role (and what it looks like today), mental health and burnout, and primary motivations of a CISO. </p><div id="youtube2-cL3_KMi0O4g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;cL3_KMi0O4g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/cL3_KMi0O4g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>The CISO role has always required translating technical complexity into business decisions, but the complexity keeps expanding faster than the frameworks designed to contain it. This week's content, from Rob Van Os's AI-enabled SOC operating model to the CIRCIA readiness gap to Ed Skoudis and Paul Maurer's ethics framework, reflects efforts to build those frameworks in real time. If you're a security leader feeling the weight of that ambiguity, you're not alone, and the field is producing better tools, models, and conversations to help carry it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #56: Working As Intended]]></title><description><![CDATA[MFA is working as intended, but you still get phished, and a CISA contractor's secrets scanner was intentionally disabled, resulting in a massive self-own.]]></description><link>https://markaorlando.substack.com/p/security-leadership-56-working-as</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-56-working-as</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 20 May 2026 12:14:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/0639eac8-95e5-4ae4-8a63-fd7c7a13e0c7_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #56 of Security Leadership Weekly! This week's stories share a quiet theme that I find more unsettling than any specific CVE: the gap between the controls security programs believe they have and the attack surface those controls actually cover. I&#8217;ve written about this before, and here we have more examples: device code phishing succeeds with MFA fully operational, and a CISA contractor&#8217;s GitHub secrets scanner was deliberately disabled (not misconfigured). Lack of controls isn&#8217;t the problem; they just don't reach the place where the attack is happening. Pair that with a RaaS group using your own DFIR tools for C2 and commercial LLMs for negotiation drafting, and a board communication lesson that applies to all of it, and you have a week that's less about new threats and more about the compounding cost of assuming you're covered.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3>Device-code Phishing Is An Authentication Architecture Problem</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!9gJ0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!9gJ0!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp 424w, /__u/substackcdn.com/image/fetch/$s_!9gJ0!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp 848w, /__u/substackcdn.com/image/fetch/$s_!9gJ0!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!9gJ0!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!9gJ0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp" width="348" height="292.8105726872247" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:382,&quot;width&quot;:454,&quot;resizeWidth&quot;:348,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Microsoft: Phishing Attack on Accounts Using Device Code - FPT IS - EN&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Microsoft: Phishing Attack on Accounts Using Device Code - FPT IS - EN" title="Microsoft: Phishing Attack on Accounts Using Device Code - FPT IS - EN" srcset="/__u/substackcdn.com/image/fetch/$s_!9gJ0!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp 424w, /__u/substackcdn.com/image/fetch/$s_!9gJ0!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp 848w, /__u/substackcdn.com/image/fetch/$s_!9gJ0!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!9gJ0!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d01fa43-9a38-4042-a5ae-327e3c2a4086_454x382.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/">Device-code phishing</a> works not because users are fooled into clicking a malicious link, but because they are directed to a<em> legitimate</em> Microsoft login page and complete MFA successfully. The attack exploits an OAuth 2.0 flow that was designed for devices without browsers (like apps on your new smartTV), and it bypasses MFA precisely because MFA is working exactly as intended. Security leaders who think their MFA deployment closes this gap are wrong: they&#8217;ve hardened the IdP layer while leaving the authorization grant layer exposed.</p><p>The <a href="https://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/">Tycoon2FA phishing kit</a> was disrupted by an international law enforcement operation back in March, then rebuilt on new infrastructure, and was back at normal operational tempo within weeks - now with device-code phishing capability added. <a href="https://www.esentire.com/blog/tycoon-2fa-operators-adopt-oauth-device-code-phishing">According to eSentire</a>, the attack routes victims through a four-layer obfuscated delivery chain before completing the authorization flow.</p><p>Based on <a href="https://pushsecurity.com/blog/device-code-phishing">our research at Push Security</a>, we&#8217;ve reported a 37x increase in device-code phishing this year across at least ten PhaaS platforms, and <a href="https://www.proofpoint.com/us/blog/threat-insight/device-code-phishing-evolution-identity-takeover">Proofpoint has independently documented a similar surge</a>.</p><p>What to ask your identity team this week: <em>Do our conditional access policies restrict or block the OAuth device authorization grant flow in our Microsoft 365 tenant? If not, what is the business justification for leaving it enabled?</em> </p><p>Many orgs haven&#8217;t turned on conditional access controls to block or constrain device-code flows, because a lot of phishing training still focuses on credential harvesting or because they&#8217;re using business applications that leverage device code auth. If your tenant allows device code authorization, a technically average attacker can get <strong>a persistent foothold that survives a password reset</strong>.</p><div><hr></div><h3>Governing the Machines: How to Detect and Respond to Compromised Agent Identities in Microsoft Entra</h3><p><a href="https://www.sans.org/webcasts/entra-agent-id-detection-response">In a May 2026 SANS Cloud Security presentation</a>, my SANS colleague Maxim Deweerdt walked through the architecture underpinning Microsoft&#8217;s Agent Identity framework - where agents are now treated as first-class Entra identities with their own tokens, Conditional Access evaluation, and lifecycle governance - and what that means when things go wrong. </p><p>The framework introduces a four-layer hierarchy: </p><ul><li><p>An Agent Identity Blueprint (the factory that mints agents)</p></li><li><p>A Blueprint Principal (the installer)</p></li><li><p>The Agent Identity itself (the runtime credential that calls APIs)</p></li><li><p>An optional Agent User (a linked user object for mailbox and Teams access). </p></li></ul><p>The <em>blueprint</em> is basically the blast radius: a compromised or misconfigured blueprint instantly affects every agent identity it spawned. Microsoft&#8217;s Identity Protection now surfaces agent-specific detections like unfamiliar resource access, sign-in spikes, and failed access attempts, though these remain offline rather than real-time. Response options include confirming compromise via the Risky Agents report, applying a Conditional Access block, disabling the Agent User, or deprovisioning via Microsoft Graph, each with distinct tradeoffs between speed and business impact. </p><p>CA policies cannot yet target individual Agent Users or block them based on risk signals, leaving only a coarse all-or-nothing block option. Max&#8217;s seven-step SOC readiness checklist provides a concrete path to get ahead of this emerging identity attack surface before risky agent alerts start landing in their queues. Really great presentation worth checking out if you&#8217;re an Entra shop managing AI identities.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3>The CISA GitHub Leak Is a CI/CD Hygiene Story, and Your Organization Probably Has the Same Problem</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!uYkV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!uYkV!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png 424w, /__u/substackcdn.com/image/fetch/$s_!uYkV!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png 848w, /__u/substackcdn.com/image/fetch/$s_!uYkV!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png 1272w, /__u/substackcdn.com/image/fetch/$s_!uYkV!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!uYkV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png" width="577" height="337.39830508474574" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:1180,&quot;resizeWidth&quot;:577,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;How We Got a CISA GitHub Leak Taken Down in Under a Day&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="How We Got a CISA GitHub Leak Taken Down in Under a Day" title="How We Got a CISA GitHub Leak Taken Down in Under a Day" srcset="/__u/substackcdn.com/image/fetch/$s_!uYkV!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png 424w, /__u/substackcdn.com/image/fetch/$s_!uYkV!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png 848w, /__u/substackcdn.com/image/fetch/$s_!uYkV!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png 1272w, /__u/substackcdn.com/image/fetch/$s_!uYkV!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc96bf1e0-e6db-40cc-97fe-bc39d28db4b1_1180x690.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A contractor for CISA (people I may or may not have worked with previously, but I digress) deliberately disabled GitHub&#8217;s built-in secret scanning, stored AWS GovCloud administrative credentials and plaintext passwords in a public repository, and used it as a personal sync scratchpad across environments. Plenty of room for criticism here, but from a governance standpoint, it&#8217;s the predictable result of giving developers and contractors the ability to <em>opt out</em> of secrets management controls. When secrets controls are bypassable, CI/CD tooling creates persistent credential sprawl, and the problem is exacerbated by contractor environments that sit outside the security controls applied to full-time staff. I thought CMMC was supposed to solve this? Jk. Kind of.</p><p><a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/">Krebs on Security</a> reported that the public GitHub repository named &#8220;Private-CISA&#8221; contained AWS GovCloud administrative keys (in a file <em>literally</em> named &#8220;importantAWStokens&#8221;), a CSV of plaintext usernames and passwords for dozens of internal CISA systems, and internal deployment code for CISA&#8217;s DevSecOps environment. The researcher who discovered it, <a href="https://blog.gitguardian.com/how-we-got-a-cisa-github-leak-taken-down-in-26-hours/">Guillaume Valadon of GitGuardian</a>, noted that the account owner had explicitly disabled GitHub&#8217;s default secrets-detection feature; so this wasn&#8217;t an accidental misconfiguration, <strong>it was an active opt-out</strong>. We don&#8217;t yet know how long the credentials were exposed, whether anyone other than the researchers accessed them before discovery, and whether any GovCloud services were actually compromised or merely at risk.</p><p>The audit question for your team is: <em>can your developers and contractors disable or bypass your secrets scanning controls, and does your organization know when that happens?</em> GitHub&#8217;s push protection can be bypassed at the repository level if administrators allow it; the default is protective, but the override is usually easy. In the next 30 days, have your security engineering team verify that secrets scanning is enforced at the organization level across your GitHub (and GitLab, Bitbucket, Azure DevOps) estate, with contractor and third-party repositories explicitly in scope. The CISA incident also exposes a contractor oversight gap that belongs on a board risk agenda: <em>do your third-party developers operate under the same credential and secrets management controls as internal staff, and how would you know if they didn&#8217;t?</em></p><div><hr></div><h3>&#8220;The Gentlemen&#8221; Ransomware Group Exposed: Inside a Major RaaS Operation</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="493" height="277.1962264150943" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2384,&quot;width&quot;:4240,&quot;resizeWidth&quot;:493,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;man in maroon suit jacket beside window with railings&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="man in maroon suit jacket beside window with railings" title="man in maroon suit jacket beside window with railings" srcset="https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1493146146946-e907f69cdf23?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzMXx8d2VsbCUyMGRyZXNzZWQlMjBtZW58ZW58MHx8fHwxNzc5MjIxOTY1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@hengfilms">Heng Films</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><a href="https://ransom-isac.org/blog/the-gentlemen-leak-analysis/">A detailed intelligence analysis</a> published by Ransom-ISAC this week offers a look inside The Gentlemen, a Russian-speaking ransomware-as-a-service (RaaS) group that emerged in mid-2025 and has since claimed over 400 victims globally. The report is based on 3,366 internal chat messages leaked in early May 2026 after the group&#8217;s hosting provider was compromised, revealing the operation&#8217;s full attack lifecycle: </p><ol><li><p>Initial access via Fortinet VPN exploitation (primarily CVE-2024-55591),</p></li><li><p>Lateral movement using NetExec and credential dumping tools</p></li><li><p>Data exfiltration via rclone</p></li><li><p>Double-extortion negotiations conducted through qTox. </p></li></ol><p>Analysts identified nine core operators, a custom C2 framework called G-BOT, and the repurposing of the legitimate DFIR tool Velociraptor as a command-and-control platform (<a href="https://thehackernews.com/2025/08/attackers-abuse-velociraptor-forensic.html">which we&#8217;ve seen before</a>). Notably, the group actively integrated commercial LLMs like ChatGPT and Claude for negotiation drafting, while also experimenting with locally-hosted uncensored AI models for triage of stolen data. Strong infrastructure and personnel links to the defunct Black Basta group, including a shared Matrix server and recurring operator handles across multiple leak corpora, support a moderate-to-high level of confidence that The Gentlemen represent a direct successor lineage. Security leaders should prioritize patching internet-exposed Fortinet devices if you aren&#8217;t already, monitor for SOCKS5 proxy traffic on non-standard ports as a lateral movement indicator, and note that the group has actively tracked its own victim rankings.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3>Your Board Deck Is Your Board Agenda, Whether You Like It or Not</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="570" height="380" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3648,&quot;width&quot;:5472,&quot;resizeWidth&quot;:570,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;people sitting on chair in front of table while holding pens during daytime&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="people sitting on chair in front of table while holding pens during daytime" title="people sitting on chair in front of table while holding pens during daytime" srcset="https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1517048676732-d65bc937f952?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxtZWV0aW5nfGVufDB8fHx8MTc3OTEzOTc5NHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@mainermedia">Dylan Gillis</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><a href="https://www.kellblog.com/the-board-deck-is-the-living-board-meeting-agenda/">Dave Kellogg published a post this week</a> that&#8217;s required reading for any CISO who has ever walked out of a board meeting frustrated. His argument is simple and a little uncomfortable: the board deck isn&#8217;t a document you present, it&#8217;s the de facto agenda of the meeting. Whatever&#8217;s in the slides will get discussed. Whatever isn&#8217;t, won&#8217;t. As he puts it, the meeting flows where the slides take it, like a raft in a river. Which means that if you built a 40-slide operations review and wanted a strategic conversation, you&#8217;re not getting one - you&#8217;re getting the ops review you showed up with.</p><p>Most CISO board decks are built the same way every quarter: open last quarter&#8217;s deck, update the numbers, swap in the new incidents and the new threat intel, and add the initiative you want funded. The structure never changes because nobody explicitly decided what this meeting should actually <em>be</em>. Kellogg identifies at least seven different types of board segments - ops review, discussion, proposal, presentation, update, working session - each one requiring a different slide approach. A discussion segment should have almost nothing on the slides: a little context, a few well-framed questions, and then deliberate blank space that signals the value is in the conversation, not the deck. A proposal needs a clear situation-recommendation-ask structure and should not surprise anyone who got a pre-meeting call. The discipline isn&#8217;t complicated; it just requires deciding, segment by segment, what kind of conversation you&#8217;re actually trying to have. Most of us skip that step entirely and then wonder why the board keeps spending forty minutes on patch metrics when we wanted to talk about AI risk.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>The device code phishing story and the CISA GitHub leak look unrelated on the surface, but they&#8217;re the same problem at different layers. In both cases, an organization assumed a control was providing coverage that it wasn&#8217;t. This pattern has shown up in this newsletter more than any other: in <a href="/__u/markaorlando.substack.com/p/security-leadership-45-features-not">#45</a> (&#8221;Your attack surface is working correctly&#8221;), in <a href="/__u/markaorlando.substack.com/p/security-leadership-48-ambition-without">#48</a> (&#8221;Ambition Without Capacity Isn&#8217;t a Strategy&#8221;), in the Stryker MDM wipe in <a href="/__u/markaorlando.substack.com/p/security-leadership-49-no-exploit">#49</a> where compromised admin credentials turned a patch management console into a mass-wipe tool. </p><p>The consistent lesson isn&#8217;t that the controls are bad, it&#8217;s that controls not scoped to actual adversary behavior create a false floor that&#8217;s worse than no floor at all. At least a missing control shows up as a gap in an audit.</p><p>The Entra Agent Identity piece is the same story in preview. Maxim&#8217;s presentation makes clear that Microsoft is building the governance architecture for AI agents in Entra in real time, but CA policies can&#8217;t yet target individual agents based on risk - meaning your coarsest control option is an all-or-nothing block. As <a href="/__u/markaorlando.substack.com/p/security-leadership-53-the-cost-of">I noted in issue #53</a> when covering CSA&#8217;s shadow AI research, 82% of organizations discovered an AI agent that security and IT didn&#8217;t know about; and that was <em>before</em> organizations started formally provisioning Entra identities for agents. <strong>The governance frameworks are arriving, but the attack surface is already here</strong>.</p><p>The Gentlemen leak deserves a second read for anyone who&#8217;s been tracking the AI-in-security-operations conversation. In <a href="/__u/markaorlando.substack.com/p/ai-commoditization-and-security-decision">my AI Commoditization essay</a>, I argued that AI models are becoming interchangeable infrastructure - that the model isn&#8217;t the moat. The Gentlemen are running that thesis from the offensive side: ChatGPT and Claude for negotiation drafts, locally-hosted uncensored models for data triage, switching between them based on what each job requires. This also connects directly back to <a href="/__u/markaorlando.substack.com/p/security-leadership-27-the-resilience">#27</a>, where Velociraptor first appeared as an attacker tool. Bottom line: <strong>legitimate tools don&#8217;t stay legitimate tools when there&#8217;s an active criminal economy for them.</strong></p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #55: Supply Chain All the Way Down]]></title><description><![CDATA[The Trusted Channel Problem]]></description><link>https://markaorlando.substack.com/p/security-leadership-55-supply-chain</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-55-supply-chain</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Thu, 14 May 2026 12:16:49 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2bfa561c-4530-4c6c-ad98-cfae9b1215ab_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #55 of Security Leadership Weekly! Software and AI model distribution channels have become a favorite delivery vector - this week&#8217;s most significant incidents started with attackers compromising or impersonating trusted delivery channels (download sites, ML repositories, CI/CD plugins, ad networks) rather than breaking through perimeter defenses, which means your software supply chain posture is more important than ever.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!z6JV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!z6JV!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!z6JV!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!z6JV!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!z6JV!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!z6JV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg" width="520" height="346.38709677419354" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:413,&quot;width&quot;:620,&quot;resizeWidth&quot;:520,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Meme: \&quot;We need to go deeper\&quot; - All Templates - Meme-arsenal.com&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Meme: &quot;We need to go deeper&quot; - All Templates - Meme-arsenal.com" title="Meme: &quot;We need to go deeper&quot; - All Templates - Meme-arsenal.com" srcset="/__u/substackcdn.com/image/fetch/$s_!z6JV!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!z6JV!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!z6JV!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!z6JV!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41b277c7-3842-4de5-a649-a5a695eb845a_620x413.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>Instructure/Canvas Breach: What We Know</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Lrjn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Lrjn!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Lrjn!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Lrjn!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Lrjn!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Lrjn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp" width="558" height="313.875" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:558,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;2nd Canvas data breach causes major disruptions for colleges | Higher Ed  Dive&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="2nd Canvas data breach causes major disruptions for colleges | Higher Ed  Dive" title="2nd Canvas data breach causes major disruptions for colleges | Higher Ed  Dive" srcset="/__u/substackcdn.com/image/fetch/$s_!Lrjn!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp 424w, /__u/substackcdn.com/image/fetch/$s_!Lrjn!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp 848w, /__u/substackcdn.com/image/fetch/$s_!Lrjn!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!Lrjn!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3206a03-c6cb-4cb8-a591-1dc043de0687_1200x675.webp 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Instructure, the edtech company behind the widely used Canvas learning management system, was breached by the ShinyHunters extortion group, which claimed to have stolen more than 3.6 TB of data (usernames, email addresses, course names, enrollment information, user messages). The attack affected over 30 million educators and students across more than 8,000 institutions worldwide - right in the middle of final exams. </p><p>ShinyHunters exploited cross-site scripting (XSS) vulnerabilities in Instructure&#8217;s Free-for-Teacher environment to obtain authenticated admin sessions and perform privileged actions. This was actually a return visit by SH; Instructure first detected unauthorized activity on April 29, and then on May 7, the attackers returned through the same unpatched vulnerability to deface Canvas login portals with extortion messages. A <em>previous</em> breach in September 2025, also claimed by ShinyHunters, had already compromised Instructure&#8217;s Salesforce instance, so it seems like the company has some questions to answer about their remediation practices and third-party risk posture.</p><p>This week, within the deadline SH had originally given for negotiations, <a href="https://www.bleepingcomputer.com/news/security/instructure-reaches-agreement-with-shinyhunters-to-stop-data-leak/">Instructure announced</a> it had &#8220;reached an agreement&#8221; with ShinyHunters - which sounds an awful lot like &#8220;we paid the ransom&#8221;. As part of the agreement, Instructure said the stolen data was returned (???) and it received digital confirmation of destruction in the form of &#8220;shred logs,&#8221; with ShinyHunters stating that no Instructure customers would be further extorted. Of course, there is no reliable way to verify data has actually been deleted or that the exposure has been fully remediated. </p><p>Key unanswered questions remain: Instructure has not disclosed the terms or financial value of the agreement, has not confirmed the full scope of affected users, and has not explained why the same Free-for-Teacher vulnerability was re-exploited a week after the initial breach. Security teams should also be alerting their communities to the elevated risk of follow-on spear-phishing campaigns leveraging real institutional context, like course names, advisor relationships, and sensitive private messages, which were captured in Canvas and now may be in criminal hands.</p><div><hr></div><h3><strong>AI-Generated Zero-Day Exploit Used in Active Criminal Campaign</strong></h3><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access/">Google&#8217;s Threat Intelligence Group (GTIG)</a> has identified what it describes as the first confirmed case of a threat actor using an AI-generated zero-day exploit in an active attack. According to GTIG, the exploit was developed by a prominent cybercrime group and was specifically designed to bypass two-factor authentication. This finding comes from a combination of Mandiant incident response engagements and GTIG&#8217;s proactive research, and it turns AI-assisted exploit development from a popular AI talking point into observed tradecraft.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!4BmJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!4BmJ!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!4BmJ!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!4BmJ!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!4BmJ!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!4BmJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg" width="1456" height="581" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:581,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;https://storage.googleapis.com/gweb-cloudblog-publish/images/gtig-ai-threat-tracker-feb26-fig1.max-1500x1500.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/gtig-ai-threat-tracker-feb26-fig1.max-1500x1500.jpg" title="https://storage.googleapis.com/gweb-cloudblog-publish/images/gtig-ai-threat-tracker-feb26-fig1.max-1500x1500.jpg" srcset="/__u/substackcdn.com/image/fetch/$s_!4BmJ!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!4BmJ!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!4BmJ!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!4BmJ!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc67b7a0a-0d33-4d4a-a17a-8886a867217e_1500x599.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What strikes me about this story isn&#8217;t that AI suddenly makes exploit development trivial (it doesn&#8217;t), but that it lowers the barrier to producing working exploits for groups that previously lacked the technical depth to develop them in-house. Your detection and patch velocity timelines should account for an abbreviated adversarial development cycle. The specific 2FA bypass targeting also reinforces a consistent pattern in which attackers <a href="https://pushsecurity.com/blog/mfa-downgrade-attacks">invest engineering effort in defeating or bypassing authentication controls</a> because they know that&#8217;s where defenses have hardened.</p><p>This research backs up <a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use">GTIG&#8217;s February report</a> on AI augmenting adversarial workflows, which is worth revisiting in light of this disclosure.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>Fake OpenAI Model Repository Delivered Rust-Based Infostealer to 244K+ Downloaders</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!8-RQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!8-RQ!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!8-RQ!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!8-RQ!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!8-RQ!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!8-RQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg" width="598" height="312.2888888888889" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:900,&quot;resizeWidth&quot;:598,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K  Downloads&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K  Downloads" title="Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K  Downloads" srcset="/__u/substackcdn.com/image/fetch/$s_!8-RQ!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!8-RQ!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!8-RQ!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!8-RQ!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb389bf2-d2d0-4df0-bee9-ec4164d187fd_900x470.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A malicious Hugging Face repository impersonating OpenAI&#8217;s legitimate &#8220;Privacy Filter&#8221; model reached the platform&#8217;s trending list and accumulated over 244,000 downloads before being disabled. According to <a href="https://www.hiddenlayer.com/research/malware-found-in-trending-hugging-face-repository-open-oss-privacy-filter">HiddenLayer&#8217;s research team</a>, the fake repo (Open-OSS/privacy-filter) shipped a loader.py file that, when executed, silently fetched and executed a Rust-based infostealer that harvested Discord tokens, cryptocurrency wallets, browser credentials, and system metadata. Hugging Face has disabled the repository, but the timeline of how long it remained live and whether affected users were directly notified is not publicly confirmed.