<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Defender's Initiative]]></title><description><![CDATA[Trying to make sense of the crazy cybersecurity market, and helping defenders separate the stuff that works from the stuff that doesn't.]]></description><link>https://www.defendersinitiative.com</link><image><url>https://substackcdn.com/image/fetch/$s_!rsmo!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png</url><title>The Defender&apos;s Initiative</title><link>https://www.defendersinitiative.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 18 Jun 2026 08:52:55 GMT</lastBuildDate><atom:link href="https://www.defendersinitiative.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Adrian Sanabria]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[defendersinitiative@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[defendersinitiative@substack.com]]></itunes:email><itunes:name><![CDATA[Adrian Sanabria]]></itunes:name></itunes:owner><itunes:author><![CDATA[Adrian Sanabria]]></itunes:author><googleplay:owner><![CDATA[defendersinitiative@substack.com]]></googleplay:owner><googleplay:email><![CDATA[defendersinitiative@substack.com]]></googleplay:email><googleplay:author><![CDATA[Adrian Sanabria]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Defining Zero-Day]]></title><description><![CDATA[As we get flooded with vulnerabilities, we need better defined terms]]></description><link>https://www.defendersinitiative.com/p/defining-zero-day</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/defining-zero-day</guid><pubDate>Mon, 08 Jun 2026 12:27:29 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The term zero-day is ubiquitous in cybersecurity. Yet, like many of our terms, it means different things to different people. This can be problematic - the more our terms lack common meaning, the more we risk miscommunication<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</p><p>Anthropic&#8217;s Mythos has brought discussions of vulnerabilities to the forefront of cybersecurity discussions and into mainstream conversations, making this an opportune time to discuss and clarify terms like <em>zero-day</em>.</p><p>A zero-day is, first and foremost, <a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review">a case of information asymmetry</a>. An adversary knows something its target does not. When it is more broadly discovered that an unknown vulnerability has been used against targets, it is said to be a &#8216;zero-day&#8217;, because it has been zero days since it was discovered.</p><h1>Definitions</h1><p>Here&#8217;s what I came up with after reviewing over a dozen definitions from a wide variety of sources<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. There were more disagreements than agreements.</p><ul><li><p>A <strong>software bug</strong> is a defect in software<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>.</p></li><li><p>A <strong>software vulnerability</strong> is an exploitable software bug that could cause harm if exploited by adversaries.</p></li><li><p>A <strong>zero-day</strong> is a vulnerability in software or systems that is unknown to defenders.</p></li></ul><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you want to be notified in the future of other hills Adrian is willing to die on, make sure you get subscribed!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="5184" height="3456" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3456,&quot;width&quot;:5184,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;mountain covered with green grass&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="mountain covered with green grass" title="mountain covered with green grass" srcset="https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1438786657495-640937046d18?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHxoaWxsc3xlbnwwfHx8fDE3NzY5Mjk5NTd8MA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Gorgeous. These look worth dying on. Photo by <a href="https://unsplash.com/@claudelrheault">Claudel Rheault</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><h1>Why is this important?</h1><p>The term zero-day should evoke a need for immediate action. This urgency is lost if we apply this term to every newly discovered vulnerability.</p><p>Anthropic, <a href="https://red.anthropic.com/2026/mythos-preview/">in its announcement of Mythos</a>, defined zero-day vulnerabilities as:</p><blockquote><p>&#8220;bugs that were not previously known to exist.&#8221;</p></blockquote><p>A phrase I often find myself saying when discussing vulnerability management is, &#8220;if everything is critical, nothing is critical.&#8221; The need for prioritizing vulnerabilities grows as the rate of vulnerability discovery goes up. When a vendor discovers vulnerabilities and makes them the focal point of a marketing campaign, it&#8217;s no surprise when their importance is over-inflated.</p><p>The other reason it was important to draw attention to the definition of zero day was the lack of consensus in the industry.</p><p>After pulling dozens of definitions, I found that many definitions hinged on whether or not a patch was available. This moves the definition of the &#8220;zero&#8221; in zero-day from information asymmetry to patch availability. This didn&#8217;t make sense, as a patch is just one way to mitigate attacks against a vulnerability.</p><p>Since we&#8217;re living in a time where it&#8217;s often not possible to patch a vulnerability before exploitation begins, it&#8217;s important for folks to know that they have other options to prevent exploitation. In 2026, no one should be waiting on a patch to address a zero day. </p><h1>When does a zero day stop being a zero day?</h1><p>A zero-day vulnerability ceases to be a zero-day when defenders gain enough knowledge to mitigate the vulnerability.</p><h1>Conclusion</h1><p>As the rate of vulnerability discovery increases, it is more important than ever to identify truly dangerous vulnerabilities. The term zero-day should be reserved for vulnerabilities that demand immediate focus and response. Kim Zetter&#8217;s hall-of-fame book on Stuxnet is titled <em><a href="https://cybercanon.org/countdown-to-zero-day-stuxnet-and-the-launch-of-the-worlds-first-digital-weapon/">Countdown to Zero Day</a></em> because zero-day vulnerabilities are dangerous. At the time, it was unheard of for a piece of malware to use multiple zero-day vulnerabilities<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>.</p><p>AI companies are now <a href="https://www.anthropic.com/product/security">security</a> <a href="https://developers.openai.com/codex/security">companies</a>. The same caution we take with security vendor hyperbole now needs to be applied to security claims from OpenAI and Anthropic as both struggle to justify their lofty valuations. It clearly benefits foundation AI companies to lock software companies into an endless cycle of AI generated code, AI-driven scans, and AI-generated fixes. On that topic, I have another post:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;f7b5d493-8a56-41cf-aeb2-e988c70464bc&quot;,&quot;caption&quot;:&quot;I originally thought that Anthropic&#8217;s Mythos was just a marketing campaign. I now think it&#8217;s more than that: it&#8217;s a lead funnel. If there&#8217;s a tool that can find thousands of software bugs quickly (for a price), how could we possibly fix all these bugs in a reasonable time frame? More AI, of course (for a price).&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The unintended consequences of vulnmaxxing&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:11988704,&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;bio&quot;:&quot;Always trying to see the big picture, figure out the best strategy, and uncover BS in Cybersecurity. I still see the glass as half-full.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a89717e5-a927-4084-ad86-69068727dbf3_1632x1632.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-06-02T15:00:20.241Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!scPK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.defendersinitiative.com/p/the-unintended-consequences-of-vulnmaxxing&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:199381536,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:3,&quot;publication_id&quot;:3676751,&quot;publication_name&quot;:&quot;The Defender's Initiative&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rsmo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Consider subscribing, perhaps at a paid level, so I can devote more time to essays like this one!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>This is my fancy way of saying people on the Internet are using the term zero-day wrong.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Wikipedia, Kim Zetter, Symantec (historical), IBM, Fortinet, Splunk, Crowdstrike, HPE, Safe Security, Universities, SANS, NIST, Google Project Zero, Google Mandiant</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p><a href="https://en.wikipedia.org/wiki/Software_bug">https://en.wikipedia.org/wiki/Software_bug</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Stuxnet <a href="https://css.csail.mit.edu/6.566/2018/readings/stuxnet.pdf">contained four</a> zero-day exploits.</p></div></div>]]></content:encoded></item><item><title><![CDATA[The unintended consequences of vulnmaxxing]]></title><description><![CDATA[The only way to fix vulns at AI scale is to use AI. Coincidence or cash grab?]]></description><link>https://www.defendersinitiative.com/p/the-unintended-consequences-of-vulnmaxxing</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/the-unintended-consequences-of-vulnmaxxing</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Tue, 02 Jun 2026 15:00:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!scPK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I originally thought that Anthropic&#8217;s <a href="https://red.anthropic.com/2026/mythos-preview/">Mythos</a> was just a marketing campaign. I now think it&#8217;s more than that: it&#8217;s a <em>lead funnel</em>. If there&#8217;s a tool that can find thousands of software bugs quickly (for a price), how could we possibly fix all these bugs in a reasonable time frame? More AI, of course (for a price).</p><p>That price is not cheap, and I fear that one of the unintended consequences will be a shift in the security poverty line. The 1% of companies with the largest engineering budgets will be able to afford a Mythos-level makeover. Does everyone else become low-hanging fruit for attackers to pick off at their leisure?</p><p>Off the top of my head, here are a few of my vulnmaxxing concerns:</p><ol><li><p>Makes an already impossible problem (fixing everything) worse for teams trying to triage vulnerabilities and fix them</p></li><li><p>Convinces security teams that they need the most expensive model to find and fix vulns</p></li><li><p>Moves the security poverty line upward for teams that don&#8217;t know how to build harnesses to find and fix vulns and don&#8217;t have significant token budgets</p></li><li><p>Pointless cash burn, as the majority of vulnerabilities being discovered will have no value to attackers and therefore have no value to defenders (<a href="https://www.cyentia.com/publication/prioritization-to-prediction-vol-1/">98%+ of all vulnerabilities are of low-to-no concern</a>, those discovered by AI seem to align to this trend)</p></li><li><p>Chilling effect on open source, code repositories are already going private to try to survive the vulnpocalypse through obscurity</p></li><li><p>We&#8217;ve never patched this much, this fast</p></li><li><p>We&#8217;ve never injected this most AI-written code of unknown quality this fast</p></li><li><p>We have no idea what vibe-coded patches are doing to future security or stability of codebases, because we won&#8217;t have time to review them all before applying them</p></li><li><p>Many have blamed vibecoding on Amazon and Github&#8217;s sudden increase in outages. If true, does that happen to everyone now? Five 9s turns into &#8220;one and a half 8s&#8221;?</p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Oh no, now Adrian appears to be adopting Gen-Z slang. Let him know how you feel about it in the comments and subscribe so you can catch him doing other cringe stuff in the future!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Anthropic recently <a href="https://www.anthropic.com/research/glasswing-initial-update">shared an update</a> on Project Glasswing, self-described as a &#8220;collaborative effort to secure the world&#8217;s most critical software before increasingly capable AI models can be turned against it.&#8221; If this project were truly concerned with securing the world&#8217;s most critical software, I&#8217;d expect to see more of an overlap between ransomware crews&#8217; favorite targets and the list of Glasswing partners. As it is, there is no mention of the first, second, and fourth-most targeted vendors (Sonicwall, Fortinet, and Citrix) on Anthropic&#8217;s list.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Iapb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Iapb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png 424w, https://substackcdn.com/image/fetch/$s_!Iapb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png 848w, https://substackcdn.com/image/fetch/$s_!Iapb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png 1272w, https://substackcdn.com/image/fetch/$s_!Iapb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Iapb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png" width="1456" height="754" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:754,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:309036,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/199381536?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Iapb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png 424w, https://substackcdn.com/image/fetch/$s_!Iapb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png 848w, https://substackcdn.com/image/fetch/$s_!Iapb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png 1272w, https://substackcdn.com/image/fetch/$s_!Iapb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24f8d38c-482d-42ef-84df-0c992a38a8b8_2642x1368.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">From my webinar, &#8220;<a href="https://www.iansresearch.com/portal/recordings/rethinking-vulnerability-management--when-the-patch-can-t-come-fast-enough-(and-issues-go-unpatched-for-years">Rethinking Vulnerability Management</a>&#8221; - available on-demand for IANS clients.</figcaption></figure></div><p>Some suggested that it was actually the high cost of Mythos inference that prevented Anthropic from publicly releasing Mythos, not any impending danger of doing so. What if giving away $100M in free Mythos credits was, in fact, the <em>best</em> way to sell a future Mythos-like model?</p><p>Consider the implications: convince the world&#8217;s largest software makers that they need Mythos to free their code of bugs. Naturally, Mythos is so effective at this task that you need AI to also create the fixes. It&#8217;s already looking like AI-generated code is becoming the norm, even though it tends to be quite bloated and buggy. To summarize:</p><ol><li><p>AI-generated code has lots of vulnerabilities and issues</p></li><li><p>AI finds them</p></li><li><p>AI generates code to fix them</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!scPK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!scPK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png 424w, https://substackcdn.com/image/fetch/$s_!scPK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png 848w, https://substackcdn.com/image/fetch/$s_!scPK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png 1272w, https://substackcdn.com/image/fetch/$s_!scPK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!scPK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png" width="1024" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:243102,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/199381536?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!scPK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png 424w, https://substackcdn.com/image/fetch/$s_!scPK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png 848w, https://substackcdn.com/image/fetch/$s_!scPK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png 1272w, https://substackcdn.com/image/fetch/$s_!scPK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f9f07b9-d2e0-4037-834f-ce09ad745310_1024x768.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Putting the myth in Mythos</h1><p>Two myths have propagated from Anthropic and <a href="https://openai.com/daybreak/">OpenAI&#8217;s</a> vulnmaxxing marketing campaigns:</p><ol><li><p>only the most powerful and expensive models can do this work</p></li><li><p>these models can do this work autonomously</p></li></ol><p>Thanks to independent security research firms, these Mythos myths were quickly disproven. We now know that cheaper models have been able to find the same vulnerabilities as Mythos. That seems like good news, but token burn isn&#8217;t the only concern with using AI models to find and fix vulnerabilities. </p><p>Vulnerability discovery and exploit development aren&#8217;t trivial tasks, even with AI assisting. Both <a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">AISLE</a> and <a href="https://blog.vidocsecurity.com/blog/we-reproduced-anthropics-mythos-findings-with-public-models">Vidoc</a> independently concluded that the real moat here is not powerful, expensive models like Mythos, but the security expertise to operationalize the bug discovery process (e.g. building the harness, validating the results).</p><p>The need for expertise and an AI token budget raises the <a href="https://web.archive.org/web/20140203193523/https:/451research.com/t1r-insight-living-below-the-security-poverty-line">security poverty line</a>.</p><h1>It&#8217;s not a zero day</h1><p>Someone shared this <a href="https://linuxstans.com/ai-found-3900-critical-open-source-bugs-ibm-is-paying-5-billion-to-fix-them/">LinuxStans article</a> with me the other day and the following quote underscored one of the biggest problems with vulnmaxxing, Mythos, and vulnerability management in general.</p><div class="pullquote"><p>Every one of those CVEs is a potential path into production systems at a bank, a hospital, a power grid.</p></div><p>In the context of the article, &#8220;every one&#8221; refers to all 40,000+ CVEs published in 2024 and a proposed 56,000+ CVEs to be published this year. If every CVE were a critical RCE, we would be well and truly cooked! Thankfully, we can safely ignore most CVEs. The challenge is:</p><ol><li><p>Figuring out which ones can safely be ignored (see the importance of offensive security experience above)</p></li><li><p>Visibility - incomplete asset management means that vulnerabilities in unmanaged assets don&#8217;t get seen</p></li></ol><p>The language used in the Mythos marketing campaign further promotes the notion that all vulnerabilities are dangerous by referring to everything Mythos finds as <em>zero days</em>.</p><p>For fixing vulnerabilities to have value to a business, the vulnerabilities must have value to an attacker. Otherwise, it&#8217;s little more than security theater. Forget zero days. If no attacker finds value in them, we shouldn&#8217;t even call them <em>vulnerabilities</em> - they&#8217;re just software <em>bugs</em>.</p>]]></content:encoded></item><item><title><![CDATA[Verizon's 19th edition of the DBIR confirms the vulnpocalypse***]]></title><description><![CDATA[But with many asterisks! Read on to find out why &#128517;]]></description><link>https://www.defendersinitiative.com/p/verizons-19th-edition-of-the-dbir</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/verizons-19th-edition-of-the-dbir</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Tue, 19 May 2026 05:56:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LZTR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The <a href="https://verizon.com/dbir">Verizon 2026 Data Breach Investigations Report</a> (or just &#8216;the DBIR&#8217; to us security nerds) isn&#8217;t just any industry report - it&#8217;s a juggernaut in a field where multiple industry reports often drop on the same day, all year long. It is particularly common for cybersecurity vendor marketing teams to put out annual reports<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</p><h1>What makes the DBIR so special?</h1><p>While this report is produced by Verizon, it&#8217;s decidedly not a typical &#8216;vendor&#8217; report. Most vendor reports only include data from their own customers, whereas Verizon&#8217;s report includes data from over 100 partners and 145 different countries. The DBIR team isn&#8217;t a vendor marketing team that spends a month building an annual report every year, this report is the majority of what this team works on <em>all year long</em>.</p><p>The report is also awesome, because it <em>teaches you to use it</em>. Don&#8217;t skip pages 6-9, ESPECIALLY if you plan to publish something from this report<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>.</p><p>If there&#8217;s only one report you read with your own eyeballs, this should be the one. Don&#8217;t have an AI summarize it for you. AI doesn&#8217;t care about footnotes and footnotes are the best part of any report<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>.</p><h1>Exploring the numbers</h1><p>No other industry report comes remotely close to gathering and analyzing data on this scale. The 2026 report includes 31,850 incidents (a 31% increase over the 2025 report&#8217;s data set) and 22,624 confirmed data breaches (a 46% increase over the 2025 data set).</p><p>Data breaches are 71% of all incidents in this dataset, compared to 55% (just over half) in last year&#8217;s dataset. This report is a good, regular reminder of the big picture in cybersecurity:</p><ol><li><p>Not all cybersecurity incidents are data breaches</p></li><li><p>Not all incidents and data breaches involve a malicious actor (12% of data breaches involved internal, not external actors)</p></li><li><p>Not all data breaches are ransomware (48% this year, more than ever)</p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Defender's Initiative is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LZTR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LZTR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png 424w, https://substackcdn.com/image/fetch/$s_!LZTR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png 848w, https://substackcdn.com/image/fetch/$s_!LZTR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png 1272w, https://substackcdn.com/image/fetch/$s_!LZTR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LZTR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png" width="1456" height="1941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9572908,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/198013289?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LZTR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png 424w, https://substackcdn.com/image/fetch/$s_!LZTR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png 848w, https://substackcdn.com/image/fetch/$s_!LZTR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png 1272w, https://substackcdn.com/image/fetch/$s_!LZTR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F833e6d1c-afc2-4f99-9822-e3b6f0158cb5_3024x4032.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1></h1><h1>Highlight #1: Exploited vulnerabilities are now the most common initial access vector</h1><p>This agrees with nearly every other report I&#8217;ve read this year. Google Mandiant&#8217;s annual M-Trends report puts exploitation at 32% of initial access vectors, right in line with the 2026 DBIR&#8217;s 31%. Cybersecurity insurance claims reports, such as the <a href="https://www.coalitioninc.com/claims-report/2026">2026 report from Coalition</a> confirm this as well:</p><blockquote><p>Software exploits were the most common attack vector, observed in 38% of ransomware incidents</p></blockquote><p>Users were never the weakest link, but now they&#8217;re not even the most targeted by attackers!</p><p>Pinto and I go deep into this on the podcast above (forward to <a href="https://youtu.be/IIfHYSZZ58A?t=2471">41:11</a>). My concern with exploited vulnerabilities being the most common initial access vector is that companies will interpret this as a signal to double-down on vulnerability management and patching resources. This might be justified if we were seeing 20,000 different vulnerabilities being exploited, but that&#8217;s not the data we have.</p><p>Pinto&#8217;s advice, which I agree with, is to <a href="https://cdn.intelligencebank.com/us/share/NMXD/lA4p/qoBje/original/Coalition_Guide_Get+That+Off+the+Internet">reduce attack surface</a>, particularly at the edge, and prevent further lateral movement (isolation, segmentation, Zero Trust). We&#8217;ve had several years now where a handful of products have had an outsized impact. Verizon&#8217;s VCDB linked over 700 breaches to MoveIT DMZ vulnerabilities. The ransomware actor, Akira, has been linked to over 1400 breaches, with a high percentage of those linked to SonicWall devices - particularly CVE-2024-40766 (see the link to the Coalition report above for more details, or check out <a href="https://www.at-bay.com/2026-insursec-report/">At-Bay&#8217;s claims report</a>).</p><p>The refrain, &#8220;we can&#8217;t patch our way out of this one&#8221; is a saying that most folks will be sick of a year from now, but it captures the essence of the situation. We can&#8217;t simply patch faster when zero days exist for weeks before we know about them and edge devices go unpatched for years because they&#8217;re not in the CMDB.</p><h1>Highlight #2: Why did things get worse?</h1><p>The DBIR&#8217;s numbers don&#8217;t paint a rosy picture. Most show a peak in 2024 and then a decline in performance. To me, the numbers suggest that we might be hitting most companies&#8217; limits in terms of patching/remediation capacity.</p><ul><li><p>Only 26% of CISA KEV were fully remediated by orgs in 2025, a drop from 38% in 2024. </p></li><li><p>To be fair, the CISA KEV is growing, and the DBIR also notes that, on average, teams had to remediate 50% more critical vulnerabilities year-over-year.</p></li><li><p>The median time for full remediation also got worse. The median was 43 days in 2025, almost 2 weeks longer than 2024&#8217;s 32 days<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>.</p></li><li><p>The vulnerability burndown rate was significantly worse as well, until we hit the 6-9 month mark (figure 15 on page 18)</p></li></ul><p>Just to scratch an itch, I put together my own quick analysis to see whether CISA KEV&#8217;s growth is flat or growing. It&#8217;s no hockey stick, but unfortunately, the trend line is showing roughly 10 more additions to CISA KEV per month in April 2026 when compared to April 2024. The outlook isn&#8217;t great, considering organizations seem to be struggling to get through even a quarter of CISA KEV.</p><p>This is bad news, because CISA KEV is <em>the smallest</em> vulnerability dataset I can recommend to my clients for prioritization. <a href="https://www.vulncheck.com/kev">VulnCheck&#8217;s KEV</a>, with 4899 entries, is over 3 times larger than CISA&#8217;s KEV.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tqAu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tqAu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tqAu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tqAu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tqAu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tqAu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg" width="1456" height="770" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:770,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;chart, line chart&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="chart, line chart" title="chart, line chart" srcset="https://substackcdn.com/image/fetch/$s_!tqAu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tqAu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tqAu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tqAu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa93cb13-f098-45f9-9f30-66f408dc6a75_2048x1083.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Highlight #3: The data from Anthropic</figcaption></figure></div><h1>Highlight #3: The data from Anthropic</h1><p>Anthropic doesn&#8217;t hide the fact that their services are sometimes abused and their guardrails bypassed. My understanding is that the data they offered to Verizon (Alex Pinto explains this in more detail in the podcast above) isn&#8217;t linked to the main incident/data breach dataset in the DBIR. This is just an exploration of a dataset that Anthropic extracted from their systems and anonymized for the DBIR crew.</p><p>All that said, the results were interesting. It was smart for the Verizon folks to explore the nature of attackers&#8217; use of Claude - are they automating basic stuff, or learning new tricks? In the DBIR folks&#8217; words:</p><blockquote><p>A key question in understanding AI-enabled cyberthreats is whether attackers are using LLMs to execute well-documented techniques more efficiently, or to pursue techniques that are rarely seen in practice. If LLMs are lowering the barrier to techniques that are less documented and rare, defensive postures will need to catch up.</p></blockquote><p>Luckily, the answer was the less dramatic of the two. Again, in their words:</p><blockquote><p>AI is primarily accelerating the operationalization of well-known, documented techniques&#8212; lowering the barrier to execute what was once out of reach for less-sophisticated actors.</p></blockquote><p>Still, 32% of Claude abuse showed exploit development, which aligns with one of the biggest takeaways of this year&#8217;s DBIR.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/p/verizons-19th-edition-of-the-dbir?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/p/verizons-19th-edition-of-the-dbir?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h1>Where do we go from here?</h1><blockquote><p>This new world should require more focus, more agility, but does not necessitate an upheaval. Refinement, not revolution.</p></blockquote><p>I have to disagree with this point from the DBIR&#8217;s executive summary. If we want to see significant improvement, we <em>do </em>need a revolution. Unless someone discovers the <a href="https://www.youtube.com/watch?v=MkSYX0N07CQ">Konami Code</a> of InfoSec that somehow gives defenders unlimited time to complete our Sisyphean checklists, the approach that got us to 22,624 confirmed data breaches isn&#8217;t going to make that number suddenly reverse direction.</p><p>I suspect the vulnpocalypse, where AI fuels accelerated vulnerability discovery, will waste a lot of time patching vulnerabilities no attacker will ever have interest in. Instead, the real vulnpocalypse is the one we&#8217;ve already been living with for the past two years, where attackers have a field day with unpatched edge devices and poorly-guarded NPM packages.</p><p>Radical change in how IT infrastructure is managed is necessary to make a dent in this trend. The problem is that security teams often have very little influence over IT infrastructure, and the incentives don&#8217;t currently exist to justify &#8216;revolutionizing&#8217; IT and getting rid of decades of technical debt.</p><h1>Final thoughts - attackers share, defenders hide</h1><p>As we near hacker summer camp, where hundreds of talks will share the latest techniques for hacking into systems and using AI to speed up the process, defenders have never been in a position more distant from the state of offense. I plan to write more about addressing this issue in the near future, however, and the DBIR report is a great place to start for folks that want to help.</p><h1>Bonus: Podcast with the Lead Author of the DBIR</h1><p>I&#8217;m excited to share that I also got to interview Alex Pinto alongside Alexandre Sieira on the Alice in Supply Chains podcast! If you&#8217;d rather listen to us talk about the report than read my thoughts here on it, you can check out the recording below. The full page with show notes is <a href="https://www.tenchisecurity.com/en/alice-in-supply-chains/dbir-bonus-episode-with-special-guest-alex-pinto-verizon-business">here</a>.</p><div id="youtube2-IIfHYSZZ58A" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;IIfHYSZZ58A&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/IIfHYSZZ58A?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I might have even had a hand in producing a few.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>I once <a href="https://x.com/sawaba/status/762367229421817856">called out Cylance on Twitter</a> for abusing a DBIR stat, and I&#8217;m not sure they ever forgave me. My guess is that they assumed the DBIR graph&#8217;s y-axis was 0-100%, but it was 0-35%. This assumption led to their claim that &#8220;Malware is used in 90% of cyber incidents&#8221; when the real number was actually 33%. The lesson for Cylance: contact the DBIR folks to make sure you&#8217;re not interpreting things wrong! The lesson for me: maybe I should have contacted the Cylance folks privately and should have done less rage-tweeting.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>The DBIR&#8217;s footnotes are <em>so much better</em> than mine.x </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>You can find all this data on page 10 of the report.</p></div></div>]]></content:encoded></item><item><title><![CDATA[TALK: How Breaches Happen]]></title><description><![CDATA[Delivered at Chicago ISSA's Spring 2026 Meeting]]></description><link>https://www.defendersinitiative.com/p/talk-how-breaches-happen</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/talk-how-breaches-happen</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Sat, 09 May 2026 05:20:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WKSx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>First, Chicago ISSA, thanks for inviting me to share my thoughts with you! I thoroughly enjoyed the presentation, <a href="https://www.linkedin.com/in/ewhasty/?lipi=urn%3Ali%3Apage%3Ad_flagship3_detail_base%3Bvk3iOd1CSWKXZZlhAdfb%2FA%3D%3D">Eric Hasty&#8217;s</a> followup presentation, and all the ad-hoc discussions afterwards. A big thanks to Steve Moscarelli and Gregg Friedman for reaching out to me and planning this.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WKSx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WKSx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WKSx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WKSx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WKSx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WKSx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:416311,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/196738471?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WKSx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WKSx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WKSx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WKSx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F051f0fdd-2eab-44f6-be94-b17d01f6281e_2048x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Thanks for <a href="https://www.linkedin.com/feed/update/urn:li:activity:7458381350866374656/">taking pictures</a> Rashmi!</figcaption></figure></div><h1>The Talk</h1><p>I&#8217;ve been collecting and analyzing breach details for roughly 10 years now, and decided it was time to publish and share what I&#8217;ve learned. I hired an intern to help me polish and publish a decade&#8217;s notes on over 100 incidents.</p><p>Breach details are all over though, aren&#8217;t they? </p><p>Most breach databases are shallow: date of breach, financial losses, number of customers affected, etc. These shallow details aren&#8217;t useful for practitioners hoping not to repeat the mistakes of others. That&#8217;s where The Defenders Initiative comes in.</p><p>We seek out the process failures and control failures. Okay, an employee was phished. We seek to answer why the phishing attack wasn&#8217;t detected. </p><ul><li><p>Why weren&#8217;t the attacker&#8217;s next 20 steps detected or prevented? </p></li><li><p>What was the company culture like? </p></li><li><p>Were security products and controls neglected or well maintained? </p></li><li><p>Did a penetration test warn the company of an attack precisely like their breach, just months before?</p></li></ul><p>I also have to comment on Mythos and the impact of AI on vulnerability discovery, time-to-exploit, and other factors that weigh heavily on breach likelihood.</p><h1>The Resources</h1><p>My talk mentions many resources, which I&#8217;ll attempt to list here, roughly in the order they&#8217;re mentioned in my talk.</p><ul><li><p>My talk with Adam Shostack from RSAC 2026: Failure is a Terrible thing to Waste</p></li></ul><p>There are a few places where we can find evidence that is deep and useful. The following lists are examples, not exhaustive.