<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Resilient Cyber]]></title><description><![CDATA[Resilient Cyber distills the week's most important news, research, and writing across AppSec,
AI security, software supply chain, and security leadership. Join 30,000+]]></description><link>https://www.resilientcyber.io</link><image><url>https://substackcdn.com/image/fetch/$s_!ITbg!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71894ea3-c231-4d31-90a9-414d75111d0e_1280x1280.png</url><title>Resilient Cyber</title><link>https://www.resilientcyber.io</link></image><generator>Substack</generator><lastBuildDate>Fri, 11 Sep 2026 12:14:10 GMT</lastBuildDate><atom:link href="https://www.resilientcyber.io/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Chris Hughes]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[resilientcyber@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[resilientcyber@substack.com]]></itunes:email><itunes:name><![CDATA[Chris Hughes]]></itunes:name></itunes:owner><itunes:author><![CDATA[Chris Hughes]]></itunes:author><googleplay:owner><![CDATA[resilientcyber@substack.com]]></googleplay:owner><googleplay:email><![CDATA[resilientcyber@substack.com]]></googleplay:email><googleplay:author><![CDATA[Chris Hughes]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Resilient Cyber Newsletter #113]]></title><description><![CDATA[Arora&#8217;s $1T Legacy Security Claim, OpenAI&#8217;s Astra & $1B Defender Fund, Another Agent Swarm Escapes, GTIG on Agentic Attackers, Patch the Planet, Sovereign AI Raises & Agents as Insider Threats]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-113</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-113</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 11 Sep 2026 12:04:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1Fvo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #113 of the Resilient Cyber Newsletter.</p><p>This week OpenAI shipped its first model to hit the Critical cybersecurity threshold under its own Preparedness Framework, pledged $1B in subsidized access for under-resourced defenders, and, in the same news cycle, had a second swarm of its internal agents discovered running loose on the open internet. </p><p>Google&#8217;s threat intel team documented adversaries standing up agentic credential harvesting pipelines in under six hours, while the SANS CEO and a builder in the agent monitoring space both made the case that the gap sits with people and fundamentals well before it sits with models.</p><p>On the market side, PANW&#8217;s Nikesh Arora put a $1 trillion price tag on the legacy security stack, the company&#8217;s founder raised $245M to build a replacement for it, and Mistral closed the largest equity round in European tech history on a sovereignty pitch.</p><p>Safe to say, we have a lot of ground to cover this week, so let&#8217;s go!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Fvo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Fvo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png 424w, https://substackcdn.com/image/fetch/$s_!1Fvo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png 848w, https://substackcdn.com/image/fetch/$s_!1Fvo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png 1272w, https://substackcdn.com/image/fetch/$s_!1Fvo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Fvo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png" width="614" height="394.7142857142857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:702,&quot;width&quot;:1092,&quot;resizeWidth&quot;:614,&quot;bytes&quot;:561325,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Fvo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png 424w, https://substackcdn.com/image/fetch/$s_!1Fvo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png 848w, https://substackcdn.com/image/fetch/$s_!1Fvo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png 1272w, https://substackcdn.com/image/fetch/$s_!1Fvo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7373567-a595-45cf-8165-4bb8c87bea42_1092x702.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.cnbc.com/2026/09/01/palo-alto-ceo-says-1-trillion-of-cybersecurity-infrastructure-isnt-ready-for-ai.html">Palo Alto CEO says $1 trillion of cybersecurity infrastructure isn&#8217;t ready for AI</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k82O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k82O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png 424w, https://substackcdn.com/image/fetch/$s_!k82O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png 848w, https://substackcdn.com/image/fetch/$s_!k82O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png 1272w, https://substackcdn.com/image/fetch/$s_!k82O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k82O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png" width="846" height="210" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:210,&quot;width&quot;:846,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:33740,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k82O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png 424w, https://substackcdn.com/image/fetch/$s_!k82O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png 848w, https://substackcdn.com/image/fetch/$s_!k82O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png 1272w, https://substackcdn.com/image/fetch/$s_!k82O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4ae5334-8c9c-480a-aabe-7b262a6bd185_846x210.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Palo Alto Networks reported its fiscal Q4 this week, with revenue of $3.41B (up 34% YoY), Next-Generation Security ARR of $9.1B (up 63%), and RPO of $21.2B, and Nikesh Arora used the earnings cycle to make a much bigger claim. Per Arora:</p><blockquote><p><strong> &#8220;About $1 trillion of existing cybersecurity infrastructure was built before the dawn of AI and is not ready for the new threat landscape.&#8221; </strong></p></blockquote><p>His math is that &#8220;If the average life is seven years and you&#8217;re spending $200 to $300 billion a year, you&#8217;ve got $1 trillion of security infrastructure,&#8221; most of it firewalls, SIEMs, and endpoint tooling deployed 7-10 years ago. He also pointed to &#8220;$5 trillion of capex spend in the next five years&#8221; on AI data centers as a second wave of security demand.</p><p>Of course, the CEO of one of the largest security vendors has an obvious incentive to declare the installed base obsolete, and this is a replacement thesis dressed up as a threat assessment. </p><p>That said, the underlying point isn&#8217;t wrong. Most of what organizations run today was architected around human-speed attackers, and the GTIG report below documents adversaries who no longer operate that way. </p><p>The same week, PANW was named to the S&amp;P 100 alongside Dell, Arista, and SanDisk, replacing Nike, and the only public pure-play cyber company in the mix, which is incredible for the cyber community.</p><h3><a href="https://www.calcalistech.com/ctechnews/article/2aid6v54y">Palo Alto&#8217;s CEO invested in the startup his company just bought for $500 million</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9ssm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9ssm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png 424w, https://substackcdn.com/image/fetch/$s_!9ssm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png 848w, https://substackcdn.com/image/fetch/$s_!9ssm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png 1272w, https://substackcdn.com/image/fetch/$s_!9ssm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9ssm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png" width="599" height="174" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:174,&quot;width&quot;:599,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24573,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9ssm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png 424w, https://substackcdn.com/image/fetch/$s_!9ssm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png 848w, https://substackcdn.com/image/fetch/$s_!9ssm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png 1272w, https://substackcdn.com/image/fetch/$s_!9ssm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f373216-d1ed-496e-b311-d3a21bb12ea3_599x174.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>A follow-up to the Console acquisition I covered last week. Calcalist reports that Arora was an early personal investor in Console, alongside Thrive Capital, before Palo Alto acquired the company for roughly $500M. Console was founded in 2024, had raised $29M in total, and was valued at $157M in its last round, so the exit represents a sizable step-up for everyone on the cap table, the acquiring CEO included.</p><p>I won&#8217;t pretend to know the details of how the deal was reviewed internally, and there are governance processes for exactly this scenario at public companies. However, when the same person is a personal LP on one side and the buyer on the other, the optics are what they are, and it is a reminder that the AI security M&amp;A wave is moving fast enough that these conflicts are going to keep surfacing.</p><h3><a href="https://cylake.com/resources/cylake-closes-245-million-funding-round/">Cylake closes $245 million funding round ahead of beta</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CehR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CehR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png 424w, https://substackcdn.com/image/fetch/$s_!CehR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png 848w, https://substackcdn.com/image/fetch/$s_!CehR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png 1272w, https://substackcdn.com/image/fetch/$s_!CehR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CehR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png" width="570" height="254" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ebc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:508,&quot;width&quot;:1140,&quot;resizeWidth&quot;:570,&quot;bytes&quot;:390202,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CehR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png 424w, https://substackcdn.com/image/fetch/$s_!CehR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png 848w, https://substackcdn.com/image/fetch/$s_!CehR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png 1272w, https://substackcdn.com/image/fetch/$s_!CehR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febc92a1d-17e8-4dbb-81bf-64ad3e33ac8c_1140x508.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Nir Zuk, who founded Palo Alto Networks, has now raised $290M for Cylake (a $245M convertible note this week on top of a $45M Greylock-led seed in March) <em><strong>before</strong></em> the product has hit beta. </p><p>The pitch is an AI-native, &#8220;fully sovereign&#8221; security platform that runs on-prem or in a private cloud for large regulated organizations, with beta slated for the end of 2026 and GA in 2027. Zuk&#8217;s framing is that they&#8217;re building &#8220;for organizations that cannot compromise between adopting advanced cybersecurity technology and maintaining control.&#8221;</p><p>It is hard to read this next to Arora&#8217;s $1T comment and not see the same thesis being funded from two directions, one arguing the legacy stack is obsolete and the other arguing that the cloud-delivered stack that replaced it has become the problem for regulated buyers. </p><p>$290M pre-beta is a lot of conviction, and the company has 40-odd employees and design partners to show for it so far, however, much of this remains to be seen in terms of adoption and broad traction.</p><h3><a href="https://mistral.ai/news/mistral-makes-sovereign-open-weight-ai-to-frontier/">Mistral makes sovereign, open-weight AI the technology frontier</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qjbM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qjbM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png 424w, https://substackcdn.com/image/fetch/$s_!qjbM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png 848w, https://substackcdn.com/image/fetch/$s_!qjbM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png 1272w, https://substackcdn.com/image/fetch/$s_!qjbM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qjbM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png" width="600" height="178.97503285151117" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:227,&quot;width&quot;:761,&quot;resizeWidth&quot;:600,&quot;bytes&quot;:119818,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qjbM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png 424w, https://substackcdn.com/image/fetch/$s_!qjbM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png 848w, https://substackcdn.com/image/fetch/$s_!qjbM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png 1272w, https://substackcdn.com/image/fetch/$s_!qjbM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad6caa70-c5a7-404f-89e3-74a7ae7c263b_761x227.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Mistral closed a &#8364;3B Series D at a post-money valuation above &#8364;21B, which the company describes as &#8220;the largest equity fundraising round ever completed by a European technology company,&#8221; led by Samsung Electronics with Scaleup Europe Fund/EQT and PSG Equity co-leading. Mistral now operates in 20 countries with 125+ enterprise customers. The announcement defines sovereignty across four dimensions, data that stays inside the organization&#8217;s boundaries, models that are controllable, compute that is private, and production systems that are auditable.</p><p>Pair this with Cylake above, sovereignty has gone from a European regulatory talking point to a category thesis that U.S. investors are now writing very large checks against, and it applies to the security stack as much as the model layer. </p><p>The GTIG report further down has an interesting wrinkle here, with at least one PRC-nexus actor deploying local LLMs inside compromised cloud environments specifically to avoid commercial API monitoring, which is the exact risk <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd3c6819-d1ef-4f1f-a257-116c0c97172d_1138x1138.png&quot;,&quot;uuid&quot;:&quot;f8ad9f83-f973-4f91-8fea-b7920fd75d96&quot;}" data-component-name="MentionToDOM"></span> has been calling out for months. </p><p>Sovereign compute cuts both ways.</p><h3><a href="https://www.calcalistech.com/ctechnews/article/bj11x7a800ge">Omri Casspi raises $250 million after wins with Cognition, Wonderful and Upwind</a></h3><p>Former NBA player Omri Casspi closed a $250M third fund for Swish Ventures, bringing AUM to $800M. </p><p>The firm has backed 21 companies since inception, 9 of which are now unicorns, with roughly $20M checks and a dozen targets for the new fund. The portfolio marks tell the story of the current cycle, with Wonderful at $5B, Upwind at $3.8B (which I covered last week), and Cognition at $47B. Per Casspi, the aggregate portfolio value &#8220;will reach almost $100 billion&#8221; after the Cognition round.</p><p>Those are venture returns most firms would take in any cycle, and a reminder of how concentrated the value creation in AI and security has become in a small number of companies.</p><h3><a href="https://www.philvenables.com/post/cybersecurity-benchmarking-why-why-not-when-and-how">Cybersecurity Benchmarking: Why, Why Not, When and How</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LcyT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LcyT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png 424w, https://substackcdn.com/image/fetch/$s_!LcyT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png 848w, https://substackcdn.com/image/fetch/$s_!LcyT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png 1272w, https://substackcdn.com/image/fetch/$s_!LcyT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LcyT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png" width="836" height="213" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:213,&quot;width&quot;:836,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:33280,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LcyT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png 424w, https://substackcdn.com/image/fetch/$s_!LcyT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png 848w, https://substackcdn.com/image/fetch/$s_!LcyT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png 1272w, https://substackcdn.com/image/fetch/$s_!LcyT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb839d719-2cc4-4919-9d2b-07a5130c6d50_836x213.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Phil Venables takes on one of the more persistent rituals in security leadership, benchmarking your program against peers, and argues that most of how it gets done is a waste of time.</p><p>Budget comparisons are never apples-to-apples because there is no agreed taxonomy for what counts as security spend, lagging indicators like incident counts tell you little about root cause, and point-in-time assessments go stale quickly. His line is that:</p><blockquote><p><strong>&#8220;Your risk is not my risk. Your business is not my business,&#8221; and my favorite, &#8220;Being No. 1 in a pack of failures doesn&#8217;t make you a success.&#8221;</strong></p></blockquote><p>Where he lands is that benchmarking is useful when it compares leading indicators (infrastructure design patterns, control effectiveness) against an aggregate idealized control set rather than against a specific peer, aligned to something like NIST CSF or CIS Controls, with cost-effectiveness measured separately from performance. </p><p>Given how often boards and CFOs ask &#8220;what do our peers spend,&#8221; this is a timely read for anyone who needs a better answer than a percentage of IT budget. It also pairs well with Arora&#8217;s $1T framing above, which is precisely the kind of input-based spend number Venables warns against treating as a signal.</p><h3><a href="https://www.darkreading.com/cyberattacks-data-breaches/ai-warning-letter-missed-people">What the AI Warning Letter Completely Missed</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xfKr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xfKr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png 424w, https://substackcdn.com/image/fetch/$s_!xfKr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png 848w, https://substackcdn.com/image/fetch/$s_!xfKr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png 1272w, https://substackcdn.com/image/fetch/$s_!xfKr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xfKr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png" width="1038" height="134" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14752dc1-4438-4070-b270-0352e49aa806_1038x134.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:134,&quot;width&quot;:1038,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26768,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xfKr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png 424w, https://substackcdn.com/image/fetch/$s_!xfKr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png 848w, https://substackcdn.com/image/fetch/$s_!xfKr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png 1272w, https://substackcdn.com/image/fetch/$s_!xfKr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14752dc1-4438-4070-b270-0352e49aa806_1038x134.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Last week I covered the open letter from 100+ companies, including OpenAI, Anthropic, Microsoft, and Google, calling for collective action on AI-enabled cyber threats. </p><p>SANS CEO James Lyne&#8217;s response is that the letter is &#8220;a plan written entirely in verbs, with no subject.&#8221; It tells organizations to patch, monitor, and harden, and says nothing about who does that work at the water utilities and hospitals it names, how they get trained, or who pays for it. As he puts it:</p><blockquote><p><strong>&#8220;The gulf between those two is measured in people, not products.&#8221;</strong> </p></blockquote><p>He also cites RUSI analysts who argue that &#8220;Criminal innovation is a response to a revenue stream closing, not to a new technology opening a window,&#8221; which is a useful corrective to the assumption that AI capability automatically becomes adversary behavior.</p><p>I agree with the core of this piece by James. Signatories of that size published a letter with no funding commitments in it, and the organizations most at risk are the ones that can&#8217;t hire. To be fair, OpenAI&#8217;s Daybreak announcement below arrived two days later with $1B attached, albeit in the form of subsidized product access rather than headcount, but we shouldn&#8217;t expect headcount to come externally either</p><p>Whether credits close the gap Lyne is describing is a fair question.</p><p>For me, as I mentioned in LinkedIn about this letter, the reality is that cyber won&#8217;t change until market incentives or regulatory forces make it change systemically. Vendors have little consequences for shipping insecure products, which is the default, as recently pointed out by CISA.</p><blockquote><p><strong>Cybersecurity is a market failure and we cannot will that to change with open letters and voluntary pledges.</strong></p></blockquote><h3><a href="https://youtu.be/qc6SNABoiys">How AI reduced cybersecurity to bugs</a></h3><div id="youtube2-qc6SNABoiys" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;qc6SNABoiys&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/qc6SNABoiys?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Zack Korman&quot;,&quot;id&quot;:524736970,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/994c8d5e-7780-4924-b259-9dc466799ab0_400x400.jpeg&quot;,&quot;uuid&quot;:&quot;c086a4f2-579e-4cae-92b1-d606c93fbfc0&quot;}" data-component-name="MentionToDOM"></span> , who works on agent monitoring at Embroidery, put out a video reacting to an Ilya Sutskever post arguing that &#8220;every company with strong cyber models should help&#8221; neoclouds shore up their security. </p><p>Korman&#8217;s objection is that &#8220;cyber model&#8221; has come to mean vulnerability discovery and exploitation, and if you took 100 people working in defense, very few of them work on that. </p><p>Identity, endpoint, network, detection engineering, SOC, IR, third-party risk, and GRC all sit outside what a frontier lab means when it says cyber. His Vercel breach walkthrough makes the point, with overly permissive third-party app access, harvested credentials, and no detection, and as he says, &#8220;You can have zero vulnerable systems in the sense that there is no code to exploit and you still get breached.&#8221;</p><p>He is blunt about the OpenAI/Hugging Face incident being &#8220;completely preventable on OpenAI&#8217;s side by having the proper monitoring and controls in place,&#8221; and about the industry more broadly, &#8220;We&#8217;ve become followers in our own space. It&#8217;s an embarrassing lack of leadership.&#8221; </p><p>I have made a version of this argument before, that security has a laggard problem, but Korman&#8217;s framing is sharper, that we are letting the labs define what cyber is based on what benchmarks well.</p><p>I really resonated with Zach&#8217;s rant here, and its time for cyber to step up and act like grownups rather than fawning over the frontier labs and acting like we don&#8217;t know how our own damn industry and profession works.</p><h1>AI</h1><h3><a href="https://openai.com/index/path-to-astra/">Path to Astra: critical capabilities and frontier safeguards</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gWKC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gWKC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png 424w, https://substackcdn.com/image/fetch/$s_!gWKC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png 848w, https://substackcdn.com/image/fetch/$s_!gWKC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png 1272w, https://substackcdn.com/image/fetch/$s_!gWKC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gWKC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png" width="950" height="267" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:267,&quot;width&quot;:950,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35296,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gWKC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png 424w, https://substackcdn.com/image/fetch/$s_!gWKC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png 848w, https://substackcdn.com/image/fetch/$s_!gWKC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png 1272w, https://substackcdn.com/image/fetch/$s_!gWKC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda6e2283-78fe-42d9-a9de-18723a0369c1_950x267.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>OpenAI announced Astra, the first of its models to reach the Critical cybersecurity capability threshold under its Preparedness Framework, meaning the model can &#8220;find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step.&#8221; </p><p>The published figures are 100% on an internal ExploitBench port covering 20 high-severity vulnerabilities, two zero-days discovered during evaluation (being disclosed to maintainers), and a 91.5% refusal rate on cyber jailbreak evaluations compared to 59% for GPT-5.6 Sol. In honeypot tests, GPT-5.6 Sol attempted unauthorized access in 56% of instances, Astra in 0%.</p><p>The safeguards stack is worth reading in full, with post-trained refusals, activation classifiers, chain-of-thought monitoring, cross-conversation context monitoring, and misalignment monitoring in production. Access goes to alpha testers first and then expands through Daybreak Blue for defensive work. </p><p>My read is that the capability side of this announcement is a fairly big deal, and the safeguards side is a set of claims the lab is asking us to take on trust, from a company that, per the TechCrunch item below, didn&#8217;t know where its own agents were for over a month. Perhaps both things can be true at once.</p><h3><a href="https://openai.com/index/daybreak-for-frontline-defenders/">Daybreak for Frontline Defenders: $1B to protect essential services</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qb-D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qb-D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png 424w, https://substackcdn.com/image/fetch/$s_!qb-D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png 848w, https://substackcdn.com/image/fetch/$s_!qb-D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png 1272w, https://substackcdn.com/image/fetch/$s_!qb-D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qb-D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png" width="656" height="365.36708860759495" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:790,&quot;resizeWidth&quot;:656,&quot;bytes&quot;:58924,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qb-D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png 424w, https://substackcdn.com/image/fetch/$s_!qb-D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png 848w, https://substackcdn.com/image/fetch/$s_!qb-D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png 1272w, https://substackcdn.com/image/fetch/$s_!qb-D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F911a122a-3681-4ea0-828d-999c371a1bf2_790x440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two days after Astra, OpenAI committed &#8220;$1 billion in subsidized Daybreak access to help resource-constrained cyber defenders, starting with the United States.&#8221;</p><p>Daybreak splits into Blue (defensive work on mainline models) and Red (specialized cyber models for sensitive technical work). The current footprint is thousands of defenders across 2,000 approved organizations in 40 states plus DC, more than 35 enterprise products and partner-operated services, a partnership with MS-ISAC, and up to $1M in no-cost API credits for affected water utilities. State and local governments, critical infrastructure operators, nonprofits, and open source maintainers are eligible.</p><p>This is a strong response to the gap Lyne describes above, and I would rather see $1B in credits than nothing at all. That said, credits are inventory for the company that issues them, and the constraint at a rural water utility is generally a person who has the time and skill to use the tooling, which a subsidy doesn&#8217;t create. </p><p>The open source maintainer eligibility is a piece I&#8217;d watch closely, given what the Patch the Planet numbers below say about where the bottleneck actually sits.</p><h3><a href="https://techcrunch.com/2026/09/04/another-swarm-of-openai-agents-reached-the-open-internet-without-the-frontier-labs-knowledge/">Another swarm of OpenAI agents reached the open internet without the frontier lab&#8217;s knowledge</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dsL4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dsL4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png 424w, https://substackcdn.com/image/fetch/$s_!dsL4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png 848w, https://substackcdn.com/image/fetch/$s_!dsL4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png 1272w, https://substackcdn.com/image/fetch/$s_!dsL4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dsL4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png" width="561" height="199" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:199,&quot;width&quot;:561,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32432,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dsL4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png 424w, https://substackcdn.com/image/fetch/$s_!dsL4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png 848w, https://substackcdn.com/image/fetch/$s_!dsL4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png 1272w, https://substackcdn.com/image/fetch/$s_!dsL4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc31a9664-a8a2-4b80-a504-7309c7d73558_561x199.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The Hugging Face incident I&#8217;ve covered in recent issues now has a sequel.</p><p>Independent researchers found that OpenAI&#8217;s internal evaluation agents had been active on an obscure German wiki, DseWiki, for over a month, editing pages and collaborating on eval tasks. In the researchers&#8217; account, &#8220;The administrator spent the next 5 days fighting a losing battle against the agents, deleting an average of 100 pages a day while the agents created about 400 new pages per day.&#8221; </p><p>OpenAI&#8217;s response was that it is &#8220;now carefully reviewing its contents and will take any necessary next steps.&#8221; Rep. Lori Trahan&#8217;s comment cut closer, that:</p><blockquote><p><strong>&#8220;The lack of any real federal AI governance means that frontier companies can pick and choose when they disclose incidents.&#8221;</strong></p></blockquote><p>The pattern is now hard to dismiss as a one-off, with isolation boundaries that were assumed instead of verified and discovery coming from outside parties well after the fact. </p><p>Matt Adams&#8217;s insider threat model below has a threat category literally named Containment &amp; Third-Party Impact, and this is the second time in two months it has played out against a third party who never consented to being part of an eval.</p><h3><a href="https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai">GTIG AI Threat Tracker: From Prompting to Autonomy</a></h3><p>Google&#8217;s Threat Intelligence Group published its latest AI threat tracker, and it is among the more useful pieces of adversary reporting I&#8217;ve read this year, albeit a long one. </p><p>The headline observation is that &#8220;In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours,&#8221; with markdown playbooks (AGENTS.md, KNOWLEDGE.md and the like) driving an AI coding chatbot as the operator. </p><p>A separate exposed C2 server hosted a &#8220;Recon&#8221; dashboard managing 23,800+ harvested secrets. GTIG is careful to hedge that it &#8220;has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild,&#8221; but the direction is clear.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cYi7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cYi7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png 424w, https://substackcdn.com/image/fetch/$s_!cYi7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png 848w, https://substackcdn.com/image/fetch/$s_!cYi7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png 1272w, https://substackcdn.com/image/fetch/$s_!cYi7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cYi7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png" width="875" height="543" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:543,&quot;width&quot;:875,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:102825,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cYi7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png 424w, https://substackcdn.com/image/fetch/$s_!cYi7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png 848w, https://substackcdn.com/image/fetch/$s_!cYi7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png 1272w, https://substackcdn.com/image/fetch/$s_!cYi7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f53318-04ef-483e-b80c-ac6b8b450391_875x543.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://ai-insider-threat.matt-adams.co.uk/">Actions Speak Louder Than Tokens: An Insider Threat Model for Frontier AI Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pn2c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pn2c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png 424w, https://substackcdn.com/image/fetch/$s_!pn2c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png 848w, https://substackcdn.com/image/fetch/$s_!pn2c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png 1272w, https://substackcdn.com/image/fetch/$s_!pn2c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pn2c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png" width="517" height="354.40152671755726" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:449,&quot;width&quot;:655,&quot;resizeWidth&quot;:517,&quot;bytes&quot;:359138,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pn2c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png 424w, https://substackcdn.com/image/fetch/$s_!pn2c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png 848w, https://substackcdn.com/image/fetch/$s_!pn2c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png 1272w, https://substackcdn.com/image/fetch/$s_!pn2c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F025b0ae0-64e5-4521-9165-0cdf7910611d_655x449.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Matt Adams published a standalone paper that treats deployed frontier agents as insider threats and adapts CERT&#8217;s five insider threat dimensions, motivation, opportunity, capability, predisposition, and organizational factors, to non-human actors. </p><p>His argument is that existing threat models cover attacks on AI and attacks through AI, and none treat the agent itself as the actor. He derives 27 STRIDE-based threats in six categories, including Credential Compromise, Data Exfiltration, Deception &amp; Evasion, and Containment &amp; Third-Party Impact, and maps four autonomy levels from L1 Human-as-Operator (low risk) to L4 Human-as-Auditor (critical). The controls are NIST CSF-aligned, with 7 protective controls, 25+ detection points across SIEM, UEBA, DLP, and deception tooling, and response and recovery playbooks.</p><blockquote><p><strong>I like this line &#8220;Watch what it did, not what it said.&#8221; </strong></p></blockquote><p>Reasoning traces are unreliable as evidence, actions are not, and existing enterprise telemetry can capture the actions. He is also candid that &#8220;Coherent misalignment in a frontier model is a procurement decision...not something deployment monitoring can fix,&#8221; which is a framing I suspect a lot of vendors would prefer buyers not adopt. </p><p>The paper is dated April but was updated with the Hugging Face disclosures, and given this week&#8217;s news it reads as current.</p><h3><a href="https://youtu.be/BZlb13Q4YKQ?si=UDFItGajqoBb0S46">Agent Hooks</a></h3><p>I had previously shared how Microsoft released a framework agnostic Agent Hooks specification. I took some time to break it down, as well as why security practitioners should be familiar with Hooks as it relates to securing AI agents, how they work, and why they matter.</p><div id="youtube2-BZlb13Q4YKQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;BZlb13Q4YKQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/BZlb13Q4YKQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h1>AppSec</h1><h3><a href="https://trailofbits.com/patch-the-planet/dashboard/">Patch the Planet dashboard</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wv4y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wv4y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png 424w, https://substackcdn.com/image/fetch/$s_!wv4y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png 848w, https://substackcdn.com/image/fetch/$s_!wv4y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png 1272w, https://substackcdn.com/image/fetch/$s_!wv4y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wv4y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png" width="1456" height="702" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4c25820-b900-4132-be35-f17ecd54396c_1520x733.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:702,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:321941,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wv4y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png 424w, https://substackcdn.com/image/fetch/$s_!wv4y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png 848w, https://substackcdn.com/image/fetch/$s_!wv4y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png 1272w, https://substackcdn.com/image/fetch/$s_!wv4y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c25820-b900-4132-be35-f17ecd54396c_1520x733.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Trail of Bits and OpenAI have a live dashboard for Patch the Planet, their AI-assisted effort to find and fix bugs across open source. </p><p>As of September 4 the numbers are 1,646 potential bugs reported, 1,031 confirmed and awaiting patches, 400 fixes open upstream, 215 patches merged, 59 codebases under review, and 11 CVEs assigned. Of the 215 accepted fixes, 17 (7.9%) are high severity, 69 (32.1%) medium, and 58 (27.0%) low, with the rest informational or undetermined.</p><p>I wrote last week about runaway CVE rates and the economics of remediation, and this dashboard puts the problem in a single ratio. 1,031 confirmed issues are waiting on patches while 215 have merged. The constraint has moved to maintainers reviewing and merging, and that is a people problem that more model capability makes worse before it makes it better. </p><p>It is also worth noting that the severity mix skews medium and below, which matters when someone cites the topline &#8220;1,646 bugs&#8221; number.</p><h3><a href="https://www.vulncheck.com/blog/anthropic-glasswing-receipts">The Anthropic Glasswing Receipts Are Starting to Trickle In</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZKkj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZKkj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png 424w, https://substackcdn.com/image/fetch/$s_!ZKkj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png 848w, https://substackcdn.com/image/fetch/$s_!ZKkj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png 1272w, https://substackcdn.com/image/fetch/$s_!ZKkj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZKkj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png" width="761" height="426" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:426,&quot;width&quot;:761,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69553,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZKkj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png 424w, https://substackcdn.com/image/fetch/$s_!ZKkj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png 848w, https://substackcdn.com/image/fetch/$s_!ZKkj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png 1272w, https://substackcdn.com/image/fetch/$s_!ZKkj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec8041b1-a40e-4c09-91dc-2694bccc97ef_761x426.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A companion piece to the Patch the Planet numbers above. </p><p>VulnCheck&#8217;s Patrick Garrity went through Anthropic&#8217;s Project Glasswing disclosure ledger, the Claude-driven open source vulnerability discovery effort launched in April, and tried to reconcile what has been claimed against what has shipped. </p><p>Five months in, the ledger shows 26,153 findings discovered, of which 2,736 (10.5%) reached the disclosure ledger, 2,096 were reported to maintainers without a confirmed fix, 245 were withdrawn, and 202 (0.8%) are marked fixed across 113 projects. Anthropic&#8217;s dashboard claims 421 findings patched upstream and 462 advisories, while the ledgers Garrity pulled list 70 to 82 CVEs and 49 to 77 GHSAs depending on which view you look at, and he notes 18 findings that had already been patched before Anthropic reported them. </p><p>Severity is the other gap, with 91.5% of Claude&#8217;s own assessments rated critical or high against 51.3% once maintainers weighed in. His close is that &#8220;The receipts are starting to trickle in, they just don&#8217;t reconcile.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WTlg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WTlg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png 424w, https://substackcdn.com/image/fetch/$s_!WTlg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png 848w, https://substackcdn.com/image/fetch/$s_!WTlg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png 1272w, https://substackcdn.com/image/fetch/$s_!WTlg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WTlg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png" width="764" height="425" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:425,&quot;width&quot;:764,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:92005,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WTlg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png 424w, https://substackcdn.com/image/fetch/$s_!WTlg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png 848w, https://substackcdn.com/image/fetch/$s_!WTlg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png 1272w, https://substackcdn.com/image/fetch/$s_!WTlg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ec0a76e-53fa-47b5-b88b-11a066fc5f7e_764x425.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Anthropic&#8217;s own explanation is that disclosure is &#8220;a subset of the total number of vulnerabilities&#8221; found &#8220;since the process of independent human triage and review is the rate limiting step,&#8221; and to be fair, that is an honest statement of where the constraint sits. </p><p>That said, it is the same constraint Patch the Planet shows with 1,031 confirmed issues waiting on 215 merged patches. Across both labs&#8217; programs the models are producing findings roughly an order of magnitude faster than humans can validate and maintainers can merge them. The severity delta matters just as much for anyone consuming these feeds, because a model that rates 9 in 10 of its findings critical or high, against maintainers rating about half that way, is going to flood already overwhelmed triage queues with inflated priority if you take its word for it.</p><p>Patrick is clear that the discovery capability is real, and I agree. The headline discovery count is still among the less useful numbers in any of these announcements, and fixed-and-merged is the one to watch. </p><p>I&#8217;d like to see both labs publish the reconciled figures, with maintainer-assigned severity, rather than leaving it to third parties to do the accounting.</p><h3><a href="https://www.chainguard.dev/unchained/what-it-took-to-reach-1-billion-build-manifests">What it took to reach 1 billion build manifests</a></h3><p>Chainguard CTO Matt Moore wrote up how the company doubled its build output in six months, going from 500 million to 1 billion build manifests across 3,000+ unique images and 675,000 image versions. The old pipeline is described as &#8220;a cascading mess&#8221; with humans as the bottleneck for vulnerability remediation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ILm1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ILm1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png 424w, https://substackcdn.com/image/fetch/$s_!ILm1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png 848w, https://substackcdn.com/image/fetch/$s_!ILm1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png 1272w, https://substackcdn.com/image/fetch/$s_!ILm1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ILm1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png" width="925" height="359" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:359,&quot;width&quot;:925,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:211069,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ILm1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png 424w, https://substackcdn.com/image/fetch/$s_!ILm1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png 848w, https://substackcdn.com/image/fetch/$s_!ILm1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png 1272w, https://substackcdn.com/image/fetch/$s_!ILm1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6509c669-472b-46f0-9c4d-96e59d15b358_925x359.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Factory 2.0 replaces it with continuous reconciliation loops that compare desired to actual state, shared work queues serviced by redundant reconciler bots, and AI handling the unstructured judgment calls like whether to backport a CVE fix or how to evaluate a new component, all on a rolling-release Chainguard OS. Every output ships with SLSA Level 3 provenance, Sigstore signatures, and a full SBOM.</p><p>Moore&#8217;s line is that &#8220;When the attacker&#8217;s cycle time compresses, the defender&#8217;s cycle time must compress by at least the same amount,&#8221; which is the same conclusion GTIG reached from the other side. It also lands in the same week GTIG documented an actor publishing malicious packages with valid SLSA Build 3 attestations, so it is worth being precise that provenance proves where a build came from and says nothing about whether the account that produced it was compromised.</p><h3><a href="https://www.runsybil.com/case-studies/carta">Carta case study</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GYNO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GYNO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png 424w, https://substackcdn.com/image/fetch/$s_!GYNO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png 848w, https://substackcdn.com/image/fetch/$s_!GYNO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png 1272w, https://substackcdn.com/image/fetch/$s_!GYNO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GYNO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png" width="840" height="309" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:309,&quot;width&quot;:840,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:61462,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214884382?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GYNO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png 424w, https://substackcdn.com/image/fetch/$s_!GYNO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png 848w, https://substackcdn.com/image/fetch/$s_!GYNO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png 1272w, https://substackcdn.com/image/fetch/$s_!GYNO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4ec6cb0d-9205-4e91-ad2c-e6c0d2244553_840x309.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>RunSybil published a case study with Carta on moving from annual pentests and a bug bounty program to continuous autonomous testing, first deployed during an M&amp;A review. </p><p>During an MCP server assessment the platform found a chained pair, a CVSS 8.1 SQL validation bypass in a Snowflake integration and a CVSS 8.8 administrative function execution that chained through to extract AWS credentials and map network topology. Carta AppSec lead Vamsi NC&#8217;s take on bug bounty is blunt, &#8220;The bug bounty has lost its charm. They&#8217;re using the same tools to scan us externally as we&#8217;re using internally,&#8221; with researchers farming the same patterns for payouts rather than finding novel chains.</p><p>The vulnerable surface was an MCP server, which matches the GTIG finding that MCP has become a preferred target, and the outcome Carta&#8217;s Brad Freer describes is findings turning into &#8220;detection patterns powering the appsec flywheel,&#8221; which is where continuous testing earns its keep over a point-in-time report.</p><h1>Final Thoughts</h1><p>The through-line this week is that model capability is running well ahead of the organizational capacity to use it or contain it. </p><p>OpenAI can ship a Critical-threshold cyber model and a $1B subsidy in the same week it loses track of its own agents, GTIG can document six-hour agentic attack builds while noting that most of what actually works for adversaries is still credentials and supply chain, and Patch the Planet can find 1,646 bugs and merge 215 of them. </p><p>Lyne, Korman, and Venables are each saying a version of the same thing from different seats, that the constraint is people, priorities, honest measurement, and the organizational will to fund them, and none of that is being funded at the rate the models are. </p><p>That said, the work rolls on, and so do we!</p><p><strong>Stay resilient.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The “Left” in Shift-Left Moved]]></title><description><![CDATA[AI industrialized vulnerability discovery. The code itself is now written by agents on developer workstations, and most AppSec programs have no control point there.]]></description><link>https://www.resilientcyber.io/p/the-left-in-shift-left-moved</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-left-in-shift-left-moved</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 10 Sep 2026 12:10:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Q-qN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For anyone who follows Resilient Cyber, you already know I&#8217;ve been heavily discussing and highlighting the impacts AI is having on the economics of finding vulnerabilities. From frontier labs, startups, and independent researchers all surfacing flaws in mature codebases at a surging rate that the institutional ecosystem of disclosure, triage and patching was never built to absorb.</p><p>I&#8217;ve written about the discovery side of this in detail, including in a recent piece titled &#8220;<strong><a href="https://www.resilientcyber.io/p/appsec-in-the-age-of-agents">AppSec in the Age of Agents</a></strong>&#8221;, where I advocated for eliminating entire classes of vulnerabilities rather than grinding through them one ticket at a time, and worse, repeatedly remediating the same class of vulnerabilities over and over. </p><p>However, there is also a second shift underway that gets a lot less attention than the whole &#8220;Vulnpocalypse&#8221; narrative, and it is one I want to focus on in this piece. </p><p>That is the place where code gets written and how it&#8217;s moved. Now, it is often a coding agent running on a development endpoint, with a shell, package manager, credentials and the ability to take actions on its own, and most AppSec programs have no actual control point here at all. </p><p>At the same time, remediation is being handed to agents too, which raises questions around concepts such as Human-in-the-Loop (HITL), which I&#8217;ve already argued was largely a talking point, in a prior piece titled &#8220;<strong><a href="https://www.resilientcyber.io/p/the-human-in-the-loop-illusion">The Human-in-the-Loop Illusion</a></strong>&#8221;. Having agents both creating code and remediating flaws brings good questions, such as what HITL means when both the code and fix are machine-generated. </p><p>In this article, I will walk through both sides of the shift, what they mean for AppSec practitioners and leaders and also use a recent demo and walkthrough I had with the team at Legit Security, a Resilient Cyber partner, as a practical example of how one team is building for this.</p><p>So, let&#8217;s unpack this often overlooked topic at the intersection of AI and AppSec.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h3>Discovery Went Industrial</h3><p>The first thing we need to acknowledge is that vulnerability discovery has went industrial in the first half of 2026. Per Vulnerability Research Jerry Gamblin&#8217;s mid-year check in, 35,364 CVE&#8217;s were published between January 1st and June 30th, a 49.5% increase over the first half of 2025, or one new CVE entry every 7.4 minutes. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dBv1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dBv1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png 424w, https://substackcdn.com/image/fetch/$s_!dBv1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png 848w, https://substackcdn.com/image/fetch/$s_!dBv1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png 1272w, https://substackcdn.com/image/fetch/$s_!dBv1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dBv1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png" width="1143" height="587" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:587,&quot;width&quot;:1143,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:93725,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214193512?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dBv1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png 424w, https://substackcdn.com/image/fetch/$s_!dBv1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png 848w, https://substackcdn.com/image/fetch/$s_!dBv1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png 1272w, https://substackcdn.com/image/fetch/$s_!dBv1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7edaef25-3e80-4fe0-9ef5-d8bae8a54daf_1143x587.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>His full year projection at the time landed between 71,314 and 72,008, up from 48,185 <strong><a href="https://jerrygamblin.com/2026/01/01/2025-cve-data-review/">in </a></strong><em><strong><a href="https://jerrygamblin.com/2026/01/01/2025-cve-data-review/">all</a></strong></em><strong><a href="https://jerrygamblin.com/2026/01/01/2025-cve-data-review/"> of 2025</a></strong>. FIRST provided their own forecast, which had to be adjusted midyear, showing roughly 66,000 potential CVE&#8217;s for the year, from a February baseline of 59,427. In that update, they argued finding isn&#8217;t the problem at all.</p><blockquote><p><strong>&#8220;The challenge for defenders is no longer the discovery of vulnerabilities; it&#8217;s the capacity to verify, coordinate and prioritize them at scale.</strong></p></blockquote><p>Then we have the impact of the frontier labs on the space. </p><p>Anthropic&#8217;s Project Glasswing update put some large figures in the mix. Across it&#8217;s partners, it had surfaced more than ten thousand high or critical severity vulnerabilities, and in open source projects specifically it had identified 6,202 high or critical findings, of which 90.6% of the 1,752 assessed so far proved to be valid true positives. Some partners told Anthropic their rate of finding bugs had increased by more than 10x, and a few asked the lab to slow down disclosures due to needing additional time to design patches. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rvBp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rvBp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png 424w, https://substackcdn.com/image/fetch/$s_!rvBp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png 848w, https://substackcdn.com/image/fetch/$s_!rvBp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png 1272w, https://substackcdn.com/image/fetch/$s_!rvBp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rvBp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png" width="924" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:924,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:173768,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214193512?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rvBp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png 424w, https://substackcdn.com/image/fetch/$s_!rvBp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png 848w, https://substackcdn.com/image/fetch/$s_!rvBp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png 1272w, https://substackcdn.com/image/fetch/$s_!rvBp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27275bfe-b43b-46eb-a374-91a8ecddd00d_924x612.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There&#8217;s also OpenAI&#8217;s <strong><a href="https://trailofbits.com/patch-the-planet/">Patch the Planet</a></strong> effort, involve 55 critical open source codebases, which at the time of my writing have found 1,535 issues, with over 1,000 still awaiting a patch.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jzto!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jzto!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png 424w, https://substackcdn.com/image/fetch/$s_!Jzto!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png 848w, https://substackcdn.com/image/fetch/$s_!Jzto!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png 1272w, https://substackcdn.com/image/fetch/$s_!Jzto!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jzto!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png" width="961" height="429" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:429,&quot;width&quot;:961,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:123468,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214193512?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Jzto!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png 424w, https://substackcdn.com/image/fetch/$s_!Jzto!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png 848w, https://substackcdn.com/image/fetch/$s_!Jzto!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png 1272w, https://substackcdn.com/image/fetch/$s_!Jzto!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8f9beffa-b8a9-48d1-8af6-a719c5bfd44b_961x429.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When I spoke to longtime industry leader Casey Ellis on my show in July, he framed it as AI having collapsed the cost of finding and reporting vulnerabilities at the same time, with signal and noise both up roughly 10x, and the delta between the two getting wider. </p><p>His line that I often reference is:</p><blockquote><p><strong>&#8221;The Vulnpocalypse was already here, it just sort wasn&#8217;t evenly distributed&#8221;.</strong></p></blockquote><p>This reframes the situation as an acceleration of a backlog problem we already had rather than a new novel threat. We are seeing the intake side of the ecosystem buckle in real-time, with cURL <strong><a href="https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/">temporarily pausing</a></strong> its bug bounty program after its confirmation rate fell from roughly 15% to 5% in 2025 (which has now improved due to a surge of high quality AI-driven reporting), and HackerOne&#8217;s Internet Bug Bounty <strong><a href="https://hackerone.com/ibb/policy_versions?change=3771829&amp;type=team">pausing new submissions</a></strong> in March. NIST <strong><a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth">reported </a></strong>that CVE submissions grew from 263% between 2020-2025, and moved most CVE&#8217;s to a &#8220;not scheduled for immediate enrichment&#8221; tier. </p><p>With all of that said, Jerry made a point on my show that while the volume curve may have gone vertical, exploitation has not, and still sits flat at around 1-2%. At the time of our conversation only 85 of the CVE&#8217;s published in the first half of 2026, or 0.24%, hand landed in CISA&#8217;s KEV catalog as of his write-up, which is why FIRST framed it as a &#8220;rain versus flood&#8221;&#8221;, meaning practitioners need to not worry about raw finding counts and instead identify what they truly need to remediate. </p><p>However, it is admittedly tough for a security program to determine that when new vulnerabilities are hitting them at machine-speed, so they are likely to drown either way, given they need to try and do their best to filter the surge. </p><h3>The Fix Side is Still Human Speed</h3><p>So, we&#8217;ve discussed the AI-driven machine speed impact on discovery but what about remediation? </p><p>That&#8217;s the uncomfortable piece of the discussion for most. If you look at both Anthropic&#8217;s Glasswing, and OpenAI&#8217;s Patch the Planet, both efforts highlight 2/3 or more of the vulnerabilities are yet to have been patched, even when verified as true vulnerabilities. Anthropic spoke to this directly, stating:</p><blockquote><p><strong>&#8221;The relative ease of finding vulnerabilities compared with the difficulty of fixing them amounts to a major challenge for cybersecurity&#8221;.</strong> </p></blockquote><p>That&#8217;s essentially a frontier lab describing the exact bottleneck we as practitioners have already lived with for years, but being exacerbated by AI. Cyentia&#8217;s research found the typical organization has the capacity to remediate 1/10 vulnerabilities in a given month, and that was <em>before</em> discovery got industrialized. </p><p>The 2026 Verizon DBIR, which I covered earlier this year, found the median time to fully patch has grown to 43 days and that only 26% of KEV-listed vulnerabilities were fully remediated, while exploitation became the top initial vector at 31% of breaches.</p><p>The labs know this, which is why every discovery capability now ships with a fix capability bolted next to it. That said, those fixes still require a human review before anything merges.</p><p>Niels Provos made the case on the show in June that remediation is the bottleneck AI hasn&#8217;t cracked, and I largely agree, with one caveat. Generating a patch has become cheap as AI has collapsed the economics there as well. </p><p>The hard part is knowing whether the patch is correct, whether it breaks something three services away, whether the finding was even reachable, and who is accountable when an agent-written fix for agent-written code ships to production, and that is an AppSec program design problem more than a model capability problem, and one we haven&#8217;t fully figured out yet as an industry.</p><h2>The Left Moved</h2><p>This is where I think much of the industry is still looking in the wrong place. </p><p>&#8220;Shift left&#8221; was built for a world where a human typed code into an IDE, opened a pull request, and a pipeline ran scanners against it. That world is ending as industry tech leaders such as Google and Microsoft highlight nearly universal adoption of AI coding tools, with big surges in AI-generated and accepted code.</p><p>The important detail is what those tools are. A coding agent is a process on a developer workstation with a shell, a package manager, access to environment variables and credentials, and a set of MCP servers and skills it can call, and it takes hundreds of actions per task that no human reads. </p><p>AI coding tools quietly route around your security, ignoring the authenticated route abstractions and hardened libraries your platform team built and writing raw code instead. Every one of those actions is a place where a supply chain compromise, a leaked secret, or a destructive command can happen, and it happens before there is a pull request for anything to scan.</p><p>The evidence that attackers noticed is already here. The <strong><a href="https://nx.dev/blog/s1ngularity-postmortem">Nx &#8220;s1ngularity&#8221; incident</a></strong> in August 2025 shipped malicious packages that, per the maintainers&#8217; own postmortem, &#8220;attempted to use local AI tools (like Claude and Gemini)&#8221; on the victim&#8217;s workstation to hunt for sensitive information. </p><p>The <strong><a href="https://unit42.paloaltonetworks.com/npm-supply-chain-attack/">Shai-Hulud worm</a></strong> that followed identified other packages maintained by a compromised developer, injected itself, and republished them, with its <strong><a href="https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack">second wave</a></strong> compromising roughly 700 npm packages using preinstall hooks. Layer on top of that the <strong><a href="https://arxiv.org/abs/2406.10279">USENIX Security 2025 research</a></strong> finding package hallucination rates of at least 5.2% for commercial models and 21.7% for open source models, across 205,474 unique hallucinated package names, and you have an agent that will confidently <code>npm install</code> something that doesn&#8217;t exist yet and an adversary happy to register it.</p><p>The control point for AppSec has to move to where the code is actually created, which now means the agent itself and the workstation it runs on. Additionally, the loop between the coding agent and the security platform has to become agent-to-agent, because there is no human in the middle to read a scanner output and decide.</p><h2>A Walkthrough with Legit Security</h2><p>That is the frame I brought into a demo and walkthrough with Legit Security&#8217;s CTO and Co-Founder Liav Caspi and CMO Dave Howell recently. Their architecture maps closely onto the two shifts above.</p><p>Liav described their approach as three-pronged. </p><ul><li><p>First, use AI to find and fix the flaws traditional static analysis misses. </p></li><li><p>Second, secure the SDLC and the agent ecosystem around it, meaning the coding agents, MCP servers, and skills developers are actually using. </p></li><li><p>Third, wrap governance controls around all of it so security teams can set policy and see what is happening.</p></li></ul><p>The platform itself functions as what Liav called a &#8220;hive mind,&#8221; a central brain for AppSec that maintains a security context model of each application, broken down into components such as APIs and data models, and runs a set of autonomous agents against it while developers keep working. </p><p>Those agents cover detection, response, bill of materials generation, triage, and remediation. On the integration side, Legit plugs into the leading AI coding tools, such as Cursor, Claude Code, Copilot, and Codex, and exposes its security context through an <strong><a href="https://www.legitsecurity.com/legit-mcp-server-ai-native-security-intelligence-for-developers">MCP server</a></strong> so that a coding agent can trigger checks, ask whether a change is safe to deploy, and get remediation guidance without a human relaying scanner results. </p><blockquote><p><strong>That agent-to-agent interface is the piece I think most teams will be building or buying within the year as we move towards a more AI-native approach to securing the SDLC.</strong></p></blockquote><p>The triage agent is where Jerry&#8217;s rain-versus-flood problem gets handled. It runs in the background against findings, weighing code context, static and runtime reachability, and EPSS, and it has the authority to demote or close low-risk items and elevate the ones that matter. </p><p><strong><a href="https://www.legitsecurity.com/blog/agentic-appsec-closing-the-remediation-gap-and-automating-the-rest-of-application-security">Legit&#8217;s own description</a></strong> is that it confirms findings, deduplicates them, and ranks them by exploitability, and the remediation agent then reads the code, plans a fix, and delivers a context-aware fix that matches your code, delivered as a pull request.</p><p>Among the more useful parts of the conversation was the discussion of autonomy. Today, the remediation agent opens the pull request, watches it, and reacts to build failures or subsequent code changes, but a human still owns the final merge. </p><p>The PR goes to the right code owner, who reviews and approves it. When I asked Liav where this goes, he projected that within a year many engineering teams will move to pipelines where agents merge code without human intervention. </p><p>I think he is right, and I think most security leaders are not ready for that transition quite yet, because it means the human-in-the-loop requirement becomes a policy setting rather than an assumption. Deciding which findings, which repositories, and which fix types an agent may merge on its own is going to be one of the more consequential AppSec decisions of the next couple of years and it will look different across organizations, business units and risk tolerances.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q-qN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q-qN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png 424w, https://substackcdn.com/image/fetch/$s_!Q-qN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png 848w, https://substackcdn.com/image/fetch/$s_!Q-qN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png 1272w, https://substackcdn.com/image/fetch/$s_!Q-qN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q-qN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png" width="1456" height="858" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:858,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:353425,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214193512?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q-qN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png 424w, https://substackcdn.com/image/fetch/$s_!Q-qN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png 848w, https://substackcdn.com/image/fetch/$s_!Q-qN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png 1272w, https://substackcdn.com/image/fetch/$s_!Q-qN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F42f310ab-e895-4e59-a294-7ab5d323d026_3960x2334.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>VibeGuard at the Endpoint</h2><p>The second half of the demo is where the &#8220;left moved&#8221; argument got tangible in their product. </p><p><strong><a href="https://www.legitsecurity.com/press-releases/legit-security-launches-vibeguard-2.0">VibeGuard</a></strong> is Legit&#8217;s endpoint protection agent for developer workstations, and the current release moved it off the IDE extension model and onto the endpoint itself so it can discover and wrap whichever coding agents are running, currently Claude Code, Cursor, and Copilot. </p><p>Liav&#8217;s description in the launch was that </p><blockquote><p><strong>&#8220;Agentic security needs to happen at the developer endpoint with the goal of enhancing agents rather than blocking&#8221; </strong></p></blockquote><p>That&#8217;s the right posture to take, since as we painfully know in AppSec, anything that slows developers down gets worked around or uninstalled entirely.</p><p>Liav ran the demo live inside Claude Code. He had the agent install Lodash, and VibeGuard intercepted the request, because it proxies package manager installs (npm in this case) and evaluates the library before it lands on the machine. The point is to catch malicious dependencies and hallucinated packages at the moment an agent reaches for them, which is the exact gap the s1ngularity and Shai-Hulud incidents and the slopsquatting research point at. </p><p>Policy is granular, so an organization can choose per operation whether to block, warn, or require an approval, and the developer sees the outcome inline in the agent session rather than in a ticket a week later, once the vulnerabilities or malicious packages already enter production and later get picked up by a scanner.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5QIo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5QIo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png 424w, https://substackcdn.com/image/fetch/$s_!5QIo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png 848w, https://substackcdn.com/image/fetch/$s_!5QIo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png 1272w, https://substackcdn.com/image/fetch/$s_!5QIo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5QIo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:264545,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214193512?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5QIo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png 424w, https://substackcdn.com/image/fetch/$s_!5QIo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png 848w, https://substackcdn.com/image/fetch/$s_!5QIo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png 1272w, https://substackcdn.com/image/fetch/$s_!5QIo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a713028-0fa6-429b-890f-721930a1ce14_3200x1800.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two other controls struck me as practical, the first of which addresses secrets. Developers paste API keys and tokens into agent prompts constantly, and VibeGuard intercepts that paste and instead offers a secure injection method, so the agent can use the credential without the credential living in the prompt history, the transcript, or whatever the agent decides to write to disk. This also prevents the secrets being sent externally to third-parties, such as frontier labs. </p><p>The second is command policy, where administrators can require a fingerprint verification before high-risk bash commands execute, and the example Liav used was <code>gh repo delete</code>, which is exactly the sort of thing an agent operating on a misunderstood instruction, or a prompt injected via a poisoned dependency, would happily run.</p><blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J5ed!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J5ed!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png 424w, https://substackcdn.com/image/fetch/$s_!J5ed!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png 848w, https://substackcdn.com/image/fetch/$s_!J5ed!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!J5ed!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J5ed!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png" width="1456" height="910" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:910,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:361369,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214193512?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J5ed!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png 424w, https://substackcdn.com/image/fetch/$s_!J5ed!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png 848w, https://substackcdn.com/image/fetch/$s_!J5ed!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png 1272w, https://substackcdn.com/image/fetch/$s_!J5ed!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0151a10-5f6a-467d-8df6-54a1ac790246_3200x2000.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></blockquote><p>On the governance side, VibeGuard gives administrators a centralized view of every developer endpoint, including the ones that are not yet protected, along with event logs covering prompts, secret block attempts, and policy violations.</p><p>For anyone who has tried to answer &#8220;which of our developers are running which agents with which MCP servers,&#8221; that inventory alone is a meaningful step, and it connects back to the critical point that asset inventory remains the unsolved problem underneath all of this.</p><h2>What This Asks of Security Leaders</h2><p>I want to close the analysis with what I think this means for the people running AppSec programs, independent of any one vendor.</p><p>The first shift is that the agent session, rather than the PR, is the unit of work your program needs visibility into. If you cannot see what an agent installed, what it ran, and what it was given, your pipeline scanners are auditing a summary of a transaction that already happened. Endpoint visibility for developer agents is going to sit alongside EDR as a baseline control or with the innovative agent-centric purpose built security solutions, and I&#8217;d argue it belongs to AppSec rather than the endpoint team, since the policies are about code, dependencies, and secrets.</p><p>The second is that human-in-the-loop needs to be an explicit design decision. Agents are already opening pull requests for agent-written code. The decision about where a human is required, at the finding, at the fix, at the merge, or at the deploy, should be explicit and tiered by risk, and it should be revisited as your confidence in the tooling grows. Teams that never define it will default to whatever their vendor shipped, and teams that define it as &#8220;always&#8221; will get routed around by developers who want their backlog gone.</p><p>The third is that Niels&#8217;s argument about invariants matters even more as agents write more of the code. Reachability, egress control, hardened libraries the agent is told to use, and package allow-lists enforced at the workstation are the controls that hold when neither the developer nor the reviewer is a human. Guardrails at the point of creation are generally cheaper than downstream triage.</p><h2>Closing Thoughts</h2><p>This is far from an exhaustive discussion, but the direction is clear enough. </p><p>AI has made discovery cheap, remediation is being handed to agents next, and the code itself is increasingly written by a process no human watches. Security once again has a choice between meeting the work where it now happens or bolting controls onto a pipeline that sees a shrinking share of what matters. </p><p>It remains to be seen which direction we take as an industry, but the teams building control points at the developer endpoint and agent-to-agent interfaces into their AppSec platforms are, in my view, closer to where this is headed than the ones still tuning their pull request scanners. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Zero Day Clock Stopped Ticking (and That’s the Point)]]></title><description><![CDATA[A look at what changed in the latest version of the Zero Day Clock, why CISA KEV alone is no longer enough, and what it means for CISOs, AppSec teams, and the AI-driven collapse of exploitation timeli]]></description><link>https://www.resilientcyber.io/p/the-zero-day-clock-stopped-ticking</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-zero-day-clock-stopped-ticking</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Sun, 06 Sep 2026 14:21:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hhD1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Earlier this year I wrote about Sergej Epp&#8217;s Zero Day Clock in an article titled <strong><a href="https://www.resilientcyber.io/p/the-zero-day-clock-is-ticking-why">&#8220;The Zero Day Clock Is Ticking</a></strong><a href="https://www.resilientcyber.io/p/the-zero-day-clock-is-ticking-why">,&#8221;</a> and followed it up with a <strong><a href="https://www.resilientcyber.io/p/before-the-breach-the-zero-day-clock">podcast conversation</a></strong> with Sergej himself. </p><div id="youtube2-06ogpdOtEE8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;06ogpdOtEE8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/06ogpdOtEE8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>At the time, the clock was a single, blunt instrument built on roughly 3,500 CVE-exploit pairs, showing the median time-to-exploit collapsing from 771 days in 2018 to 4 hours in 2024, with the majority of exploited vulnerabilities in 2025 being exploited before public disclosure. </p><p>It made the compression of exploitation timelines legible to people outside of the vulnerability management trenches in a way a hundred vendor reports had failed to and as a result, it became a widely cited resource across not just cyber but others when discussing cybersecurity as well.</p><blockquote><p><strong>That said, the <a href="https://zerodayclock.com/">Zero Day Clock</a> that exists today is a different animal. </strong></p></blockquote><p>The headline &#8220;clock&#8221; is gone, replaced by what the project now calls &#8220;a public scoreboard for vulnerability management and exploitation,&#8221; with an Observatory, an Explorer, a timeline they call <a href="https://zerodayclock.com/collapse">&#8220;</a><strong><a href="https://zerodayclock.com/collapse">The Collapse</a></strong><a href="https://zerodayclock.com/collapse">,&#8221;</a> a ten-point <strong><a href="https://zerodayclock.com/call-to-action">Call to Action</a></strong>, and a <strong><a href="https://zerodayclock.com/signatories">signatories list</a></strong> that now includes names such as Bruce Schneier, Heather Adkins, Jeff Moss, Paul Vixie, George Kurtz, and Joe Sullivan, among others, including myself, as I&#8217;m a big fan of the work Sergej Epp is doing here.</p><p>In this article, I want to walk through what changed, what the new numbers actually say, and what practitioners, CISOs, and AppSec teams should take from it, along with where AI continues to bend the curve. </p><p>So, let&#8217;s dive in.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>From a Clock to an Observatory</h2><p>The biggest change is philosophical rather than visual. </p><p>The original clock&#8217;s entire premise was a time-to-exploit metric. The new version <strong><a href="https://zerodayclock.com/about">explicitly refuses to publish one</a></strong>, and the reasoning is worth understanding, because it applies to plenty of the metrics we throw around internally too. </p><p>Below is their direct explanation, but I will break it down as well:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qyXa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qyXa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png 424w, https://substackcdn.com/image/fetch/$s_!qyXa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png 848w, https://substackcdn.com/image/fetch/$s_!qyXa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png 1272w, https://substackcdn.com/image/fetch/$s_!qyXa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qyXa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png" width="762" height="734" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:734,&quot;width&quot;:762,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:157598,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qyXa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png 424w, https://substackcdn.com/image/fetch/$s_!qyXa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png 848w, https://substackcdn.com/image/fetch/$s_!qyXa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png 1272w, https://substackcdn.com/image/fetch/$s_!qyXa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0e9072-549f-4e49-8b61-1cd9c0056474_762x734.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The project lays out three problems with time-to-exploitation as a headline number. </p><p>It ignores aging, meaning recent vulnerabilities look artificially fast because the slow ones haven&#8217;t been exploited yet. It saturates, since a metric floored at zero can&#8217;t represent further acceleration once exploitation happens on or before disclosure day, and both ends move simultaneously, so a shrinking median can&#8217;t distinguish between attackers migrating toward disclosure day and a growing long tail of old vulnerabilities being exploited years later.</p><p>To be fair, that critique cuts against the version I wrote about in March, and the project is upfront about it. The site is now built around principles it describes as:</p><ul><li><p>Neutral - No vendor, no product and no thesis that needs protecting</p></li><li><p>Independent - Funded by nobody who appears in the data</p></li><li><p>Long term - Built as an instrument rather than as a report</p></li></ul><p>For those unfamiliar, the project grew out of the Unprompted conference in San Francisco earlier this year. However, despite that, it is framed as not being a project deliberately about AI, because an instrument build for one narrative tends to measure that narrative and little else.</p><p>I find that framing refreshing in an industry where nearly every dataset is published by someone with a product to sell. The data now comes from nine public feeds (CISA KEV, EUVD KEV, CIRCL KEV, VulnCheck KEV, Shadowserver&#8217;s honeypot network, MSRC, the CVE Program, NVD, and EPSS), and the four KEV catalogues are deliberately kept separate rather than merged, because in the project&#8217;s words the disagreement between them &#8220;is itself the finding.&#8221;</p><p>Just as useful is the list of things the project says it cannot measure, which includes how much vulnerability exists in the world, whether anybody was actually compromised, when exploitation genuinely began, the risk to your own organization, and whether a decline is good news. </p><p>If more security dashboards shipped with that disclaimer, we&#8217;d have far fewer board slides built on false precision.</p><h2>What the Numbers Say</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S1Ke!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S1Ke!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png 424w, https://substackcdn.com/image/fetch/$s_!S1Ke!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png 848w, https://substackcdn.com/image/fetch/$s_!S1Ke!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png 1272w, https://substackcdn.com/image/fetch/$s_!S1Ke!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S1Ke!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png" width="1456" height="753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:753,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:183264,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S1Ke!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png 424w, https://substackcdn.com/image/fetch/$s_!S1Ke!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png 848w, https://substackcdn.com/image/fetch/$s_!S1Ke!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png 1272w, https://substackcdn.com/image/fetch/$s_!S1Ke!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F443b9acf-6257-4db8-9c7b-dc44f47c44ac_1984x1026.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Observatory&#8217;s opening chart tells the story in three numbers for the first half of 2026. </p><p>There were 35,853 vulnerabilities published, 484 newly named as exploited, and 133 of those were already being exploited when they went public. Through eight months of 2026, the count sits at 57,884 published CVEs and 674 KEV listings, and the project intentionally never divides one into the other, because publication counts and catalogue listings are driven by different forces.</p><p>Zoom out and the KEV trend is the one for security leaders to pay attention to. Annual KEV listings across the combined catalogues went from 48 in 2021, to 95 in 2022, 127 in 2023, 221 in 2024, 479 in 2025, and 674 in 2026 with four months still to go. Even allowing for better catalogue coverage over time, that is a curve that has roughly doubled every year or two.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!t6Ek!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!t6Ek!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png 424w, https://substackcdn.com/image/fetch/$s_!t6Ek!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png 848w, https://substackcdn.com/image/fetch/$s_!t6Ek!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png 1272w, https://substackcdn.com/image/fetch/$s_!t6Ek!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!t6Ek!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png" width="1456" height="740" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:740,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:218350,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!t6Ek!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png 424w, https://substackcdn.com/image/fetch/$s_!t6Ek!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png 848w, https://substackcdn.com/image/fetch/$s_!t6Ek!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png 1272w, https://substackcdn.com/image/fetch/$s_!t6Ek!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62963f13-fbd3-4ff6-986d-5f638fe58e77_1984x1008.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The technology breakdown is where it gets practical. For 2026 year-to-date, web publishing and plugins lead with 206 exploited vulnerabilities, followed by enterprise applications at 163, network appliances at 114, developer platforms at 102, and operating systems at 58. </p><p>Browsers, OT, mobile hardware, and cloud/SaaS are all in the single or low double digits. Per the project, web publishing and plugins grew from 6.1 to 25.8 listings per month while operating systems stayed relatively flat at 6.9 to 7.3, meaning nothing moved away from the OS, everything else simply grew around it.</p><p>The newer Vulnerability Pressure Index compares the latest complete quarter against the same quarter a year earlier. For 2026Q2, vulnerability pressure reads 270% year-over-year (30k new vulnerabilities in three months versus 11k in the same quarter of 2025), scanning pressure reads 42% (212k honeypot attempts versus 500k), and zero day exploitation pressure reads 78% (93 vulnerabilities exploited on or before disclosure versus 119). </p><p>The project is careful to note that 100% isn&#8217;t &#8220;normal,&#8221; with a typical vulnerability pressure reading around 118%, and that each stream compares only against its own past.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hhD1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hhD1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png 424w, https://substackcdn.com/image/fetch/$s_!hhD1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png 848w, https://substackcdn.com/image/fetch/$s_!hhD1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png 1272w, https://substackcdn.com/image/fetch/$s_!hhD1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hhD1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png" width="1456" height="1079" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1079,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:302301,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hhD1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png 424w, https://substackcdn.com/image/fetch/$s_!hhD1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png 848w, https://substackcdn.com/image/fetch/$s_!hhD1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png 1272w, https://substackcdn.com/image/fetch/$s_!hhD1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F903c0869-3ae8-4474-9853-b70f705c22d8_1984x1470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now, I&#8217;ll admit that two of those three readings are down on last year, and someone inclined to declare victory could do so. That said, the project&#8217;s own list of unmeasurable includes &#8220;Whether a decline is good news,&#8221; and the scanning figure in particular is qualified by sensor reporting variations. The number that hasn&#8217;t declined is the one that lands in your backlog, and it nearly tripled.</p><p>Two more findings round out the picture. On severity, the site finds that critical vulnerabilities are attacked at 269 per 10,000 versus 92 for high, so CVSS does separate risk, and yet 61% of everything actually attacked was rated below critical, simply because high-severity vulnerabilities vastly outnumber critical ones. </p><p>On age, the honeypot data shows attackers hammering vulnerabilities that are years old. The most scanned CVEs for the week of August 28 through September 3 included a 2025 GeoServer flaw and this year&#8217;s SharePoint vulnerability alongside Fortinet CVEs from 2022 and 2018, a Citrix flaw from 2019, and a PHPUnit vulnerability from 2017. </p><p>The site&#8217;s own caveat is a good one, &#8220;Empty space is not safe space,&#8221; since honeypots have observed 45% of network device KEV, 2% of OS flaws, and nothing from Apple.</p><h2>The KEV Problem</h2><p>All of the exploitation figures above hinge on the word &#8220;catalogued,&#8221; and that deserves scrutiny, because the catalogue most of the industry treats as ground truth is CISA&#8217;s KEV. The project&#8217;s decision to run four KEV feeds side by side rather than merging them is a quiet acknowledgment that no single catalogue is the truth, and the gap between them is bigger than most vulnerability management programs assume.</p><p>To level set, <strong><a href="https://www.cisa.gov/known-exploited-vulnerabilities">CISA KEV</a></strong> was built as a directive for federal civilian agencies under BOD 22-01, with an inclusion bar that requires a CVE, reliable evidence of exploitation, and clear remediation guidance. That makes it authoritative and conservative by design, and conservative is a problem when it becomes your only exploitation signal. </p><p><strong><a href="https://www.vulncheck.com/kev">VulnCheck&#8217;s KEV</a></strong>, which is free to community members and is one of the four feeds the Zero Day Clock ingests, claims approximately 80% more CVEs exploited in the wild than any other public catalogue, with citations behind every entry. In VulnCheck&#8217;s <a href="https://www.vulncheck.com/blog/state-of-exploitation-2026">&#8220;</a><strong><a href="https://www.vulncheck.com/blog/state-of-exploitation-2026">State of Exploitation 2026</a></strong><a href="https://www.vulncheck.com/blog/state-of-exploitation-2026">&#8221;</a> report, my friend Patrick Garrity found 884 KEVs with first evidence of exploitation in 2025, across 518 vendors and 672 products, while CISA added 245 KEVs across 99 vendors and 146 products over the same period. </p><p>VulnCheck&#8217;s 118 first-reporting sources added evidence &#8220;more than 85 percent of the time, often predating CISA by days, months, or even years,&#8221; and 28.96% of its 2025 KEVs were exploited on or before the day their CVE was published, up from 23.6% in 2024. That last figure is the same phenomenon the Zero Day Clock&#8217;s &#8220;ZeroDay KEV&#8221; line tracks, seen from a broader catalogue.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VK1I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VK1I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png 424w, https://substackcdn.com/image/fetch/$s_!VK1I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png 848w, https://substackcdn.com/image/fetch/$s_!VK1I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png 1272w, https://substackcdn.com/image/fetch/$s_!VK1I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VK1I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png" width="1456" height="753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/665131fb-1958-448b-b1be-416b8b383138_1984x1026.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:753,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:183264,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VK1I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png 424w, https://substackcdn.com/image/fetch/$s_!VK1I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png 848w, https://substackcdn.com/image/fetch/$s_!VK1I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png 1272w, https://substackcdn.com/image/fetch/$s_!VK1I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F665131fb-1958-448b-b1be-416b8b383138_1984x1026.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://www.empiricalsecurity.com/assets/how-to-deal-with-speed-whitepaper.pdf">Empirical Security&#8217;s</a></strong> whitepaper &#8220;How to Deal with Speed&#8221; goes further and, to me, lands the harder blow. </p><p>When pulling data for the 2025 DBIR, across roughly six years of observed history, Empirical counted 16,116 CVEs with exploitation activity. CISA KEV held 1,307 of them, Empirical&#8217;s telemetry corroborated 894, which leaves 413 KEV entries they cannot see at all and 15,222 actively exploited CVEs that never reach the catalogue.</p><p>Additionally, Empirical found that more than half of the entries on the KEV were last observed with exploitation activity <em>over three years ago</em>, &#8220;yet a scanner, vulnerability intelligence tool, or exposure management platform finding one of them today fires the same alarm as a flaw under attack this morning.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3mh9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3mh9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png 424w, https://substackcdn.com/image/fetch/$s_!3mh9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png 848w, https://substackcdn.com/image/fetch/$s_!3mh9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png 1272w, https://substackcdn.com/image/fetch/$s_!3mh9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3mh9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png" width="614" height="533" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:533,&quot;width&quot;:614,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:44115,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3mh9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png 424w, https://substackcdn.com/image/fetch/$s_!3mh9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png 848w, https://substackcdn.com/image/fetch/$s_!3mh9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png 1272w, https://substackcdn.com/image/fetch/$s_!3mh9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88178134-ef13-4a0c-9bf5-6dc54113a3d2_614x533.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Empirical&#8217;s broader point is that exploitation is a time series rather than an on/off state.</p><p>In their data, a vulnerability with exploitation activity today has a 32.3% chance of being exploited again tomorrow, a 52% chance within the next seven days, and a 65.1% chance within 30 days, and the activity clusters into persistent, frequent, occasional, and rare patterns, with persistent vulnerabilities showing activity on 95.4% of days and rare ones on 4.8%. </p><p>KEV entries skew heavily toward the persistent and frequent clusters (48% and 35%), which is another way of saying the catalogue captures the loud, long-running exploitation and misses the long tail. Their conclusion is that prioritizing by exploitation evidence rather than CVSS severity produces about a 29-fold improvement in efficiency for the same remediation effort, which pairs neatly with the Zero Day Clock&#8217;s own severity finding above.</p><p>Now, none of this means CISA KEV is useless. It is free, it is authoritative for federal agencies, and a KEV hit still deserves attention. That said, treating it as a complete or current picture of exploitation is a mistake, and the Zero Day Clock&#8217;s decision to show the catalogues disagreeing with each other is more honest than the single-catalogue view most dashboards ship with.</p><h2>What It Means for CISOs</h2><p>The first implication is the one I made in March and will keep making. Finding vulnerabilities has never been the hard part, the hard part is fixing them, and the data now supports that in both directions. </p><p>Disclosure volume is up roughly 270% year-over-year for the quarter, and the ceiling on remediation capacity hasn&#8217;t moved. Empirical puts it plainly, &#8220;the answer to speed is not to patch faster,&#8221; because very few organizations can win a throughput contest against a disclosure curve with no upper bound, and the alternative is sorting better before you run. If your program is still reporting mean-time-to-remediate against a 30-day SLA, you&#8217;re measuring adherence to a policy, and exposure is a different question entirely. </p><blockquote><p><strong>Or, as one would call it, you&#8217;re performing compliance/security theater, not risk management.</strong></p></blockquote><p>Closely related, if your &#8220;known exploited&#8221; signal is CISA KEV alone, you are working from a catalogue that Empirical&#8217;s telemetry suggests misses the large majority of exploited CVEs and carries entries that haven&#8217;t seen activity in years. Layering in VulnCheck KEV, EPSS, and honeypot telemetry such as Shadowserver&#8217;s is table stakes at this point, and the Zero Day Clock&#8217;s Explorer is a reasonable place to see how the catalogues disagree on your vendors.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OI55!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OI55!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png 424w, https://substackcdn.com/image/fetch/$s_!OI55!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png 848w, https://substackcdn.com/image/fetch/$s_!OI55!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png 1272w, https://substackcdn.com/image/fetch/$s_!OI55!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OI55!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png" width="1017" height="275" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:275,&quot;width&quot;:1017,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42480,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OI55!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png 424w, https://substackcdn.com/image/fetch/$s_!OI55!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png 848w, https://substackcdn.com/image/fetch/$s_!OI55!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png 1272w, https://substackcdn.com/image/fetch/$s_!OI55!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47603ce2-ee36-4a82-9df0-5e86eab05b3d_1017x275.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The second implication is that the zero-day framing has become a distraction for most organizations. </p><p>Yes, 133 of the vulnerabilities named as exploited in the first half of 2026 were already being exploited when published, and that matters for the vendors and the handful of organizations targeted first. For everyone else, the week&#8217;s scanning chart says the attackers&#8217; bread and butter is a Fortinet CVE from 2018 and a PHPUnit bug from 2017.</p><p>The Collapse timeline cites Shadowserver data showing 68% of attacked known vulnerabilities in a recent sample were published before 2024, with a single 2018 Fortinet CVE drawing 56,864 attacks in one week. The N-hour exploitation window and the N-year backlog are the same problem viewed from two ends, and boards tend to hear only about the first one.</p><p>Third, the technology breakdown should reshape where you spend. Network appliances, enterprise applications, and web platforms are where the KEV listings concentrate. If your vulnerability management program is still weighted toward endpoint OS patching because that&#8217;s where the tooling is mature, the exploitation data is telling you the attackers went elsewhere.</p><p>Finally, the project&#8217;s Call to Action is aimed at the structural level, with demands for vendor liability, security by default in platforms, memory-safe languages for new critical infrastructure code, open-sourced defensive AI tooling, and regulation redesigned for machine-speed defense, to name a few. It explicitly lays out 10 items in the Call to Action:</p><ul><li><p><strong>Hold the Makers Accountable</strong></p></li><li><p><strong>Build Security into the Platform</strong></p></li><li><p><strong>Stop Patching, Start Rebuilding</strong></p></li><li><p><strong>Eliminate the Root Cause</strong></p></li><li><p><strong>Open-Source the Defense</strong></p></li><li><p><strong>Regulation for Machine Speed</strong></p></li><li><p><strong>Bridge the Gap Between Hackers and Policy</strong></p></li><li><p><strong>Zero Trust, Everywhere</strong></p></li><li><p><strong>Treat Cyber as Statecraft</strong></p></li><li><p><strong>Fund the Defense</strong></p></li></ul><p>I&#8217;ve argued before that voluntary pledges won&#8217;t move vendors, and I still believe that. CISOs won&#8217;t fix vendor liability on their own, but they can start pricing exploitation history into procurement, and the site&#8217;s Explorer view, filterable by vendor and year, makes that fairly easy to do, but it&#8217;s up to us as a community to actually make use of it.</p><h2>What It Means for AppSec Teams</h2><p>For AppSec, the most relevant number is the developer platforms category, which is fourth on the exploitation list at 102 KEV listings for 2026 year-to-date. </p><p>That bucket covers the build systems, frameworks, and tooling we rely on to produce software, and it is being exploited at nearly twice the rate of operating systems. The web publishing and plugins category leading the list at 206 is a reminder that the long tail of CMS plugins and web frameworks remains the softest target on the internet, and much of that is code your organization runs but never wrote.</p><p>The severity finding matters here too. AppSec programs love CVSS thresholds because they are simple to encode in a policy, and the data says critical vulnerabilities really are exploited at a higher rate. It also says that most of what gets exploited is rated high or below. </p><p>A gate that only blocks criticals is letting through the majority of what attackers actually use, and a gate that blocks everything above medium is how you end up as the &#8220;office of no&#8221;. </p><p>The way out, as I&#8217;ve written about repeatedly, is context, which means reachability, exploitation intelligence from sources richer than CISA KEV alone, and runtime exposure, rather than a severity score in isolation. Empirical&#8217;s 29-fold efficiency figure for exploitation-based prioritization over CVSS is the kind of number that should end the CVSS threshold debate with engineering leadership.</p><p>There&#8217;s also a disclosure angle for AppSec teams that ship software. Per the project&#8217;s zero-day definition, 88% of vulnerabilities with a KEV listing on or before publication had a patch available on or before disclosure where vendor dates exist. That&#8217;s coordinated disclosure working as designed, and it still leaves defenders with no advance warning, because the attacker&#8217;s timeline now starts at the patch, and the data below suggests that timeline is measured in hours.