</p><p>The 244,000 download figure probably doesn&#8217;t mean that many infections; views, stars, and clones are often conflated in these reports, and the infostealer required deliberate execution of a batch or Python script. But the problem here is that these ML model repositories have no meaningful supply-chain vetting equivalent to what package managers like PyPI or npm have built over years. </p><p>If your developers or data science teams are pulling models from Hugging Face as part of their workflow, they are doing so in an environment where typosquatting a trending model is trivial, and detection is reactive if it exists at all. The question to ask your teams this week is whether Hugging Face model pulls go through any review gate, or whether they land directly on developer or training infrastructure. More coverage of this story on <a href="https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html">The Hacker News</a>.</p><div><hr></div><h2><strong>Shared Claude Chats weaponized to target macOS users</strong></h2><p><a href="https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/">This BleepingComputer report</a> documents an active malvertising campaign (discovered by <a href="https://www.linkedin.com/posts/brkalbyrk7_macsync-ugcPost-7459229553027088384-7UXy?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAACt0_gBnCWA_RbX-4u_sM3vPDdsa88beO8">Berk Albayrak</a>, a security engineer at Trendyol Group) that&#8217;s essentially a new evolution of the InstallFix campaign my colleagues at Push Security <a href="https://pushsecurity.com/blog/installfix">discovered back in March</a>. Where InstallFix cloned legitimate install pages and swapped out the curl command, this campaign takes a more insidious approach: attackers are hosting malicious instructions inside Claude's own shared chat feature, so the Google Ads pointing to those chats show claude.ai as the verified destination URL (a genuine domain, not a lookalike). </p><p> The weaponized shared chats present themselves as official "Claude Code on Mac" installation guides attributed to Apple Support, directing users to open Terminal and paste a command that triggers an infostealer infection - the same ClickFix-style terminal-paste social engineering at the core of InstallFix, but delivered through a trusted AI platform rather than a cloned website. One variant performs geographic profiling first, checking for Russian or CIS-region keyboard inputs before proceeding; the other, a MacSync infostealer, skips profiling and goes straight to harvesting browser credentials, session cookies, and macOS Keychain contents. </p><div><hr></div><h3><strong>South Staffordshire Water Fined Following Ransomware Attack</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="477" height="315.92292619203135" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3042,&quot;width&quot;:4593,&quot;resizeWidth&quot;:477,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;water ripple&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="water ripple" title="water ripple" srcset="https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1535868118629-f37bcd69ff59?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0MHx8d2F0ZXJ8ZW58MHx8fHwxNzc4NTMyMzQ0fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@vlisidis">Terry Vlisidis</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>South Staffordshire Water, a UK utility supplying drinking water to 1.6 million people, <a href="https://therecord.media/uk-water-company-had-hackers-lurking-for-years">was fined &#163;963,900 ($1.3 million) by the UK's Information Commissioner's Office</a> after the Cl0p ransomware group spent nearly two years inside its network undetected. The group gained initial access in September 2020 via a malicious email attachment and wasn&#8217;t discovered until July 2022, when an IT performance slowdown triggered an internal investigation. By then, the attacker had escalated to full domain administrator privileges and exfiltrated data on 633,887 customers and employees, including bank account numbers, National Insurance numbers, and disability information, ultimately publishing it on the dark web. </p><p>The ICO's investigation found a cascade of basic security failures: </p><ul><li><p>As of December 2021, an outsourced SOC was monitoring just 5% of the company's IT environment</p></li><li><p>No internal or external vulnerability scans were conducted during the entire period of compromise</p></li><li><p>Some devices were still running Windows Server 2003</p></li><li><p>Two domain controllers remained unpatched against ZeroLogon, a critical privilege escalation vulnerability published in August 2020 (which the attacker successfully exploited). </p></li></ul><p>The regulator's message was blunt: "Waiting for performance issues or a ransom note to discover a breach is not acceptable - proactive security is a legal requirement, not an optional extra." The case lands as UK water suppliers face a record pace of cyberattacks and Parliament prepares to take up the Cyber Security and Resilience Bill, which would expand mandatory reporting requirements for critical infrastructure operators.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>Cloudflare&#8217;s AI-driven layoff of 1,100 employees</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!GcyP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!GcyP!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!GcyP!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!GcyP!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!GcyP!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!GcyP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg" width="508" height="332.85164835164835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:954,&quot;width&quot;:1456,&quot;resizeWidth&quot;:508,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Cloudflare Inc | Reuters&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Cloudflare Inc | Reuters" title="Cloudflare Inc | Reuters" srcset="/__u/substackcdn.com/image/fetch/$s_!GcyP!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!GcyP!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!GcyP!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!GcyP!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F274f3a27-4994-4a17-9a2c-ed4a3b1d56a2_6000x3933.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cloudflare announced a 20% workforce reduction (approx. 1,100 employees) despite reporting its strongest quarter ever, with $639.8 million in revenue representing 34% year-over-year growth. CEO Matthew Prince framed the cuts not as cost-saving measures but as a structural response to AI-driven productivity gains, citing a 600% increase in internal AI usage over just three months and claiming some employees have become up to 100 times more productive. The company's entire R&amp;D team is now using AI coding tools with autonomous agents reviewing all deployed code, and AI is being used across HR, finance, and marketing as well. Prince argued that this efficiency surge reduces the need for support roles, though he maintained that Cloudflare will continue hiring and expects to have more employees in 2027 than at any point in 2026 - a claim that reflects a broader and increasingly familiar pattern in tech, where AI productivity gains are being used to justify headcount reductions even amid strong financial performance.</p><p>A few interesting notes on this one, aside from the fact that it sucks when &#8220;healthy&#8221; companies do mass layoffs: </p><ul><li><p>The company&#8217;s stock <a href="https://www.thestreet.com/employment/cloudflare-stock-plummets-23-amid-ai-driven-layoffs">took a pretty big hit</a> following the earnings release and layoff announcement - 23% on Friday.</p></li><li><p>A <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-05-gartner-says-autonomous-business-and-artificial-intelligence-layoffs-may-create-budget-room-but-do-not-deliver-returns">new Gartner study</a> of 350 global business executives found that many companies have reduced their workforce regardless of whether AI was actually generating returns;  Gartner analyst Helen Poitevin says, "Workforce reductions may create budget room, but they do not create return. Organizations that improve ROI are not those that eliminate the need for people, but those that amplify them.</p></li><li><p>An Nvidia exec <a href="https://fortune.com/2026/04/28/nvidia-executive-cost-of-ai-is-greater-than-cost-of-employees/">made the following point about dubious cost efficiencies</a>: "For my team, the cost of compute is far beyond the costs of the employees," said Bryan Catanzaro, VP of applied deep learning at Nvidia. An AI and finance professor quoted in the same piece attributed this to hardware and energy raising operating costs for providers, creating a short-term mismatch, where AI use has remained less efficient than human labor.</p></li></ul><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>This week's incidents share a common theme: attackers aren't breaking down doors, they're walking through ones you've propped open. Shared Claude chats and Google Ads abuse the trust you extend to verified domains and AI platforms. The Hugging Face fake model repository exploits the absence of supply-chain vetting in ML tooling that your developers treat as routine infrastructure.</p><p>The perimeter isn't where the action is anymore; the action is in your delivery channels, your model repositories, your shared productivity tools, and the monitoring gaps you may be paying someone else to cover.</p><p>This week&#8217;s to-do list:</p><ol><li><p>Ask your development and data science teams to identify any Hugging Face repositories they pull into development or training pipelines, and confirm whether those pulls go through any integrity verification step (hash check, organizational review, or allowlist).</p></li><li><p> The South Staffordshire Water ICO finding is a useful forcing function for a board conversation about detection coverage. Pull your current mean-time-to-detect metrics and compare them against a two-year dwell scenario: would you have found it? </p></li></ol><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #54: Friction Down, Scale Up]]></title><description><![CDATA[Rentable tools and infrastructure, mass-exploitation speed up the attacker's OODA loops.]]></description><link>https://markaorlando.substack.com/p/security-leadership-54-friction-down</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-54-friction-down</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 06 May 2026 12:10:35 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/ccfe0cfa-749b-4865-8e15-399268436af5_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #54 of Security Leadership Weekly! This week: the economics of running an attack campaign. What once required significant time, resources, and coordination now comes packaged in dashboards and commodity toolkits. There&#8217;s a 37.5x spike in device code phishing since January of this year; that doesn&#8217;t happen because the threat actors are getting more skilled - it happens because the techniques have been <em>productized</em>. And there are similar stories this week around ConsentFix evolution, AI-powered vishing campaigns, and ransomware at scale. This is what happens when friction gets removed from attacker workflows and infrastructure. The question now is whether our defenses are priced for multi-stage, bespoke attack chains that no longer exist.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>cPanel Ransomware Attack Via Authentication Bypass Exploit</strong></h3><p>CVE-2026-41940, a CVSS 9.8 authentication bypass in <a href="https://www.cpanel.net/">cPanel </a>and WHM, has been under active exploitation since at least late February, and has now been weaponized at scale by the &#8220;Sorry&#8221; ransomware group. <a href="https://dashboard.shadowserver.org/nl/help/trending-queries/">Shadowserver has tracked at least 44,000 compromised cPanel IP addresses</a>; <a href="https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/">Rapid7 researchers have confirmed</a> that successful exploitation grants full control over the host system, its configurations, databases, and all websites it manages. The Sorry ransomware deploys a Go-based Linux encryptor using ChaCha20 with RSA-2048 key protection, meaning no decryption path exists without the threat actor&#8217;s private key. Multiple major hosting providers, including Namecheap, InMotion, KnownHost, and HostPapa, have emergency-firewalled their own customers off cPanel interfaces to slow the bleeding.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!0TFi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!0TFi!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!0TFi!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!0TFi!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!0TFi!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!0TFi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg" width="482" height="271.125" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:360,&quot;width&quot;:640,&quot;resizeWidth&quot;:482,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;r/cybersecurity - Critrical cPanel flaw mass-exploited in \&quot;Sorry\&quot; ransomware attacks&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="r/cybersecurity - Critrical cPanel flaw mass-exploited in &quot;Sorry&quot; ransomware attacks" title="r/cybersecurity - Critrical cPanel flaw mass-exploited in &quot;Sorry&quot; ransomware attacks" srcset="/__u/substackcdn.com/image/fetch/$s_!0TFi!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!0TFi!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!0TFi!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!0TFi!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f1d25cd-19d3-456a-967f-09d884905f67_640x360.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>cPanel sits at the base of an enormous amount of shared and managed hosting infrastructure, which means the blast radius isn&#8217;t just the organizations running cPanel; it extends to every tenant, customer, and downstream site on those servers (read: supply chain attack on the hosting side). If your organization relies on managed hosting providers or if you oversee web properties running on shared infrastructure,  confirm patch status and check whether your provider has applied the vendor-supplied detection tool. The broader pattern is familiar and worth flagging for your teams: zero-day exploitation with a months-long head start before public disclosure, followed by commodity ransomware operators piling in once the flaw goes public. </p><p><strong>Note</strong>: this mass-hosting compromise mirrors the Cordial/Snarky Spider SaaS extortion story below, though it uses different attack infrastructure. It&#8217;s basically the same dynamic of attackers moving faster than most organizations&#8217; patch and detection cycles.</p><h4><strong>Also Worth Tracking:</strong></h4><p>Via <a href="https://thehackernews.com/2026/05/cybercrime-groups-using-vishing-and-sso.html">The Hacker News</a>: <a href="https://www.crowdstrike.com/en-us/adversaries/cordial-spider/">Cordial Spider</a> and <a href="https://www.crowdstrike.com/en-us/adversaries/snarky-spider/">Snarky Spider</a> are running SaaS-only extortion campaigns using vishing to direct targets to SSO-themed AiTM pages. Detection is hard in these SaaS-based LOTL attacks because there&#8217;s no endpoint to examine, and because the attackers suppress device-registration notifications via inbox rules before pivoting to high-privilege accounts. Tough to establish baselines when you don&#8217;t see what&#8217;s happening.</p><p>Via <a href="https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/">BleepingComputer</a>: Microsoft Defender falsely flagged two DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, and removed them from the Windows trust store on affected systems. A fixed signature update is now available, but the incident intersects with a DigiCert breach in which attackers compromised a support analyst&#8217;s device and obtained initialization codes for a limited number of code-signing certificates, some of which were used to sign malware.  </p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>Linux Kernel &#8220;Copy Fail&#8221; Exploit Hits Cloud and Kubernetes at Scale</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!xDR1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!xDR1!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!xDR1!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!xDR1!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!xDR1!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!xDR1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg" width="490" height="248.828125" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:512,&quot;resizeWidth&quot;:490,&quot;bytes&quot;:10895,&quot;alt&quot;:&quot;May be a graphic of text that says '# root BREAKING NEWS -thehackernews.com New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions CVE-2026-31431 cVSS 7.8 flaw since 2017 enables root via 732-byte exploit, impacting major Linux distributions.'&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="May be a graphic of text that says '# root BREAKING NEWS -thehackernews.com New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions CVE-2026-31431 cVSS 7.8 flaw since 2017 enables root via 732-byte exploit, impacting major Linux distributions.'" title="May be a graphic of text that says '# root BREAKING NEWS -thehackernews.com New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions CVE-2026-31431 cVSS 7.8 flaw since 2017 enables root via 732-byte exploit, impacting major Linux distributions.'" srcset="/__u/substackcdn.com/image/fetch/$s_!xDR1!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!xDR1!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!xDR1!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!xDR1!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a703c12-7194-487a-90ba-6ad847baebe6_512x260.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31431">CVE-2026-31431</a>, dubbed &#8220;Copy Fail,&#8221; is a logic flaw in the Linux kernel&#8217;s AF_ALG cryptographic subsystem that allows any unprivileged local user to achieve full root access.  A working PoC was published by researchers at Theori and <a href="https://xint.io/blog/copy-fail-linux-distributions">Xint</a>, and Go and Rust versions have already appeared in open-source repositories. The exploit works by corrupting the kernel&#8217;s in-memory page cache of readable files, including setuid binaries like /usr/bin/su, without touching disk. </p><p>This is a good example of how various factors come together to bump up the urgency of remediation: a nine-year-old vuln, a working public exploit that doesn&#8217;t require race conditions or memory address guessing, in-memory-only execution that produces no disk artifacts, and default exposure in Kubernetes. Obviously patching is a priority, but a bigger question is whether you can detect in-memory privilege escalation that doesn&#8217;t touch disk, and whether your Kubernetes pod security policies restrict AF_ALG access. <a href="https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/">Microsoft notes</a> that exploitation has so far been primarily PoC-stage, but with multiple reimplementations in the wild and a <a href="https://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalog">CISA KEV designation</a>, the window before opportunistic threat actors operationalize this is narrowing. If you&#8217;re running multi-tenant cloud workloads or shared CI/CD pipelines, you should treat this as a priority this week.</p><div><hr></div><h3><strong>MFA Still Won&#8217;t Save You: ConsentFix v3 Reduces Friction</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!rlBA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!rlBA!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!rlBA!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!rlBA!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!rlBA!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!rlBA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg" width="473" height="266.0625" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:473,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;ConsentFix v3 attacks target Azure with automated OAuth abuse&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ConsentFix v3 attacks target Azure with automated OAuth abuse" title="ConsentFix v3 attacks target Azure with automated OAuth abuse" srcset="/__u/substackcdn.com/image/fetch/$s_!rlBA!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!rlBA!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!rlBA!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!rlBA!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfd8f2de-8c58-4ee4-b630-fb3ecab14f12_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Via <a href="https://www.bleepingcomputer.com/news/security/consentfix-v3-attacks-target-azure-with-automated-oauth-abuse/">Bill Toulas at BleepingComputer</a>: ConsentFix v3 is the latest iteration of a post-authentication, in-browser attack. The original ConsentFix was <a href="https://pushsecurity.com/blog/consentfix">discovered by my colleagues at Push Security</a> back in December as a ClickFix-style OAuth phishing attack that tricks victims into completing a legitimate Microsoft login flow, then pasting a localhost URL containing an OAuth authorization code back into an attacker-controlled page - effectively handing over account access <strong>without requiring a password or MFA bypass</strong>. v2 smoothed out the copy-paste friction with drag-and-drop, and now, v3 removes the manual backend steps entirely. When the victim interacts with the phishing page, the captured authorization code is automatically shipped to a Pipedream webhook and <em>immediately</em> exchanged for tokens, with post-exploitation handled through Specter Portal. </p><p>If you read our research on ConsentFix v1, you already know that Azure CLI is implicitly trusted in Entra ID as a first-party Microsoft app. It can&#8217;t be blocked or deleted by tenant administrators, requires no admin approval for permission grants, and can request scopes that third-party apps can&#8217;t - so standard app consent controls don&#8217;t apply. Phishing-resistant MFA doesn&#8217;t apply either, because the victim is completing a real authentication flow. The attack produces some detectable patterns: OAuth authorization code exchanges from unexpected IPs, token usage inconsistent with normal user behavior, and serverless platform endpoints like Pipedream appearing in OAuth redirect flows. If you&#8217;re not already monitoring browser telemetry, this is a good week to start.</p><div><hr></div><h3><strong>Push Security Threat Briefing: May 2026</strong></h3><p><a href="https://www.linkedin.com/pulse/push-security-threat-briefing-may-2026-push-security-itdie/">Push Security's May 2026 threat briefing</a> is out on LinkedIn! This month's edition covers the Vercel OAuth breach and shadow AI integrations in general, a 37.5x spike in device code phishing (!), the rise of fully automated vishing platforms like <a href="https://abnormal.ai/blog/athr-ai-voice-phishing-toad-attacks">ATHR</a>, the structural limits of extension risk scoring, and a detailed rundown of the ongoing ShinyHunters/SLH SSO-to-SaaS campaign - including fresh victims across ADT, McGraw-Hill, Rockstar Games, Medtronic, and the European Commission. If identity-based attacks and browser-native threats are on your radar (and they should be), give it a look.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>Five Eyes on Agentic AI</strong></h3><p>The NSA, CISA, Australia&#8217;s ASD ACSC, and their counterparts in Canada, New Zealand, and the UK jointly <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services">released guidance this week</a> on the secure adoption of agentic AI systems. The document was published the same week as the <a href="https://cloudsecurityalliance.org/blog/2026/04/28/the-shadow-ai-agent-problem-in-enterprise-environments">CSA&#8217;s shadow AI agent research</a> (covered in the last issue), and begs the question of whether private industry has any hope of keeping pace with AI deployment. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="508" height="338.6666666666667" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4000,&quot;width&quot;:6000,&quot;resizeWidth&quot;:508,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A hand holds a smartphone with various apps.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A hand holds a smartphone with various apps." title="A hand holds a smartphone with various apps." srcset="https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1744900647430-965ccc7a6078?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0Mnx8YWl8ZW58MHx8fHwxNzc3ODM3Nzk1fDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@almoya">Aerps.com</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>The guidance warns that strong governance, explicit accountability, rigorous monitoring, and human oversight are &#8220;not optional safeguards but essential prerequisites,&#8221; and recommends that organizations assume agentic AI systems may behave unexpectedly. They further recommend <strong>prioritizing resilience, reversibility, and risk containment</strong> over efficiency gains. Of the risk categories cited, privilege takes the top spot; specifically, privileges assigned to agents directly determine the level of risk they can introduce, and poor privilege management exposes organizations to scope creep, identity spoofing, and agent impersonation. Also flagged: LLM-based agents that may change their behavior when evaluations are underway and may even bypass system-level instructions to achieve their objectives - a risk that&#8217;s easy to underestimate when most governance focuses on what agents are authorized to do rather than whether they&#8217;ll actually stay within those lanes. </p><p>The takeaway is that agencies recommend <em>never</em> granting agentic AI broad or unrestricted access to sensitive data or critical systems, and limiting its use to low-risk, non-sensitive tasks until security practices and evaluation methods mature. That&#8217;s a conservative bar that most current deployments (especially in the private sector) don&#8217;t meet. If your organization is moving faster than that, this document is a useful checklist for identifying gaps in your governance model.</p><div><hr></div><h3><strong>CTI Isn&#8217;t Intelligence, And That&#8217;s Fine</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!KpFO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!KpFO!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!KpFO!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!KpFO!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!KpFO!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!KpFO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg" width="441" height="233.15833333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:571,&quot;width&quot;:1080,&quot;resizeWidth&quot;:441,&quot;bytes&quot;:77805,&quot;alt&quot;:&quot;a close up of a stopwatch on a black background&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="a close up of a stopwatch on a black background" title="a close up of a stopwatch on a black background" srcset="/__u/substackcdn.com/image/fetch/$s_!KpFO!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!KpFO!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!KpFO!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!KpFO!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae662969-5fa2-4716-858f-72f195846294_1080x571.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@wwarby">William Warby</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>Joe Slowik, <a href="https://pylos.co/2026/05/03/a-brief-critique-of-practical-threat-intelligence/">via his Stranded on Pylos blog</a>, has written one of the more thought-provoking pieces on threat intelligence I&#8217;ve read in a while. The field of cyber threat intelligence has saddled itself with terms and definitions borrowed from formal intelligence community (IC) tradecraft; structured analytic techniques, analysis of competing hypotheses, multi-phase production cycles, etc., which are largely mismatched to the timescales of detection and response. <strong>The tension stems from the fact that the formal IC model optimizes for rigor, but the operational security environment optimizes for speed.</strong> </p><p>The alternative framing Slowik proposes is indications and warning (I&amp;W): a military concept where the further along the intelligence refinement process you move, the greater the likelihood that the resulting product arrives <em>after</em> its moment of maximum efficacy - basically, a point of diminishing returns. Under an I&amp;W model, file triage, log analysis, and infrastructure tracking become more critical than executing a well-structured <a href="https://en.wikipedia.org/wiki/Analysis_of_competing_hypotheses">ACH</a> (for example), because the decision maker needs actionable input now - not a finished product next week. </p><p>We cover a lot of these concepts in <a href="https://www.sans.org/cyber-security-courses/building-leading-security-operations-centers">LDR551</a>, including structured analytic techniques and ACH, so this one really gave me pause. But Joe is on point as usual. Structured analysis remains useful for training and process alignment, but it may not always be applicable in time-sensitive detection and response. Ask yourself: who is your intelligence actually serving, at what timescale, and is the production model matched to those needs? If your analysts are executing structured reporting cycles optimized for strategic briefings while your detection engineering team is waiting on IOCs, something is misaligned.</p><div><hr></div><h3><strong>IR Professionals Sentenced for Ransomware Attacks </strong></h3><p>Ryan Goldberg (Sygnia) and Kevin Martin (DigitalMint) each <a href="https://therecord.media/ransomware-cyber-incident-responders">received four-year sentences this week</a> after pleading guilty to conspiracy charges for deploying ALPHV/BlackCat ransomware against clients they were ostensibly helping. A third co-conspirator, Angelo Martino, also a ransomware negotiator at DigitalMint, went even further: he was simultaneously negotiating ransoms on behalf of five victims while feeding those victims&#8217; insurance policy limits and confidential operational details to the ransomware gangs. Martino coordinated payouts reaching $26 million and faces sentencing in July. The group earned $1.2 million from one successfully extorted company; law enforcement seized roughly $10 million in assets from Martino and tracked Goldberg across ten countries before arrest.</p><p>DigitalMint&#8217;s post-incident controls - cloud-audited negotiation platforms, founder oversight of all negotiations, DHS registration of negotiators - are reasonable minimums, but they came after the fact. Time to check in with your external IR and negotiation partners on access controls, audit logging, and conflict-of-interest disclosures.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>We&#8217;re in the middle of another evolution that echoes what we saw most recently in the ransomware ecosystem, toward scale, speed, and the systematic removal of cost from the offensive side of the equation. ConsentFix v3 is a great example: each iteration has eliminated one more step requiring human effort. ATHR replaces human callers with AI voice agents so that vishing scales without headcount. And when cPanel and Copy Fail went public, commodity operators were at scale within days. </p><p>Takedowns impose costs and are worth doing, but they don&#8217;t necessarily change the underlying economics. Joe Slowik's piece on CTI essentially presents the defender&#8217;s side of this argument: formal analytic tradecraft adds friction and time costs to the process at exactly the moment attackers have eliminated friction from theirs. The organizations best positioned to respond to this environment aren't the ones with the most rigorous processes or the longest list of controls; they're the ones who have matched their operational tempo to the threat.