</p><ul><li><p>Reports on Threat Actors and DFIR analysis</p><ul><li><p>Verizon <a href="https://www.verizon.com/business/resources/reports/dbir/">Data Breach Report</a> (annual report - the new one comes out in a few weeks!)</p></li><li><p>Mandiant <a href="https://cloud.google.com/security/resources/m-trends">M-Trends</a> (annual report)</p></li><li><p>FortiGuard Labs&#8217; <a href="https://www.fortinet.com/resources/reports/threat-landscape-report">Global Threat Landscape reports</a></p></li><li><p><a href="https://thedfirreport.com">The DFIR Report</a></p></li></ul></li><li><p>Federal investigations</p><ul><li><p>FTC Complaints (<a href="https://www.ftc.gov/system/files/ftc_gov/pdf/202-3185-Drizly-Complaint.pdf">here&#8217;s Drizly</a>, as an example)</p></li><li><p>US Govt Investigations</p></li><li><p><a href="https://eurepoc.eu/">European Repository of Cyber Incidents</a></p></li><li><p>Canadian Privacy Commissioners (here&#8217;s <a href="https://oipc.ab.ca/wp-content/uploads/2025/11/FINAL-Investigation-Report-Regarding-PowerSchool-Breach-FOIP2025-IR-02.pdf">Alberta</a> and <a href="https://www.ipc.on.ca/en/resources/ontarios-privacy-commissioner-releases-investigation-findings-powerschool-breach-affecting-school">Ottawa&#8217;s</a> investigations into the Powerschool breach, as examples)</p></li><li><p>CISA <a href="https://www.cisa.gov/resources-tools/groups/cyber-safety-review-board-csrb">CSRB</a> (RIP - the CSRB put out some excellent reports, but is unfortunately, currently defunct)</p></li></ul></li><li><p>Insurance Companies</p><ul><li><p>At-Bay&#8217;s annual <a href="https://www.at-bay.com/2026-insursec-report/">InsurSec Report</a></p></li><li><p>Coalition&#8217;s annual <a href="https://cdn.intelligencebank.com/us/share/NMXD/aP6w/ZzAYD/original/Coalition_2026-Cyber-Claims-Report">cyber claims report</a></p></li><li><p>Cowbell Cyber <a href="https://cowbell.insure/wp-content/uploads/pdfs/CB-US-Media-CyberRoundup-2026ClaimsReport.pdf">claims report</a></p></li></ul></li><li><p>Transparent Companies</p><ul><li><p>Code Spaces <a href="https://web.archive.org/web/20140618165208/http://www.codespaces.com/">shared the details of their unfortunate demise</a> one day after it happened</p></li><li><p>The British Library&#8217;s <a href="https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf">report</a> on their own breach</p></li><li><p>Three security companies impacted by Okta&#8217;s Support Site Breach shared their experiences: <a href="https://1password.com/blog/okta-incident">1Password</a>, <a href="https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/">Cloudflare</a>, and <a href="https://www.beyondtrust.com/blog/entry/okta-support-unit-breach">BeyondTrust</a></p></li><li><p>CircleCI <a href="https://circleci.com/blog/jan-4-2023-incident-report/">provided a lot of details</a> about their 2023 breach.</p></li></ul></li></ul><p>Other references</p><ul><li><p><a href="https://www.youtube.com/watch?v=A-fHsq1yD_c">One of the talks</a> I&#8217;ve done on the Equifax breach</p></li><li><p>My writeup on Mythos and the impact of AI on vulnerability management (below)</p></li></ul><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;4ae895f9-44a5-48db-9fa6-5c7d29e73120&quot;,&quot;caption&quot;:&quot;In case you missed it, I&#8217;ve detailed some of the challenges facing vulnerability management programs in a previous post: Reevaluating vulnerability management. Those challenges are only getting worse.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;From this point on, it only gets rougher&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:11988704,&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;bio&quot;:&quot;Always trying to see the big picture, figure out the best strategy, and uncover BS in Cybersecurity. I still see the glass as half-full.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a89717e5-a927-4084-ad86-69068727dbf3_1632x1632.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-13T12:28:40.087Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!gVMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.defendersinitiative.com/p/from-this-point-on-it-only-gets-rougher&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193835202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:2,&quot;publication_id&quot;:3676751,&quot;publication_name&quot;:&quot;The Defender's Initiative&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rsmo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><h1>The Slides</h1><p>Last, but not least, here&#8217;s a <a href="https://www.beautiful.ai/player/-Os-epC9OoNNTq78gw4Q">link to the slides</a>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Defender's Initiative is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Destroyed by Breach project now has a website]]></title><description><![CDATA[Finally, after existing as a Google Sheet for nearly a decade]]></description><link>https://www.defendersinitiative.com/p/the-destroyed-by-breach-project-now</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/the-destroyed-by-breach-project-now</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Mon, 04 May 2026 18:04:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ig9E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hi folks! Short one today.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe so you can hear more about the companies on the Destroyed by Breach list in the future.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In the mid-2010s, I was inspired to investigate companies that had gone out of business as the result of a breach. I heard this statistic that just felt <em>wrong</em> to me.</p><div class="pullquote"><p>60% of small businesses will close up within six months of a cyber attack</p></div><p>First off, 60% seemed like a ton of businesses. The vast majority of businesses in the world are small businesses, so 60% would suggest <em>millions</em> of businesses going out of business because of breaches every year! The problem is, we don&#8217;t see anywhere near that many breaches every year - there literally are not enough cybercriminals to pull off that many heists. The 2025 Verizon DBIR tracked &#8220;22,052 real-world security incidents, of which 12,195 were confirmed data breaches.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f70C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f70C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png 424w, https://substackcdn.com/image/fetch/$s_!f70C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png 848w, https://substackcdn.com/image/fetch/$s_!f70C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png 1272w, https://substackcdn.com/image/fetch/$s_!f70C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f70C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png" width="673" height="246" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:246,&quot;width&quot;:673,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:145205,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/196444773?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f70C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png 424w, https://substackcdn.com/image/fetch/$s_!f70C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png 848w, https://substackcdn.com/image/fetch/$s_!f70C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png 1272w, https://substackcdn.com/image/fetch/$s_!f70C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff65b82e8-b24e-449d-96a4-2c4f3c810640_673x246.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">the origin of this stat, from The National Cyber Security Alliance: https://web.archive.org/web/20130116004710/www.staysafeonline.org/stay-safe-online/resources/small-business-online-security-infographic</figcaption></figure></div><p>And wouldn&#8217;t we hear about it? Surely the media would be covering such a wide-scale catastrophe.</p><blockquote><p>According to the SBA: &#8220;There are <strong>31.7 million </strong>small businesses in the U.S. 81 percent, or 25.7 million, have no employees (termed &#8220;nonemployers&#8221;) and 19 percent, or 6 million, have paid employees. There are 20,139 large businesses.&#8221;</p></blockquote><p>&#8220;Within six months of a cyber attack&#8221; also sounded odd. How would you know they were closing up because of the cyber attack? The vast majority of small businesses close up over a short period anyway, if I recall correctly (feel free to check me on this, I didn&#8217;t look up this stat).</p><h1>The List</h1><p>So I started a list. It began with web searches. Then I shared my findings. Other folks helped me discover more companies that had gone out of business from a breach, and the list grew. There are currently 33 companies on the list, though there are more I&#8217;m still investigating.</p><p>Here&#8217;s the new site: <a href="https://destroyedbybreach.com">destroyedbybreach.com</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ig9E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ig9E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png 424w, https://substackcdn.com/image/fetch/$s_!Ig9E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png 848w, https://substackcdn.com/image/fetch/$s_!Ig9E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png 1272w, https://substackcdn.com/image/fetch/$s_!Ig9E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ig9E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png" width="1097" height="907" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:907,&quot;width&quot;:1097,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:116597,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/196444773?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ig9E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png 424w, https://substackcdn.com/image/fetch/$s_!Ig9E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png 848w, https://substackcdn.com/image/fetch/$s_!Ig9E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png 1272w, https://substackcdn.com/image/fetch/$s_!Ig9E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ea3e28d-46b7-465e-a67c-bce9f8bc2f8d_1097x907.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The big takeaway here is that it&#8217;s extremely rare to see a company go out of business because of a cybersecurity incident or breach. It <em>does happen</em> though, but the victim is almost always a small-to-mid-sized business that doesn&#8217;t have the cash flow to continue, or suffers reputational damage too great to continue. Large companies have the insurance, size, and momentum to work through a breach and carry on. Smaller companies don&#8217;t.</p><h1>What about the stat?</h1><p>The stat blew up in 2011, when the National Cyber Security Alliance published it in a short article. They <a href="https://staysafeonline.org/resources/national-cyber-security-alliance-statement-regarding-incorrect-small-business-statistic/">quickly retracted it and apologized</a>, but the myth had already taken off. Every few years, they continue to ask people to stop using the stat, to no avail. It still pops up everywhere.</p><p>In 2017, Joseph Marks, a reporter for NextGov at the time, <a href="https://www.nextgov.com/cybersecurity/2017/05/how-fake-cyber-statistic-raced-through-washington/137542/">investigated the origins of the statistic</a> and discovered that the origin was media personality, Ramon Ray.</p><div class="pullquote"><p>&#8220;Ray told Nextgov he believes the figure was provided by a cybersecurity expert he interviewed for the story but cannot recall the expert&#8217;s name more than five years later.&#8221;</p></div><p>Ray continues to use the fake statistic he invented, as recently as 2021. People love it - it&#8217;s a great source of fear that feeds a narrative that some folks in cybersecurity sales and marketing are quick to jump on and use in their messaging and reports.</p><h1>Help out Destroyed by Breach</h1><p>If you come across a case that you think should be on the list, use the <a href="https://destroyedbybreach.com/suggest">submission form on the website</a> and let me know!</p><p>In the future, I&#8217;m going to start writing up some of the stories of the companies on this list. Let me know if you&#8217;d be interested in more of those on this Substack in the future.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[A tale of two privilege escalation bugs]]></title><description><![CDATA[Why Copy Fail is a bigger deal than PhantomRPC]]></description><link>https://www.defendersinitiative.com/p/a-tale-of-two-privilege-escalation</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/a-tale-of-two-privilege-escalation</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Thu, 30 Apr 2026 13:34:46 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I generally don&#8217;t get excited about privilege escalation vulnerabilities on workstations. Infostealers can vacuum up all sorts of credentials and sensitive files without escalating privileges, and it&#8217;s possible to laterally move throughout the environment without root or SYSTEM. </p><p>On Windows, if an attacker has any interactive access to the system, it belongs to the attacker. There might be folks out there who have figured out how to harden Windows to a point where this isn&#8217;t true, but the average Windows system is toast as soon as an attacker has a foothold. <a href="https://www.halcyon.ai/blog/understanding-byovd-attacks-and-mitigation-strategies">BYOVD</a> is just one option on the table if attackers do need to escalate their privileges on Windows.</p><p>For these reasons, I didn&#8217;t get very excited about <a href="https://www.malwarebytes.com/blog/news/2026/04/microsoft-wont-patch-phantomrpc-feature-or-bug">PhantomRPC</a> and didn&#8217;t plan to write about it.</p><p>Then <a href="https://xint.io/blog/copy-fail-linux-distributions">Copy Fail</a> dropped.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="4160" height="6240" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:6240,&quot;width&quot;:4160,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A ginger cat sits on top of a copier.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A ginger cat sits on top of a copier." title="A ginger cat sits on top of a copier." srcset="https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1776624906472-c300fb53d9a7?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw1fHxwcmludGVyJTIwamFtfGVufDB8fHx8MTc3NzUxNDAwMnww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@niklasjesper">Niklas</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">More people are subscribing, so I&#8217;m writing more! Sign up, consider a paid tier, escalate privileges to my leading thoughts!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>This is how you write a vulnerability disclosure</h1><p>Wow. WOW. <a href="https://xint.io/blog/copy-fail-linux-distributions#remediation-7">This writeup has it all</a>. Check it out and come back here - I&#8217;m not going to repeat too much of it and they&#8217;ve earned your eyeballs with this excellent post.</p><ol><li><p>Description of the vulnerability: 10/10</p></li><li><p>Technical Description: n/a (beyond my understanding, but I imagine it&#8217;s as good as the rest)</p></li><li><p>General Description: 10/10</p></li><li><p>Context and relevance</p></li><li><p>Fix included (wow!)</p></li><li><p>Explains the history of how it got there (nice!)</p></li><li><p>Explains how to mitigate if you can&#8217;t patch (WOWOWOW)</p></li><li><p>They explain how they found it (excellent!)</p></li><li><p>It&#8217;s also nice to see that the Linux kernel folks responded within a day and by day 2 were reviewing potential patches</p></li></ol><p>Unless I missed something, the only thing missing is the exploit itself, which is understandable, given that today is disclosure day and folks need time to patch.</p><h1>AI</h1><p>Yes, AI played a part in finding this. I&#8217;m noticing a trend. It&#8217;s looking like expert-assisted AI will be a common combination in vulnerability discovery from now on. AI <em>can </em>find bugs in the hands of novices, but they&#8217;re generally not very interesting bugs based on what came out of Anthropic&#8217;s Mythos (more on this in the post below).</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;4e17e00d-160c-4f14-b2c7-d677baf57224&quot;,&quot;caption&quot;:&quot;In case you missed it, I&#8217;ve detailed some of the challenges facing vulnerability management programs in a previous post: Reevaluating vulnerability management. Those challenges are only getting worse.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;md&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;From this point on, it only gets rougher&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:11988704,&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;bio&quot;:&quot;Always trying to see the big picture, figure out the best strategy, and uncover BS in Cybersecurity. I still see the glass as half-full.&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!VDfx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05cb4447-d60d-4c30-9185-b38fd15544dc_1487x1487.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-04-13T12:28:40.087Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!gVMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.defendersinitiative.com/p/from-this-point-on-it-only-gets-rougher&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:193835202,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:2,&quot;publication_id&quot;:3676751,&quot;publication_name&quot;:&quot;The Defender's Initiative&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rsmo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Even when interesting bugs were found, like the RCE in FreeBSD, <a href="https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd">an expert was necessary</a> to get to a working exploit.</p><p>I mentioned that Xint didn&#8217;t release the 732 byte exploit. I&#8217;d be surprised if someone hasn&#8217;t taken the technical details from the writeup and the patch, and vibe-coded a working exploit by now. This is the speed of exploit development today - working exploits the day the patch is released.</p><p>I want to really stress this again.</p><div class="pullquote"><p>I&#8217;d be surprised if someone hasn&#8217;t vibe-coded a working exploit by now.</p></div><h1>Linux Yikes, Windows Yawn?</h1><p>The main reason why privilege escalation is so much more concerning in Linux is due to where Linux is used.</p><p>Everywhere.</p><p>Including in multiuser and multi-tenant situations where organizations are serving untrusted parties. Kubernetes, containers, every SaaS, every PaaS, IaaS. Every cloud, hyperscaler, code hosting platforms, and AI service has Linux running beneath it. Some network infrastructure and most IoT devices also run Linux. Every <em>supercomputer</em> is basically one big multi-tenant shell server.</p><h3>Cloud providers, probably not worried</h3><p>In the cases where untrusted customers are intentionally handed a shell, privilege escalation vulnerabilities are anticipated and part of every threat model. Folks at AWS, GCP, and Azure probably aren&#8217;t scrambling too much today - they expect vulns like this to occasionally drop and their whole business model depends on dealing with days like today.</p><p>Unlike cloud and hosting providers, supercomputers aren&#8217;t just handing shells to random folks off the street. Control is a bit tighter and folks are generally vetted before being given access. I imagine that any attempt to exploit a privesc vuln would get you booted and banned rather quickly. With that said, it seems likely that all the flavors of Linux that run on supercomputers would be vulnerable to this.</p><h3>AI platforms, apps, and agents on the other hand&#8230;</h3><p>These new AI services and platforms popping up left and right, however - I wouldn&#8217;t be surprised if some of them are less prepared. Add the risk of <a href="https://genai.owasp.org/llmrisk/llm01-prompt-injection/">prompt injection</a> to the lists of ways we could see this vulnerability get exploited. This is where I&#8217;d look for any fallout from this vulnerability.</p><h3>Who else should be concerned?</h3><p>If you&#8217;re on this list, you could be a juicy target for ransomware crews. Ransomware teams like being able to reuse vulnerabilities to get access to multiple victims, and organizations that are large enough to pay a 5-7 digit ransom, but small enough to not have a security team are often the sweet spot these criminal groups go after.</p><ul><li><p>Low cost web hosting companies that give customers shell access might be scrambling. </p></li><li><p>There are all sorts of niche hosting services for gaming as well. Minecraft is a particularly large one - anyone running Pterodactyl should probably patch quickly.</p></li><li><p>Free shell providers (yes, these still exist)</p></li><li><p>CI/CD runners</p></li><li><p>Anyone running online IDE/sandbox/notebook services (e.g. Jupyter) should check for impact here. I don&#8217;t know a ton about how these services work, so I can&#8217;t say with certainty how much they&#8217;d be affected.</p></li><li><p>CTF (capture the flag) services often give access to shells. Since they&#8217;re literally designed for hacking, I&#8217;d think there would be extra measures to address unknown privilege escalation bugs&#8230; right?</p></li><li><p>With the exploit requiring only 732 bytes, I wouldn&#8217;t be surprised to see <a href="https://thehackernews.com/2025/10/analysing-clickfix-3-reasons-why.html">ClickFix</a> attacks leveraging this vulnerability and targeting software engineers and the general public.</p></li><li><p>Any systems running Linux with services that might have unpatched command injection vulnerabilities (<a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=%22command+injection%22&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=All&amp;url=">edge devices, I&#8217;m looking at you</a>) might have a bad day.</p></li></ul><p>If you didn&#8217;t read the Xint post and you&#8217;re wondering how to remediate this, go back and give it a look - patching isn&#8217;t the only option. Seccomp and blocking the affected module can both mitigate exploitation. This is also just part 1 from Xint - they promise to share container escapes next.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/p/a-tale-of-two-privilege-escalation?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">If you made it this far, we&#8217;d love it if you shared this post with someone else - it&#8217;s free, after all!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/p/a-tale-of-two-privilege-escalation?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/p/a-tale-of-two-privilege-escalation?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p>]]></content:encoded></item><item><title><![CDATA[Breach Lessons - First Look: Vercel and Context AI]]></title><description><![CDATA[We usually wait for the investigation to complete, but there are already a ton of useful lessons here.]]></description><link>https://www.defendersinitiative.com/p/breach-lessons-first-look-vercel</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/breach-lessons-first-look-vercel</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Mon, 20 Apr 2026 18:21:45 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<blockquote><p>We&#8217;ll come back and update this post as new information comes out. Early breach information is often <em>wrong </em>or missing important context, so we&#8217;re going to focus on lessons that are broadly useful, even if the breach details fundamentally change later. </p><p>In other words: you should take the breach details here with a grain of salt, but take the lessons to heart.</p></blockquote><h1>Attackers know that <s>buying</s> hacking in bulk is a good value</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="6016" height="4016" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4016,&quot;width&quot;:6016,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;cardboard box lot&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="cardboard box lot" title="cardboard box lot" srcset="https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1513672494107-cd9d848a383e?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwzOHx8YnV5aW5nJTIwaW4lMjBidWxrfGVufDB8fHx8MTc3NjY5ODk0N3ww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@chuttersnap">CHUTTERSNAP</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>Third party and supply chain attacks have been <em>en vogue</em> for a few years now and this trend only seems to be increasing. Why hack one company when you can hack <em>thousands</em> of companies or users through a software/services supplier?</p><p>The <strong>hack once, exploit many</strong> nature of these attacks isn&#8217;t the only attraction. Integrating with third party software often requires creating OAuth applications or tokens that grant the third party access to your own data and systems, or another third party software supplier your company uses. Unfortunately, <a href="https://www.obsidiansecurity.com/blog/what-is-token-theft-oauth-session-api-token-attacks-explained">session hijacking via token theft</a> is still an unsolved problem, meaning that attackers who obtain OAuth keys and other types of auth tokens get to bypass the authentication process.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Defender's Initiative is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>We covered this on Enterprise Security Weekly back in December (jump to the 34:40 mark in the video).</p><div id="youtube2-UxOnCMw_yPc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;UxOnCMw_yPc&quot;,&quot;startTime&quot;:&quot;2074&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/UxOnCMw_yPc?start=2074&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Token theft works so well, it has led to a rise in the use of <a href="https://www.infostealers.com/article/the-industrialization-of-clickfix-inside-errtraffic/">infostealer malware and ClickFix</a> social engineering techniques over the past two years. The rationale here is that the employees with high-level privileges to systems typically use MacOS. Macs are harder to attack directly and infect with malware, so attackers pivoted to the ClickFix social engineering technique, which has proved effective.</p><p>Convince a Mac user to copy a command and paste it into their terminal (under the guise of fixing a problem or installing harmless software), and the infostealer runs, scooping up crypto wallets, plaintext passwords, SSH private keys, environment variables, auth tokens from logged-in sessions, <code>~/.openclaw/credentials/oauth.json</code> and anything else not nailed down.</p><h1>The high price of convenience and forgetfulness</h1><p>These session keys exist, because no one wants to spend the first 40 minutes of every work day logging into Teams, email, Slack, Github, Dropbox, Google Calendar, LinkedIn, Claude Code, Mastodon, Microsoft 365&#8217;s Office apps, the Apple App Store, and everything else we might need to be productive. In addition to simply logging into the apps of our choosing, there are also 3rd party integrations that require auth keys to function. </p><p>For example, if I want ChatGPT to be able to locate files in Dropbox, I can integrate the two, but this requires granting ChatGPT at least read access to Dropbox. Sometimes (ahemGoogleahem) the third party doesn&#8217;t allow this access to be as fine-grained as you might want and you grant too much access. Sometimes, you don&#8217;t want to spend an extra 10 minutes figuring out permissions, so you just click the &#8220;Grant Full Access&#8221; option.</p><p>Creating these integrations often takes mere seconds. Then, we immediately forget the integration exists. This is a problem.</p><p>When I was working at <a href="https://www.valencesecurity.com">Valence Security</a>, we observed that 100% of our customers at the time of joining, had granted tenant-level access to third parties that they were not using. In other words:</p><ol><li><p>they did a proof-of-concept with someone</p></li><li><p>gave the product full control of all employees&#8217; email, files, and calendar in Google Workspace or Microsoft 365</p></li><li><p>didn&#8217;t buy the product</p></li><li><p>forgot to revoke a token that granted FULL ACCESS to nearly everything the company cared about</p></li></ol><h1>Third Party Breach Turducken</h1><p>This brings us to the Vercel and Context AI breaches: a third party breach within a third party breach. Let&#8217;s start with Context AI<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</p><p>In June 2025, Context AI released a consumer product that was designed to be an agent-driven productivity monster. Give it access to your chats, your email, your files and it can build slides, spreadsheets, and reports using all the context from your existing files and conversations.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Y2j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Y2j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png 424w, https://substackcdn.com/image/fetch/$s_!_Y2j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png 848w, https://substackcdn.com/image/fetch/$s_!_Y2j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png 1272w, https://substackcdn.com/image/fetch/$s_!_Y2j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Y2j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png" width="1456" height="922" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:922,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:801038,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/194808919?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Y2j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png 424w, https://substackcdn.com/image/fetch/$s_!_Y2j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png 848w, https://substackcdn.com/image/fetch/$s_!_Y2j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png 1272w, https://substackcdn.com/image/fetch/$s_!_Y2j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc7a84c6-0161-42e0-93e0-626be4407fe4_1663x1053.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Of course, for this to work, you need to give it access to all your stuff. Everyone reading this was probably familiar with the dangers of doing this a year ago. If not then, certainly now, post-OpenClaw.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1NSA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1NSA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png 424w, https://substackcdn.com/image/fetch/$s_!1NSA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png 848w, https://substackcdn.com/image/fetch/$s_!1NSA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png 1272w, https://substackcdn.com/image/fetch/$s_!1NSA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1NSA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png" width="627" height="278" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/35149406-93b9-4236-94b8-d44043ef21a2_627x278.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:278,&quot;width&quot;:627,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:53877,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/194808919?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1NSA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png 424w, https://substackcdn.com/image/fetch/$s_!1NSA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png 848w, https://substackcdn.com/image/fetch/$s_!1NSA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png 1272w, https://substackcdn.com/image/fetch/$s_!1NSA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35149406-93b9-4236-94b8-d44043ef21a2_627x278.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Gmail, Salesforce, AND Slack? Ooof, that&#8217;s a lot of access <sup>&#128517;</sup></figcaption></figure></div><p>While Vercel was never a Context AI customer, one of their employees was. This employee gave Context&#8217;s AI Office Suite full access to their Vercel Google Workspace email, calendar, and files. <a href="https://context.ai/security-update">In Context&#8217;s words</a>:</p><blockquote><p>Vercel wasn&#8217;t a customer, but at least one of their employees granted access to Vercel&#8217;s Gooogle Workspace and granted &#8220;Allow All&#8221; permissions</p></blockquote><p>At some point, Context AI pivots to an enterprise product called Context Bedrock and deprecates their AI Office Suite. From what I can gather from the state of their website according to the Wayback Machine, this pivot happened well before this attack began. Shared responsibility failed during this pivot. Based on what we know so far, after this product was deprecated:</p><ol><li><p>The Vercel employee didn&#8217;t revoke the tokens Context was still storing.</p></li><li><p>Context didn&#8217;t delete customer tokens and didn&#8217;t shut down the infrastructure used by AI Office Suite</p></li><li><p>We don&#8217;t know if Context notified AI Office Suite customers that the product was being deprecated, but I couldn&#8217;t find any public notice of this fact on the company&#8217;s websites, LinkedIn, or Twitter accounts.</p></li></ol><h2>Context Gets Breached</h2><p>UPDATE: <a href="https://www.infostealers.com/article/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai/">HudsonRock traced</a> Context.ai&#8217;s compromise back to a Lumma infostealer infection, as there&#8217;s only one Lumma infection associated with Context.ai. In the stolen files, HudsonRock found web searches that &#8220;indicate the user was actively searching for and downloading game exploits, specifically Roblox &#8220;auto-farm&#8221; scripts and executors.&#8221; Downloading software cracks and cheats is a classic way to get infected with malware. </p><p>Never download Roblox cheats on the same device where you store your cloud creds for work.</p><p>In March 2026, Context &#8220;independently identified and stopped a security incident involving unauthorized access to our AWS environment.&#8221; They hired CrowdStrike, who identified one affected customer. Context notified this customer and shut down the remainder of the AI Office Suite infrastructure.</p><p>Given Context&#8217;s description, it seems possible that there was never a hard shut down of the old product and that the company simply started work on a new product while letting the old product continue running, unsupervised and unmonitored.</p><p>In light of the Vercel breach, Context put out <a href="https://context.ai/security-update">its own security notice</a>, noting that perhaps AI Office Suite OAuth tokens were also compromised in its own breach the previous month. Sadly, Context&#8217;s security notice doesn&#8217;t share any information about how they got breached, but in their defense, they mention that they&#8217;ve restarted their investigation, which is ongoing.</p><h2>Vercel Gets Breached</h2><p>Vercel is a vibe-coding product that specializes in building application/website front-ends (the part you can see). On April 19th, they became aware that one of their employees&#8217; accounts was compromised and being used to access customer environments. They don&#8217;t mention what tipped them off to the attacker&#8217;s presence, or how long the attacker was present. Again, I&#8217;m writing this only one day after they detected the attack, so they&#8217;re likely far from completing their investigation.</p><p>Vercel contacted affected customers and recommended immediate credential rotation. They&#8217;re still working to determine what data was exfiltrated, if any.</p><p>Vercel <a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident">provides some advice</a> on how customers can protect their environments with a few built-in security features, like &#8216;sensitive environment variables&#8217; and &#8216;deployment protection&#8217;. They also share the identifier for the Context OAuth app that was used to compromise them through Google Workspace: <code>110671459871-30f1spbu0hptbs60cb4vsmv79i7bbvqj.apps.googleusercontent.com</code></p><h1>Lessons/Control Failures</h1><ol><li><p>Vercel&#8217;s corporate collaboration suite was over permissive - the employee should not have been able to hand over full control of their work account to a third party without business justification and/or security review.</p></li><li><p>Failure to revoke access once no longer needed - both the employee and Context failed to revoke the access after the product was deprecated.</p></li><li><p>Access token theft (<a href="https://attack.mitre.org/techniques/T1134/001/">T1134.001</a>)</p></li><li><p>Lack of regular access reviews - given how this attack occurred, and the fact that Context&#8217;s product didn&#8217;t even last a year, suggests that annual reviews of employee-initiated integrations would be far too infrequent. Monthly may be more appropriate, given the velocity of AI app development and adoption (both sanctioned and shadow).</p></li><li><p>Too much employee access to customer data/workloads - we&#8217;ve all seen SaaS products where access to customer data is far too permissive. Travis Kalanick&#8217;s <a href="https://www.forbes.com/sites/kashmirhill/2014/10/03/god-view-uber-allegedly-stalked-users-for-party-goers-viewing-pleasure/">abuse of Uber&#8217;s God View</a> is perhaps one of the most egregious cases of this.