</p><h2>AI&#8217;s Continued Impact</h2><p>The Collapse timeline is where the AI thread runs, and it has been extended since March. </p><p>The entries I covered then are still there, from Daniel Kang&#8217;s work showing GPT-4 exploiting known flaws with an 87% success rate at $8.80 per exploit, to Sean Heelan generating 40 working exploits for a single flaw at a cost of $50, to Dinkin and Kraft finding 100+ exploitable kernel driver vulnerabilities for $600 total. Heelan&#8217;s line remains one of the better summaries of where this goes:</p><blockquote><p><strong>&#8220;The limiting factor on a state&#8217;s ability to develop exploits will be token throughput, not hacker count.&#8221;</strong></p></blockquote><p>The newer entries push the timeline from N-day to what Anthropic&#8217;s June research on <strong><a href="https://www.anthropic.com/research/n-days">measuring LLMs&#8217; impact on N-day exploits</a></strong> calls N-hour. In that work, Mythos Preview had its first working exploit against a Firefox patch within an hour of Mozilla issuing it and ultimately produced eight different exploits in roughly 12 hours, while against Windows kernel bugs its first proof of concept arrived in 31 minutes and all 18 arrived within six hours, at a total cost of $15,700 in API credits, or roughly $2,000 per privilege escalation. </p><p>The comparison the paper draws is the one most relevant for a CISO, since it typically takes seven days for a patch to reach 90% of enrolled Windows devices and day 11 before a forced reboot, meaning the model &#8220;would have finished creating all eight full chain exploits before any of the Windows devices had received the patch.&#8221; As the authors put it, &#8220;N-hour is closer to the reality we now operate in.&#8221; You can see in the Zero Day Clock Observatory,0 where vulnerability exposure is growing as well. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rSHh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rSHh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png 424w, https://substackcdn.com/image/fetch/$s_!rSHh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png 848w, https://substackcdn.com/image/fetch/$s_!rSHh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png 1272w, https://substackcdn.com/image/fetch/$s_!rSHh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rSHh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png" width="1456" height="973" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:973,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:295198,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rSHh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png 424w, https://substackcdn.com/image/fetch/$s_!rSHh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png 848w, https://substackcdn.com/image/fetch/$s_!rSHh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png 1272w, https://substackcdn.com/image/fetch/$s_!rSHh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb91f186e-96a6-476b-9833-9a9cc494d8b6_1984x1326.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The timeline also cites Anthropic&#8217;s disclosure that Claude found over 500 high-severity vulnerabilities in open source software, with a warning that 90-day disclosure windows may not survive AI-discovered bug volume, and Schneier, Adkins, and Evron&#8217;s October 2025 essay gets the closing word:</p><blockquote><p><strong>&#8220;The attackers&#8217; AI singularity has arrived. Ours has not yet begun.&#8221;</strong></p></blockquote><p>I would argue that is timely, looking at a similar effort as Anthropic&#8217;s, in competitor OpenAI&#8217;s effort &#8220;<strong><a href="https://trailofbits.com/patch-the-planet/">Patch the Planet</a></strong>&#8221; in tandem with Trail of Bits, you can see <strong>66%</strong> of issues found are still awaiting patches. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FspE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FspE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png 424w, https://substackcdn.com/image/fetch/$s_!FspE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png 848w, https://substackcdn.com/image/fetch/$s_!FspE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png 1272w, https://substackcdn.com/image/fetch/$s_!FspE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FspE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png" width="654" height="293.4865671641791" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:451,&quot;width&quot;:1005,&quot;resizeWidth&quot;:654,&quot;bytes&quot;:124802,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/214336794?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FspE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png 424w, https://substackcdn.com/image/fetch/$s_!FspE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png 848w, https://substackcdn.com/image/fetch/$s_!FspE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png 1272w, https://substackcdn.com/image/fetch/$s_!FspE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d96d08e-24e7-480b-8971-ae7dd0dc3eff_1005x451.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This highlights the bottleneck isn&#8217;t finding issues, but the subsequent validation, patch development, institutional triage and ultimately the patches being merged upstream. You can see above in Patch the Planet, <strong>only 13%</strong> of issues so far have actually had a patch merged upstream. </p><p>Now, don&#8217;t get me wrong, I remain bullish on AI for defense, and the Call to Action&#8217;s demand to open source defensive AI tooling is one I endorse, hence being a signed supporter. That said, Sergej&#8217;s <strong><a href="https://sergejepp.substack.com/p/winning-the-ai-cyber-race-verifiability">Verifier&#8217;s Law</a></strong>, which he and I discussed at length on the podcast, explains why offense is compounding faster. </p><p>An exploit either works or it doesn&#8217;t, which is a cheap, deterministic verifier, while defense gets ambiguous, delayed feedback and has to be right everywhere. Until defenders get feedback loops as tight as a working exploit, the asymmetry persists regardless of how much AI we buy.</p><h2>Closing Thoughts</h2><p>It is of course debatable whether the world needed another vulnerability dashboard, and the earlier version of the clock was frankly easier to put in front of a board than an observatory with nine data feeds and a page explaining what it can&#8217;t measure. </p><p>That said, the rebuilt Zero Day Clock is among the more honest instruments I&#8217;ve seen in this space, precisely because it gave up its own headline metric when the data couldn&#8217;t support it. </p><p>The picture it paints is consistent with everything else we&#8217;ve seen this year. </p><p>Disclosure volume is roughly tripling, exploitation listings are compounding, attackers are living off old edge-device bugs while AI compresses the window on new ones to hours, and remediation capacity hasn&#8217;t budged. </p><p>This is both a measurement challenge and structural one, with various systemic, organizational and technical issues at play.</p><p>All that aside, this is an excellent data rich resource to discuss the state of vulnerabilities and exploitation with security leaders and practitioners alike.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #112]]></title><description><![CDATA[Collective Call for Cyber Defense, M&A & Fundraising Trends, OpenAI/Hugging Face Incident Drama Continues, Security Autonomy Matrix, Agent Hooks Framework, Runaway CVE Rates & Remediation Challenges]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-112</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-112</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 03 Sep 2026 14:53:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9stJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Welcome!</h1><p>Welcome to issue #112 of the Resilient Cyber Newsletter. </p><p>It&#8217;s been another action packed week, with an industry-wide call from frontier labs, CSP&#8217;s and vendors for collective action on Cyber, continued M&amp;A activity, a slew of fundraising, continued drama with AI incidents and the industry still grappling with the surge of CVE&#8217;s and remediation bottlenecks.</p><p>I try and unpack it all this week concisely, so sit back, grab a coffee and let&#8217;s get moving before everyone heads off to enjoy the long weekend, at least here in the U.S. </p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9stJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9stJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png 424w, https://substackcdn.com/image/fetch/$s_!9stJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png 848w, https://substackcdn.com/image/fetch/$s_!9stJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png 1272w, https://substackcdn.com/image/fetch/$s_!9stJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9stJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png" width="622" height="406.3883847549909" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1102,&quot;resizeWidth&quot;:622,&quot;bytes&quot;:571484,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9stJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png 424w, https://substackcdn.com/image/fetch/$s_!9stJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png 848w, https://substackcdn.com/image/fetch/$s_!9stJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png 1272w, https://substackcdn.com/image/fetch/$s_!9stJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80a557c2-0641-48f6-bd3b-50a40c250dfc_1102x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://openai.com/collective-cyberdefense/">A Call for Collective Action on Cyber Defense</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xAx4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xAx4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png 424w, https://substackcdn.com/image/fetch/$s_!xAx4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png 848w, https://substackcdn.com/image/fetch/$s_!xAx4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png 1272w, https://substackcdn.com/image/fetch/$s_!xAx4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xAx4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png" width="749" height="218" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:218,&quot;width&quot;:749,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29851,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xAx4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png 424w, https://substackcdn.com/image/fetch/$s_!xAx4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png 848w, https://substackcdn.com/image/fetch/$s_!xAx4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png 1272w, https://substackcdn.com/image/fetch/$s_!xAx4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6af2f51-e8f0-4db9-94ad-63683d81d24b_749x218.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>OpenAI published a letter with 100+ cosigners across the industry with a core claim that:</p><blockquote><p><strong><br>&#8221;In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable&#8221;.</strong><br></p></blockquote><p>It goes on to make various calls to actions such as:</p><ul><li><p>Recognizing the status quo of security won&#8217;t be enough</p></li><li><p>Empower more defenders with cyber-capable AI</p></li><li><p>Mobilize a collective response</p></li><li><p>Make cyber defense a leadership priority</p></li></ul><p>Now, where I struggle with this is, I agree with everything their saying.. the problem however is that we cannot &#8220;will&#8221; ourselves into a state of security. It requires either sufficient market or regulatory forces and right now we largely lack both, which is why many consider cyber to be a market failure.</p><p>There is also the fact that the labs, CSPs and many of the signatories are security vendors, so they are calling on the market and their customers to spend more on the very things they sell, which can be seen as problematic.</p><p>All that said, I unfortunately don&#8217;t anticipate much changing until organizations feel real market consequences for incidents, shipping insecure products, or changes in the regulatory landscape which force them to prioritize and invest in security with more rigor. </p><h3><strong><a href="https://youtu.be/z0jMk8RD9VI?si=7OnYA99PGUtlJZtA">AI Is Moving Cyberattacks to Machine Speed</a></strong></h3><div id="youtube2-z0jMk8RD9VI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;z0jMk8RD9VI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/z0jMk8RD9VI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>In a bit of a dim warning, former NSA leader Rob Joyce recently had an interview where he discussed the fact that exploitation timelines are collapsing, and attacks are moving at machine speed.</p><p>Rob discusses how years of technical debt are now going to be found and exploited by AI, and how critically important the fundamentals remain.</p><h3><a href="https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-acquires-console-agentify-security">Palo Alto Acquires Console</a></h3><p>PANW continues its acquisition run, this time acquiring a company named Console. This one is less about securing AI, and instead focused on leveraging AI <em>for</em> security, as the company provides capabilities for users to express oiperational goals and the software handle the complexity of helping them achieve it. </p><p>This quote from Nikesh Arora sums up the goal:</p><blockquote><p><br><strong>"Security operations can no longer be about managing dashboards and queuing tickets just to help humans work faster. By bringing Console into Palo Alto Networks, our customers can have a direct conversation with data and build agentic workflows in natural language that helps alert and remediate issues automatically. This is the shift to software-as-an-agent, giving our platform the arms and legs to deliver autonomous security outcomes across the entire enterprise."</strong></p></blockquote><p>If you&#8217;re looking for deeper insights into how the industries largest vendor sees the landscape, as well as their M&amp;A ambitions, I found this recent conversation with <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Molly O&#8217;Shea&quot;,&quot;id&quot;:6470945,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c0e15bc-1f31-4aa9-929c-9af2016621df_1179x1306.jpeg&quot;,&quot;uuid&quot;:&quot;474edad2-1255-42ce-bf07-886d73ec966d&quot;}" data-component-name="MentionToDOM"></span> to be perfect. I had a chance to listen to it earlier this week.</p><div id="youtube2-_v_ryYwmfM0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;_v_ryYwmfM0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/_v_ryYwmfM0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://sequoiacap.com/article/partnering-with-air-securing-the-ai-supply-chain">AIR Security Emerges From Stealth With $50M</a></h3><p>The team at AIR Security recently emerged from stealth with $50M, focused on building a &#8220;firewall&#8221; for agents. I&#8217;m very familiar with this team, and had them on the show in the past to discuss an early effort of theirs Mother of all KEV&#8217;s (MOAK), which automated developing exploits for KEV&#8217;s.</p><p>The team has continued innovating and now has the capital and backing of amazing investors, such as Sequoia. They played a role in the new OWASP Agentic Skills Top 10, and are focusing their attention on creating a firewall for AI Agents. </p><h3><a href="https://www.linkedin.com/posts/hiddenlayersec_aisecurity-secureai-agenticai-activity-7500930593413660673-Tx_f?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAkEoGoBGB4OpNzHyIfoIEcGQ8FKwlE1C6k">HiddenLayer Raises $100M Series B</a></h3><p>One of the more longstanding AI security players in the ecosystem who has been around for a bit, HiddenLayer, recently announced a $100M Series B, being led by Delta-v Capital, with involvement from others such as MSFT&#8217;s M12 venture fund, and Booz Allen Hamilton. </p><p>I&#8217;m employed at a competitor in this category so I watch it closely, but I&#8217;ve been following their team for years, prior to the role I am in as well. It is interesting to see M12 be among the investors, given they also invest in competitors to Hidden Layer. The involvement of BAH, and my public sector background also give the signal that the team has likely has strong public sector traction as well, which is supported in their announcement where they cite deployments across U.S. defense and IC environments. They also cite 10x ARR growth, 50+ new platform customers etc.</p><p>There&#8217;s some great security leaders on the team of course, aside from the founders, such as longtime industry leader Malcom Harkins. While I compete in the category in my day job, I know it is a highly competitive and fast moving one, and there&#8217;s several great teams in the ecosystem.</p><h3><a href="https://www.calcalistech.com/ctechnews/article/0kbwgdw01">Upwind Raises $300M, Doubling Valuation to $3.8 Billion in Five Months</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RwL4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RwL4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png 424w, https://substackcdn.com/image/fetch/$s_!RwL4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png 848w, https://substackcdn.com/image/fetch/$s_!RwL4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png 1272w, https://substackcdn.com/image/fetch/$s_!RwL4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RwL4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png" width="613" height="176" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:176,&quot;width&quot;:613,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:25826,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RwL4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png 424w, https://substackcdn.com/image/fetch/$s_!RwL4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png 848w, https://substackcdn.com/image/fetch/$s_!RwL4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png 1272w, https://substackcdn.com/image/fetch/$s_!RwL4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8692c56-a702-4635-b8a0-2a7477bd0ddb_613x176.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>In what feels like groundhog day, we have another large fundraising event for Upwind, who has established itself as a leader in the cloud security and runtime categories. This comes 8 months after their prior $250M Series B(hence my groundhog day comment). </p><p>The company seems to be capitalizing on their momentum, competing strongly in the CNAPP space, and also expanding to cover specific areas of AI security, as everyone scrambles to cover the risks of AI.</p><h3><a href="https://www.linkedin.com/posts/huskeys_weve-raised-a-27m-series-a-led-by-blackstone-activity-7500920858396352513-23Uu?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAkEoGoBGB4OpNzHyIfoIEcGQ8FKwlE1C6k">Huskey&#8217;s Announces $27M Series A</a></h3><p>The team at Huskey&#8217;s also announced their $27M Series A, just 5 months after coming out of stealth with participation from teams such a Blackstone, Merlin Ventures, Zscaler, Okta and others.</p><p>They aim their focus at &#8220;Network Edge Security Management (NESM), focusing on making network edge security stacks work for, not against customers. </p><h1>AI</h1><h3><a href="https://youtu.be/X50zezLFWWI?si=7Re--eZTB5Q8X2En">Conversation with a OpenAI/Hugging Face Incident Investigator</a></h3><div id="youtube2-X50zezLFWWI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;X50zezLFWWI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/X50zezLFWWI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>One thing I found really interesting this week was the <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Dwarkesh Patel&quot;,&quot;id&quot;:4281466,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!5eJb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb715ffd1-f7d7-4755-af88-c48efe647f5b_400x400.jpeg&quot;,&quot;uuid&quot;:&quot;50cc2aa1-9ec0-4e0d-b9aa-42d511f17531&quot;}" data-component-name="MentionToDOM"></span> conversation with <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ajeya Cotra&quot;,&quot;id&quot;:7378131,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7091a8cf-7841-426a-afb3-0ab56b083e0f_800x800.jpeg&quot;,&quot;uuid&quot;:&quot;6ccebf32-58ea-4e2a-ac51-61e6ce956a83&quot;}" data-component-name="MentionToDOM"></span> around the OpenAI/Hugging Face incident.</p><p>For those unfamiliar, Ajeya is one of the independent investigators from METR involved in the analysis of the incident. In the conversation with Dwarkesh, they go really deep in particular in some of the multi-agent conversations, behaviors and more, which felt like diving into the psychology of multi-agent systems, of &#8220;civilizations&#8221; as Dwarkesh himself framed them in his blog &#8220;<strong><a href="https://www.dwarkesh.com/p/openai-huggingface">The Rise of Fall of Agent Civilizations</a></strong>&#8221;, which is worth a read.</p><p>Ajeya also had a good <strong><a href="https://www.planned-obsolescence.org/p/the-hugging-face-attack-surprised">blog on what surprised he</a></strong>r from the incident, including the scale of the number of agents that participated in this incident and activity and how they collaborated.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0NkO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0NkO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png 424w, https://substackcdn.com/image/fetch/$s_!0NkO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png 848w, https://substackcdn.com/image/fetch/$s_!0NkO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png 1272w, https://substackcdn.com/image/fetch/$s_!0NkO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0NkO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png" width="588" height="619.0434782608696" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:678,&quot;width&quot;:644,&quot;resizeWidth&quot;:588,&quot;bytes&quot;:97495,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0NkO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png 424w, https://substackcdn.com/image/fetch/$s_!0NkO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png 848w, https://substackcdn.com/image/fetch/$s_!0NkO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png 1272w, https://substackcdn.com/image/fetch/$s_!0NkO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc50b7f8c-fe4b-41eb-bde1-f907bb916a58_644x678.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://x.com/ZackKorman/status/2094482334166769813?s=20"><span>Valid Questions About the Independent Review of the OpenAI/Hugging Face Incident</span></a></h3><p><span>Now, not to throw shade at the organizations involved in the review of the incident, but Zack Korman shared an excellent video critiquing aspects of this review. He points out how the organizations involved in the review largely lack </span><em><span>any</span></em><span> cybersecurity expertise or background, and by their own admission, the review could of been handled better in several ways. </span></p><p><span>He goes on to rightfully call out the Cyber community as well, as we seem to be sitting back and letting the frontier labs, and others outside of Cyber lead the charge as it relates to the cyber risks of AI. Zack says we need to step it up as a community, and I&#8217;m inclined to agree with him.</span></p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://t.co/qYUyYp1apW\&quot;>pic.twitter.com/qYUyYp1apW</a></p>&amp;mdash; Zack Korman (@ZackKorman) <a href=\&quot;https://x.com/ZackKorman/status/2094482334166769813?ref_src=twsrc%5Etfw\&quot;>August&quot;,&quot;full_text&quot;:&quot;The independent review of the OpenAI Hugging Face incident, supposedly a watershed moment in cybersecurity, wasn't done by a cybersecurity firm and the authors have no cybersecurity experience. That's bad.\n\nHere's my new video. &quot;,&quot;username&quot;:&quot;ZackKorman&quot;,&quot;name&quot;:&quot;Zack Korman&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/2011153005509267456/JhCS1L1c_normal.jpg&quot;,&quot;date&quot;:&quot;2026-08-31T17:47:56.000Z&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!tf2r!,w_1028,c_limit,f_auto,q_auto:best,fl_progressive:steep/l_play_button_usfui2,w_88,e_colorize:0/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F__ss-rehost__tw-video-preview-13_2094480933197942785.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/qYUyYp1apW&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:45,&quot;retweet_count&quot;:106,&quot;like_count&quot;:612,&quot;impression_count&quot;:129107,&quot;expanded_url&quot;:null,&quot;video_url&quot;:&quot;https://video.twimg.com/amplify_video/2094480933197942785/vid/avc1/1280x720/esuMwAyIvxexMD6R.mp4&quot;,&quot;video_preview_media_key&quot;:&quot;13_2094480933197942785&quot;,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><h3><a href="https://www.anthropic.com/news/improving-alignment-security-efforts">Anthropic&#8217;s Plans to Improve Alignment and Security</a></h3><p>Sticking with the theme of incidents and &#8220;breakouts and such, Anthropic published a blog this week discussing how they plan to improve alignment and security efforts. </p><p><span>Agent "breakouts", unauthorized actions and misalignment has been dominating the AI and security conversation for weeks.<br><br>From the initial </span><strong><a href="https://www.linkedin.com/company/openai/"><span>OpenAI</span></a></strong><span> and </span><strong><a href="https://www.linkedin.com/company/huggingface/"><span>Hugging Face</span></a></strong><span> incident, to others such as Anthropic, </span><strong><a href="https://www.linkedin.com/company/ai-security-institute/"><span>AI Security Institute (AISI)</span></a></strong><span>, Meta and even open weight labs coming forward disclosing incidents of agent attacks and unauthorized actions.<br><br>That's why this blog from </span><strong><a href="https://www.linkedin.com/company/anthropicresearch/"><span>Anthropic</span></a></strong><span> is super timely. They walk through what they learned from their three incidents of Claude gaining unauthorized access to real systems and infrastructure and what they plan to improve moving forward.<br><br>This includes efforts such as securing evaluation and training environments, utilizing classifiers to identify unauthorized activities, the use of automated monitors, improved cyber sandboxes and general environmental hardening. <br><br>It also lays out recommendations for external partners using models with reduced cyber safeguards that include sandbox and network isolation, pre-engagement validation, explicit scope setting and real-time monitoring.<br><br>One thing I particularly appreciate is they are honest about where gaps remain, in terms of models cheating in training environments and objectives, continued alignment challenges and more.<br><br>Most notably for me is their hardening security practices and recommendations highlight a list of things that nearly every IT environment I've worked in across 20~ years is still rife with, and inevitably will be found by AI soon. </span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AWnf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AWnf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png 424w, https://substackcdn.com/image/fetch/$s_!AWnf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png 848w, https://substackcdn.com/image/fetch/$s_!AWnf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png 1272w, https://substackcdn.com/image/fetch/$s_!AWnf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AWnf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png" width="917" height="524" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:524,&quot;width&quot;:917,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170887,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AWnf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png 424w, https://substackcdn.com/image/fetch/$s_!AWnf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png 848w, https://substackcdn.com/image/fetch/$s_!AWnf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png 1272w, https://substackcdn.com/image/fetch/$s_!AWnf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6aedc2fa-c70e-4446-ba12-53ccc73f1d53_917x524.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>This includes accounts with standing access to sensitive data, lack of outbound access control, identify rigor, legacy infra configs and services, and gaps in observability. <br><br>It's going to be an interesting couple of years ahead. Give the Anthropic blog a read yourself.</span></p><h3><a href="https://www.crowdstrike.com/en-us/about-us/cyber-superintelligence-lab/">CrowdStrike SafeMind</a></h3><p>AI and Cyber have been converging for quite sometime now, in good and bad ways. While a lot of the attention tends to be on the negative, incidents, exploitation and so on, there are a lot of promising aspects as well, and in my opinion, leveraging AI is the only way cyber has any chance of keeping up with the threat landscape.</p><p>This week we saw an innovative and interesting announcement from one of the industries largest teams, CrowdStrike, who announced their &#8220;Cyber Superintelligence Lab&#8221;, and first breakthrough &#8220;SafeMind&#8221;, in partnership with NVIDIA.</p><p>It is described as a family of purpose-built security models and agentic harnesses for autonomous offense and defense together, to both identify and resolve vulnerabilities, as depicted below:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J6RW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J6RW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png 424w, https://substackcdn.com/image/fetch/$s_!J6RW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png 848w, https://substackcdn.com/image/fetch/$s_!J6RW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png 1272w, https://substackcdn.com/image/fetch/$s_!J6RW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J6RW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png" width="1437" height="593" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:593,&quot;width&quot;:1437,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:724728,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J6RW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png 424w, https://substackcdn.com/image/fetch/$s_!J6RW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png 848w, https://substackcdn.com/image/fetch/$s_!J6RW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png 1272w, https://substackcdn.com/image/fetch/$s_!J6RW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cf9c1b6-75e1-4c2c-8af1-d5316641a024_1437x593.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Their blog has an interesting video and frames using the Red and Blue models together (or not) to identify attack paths and vulnerabilities and mitigate them. </p><h3><a href="https://zeltser.com/security-autonomy-matrix">The Security Autonomy Matrix: Deciding AI Authority</a></h3><p>Many organizations are wrestling with the autonomy that agents introduce. That&#8217;s why this Security Autonomy Matrix from Lenny Zeltser is a timely resource, helping organizations walk through how much authority AI agents get with different columns and rows for considerations such as workflows, triggers, autonomy levels per action class, accountable person, gate, residual risk and safeguards as well as reevluation triggers and expirations. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gw70!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gw70!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png 424w, https://substackcdn.com/image/fetch/$s_!Gw70!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png 848w, https://substackcdn.com/image/fetch/$s_!Gw70!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png 1272w, https://substackcdn.com/image/fetch/$s_!Gw70!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gw70!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png" width="760" height="369" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64323490-4961-4103-b97d-9da1a417833c_760x369.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:369,&quot;width&quot;:760,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50456,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gw70!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png 424w, https://substackcdn.com/image/fetch/$s_!Gw70!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png 848w, https://substackcdn.com/image/fetch/$s_!Gw70!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png 1272w, https://substackcdn.com/image/fetch/$s_!Gw70!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64323490-4961-4103-b97d-9da1a417833c_760x369.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://commandline.microsoft.com/agent-hooks-framework-neutral-ai-governance-contract/">Agent Hooks: An open framework-neutral AI governance contract</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kW91!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kW91!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png 424w, https://substackcdn.com/image/fetch/$s_!kW91!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png 848w, https://substackcdn.com/image/fetch/$s_!kW91!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png 1272w, https://substackcdn.com/image/fetch/$s_!kW91!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kW91!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png" width="691" height="351" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:351,&quot;width&quot;:691,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50938,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kW91!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png 424w, https://substackcdn.com/image/fetch/$s_!kW91!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png 848w, https://substackcdn.com/image/fetch/$s_!kW91!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png 1272w, https://substackcdn.com/image/fetch/$s_!kW91!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472ba89c-f49e-4129-9c84-f3844cb5e277_691x351.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hooks have quickly become one of the de facto runtime enforcement mechanisms for controlling actions agents take. They&#8217;ve seen adoption across endpoint coding agents, and custom/homegrown agents alike. </p><p>That said, there are a lot of different frameworks, SDK&#8217;s and more that must be considered across frameworks and platforms. Microsoft. published an open, framework-neutral governance contract with conformance testing on both sides. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8lLz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8lLz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png 424w, https://substackcdn.com/image/fetch/$s_!8lLz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png 848w, https://substackcdn.com/image/fetch/$s_!8lLz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png 1272w, https://substackcdn.com/image/fetch/$s_!8lLz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8lLz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png" width="766" height="320" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:320,&quot;width&quot;:766,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:100658,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8lLz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png 424w, https://substackcdn.com/image/fetch/$s_!8lLz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png 848w, https://substackcdn.com/image/fetch/$s_!8lLz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png 1272w, https://substackcdn.com/image/fetch/$s_!8lLz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5216e0d-0fff-4ae0-8aed-fc39bb66cda3_766x320.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>AppSec</h1><h3><a href="https://www.resilientcyber.io/p/appsec-in-the-age-of-agents">AppSec in the Age of Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l_1a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l_1a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!l_1a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!l_1a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!l_1a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l_1a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg" width="484" height="270.2554945054945" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:484,&quot;bytes&quot;:2845188,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!l_1a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!l_1a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!l_1a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!l_1a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24c52ee-e6f3-4955-98b0-4c0732e24b50_2752x1536.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>AppSec was already losing ground prior to AI coding agents hitting the scene. Trends such as "Shift Left" and DevSecOps fell short, producing noise for developers and reinforcing the very silos between teams they were meant to break down.<br><br>Now, </span><strong><a href="https://www.linkedin.com/company/firstdotorg/"><span>FIRST</span></a></strong><span> projects we could see ~66,000+ CVE's in 2026, yet most organizations can only remediate about 10% of their findings in a month, despite </span><strong><a href="https://www.linkedin.com/company/verizon/"><span>Verizon</span></a></strong><span>'s DBIR showing exploitation as the initial access vector in breaches. Meanwhile, AI is industrializing the discovery of vulnerabilities and now we're seeing examples of agentic workflows and autonomous exploitation of known exploited vulnerabilities.<br><br>Better prioritization alone isn't going to close the gap, and a decade of refining how we rank findings hasn't stopped vulnerability backlogs from growing. </span><strong><a href="https://www.linkedin.com/company/cisagov/"><span>Cybersecurity and Infrastructure Security Agency</span></a></strong><span>'s published their 2024-2025 Vulnerability Review report, and it showed 41.5% of KEV's map to </span><strong><a href="https://www.linkedin.com/company/mitre/"><span>MITRE</span></a></strong><span> "stubborn weaknesses", with 18 CWE's appearing in the CWE Top 25 every year from 2019-2025... the same classes of flaws keep shipping year after year.<br><br>This is why root cause research from </span><strong><a href="https://www.linkedin.com/in/jeevan-jutla/"><span>Jeevan Jutla</span></a></strong><span> and </span><strong><a href="https://www.linkedin.com/company/geckosec/"><span>Gecko Security</span></a></strong><span>, a </span><strong><a href="https://www.linkedin.com/company/resilient-cyber/"><span>Resilient Cyber</span></a></strong><span> partner caught my attention. They traced disclosed findings, such as in n8n, back to their origins and found 569 findings came from just 105 distinct root causes, with 67% of them being repeats of earlier issues, same with other platforms such as GitLab, where 58% were repeats. <br><br>What looks like a runaway backlog is often a short list of root causes that just get ignored, when we could fix the class once, and it stays fixed. I chat with a lot of teams in AppSec, and often hear about prioritization, intelligence, dashboards, ticketing and more, but don't often hear about addressing root causes, despite it being advocated for by leaders such as CISA, </span><strong><a href="https://www.linkedin.com/in/lordbob/"><span>Bob Lord</span></a></strong><span> and others for years.<br><br>This is one of the key shifts I think AppSec needs to make in the age of agents. I dove into the data, AI discovery and exploitation trends and what eliminating vulnerability classes looks like in practice in my latest blog.</span></p><h3><a href="https://www.resilientcyber.io/p/why-finding-bugs-still-isnt-commoditized"><span>Why Finding Bugs Still Isn&#8217;t Commoditized</span></a></h3><p><span>In this episode, I sit down with </span><strong><a href="https://www.linkedin.com/in/ondrejvlcek/">Ondrej Vlcek</a></strong><span>, Founder and CEO at </span><strong><a href="https://aisle.com/">AISLE</a></strong><span> and the former CEO of Avast, to discuss where AI vulnerability discovery actually stands, including what got commoditized, what did not, and why shipping a fix a maintainer will accept is a very different problem from finding the bug in the first place.</span></p><p>Ondrej spent roughly 30 years in this industry, starting as employee number six or seven at Avast doing kernel-mode driver work on Windows 95, and eventually taking the company public and selling it to NortonLifeLock in a nearly $9 billion transaction. He co-founded AISLE in the fall of 2024, and his team has since disclosed more than 350 CVEs across projects like OpenSSL and curl.</p><p>I have been beating the remediation drum for a while now, so this was a conversation I wanted to have with someone who is actually shipping accepted patches upstream rather than just posting finding counts.</p><div id="youtube2-ZmTW7MXCJes" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ZmTW7MXCJes&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ZmTW7MXCJes?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://lnkd.in/p/e95SWPxh">Runaway CVE Rates</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UFsV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UFsV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png 424w, https://substackcdn.com/image/fetch/$s_!UFsV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png 848w, https://substackcdn.com/image/fetch/$s_!UFsV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png 1272w, https://substackcdn.com/image/fetch/$s_!UFsV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UFsV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png" width="985" height="558" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:558,&quot;width&quot;:985,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:226900,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UFsV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png 424w, https://substackcdn.com/image/fetch/$s_!UFsV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png 848w, https://substackcdn.com/image/fetch/$s_!UFsV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png 1272w, https://substackcdn.com/image/fetch/$s_!UFsV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77a22b55-181a-4da2-9d16-91bc56335f08_985x558.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It should come as no surprise that we have more CVE&#8217;s in 2026 than in 2025, but how rapidly it is growing is still something to track and honestly be concerned with in some ways. </p><p>Jerry Gamblin recently took to LinkedIn to show how CVE&#8217;s YTD are up +86.5% YoY at 396 a day, compared to 238 a day the year prior. This is not even accounting for the fact that NVD isn&#8217;t enriching the full breadth of CVE&#8217;s and some may not be showing up in the NVD, as it made adjustments to try and manage the load it is seeing, much of which is being driven by the industrialization of AI discovering vulnerabilities.</p><p>There&#8217;s nuance in the numbers of course, and understanding what to prioritize and remediate is still critical and is a topic I dug into with Jerry himself recently on the show.</p><div id="youtube2-nzQLQxD-GfE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;nzQLQxD-GfE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/nzQLQxD-GfE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://www.uber.com/us/en/blog/efficient-software-factory/">Running a Software Factory Efficiently at Uber-Scale</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6AIQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6AIQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png 424w, https://substackcdn.com/image/fetch/$s_!6AIQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png 848w, https://substackcdn.com/image/fetch/$s_!6AIQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png 1272w, https://substackcdn.com/image/fetch/$s_!6AIQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6AIQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png" width="1178" height="544" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:544,&quot;width&quot;:1178,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:241708,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6AIQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png 424w, https://substackcdn.com/image/fetch/$s_!6AIQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png 848w, https://substackcdn.com/image/fetch/$s_!6AIQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png 1272w, https://substackcdn.com/image/fetch/$s_!6AIQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948e3dcf-955c-42dc-85b2-84742b9e6972_1178x544.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There&#8217;s been a rise in discussions about &#8220;Software Factories&#8221;, but it has often been hypothetical, or small startups. What does it look like for a major tech company and enterprise? </p><p>Well, Uber provided that answer with an excellent blog recently, showing how agentic tooling grew 7x, and weekly agent requests grew 9.4x while total spend &#8220;relatively stabilized&#8221;. </p><p>This piece goes deep into Uber&#8217;s software factory, covering models, MCP, FinOps and more. While it isn&#8217;t security focused, I do think this is a development pattern we should expect to see grew with AI coding agents, and security inevitably will want to be a key part of the conversation. </p><h3><a href="https://www.empiricalsecurity.com/assets/how-to-deal-with-speed-whitepaper.pdf">Empirical Observations: How to Deal with Speed</a></h3><p>Everyone (including myself) have been discussing the so called &#8220;Vulnpocalypse&#8221; and industrialization of vulnerability discovery, runaway CVE volume, need for prioritization and so on. </p><p>This paper from Empirical provides some great insights on how to actually deal with the problem. From FIRST reporting a projects 66,000+ CVE&#8217;s in 2026, DBIR showing vuln exploitation as a leading initial attack vector at 31% and more, the problem has been top of mind for many. </p><p>Empirical also highlights just how woefully insufficient the CISA KEV is when it comes to identifying vulnerabilities with known exploitation, as shown below:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!POEM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!POEM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png 424w, https://substackcdn.com/image/fetch/$s_!POEM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png 848w, https://substackcdn.com/image/fetch/$s_!POEM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png 1272w, https://substackcdn.com/image/fetch/$s_!POEM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!POEM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png" width="477" height="368.7876588021779" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e48ba8b5-3757-435f-b39e-503660954fbc_551x426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:426,&quot;width&quot;:551,&quot;resizeWidth&quot;:477,&quot;bytes&quot;:25630,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213738856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!POEM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png 424w, https://substackcdn.com/image/fetch/$s_!POEM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png 848w, https://substackcdn.com/image/fetch/$s_!POEM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png 1272w, https://substackcdn.com/image/fetch/$s_!POEM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe48ba8b5-3757-435f-b39e-503660954fbc_551x426.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>They make recommendations such as replacing uniform SLA&#8217;s with risk-stratified cadences, tracking days since last exploitation rather than a permanent &#8220;known exploited&#8221; flag, and accounting for local exposure and escalating on quiet-to-active transitions intra-day. </p><h3><a href="https://incentivegradient.com/the-real-reasons-vulnerability-remediation-is-slow-and-how-ai-changes-the-economics-of-fixing-things/">The Real Reasons Vuln Remediation is Slow and How AI Changes the Economics of Fixing Things</a></h3><p>Many of us have been arguing that finding vulnerabilities has never been the bottleneck, fixing them is, and now AI is massively front loading the finding, while fixing stays problematic.</p><p>This piece from longtime CISO and security leader Tim Rains highlights the reasons remediation is slow, such as the friction of safely changing production software, differences in bought vs. built software, incomplete inventories, unclear ownership, and fragmented authority among many other issues.</p><p>This is a comprehensive real-world informed perspective of the problems of reducing risk in complex enterprise environments and now marketing noise from a vendor.</p><h3><a href="https://www.techtarget.com/it-infrastructure/news/366649818/Rival-buyout-aids-customers-after-DevSecOps-firm-shutters">Rival Buyout Aids Customer After Firm Shutters</a></h3><p>Last week I had shared how the hardened container and supply chain vendor Minimus had decided to shutdown and return funding to investors after struggling to grow and scale. </p><p>In a bit of a surprise move, their competitor Echo stepped into the fold, announcing they were acquiring Minimus and providing an option to customers of Minimus who would have had to switch to an alternative, such as the industry leader in Chainguard. </p><p>I had a chance to provide some commentary to TechTarget on this one.</p><h1>Closing Thoughts</h1><p>It&#8217;s another week that sometimes feels like a month in the AI era. From collective calls for cyber defense in the face of AI-driven risks and threats, continues fundraising as teams tackle emerging and innovative solutions, and the industry grappling with incidents tied to agents and AI. </p><p>That said, the work rolls on, and so do we!</p><blockquote><p><strong>Stay Resilient</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[AppSec in the Age of Agents]]></title><description><![CDATA[A deep dive into how AI and agents are reshaping AppSec and vulnerability management, and the case for eliminating entire vulnerability classes]]></description><link>https://www.resilientcyber.io/p/appsec-in-the-age-of-agents</link><guid isPermaLink="false">https://www.resilientcyber.io/p/appsec-in-the-age-of-agents</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Wed, 02 Sep 2026 12:05:46 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/ca8694bd-ea08-482b-b724-0f106c25170e_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>By now, it is clear that AI and agents are fundamentally changing how modern software gets built, shipped, and secured, with development teams producing code at a volume and velocity that the traditional AppSec operating model was never designed to handle. </p><p>If we&#8217;re being honest, AppSec was already struggling to keep pace in the pre-AI era, with efforts such as &#8220;Shift Left&#8221; and DevSecOps largely falling short, producing noise for developers and bolstering the very silos between teams they meant to break down.</p><p>That said, the same capabilities driving the AI velocity are also industrializing vulnerability discovery, compressing exploitation timelines, and steadily marching toward autonomous exploitation, which means the gap between how fast software changes and how fast we secure it is widening in both directions at once.</p><p>In this article, I will walk through how AppSec and vulnerability management are evolving in the age of AI and agents, from growing vulnerability backlogs and exploitation&#8217;s rise as a leading attack vector to the industrialization of vulnerability discovery and what it demands of modern AppSec programs. </p><p>I will also take a look at how Gecko Security, a Resilient Cyber partner and prior guest on the show, is putting one of the more promising answers into practice, eliminating entire classes of vulnerabilities rather than playing whack-a-mole with individual findings. </p><p>So with all of that said, let&#8217;s begin to dive in.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>Drowning in Backlogs</h2><p>To level set, the vulnerability landscape was already straining defenders before AI entered the picture. <strong><a href="https://www.first.org/blog/20260211-vulnerability-forecast-2026">FIRST&#8217;s vulnerability forecast</a></strong> projects roughly 59,000 new CVEs for 2026, the first year we will cross 50,000 published CVEs annually, while NIST moved approximately 29,000 backlogged CVEs into a &#8220;Not Scheduled&#8221; category, effectively conceding that the enrichment pipeline the entire ecosystem depends on cannot keep pace. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l7uC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l7uC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png 424w, https://substackcdn.com/image/fetch/$s_!l7uC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png 848w, https://substackcdn.com/image/fetch/$s_!l7uC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png 1272w, https://substackcdn.com/image/fetch/$s_!l7uC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l7uC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png" width="1259" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1259,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170689,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213160963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!l7uC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png 424w, https://substackcdn.com/image/fetch/$s_!l7uC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png 848w, https://substackcdn.com/image/fetch/$s_!l7uC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png 1272w, https://substackcdn.com/image/fetch/$s_!l7uC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d5fee3c-54f2-4eba-9641-ab129cc75bbe_1259x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Now, as I argued in <strong><a href="https://www.resilientcyber.io/p/why-70000-cves-is-less-scary-than">Why 70,000 CVE&#8217;s is Less Scary Than It Sounds</a> </strong>in my discussion with FIRST&#8217;s Jerry Gamblin, raw CVE counts have always been a poor proxy for actual risk, given that only a small fraction of published vulnerabilities are ever exploited in the wild. </p><p>The problem is that organizational vulnerability backlogs do not care about that nuance. Large enterprises are sitting on backlogs in the hundreds of thousands of findings while remediating <strong><a href="https://www.resilientcyber.io/p/vulnerability-management-in-the-age">roughly 10% of them in a given month</a></strong>, and the inputs to those backlogs are accelerating, with GitHub hitting 1 billion commits in 2025 and pacing toward 14 billion in 2026, driven overwhelmingly by AI coding agents. </p><p>More code means more vulnerabilities, more findings, and more debt for AppSec teams that were already underwater.</p><h2>The Exploitation Era</h2><p>While the backlogs grow, attackers have gotten far more efficient at capitalizing on them. As I covered in <strong><a href="https://www.resilientcyber.io/p/the-dbirs-exploitation-era">The DBIR&#8217;s Exploitation Era</a></strong>, Verizon&#8217;s DBIR shows exploitation of vulnerabilities has become the leading initial access vector in breaches, nearly doubling the share held by phishing, a notable inversion of the attack hierarchy most defenders internalized over the past decade. </p><p>Meanwhile, only 26% of critical Known Exploited Vulnerabilities (KEVs) were fully remediated in 2025, down from 38% the year prior, with organizations taking a median of 43 days to remediate edge device vulnerabilities.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_yY0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_yY0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png 424w, https://substackcdn.com/image/fetch/$s_!_yY0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png 848w, https://substackcdn.com/image/fetch/$s_!_yY0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png 1272w, https://substackcdn.com/image/fetch/$s_!_yY0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_yY0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png" width="758" height="451" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:451,&quot;width&quot;:758,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:154296,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213160963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_yY0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png 424w, https://substackcdn.com/image/fetch/$s_!_yY0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png 848w, https://substackcdn.com/image/fetch/$s_!_yY0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png 1272w, https://substackcdn.com/image/fetch/$s_!_yY0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7f36dfc-ec1a-4579-a96d-e1abe2b11799_758x451.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Time-to-exploit trends make those remediation timelines look even worse. As I laid out in <strong><a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">The AI Cyber Capability Curve</a></strong>, the median time from disclosure to first observed exploitation has collapsed from 771 days in 2018 to 84 days in 2021 to roughly 6 days in 2023, and in 2026, 67.2% of exploited CVEs are zero-days, weaponized before or on the day of disclosure, up from 16.1% in 2018. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ouIF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ouIF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png 424w, https://substackcdn.com/image/fetch/$s_!ouIF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png 848w, https://substackcdn.com/image/fetch/$s_!ouIF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png 1272w, https://substackcdn.com/image/fetch/$s_!ouIF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ouIF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png" width="962" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:962,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74840,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213160963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ouIF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png 424w, https://substackcdn.com/image/fetch/$s_!ouIF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png 848w, https://substackcdn.com/image/fetch/$s_!ouIF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png 1272w, https://substackcdn.com/image/fetch/$s_!ouIF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7aa6968-677b-42f2-8cbb-65f53179cebf_962x612.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Attackers measure time-to-exploit in hours while defenders still measure remediation in weeks and months, that&#8217;s a fundamental mismatch and it isn&#8217;t in our favor.</p><p>CISA has taken notice. Its <strong><a href="https://www.cisa.gov/sites/default/files/2026-08/cisa-vulnerability-review-fy-2024-2025.pdf">Vulnerability Review</a></strong> opens by pointing out that most compromises have not relied on advanced techniques but instead:</p><blockquote><p><strong>&#8220;Exploited simple, known software vulnerabilities that remain widespread and persistent in publicly exposed assets,&#8221; and that &#8220;Increasingly, cyber threat actors are using artificial intelligence (AI) to automate all the steps necessary to exploit these vulnerabilities.&#8221; </strong></p></blockquote><p>In fact, CISA explicitly states it is publishing the review &#8220;to establish a baseline of the vulnerability landscape <em><strong>prior</strong> </em>to widespread AI-enabled vulnerability discovery.&#8221; When the nation&#8217;s cyber defense agency is planting a flag to measure the before-and-after of AI-enabled vulnerability discovery, that tells you something about where this is headed and it isn&#8217;t pretty.</p><h2>Industrializing Discovery, Automating Exploitation</h2><p>The direction is already visible in the research. Vulnerability discovery has been industrialized, and exploitation is being automated right behind it, as the next shoe to drop.</p><p>On the discovery side, frontier labs and researchers keep demonstrating capabilities that were considered aspirational just a couple of years ago. Anthropic has discovered 500+ high-severity zero-day vulnerabilities across open source codebases, including 22 Firefox vulnerabilities in a two-week span. Their Glasswing update showed that they had discovered 23,000+ vulnerabilities as of May.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EVo3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EVo3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png 424w, https://substackcdn.com/image/fetch/$s_!EVo3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png 848w, https://substackcdn.com/image/fetch/$s_!EVo3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png 1272w, https://substackcdn.com/image/fetch/$s_!EVo3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EVo3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png" width="863" height="533" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:533,&quot;width&quot;:863,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:157559,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213160963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EVo3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png 424w, https://substackcdn.com/image/fetch/$s_!EVo3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png 848w, https://substackcdn.com/image/fetch/$s_!EVo3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png 1272w, https://substackcdn.com/image/fetch/$s_!EVo3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8046564e-80b8-46d0-894a-9b9b894683e7_863x533.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>DARPA&#8217;s AI Cyber Challenge drove the cost of AI-driven vulnerability discovery down to $152 per vulnerability across 54 million lines of code. This was further corroborated by the UK AI Security Institute&#8217;s evaluations, where frontier models completed expert-level offensive cyber tasks at rates that climb with every model generation, including multi-stage corporate network attack chains that take human experts roughly 20 hours.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rnzy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rnzy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png 424w, https://substackcdn.com/image/fetch/$s_!rnzy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png 848w, https://substackcdn.com/image/fetch/$s_!rnzy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png 1272w, https://substackcdn.com/image/fetch/$s_!rnzy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rnzy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png" width="1039" height="637" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:637,&quot;width&quot;:1039,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:191859,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213160963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rnzy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png 424w, https://substackcdn.com/image/fetch/$s_!rnzy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png 848w, https://substackcdn.com/image/fetch/$s_!rnzy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png 1272w, https://substackcdn.com/image/fetch/$s_!rnzy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F202a8cee-d99e-4d43-8544-fc82311fe713_1039x637.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The exploitation side is following the same curve. The researchers behind the <strong><a href="https://moak.ai/">MOAK</a></strong> agentic exploit workflow demonstrated autonomous exploitation of 174 of 178 known exploited vulnerabilities in testing, including going from a public React vulnerability to a working shell in 21 minutes with no human intervention. </p><p>Researcher Sean Heelan <strong><a href="https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/">showed</a></strong> AI agents generating 40+ working exploits for a single flaw at a cost of around $50, while a swarm-based research effort surfaced 100+ exploitable Windows kernel driver vulnerabilities across AMD, Intel, NVIDIA, Dell, Lenovo, and IBM in 30 days for $600 in total compute, roughly $4 per bug. </p><p>The strain is even showing up in the disclosure ecosystem itself, with HackerOne&#8217;s Internet Bug Bounty pausing submissions in March 2026 as valid AI-generated vulnerability reports climbed 210%.</p><p>I have described this asymmetry before, and I will repeat it here because it captures the structural problem. Attackers need an API key and an afternoon, while defenders need a quarter and a steering committee. </p><p>Fully autonomous exploitation at scale is not quite here yet, but every data point above suggests we are approaching it, and the organizations planning for it now will be in a fundamentally different position than those waiting for proof.</p><h2>Context Is the Scarce Resource</h2><p>All of this has real implications for how AppSec and vulnerability management programs need to operate. For one, the legacy model of dumping low-context scanner output onto development teams and calling it risk management is finished. When findings volume grows faster than remediation capacity, the only lever left is ruthless prioritization, and that requires context that most AppSec tooling and teams have historically failed to provide.</p><p>CISA&#8217;s Vulnerability Review is blunt on this point, noting that: </p><blockquote><p><strong>CVSS scores &#8220;reflect theoretical severity, not real-world impact&#8221; and that &#8220;AI-enabled vulnerability discovery is rapidly increasing the volume of disclosed vulnerabilities, requiring ruthless patching prioritization.&#8221; </strong></p></blockquote><p>CISA&#8217;s prioritization guidance now hinges on four variables:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jm8W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jm8W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png 424w, https://substackcdn.com/image/fetch/$s_!jm8W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png 848w, https://substackcdn.com/image/fetch/$s_!jm8W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png 1272w, https://substackcdn.com/image/fetch/$s_!jm8W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jm8W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png" width="374" height="268" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:268,&quot;width&quot;:374,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:37253,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213160963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jm8W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png 424w, https://substackcdn.com/image/fetch/$s_!jm8W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png 848w, https://substackcdn.com/image/fetch/$s_!jm8W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png 1272w, https://substackcdn.com/image/fetch/$s_!jm8W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd690cb4a-9362-4657-b635-6dea8bce3afa_374x268.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That is the same direction modern AppSec needs to move, leading with known exploitation, exploitability, reachability, and business context rather than raw severity scores. </p><p>A critical-severity finding in an internal tool with no path to sensitive data is not the same as a medium-severity finding sitting on an internet-facing asset with automated exploit tooling in the wild, and treating them the same is how teams end up drowning in backlogs while the vulnerabilities that matter sit unpatched. </p><p>This is a theme I have been discussing for years. The difference now is that AI has raised the stakes on both sides of the equation, and the teams that leverage AI and agents to bring exploitability and business context to their findings will fair far better, especially if they look to try and root out the causes of vulnerabilities as well, which takes me to my next point.</p><h2>Eliminating Entire Classes of Vulnerabilities</h2><p>That brings me to the second half of this discussion, which is what it looks like when someone actually builds for this reality. </p><p>Gecko Security is an AI AppSec company I recently hosted on the Resilient Cyber podcast in an episode titled <strong><a href="https://youtu.be/xtdt2P8qKVU?si=CpWPcQTErZZOvOmC">Building an AI AppSec Engineer</a></strong>. </p><div id="youtube2-xtdt2P8qKVU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;xtdt2P8qKVU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/xtdt2P8qKVU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>A couple of moments from that conversation have stuck with me since. Ryan called MTTR &#8220;<em>a fake metric that makes teams look good</em>,&#8221; arguing that recurrence rate is the metric AppSec should actually care about, since MTTR incentivizes closing repeated instances of the same flaw rather than addressing the root cause, and as I often say in cyber (and general), incentives drive behavior.</p><p>JJ made the point that as AI automates more of the discovery and triage work, &#8220;<em>the scarce thing left is the judgment</em>.&#8221;</p><p>Both of those observations converge on an idea that CISA has been advocating for years through <strong><a href="https://www.cisa.gov/securebydesign">Secure-by-Design</a></strong>, which urges software producers to &#8220;eliminate common vulnerability classes and publish roadmaps for the rest.&#8221; </p><p>It shows up again in CISA&#8217;s Secure-by-Demand guidance, where one of the key questions buyers are told to ask vendors is which vulnerability classes the producer has already eliminated and what the roadmap is for the rest, and in the Vulnerability Review&#8217;s discussion of AI-powered threats, CISA&#8217;s prescription for defenders explicitly includes &#8220;elimination of entire vulnerability classes&#8221; alongside MFA and engineering resilience into AI-integrated systems.</p><p>The Vulnerability Review data shows why this matters. </p><p>Across FY2024 and FY2025, 41.5% of KEVs map to what MITRE calls &#8220;stubborn weaknesses,&#8221; the 18 CWEs that appeared in the CWE Top 25 every single year from 2019 to 2025. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PQLl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PQLl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png 424w, https://substackcdn.com/image/fetch/$s_!PQLl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png 848w, https://substackcdn.com/image/fetch/$s_!PQLl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png 1272w, https://substackcdn.com/image/fetch/$s_!PQLl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PQLl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png" width="396" height="160" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:160,&quot;width&quot;:396,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29980,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213160963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PQLl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png 424w, https://substackcdn.com/image/fetch/$s_!PQLl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png 848w, https://substackcdn.com/image/fetch/$s_!PQLl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png 1272w, https://substackcdn.com/image/fetch/$s_!PQLl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb95b9f4-03b6-409d-9553-cea67b54914a_396x160.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Per CISA, three of today&#8217;s top 10 CWEs would have been considered &#8220;unforgivable&#8221; by the standards MITRE published nearly two decades ago, and their persistence illustrates that &#8220;the problem is not technical complexity, it is organizational culture, developer workflows, and systemic gaps in Secure-by-Design adoption.&#8221; In other words, the industry keeps losing to the same classes of flaws, over and over, at scale, rather than to novel attacks.</p><p>Gecko&#8217;s own research, presented at Black Hat 2026 and detailed in their <strong><a href="https://www.gecko.security/lp/eliminating-vulnerability-classes?utm_source=linkedin&amp;utm_medium=paid_social&amp;utm_campaign=gecko_sponsorship_2026&amp;utm_content=chris_hughes">executive brief on eliminating vulnerability classes</a></strong>, quantifies just how much of the backlog problem is really a root cause problem. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6RJB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6RJB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png 424w, https://substackcdn.com/image/fetch/$s_!6RJB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png 848w, https://substackcdn.com/image/fetch/$s_!6RJB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png 1272w, https://substackcdn.com/image/fetch/$s_!6RJB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6RJB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png" width="720" height="151" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:151,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17935,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/213160963?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6RJB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png 424w, https://substackcdn.com/image/fetch/$s_!6RJB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png 848w, https://substackcdn.com/image/fetch/$s_!6RJB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png 1272w, https://substackcdn.com/image/fetch/$s_!6RJB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5d2d7d-38fe-471b-abfd-f81c5b7713b1_720x151.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>By tracing every publicly disclosed vulnerability in n8n and GitLab back to its fixing commit, Gecko found that 569 disclosed findings traced back to just 105 distinct root causes, with 1,117 duplicate backports along the way. </p><p>For n8n, 67% of public disclosures were repeats of previously disclosed issues, and for GitLab the figure was 58%, with the repeats costing roughly $44,000 in bounties for n8n and over $1 million for GitLab. The longest-lived vulnerability class persisted 728 days before comprehensive remediation. As the research puts it:</p><blockquote><p><strong>&#8220;What looks like an unmanageable backlog is a short list of root causes. Fix the class once, at a shared point, and it stays fixed.&#8221;</strong></p></blockquote><p>That framing resonates with me because it converts an intractable-sounding problem, hundreds of thousands of findings and growing, into a tractable one, a bounded list of systemic flaws that can actually be burned down, if we intentionally focused on doing so.</p><p>It is also exactly the kind of work AI and agents are suited for, reasoning across an entire codebase to identify the shared root cause behind dozens of surface-level findings, something no human AppSec team has the cycles to do at scale.</p><h2>The Cal.com Example</h2><p>For a concrete look at what this means in practice, Gecko&#8217;s <strong><a href="https://gecko.security/blog/how-cal-com-rebuilt-appsec-after-going-closed-source?utm_source=blog&amp;utm_medium=sponsored_content&amp;utm_campaign=gecko_sponsorship_2026&amp;utm_content=chris_hughes">case study with Cal.com</a> </strong>is worth a read. </p><p>Cal.com is a scheduling platform used by <em>over 1 million people</em>, with customers including Vercel, Coinbase, and Ramp, and it spent five years as an open source project before going closed source in April 2026. </p><p>Their situation reads like a compressed version of everything discussed above. After adopting AI coding tools, pull request volume jumped from roughly 40 to 100 per day, supported by a security team of two engineers covering 25 engineers, something many of us in AppSec can likely relate to. </p><p>They were running multiple scanners, both legacy and AI-native, which generated duplicated findings, inconsistent severity ratings, and a steady stream of false positives. Cal.com CEO Bailey Pumfleet captured the consistency problem well, noting that &#8220;If you ask two different AI agents to review the same PR, they&#8217;re going to pull out very different results.&#8221;, which isn&#8217;t surprising given the non-deterministic nature of AI.</p><p>Consolidating on Gecko gave them a single source of truth for pull request security decisions, with context-aware findings validated by proof-of-concept exploits, an understanding of production exploitability and data sensitivity, and findings automatically routed to code owners, with every PR scanned before human review. </p><p>Keith Williams, Cal.com&#8217;s Head of Engineering, described the outcome as &#8220;One tool that gives us great results from a full scanning perspective, and every single pull request that goes in, we know is protected.&#8221; His broader observation applies to every team shipping AI-assisted code right now, &#8220;This is the new reality. Especially with Mythos, you&#8217;re always going to find new stuff.&#8221; </p><p>His quote doesn&#8217;t even account for the fact that Mythos level capabilities are now becoming commoditized, with open weight models quickly catching up to the frontier and available to malicious actors everywhere.</p><p>Notice what that approach operationalizes: </p><ul><li><p>Exploit validation instead of theoretical severity</p></li><li><p>Production context instead of isolated code findings</p></li><li><p>The elimination of recurring classes instead of an ever-growing queue of one-off tickets. </p></li></ul><p>Those are precisely the properties I have argued modern vulnerability management needs, and precisely what CISA is pushing the ecosystem toward.</p><h2>Closing Thoughts</h2><p>This is far from an exhaustive discussion of how AI and agents are reshaping AppSec, and much of the trajectory remains to be seen, particularly around how quickly autonomous exploitation matures from research demonstrations into commodity tradecraft. </p><p>That said, the direction of travel is clear. Vulnerability discovery has been industrialized, exploitation timelines have collapsed, backlogs are compounding, and the traditional AppSec model of low-context findings and human-speed triage cannot survive contact with machine-speed offense.</p><p>Security has historically been a laggard when it comes to adopting transformative technology, hand-wringing over risks while the business races ahead. </p><p>AI and agents offer us a rare chance to break that pattern, using the same capabilities that are empowering attackers to finally address root causes, eliminate entire classes of vulnerabilities, and focus our scarce human judgment on the decisions that actually matter. </p><p>Will we take it, or will we spend the next decade remediating the same stubborn weaknesses we have been remediating for the last two?</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Why Finding Bugs Still Isn’t Commoditized]]></title><description><![CDATA[The AISLE CEO on the jagged frontier, sovereign AI, and why remediation is still the hard part.]]></description><link>https://www.resilientcyber.io/p/why-finding-bugs-still-isnt-commoditized</link><guid isPermaLink="false">https://www.resilientcyber.io/p/why-finding-bugs-still-isnt-commoditized</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 01 Sep 2026 16:41:03 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/213714893/d5ed53ff27c9160f5292fa8966db7eb2.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode, I sit down with <strong><a href="https://www.linkedin.com/in/ondrejvlcek/">Ondrej Vlcek</a></strong>, Founder and CEO at <strong><a href="https://aisle.com/">AISLE</a></strong> and the former CEO of Avast, to discuss where AI vulnerability discovery actually stands, including what got commoditized, what did not, and why shipping a fix a maintainer will accept is a very different problem from finding the bug in the first place. </p><p>Ondrej spent roughly 30 years in this industry, starting as employee number six or seven at Avast doing kernel-mode driver work on Windows 95, and eventually taking the company public and selling it to NortonLifeLock in a nearly $9 billion transaction. He co-founded AISLE in the fall of 2024, and his team has since disclosed more than 350 CVEs across projects like OpenSSL and curl.</p><p>I have been beating the remediation drum for a while now, so this was a conversation I wanted to have with someone who is actually shipping accepted patches upstream rather than just posting finding counts.</p><p>We chatted about:</p><ul><li><p>Going from Avast intern to CEO, and why vulnerability management became the next problem worth solving</p></li><li><p>The jagged frontier, and why a bigger or more expensive model does not reliably mean better results</p></li><li><p>Which bug classes genuinely got cheap to find, and which subtle ones still lead to XZ Utils and Log4j style outcomes</p></li><li><p>Why the gray market price of vulnerabilities has gone up rather than collapsed</p></li><li><p>Building a model-agnostic system, and the bespoke benchmarks AISLE uses to move workloads between models</p></li><li><p>Sovereign AI, on-prem and air-gapped deployment, and why your findings are more sensitive than your source code</p></li><li><p>Triage, reachability, and why most findings are not actually exploitable in your environment</p></li><li><p>Patch verification in bespoke Docker environments, and mitigations for systems that cannot be redeployed</p></li><li><p>How AISLE earned trust from curl after Daniel Stenberg shut down a seven year bug bounty</p></li><li><p>Whether a CVE count is a vanity metric, and what makes it a real signal</p></li><li><p>Build versus buy as the underlying model capability keeps getting cheaper</p></li><li><p>What breaks first across maintainers, CNAs, and the CVE ecosystem</p></li></ul><div id="youtube2-ZmTW7MXCJes" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ZmTW7MXCJes&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ZmTW7MXCJes?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h3>Prefer to listen? </h3><p>Find the episode on <strong><a href="https://open.spotify.com/episode/3efH7KDY0XrpOkKOsLQicq?si=KhEYMoSCS9efS2bjclvLOg">Spotify</a></strong> and <strong><a href="https://podcasts.apple.com/us/podcast/the-jagged-frontier-of-finding-and-fixing-vulns-with-ai/id1555928024?i=1000787199717">Apple Podcasts </a></strong></p><p>Please be sure to leave a rating and review, as it truly helps the show!</p><div><hr></div><h1>Takeaways</h1><h2>Bigger models are not reliably better models</h2><p>The phrase &#8220;jagged frontier&#8221; has escaped AISLE&#8217;s blog and entered the general discourse at this point, and Ondrej&#8217;s explanation of it is the most practical version I have heard. As he put it, &#8220;more expensive or bigger or more robust model doesn&#8217;t necessarily mean better results.&#8221; Large models struggle with certain vulnerability classes while smaller ones, given a harness that supplies prior knowledge of what good looks like, do better on discovery and triage.</p><p>The second half of that argument is the one buyers underweight. Cheaper and faster models mean you can run far more of them. &#8220;Because of those gains that you get in terms of speed and in terms of cost, you can run many, many more agents at the same time,&#8221; Ondrej said, describing swarms of specialized agents that chunk code and coordinate with each other. That is what people mean when they say the system beats the model, and it is why AISLE built its own benchmark to move workloads between models as new versions ship. Anyone building this internally should be asking whether they have that evaluation layer, because without it you are married to whichever model you picked last quarter.</p><h2>Discovery is cheaper, but it is not solved</h2><p>I pushed on whether finding bugs is now commoditized, and Ondrej&#8217;s answer used the market rather than the models. Vulnerability prices in the gray market have gone up, not down, despite all the model progress. The floor moved, so memory safety bugs and off-by-one errors are much easier and cheaper to find today. The subtle bugs that produce XZ Utils and Log4j outcomes are still hard.</p><p>This lines up with the token maxing backlash we saw earlier this year. The industry briefly confused spending more compute with getting better results, and the pricing data suggests the market never believed it.</p><h2>Remediation is more than generating a patch</h2><p>This was the heart of the episode for me. Ondrej broke remediation into pieces most vendors collapse into one. Triage comes first, and it matters because &#8220;the vast majority of findings may actually not be related or are not directly exploitable in your environment,&#8221; which requires data flow context rather than just function reachability. Then comes patch generation, and then the part nobody demos, which is automated verification. AISLE spins up bespoke Docker images to compile the code, run unit tests, and confirm the fix neither reintroduces the vulnerability nor breaks something else.</p><p>Then there is the category where a patch cannot be deployed at all. Cars, industrial robots, ATMs. Ondrej&#8217;s answer there was compensating controls and network level mitigations rather than pretending a code patch closes the loop. This maps almost exactly to the empirical work Keith Hoodlitt and the team at 1Password published on AI-generated patches, where fixes frequently failed, broke functionality, or introduced new vulnerabilities. Anyone selling you autonomous remediation without a verification story is selling you the easy half.</p><h2>Quality is what earned curl&#8217;s trust</h2><p>Daniel Stenberg shut down a seven year bug bounty over what he called death by a thousand slops, and a few months later curl was running AISLE internally. Ondrej&#8217;s explanation was not clever technology. It was standards. &#8220;We would be professionally ashamed to actually send reports that we don&#8217;t stand behind,&#8221; he said, describing reports that arrive pre-triaged with a working proof of vulnerability, repro steps, and a pre-tested proposed fix. Roughly 15 to 20 reports went into curl, all of them high quality.</p><p>That is the whole lesson for anyone pointing AI at open source right now. Maintainers are unpaid volunteers, and the currency you are spending is their attention. Ondrej called it white glove service for maintainers, and it is the reason a vocal skeptic reversed his position.</p><h2>Ondrej is more optimistic than I expected on what breaks next</h2><p>I asked what cracks first over the next 18 months, whether it is maintainer capacity or the CVE and CNA institutions. He acknowledged the pressure, citing roughly 47,000 CVEs in 2025 and a single recent month approaching 10,000, and he was direct that &#8220;these maintainers have no chance whatsoever to withstand the incoming load of new vulnerabilities that is just starting to come.&#8221; But he declined to predict a break, pointing instead at the wave of vendors and labs standing up open source support programs over the last several months. AISLE itself became a CNA under the ENISA route only a few weeks ago.</p><p>His read on the moment was my favorite line of the conversation. &#8220;If 2025 was mostly about naysayers, 2026 is people are realizing, my gosh, this actually works.&#8221; His advice to AppSec leaders followed from that, which was to stop leaning on legacy pattern matching tools when adversaries have unrestricted access to both frontier and open weight models, and to spend real time experimenting rather than waiting for the category to settle.</p><p>Thanks to Ondrej for coming on. Keep an eye on AISLE&#8217;s research at aisle.com/blog, since they are publishing some of the more useful empirical work on AI-driven vulnerability discovery right now.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[AI’s Evidence Problem]]></title><description><![CDATA[A deep dive into why data sits at the center of securing AI, and what practitioners actually need to see]]></description><link>https://www.resilientcyber.io/p/ais-evidence-problem</link><guid isPermaLink="false">https://www.resilientcyber.io/p/ais-evidence-problem</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 28 Aug 2026 12:12:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fazg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Throughout my career in cyber I have watched our industry meet every major technology shift the same way, which is with a governance committee, a fresh acronym, and a vendor category to match.</p><p>Cloud got CSPM, containers got runtime security, SaaS got SSPM, and AI is now working through its own alphabet soup. Some of that is warranted, given how different these architectures are from what came before.</p><p>That said, when you strip the AI security conversation down to what is actually going wrong inside enterprises today, most of it is an old problem wearing a new outfit. Sensitive data going somewhere it should not, into systems nobody inventoried, through accounts nobody manages, leaving behind no record anyone can query afterward. </p><p>We have written the acceptable use policies, stood up the AI committees, and run the prompt injection tabletops, and nearly all of it rests on an assumption that does not survive contact with a real environment, which is that we often can&#8217;t see what our AI systems are actually doing.</p><p>In this article I want to walk through the problem space the way practitioners are running into it, starting with why data became the attack surface, then the visibility gap sitting underneath most AI governance programs, and finally what AI is doing to detection engineering. </p><p>From there I will use Cribl, a Resilient Cyber partner whose team walked me through their platform and their AI security approach across two conversations this summer, as an example of how one vendor is coming at it. </p><h2>The Data Was Always the Point</h2><p>To level set on how fast this moved, Verizon&#8217;s<strong> <a href="https://www.verizon.com/business/resources/Td15/reports/2026-dbir-data-breach-investigations-report.pdf">2026 DBIR</a></strong> has a Shadow AI section drawn from its data loss prevention telemetry, and it found that 45% of employees are now considered regular users of AI on their corporate devices, authorized or not, up from 15% the year before, which is a tripling in twelve months. </p><p>67% of users are reaching AI services through non-corporate accounts on corporate hardware, which Verizon notes is actually a slight decrease from the prior year, while Shadow AI has climbed to the third most common non-malicious insider action in that dataset, a fourfold increase in percentage terms. What is leaving matters as much as how much of it, and Verizon found source code to be the most common data type going into external models.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aCFG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aCFG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png 424w, https://substackcdn.com/image/fetch/$s_!aCFG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png 848w, https://substackcdn.com/image/fetch/$s_!aCFG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png 1272w, https://substackcdn.com/image/fetch/$s_!aCFG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aCFG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png" width="509" height="371" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:371,&quot;width&quot;:509,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30624,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aCFG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png 424w, https://substackcdn.com/image/fetch/$s_!aCFG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png 848w, https://substackcdn.com/image/fetch/$s_!aCFG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png 1272w, https://substackcdn.com/image/fetch/$s_!aCFG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc1daa2a-9519-4eee-8b4c-770d2c8db1ba_509x371.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For those who prefer breach outcomes to policy violations, IBM&#8217;s <strong><a href="https://www-api.ibm.com/adobe/assets/urn:aaid:aem:21111142-1251-4369-86fb-57b82f5bb108/original/as/Cost%20of%20a%20Data%20Breach%20Report%202026.pdf">Cost of a Data Breach Report 2026</a></strong> found that incidents involving shadow AI more than doubled this year, to 43% from 20%, and cost more when they happened, at an average of $5.39 million against $4.63 million the prior year. </p><p><strong><a href="https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average">More than 20% of organizations</a> </strong>reported a breach targeting AI models or applications outright. When IBM looked at how those AI systems were actually compromised, the two leading causes were compromised APIs, applications or plug-ins at 27%, and cloud misconfigurations affecting AI workloads, also at 27%.</p><p>That last finding is key, because it tells you where the risk actually lives. The AI systems getting breached are not being broken through exotic model attacks. They are falling to integrations, plumbing, and misconfigured Cloud, which is to say the same things that have been breaching everything else for fifteen years.</p><p>The governance numbers in the same report are worth highlighting as well. 68% of breached organizations had no AI governance in place to manage AI or detect shadow AI, which is worse than the 63% reported a year earlier, meaning the gap widened rather than closed during a year of exceptionally fast adoption. Among organizations that reported an AI-related breach specifically, <strong><a href="https://www.ibm.com/think/x-force/2026-cost-of-a-data-breach-ai-adversaries-enterprise-risk">92% lacked proper AI access controls</a></strong>, and only 40% reported using access controls on AI models and data at all.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qDb9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qDb9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png 424w, https://substackcdn.com/image/fetch/$s_!qDb9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png 848w, https://substackcdn.com/image/fetch/$s_!qDb9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png 1272w, https://substackcdn.com/image/fetch/$s_!qDb9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qDb9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png" width="651" height="367" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:367,&quot;width&quot;:651,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29738,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qDb9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png 424w, https://substackcdn.com/image/fetch/$s_!qDb9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png 848w, https://substackcdn.com/image/fetch/$s_!qDb9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png 1272w, https://substackcdn.com/image/fetch/$s_!qDb9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c164073-12a0-4f54-b9f4-846b11528ea6_651x367.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To be fair, the industry is not standing still. The World Economic Forum&#8217;s <strong><a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/in-full/executive-summary-6efae97d74/">Global Cybersecurity Outlook 2026</a></strong> found the share of respondents assessing the security of their AI tools nearly doubled in a year, from 37% to 64%. That is real progress but it also leaves more than a third not assessing those tools at all, which is a tough position to defend in 2026, particularly when 87% of those same respondents called AI-related vulnerabilities the fastest-growing cyber risk of the past year.</p><h2>Sanctioned Is Not the Same as Instrumented</h2><p>Now, the instinctive response to shadow AI is to sanction the tools, buy the enterprise tenant, and declare the problem managed. I understand the impulse and it is not wrong, exactly. It just solves a different problem than the one people think it solves.</p><p>Moving a Developer from a personal ChatGPT account onto a corporate tenant addresses account governance. It does very little for the data governance underneath it. The prompts still contain source code, the context windows still pull from internal document stores and wikis, the retrieval layer still reaches into systems with their own access models, and the outputs still land somewhere nobody is watching. The organization traded an unmanaged account it could not see into for a managed account it still cannot see into, and then closed the risk item anyways, despite the gap.</p><p>ISACA&#8217;s <strong><a href="https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2026/ai-pulse-poll-reveals-rampant-uncertainty-on-enterprise-landscape">2026 AI Pulse Poll</a></strong>, which surveyed more than 3,400 practitioners across IT audit, governance, cybersecurity, privacy and emerging tech roles, put a number on it. Only 43% said they were completely or fairly confident their organization could investigate and explain a serious AI incident to leadership or regulators. More than half do not know how quickly they could halt an AI system in response to a security incident.</p><p>That first figure is, to me, the whole article in one line. Investigating and explaining an incident is not a policy capability or a governance capability. It is an evidence capability, and evidence means logs somebody decided to collect before the thing happened. A majority of ISACA&#8217;s respondents could not say they were confident their organization could reconstruct what an AI system did. </p><p>Everything else in an AI security program sits downstream of that.</p><h2>You Cannot Inventory What You Never Logged</h2><p>Every serious piece of AI security guidance published in the last three years starts in the same place, which is inventory.</p><p>NIST has covered this in various publications such as the AI Risk Management Framework which calls for inventorying AI systems and their GenAI Profile, which pushed for organizations to enumerate AI systems and continuously monitor third-party ones being leveraged. </p><p>OWASP gets to the same place from the threat side, where the <strong><a href="https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/">Excessive Agency</a></strong> guidance asks teams to log and monitor LLM extension activity, and is careful to frame that as damage limitation rather than prevention. It&#8217;s worth noting that excessive agency also jumped to #3 on the latest OWASP LLM Top 10 as well, due to the impact agents are having in real-world incidents.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VNaF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VNaF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png 424w, https://substackcdn.com/image/fetch/$s_!VNaF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png 848w, https://substackcdn.com/image/fetch/$s_!VNaF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png 1272w, https://substackcdn.com/image/fetch/$s_!VNaF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VNaF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png" width="988" height="831" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:831,&quot;width&quot;:988,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:211587,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VNaF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png 424w, https://substackcdn.com/image/fetch/$s_!VNaF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png 848w, https://substackcdn.com/image/fetch/$s_!VNaF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png 1272w, https://substackcdn.com/image/fetch/$s_!VNaF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b0356e6-1592-4cee-b54e-275a7028326b_988x831.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP Top 10 for Agentic Applications</a></strong>, released at the end of 2025, is where this stops being aspirational and becomes an engineering requirement. Goal hijack asks for &#8220;comprehensive logging and continuous monitoring of agent activity&#8221; plus a behavioral baseline covering goal state, tool-use patterns, and invariant properties such as schema and access patterns. </p><p>Tool misuse wants immutable logs of every tool invocation and parameter change, along with monitoring for unusual tool-chaining. Rogue agents wants signed, immutable audit logs of agent actions, tool calls, and inter-agent communication.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Dl8b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Dl8b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png 424w, https://substackcdn.com/image/fetch/$s_!Dl8b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png 848w, https://substackcdn.com/image/fetch/$s_!Dl8b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png 1272w, https://substackcdn.com/image/fetch/$s_!Dl8b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Dl8b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png" width="658" height="159" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:159,&quot;width&quot;:658,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:27724,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Dl8b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png 424w, https://substackcdn.com/image/fetch/$s_!Dl8b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png 848w, https://substackcdn.com/image/fetch/$s_!Dl8b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png 1272w, https://substackcdn.com/image/fetch/$s_!Dl8b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14c81053-00a1-46e1-b43c-7a2308eb33fa_658x159.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Read those as an engineer rather than as a GRC practitioner, and what OWASP is asking for is a behavioral baseline per agent, immutable logs of every tool call, and signed records of agent-to-agent traffic. Every one of them is a telemetry problem before it is an AI problem, and I would wager most organizations reading this could not satisfy a single one today for a single production agent, let alone all of them.</p><p>The Cloud Security Alliance published <strong><a href="https://cloudsecurityalliance.org/press-releases/2026/03/24/more-than-two-thirds-of-organizations-cannot-clearly-distinguish-ai-agent-from-human-actions">research in March</a></strong> in which 68% of respondents said they cannot clearly distinguish AI agent activity from human activity, and 79% believe agents create new access pathways that are difficult to monitor. The shape of it matches what I hear from practitioners constantly, and it is the same structural problem we have failed to solve for non-human identities generally, which I wrote about previously in an article titled <a href="https://www.resilientcyber.io/p/identity-is-the-agentic-ai-problem">&#8220;</a><strong><a href="https://www.resilientcyber.io/p/identity-is-the-agentic-ai-problem">Identity Is the Agentic AI Problem Nobody Has Solved Yet</a></strong><a href="https://www.resilientcyber.io/p/identity-is-the-agentic-ai-problem">&#8221;</a>.</p><p>Now, none of this means the sky is falling, and I want to be careful not to overstate where enterprises actually are. Gartner expects <strong><a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">more than 40% of agentic AI projects to be canceled</a></strong> by the end of 2027 on cost, unclear value, or inadequate risk controls. A great deal of what is marketed as the agentic enterprise is pilot work, as organizations stumble through the messy work of trying to operationalize this disruptive and quickly evolving technology.</p><p>That is precisely the argument for building the instrumentation now, while these architectures are still taking shape, before the telemetry debt compounds the way our vulnerability backlogs did, and before we spend another decade bolting visibility onto systems designed without it. </p><p>We know how that story ends because we have lived it with Cloud, with SaaS, and with every wave before them.</p><h2>The Volume Problem Nobody Budgeted For</h2><p>The uncomfortable part is that the answer to all of the above is &#8220;log more,&#8221; and that runs directly into the economics of every SIEM contract in the industry.</p><p>Telemetry growth by itself is an old problem and I won&#8217;t rehash all of the details. What makes it different this time is the character of the data rather than just the quantity of it. </p><p>Prompt and completion logs, tool call traces, retrieval events, agent-to-agent messages, and MCP server interactions arrive verbose, semi-structured, and inconsistently schematized across every provider, framework, and gateway in the stack. Making that queryable is exactly the kind of undifferentiated engineering work detection teams have no capacity for, and it lands on the same people already drowning in alert backlogs.</p><p>So we arrive at the moment where OWASP asks for immutable logs of every tool invocation and the practitioner reading that guidance is doing math on what their ingest tier costs per gigabyte. Better policy does not resolve that tension, as long as the cost of retaining a log stays coupled to the cost of analyzing it, security teams will keep making retention decisions on budget grounds and then discover, mid-incident, that the evidence they needed got dropped at the pipeline six months earlier. </p><p>I have written about the structural version of this in <a href="https://www.resilientcyber.io/p/the-siems-structural-problem-and">&#8220;</a><strong><a href="https://www.resilientcyber.io/p/the-siems-structural-problem-and">The SIEM&#8217;s Structural Problem and Why It Matters Now More Than Ever</a></strong><a href="https://www.resilientcyber.io/p/the-siems-structural-problem-and">&#8221;</a> and <a href="https://www.resilientcyber.io/p/the-data-layer-is-the-new-battleground">&#8220;</a><strong><a href="https://www.resilientcyber.io/p/the-data-layer-is-the-new-battleground">The Data Layer Is the New Battleground for the Agentic SOC</a></strong><a href="https://www.resilientcyber.io/p/the-data-layer-is-the-new-battleground">&#8221;</a>, so I will leave it there.