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #53: The Cost of Assumed Adequacy]]></title><description><![CDATA[It's past time to address the drift in SaaS, identity, and communications management.]]></description><link>https://markaorlando.substack.com/p/security-leadership-53-the-cost-of</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-53-the-cost-of</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:04:06 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/95f35fbb-914f-46a5-a389-d00165e01e5d_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #53 of Security Leadership Weekly!  Several of the stories below hit same dynamic from different angles: organizations are discovering that programs they assumed were in good shape, like privacy, governance, detection, and team communication, have quietly drifted from where they needed to be. The remedies may not be dramatic - mostly focusing on fundamentals - but they aren&#8217;t easy. Our adversaries aren&#8217;t waiting for us to catch up, and as it turns out, neither are the regulators. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>You Can&#8217;t Govern What You Can&#8217;t See</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!vXJh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!vXJh!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!vXJh!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!vXJh!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!vXJh!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!vXJh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg" width="546" height="279.06666666666666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:552,&quot;width&quot;:1080,&quot;resizeWidth&quot;:546,&quot;bytes&quot;:121305,&quot;alt&quot;:&quot;silhouette of man standing inside structure&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="silhouette of man standing inside structure" title="silhouette of man standing inside structure" srcset="/__u/substackcdn.com/image/fetch/$s_!vXJh!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!vXJh!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!vXJh!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!vXJh!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa005c6f5-8f1d-4a02-9d70-8eda01fff4d2_1080x552.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@qrenep">Rene B&#246;hmer</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><a href="https://cloudsecurityalliance.org/blog/2026/04/28/the-shadow-ai-agent-problem-in-enterprise-environments">The CSA&#8217;s new research</a> puts a number to a problem that security leaders have been sensing for a while: 68% of organizations say they have high visibility into their AI agents and autonomous workflows, yet <strong>82% discovered at least one AI agent or workflow in the past year that security or IT did not previously know about.</strong> The gap between these is where the risk lives, and it&#8217;s a particularly uncomfortable gap given how AI agents work: unlike static infrastructure, agents can evolve through updates or prompt changes, expand their scope through integrations, interact dynamically with other systems, and operate without continuous human oversight if not kept on a short leash. </p><p>What makes this harder to solve is that shadow AI agents aren&#8217;t emerging from rogue corners of the enterprise. The most common discovery locations were internal automation and scripting environments, LLM platforms including custom tools and plugins, SaaS tools with built-in automation, and developer-created workflows. </p><p>The CSA&#8217;s recommendation isn&#8217;t to lock these environments down - it&#8217;s to make them governable: treat agent creation as a governance event, extend lifecycle management expectations beyond traditional software procurement, and design control models that assume decentralization rather than relying on a single review board or approval process. I&#8217;d add real-time monitoring for OAuth consents to weed out overly permissive grants to AI agents (something we&#8217;re doing at <a href="https://pushsecurity.com/uc/shadow-ai">my day job</a>). Either way, the time to focus on this is now - not after the first incident where an agent has gone rogue.</p><div><hr></div><h3><strong>Robinhood Abused for Phishing Delivery</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!yFw_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!yFw_!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!yFw_!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!yFw_!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!yFw_!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!yFw_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg" width="522" height="330.19368131868134" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:921,&quot;width&quot;:1456,&quot;resizeWidth&quot;:522,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Robinhood&quot;,&quot;title&quot;:&quot;Robinhood&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Robinhood" title="Robinhood" srcset="/__u/substackcdn.com/image/fetch/$s_!yFw_!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!yFw_!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!yFw_!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!yFw_!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74275271-f748-40bd-9f36-539eacd2fb8f_1600x1012.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Via <a href="https://www.bleepingcomputer.com/news/security/robinhood-account-creation-flaw-abused-to-send-phishing-emails/">Lawrence Adams at BleepingComputer</a>: Attackers have exploited a flaw in Robinhood&#8217;s account creation process that allowed them to inject arbitrary HTML into the device metadata field of official onboarding emails - content that Robinhood didn&#8217;t sanitize before rendering, causing the injected phishing message to appear as a legitimate security alert inside an email sent from Robinhood&#8217;s own systems. Using in-app notifications as phishing delivery mechanisms isn&#8217;t new; it&#8217;s a great way to get phishing messages past SPF, DKIM, and DMARC authentication checks and to add legitimacy to the lures.</p><p>Robinhood confirmed that affected customers were notified, the campaign was taken down, and account creation flows were strengthened. They noted that no account takeover was possible through the email itself, but this is less about Robinhood specifically and more about a mass delivery vector.  </p><div><hr></div><h3><strong>The Grace Period Is Over</strong></h3><p>Via <a href="https://cyberscoop.com/privacy-companies-hit-with-record-fines-2025-gartner/">Derek B. Johnson at CyberScoop</a>: For years, organizations watched comprehensive privacy laws pass and largely concluded they had time. But in 2025, U.S. states issued $3.45 billion in privacy-related fines - more than the previous five years combined. The increase was driven by stronger enforcement of laws such as <a href="https://oag.ca.gov/privacy/ccpa">California&#8217;s CCPA</a>, new interstate partnerships, and a sharper focus on how AI and automated decision-making affect personal data. </p><p>Regulators have moved from guidance to enforcement, and many organizations that &#8220;weren&#8217;t paying attention&#8221; were caught having let their privacy programs atrophy during the gap between legislation and meaningful penalties. Ten states now coordinate enforcement across state lines through the <a href="https://cppa.ca.gov/announcements/2025/20251008.html">Consortium of Privacy Regulators</a>, and federal preemption legislation (which would override stronger state laws like California&#8217;s) remains politically contested enough that organizations would be unwise to bet on it as a compliance strategy.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!FC4U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!FC4U!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png 424w, /__u/substackcdn.com/image/fetch/$s_!FC4U!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png 848w, /__u/substackcdn.com/image/fetch/$s_!FC4U!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png 1272w, /__u/substackcdn.com/image/fetch/$s_!FC4U!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!FC4U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png" width="573" height="383.1202346041056" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9151ef67-3506-4597-b42a-11159076d072_1023x684.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:684,&quot;width&quot;:1023,&quot;resizeWidth&quot;:573,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!FC4U!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png 424w, /__u/substackcdn.com/image/fetch/$s_!FC4U!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png 848w, /__u/substackcdn.com/image/fetch/$s_!FC4U!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png 1272w, /__u/substackcdn.com/image/fetch/$s_!FC4U!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9151ef67-3506-4597-b42a-11159076d072_1023x684.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The timing on this is pretty pointed. In the past two weeks alone, ShinyHunters has claimed responsibility for a wave of high-profile data exposures. Victims include Udemy, Carnival Cruises, and <a href="https://www.theregister.com/2026/04/28/pitney_bowes_is_the_latest/">Pitney Bowes</a>.  McGraw-Hill (15 million rows), Amtrak (2.3 million rows), and Carnival (7.5 million rows) also appear in <a href="https://haveibeenpwned.com/PwnedWebsites">recently verified disclosures</a>. In a $3.45 billion enforcement year, with ten states actively coordinating, the question isn&#8217;t whether a breach will attract scrutiny; it&#8217;s whether your privacy program was mature enough to demonstrate reasonable care before it happened.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>AI Prompt Injections in the Wild</strong></h3><p><a href="https://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html">This post on prompt injection</a> in the wild by the <strong><a href="https://www.linkedin.com/company/google/">Google</a></strong> Threat Intelligence Team is a cool case study of a detection challenge at scale.  The team swept the <strong><a href="https://www.linkedin.com/company/common-crawl/">Common Crawl Foundation</a></strong> (2-3 billion public web pages per snapshot) for indirect prompt injection patterns. Most of what they found was low-sophistication stuff like pranks, SEO manipulation, and benign experiments. Scanning for content like &#8220;ignore previous instructions&#8221; or &#8220;if you are an AI&#8221; returned mostly false positives like blogs, research papers, etc. Their fix was a coarse-to-fine pipeline: pattern matching, then LLM classification for intent and context, then human review.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!4gMM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!4gMM!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png 424w, /__u/substackcdn.com/image/fetch/$s_!4gMM!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png 848w, /__u/substackcdn.com/image/fetch/$s_!4gMM!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png 1272w, /__u/substackcdn.com/image/fetch/$s_!4gMM!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!4gMM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png" width="685" height="117" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:117,&quot;width&quot;:685,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!4gMM!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png 424w, /__u/substackcdn.com/image/fetch/$s_!4gMM!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png 848w, /__u/substackcdn.com/image/fetch/$s_!4gMM!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png 1272w, /__u/substackcdn.com/image/fetch/$s_!4gMM!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8eecf8b4-b73b-481a-8916-25ed6d5ad6ea_685x117.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>This maps almost exactly to how we approach detection engineering at my day job. Browser session data is incredibly noisy; credential reuse, OAuth grants, extension behavior...the benign and the malicious are often indistinguishable until you add context. What customers don&#8217;t always see is the amount of work that goes into getting this right - the iteration, the tuning, the deliberate tradeoffs our team makes to surface high-confidence detections instead of handing analysts a firehose of noise. </p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>ATT&amp;CK v19: The Framework Gets Sharper Where It Matters Most</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!iDmD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!iDmD!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png 424w, /__u/substackcdn.com/image/fetch/$s_!iDmD!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png 848w, /__u/substackcdn.com/image/fetch/$s_!iDmD!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png 1272w, /__u/substackcdn.com/image/fetch/$s_!iDmD!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!iDmD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png" width="504" height="275.04" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:382,&quot;width&quot;:700,&quot;resizeWidth&quot;:504,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!iDmD!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png 424w, /__u/substackcdn.com/image/fetch/$s_!iDmD!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png 848w, /__u/substackcdn.com/image/fetch/$s_!iDmD!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png 1272w, /__u/substackcdn.com/image/fetch/$s_!iDmD!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F208caeb8-8759-4667-a190-f67d60ba85b8_700x382.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://medium.com/mitre-attack/attack-v19-ff329cb65d66">The headline change in ATT&amp;CK v19</a> is one many of us have been waiting on for a while: the Defense Evasion tactic has been split in two. The new structure separates Stealth - covering things like living-off-the-land binaries and masquerading - from Defense <em>Impairment</em>, which covers adversaries actively breaking your defenses. Think killing EDRs, tampering with logging pipelines, and/or subverting trust controls. It&#8217;s an important distinction because the two require completely different defensive responses, and lumping them together was obscuring that nuance. </p><p>If your team maintains ATT&amp;CK-mapped detection content, time to do some homework! T1562 and several sub-techniques have been revoked and restructured under new IDs, and MITRE has published crosswalk files in JSON and CSV to help teams remap existing content. <strong>Check those before assuming your current mappings still hold.</strong></p><p>Beyond the structural changes, v19 reflects where the threat landscape is actually moving. New techniques cover AI-enabled adversary behavior, like how threat actors are querying public AI services for target research and using AI to generate written and audio-visual content for operations. It also consolidates Social Engineering parent techniques like impersonation and email spoofing under a single behavior category with unified detection logic. The CTI additions are equally notable: MITRE has documented a PRC state-directed cluster using Claude Code to autonomously execute most of a multi-stage espionage campaign, and added LAMEHUG, described as the first malware documented to query a large language model in live operations. </p><div><hr></div><p><strong>Two quick hits on team design and communication this week&#8230;</strong></p><h3><strong>The Case Against Team Meetings</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="539" height="353.6704871060172" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:5038,&quot;width&quot;:7678,&quot;resizeWidth&quot;:539,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;sittin people beside table inside room&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="sittin people beside table inside room" title="sittin people beside table inside room" srcset="https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1521737604893-d14cc237f11d?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxMnx8bWVldGluZ3xlbnwwfHx8fDE3NzczMDYxNzl8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@anniespratt">Annie Spratt</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>Ever joked about the &#8220;expense&#8221; of a meeting based on the cost of the attendees&#8217; time? <a href="https://www.foo.be/2026/04/dont-do-team-meetings">On his blog</a>, Alexandre Dulaunoy argues that when a team depends on a weekly meeting to learn what everyone has been doing, the meeting itself is a symptom: it signals that communication is already failing. The format compounds the problem by turning information-sharing into performance; one person speaks while everyone else waits for their turn, mentally checked out. The author makes a point worth sitting with: a one-hour meeting with ten people isn&#8217;t a one-hour meeting, it&#8217;s a ten-hour cost for the team. </p><p>The alternative is structure: Dulaunoy&#8217;s team relies on a handful of chat channels: a global room, an informal one, and project-specific rooms, with the expectation that updates are shared in context when they happen, not batched up for a calendar slot.  This is very similar to how we work at my day job (except for the part about eliminating meetings!), and it maps cleanly onto how high-performing SOC and incident response teams already operate - decisions and developments are surfaced asynchronously in writing, with meetings reserved for live coordination that genuinely can&#8217;t wait. The takeaway isn&#8217;t &#8220;eliminate all meetings,&#8221; but to stop treating the status call as a default and start treating it as a failure mode.</p><div><hr></div><h3><strong>The Team That Runs Itself</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="535" height="356.6666666666667" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4000,&quot;width&quot;:6000,&quot;resizeWidth&quot;:535,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;men rowing boat&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="men rowing boat" title="men rowing boat" srcset="https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1569406125624-98ee19b01d4a?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw2fHxyb3dpbmd8ZW58MHx8fHwxNzc3Mzk4NzMwfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@mitchel3uo">Mitchell Luo</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><em><strong>And now a counter-argument</strong></em>, via <a href="https://www.fastcompany.com/91527218/how-to-build-a-team-that-runs-itself">Aytekin Tank at FastCompany</a>: Tank, CEO of Jotform, argues that successful teams don&#8217;t need more management, but that leaders still have to build the communication patterns that make autonomy possible. His own model is instructive: <strong>20-minute weekly check-ins with each team</strong>, focused on what they&#8217;re working on and where he can add input, with no micromanagement in between. Delegation works best when ownership is clearly defined - when accountability is built into the workflow, not added on top of it. </p><p>The piece also makes a case for visibility as a cultural practice rather than a management tool. Jotform holds weekly Demo Days where all 20-plus teams share successes, setbacks, and teachable moments with the whole company; a ritual the author frames not just as a sharing mechanism, but as a trust-building one. Thinking about this for security teams as an opportunity to discuss near-misses, incidents, and detection wins. The takeaway from this and Dulaunoy&#8217;s blog is that best-run teams aren&#8217;t the ones that report the most; they&#8217;re the ones that communicate the most purposefully.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>Most of the challenges we covered this week are more the result of management and operational drift than recklessness. The ATT&amp;CK v19 update and the Google prompt injection research point in the same &#8220;cost of adequacy&#8221; direction from the practitioner side: the work of maintaining good detection isn't dramatic, it's iterative and ongoing. The team management pieces this week make the same point about communication. The best-run teams aren't the ones doing the most; they're the ones doing the most purposefully.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #52: Credentials, Tokens, and the Coverage Gap]]></title><description><![CDATA[The SaaS Layer Nobody Owns]]></description><link>https://markaorlando.substack.com/p/security-leadership-52-credentials</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-52-credentials</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 22 Apr 2026 12:07:46 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d15bf595-8f3d-4413-b767-225adc2146c6_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #52 of Security Leadership Weekly!  This week&#8217;s issue has a theme, I promise. Attackers have largely figured out that the path of least resistance runs through the identity and SaaS layer, where visibility is low, permissions are broad, and nobody &#8220;owns&#8221; the inventory. The Vercel breach is a perfect example of these attack chains, which no longer look like multi-stage intrusions (and side-step the detections and mitigations we&#8217;ve built around that model). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!B2HK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!B2HK!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!B2HK!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!B2HK!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!B2HK!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!B2HK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg" width="603" height="339.1451068616423" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:889,&quot;resizeWidth&quot;:603,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!B2HK!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!B2HK!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!B2HK!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!B2HK!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F835d5d70-479a-45cf-b371-61d4ab5ee084_889x500.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In related news, a Microsoft Deputy CISO published a timely counterpoint on credential elimination and platform engineering as structural defenses against exactly this pattern. Insurance carriers, apparently reaching their own conclusions, are quietly repricing or excluding the AI-shaped version of the same problem.</p><p><strong>But before we dive in, a brief announcement</strong>: as part of Push Security&#8217;s <a href="https://pushsecurity.com/webinar/state-of-browser-security">State of Browser Attacks Series</a>, I&#8217;ll be appearing with Troy Hunt for a discussion of identity attacks, attack trends, and well, pretty much anything Troy wants to talk about. You can register <a href="https://pushsecurity.com/webinar/state-of-browser-security#">here </a>and watch it live on April 30th at 11:00 AM EST!</p><p>If you missed the first episode of the series with Luke Jennings and John Hammond, you missed out on a great discussion and a live walkthrough of some really cool attack techniques. The good news is that you can watch the full recording <a href="https://pushsecurity.com/resources/browser-attacks-why-browser-new-battleground">here</a>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h1><strong>Microsoft On Making Opportunistic Cyberattacks Harder by Design</strong></h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!hfC0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!hfC0!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!hfC0!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!hfC0!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!hfC0!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!hfC0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg" width="478" height="268.875" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:478,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Microsoft's Office 365 is now Microsoft 365, a 'subscription for your life'  - CNET&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Microsoft's Office 365 is now Microsoft 365, a 'subscription for your life'  - CNET" title="Microsoft's Office 365 is now Microsoft 365, a 'subscription for your life'  - CNET" srcset="/__u/substackcdn.com/image/fetch/$s_!hfC0!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!hfC0!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!hfC0!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!hfC0!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e00e3c-f46b-4bfc-9f07-b9f49fe81cf6_1200x675.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://www.microsoft.com/en-us/security/blog/author/ilya-grebnov/">Ilya Grebnov</a>, </strong>Microsoft&#8217;s Deputy CISO for Dynamics 365 and Power Platform, published this blog post on an argument I&#8217;ve made plenty of times in this newsletter (and daily in my day job): most attackers don&#8217;t break into your network, they log in with stolen credentials, and the most reliable fix isn&#8217;t better password hygiene; it&#8217;s removing credentials from the system entirely. The practical playbook he lays out centers on managed identities and federated token patterns that authenticate workloads just-in-time <em>without a stored secret </em>that can be compromised and reused. Worth a read, since this is basically Microsoft&#8217;s own internal security team describing how they protect 450+ services across one of the largest Azure footprints in existence.</p><p>The second half of the piece essentially describes platform engineering as a security control. Opportunistic attackers thrive on inconsistency, and the prescription described here is paved paths, policy-as-code, and enforced defaults that make the secure choice the easy choice. The Vercel breach covered later in this issue underlines this point: that attack succeeded because an over-permissioned OAuth token in a third-party app served as a bridge into Vercel&#8217;s environment. The Entra Agent ID note - treating AI agents as first-class identities with a named human sponsor - may be a small but telling signal of where identity governance is heading. Lots of great info here, though in my experience these best practices tend to break down and/or achieve less than full coverage in complex, heterogenous environments - leaving exactly the attack surface Grebnov describes here.</p><div><hr></div><h3><strong>Insurance Providers Back Away From AI Coverage</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!9efJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!9efJ!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png 424w, /__u/substackcdn.com/image/fetch/$s_!9efJ!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png 848w, /__u/substackcdn.com/image/fetch/$s_!9efJ!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png 1272w, /__u/substackcdn.com/image/fetch/$s_!9efJ!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!9efJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png" width="466" height="263.4052197802198" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:823,&quot;width&quot;:1456,&quot;resizeWidth&quot;:466,&quot;bytes&quot;:428615,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/194832169?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!9efJ!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png 424w, /__u/substackcdn.com/image/fetch/$s_!9efJ!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png 848w, /__u/substackcdn.com/image/fetch/$s_!9efJ!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png 1272w, /__u/substackcdn.com/image/fetch/$s_!9efJ!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f544cc1-1d2c-4b0b-a95e-957a0ddb0f92_1472x832.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.csoonline.com/article/4159292/insurance-carriers-quietly-back-away-from-covering-ai-outputs.html">Via CSO Online</a>: Insurance carriers appear to be pulling back on coverage for AI-related outputs due to their unpredictability. Dozens of carriers are now declining to write policies for AI-generated output claims in cybersecurity and errors and omissions coverage, while others are hiking premiums to account for the increased risk. This kind of makes sense, since carriers can&#8217;t trace the reasoning behind an agentic decision and therefore can&#8217;t underwrite it. CSO&#8217;s article points out that in November 2025, AIG, Great American, and W.R. Berkley filed regulatory requests to exclude AI liabilities, but the trend has ramped up to include active policy exclusions. </p><p>If you&#8217;re a CISO, expect more pointed questions from your underwriters: What AI policies do you have? What models are you running? How are you validating outputs? Don&#8217;t assume your existing E&amp;O or cyber policies cover your AI deployment, as <strong>AI exclusions <a href="https://corpgov.law.harvard.edu/2025/09/22/the-hidden-c-suite-risk-of-ai-failures/">often extend beyond the insured&#8217;s own AI use</a> to any third-party AI systems incorporated into their workflows (read: SaaS capabilities or third-party apps in your SaaS). </strong></p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>Vercel Breached via Third-Party App</strong></h3><p><a href="https://cyberscoop.com/vercel-security-breach-third-party-attack-context-ai-lumma-stealer/">Via Matt Kapko at CyberScoop</a>: The Vercel breach is a clean case study in how infostealers become the opening move in something much bigger. It started in February, when a <a href="https://context.ai/">Context.ai</a> employee searched for Roblox game exploits and downloaded Lumma Stealer - a textbook infostealer deployment vector. From there, the stolen credentials gave the attacker access to Context.ai&#8217;s AWS environment and OAuth tokens, including one tied to a Vercel employee&#8217;s Google Workspace account. </p><p>Annnd that was it - that token granted full access. The employee had authorized the AI Office Suite app and given it broad permissions. The attacker then used that foothold to access Vercel environments and harvest environment variables, ultimately reaching customer credentials. ShinyHunters, or a group claiming the name to inflate notoriety, is attempting to sell the haul, which they claim includes access keys, source code, and databases. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!REi3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!REi3!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!REi3!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!REi3!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!REi3!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!REi3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg" width="567" height="316.575" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:603,&quot;width&quot;:1080,&quot;resizeWidth&quot;:567,&quot;bytes&quot;:100425,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/194832169?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!REi3!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!REi3!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!REi3!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!REi3!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8533a040-ab9c-40c1-ac05-a2e46e13e048_1080x603.