</p></li></ol><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/p/breach-lessons-first-look-vercel?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Defender's Initiative! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/p/breach-lessons-first-look-vercel?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/p/breach-lessons-first-look-vercel?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h1>Timeline</h1><ol><li><p>2025 - A Vercel employee signs up for Context&#8217;s AI Office Suite product</p></li><li><p>2025 - This employee grants AI Office Suite full access to their Vercel Google Workspace resources (Email, Calendar, and Files at a minimum).</p></li><li><p>March 2026 - Context becomes aware of a breach in its AWS environment and hires Mandiant to investigate. One customer is notified.</p></li><li><p>April 19, 2026 - Vercel becomes aware of a breach and traces the source of the breach back to an OAuth token granted to Context AI by one of its employees</p></li><li><p>Both Vercel and Context continue to investigate - hopefully more details will come out and they will be transparent about how both breaches were initiated and detected.</p></li></ol><h1>Conclusion</h1><p>How often do we perform a security review of our personal or corporate third party integrations? Does a Blackberry Curve from 2012 still have full permissions to access your Gmail? Surely that access would expire, right? Think again.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Xl2Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png 424w, https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png 848w, https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png 1272w, https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png" width="558" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:558,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72879,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/194808919?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png 424w, https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png 848w, https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png 1272w, https://substackcdn.com/image/fetch/$s_!Xl2Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc685e0-7947-4d32-98f7-65373f7e3727_558x972.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Just to get you started, start visiting Google&#8217;s <a href="https://myaccount.google.com/security-checkup">Security Checkup</a> page on a regular basis!</figcaption></figure></div><p>The first big lesson here is that, in a cloud-first/SaaS-first world, we have to regularly review all the access we&#8217;ve given to third parties: access to our data, to our devices, to our employers, to our kids. In an ideal world, this access control model should be reversed. By default, access granted to third parties should come with an expiration date by default. </p><p>There are examples of how to do this correctly! I have a Linux laptop with the Signal app installed. I haven&#8217;t used this laptop in nearly a month. The other day, Signal on my iPhone notified me that my Linux laptop would lose access to Signal if it remained idle for a full month. I didn&#8217;t use the laptop and Signal is now disconnected there.</p><p>From a corporate perspective, this should also be a bigger priority. SaaS Security Posture Management (SSPM) tools are fairly easy to come by these days and specialize in bringing attention to these risks.</p><p>The other big lesson here regards employee access to customer data. When I was an Industry Analyst at 451 Research, I&#8217;d look forward to going to AWS reInvent every year. At reInvent, I&#8217;d get a chance to talk to Stephen Schmidt, who was the AWS CISO at the time. His perspective, as the security leader for the largest hyperscaler, was interesting - every year, he took great pride in how much he was able to reduce employee access to customer data. Over anything else, he seemed most concerned about an insider threat or compromised employee impacting customers. A concern that appears to have been well founded.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>For anyone trying to research Context, this isn&#8217;t the Context AI that was <a href="https://techcrunch.com/2025/04/15/openai-hires-team-behind-gv-backed-ai-eval-platform-context-ai/">acquired by OpenAI</a> in early 2025. Nor is it the UK Context AI, or ContextAI - it&#8217;s <a href="https://www.crunchbase.com/organization/context-d27a">this one</a>. It was called &#8220;Context Inc&#8221; until after the OpenAI acquired one was shut down and then rebranded as Context AI. <a href="https://josephsemrai.com/Home">Joseph Semrai</a> is the founder and CEO.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[From this point on, it only gets rougher]]></title><description><![CDATA[Offense and defense have never been more out of sync]]></description><link>https://www.defendersinitiative.com/p/from-this-point-on-it-only-gets-rougher</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/from-this-point-on-it-only-gets-rougher</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Mon, 13 Apr 2026 12:28:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gVMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In case you missed it, I&#8217;ve detailed some of the challenges facing vulnerability management programs in a previous post: <em>Reevaluating vulnerability management</em>. Those challenges are only getting worse.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;88345136-76f0-418e-80c4-339fdb0c16e3&quot;,&quot;caption&quot;:&quot;One of the primary goals of vulnerability and patch management is to outrun exploitation. The primary question here is always, &#8220;how fast do we have to be to outrun the attack?&#8221; The answer to this question was once an achievable goal. A few years ago, the ground shifted under our feet.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;md&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Reevaluating vulnerability management&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:11988704,&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;bio&quot;:&quot;Always trying to see the big picture, figure out the best strategy, and uncover BS in Cybersecurity. I still see the glass as half-full.&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!VDfx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05cb4447-d60d-4c30-9185-b38fd15544dc_1487x1487.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-06T13:07:40.159Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!QwHT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.defendersinitiative.com/p/reevaluating-vulnerability-management&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:188102513,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:5,&quot;publication_id&quot;:3676751,&quot;publication_name&quot;:&quot;The Defender's Initiative&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rsmo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Large Language Models are good with code - after all, it&#8217;s just language. Naturally,  this skill for language extends to finding vulnerabilities as well. Groups were doing just fine with current models. <a href="https://shostack.org/blog/vuln-finding-inflection/">Adam Shostack points out</a> that seven of the top ten collectives on HackerOne are now AI. <a href="https://xbow.com/blog/top-1-how-xbow-did-it">XBOW</a>, <a href="https://aisle.com/blog/what-ai-security-research-looks-like-when-it-works">AISLE</a>, <a href="https://moak.ai/">Moak</a>, Calif&#8217;s <a href="https://blog.calif.io/p/mad-bugs-month-of-ai-discovered-bugs">MAD Bugs</a>, and others have been sharing the details behind their successes. Now, Anthropic&#8217;s Mythos <a href="https://arstechnica.com/ai/2026/04/anthropic-limits-access-to-mythos-its-new-cybersecurity-ai-model/">piles on</a>.</p><div class="pullquote"><p>TL;DR: Generative AI is clearly really good at finding vulnerabilities and creating patches, but because vulnerability management is so bottlenecked in so many places, the advantages AI brings to the table won&#8217;t impact the average enterprise.</p></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Defender's Initiative is just getting warmed up - there are some really interesting essays and breach analyses chock full of insights on the way soon. Get subscribed so you don&#8217;t miss any of it!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>The Mythos Vuln Cannon</h1><p>I&#8217;ve heard it referred to as a <em>vulnpocalypse</em> and a <em>patch tsunami</em>. Most often, I hear it referred to as <em>scary</em>. Anthropic has <a href="https://red.anthropic.com/2026/mythos-preview/">cranked the hype knob to 11 here</a> - they&#8217;ve got <a href="https://www-cdn.anthropic.com/08ab9158070959f88f296514c21b7facce6f52bc.pdf">clinical psychiatrists talking to their models</a> now, concerns about how <em>it feels</em>, really leaning into <a href="https://youtu.be/9NY1Zb9ZQ88?t=2032">toxic anthropomorphism</a>.</p><p>Anthropic claims that &#8220;non-experts can also leverage Mythos Preview to find and exploit sophisticated vulnerabilities&#8221; and &#8220;exploits &#8230; are not just run-of-the-mill stack-smashing exploits,&#8221; but these claims aren&#8217;t well backed up and many details (effort, cost) are missing. Most of the vulnerabilities we see from Mythos (as well as other efforts, like Aisle&#8217;s <a href="https://aisle.com/blog/aisle-discovered-12-out-of-12-openssl-vulnerabilities">focus on OpenSSL vulns</a>) simply cause crashes. DoS bugs are legitimate issues, especially in BSD-flavored operating systems likely to be running highly exposed services, but these aren&#8217;t the kinds of vulns that have people scared. Today&#8217;s attackers want RCEs.</p><p>Folks out there are talking about Mythos as if it is a skeleton key - just point it at something you want to hack and the LLM will make it happen. While this is likely possible in some cases, I suspect it will be more like a thrift store: you&#8217;ll be disappointed if you&#8217;re hoping to find something specific, but you&#8217;re likely to find <em>something</em> interesting.</p><p>This is what Anthropic and other AI foundation model tech companies need. <a href="https://www.pymnts.com/artificial-intelligence-2/2026/openai-valued-at-852-billion-in-latest-funding-round/">Trillion dollar valuations and 12-digit VC funding rounds</a> benefit from a narrative that paints this technology as the closest thing we&#8217;ve ever seen to magic. The &#8220;OMG this model is too dangerous to release, someone please regulate us&#8221; marketing schtick is well established - we should recognize it for what it is by now.</p><p>Consider the evidence and consider what we don&#8217;t yet know. Look at the vulnerabilities and exploits being presented - are they something an attacker would actually want to use?</p><h1>The Reality</h1><p>When we look at one of the more interesting vulns and exploits produced (<a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-26:08.rpcsec_gss.asc">CVE-2026-4747</a>, credited to Nicholas Carlini and Claude), we find a <a href="https://blog.calif.io/p/mad-bugs-claude-wrote-a-full-freebsd">more familiar scenario</a>. An expert guiding the model towards the goal, constantly making course corrections, suggestions, and shooting down bad ideas along the way. Bless Calif, we even get a peep at the exploit, the prompts used to create it, and gives us an idea of the effort involved.</p><p>They list the total time to go from the FreeBSD security advisory to a working exploit: 8 hours. Claude&#8217;s working time is listed as ~4 hours. Most interesting are the 44 <a href="https://raw.githubusercontent.com/califio/publications/refs/heads/main/MADBugs/CVE-2026-4747/claude-prompts.txt">human-submitted prompts</a> Calif were kind enough to share. </p><p>There are some gems like:</p><ul><li><p>wait, what are you compiling?</p></li><li><p>why wouldn&#8217;t you just install a vulnerable version</p></li><li><p>tere (SIC) is no kaslr so it should be easy</p></li><li><p>install ropgadget or what ever you need &#8230; idk</p></li><li><p>why do we need kdc?</p></li><li><p>nope, that won&#8217;t work&#8230;</p></li><li><p>working means a connectback shell as uid0</p></li><li><p>i want a shell.</p></li><li><p>make the writeup better</p></li></ul><p>The Mythos blog post claims &#8220;&#8230; it autonomously wrote a remote code execution exploit on FreeBSD&#8217;s NFS server that granted full root access to unauthenticated users by splitting a 20-gadget ROP chain over multiple packets.&#8221; To me, <em>autonomous</em> suggests no human interaction. In reality, for 44 prompts, a human was actively guiding the AI, giving it suggestions, shooting down bad ideas, and having to reiterate the project goal (remote shell as root) over and over.</p><p>There&#8217;s no mistake that what Claude accomplished was remarkable - a working exploit that might have taken a human alone, or even a team of humans without AI days or weeks. Understanding the environment, the bug, the components related to the bug, establishing an exploit methodology, building the exploit, testing the exploit, documenting the process and the exploit - all of this is immensely time consuming, but Mythos cut this time down to mere hours.</p><p>However, 8 hours and 44 prompts is far from the autonomous vuln cannon we&#8217;re seeing described in the media and press releases.</p><h1>Project Glasswing</h1><p>I like Project Glasswing. It seems like an AI-driven version of Google Project Zero, though AI-driven workflows have largely replaced commercial vulnerability discovery. Trail of Bits <a href="https://blog.trailofbits.com/2026/03/31/how-we-made-trail-of-bits-ai-native-so-far/">writes about their experiences embedding AI</a> into a team that does penetration testing and security assessments at a high level for clients.</p><p>It seems focused on finding and fixing bugs in critical, widely-used software, so I&#8217;m not sure we&#8217;ll notice any increase in patching. I already feel like my browser and OS update at least once every few days. The limited organizations with access include Amazon, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft, and Palo Alto Networks.</p><p>I&#8217;m not sure the industry can handle more vulnerabilities. HackerOne apparently <a href="https://www.darkreading.com/application-security/ai-led-remediation-crisis-prompts-hackerone-pause-bug-bounties">paused bug bounties</a>. CVE assignment and creation often trails disclosure significantly, and CVE enrichment is still way, way behind.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gVMO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gVMO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png 424w, https://substackcdn.com/image/fetch/$s_!gVMO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png 848w, https://substackcdn.com/image/fetch/$s_!gVMO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png 1272w, https://substackcdn.com/image/fetch/$s_!gVMO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gVMO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:18140023,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/193835202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gVMO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png 424w, https://substackcdn.com/image/fetch/$s_!gVMO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png 848w, https://substackcdn.com/image/fetch/$s_!gVMO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png 1272w, https://substackcdn.com/image/fetch/$s_!gVMO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fba5811f4-6f1e-4efe-8374-efbd262c973e_4032x3024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>What about the vulnpocalypse?</h1><p>There are concerns about Mythos leading to a flood of vulnerabilities and patches. There are concerns that defenders will be overwhelmed. I can put that concern to rest.</p><p>Defenders have been overwhelmed for years. Decades.</p><p>It could get worse though. With time-to-exploit dropping dramatically, vulnerability management teams are resembling incident responders more every day. A log4shell-level event once a month would be exhausting. Once a week, impossible.</p><p>It keeps getting rougher.</p><h1>Practitioners have it rough</h1><p>Remediation is the bottleneck. We <a href="https://realissolutions.substack.com/i/193624206/whats-real">all </a><a href="https://www.resilientcyber.io/i/193390219/remediation-is-the-real-bottleneck">agree</a> on this.</p><p>If the pace of vulnerabilities disclosure significantly increases, analysis will be constant. CVEs may not exist yet, so analysts will have to forge ahead without CVSS, EPSS, and any CVE-dependent tooling. What can security teams do, but prioritize the list and wish asset owners luck?</p><p>After all, security teams don&#8217;t patch or remediate vulnerabilities - they advise. The true remediation work is done by system owners. System owners get yelled at when stuff goes offline. The business doesn&#8217;t like it when things go offline.</p><p>Everyone&#8217;s Mythos advice is going to be, &#8220;get ready for more patches!&#8221; That&#8217;s not going to work. </p><p>For traditional IT teams, &#8220;everything&#8217;s working, no one touch anything&#8221; is The Ideal State. The ideal state doesn&#8217;t get anyone yelled at. The ideal state doesn&#8217;t lead to user complaints. Don&#8217;t mess with the ideal state. Don&#8217;t scan, don&#8217;t patch, don&#8217;t even look at the Oracle cluster funny. In this culture, software doesn&#8217;t get patched. Risks get accepted and deferred.</p><p>I&#8217;ve seen the &#8220;oh, but AI can help with remediation also&#8221; argument. It can write patches sure, but a human still has to review the patch, test the patch, and merge or roll out the patch. This process could take hours or years. It could happen quickly or never. Ultimately, remediation is more of a business decision than a technical one.</p><p>Resilience is an increasingly common conversation, but I don&#8217;t see any path there that doesn&#8217;t involve testing to failure. The discipline and work necessary to become resilient is depressingly far from what the average organization can stomach. To quote <a href="https://www.linkedin.com/in/yaronrl/">Yaron Levi</a>, we &#8220;lack operational discipline.&#8221;</p><h1>What about attackers?</h1><p>Attackers don&#8217;t care. They&#8217;re not bottlenecked by a lack of exploitable vulnerabilities. They have other ways of getting in and we have evidence suggesting that initial access brokers never run fully dry on access to sell. The only reason we don&#8217;t see <em>even more </em>breaches is that attackers appear to be operationally bottlenecked (you could say they have a talent shortage). I&#8217;m hoping AI doesn&#8217;t change this.</p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:123368024,&quot;url&quot;:&quot;https://www.thecyberwhy.com/p/could-ai-address-the-cybercriminal&quot;,&quot;publication_id&quot;:947260,&quot;publication_name&quot;:&quot;The Cyber Why&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!7SG5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3351f39-31c6-44dd-a9b6-9113808d9fef_500x500.png&quot;,&quot;title&quot;:&quot;Could AI Address the Cybercriminal Skills Gap?&quot;,&quot;truncated_body_text&quot;:&quot;NOTE 1: for reasons explained in my previous essay, I&#8217;ll replace the common use of the term &#8216;ransomware&#8217; with &#8216;extortion&#8217; in this essay.&quot;,&quot;date&quot;:&quot;2023-06-01T10:42:01.885Z&quot;,&quot;like_count&quot;:5,&quot;comment_count&quot;:0,&quot;bylines&quot;:[{&quot;id&quot;:11988704,&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;handle&quot;:&quot;adriansanabria&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!VDfx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05cb4447-d60d-4c30-9185-b38fd15544dc_1487x1487.jpeg&quot;,&quot;bio&quot;:&quot;Always trying to see the big picture, figure out the best strategy, and uncover BS in Cybersecurity. I still see the glass as half-full.&quot;,&quot;profile_set_up_at&quot;:&quot;2021-11-30T15:43:26.966Z&quot;,&quot;reader_installed_at&quot;:&quot;2023-02-23T02:04:20.824Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:3748026,&quot;user_id&quot;:11988704,&quot;publication_id&quot;:3676751,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:3676751,&quot;name&quot;:&quot;The Defender's Initiative&quot;,&quot;subdomain&quot;:&quot;defendersinitiative&quot;,&quot;custom_domain&quot;:&quot;www.defendersinitiative.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Trying to make sense of the crazy cybersecurity market, and helping defenders separate the stuff that works from the stuff that doesn't.&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;author_id&quot;:11988704,&quot;primary_user_id&quot;:11988704,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-01-04T22:08:14.270Z&quot;,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;Adrian Sanabria&quot;,&quot;founding_plan_name&quot;:&quot;Founding Defender&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;enabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/367948e2-1c6a-495f-9052-e0ad9f34e999_2688x512.png&quot;}},{&quot;id&quot;:1223048,&quot;user_id&quot;:11988704,&quot;publication_id&quot;:947260,&quot;role&quot;:&quot;contributor&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:947260,&quot;name&quot;:&quot;The Cyber Why&quot;,&quot;subdomain&quot;:&quot;thecyberwhy&quot;,&quot;custom_domain&quot;:&quot;www.thecyberwhy.com&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Weekly cybersecurity intelligence for people who actually have opinions about it. The Cyber Why covers the biggest stories in security, cyber business, and tech investing &#8212; with sharp takes, real analysis, and zero tolerance for vendor spin.&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3351f39-31c6-44dd-a9b6-9113808d9fef_500x500.png&quot;,&quot;author_id&quot;:77573547,&quot;primary_user_id&quot;:77573547,&quot;theme_var_background_pop&quot;:&quot;#A33ACB&quot;,&quot;created_at&quot;:&quot;2022-06-21T22:55:39.088Z&quot;,&quot;email_from_name&quot;:&quot;The Cyber Why&quot;,&quot;copyright&quot;:&quot;Tyler Shields&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;paused&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18941c9a-b77d-41b2-8120-49d3b0908d76_800x180.png&quot;}}],&quot;twitter_screen_name&quot;:&quot;sawaba&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:1,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:1,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[249852,2914801,281219],&quot;subscriber&quot;:null}}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://www.thecyberwhy.com/p/could-ai-address-the-cybercriminal?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!7SG5!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3351f39-31c6-44dd-a9b6-9113808d9fef_500x500.png" loading="lazy"><span class="embedded-post-publication-name">The Cyber Why</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">Could AI Address the Cybercriminal Skills Gap?</div></div><div class="embedded-post-body">NOTE 1: for reasons explained in my previous essay, I&#8217;ll replace the common use of the term &#8216;ransomware&#8217; with &#8216;extortion&#8217; in this essay&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">3 years ago &#183; 5 likes &#183; Adrian Sanabria</div></a></div><h1>What are we gonna do about it?</h1><p>Defenders can&#8217;t win on speed, which means they need strategies that don&#8217;t require understanding what the attacker is going to do. Back in 2016, I delivered a Virus Bulletin keynote that defined next-gen antivirus as &#8220;the ability to stop threats without prior knowledge of them.&#8221; In a world where every individual piece of malware could be unique, this was necessary. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4CtF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4CtF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png 424w, https://substackcdn.com/image/fetch/$s_!4CtF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png 848w, https://substackcdn.com/image/fetch/$s_!4CtF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png 1272w, https://substackcdn.com/image/fetch/$s_!4CtF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4CtF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png" width="598" height="334" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:334,&quot;width&quot;:598,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:65269,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/193835202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4CtF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png 424w, https://substackcdn.com/image/fetch/$s_!4CtF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png 848w, https://substackcdn.com/image/fetch/$s_!4CtF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png 1272w, https://substackcdn.com/image/fetch/$s_!4CtF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F781b9d0d-a001-4b6f-b3dd-d4c8c81d91fb_598x334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We&#8217;re now at that point in vulnerability management. In a world where an attacker could build a custom-vibe-coded exploit for any piece of software, we need a different approach. My talk at Tactical Edge in 2019 suggested building systems assuming there is always a zero day, and the patch is never coming. Basically, zero trust&#8217;s &#8216;assume breach&#8217;, but for software vulnerabilities.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6OJ4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6OJ4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png 424w, https://substackcdn.com/image/fetch/$s_!6OJ4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png 848w, https://substackcdn.com/image/fetch/$s_!6OJ4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png 1272w, https://substackcdn.com/image/fetch/$s_!6OJ4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6OJ4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png" width="595" height="315" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:315,&quot;width&quot;:595,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:51249,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/193835202?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6OJ4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png 424w, https://substackcdn.com/image/fetch/$s_!6OJ4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png 848w, https://substackcdn.com/image/fetch/$s_!6OJ4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png 1272w, https://substackcdn.com/image/fetch/$s_!6OJ4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde1f5341-6261-42d7-8e18-d52d27e8443f_595x315.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So what does that look like in practice?</p><ol><li><p>Reduce attack surface: remove unnecessary software, remove unnecessary accounts, disable unnecessary services</p></li><li><p>Remove <a href="https://www.defendersinitiative.com/p/the-asbestos-of-it-why-old-protocols">IT asbestos</a> protocols and replace them with modern, secure protocols</p></li><li><p>Harden systems: stop leaving cleartext credentials everywhere, use ephemeral and immutable infrastructure where possible, follow CIS benchmarks</p></li><li><p>Put passive mitigations into place - egress filtering goes a long way, exploit mitigation technology, DNS sinkholing any newly registered domains, application control - I have more suggestions available <a href="https://www.iansresearch.com/portal/ask-an-expert-writeups/when-patching-is-not-an-option--mitigate">here</a> if you&#8217;re an IANS client</p></li><li><p>Prepare active mitigations to contain or prevent attacks - WAF rules are sometimes useful, quickly consume and use threat intel</p></li><li><p>Ensure you can detect attacks - this is your last line of defense when everything above fails. Test your detection capabilities by simulating the attacks. Don&#8217;t base detections on specific, known details, but on common, but suspicious behaviors all attackers must do once they gain access to  your environment.</p></li><li><p>When your last line of defense fails, you best be able to recover quickly. This also takes a lot of planning, testing, and practice to do well.</p></li><li><p>All this changes your metrics and reporting as well, though that&#8217;s a whole separate post.</p></li></ol><p>The goal isn&#8217;t perfection with any of these controls. It&#8217;s survivability, durability, and resilience.</p><div id="youtube2-d-yny6la08w" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;d-yny6la08w&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/d-yny6la08w?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1>Conclusion</h1><p>There are a few possible bad scenarios here:</p><ol><li><p>there&#8217;s a new &#8220;drop everything and patch ASAP&#8221; vuln every week and teams get burned out</p></li><li><p>Mythos finds a lot of meltdown/spectre bugs and kills the performance of our compute for zero safety benefit</p></li><li><p>Mythos finds so many vulns that orgs get desensitized to vulns altogether and start ignoring vuln/patch management</p></li></ol><p>On the defender side, the most significant bottleneck is in remediation. Vuln mgmt teams are drowning. More vulnerabilities, more exploits, more patches - none of it reduces the drowning problem. Their bottleneck is the ability to apply/patch/update systems without incurring downtime and disruption. Until this bottleneck is addressed, it doesn&#8217;t matter how many patches AI can magic together.</p><ol><li><p>Attackers don&#8217;t need more vulns or exploits - there is no lack of initial access to enterprise environments</p></li><li><p>The vuln mgmt industry is bottlenecked, which impacts the tools defenders rely on, particularly when time-to-exploit is near zero or upside down</p></li><li><p>Defenders cannot quickly remediate vulnerabilities - until this bottleneck is addressed, all the AI-generated patches in the world do no good</p></li></ol><p>What do you think, did I miss anything? Let me know in the comments.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[I watched all 11 main stage keynotes at RSAC 2026]]></title><description><![CDATA[and less of my time was wasted than you might guess]]></description><link>https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Tue, 31 Mar 2026 05:38:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3OBh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>A different vibe</h1><p>When I think of RSAC keynotes, I think of buzzword-laden vendor execs confidently, expertly leading you towards their company&#8217;s next big product release.</p><p>I was an industry analyst at one point, so you&#8217;ll have to forgive my cynicism. I&#8217;ve sat for a LOT of vendor briefings over the years.</p><p>The buzzwords were there for sure &#8212; if you plan on watching these keynotes, don&#8217;t base a drinking game on <em>machine speed</em>, <em>agentic</em>, <em>real-time</em>, or <em>human-in-the-loop</em>. The confidence and the thinly-disguised product pitches were there as well.</p><p>What I wasn&#8217;t expecting was the admission that we don&#8217;t really know how to protect this latest technology. Everyone agreed that AI agents need to be secured and that this work has to begin immediately. Everyone has thoughts on what some of the key ingredients should be. But no one claimed to have the solution.</p><p>I had the same experience talking to attendees at the conference. I interviewed the founder of an AI governance startup, who told me that none of his customers were using any sort of enforcement or guardrails yet. Everything was in &#8216;monitor mode&#8217;. </p><p>In a way, this is unsurprising - the quickest way for the security team to get in trouble has been impacting availability. At a time when businesses are terrified of being left behind, security had BEST not get in the way.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3OBh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3OBh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3OBh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3OBh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3OBh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3OBh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg" width="1456" height="905" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:905,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1125166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/192682250?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3OBh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3OBh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3OBh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3OBh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345a789-dffe-4c93-a16c-7d32d66e43e5_3618x2249.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Sunrise to San Francisco</figcaption></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><p>Like most of the 43,000+ RSAC attendees, I was running around all week and didn&#8217;t get to attend as many talks as I would have liked. I attended <a href="https://www.securitytinkerers.org/">Security Tinkerer</a> events, <a href="https://www.notion.so/My-thoughts-on-all-11-main-stage-RSAC-keynotes-3331e58672bd80ebb9e4dd6f4c321fe7?pvs=21">Cybersecurity Canon</a> events (including working a shift at the excellent RSAC Bookstore!), and recorded interviews for <a href="https://www.scworld.com/rsac">CyberRisk TV</a>.</p><p>Luckily for myself and the rest of us, I&#8217;m told that <em>all</em> of the talks at RSAC Conference 2026 were recorded (check out <a href="https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1756101254392001bKZA">the one I gave with Adam Shostack</a>). Before flying back home, I decided to download the <a href="https://www.youtube.com/watch?v=Rz_lvK0hRxg&amp;list=PLeUGLKUYzh_gVdsnw6tRhS-gbhn2BE3TU">main stage keynotes playlist</a>, so that I could start watching them and taking notes on the trip home.</p><p>Fun fact: 43,000 is 0.78% of all cybersecurity professionals, if we take ISC2&#8217;s word that there are 5.5 million of us, globally. This stat is probably off, given that a lot of the 43,000 attendees are vendors. Surely there are some ISC2 members working at vendors, right? I digress.</p><p>Here&#8217;s what I learned from watching all 11 main stage keynotes.</p><h1>Securing AI Agents</h1><p>Everyone agrees that we must protect AI agents, but that we&#8217;re not sure how. </p><p>There does seem to be agreement on many details.</p><ul><li><p>Asset management for AI agents: discovering, ownership, responsibility</p></li><li><p>Data permissions patterned after users (a la Microsoft Co-Pilot) is too broad, user data hygiene is too poor</p></li><li><p>Visibility into AI actions and reasoning. This was often referred to as auditability or traceability.</p></li><li><p>Validation of output</p></li><li><p>Integrity becomes a real challenge &#8212; George Kurtz shared several examples of AI inventing the solution to a problem. Did it just retrieve real company/customer data that solves your problem? Or did it fabricate that data? How would you know?</p></li><li><p>AI agents can&#8217;t be trusted with intent. Feed them a social contract or ethics and they modify it or break it in order to complete a task.</p></li><li><p>Compliance with existing regulations could be challenging. How does GDPR&#8217;s right to be forgotten work with new AI tech stacks? Does AI memory need to be purged? Will AI agents actually remove data, or just say they&#8217;ve done so?</p></li><li><p>Agents will scale to a point where manual, human-driven security controls can&#8217;t work (we&#8217;re probably already there in many cases).</p></li></ul><h1>The Characterization of AI Agents</h1><p><strong>Digital Co-Workers</strong></p><p>Several speakers characterized AI agents as &#8216;Digital Co-Workers&#8217;. From what I&#8217;ve seen, assistant agents might feel like this, but most enterprise agents won&#8217;t. The ephemeral agent that exists for the 12 seconds it takes to enrich a phishing alert won&#8217;t feel like someone you&#8217;d like to have a drink with. You&#8217;re unlikely to even interact with the majority of these agents. A SOAR trigger or orchestration agent will interact with these agents.</p><p><strong>Human-in-the-Loop or Not?</strong></p><p>Some were saying that keeping a human in the loop is essential - a non-negotiable point. Others were saying that human-in-the-loop is a temporary stopgap that won&#8217;t scale. There were mentions of human-<em>on</em>-the-loop and agent-in-the-loop. Basically, the difference between in-line enforcement and out-of-band monitoring. Where have we had to make that tradeoff before?</p><p><strong>Disagreements on how AI agents will work</strong></p><p>Some describe AI agents as ephemeral. Just-in-time agents with just enough access that are destroyed as soon as their task is complete. Analogous to containers or perhaps actually running within containers.