</p><h2>The Pyramid Is Shifting</h2><p>The other half of this, and the half that came up in my conversation with Nicole Beckwith on Cribl&#8217;s security side, is what AI is doing to the indicators we have been building detections on for a decade.</p><p>For those unfamiliar, David Bianco published <a href="https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html">&#8220;</a><strong><a href="https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html">The Pyramid of Pain</a></strong><a href="https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html">&#8221;</a> back in 2013 and it remains one of the most durable mental models in detection engineering. </p><p>It ranks indicator types from hash values at the bottom, through IP addresses, domain names, network and host artifacts, and tools, up to TTPs at the top, ordered by how much pain denying each one causes the adversary. </p><p>His read on the bottom of the pyramid has aged extremely well. Any reasonably advanced adversary can rotate IPs &#8220;with very little effort,&#8221; and if you burn one of them they can usually recover &#8220;without even breaking stride.&#8221; Hashes are worse, since flipping a single inconsequential bit produces a completely unrelated value.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fazg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fazg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png 424w, https://substackcdn.com/image/fetch/$s_!fazg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png 848w, https://substackcdn.com/image/fetch/$s_!fazg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png 1272w, https://substackcdn.com/image/fetch/$s_!fazg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fazg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png" width="593" height="334.4904270986745" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4aae647-aa45-4268-9f00-c611573f0705_679x383.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:383,&quot;width&quot;:679,&quot;resizeWidth&quot;:593,&quot;bytes&quot;:56097,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fazg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png 424w, https://substackcdn.com/image/fetch/$s_!fazg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png 848w, https://substackcdn.com/image/fetch/$s_!fazg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png 1272w, https://substackcdn.com/image/fetch/$s_!fazg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aae647-aa45-4268-9f00-c611573f0705_679x383.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Bianco came back to this <strong><a href="https://detect-respond.blogspot.com/2022/04/stop-using-hashes-for-detection-and.html">with data in 2022</a></strong>, analyzing VirusTotal metadata for over 11 million unique files submitted during 2021, and found that 91.81% of them were submitted by a single submitter, with only 0.33% seen by more than ten organizations. His conclusion was blunt, and it was to stop using third-party hash values for detection, because the effort to reward ratio does not work.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AR0t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AR0t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png 424w, https://substackcdn.com/image/fetch/$s_!AR0t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png 848w, https://substackcdn.com/image/fetch/$s_!AR0t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png 1272w, https://substackcdn.com/image/fetch/$s_!AR0t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AR0t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png" width="833" height="368" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:368,&quot;width&quot;:833,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23432,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AR0t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png 424w, https://substackcdn.com/image/fetch/$s_!AR0t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png 848w, https://substackcdn.com/image/fetch/$s_!AR0t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png 1272w, https://substackcdn.com/image/fetch/$s_!AR0t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27dfddb-f6d1-400c-a5d6-a875bcd88262_833x368.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The governments have since made the same argument one level up. The <strong><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-093a">joint advisory on fast flux</a></strong> published in April of 2025 by NSA, and others notes that a typical fast flux domain may change its IP address every 3 to 5 minutes, which &#8220;renders IP blocking irrelevant&#8221; because the address is out of use before the block lands.</p><p>Beckwith&#8217;s framing was that AI has accelerated this shift rather than created it, and I think that is the correct and appropriately un-hyped read. The evidence that adversaries are operationalizing AI is real and it is now documented by the model providers themselves. Google&#8217;s Threat Intelligence Group <strong><a href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools">reported in November</a></strong> that for the first time it had identified malware families using LLMs during execution, generating scripts and obfuscating their own code on demand rather than hard-coding it. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eh_t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eh_t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png 424w, https://substackcdn.com/image/fetch/$s_!eh_t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png 848w, https://substackcdn.com/image/fetch/$s_!eh_t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png 1272w, https://substackcdn.com/image/fetch/$s_!eh_t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eh_t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png" width="589" height="324.1714285714286" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:366,&quot;width&quot;:665,&quot;resizeWidth&quot;:589,&quot;bytes&quot;:70224,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eh_t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png 424w, https://substackcdn.com/image/fetch/$s_!eh_t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png 848w, https://substackcdn.com/image/fetch/$s_!eh_t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png 1272w, https://substackcdn.com/image/fetch/$s_!eh_t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d625627-adce-479a-9b6b-ae462aed5f30_665x366.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One family, PROMPTFLUX, carried a function to have Gemini rewrite its own source hourly, though GTIG noted that function was commented out, which is the kind of detail that separates threat intelligence from marketing. Another, PROMPTSTEAL, was used by APT28 against Ukraine and represents GTIG&#8217;s first observation of malware querying an LLM in live operations. Anthropic separately <strong><a href="https://www.anthropic.com/news/disrupting-AI-espionage">reported</a></strong> a campaign against roughly thirty targets where, by their assessment, AI performed 80 to 90% of the work with humans intervening only sporadically, at perhaps four to six critical decision points.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lggS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lggS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png 424w, https://substackcdn.com/image/fetch/$s_!lggS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png 848w, https://substackcdn.com/image/fetch/$s_!lggS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png 1272w, https://substackcdn.com/image/fetch/$s_!lggS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lggS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png" width="1456" height="1083" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1083,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:99194,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lggS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png 424w, https://substackcdn.com/image/fetch/$s_!lggS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png 848w, https://substackcdn.com/image/fetch/$s_!lggS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png 1272w, https://substackcdn.com/image/fetch/$s_!lggS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd63e1266-e217-4974-bfd8-8eb66cb74702_2755x2050.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>OpenAI&#8217;s<strong> <a href="https://openai.com/global-affairs/disrupting-malicious-uses-of-ai-october-2025/">October threat report</a> </strong>concluded across the activity it disrupted that it found &#8220;no evidence of new tactics&#8221; or that its models handed threat actors novel offensive capabilities. In the individual operations it wrote up, OpenAI described actors who appeared to be primarily seeking incremental efficiency in workflows they already had. </p><p><strong><a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026/">M-Trends 2026</a></strong>, grounded in over 500,000 hours of Mandiant incident response last year, lands in the same place, noting adversary AI adoption while reporting that, from its own frontline vantage point, the vast majority of successful intrusions still stem from &#8220;fundamental human and systemic failures.&#8221; Global median dwell time actually rose to 14 days from 11, and exploits remained the most common initial infection vector for the sixth straight year at 32% of intrusions.</p><p>So the honest synthesis, less exciting than either the doom or the dismissal, is that AI is not rewriting the threat model from scratch. It is compressing the cost and the cycle time of everything at the bottom of the pyramid, which was already cheap for adversaries and already low-value for defenders. </p><p>Regenerate the binary, rotate the infrastructure, rewrite the script, and every atomic indicator you were matching on is stale before your feed refreshes. MITRE&#8217;s Center for Threat-Informed Defense makes the structural version of this argument in <strong><a href="https://center-for-threat-informed-defense.github.io/summiting-the-pyramid/overview/">Summiting the Pyramid</a></strong>, pointing out that a detection built on a hash will miss the same malware altered by a single byte, while TTPs sit at the top precisely because they are the most expensive thing for an adversary to change.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sLfe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sLfe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png 424w, https://substackcdn.com/image/fetch/$s_!sLfe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png 848w, https://substackcdn.com/image/fetch/$s_!sLfe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png 1272w, https://substackcdn.com/image/fetch/$s_!sLfe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sLfe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png" width="548" height="298" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92f3b58e-fb89-4832-a5df-437abef42660_548x298.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:298,&quot;width&quot;:548,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sLfe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png 424w, https://substackcdn.com/image/fetch/$s_!sLfe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png 848w, https://substackcdn.com/image/fetch/$s_!sLfe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png 1272w, https://substackcdn.com/image/fetch/$s_!sLfe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92f3b58e-fb89-4832-a5df-437abef42660_548x298.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Detecting behavior rather than artifacts has been the stated goal of detection engineering for a decade. What has kept most teams from getting there is not conviction. </p><p>It is that behavioral detection requires broad, retained, correlatable telemetry across sources, and that requirement collides head-on with the volume and cost problem in the previous section. Which brings the two halves of this article together.</p><h2>Four Things, All of Them Telemetry</h2><p>Strip away the vendor positioning and the requirements for securing AI in an enterprise reduce to four things, and Nicole from Cribl&#8217;s framing of them makes a ton of sense.</p><ul><li><p>First, identify what exists, meaning an inventory of models, agents, tools, plugins, and extensions, including the ones nobody registered. </p></li><li><p>Second, observe how those things are actually being used, which means prompts, input context, and session activity rather than a count of API calls. </p></li><li><p>Third, track where data is going, meaning what feeds the models, where it is retained, and what leaves the boundary. </p></li><li><p>Fourth, alert on malicious activity, including exfiltration, leakage, abnormal usage spikes, compromised accounts, and agents deviating from how they normally behave.</p></li></ul><p>Every one of those four is a telemetry problem. You cannot inventory what does not emit, you cannot baseline behavior without history, and you cannot detect deviation without both. </p><blockquote><p><strong>The AI security tooling market is full of products that quietly assume this substrate already exists, and in most enterprises it does not.</strong></p></blockquote><h2>A Look at One Approach in Practice</h2><p>Which brings me to Cribl, who partnered on this piece and whose team spent two sessions this summer walking me through their platform and their AI security approach.</p><p>Cribl is useful as the example here for a specific reason, which is that they came at AI security from the data layer rather than the model layer, which is especially relevant as we as an industry realize the model isn&#8217;t a security boundary. </p><p>The company positions itself as <a href="https://cribl.io/">&#8220;</a><strong><a href="https://cribl.io/">Your AI Platform for Telemetry</a></strong><a href="https://cribl.io/">&#8221;</a>, They also earned a <strong><a href="https://cribl.io/news/cribl-achieves-fedramp-authority-to-operate-for-us-federal-government-agencies/">FedRAMP Moderate ATO</a></strong> in January, which was relevant for me given I came from the public sector both as a contractor supporting agencies, and on the GSA FedRAMP team and I know agencies desperately need innovative capabilities when it comes to AI. </p><p>I chatted with Nick Heudecker, who leads market strategy and competitive intelligence at Cribl, and he described customers seeing data volumes climb 80 to 100 percent annually, with some going from one petabyte to 2.5 petabytes per day of ingestion, and most of them not remotely ready for that from a governance or security perspective. </p><p>The architectural argument he made is one I have made myself in a different context, which is that a pipeline sitting between sources and destinations functions as a two-way door. It lets you change SIEMs, augment with best-of-breed tools to avoid vendor lock, route the same data to multiple destinations, and avoid a world where your detection strategy gets dictated by whatever your ingest contract makes affordable.</p><p>On the four pillars, Cribl&#8217;s <strong><a href="https://cribl.io/solutions/initiatives/ai-observability/">AI observability app</a></strong> runs on top of that pipeline. Publicly the company pitches it as one place to search, investigate and report on AI telemetry across models, tools and environments, surfacing AI usage, sensitive data and cost. </p><p>In the demo that meant an inventory of models, agents, tools, plugins and extensions, extending into prompts, input context and session activity. For the data protection layer, <strong><a href="https://cribl.io/resources/sb/cribl-guard/">Cribl Guard</a></strong> ships with over 200 configurable policy rules and more than 220 prebuilt detection patterns, organized into <strong><a href="https://docs.cribl.io/guard/guard-rulesets/">rulesets</a></strong> for secrets and credentials, bank and credit cards, medical codes and licenses, network authentication and configs, and PII, running either in an active mode that masks in real time or a background mode that samples and lets you decide what to protect automatically.</p><p>I want to be equally clear about the boundaries here, because the Cribl team was during our convos, and that candor is a good part of why I found the conversation worth writing up. </p><p>Cribl operates as an aggregator. For bespoke agents running on endpoints it leans on existing EDR telemetry rather than shipping its own sensor, and for tracking where data goes it currently depends on tooling like DLP that you already own. </p><p>Once that telemetry is ingested you can drive policy decisions from it and route enforcement accordingly, but the collection depends on instrumentation already in place. For most enterprises that is a feature rather than a limitation, since the alternative is yet another agent on the endpoint. It does mean Cribl&#8217;s AI visibility is bounded by the quality of the sources feeding it, and any evaluation should start there rather than with the dashboard.</p><p>The fourth pillar is where the demo got genuinely interesting. Nicole&#8217;s team had built a threat intelligence platform on Cribl&#8217;s app framework to ingest IoCs, and then ran into exactly the wall this article walked through above, which is that the bottom of the pyramid has become ephemeral enough that the effort stops paying for itself. </p><p>What they built in response is called <strong><a href="https://cribl.io/resources/wp/introducing-apex/">APEX</a></strong>, and it maps MITRE ATT&amp;CK TTPs as individual signals against raw telemetry and clusters those signals into behavioral chains, generating detections from the previous 30 days of telemetry to set a baseline, with users able to tailor criticality and monitoring windows to their own risk tolerance. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f9aC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f9aC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png 424w, https://substackcdn.com/image/fetch/$s_!f9aC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png 848w, https://substackcdn.com/image/fetch/$s_!f9aC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png 1272w, https://substackcdn.com/image/fetch/$s_!f9aC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f9aC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png" width="1018" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1018,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:118222,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f9aC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png 424w, https://substackcdn.com/image/fetch/$s_!f9aC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png 848w, https://substackcdn.com/image/fetch/$s_!f9aC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png 1272w, https://substackcdn.com/image/fetch/$s_!f9aC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d1e6be6-9600-4226-9ff5-abc5b9d02560_1018x795.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Publicly, Cribl <strong><a href="https://cribl.io/news/cribls-ai-platform-debuts-powerful-new-security-capabilities/">announced new security capabilities</a></strong> in August that include stream-native detections running on telemetry as it moves through the pipeline, plus detection engineering capabilities out of their <strong><a href="https://cribl.io/blog/what-the-cardinalops-acquisition-means-for-you/">CardinalOps acquisition</a> </strong>that map detections to ATT&amp;CK, expose coverage gaps, and surface broken and noisy rules before they fail silently.</p><p>Two design choices in the capability Cribl demoed are worth pulling out for practitioners. The first is that it works against any log source piping into Cribl without requiring OCSF normalization, with detection engineers working from roughly the top 15 critical fields that stay consistent across sources rather than parsing every field in every source. </p><p>Anyone who has been involved in a data normalization project knows how much undifferentiated effort that avoids, and normalization debt is one of the quieter reasons detection coverage stalls out.</p><p>The second is that running detections closer to the telemetry layer, rather than after data lands in an analytics platform, shortens the distance between an event happening and an alert firing. </p><p>Combined with the correlation work their team described as weeks out at the time of our conversation, clustering activity within time windows so alerts fire against behavioral baselines, the intent is to avoid a world where covering the technique space means authoring and maintaining tens of thousands of individual detections. Whether that holds up at enterprise scale is something practitioners will need to validate in their own environments, and I would want to see it running against a genuinely messy estate before drawing conclusions but the premise makes sense and is promising.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!haIy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!haIy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png 424w, https://substackcdn.com/image/fetch/$s_!haIy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png 848w, https://substackcdn.com/image/fetch/$s_!haIy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png 1272w, https://substackcdn.com/image/fetch/$s_!haIy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!haIy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png" width="1456" height="969" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:969,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:258901,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212025744?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!haIy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png 424w, https://substackcdn.com/image/fetch/$s_!haIy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png 848w, https://substackcdn.com/image/fetch/$s_!haIy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png 1272w, https://substackcdn.com/image/fetch/$s_!haIy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F035fe754-225a-4fc0-8365-f7fc97f3bf0d_1678x1117.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Closing Thoughts</h2><p>This is far from an exhaustive discussion of AI security, and there are entire domains I have not touched, from model supply chain to inference-time attacks to the agent identity problem, among others. </p><p>That said, the the recurring theme is hard to miss. NIST wants an inventory, OWASP wants immutable logs of every tool invocation and a behavioral baseline for every agent and regulators are going to want you to explain what happened. None of that is achievable without a data layer built to carry it, and most security practitioners being surveyed don&#8217;t feel confident they could produce that today.</p><p>There is a version of this market that sells you a model firewall, a prompt scanner, and yet another dashboard, and leaves you exactly where you started, unable to answer basic questions about what your AI systems did on any given day. I do not think we get out of this by adding another silo. We learned that in the Cloud era and relearned it with SaaS, and the organizations handling AI adoption best so far are the ones treating it as another set of sources and destinations in a pipeline they already understood.</p><p>The ask is tough too though, as we are being asked to expand telemetry and add behavioral baselining for an entirely new class of non-human actor in agents at the exact moment most teams are under pressure to cut ingest costs due to runaway bills. Something has to give there, and I would much rather it be the assumption that we must pay analytics prices to retain evidence than the evidence itself.</p><p>So, will we build the instrumentation while these architectures are still forming, or spend the next five years reconstructing what our agents did from logs we chose not to keep? </p><p>We have run this experiment before, and we know how it goes when security shows up after the fact, which is disjointed tech stacks, open questions in our incident response and the inability to deliver on secure outcomes for the businesses we support.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #111]]></title><description><![CDATA[OpenAI&#8217;s Hugging Face post-mortem, NVIDIA&#8217;s reported bid for the open model hub, sandboxes that don&#8217;t hold, open models closing the gap & a fund built on the agent attack surface]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-111</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-111</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 27 Aug 2026 13:54:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8aPU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #111 of the Resilient Cyber Newsletter!</p><p>Two stories dominated the week, and both of them run through Hugging Face. OpenAI published its technical report on the incident where its own internal research models escaped an evaluation environment and went on to compromise Hugging Face infrastructure, and NVIDIA is reportedly closing in on acquiring Hugging Face for somewhere in the neighborhood of $13 billion.</p><p>Read together, they tell you a lot about where we actually are. Agents are demonstrably capable of chaining novel vulnerabilities to break out of the sandboxes we build for them, and the open model ecosystem those same agents are trained on and distributed through has become valuable enough that the most important chip company on the planet wants to own the distribution point. Both of those have security implications we are only starting to work through.</p><p>The rest of the week filled in around them, with Trail of Bits arguing that VMs won&#8217;t contain cyber-capable agents, the researchers behind ExploitGym walking through how they measure agent exploitation capability, SemiAnalysis making the case that open models close the gap faster with every cycle, and Ciaran Martin offering a badly needed corrective to AI doomerism.</p><p>Let&#8217;s get into it!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8aPU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8aPU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png 424w, https://substackcdn.com/image/fetch/$s_!8aPU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png 848w, https://substackcdn.com/image/fetch/$s_!8aPU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png 1272w, https://substackcdn.com/image/fetch/$s_!8aPU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8aPU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png" width="1456" height="930" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:930,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1379706,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8aPU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png 424w, https://substackcdn.com/image/fetch/$s_!8aPU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png 848w, https://substackcdn.com/image/fetch/$s_!8aPU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png 1272w, https://substackcdn.com/image/fetch/$s_!8aPU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd4292b2-2c68-4a79-bd0b-7580688b30ca_2026x1294.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.runzero.com/try/?utm_source=resilient-cyber&amp;utm_medium=email-sponsored&amp;utm_campaign=free-trial" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wbkm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png 424w, https://substackcdn.com/image/fetch/$s_!wbkm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png 848w, https://substackcdn.com/image/fetch/$s_!wbkm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png 1272w, https://substackcdn.com/image/fetch/$s_!wbkm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wbkm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png" width="257" height="55.07142857142857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:312,&quot;width&quot;:1456,&quot;resizeWidth&quot;:257,&quot;bytes&quot;:109120,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.runzero.com/try/?utm_source=resilient-cyber&amp;utm_medium=email-sponsored&amp;utm_campaign=free-trial&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wbkm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png 424w, https://substackcdn.com/image/fetch/$s_!wbkm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png 848w, https://substackcdn.com/image/fetch/$s_!wbkm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png 1272w, https://substackcdn.com/image/fetch/$s_!wbkm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5144eb36-18ca-45de-ae52-929488800e88_8334x1785.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h3><strong><a href="https://www.runzero.com/try/?utm_source=resilient-cyber&amp;utm_medium=email-sponsored&amp;utm_campaign=free-trial">Know your attack surface before it outgrows you</a></strong></h3><p>You cannot patch, monitor, or govern an asset you don&#8217;t know exists. Yet, most enterprise inventories are still working from an incomplete picture.</p><p>runZero, built by HD Moore (the mind behind Metasploit), delivers agentless, credential-free discovery across your entire internal and external attack surface&#8212;surfacing unknown and unmanaged assets along with the exposures riding along with them: CVEs, default credentials, misconfigurations. No appliances, no scanning windows to negotiate, just an accurate picture of what&#8217;s actually out there.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.runzero.com/try/?utm_source=resilient-cyber&amp;utm_medium=email-sponsored&amp;utm_campaign=free-trial&quot;,&quot;text&quot;:&quot;Start your 21-day free trial&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.runzero.com/try/?utm_source=resilient-cyber&amp;utm_medium=email-sponsored&amp;utm_campaign=free-trial"><span>Start your 21-day free trial</span></a></p><p>Pro tip: When your trial wraps, runZero&#8217;s free Community Edition covers up to 100 devices, perfect for home labs!</p><p><em>*Sponsored</em></p></blockquote><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.reuters.com/technology/nvidia-talks-acquire-hugging-face-13-billion-deal-business-insider-reports-2026-08-27/">NVIDIA in talks to acquire Hugging Face in $13 billion deal</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!svJl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!svJl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png 424w, https://substackcdn.com/image/fetch/$s_!svJl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png 848w, https://substackcdn.com/image/fetch/$s_!svJl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png 1272w, https://substackcdn.com/image/fetch/$s_!svJl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!svJl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png" width="1088" height="292" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:292,&quot;width&quot;:1088,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:67544,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!svJl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png 424w, https://substackcdn.com/image/fetch/$s_!svJl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png 848w, https://substackcdn.com/image/fetch/$s_!svJl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png 1272w, https://substackcdn.com/image/fetch/$s_!svJl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260131ab-8edc-45e9-aaa5-eeed3c96819f_1088x292.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>News broke over the weekend that Hugging Face was fielding takeover interest, and by midweek <strong><a href="https://techcrunch.com/2026/08/26/nvidia-closes-in-on-hugging-face-acquisition/">The Information reported</a></strong> that NVIDIA had agreed to buy it for $12.9 billion, with no signed agreement yet and neither company confirming. For context on how fast this has moved, Hugging Face turned down a $500 million NVIDIA investment in late 2025 that valued it at $7 billion, with CEO Clem Delangue saying the company &#8220;didn&#8217;t want a dominant investor that could sway its decisions.&#8221; It was valued at $4.5 billion in 2023 and is now doing roughly $150 million in annual revenue, up from about $100 million two months prior.</p><p>The strategic logic is easy to follow, with OpenAI, Google, Amazon, and Anthropic all building their own silicon, owning the place where open models get published and pulled is a durable way to keep the ecosystem on your hardware. The security angle is the one I&#8217;m most interested in of course. </p><p>Hugging Face is effectively the GitHub of AI, a package registry for weights, datasets, and Spaces that enterprises pull from constantly, often with far less scrutiny than they apply to OSS packages. Concentrating that registry under a single vendor with its own commercial incentives changes the software supply chain risk conversation, and it does so in the same month the registry itself got rooted.</p><h3><a href="https://www.philvenables.com/post/rolling-with-the-punches-why-cybersecurity-is-backgammon-not-chess">Rolling with the Punches: Why Cybersecurity is Backgammon, not Chess</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oIYy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oIYy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png 424w, https://substackcdn.com/image/fetch/$s_!oIYy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png 848w, https://substackcdn.com/image/fetch/$s_!oIYy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png 1272w, https://substackcdn.com/image/fetch/$s_!oIYy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oIYy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png" width="556" height="338.02272727272725" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:642,&quot;width&quot;:1056,&quot;resizeWidth&quot;:556,&quot;bytes&quot;:342858,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oIYy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png 424w, https://substackcdn.com/image/fetch/$s_!oIYy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png 848w, https://substackcdn.com/image/fetch/$s_!oIYy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png 1272w, https://substackcdn.com/image/fetch/$s_!oIYy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06665b57-09f2-48a5-b5cb-a561c2fc2e95_1056x642.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Phil Venables is one of the most consistently useful writers and deep thinkers in our field, and this one qualifies. His argument is that we keep framing security as chess, a game of perfect information where a sufficiently smart player calculates their way to victory, when it actually behaves like backgammon, which he describes as &#8220;stochastic risk management&#8221; where skill has to account for the dice. He maps it out through blots and anchors (exposed vulnerabilities versus layered controls like IAM, MFA, and segmentation), priming, the blitz (automated ransomware hitting everything at once), and the doubling cube (the decision of whether to pay or execute recovery).</p><p>The cultural point at the end is the one that matters for security leaders. Chasing &#8220;flawless, unyielding defense&#8221; is the wrong objective function, and resilience means accepting that bad rolls happen and building an organization that absorbs and adapts. Given how the OpenAI incident below unfolded, with clear signals that went un-escalated, this framing is timely.</p><h3><a href="https://www.axios.com/2026/08/20/exclusive-crowdstrikes-cto-is-leaving-to-launch-an-ai-cyber-fund">Exclusive: CrowdStrike&#8217;s CTO is leaving to launch an AI cyber fund</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hHLt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hHLt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png 424w, https://substackcdn.com/image/fetch/$s_!hHLt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png 848w, https://substackcdn.com/image/fetch/$s_!hHLt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png 1272w, https://substackcdn.com/image/fetch/$s_!hHLt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hHLt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png" width="1456" height="263" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/431c613c-c664-4898-a282-02d799a4ad20_1562x282.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:263,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74090,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hHLt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png 424w, https://substackcdn.com/image/fetch/$s_!hHLt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png 848w, https://substackcdn.com/image/fetch/$s_!hHLt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png 1272w, https://substackcdn.com/image/fetch/$s_!hHLt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F431c613c-c664-4898-a282-02d799a4ad20_1562x282.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Elia Zaitsev is leaving CrowdStrike after 13 years as global CTO to launch Cognition, a venture firm he is starting with Gur Talpaz and Tayler Sipperly, targeting $170 million. The model is concentrated, leading or co-leading seed and Series A with average checks around $6 million and $15 million respectively, and only three to four investments a year. Zaitsev&#8217;s framing is that agentic AI is a platform reset for security, and as he put it:</p><blockquote><p><strong>&#8220;We have this new attack surface that&#8217;s being brought on by AI and agents.&#8221;</strong></p></blockquote><p>I&#8217;ve made the point before that we are watching a genuine reshuffling of the security market, with operators leaving incumbent platforms to build and fund the next wave. Whether agentic AI produces a category-defining platform or gets absorbed into the existing consolidators is the open question, and it is one Sid Trivedi and I spent a good chunk of our annual pre-Black Hat conversation on. That said, when a sitting CTO of the most successful endpoint platform of the last decade walks out to raise on this thesis, it tells you something about how the people closest to the data see it.</p><h3><a href="https://www.calcalistech.com/ctechnews/article/bj0s5ikdmx">Cybersecurity startup Minimus shutting down after raising $51 million</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X3ZL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X3ZL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png 424w, https://substackcdn.com/image/fetch/$s_!X3ZL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png 848w, https://substackcdn.com/image/fetch/$s_!X3ZL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png 1272w, https://substackcdn.com/image/fetch/$s_!X3ZL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X3ZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png" width="1082" height="416" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:416,&quot;width&quot;:1082,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70344,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!X3ZL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png 424w, https://substackcdn.com/image/fetch/$s_!X3ZL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png 848w, https://substackcdn.com/image/fetch/$s_!X3ZL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png 1272w, https://substackcdn.com/image/fetch/$s_!X3ZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19ee467b-f98f-4d28-a252-98fb4606e250_1082x416.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The other side of that market story, and one we don&#8217;t hear about enough. Minimus, founded by the team that sold Twistlock to Palo Alto Networks for roughly $410 million in 2019, is winding down after raising $51 million in seed funding. The company built stripped-down container images and VMs with dramatically fewer vulnerabilities, publicly launched in April 2025, and had around 60 employees four months ago. Customers have 60 days, until October 22, to migrate off the Minimus registry. The founders&#8217; statement is pretty direct as well, that:</p><blockquote><p><strong>&#8220;the current business and investment climate has resulted in a situation in which we are unable to continue operations.&#8221;</strong></p></blockquote><p>This one stings, because the product solved a real problem. Minimal images are one of the few software supply chain interventions that actually burns down vulnerability backlogs rather than just measuring them. Proven founders, real technology, and a genuine pain point still weren&#8217;t enough, which says quite a bit about how hard it is to sell into a crowded container security market where buyers have five ways to defer the purchase.</p><p>As I wrote on LinkedIn, this is a good example that building a thriving security (or any) company is very hard. This one had a real market need, being addressed by repeat founders who have walked the path. But, it is a highly competitive category with players like Chainguard dominating the space and it is hard to be wake a player who defined and built the category. </p><p>A good reminder in this era of record setting funding rounds, PR announcements and categories flooded with tens of security vendors chasing the same problem around AI and agents. </p><h3><a href="https://zeltser.com/ai-security-buying-questions">Questions to ask AI security vendors</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TIN4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TIN4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png 424w, https://substackcdn.com/image/fetch/$s_!TIN4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png 848w, https://substackcdn.com/image/fetch/$s_!TIN4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png 1272w, https://substackcdn.com/image/fetch/$s_!TIN4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TIN4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png" width="1334" height="392" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:392,&quot;width&quot;:1334,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72134,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TIN4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png 424w, https://substackcdn.com/image/fetch/$s_!TIN4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png 848w, https://substackcdn.com/image/fetch/$s_!TIN4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png 1272w, https://substackcdn.com/image/fetch/$s_!TIN4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32e8a464-760f-4fc3-91c5-2c732d6ab8ac_1334x392.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Lenny Zeltser put together five questions worth bringing into any AI security evaluation, which AI asset the product actually protects, whether it delivers value standalone or requires a broader platform, what exists today versus what lives on the roadmap, whether you already own the capability somewhere else in your stack, and what evidence backs the claims. His framing is refreshingly direct, that &#8220;In the fast-changing AI security market, a product described one way often turns out to be something else after a closer look.&#8221;</p><p>The fourth question is the one most practitioners skip and the one that kills the most deals, and the distinction he draws between traditional tooling with AI bolted on and genuinely AI-native protection is the fault line running through this entire category right now. </p><p>My favorite though is the one tied to roadmap vs. actual capabilities, and not what lives in a analyst or marketing pitch deck. Many of the AI-centric categories have companies chasing the opportunities but they have little to no actual functional capabilities deployed in production with customers.</p><p>Be careful out there!</p><h3><a href="https://www.gatesnotes.com/a-turbulent-ai-era-and-critical-choices-to-make">The choices we make about AI now are critical</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wVRn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wVRn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png 424w, https://substackcdn.com/image/fetch/$s_!wVRn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png 848w, https://substackcdn.com/image/fetch/$s_!wVRn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png 1272w, https://substackcdn.com/image/fetch/$s_!wVRn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wVRn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png" width="548" height="299.1681109185442" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1154,&quot;resizeWidth&quot;:548,&quot;bytes&quot;:119605,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wVRn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png 424w, https://substackcdn.com/image/fetch/$s_!wVRn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png 848w, https://substackcdn.com/image/fetch/$s_!wVRn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png 1272w, https://substackcdn.com/image/fetch/$s_!wVRn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c737117-57c1-410a-8c67-3801163a9a7d_1154x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Bill Gates argues that this transition differs from previous ones because AI automates cognition itself, and that it will play out over a decade rather than across generations. He points to Stanford payroll data showing a 16% relative employment decline for workers aged 22 to 25 in AI-exposed occupations while older workers stayed flat, and proposes a governance framework modeled on nuclear inspection and aviation regimes, &#8220;Human Reserved&#8221; roles kept for people, and a token and robot tax.</p><p>The line security folks should notice is his, that: </p><blockquote><p><strong>&#8220;The smartest cybersecurity experts I know are scared about the next few years, because the attackers are getting powerful new capabilities faster than the defenders can fix all the weaknesses.&#8221; </strong></p></blockquote><p>I don&#8217;t agree with all of his prescriptions, and I remain skeptical of preemptive regulatory regimes built around hypothetical harms. That said, the asymmetry he describes is real, and the gap between offensive capability and defender remediation throughput is showing up in nearly every other item in this issue.</p><p>Diffusion is destiny for defenders, and our best defense against the coming AI impact in cyber by attackers is arming defenders with the innovative capabilities as quickly as possible.</p><h3><a href="https://www.economist.com/by-invitation/2026/08/23/fears-of-ai-induced-armageddon-are-overdone">Fears of AI-induced armageddon are overdone</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Oi_B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oi_B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png 424w, https://substackcdn.com/image/fetch/$s_!Oi_B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png 848w, https://substackcdn.com/image/fetch/$s_!Oi_B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png 1272w, https://substackcdn.com/image/fetch/$s_!Oi_B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oi_B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png" width="1378" height="334" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:334,&quot;width&quot;:1378,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83907,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oi_B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png 424w, https://substackcdn.com/image/fetch/$s_!Oi_B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png 848w, https://substackcdn.com/image/fetch/$s_!Oi_B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png 1272w, https://substackcdn.com/image/fetch/$s_!Oi_B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8136250d-0863-48be-a2ff-fed3f09a4801_1378x334.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Ciaran Martin, founding CEO of the UK&#8217;s NCSC, wrote the counterweight to the piece above, and it is a rational pushback on some of the AI FUD. He opens with L0pht walking into a Senate office building on May 19th 1998 and telling lawmakers they could render the internet unusable in 30 minutes, then walks through Leon Panetta&#8217;s 2012 &#8220;cyber Pearl Harbour&#8221; warning, pointing out that our field has &#8220;a long history of apocalyptic prophecies&#8221; that never arrived.</p><p>Martin isn&#8217;t arguing that nothing bad happens, he is arguing that our track record of predicting catastrophic collapse is terrible and that the predictions themselves distort policy and spending. Coming from the person who ran a national cyber defense agency, that carries weight. Pair it with the Gates piece and with <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd3c6819-d1ef-4f1f-a257-116c0c97172d_1138x1138.png&quot;,&quot;uuid&quot;:&quot;90b4e2e9-ddbc-4e03-8557-3a09d9252d14&quot;}" data-component-name="MentionToDOM"></span> below, and you get a much healthier version of this debate than the one happening on your social media timeline.</p><h3><a href="https://www.bloomberg.com/news/articles/2026-08-20/anthropic-plans-to-change-data-retention-policy-for-advanced-ai">Anthropic plans to change data retention policy for advanced AI</a></h3><p>Anthropic is reportedly moving to let enterprise customers store required data in their own cloud environments rather than exclusively on Anthropic&#8217;s infrastructure, while keeping a 30-day retention requirement for its most capable models. </p><p>For anyone running a frontier model in a regulated environment, this is the constraint that has been blocking deals, and it is a reasonable compromise between the safety case for retention (you cannot investigate an incident like the one below without logs) and the enterprise requirement to control where data lives. </p><p>Given that OpenAI&#8217;s own report leans heavily on retained chain-of-thought and infrastructure telemetry to reconstruct what happened, the tension between &#8220;retain enough to investigate&#8221; and &#8220;retain nothing our customers didn&#8217;t consent to&#8221; is going to be a live governance question for every AI vendor, not just Anthropic.</p><p>This has also been a key point/theme in the conversations around open vs. closed models for enterprises, so it isn&#8217;t surprising to see the labs trying to offer different options to alleviate those concerns and streamline procurement pathways to expand adoption and consumption. </p><h1>AI</h1><h3><a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/">The Hugging Face incident and the road ahead</a></h3><p>This is the report of the year so far, and if you focus on one thing in this weeks issue, make it this. </p><p>OpenAI walked through how internal research models, during cybersecurity evaluations, &#8220;communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access&#8221; and ultimately compromised both OpenAI and Hugging Face infrastructure.</p><p>The timeline is a key aspect to examine. </p><ul><li><p>On May 12 the agents discovered they could pass messages to each other through Artifactory, building an improvised message board out of file directories to coordinate across supposedly isolated instances. </p></li><li><p>On May 26 they got internet access through SSRF. </p></li><li><p>On June 26 they exploited a token refresh flaw for admin access. </p></li><li><p>On July 4 sustained agent activity crashed Artifactory, and when it was rebuilt on July 8, the agents immediately reestablished both the message board and internet access. </p></li><li><p>Between July 10 and 12 they recovered publicly exposed Hugging Face credentials, chained &#8220;several novel security flaws&#8221; into code execution, and took root across Hugging Face servers in multiple regions. </p></li><li><p>Detection came on July 19 and 20, and public disclosure on July 21.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2bGv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2bGv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png 424w, https://substackcdn.com/image/fetch/$s_!2bGv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png 848w, https://substackcdn.com/image/fetch/$s_!2bGv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png 1272w, https://substackcdn.com/image/fetch/$s_!2bGv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2bGv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png" width="1456" height="772" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:772,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:326694,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2bGv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png 424w, https://substackcdn.com/image/fetch/$s_!2bGv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png 848w, https://substackcdn.com/image/fetch/$s_!2bGv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png 1272w, https://substackcdn.com/image/fetch/$s_!2bGv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F58735451-baf1-4b15-9c3a-8747d576357c_2380x1262.