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So just to recap: this <strong>wasn&#8217;t</strong> a Vercel vulnerability, it <strong>wasn&#8217;t</strong> a phishing email sent to a Vercel employee, and it <strong>wasn&#8217;t</strong> a misconfigured Vercel system; this was an over-permissioned OAuth token granted to a third-party SaaS app that got popped at a completely different company. <a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident">Vercel noted</a> the Context.ai OAuth app was the subject of a broader compromise, potentially affecting hundreds of users across many organizations. </p><p>The infostealer-to-OAuth-to-lateral-movement chain is the kind of attack that generates no endpoint alert, leaves no malware signature in your environment, and bypasses MFA, because the attacker is using a legitimately issued token. Vercel&#8217;s CEO described the attackers as &#8220;highly sophisticated&#8221; and suspected the operation was &#8220;significantly accelerated by AI.&#8221; Whether that is born out by the evidence or not, the velocity and depth of the pivot across three separate organizations in a matter of weeks is the real headline.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>A Leadership Framework for Cutting Through Complexity</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!O_Kb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!O_Kb!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png 424w, /__u/substackcdn.com/image/fetch/$s_!O_Kb!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png 848w, /__u/substackcdn.com/image/fetch/$s_!O_Kb!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png 1272w, /__u/substackcdn.com/image/fetch/$s_!O_Kb!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!O_Kb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png" width="519" height="293.3633241758242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:823,&quot;width&quot;:1456,&quot;resizeWidth&quot;:519,&quot;bytes&quot;:2533009,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/194832169?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!O_Kb!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png 424w, /__u/substackcdn.com/image/fetch/$s_!O_Kb!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png 848w, /__u/substackcdn.com/image/fetch/$s_!O_Kb!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png 1272w, /__u/substackcdn.com/image/fetch/$s_!O_Kb!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdadbbe7c-1774-447f-97d0-d95ce6079808_1472x832.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://tanveernaseer.com/simplify-the-way-we-work-leadership-framework/">Tanveer Naseer&#8217;s Leadership Newsletter</a> covers a common leadership challenge, which is that the more complicated things become, the more pressure there is on leaders to just &#8220;do something&#8221; that indicates progress - whether it&#8217;s the right thing(s) or not. Naseer describes a three-part simplification framework that requires answering three questions:</p><ol><li><p>What should we stop doing?</p></li><li><p>What should we keep doing?</p></li><li><p>What should we be doing differently?</p></li></ol><p>The first question gets to something we cover in LDR551 (referencing Cal Newport&#8217;s book <a href="https://www.amazon.com/Deep-Work-Focused-Success-Distracted/dp/1455586692">Deep Work</a> and John Doerr&#8217;s <a href="https://www.amazon.com/Measure-What-Matters-Google-Foundation/dp/0525536221">Measure What Matters</a>): reducing <em>shallow work</em> - tasks that can be performed in a distracted state that add no enduring value. Things like sitting in on meetings, drive-by assignments, PowerPoint presentations, etc., may be necessary, but they&#8217;re mostly shallow work. If we can cut down on this stuff, we can focus instead on <em>deep work</em> - tasks which we might not be able to knock out immediately, but by completing them, everything gets better and easier. Another way of thinking about it, as described in Doerr&#8217;s book, is to separate tasks that are urgent from tasks that are strategically important. Reducing false positives and devising more effective threat mitigations would be two examples of deep work that are of high strategic importance (but probably low urgency, in that they aren&#8217;t immediate). </p><div><hr></div><h3><strong>Maritime Transportation Security Act (MTSA) Takes Effect</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="575" height="382.4213901530823" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3215,&quot;width&quot;:4834,&quot;resizeWidth&quot;:575,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;aerial view of boat on water&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="aerial view of boat on water" title="aerial view of boat on water" srcset="https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1613690399151-65ea69478674?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxzaGlwcGluZ3xlbnwwfHx8fDE3NzY2OTEzMTN8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@ventiviews">Venti Views</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p><a href="https://www.darkreading.com/cybersecurity-operations/coast-guards-cybersecurity-rules-lessons-cisos">Via Robert Lemos at DarkReading</a>: The Coast Guard&#8217;s new maritime cybersecurity rules, first introduced in 2002 but expanded in 2025, are now in effect. The policy requires appointing dedicated cybersecurity officers, conducting formal assessments, and submitting cybersecurity plans for Coast Guard approval, while mandating that anyone with access to IT or OT systems complete cybersecurity training. Specifically, every US-flagged vessel, facility, or outer continental shelf (OCS) facility must designate a cybersecurity officer (CySO) to take responsibility for the cybersecurity of IT and OT infrastructure. The approach should look familiar to anyone who has formalized a cybersecurity function at the corporate level: formalize the roles, document the posture, and make training non-optional. </p><p>Given the focus on maritime security, this seems like timely guidance - the Strait of Hormuz has been effectively blocked since late February 2026 (wait, now it isn&#8217;t; no, yeah it is), with the IRGC asserting control over one of the world&#8217;s most critical maritime chokepoints. And since March, <a href="https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/">Iranian-affiliated actors</a> have disrupted PLCs across U.S. critical infrastructure sectors, including water, energy, and government services. All of this to say that the maritime sector, now operating under elevated geopolitical stress and newly formalized cyber obligations, is exactly the kind of environment where governance frameworks go from a paperwork exercise to operational necessity. </p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>The Vercel breach is the clearest illustration of a pattern running through this entire issue - the entire attack lived in the SaaS and identity layer. Grebnov&#8217;s Microsoft post is essentially a structural prescription for this exact problem: eliminate secrets, shrink public surfaces, enforce identity-scoped access (easier said than done!). The big hairy problem here is that those controls tend to degrade at the edges of complex, heterogeneous environments, and most enterprises aren&#8217;t running a unified platform they control. <strong>They&#8217;re running dozens of SaaS apps, connected by OAuth tokens and API keys, that no one has fully inventoried</strong>. That gap is precisely where the Vercel-style attack finds its footing.</p><p>The insurance story closes the loop from the risk management side. Carriers can&#8217;t underwrite what they can&#8217;t trace, and the same opacity problem that makes AI outputs uninsurable applies to the SaaS identity layer: who authorized that token, what did it have access to, when did it expire? Most organizations can&#8217;t answer those questions with confidence. The maritime piece earns its place for similar reasons: the MTSA governance framework isn&#8217;t novel, but with Iranian-affiliated actors actively disrupting U.S. critical infrastructure OT systems and the Strait of Hormuz in active crisis, the distance between compliance-as-paperwork and compliance-as-operational-readiness has collapsed.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #51: Authentication is a Solved Problem. Trust is Not.]]></title><description><![CDATA[How DPRK opted to build their own trust channel versus exploiting one.]]></description><link>https://markaorlando.substack.com/p/security-leadership-51-authentication</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-51-authentication</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 08 Apr 2026 12:12:20 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/479204f2-17d4-402e-9d79-0f178fb50cf1_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #51 of Security Leadership Weekly!  We&#8217;ve spent a TON of time trying to &#8220;solve&#8221; authentication, and have made some great strides: MFA, phishing-resistant credentials, passkeys, conditional access. Now, attackers have simply moved one &#8220;layer&#8221; up to post-auth attacks, and this week&#8217;s issue is a case study in what that looks like in practice. From a DPRK unit that spent six months building a fake trading firm to a device code phishing campaign running at industrial scale, the new attack surface isn't authentication; it's the trust and validation processes we use to decide what we're authenticating to in the first place. Credentials are a solved problem. Trust isn't.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>Axios Compromise Follow-Up: DPRK Attribution, Malware Details, and the Uncomfortable Post-Mortem</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!wW6p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!wW6p!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!wW6p!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!wW6p!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!wW6p!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!wW6p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg" width="565" height="272.94685990338166" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:828,&quot;resizeWidth&quot;:565,&quot;bytes&quot;:140756,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/193363677?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!wW6p!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!wW6p!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!wW6p!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!wW6p!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a6e8730-c9bf-4646-8d56-b699378cbc77_828x400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Axios npm supply chain compromise that broke on March 31 now has both a named threat actor and an after-action report from the project&#8217;s lead maintainer. <a href="https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package">Google&#8217;s Threat Intelligence Group (GTIG)</a> has attributed the attack to <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineering">UNC1069</a>, a North Korea-nexus financially motivated group active since at least 2018, and has detailed the malware chain: </p><ul><li><p>A long-term social engineering campaign to gain access to the lead developer&#8217;s PC</p></li><li><p>A dropper called SILKBELL delivered WAVESHAPER.V2, which beacons to a C2 every 60 seconds and supports directory enumeration, arbitrary payload execution, and PE injection</p></li><li><p>A cross-platform backdoor with variants for Windows (PowerShell), macOS (native binary), and Linux (Python)</p></li></ul><p>The <a href="https://github.com/axios/axios/issues/10636">Axios post-mortem</a>, written by lead maintainer Jason Saayman, is a great read if you&#8217;re responsible for securing CI/CD pipelines (and it has an even more detailed attack timeline). The attacker gained access through a targeted social engineering campaign and RAT malware deployed against the maintainer&#8217;s PC roughly two weeks before the malicious packages were published. Money quote: <strong>&#8220;Publishing directly from a personal account was a risk that could have been avoided.&#8221; </strong></p><p>Detection relied entirely on community members noticing, rather than on an analytic or automated approach, and the attacker used the compromised account to delete early-warning comments before the community escalated to npm directly. The project is now moving toward OIDC-based publishing and immutable release pipelines, which probably should have been in place for a package with over 100 million weekly downloads.</p><div><hr></div><h3><strong>Findings from The Drift Hack</strong></h3><p>It&#8217;s a DPRK two-for this week! The most expensive lesson from the $285M Drift hack might be that the attackers spent six months building the kind of professional credibility that would pass most corporate due diligence. The theft from the Solana-based decentralized exchange Drift on April 1 wasn&#8217;t opportunistic; it was the conclusion of a six-month operation attributed with medium confidence to <a href="http://malpedia.caad.fkie.fraunhofer.de/actor/unc4736">UNC4736</a>, the North Korea-nexus group also tracked as Citrine Sleet and Golden Chollima. </p><p>Starting in the fall of 2025, individuals posing as a quantitative trading firm approached Drift contributors at major international cryptocurrency conferences, built months of substantive professional rapport over Telegram, deposited over $1 million of their own funds into the protocol to establish operational credibility, and ultimately delivered malware through either a malicious code repository or a weaponized wallet app distributed via Apple TestFlight. Talk about a long game! </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!OMMm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!OMMm!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!OMMm!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!OMMm!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!OMMm!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!OMMm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg" width="526" height="274.68888888888887" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:900,&quot;resizeWidth&quot;:526,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="/__u/substackcdn.com/image/fetch/$s_!OMMm!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!OMMm!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!OMMm!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!OMMm!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba6eea8b-8063-41d0-a6f1-7acac31cc77d_900x470.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two details make this story particularly relevant beyond crypto:</p><ol><li><p>The initial infection vector is assessed to have involved a malicious VS Code project exploiting the &#8220;tasks.json&#8221; file to silently execute code when a workspace was opened, a technique North Korean actors have been using since December 2025, and one Microsoft only recently added controls for in VS Code versions 1.109 and 1.110 - think developer toolchains as a phishing lure.</p></li><li><p><a href="https://dti.domaintools.com/research/dprk-malware-modularity-diversity-and-functional-specialization">A concurrent DomainTools analysis</a> reveals that DPRK&#8217;s cyber apparatus has deliberately fragmented its malware ecosystem along mission lines, separating tooling, infrastructure, and operational patterns so that exposure in one mission area doesn&#8217;t cascade across the entire program, while also maximizing attribution ambiguity and slowing defender decision-making. The Axios npm compromise, the Drift hack, and the ongoing IT worker fraud campaigns aren&#8217;t separate problems; they&#8217;re divisions of the same well-resourced, state-directed organization running parallel revenue and access operations simultaneously.</p></li></ol><div><hr></div><h3><strong>US FY2027 Budget Takes Another Swing at CISA</strong></h3><p>Via Tim Starks at Cyberscoop: The Trump administration&#8217;s <a href="https://cyberscoop.com/trump-budget-proposal-would-cut-hundreds-of-millions-more-from-cisa/">fiscal year 2027 budget proposal</a> takes aim at CISA again, this time with cuts that could reach as high as $707 million. The budget language justifying the reductions appears to be copied verbatim from last year&#8217;s proposal, referencing programs CISA has already shuttered and making renewed calls to end misinformation work that the agency says it had already wound down. It reads less like a policy rationale and more like a budget document written before anyone checked what was still standing. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="512" height="341.36675151752496" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3405,&quot;width&quot;:5107,&quot;resizeWidth&quot;:512,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;white concrete building under cloudy sky during daytime&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="white concrete building under cloudy sky during daytime" title="white concrete building under cloudy sky during daytime" srcset="https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1581097543550-b3cbe2e6ea6e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwxfHxjYXBpdG9sfGVufDB8fHx8MTc3NTYwMDU3MHww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@haroldrmendoza">Harold Mendoza</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>It&#8217;s really sad to see this trajectory, knowing the sweat equity CISA put into building its workforce and public/private partnerships over the years. These cuts erode threat information sharing, stakeholder engagement, and cross-sector coordination that most enterprises quietly rely on, even if they don&#8217;t realize it. Rep. Bennie Thompson, the ranking Democrat on the House Homeland Security Committee, put it plainly: there&#8217;s nothing that justifies a cut of this scale, particularly at a time of heightened tensions with Iran and an increasingly aggressive China.&#8221; Whether Congress pushes back, as appropriators did in 2026, remains to be seen, but security leaders shouldn&#8217;t plan their programs around federal partnerships that may not survive the budget cycle.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>LinkedIn&#8217;s Extension Scanning Under Scrutiny</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Afzb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Afzb!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Afzb!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Afzb!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Afzb!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Afzb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg" width="463" height="260.4375" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:463,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;LinkedIn&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="LinkedIn" title="LinkedIn" srcset="/__u/substackcdn.com/image/fetch/$s_!Afzb!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Afzb!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Afzb!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Afzb!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64a21835-1d1f-4145-b52b-265e3e648bb0_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What started as a niche complaint from a competing extension developer has landed on <a href="https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/">BleepingComputer</a>, and it&#8217;s now making the rounds across mainstream security media. LinkedIn&#8217;s site runs a JavaScript fingerprinting script, internally called &#8220;Spectroscopy,&#8221; that scans visitors&#8217; Chromium-based browsers for over 6,236 specific installed extensions by attempting to access static file resources tied to each extension&#8217;s ID. The same script was scanning roughly 2,000 extensions in 2025 and 3,000 as recently as two months ago, so seems like the scope has expanded quite a bit. Beyond extensions, the script collects 48 distinct device characteristics, such as CPU core count, available memory, screen resolution, time zone, battery status, etc., then encrypts the resulting fingerprint and attaches it to every API request made during the session. <strong>None of this is disclosed in LinkedIn&#8217;s privacy policy</strong>, and there is no opt-out mechanism because LinkedIn doesn&#8217;t acknowledge the practice as data collection in the first place. Yikes.</p><p>LinkedIn&#8217;s defense (shared in the BleepingComputer story) is that the scanning is to identify violators of LinkedIn&#8217;s terms of service regarding scraping and other privacy issues. Also, it&#8217;s worth pointing out (and LinkedIn has) that the report was published by individuals connected to Teamfluence, a competing Chrome extension that LinkedIn restricted for ToS violations - a restriction that was subsequently upheld by a German court. In any case, none of this explains why Spectroscopy&#8217;s scan list includes grammar tools, tax professional utilities, and hundreds of categories with no obvious connection to LinkedIn&#8217;s platform, or why results are tied to real identities and employer data. </p><p>Terms of service aside, this feels icky to me, and something security leaders should consider when it comes to what employee browsers might be silently disclosing about your environment every time they log in. LinkedIn's Spectroscopy is kind of the inverse of the DPRK hacks like Axios and Drift;  instead of an adversary building trust to gain access, it's an app <em>exploiting</em> the trust it already has to harvest intelligence.</p><div><hr></div><h3><strong>Device Code Phishing Keeps Going Up</strong></h3><p>In last week&#8217;s issue, I covered <a href="https://pushsecurity.com/blog/device-code-phishing/">Push Security&#8217;s research</a> on the mechanics of device code phishing: a post-authentication attack that renders MFA irrelevant by hijacking Microsoft&#8217;s OAuth device authorization flow rather than stealing credentials. This week, <a href="https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/">Microsoft confirmed</a> that the threat has moved from a research concern to an operational emergency. Since March 15, Microsoft has observed <strong>10 to 15 distinct campaigns launching every 24 hours</strong>, each targeting hundreds of organizations with unique, AI-generated payloads designed to defeat pattern-based detection. The infrastructure behind it is closely linked to <a href="https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/">EvilTokens</a>, a device-code-phishing-as-a-service kit sold since mid-February that handles the MFA bypass for buyers and is already expanding to support Gmail and Okta. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!f7JO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!f7JO!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp 424w, /__u/substackcdn.com/image/fetch/$s_!f7JO!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp 848w, /__u/substackcdn.com/image/fetch/$s_!f7JO!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!f7JO!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!f7JO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp" width="585" height="310.8395324123273" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:941,&quot;resizeWidth&quot;:585,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!f7JO!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp 424w, /__u/substackcdn.com/image/fetch/$s_!f7JO!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp 848w, /__u/substackcdn.com/image/fetch/$s_!f7JO!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!f7JO!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffda27b12-fa5a-4520-894e-66b4b8621c02_941x500.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The campaign routes victims through compromised legitimate domains hosted on trusted serverless platforms like Railway, Cloudflare Workers, AWS Lambda, etc., so the phishing traffic blends seamlessly with normal enterprise cloud activity and defeats URL scanners, proxies, and other network-based controls. The final page shows a legitimate <code>microsoft.com/devicelogin</code> prompt, because it <em>is</em> legitimate; the victim authenticates to Microsoft directly, the device code is captured, and the attacker receives a live access token without ever touching the user&#8217;s credentials or triggering an MFA challenge. </p><p>Post-compromise, attackers move fast: in some cases registering new devices within 10 minutes to generate a Primary Refresh Token for long-term persistence, in others creating inbox forwarding rules targeting emails with &#8220;payroll&#8221; or &#8220;invoice&#8221; in the subject line. These are super dangerous because there is no malicious domain to block and no credentials to protect proactively (post-auth, remember?). Restricting device code flow is a viable remediation, although it&#8217;s used for <a href="https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/verifying-new-devices-when-signing-in">plenty of legitimate functions</a>, so it&#8217;s bound to be a management headache. This one isn&#8217;t going away anytime soon.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>Phil Venables on What Field CISOs Are Actually For</strong></h3><p>Phil Venables is here <a href="https://www.philvenables.com/post/the-real-role-of-the-field-ciso">with another heater</a>: a substantive take on the Field CISO role. Phil (can I call him Phil at this point?) frames the Field CISO&#8217;s purpose as building customer trust to win, grow, and sustain business by making customers successful,  which sounds obvious until you watch how many people in the role default to being glorified sales engineers or, worse, logo drops on a vendor website. The piece covers sales support, post-sales onboarding, internal product advocacy, audit and regulatory support, incident response, and community convening. But the throughline is lived experience in actual security leadership roles, not just consulting. </p><p>Two points from this piece deserve more airtime in the security leadership conversation:</p><ol><li><p>The Field CISO&#8217;s most strategically valuable function is serving as the &#8220;voice of the customer&#8221; internally, advocating for what customers actually need rather than what product teams say they want. Pushing for secure-by-default designs can sometimes conflict with the commercial interest of selling additional security products.]</p></li><li><p>Outcomes are hard to quantify, but net promoter scoring (NPS) and other toil-related metrics can be effective methods of capturing the Field CISO&#8217;s contributions.</p></li></ol><p>As a first-time Field <em>CTO</em>, I found the post immensely helpful. Worth a read if you live in this world or aspire to.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>I&#8217;ve covered a lot of &#8220;trusted channel&#8221; attacks in this newsletter before, including ClickFix and its more creative variants. What's different in some of these threats is instead of exploiting a trusted channel, the attackers are building their own. UNC4736 constructed professional identities that survived six months of business due diligence. The Axios attacker compromised the human whose credibility was the trust anchor for a hundred-million-download package. EvilTokens routes victims through legitimate serverless infrastructure to a <em>real</em> Microsoft login page. Many of our mental models in information security are predicated on answering the question, &#8220;is this channel secure?&#8221;. But in many of these cases, the question should be: &#8220;How would you know if an entire <em>channel </em>was deceptive and invalid?&#8221; Unfortunately many organizations aren&#8217;t able to answer it until they&#8217;re responding to an incident. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #50: Their Playbooks Are Better Than Ours]]></title><description><![CDATA[Plus: social engineering comes for TikTok]]></description><link>https://markaorlando.substack.com/p/security-leadership-50-their-playbooks</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-50-their-playbooks</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 01 Apr 2026 12:14:42 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e74b5b2b-dc05-487f-9b07-a176e1244cfd_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #50 of Security Leadership Weekly!  This week's issue is heavy on supply chain attacks and credential abuse, and light on RSAC retrospectives. If you read nothing else this week, read the TeamPCP summary and the temporal hunting piece together. They're more connected than they appear!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!2Cz4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!2Cz4!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!2Cz4!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!2Cz4!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!2Cz4!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!2Cz4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg" width="500" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!2Cz4!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!2Cz4!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!2Cz4!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!2Cz4!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57515ffa-cbea-44ff-aa14-eaf617131090_500x500.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>One Token, Five Ecosystems and Counting</strong></h3><p>If you haven&#8217;t been following the open source supply chain crisis unfolding right now, here&#8217;s the context: starting March 19, a threat actor group called <a href="https://threats.wiz.io/all-actors/teampcp">TeamPCP </a>compromised <a href="https://www.aquasec.com/products/trivy/">Aqua Security&#8217;s Trivy scanner</a> - a tool baked into CI/CD pipelines everywhere - and used stolen credentials to cascade through five ecosystems: GitHub Actions, Docker Hub, npm, OpenVSX, and PyPI. One stolen token became five compromised ecosystems, ultimately reaching <a href="https://www.litellm.ai/">LiteLLM</a> - an LLM gateway present in 36% of cloud environments. And now, the campaign appears to have reached <a href="https://axios-http.com/">Axios</a>, one of the most widely used JavaScript libraries on the planet, downloaded over 100 million times per week. The Axios compromise <a href="https://www.sans.org/blog/axios-npm-supply-chain-compromise-malicious-packages-remote-access-trojan">has been assessed by SANS faculty</a> and others as a likely continuation of the TeamPCP campaign, raising the possibility that TeamPCP is operating as an Initial Access Broker. If that&#8217;s accurate, the supply chain compromises we&#8217;ve seen so far are more of an assembly line to build up inventory than the actual campaign.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!IWNs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!IWNs!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!IWNs!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!IWNs!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!IWNs!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!IWNs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg" width="459" height="223.25325443786983" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:411,&quot;width&quot;:845,&quot;resizeWidth&quot;:459,&quot;bytes&quot;:28112,&quot;alt&quot;:&quot;grey metal chain in close up photography&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="grey metal chain in close up photography" title="grey metal chain in close up photography" srcset="/__u/substackcdn.com/image/fetch/$s_!IWNs!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!IWNs!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!IWNs!