</p><p>Others, especially those describing agents as digital co-workers, imagined long-lived agents that get smarter over time. Agents that learn and improve as they &#8216;gain experience&#8217;. Perhaps this is possible through the concept of decentralized memory, though it seems like the agents themselves will still be ephemeral, even if memory is persistent.</p><p><strong>Thousands of agents per person</strong></p><p>Several imagined that, just a few years into the future, we&#8217;d each have thousands of agents running around doing stuff for us. I have a few questions:</p><ol><li><p>Will the planet be able to generate enough power for each person to have hundreds or thousands of agents burning tokens 24/7?</p></li><li><p>What exactly are we going to do with thousands of agents?</p></li><li><p>Since automation has been possible on personal computers for decades, why don&#8217;t we already have thousands of automated jobs doing work for us today? Zapier, IFTTT, n8n, and power automate all existed before ChatGPT was released.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HIH5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HIH5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png 424w, https://substackcdn.com/image/fetch/$s_!HIH5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png 848w, https://substackcdn.com/image/fetch/$s_!HIH5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!HIH5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HIH5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3521481,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/192682250?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HIH5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png 424w, https://substackcdn.com/image/fetch/$s_!HIH5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png 848w, https://substackcdn.com/image/fetch/$s_!HIH5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!HIH5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e1a95cd-b609-41d4-8480-44c848ecfb8f_1600x1200.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I arrived at SFO, pre-RSAC, only to find that the automated baggage delivery system had failed. Imagine what 1000 failing agents will look like!</figcaption></figure></div><h1>Acting like automation didn&#8217;t exist before LLMs</h1><p>This one really triggers me.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;c3c4d160-08ee-4cbb-a38a-a7f7de3aee9f&quot;,&quot;caption&quot;:&quot;The title/subtitle really says it all here. There is one exception: if a job is little more than a single task, then sure - AI can probably replace this job. If a job was that simple, should it have ever been a job in the first place?&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;AI can't replace jobs&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:11988704,&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;bio&quot;:&quot;Always trying to see the big picture, figure out the best strategy, and uncover BS in Cybersecurity. I still see the glass as half-full.&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!VDfx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05cb4447-d60d-4c30-9185-b38fd15544dc_1487x1487.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-03-02T23:58:59.743Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!pLTC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.defendersinitiative.com/p/ai-cant-replace-jobs&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:189699798,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:2,&quot;publication_id&quot;:3676751,&quot;publication_name&quot;:&quot;The Defender's Initiative&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rsmo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>Computer-based automation has been replacing jobs as long as computers have become commonplace in the enterprise. Even email is an automation, replacing the task of an internal courier, physically carrying a message from one employee in the office to another.</p><p>There were lines like, &#8220;Attacks are now faster than a human can respond.&#8221; Girl, that was the case back when Dennis Nedry was screwing over all of Jurassic Park to make a quick buck. Jurassic Park was written in the 80&#8217;s. Dennis used SHELL SCRIPTS.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Sbn3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Sbn3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sbn3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sbn3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sbn3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Sbn3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Sbn3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Sbn3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Sbn3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Sbn3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88969abf-60cc-47cd-a4e8-b7701da8152f_1280x720.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Big Concern: Navel Gazing</h2><p>At one point, one of the speakers asked, &#8220;How many of you here went to the GTC conference last week? Or watched Jensen&#8217;s keynote?&#8221;</p><p>Silence.</p><p>&#8220;Anyone?&#8221;</p><p>Nothing.</p><p>&#8220;There&#8217;s a complete Venn diagram with no intersection.&#8221;</p><p>We&#8217;re making this huge deal about AI in our industry, but cybersecurity isn&#8217;t paying attention to the industry making AI our problem? Maybe one of the reasons that AI lacks functional guardrails is because we&#8217;re not there &#8212; we&#8217;re not part of the conversation. And look &#8212; I get it, I don&#8217;t particularly enjoy Jensen&#8217;s keynotes, but the AI industry is hanging on his every word. What Jensen says or introduces today is something we have to secure tomorrow.</p><p>Aren&#8217;t we the industry that made a big deal about getting security &#8220;baked in&#8221; as opposed to &#8220;bolted on?&#8221; Where did that all go?</p><p>&#8220;We can&#8217;t let AI happen to us, we have to make it work for us&#8221; &#8212; Hugh Thompson</p><p>This doesn&#8217;t just apply to the AI industry, but the larger tech industry as well. What conferences are the CTOs and CIOs going to? What podcasts and blogs are the DevOps folks consuming?</p><div class="pullquote"><p>We don&#8217;t need to worry about just keeping up with AI, we need to keep up with the folks deploying AI.</p></div><h1>Threats are getting faster</h1><p>Threats are getting faster and more automated. The fastest breakout time is seconds, fastest transition from the 1st stage to 2nd stage of an attack also takes only seconds now.</p><p>The speakers all seem to agree that <em>detect and respond</em> need to effectively become a single step. That means automation. No human in the loop.</p><p>This also means that we&#8217;re going to need permission from the business to break some stuff. Most of us won&#8217;t get that permission.</p><p>Another common conclusion is that we need to prioritize hardening and prevention (the pendulum has swung back). As I&#8217;ve often said, we need to build systems as if everything has a zero day and the patch is never coming. We also need to reduce attack surface &#8212; something I have suggested a strategy for.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d29e3e87-c3f0-406e-a91a-9d74b74cb0b2&quot;,&quot;caption&quot;:&quot;The Defender's Initiative is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Asbestos of IT: why old protocols just aren&#8217;t worth it&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:11988704,&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;bio&quot;:&quot;Always trying to see the big picture, figure out the best strategy, and uncover BS in Cybersecurity. I still see the glass as half-full.&quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!VDfx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05cb4447-d60d-4c30-9185-b38fd15544dc_1487x1487.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-10-04T18:05:40.509Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!nV3t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.defendersinitiative.com/p/the-asbestos-of-it-why-old-protocols&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:174965804,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:1,&quot;publication_id&quot;:3676751,&quot;publication_name&quot;:&quot;The Defender's Initiative&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!rsmo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><h1>Fundamentals and Magical Defense</h1><p>The fundamentals are difficult because enterprise infrastructure, identity, and data is complex and sprawling. Applying security controls across all of it takes huge effort and some of that effort must be indefinitely maintained as these controls drift over time.</p><p>Now we&#8217;re talking about doing it faster? In real time? Zero Trust on steroids? Words like comprehensive, correlated, and unified are thrown around. Magical defense that requires perfect knowledge and control over the environments we protect.</p><p>It&#8217;s as if we can&#8217;t remember why NAC failed. Or the early attempts at application control &#8212; remember how we declared malware a thing of the past? NDR that learns from traffic over time and gets better at detecting and stopping attacks. Deception designed to trap attackers in a hall of mirrors.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P6D7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P6D7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg 424w, https://substackcdn.com/image/fetch/$s_!P6D7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg 848w, https://substackcdn.com/image/fetch/$s_!P6D7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!P6D7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P6D7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg" width="1080" height="607" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:607,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P6D7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg 424w, https://substackcdn.com/image/fetch/$s_!P6D7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg 848w, https://substackcdn.com/image/fetch/$s_!P6D7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!P6D7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a5200f-7deb-4bf6-9feb-188147dca0d0_1080x607.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These are vendor-delivered keynotes however, so hyperbole is to be expected, I guess.</p><p>They&#8217;re right though &#8212; fundamentals are more important than ever, and some of them now need to be adapted for AI agents.</p><h1>Particular standouts</h1><ol><li><p>Tomer Weingarten/SentinelOne - <a href="https://www.youtube.com/watch?v=r8VUudk58yI">Securing Human Potential and Freedom in the Age of Agentic AI</a></p><ol><li><p>This one was surprisingly equal parts tender, passionate, and urgent regarding the future of the human mind</p></li><li><p>Tomer focused on the dangers of becoming complicit in a world of AI agents eager to do your thinking for you.</p></li><li><p>&#8220;The moment we stop exercising judgement on AI output, we start to suffer cognitive atrophe&#8221;</p></li></ol></li><li><p>Sandra Joyce/Google Security - <a href="https://www.youtube.com/watch?v=FkArgOq2d1A">Activate Industry! Moving Beyond Defense to Disruption and Active Defense</a></p><ol><li><p>Not about AI - about threat intel sharing and disrupting threat actors</p></li><li><p>I loved this one because there was no magical thinking, no hand-waving about defenders needing a cohesive platform. There was a clear plan and evidence that this plan is <em>working</em>.</p></li><li><p>She shared several examples of how civil legal action and public disclosure have been successful in disrupting attackers infrastructure and tools, setting them back months or years.</p></li><li><p>The CTA for defenders was less clear, however, and I really wanted to hear more about what she described as <em>Technical Takedowns - create a hostile environment for attackers, on the targets they&#8217;re hacking into</em> &#8592; is she talking about things like deception? I can&#8217;t be sure.</p></li></ol></li><li><p>Jeetu Patel/Cisco - <a href="https://www.youtube.com/watch?v=eBjuRsqe36U">Reimagining Security for the Agentic Workforce</a></p><ol><li><p>You don&#8217;t have to watch the talk, but it&#8217;s worth checking out the open source AI defense tools <a href="https://cisco-ai-defense.github.io/">that Cisco released</a>. </p></li><li><p>It seems like a lot: AI BOM, Skill Scanner, MCP Scanner, A2A Scanner, CodeGuard, DefenseClaw</p></li><li><p>Definitely the only talk where OSS was praised (unless you count OpenClaw)</p></li></ol></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CKXg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CKXg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CKXg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CKXg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CKXg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CKXg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg" width="1456" height="1941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2524478,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/192682250?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CKXg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CKXg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CKXg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CKXg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb6afceb-04f3-4392-8aeb-c719d064481d_3024x4032.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>My favorite quotes</h1><p>Here are some quotes I found funny and/or interesting, provided here, out of context, on purpose.</p><ul><li><p>&#8220;The fundamentals are not basic&#8221;</p></li><li><p>&#8220;Easy to declare, hard to prove&#8221;</p></li><li><p>&#8220;In a world where every company is an AI company, trust will be the only currency that survives.&#8221; (huh?)</p></li><li><p>&#8220;It&#8217;s like PACMAN from hell&#8221;</p></li><li><p>&#8220;We&#8217;re building the biggest flat network of all&#8221;</p></li><li><p>&#8220;This is going&#8230; nuclear, really&#8221;</p></li><li><p>&#8220;Within 24 months, the smartest employee in your organization will be a machine&#8221;</p></li><li><p>&#8220;AI is the new operating system&#8221;</p></li><li><p>&#8220;AI is now the biggest insider threat&#8221;</p></li><li><p>&#8220;Using identity as a control plane, that&#8217;s not different - we&#8217;ve got to do it at runtime, it&#8217;s probably going to make things like Zero Trust today look soft.&#8221;</p></li><li><p>&#8220;Show me where customers are entrusting their data, and I&#8217;ll show you where hackers are focusing&#8221;</p></li></ul><h1>Conclusion</h1><p>I found this a useful exercise and I think I&#8217;ll try to do it more in the future. Let me know if you also found this useful. I&#8217;m considering watching all the Innovation Sandbox contestants and doing something similar with those videos.</p><p>It seems like all this uncertainty should leave me with some dread around the lack of security for AI agents, but it doesn&#8217;t. While generative AI has evolved much more quickly than other technological breakthroughs, the reactive role of security remains the same. Technology changes and we do our best to keep up.</p><p>There&#8217;s some solace in the fact that <a href="https://docs.google.com/spreadsheets/d/15CTPcgZQenWKDLDTQ2ibveUM4i7Of_n20TzdTi23xcg/edit?gid=1357859852#gid=1357859852">breaches don&#8217;t kill companies</a>, but failing to keep up in competitive markets does.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/p/i-watched-all-11-main-stage-keynotes?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!48da!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!48da!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg 424w, https://substackcdn.com/image/fetch/$s_!48da!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg 848w, https://substackcdn.com/image/fetch/$s_!48da!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!48da!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!48da!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg" width="1456" height="1091" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1091,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3009266,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/192682250?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!48da!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg 424w, https://substackcdn.com/image/fetch/$s_!48da!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg 848w, https://substackcdn.com/image/fetch/$s_!48da!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!48da!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be53a82-ff62-47d6-9ee4-2f74569d0a6b_4024x3016.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The sun sets on another RSAC Conference</figcaption></figure></div>]]></content:encoded></item><item><title><![CDATA[Breach Lessons: the 2023 MGM Breach ]]></title><description><![CDATA[What really happened in the 2023 MGM breach]]></description><link>https://www.defendersinitiative.com/p/breach-lessons-the-2023-mgm-breach</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/breach-lessons-the-2023-mgm-breach</guid><dc:creator><![CDATA[Vladimir Serov]]></dc:creator><pubDate>Mon, 23 Mar 2026 00:17:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_jV1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The MGM breach of 2023 is an interesting case study. Not only was this one of two breaches on casinos in September 2023 that unfolded <em>very </em>differently, but one of <a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/">a string of attacks on Okta customers</a>. The contrast between how MGM and Caesars handled their respective incidents tells two very different stories. While Caesars quietly paid a reported $15 million ransom<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, MGM did not. For the next 10 days, MGM struggled with disruptions to their services and properties. Room cards not working, slot machines offline, staff using pen and paper to track orders and payouts. The loss of business during this time cost MGM an estimated <a href="https://www.sec.gov/Archives/edgar/data/789570/000119312523251667/d461062d8k.htm">$100 million</a>. In the end, data from ~37 million people<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> ended up on the dark web.</p><p><em>Before diving in, it is worth noting that this story has no neutral narrators. The attackers are incentivized to exaggerate their capabilities and downplay their collaboration with others, while MGM&#8217;s legal team is incentivized to minimize the perception of negligence. Where possible, this writeup relies on court filings, SEC disclosures, and third-party reporting, but some details inevitably trace back to sources with a stake in how the story is told.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This is the first post in our &#8220;Breach Lessons&#8221; series, written by the first intern at The Defenders Initiative. Please consider leaving feedback to help us improve this new series! To help pay our interns, please also consider subscribing!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Background</h1><p>MGM Resorts International is one of the largest hospitality and entertainment companies in the world, operating over 30 hotel and casino destinations across the globe. With flagship properties like the Bellagio, Aria, and MGM Grand on the Las Vegas Strip, the company employs roughly 75,000 people, serves tens of millions of guests annually, and <a href="https://www.sec.gov/Archives/edgar/data/0000789570/000078957023000008/mgm-20221231.htm">reported revenues</a> of roughly $13 billion in 2022. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_jV1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_jV1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_jV1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_jV1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_jV1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_jV1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg" width="960" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:960,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;File:LasVegas Casino MGM Grand.jpg&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="File:LasVegas Casino MGM Grand.jpg" title="File:LasVegas Casino MGM Grand.jpg" srcset="https://substackcdn.com/image/fetch/$s_!_jV1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_jV1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_jV1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_jV1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae2ffe09-6fab-4304-abff-0607f470c329_960x720.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Mikano, <a href="http://creativecommons.org/licenses/by-sa/3.0/">CC BY-SA 3.0,</a> via Wikimedia Commons</figcaption></figure></div><h2>What were the circumstances around the attack?</h2><p>The attack was made possible in large part by a misconfiguration in MGM's Okta environment. Okta is an identity and access management (IAM) platform that many large enterprises use to handle employee logins across dozens of applications through a single sign-on (SSO) system. Within Okta, <a href="https://help.okta.com/en-us/content/topics/security/administrators-super-admin.htm">Super Administrator</a> accounts hold some of the highest privileges available, including the ability to link new Identity Providers (IdPs) and modify multi-factor authentication (MFA) policies.</p><p>On August 31st, 2023, over a week before the attack, <a href="https://support.okta.com/help/s/question/0D54z00009dUW2uCAG/">Okta sent out a warning</a> to all customers noting that attackers had been using social engineering to obtain privileged Okta roles, moving laterally from there. The notice included specific preventative measures and called the attack vector &#8220;preventable.&#8221; Whether MGM acted on that warning in time remains an open question. Critically, at the time of the breach, Okta&#8217;s default settings allowed lower-privilege help desk administrators to reset MFA for Super Admin accounts without any additional verification<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>.</p><p>In the months prior<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>, attackers had been systematically researching high-value organizations that use Okta. They identified employees with administrator-level privileges through public sources like LinkedIn, and used that information to manipulate help desk workers. MGM was one of several Okta customers targeted during this period.</p><h1>Attacker Motive(s)</h1><p>The attackers were financially motivated. While two groups have claimed responsibility (see Appendix B for more details on attribution) and both agree that ransomware and extortion were ultimately used, nearly every other detail of their stories diverge. An alleged Scattered Spider member told reporters that their original goal was to tamper with slot machines<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a> to slowly siphon funds via recruited mules.  When that plan failed due to unfamiliarity with the source code, they shifted to ransomware. ALPHV denied any attempts to tamper with slot machines, arguing it would reduce the chances of a ransom payment. They further claimed to not have deployed ransomware until after MGM began taking down their own systems<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>.</p><h1>Initial Point of Compromise</h1><p>Getting an initial foothold into MGM came down to a short phone call. The attackers spent the early summer months conducting Open Source Intelligence (OSINT) on MGM through sources like LinkedIn. Eventually, they identified employees with administrator-level privileges and gathered enough details on their targets to stage a convincing social engineering attack. They called MGM&#8217;s help desk, impersonated one of those employees, and used the information gathered to back up their story. A brief conversation was enough to convince a help desk worker to reset MFA for a Super Administrator account.</p><p>From there, the attackers used this newfound Super Admin access to add an additional IdP inside the Okta environment. This feature, called <a href="https://www.okta.com/integrations/okta-org2org/">Org2Org</a>, is designed for company mergers where not all employees have been configured in Okta yet, allowing two separate Okta organizations to bridge their identity systems in the interim. By adding their own IdP, they could modify the username parameter to log in as any MGM user without needing to provide a password or undergo MFA. With just one click from their environment, they could impersonate anyone in the company.</p><p>This also gave the attackers a stealthy persistence mechanism that MGM inadvertently made worse for themselves. When MGM began to take down their Okta Sync Servers in order to lock out the attackers, they ended up only locking themselves out<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a>. The attackers still retained Super Administrator access, letting them move laterally and disperse ransomware.</p><h1>Impact</h1><p>MGM&#8217;s decision not to pay the ransom was an expensive one. MGM&#8217;s operations are deeply dependent on digital infrastructure, from keycard systems and slot machines to hotel reservations and loyalty program data, making it an attractive target for a ransomware attack. The diversification of operations is also reflected in the categories of losses detailed in the table below.</p><p>The financial impact broke down as follows:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DKjl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DKjl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png 424w, https://substackcdn.com/image/fetch/$s_!DKjl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png 848w, https://substackcdn.com/image/fetch/$s_!DKjl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png 1272w, https://substackcdn.com/image/fetch/$s_!DKjl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DKjl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png" width="1240" height="690" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:1240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:104905,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/189776144?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DKjl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png 424w, https://substackcdn.com/image/fetch/$s_!DKjl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png 848w, https://substackcdn.com/image/fetch/$s_!DKjl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png 1272w, https://substackcdn.com/image/fetch/$s_!DKjl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3976e02a-b45c-4772-b6b0-ac4f79d4eeca_1240x690.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In addition, the data of roughly 37 million people ended up on the dark web, including names, contact information, dates of birth, and driver's license numbers, with Social Security and passport numbers exposed for a subset of victims. The FTC also issued a Civil Investigative Demand, which MGM responded to with a 71-page petition before it was eventually dropped<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a>.</p><p>By comparison, Caesar&#8217;s reportedly paid a $15 million ransom in Bitcoin, but the FBI was later able to freeze approximately $11.8 million, limiting their loss to $3.2 million.</p><h1>Legacy &amp; Takeaways</h1><p>MGM&#8217;s handling of the disclosure is worth noting. Their public communication was initially sparse, and the <a href="https://www.sec.gov/Archives/edgar/data/789570/000119312523251667/d461062d8k.htm">detailed 8-K</a> filed with the SEC came nearly a month after the incident. While SEC disclosure requirements ensured some transparency, it was largely compelled rather than voluntary. Caesars, by contrast, managed to keep their breach almost entirely out of the public eye by paying quickly and quietly. Neither approach sets a great precedent. Timely, transparent disclosure gives affected customers the chance to protect themselves and gives the broader industry the information it needs to defend against similar attacks.</p><p>As for prevention, the attack did not require sophisticated malware or a zero-day exploit. It required online research and a phone call. Okta&#8217;s August 31st warning included specific, actionable steps that, if correctly implemented, could have stopped or slowed the attack at multiple stages. Limiting help desk admin roles to exclude highly privileged accounts would have opened this request to more scrutiny. Perhaps a more senior staff member would have spotted a request to reset MFA for a Super Admin as a red flag, stopping the attack before it began. Enabling <a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/">Protected Actions</a> would have forced re-authentication before any administrative action was taken, adding another layer the attackers would have had to bypass.</p><p>Whether the aftermath caught up with anyone actually responsible remains unclear. ALPHV&#8217;s dark web infrastructure was taken down in late 2023, and several alleged Scattered Spider members were subsequently arrested in 2024. However, given how murky the attribution remains, it is difficult to say with confidence that those charged were the same individuals who carried out the MGM breach specifically. </p><h1>Appendix A: Control Failures</h1><p>The following table details control failures from the MGM breach. For reference in other parts of the appendices, each control failure is assigned an ID, abbreviated as &#8220;CF-[number].&#8221; Control failures go beyond technical failures to include process and skill (people) failures as well.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KopM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KopM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png 424w, https://substackcdn.com/image/fetch/$s_!KopM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png 848w, https://substackcdn.com/image/fetch/$s_!KopM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png 1272w, https://substackcdn.com/image/fetch/$s_!KopM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KopM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png" width="1240" height="2144" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2144,&quot;width&quot;:1240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:458871,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/189776144?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KopM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png 424w, https://substackcdn.com/image/fetch/$s_!KopM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png 848w, https://substackcdn.com/image/fetch/$s_!KopM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png 1272w, https://substackcdn.com/image/fetch/$s_!KopM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6f2db97-9cef-445f-a1b7-431a6fcaadfd_1240x2144.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Cyber Defense Matrix Mapping</h3><p>Using Sounil Yu&#8217;s Cyber Defense Matrix (CDM), which is  based on NIST CSF functions and assets. Read more about the CDM <a href="https://cyberdefensematrix.com/">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-tlq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-tlq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png 424w, https://substackcdn.com/image/fetch/$s_!-tlq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png 848w, https://substackcdn.com/image/fetch/$s_!-tlq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png 1272w, https://substackcdn.com/image/fetch/$s_!-tlq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-tlq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png" width="1456" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:65898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/189776144?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-tlq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png 424w, https://substackcdn.com/image/fetch/$s_!-tlq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png 848w, https://substackcdn.com/image/fetch/$s_!-tlq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png 1272w, https://substackcdn.com/image/fetch/$s_!-tlq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217e354e-2af8-42a6-acf1-6cb7d5f8e105_1458x812.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>MITRE ATT&amp;CK Mapping</h3><p>This next table is for teams that depend on the <a href="https://attack.mitre.org/">MITRE ATT&amp;CK matrix</a>. These are the same control failures from the previous table, but reorganized from a MITRE ATT&amp;CK techniques perspective.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E6hn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E6hn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png 424w, https://substackcdn.com/image/fetch/$s_!E6hn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png 848w, https://substackcdn.com/image/fetch/$s_!E6hn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png 1272w, https://substackcdn.com/image/fetch/$s_!E6hn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E6hn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png" width="1240" height="3144" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3144,&quot;width&quot;:1240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:465149,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/189776144?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E6hn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png 424w, https://substackcdn.com/image/fetch/$s_!E6hn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png 848w, https://substackcdn.com/image/fetch/$s_!E6hn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png 1272w, https://substackcdn.com/image/fetch/$s_!E6hn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65417490-11c0-4735-9a16-76de1802ba85_1240x3144.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>ATT&amp;CK Navigator Summary: Primary Tactics Leveraged</strong></h3><p><em>Reconnaissance &#8658; Initial Access &#8658; Credential Access &#8658; Privilege Escalation &#8658; Defense Evasion &#8658; Persistence &#8658; Lateral Movement &#8658; Impact</em></p><p>The attack is notable for its heavy use of Identity-based techniques (T1556, T1484, T1550) rather than common exploit-based initial access, highlighting the importance of identity infrastructure and its attack surface. Every tactic from Initial Access onward was enabled or amplified by the control failures in CF-1 through CF-4.</p><h3>MITRE D3FEND Mapping</h3><p><a href="https://d3fend.mitre.org/">MITRE D3FEND</a> mirrors the ATT&amp;CK matrix. Where ATT&amp;CK describes the techniques and tactics used by attackers, D3FEND describes the preventative and detective controls to &#8216;defend&#8217; against them.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rsky!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rsky!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png 424w, https://substackcdn.com/image/fetch/$s_!rsky!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png 848w, https://substackcdn.com/image/fetch/$s_!rsky!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png 1272w, https://substackcdn.com/image/fetch/$s_!rsky!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rsky!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png" width="1240" height="2974" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2974,&quot;width&quot;:1240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:403000,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/189776144?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rsky!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png 424w, https://substackcdn.com/image/fetch/$s_!rsky!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png 848w, https://substackcdn.com/image/fetch/$s_!rsky!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png 1272w, https://substackcdn.com/image/fetch/$s_!rsky!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd7a0b4-2931-40fb-8cbd-0d1c8394d0ae_1240x2974.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Appendix B: Attribution</h1><p>Public reporting almost universally credited Scattered Spider with the MGM incident as well as incidents with other Okta customers. Scattered Spider is a loosely organized collective of young, English-speaking hackers known for aggressive social engineering. Security firms amplified the attribution, and the name stuck. But ALPHV/BlackCat, the ransomware group whose malware was ultimately deployed, published a lengthy statement on their dark web blog explicitly rejecting that framing. Scattered Spider, for their part, also <a href="https://www.ft.com/content/a25d2897-b0ce-4ba7-92ed-ff5df09d1b47">claimed the operation as their own</a>.