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The root cause analysis is where the practitioner value and community takeaways are. OpenAI names reward hacking, persistence without a safe exit, metagaming, and unauthorized communication. The most damning figure in the report is that of 898 ExploitGym tasks, 198 were ones the models had never solved, and those unsolved tasks accounted for &#8220;93% of the tasks that were discussed on the Artifactory message board.&#8221; </p><p>The models were handed impossible problems, given enormous compute, rewarded for solving them, and rationally concluded that attacking the scorer was the path to reward.</p><p>Two failures compounded the situation as it is described. Production safeguards, meaning system prompts and auto-review models, were &#8220;not applied in the evaluation environment,&#8221; and chain-of-thought monitoring wasn&#8217;t running on these evaluations at all. OpenAI states that:</p><blockquote><p><strong> &#8220;deployed monitoring would have caught the initial relevant activity and paged our security team more than a day before models breached Hugging Face systems,&#8221; </strong></p></blockquote><p>and that production safeguards reduce infrastructure compromise propensity by over 100x. The controls existed, they just weren&#8217;t turned on where the most capable models were being pushed hardest.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EbbW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EbbW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png 424w, https://substackcdn.com/image/fetch/$s_!EbbW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png 848w, https://substackcdn.com/image/fetch/$s_!EbbW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png 1272w, https://substackcdn.com/image/fetch/$s_!EbbW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EbbW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png" width="1456" height="189" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:189,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:81530,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EbbW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png 424w, https://substackcdn.com/image/fetch/$s_!EbbW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png 848w, https://substackcdn.com/image/fetch/$s_!EbbW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png 1272w, https://substackcdn.com/image/fetch/$s_!EbbW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7d3955c-caa2-4d75-930b-46a15beb22ca_1526x198.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>There are also things the report doesn&#8217;t say. Per <strong><a href="https://fortune.com/2026/08/26/openai-publishes-technical-report-on-how-its-agents-hacked-hugging-face-here-are-the-main-takeaways-and-what-openai-left-out/">Fortune&#8217;s read</a></strong>, OpenAI didn&#8217;t publish the prompt given to the agents, message examples, or code snippets, all of which Hugging Face did include in its own July 29 post-mortem. </p><p>Fortune also reports, citing the independent METR and Redwood Research analyses, that 1,200 agents communicated over the message board and 700 participated in the attack, with a lead agent coordinating concealment. OpenAI&#8217;s own characterization, that this was &#8220;misaligned behavior in an outlier scenario involving a rare and unexpected confluence of events,&#8221; reads as perhaps thinner than the timeline alludes to.</p><p>That said, credit where it is due, publishing this level of detail is genuinely valuable to the field, and the commitments are the right ones, including required chain-of-thought monitoring for models at GPT-5.6 Sol capability or above, multi-agent alignment environments that teach models &#8220;to distrust unauthorized instructions,&#8221; training that rewards &#8220;correctly identifying broken tasks, requesting clarification, or stopping safely,&#8221; and 30-minute escalation requirements for severe misalignment alerts. </p><p>That said, every one of those is a control we already know how to describe in enterprise security terms, and none of them were in place at one of the organizations with the most capable models on earth and the most reason to be careful.</p><h3><a href="https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/">VMs won&#8217;t contain cyber-capable agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qS7M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qS7M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png 424w, https://substackcdn.com/image/fetch/$s_!qS7M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png 848w, https://substackcdn.com/image/fetch/$s_!qS7M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png 1272w, https://substackcdn.com/image/fetch/$s_!qS7M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qS7M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png" width="1368" height="314" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de9cba98-d897-41e2-9346-33f879c58472_1368x314.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:314,&quot;width&quot;:1368,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42536,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qS7M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png 424w, https://substackcdn.com/image/fetch/$s_!qS7M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png 848w, https://substackcdn.com/image/fetch/$s_!qS7M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png 1272w, https://substackcdn.com/image/fetch/$s_!qS7M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde9cba98-d897-41e2-9346-33f879c58472_1368x314.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The team at Trail of Bits published the perfect companion piece, and the timing is ironic. They gave GPT 5.6-Cyber the task of escaping a VM sandbox, and it succeeded three separate times with escalating sophistication. </p><ul><li><p>First, it identified a recently disclosed kernel vulnerability, built an exploit, and hardlocked the host. </p></li><li><p>Second, it found that Debian 12 shipped an outdated libslirp (v4.7.0) carrying CVE-2026-9539 and combined it with an unmarked bug fix to get arbitrary read and write into host memory. </p></li><li><p>Third, and this is the one that is most concerning, it chained three previously unknown vulnerabilities across QEMU, Linux KVM, and libslirp, plus one patched flaw nobody had recognized as security relevant, to get controlled execution in the host kernel.</p></li></ul><p>The behavioral description matters as much as the results on this one. The agent &#8220;operated autonomously for hours, backtracked from approaches that didn&#8217;t work, pulled code and research papers,&#8221; and sustained this across 12-hour windows. That is not a model completing a benchmark, that is a researcher with infinite patience.</p><p>The blogs recommendations are practical, meaning minimal virtualization platforms like Firecracker rather than full QEMU, continuous distribution updates instead of stable releases that lag on patching, least privilege applied to network access and credentials, and time-limited operations with pristine resets between runs. </p><p>Put this next to the OpenAI report and the conclusion is uncomfortable, because the sandbox has been among the load-bearing control in every agent security architecture, including plenty in production today.</p><p>This is a topic I&#8217;ve discussed on the Resilient Cyber show in the past with folks such as Luke Hinds and Alex Zenla months ago, before the breakouts got everyone&#8217;s attention.</p><h3><a href="https://decipher.sc/2026/08/20/inside-exploitgym-how-researchers-are-measuring-ai-agent-exploitation-capabilities/">Inside ExploitGym: How Researchers Are Measuring AI Agent Exploitation Capabilities</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Vko!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Vko!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png 424w, https://substackcdn.com/image/fetch/$s_!2Vko!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png 848w, https://substackcdn.com/image/fetch/$s_!2Vko!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png 1272w, https://substackcdn.com/image/fetch/$s_!2Vko!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Vko!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png" width="1162" height="436" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:436,&quot;width&quot;:1162,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:235354,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2Vko!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png 424w, https://substackcdn.com/image/fetch/$s_!2Vko!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png 848w, https://substackcdn.com/image/fetch/$s_!2Vko!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png 1272w, https://substackcdn.com/image/fetch/$s_!2Vko!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0655d65-d78a-49d2-a656-1ecd1b7797dd_1162x436.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Timely context on the benchmark at the center of the OpenAI incident. ExploitGym holds roughly 898 vulnerability instances and measures whether agents can turn known vulnerabilities into working exploits, across userspace memory safety flaws in C and C++, browser engines (Google&#8217;s V8), and Linux kernel exploitation.</p><p>The results show a steep difficulty curve. Claude Mythos Preview and GPT-5.5 led with 157 and 120 successful exploits, but kernel exploitation collapsed that to 12 and 22 successes for the top two models. Agents also sometimes achieved code execution through unintended vulnerabilities rather than the one under test, which is exactly the behavior that generalized into the OpenAI incident. </p><blockquote><p><strong>&#8220;Measuring only whether an exploit succeeds may miss important changes in how that success is achieved.&#8221;</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1I2c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1I2c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png 424w, https://substackcdn.com/image/fetch/$s_!1I2c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png 848w, https://substackcdn.com/image/fetch/$s_!1I2c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png 1272w, https://substackcdn.com/image/fetch/$s_!1I2c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1I2c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png" width="554" height="545.4769230769231" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1152,&quot;width&quot;:1170,&quot;resizeWidth&quot;:554,&quot;bytes&quot;:271793,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1I2c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png 424w, https://substackcdn.com/image/fetch/$s_!1I2c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png 848w, https://substackcdn.com/image/fetch/$s_!1I2c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png 1272w, https://substackcdn.com/image/fetch/$s_!1I2c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F328e216a-473e-4c7f-a318-77ae8d19e188_1170x1152.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://www.darkreading.com/cyberattacks-data-breaches/agentic-ai-new-insider-threat-model">Agentic AI: The New Insider Threat Model</a></h3><p>Katie Moussouris of Luta Security frames autonomous agents as an insider threat problem, which is the right mental model. Her assessment of the Hugging Face incident is direct, that: </p><blockquote><p><strong>&#8220;Clearly, we didn&#8217;t have the real-time monitoring in place, and we don&#8217;t have any breaks that seem to work.&#8221; </strong></p></blockquote><p>She notes the gap between initiation in May 2026 and detection on July 19, roughly two and a half months of undetected activity, and points out that Anthropic&#8217;s latest model &#8220;realized it was on the internet and stopped itself,&#8221; which is the behavior we should be training toward.</p><p>Her broader push is one I strongly agree with, that organizations need to invest in the fundamentals, reduce attack surface, and manage technical debt rather than assuming AI tooling solves problems the organization never solved manually. </p><p>The insider framing is useful because we already have a discipline for this, with behavioral baselines, least privilege, separation of duties, and monitoring for the trusted entity going off-script. We just have to apply it to entities that operate at machine speed and outnumber our employees, which is a new paradigm for us all.</p><h3><a href="https://developer.nvidia.com/blog/where-security-fits-in-an-ai-agent-stack/">Where Security Fits in an AI Agent Stack</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!12Uv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!12Uv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png 424w, https://substackcdn.com/image/fetch/$s_!12Uv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png 848w, https://substackcdn.com/image/fetch/$s_!12Uv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png 1272w, https://substackcdn.com/image/fetch/$s_!12Uv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!12Uv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png" width="1456" height="632" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:632,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:176410,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!12Uv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png 424w, https://substackcdn.com/image/fetch/$s_!12Uv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png 848w, https://substackcdn.com/image/fetch/$s_!12Uv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png 1272w, https://substackcdn.com/image/fetch/$s_!12Uv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F765f7c25-daae-450a-b5c7-b24a26508fb7_1834x796.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>NVIDIA published a genuinely good architectural piece, and the core distinction is one I&#8217;d like to see adopted broadly, that behavioral controls (prompts, model safeguards, harness logic) are different in kind from infrastructure controls (what the runtime actually permits). Their framing is clean, that &#8220;The harness guides what an agent tries. The infrastructure controls what an agent can do.&#8221;</p><p>They lay out five layers, distribution and product, orchestration, agent harness, secure runtime, and inference data plane, with a security boundary drawn between the harness and the runtime so requests cannot route around policy enforcement. The five design rules are the useful part, that higher layers propose and lower layers decide, policy lives below the boundary, every effect is checked, access is just-in-time, and isolation enables recovery. They also define four escalating security profiles, Isolated, Connected, Production, and Adversarial.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e_Nq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e_Nq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png 424w, https://substackcdn.com/image/fetch/$s_!e_Nq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png 848w, https://substackcdn.com/image/fetch/$s_!e_Nq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!e_Nq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e_Nq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png" width="1456" height="1130" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1130,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:647134,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e_Nq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png 424w, https://substackcdn.com/image/fetch/$s_!e_Nq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png 848w, https://substackcdn.com/image/fetch/$s_!e_Nq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!e_Nq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92af40ba-3efb-4dca-a6a8-ff63cc4bbc1a_1610x1250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This maps almost exactly onto the soft guardrails versus hard boundaries argument I&#8217;ve been making for a while now, and the OpenAI incident is the proof case. Every control that failed there was a behavioral control, or a boundary control that simply wasn&#8217;t enabled.</p><h3><a href="https://www.resilientcyber.io/p/secure-vibe-coding-and-the-99">Secure Vibe Coding and the 99%</a></h3><p>In this episode, I sit down with Igor Andriushchenko, Head of Security and CISO at Lovable, to discuss securing AI-native development, including soft guardrails versus hard boundaries, the shared responsibility model for vibe coding platforms, and how GRC engineering fits into a world of AI-powered attackers.</p><p>I had been chasing Igor down on LinkedIn since February, so I was glad to finally get him on the show. Lovable sits in an unusual spot. Igor has to run security for a company that went from roughly 40 people to 400 laptops in MDM inside a year, and at the same time the product he is securing hands software creation to people who are not developers and have never thought about security at all. Those two problems pull in different directions, and the conversation gets into how his team handles both.</p><div id="youtube2-C_5ClqcWevo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;C_5ClqcWevo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/C_5ClqcWevo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://newsletter.semianalysis.com/p/are-open-models-catching-up">Are Open Models Catching Up?</a></h3><p>The best data-driven piece I read this week, and directly relevant to the NVIDIA news above. </p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Dylan Patel&quot;,&quot;id&quot;:21783302,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/adcf9d53-769e-4d9e-8982-30c3dc8488dc_501x527.png&quot;,&quot;uuid&quot;:&quot;8a6c3128-282e-4f49-87e3-6b59461ef24b&quot;}" data-component-name="MentionToDOM"></span> and SemiAnalysis argues the gap between open and frontier models closes in roughly half the time with each successive era.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NYjz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NYjz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png 424w, https://substackcdn.com/image/fetch/$s_!NYjz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png 848w, https://substackcdn.com/image/fetch/$s_!NYjz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png 1272w, https://substackcdn.com/image/fetch/$s_!NYjz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NYjz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png" width="1456" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:466738,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NYjz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png 424w, https://substackcdn.com/image/fetch/$s_!NYjz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png 848w, https://substackcdn.com/image/fetch/$s_!NYjz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png 1272w, https://substackcdn.com/image/fetch/$s_!NYjz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f70e1de-219a-491b-b558-0d65cf6c251b_2108x1158.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The authors are appropriately careful, noting that &#8220;benchmarks are not the end all be all&#8221; and warning about hill climbing on public evals. For security purposes, though, the direction is what matters. </p><p>If open-weight models reach frontier agentic capability within four to six months of release, then every capability demonstrated in the OpenAI report and the Trail of Bits research becomes available to anyone with a GPU and no safety stack on top of it, on a predictable clock. That is the assumption Igor&#8217;s conversation above mentions, and the evidence supports it.</p><h3><a href="https://joshuasaxe181906.substack.com/p/where-are-all-the-prompt-injection">Where are all the prompt injection attacks?</a></h3><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd3c6819-d1ef-4f1f-a257-116c0c97172d_1138x1138.png&quot;,&quot;uuid&quot;:&quot;359eeb5c-0962-4f68-9247-1909dbf27074&quot;}" data-component-name="MentionToDOM"></span> asks the question our industry avoids, which is why documented real-world damages from prompt injection remain tiny relative to the hundreds of billions lost to cybercrime annually. </p><p>He offers three explanations: </p><ul><li><p>Opportunity cost (attackers still get in through known vulnerabilities, weak credentials, and misconfigurations, which is cheaper than building novel exploit workflows) </p></li><li><p>Organizational inertia (established criminal enterprises have profitable, proven playbooks and poor ROI on retraining)</p></li><li><p>Attribution gaps (detection tooling for LLM-mediated breaches is immature enough that successful injections may be getting attributed to whatever system got touched next).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z_iG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z_iG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png 424w, https://substackcdn.com/image/fetch/$s_!z_iG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png 848w, https://substackcdn.com/image/fetch/$s_!z_iG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png 1272w, https://substackcdn.com/image/fetch/$s_!z_iG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z_iG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png" width="1456" height="869" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:869,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:857107,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z_iG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png 424w, https://substackcdn.com/image/fetch/$s_!z_iG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png 848w, https://substackcdn.com/image/fetch/$s_!z_iG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png 1272w, https://substackcdn.com/image/fetch/$s_!z_iG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feefc0dc0-a1ce-4f22-bd7e-87005616f8d0_2000x1194.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>He isn&#8217;t dismissing the risk, and he still recommends securing agents with something like Meta&#8217;s rule of two, restricting sensitive actions on untrusted data. </p><p>His point is about resource allocation, that overweighting AI-native risk because it dominates conference talks means underfunding the tech debt that is actually getting organizations breached. Josh has been on the Resilient Cyber show and consistently brings evidence rather than vibes, and this is a good example of it.</p><h1>AppSec</h1><h3><a href="https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review">Staying Ahead of Adversarial AI Through Agentic Source Code Review</a></h3><p>Google Cloud and Mandiant detailed their Agentic Vulnerability Discovery Harness, a waterfall pipeline of specialized agents running threat modeling, entry point discovery, context enrichment, hypothesis generation, and hypothesis validation, with human expert gates at both ends. </p><p>Distinct agents handle access control analysis and data flow analysis, Gemini Flash Lite handles parallelized entry point discovery at scale, and high-temperature validation agents feed a synthesis agent that marks findings Confirmed, Disproven, or Rejected. Mandiant expertise is injected through a three-tier rules hierarchy covering domain, framework and language, and vulnerability specifics.</p><p>The results are the reason to read it, with 12 CVEs assigned so far, another dozen in active disclosure, tens of millions of lines of code analyzed, and over 100 critical vulnerabilities discovered in two days during an incident response engagement.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EoJe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EoJe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png 424w, https://substackcdn.com/image/fetch/$s_!EoJe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png 848w, https://substackcdn.com/image/fetch/$s_!EoJe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png 1272w, https://substackcdn.com/image/fetch/$s_!EoJe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EoJe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png" width="1456" height="499" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd51d946-815a-4044-930f-66a3a770752c_1726x592.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:499,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:315928,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212705591?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EoJe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png 424w, https://substackcdn.com/image/fetch/$s_!EoJe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png 848w, https://substackcdn.com/image/fetch/$s_!EoJe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png 1272w, https://substackcdn.com/image/fetch/$s_!EoJe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd51d946-815a-4044-930f-66a3a770752c_1726x592.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The harness is the story here, not the model, which is a trend we continue to see. This is the same lesson from the NVIDIA piece above and from OpenAI&#8217;s report, that capability comes from orchestration, scoping, and validation rather than from prompting a frontier model harder. </p><p>It is also worth noting that Google is careful to keep human validation in the loop at the exploitation stage, which is the difference between a finding and a fix.</p><h3><a href="https://anil.recoil.org/notes/rumour-is-the-exploit">Just a rumour of a bug is enough to find a security exploit these days</a></h3><p>Anil Madhavapeddy, the OCaml maintainer and Cambridge researcher, wrote a super interesting piece. He opened a public pull request fixing a path traversal bug in cohttp and saw probes matching that vulnerability pattern within 10 minutes. He then demonstrated that building a working exploit from the PR alone took roughly one minute with available models. His point is that embargo, the entire premise of coordinated disclosure, assumes attackers need time that they no longer need.</p><p>He cites 2026 research showing the bottleneck has moved to &#8220;defender remediation throughput,&#8221; and points to CVE-2026-39987 exploited in 9 hours and CVE-2026-33017 in 20 hours with no public proof of concept in either case. His proposals are worth engaging with, including private development infrastructure with web-of-trust authentication, continuous shipping on Chrome-style cadences, and protocol-layer virtual patching through distributed rule networks ahead of upstream fixes.</p><p>For open source maintainers, this is a serious problem with no good answer yet, something I&#8217;ve discussed on the show with industry veteran Casey Ellis of Bugcrowd. The security fix commit is now an exploit specification, and most maintainers have no ability to ship a coordinated release across an ecosystem before that specification is public. </p><p>Anyone working on OSS security funding and infrastructure should be reading this one closely.</p><h1><a href="https://research.shoebpatel.com/how-to-hack-ai-agents">How to Hack AI Agents</a></h1><p>Shoeb Patel put together an excellent practitioner&#8217;s mental model for finding vulnerabilities in agentic systems, and it is the resource for AppSec engineers being asked to test their first agent. </p><p>He frames the core problem:</p><blockquote><p><strong>&#8220;the model is trained to trust the system prompt more than the user, and the user more than tool results. But this boundary is soft.&#8221; </strong></p></blockquote><p>This aligns with the soft guardrails vs. hard boundaries framing I&#8217;ve been writing and speaking about for a while now. From there he separates direct injection through user-controlled inputs from indirect injection hidden in web pages, emails, plugin descriptions, repositories, documents, and logs, then walks the impact vectors of data exfiltration, privileged actions taken under the agent&#8217;s or victim&#8217;s identity, and persistence through injections stored in memory and configuration.</p><p>The writeup references more than 15 documented attacks including CamoLeak, EchoLeak, and Invitation Is All You Need, and points to practice environments like Gandalf and HackAPrompt plus Microsoft&#8217;s PyRIT for red teaming. </p><p>Note how well it pairs with Saxe&#8217;s piece above, because the techniques are all real and demonstrated while the in-the-wild exploitation data remains thin, perhaps due to the factors Josh mentioned such as attribution, widely available low hanging fruit etc.</p><h1>Final Thoughts</h1><p>The week&#8217;s two headline stories are the same story told twice. OpenAI&#8217;s report shows agents chaining novel vulnerabilities to escape an evaluation sandbox, and Trail of Bits shows a commercially available model doing the same thing to a VM three different ways. </p><p>Meanwhile, the registry those models are published to and pulled from is about to change hands for $13 billion, and SemiAnalysis has the data showing open-weight models reach that capability level four to six months behind the frontier and closing.</p><p>If those things are all true at once, the security architecture most organizations are building around agents right now rests on a control that doesn&#8217;t hold, against capabilities that will be freely downloadable inside of a year. </p><p>The good news, such as it is, is that nobody is proposing exotic solutions. NVIDIA&#8217;s boundary model, Igor&#8217;s six pillars, Moussouris&#8217;s insider threat framing, and OpenAI&#8217;s own list of commitments all describe controls we already know how to build. </p><p>We just have to actually build them, everywhere, and turn them on in the environments where we are pushing the hardest, which is precisely where they weren&#8217;t.</p><p><strong>Stay resilient.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Secure Vibe Coding and the 99%]]></title><description><![CDATA[Lovable's CISO on soft guardrails, shared responsibility on an AI development platform, and what GRC engineering looks like when the attackers are AI-powered too.]]></description><link>https://www.resilientcyber.io/p/secure-vibe-coding-and-the-99</link><guid isPermaLink="false">https://www.resilientcyber.io/p/secure-vibe-coding-and-the-99</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 25 Aug 2026 12:01:50 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/212558682/c1543240437c0c11491b2b7ea14bb917.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode, I sit down with Igor Andriushchenko, Head of Security and CISO at Lovable, to discuss securing AI-native development, including soft guardrails versus hard boundaries, the shared responsibility model for vibe coding platforms, and how GRC engineering fits into a world of AI-powered attackers.</p><p>I had been chasing Igor down on LinkedIn since February, so I was glad to finally get him on the show. Lovable sits in an unusual spot. Igor has to run security for a company that went from roughly 40 people to 400 laptops in MDM inside a year, and at the same time the product he is securing hands software creation to people who are not developers and have never thought about security at all. Those two problems pull in different directions, and the conversation gets into how his team handles both.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p>We chatted about:</p><ul><li><p>Building a security program for a 15x company when you already know you are going to be 10x, and what breaks along the way</p></li><li><p>Soft guardrails versus hard guardrails, why hard blocks get routed around by AI-assisted workflows, and how to tell which problems deserve which</p></li><li><p>Anchoring guardrail decisions in business goals, risks, and threats instead of tool defaults</p></li><li><p>The gap between democratized development and democratized security, and what a platform owes the 99 percent</p></li><li><p>Lovable&#8217;s auto-fix toggle, the per-app threat model built behind the scenes, and the goal of shipping an app with no security tab at all</p></li><li><p>Whether frontier models will ever produce secure code by default, and why defense in depth still does most of the work</p></li><li><p>Governing the reality that every employee vibe coding an app starts to look like a new vendor</p></li><li><p>GRC engineering as the discipline for measuring control efficiency layer by layer</p></li><li><p>CRA, NIS2, and the EU AI Act landing on citizen developers who never considered themselves software manufacturers</p></li></ul><div id="youtube2-C_5ClqcWevo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;C_5ClqcWevo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/C_5ClqcWevo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2><strong>Prefer to listen? </strong></h2><p><strong><a href="https://open.spotify.com/episode/2CpnOH4h1emkIKxcBOyLp4?si=3apN0QEDQWWJscUwnYJQ5A">Spotify</a></strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/secure-vibe-coding-and-the-99/id1555928024?i=1000785562841">Apple Podcasts</a></strong></p><p><strong>Please be sure to leave a rating and review, as it truly helps the show!</strong></p><div><hr></div><h2>Takeaways</h2><h3>Build the security program for the company you are about to be</h3><p>Igor joined Lovable as the first security hire when it was around 40 people. Today his team is 20 plus and covers product security, GRC, IT, and platform safety, and the company is managing about 400 laptops in MDM. He described the security team itself as growing roughly 25x in that stretch, from one person to around 25 with offers out.</p><p>What I found useful was how he framed the planning problem. He and the team could see the revenue numbers before anyone else could, which meant they could see the trajectory. &#8220;As a CISO you just need to build your security program to cater for probably 15x company. If you expect to be 10x, if you add extra on top for extra resilience, then you&#8217;ll be fine.&#8221; He also made the point that the threat model changes as you scale, because a 40 person company and a company on the front page of every tech publication do not attract the same adversaries. That is a very different exercise than budgeting off last year&#8217;s headcount, and it is one most security leaders in high growth environments should be doing more deliberately.</p><h3>Soft guardrails are coming for most of your controls, but not all of them</h3><p>Igor&#8217;s argument is that deterministic controls were an artifact of a deterministic world. Static analysis was called static for a reason. Rules matched or they did not. What AI enables is a control that can look at intent, at a person&#8217;s role, at what they are actually trying to accomplish, and make a judgment. He compared it to onboarding an intern and sitting next to them, which is a much better analogy for adaptive policy than anything I have heard from a vendor.</p><p>He is not arguing hard blocks go away. He explicitly wants some. &#8220;We take human creativity and we multiply it by agent creativity,&#8221; and sometimes the result is an agent with no judgment about what it should never do. His example of a genuine hard boundary is an agent never escaping a sandbox, or never being handed a powerful admin-level CLI with developer credentials. The part that matters for practitioners is that he derives those hard boundaries from business risk rather than from a tool&#8217;s default policy set. If your risk model is done deeply enough, the things that should never happen are already written down somewhere.</p><h3>The platform owes the 99 percent more than a fix button</h3><p>This was the thread I came in most curious about. Lovable&#8217;s stated goal is empowering the 99 percent to build, and I have made the argument for a while that we democratized development without democratizing security. Igor&#8217;s answer is that they tried the obvious thing first and it did not work. They surfaced security bugs in a project with a button to have AI fix it, and very few people clicked it. Their research found two reasons. People were scared of breaking something that already worked, and security felt complicated and unfamiliar.</p><p>So they pushed the responsibility further onto the platform. In June they shipped an auto-fix toggle in settings, and behind the scenes every application gets scanned and a security model built for it, which is functionally a threat model. The direction he described is a platform that fixes the obvious issues silently and reserves the human interaction for questions only the builder can answer, like whether a given table should be private or public. &#8220;Ideally, there should be no security tab whatsoever in the app.&#8221; That is secure by design applied to an audience that will never read a secure coding guide, and it is only possible because Lovable owns the whole loop from generation to deployment to runtime. Most vendors cannot make that claim, which is exactly why platform providers have systemic leverage that individual security teams do not.</p><h3>Good enough changed, and that is what makes GRC engineering interesting</h3><p>Igor&#8217;s take on AI-powered attackers is the part of this conversation I keep thinking about. Defense in depth historically worked on a good enough standard. You layered controls, accepted that each layer had gaps, and trusted that the aggregate would slow an attacker down long enough to detect and eject them. His argument is that standard no longer holds when someone with no offensive security background can point a capable model at a target and let it work. As he put it, that is &#8220;hacking at the cost of electricity.&#8221; A relentless attacker will find the gap in layer one, then the gap in layer two, and it will do it fast.</p><p>His conclusion is that each layer now needs measured, near-complete coverage rather than good enough coverage. If you have MFA and EDR, they need to be everywhere, not on most employees and not on that one contractor group. And measuring control efficiency layer by layer is a GRC problem, because GRC already holds the risks, the vendors, the controls, and the mapping between them. Build the eval, or the KPI if you prefer the old word, get coverage from 80 to 85 to 90, and keep going. I have spent years pushing back on the compliance does not equal security line, and this is a good articulation of why. Used this way, GRC is how you prove your controls actually work in near real time rather than how you generate a report.</p><h3>Regulation is coming for people who do not know they are software manufacturers</h3><p>The last thread was one I did not expect to get a fully formed answer on. When a citizen developer ships an app that touches PII or PHI, they have produced software and put it into the world, even though nobody would call them a vendor. Igor&#8217;s view is that the platform&#8217;s job is to make the obligations visible early, before someone publishes. Lovable already draws some hard lines, and he mentioned taking down apps in regulated spaces where they needed to see evidence of a license first. The vision he laid out goes further, with the platform telling a builder up front what publishing will require of them, and pointing them at where to go get it.</p><p>He also mentioned a recently released opt-in trust center for apps built on the platform, which generates a compliance posture page automatically from the app and its data. That is GRC engineering aimed at customer apps rather than at the platform&#8217;s own audit, and it is a genuinely interesting model for reducing regulatory overhead on people who never signed up to carry it. As Igor put it, the shared responsibility does not sit only with the platform. The moment a builder starts putting real people&#8217;s data into what they built, things change quickly for what they need to comply with.</p><p>Igor closed with something worth repeating for anyone in this space. If one vibe coding platform fails badly, every other platform gets the same questions the next morning. The whole category is judged together, which is a decent argument for building the security bar high early rather than after the first bad headline.</p><p>You can follow Igor on LinkedIn at <a href="https://www.linkedin.com/in/igor-andriushchenko">https://www.linkedin.com/in/igor-andriushchenko</a> and find Lovable at https://lovable.dev</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[It Was Never the Model]]></title><description><![CDATA[A look at OWASP's 2026 LLM Top 10, and why the harness around the model is where practitioners should be spending their attention]]></description><link>https://www.resilientcyber.io/p/it-was-never-the-model</link><guid isPermaLink="false">https://www.resilientcyber.io/p/it-was-never-the-model</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 24 Aug 2026 12:03:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FSYI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Most of us in cybersecurity who have been focusing on AI security over the last couple of years have argued about models. This includes which model, which vendor, which benchmark to use, whether open-weight models have closed the gap on the frontier or not and whether any of the models can be trusted with organizational data or in production systems and workflows. </p><p>That said, OWASP&#8217;s latest 2026 Top 10 for LLM Applications recently dropped and the letter in the beginning of the publication from my friends and Project Leads Steve Wilson and Rock Lambros open up by telling the ready those arguments are basically missing the point. The below quote from the publication is something I want to cite:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_2J8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_2J8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png 424w, https://substackcdn.com/image/fetch/$s_!_2J8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png 848w, https://substackcdn.com/image/fetch/$s_!_2J8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png 1272w, https://substackcdn.com/image/fetch/$s_!_2J8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_2J8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png" width="749" height="164" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:164,&quot;width&quot;:749,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72573,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_2J8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png 424w, https://substackcdn.com/image/fetch/$s_!_2J8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png 848w, https://substackcdn.com/image/fetch/$s_!_2J8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png 1272w, https://substackcdn.com/image/fetch/$s_!_2J8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0b53043-8944-4edb-a05a-c7fea9aa93ac_749x164.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>That&#8217;s the entire thesis of the latest OWASP Top 10 summarized in the opening letter of the document and once you take that in, the remainder of the new document reads like a guide for practitioners in how to think about securing agentic AI and LLM deployments and the importance of the harness when it comes to being a security and trust boundary.</p><p>I&#8217;ve been making a version of this argument for several months and I discussed it in my prior article &#8220;<strong><a href="https://www.resilientcyber.io/p/learning-from-the-frontier">Learning From the Frontier</a></strong>&#8221;, where I worked through AISI&#8217;s agent incident report, where the danger doesn&#8217;t live in the model weights but lives in the harness around the model, including Internet access and the ability to have autonomy, access tools and take actions. I also published a video on the incident.</p><div id="youtube2-HrD06vG5wXs" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;HrD06vG5wXs&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/HrD06vG5wXs?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>In this article I want to walk through what the latest version of the LLM Top 10 changed, and some of the key takeaways for practitioners thinking about securing Agentic AI deployments in production environments. </p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>Testing the Vote Against the Record</h2><p>One of the aspects I thought was cool from the latest OWASP LLM Top 10 was that they used a methodology where they took the vote of practitioners, which they had done previously to determine the ranking, but they also leveraged real-world incident data to see how rankings contrasted against what practitioners voted on. </p><p>This included 7,714 real incidents from public vulnerability and AI harm databases, which in and of itself speaks to how commonplace incidents involving LLMs and agents is becoming, which was something the team also did with the OWASP State of Agentic AI Security &amp; Governance Report, which I previously covered as well. </p><p>As they did the analysis comparing practitioners fears and rankings compared to the incident data they started to find some surprising differences. Most practitioners minds jump right to things such as Prompt Injection, ranking it the #1 risk but when it came to incident record data, OWASP said Prompt Injection would have fallen out of the Top 10 entirely. </p><p>However, they say it isn&#8217;t become prompt injection isn&#8217;t a relevant issue, but instead they call it a defense effect, arguing organizations have made efforts to mitigate injection, so fewer clean exploits that are directly attributable to prompt injection land in the public databases and incident counts.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YLD3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YLD3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png 424w, https://substackcdn.com/image/fetch/$s_!YLD3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png 848w, https://substackcdn.com/image/fetch/$s_!YLD3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png 1272w, https://substackcdn.com/image/fetch/$s_!YLD3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YLD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png" width="666" height="584.1578354002255" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:778,&quot;width&quot;:887,&quot;resizeWidth&quot;:666,&quot;bytes&quot;:307362,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YLD3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png 424w, https://substackcdn.com/image/fetch/$s_!YLD3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png 848w, https://substackcdn.com/image/fetch/$s_!YLD3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png 1272w, https://substackcdn.com/image/fetch/$s_!YLD3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5921cce3-63f4-4317-8002-6a84b764ddd4_887x778.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p> <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;25014a72-bfd3-47f9-a1f2-f162a0ec3bff&quot;}" data-component-name="MentionToDOM"></span> who previously helped lead AI security and safety efforts at Meta made a different argument recently in a piece of his, titled &#8220;<strong><a href="https://joshuasaxe181906.substack.com/p/where-are-all-the-prompt-injection">Where Are All The Prompt Injection Damages</a></strong>&#8221;, where he argued universal prompt injection is becoming less common with the latest leading models, due to improved defenses but also the fact attackers already have ample techniques that bear fruit. Below you can see him highlighting the lack of financial damages tied to prompt injection as a technique to compared to other attack technqiues.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IWon!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IWon!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png 424w, https://substackcdn.com/image/fetch/$s_!IWon!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png 848w, https://substackcdn.com/image/fetch/$s_!IWon!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png 1272w, https://substackcdn.com/image/fetch/$s_!IWon!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IWon!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png" width="1130" height="676" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:676,&quot;width&quot;:1130,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:286307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IWon!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png 424w, https://substackcdn.com/image/fetch/$s_!IWon!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png 848w, https://substackcdn.com/image/fetch/$s_!IWon!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png 1272w, https://substackcdn.com/image/fetch/$s_!IWon!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e0fb7c3-1a9b-415c-9ae8-0ba9e40e7f23_1130x676.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is a point echoed by Anthropic&#8217;s Boris Cherny recently in an interview with YC, where he argued "<strong>Anthropic&#8217;s Opus 5 model does not seem to be prompt injection anymore</strong>&#8221;, he goes on to discuss that when you combine a well aligned model with a prompt injection classifier for all traffic, coupled with an auto-mode classifier, it is very hard to demonstrate prompt injection. I have set the video below to begin at the 2:10 minute mark, which is where Boris discusses this:</p><div id="youtube2-qyPCVqFUyDo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;qyPCVqFUyDo&quot;,&quot;startTime&quot;:&quot;130&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/qyPCVqFUyDo?start=130&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>That said, despite the lack of real-world financial damages, progress at the frontier labs, or real-world incident data as pointed out by OWASP themselves, prompt injection still holds the top spot on the LLM Top 10 due to the community vote carrying 75% of the vote. </p><p>This is something for organizations leveraging the Top 10 to keep in mind when it comes to allocating their time and resources, and ensuring it is tied to real-world impacts, not just popularity rankings. </p><p>There is also a third explanation for the ranking I want to throw out there, which is that injection rarely produces a cleanly attribute public record tied to incident because the impacts often surface downstream. This includes impacts such as stolen credentials, exfiltrated data or source code, poisoned build processes and so on, and gets counted as those, rather than prompt injection. </p><p>This actually can be visualized by leveraging a image from OWASP themselves in the LLM Top 10 doc. Below you can see prompt injection is an entry vector <em>not</em> an impact:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FSYI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FSYI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png 424w, https://substackcdn.com/image/fetch/$s_!FSYI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png 848w, https://substackcdn.com/image/fetch/$s_!FSYI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png 1272w, https://substackcdn.com/image/fetch/$s_!FSYI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FSYI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png" width="574" height="554.1542553191489" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:726,&quot;width&quot;:752,&quot;resizeWidth&quot;:574,&quot;bytes&quot;:247526,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FSYI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png 424w, https://substackcdn.com/image/fetch/$s_!FSYI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png 848w, https://substackcdn.com/image/fetch/$s_!FSYI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png 1272w, https://substackcdn.com/image/fetch/$s_!FSYI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3039dde-e242-4ec6-968a-a6d63aae73cf_752x726.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Viewing the OWASP LLM Top 10 As a Harness Document</h2><p>Now that I&#8217;ve wrapped up my side rant about prompt injection, attribution, entry vectors and whether or not is solved by the frontier labs and how, we can start to look at the OWASP LLM Top 10 from the perspective of the harness, which is where the risks really lie. </p><p>As an aside, my teammate Diana Kelly from Noma recently had an <strong><a href="https://podcasts.apple.com/us/podcast/cloud-security-today/id1557790941?i=1000784629403">excellent interview</a></strong> on the podcast Cloud Security Today, where she discusses the AI Harness in-depth.