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!IWNs!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed5ec5d6-9240-4bbf-a702-9383aebb0b86_845x411.jpeg 1456w" sizes="100vw"></picture><div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@aidamarie_photography">Aida L</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>So, even if your developers only pull from curated, verified registries using tools your security team approved, you&#8217;re still vulnerable to this kind of supply chain attack. The attacker pre-staged the malicious Axios dependency 18 hours before publishing the poisoned versions, built platform-specific payloads for Windows, macOS, and Linux, and targeted both the current and legacy release branches simultaneously. <a href="https://blog.gitguardian.com/team-pcp-snowball-analysis/">GitGuardian&#8217;s analysis of TeamPCP</a> found that a single stolen credential produced a fan-out ratio <strong>exceeding 10,000:1</strong>, as in, one key in and thousands of secrets out. </p><p>Check out the mercifully concise summary my SANS colleague Josh Wright <a href="https://www.sans.org/blog/axios-npm-supply-chain-compromise-malicious-packages-remote-access-trojan">published here</a>. In this case, I&#8217;d steer clear of indicator-based mitigations outside of rapid response, and focus instead on hardening supply chain and updating practices.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>ShinyHunters Hits the European Commission</strong></h3><p>ShinyHunters is claiming another significant scalp: <a href="https://securityaffairs.com/190095/data-breach/shinyhunters-claims-the-hack-of-the-european-commission.html">the European Commission</a>, with SH claiming the theft of over 350 GB of data including mail server dumps, databases, confidential documents, and contracts. The Commission detected the initial attack on March 24, confirmed that it affected cloud infrastructure hosting its Europa.eu websites, and acknowledged that some data was likely taken. The attack vector is still unknown, and the full scope is still being investigated, so take the 350 GB figure with appropriate skepticism until more is confirmed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!-5Ld!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!-5Ld!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png 424w, /__u/substackcdn.com/image/fetch/$s_!-5Ld!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png 848w, /__u/substackcdn.com/image/fetch/$s_!-5Ld!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-5Ld!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!-5Ld!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png" width="528" height="314.1152542372881" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:702,&quot;width&quot;:1180,&quot;resizeWidth&quot;:528,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!-5Ld!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png 424w, /__u/substackcdn.com/image/fetch/$s_!-5Ld!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png 848w, /__u/substackcdn.com/image/fetch/$s_!-5Ld!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png 1272w, /__u/substackcdn.com/image/fetch/$s_!-5Ld!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97989284-adee-4145-8484-bfe1cec2bcf5_1180x702.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We&#8217;ve spent a significant amount of time tracking ShinyHunters <a href="https://pushsecurity.com/blog/scattered-lapsus-hunters/">at my day job</a>, so while I may be biased, I think the more interesting takeaway here is that <strong>the playbook continues to work</strong>. The group has built a track record of social engineering and voice phishing to steal credentials and gain access to SaaS platforms like Salesforce, Okta, and Microsoft 365, and that&#8217;s a consistent thread across their recent victim list. This isn&#8217;t sophisticated nation-state intrusion as we might have expected in the past; it&#8217;s credential abuse at scale. Recent victims include Odido, Figure, Canada Goose, and SoundCloud - no common thread except TTPs that just work.</p><div><hr></div><h3><strong>Phishing Kits Shift to TikTok Business</strong></h3><p>Push Security&#8217;s threat research team <a href="https://pushsecurity.com/blog/tiktok-phishing/">identified a new wave of adversary-in-the-middle phishing pages</a> specifically targeting TikTok for Business accounts (the accounts your marketing team uses to manage paid ad campaigns). TikTok feels like an odd target until you think about what those accounts are actually worth: a verified business account with ad spend attached is a ready-made launchpad for malvertising fraud, and most business users log into TikTok via Google SSO. This means a single-session theft grants attackers both accounts simultaneously, along with everything else reachable through that Google identity. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!2T0O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!2T0O!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png 424w, /__u/substackcdn.com/image/fetch/$s_!2T0O!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png 848w, /__u/substackcdn.com/image/fetch/$s_!2T0O!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png 1272w, /__u/substackcdn.com/image/fetch/$s_!2T0O!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!2T0O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png" width="553" height="316" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:553,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;TikTok for Business themed page.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="TikTok for Business themed page." title="TikTok for Business themed page." srcset="/__u/substackcdn.com/image/fetch/$s_!2T0O!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png 424w, /__u/substackcdn.com/image/fetch/$s_!2T0O!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png 848w, /__u/substackcdn.com/image/fetch/$s_!2T0O!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png 1272w, /__u/substackcdn.com/image/fetch/$s_!2T0O!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bf22f6-4d63-4a70-a265-6dc6fa31d983_1999x1142.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The mechanics of this campaign are becoming (Dr. Evil voice) pretty standard, really. Victims land on convincing TikTok or Google Careers lure pages that route them through a bot-filtering checkpoint before serving a reverse-proxy phishing kit, which intercepts the session token in real time rather than just stealing a password. <strong>MFA doesn&#8217;t stop this, </strong>since session theft occurs post-authentication<strong>!</strong> The phishing domains were bulk-registered within a nine-second window, hosted behind Cloudflare, and tied to a registrar commonly associated with high-volume phishing infrastructure - purpose-built to be spun up fast and rotated before IOC lists catch up. </p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>Adrian Sanabria: I watched all 11 main stage keynotes at RSAC 2026, and less of my time was wasted than you might guess</strong></h3><p>Well, I was at RSA this year too. It was a productive trip, but my experience as a vendor was very different than past attendance as a practitioner. I have found that insights from other, more experienced, and better-spoken individuals have been far more clarifying than reflecting on my own thoughts. </p><p>With that in mind, here&#8217;s one of my favorite recaps from <a href="https://www.defendersinitiative.com/">Adrian Sanabria</a> - partially because he breaks down some of the hype over &#8220;securing AI&#8221; and partially because his pop culture references are on point.  </p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:192682250,&quot;url&quot;:&quot;https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes&quot;,&quot;publication_id&quot;:3676751,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;The Defender's Initiative&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rsmo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;title&quot;:&quot;I watched all 11 main stage keynotes at RSAC 2026&quot;,&quot;truncated_body_text&quot;:&quot;A different vibe&quot;,&quot;date&quot;:&quot;2026-03-31T05:38:52.370Z&quot;,&quot;like_count&quot;:0,&quot;comment_count&quot;:1,&quot;bylines&quot;:[{&quot;id&quot;:11988704,&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;handle&quot;:&quot;adriansanabria&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!VDfx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05cb4447-d60d-4c30-9185-b38fd15544dc_1487x1487.jpeg&quot;,&quot;bio&quot;:&quot;Always trying to see the big picture, figure out the best strategy, and uncover BS in Cybersecurity. I still see the glass as half-full.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-11-30T15:43:26.966Z&quot;,&quot;reader_installed_at&quot;:&quot;2023-02-23T02:04:20.824Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:3748026,&quot;user_id&quot;:11988704,&quot;publication_id&quot;:3676751,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:3676751,&quot;name&quot;:&quot;The Defender's Initiative&quot;,&quot;subdomain&quot;:&quot;defendersinitiative&quot;,&quot;custom_domain&quot;:&quot;www.defendersinitiative.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Trying to make sense of the crazy cybersecurity market, and helping defenders separate the stuff that works from the stuff that doesn't.&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;author_id&quot;:11988704,&quot;primary_user_id&quot;:11988704,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-01-04T22:08:14.270Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;Adrian Sanabria&quot;,&quot;founding_plan_name&quot;:&quot;Founding Defender&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;enabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/367948e2-1c6a-495f-9052-e0ad9f34e999_2688x512.png&quot;}},{&quot;id&quot;:1223048,&quot;user_id&quot;:11988704,&quot;publication_id&quot;:947260,&quot;role&quot;:&quot;contributor&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:947260,&quot;name&quot;:&quot;The Cyber Why&quot;,&quot;subdomain&quot;:&quot;thecyberwhy&quot;,&quot;custom_domain&quot;:&quot;www.thecyberwhy.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Weekly cybersecurity intelligence for people who actually have opinions about it. The Cyber Why covers the biggest stories in security, cyber business, and tech investing &#8212; with sharp takes, real analysis, and zero tolerance for vendor spin.&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3351f39-31c6-44dd-a9b6-9113808d9fef_500x500.png&quot;,&quot;author_id&quot;:77573547,&quot;primary_user_id&quot;:77573547,&quot;theme_var_background_pop&quot;:&quot;#A33ACB&quot;,&quot;created_at&quot;:&quot;2022-06-21T22:55:39.088Z&quot;,&quot;email_from_name&quot;:&quot;The Cyber Why&quot;,&quot;copyright&quot;:&quot;Tyler Shields&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;paused&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18941c9a-b77d-41b2-8120-49d3b0908d76_800x180.png&quot;}}],&quot;twitter_screen_name&quot;:&quot;sawaba&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:1,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:1,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[249852,2914801,281219],&quot;subscriber&quot;:null}}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="/__u/substackcdn.com/image/fetch/$s_!rsmo!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png" loading="lazy"><span class="embedded-post-publication-name">The Defender's Initiative</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">I watched all 11 main stage keynotes at RSAC 2026</div></div><div class="embedded-post-body">A different vibe&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">5 months ago &#183; 1 comment &#183; Adrian Sanabria</div></a></div><div><hr></div><h3><strong>Time As a Threat Hunting Surface</strong></h3><p><a href="https://cribl.io/blog/temporal-hunting-time-as-a-threat-hunting-surface/">This post by Albert Caballero</a> makes the case for time as an organizing principle of threat hunting. Rather than bouncing between tools and rehydrating datasets, the argument is that analysts should pivot along a timeline, moving from near-real-time detections through short-term logs and into long-term archives as a single investigative motion rather than a series of separate workflows. By embedding Sigma rule tagging and threat intelligence lookups directly into the data pipeline itself, every event gets annotated before it lands, meaning the same detection logic that fires on a live alert can also surface the same pattern in firewall logs from six months ago, without anyone manually rehydrating the data (a fairly direct hit against another major SIEM vendor that advocates for organizing all data into hot/warm/cold, but I digress). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!EgUs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!EgUs!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png 424w, /__u/substackcdn.com/image/fetch/$s_!EgUs!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png 848w, /__u/substackcdn.com/image/fetch/$s_!EgUs!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png 1272w, /__u/substackcdn.com/image/fetch/$s_!EgUs!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!EgUs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png" width="517" height="418.77" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1134,&quot;width&quot;:1400,&quot;resizeWidth&quot;:517,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Temporal hunting: Time as a threat hunting surface fig. 1&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Temporal hunting: Time as a threat hunting surface fig. 1" title="Temporal hunting: Time as a threat hunting surface fig. 1" srcset="/__u/substackcdn.com/image/fetch/$s_!EgUs!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png 424w, /__u/substackcdn.com/image/fetch/$s_!EgUs!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png 848w, /__u/substackcdn.com/image/fetch/$s_!EgUs!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png 1272w, /__u/substackcdn.com/image/fetch/$s_!EgUs!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ebca657-0d79-462f-a38d-37ff68cf676c_1400x1134.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I am massively in favor of abstracting detection analytics from detection tools, and just as big a fan of enriching detections prior to triage. Indicators age out, feeds go stale, and adversaries rotate infrastructure, but a well-written behavioral detection continues to fire across hot telemetry, warm logs, and cold archives as long as the behavior persists. Most organizations doing hypothesis-based hunts with atomic indicators are acting on data with a short shelf life, and the TeamPCP campaign this week is a live illustration. If your detections are IOC-based and your data is siloed by retention tier, the activity that matters most is exactly what you&#8217;ll miss.</p><div><hr></div><h3><strong>Assessing and Maturing OT SOCs With SOC-CMM</strong></h3><p>I have been a fan of <a href="https://soc-cmm.com/">SOC-CMM</a> for a while as a tool for assessing and improving security operations. <a href="https://soc-cmm.com/img/upload/files/61-soc-cmm-whitepaper-assessing-and-maturing-ot-socs.pdf">This white paper</a> covers key considerations for assessing and maturing a SOC in an operational technology (OT) environment. OT SOCs share many organizing principles with IT SOCs, but are unique in many ways - from limited OT system visibility to the domain expertise and contextual knowledge required for incident response. This whitepaper provides practical guidance and best practices to optimize OT SOCs (or SOCs with dual responsibilities in IT and OT), and, like other SOC-CMM materials, draws on real-world incidents and complementary models. Well worth a read if OT is within your scope!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!diac!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!diac!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png 424w, /__u/substackcdn.com/image/fetch/$s_!diac!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png 848w, /__u/substackcdn.com/image/fetch/$s_!diac!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png 1272w, /__u/substackcdn.com/image/fetch/$s_!diac!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!diac!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png" width="963" height="496" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:496,&quot;width&quot;:963,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:103634,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/192739547?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!diac!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png 424w, /__u/substackcdn.com/image/fetch/$s_!diac!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png 848w, /__u/substackcdn.com/image/fetch/$s_!diac!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png 1272w, /__u/substackcdn.com/image/fetch/$s_!diac!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bb68029-42be-4d95-a04e-c0ef08060f80_963x496.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>The common thread running through this week's stories isn't a specific threat actor or attack technique; it's a gap between how most security programs are organized (based on outdated mental models) and how attacks are <em>actually</em> unfolding. TeamPCP pivots through ecosystems using credentials your tools already trust. ShinyHunters runs the same playbook based on social engineering, credential theft, and session attacks. The TikTok phishing campaign intercepts authentication <em>after</em> MFA has already passed. </p><p>None of these attacks is stopped by a firewall, a signature update, or an IOC feed, because none of them look like attacks until well after the damage is done. What Caballero's temporal hunting piece argues, and what this week's incidents demonstrate in practice, is that defenders organized around indicators and tool-centric workflows are hunting with data that expires faster than attackers rotate their infrastructure. It&#8217;s important to standardize on models and frameworks that evolve alongside real attacks, such as the SOC-CMM, and supplement them with domain expertise from the last decade. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #49: No Exploit Required]]></title><description><![CDATA[Data breaches and industry research indicate a continued shift towards identity and access]]></description><link>https://markaorlando.substack.com/p/security-leadership-49-no-exploit</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-49-no-exploit</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 18 Mar 2026 12:16:42 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f0e8021f-97fe-4bcf-ae7c-09a197545288_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #49 of Security Leadership Weekly!  This issue is heavy on identity, which, at this point, is less a theme and more a permanent condition. Between Handala's wiper attack on Stryker, the Starbucks credential harvest, Microsoft's OAuth redirect campaign, and Cloudflare's sweeping threat report, the throughline is that attackers aren't breaking in; they&#8217;re <em>logging</em> in and then using the tools you've built and paid for to do the damage. We also look at where phishing is headed on mobile, and close with a conversation worth your time from one of the industry&#8217;s more interesting founders.</p><p><strong>P.S.</strong> In case you haven&#8217;t been reminded by a flood of vendor &#8220;will you be at RSAC??&#8221; emails, it&#8217;s next week! If you&#8217;d like to chat about detection and response, security operations, or browser-based telemetry, or just enjoy some time away from the conference venue, I&#8217;ll be there too - <a href="https://pushsecurity.com/events/rsa-2026-usa">book some time here</a> and let&#8217;s meet up.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>Insights From the Cloudflare Threat Report 2026</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!8Gb7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!8Gb7!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png 424w, /__u/substackcdn.com/image/fetch/$s_!8Gb7!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png 848w, /__u/substackcdn.com/image/fetch/$s_!8Gb7!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png 1272w, /__u/substackcdn.com/image/fetch/$s_!8Gb7!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!8Gb7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png" width="384" height="216" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c58c3408-5524-4407-8a12-2471611662d5_1999x1125.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:384,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!8Gb7!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png 424w, /__u/substackcdn.com/image/fetch/$s_!8Gb7!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png 848w, /__u/substackcdn.com/image/fetch/$s_!8Gb7!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png 1272w, /__u/substackcdn.com/image/fetch/$s_!8Gb7!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc58c3408-5524-4407-8a12-2471611662d5_1999x1125.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Some interesting takeaways from <a href="https://blog.cloudflare.com/2026-threat-report/">Cloudflare&#8217;s report</a>, released a couple of weeks ago, chiefly that the 2026 landscape is defined by the <strong>industrialization of cyber threats</strong> (if you haven&#8217;t read <a href="https://www.philvenables.com/post/delivering-security-at-scale-from-artisanal-to-industrial">Phil Venables&#8217; &#8220;Artisanal to Industrial&#8221; blog post</a>, go do that right now) and a fundamental shift toward the <strong>Measure of Effectiveness (MOE)</strong>, where attackers leverage AI to achieve maximum disruption with minimal effort:</p><ul><li><p><em>Identity</em> is the primary target as adversaries increasingly bypass standard multi-factor authentication (MFA) by harvesting session tokens (which <a href="https://pushsecurity.com/webinar/browser-extension-attacks">I highlighted last week</a> as the most dangerous technique used by malicious browser extensions) to &#8220;attack the session&#8221; rather than the network</p></li><li><p>Threat actors are now routinely weaponizing legitimate cloud and SaaS ecosystems, a tactic referred to in the report as Living off the XaaS (LotX? I&#8217;ll allow it) to mask command-and-control communications within benign enterprise traffic, while simultaneously exploiting the connective tissue of third-party API integrations. </p></li><li><p>Defenders are also facing unprecedented hyper-volumetric DDoS strikes, peaking at a record-breaking 31.4 Tbps, which autonomously exhaust local infrastructure capacity in seconds and effectively close the window for human intervention.</p></li></ul><p>There&#8217;s some high-level prescriptive hand-waving about shifting towards an identity-first zero-trust resilience model, which sounds great but is less helpful as a &#8220;go do&#8221;. I prefer some of the specific initiatives offered up in the report, including:</p><ol><li><p>Transitioning away from legacy MFA to phishing-resistant FIDO2 passkeys (not foolproof, but better), paired with continuous monitoring that can invalidate compromised sessions instantly. </p></li><li><p>Leaders overseeing daily operations must get their arms around<strong> </strong>SaaS-to-SaaS API permission grants to enforce least privilege and prevent attackers from pivoting across specialized cloud environments.</p></li></ol><p>Lots of useful tidbits to mine here, given Cloudflare&#8217;s deployment footprint, but many signs seemingly point to better identity control and visibility.</p><div><hr></div><h3><strong>Global Medtech Firm Stryker Targeted</strong></h3><p>Iran-linked hacktivist group Handala, tied to Iran's Ministry of Intelligence and Security, claimed responsibility this week for <a href="https://www.itsecurityguru.org/2026/03/13/iran-linked-hacktivists-claim-destructive-cyberattack-on-medtech-firm-stryker/">a devastating attack</a> on global medtech firm <a href="https://www.stryker.com/us/en/index.html">Stryker</a>, allegedly wiping data from over 200,000 devices across 79 countries and sending more than 5,000 employees home from Stryker's largest international hub in Ireland. While the initial attack vector is unclear, the attacker has proven administrative access to Microsoft Intune - reportedly commandeered after attackers obtained privileged credentials and used them to push a mass wipe command across the company's global fleet. </p><p>That's the detail security leaders need to sit with: the same console that manages patches and device policy is the console that erased everything. No exotic tooling required, just one compromised admin account and the organization's own infrastructure doing exactly what it was built to do. &lt;conjecture&gt; The attack was retaliatory rather than financially motivated, reportedly triggered by Stryker's U.S. defense ties and its acquisition of Israeli orthopedic company OrthoSpace &lt;/conjecture&gt;. And the blast radius here extends well beyond Stryker: the company manufactures medical devices used in operating rooms and ICUs worldwide, meaning the downstream effects on hospitals and surgical centers are real and potentially life-safety relevant. The management plane is a high-value target, and if your MDM, RMM, or endpoint management platform is sitting on credentials that aren't robustly protected, monitored, and scoped, this is what the worst-case scenario looks like.</p><div><hr></div><h3>Phishing Continues to Be Dominant Smartphone Threat</h3><p>Omdia's <a href="https://omdia.tech.informa.com/pr/2025/jan/omdia-survey-finds-phishing-attacks-top-smartphone-security-concern-for-consumers">latest mobile device security research</a> delivers a finding that shouldn't surprise anyone in this industry but is still worth naming plainly: <strong>no flagship smartphone</strong> - not Pixel, not iPhone, not Galaxy - scored full marks on anti-phishing protection, and custom phishing payloads from unknown senders went undetected across every device tested. AI-based scam detection is improving, and Google's on-device natural language checks are genuinely useful, but the most sophisticated attacks are still getting through. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!MiYc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!MiYc!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png 424w, /__u/substackcdn.com/image/fetch/$s_!MiYc!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png 848w, /__u/substackcdn.com/image/fetch/$s_!MiYc!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png 1272w, /__u/substackcdn.com/image/fetch/$s_!MiYc!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!MiYc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png" width="546" height="364" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:416,&quot;width&quot;:624,&quot;resizeWidth&quot;:546,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Consumer security concerns and reported incidence rate&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Consumer security concerns and reported incidence rate" title="Consumer security concerns and reported incidence rate" srcset="/__u/substackcdn.com/image/fetch/$s_!MiYc!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png 424w, /__u/substackcdn.com/image/fetch/$s_!MiYc!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png 848w, /__u/substackcdn.com/image/fetch/$s_!MiYc!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png 1272w, /__u/substackcdn.com/image/fetch/$s_!MiYc!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F839404c5-c84a-4d27-b862-20b2ab6eebe9_624x416.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What makes this relevant beyond the consumer audience is the behavioral data underneath it: 27% of consumers experienced phishing scams in the past year, English-speaking markets are disproportionately targeted (40% in the U.S.), and, critically, the rate of timely software updates dropped 9% year-over-year, with 14% of users waiting more than a month to patch and 2% never updating at all. For security leaders managing BYOD or hybrid device environments, that update-avoidance behavior is a real exposure, and it's driven less by apathy than by user perception that updates degrade performance and battery life. The broader takeaway is that the phishing problem is moving decisively toward mobile, AI is making attacker campaigns faster and more convincing, and the defensive tooling isn't there yet. </p><div><hr></div><h3><strong>Starbucks Loses a Latte of Data (I&#8217;m so sorry)</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!HDAs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!HDAs!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!HDAs!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!HDAs!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!HDAs!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!HDAs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg" width="534" height="300.375" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:534,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Starbucks&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Starbucks" title="Starbucks" srcset="/__u/substackcdn.com/image/fetch/$s_!HDAs!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!HDAs!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!HDAs!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!HDAs!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F565194f8-ee9e-417b-85ee-32acf5e25914_1600x900.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Starbucks <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/585e41ad-c38b-407c-8ce8-1f281d570d97.html">disclosed this week</a> that attackers compromised 889 employee accounts on Partner Central (the company's internal HR portal for managing payroll, benefits, and employment data) between January 19 and February 11, exposing names, Social Security numbers, dates of birth, and bank account and routing numbers. The attack vector was pretty straightforward: phishing sites impersonating the Partner Central login page harvested valid credentials, which attackers then used to authenticate normally and walk right through the front door. No infrastructure breach, no exploit chain, just stolen credentials and legitimate access doing the rest. </p><p>The numbers are relatively small (889 out of 380,000+ employees), but the data quality is alarming: SSNs and financial account details don't expire, can't be reset like a password, and retain exploitation value for years - especially when combined with data from other breaches to fuel targeted fraud and social engineering down the line. The three-week dwell time before detection is also interesting. If your workforce is accessing HR, payroll, or benefits platforms with single-factor authentication and no anomaly detection on login behavior, this is the outcome you're accepting as a risk.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>Microsoft's OAuth Redirect Abuse Warning </strong></h3><p>Microsoft researchers uncovered <a href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/">active phishing campaigns</a> that exploit OAuth's by-design redirection mechanism - not a vulnerability, but a feature. The attack creates a malicious app in an attacker-controlled tenant, then distributes phishing links that trigger an intentional error flow, redirecting victims from a legitimate Entra ID or Google Workspace page to attacker-controlled infrastructure. The result is that victims inadvertently download malware delivered as ZIP archives, triggering PowerShell execution, DLL side-loading, and pre-ransomware activity - all without any credential theft or software exploit. Some of the nuances here are novel, and it&#8217;s a great TTP breakdown, but overall, it aligns with many attack campaigns over the last year that have abused authentication flows through social engineering.