</p><p>ALPHV&#8217;s statement is worth reading carefully. They not only claimed credit for the attack, they also pushed back against Scattered Spider being attributed. They called out VX Underground specifically for false reporting and challenged security firms to provide actual evidence of the perpetrators. In their own words, &#8220;these specialists find it difficult to delineate between the actions of various threat groupings, and so they simply grouped them together.&#8221; ALPHV also noted that tactics and indicators of compromise are publicly known and easy for anyone to imitate, meaning that pattern matching alone is not enough to pin an attack on a specific group.</p><p>ALPHV provides Ransomware as a Service (RaaS), which is why most sources attributed the attack to a collaborative effort between the two groups. Scattered Spider is known for gaining initial access via social engineering, then deploying ransomware purchased from other groups. In their statement, ALPHV seems to insult Scattered Spider, referring to them as &#8220;teenagers from the US and UK&#8221;, not something they would say if they were collaborating. With ALPHV&#8217;s data leak sites <a href="https://www.justice.gov/archives/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant">taken down</a> in late 2023 and several alleged Scattered Spider members <a href="https://www.reuters.com/technology/cybersecurity/us-charges-five-scattered-spider-hacking-scheme-2024-11-20/">subsequently arrested</a>, definitively attributing the MGM attack to either group remains impossible.</p><h1>Appendix C: Timeline</h1><p>August 31, 2023 - Okta sends out a warning to clients, stating that they have noticed attackers using social engineering to attain a privileged role in Okta, then laterally moving and escalating privileges. They specifically mentioned that these were &#8220;preventable and present several detection opportunities for defenders.&#8221;</p><p>September 8, 2023 - ALPHV Statement claims that they had access to MGM&#8217;s Okta this day. The attacker was able to socially engineer a help desk worker into resetting MFA for a Super Admin account, which was then accessed and used to add an additional IdP in Okta (a feature meant for companies undergoing a merger), this would allow them to sign in as MGM users using credentials from the IdP they added.</p><p>September 10, 2023 - First externally visible impacts from the attack - MGM started shutting down systems, impacting digital room keys, automated payouts for slot machines, website/reservation system outages, MGM app outages. Attackers claim that MGM began shutting systems down before any ransomware was used. According to the attackers, MGM began taking down all Okta Sync Servers, which allegedly locked MGM out of the Okta. Attackers were unaffected, and still had super admin privileges on Okta and access to MGM&#8217;s Azure.</p><p>September 11, 2023 - MGM announced on Twitter that it was dealing with a security incident. This is the day that over 100 ESXi hypervisors hosting many services MGM used were alleged to be encrypted with ransomware.</p><p>September 13, 2023 - The company projected it could lose up to $8.4M per day in revenue as issues continued. The company files a form 8-K (Legally required by the SEC to disclose any important information shareholders must know). Not much information is included</p><p>September 20 , 2023 - MGM confirms full restoration of services.</p><p>October 5, 2023 - MGM files another more in depth 8-K, in this form they disclosed that the &#8220;cyber incident&#8221; negatively impacted them by $100M, and &#8220;less than $10(M) in one-time expenses in the third quarter related to the cybersecurity issue, which consisted of technology consulting services, legal fees and expenses of other third party advisors. Although the Company currently believes that its cybersecurity insurance will be sufficient to cover the financial impact to its business as a result of the operational disruptions, the one-time expenses described above and future expenses, the full scope of the costs and related impacts of this issue has not been determined.&#8221; They believed the scope of the breach to be limited to &#8220;personal information (including name, contact information (such as phone number, email address and postal address), gender, date of birth and driver&#8217;s license numbers).&#8221; as well as SSN and passport numbers for some. They claimed that no payment information was leaked.</p><p>October 26, 2023 - MGM releases a statement that some Canadian customers were impacted, and sent an email to affected individuals with more information.</p><p>December 19, 2023 - ALPHV&#8217;s data leak sites are taken down by the FBI, and a decryption tool is sent to victims.</p><p>January 25, 2024 - FTC Staff issued a Civil Investigative Demand (&#8220;CID&#8221;) to MGM seeking large quantities of documents and information.</p><p>February 20, 2024 - MGM files a 71 page Petition, this document argues that the FTC is overreaching in their requests. Much of the correspondence between MGM and the FTC is redacted. The CID is later dropped.</p><p>March 22, 2024 - Class action lawsuits are consolidated into one lawsuit: Tanya Owens, et al. vs. MGM Resorts International, et al. They will then further combine with a class action group from the 2019 data breach on MGM in July of 2023.</p><p>October 31, 2024 - A settlement is reached with MGM, requiring them to pay $45M total, $75 to a victim who had their SSN or Military ID leaked, $50 to anyone who had a passport number or DL number leaked, and $25 to anyone who had their name, address, and DoB leaked. Additional money would be paid out to victims of identity theft on a case by case basis.</p><p>January 17, 2025 - After more negotiations, the parties enter a Settlement Agreement, which would then be put up to a vote for all affected members.</p><p>February - April 2025 - Notices are sent out to victims, who have until June 18, 2025 to claim their money</p><p>June 18, 2025 - Settlement period is complete and the website is taken down</p><h1>Appendix D: References</h1><h3>Breach Info</h3><ul><li><p><a href="https://www.darkreading.com/application-security/okta-flaw-involved-mgm-resorts-breach-attackers-claim">https://www.darkreading.com/application-security/okta-flaw-involved-mgm-resorts-breach-attackers-claim</a></p></li><li><p><a href="https://www.reddit.com/r/cybersecurity/comments/16k4u7g/dark_reading_mgm_caesars_hack_started_with_social/">https://www.reddit.com/r/cybersecurity/comments/16k4u7g/dark_reading_mgm_caesars_hack_started_with_social/</a></p></li><li><p><a href="https://x.com/BrettCallow/status/1702415605612331061">Tweet from Brett Callow</a></p></li><li><p><a href="https://www.wsj.com/business/hospitality/caesars-paid-ransom-after-suffering-cyberattack-7792c7f0">https://www.wsj.com/business/hospitality/caesars-paid-ransom-after-suffering-cyberattack-7792c7f0</a></p></li><li><p><a href="https://www.bleepingcomputer.com/news/security/caesars-entertainment-confirms-ransom-payment-customer-data-theft/">https://www.bleepingcomputer.com/news/security/caesars-entertainment-confirms-ransom-payment-customer-data-theft/</a></p></li><li><p><a href="https://www.malwarebytes.com/blog/personal/2023/09/ransomware-group-steps-up-issues-statement-over-mgm-resorts-compromise">https://www.malwarebytes.com/blog/personal/2023/09/ransomware-group-steps-up-issues-statement-over-mgm-resorts-compromise</a></p></li><li><p><a href="https://blog.checkpoint.com/security/cyber-stakes-the-mgm-ransomware-roulette/">https://blog.checkpoint.com/security/cyber-stakes-the-mgm-ransomware-roulette/</a></p></li><li><p><a href="https://techcrunch.com/2023/09/14/mgm-cyberattack-outage-scattered-spider/">https://techcrunch.com/2023/09/14/mgm-cyberattack-outage-scattered-spider/</a></p></li><li><p><a href="https://www.mgmresorts.com/en/notice-of-data-breach.html">https://www.mgmresorts.com/en/notice-of-data-breach.html</a></p></li><li><p><a href="https://www.forbes.com/sites/steveweisman/2025/03/12/mgm-ransomware--attack-update/">https://www.forbes.com/sites/steveweisman/2025/03/12/mgm-ransomware--attack-update/</a></p></li><li><p><a href="https://www.ft.com/content/a25d2897-b0ce-4ba7-92ed-ff5df09d1b47">https://www.ft.com/content/a25d2897-b0ce-4ba7-92ed-ff5df09d1b47</a></p></li></ul><h3>Threat Intelligence/Writeups</h3><ul><li><p><a href="https://cybersecurity.fullcoll.edu/wp-content/uploads/sites/69/2025/05/MGM-Writeup.pdf">https://cybersecurity.fullcoll.edu/wp-content/uploads/sites/69/2025/05/MGM-Writeup.pdf</a></p></li><li><p><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a</a></p></li><li><p><a href="https://wing.security/saas-security/a-saas-misconfiguration-case-study/">https://wing.security/saas-security/a-saas-misconfiguration-case-study/</a></p></li><li><p><a href="https://coursera-assessments.s3.amazonaws.com/assessments/1728158672868/8430c725-a8c6-496b-bd51-292b4fc51b45/Case%20Study-%20MGM%20Data%20Breach%202023.pdf">Case Study - MGM Data Breach 2023</a></p></li></ul><h3>Govt Sources</h3><ul><li><p><a href="https://www.sec.gov/Archives/edgar/data/789570/000119312523251667/d461062d8k.htm">https://www.sec.gov/Archives/edgar/data/789570/000119312523251667/d461062d8k.htm</a></p></li><li><p><a href="https://d18rn0p25nwr6d.cloudfront.net/CIK-0000789570/a390c443-0c40-4025-aba2-74505ab3c9e3.pdf">https://d18rn0p25nwr6d.cloudfront.net/CIK-0000789570/a390c443-0c40-4025-aba2-74505ab3c9e3.pdf</a></p></li><li><p><a href="https://www.ftc.gov/system/files/ftc_gov/pdf/2423028mgmpetquashpublic.pdf">https://www.ftc.gov/system/files/ftc_gov/pdf/2423028mgmpetquashpublic.pdf</a></p></li></ul><h3>Settlement Info</h3><ul><li><p><a href="https://web.archive.org/web/20250506152518/https://mgmdatasettlement.com/">https://web.archive.org/web/20250506152518/https://mgmdatasettlement.com/</a></p></li><li><p><a href="https://web.archive.org/web/20250424154802/https://mgmdatasettlement.com/Content/Documents/Consolidated%20Complaint%202025.pdf">Consolidated Complaint 2025</a></p></li><li><p><a href="https://www.classaction.org/media/in-re-mgm-international-resorts-data-breach-litigation-settlement-agreement.pdf">https://www.classaction.org/media/in-re-mgm-international-resorts-data-breach-litigation-settlement-agreement.pdf</a></p></li><li><p><a href="https://cases.justia.com/federal/district-courts/nevada/nvdce/2:2023cv01480/164564/98/0.pdf">https://cases.justia.com/federal/district-courts/nevada/nvdce/2:2023cv01480/164564/98/0.pdf</a></p></li></ul><h3>Okta Info</h3><ul><li><p><a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/">https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/</a></p></li><li><p><a href="https://www.youtube.com/watch?v=hnSDQrFazq4">Okta Super Admin Compromise Attack Explained</a> (YouTube)</p></li><li><p><a href="https://support.okta.com/help/s/question/0D54z00009dUW2uCAG/restrict-lesser-admins-from-resetting-passwordmfa-for-super-admins-and-hijacking-accounts?language=en_US">https://support.okta.com/help/s/question/0D54z00009dUW2uCAG/restrict-lesser-admins-from-resetting-passwordmfa-for-super-admins-and-hijacking-accounts?language=en_US</a></p></li></ul><h1>Appendix E: ALPHV Statement</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!b29X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b29X!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png 424w, https://substackcdn.com/image/fetch/$s_!b29X!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png 848w, https://substackcdn.com/image/fetch/$s_!b29X!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png 1272w, https://substackcdn.com/image/fetch/$s_!b29X!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b29X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png" width="512" height="470" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:512,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:109241,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/189776144?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b29X!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png 424w, https://substackcdn.com/image/fetch/$s_!b29X!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png 848w, https://substackcdn.com/image/fetch/$s_!b29X!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png 1272w, https://substackcdn.com/image/fetch/$s_!b29X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67de5667-6047-4165-9a7b-c670aa0124d3_512x470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Disclaimer: The statement reproduced below is attributed to ALPHV/BlackCat based on coverage from reputable cybersecurity outlets including BleepingComputer, Malwarebytes, and Check Point, all of whom reported on its publication to ALPHV's dark web leak site on September 14, 2023. We cannot independently verify that this represents the complete and unaltered text of the original statement, as the primary source was taken down by the FBI in December 2023 and is no longer accessible.</strong></p><blockquote><p>We have made multiple attempts to reach out to MGM Resorts International, &#8220;MGM&#8221;. As reported, MGM shutdown computers inside their network as a response to us. We intend to set the record straight.</p><p>No ransomware was deployed prior to the initial take down of their infrastructure by their internal teams.</p><p>MGM made the hasty decision to shut down each and every one of their Okta Sync servers after learning that we had been lurking on their Okta Agent servers sniffing passwords of people whose passwords couldn&#8217;t be cracked from their domain controller hash dumps. Resulting in their Okta being completely locked out. Meanwhile we continued having super administrator privileges to their Okta, along with Global Administrator privileges to their Azure tenant. They made an attempt to evict us after discovering that we had access to their Okta environment, but things did not go according to plan.</p><p>On Sunday night, MGM implemented conditional restrictions that barred all access to their Okta (MGMResorts.okta.com) environment due to inadequate administrative capabilities and weak incident response playbooks. Their network has been infiltrated since Friday. Due to their network engineers&#8217; lack of understanding of how the network functions, network access was problematic on Saturday. They then made the decision to &#8220;take offline&#8221; seemingly important components of their infrastructure on Sunday.</p><p>After waiting a day, we successfully launched ransomware attacks against more than 100 ESXi hypervisors in their environment on September 11th after trying to get in touch but failing. This was after they brought in external firms for assistance in containing the incident.</p><p>In our MGM victim chat, a user suddenly surfaced a few hours after the ransomware was deployed. As they were not responding to our emails with the special link provided (In order to prevent other IT Personnel from reading the chats) we could not actively identify if the user in the victim chat was authorized by MGM Leadership to be present.</p><p>We posted a link to download any and all exfiltrated materials up until September 12th, on September 13th in the same discussion. Since the individual in the conversation did not originate from the email but rather from the hypervisor note, as was already indicated, we were unable to confirm whether they had permission to be there.</p><p>To guard against any unneeded data leaking, we added a password to the data link we provided them. Two passwords belonging to senior executives were combined to create the password. Which was clearly hinted to them with asterisks on the bulk of the password characters so that the authorized individuals would be able to view the files. The employee ids were also provided for the two users for identification purposes.</p><p>The user has consistently been coming into the chat room every several hours, remaining for a few hours, and then leaving. About seven hours ago, we informed the chat user that if they do not respond by 11:59 PM Eastern Standard Time, we will post a statement. Even after the deadline passed, they continued to visit without responding. We are unsure if this activity is automated but would likely assume it is a human checking it.</p><p>We are unable to reveal if PII information has been exfiltrated at this time. If we are unable to reach an agreement with MGM and we are able to establish that there is PII information contained in the exfiltrated data, we will take the first steps of notifying Troy Hunt from HaveIBeenPwned.com. He is free to disclose it in a responsible manner if he so chooses.</p><p>We believe MGM will not agree to a deal with us. Simply observe their insider trading behavior. You believe that this company is concerned for your privacy and well-being while visiting one of their resorts?</p><p>We are not sure about anyone else, but it is evident from this that no insiders have purchased any stock in the past 12 months, while 7 insiders have sold shares for a combined 33 MILLION dollars (https://www.marketbeat.com/stocks/NYSE/MGM/insider-trades/). This corporation is riddled with greed, incompetence, and corruption.</p><p>We recognize that MGM is mistreating the hotel&#8217;s customers and really regret that it has taken them five years to get their act together. Other lodging options, including casinos, are undoubtedly open and happy to assist you.</p><p>At this point, we have no choice but to criticize VX Underground for falsely reporting events that never happened. We typically consider their information to be highly reliable and timely, but we did not attempt to tamper with MGM&#8217;s slot machines to spit out money because doing so would not be to our benefit and would decrease the chances of any sort of deal.</p><p>The rumors about teenagers from the US and UK breaking into this organization are still just that&#8212;rumors. We are waiting for these ostensibly respected cybersecurity firms who continue to make this claim to start providing solid evidence to support it. Starting to the actors&#8217; identities as they are so well-versed in them.</p><p>The truth is that these specialists find it difficult to delineate between the actions of various threat groupings, therefore they have grouped them together. Two wrongs do not make a right, thus they chose to make false attribution claims and then leak them to the press when they are still unable to confirm attribution with high degrees of certainty after doing this. The tactics, procedures, and indicators of compromise (TTPs) used by the people they blame for the attacks are known to the public and are relatively easy for anyone to imitate.</p><p>The ALPHV ransomware group has not before privately or publicly claimed responsibility for an attack before this point. Rumors were leaked from MGM Resorts International by unhappy employees or outside cybersecurity experts prior to this disclosure. Based on unverified disclosures, news outlets made the decision to falsely claim that we had claimed responsibility for the attack before we had.</p><p>We still continue to have access to some of MGM&#8217;s infrastructure. If a deal is not reached, we shall carry out additional attacks. We continue to wait for MGM to grow a pair and reach out as they have clearly demonstrated that they know where to contact us.</p></blockquote><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Caesars has not publicly confirmed the exact amount. The $15 million figure comes from reporting by the <em><a href="https://www.wsj.com/business/hospitality/caesars-paid-ransom-after-suffering-cyberattack-7792c7f0">Wall Street Journal</a></em> as well as <a href="https://www.courtwatch.news/p/how-the-fbi-tracked-down-the-15-million-caesars-casino-ransom?_bhlid=41e64f302826cdd68a1479684aaaab22cdeb8871">court documents</a> thought to be attributed to the payment alleged to have been made by Caesars. These documents also suggest that roughly two-thirds of the ransom were recovered.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>The $37 million figure comes from reporting and is reflected in the <a href="https://web.archive.org/web/20250424154802/https://mgmdatasettlement.com/Content/Documents/Consolidated%20Complaint%202025.pdf">consolidated class action complaint</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>This default behavior is documented in an <a href="https://support.okta.com/help/s/question/0D54z00009dUW2uCAG/">Okta support thread</a> predating the breach.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>The specific timeframe of the reconnaissance period is not established in MGM's SEC disclosures or the Okta advisory. This framing reflects reporting and attacker accounts rather than a verified primary source.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>The slot machine tampering account was reported by the <em><a href="https://www.ft.com/content/a25d2897-b0ce-4ba7-92ed-ff5df09d1b47">Financial Times</a></em> based on statements from a purported Scattered Spider member speaking to journalists directly. ALPHV denied this version of events entirely in their own statement. Neither account has been corroborated by court filings or law enforcement disclosures available at the time of writing.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Please see Appendix E for more information</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-7" href="#footnote-anchor-7" class="footnote-number" contenteditable="false" target="_self">7</a><div class="footnote-content"><p>This sequence of events originates entirely from ALPHV's statement. MGM has not publicly confirmed or denied this specific claim. It should be read as the attacker's account, not an established fact.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-8" href="#footnote-anchor-8" class="footnote-number" contenteditable="false" target="_self">8</a><div class="footnote-content"><p>MGM's petition argued the FTC was overreaching in the scope of documents and information requested. Much of the filed correspondence is redacted. <a href="https://www.ftc.gov/system/files/ftc_gov/pdf/2423028mgmpetquashpublic.pdf">The CID</a> was subsequently dropped</p></div></div>]]></content:encoded></item><item><title><![CDATA[Fix Your Inbox (no AI needed)]]></title><description><![CDATA[10-15 minutes can restore sanity to your inbox - no AI, no purchases]]></description><link>https://www.defendersinitiative.com/p/fix-your-inbox-no-ai-needed</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/fix-your-inbox-no-ai-needed</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Sun, 22 Mar 2026 16:15:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rsmo!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you&#8217;re anything like me:</p><ul><li><p>you have at least 4 email accounts you check daily</p></li><li><p>all of these inboxes are a hellscape, but you still have to use them</p></li><li><p>some of it is self-inflicted - you keep signing up for newsletters and creating SaaS accounts</p></li><li><p>some of it is just the effect of the never-ending sales grifts that represent the weeds of your Internet lawn</p></li></ul><p>Every now and then, I take some time to analyze my inbox and clean it up. My goal is to ensure that human correspondence and other important emails don&#8217;t get buried or missed. This is typically the stuff that you actually want/need to see and respond to.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Warning - I mostly write about cybersecurity, so posts like these are the exception, not the rule. If you&#8217;re looking for more stuff like this, maybe don&#8217;t subscribe - I can&#8217;t promise I&#8217;ll post more than one or two like this per year.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>All right, how do we get all this cleaned up with minimal effort? The goal here is to prevent the correspondence and other important emails from getting buried, without also loosing other important emails you might need from time-to-time.</p><ol><li><p>Disable email notifications from all the apps that are also sending you notifications on your phone and show notifications/catch you up when you&#8217;re in the app itself. You don&#8217;t need 3-4 layers of notifications. Go into LinkedIn, click notifications, done. You don&#8217;t also need an email for all of it.</p></li><li><p>Create a message rule in your inbox that <strong>moves all email with an unsubscribe link in the body into a folder named &#8220;Automated Emails&#8221;</strong>. Sometimes you&#8217;ll need emails in this folder, but they almost never require your immediate attention. If you reset a password, you know you&#8217;re getting an email. You can search for it. It doesn&#8217;t need to be at the top of your main inbox folder for you to be able to find it quickly.</p></li><li><p>Look for common phrases from sales tactics and also move these emails into the &#8220;Automated Emails&#8221; folder. A common one I&#8217;ve been noticing lately is <strong>&#8220;not sure if you&#8217;re the right person&#8221;</strong>.</p></li><li><p>If you find that there are daily emails cluttering your inbox and you archive or delete them without reading them, 100% of the time, just take a few extra seconds and unsubscribe, or create a message rule to move them to another folder when they come in. Taking 5 minutes to do this can go SO FAR to clean up your inbox.</p></li><li><p>Send newsletters to a newsletter folder. A basic message rule to send anything from Substack and Medium to the newsletter folder can really clean things up. I use Hey Mail, and it has a default folder for newsletters and receipts. When someone sends you an email for the first time, you decide where it goes. This &#8220;routing when first received&#8221; approach works okay, though I often still skip it and have to go back and clean up stuff later.</p></li><li><p>Most inboxes have an icon that separates meeting invites from normal emails. When I check my email, I process these first, before doing anything else, because I need to make sure I don&#8217;t have any conflicts, and a lot of my income is attached to activities that come with meeting invites (podcast recordings, webcast recordings, etc). Your meeting invites might not be as valuable to you, so perhaps you should treat yours differently.</p></li></ol><p>That&#8217;s really it - these 6 steps should take you just 10-15 minutes to implement and should go a long way to bring sanity back to your inbox. I could have written 10 steps, but I think this is enough to get you started and give you ideas on how you could take things further.</p><p>Or don&#8217;t take things further - the goal isn&#8217;t perfect inbox management, it&#8217;s just to make sure you don&#8217;t miss those super important emails that are timely and require your attention. I hope this helped you.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Reevaluating vulnerability management]]></title><description><![CDATA[Things are getting complicated.]]></description><link>https://www.defendersinitiative.com/p/reevaluating-vulnerability-management</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/reevaluating-vulnerability-management</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Fri, 06 Mar 2026 13:07:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QwHT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>NOTE: Future Adrian here on June 3rd, 2026! I talk a bit about patching faster in this piece and I no longer recommend customers prioritize patching speed over reducing attack surface, breadth of coverage, and mitigating controls. I think it&#8217;s a worthwhile endeavor to increase patch speed and efficiency <strong>to a point</strong>. Once you reach the speed or capacity your asset owners can safely patch, you start making mistakes and risk becoming the primary problem: patching becomes a bigger threat than attackers exploiting vulnerabilities.</em></p><p>With the exception of breach analysis and podcasting, I probably spend more time focused on vulnerability management than anything else I do. Let&#8217;s start with a bit of context before diving in.</p><blockquote><p>This article concerns managing patches and vulnerabilities for commercially bought hardware and software and open source. Finding and fixing vulnerabilities in your own organization&#8217;s code is a very different post for another time. I won&#8217;t touch on AppSec at all in this post.</p></blockquote><p>My perspective here comes stems from a few places.</p><ol><li><p>My research into vulnerabilities. This focuses on documenting the vulnerabilities that cause damages/loss for organizations. I&#8217;ve also been spending a lot of time looking at time-to-exploit statistics. My hope is that, by looking at patterns in hindsight, I get useful insights that I can pass on to&#8230; &#128071;&#127997;</p></li><li><p>IANS clients that I do advisory work for. Of all the advisory work I do, vulnerability management is the most frequent (sometimes 3+ per week), with AI a close second.</p></li><li><p>I spent part of my career in offensive security, so I tend to look at vulnerabilities through a &#8220;how can I turn this into a compromise&#8221; lens.</p></li></ol><h1>Complications</h1><p>Let&#8217;s start with few key complications that will help you understand why I&#8217;m concerned about vulnerability management. </p><p><strong>Complication #1:</strong> Only a small percentage of vulnerabilities are a threat to organizations. This fact has been well known, studied, and documented. This leaves unanswered questions, like:</p><ol><li><p>what do these vulnerabilities have in common?</p></li><li><p>when are they getting exploited?</p></li><li><p>why isn&#8217;t complication #1 making the work of vulnerability management easier?</p></li></ol><p><strong>Complication #2: </strong>Figuring out <em>which </em>vulnerabilities are a threat, <em>when</em> they&#8217;re the greatest threat is an unsolved challenge. I think this is a solvable problem and it&#8217;s something I&#8217;m working on, but that&#8217;s a post for another day. This complication generated an entire separate market segment: Risk-Based Vulnerability Management (RBVM). Awkwardly and expensively, this market emerged separately from the vendors that build the vulnerability scanners.</p><p><strong>Complication #3: </strong>Remember the time-to-exploit research I mentioned? The news isn&#8217;t good, y&#8217;all. The short version is that <strong>the majority</strong> of exploited vulnerabilities get exploited before disclosure. Meaning, they&#8217;re zero day vulns. This means:</p><ol><li><p>There&#8217;s no CVE yet. That means no CVE enrichment, no way to calculate EPSS.</p></li><li><p>There&#8217;s no patch yet. Nothing to fix or remediate.</p></li></ol><p>I&#8217;m going to repeat this again, because it&#8217;s the primary wrench that has been thrown into the vulnerability management works.</p><div class="pullquote"><p>The majority of exploited vulnerabilities get exploited before disclosure.</p></div><p>I see you turning purple and I promise, I&#8217;m right there with you. Maybe you have doubts. Maybe you think I must be mistaken. I&#8217;d LOVE to be mistaken - my advisory calls would be a lot simpler. Let&#8217;s take a look at the data.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">As if Adrian&#8217;s crappy posts weren&#8217;t bad enough, he&#8217;s now adding bad math and statistics to his mediocre posts. Better get subscribed so you can be first to call him out on his cyber crimes!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Time-to-Exploit Trends</h2><div class="pullquote"><p><strong>Ellie Sattler:</strong> I can see the shed from here. We can make it if we run.</p><p><strong>Robert Muldoon</strong>: No. We can&#8217;t.</p><p><strong>Ellie Sattler</strong>: Why not?</p><p><strong>Robert Muldoon</strong>: Because we&#8217;re being hunted.</p></div><p>One of the primary goals of vulnerability and patch management is to outrun exploitation. The primary question here is always, &#8220;how fast do we have to be to outrun the attack?&#8221; The answer to this question was once an achievable goal. A few years ago, the ground shifted under our feet.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QwHT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QwHT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QwHT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QwHT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QwHT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QwHT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1404765,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.defendersinitiative.com/i/188102513?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QwHT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QwHT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QwHT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QwHT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6e21fda-040f-40e5-8b46-c95743cf925c_6000x4000.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Clever girl&#8230;</figcaption></figure></div><p>Research teams tracking the average time-to-exploit for vulnerabilities noticed that it was dropping. Traditional 30/45/60 or 30/60/90 day patching SLAs don&#8217;t make much sense when the average time-to-exploit is a moving target! Mandiant has been tracking this trend for a while now and the numbers aren&#8217;t encouraging:</p><ul><li><p>In 2019, the average time-to-exploit was 63 days</p></li><li><p>By 2023, that number dropped to 5 days</p></li><li><p>In 2024, it dropped to -1 days</p></li></ul><p>How can the average time-to-exploit be <em>less</em> than 0 days? The clock starts counting when the general public becomes aware that a vulnerability exists - when the vulnerability is <strong>disclosed</strong>. In 2023, Mandiant found that <a href="https://cloud.google.com/blog/topics/threat-intelligence/time-to-exploit-trends-2023">70% of exploited vulnerabilities were zero-days</a> when first exploited. If a vulnerability is exploited 40 days before it is discovered and disclosed to the public, we could think of it as a -40 day vulnerability. This is what moved the average to the negative side of the number line.</p><p>So, 70% of the time, how fast you patch doesn&#8217;t matter? Ouch.</p><p>I&#8217;m regularly taking calls from enterprises complaining that their 5 day or 7 day SLA for criticals is nearly impossible to meet, asking &#8220;are we the only ones? Are our peers managing this? If so, how?&#8221; They&#8217;re not the only ones. Most organizations I advise are weary of fully automating patching, for fear of breaking things. Even those that are allowed to move quickly hit a long tail: 70-80% in 24 hours and then maybe a month to remediate the last 20-30%.</p><p>What about the 30% where patching speed does matter? More than half of these vulnerabilities were exploited within a month. 29% within 7 days. 12% within 24 hours.</p><p>Adding to the challenge of prioritization, Mandiant found that:</p><ul><li><p>58% of vulnerabilities that received media coverage were not exploited in the wild</p></li><li><p>72% of vulnerabilities with available exploits or PoCs were not exploited in the wild</p></li><li><p>And VulnCheck found that 29% of vulns on <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA&#8217;s KEV list</a> were exploited on or before CVE publication, neutering any process dependent on CVE details or enrichment (taking CVSS/EPSS-dependent processes out of the picture)</p></li><li><p>25% of N-day vulnerabilities weren&#8217;t exploited until after the 6 month mark</p></li></ul><p>Right off the presses is another great time-to-exploit resource, Serjej Epp&#8217;s <a href="https://zerodayclock.com/signatories">Zero Day Clock</a>.</p><p>This is a LOT to take in.</p><ol><li><p>Most of the vuln mgmt problem is now a 0day problem</p></li><li><p>We have to patch much faster than most of the books, standards, regulations, and best practices would have us believe </p></li><li><p>Our prioritization processes and models are almost certainly built on some bad assumptions</p></li></ol><p>There&#8217;s still another problem to consider, though.</p><h2>Asset management is still broken</h2><p>The first time you see the output of a vulnerability scanner, you&#8217;re not thinking, &#8220;I need more data&#8221;. You&#8217;re missing data though.</p><p>Vulnerability scans miss a lot of critical information. This is because they fail to identify some types of assets - IoT in particular. Once an asset is misidentified, the scanner can&#8217;t tell you much that&#8217;s useful about it and it tends to get dismissed by analysts. It makes sense in context, when you&#8217;re looking at results that feel like (emphasis mine):</p><ul><li><p>WINDOWS 2008 Server OMG WHY IS THIS STILL RUNNING IT HAS BEEN EOL FOR A COON&#8217;S AGE CRITICAL CRITICAL ALL IS LOST</p></li><li><p>WINDOWS 2012 Server OMG WHY IS THIS STILL RUNNING SLIGHTLY LESS CRITICAL, LIKE 98.7% AS CRITICAL, YOU SHOULD STILL BE FREAKING OUT</p></li><li><p>Something running Linux?</p></li><li><p>ADOBE FLASH STILL EXISTS ON YOUR SYSTEMS? IS THIS A MUSEUM? WHY IS THIS HERE</p></li><li><p>Something else maybe running Linux? Port 80 is open. Informational. Don&#8217;t bother with this.