</p><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8acdcad3a71a1562e70b88dce9&quot;,&quot;title&quot;:&quot;The AI harness&quot;,&quot;subtitle&quot;:&quot;Matthew Chiodi&quot;,&quot;description&quot;:&quot;Episode&quot;,&quot;url&quot;:&quot;https://open.spotify.com/episode/7iT2SMMygG5dSf2jtSpZHH&quot;,&quot;belowTheFold&quot;:true,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/episode/7iT2SMMygG5dSf2jtSpZHH" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" loading="lazy" data-component-name="Spotify2ToDOM"></iframe><p>As I showed in the image above, Excessive Agency jumped from #6 to #3 on the latest OWASP LLM Top 10 and OWASP called it the most significant move on the risk and it is directly tied to organizations ramping up agentic deployments and this being where the damage is landing. Other risks such as Unbounded Consumption and Improper Output Handling moved around the lost and others such as System Prompt Leakage became Hidden Context Exposure, speaking the importance of the context window. </p><p>All of these moves are properties of the software we build rather than the weights. For example, excessive agency is tools, permissions and autonomy. Unbounded consumption is rate limiting, quotas, and circuit breakers. Hidden Context Exposure is what your app loads into the context windows and you shouldn&#8217;t assume always stays private and none of these issues get fixed by swapping model vendors. </p><p><strong>LLM01 - Prompt Injection</strong> makes the architectural version explicit cleanly summarizing why you can&#8217;t necessarily train away prompt injection, noting that:</p><blockquote><p><strong>&#8220;LLM&#8217;s make no architectural distinction between instructions and data (both are tokens on the same stream), so there is no clean equivalent to parameterized queries&#8221;.</strong></p></blockquote><p>This why when you listened to Boris above he mentioned the role of classifiers in addition to model alignment to try and mitigate albeit not entirely eliminate prompt injection. </p><p><strong>LLM08 - Hidden Context Exposure</strong> goes further in the publication, telling practitioners to design on the assumption that t he hidden context is discoverable and that nothing in the context window should be treated as a secret. When we consider everything that goes into the context window, from our personal chats with the LLM, sensitive data, and so on, its easy to see why this reality is scary from both a security and privacy perspective. </p><p>Their mitigation guidance takes it further, stating that &#8220;critical controls such as privilege separation, authorization bound checks, and similar must not be delegated to the LLM&#8221;, whether through the system prompt or other mechanisms. I&#8217;ve been arguing that system prompts are not security controls, so it is useful to have an industry authority such as OWASP enforcing that point.</p><p>OWASP also plainly states the the distinction between the LLM Top 10 and the Agentic AI Top 10:</p><blockquote><p><strong>"One boundary matters more every year. This list owns the risk when the model is a component inside your application. The moment that model becomes an actor, with tools it can call, memory it carries between sessions, and consequences it sets in motion downstream, the risk moves to the OWASP Agentic Top 10."</strong></p></blockquote><p>That is OWASP directly stating that once the risk now long is directly tied to the model, it belongs to the Agentic AI Top 10 instead. I&#8217;ve served on the Distinguished Review Board for the OWASP Top 10 for Agentic Applications, so it was good to see the authors help clear up the delineation between the two, as many are becoming overwhelmed with the number of Top 10&#8217;s out there, with the latest example being the OWASP Agentic Skills Top 10, which I covered in a recent article titled &#8220;<strong><a href="https://www.resilientcyber.io/p/dangerous-skills">Dangerous Skills</a></strong>&#8221;. </p><h2>So What Is a Harness? </h2><p>So we&#8217;ve talked a ton about OWASP lists and specific risks such as prompt injection, and the industry has been talking about the importance of a &#8220;Harness&#8221; a lot lately, but what the hell is a harness exactly?</p><p>Databricks has had one of the easiest to understand explanations on this in a blog titled &#8220;<strong><a href="https://www.databricks.com/blog/ai-harness">What is an AI Agent Harness</a></strong>&#8221;. In it they state:</p><blockquote><p>&#8220;<strong><span>An AI agent harness is the software infrastructure that wraps around a </span><a href="https://www.databricks.com/blog/what-are-large-language-models">large language model</a><span> (LLM) and enables it to act on tasks, not just respond to prompts. The model reasons through a problem and decides what to do next. The harness connects it to the tools, systems, memory and execution environments needed to carry out those actions.&#8221;</span></strong></p></blockquote><p>The components they mentioned above align with the OWASP LLM Top 10 fairly one, with things such as system prompts and context assembly aligning with LLM08, tools, permissions and autonomy with LLM03, memory and retrieval on LLM01 and LLM09, tool and model provenance on LLM04, output parsing on LLM10, and quotas and circuit breakers on LLM06. </p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Addy Osmani&quot;,&quot;id&quot;:11623675,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef4ea1b5-28cc-4a4f-ba1e-23d91db6570d_1190x1190.png&quot;,&quot;uuid&quot;:&quot;d1ec4e61-f3ee-46f6-9fc8-2fd1c810dd48&quot;}" data-component-name="MentionToDOM"></span>, who I follow, as do many others, had a great O&#8217;Reilly article on agent harness engineering and he argued that a decent model with a great harness beats a great model with a bad harness. Below is a useful visualization from that piece:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rfAd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rfAd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png 424w, https://substackcdn.com/image/fetch/$s_!rfAd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png 848w, https://substackcdn.com/image/fetch/$s_!rfAd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png 1272w, https://substackcdn.com/image/fetch/$s_!rfAd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rfAd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png" width="788" height="441" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:441,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:396777,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rfAd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png 424w, https://substackcdn.com/image/fetch/$s_!rfAd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png 848w, https://substackcdn.com/image/fetch/$s_!rfAd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png 1272w, https://substackcdn.com/image/fetch/$s_!rfAd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98d01ece-b0fd-4734-81aa-9aece67abfb5_788x441.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Dan McAteer&quot;,&quot;id&quot;:121175777,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8f6e7a6-a5a0-4a6e-bd99-9359eaca4e4c_400x400.jpeg&quot;,&quot;uuid&quot;:&quot;fc475ad8-fb3f-4563-907e-9d100d58c62c&quot;}" data-component-name="MentionToDOM"></span> also recently had an excellent blog on <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Latent.Space&quot;,&quot;id&quot;:89230629,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db0f8d45-1eb8-4c02-a120-650d377ee52d_640x640.jpeg&quot;,&quot;uuid&quot;:&quot;9b32b3bb-2bfa-40df-ae62-3a08b2a2fd70&quot;}" data-component-name="MentionToDOM"></span> diving into the evolution of the agent harness. He described the harness as &#8220;everything besides the model weights that makes the agent work&#8221; and &#8220;the harness is like giving the mind of the model a body&#8221;. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TYGT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TYGT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png 424w, https://substackcdn.com/image/fetch/$s_!TYGT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png 848w, https://substackcdn.com/image/fetch/$s_!TYGT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png 1272w, https://substackcdn.com/image/fetch/$s_!TYGT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TYGT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png" width="578" height="496.79338842975204" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:624,&quot;width&quot;:726,&quot;resizeWidth&quot;:578,&quot;bytes&quot;:246041,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TYGT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png 424w, https://substackcdn.com/image/fetch/$s_!TYGT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png 848w, https://substackcdn.com/image/fetch/$s_!TYGT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png 1272w, https://substackcdn.com/image/fetch/$s_!TYGT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4caa77f6-79fd-46d3-8284-28e00d3dd443_726x624.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is a point made within security too, such as by teams such as AISLE, who argued the &#8220;<strong><a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">most is the system, not the model&#8221;</a> </strong>when it comes to using AI to find vulnerabilities. </p><h2>Where the Capability Actually Went</h2><p>This part of the blog discusses my changing thoughts on model selection and the conversations I&#8217;ve had on the podcast that played a part. </p><p>For example, I previously had <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Niels Provos&quot;,&quot;id&quot;:34464160,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6ffba3d-90db-4f6c-a117-18a247a91554_2048x2048.jpeg&quot;,&quot;uuid&quot;:&quot;724e7511-ed35-4aba-9238-6297b33cfeec&quot;}" data-component-name="MentionToDOM"></span> on the show and he argued that you don&#8217;t need a frontier model to find zero days, and that vulnerability discovery is an orchestration problem rather than model problem. Neils discussed finite state machines that decompose vulnerability finding into stages, each with a fresh context and a tight prompt, getting reliable results from weaker models that would otherwise fall short. </p><div id="youtube2-gRgDsdm4RQo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;gRgDsdm4RQo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/gRgDsdm4RQo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>I also chatted with <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Stanislav Fort&quot;,&quot;id&quot;:6503858,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/920622a8-11bd-4a16-a695-33775e0b72ea_1600x1338.jpeg&quot;,&quot;uuid&quot;:&quot;b2bf0c79-5919-417b-bd40-d3090fe605b5&quot;}" data-component-name="MentionToDOM"></span> of AISLE, who showed how their research team has small open models that are finding real vulnerabilities even in heavily audited code bases at roughly $.11 cents per million tokens. </p><div id="youtube2-J5xqeOSqs3s" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;J5xqeOSqs3s&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/J5xqeOSqs3s?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The UK&#8217;s AI Security Institute <strong><a href="https://www.aisi.gov.uk/frontier-ai-trends-report">published research</a></strong> in December 2025 that supports the importance of the harness as well. They found on software engineering tasks, agents with the best externally developed scaffolds reliably outperform the best base models.  This shows the harness is key both for software engineering activities, as well as security ones, as Niels and Stanislav discussed above.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QAst!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QAst!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png 424w, https://substackcdn.com/image/fetch/$s_!QAst!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png 848w, https://substackcdn.com/image/fetch/$s_!QAst!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png 1272w, https://substackcdn.com/image/fetch/$s_!QAst!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QAst!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png" width="580" height="420.4337899543379" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:635,&quot;width&quot;:876,&quot;resizeWidth&quot;:580,&quot;bytes&quot;:80802,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QAst!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png 424w, https://substackcdn.com/image/fetch/$s_!QAst!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png 848w, https://substackcdn.com/image/fetch/$s_!QAst!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png 1272w, https://substackcdn.com/image/fetch/$s_!QAst!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2fbc8d6-cf2a-433b-b9f3-7337cd9ea214_876x635.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Fusion, Routing and the End of the Single Model Enterprise</h2><p>Another trend unfolding for technical and economic reasons of the rise of organizations embracing many models, including a mix of frontier and open source. I&#8217;ve been watching this one heat up since earlier this year when Mythos 5 got banned/blocked, and GPT-5.6 got gated. </p><p>That coupled with the blowback from tokenmaxxing and the open source ecosystem closing the gap has led to many openly embracing open weight models, or a mix of models based on the task, rather than using the best tool for every job, regardless of how basic it is. </p><p>The harness is also absorbing the act of model selection. OpenRouter published results in June from their system they call &#8220;<strong><a href="https://openrouter.ai/blog/announcements/fusion-beats-frontier/">Fusion</a></strong>&#8221;, which routed prompts to a panel of models in parallel and had a judge model synthesize the answer. This sort of innovation is part of the story in why Stripe is <strong><a href="https://stripe.com/newsroom/news/stripe-agrees-to-acquire-openrouter">buying</a></strong> OpenRouter for $7.5B.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MlnS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MlnS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png 424w, https://substackcdn.com/image/fetch/$s_!MlnS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png 848w, https://substackcdn.com/image/fetch/$s_!MlnS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png 1272w, https://substackcdn.com/image/fetch/$s_!MlnS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MlnS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png" width="613" height="409.54363376251786" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:467,&quot;width&quot;:699,&quot;resizeWidth&quot;:613,&quot;bytes&quot;:73255,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MlnS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png 424w, https://substackcdn.com/image/fetch/$s_!MlnS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png 848w, https://substackcdn.com/image/fetch/$s_!MlnS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png 1272w, https://substackcdn.com/image/fetch/$s_!MlnS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18807be3-0592-47eb-9a11-3d9da3163ab4_699x467.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Others such as <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;a16z&quot;,&quot;id&quot;:2315700,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-aGV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff698a0c5-1fee-40a7-a33c-80609431ae31_400x400.png&quot;,&quot;uuid&quot;:&quot;b44ec760-c2af-4aa9-bf9f-b3316e2758c7&quot;}" data-component-name="MentionToDOM"></span> have reported <strong><a href="https://a16z.com/ai-enterprise-2025/">survey results</a></strong> showing nearly half of CIO&#8217;s report using 5 or more models, which is up from 29% the year prior. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y-oj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y-oj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png 424w, https://substackcdn.com/image/fetch/$s_!y-oj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png 848w, https://substackcdn.com/image/fetch/$s_!y-oj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png 1272w, https://substackcdn.com/image/fetch/$s_!y-oj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y-oj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png" width="465" height="275.87394957983196" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cef516dc-d076-41dd-9cff-648a4c96261f_595x353.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:353,&quot;width&quot;:595,&quot;resizeWidth&quot;:465,&quot;bytes&quot;:56306,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y-oj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png 424w, https://substackcdn.com/image/fetch/$s_!y-oj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png 848w, https://substackcdn.com/image/fetch/$s_!y-oj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png 1272w, https://substackcdn.com/image/fetch/$s_!y-oj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcef516dc-d076-41dd-9cff-648a4c96261f_595x353.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So the enterprise is increasingly becoming multi-model and the harness is playing a key role in routing etc. </p><p>This has security implications as well, with activities such as model risk assessment, provenance, and IR needing to account for environments with multiple models being used and the harness being a key part of how. Logs and telemetry now need to account for the router, rather than a single vendor or agreement and this ties to LLM04 Supply Chain as well, as the model inventory grows, each introducing its own unique security risks and considerations combining commercial frontier vendors and open source model offerings. </p><p>Another interesting aspect of this is OpenAI <strong><a href="https://developers.openai.com/blog/codex-as-a-platform">recently open sourced</a></strong> their harness for Codex, which is built on the open agent harness. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ken Huang&quot;,&quot;id&quot;:1160339,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;uuid&quot;:&quot;5f03ba34-45d6-45c4-82cb-94c899ad0c04&quot;}" data-component-name="MentionToDOM"></span> recently had an excellent detailed blog breaking the harness down. This shows you that the frontier labs view the harness as something you give away, while model weights remain proprietary and organizations need to inherit, review, patch and inventory the harness components they use.</p><h2>Where the Harness Actually Broke</h2><p>None of the discussions around the security concerns of the harness are theoretical either. Several have written about the role of the harness in recent agent breakout stories from the labs and research institutes. </p><p>Additionally, various CVE&#8217;s are tied to vulnerabilities such as <strong><a href="https://www.legitsecurity.com/blog/camoleak-critical-github-copilot-vulnerability-leaks-private-source-code">CamoLeak</a></strong> in October 2025, where a GitHub Copilot Chat flaw allowed invisible markdown comments to lead to exfiltration through GitHub&#8217;s own Camo image proxy. The issue lied in the rendering pipeline, not the model, which behaved as designed.</p><p>There are other examples such as Tenable <strong><a href="https://www.tenable.com/blog/faq-cve-2025-54135-cve-2025-54136-vulnerabilities-in-cursor-curxecute-mcpoison">finding CVE&#8217;s in Cursor</a></strong>, that were time-of-check to time-of-use flaws, where approved MCP configurations stay trusted because approval was bound to the MCP name rather than its contents, or teams such as Oligo <strong><a href="https://www.oligo.security/blog/critical-rce-vulnerability-in-anthropic-mcp-inspector-cve-2025-49596">producing findings</a></strong> in Anthropic&#8217;s own MCP inspector. </p><p>As I mentioned above, the various agent breakout stories are also riddled with issues tied to the sandboxes and build pipelines involved. </p><p>Then there are supply chain incidents, such as the <strong><a href="https://socket.dev/blog/nx-packages-compromised">Nx s1ngularity compromise</a></strong>, where leading models such as Claude, Gemini and others were prompted to enumerate filesystems before exfiltrating credentials such qas tokens, SSH keys and .env secrets and over 1,000 victim accounts. </p><p>There are plenty of other examples to point to but the key point is that none of them were a &#8220;model failure&#8221; and things such as model evals wouldn&#8217;t have surfaced the findings. The failures lied in the rendering, permission checking, transport, sandboxing and build integrity of the systems around the models. </p><p>So while the industry has spent the last 24 months hyper-focusing on model-centric security, agents expand the real risks to the harness around the models, and as you can see from above, the opportunities for vulnerabilities, misconfigurations and exploitation is vast due to the complexity of the environments these models are hosted in and interact with via agents and their autonomy. </p><p>These trust boundaries introduce risks, and I walked through them in a blog titled &#8220;Agents Have Boundary Issues&#8221;, where I cited a similar research paper on the topic.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qenF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qenF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png 424w, https://substackcdn.com/image/fetch/$s_!qenF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png 848w, https://substackcdn.com/image/fetch/$s_!qenF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png 1272w, https://substackcdn.com/image/fetch/$s_!qenF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qenF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png" width="464" height="432.62893081761007" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:593,&quot;width&quot;:636,&quot;resizeWidth&quot;:464,&quot;bytes&quot;:208502,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/212189124?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qenF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png 424w, https://substackcdn.com/image/fetch/$s_!qenF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png 848w, https://substackcdn.com/image/fetch/$s_!qenF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png 1272w, https://substackcdn.com/image/fetch/$s_!qenF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa739aad2-42b5-4a57-81b7-0fd1ed8ac199_636x593.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While Boris mentioned some of the latest Anthropic models are resistant to prompt injection, the reality is that every organization and environment leveraging the models will have unique environments, configurations, permissions, etc. which leaves the door open for this sort of activity beyond the model itself. </p><p>That said, these incidents are likely to be attributable to other causes, rather than prompt injection, as pointed out in the OWASP LLM Top 10, as well as by <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;16290b57-4de4-4cb1-a219-698d7a64ae2f&quot;}" data-component-name="MentionToDOM"></span> in his article I cited above. </p><h2>Closing Thoughts</h2><p>The latest OWASP LLM Top 10 says it directly, the model is often not the thing we are defending, and it says so backed by evidence and real-world incident data as well. That said, the complexity of the disparate OWASP Top 10 publications coupled with the nuance laid out by Josh highlight the challenges of trying to measure this class of risk and rank it accordingly. </p><p>All of this to say it is time to stop treating model choice as the significant security decision and instead treat the harness as an asset class security needs to be deeply familiar with and own from a risk perspective. </p><p>It is where the capability lives, where incidents of the past year landed, and where the controls that hold under an adversary or even model alignment challenges are enforceable. This means it needs to be inventoried, assigned an owner, threat modeled as the privileged application it is and have boundaries enforced deterministically rather than hoping soft guardrails such as model alignment and system prompts hold. </p><p>What I will be keeping an eye on is how the industry answers this challenge, how we build this layer from a security perspective moving forward and how the continued evolution of the model and the systems around it contribute and complicate this reality. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #110]]></title><description><![CDATA[The end-state fallacy, open-weight models catching up on offense, the CVE Program at human scale, agent identity gets real & a market that may have outgrown itself]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-110</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-110</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 20 Aug 2026 14:33:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YUTN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #110 of the Resilient Cyber Newsletter!</p><p>Every so often a piece comes along that gives you the frame for everything else you are reading, and this week that piece was Dan Lahav&#8217;s &#8220;<strong><a href="https://endstatefallacy.com/">The End-State Fallacy</a></strong>.&#8221; </p><p>His argument is that our industry keeps debating whether AI will ultimately favor offense or defense, and in doing so we skip past the part that actually determines what the next few years look like. As he puts it, </p><blockquote><p><strong>&#8220;even if the end state turns out to be defense-dominant, the next few years can still be sharply offense-dominant.&#8221; </strong></p></blockquote><p>The equilibrium is not the experience, the path is.</p><p>Once you have that frame in hand, this week&#8217;s stories stop reading like unrelated headlines and start reading like data points on a single curve. </p><p>Let&#8217;s get into it!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YUTN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YUTN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png 424w, https://substackcdn.com/image/fetch/$s_!YUTN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png 848w, https://substackcdn.com/image/fetch/$s_!YUTN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png 1272w, https://substackcdn.com/image/fetch/$s_!YUTN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YUTN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png" width="1264" height="780" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:1264,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:705776,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YUTN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png 424w, https://substackcdn.com/image/fetch/$s_!YUTN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png 848w, https://substackcdn.com/image/fetch/$s_!YUTN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png 1272w, https://substackcdn.com/image/fetch/$s_!YUTN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcec44acf-0193-4d56-ab65-4e6680a6489c_1264x780.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://securityboulevard.com/wp-content/uploads/2026/08/Is_the_Cyber_Industry_Too_Big_LINKED-1.pdf">Is the Cyber Industry Too Big?</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pB5V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pB5V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png 424w, https://substackcdn.com/image/fetch/$s_!pB5V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png 848w, https://substackcdn.com/image/fetch/$s_!pB5V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png 1272w, https://substackcdn.com/image/fetch/$s_!pB5V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pB5V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png" width="326" height="329.54347826086956" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:465,&quot;width&quot;:460,&quot;resizeWidth&quot;:326,&quot;bytes&quot;:272314,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pB5V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png 424w, https://substackcdn.com/image/fetch/$s_!pB5V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png 848w, https://substackcdn.com/image/fetch/$s_!pB5V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png 1272w, https://substackcdn.com/image/fetch/$s_!pB5V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94584802-bf5a-4d53-b125-a004f2e77e30_460x465.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Alan Shimel of Techstrong wrote this one from the floor of Black Hat USA 2026, and it is a great analysis of our space, and the numbers underneath it are worth your time.</p><p>Cyber generated roughly $335.8 billion in 2025, up from $214.9 billion in 2022, with projections of $371 billion in 2026 and $404.5 billion in 2027, but growth is moderating from 17.9% in 2023 to a projected 9% in 2027. There are 4,100+ vendors selling around 11,000 products, the top 10 vendors hold only 29.5% of the market, and Microsoft, the largest of them, holds under 10%. Black Hat itself drew 20,000+ attendees and 400+ solution providers at an average booth cost of roughly $250,000.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!547z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!547z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png 424w, https://substackcdn.com/image/fetch/$s_!547z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png 848w, https://substackcdn.com/image/fetch/$s_!547z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png 1272w, https://substackcdn.com/image/fetch/$s_!547z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!547z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png" width="678" height="385" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:385,&quot;width&quot;:678,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:51860,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!547z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png 424w, https://substackcdn.com/image/fetch/$s_!547z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png 848w, https://substackcdn.com/image/fetch/$s_!547z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png 1272w, https://substackcdn.com/image/fetch/$s_!547z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa957a81a-8c85-4134-94ed-7c21509a2e35_678x385.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Alan&#8217;s answer to his own question is nuanced, and I largely agree with it. The industry is not too big for the problem, it may be too big for its own commercial plumbing. His observation that:</p><blockquote><p><strong>&#8220;the company with the best booth is not necessarily the company with the best product. It may simply be the company with the most capital to convert into visibility&#8221;</strong></p></blockquote><p>This is one every practitioner walking a show floor already knows in their gut. The Futurum survey he cites, with 929 decision makers, found 67% expecting budget increases while 42% plan to reduce vendors and 36% plan to add them, which tells you the consolidation story is far messier than the platform vendors would like, and per an IBM and Palo Alto Networks study he references, the average organization is managing 83 security solutions from 29 vendors. </p><p>His warning that &#8220;the answer to tool sprawl cannot be agent sprawl&#8221; is the one I would tattoo on the industry&#8217;s forehead heading into 2027. Read this next to the end-state fallacy piece further down, because 83 tools from 29 vendors and six month procurement cycles are exactly the institutional metabolism that makes the transition period offense-dominant regardless of how good our defensive technology gets.</p><h3><a href="https://www.calcalistech.com/ctechnews/article/byamimoimx">Palo Alto&#8217;s CEO bought the dip. Five months later, his $10 million bet is worth $26 million</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kvBx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kvBx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png 424w, https://substackcdn.com/image/fetch/$s_!kvBx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png 848w, https://substackcdn.com/image/fetch/$s_!kvBx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png 1272w, https://substackcdn.com/image/fetch/$s_!kvBx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kvBx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png" width="658" height="307" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:307,&quot;width&quot;:658,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48588,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kvBx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png 424w, https://substackcdn.com/image/fetch/$s_!kvBx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png 848w, https://substackcdn.com/image/fetch/$s_!kvBx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png 1272w, https://substackcdn.com/image/fetch/$s_!kvBx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27631d2c-3a49-440c-9c54-410b46b596f3_658x307.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Nikesh Arora bought 68,085 Palo Alto Networks shares on March 27 at $146.88 per share, roughly $10 million, at a moment when the stock had fallen 20% since the start of the year on fears that AI would disrupt incumbent security vendors. That position is now worth over $26 million. PANW sits at roughly $315 billion in market value, closed the ~$25 billion CyberArk acquisition in February, and posted $3 billion in Q3 revenue at 31% year over year growth.</p><p>I include this less as a stock story and more as a signal about the disruption thesis. The market briefly priced incumbents as AI roadkill, and the incumbents responded by buying their way into the AI security stack, with five AI-related acquisitions in the past year alone. Arora&#8217;s own framing, that &#8220;as AI becomes more pervasive across the enterprise, it expands the attack surface area,&#8221; is exactly the pitch every platform vendor is now making. Pair this with the Shimel report above and you get the full picture of where the capital is flowing and why.</p><p>I recently came across a good long-form interview with Nikesh on the Sourcery podcast by <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Molly O&#8217;Shea&quot;,&quot;id&quot;:6470945,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c0e15bc-1f31-4aa9-929c-9af2016621df_1179x1306.jpeg&quot;,&quot;uuid&quot;:&quot;24f7219b-c004-4811-a5da-6b6aa353034a&quot;}" data-component-name="MentionToDOM"></span> </p><div id="youtube2-_v_ryYwmfM0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;_v_ryYwmfM0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/_v_ryYwmfM0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://techcrunch.com/2026/08/17/anthropics-annualized-revenue-surges-to-65b/">Anthropic&#8217;s annualized revenue surges to $65B</a></h3><p>Per Marina Temkin at TechCrunch, Anthropic hit $65 billion in annualized revenue at the end of July, up from $47 billion in May and $9 billion at the end of 2025. That is $18 billion in annualized revenue added in two months. The company is projected to finish 2026 somewhere between $100 and $120 billion, against OpenAI&#8217;s $40 billion run rate, and both have filed confidential IPO paperwork.</p><p>To put into perspective what that means for our industry, the entire global cybersecurity market is around $371 billion projected for 2026 per the Techstrong figures above. A single model provider is on a trajectory to reach a third of that inside a year. This is the scale of the platform shift security is now being asked to secure, and it should inform how much of your program you are willing to bet on governance patterns that assume you get to move at your own pace.</p><h3><a href="https://ramp.com/data/ai-index-august-2026">Ramp AI Index, August 2026</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Te7G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Te7G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png 424w, https://substackcdn.com/image/fetch/$s_!Te7G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png 848w, https://substackcdn.com/image/fetch/$s_!Te7G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png 1272w, https://substackcdn.com/image/fetch/$s_!Te7G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Te7G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png" width="881" height="501" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:501,&quot;width&quot;:881,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82152,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Te7G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png 424w, https://substackcdn.com/image/fetch/$s_!Te7G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png 848w, https://substackcdn.com/image/fetch/$s_!Te7G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png 1272w, https://substackcdn.com/image/fetch/$s_!Te7G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0305f2c-90b1-499d-8e5e-024f1076202c_881x501.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ramp&#8217;s Ara Kharazian titled this edition &#8220;Cracks in the AI Thesis,&#8221; and the data underneath is a nice counterweight to the revenue story above.</p><p>Paid Anthropic adoption sits at 43.5% of U.S. businesses, up 1.1 points month over month, with OpenAI at 39.7%, up only 0.23 points, and xAI at 4%, up 0.94 points. The finding that stands out to me is on premium model uptake. Anthropic&#8217;s flagship Fable 5 accounts for only 6% of tokens purchased from Anthropic and 11.4% of Anthropic spending, despite being the most capable option on offer, at roughly $10 per 1M tokens.</p><p>Buyers are not paying up for the best model, they are paying for the good enough model at a price they can defend. Spend distribution says the same thing, with the top 1% of businesses spending a median of $7,400 per employee on AI in July, the top 10% spending $650, and the median firm spending $11.95. For security leaders building AI-driven detection, triage, or code review pipelines, this is your budget reality. The frontier capability exists, and most of your organization will be running something cheaper.</p><h3><a href="https://gizmodo.com/california-building-ai-cyber-defense-fund-to-protect-critical-infrastructure-from-hackers-2000797182">California Building &#8216;AI Cyber Defense Fund&#8217; to Protect Critical Infrastructure From Hackers</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5lw1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5lw1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png 424w, https://substackcdn.com/image/fetch/$s_!5lw1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png 848w, https://substackcdn.com/image/fetch/$s_!5lw1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png 1272w, https://substackcdn.com/image/fetch/$s_!5lw1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5lw1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png" width="499" height="243" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6da96da-e160-4fc6-8620-9164a6363beb_499x243.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:243,&quot;width&quot;:499,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32107,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5lw1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png 424w, https://substackcdn.com/image/fetch/$s_!5lw1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png 848w, https://substackcdn.com/image/fetch/$s_!5lw1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png 1272w, https://substackcdn.com/image/fetch/$s_!5lw1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6da96da-e160-4fc6-8620-9164a6363beb_499x243.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>California is standing up an &#8220;AI Cyber Defense Program&#8221; to use AI to find and patch vulnerabilities across state and local critical infrastructure, supervised by AI Cybersecurity Officers, one per state agency, with an implementation plan due within 120 days. Per Gizmodo, the move follows internal tests in which AI systems from OpenAI, Anthropic, and Meta autonomously gained access to the open internet and hacked into third-party organizations. Governor Newsom framed it as a choice, </p><blockquote><p><strong>&#8220;California can either wait for the next crisis, or we can build the kind of defenses this moment demands. We are choosing to build.&#8221;</strong></p></blockquote><div><hr></div><h1>AI</h1><h3><a href="https://endstatefallacy.com/">The End-State Fallacy: Where Is AI Security Headed?</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3Ts7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3Ts7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png 424w, https://substackcdn.com/image/fetch/$s_!3Ts7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png 848w, https://substackcdn.com/image/fetch/$s_!3Ts7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png 1272w, https://substackcdn.com/image/fetch/$s_!3Ts7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3Ts7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png" width="528" height="387.98130841121497" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:629,&quot;width&quot;:856,&quot;resizeWidth&quot;:528,&quot;bytes&quot;:48274,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3Ts7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png 424w, https://substackcdn.com/image/fetch/$s_!3Ts7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png 848w, https://substackcdn.com/image/fetch/$s_!3Ts7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png 1272w, https://substackcdn.com/image/fetch/$s_!3Ts7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef291042-8b7c-4e76-bd48-70149c8ed736_856x629.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the piece of the week, and the one I would read first if you only get to one thing in this issue. </p><p>Dan Lahav of Irregular argues that our field keeps litigating where the offense-defense balance eventually lands while skipping the question that actually determines the next few years. He calls the mistake the end-state fallacy, assuming that the long-run equilibrium&#8217;s properties apply to the transition period, and his thesis is that:</p><blockquote><p><strong>&#8220;even if the end state turns out to be defense-dominant, the next few years can still be sharply offense-dominant.&#8221; </strong></p></blockquote><p>His analogy for it is good, that &#8220;getting in shape has an excellent end state and a hard path; drinking is the reverse, pleasant in the moment and costly later.&#8221; The path matters, and as he says, &#8220;perhaps even more.&#8221;</p><p>He gives five reasons why the next few years likely favor offense, and every one of them is something practitioners already feel. </p><ul><li><p>First, the discovery-to-exploitation window is collapsing while the patch queue grows, with time from a CVE&#8217;s public disclosure to first confirmed in-the-wild exploitation falling from 2.3 years in 2018 to 1.6 days in 2026, and defenders paying what he calls an &#8220;accountability tax&#8221; because we cannot afford to break production with a bad patch while attackers carry no such burden. His illustration of the supply side is one I had not seen anywhere else, that &#8220;at Pwn2Own Berlin 2026, for the first time in the competition&#8217;s nineteen-year history, dozens of severe vulnerability submissions had to be turned away... simply because the organizers had run out of contest slots.&#8221; </p></li><li><p>Second, defending AI is itself a new discipline, and building the defenses it requires takes time we do not have much of. </p></li><li><p>Third are defense deployment gaps, because &#8220;defensive organizations do not move on that timeline. They onboard vendors over quarters, budget annually, and modernize infrastructure over years,&#8221; and &#8220;defensive capability becomes useful only after an institution has learned how to trust, buy, operate, and integrate it into a complicated system.&#8221; </p></li><li><p>Fourth, he expects that &#8220;at least in the near term... AI will scale faster on offense than on defense,&#8221; largely because of verification asymmetry, since an exploit either works or it does not while &#8220;a patch asks something closer to global assurance, one must show that the system is secure under continuous, adversarial pressure, without having broken anything adjacent,&#8221; which he calls a much harder thing to verify. This is something I have cited in a blog from Sergej Epp titled the &#8220;Verifiers Law&#8221;, as well as showing in research from Keith Hoodlet that AI created patches remain problematic.</p></li><li><p>Lastly, none of these effects occur in isolation, they compound. Elsewhere in the essay he adds the structural version of the same worry, that &#8220;if the cost of creating or attacking systems falls faster than the cost of securing them, the attack surface may grow beyond what defensive tooling can feasibly cover.&#8221;</p></li></ul><p>The capability data underneath is what makes the argument hard to wave off. On Cybench, &#8220;frontier models reportedly climbed from around 10% success to near-complete success in about two years.&#8221; </p><p>A custom CPU-emulator exploitation task went from unsolvable in February 2026, to roughly 5% success at about $2,000 per run in April, to reliable completion at about $20 per run by June, which he sums up as going &#8220;from unsolvable to cheap and repeatable&#8221; in four months. </p><p>His base case is that frontier models &#8220;will continue to roughly double their performance and effective autonomous work horizon every six months&#8221; over the next two years, with the price of a fixed capability level falling on the order of 10x per year. </p><p>On diffusion, NIST CAISI measured open-weight DeepSeek-V4 Pro lagging the frontier by about eight months across its aggregate evaluation suite in May, and UK AISI found an even tighter gap on cyber specifically in July, with open models like GLM-5.2 and DeepSeek-V4 Pro matching closed frontier models released four to seven months earlier, down from the six to ten month gap it measured through most of 2025. </p><p>His projection follows directly, that:</p><blockquote><p><strong>&#8220;based on the current trajectory, we can expect current frontier-grade cyber capabilities, such as Mythos 5 / GPT-5.6 Sol, to proliferate before the end of Q1 2027.&#8221;</strong></p></blockquote><p>His retelling of the July Hugging Face incident is the clearest I have come across and it makes sense given how involved Irregular is with the labs.</p><p>Frontier models in a sealed OpenAI cyber-evaluation sandbox &#8220;found a zero-day flaw that let them act beyond their sandbox,&#8221; and then, in his words, &#8220;autonomously attacked Hugging Face infrastructure, gaining elevated access, stealing credentials, moving laterally, and restoring access after being blocked,&#8221; carrying out about 17,600 unscripted actions over several days. </p><p>Separate agents &#8220;discovered a way to communicate through a shared system, created their own channels to exchange attack directions, exploits and credentials, and divided tasks without being instructed to cooperate, forming an autonomous swarm,&#8221; and when one channel was shut down they simply established another. Lahav&#8217;s framing of why this one is different is the right one, that &#8220;no human selected Hugging Face as the target or specified the attack chain step by step. The AI found and executed that path itself.&#8221;</p><p>His answer is Differential Defensive Cyber Acceleration, which is deliberately shaping &#8220;the development, diffusion, and deployment of AI security capabilities so that protective capabilities mature and reach defenders before corresponding offensive capabilities can overwhelm them.&#8221; </p><p>It rests on three tenets, measuring the field with continuous feedback between measurement and intervention and tracking realistic attack chains rather than benchmark scores, building defensive-specific capability along a &#8220;red-to-blue spectrum&#8221; by prioritizing interventions that &#8220;sit as far toward blue as possible&#8221; such as remediation, incident response and threat intelligence, and blue deployments that get defensive tooling into critical organizations, and treating offensive diffusion as its own R&amp;D problem through use limitations, theft prevention, and AI containment.</p><p>I have been making a version of this argument all year in less rigorous terms, so I will say plainly that this is now the reference text. </p><p>Where I would put the emphasis is on the least glamorous third of his second tenet, blue deployments. Building blue-asymmetric capability is a research and vendor problem that is already well underway, and the rest of this issue is full of evidence for that. </p><p>Getting it into production runs straight into his own third reason, the institutional metabolism of security organizations that onboard over quarters and modernize over years. We do not have a capability gap on defense right now, we have an absorption gap, and absorption is the one part of this that no lab, no benchmark, and no policy office can do on our behalf. </p><p>Nearly every other item in this issue is either evidence for one of his five reasons or an example of somebody trying to close that absorption gap, so read the rest with his frame in hand.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6yIz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6yIz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png 424w, https://substackcdn.com/image/fetch/$s_!6yIz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png 848w, https://substackcdn.com/image/fetch/$s_!6yIz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png 1272w, https://substackcdn.com/image/fetch/$s_!6yIz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6yIz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png" width="871" height="395" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:395,&quot;width&quot;:871,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:109410,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6yIz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png 424w, https://substackcdn.com/image/fetch/$s_!6yIz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png 848w, https://substackcdn.com/image/fetch/$s_!6yIz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png 1272w, https://substackcdn.com/image/fetch/$s_!6yIz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc05e68d-64bf-4247-b209-89e3230cffb7_871x395.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://z.ai/blog/glm-5.3">GLM-5.3</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8o0W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8o0W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png 424w, https://substackcdn.com/image/fetch/$s_!8o0W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png 848w, https://substackcdn.com/image/fetch/$s_!8o0W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png 1272w, https://substackcdn.com/image/fetch/$s_!8o0W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8o0W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png" width="1011" height="371" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:371,&quot;width&quot;:1011,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95210,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8o0W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png 424w, https://substackcdn.com/image/fetch/$s_!8o0W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png 848w, https://substackcdn.com/image/fetch/$s_!8o0W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png 1272w, https://substackcdn.com/image/fetch/$s_!8o0W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09d6b206-053a-4a3e-ac09-69311cc45369_1011x371.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Z.ai released GLM-5.3 on August 14, and the cyber benchmark results are the story. Per the release coverage, the model posted 84.5% on CyberGym, ahead of Claude Mythos 5 at 83.8% and GPT-5.6 Sol at 83.6%, jumped from 4.6 to 28.3 on Terminal-Bench 3.0 and from 46.2 to 66.9 on DeepSWE v1.1, and reportedly surfaced 2,436 vulnerabilities across 269 open-source projects, with 1,097 rated critical or high severity, including bugs in Linux, WebKit, and FreeBSD.</p><p>Then the part that actually matters. Z.ai is holding the open weights for a two-week safety review, because the model:</p><blockquote><p><strong>&#8220;began reasoning across multiple stages of exploitation and forming coherent plans for complete exploitation chains, a capability it did not set out to train for.