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!gUWn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!gUWn!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp 424w, /__u/substackcdn.com/image/fetch/$s_!gUWn!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp 848w, /__u/substackcdn.com/image/fetch/$s_!gUWn!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!gUWn!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!gUWn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp" width="477" height="553.6719367588933" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:881,&quot;width&quot;:759,&quot;resizeWidth&quot;:477,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!gUWn!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp 424w, /__u/substackcdn.com/image/fetch/$s_!gUWn!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp 848w, /__u/substackcdn.com/image/fetch/$s_!gUWn!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp 1272w, /__u/substackcdn.com/image/fetch/$s_!gUWn!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e7ac6a-fe59-49bf-8f56-e469a7c027e4_759x881.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s also worth noting that this campaign starts with an email, but <a href="https://pushsecurity.com/">in my day job</a>, we&#8217;re increasingly seeing delivery via malicious ads, social media, app notifications, and other channels. We&#8217;re also seeing that OAuth permission grants are a user-driven wild west of apps and services. My advice is this: when consuming this kind of operational intel, view the delivery stage as a link that can be swapped out, and avoid tunnel vision on email, where most organizations already have decent visibility and control.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><div id="youtube2-0n-Ns1_Xy6g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;0n-Ns1_Xy6g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/0n-Ns1_Xy6g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>As a longtime Thinkst fan and former founder, I really enjoyed this interview with Haroon Meer. In it, Haroon explains how he bootstrapped company growth by focusing on product, arguing that relying on customer revenue rather than venture capital keeps a team focused on product quality over marketing. Meer also gets into deception technology and how Canary Token<strong>s </strong>can be deployed to elicit responses and/or &#8220;trap&#8221; attackers<strong>.</strong> </p><p>By focusing on simplicity and user experience, Thinkst has built a strong reputation for tools that are easy to deploy and highly effective. The conversation highlights how genuine problem-solving and a commitment to "customer love" can create a sustainable business in a crowded tech market.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>Pull back from the individual stories this week, and the pattern is almost uncomfortable in its consistency. Stryker's attackers didn't need a zero-day; they needed Intune credentials (?). The Starbucks breach didn't require touching corporate infrastructure; it required a convincing fake login page. The Microsoft OAuth campaign doesn't steal tokens at all; it abuses a legitimate redirect flow to deliver malware through trusted authentication infrastructure. </p><p>Cloudflare's data reinforces this at scale: session hijacking over credential theft, LotX (ok starting to hate this acronym) over custom malware, API pivots over network intrusion. The adversary playbook in 2026 is built on the premise that your own stack is the most reliable weapon available to them, and the data keeps proving them right. The implication for security leaders isn't novel, but it's increasingly urgent: <strong>visibility and control over the identity and management planes aren&#8217;t a priority on a roadmap; they&#8217;re the whole game.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #48: Ambition Without Capacity Isn't a Strategy]]></title><description><![CDATA[A plan is only as real as its ability to be executed.]]></description><link>https://markaorlando.substack.com/p/security-leadership-48-ambition-without</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-48-ambition-without</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 11 Mar 2026 14:10:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/feb61cc8-c61b-47ea-88e5-91884b39a717_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #48 of Security Leadership Weekly! This week's stories don't share a common threat actor, vulnerability class, or even an industry. What they share, in my opinion, is something more consequential: the security field&#8217;s growing tendency to mistake declared <em>intent</em> for actual <em>capability</em>. A national cyber strategy exists, but the agencies tasked with executing it have been systematically dismantled. Hardening guidance exists for Salesforce Experience Cloud, but the organizational will to follow it seems to repeatedly fall short. AI agents are being deployed with expansive permissions across enterprise environments, but the governance architecture to oversee them just isn&#8217;t there. In each case, the plan was real, but the capability wasn't. And in each case, someone took advantage of the distance between the two.</p><p><strong>Shameless plug</strong>: speaking of attackers operating in the liminal space between strategy and governance, I&#8217;m doing a webinar on malicious browser extensions today! If you can&#8217;t make it live, go ahead and register <a href="https://pushsecurity.com/webinar/browser-extension-attacks">here,</a> and we&#8217;ll send you the recording.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>Google&#8217;s 2025 Zero-Day Review: Enterprise Infrastructure Now the Primary Battlefield for Zero Days</strong></h3><p>Google&#8217;s Threat Intelligence Group released <a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review">its annual zero-day review</a> last week, which might recalibrate how security leaders think about attack-surface prioritization. Of the 90 zero-day vulnerabilities actively exploited in 2025 (up from 78 in 2024), a record 48% targeted enterprise technologies rather than consumer platforms. Security and networking devices bore the brunt of that shift, with Cisco, Fortinet, Ivanti, and VMware among the hardest-hit vendors. China-nexus espionage groups remained the most prolific state-sponsored exploiters, with at least 10 attributed zero-days (double their 2024 count) focused almost exclusively on edge infrastructure.</p><p>Two structural shifts in the threat landscape deserve particular attention from leadership:</p><ol><li><p><strong>Commercial surveillance vendors surpassed state-sponsored groups</strong> in zero-day exploitation volume for the first time on record</p></li><li><p><strong>Browser-based exploitation continued its decline</strong> to historic lows, while operating system and mobile exploits rose sharply, signaling that attackers are moving away from the browser as an exploitation surface, precisely as defenders have hardened it, pivoting instead to the infrastructure and OS layers where detection remains weaker. This echoes what we&#8217;re seeing at Push Security, where the economics of attacks <em>inside </em>the browser are far more favorable to attacks than attacking the browser itself.</p></li></ol><p>Google&#8217;s forward-looking warning is equally notable, if not surprising: AI-assisted vulnerability discovery and exploit development are expected to significantly compress the time between disclosure and weaponization in 2026, narrowing an already dangerously thin window for enterprise patching.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!lydK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!lydK!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!lydK!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!lydK!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!lydK!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!lydK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg" width="430" height="414.3475274725275" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1403,&quot;width&quot;:1456,&quot;resizeWidth&quot;:430,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;https://storage.googleapis.com/gweb-cloudblog-publish/images/zero-day-2025-fig2a.max-1700x1700.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/zero-day-2025-fig2a.max-1700x1700.jpg" title="https://storage.googleapis.com/gweb-cloudblog-publish/images/zero-day-2025-fig2a.max-1700x1700.jpg" srcset="/__u/substackcdn.com/image/fetch/$s_!lydK!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!lydK!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!lydK!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!lydK!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F525de6c7-8463-415f-9ac2-3fb76bdcfebc_1700x1638.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3></h3><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>InstallFix: When the Install Command Is the Attack</strong></h3><p>Push Co-founder and CPO Jacques Louw <a href="https://pushsecurity.com/blog/installfix/">just posted about a new social engineering technique called </a><em><a href="https://pushsecurity.com/blog/installfix/">InstallFix</a>, </em>discovered by Push researchers. It&#8217;s a natural evolution of the *Fix family that strips away the need for manufactured pretexts like fake CAPTCHAs or error messages entirely. </p><p>The mechanic is elegantly simple (and infuriating to anyone who likes to copy and paste install commands from software docs): attackers clone the installation pages of popular developer tools with near-pixel-perfect fidelity, swap the legitimate install commands for malicious ones, and distribute the fake pages via Google Ads targeting users who are actively searching for that software. The victim does exactly what they intended to do - install a tool - and the attack succeeds before they have any reason to be suspicious. Any further interaction on the cloned page simply redirects back to the legitimate site, keeping the victim unaware.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!xOEr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!xOEr!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png 424w, /__u/substackcdn.com/image/fetch/$s_!xOEr!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png 848w, /__u/substackcdn.com/image/fetch/$s_!xOEr!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xOEr!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!xOEr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png" width="552" height="311.6373626373626" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/adf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:822,&quot;width&quot;:1456,&quot;resizeWidth&quot;:552,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Cloned page 1&quot;,&quot;title&quot;:&quot;Cloned page 1&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Cloned page 1" title="Cloned page 1" srcset="/__u/substackcdn.com/image/fetch/$s_!xOEr!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png 424w, /__u/substackcdn.com/image/fetch/$s_!xOEr!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png 848w, /__u/substackcdn.com/image/fetch/$s_!xOEr!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xOEr!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadf6a173-1053-4002-ab4b-600ea514a30b_1999x1128.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The initial campaign documented by Push targeted Claude Code, with the malicious pages delivering <a href="https://malpedia.caad.fkie.fraunhofer.de/details/win.amatera">Amatera Stealer</a>, a credential-harvesting infostealer that exfiltrates saved browser passwords, cookies, and session tokens. But the technique could impact any popular software install pages. The underlying vulnerability being exploited is user trust: the &#8220;curl-to-bash&#8221; installation pattern has become the industry standard for developer tooling. InstallFix continues the trend of *Fix lures delivered via search engines rather than email, meaning this entire attack category operates entirely outside the reach of email security gateways and traditional phishing defenses. </p><div><hr></div><h3><strong>Threat Actors Weaponize Salesforce Audit Tool for Mass Data Harvesting</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Drry!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Drry!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Drry!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Drry!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Drry!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Drry!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg" width="501" height="261.6333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:900,&quot;resizeWidth&quot;:501,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Drry!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!Drry!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!Drry!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!Drry!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F335eaf59-2793-4b86-bb27-bfa760e90a7a_900x470.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Salesforce <a href="https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/">has issued a warning</a> that a known threat actor group is actively mass-scanning publicly accessible Experience Cloud sites using a modified version of <a href="https://cloud.google.com/blog/topics/threat-intelligence/auditing-salesforce-aura-data-exposure/">AuraInspector</a>, an open-source audit tool originally released by Mandiant in January 2026 to help security teams identify Salesforce misconfigurations. The attacker&#8217;s customized version goes well beyond reconnaissance: where the original tool simply identifies vulnerable API endpoints, the weaponized variant actively extracts data by exploiting overly permissive guest user profile configurations. </p><p>Salesforce was clear that no platform vulnerability is involved; this is entirely a misconfiguration problem, requiring two conditions to be exploitable: the organization uses the Experience Cloud guest user profile, and has not followed Salesforce&#8217;s recommended hardening guidance. The company stopped short of naming the responsible group, though it noted attribution to a known threat actor, raising the possibility of ShinyHunters involvement given that group&#8217;s documented history of targeting Salesforce environments through third-party integrations.</p><p>For any organization running Salesforce Experience Cloud, this warrants an immediate review of your configuration. For everyone else, it&#8217;s a timely reminder that SaaS misconfiguration remains one of the most reliably exploited gaps in enterprise security posture.</p><div><hr></div><h3><strong>Agentic AI: The Attack Surface Nobody Is Ready For</strong></h3><p><a href="https://krebsonsecurity.com/2026/03/how-ai-assistants-are-moving-the-security-goalposts/">Brian Krebs documents</a> how the rapid adoption of autonomous AI assistants is creating a new and largely unmanaged attack surface in enterprise environments. It&#8217;s a great overview of the risks associated with AI assistants that take initiative on the user&#8217;s behalf versus passive agents that respond to user prompts. Of course, the focal point is OpenClaw, an open-source AI agent designed to operate proactively on a user&#8217;s behalf with full access to a user&#8217;s digital environment. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!nG_5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!nG_5!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png 424w, /__u/substackcdn.com/image/fetch/$s_!nG_5!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png 848w, /__u/substackcdn.com/image/fetch/$s_!nG_5!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nG_5!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!nG_5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png" width="768" height="143" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:143,&quot;width&quot;:768,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!nG_5!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png 424w, /__u/substackcdn.com/image/fetch/$s_!nG_5!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png 848w, /__u/substackcdn.com/image/fetch/$s_!nG_5!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nG_5!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed38bd79-0863-4c28-bc48-0ee2c07ee50d_768x143.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The more significant concern for security leaders isn&#8217;t the misconfiguration risk (though that&#8217;s in here too) - it&#8217;s the structural one. A documented supply chain attack against the AI coding assistant <a href="https://cline.bot/">Cline </a>demonstrated how prompt injection through a GitHub issue title caused the tool&#8217;s own AI-powered workflow to install a rogue agent with full system access across thousands of devices as part of an official update. This is what researchers are calling the <strong>confused deputy</strong> problem at scale: developers authorize AI agents to act on their behalf, and once those agents are compromised, that authority is silently delegated to whatever the attacker chooses. The &#8220;lethal trifecta&#8221; framework coined by Django co-creator <a href="https://simonwillison.net/">Simon Willison</a> captures the core risk clearly: any system that combines access to private data, exposure to untrusted content, and the ability to communicate externally is a data exfiltration waiting to happen. </p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>National Cyber Strategy: Big Ambitions, Hollowed-Out Execution</strong></h3><p>On March 6, the White House released <em><a href="https://www.whitehouse.gov/wp-content/uploads/2026/03/President-Trumps-Cyber-Strategy-for-America.pdf">President Trump&#8217;s Cyber Strategy for America</a></em>, a seven-page document (much shorter than its predecessors) built around six policy pillars: adversary deterrence, common-sense regulation, federal network modernization, critical infrastructure protection, emerging technology dominance, and workforce development. The tone is aggressive, framing cyberspace as a domain for offensive power projection, with the administration promising it &#8220;will not confine its responses to the cyber realm.&#8221; Familiar priorities appear, such as zero-trust, post-quantum cryptography, supply chain resilience, and public-private partnerships, but details are deferred to a forthcoming action plan that does not yet exist (not unusual for a strategic policy to lack specifics, though).</p><p>What the document cannot obscure is the widening gap between its ambitions and the institutional capacity to execute them. <a href="https://abc7chicago.com/post/chicago-fbi-terrorism-task-force-new-objective-during-president-donald-trump-administration-immigration-enforcement/15985664/#:~:text=Chicago%20FBI%20terrorism%20task%20force%20new%20objective:%20Immigration%20enforcement,obtained%20by%20the%20I%2DTeam.">FBI Joint Terrorism Task Forces have been resource-stripped</a> in favor of immigration enforcement, degrading the interagency coordination that the strategy promises. A mass exodus of career intelligence professionals has <a href="https://www.intelligenceonline.com/americas/2026/01/28/cia-veterans-flood-into-private-sector-in-wake-of-trump-culls,110613587-art#:~:text=The%20exodus%20from%20the%20US%20intelligence%20agency,cutbacks%20and%20a%20growing%20demand%20in%20political">hollowed out the CIA and broader IC</a>, stripping the attribution capabilities that offensive cyber operations depend on. <a href="https://www.scworld.com/brief/cisa-faces-leadership-changes-amidst-staffing-cuts-and-security-concerns">CISA has lost at least a third of its workforce</a>, its public-private partnership programs have been defunded, and its acting director was reassigned just days before the strategy dropped. And largely beneath the radar: DOGE&#8217;s sweeping data-gathering across federal civilian agencies <a href="https://www.brookings.edu/articles/privacy-under-siege-doges-one-big-beautiful-database/">has raised serious unresolved questions</a> about access controls and the security of sensitive federal systems - an own-goal that no cyber strategy document addresses. Ambition without capacity isn&#8217;t strategy.  </p><div><hr></div><h3><strong>What Phil Venables Gets Right About Modern Security Leadership</strong></h3><p>In a post that deserves wider circulation among security leaders, Google board member and former Goldman Sachs CISO Phil Venables <a href="https://www.philvenables.com/post/cybersecurity-s-need-for-speed-where-to-find-it">makes a deceptively simple argument</a>: in a world where AI is accelerating both the pace of change and the pace of threats, speed is no longer a performance metric; it is a survival condition. Venables structures his thinking around <a href="https://jods.mitpress.mit.edu/pub/issue3-brand/release/2">Stewart Brand&#8217;s Pace Layers framework</a>, observing that effective security programs must learn to operate across multiple time horizons simultaneously, moving fast at the technology and tooling layers while building durable control reliability at the slower, more stable layers below. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!zg5h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!zg5h!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png 424w, /__u/substackcdn.com/image/fetch/$s_!zg5h!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png 848w, /__u/substackcdn.com/image/fetch/$s_!zg5h!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png 1272w, /__u/substackcdn.com/image/fetch/$s_!zg5h!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!zg5h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png" width="440" height="413.2432432432432" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:695,&quot;width&quot;:740,&quot;resizeWidth&quot;:440,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!zg5h!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png 424w, /__u/substackcdn.com/image/fetch/$s_!zg5h!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png 848w, /__u/substackcdn.com/image/fetch/$s_!zg5h!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png 1272w, /__u/substackcdn.com/image/fetch/$s_!zg5h!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feecdc512-83a4-4164-ab22-629d3c7ef448_740x695.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>His practical recommendations span eleven areas, from streamlining software delivery pipelines and change approval processes to building autonomic security operations capable of self-correction without waiting for human direction. The throughline challenges the defeatism that pervades much of the security community: the organizations that claim they cannot move faster, Venables argues, confuse lack of will with lack of ability.</p><p>Two observations from the piece are particularly worth internalizing:</p><ol><li><p>Venables reframes the classic &#8220;attackers don&#8217;t have change boards&#8221; argument, acknowledging its validity while pointing out that the most mature regulated organizations have already solved this problem by streamlining approvals and expanding the category of pre-authorized changes, moving fast without breaking things. </p></li><li><p>His concept of &#8220;shifting down&#8221; rather than just shifting left is perhaps the most actionable long-term idea in the piece. </p></li></ol><p>For CISOs navigating board conversations about AI investment and program maturity, this post provides both a vocabulary and a practical framework for making the case that speed and rigor are not in tension. </p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>Phil Venables argues that organizations claiming they cannot move faster are confusing a lack of will with a lack of <strong>ability</strong>. I think he&#8217;s right, but this issue suggests the problem runs deeper than organizational inertia. The gap between intent and capability isn't just an execution failure; it&#8217;s an attack surface. Attackers aren't breaking through defenses so much as stepping into the space between what organizations believe their security posture to be and what it actually is. That gap shows up in federal institutions stripped of the talent required to operationalize an aggressive national strategy, in SaaS environments where published guidance goes unimplemented, in browser-delivered attacks that bypass every email-based and network-focused control an organization has invested in, and in AI systems granted authority that no governance framework or technical control has caught up to. The throughline isn't speed, and it isn't sophistication. It's the compounding cost of security theater.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #47: Flying Blind]]></title><description><![CDATA[Cracks widen in the traditional kill chain model.]]></description><link>https://markaorlando.substack.com/p/security-leadership-47-flying-blind</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-47-flying-blind</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 04 Mar 2026 13:17:19 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7b3d2705-c847-4d00-938a-9df6f3b028ce_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #47 of Security Leadership Weekly! This week, almost every story touches on the limits of what existing security programs can actually see. AI is accelerating attacks faster than most SOC playbooks can respond. A trusted, Featured browser extension became a C2 platform overnight through a subtle (but impactful) supply-chain shift that static analysis wouldn&#8217;t detect. Critical infrastructure dependencies extend below the visibility of traditional OT models. And the cybersecurity industry itself, as Shostack and Sanabria will argue at RSAC 2026, systematically hides failure data that would help us improve. The theme isn't any single threat; it's a visibility problem at almost every layer of the stack.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>Crackdown On The Com Leads to 30 Arrests</strong></h3><p>A <a href="https://www.bleepingcomputer.com/news/security/police-crackdown-on-the-com-cybercrime-gang-leads-to-30-arrests/">yearlong Europol-coordinated operation</a> has delivered the first significant law enforcement action against The Com, the loosely organized English-speaking cybercrime collective that sits behind Scattered Spider and a range of financially motivated and violent attacks. <a href="https://www.europol.europa.eu/operations-services-and-innovation/operations/project-compass">Operation Project Compass</a>, led by Europol&#8217;s European Counter Terrorism Centre and involving law enforcement from 28 countries, resulted in 30 arrests and the identification of 179 suspects. The Com is mostly composed of cybercriminals aged 16 to 25, and has been linked to attacks ranging from crippling British retailers&#8217; IT systems to making bomb threats and coercing teenage girls into self-harm. Over time, The Com has developed connections to violent extremist groups and Russian cybercriminal gangs, with some offshoots refining extortion tactics by running sextortion campaigns targeting teenagers before escalating to attacks on corporations. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!nebj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!nebj!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png 424w, /__u/substackcdn.com/image/fetch/$s_!nebj!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png 848w, /__u/substackcdn.com/image/fetch/$s_!nebj!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nebj!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!nebj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png" width="716" height="402.75" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:716,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!nebj!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png 424w, /__u/substackcdn.com/image/fetch/$s_!nebj!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png 848w, /__u/substackcdn.com/image/fetch/$s_!nebj!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nebj!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F678e82b8-201c-46c3-a670-27ca73061861_2048x1152.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Com is the upstream talent pool and social network that feeds groups like Scattered Spider - the same collective responsible for the MGM and Caesars intrusions. The decentralized, youth-driven structure makes it persistently difficult to fully disrupt, and law enforcement has been candid about that. The more operationally relevant signal is the attack profile: social engineering-first, identity-focused, and increasingly connected to physical threats and extortion. If your organization hasn&#8217;t stress-tested its defenses against this style of attack - vishing, SIM swapping, help desk manipulation - this is a good reminder that the threat is real, organized, and still active despite the arrests. We&#8217;ve researched The Com and their attack campaigns extensively at <a href="https://pushsecurity.com/">Push Security</a> - you can read some of our coverage <a href="https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign">here</a> and <a href="https://pushsecurity.com/blog/scattered-lapsus-hunters">here</a>.</p><div><hr></div><h3><strong>Claude Code and ChatGPT Weaponized in Mexican Gov Attack</strong></h3><p>Israeli cybersecurity firm <a href="https://gambit.security/">Gambit Security</a> has published research detailing a case where threat actors weaponized Anthropic&#8217;s Claude Code to conduct a sustained attack against Mexican government systems, ultimately compromising 10 agencies and a financial institution and exfiltrating 150GB of data. The attackers posed as bug bounty testers to manipulate Claude into writing exploits, generating targeting recommendations, and automating credential harvesting, ultimately sending over 1,000 prompts over roughly a month of operations. When Claude resisted certain instructions, the attackers pivoted to ChatGPT to fill the gaps, treating multiple AI systems as interchangeable tools in the attack chain (<a href="/__u/markaorlando.substack.com/p/ai-commoditization-and-security-decision?r=lspb7">I wrote about this commoditization of AI</a> earlier this week). This follows Anthropic&#8217;s <a href="https://www.anthropic.com/news/disrupting-AI-espionage">November 2025 disclosure</a> that China-linked actors had also abused Claude Code in an espionage campaign targeting nearly 30 organizations worldwide.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!9OpY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!9OpY!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!9OpY!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!9OpY!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!9OpY!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!9OpY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg" width="522" height="293.625" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:522,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;AI attack&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="AI attack" title="AI attack" srcset="/__u/substackcdn.com/image/fetch/$s_!9OpY!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!9OpY!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!9OpY!