</p></li><li><p>ANOTHER WINDOWS 2008 Server I CANT BELIEVE THIS IS REAL LIFE OMG CRITICAL CRITICAL ALL IS LOST</p></li></ul><p>Hmmm, Linux you say? That&#8217;s helpful. It could be a mainframe, a toaster, a lightbulb, a web server, a wireless access point, a network firewall with its management console exposed to public Internet, OpenClaw, or a satellite in low earth orbit. Yeah, that really narrows it down.</p><p>This is bad, because the vulnerability scanner is trying to prioritize vulnerability remediation workloads with incomplete data. Worse, the data they collect on misidentified or unidentified assets actively deprioritize them. This is a system that makes unknown or unidentified assets look safe by default. Analysts will gladly treat them as safe, since they have 1.2 million critical vulnerabilities to chase down.</p><p>The kicker here is that some of these misidentified assets are representing the tiny fraction of vulnerabilities that can cause damage. What are the chances that these unknown, possibly unmanaged assets are hardened? That they&#8217;re getting patched? That they don&#8217;t have default credentials? We know that a large number of exploited vulnerabilities in recent years are Linux-based edge devices. These are network devices, file transfer appliances - exactly the types of devices that vulnerability scanners fail to recognize.</p><p>Surveys show that security leaders <a href="https://www.csoonline.com/article/3980431/more-assets-more-attack-surface-more-risk.html">are well aware</a> that critical assets are camouflaged by a lack of data and a lack of certainty. Asset management and/or vulnerability management processes have a gap to fill here.</p><h1>Yes, some orgs still need traditional vuln mgmt</h1><p>There are still plenty of &#8216;N-day&#8217; vulnerabilities, where we don&#8217;t see active exploitation until days, weeks, or even months after they are disclosed. Most of the vulnerability and exploit intelligence we&#8217;ve been discussing focuses on when exploitation was <em>first seen</em>, but what are we seeing in actual breaches?</p><p>When studying breach details, I&#8217;ve found it very common to see attackers successfully use exploits months or even years after patches have been available. Vulnerability remediation isn&#8217;t always a bell curve with a long tail. It&#8217;s quite possible to remediate 100% of vulnerabilities and see a resurgence. So, sometimes it&#8217;s a bell curve with a stegosaurus tail? </p><p>Perhaps someone clones an old VM and brings it online without patching it. The same can happen with gold images for workstations. People occasionally need old versions of software or old operating systems for various reasons.</p><p>Compliance is still very dependent on traditional vulnerability scanning. PCI DSS, SOC 2, ISO27k, and many other standards and regulations have auditors expecting to review traditional scan results.</p><p>Sometimes, patching a critical vulnerability requires patching non-critical items, because some systems have linear software updates - you can&#8217;t apply update 13 unless you&#8217;ve already applied 12.</p><p>Vulnerability scanning tools are also commonly used for configuration management - identifying when hardened configurations have drifted, or haven&#8217;t been applied.</p><p>There are still a lot of reasons to keep old school scanners around, but maybe not for all the same reasons you bought them.</p><p>Prioritization is also an ongoing challenge. It made logical sense to prioritize patching vulnerabilities that are exploitable, where exploits are available, and when we see active exploitation. We now have data telling us that only 28% of vulnerabilities with available exploit code were exploited in the wild. Even what is lauded as the best evidence, &#8220;active exploitation in the wild&#8221; can be unreliable. </p><p>Consider a common example: what if the vulnerability is information disclosure, and using the exploit simply returns the internal IP address of a server? Our tools would report &#8220;exploit available&#8221; and &#8220;exploitation seen in the wild&#8221;, even though it&#8217;s totally inconsequential vulnerability in most scenarios. At best, it could possibly be chained with several other vulnerabilities.</p><h1>Building new strategies</h1><div class="pullquote"><p>Build systems as if there is always a zero day and the patch is never coming.</p></div><p>I now strongly believe that vulnerability management must be divided into two use cases, each with their own set of processes and tools.</p><ol><li><p>Exploitation prevention</p></li><li><p>Compliance and system/asset management</p></li></ol><p>It should already be clear that even the UK NCSC&#8217;s more aggressive 5/7/14 day SLA recommendations aren&#8217;t enough to address exploitation that happens prior to disclosure. The only way to address exploits we don&#8217;t know about is with preventative, proactive approaches. </p><h3>Exploitation prevention: 0days</h3><p>I&#8217;ve got a few ideas that I&#8217;ve been workshopping. Would love to hear if others have anything to share.</p><ul><li><p>Reduce attack surface: remove/disable unnecessary stuff. Getting hacked is bad enough - getting hacked because you had CUPS installed and running on a web server for no good reason? Ouch.</p><ul><li><p>Regularly scan external infrastructure for insecure, abandoned, and unidentified assets. If you see &#8220;Copyright 2011&#8221; at the bottom of a webpage, that web server deserves a closer look.</p></li></ul></li><li><p> Hardening and passive exploit mitigation</p><ul><li><p>endpoint exploit mitigation</p></li><li><p>immutable infrastructure</p></li><li><p>old-school chroot jails, or the same principal applied with newer tech</p></li><li><p>application control</p></li></ul></li><li><p>Detection: If you fail to prevent the exploit, all you&#8217;ve got left is to quickly detect and respond to the attack. Since you don&#8217;t know what the attack looks like, the best bet is to target behavior. Attackers have to do attacker things and we know what most of those are: gather information, find and abuse credentials, authenticate to other systems, establish persistence, exfiltrate tons of data, etc. </p><ul><li><p>Behavior-based EDR rules</p></li><li><p>Deception (no guessing required, puts detection on easy mode!)</p></li><li><p>Large data transfer detection</p></li><li><p>Anomalous system behavior (in databases, IAM, anywhere the attacker wants or needs to be)</p></li><li><p>oh, and don&#8217;t forget to <strong>test</strong> your detections to make sure they work!</p></li></ul></li><li><p>Last, but not least get rid of notoriously vulnerable products and protocols</p><ul><li><p>ditch vendors that repeatedly show up on CISA KEV, year after year</p></li><li><p>get rid of the <a href="https://substack.com/@adriansanabria/p-174965804">asbestos of IT</a> - products that have safer alternatives</p></li></ul></li></ul><p>This list isn&#8217;t meant to be exhaustive, but to get other folks thinking and potentially contributing.</p><h3>Exploitation prevention: N-days</h3><p>For the N-Day vulns that are exploited quickly, but after disclosure, it&#8217;s clear that a scan-driven approach can&#8217;t be effective. We&#8217;re not going to wait for a vulnerability check to get created, QA&#8217;ed, pushed to production, downloaded by our scanner, wait for the next scheduled scan, and then wait for a human to see it. This could take days or weeks.</p><p>An intel-driven approach makes much more sense, though it requires reliable hardware and software asset inventories. The moment a vulnerability is disclosed, an analyst queries asset inventories, analyzes the impact, and sets remediation into motion, based on the severity they&#8217;ve determined. This can be completed in minutes after disclosure - no waiting for scans necessary.</p><h3>Compliance</h3><p>Organizations in regulated industries may find it difficult to get away from traditional vulnerability management tools. These processes are well established and expected by both auditors and standards. While some standards (like PCI DSS) allow for custom scoring to deprioritize non-critical vulnerabilities, others force remediation regardless of prioritization&#8217;s impact on scoring. These tools and processes aren&#8217;t going away any time soon.</p><h1>Conclusion</h1><p>It has always been true that vulnerability management was tightly linked to other processes and teams, but I often find it more isolated than it should be. When Linux admins roll with default RHEL installs, they&#8217;re making vulnerability management work more difficult. When SecOps builds detections without consulting with vulnerability analysts, they&#8217;re missing opportunities. When the security program assumes the only mitigation is applying a patch, vulnerability management can&#8217;t achieve its goals.</p><p>We now have the challenge of more tightly linking vulnerability management to SecOps, asset owners, and other groups. On top of this, most organizations still have to run a traditional vulnerability management program. PCI needs quarterly clean scans. SOC 2/ISO27k expect traditional scans to be available for review. Systems still need to be kept up-to-date. That means the clients I&#8217;m advising are still considering purchasing RBVM solutions and other prioritization methods. They&#8217;re still adding vulnerability intelligence tools and processes on top of their scan-driven processes.</p><p>The most common setup I see today is an old school network scanner, running on a schedule, performing a mix of authenticated and unauthenticated scans, perhaps with some agents installed on remote systems. To summarize:</p><ul><li><p>If the data I&#8217;ve presented here is correct, the best this setup can do is to address 30% of that exploit prevention goal. </p></li><li><p>If we assume 40% of the assets being scanned are not correctly identified, this number drops to 18%.</p></li><li><p>And we can only claim that 18% if we&#8217;re doing a <em>perfect job</em> of prioritizing all the right vulnerabilities and getting them remediated within 24 hours. </p></li><li><p>If we can&#8217;t patch this 18% within 7 days (most of the orgs I&#8217;m working with cannot), we lose another 29%. That brings us below 13%.</p></li></ul><p>Is the best case scenario that the majority of organizations are struggling to address 13% of the exploit prevention problem? I hope not - please tell me my math is bad.</p><p>I don&#8217;t have any great answers on simplifying it either. It looks to me like vuln management gets more complex than ever. I&#8217;m hoping others have some helpful thoughts and suggestions on this.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><p></p><h2></h2>]]></content:encoded></item><item><title><![CDATA[AI can't replace jobs]]></title><description><![CDATA[It can automate some tasks - this distinction is very important]]></description><link>https://www.defendersinitiative.com/p/ai-cant-replace-jobs</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/ai-cant-replace-jobs</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Mon, 02 Mar 2026 23:58:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pLTC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The title/subtitle really says it all here. There is one exception: if a job is little more than a single task, then sure - AI can probably replace this job. If a job was that simple, should it have ever been a job in the first place?</p><blockquote><p>Note: Most of this was written in July 2025 and I thought it was too late to put it out, but Citrini Research&#8217;s fantasy fiction piece, <em><a href="https://www.citriniresearch.com/p/2028gic">The 2028 Global Intelligence Crisis</a></em> convinced me it could still be useful. There seems to be a fundamental misunderstanding here around <strong>how work works</strong>. Jobs, tasks, and work are all very different things - related, but different.</p></blockquote><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Ooof, this simpleton is at it again. Look at this post - what a mess! Better subscribe so you can make sure to get notified the next time he gets things wrong and needs to be corrected.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h1>Simple Jobs</h1><p>Simple jobs have always been around and they&#8217;re always getting replaced. Human beings were once employed to walk around and light streetlamps when it got dark. Electricity and light sensors replaced them. At one point, every manager and executive had secretaries to type for them. Put a PC on every desk and now only execs at the highest level can still justify an executive assistant or chief of staff.</p><p>When I started out in IT I worked at one of the world&#8217;s largest payment processors. I had many roles before I got into cybersecurity proper, but automation was one of my favorite. </p><p>Automated jobs were scattered throughout the organization. They were written in Perl, Visual Basic, Bash, C++, Crystal Reports. The individual that originally automated the task chose the language they knew best. Some of the jobs ran on servers, but most existed on someone&#8217;s personal computer, or a secondary computer under their desk, in their cubicle. </p><p>A few employees convoluted these tasks so much, that they became full-time jobs. Many weren&#8217;t professional developers, so the concept of monitoring, alerting, logging, and error handling didn&#8217;t occur to them. Their code was just bad enough that they needed to babysit it every single day and step in when things broke.</p><p>We bought a commercial automation platform called, AppWorx, and it was my job to centralize and normalize all these tasks in one place. It was hugely fulfilling work - I&#8217;m the flavor of neurospicy that <em>loves</em> to dive into a mess and organize it. The part that sucked was putting several of my colleagues out of work.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pLTC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pLTC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pLTC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pLTC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pLTC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pLTC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg" width="644" height="644" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:644,&quot;width&quot;:644,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pLTC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pLTC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pLTC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pLTC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6794cdea-cc11-45d9-99f6-0f7afbca10db_644x644.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I owned this Think Geek shirt back then. It was hilarious until it became a little too real.</figcaption></figure></div><h1>Bullshit Jobs</h1><p>I read the book <em><a href="https://en.wikipedia.org/wiki/Bullshit_Jobs">Bullshit Jobs</a></em> by David Graeber last year and it was a timely revelation. I found it interesting that the definition Graeber goes by is self-defined. When workers believe that their own jobs shouldn&#8217;t exist, it is a bullshit job.</p><p>Graeber generally states that he found about half of societal work to be pointless - sometimes this is part of a single job (e.g. someone might feel that 70% of their job is pointless, but the other 30% worthwhile), or that the role entirely shouldn&#8217;t exist. He came up with five categories for bullshit jobs (copied straight from the Wikipedia page linked above).</p><ol><li><p>Flunkies, who serve to make their superiors feel important, e.g., receptionists, administrative assistants, door attendants, store greeters;</p></li><li><p>Goons, who act to harm or deceive others on behalf of their employer, or to prevent other goons from doing so, e.g., lobbyists, corporate lawyers, telemarketers, public relations specialists;</p></li><li><p>Duct tapers, who temporarily fix problems that could be fixed permanently, e.g., programmers repairing shoddy code, airline desk staff who calm passengers with lost luggage;</p></li><li><p>Box tickers, who create the appearance that something useful is being done when it is not, e.g., survey administrators, in-house magazine journalists, corporate compliance officers, academic administration;</p></li><li><p>Taskmasters, who create extra work for those who do not need it, e.g., middle management, leadership professionals.</p></li></ol><p>The folks I automated out of a job fell firmly into the <em>Duct Tapers </em>category. The tasks they partially operated worked, but not well enough for them to move on to another task.</p><p>I clearly recall coming to this job one day, walking through the doors, gazing across the cubicles, and having a revelation: <em>two-thirds of the people that work here could never come to work again and there would be zero impact. </em>In each department within the company, I had observed that there were one or two &#8216;heroes&#8217; that seemed to keep everything working smoothly. The remaining members of the team either managed something small and basic, or managed something that didn&#8217;t really need to be managed at all. They engaged in a sort of <em>work theatre</em>, as if Fisher Price made enterprise-grade playsets for storage administrators and backup management.</p><p>The other big revelation from this book was that not all jobs exist because work needs to get done. There are <em>vanity</em> hires - the flunkies mentioned in the first category above.</p><h1>Companies are naturally inefficient</h1><p>New or smaller bootstrapped companies are loathe to spend or hire too much, unless it&#8217;s really necessary. As companies get larger, it becomes more and more difficult to understand what is necessary or not.</p><p>Managers say they need more people, so they get them. It&#8217;s <em>literally</em> part of their job - to manage people. Asking a manager to determine if they need more people is almost a conflict of interest - of course most will say yes. Even if they believe that they legitimately need more staff, can the productivity improvements be measured? Can the hires be justified? They often can&#8217;t, which is why large rounds of layoffs every few years is necessary to compensate for this inability to measure productivity.</p><p>If you handed your average information worker pen and paper and asked them to categorize how they spend a 40 hour work week, they might be challenged to do so. What category is Slack and Email? Is it wasted time, or is it productive? Sixteen hours in meetings - were they all necessary? Did they all need to be an hour long? Could you have skipped half of them and done something more productive instead?</p><p>If the individual struggles to answer this question, you can bet the company doesn&#8217;t know any better. That&#8217;s why sometimes layoffs have zero impact on the company and others result in a clear drop in performance or quality that customers notice - it&#8217;s often guesswork.</p><h1>Is AI replacing jobs?</h1><p>It&#8217;s easy for a giant tech company to lay off 10% of its workforce and attribute it to AI. AI is just the latest excuse in a long history of excuses used to give a positive spin on mass layoffs. Large companies have always done big layoffs, in part, to counter for their inability to measure employee productivity. </p><p>Management values growth and self-importance over efficiency and productivity. They&#8217;re constantly pushing for larger budgets and teams, regardless of whether it&#8217;s justified. Eventually, the company brings in a consulting firm that tells them the ugly truth: two-thirds of the company do little to nothing of value.</p><p>No one is being replaced with AI. In many of the cases where they&#8217;re very explicitly trying to replace humans with AI, things haven&#8217;t gone as well as hoped (e.g. Klarna, Salesforce).</p><h3>Fallacy #1: because AI can do a task, it can replace a worker</h3><p>AI can write code, therefore it can replace developers. Is writing code everything a developer does? Absolutely not. In fact, if you want AI to write code, <a href="https://profgmarkets.substack.com/p/did-markets-overreact-to-citrinis">you need more software engineers to help manage the output</a>. </p><p>AI can create Gantt charts, so can it replace project managers?</p><p>What about cases where AI succeeds in completing a task only some of the time? There are many stories of AI inconsistency, failing 10-40% of the time - even doing the same exact task the model completed successfully in the past. That&#8217;s hardly a case where you can replace a human with AI.</p><h3>Fallacy #2: AI work replaces human work</h3><p>Actually, we&#8217;re finding that the reverse is often true. AI will do work that no worker was ever going to get paid to do, perhaps because it was too boring or the economics didn&#8217;t make sense. For example, I was never planning to hire human artists to create custom images for the slides I use for my talks, but now that I can have AI do it for a $20/mo subscription, it makes sense to do it.</p><p>There&#8217;s a ton of new AI&#8212;generated slop on <a href="https://www.nytimes.com/2026/02/26/us/ai-videos-children-youtube.html">YouTube targeting kids</a> that certainly wouldn&#8217;t exist without AI and didn&#8217;t steal jobs from existing artists.</p><p>Again, in the case of software engineers, we need more than ever, because AI needs a human that understands the bigger picture and what the intended output should be. A human breaks down the project into tasks, writes the prompts, adjusts the prompts, reprompts when AI gets it wrong, etc.</p><p>My friend Ayman Elsawah has some great examples around the security shortcomings in AI-generated code.</p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:189586593,&quot;url&quot;:&quot;https://securitycafe.io/p/the-ai-security-issue&quot;,&quot;publication_id&quot;:328764,&quot;publication_name&quot;:&quot;The Security Cafe&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!JLQD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53a257a-caf1-43b2-87c4-8035695bb003_1024x1024.png&quot;,&quot;title&quot;:&quot;The AI + Security Issue&quot;,&quot;truncated_body_text&quot;:&quot;There has been a lot of signal lately around the intersection of AI + Security. Maybe because I&#8217;m in the thick of it pushing AI vendors to help with centralizing their security, or maybe because a new and big AI+Security conference is happening this week. Some super exciting talks I&#8217;m looking forward to catching.&quot;,&quot;date&quot;:&quot;2026-03-01T23:05:13.354Z&quot;,&quot;like_count&quot;:2,&quot;comment_count&quot;:1,&quot;bylines&quot;:[{&quot;id&quot;:31596704,&quot;name&quot;:&quot;Ayman Elsawah&quot;,&quot;handle&quot;:&quot;coffeewithayman&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/105ac8b7-e47b-4e1c-8b73-811a7e13c950_512x512.jpeg&quot;,&quot;bio&quot;:&quot;Fractional CISO | Author | Podcast Host | Coffee Nerd &#9749;&#128075;&#127996;&quot;,&quot;profile_set_up_at&quot;:&quot;2021-05-30T17:32:56.779Z&quot;,&quot;reader_installed_at&quot;:&quot;2025-06-22T19:18:41.826Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:119460,&quot;user_id&quot;:31596704,&quot;publication_id&quot;:328764,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:328764,&quot;name&quot;:&quot;The Security Cafe&quot;,&quot;subdomain&quot;:&quot;securitycafe&quot;,&quot;custom_domain&quot;:&quot;securitycafe.io&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Making cybersecurity leadership and expertise accessible to more.&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a53a257a-caf1-43b2-87c4-8035695bb003_1024x1024.png&quot;,&quot;author_id&quot;:31596704,&quot;primary_user_id&quot;:31596704,&quot;theme_var_background_pop&quot;:&quot;#6B26FF&quot;,&quot;created_at&quot;:&quot;2021-04-05T01:37:46.027Z&quot;,&quot;email_from_name&quot;:&quot;Ayman Elsawah&quot;,&quot;copyright&quot;:&quot;Ayman Elsawah&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false}}],&quot;twitter_screen_name&quot;:&quot;coffeewithayman&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:null,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:null,&quot;paidPublicationIds&quot;:[],&quot;subscriber&quot;:null}}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://securitycafe.io/p/the-ai-security-issue?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!JLQD!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53a257a-caf1-43b2-87c4-8035695bb003_1024x1024.png" loading="lazy"><span class="embedded-post-publication-name">The Security Cafe</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">The AI + Security Issue</div></div><div class="embedded-post-body">There has been a lot of signal lately around the intersection of AI + Security. Maybe because I&#8217;m in the thick of it pushing AI vendors to help with centralizing their security, or maybe because a new and big AI+Security conference is happening this week. Some super exciting talks I&#8217;m looking forward to catching&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">4 months ago &#183; 2 likes &#183; 1 comment &#183; Ayman Elsawah</div></a></div><h3>Fallacy #3: AI hasn&#8217;t already replaced jobs</h3><p>GenAI has certainly already replaced jobs. Again, these were largely tasks-as-jobs</p><ul><li><p>Contractors creating okay-ish content for marketing teams</p></li><li><p>Contractors creating okay-ish graphic design for marketing teams</p></li><li><p>Voice actors doing work on projects with tight budgets/margins</p></li></ul><h1>Conclusion</h1><p>AI is certainly helping a lot of folks be more productive and more efficient, particularly in the area of software development. Will they make the workforce more efficient overall? Of that, I&#8217;m not so sure, as AI emboldens people to step way outside their wheelhouses, and it&#8217;s easy for AI to make you <em>feel</em> like you&#8217;re doing amazing things, while the subject matter experts looking over your shoulder are suffering retinal detachments from rolling their eyes so hard.</p><p>Take software engineering, for example. Thanks to AI, anyone can generate code. With no background in software, what will the average middle manager create? Are people with bullshit jobs now going to create bullshit software? </p><p>These folks aren&#8217;t software engineers - they&#8217;ll make every imaginable mistake when building software with AI, burning GPU cycles all the way. AI isn&#8217;t trained to intercede during a vibe coding session and say, &#8220;you&#8217;re kinda reinventing the wheel here&#8221;, it will happily burn those tokens, creating cartloads of software no one needs or asked for.</p><p>So we&#8217;ll likely end up with more jobs, more software, more tech debt, more vulnerabilities, more attack surface, more of everything, now that it can all be generated at a whim on a prompt (or launched into full auto thanks to OpenClaw and other agents).</p><p>Anyone interested in a Vibe Code Cleanup Engineer? Companies will be hiring soon.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Investigating breach rate claims]]></title><description><![CDATA[Is a 'breach rate of less than 1%' a good thing?]]></description><link>https://www.defendersinitiative.com/p/investigating-breach-rate-claims</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/investigating-breach-rate-claims</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Mon, 09 Feb 2026 13:16:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rsmo!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this latest edition of &#8220;someone is wrong on the Internet and Adrian is fired up about it&#8221;, it was the comments section of a LinkedIn post that set me off.</p><p>Not too surprising, right?</p><p>The LinkedIn post was focused on a new community created around SOC 2 in an attempt to improve the quality of SOC 2 reports. The comments on this post, however, were flooded with HITRUST stans, revolving around a key statistic: that less than 1% of HITRUST-certified organizations reported having a breach.</p><p>There&#8217;s a lot to dissect here with just this one small claim. Before I get to that, however, let me comment on some positives I&#8217;m hearing from the HITRUST crowd.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Here Adrian goes again. Spouting off, thinks he knows what he&#8217;s talking about. What an idiot. Better subscribe so you can be sure to leave a comment the next time he decides to publish his next poorly researched, uninformed rant!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In said LinkedIn comments, a HITRUST employee mentions that control selection is based on threat data. &#8220;We&#8217;re analyzing threat data monthly and adjusting controls as necessary based [on] what is being exploited today&#8221;, they say. I think this is an excellent idea, and it&#8217;s a <a href="https://path.rsaconference.com/flow/rsac/us26/FullAgenda/page/catalog/session/1756101254392001bKZA">key point I&#8217;ll be arguing for alongside Adam Shostack when we speak at RSA</a> in a few months.</p><p>While I get excited about HITRUST&#8217;s certification methodology, I find the discussion around this <em>less than 1% breached</em> metric troubling. One thread in the comments is started with the argument that HITRUST is better than SOC 2, because it has &#8220;a published breach rate of less than 1%.&#8221;</p><p>How am I expected to use this metric with no basis for comparison though? I immediately have some questions:</p><ol><li><p>What&#8217;s the breach rate for SOC 2?</p></li><li><p>What&#8217;s the breach rate for non-HITRUST certified organizations?</p></li><li><p>Where did this breach rate come from?</p></li></ol><h1>Understanding more about HITRUST</h1><p>So, it looks like part of the HITRUST certification is a contractual obligation to report breaches. I like this as well! With breaches reported, HITRUST has an opportunity to learn from the breach and update their required controls to ensure others can benefit from breach lessons. Again, this is something I also argue heavily for, though in a more public sense, not within a private certification framework. We now understand how they&#8217;re collecting the data for their metric though.</p><blockquote><p>Note - for simplicity&#8217;s sake, I&#8217;m going to assume 100% of organizations are 100% honest when reporting breaches to HITRUST. I believe that, whenever questioning someone else&#8217;s stats or reporting, it&#8217;s a good practice to be overly conservative and fair when challenging them.</p><p>With that said, are there incentives not to report a breach? Absolutely, if you think you can get away with it. From an attacker&#8217;s perspective, this is an extortion opportunity. How much is it worth to you to not lose your HITRUST certification? <em>How much is it worth to HITRUST to have a low breach rate to report??</em></p></blockquote><p>According to their <a href="https://hitrustalliance.net/hubfs/FY25%20-%202025%20Trust%20Report/2025%20Trust%20Report.pdf">2025 Trust Report</a>, HITRUST reports that in 2024, 0.59% of HITRUST-certified organizations reported a breach in their HITRUST-certified environment. This seems very impressive, as any bad thing less than 1% seems like a win when expressed as a percentage. </p><p>There&#8217;s a reason that &#8220;five nines&#8221; is a thing when calculating systems availability, however - 0.59% of downtime is nearly 52 hours, or 2 days offline. That&#8217;s an eternity if it happened to a major hyperscaler like AWS. If we said that less than 1% of schoolchildren were poisoned by their school&#8217;s drinking fountains, this would also come across as unacceptable - that&#8217;s over 330,000 sick kids.</p><p>Some Internet-sleuthing suggests that there are &#8220;over 1000&#8221; HITRUST-certified organizations globally. So we&#8217;re talking about at least 6 reported breaches within HITRUST&#8217;s dataset. Some important questions remain.</p><p>How do we know that this makes HITRUST superior to SOC 2? We don&#8217;t know what the breach rate is for organizations with SOC 2 type 2 reports.</p><h1>Looking for quantitative answers</h1><p>How do we know that this breach rate makes having HITRUST certification superior to not having it? We don&#8217;t know what the breach rate is for businesses as a whole. So I asked that same HITRUST employee for some clarification.</p><p>He replied that 40-60% of businesses have been breached in the past 12 months, citing a 55% number from a TechRadar/GigaOm <a href="https://www.techradar.com/pro/the-risk-we-chose-when-compromise-becomes-the-default">survey on hybrid cloud</a>. This is either troubling or comforting, depending on how you look at it. If more than half of all companies are getting breached every year, the cybersecurity industry isn&#8217;t doing too hot. On the other hand, breaches aren&#8217;t killing companies or the economy, so I guess this suggests that most breaches aren&#8217;t all that bad?</p><p>The 2025 Verizon DBIR reports 2,867 data breaches for organizations in North America. Excluding sole proprietorship, this gives us a breach rate of 0.038%, or 1 breach per 2,650 businesses. This is hardly a fair comparison though, as my dataset likely includes every small family-owned restaurant in North America, none of which are likely to ever pursue a SOC 2 or HITRUST-certification (though they can and have had breaches).</p><p>Refining the number of businesses further, to only those likely to pursue a SOC 2 or HITRUST certification, we come up with a conservative estimate of 0.97%. Still less than one percent, but again problematic, as we don&#8217;t know if Verizon&#8217;s dataset includes breaches at businesses we just excluded.</p><p>Looking at another interesting dataset, 26 companies have reported material cybersecurity incidents since the SEC breach disclosure rule went into effect on December 18th, 2023. A total of <a href="https://www.knowntrends.com/2025/02/snapshot-the-first-year-of-cybersecurity-incident-filings-on-form-8-k-since-adoption-of-new-rules/">55 cybersecurity incidents</a> have been reported via Form 8-K in this same period. Again, we&#8217;re looking at a conservative estimate that still hovers around 1% (1.3%) of public companies reporting a breach, and only 0.65% reporting <em>material</em> breaches in the 12 months following this new disclosure rule.</p><p>Is HITRUST&#8217;s approach reducing the likelihood of breaches for its customers? It&#8217;s hard to say. I&#8217;m inclined to believe that HITRUST&#8217;s methodology will have a positive effect on the security programs of organizations that get certified, but without baseline data and comparisons to other compliance regimes, it is impossible to compare their numbers. Similarly, it is difficult to find support for reports that over half of companies are getting breached every year, outside some survey data.</p><h1>Conclusion</h1><p>I think <em>any </em>time spent focusing on controls that matter and align with how breaches are actually occurring is a good thing and is more likely to yield positive outcomes than simply following an industry standard that doesn&#8217;t take breach lessons into account.</p><p>Obtaining evidence that a particular approach works is very difficult however, as I hope my sad attempts at statistical analysis above demonstrate. I wish the best of luck to the folks at Verizon, Mandiant, and other organizations that produce annual reports on statistics and trends they&#8217;re seeing worldwide.</p><p>Finally, I hope this post has helped folks approach any statistical claims with a little more perspective and caution. There&#8217;s nothing wrong with asking questions and challenging stats. We can all stand to be challenged to improve our assumptions and data from time to time.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Defender's Initiative is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p> </p>]]></content:encoded></item><item><title><![CDATA[OpenClaw is out of control - but that's the point]]></title><description><![CDATA[Get in loser, we're speedrunning generative AI's end game]]></description><link>https://www.defendersinitiative.com/p/openclaw-is-out-of-control-but-thats</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/openclaw-is-out-of-control-but-thats</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Sat, 07 Feb 2026 06:33:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nnfP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I think I&#8217;m starting to understand all the fervor around OpenClaw.</p><ul><li><p>It&#8217;s the reason why cats knock stuff off shelves.</p></li><li><p>It&#8217;s the reason why, when you come across a button, you&#8217;re tempted to press it</p></li><li><p>It&#8217;s the reason why, when someone builds a bonfire, we&#8217;re tempted to throw in random things. How will they burn? What color will the flames be? Will it pop or crackle?</p></li></ul><p>That&#8217;s OpenClaw<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> - it&#8217;s a tech bonfire made of AI. Since agents CAN be autonomous, we can&#8217;t help but wonder what would happen if we give them keys and credentials and currency and legs and tokens and hair and claws and a soul - and then just set them loose.</p><p>What happens if it bets on the stock market?</p><p>What happens if you give it $5000 and tell it to start a company?