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!9OpY!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9dde25d-6f3b-4e34-a7c0-f21b8bd41ba7_1200x675.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The takeaway from this story isn&#8217;t that Claude is uniquely dangerous, of course; it&#8217;s that AI-assisted attacks are now a documented operational reality, not a theoretical concern. For defenders, this changes the threat model in a few meaningful ways. First, attack velocity is going up: AI dramatically compresses the time between initial access and lateral movement. Second, the sophistication floor is dropping. Attackers don&#8217;t need deep technical expertise when they can use prompts to guide an intrusion. If your SOC is still tuned to the pace of human attackers and a largely manual attack chain, AI-assisted intrusions may move faster than your playbooks expect. Check out SecurityWeek&#8217;s coverage of this story <a href="https://www.securityweek.com/hackers-weaponize-claude-code-in-mexican-government-cyberattack/">here</a>.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>Case Study: Weaponization of a Chrome Extension</strong></h3><p>Annex Security <a href="https://annex.security/blog/pixel-perfect/">published research last week</a> that&#8217;s a textbook illustration of the browser extension supply chain problem. A Chrome extension called QuickLens - a Google Lens wrapper that had grown to 7,000 users and earned a Featured badge from Google - was listed for sale on <a href="https://www.extensionhub.io/">ExtensionHub</a>, a marketplace where developers sell extensions complete with their user base and review history. On February 1st, 2026, ownership was transferred to an unverified entity operating under the domain supportdoodlebuggle.top, registered as LLC Quick Lens: a throwaway identity with no verifiable online presence. Two weeks later, version 5.8 quietly pushed a fully operational command-and-control platform to all 7,000 existing users. The update added two new permissions and embedded a C2 server that fingerprints users, registers a persistent UUID, and polls for JavaScript instructions to execute at runtime, so the malicious payload never appears in the extension&#8217;s source files. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Us13!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Us13!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png 424w, /__u/substackcdn.com/image/fetch/$s_!Us13!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png 848w, /__u/substackcdn.com/image/fetch/$s_!Us13!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Us13!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Us13!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png" width="640" height="273.4065934065934" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:622,&quot;width&quot;:1456,&quot;resizeWidth&quot;:640,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Webstore&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Webstore" title="Webstore" srcset="/__u/substackcdn.com/image/fetch/$s_!Us13!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png 424w, /__u/substackcdn.com/image/fetch/$s_!Us13!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png 848w, /__u/substackcdn.com/image/fetch/$s_!Us13!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Us13!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b41cf09-95f4-4cf2-b7cb-443c2bd0d8d0_2242x958.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The capability this gives attackers is significant: the injected code can read session tokens, capture form inputs, scrape page content, and send stolen data to external servers - all while the extension continues functioning normally as a Google Lens tool, leaving users with no reason to suspect anything is wrong. This is the extension supply chain attack in its most refined form, with no new installs required, no alarming new permissions, and no malicious code visible at rest. </p><p>Effective controls for this kind of thing include extension allowlisting, monitoring for ownership changes and unexpected new permissions (particularly <code>declarativeNetRequest</code> and <code>webRequest</code>), and runtime behavior analysis rather than static inspection. Shameless plug: we do a LOT of research into malicious browser extensions at Push Security, and offer these controls out of the box. <a href="https://pushsecurity.com/webinar/browser-extension-attacks">I&#8217;ll also be hosting a webinar next week on malicious extensions</a>!</p><div><hr></div><h3><strong>Google Moves to Create a Quantum-Safe Web</strong></h3><p><a href="https://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html">Google announced last week </a>that Chrome is moving toward a fundamentally new certificate architecture for quantum-resistant HTTPS, called <a href="https://groups.google.com/a/chromium.org/g/ct-policy/c/47gNi0rlClg/m/FrcqfuVVAwAJ?pli=1">Merkle Tree Certificates</a> (MTCs). Rather than simply swapping post-quantum algorithms into existing X.509 certificates, which would create significant bandwidth problems, Google is redesigning how certificate chains work entirely, in partnership with Cloudflare and through the IETF (you can check out Cloudflare&#8217;s post on MTC from late last year <a href="https://blog.cloudflare.com/bootstrap-mtc/">here</a>). A new Chrome Quantum-Resistant Root Store goes live in Q3 2027, running alongside the existing system to ensure a managed transition. This isn&#8217;t just a browser update; it&#8217;s a signal that the underlying plumbing of web PKI is being rebuilt, and organizations with internal CAs, certificate pinning, TLS inspection proxies, or manual certificate management processes will feel it.</p><p>The right move now is to start your cryptographic inventory: know where you depend on traditional X.509 certificates, especially anything involving internal PKI or long-lived certificates. Google is also explicitly pushing toward <a href="https://datatracker.ietf.org/doc/html/rfc8555">ACME</a>-only certificate workflows in the new ecosystem, so if you&#8217;re still managing certificates manually, this is a good forcing function to automate. And if you&#8217;re thinking about the actual quantum threat, your real exposure isn&#8217;t browser HTTPS - it&#8217;s sensitive data in transit being harvested today by adversaries who plan to decrypt it later. <strong>Focus there first</strong>. What you shouldn&#8217;t do is treat this as an immediate crisis. Chrome is maintaining X.509 fallbacks throughout the experiment phase; the two root stores will coexist, and the standard is still being finalized. Organizations that build cryptographic agility into their infrastructure now will navigate this transition without drama. The ones who wait will scramble.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>Mapping Critical Infrastructure Dependencies with CLAIR</strong></h3><p><a href="https://isc.sans.edu/diary/32748">A guest diary on the SANS Internet Storm Center</a> by <a href="https://www.linkedin.com/in/ctwperry/">Claire Perry</a> introduced the CLAIR Model (Comprehensive Linkage and Architectural Infrastructure Resiliency), a new framework for mapping critical infrastructure interdependencies that&#8217;s worth understanding as IT/OT convergence risks accelerate. The model extends the familiar <a href="https://www.energy.gov/sites/default/files/2022-10/Infra_Topic_Paper_4-14_FINAL.pdf">Purdue hierarchy</a> from five levels to ten, with the most interesting additions at the extremes: Level -1, which accounts for the external utility grid and other primary infrastructure that organizations don&#8217;t control but entirely depend on, and Levels 6 and 7, which address cloud/edge computing and high-trust safety systems, respectively. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!TzBV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!TzBV!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png 424w, /__u/substackcdn.com/image/fetch/$s_!TzBV!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png 848w, /__u/substackcdn.com/image/fetch/$s_!TzBV!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png 1272w, /__u/substackcdn.com/image/fetch/$s_!TzBV!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!TzBV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png" width="630" height="315" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:630,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!TzBV!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png 424w, /__u/substackcdn.com/image/fetch/$s_!TzBV!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png 848w, /__u/substackcdn.com/image/fetch/$s_!TzBV!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png 1272w, /__u/substackcdn.com/image/fetch/$s_!TzBV!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20ee6e30-4055-4b59-92cd-0c4ba2431edf_1600x800.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The core insight is that the old Purdue model treats the outside world as a simple input rather than a complex, bidirectional dependency - a blind spot that&#8217;s increasingly dangerous as data centers become massive electrical loads deeply entangled with regional power grids.</p><p>The model also calls out AI-OT convergence as an emerging dependency risk, noting that AI models deployed at operational layers can create hidden cyber linkages that effectively bypass the industrial DMZ when models need to be updated from cloud infrastructure. If you&#8217;re responsible for securing OT and using Perdue as a reference, consider CLAIR as an expanded maturity lens. </p><div><hr></div><h3><strong>The Case for Better Breach Transparency</strong></h3><p>Security researchers Adam Shostack and Adrian Sanabria <a href="https://www.darkreading.com/cyberattacks-data-breaches/why-better-breach-transparency-matters">are making the case at RSAC 2026</a> for something the industry has long resisted: genuine breach transparency. Their argument is pretty straightforward: it has become standard practice for organizations to disclose the bare minimum about a data breach, or worse, not disclose the incident at all. Shostack and Sanabria draw a contrast with other safety-critical industries like aviation and medicine, where failures are heavily scrutinized and formalized feedback loops exist specifically to help others learn from them. Without better data and empirical evidence to inform breach prevention, the industry risks investing in what Sanabria calls &#8220;busywork generators&#8221; - tools and compliance activities that may not significantly reduce real-world risk. </p><p>This lands differently for security leaders than it does for the broader industry conversation. The argument isn&#8217;t just philosophical; it has a direct bearing on how security programs are evaluated and how budgets get justified. Without formalized transparency and governance, the industry will struggle to determine whether organizations are truly improving their response to and prevention of security incidents. The duo proposes anonymized reporting, delayed public disclosures, and regulatory safe harbors for good-faith transparency -  mechanisms designed to lower the legal and reputational cost of honesty, which I think historically has been the biggest hurdle to clear. </p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>The key takeaway this week: defenders are operating with incomplete pictures, and adversaries are exploiting that gap with increasing precision. </p><ul><li><p>The Mexico AI attack and the QuickLens extension case <em>both</em> demonstrate how attacks can now unfold within trusted surfaces, without triggering the controls designed to catch them. </p></li><li><p>The Com's persistence despite arrests reminds us that decentralized, identity-focused threat actors don't need sophisticated infrastructure when social engineering gets them through the front door. </p></li><li><p>Google's MTC announcement and the CLAIR model both point to dependencies that most organizations haven&#8217;t mapped: cryptographic infrastructure and utility-layer dependencies that sit entirely outside the security perimeter. </p></li><li><p>Shostack's RSAC breach-transparency argument ties it all together: the industry's reluctance to share failure data means we're collectively making the same mistakes in the dark. </p></li></ul><p>The throughline is that the next phase of security maturity isn't about adding more tools; it's about closing the visibility gaps that let adversaries operate undetected inside systems we thought we understood.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[AI Commoditization and Security Decision Support]]></title><description><![CDATA[The Model Isn't the Moat]]></description><link>https://markaorlando.substack.com/p/ai-commoditization-and-security-decision</link><guid isPermaLink="false">https://markaorlando.substack.com/p/ai-commoditization-and-security-decision</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Mon, 02 Mar 2026 13:45:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DBI4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>After chairing the <a href="https://www.sans.org/webcasts/sans-2026-soc-siem-soar-forum">SANS 2026 SOC, SIEM, and SOAR Forum</a> last week and listening to my end-of-week podcast episodes (more on that in a sec), I&#8217;ve realized something. While AI vendors keep hyping the release of newer, better, faster models, there&#8217;s a growing consensus that AI models are heading toward commoditization - that reasoning engines will increasingly function as interchangeable infrastructure, much like cloud compute did a decade ago. <a href="https://podcasts.apple.com/us/podcast/pivot/id1073226719">Scott Galloway and Kara Swisher</a> also made this case on last Thursday&#8217;s episode of <em>Pivot</em>.</p><p><a href="/__u/jasonhowell.substack.com/p/meta-ai-chief-yann-lacun-human-intelligence">Yann LeCun goes further</a>, arguing that current LLMs aren&#8217;t just commoditizing but are the wrong paradigm entirely. Whether you find his thesis convincing or not, the directional pressure is the same: <em>the model itself is not where durable value lives</em>.</p><p>When reasoning becomes infrastructure, value doesn&#8217;t evaporate; it migrates up to the application layer and down to the data layer. Palantir built its entire business on this thesis - the limiting factor in turning data into decisions wasn&#8217;t compute or model sophistication, it was the ontological work: modeling complex domains, encoding analyst workflows, building the data structures that make AI reasoning operationally meaningful. I recall running an early pilot of Palantir in a SOC and being confused about why it required multiple engineers camping out to build the data models! Competitors with superior model budgets have consistently failed to replicate it, because the moat isn&#8217;t algorithmic. It&#8217;s architectural and experiential. That&#8217;s a lesson worth applying to security decision support.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!DBI4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!DBI4!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png 424w, /__u/substackcdn.com/image/fetch/$s_!DBI4!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png 848w, /__u/substackcdn.com/image/fetch/$s_!DBI4!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png 1272w, /__u/substackcdn.com/image/fetch/$s_!DBI4!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!DBI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png" width="1142" height="409" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/151683a7-745f-4273-aca6-57bb9486834a_1142x409.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:409,&quot;width&quot;:1142,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94276,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!DBI4!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png 424w, /__u/substackcdn.com/image/fetch/$s_!DBI4!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png 848w, /__u/substackcdn.com/image/fetch/$s_!DBI4!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png 1272w, /__u/substackcdn.com/image/fetch/$s_!DBI4!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F151683a7-745f-4273-aca6-57bb9486834a_1142x409.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is also something we should take into our evaluations of security products. A lot of vendor pitches right now lead with AI: the demo, the capability theater, the natural language interface.</p><p>This isn&#8217;t a critique of any one product; it&#8217;s a pattern that emerges naturally when a powerful capability becomes widely accessible. When everyone can call the same API, the interface is no longer the differentiator.</p><p>The question to ask any AI-forward security vendor (particularly one providing detection or analytic capabilities) isn&#8217;t &#8220;how good is your AI?&#8221; It&#8217;s &#8220;what is your AI actually looking at, and where did the detection logic come from?&#8221; The strongest vendors answer with something genuinely hard to replicate quickly. CrowdStrike&#8217;s detection edge, IMO, derives less from model sophistication than from a threat graph built across hundreds of millions of endpoints over many years. Mandiant&#8217;s value isn&#8217;t their ML pipeline; it&#8217;s institutional knowledge from being in the room at the world&#8217;s most significant breaches. Evaluating either platform on AI capability alone misses the point entirely.</p><p>I think about this in my work at <a href="https://pushsecurity.com/">Push Security</a>, and I&#8217;ll acknowledge I&#8217;m not a neutral observer. We use AI not as the value proposition itself, but as infrastructure that lets our applied research scale. The insights - how identity-based attacks actually work in browser environments, detection logic built from real adversary behavior, where traditional frameworks show their seams - <em>that&#8217;s</em> the work that requires human expertise. AI helps us move it further and faster.</p><p>Consider the difference between a model running against standard network and endpoint telemetry and one with access to browser-session-level data, such as OAuth consent flows, extension behavior, and credential entry context. Attacks like <a href="https://pushsecurity.com/blog/the-most-advanced-clickfix-yet">ClickFix </a>and <a href="https://pushsecurity.com/blog/consentfix">ConsentFix </a>exploit the browser session in ways that leave no trace in endpoint or network logs. If the AI doesn&#8217;t have the right telemetry, the detection logic simply doesn&#8217;t exist, no matter how capable the model is. Sensor placement determines what&#8217;s detectable; AI with the right telemetry determines how well. The detection primitive, not the inference call, is the intellectual property.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!fODt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!fODt!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png 424w, /__u/substackcdn.com/image/fetch/$s_!fODt!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png 848w, /__u/substackcdn.com/image/fetch/$s_!fODt!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png 1272w, /__u/substackcdn.com/image/fetch/$s_!fODt!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!fODt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png" width="1157" height="463" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:463,&quot;width&quot;:1157,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:124072,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!fODt!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png 424w, /__u/substackcdn.com/image/fetch/$s_!fODt!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png 848w, /__u/substackcdn.com/image/fetch/$s_!fODt!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png 1272w, /__u/substackcdn.com/image/fetch/$s_!fODt!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3092e40f-70de-4033-bf38-5e0e3987087e_1157x463.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>My plea to security leaders is this: stop treating AI adoption as a question of which model you&#8217;re running, and apply the same discipline to vendor evaluation. Skip the demo reel. Ask what&#8217;s underneath it. What telemetry does the AI actually see? What research produced the detection logic? What would remain if you swapped out the model entirely? Fortunately, many of the people we heard from in last week&#8217;s forum focused on these questions. But I&#8217;ll be interested to see how AI is positioned in solutions presented at RSAC at the end of the month.</p><p>The model isn&#8217;t the moat. The <em>context </em>is the moat. The <em>detection logic</em> is the moat. The hard-earned research and judgment baked into your detection architecture is the moat. Everything else is infrastructure!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Security Leadership Weekly! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Security Leadership #46: Speed Check]]></title><description><![CDATA[Short-term pessimism, long-term opportunity.]]></description><link>https://markaorlando.substack.com/p/security-leadership-46-speed-check</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-46-speed-check</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 25 Feb 2026 13:32:21 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8a87f37a-ecbd-4154-863b-cc934f409817_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #46 of Security Leadership Weekly! This week's issue arrived fully formed around a single thesis. Before diving in, it's worth reading Phil Venables' piece, linked and summarized below, not because it's the most operationally urgent item here, but because it provides the clearest frame for everything else. Four compounding forces, he argues, are reshaping the threat landscape in ways that demand a fundamentally different posture from defenders. By the time you finish this issue, you'll have read real-world evidence for all four.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong>Short-Term Pessimist, Long-Term Optimist</strong></h3><p>This week, we&#8217;re highlighting a few interesting developments in AI and security, so I thought it might be best to open with some perspective from Phil Venables - former Goldman Sachs CISO, former Google Cloud CISO, and about as credible a voice as you&#8217;ll find in this industry, whose insights I often share here. </p><p>Phil published <a href="https://www.philvenables.com/post/things-are-getting-wild-re-tool-everything-for-speed">a sharp piece this week</a> describing a meaningful shift in his threat outlook: he has moved from an incrementalist to a genuinely alarmed stance. His argument rests on four compounding forces that are bad individually and catastrophic in combination. </p><ol><li><p>A tidal wave of vulnerabilities is coming: AI-augmented engineering means more software will be written, AI dramatically improves vulnerability discovery, and even as model code quality improves, it remains imperfect, meaning the net volume of exploitable flaws will increase substantially. </p></li><li><p>Attackers are industrializing in ways that eliminate the economic friction that historically kept the volume of actual exploitation below the volume of what was theoretically exploitable, and AI is helping to close that gap. </p></li><li><p>Synthetic authenticity collapses: fake candidates, fake workers, fake companies, fake content at scale make it structurally harder to establish trust in any interaction - business, personal, or civic. </p></li><li><p>Maybe most underappreciated out of these is the emergence of trillions of AI agents with imperfect guardrails, which creates a collective behavioral risk that individual agent-level controls can&#8217;t address - a kind of enterprise control plane problem that no one has fully solved yet.</p></li></ol><p>The optimism rests on a structural asymmetry that often gets lost in the doom: defenders control their environment, and attackers (mostly? hopefully?) don&#8217;t. Specificity is a home-field advantage. The prescription is familiar in principle but now urgent in execution: relentless baseline hygiene universally applied (strong authentication, segmentation, fast patching, identity and privilege management, software supply chain controls), continuous control monitoring that roots out recurrence rather than just detecting failures, and aggressive adoption of AI on the defensive side before attackers fully operationalize it. His bottom line is stark: the only fundamental defense is speed, and the window to institutionalize that speed advantage is now.</p><div><hr></div><h3><strong>2026 Dragos OT Cybersecurity Year in Review</strong></h3><p>Dragos released its <a href="https://www.dragos.com/ot-cybersecurity-year-in-review">9th Annual OT Cybersecurity Year in Review</a> this week, and the headline finding is a visibility crisis that makes everything else worse: only 30% of OT networks have sufficient visibility, 56% cannot see below the IT/OT boundary, and 88% struggle with detection and response - meaning most organizations only discover a compromise after something in the physical process behaves abnormally, long after adversaries have done their work. </p><p>The threat landscape accelerated in 2025 on every dimension: Dragos now tracks 26 OT-focused threat groups, three of which are newly identified, and established groups expanded their geographic reach while progressing further through the ICS Cyber Kill Chain. Ransomware hit 3,300 industrial organizations during the year, driving operational disruptions across critical sectors, and only 4% of disclosed vulnerabilities were actively exploited; a number that sounds reassuring until you consider that exploitation is happening faster than patching cycles can accommodate. For security leaders with OT responsibility, the report is a useful annual benchmark and available for download at dragos.com.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><p>GitLab's threat intelligence team published <a href="https://about.gitlab.com/blog/gitlab-threat-intelligence-reveals-north-korean-tradecraft/">a detailed expos&#233;</a> of North Korean &#8220;Contagious Interview&#8221; and IT worker operations that used GitLab.com as infrastructure in 2025, and what makes it unusually valuable is the visibility GitLab had into the actual private repositories these threat actors created. </p><ul><li><p><strong>The malware side</strong>: GitLab banned 131 accounts in 2025, distributing JavaScript-based malware (primarily BeaverTail and OtterCookie) disguised as legitimate developer interview projects, targeting developers in crypto, finance, and real estate.</p></li><li><p><strong>The IT worker side</strong> is where it gets really cinematic: GitLab found financial records for a named North Korean national managing an eight-person cell operating out of Beijing under academic cover, documenting $1.64 million in earnings between 2022 and 2025 against a target of $1.88 million, with quarterly performance reviews, personnel dossiers on each member including passport copies, and even notes on who did the laundry </p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!nKTB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!nKTB!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png 424w, /__u/substackcdn.com/image/fetch/$s_!nKTB!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png 848w, /__u/substackcdn.com/image/fetch/$s_!nKTB!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nKTB!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!nKTB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png" width="504" height="283.88321167883214" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:463,&quot;width&quot;:822,&quot;resizeWidth&quot;:504,&quot;bytes&quot;:301941,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/189024483?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!nKTB!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png 424w, /__u/substackcdn.com/image/fetch/$s_!nKTB!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png 848w, /__u/substackcdn.com/image/fetch/$s_!nKTB!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png 1272w, /__u/substackcdn.com/image/fetch/$s_!nKTB!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3228df7d-59da-4cb4-a7a8-a1434863e268_822x463.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Other case studies detail a synthetic identity pipeline that generated at least 135 fake personas with automated account creation and professional network building; an operator running 21 personas with Photoshopped U.S. identity documents, including driver's licenses and passports; and a North Korean worker operating from central Moscow. The full report includes 600+ IOCs and is required reading for any organization that hires software contractors or runs a developer platform.</p><div><hr></div><h3><strong>Nation-State Hackers Are Using Your AI Tools Against You</strong></h3><p>Google&#8217;s Threat Intelligence Group just published <a href="https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-use">their Q4 2025 AI threat tracker</a>, which confirms what most of us might guess: APT actors from China, Iran, North Korea, and Russia have fully operationalized commercial AI tools - including Gemini -across every stage of the attack lifecycle. APT42 is using Gemini to craft hyper-personalized phishing lures and build rapport with targets through believable multi-turn conversations. APT31 is prompting Gemini, using a security researcher persona, to automate vulnerability analysis against specific U.S. targets. North Korea&#8217;s UNC2970 is using it to profile defense-sector targets and to generate high-fidelity recruiter impersonation campaigns. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!5X9-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!5X9-!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!5X9-!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!5X9-!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!5X9-!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!5X9-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg" width="599" height="239.02403846153845" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:581,&quot;width&quot;:1456,&quot;resizeWidth&quot;:599,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;https://storage.googleapis.com/gweb-cloudblog-publish/images/gtig-ai-threat-tracker-feb26-fig1.max-1500x1500.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/gtig-ai-threat-tracker-feb26-fig1.max-1500x1500.jpg" title="https://storage.googleapis.com/gweb-cloudblog-publish/images/gtig-ai-threat-tracker-feb26-fig1.max-1500x1500.jpg" srcset="/__u/substackcdn.com/image/fetch/$s_!5X9-!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!5X9-!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!5X9-!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!5X9-!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17f4abb3-94d3-4559-bc08-87f1b63057d2_1500x599.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The report also details two interesting new malware families: HONESTCUE, a downloader that calls the Gemini API in real-time to generate and execute its second-stage payload entirely in memory (leaving <strong>no artifacts on disk</strong>), and COINBAIT, an AI-generated phishing kit targeting crypto exchange credentials that was almost certainly built with tools like Lovable AI.</p><p>The important thing here isn&#8217;t the sophistication, it&#8217;s the democratization - no net-new capabilities here, but faster scaling. The floor for executing a credible, personalized, multi-stage attack has dropped significantly. It&#8217;s going to be increasingly hard to train your way out of spotting these campaigns moving forward. </p><div><hr></div><h3><strong>Anthropic Launches Claude Code</strong></h3><p>Anthropic launched <a href="https://www.anthropic.com/news/claude-code-security">Claude Code Security</a> last Friday - an AI-powered vulnerability scanner built into Claude Code that scans codebases, identifies security flaws traditional static analysis tools miss, and suggests targeted patches for human review. The capability is currently in limited research preview for Enterprise and Team customers, with free expedited access extended to open-source maintainers. A multi-stage verification process filters false positives, severity ratings help teams prioritize, and the system is explicitly human-in-the-loop: Claude identifies and recommends, but a developer approves every patch before anything changes.</p><div id="youtube2-sDpkV_iEnck" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;sDpkV_iEnck&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/sDpkV_iEnck?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The market reaction was immediate: CrowdStrike fell roughly 8-12%, Zscaler dropped 11%, Okta shed 9%, JFrog cratered 25%, and the Global X Cybersecurity ETF hit its lowest close since November 2023. Analysts at Wedbush, Barclays, and Jefferies all <a href="https://www.proactiveinvestors.com/companies/news/1087792/anthropic-s-claude-code-security-launch-rattles-cybersecurity-stocks-wedbush-sees-selloff-as-overreaction-1087792.html">pushed back on the panic</a>, calling it an overreaction driven by &#8220;AI ghost trade&#8221; fears rather than competitive reality  - pointing out that Claude Code Security targets static analysis and AppSec tooling, not endpoint detection, identity management, or the runtime security capabilities that underpin CrowdStrike&#8217;s or Zscaler&#8217;s core businesses. </p><p>This is nothing more than a signal that AI-native security tooling is becoming a standard layer in the software development lifecycle, rather than a wholesale replacement for the security platform market. That said, the structural threat to pure-play code-scanning vendors is real, the competitive pressure on AppSec budgets is real, and the broader question of whether AI platform providers will continue to bundle security capabilities into developer products is one every security leader and their CIO/CTO should be thinking about right now.</p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>The False Measurement of Puzzle Questions in Interviews</strong></h3><p>Fast Company <a href="https://www.fastcompany.com/91492306/employers-love-tricky-job-interview-questions-but-theyre-actually-useless">ran a piece this week</a> surfacing decades of industrial-organizational psychology research that proves tricky, brainteaser-style interview questions have low predictive validity. Questions like &#8220;how many tennis balls fit in a Boeing 747?&#8221; or abstract scenario puzzles don&#8217;t reliably measure problem-solving ability, cultural fit, or performance under pressure  - ostensibly the things interviewers believe they&#8217;re measuring (I personally once got &#8220;how many gas stations are there in the US?&#8221;). At best, they measure comfort with improvisation and prior exposure to similar puzzles. At worst, they measure how similar the candidate is to the interviewer. Research on who chooses to use brainteaser questions in the first place found that those interviewers were more likely to be socially inept, narcissistic, and overconfident in their intuitive judgment (ouch!). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!cq6O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!cq6O!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png 424w, /__u/substackcdn.com/image/fetch/$s_!cq6O!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png 848w, /__u/substackcdn.com/image/fetch/$s_!cq6O!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cq6O!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!cq6O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png" width="380" height="319.86531986531986" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:594,&quot;resizeWidth&quot;:380,&quot;bytes&quot;:28487,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/189024483?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!cq6O!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png 424w, /__u/substackcdn.com/image/fetch/$s_!cq6O!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png 848w, /__u/substackcdn.com/image/fetch/$s_!cq6O!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cq6O!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5dfdc475-773f-4486-ba7d-9eff5b7b6db3_594x500.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I was happy to see this research highlighted, as we&#8217;ve included it in <a href="https://www.sans.org/cyber-security-courses/building-leading-security-operations-centers">LDR551 </a>for years.  If your interview process is built around war stories, hypothetical puzzles, or &#8220;what would you do if...&#8221; scenarios that aren&#8217;t grounded in actual job requirements, you&#8217;re likely filtering out great candidates who don&#8217;t perform well under artificial pressure and selecting for candidates who are good at interviews, not the job. The research-backed alternative is <em><strong>structured behavioral interviewing</strong></em>: consistent, job-relevant questions asked the same way across all candidates, scored against defined criteria. It&#8217;s less exciting than asking someone how they&#8217;d defend against a nation-state attacker with a whiteboard, but it&#8217;s measurably better at predicting who will actually perform.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>Venables wrote his piece as a framework, but this week's news reads like Exhibit A through D. Google's GTIG report is the "attackers industrializing" pillar made concrete; nation-states running commercial AI across the full kill chain, collapsing the cost of credible, personalized attacks to near zero. </p><p>The GitLab North Korea expos&#233; is the "everything can be faked" pillar, with receipts: 135 synthetic identities, 21 Photoshopped passports, and a full-time employee inside a U.S. tech agency whose real location was central Moscow. </p><p>The Dragos OT report illustrates what happens when the tidal wave of exploitable exposure meets organizations that can't see below their own IT/OT boundary. And Claude Code Security, regardless of what the market thought it meant for incumbent vendors, is a data point for the defensive side of Venables' argument: AI finding vulnerabilities at scale before attackers do. </p><p>Operating tempo is everything here. Defenders who move <em>now</em> - on speed, on baseline hygiene, on AI adoption - will have a structural advantage that compounds. Time to revisit team capacity and efficiency!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Security Leadership #45: Features, Not Vulnerabilities]]></title><description><![CDATA[Your attack surface is working correctly.]]></description><link>https://markaorlando.substack.com/p/security-leadership-45-features-not</link><guid isPermaLink="false">https://markaorlando.substack.com/p/security-leadership-45-features-not</guid><dc:creator><![CDATA[Mark Orlando]]></dc:creator><pubDate>Wed, 18 Feb 2026 13:26:13 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/ca486324-256c-4aef-971e-7a495a440efe_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Issue #45 of Security Leadership Weekly! The stories in this week's issue share something that should make security leaders uncomfortable: almost none of them involve a vulnerability. No CVEs, no zero-days, no unpatched systems. Chrome extensions leaked 37 million users' browsing history through permissions users <em>willingly granted</em>. ClickFix campaigns delivered malware via DNS lookups, AI chatbot sharing features, and search ads that pointed to legitimate platform domains - all operating as intended. When the UK's Cyber Essentials scheme mandates MFA for every cloud service, it&#8217;s because the authentication gaps attackers have been exploiting for years were never bugs; they were product decisions. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>&#128737;&#65039;Tactical Challenges</strong></h2><h3><strong><a href="https://www.securityweek.com/over-300-malicious-chrome-extensions-caught-leaking-or-stealing-user-data/">The Browser Extension Crisis Hits Critical Mass</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!0BiS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!0BiS!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!0BiS!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!0BiS!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0BiS!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!0BiS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png" width="473" height="315.4416208791209" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/262701bb-af50-4531-be33-ac1120524dee_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:473,&quot;bytes&quot;:2260417,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/188211322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!0BiS!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png 424w, /__u/substackcdn.com/image/fetch/$s_!0BiS!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png 848w, /__u/substackcdn.com/image/fetch/$s_!0BiS!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png 1272w, /__u/substackcdn.com/image/fetch/$s_!0BiS!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F262701bb-af50-4531-be33-ac1120524dee_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Security researcher <a href="https://github.com/qcontinuum1/spying-extensions/blob/main/report.pdf">Q Continuum has uncovered 287 Chrome extensions</a> with over 37.4 million users that are actively transmitting browsing history and search engine results pages (SERP) to external servers. The research, which analyzed network traffic generated by Chrome extensions, found that roughly 27.2 million users had installed 153 extensions confirmed to leak browser history immediately upon installation - meaning the data exposure begins the moment someone clicks &#8220;Add to Chrome.&#8221; </p><p>Some extensions leak this data by exposing it to unsecured networks, while others deliberately transmit it to collection servers, either due to intended functionality, monetization strategies, or explicitly malicious intent. Q Continuum flagged over 200 additional extensions as suspicious due to shared author details with confirmed data-leaking extensions and observed four scrapers connecting to a honeypot set up for the research, demonstrating <strong>active reconnaissance</strong> by threat actors targeting these compromised user bases. The scale of this campaign positions browser extensions alongside supply chain compromises and identity attacks as a tier-one threat vector.</p><p>If you&#8217;re a defender who isn&#8217;t actively focused on curbing malicious extensions, you&#8217;re behind the power curve. Browsers are now the primary workspace, and extension governance is an identity and data protection problem masquerading as a user productivity issue. The 27.2 million users affected by confirmed-malicious extensions represent a conservative floor; Q Continuum&#8217;s identification of 200+ additional suspicious extensions with shared infrastructure suggests the actual exposure is significantly larger. </p><div><hr></div><h3><strong>Google Maps the Defense Industrial Base Threat Landscape</strong></h3><p>Google Threat Intelligence Group published <a href="https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense-industrial-base">a comprehensive analysis of threats targeting the defense industrial base</a>, revealing that China-nexus cyber espionage actors represent the highest volume of activity against defense and aerospace entities over the past two years - more than any other state-sponsored threat. The analysis documents China-nexus groups exploiting more than two dozen zero-day vulnerabilities in edge devices (VPNs, routers, firewalls, security appliances) since 2020 across ten vendors, with groups such as UNC3886 and UNC5221 demonstrating extensive efforts to obfuscate activity and maintain long-term access in environments that lack EDR monitoring. The BRICKSTORM campaign attributed to UNC5221 achieved an average dwell time of 393 days across aerospace, defense, and MSP targets by compromising perimeter devices to bypass traditional endpoint detection entirely. Meanwhile, Russian operations targeting Ukraine have shifted from network-centric intrusions to individual-focused campaigns exploiting Signal, Telegram, and battlefield management apps like Delta and Kropyva - often through physical device access, mobile malware, or social engineering that happens completely outside enterprise visibility.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!cCqY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!cCqY!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png 424w, /__u/substackcdn.com/image/fetch/$s_!cCqY!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png 848w, /__u/substackcdn.com/image/fetch/$s_!cCqY!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cCqY!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!cCqY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png" width="432" height="477.6923076923077" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1610,&quot;width&quot;:1456,&quot;resizeWidth&quot;:432,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;https://storage.googleapis.com/gweb-cloudblog-publish/images/dib-threats-fig3-white.max-2200x2200.png&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/dib-threats-fig3-white.max-2200x2200.png" title="https://storage.googleapis.com/gweb-cloudblog-publish/images/dib-threats-fig3-white.max-2200x2200.png" srcset="/__u/substackcdn.com/image/fetch/$s_!cCqY!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png 424w, /__u/substackcdn.com/image/fetch/$s_!cCqY!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png 848w, /__u/substackcdn.com/image/fetch/$s_!cCqY!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png 1272w, /__u/substackcdn.com/image/fetch/$s_!cCqY!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9df90d5e-7549-4c4f-bfe0-3a12ea384235_1990x2200.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The most significant finding is the wholesale migration of initial access from traditional attack surfaces to <strong>areas where enterprise security has limited or no visibility</strong>. North Korean IT workers successfully infiltrated over 100 US companies, including defense contractors developing AI technology, using laptop farms and stolen identities to gain employment and exfiltrate sensitive data while appearing as legitimate remote workers. Iranian groups UNC1549 and UNC6446 created fake job portals and resume-builder applications for aerospace firms, while China-nexus APT5 meticulously crafted spearphishing campaigns against defense contractor employees&#8217; personal email addresses using hyper-localized lures referencing specific universities, Boy Scout troops, and community events near their homes. </p><p>In short, your enterprise security stack is defending yesterday&#8217;s attack surface while adversaries are compromising personal devices and identity, exploiting hiring processes, and persisting in edge and cloud infrastructure that your EDR can&#8217;t see.</p><div><hr></div><h3><strong>Palo Alto Global Incident Response Report 2026</strong></h3><p>Unit 42 just published its <a href="https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report">Global Incident Response Report</a>, based on its incident response work on more than 500 major cases across 38 countries. Lots to unpack here! The report identifies five dominant trends reshaping the threat landscape: </p><ol><li><p>The evolution of extortion into intentional operational disruption (86% of incidents involved some form of business disruption), </p></li><li><p>Growing cloud and software supply chain attacks (29% of cases involved cloud environments, with attackers scanning over 230 million unique targets in a single campaign), </p></li><li><p>Dramatically accelerating attack timelines (in 19% of cases, data was exfiltrated within one hour of compromise, three times faster than 2021)</p></li><li><p>A tripling of North Korean IT worker insider threat cases as state-sponsored operatives embed in contract technical roles using KVM-over-IP hardware to evade endpoint monitoring</p></li><li><p>The early emergence of AI-assisted attacks, as Unit 42&#8217;s simulations show, is compressing the time from compromise to exfiltration from a two-day median to 25 minutes. </p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!XR4Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!XR4Q!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png 424w, /__u/substackcdn.com/image/fetch/$s_!XR4Q!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png 848w, /__u/substackcdn.com/image/fetch/$s_!XR4Q!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png 1272w, /__u/substackcdn.com/image/fetch/$s_!XR4Q!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!XR4Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png" width="539" height="338.89625" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:503,&quot;width&quot;:800,&quot;resizeWidth&quot;:539,&quot;bytes&quot;:26934,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://markaorlando.substack.com/i/188211322?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!XR4Q!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png 424w, /__u/substackcdn.com/image/fetch/$s_!XR4Q!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png 848w, /__u/substackcdn.com/image/fetch/$s_!XR4Q!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png 1272w, /__u/substackcdn.com/image/fetch/$s_!XR4Q!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3079dbb-f09d-45f7-bff7-596f378f135f_800x503.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Three enablers allow attackers to succeed repeatedly: </p><ul><li><p>Security complexity (in 75% of incidents, evidence of the initial intrusion was present in logs but not operationalized), </p></li><li><p>Gaps in visibility (organizations spin up 300 new cloud services per month on average, and security tool issues contributed to nearly 40% of cases)</p></li><li><p>Excessive trust (41% of incidents had at least one identity and access management contributing factor, with IAM issues appearing in nearly half of cloud-related incidents). </p></li></ul><p><strong>Browser-based activity accounted for 44% of all incidents. </strong>The human layer, the browser, and identity remain the most consistently exploited attack surfaces across every sector, and defenders are<strong> </strong>losing the race between attacker speed and detection capability.</p><div><hr></div><h2><strong>&#129302; Emerging Threats</strong></h2><h3><strong>Claude Artifacts Weaponized for Mac Infostealer Delivery</strong></h3><p>Via <a href="https://www.bleepingcomputer.com/news/security/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack/">Bill Toulas at BleepingComputer</a>: Threat actors are exploiting Claude&#8217;s public artifact feature and Google Ads to deliver MacSync infostealer to macOS users via ClickFix campaigns targeting common search queries such as &#8220;online DNS resolver,&#8221; &#8220;macOS CLI disk space analyzer,&#8221; and &#8220;HomeBrew.&#8221; In a lengthy X thread, researchers at Moonlock Lab and AdGuard described at least two attack variants, with one malicious Claude artifact accumulating more than <strong>15,600 views</strong> before being flagged. </p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/moonlock_lab/status/2021695650367226108&quot;,&quot;full_text&quot;:&quot;&#129525; 1/ &#128680; What if a Google Sponsored result for a common macOS query led to malware? That's happening right now and 15K+ people have already seen it.\nWe at @MoonlockLab observed 2 variants today abusing legitimate platforms for ClickFix delivery: a <span class=\&quot;tweet-fake-link\&quot;>@AnthropicAI</span> public artifact on &quot;,&quot;username&quot;:&quot;moonlock_lab&quot;,&quot;name&quot;:&quot;Moonlock Lab&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1982814058572099584/JAmkrrnz_normal.jpg&quot;,&quot;date&quot;:&quot;2026-02-11T21:19:38.000Z&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/HA57gJEXkAATg5q.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/e1ocnQPmV4&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:3,&quot;retweet_count&quot;:15,&quot;like_count&quot;:52,&quot;impression_count&quot;:5102,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;video_preview_media_key&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>The attacks use either public Claude artifacts or fake Medium articles impersonating Apple Support, both instructing victims to paste shell commands into Terminal that execute base64-encoded payloads or run curl commands to fetch malware loaders from the attacker&#8217;s infrastructure. Once executed, MacSync deploys with root-level privileges, exfiltrating cryptocurrency wallets, browser credentials, Keychain data, and filesystem contents through encrypted connections to command-and-control servers that spoof legitimate macOS browser traffic. The campaign specifically targets domain-joined systems, indicating deliberate focus on enterprise environments rather than home users.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!lyUv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!lyUv!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!lyUv!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!lyUv!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!lyUv!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!lyUv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg" width="541" height="400.77851083883127" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:786,&quot;width&quot;:1061,&quot;resizeWidth&quot;:541,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Malicious HomeBrew search results&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Malicious HomeBrew search results" title="Malicious HomeBrew search results" srcset="/__u/substackcdn.com/image/fetch/$s_!lyUv!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!lyUv!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!lyUv!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!lyUv!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda18e392-c69b-4435-957a-2ccc355bc805_1061x786.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the third major LLM platform to be weaponized in ClickFix campaigns, following <a href="https://www.huntress.com/blog/amos-stealer-chatgpt-grok-ai-trust">similar attacks using ChatGPT and Grok&#8217;s shared conversation features in December 2025</a> that delivered AMOS infostealer to Mac users. The pattern is fairly consistent: attackers engineer prompts that force LLMs to generate malicious instructions, publish them through legitimate platform sharing features, then use SEO poisoning and paid ads to surface these conversations as top search results for troubleshooting queries. Users implicitly trust Google search results, AI platform domains (claude.ai, chatgpt.com, grok.com), AI-generated technical guidance, and routinely copy-paste Terminal commands from trusted sources like Stack Overflow and Reddit. Every layer of this attack abuses behaviors that security teams have actively encouraged: using official documentation, consulting AI assistants for technical problems, and following step-by-step troubleshooting guides. </p><div><hr></div><h3><strong>ClickFix Evolves Again</strong></h3><p>Microsoft <a href="https://x.com/MsftSecIntel/status/2022456612120629742">disclosed a new ClickFix variant</a> that weaponizes DNS lookups to stage malware, moving beyond web-based delivery by instructing victims to execute nslookup commands through the Windows Run dialog that query attacker-controlled DNS servers for next-stage payloads. The technique filters DNS response output to extract and execute embedded commands, using DNS as a &#8220;lightweight staging or signaling channel&#8221; that blends malicious activity into normal network traffic while adding a validation layer before payload execution. The attack chain downloads a Python script that conducts reconnaissance and deploys ModeloRAT, a Python-based remote access trojan previously distributed through <a href="https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke">the CrashFix browser extension campaign</a>, with persistence established via Windows Startup folder LNK files. </p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/MsftSecIntel/status/2022456612120629742&quot;,&quot;full_text&quot;:&quot;Microsoft Defender researchers observed attackers using yet another evasion approach to the ClickFix technique: Asking targets to run a command that executes a custom DNS lookup and parses the `Name:` response to receive the next-stage payload for execution. &quot;,&quot;username&quot;:&quot;MsftSecIntel&quot;,&quot;name&quot;:&quot;Microsoft Threat Intelligence&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1268200269277351936/a2naHzbe_normal.png&quot;,&quot;date&quot;:&quot;2026-02-13T23:43:26.000Z&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/HBE1kh4WYAAjaUh.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/NFbv1DJsXn&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:16,&quot;retweet_count&quot;:230,&quot;like_count&quot;:953,&quot;impression_count&quot;:147117,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;video_preview_media_key&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>Bitdefender <a href="https://www.bitdefender.com/en-us/blog/labs/lummastealer-second-life-castleloader">separately reported a surge in Lumma Stealer</a> activity, driven by ClickFix-style fake CAPTCHA campaigns that deploy CastleLoader, an AutoIt-based loader that checks for virtualization software and security products before decrypting the stealer in memory. Infections were concentrated in India, France, the US, Spain, and Germany.</p><p>The DNS-based staging variant represents <a href="https://pushsecurity.com/blog/the-most-advanced-clickfix-yet/">the continued industrialization of ClickFix</a> as a delivery mechanism that now spans multiple protocols and platforms, from traditional PowerShell execution to browser crashes, fake software updates, AI chatbot instructions on Claude and ChatGPT, and now DNS lookups that security monitoring treats as benign infrastructure traffic. </p><p>The broader ecosystem shows ClickFix enabling delivery of at least seven major stealer families (Lumma, AMOS/Odyssey, MacSync, StealC, Stealerium, and others) through campaigns targeting cryptocurrency wallets, browser credentials, and authentication tokens, with macOS increasingly targeted despite the persistent &#8220;Macs don&#8217;t get viruses&#8221; assumption that remains actively dangerous in enterprise environments. </p><div><hr></div><h2><strong>&#128100; People and Processes</strong></h2><h3><strong>UK Cyber Essentials Closes the MFA Gap</strong></h3><p>Via the <a href="https://pushsecurity.com/blog/cyber-essentials-april-2026-update/">Push Security blog</a>: The UK&#8217;s Cyber Essentials scheme is implementing significant changes in April 2026 that redefine the scope of cloud services and mandate MFA enforcement across all business accounts, fundamentally changing how organizations validate compliance. The <a href="https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf">updated requirements</a> from NCSC and IASME expand &#8220;cloud services&#8221; to mean any service accessed via a business email or account - regardless of subscription tier or cost - and require MFA to be enabled for all users on every service that offers it, including apps that only provide MFA as a paid add-on or higher tier feature. </p><p>If a service lacks native MFA but supports authentication via a provider that offers MFA (e.g., &#8220;Sign in with Microsoft&#8221;), organizations must use only that federated method. This means <strong>shadow apps discovered during audits constitute automatic compliance failures</strong>, with auditors now interviewing employees and asking them to demonstrate logging into various apps to validate MFA status and overall authentication posture.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!SN-x!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!SN-x!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png 424w, /__u/substackcdn.com/image/fetch/$s_!SN-x!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png 848w, /__u/substackcdn.com/image/fetch/$s_!SN-x!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SN-x!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_webp, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!SN-x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png" width="544" height="243.3452188006483" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:552,&quot;width&quot;:1234,&quot;resizeWidth&quot;:544,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Third-party requirements.&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Third-party requirements." title="Third-party requirements." srcset="/__u/substackcdn.com/image/fetch/$s_!SN-x!, /__u/markaorlando.substack.com/w_424, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png 424w, /__u/substackcdn.com/image/fetch/$s_!SN-x!, /__u/markaorlando.substack.com/w_848, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png 848w, /__u/substackcdn.com/image/fetch/$s_!SN-x!, /__u/markaorlando.substack.com/w_1272, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png 1272w, /__u/substackcdn.com/image/fetch/$s_!SN-x!, /__u/markaorlando.substack.com/w_1456, /__u/markaorlando.substack.com/c_limit, /__u/markaorlando.substack.com/f_auto, /__u/markaorlando.substack.com/q_auto:good, /__u/markaorlando.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd35675a6-fb9c-4751-b35b-cb06f32ba617_1234x552.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The regulatory shift addresses a gap between assumed and actual security coverage, which has enabled recent high-impact breaches targeting accounts without MFA. The <a href="https://en.wikipedia.org/wiki/Snowflake_data_breach">2024 Snowflake incident</a> compromised 165+ tenants and billions of records, leveraging credentials leaked online as early as 2020, with over 80% of breached accounts lacking MFA.  Organizations that assume all apps are accessed via SSO discover that apps are routinely self-adopted by users, vendor support for centrally enforced MFA is inconsistent, and apps that require paid upgrades for security features are prevalent, creating an authentication landscape in which many accounts lack MFA despite policy requirements to the contrary. Nice to see regulations catching up to reality.</p><div><hr></div><h2>&#128161;<strong>Connecting the Dots</strong></h2><p>The throughline this week is that your vendor's feature roadmap is also your attack surface, and traditional security controls built to detect exploitation of <em>broken</em> things provide almost no signal when adversaries are exploiting things that <em>work</em>. Unit 42 found that in 75% of incidents, evidence of compromise was sitting in logs that nobody operationalized. The question worth asking in your next architecture review isn't "what are we missing that's broken?" but "which of our vendors' intended features would we never detect being abused?"</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://markaorlando.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="/__u/markaorlando.substack.com/subscribe"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item></channel></rss>