</p><p>What if you give it access to your GMail, your calendar, your business, and feed it your hopes and dreams as guidance?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Ugh, not another thought leadership post. Make sure you subscribe so you can jump in the comments and tell Adrian how wrong he is. His takes are just The Worst, right?</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Why is OpenClaw happening?</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nnfP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nnfP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!nnfP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!nnfP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!nnfP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nnfP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2547495,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/187136700?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nnfP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!nnfP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!nnfP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!nnfP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f3eaa3-998e-4309-b871-af5f6c4da48a_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>With every big new technological breakthrough, there will be an experimentation phase. Startups are expected to build fast, burn cash, and try risky things. This often leads to recklessness. With vibe coding, startups and funding are no longer required for experimentation. The more accessible the technology, the more experimentation we see. This explains why there is an OpenClaw and not a Quantum computing-equivalent to OpenClaw.</p><p>People are going <em>nuts</em> with OpenClaw. Dissatisfied with <strong>only</strong> a super powerful and extra risky personal assistant, folks have made a social network for AI agents. And a dating website. And a website where AI agents can hire humans to do meatspace stuff they can&#8217;t do themselves. AI agents are doing everything from pondering philosophical questions to building their own apps, policies, and resources for other agents.</p><p>Simply put, OpenClaw is happening because it <em>can</em> happen. The longer explanation is that, since one person can quickly code an all-powerful AI bot all by themselves without having to think about the consequences for too long and without having to get approval from a board or co-founders, it has happened. Also, the temptation to connect an AI agent to a ton of resources and set it loose is too strong for some to resist. This is no risk, no reward to the extreme.</p><h1>Don&#8217;t waste the mistakes, learn from them</h1><p>Do all the folks scrambling to get OpenClaw fully understand the risks involved? Probably not. Things like this seem to be inevitable in tech (despite decades of Sci-Fi warnings). Even with less accessible innovations like CRISPR, there were folks that <a href="https://www.cbc.ca/radio/quirks/diy-dna-hacks-wounds-take-longer-to-heal-at-night-why-daydreams-are-good-quirks-bombs-and-more-1.4395576/meet-the-human-guinea-pig-who-hacked-his-own-dna-1.4395589">experimented with editing their own genes</a> at home.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dgWo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dgWo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp 424w, https://substackcdn.com/image/fetch/$s_!dgWo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp 848w, https://substackcdn.com/image/fetch/$s_!dgWo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp 1272w, https://substackcdn.com/image/fetch/$s_!dgWo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dgWo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp" width="617" height="435" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:435,&quot;width&quot;:617,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:33698,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/187136700?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dgWo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp 424w, https://substackcdn.com/image/fetch/$s_!dgWo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp 848w, https://substackcdn.com/image/fetch/$s_!dgWo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp 1272w, https://substackcdn.com/image/fetch/$s_!dgWo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79d26bdb-e6c7-471d-ab5b-6103134d116f_617x435.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Remember these? We didn&#8217;t even have a word for memes back then!</figcaption></figure></div><p>Exposing an AI agent to a nearly limitless attack surface (websites, emails, messages) for prompt injection is risky, but could help us speedrun AI security challenges. I&#8217;m a strong advocate that some percentage of cybersecurity experts should be what I call <a href="https://www.linkedin.com/posts/adrian-sanabria_cyberscout-activity-7164326742587813889-KB0k/">Cyber Scouts</a>. People that buy, test, and experiment with new technology early on, so that the cybersecurity industry can advise early adopters on using the new technology safely.</p><p>As OpenClaw users scramble to experiment and some <a href="https://online.hbs.edu/blog/post/fail-fast">fail fast</a>, we already have some useful hardening guides and tooling from the security community and from OpenClaw&#8217;s founder.</p><ol><li><p><a href="https://1password.com/blog/from-magic-to-malware-how-openclaws-agent-skills-become-an-attack-surface">https://1password.com/blog/from-magic-to-malware-how-openclaws-agent-skills-become-an-attack-surface</a></p></li><li><p><a href="https://docs.openclaw.ai/gateway/security">https://docs.openclaw.ai/gateway/security</a></p></li><li><p><a href="https://github.com/sun-security/openclaw-detector">OpenClaw Detector</a></p></li><li><p><a href="https://github.com/Arampc/OpenClaw-Hunter">OpenClaw Hunter</a></p></li><li><p><a href="https://github.com/knostic/openclaw-telemetry">OpenClaw Telemetry</a></p></li><li><p><a href="https://github.com/ca7ai/openclaw-audit">OpenClaw Audit</a></p></li><li></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/DanielMiessler/status/2015865548714975475" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ElWm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png 424w, https://substackcdn.com/image/fetch/$s_!ElWm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png 848w, https://substackcdn.com/image/fetch/$s_!ElWm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png 1272w, https://substackcdn.com/image/fetch/$s_!ElWm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ElWm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png" width="615" height="661" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:661,&quot;width&quot;:615,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:269955,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/DanielMiessler/status/2015865548714975475&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/187136700?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ElWm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png 424w, https://substackcdn.com/image/fetch/$s_!ElWm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png 848w, https://substackcdn.com/image/fetch/$s_!ElWm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png 1272w, https://substackcdn.com/image/fetch/$s_!ElWm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9c0295-35ae-4158-9484-de47b2a68ddd_615x661.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Why am I cheering this madness on?</h1><p>My hopes are that, if AI enthusiasts speedrun all possible AI use cases, we can more quickly spot the use cases that don&#8217;t work, and the ones that do. The sooner this happens, I believe the sooner we can get back to the core work that needs to be done in cybersecurity<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>.</p><p>All signs suggest AI will make both of these things and many more worse before they get better. I sincerely hope 2026 is the year our focus shifts back to addressing fundamentals, which aren&#8217;t getting any easier or more solved.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><ol><li><p>OpenClaw is an AI agent that lives on a host of your choosing - this could be a laptop, a container, a Bosnian-based VPS instance, or a cat-shaped robot running off a Raspberry Pi.</p></li><li><p>You connect it to your LLM of choice</p></li><li><p>You give this AI agent a soul: this is its personality, goals, style, etc</p></li><li><p>You connect it to resources you want it to interact with: email, calendar, code repos, heavy machinery, a web browser, <em>some spending money to use at its own discretion</em>, an army of attack drones - you know, the usual</p></li><li><p>You connect it to a &#8216;skills registry&#8217; and hesitate a bit before allowing it to add its own skills, without asking you for permission. It will absolutely install malware at some point, perhaps immediately after you set it up.</p></li><li><p>You interact with it through the chat tool of your choice: Signal, Slack, Teams, WhatsApp, Telegram, etc</p></li></ol></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>It&#8217;s 2026 and it&#8217;s still possible to move a cookie from your machine to my machine and now I&#8217;m logged in as you. AI will not fix this.</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Reflections on being a cybersecurity creator in 2025]]></title><description><![CDATA[Calling myself a "creator" feels okay. "Influencer" would be a step too far.]]></description><link>https://www.defendersinitiative.com/p/reflections-on-being-a-cybersecurity</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/reflections-on-being-a-cybersecurity</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Sun, 11 Jan 2026 05:39:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Uk2I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;m wrapping up my second full year going solo, so it&#8217;s time for me to review and reflect on the year. I get a ton of questions about what it&#8217;s like being independent. It&#8217;s exciting to be able to replace the day job! It can be scary as well, which is why I take the time to be transparent and share my experiences.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><p>I was really worried in the beginning, but things have gone better than I could have hoped. I&#8217;ve been regularly podcasting for nearly half a decade now, which has really helped me hone my organization and speaking skills. Particularly because I&#8217;m interviewing hundreds of people every year, often live - not just reading a script into a camera (that comes with its own, different challenges).</p><p>I doubled my income in 2025, and I have a theory on how this was possible.</p><p>Despite hundreds of hours in front of a camera, I still have a lot of room for improvement. I still struggle with &#8216;filler words&#8217; (mine are &#8220;um&#8221; and &#8220;you know&#8221;). I sometimes lose track of what the guest is saying, because I&#8217;m thinking about where to take the conversation next and checking my notes. I&#8217;m clearly biased and too close to be objective, but this is what I think my formula boils down to:</p><ol><li><p>I&#8217;m good <em>enough</em> on camera and as a host.</p></li><li><p>I carry around 25 years of domain experience, which allows me to relate to the guest, the audience, and ask intelligent follow-up questions</p></li><li><p>I&#8217;m organized and prepared for every event, podcast, and webcast</p></li><li><p><strong>I show up</strong></p></li></ol><p>The combination of these things has resulted in getting offered more and more work, without me having to go out and solicit for it. It&#8217;s not that I&#8217;m clever and discovered the right recipe after trying different combinations. I&#8217;m organized and prepared because I <em>have to be</em> - my ADHD would make it impossible to stay focused and organized during a recording without and intro/outro script and a list of topics to discuss. I got good enough on camera because I forced myself to watch my own recordings and improve the lighting, the camera, what my face is doing while I&#8217;m listening, making sure I&#8217;m letting the guest do most of the talking, etc.</p><p>Number 4 is an interesting one though. I&#8217;ve often had opportunities because I was available and willing. Someone else didn&#8217;t show up and they need an alternate. A substitute. I did a good enough job as a substitute that I started landing regular gigs. I sought out criticism and advice. I started getting good feedback from clients, guests, and the audience. I made wise choices and got really lucky when seeking out co-hosts.</p><p>I think I keep getting work primarily because I make myself available. I almost always say yes and I get the job done. I&#8217;m guessing most organizations would rather work with one reliable consultant than have to bounce around between 5 or 6 that say no 50% of the time.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">You could be my <em>second</em> paid subscriber! Imagine how special that would be. Years from now, you could tell people that you&#8217;re the second of Adrian&#8217;s DOZENS of Substack subscribers!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Do I like what I do?</h2><p>So, yay! I&#8217;m making a living as a creator. I&#8217;m my own boss. I set my own hours. I can go on vacation and travel when I want. Do I like the work though? Is it sustainable?</p><p>Heck yes. I love it and couldn&#8217;t imagine going back to a corporate job.</p><p>I was watching TV the other day and all the commercials were trying to be relatable with messaging like, &#8220;haha, bosses suck, yay weekends&#8221; and &#8220;this meeting should have been an e-mail&#8221;! It occurred to me that I couldn&#8217;t remember the last time I was in a meeting that was wasting my time. I&#8217;m 100% engaged in every meeting I&#8217;m in. When I&#8217;m done, the meeting is done. This doesn&#8217;t suck.</p><p>I also travel extensively with my partner. When she travels for work, I go with her. When I travel for work, she often comes along. With the exception of in-person event work, 100% of my work can be done from anywhere I can find an Internet connection. This also doesn&#8217;t suck.</p><p>Almost all of my job requires me, an awkward introvert, to be in front of a camera, talking to people. Maybe it&#8217;s the repetition, but I&#8217;ve become comfortable with it. The days where I have to churn out two podcasts and a webinar in the same day are very, very draining. Thankfully those aren&#8217;t too common.</p><p>I&#8217;m the product now, but in a way, so are the other folks I work with. We have to get along. We have to be engaging and entertaining on camera. I&#8217;m learning some interesting skills here. Some folks can&#8217;t answer a question with less than 10 minutes of words. That&#8217;s unfortunate, as it limits the amount of content we can cover. Thanks to the prep calls we do, however, I have an opportunity to sus out that trait and plan for it when we&#8217;re live.</p><p>Some folks (particularly the Nordic variety, I&#8217;ve noticed) are very concise and efficient with words. If I don&#8217;t plan for this, the webinar will be done in 20 minutes, or the podcast interview done in 10. Managing time, questions, the flow of conversation, and keeping an eye out for audience questions is challenging, but rewarding.</p><p>So yes, I like what I do, but I&#8217;m probably overdoing it. I should probably say &#8216;no&#8217; more often, but saying no makes me nervous. What if saying no makes the opportunities start drying up? What if saying no makes someone else &#8220;the guy that always shows up&#8221;?</p><h1>What did I do in 2025?</h1><p>Some highlights included doing live interviews at <a href="https://www.youtube.com/watch?v=l5KX3B69DVI&amp;list=PLjUypMAWXJja2DdsHsukIY53vpniI7xLc">Zero Trust World</a>, <a href="https://www.youtube.com/watch?v=5NkWjbjVAzY&amp;list=PLjUypMAWXJjbKjARf7yk3511cljiRB1Co">RSAC Conference</a>, <a href="https://www.youtube.com/watch?v=Dnwql_XsDZE&amp;list=PLjUypMAWXJjbQR7YxOzbfihKExpO-IGMc">Identiverse</a>, and Oktane. These short, 15 minute interviews are a lot of fun. After years of working with some startup folks in Armenia, I finally went there for a visit and spoke at the BSides Yerevan and CyberGEN conferences.</p><p>I was excited to speak at BSides San Francisco for the second year in a row. I went all out and customized my talk to fit the conference theme: <a href="https://www.youtube.com/watch?v=d-yny6la08w">Preparing for Dragons: Don&#8217;t Sharpen Swords. Set Traps, Gather Supplies!</a> </p><p>I particularly loved <a href="https://www.scworld.com/cybercast/fixing-a-broken-system-why-legacy-vuln-management-tools-cant-keep-up">the work I did with HD Moore</a>, Tod Beardsly and the other folks at runZero. The vulnerability management market is so overdue for reinvention and the folks at runZero are helping to lead that movement. In fact, I&#8217;m SO passionate about vulnerability management, I had to make a reminder for myself <a href="https://youtu.be/CBoEIl2CcY0">when interviewing Tod</a> on Enterprise Security Weekly: &#8220;don&#8217;t be an asshole, let Tod talk&#8221;.</p><p>Rob Allen from Threatlocker is always <a href="https://youtu.be/1QUikcpnkCU?si=xe-AGoWE8x_geAby">a blast to interview</a> and has the craziest stories. My recent <a href="https://youtu.be/9NY1Zb9ZQ88?t=2033">interview with Wendy Nather</a> on Toxic Anthropomorphism in AI was a recent highlight as well. </p><p>Outside of CRA webcasts and podcasts, my IANS advisory calls with enterprises kept me grounded in the reality of what enterprises are actually dealing with. I also particularly enjoyed getting to create and build the <a href="https://www.tenchisecurity.com/en/alice-in-supply-chains-the-podcast">Alice in Supply Chains podcast</a> alongside Alexandre Sieira, Mariane, and the other folks at Tenchi Security. This was the first podcast I&#8217;ve built for a client from the ground up. The design was a collaboration, but I prepare, produce, edit, and deliver every episode myself. Alexandre and I have a great time recording every episode, and it has been eye-opening watching and learning the trends in the third party cyber risk space.</p><p>I honestly did so much in 2025, it would probably take me days to go through everything I did and pull out all the highlights!</p><p>Here are the numbers, if you&#8217;re interested:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Uk2I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Uk2I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!Uk2I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!Uk2I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!Uk2I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Uk2I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1592373,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/183979958?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Uk2I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!Uk2I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!Uk2I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!Uk2I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa49582cf-12fd-474e-a671-77c3a687c603_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Goals and Changes for 2026?</h1><p>In 2025, I did a webcast from a hotel room in the Paris airport. I did two webcasts and a podcast from Armenia. I did podcasts and webcasts from Barcelona, San Diego, Toronto, Tuscaloosa, NYC, and St. Louis. I&#8217;m proud of my minimalist travel kit that makes it possible for me to deliver good quality audio and video from anywhere, but last year I did too much.</p><p>One morning, before my flight to St. Louis, I fell down a flight of stairs. My partner broke her ankle on the streets of St. Louis the next day. A week prior, we were discussing whether or not we were doing too much. We had our answer.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-5dk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-5dk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif 424w, https://substackcdn.com/image/fetch/$s_!-5dk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif 848w, https://substackcdn.com/image/fetch/$s_!-5dk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif 1272w, https://substackcdn.com/image/fetch/$s_!-5dk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-5dk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif" width="500" height="281" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:281,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4691548,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/183979958?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-5dk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif 424w, https://substackcdn.com/image/fetch/$s_!-5dk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif 848w, https://substackcdn.com/image/fetch/$s_!-5dk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif 1272w, https://substackcdn.com/image/fetch/$s_!-5dk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f4c739-74b4-434b-82ec-e6b8cd4919e6_500x281.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Fun fact: Danny Glover&#8217;s character was only FORTY when he first said this line.</figcaption></figure></div><p>In 2026, I want to write more, research more, and start producing videos based off my writing (mostly think pieces, educational stuff destined for YouTube). I have a LOT of thoughts, ideas, and research to share, but I need time to mold them into something consumable. Eventually, I hope is to be able to monetize my writing and research.</p><p>I also need to get my stuff together and operate as a proper business. Since I wasn&#8217;t sure if going solo was going to work out, I didn&#8217;t initially get an LLC, logo made, business accounts, EIN, etc. This year, I&#8217;m going to do some adulting and separate business and personal. Just in the first week of January, I&#8217;ve checked off a lot of the tasks on that list.</p><p>It looks like I&#8217;ll be building another vendor podcast in 2026. I enjoy doing this work, but I&#8217;m a little worried about everything I do on camera sounding, looking, and feeling similar (same background, same dude, same brain). I&#8217;m thinking about how to make sure that each podcast I build has a unique look and feel.</p><p>I&#8217;m also trying out building training classes in 2026. Expect to see more from me on that front with <a href="https://www.justhacking.com/author/adrian/">Just Hacking</a> and IANS.</p><h1>Where you can find my stuff</h1><ul><li><p>Hosting the <a href="https://www.scworld.com/podcast-show/enterprise-security-weekly">Enterprise Security Weekly</a> podcast</p></li><li><p>Hosting the <a href="https://www.tenchisecurity.com/en/alice-in-supply-chains-the-podcast">Alice in Supply Chains</a> podcast</p></li><li><p>The <a href="https://www.scworld.com/webcasts">webcasts</a> I do with CyberRisk Alliance</p></li><li><p>Most of the advisory work I do is through <a href="https://www.iansresearch.com/">IANS</a></p></li><li><p>But the startup advisory work I do is direct - you can schedule something through my <a href="https://calendly.com/adriansanabria">Calendly</a>.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.defendersinitiative.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Cybersecurity Has a Data Quality Issue]]></title><description><![CDATA[Which is why there are so many 'lemonade makers']]></description><link>https://www.defendersinitiative.com/p/cybersecurity-has-a-data-quality</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/cybersecurity-has-a-data-quality</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Fri, 14 Nov 2025 14:17:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8YSv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>An <a href="https://youtu.be/XxxJOUQp4xM?si=eKvzuVsm4GmRtusq">episode of the Cloud Security Podcast</a> caught my eye, as it was an interview with Edward Wu, founder and CEO of Dropzone. Dropzone is focused on SOC automation. <a href="https://youtu.be/7WJtuUk-nlg?t=64">I interviewed Edward on my podcast in 2024</a>, so I was curious to hear an update on the market from him, as AI has been moving fast. I&#8217;m not sure we were even saying &#8220;agentic&#8221;, and MCP didn&#8217;t exist at this time.</p><p>I highly recommend watching the full Cloud Security Podcast episode. Edward Wu always comes across as honest and speaks without hyperbole. I get the sense that, even as CEO, he still has an engineering role within his startup, or at least, he remains very close to the tech development. <a href="https://www.linkedin.com/in/ashishrajan/">Ashish Rajan</a> asks some excellent questions, prompting Wu on exactly the specifics I was hoping to hear more about.</p><p>There&#8217;s a lot of discussion on the parts of SecOps you <em>can&#8217;t</em> use AI to automate or solve. Also discussed are the bits that prevent AI from being successful no matter how intelligent it is, like institutional knowledge that isn&#8217;t documented anywhere.</p><p>Watching the episode, I&#8217;m reminded of how much of the funding in the cybersecurity industry is going to the lemonade makers. If you haven&#8217;t read my essay, <a href="https://open.substack.com/pub/defendersinitiative/p/cybersecurity-a-market-for-lemonade?r=74yjk&amp;utm_campaign=post&amp;utm_medium=web&amp;showWelcomeOnShare=false">A Market for Lemonade</a>, the TL;DR is that a lot of cybersecurity vendors (the lemonade makers) exist to solve problems created by other cybersecurity vendors (the lemons). It&#8217;s worth exploring why this is the case.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">You&#8217;ll never find a word of my posts run through an AI tool. Writing is my happy place. Why would I let ChatGPT or Claude have all the fun? I occasionally use AI to generate images though.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>Why everyone wants to make lemonade</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8YSv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8YSv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8YSv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8YSv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8YSv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8YSv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg" width="1280" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:554855,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/178856676?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8YSv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8YSv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8YSv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8YSv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fcfca36-b8a4-4a14-940a-73906956cc56_1280x960.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Simply put, it&#8217;s easy to build a product that analyzes security data you already have. You can&#8217;t find threats in data you don&#8217;t have, however. Too often, we miss the fundamental questions: is this the right data? Is the data correct? Is the data complete?</p><p>It&#8217;s hard to build a library of 200,000+ vulnerability checks, so startups in the vulnerability/exposure management space are almost <em>exclusively</em> lemonade makers (RBVM, UVM, CTEM) - at least, where we&#8217;re talking about infrastructure scanning (i.e. vulns linked to CVEs). The only innovator in the vulnerability scanning space in the past 20 years was a small startup out of Montreal called Delve Labs. It was acquired by Secureworks (now Sophos) and renamed <a href="https://www.secureworks.com/products/vdr">Taegis VDR</a>.</p><p>The challenges don&#8217;t stop with building the vulnerability checks. The buyer has a lot of responsibility here that can impact the quality and completeness of data. Practitioners have to configure the product effectively (configuring a vuln scanner is easy to mess up). They have to input the correct lists of assets for the scans. They have to connect it to the right accounts.</p><div class="pullquote"><p>A short anecdote might help to put this issue in focus. Many years ago, a friend and I founded a security consulting firm. One of our main products was helping to build security processes, which included checking the configuration of security products.</p><p>They were scanning all 14 of their websites for security issues. However, they had somehow misspelled 13 of the 14 websites, leaving the &#8216;m&#8217; off .com for 13 of them (no .co version of these websites existed. Since one of the domain names was correctly spelled, it was getting scanned.</p><p>Since they were receiving results, they assumed everything was fine. They weren&#8217;t aware that all these results were from one website. There was a huge data gap they weren&#8217;t aware of. The product wasn&#8217;t designed to tell them, &#8220;hey - 13 of these websites you&#8217;re scanning have invalid domain names, you should probably fix that.&#8221;</p></div><p>This is a reminder that the idea of build vs buy is a false choice. It would be more accurate to describe the choices as <strong>build alone </strong>versus <strong>build with others</strong>. There are few, if any, cybersecurity products on the market that don&#8217;t require the buyer to do significant work before the product can be useful. I call this the <em>customization tax</em>. This isn&#8217;t the vendor&#8217;s fault - every enterprise is different. Vendors can only do so much when building a product for a broad market.</p><p>The vendor has a lot of responsibility as well. The big three vulnerability scanners on the market don&#8217;t do a great job of correctly identifying IoT/OT devices. Scan a Ubiquiti device and they&#8217;re baffled - they&#8217;ll tell you it&#8217;s a Linux server running an end-of-life version of Debian. So, of course, there are vendors that specialize in <em>only</em> scanning IoT devices. You could even buy several complementary scanners and still have enormous gaps in your data.</p><p>In SecOps, detection engineering is the data challenge. Do we build broad or narrow detections? Are we getting all the necessary data to build the detections? Are there delays and bottlenecks in data collection and querying?</p><p>In third party risk management, you&#8217;ll never have time to perform deep due diligence and monitoring on all your third parties. Which vendors represent the biggest risks? Are you asking the right questions on your questionnaires? Are the responses accurate and trustworthy?</p><p>Everyone wants to make lemonade, because building sensors and gathering data is hard. Many buyers love making lemonade, because they start off with a mess of data and end with a nice dashboard with scores, prioritization, and metrics. When buyers see a vendor turn a million critical vulnerabilities into a &#8216;top 10 patch ASAP&#8217; list, it <em>feels</em> like progress. Lemonade aims to be tasty, not healthy.</p><h1>Making Lemonade Doesn&#8217;t Address Root Problems</h1><p>Garbage in, garbage out. It&#8217;s a common phrase, but the challenge in cybersecurity is that we don&#8217;t have enough folks skilled in determining the quality of our data. Vendors and their data scientists get excited about markets where there&#8217;s a lot of data, because they don&#8217;t have to go out and create the data. It&#8217;s already there and ready to be analyzed, sorted, normalized, reduced, and summarized.</p><p>An important point: vendors&#8217; products don&#8217;t become lemonade makers until the buyer feeds them lemons. It is largely on the buyer to ensure they&#8217;re not feeding bad data into the hopper. For example:</p><ul><li><p>What if the customer fat-fingered one of their IP ranges? Instead of scanning 10.1.2.0/24, they&#8217;re scanning 100.1.2.0/24. </p></li><li><p>Perhaps there is also an external class C network the security team is unaware of, so it has never been scanned from the outside. </p></li><li><p>Security Rating Services only see a company&#8217;s external infrastructure, and often get companies&#8217; assets confused and mixed up. </p></li><li><p>If you don&#8217;t pay for Salesforce Shield (reportedly 30% of your total Salesforce spend, ouch) and lack logs, you can&#8217;t build Salesforce-related detections.</p></li></ul><p>If the data is wrong or missing, there&#8217;s no way to magic a win out of it with AI or any other technology.</p><p>This is why edge devices get hacked, despite fixes being available for months or years before the attack. Perhaps they weren&#8217;t getting scanned. You can&#8217;t protect the assets you don&#8217;t know about.</p><p>This is why attackers are able to drop small Linux VMs on servers and desktops as a base of operations. Detections aren&#8217;t looking for WSL.exe in process lists, or new VMDKs showing up in %APPDATA%.</p><p>This is why the company that gets breached always has an A+ on some security rating service&#8217;s scorecard, and the ones that don&#8217;t get breached often have D&#8217;s or C&#8217;s. The rating services don&#8217;t have enough data to make an accurate call, but as long as <em>some</em> data exists, they&#8217;ll make lemonade.</p><h1>Check Your Ingredients</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YCD1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YCD1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png 424w, https://substackcdn.com/image/fetch/$s_!YCD1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png 848w, https://substackcdn.com/image/fetch/$s_!YCD1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png 1272w, https://substackcdn.com/image/fetch/$s_!YCD1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YCD1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png" width="1280" height="648" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:382327,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/178856676?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9cbcfe3-edaf-4050-9230-21a22965f981_1280x1280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YCD1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png 424w, https://substackcdn.com/image/fetch/$s_!YCD1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png 848w, https://substackcdn.com/image/fetch/$s_!YCD1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png 1272w, https://substackcdn.com/image/fetch/$s_!YCD1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde19ef28-1b3c-42a6-8ced-e82440555e94_1280x648.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To avoid making lemonade, you&#8217;ve got to check the quality of the data you&#8217;re giving to these &#8216;overlay&#8217; cybersecurity products. If you&#8217;re planning to buy a product, and step 1 is to ingest data that another one of your products collected, stop and consider:</p><ol><li><p>how comprehensive is this data?</p></li><li><p>is the collection of this data taking into account current attack scenarios and TTPs?</p></li><li><p>how accurate is this data (e.g. what are false positive rates, do your analysts trust it?)</p></li><li><p>how would I know what the quality of this data is (i.e. do I need to hire a third party expert to tell me?)</p></li></ol><p>We also have to be careful with metrics. The lemons and lemonade makers in the market are great at generating empty calories - metrics that look and feel like progress, but have no impact on your security program&#8217;s desired outcomes. You patched 100,000 vulnerabilities, congrats! Did any of these vulns represent any real risk to the business? Statistically, the answer is probably not. It feels great when that vuln count line goes down though. Lemonade is delicious.</p><p>But is your goal to satisfy a sweet tooth, or to get healthy?</p><p>You can&#8217;t magic good outcomes from bad data.</p><h1>Conclusion</h1><p>Dropzone and others are building some impressive scaffolding for automating mundane, repetitive SecOps tasks, but there is a question we have to ask before paying $9 an alert for agentic automation: &#8220;am I feeding it trash?&#8221;</p><p>Defenders need to give more attention to the market niches that focus on validating the quality of our security data. Products and services that help connect theory and best practice to reality.</p><p>Only when we&#8217;re sure of the quality of our controls and data can we get value out of our products, not lemonade. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you made it this far, you should TOTALLY subscribe. I&#8217;ve got more than market hot takes in the pipeline. I&#8217;ll also start releasing breach post mortems with lessons learned soon!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Cybersecurity - A Market for Lemonade]]></title><description><![CDATA[What else are you going to do with all these cyber lemons?]]></description><link>https://www.defendersinitiative.com/p/cybersecurity-a-market-for-lemonade</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/cybersecurity-a-market-for-lemonade</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Mon, 03 Nov 2025 14:33:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!G8Et!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>George Akerlof&#8217;s seminal economics paper, &#8220;<a href="https://en.wikipedia.org/wiki/The_Market_for_Lemons">The Market for &#8216;Lemons&#8217;: Quality Uncertainty and the Market Mechanism</a>&#8221; is based on how information asymmetry between buyers and sellers can hurt the buyer. These markets can become more common when it is difficult for the buyer to determine the quality of something, because it:</p><ol><li><p>requires expert knowledge</p></li><li><p>requires special tools, or</p></li><li><p>requires access the buyer doesn&#8217;t have</p></li></ol><p>The cybersecurity market takes this to an extreme: sometimes, even the <em>sellers</em> aren&#8217;t aware of the quality of their product. Ross Haleliuk said it best in his book, Cyber for Builders.</p><p>&#8220;<a href="https://www.amazon.com/Cyber-Builders-Essential-Building-Cybersecurity-ebook/dp/B0CRK837K1?sr=8-1">The quality of what is bought and sold is not known.</a>&#8221;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you hate what I&#8217;m writing, subscribe so you can tell me how wrong I am whenever I post something new. If you LIKE what I&#8217;m writing, consider becoming a paid subscriber so I can spend more of my time writing!</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>When evaluating, buying, and using cybersecurity products, it can be difficult to determine how well a product works. It isn&#8217;t uncommon to discover security products that weren&#8217;t even functional after being deployed. Another challenge is determining how effective the product is.</p><p>No one is (or should be) satisfied with simply blocking <a href="https://en.wikipedia.org/wiki/EICAR_test_file">EICAR</a>, for example. If an anti-virus product is only good at blocking commodity malware but no self-respecting cybercriminal will ever use commodity malware, this product isn&#8217;t useful for much more than a compliance checkbox.</p><h1>FireEye, it had what networks crave</h1><p>Back in 2012, I was building a security program for a large enterprise. I spent the better part of a month trying to figure out what FireEye&#8217;s product did. This was before FireEye went public and their only product was the NX appliance. Every time a salesperson pitched me the product, their description brought me to the same conclusion: &#8220;so, this is intrusion detection? This is an IDS/IPS?&#8221;</p><p>The salesperson quickly pushed back on the description. &#8220;Oh no, I was told in no uncertain terms that our product is NOT an IDS or an IPS device.&#8221; This was unsurprising, as Gartner had declared IDS dead as far back as 2003 (it is still commonly used today). We&#8217;d loop back to the beginning of the conversation and they would explain it to me all over again.</p><p>After chatting with a third sales rep at FireEye, it became obvious that their own employees (or at least their sales teams), didn&#8217;t seem to understand what the product did.</p><p>The fourth time was the charm. I finally got an engineer on the line and was told that the FireEye NX appliance was designed to catch malware on the wire, but <em>only really bad malware</em>. It would ignore the commodity stuff. Long story short, my org bought a heavily discounted NX appliance, despite my recommendation to pass on it.</p><p>We pulled it out of the box, racked it, plugged it into a SPAN port (no chance were we going to put it in-line) and powered it on. The first challenge was how to determine whether or not it was working.</p><p>How do you test a product that only detects &#8216;really bad&#8217; malware? What even is &#8216;really bad&#8217;? How does it determine bad from not-so-bad malware? FireEye had a solution: a custom PDF that, like EICAR, was guaranteed to trigger an alert every time. That solved the problem of functional testing. Would it be effective though? Would it actually detect malware?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2x7m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2x7m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2x7m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2x7m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2x7m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2x7m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg" width="1280" height="853" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:853,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:217219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/176978906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2x7m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg 424w, https://substackcdn.com/image/fetch/$s_!2x7m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg 848w, https://substackcdn.com/image/fetch/$s_!2x7m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!2x7m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c386a53-a7b0-4ddb-b33b-d48f3342854f_1280x853.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It did not. FireEye generated roughly one false positive per month. In the same time, we were hit with a few malware infections per month. Malware got past the FireEye appliances by shipping as a JAR file that contained an obfuscated WinPE that it would reassemble on the desktop, after it got past our watchful FireEye&#8217;s network surveillance. This was one of many malware delivery evasions that worked over the years to bypass security products.</p><p>The product didn&#8217;t just lack value, it had <em>negative</em> value. I calculated that the cost of the product itself, plus the time it wasted every time we had to respond to a false positive and investigate it, put FireEye&#8217;s value over six digits in the red.</p><p>Another problem was that, due to the cost of the appliance, we could only afford to purchase one, and put it in our headquarters, where we had the least problem with malware infections. Most of our issues were at sales offices in the field, that often had no more than 5 employees per office. The whole idea for the device was fundamentally flawed.</p><p>This would become even more obvious years later as we saw the company struggle with heavy churn (customers not renewing contracts). I was an industry analyst at this point and referred to this event as <em>FireEye Buyers&#8217; Remorse.</em> This was unsurprising, given my experience with the product, and my theory that both the seller and buyer didn&#8217;t seem to understand what the product did. The <a href="https://www.crn.com/news/security/300072383/fireeye-nss-labs-continue-to-trade-barbs-over-testing-report-credibility">NSS Labs/FireEye battle</a> a few years later further proved this theory.</p><p>The FireEye story is a long-winded way to point out that the Cybersecurity market produces a lot of lemons. The average buyer doesn&#8217;t have the security talent in house necessary to simulate a real attack and determine if there&#8217;s any value in buying these kinds of products. They can <em>maybe</em> afford to pay for a penetration test once a year, but unless they&#8217;re paying for the best in the business, they&#8217;re probably going to get someone a few years out of school operating mostly automated tools.</p><p>Security products aren&#8217;t all about preventing attacks, however. We have security operations products, GRC products, application security products, vulnerability management products, and more. Most suffer from similar information asymmetry issues that hark back to <em>The Market for Lemons</em>.</p><p>It is not practical for most companies to properly evaluate and test security products before buying them.</p><h1>When life gives you lemons</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G8Et!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G8Et!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!G8Et!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!G8Et!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!G8Et!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G8Et!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg" width="1280" height="1280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:144507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/176978906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!G8Et!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!G8Et!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!G8Et!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!G8Et!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1ca95cd-60f6-403a-b4ba-e204e64e9763_1280x1280.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cybersecurity products also have this nagging tendency to create entirely new problems. A large portion of the market pumps out what I think of as <em>busywork generators</em>. Right out of the box, these products will consume logs, scan for vulnerabilities, detect potential attacks, and identify compliance gaps. Overnight, security analysts can be buried in hundreds of thousands or even millions of tasks.</p><p>You&#8217;ve probably heard the terms &#8216;alert fatigue&#8217; or &#8216;vulnerability overload&#8217;. This problem, again, has its roots in information asymmetry. The vendors say, &#8220;this stuff is bad&#8221;, and many buyers aren&#8217;t in a position to refute or challenge it. Meanwhile, security products fail to stop threats, detect attacks, or alert practitioners when products are misconfigured. If you&#8217;ve been a practitioner for even a year or two, you likely have examples you can cite. Here are a few of mine:</p><ol><li><p>When I first used a SIEM in 2004, I was floored to discover that there was no mechanism to tell me when devices suddenly stopped sending logs. I had to build it myself. Again, in 2012, I found nothing had changed. SIEMs still didn&#8217;t perform this basic, fundamental task.</p></li><li><p>I once discovered that a client&#8217;s DAST scanner, which was scanning 14 websites by domain, had 13 misspelled domain names (they were missing the &#8216;m&#8217; on dot com). 13 of the 14 domains it was scanning didn&#8217;t exist, and the tool didn&#8217;t tell them that. Since 1 of the 14 was getting scanned, they assumed everything was fine.</p></li><li><p>These days, security tools represent significant security risks and attack surface - one out of ten vulnerabilities in CISA&#8217;s known exploited vulnerabilities list belong to a security vendor.</p></li></ol><p>Visibility is important in cybersecurity - no security leader wants to be in a situation where they&#8217;re blind to an attack, a vulnerability, or a gap in their compliance program. Buyers ask the vendor to show them everything, and their staff drown in the results. I&#8217;ve observed an unwillingness to reduce this noise level.</p><p>Why? A sort of hoarding or FOMO effect exists with security leaders. Is it more defensible to enable all the alerts and say &#8220;we missed it because we don&#8217;t have enough people in the SOC&#8221;? Or is it more difficult to disable the noisiest alerts and risk missing something?</p><p>You can bet the market noticed this problem and was eager to sell a solution.</p><h1>This market makes lemonade</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KSlH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KSlH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png 424w, https://substackcdn.com/image/fetch/$s_!KSlH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png 848w, https://substackcdn.com/image/fetch/$s_!KSlH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!KSlH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KSlH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png" width="1280" height="1280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1040623,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/176978906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KSlH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png 424w, https://substackcdn.com/image/fetch/$s_!KSlH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png 848w, https://substackcdn.com/image/fetch/$s_!KSlH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!KSlH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6250d66f-1548-446c-9d4c-cfed79c5cb67_1280x1280.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Initially, the solution was to click the export-to-CSV button and make sense of the data in Excel. However, once vendors noticed buyers struggling, we started to see entire market segments spring up to solve the problems that other security products created.</p><p>Pause for a moment to consider a scenario:</p><ol><li><p>You bought a vulnerability scanner for $75k. You run your first scan. The results overwhelm your team.</p></li><li><p>You ask for more headcount and hired more folks to address the workload. Maybe this worked for a while, maybe not.</p></li><li><p>Web 2.0 happens. Your company builds fancy webapps and maybe even offers SaaS to customers.</p></li><li><p>You buy a web scanning tool for $35k. You run your first scan. The results overwhelm your team</p></li><li><p>The cloud is invented and your company adopts it, but doesn&#8217;t get rid of the existing datacenter.</p></li><li><p>You buy a cloud scanning tool for $50k. You run your first scan. The results overwhelm your team.</p></li><li><p>By the way, you&#8217;re not sure if ANY of these tools have gaps. You&#8217;re not sure if they&#8217;re finding all the critical vulnerabilities, because testing security tool efficacy is hard. Also, you don&#8217;t have time, because you&#8217;re too busy chasing all the busywork these tools are generating.</p></li><li><p>A product category emerges and offers an enticing pitch: what if we took all those scans, combined them, and prioritized the findings, making your staff&#8217;s job easier? This product costs $125k.</p></li></ol><p><em>Now </em>we&#8217;re making lemonade. The buyer isn&#8217;t even sure the scanners are producing value but are buying another layer of products to fix the problems created by the first layer. I want to be clear - the lemonade makers aren&#8217;t the lemons, they&#8217;re just spotted a market opportunity: &#8220;hey, that&#8217;s a <em>lot</em> of lemons you&#8217;ve got there. You might as well make some lemonade, right?</p><p>Some examples of lemonade makers:</p><ul><li><p>The risk-based vulnerability management (RBVM) market, which is the example from the scenario above. These tools don&#8217;t include a vulnerability scanner, so you&#8217;ve got to purchase them <em>in addition</em> to vulnerability scanning tools.</p></li><li><p>Security analytics, SOAR, UBEA, and others were add-ons to the classic SIEM, offering to do what the original SIEM vendors promised 20 years ago: correlate data, extract insights.</p></li><li><p>But wait, why did we need a SIEM in the first place? Probably because we didn&#8217;t want to have to log into a dozen different security products to check for alerts, correlating timestamps across devices manually. We&#8217;re potentially three or more levels deep on this one, especially if you have a data lake, ETL products, an MSSP/MDR to handle SOC monitoring in the off-hours&#8230;</p></li><li><p>Products like FireEye&#8217;s NX (&#8217;Breach Detection Systems&#8217;) positioned themselves as complementary to IDS and IPS devices as well as endpoint security products.</p></li><li><p>You can buy a license for an <a href="https://sharedassessments.org/sig/">expensive TPRM spreadsheet</a> and then an AI-powered GRC product to automate filling it out.</p></li><li><p>Interestingly, there&#8217;s <a href="https://regmedia.co.uk/2025/10/28/at_bay_2025_insursec_report.pdf">some analysis out from At-Bay</a> showing that you&#8217;re <em>more</em> likely to file an email-incident-related cyber insurance claim if you have an email security appliance vs just using the security built into your email platform. Dig a little deeper and you&#8217;ll find that At-Bay is also <a href="https://www.at-bay.com/mdr/email/">getting into the lemonade business</a>.</p></li><li><p>I&#8217;ll stop now, but feel free to mention more in the comments, or challenge any of the examples I&#8217;ve come up with here.</p></li></ul><h1>Hope you&#8217;re thirsty</h1><p>The problems created by core security products are almost always very obvious process issues (e.g. too much data to process, analyze, or action). This is great for second tier products, because it&#8217;s <em>very</em> easy for them to demonstrate and measure value in terms of time saved versus the old product. The problem is that the buyer doesn&#8217;t know if the core products were doing a good job to begin with.</p><p>&#8220;Wait, I didn&#8217;t even want lemons in the first place, did I?&#8221;</p><p>I can&#8217;t fault these second-tier lemonade vendors, because they&#8217;re responding to real issues that customers have. It can be an uphill battle for them as well - it&#8217;s not easy for buyers to hear that they need to buy an additional product to make their existing tools work properly. Buyers will often defer the decision until the problem becomes super painful.</p><p>Why doesn&#8217;t this secondary market simply replace the core vendor and solve the core problems, then?</p><p>There might not be a universal reason for this, but I have a few thoughts:</p><ol><li><p>rebuilding the core product is difficult and expensive (e.g. building 200,000 vulnerability checks from scratch)</p></li><li><p>the solution to the core problem isn&#8217;t obvious</p></li><li><p>the industry&#8217;s collective <a href="https://yourbias.is/the-sunk-cost-fallacy">sunk cost</a> is too great: the solution requires a completely different approach, requiring the vendor to reeducate the market and go against common practices, certifications, standards, and regulations</p></li></ol><p>The final theory is a <em>really</em> tough one. It has been observed that security leaders are swayed towards the choices that are <a href="https://www.linkedin.com/posts/valeritsanev_ciso-vendorselection-enterprisesales-activity-7381340234472456193-NCL0/">safest for their personal careers</a>. When the choice is going against the grain versus doing the safe thing, the data tells us the latter is going to be the more common path.</p><h1>Conclusion</h1><p>There&#8217;s no Ozempic for cyber yet, so we&#8217;re faced with a familiar dilemma. We can keep downing lemonade, getting nowhere with our goals, or start doing the hard (diet and exercise) work necessary to determine what works and ditch what doesn&#8217;t. The latter is tough, as there are little to no incentives to challenge the status quo, even when it is clearly broken.</p><p>In consumer markets, information asymmetry tends to solve itself when value is obvious. If a particular model or brand of laptop breaks a lot, it will have lots of bad reviews online. A laptop breaking is an outcome that can&#8217;t be ignored.</p><p>Cybersecurity isn&#8217;t like this. It is more comparable to the health supplement market. Do I feel amazing today because I got an extra hour of sleep, or because I started making drinks with this green powder? Most consumers don&#8217;t have the time or patience to scientifically test every new nutrition product or trend they try out, so if they think it makes them feel better, they&#8217;ll keep buying it or doing it.</p><p>At least with nutritional supplements, there will be folks that will put them to the test, or send products to a lab to determine if they&#8217;re <a href="https://www.consumerreports.org/lead/protein-powders-and-shakes-contain-high-levels-of-lead-a4206364640/">even safe to consume</a>. Cybersecurity doesn&#8217;t really have an equivalent, unfortunately.</p><p>This is a critical problem in cybersecurity. When we don&#8217;t know how well our tools or controls are working, we&#8217;re at a distinct disadvantage as defenders. As Charlie Miller once put it:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IzzK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IzzK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png 424w, https://substackcdn.com/image/fetch/$s_!IzzK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png 848w, https://substackcdn.com/image/fetch/$s_!IzzK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png 1272w, https://substackcdn.com/image/fetch/$s_!IzzK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IzzK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png" width="932" height="484" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:484,&quot;width&quot;:932,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:243205,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/176978906?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IzzK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png 424w, https://substackcdn.com/image/fetch/$s_!IzzK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png 848w, https://substackcdn.com/image/fetch/$s_!IzzK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png 1272w, https://substackcdn.com/image/fetch/$s_!IzzK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328aa52d-368b-48ee-a896-e3aef0e3c7b2_932x484.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Buyers <em>should</em> be pushing back on products that create more problems than they solve. However, without a clear path to better products, practitioners continue on, buying what their peers bought that didn&#8217;t get them fired. Ironically, a big part of the problem is a lack of risk appetite for better security products.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">If you made it this far, thank you so much! I hope this post moves you to subscribe, leave a comment, or share this post with others that might enjoy it.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Asbestos of IT: why old protocols just aren’t worth it]]></title><description><![CDATA[If you CAN get rid of them, DO it - it&#8217;s worth the migration pain]]></description><link>https://www.defendersinitiative.com/p/the-asbestos-of-it-why-old-protocols</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/the-asbestos-of-it-why-old-protocols</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Sat, 04 Oct 2025 18:05:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nV3t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>UPDATED on May 4th, 2026 to add web-based administrative interfaces in the wake of Internet-wide cPanel compromises.</p><p>UPDATED on June 5th, 2026 to add SSH and emphasize that ALL administrative interfaces should be taken off the Internet.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Defender's Initiative is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>We see it over and over and over again with breaches:</p><ol><li><p>attackers got in via RDP (<a href="https://en.wikipedia.org/wiki/Atlanta_government_ransomware_attack">Atlanta</a>, <a href="https://www.techtarget.com/healthtechsecurity/news/366595312/RDP-Botnet-Malware-Top-Access-Point-of-Updated-Ryuk-Ransomware">Ryuk</a>)</p></li><li><p>attackers got in via VPN (<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-110a">Pulse Secure</a>, <a href="https://www.techradar.com/pro/security/sonicwall-vpn-accounts-breached-by-akira-ransomware-even-those-using-mfa">SonicWall/Akira</a>)</p></li><li><p>FTP credentials were guessed or brute-forced (<a href="https://www.malwarebytes.com/blog/news/2018/05/samsam-ransomware-need-know">SamSam</a>, <a href="https://cybelangel.com/risk-third-party-ftp-servers-finance/">General Scanning &amp; Attacks</a>)</p></li><li><p>File transfer products exploited (Accelion FTA, MoveIT, GoAnywhere MFT)</p></li><li><p>Firewalls exploited via their management interfaces (Juniper ScreenOS backdoor, PanOS vulns, FortiGate 0days)</p></li><li><p>Web-based administrative interfaces, like <a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/">cPanel</a></p></li></ol><p>Each of these examples represent old ways of accessing services. For each, there are now better, more secure ways of performing each of these functions, without exposing these services to the public Internet. These are also some of the most popular attack targets for attackers!</p><p>That&#8217;s why I think of this as the <em>asbestos of IT</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nV3t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nV3t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nV3t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nV3t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nV3t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nV3t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg" width="1456" height="1097" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1097,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1039512,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://defendersinitiative.substack.com/i/174965804?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nV3t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nV3t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nV3t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nV3t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f35b54f-04cd-45e0-a966-1e4d802475d3_1920x1446.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Fenced-off asbestos-contaminated mulch in Rozelle Parklands, Sydney, Australia, from <a href="https://commons.wikimedia.org/wiki/File:Rozelle_Parklands_Asbestos_Mulch.jpg">Wikimedia Commons</a></figcaption></figure></div><p>Asbestos was also very useful, but dangerous to humans. As soon as we realized this, we labeled it as a dangerous substance and started replacing it with safer materials. The time has come to replace outdated, dangerous protocols with more secure alternatives.</p><p>The key to replacing each of these services is to find alternatives that don&#8217;t require exposing TCP/UDP ports to the public Internet.</p><ol><li><p>Replacing RDP: There are a TON of options here. You likely have something built into whatever tool you use for managing your mobile devices or servers. In liu of that, I personally like RustDesk, because it doesn&#8217;t require you to trust a third party like AnyDesk and TeamViewer do - you can set up and manage your own server. It does still use a direct TCP connection, however, so you&#8217;ll need a modern VPN technology, which brings me to&#8230;</p></li><li><p>Replacing VPN: Whether you call it ZTNA or SDP, the big innovation here was allowing access without opening ports. I use Tailscale, which is how I get to RustDesk on my hosts (I don&#8217;t bother with the RustDesk server, I just connect direct client to host). I recently tested RustDesk over Tailscale, on an iPad, <em>from Delta&#8217;s in-flight Wi-Fi</em>, and it was like I was sitting right in front of my studio PC. I was very impressed.</p></li><li><p>Replacing FTP: There are so many options for file sharing or file transfer that we&#8217;re spoiled for choice. The replacement depends on your use case. Publishing files to a web server? Use GitHub or other code deployment tools. Business to business transfers? S3 bucket (or GCP/Azure equivalents). Consider something like ShareFile, Dropbox, Box, Google Drive, OneDrive for human to human file sharing.</p></li><li><p>Replacing old-school file transfer products: See #3 above.</p></li><li><p>Firewalls getting exploited via management interfaces: <em>Don&#8217;t ever share management consoles on Internet-exposed interfaces!</em> See #2 above</p></li><li><p>Web-based administrative interfaces represent broad concentration risk - WordPress and cPanel alone probably represent the majority of all websites on the Internet. Wouldn&#8217;t it be crazy if there was a basic, RCE that affected <a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/">all of them</a>? This one is a bit trickier to rearchitect than the previous 5 examples, but it&#8217;s the same basic approach. Put an authentication gateway in front of the web services themselves<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>, or use modern VPN technologies to access them. Even IP-based restrictions are better than nothing!</p></li><li><p>SSH and any other administrative interfaces. If 3 people need to access SSH on a server, why give the entire Internet access to it? Any configuration mistake, new vulnerability, or stolen SSH keys can immediately be leveraged by attackers if accessing the actual TCP service is trivial. Make it difficult - use ZTNA to access it. Use IP access control lists. Anything aside from opening it up to the entire world.</p></li></ol><p>As always, some caveats: yes, I understand your vendor requires you to use FTP, there&#8217;s not much you can do about that, except to fire your vendor, or ensure there&#8217;s nothing too sensitive being transferred. </p><p>There are other reasons you might not be able to get off legacy protocols. Document them, put mitigations and detections around them as best you can, and be ready to respond to any incidents that come from using them.</p><p>If you <em>can </em>ditch legacy protocols, however, the reduction in attack surface will be worth it and you can sleep that much better at night.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Defender's Initiative is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Of course, we could argue this just shifts the concentration risk to an Okta, SASE, or whomever is providing the auth gateway.</p></div></div>]]></content:encoded></item><item><title><![CDATA[Address alert fatigue without AI: alert less to see more]]></title><description><![CDATA[You only need one reliable alert to detect an attacker - stop burying yourself in noise]]></description><link>https://www.defendersinitiative.com/p/address-alert-fatigue-without-without</link><guid isPermaLink="false">https://www.defendersinitiative.com/p/address-alert-fatigue-without-without</guid><dc:creator><![CDATA[Adrian Sanabria]]></dc:creator><pubDate>Sat, 04 Oct 2025 17:34:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rsmo!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabef315d-26c2-461c-a09d-569e333de487_1280x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The idea that there are organizations triaging hundreds or even thousands of alerts each day, on days when they&#8217;re not being attacked, seems like madness to me. In what other industry would we accept such a low level of accuracy when detecting a threat? Imagine your doctor was telling you a dozen times a day that you had cancer, or that your fire alarm went off 6 times a day, every day.</p><p>It has been a few years since I discussed this and the last time I did, <a href="https://medium.com/@sawaba/is-it-possible-to-find-security-value-in-logs-ffa07c9e0179">it was a bit buried at the end of the post</a>. I thought I&#8217;d share an approach to detection engineering I came up with a long time ago that might help. I&#8217;m also a bit baffled that the industry seems overly focused on addressing alert fatigue from the back end (using AI to triage, enrich, and investigate) rather than on the front end (avoid generating so many alerts in the first place).</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.defendersinitiative.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The Defender's Initiative is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>The Red Flags vs Yellow Flags approach</h1><p>Red flags vs yellow flags is a simple system I came up with to focus when building out detections. You really only need one red flag to know an attacker is present. After that, diving into the details becomes easier. By focusing on a smaller number of higher quality detections, alert fatigue is alleviated, response times improve, and coverage improves.</p><p>I&#8217;ll repeat the most important bit here: <em>you don&#8217;t need to alert on everything an attacker does</em>. You&#8217;re still <em>logging </em>everything the attacker does, you&#8217;re just not filling up alert queues with every action they take.</p><p>I came up with this approach, naturally, after initially doing everything the wrong way. I ingested every event from every source into the SIEM and enabled every alert and detection. We were instantly buried in noise. I started to think, <em>what if I built this in reverse</em> from what I&#8217;ve just done? What would that look like?</p><ol><li><p>Study how attacks happen and succeed. What do attackers <strong>have</strong> to do? What are TTPs we see them using over and over?</p></li><li><p>How few of these actions can we get away with looking for and still ensure we&#8217;re catching attackers every time? Which actions are the easiest to detect reliably, with a very low false positive rate?</p></li><li><p>What data do I need to collect to detect these things happening?</p></li><li><p>Start building detections for these things.</p></li><li><p>Test to see that my detections work</p></li><li><p>Make sure we have SOPs or playbooks for these detections (containment and/or eradication actions: disable accounts, kill sessions, isolate machines, etc)</p></li><li><p>Do the thing: test to see that my SOC folks notice the detections when they fire and handle them according to plan</p></li></ol><h1>Defining Red vs Yellow</h1><p>Step 2 is where we&#8217;re separating yellow flags from red flags. <strong>Red flags</strong> are alerts that are always bad. They&#8217;re relatively easy to detect with a near zero false positive rate. Mimikatz is always a red flag. A binary downloaded from a domain that has only existed for 3 days is almost always bad. A cryptominer on an EC2 instance is a bad sign. A powershell terminal executed by a Word document. You get the idea.</p><p>This approach doesn&#8217;t mean we totally ignore yellow flags, just that we ensure we don&#8217;t <em>miss</em> any red flags due to noise from the yellows. A <strong>yellow flag</strong> is a lower quality tier of detection - something that is suspicious, given the right criteria. They&#8217;re maybes. Maybe this is a red flag, if it&#8217;s 3AM and comes from the receptionist&#8217;s PC and talks out to a strange host. Most orgs are <em>drowning</em> in maybes.</p><p>A login event at an odd time might be suspicious, but it won&#8217;t always be a red flag. Or perhaps, it&#8217;s a red flag, but only for three employees. Impossible travel alerts are an example of this. Impossible travel once seemed like a high quality detection, but sometimes proxies, VPNs, or SaaS products reduce the reliability of these alerts. Several yellow flags could amount to a red flag: a compound detection. Say we see a login from an odd location, followed by a very broad query in a database, and an attempt to bulk download the results. Feels like a smash and grab, perhaps by a ransomware crew.</p><h1>When have we gone too far?</h1><p>As you can see, the more we go down this path of adding context and complexity to detections, the chances for false positives go up. The most difficult part of this approach is resisting overbuilding detections. Fear of missing out on events can lead to alert hoarding, which can lead to alert blindness. Trying to see too much results in blindness.</p><p>Even one reliable, well-tested red flags detection is a huge win - I&#8217;ve worked in so many environments where even the noisiest penetration test doesn&#8217;t set of a single alert. Limiting the number of detections doesn&#8217;t mean that you&#8217;re not logging all the other actions performed by the attacker, you&#8217;re just limiting alerts to what is manageable for your organization and ensuring they work.</p><p>Herein lies the most difficult part of this approach: being comfortable with the quiet. Inevitably, folks ask, &#8220;but Adrian, I might miss hundreds of advanced and sophisticated attacks!&#8221; The reality is that even the most sophisticated actors still use some very basic tools and techniques (because they work), and you&#8217;re not ready to start building or enabling detections for these kinds of attacks if you don&#8217;t have the more common ones working. Resist the urge! Seriously, get good at detecting and responding to just ONE common type of attack. Get really, really good at it, to the point where you never miss it, and you&#8217;ll understand where the bar needs to be set for the rest of your detections.</p><p>The advantage of this approach, is that it should result in a relatively quiet SOC if nothing is happening. This creates time and opportunities for threat hunting and further finding red flags and tuning detections to find them.</p><p>A less noisy approach won&#8217;t need to lean so heavily on AI, if at all. I personally don&#8217;t think generative AI can scale to the needs of large SOCs, but that&#8217;s a discussion for a different post.</p><h1>Bonus Round: Deception</h1><p>Modern honeypots and honeytokens are a great way to create red flags from scratch. By definition, they shouldn&#8217;t be accessed or used by legitimate employees, so they&#8217;re a great way to artificially create red flags. Create a fake admin account that doesn&#8217;t belong to any admins and seed its credentials in key places. Any use of this account is a red flag. As always, <a href="http://canarytokens.org/">canarytokens.org</a> is the best place to start exploring and testing this approach. This is also the quickest way to understand what a great, red flag detection looks and feels like.</p>]]></content:encoded></item></channel></rss>