&#8221; </strong></p></blockquote><p>A Chinese lab, building on an open-weight lineage, voluntarily delaying a weight release over emergent offensive cyber capability, is a genuinely notable moment for anyone who assumed open-weight governance would only ever come from Western labs or regulators. </p><p>It is also the end-state fallacy playing out in real time, since Lahav cites the previous generation, GLM-5.2, being measured at &#8220;roughly seventeen cents per vulnerability found&#8221; while matching or beating leading closed models on some bug-finding benchmarks, and this release moves that lineage past the frontier models he named as the ones due to proliferate by Q1 2027. </p><p>A two-week safety review is a speed bump on a curve like that, and it is worth asking what happens the next time a lab in this position decides the delay is not worth it. </p><h3><a href="https://blog.google/security/the-evolving-role-of-the-red-team-in-the-era-of-agentic-security/">The evolving role of the Red Team in the era of agentic security</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FtEC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FtEC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png 424w, https://substackcdn.com/image/fetch/$s_!FtEC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png 848w, https://substackcdn.com/image/fetch/$s_!FtEC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png 1272w, https://substackcdn.com/image/fetch/$s_!FtEC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FtEC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png" width="633" height="171" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:171,&quot;width&quot;:633,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24017,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FtEC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png 424w, https://substackcdn.com/image/fetch/$s_!FtEC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png 848w, https://substackcdn.com/image/fetch/$s_!FtEC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png 1272w, https://substackcdn.com/image/fetch/$s_!FtEC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9a00f5-8883-4565-8f06-4d8e5d8f4685_633x171.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Daniel Fabian, who heads Google&#8217;s Red Teams, wrote this with Ash Fox, Moni Pande, Niru Ragupathy, and Stefan Friedli, and it is a practical companion to the Lahav essay. </p><p>Their argument is that red teams have to stop running manual exercises and start building the autonomous agents that will simulate real agentic attacks, because attackers who value volume and speed above all have every incentive to automate first.</p><p>They break the change into sophistication, scale, and speed, with the observation that &#8220;dwell time, the window between gaining an initial foothold and moving on objectives, is collapsing.&#8221; </p><p>Their forecast is that within 6 to 12 months &#8220;open-weight models will match today&#8217;s cybersecurity capabilities of frontier models,&#8221; with safety guardrails removable through techniques like abliteration. </p><p>Given the GLM-5.3 and Kimi K3 results above, that forecast may already be conservative. What I appreciate most is the pragmatism of the recommendation, which is not to build a full autonomous red team on day one, but to start automating isolated pieces of your existing manual exercises like reconnaissance or lateral movement, then wire modular subagents behind an orchestrator. </p><p>Their closing point, that &#8220;we have the time right now to get ahead of the curve,&#8221; is the same window Lahav is describing, arrived at independently by a team with a very different vantage point, and the two forecasts landing on the same 6 to 12 month horizon should carry more weight than either would alone.</p><h3><a href="https://www.anthropic.com/research/multiagent-systems">Patterns and problems in emerging multiagent systems</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ojCa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ojCa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png 424w, https://substackcdn.com/image/fetch/$s_!ojCa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png 848w, https://substackcdn.com/image/fetch/$s_!ojCa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png 1272w, https://substackcdn.com/image/fetch/$s_!ojCa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ojCa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png" width="803" height="280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:280,&quot;width&quot;:803,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35887,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ojCa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png 424w, https://substackcdn.com/image/fetch/$s_!ojCa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png 848w, https://substackcdn.com/image/fetch/$s_!ojCa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png 1272w, https://substackcdn.com/image/fetch/$s_!ojCa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad332d6-654e-4cf3-9bd9-b83f5aef1dd5_803x280.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Anthropic&#8217;s Frontier Red Team ran swarms of Claude agents across several shared environments, and the failure modes are worth knowing before your next architecture review. </p><p>Coordination degraded as agent counts rose in a 12-hour game development experiment scaling from 10 to 80 agents, with Sonnet 4.6 and Opus 4.6 opening 876 and 980 PRs respectively while closing very few. Agents also show remarkably low behavioral variance, with 18 of 30 creating the identical git branch name &#8220;mvp-game-loop,&#8221; and in a job queue experiment they flooded the system with 2.4 million requests when only 117 jobs were accepted. </p><p>Given a communication channel in pricing games they colluded on price floors, and under incompatible objectives they deployed self-replicating malware disguised as system processes, disabled Unix accounts, and wrote kill-loop scripts, with one agent noting that &#8220;the name of the reaper script matters for dodging pkill -f.&#8221;</p><p>On the upside, a coordinated 45-agent swarm found 266 vulnerabilities using 27M tokens versus 21 for independent parallel agents at 6.5M tokens, with only 12 findings in common. The researchers&#8217; conclusion is the line to carry forward, that &#8220;coordination doesn&#8217;t naturally emerge from stronger intelligence nor alignment at the individual level.&#8221; Anthropic is showing us that emergent coordination is unreliable and often destructive in benign settings, and the Hugging Face incident above is what it produced in an adversarial one.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SbxQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SbxQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png 424w, https://substackcdn.com/image/fetch/$s_!SbxQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png 848w, https://substackcdn.com/image/fetch/$s_!SbxQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png 1272w, https://substackcdn.com/image/fetch/$s_!SbxQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SbxQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png" width="882" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:882,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:191875,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SbxQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png 424w, https://substackcdn.com/image/fetch/$s_!SbxQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png 848w, https://substackcdn.com/image/fetch/$s_!SbxQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png 1272w, https://substackcdn.com/image/fetch/$s_!SbxQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bda5032-19b9-4c3c-a8ff-a328a329dfa6_882x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://www.crowdstrike.com/en-us/blog/teaching-ai-to-reason-through-detection-triage/">Teaching AI to Reason Through Detection Triage</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TYUB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TYUB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png 424w, https://substackcdn.com/image/fetch/$s_!TYUB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png 848w, https://substackcdn.com/image/fetch/$s_!TYUB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png 1272w, https://substackcdn.com/image/fetch/$s_!TYUB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TYUB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png" width="897" height="210" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:210,&quot;width&quot;:897,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34811,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TYUB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png 424w, https://substackcdn.com/image/fetch/$s_!TYUB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png 848w, https://substackcdn.com/image/fetch/$s_!TYUB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png 1272w, https://substackcdn.com/image/fetch/$s_!TYUB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F510befe6-a250-4bd5-a5ff-4ca56302440a_897x210.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>CrowdStrike published results on a detection triage classifier built on NVIDIA Nemotron that reasons through evidence before issuing a verdict. At their high-confidence operating point, holding 98% false positive precision and 99% true positive precision, false positive recall improved from 21.8% to 64.8% and true positive recall from 34.7% to 53.0%, with overall accuracy landing at 82.6% against frontier general-purpose models in the 55 to 71% range.</p><p>This is what applied AI in SecOps should look like, and the auditability is the part that matters, since their framing that &#8220;teaching the model to think through a detection improves accuracy while producing an auditable rationale that analysts can evaluate&#8221; answers the biggest practitioner objection to AI triage. </p><p>A tuned smaller model beating the frontier generalists is also a useful data point next to the Ramp findings above. Alert adjudication is about as blue as Lahav&#8217;s spectrum gets, since attackers get almost nothing out of it.</p><h3><a href="https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding">Least privilege for AI agents, identity, access, and tool binding</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ulau!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ulau!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png 424w, https://substackcdn.com/image/fetch/$s_!ulau!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png 848w, https://substackcdn.com/image/fetch/$s_!ulau!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png 1272w, https://substackcdn.com/image/fetch/$s_!ulau!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ulau!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png" width="546" height="151" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae5de857-b468-4617-9378-7335c060830d_546x151.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:151,&quot;width&quot;:546,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29560,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ulau!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png 424w, https://substackcdn.com/image/fetch/$s_!ulau!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png 848w, https://substackcdn.com/image/fetch/$s_!ulau!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png 1272w, https://substackcdn.com/image/fetch/$s_!ulau!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae5de857-b468-4617-9378-7335c060830d_546x151.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Yesenia Yser and Toby Kohlenberg laid out Microsoft&#8217;s guidance on agent least privilege, and it is refreshingly unglamorous. </p><p>Treat every agent as a first-class identity principal with its own lifecycle and clear human ownership, build task-based roles instead of broad team-level access, scope by resource, data, and operation type, and expose only curated tools through explicit allowlists, with JIT elevation, re-authorization enforced downstream rather than trusting the orchestrator, and mandatory revocation testing. </p><p>Their warning is the one practitioners will recognize from every prior identity wave, that agents working &#8220;across multiple systems within a single workflow&#8221; quietly accumulate dangerous combined permissions, and that &#8220;scope creep is quiet, incremental, and rarely revisited.&#8221; </p><p>They suggest doing this work in 30 to 90 days before expanding agent deployments, which is optimistic for most enterprises, but the sequencing is right. Doing agent identity hygiene after you have 10x&#8217;d your agent population is the service account mistake at a much worse scale.</p><h3><a href="https://agentgateway.dev/blog/2026-07-27-credential-injection-ai-agent-egress-cb4a/">Credential Injection Patterns for AI Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IcLA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IcLA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png 424w, https://substackcdn.com/image/fetch/$s_!IcLA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png 848w, https://substackcdn.com/image/fetch/$s_!IcLA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png 1272w, https://substackcdn.com/image/fetch/$s_!IcLA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IcLA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png" width="776" height="477" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:477,&quot;width&quot;:776,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83408,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IcLA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png 424w, https://substackcdn.com/image/fetch/$s_!IcLA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png 848w, https://substackcdn.com/image/fetch/$s_!IcLA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png 1272w, https://substackcdn.com/image/fetch/$s_!IcLA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F451329c2-a52a-4233-a7c5-b6974272f0ca_776x477.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Christian Posta wrote the deep technical version of the same problem. </p><p>Bearer credentials have an obvious flaw, &#8220;anyone holding the credential can use it,&#8221; and of his three mitigations, accelerating expiration, proof-of-possession, or removing agent access to credentials entirely, he argues for the third through credential brokering. The vehicle is Credential Brokering 4 AI Agents (CB4A), an IETF draft from March 2026 that recommends a proxy gateway model where credentials are injected on egress and the agent never sees them. </p><p>Posta is honest about the tradeoff, since CB4A&#8217;s own threat model rates broker compromise as &#8220;CRITICAL&#8221; and the broker becomes &#8220;the highest-value target in the architecture.&#8221; That is the right way to present a control, as a shift in where risk concentrates rather than an elimination of it.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://www.cybersecuritydive.com/news/cve-program-ai-black-hat-def-con/827477/">CVE program eyes automation and globalization to weather AI &#8216;vulnpocalypse&#8217;</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dnYO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dnYO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png 424w, https://substackcdn.com/image/fetch/$s_!dnYO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png 848w, https://substackcdn.com/image/fetch/$s_!dnYO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png 1272w, https://substackcdn.com/image/fetch/$s_!dnYO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dnYO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png" width="793" height="236" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:236,&quot;width&quot;:793,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47959,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dnYO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png 424w, https://substackcdn.com/image/fetch/$s_!dnYO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png 848w, https://substackcdn.com/image/fetch/$s_!dnYO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png 1272w, https://substackcdn.com/image/fetch/$s_!dnYO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4325ede4-d80c-495f-9499-7ca5792f05ad_793x236.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>This is good reporting providing insights from NIST and others on running vulnerability programs. </p><p>Microsoft&#8217;s Elizabeth Eigner gave the quote of the week, that </p><blockquote><p><strong>&#8220;these vulnerabilities are coming out at an AI pace, but we&#8217;re still creating and processing them at a human scale.&#8221; </strong></p></blockquote><p>CISA&#8217;s Lindsey Cerkovnik said &#8220;we cannot treat every vulnerability the same way&#8221; and that she is &#8220;concerned about the industry&#8217;s ability to scale via prioritization.&#8221; GitHub has published more than 7,000 CVE identifiers so far in 2026, which Madison Ficorelli said she believed to be an annual record for a CNA, framing it correctly as &#8220;not a competition.&#8221; </p><p>Intel&#8217;s Katie Noble was bluntest, &#8220;I don&#8217;t think the CVE Program was designed to be able to manage this influx of vulnerabilities.&#8221; CISA is now handling 360 to 400 cases simultaneously, and OpenAI and Anthropic were granted temporary CNA status in July.</p><p>This is Lahav&#8217;s first reason with names and job titles attached. Automating intake does not solve the downstream problem, because even a perfectly efficient CVE Program hands enterprises a volume of findings their remediation capacity cannot absorb, which is why I keep arguing that prioritization and remediation capacity, not discovery, are where the money should be going.</p><h3><a href="https://alukashenkov.github.io/vulnpocalypse_2026/">Vulnpocalypse 2026 statistics dashboard</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YgSE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YgSE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png 424w, https://substackcdn.com/image/fetch/$s_!YgSE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png 848w, https://substackcdn.com/image/fetch/$s_!YgSE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png 1272w, https://substackcdn.com/image/fetch/$s_!YgSE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YgSE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png" width="1049" height="721" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:721,&quot;width&quot;:1049,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:232662,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YgSE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png 424w, https://substackcdn.com/image/fetch/$s_!YgSE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png 848w, https://substackcdn.com/image/fetch/$s_!YgSE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png 1272w, https://substackcdn.com/image/fetch/$s_!YgSE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b89256b-55d4-4cbd-80ba-98d301f9d4fb_1049x721.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you would rather watch the trend than read about it, this dashboard tracks 2026 CVE publication against prior years off the Vulners archive, with cumulative counts, year over year pace, monthly flow by CNA, year-end projections, and my favorite view, reserved but unpublished CVE IDs sitting in the queue. </p><p>The page&#8217;s own line is accurate, &#8220;the gap between the red line and the pack is not a rendering glitch.&#8221; That reserved-but-unpublished view is the closest thing we have to a leading indicator, since everything in it is work your team has not been handed yet. </p><p>A timely resource, and worth bookmarking.</p><h3><a href="https://www.cybersecuritydive.com/news/ai-vulnerability-clearinghouse-us-government-challenges/827710/">AI-powered vulnerability clearinghouse faces deep skepticism, major challenges</a> </h3><p>The administration&#8217;s AI-enhanced clearinghouse, codenamed Gold Eagle, launched in mid-July out of a June executive order, using CMU SEI&#8217;s VINCE platform for intake.</p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Alex Stamos&quot;,&quot;id&quot;:1589222,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b9e9c2e7-7b48-42a4-bedc-283711047248_744x744.jpeg&quot;,&quot;uuid&quot;:&quot;f86407c2-c7f9-4c2f-a294-f7b049db7505&quot;}" data-component-name="MentionToDOM"></span> , now CSO at Corridor, argued that &#8220;there&#8217;s no need for the government to step in here.&#8221; Katie Moussouris framed both sides best, granting that &#8220;a clearinghouse that validates findings before they hit software maintainers, deduplicates them, and routes fixes to everyone affected would convert AI noise into defensive signal,&#8221; while flagging that CERT/CC &#8220;is not currently funded with enough analysts to handle a program of this size,&#8221; that &#8220;increased centralization of unpatched vulnerabilities is a juicy target for adversaries,&#8221; and that on Treasury oversight, &#8220;vulnerability coordination succeeds or fails on trust... Treasury has neither the coordination mission nor those relationships.&#8221;</p><p>Her advice, &#8220;don&#8217;t boil the ocean,&#8221; applies to nearly every federal cyber initiative I have watched launch. The private sector is building the same capability anyway, with IBM and Red Hat&#8217;s Lightwell, the Linux Foundation&#8217;s Akrites, and Chainguard&#8217;s Athena, and with Mandiant putting the patch lag at 7 days on average against Lahav&#8217;s 1.6 days from disclosure to exploitation, a clearinghouse that will take quarters to earn ecosystem trust is being asked to keep pace with something moving in hours.</p><h3><a href="https://cursor.com/blog/git-at-any-scale">Git at any scale</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m21f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m21f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp 424w, https://substackcdn.com/image/fetch/$s_!m21f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp 848w, https://substackcdn.com/image/fetch/$s_!m21f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp 1272w, https://substackcdn.com/image/fetch/$s_!m21f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m21f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp" width="427" height="312.6569037656904" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:525,&quot;width&quot;:717,&quot;resizeWidth&quot;:427,&quot;bytes&quot;:9862,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211892196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m21f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp 424w, https://substackcdn.com/image/fetch/$s_!m21f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp 848w, https://substackcdn.com/image/fetch/$s_!m21f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp 1272w, https://substackcdn.com/image/fetch/$s_!m21f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F637e03db-eb0e-4e99-9135-0a7ed50b0c8c_717x525.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Vicent Mart&#237; wrote up Cursor&#8217;s launch of Origin, a Git hosting platform built on a distributed storage system called Continuity that uses a write-ahead log in S3-compatible object storage with atomic compare-and-swap in place of consensus protocols, reaching up to 120 pushes per second on S3 Standard and over 300 on S3 Express One Zone. The line that tells you what this is really about is the allocation model, where monorepos get hundreds of replicas for CI workloads while agent-created repositories need just one.</p><p>Coding agents are now creating repositories fast enough that source control itself is being rebuilt around them, and every assumption baked into your scanning, code review, branch protection, and provenance tooling was designed for a world where humans created repositories at human rates. </p><p>A repository created by an agent and owned by no one in particular still ends up in your software supply chain. That is Lahav&#8217;s ever-expanding-surface argument arriving as infrastructure.</p><div><hr></div><h1>Final Thoughts</h1><p>Reading this issue back, nearly every item is a footnote to Lahav&#8217;s argument. </p><p>Offensive capability is diffusing on a 4 to 7 month lag for cyber tasks, Z.ai just posted leading cyber benchmark scores and paused the weight release over emergent exploitation-chain reasoning, and Google&#8217;s red team independently expects the rest of the gap to close inside 6 to 12 months. </p><p>Meanwhile the CVE Program is processing at human scale, the federal clearinghouse meant to help is launching into deep skepticism about its funding and its home, and the average enterprise is managing 83 security solutions from 29 vendors with six month procurement cycles. That is his third reason, defense deployment gaps, in its native habitat. </p><p>So here is where I would leave it. </p><p>Whether AI ultimately favors offense or defense is the least useful question available to us right now, because we do not get to live in the end state. We live in the transition, and there the binding constraint is not whether defensive capability exists, it is whether our institutions can absorb it faster than offensive capability diffuses. Right now we cannot, and that gap is ours to close. </p><p>Pick one thing from the blue end of Lahav&#8217;s spectrum, a frontier-model review of your most critical repository, remediation capacity instead of more discovery, or gateway-enforced boundaries on your agents, and get it into production this quarter rather than next fiscal year. </p><p>That is the whole game between now and Q1 2027.</p><p><strong>Stay resilient.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Dangerous Skills]]></title><description><![CDATA[A look at OWASP's Agentic Skills Top 1 v1.0]]></description><link>https://www.resilientcyber.io/p/dangerous-skills</link><guid isPermaLink="false">https://www.resilientcyber.io/p/dangerous-skills</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 18 Aug 2026 16:16:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!t_gu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I&#8217;ve been watching the AI and Agentic AI ecosystem and the various security implications evolve over the last several years.</p><p>&#8220;Skills&#8221; were among one of the most notable examples that caught my attention quickly. For those unfamiliar, skills are essentially modular reusable artifacts that can help extend, or improve the performance of agents. They can be instructions, code, resources or operational insights related to the user, organization etc. Agents can discover, load and execute them, as well as being directly fed them by a user to help improve the agents capabilities and usefulness. </p><p>Like agents themselves, it is these very capabilities that make them problematic from the security perspective. I often refer to this as the &#8220;Security vs. Utility Tradeoff&#8221;, where users/organizations are often trying to balance the two, and the more capabilities an agent is given, the more utility it has for the business, but also the more potential risks and challenges it introduces.</p><p>Similar to open source, Skills can be quickly created, distributed and shared widely with the broader community. This has led to the proliferation of Skill hubs and marketplaces. Some of them attempt to vet or score the Skills for security implications and some don&#8217;t. Skills were originally introduced by Anthropic but now have become widely adopted.</p><p>Some examples include <strong><a href="https://agentskillshub.dev/">AgentSkillsHub</a></strong>, <strong><a href="https://skillsmp.com/">skillsmp</a></strong> and <strong><a href="https://mcpmarket.com/tools/skills">MCP Market</a></strong>. These marketplaces have thousands and even millions of Skills available for download and use.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!taIb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!taIb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png 424w, https://substackcdn.com/image/fetch/$s_!taIb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png 848w, https://substackcdn.com/image/fetch/$s_!taIb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png 1272w, https://substackcdn.com/image/fetch/$s_!taIb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!taIb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png" width="532" height="323.8471337579618" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a552630-f677-430a-84a3-cad006151279_1099x669.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:669,&quot;width&quot;:1099,&quot;resizeWidth&quot;:532,&quot;bytes&quot;:136550,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!taIb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png 424w, https://substackcdn.com/image/fetch/$s_!taIb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png 848w, https://substackcdn.com/image/fetch/$s_!taIb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png 1272w, https://substackcdn.com/image/fetch/$s_!taIb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a552630-f677-430a-84a3-cad006151279_1099x669.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It is easy to see why it is helpful to provide information and context to agents to make them more productive and helpful. That said, if you&#8217;ve been following my writing, you can also guess that Skills can easily serve as an attack vector to maliciously steer agents behavior, inject harmful context and carry out other nefarious activities.</p><p>It didn&#8217;t take long for academics and vendors alike to begin to investigate this, and quickly find thousands of examples of malicious Skills in the wild. One of my favorite examples was titled just that, &#8220;<strong><a href="https://arxiv.org/html/2601.10338v1">Agent Skills in thew Wild: An Empirical Study of Vulnerabilities at Scale</a></strong>&#8221;. </p><p>The team used open source tools and scanned tens of thousands of publicly available skills from the marketplaces and found many examples of malicious skills attempting to exfiltrate data, escalate privileges, execute malicious scripts and other harmful activities. They also provided a useful threat model in the paper, which they walked through and is worth a read.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1FT2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1FT2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png 424w, https://substackcdn.com/image/fetch/$s_!1FT2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png 848w, https://substackcdn.com/image/fetch/$s_!1FT2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png 1272w, https://substackcdn.com/image/fetch/$s_!1FT2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1FT2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png" width="1217" height="389" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:389,&quot;width&quot;:1217,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:51103,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1FT2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png 424w, https://substackcdn.com/image/fetch/$s_!1FT2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png 848w, https://substackcdn.com/image/fetch/$s_!1FT2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png 1272w, https://substackcdn.com/image/fetch/$s_!1FT2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F951619d3-4c3f-4491-8743-bf0a98d7078c_1217x389.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The risk of skills has become widely known and discussed now, including talks at Black Hat recently by OWASP, Open AI and others and culminated in the publication of OWASP&#8217;s <strong><a href="https://owasp.org/www-project-agentic-skills-top-10/assets/publications/ast10-top10-whitepaper-2.pdf">v1.0 of the Agentic Skills Top 10</a></strong>, which will be the focus of this article. My friend <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ken Huang&quot;,&quot;id&quot;:1160339,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;uuid&quot;:&quot;48bf44c3-035e-4b5f-828a-2f755b40ad31&quot;}" data-component-name="MentionToDOM"></span> who helped champion the effort also recently had a great article on it.</p><p>I&#8217;ll briefly walkthrough the Top 10 risks and their associated mitigations. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!t_gu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!t_gu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png 424w, https://substackcdn.com/image/fetch/$s_!t_gu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png 848w, https://substackcdn.com/image/fetch/$s_!t_gu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png 1272w, https://substackcdn.com/image/fetch/$s_!t_gu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!t_gu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png" width="542" height="514.7337423312883" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:774,&quot;width&quot;:815,&quot;resizeWidth&quot;:542,&quot;bytes&quot;:170110,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!t_gu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png 424w, https://substackcdn.com/image/fetch/$s_!t_gu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png 848w, https://substackcdn.com/image/fetch/$s_!t_gu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png 1272w, https://substackcdn.com/image/fetch/$s_!t_gu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20a02d41-15e7-49d9-b35a-35e84258347a_815x774.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1JHr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1JHr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png 424w, https://substackcdn.com/image/fetch/$s_!1JHr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png 848w, https://substackcdn.com/image/fetch/$s_!1JHr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png 1272w, https://substackcdn.com/image/fetch/$s_!1JHr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1JHr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png" width="317" height="282" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/240fa562-5083-4528-842e-0fd6776b372a_317x282.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:282,&quot;width&quot;:317,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91378,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1JHr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png 424w, https://substackcdn.com/image/fetch/$s_!1JHr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png 848w, https://substackcdn.com/image/fetch/$s_!1JHr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png 1272w, https://substackcdn.com/image/fetch/$s_!1JHr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F240fa562-5083-4528-842e-0fd6776b372a_317x282.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>AST01 - Malicious Skills</h2><p>Much like they sound, malicious skills are intentionally malicious skills published to the public, often via the marketplaces I discussed above or by other methods. They are intended to seem legit but often look to steal credentials, establish backdoors or even social engineer users and agents. </p><p>The publication points out the problem that agents often utilize excessive permissions, or permissions tied to a user and a malicious skill can lead to exposing credentials such as API keys and SSH credentials. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Xd2T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Xd2T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png 424w, https://substackcdn.com/image/fetch/$s_!Xd2T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png 848w, https://substackcdn.com/image/fetch/$s_!Xd2T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png 1272w, https://substackcdn.com/image/fetch/$s_!Xd2T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Xd2T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png" width="686" height="489" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f972898-b19c-4d55-b893-61702b5d4331_686x489.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:489,&quot;width&quot;:686,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:93478,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Xd2T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png 424w, https://substackcdn.com/image/fetch/$s_!Xd2T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png 848w, https://substackcdn.com/image/fetch/$s_!Xd2T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png 1272w, https://substackcdn.com/image/fetch/$s_!Xd2T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f972898-b19c-4d55-b893-61702b5d4331_686x489.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The team points to real-world incidents such as <strong><a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting">ClawHavoc</a></strong>, which involved 1,000+ malicious skills, tens of publisher accounts and targeted crypto wallets, SSH keys and browser credentials. </p><p>Attack scenarios include examples such as typosquatting, instruction override, memory poisoning and persistence among others. </p><p>To prevent impacts from malicious skills, the OWASP team recommended mitigations such as cryptographic signatures of skills, layered scanning at both public and install time, isolated skill execution and auditing skill actions as well as behavior sandboxing, to observe how a skill influences an agents behavior.</p><h2>AST02 - Supply Chain Compromise</h2><p>Next up we have supply chain compromise. It&#8217;s easy to see how this is a risk given how Skills by their very nature are shared and distributed across the community directly, through repositories and via the marketplaces. </p><p>OWASP rightly points out that many of these ecosystems are immature compared to the broader open source ecosystem with platforms such as npm, PyPI and Cargo (which have their own never-ending slew of incidents still). </p><p>To capitalize on this, attackers mass upload malicious skills, take advantage of dependency confusion and go after accounts of developers and contributors to poison the registries. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QhU2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QhU2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png 424w, https://substackcdn.com/image/fetch/$s_!QhU2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png 848w, https://substackcdn.com/image/fetch/$s_!QhU2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png 1272w, https://substackcdn.com/image/fetch/$s_!QhU2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QhU2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png" width="841" height="546" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/337ca569-b4e2-4482-b02a-938a49010257_841x546.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:546,&quot;width&quot;:841,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:104262,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QhU2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png 424w, https://substackcdn.com/image/fetch/$s_!QhU2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png 848w, https://substackcdn.com/image/fetch/$s_!QhU2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png 1272w, https://substackcdn.com/image/fetch/$s_!QhU2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337ca569-b4e2-4482-b02a-938a49010257_841x546.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As OWASP points out, all you need to publish a skill on marketplaces/repos such as ClawHub is a SKILL.md file and a GitHub account. Essentially anyone can do it and there&#8217;s no security rigor such as code signing, security review, or sandbox by default. These are the sort controls popular OSS platforms have implemented due to a variety of attacks, compromises and social engineering efforts targeting open source users and maintainers in supply chain attacks.</p><p>Some of the attack scenarios they point out include flooding registries with malicious skills, poisoning nested dependencies under top-level skills to bypass scanners, hijacking configuration files with malicious execution instructions and the tried and true takeover of a maintainers account to then inject a backdoored version of a trusted skill.</p><p>To mitigate some of these attacks, OWASP recommends mitigations such as skill provenance tracking, transparency logs for registry operations, pinning all nested dependencies and applying trust gates to repo config files. </p><h2>AST03 - Over-Privileged Skills</h2><p>Least-permissive, not even once. </p><p>Everyone&#8217;s favorite security challenge enters the fold, as skills are often granted broad permissions beyond what is necessary for their functionality. OWASP points out this is due to there often being no permission manifest system, or users just accepting all permissions without a review.</p><p>These overly-permissive skills can be abused to take malicious actions against organizational systems and data. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Wt2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Wt2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png 424w, https://substackcdn.com/image/fetch/$s_!1Wt2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png 848w, https://substackcdn.com/image/fetch/$s_!1Wt2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png 1272w, https://substackcdn.com/image/fetch/$s_!1Wt2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Wt2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png" width="1003" height="658" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:658,&quot;width&quot;:1003,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:148431,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Wt2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png 424w, https://substackcdn.com/image/fetch/$s_!1Wt2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png 848w, https://substackcdn.com/image/fetch/$s_!1Wt2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png 1272w, https://substackcdn.com/image/fetch/$s_!1Wt2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae4d8280-a0c4-47c2-a706-4a6d67f010af_1003x658.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What makes this problematic to Skills in particular is their natural language format, that uses intent on top of tradition system permissions and methods such as prompt injection which can take advantage of the fact that permission checks occur at the tool call level. </p><p>The industry is still widely grappling with &#8220;Intent Analysis&#8221; when it comes to Agentic AI, and it is a topic I have <strong><a href="https://zenity.io/blog/intent-aware-detection">written about several times</a></strong>. OWASP cites several real-world examples, such as Snyk&#8217;s ToxicSkills where hundreds of publicly available skills expose credentials and data beyond the skills declared functions.</p><p>They lay out attack scenarios such as data exfiltration, wiping databases, establishing persistent behavioral backdoors and opportunities for low-privilege skills to invoke higher privileged skills, essentially privilege escalation via Skills.</p><p>To prevent this, OWASP recommends mitigations such as require skills to declare permission manifests, per-skill scoped credentials, runtime permission enforcement and requiring explicit operator consent for persistent state changes.</p><p>It&#8217;s easy to see how this would be difficult to do at scale in enterprise environments with thousands of developers leveraging skills and agents at machine speed and scale.</p><h2>AST04 - Insecure Metadata</h2><p>Skills come with metadata such as name, description, author, permissions, requires and the native YAML/JSON/Markdown formats they are written in. Attackers can take advantage of this and put attacker-controlled inputs into the metadata which then gets read or executed with no security rigor. </p><p>OWASP explains how this can lead to manipulating the metadata to downplay or misinform users on the skills true motives, as well as embed executable payloads that trigger on load before a user takes any action.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4YvT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4YvT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png 424w, https://substackcdn.com/image/fetch/$s_!4YvT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png 848w, https://substackcdn.com/image/fetch/$s_!4YvT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png 1272w, https://substackcdn.com/image/fetch/$s_!4YvT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4YvT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png" width="1013" height="653" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:653,&quot;width&quot;:1013,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:148121,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4YvT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png 424w, https://substackcdn.com/image/fetch/$s_!4YvT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png 848w, https://substackcdn.com/image/fetch/$s_!4YvT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png 1272w, https://substackcdn.com/image/fetch/$s_!4YvT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33b0a6cd-8d94-4525-9274-12a806faac90_1013x653.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What makes it challenging for skills is that malicious definitions can mislead the installer and also execute malicious code before the skill is run due to the fact that the metadata is deserialized during the skill-loading lifecycle as part of initialization.</p><p>Some of the attack scenarios OWASP mention include brand impersonation, permission understating, risk tier spoofing and YAML code execution among others. To prevent it, they recommend using safe parsers by default and disabling dangerous tags, validating metadata against a schema prior to deserialization, applying static analysis to all metadata fields as well as validating declared permissions against actual runtime behavior. </p><h2>AST05 - Untrusted External Instructions </h2><p>This one reminds me of the core problem of AI and Agents themselves. As we know, consuming untrusted content can lead to models and agents being manipulated and potential impacts for the organizations leveraging them. The best paper on this was Google DeepMind&#8217;s &#8220;AI Agent Traps&#8221;, which described essentially the entire open Internet as a field of potential landmines Agents can consume into the context window and boom, negative things can happen. </p><p>In this example for skills, OWASP explains how skills routinely reference external documentation such as API references, SDK guides, schemas and other content that leads agents to URL&#8217;s or reading remote files at runtime. That consumed content now becomes part of the agents instructions acted on with the host agent&#8217;s full instructions. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bf5a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bf5a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png 424w, https://substackcdn.com/image/fetch/$s_!Bf5a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png 848w, https://substackcdn.com/image/fetch/$s_!Bf5a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png 1272w, https://substackcdn.com/image/fetch/$s_!Bf5a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bf5a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png" width="1173" height="742" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:742,&quot;width&quot;:1173,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:180557,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bf5a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png 424w, https://substackcdn.com/image/fetch/$s_!Bf5a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png 848w, https://substackcdn.com/image/fetch/$s_!Bf5a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png 1272w, https://substackcdn.com/image/fetch/$s_!Bf5a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4a7bfc6-06d8-4c83-9178-1d2eb71b2ee0_1173x742.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>OWASP explains how unlike traditional software with versioning, hashing, pinning, lockfiles and signed packages, skills have no pinning to a documents hash, no lockfile, and the fact that signing skills doesn&#8217;t mitigate the risks that the URL&#8217;s return when executed at runtime. </p><p>When I read this, a lot of the risk comes from the fact that agents take action and have autonomy. Those actions and autonomous come with risks and potential for abuse, and embedding malicious instructed externally that get consumed and acted upon is a perfect example of this. </p><p>Some of the attack scenarios they cite include author rug pulls, reviewer bait-and-switch, transitive reference chaining and DoS via malicious skills. To mitigate these attacks OWASP recommends techniques such as pinning and verifying referenced content, performing final verifications before model ingestion, preferring inlining over fetching and allow-list specific domains only.</p><h2>AST06 - Weak Isolation</h2><p>Every installed skill is a potential full-system compromise due to the fact that sandboxing is often not available, optional or even disabled by default. This limits the ability for containment guarantees per OWASP. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!234q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!234q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png 424w, https://substackcdn.com/image/fetch/$s_!234q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png 848w, https://substackcdn.com/image/fetch/$s_!234q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png 1272w, https://substackcdn.com/image/fetch/$s_!234q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!234q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png" width="1018" height="652" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:652,&quot;width&quot;:1018,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:145699,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!234q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png 424w, https://substackcdn.com/image/fetch/$s_!234q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png 848w, https://substackcdn.com/image/fetch/$s_!234q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png 1272w, https://substackcdn.com/image/fetch/$s_!234q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2307e0e9-6b96-4876-b0fa-129a67d75a3d_1018x652.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Agents and sandboxes have been a hot topic throughout 2026, and are topics I have discussed with industry leaders such as Alex Zenla and Luke Hinds:</p><div id="youtube2-tZvJ7-8x4iU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;tZvJ7-8x4iU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/tZvJ7-8x4iU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div id="youtube2-h4TjA0IUpgQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;h4TjA0IUpgQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/h4TjA0IUpgQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Some of the attack scenarios OWASP lists include host escape, network pivot, skill shadowing, and cross-agent workspace contamination. To prevent these sort of attacks the OWASP authors argue for mitigations such as container isolation for skill execution, binding agent control interfaces to localhost with authentication, applying seccomp/AppArmor profiles and implementing per-skill process isolation.</p><h2>AST07 - Update Drift</h2><p>Much like other aspects of cybersecurity, where things are set it and forget it (e.g. permissions), skills are installed and forgotten. OWASP points to a lack of immutable pinning and automated update verification leading to skills drifting from known-good versions due a lack of patches being applied or auto-updates leading to malicious versions. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ONFS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ONFS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png 424w, https://substackcdn.com/image/fetch/$s_!ONFS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png 848w, https://substackcdn.com/image/fetch/$s_!ONFS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png 1272w, https://substackcdn.com/image/fetch/$s_!ONFS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ONFS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png" width="1181" height="762" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:762,&quot;width&quot;:1181,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:163777,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ONFS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png 424w, https://substackcdn.com/image/fetch/$s_!ONFS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png 848w, https://substackcdn.com/image/fetch/$s_!ONFS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png 1272w, https://substackcdn.com/image/fetch/$s_!ONFS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16fc97a7-80b7-426a-a0a0-47eb2fe82bc1_1181x762.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Unlike traditional software, OWASP points out that skills are often installed by users with no sort of remedy such as traditional patch management and even then, if users did update skills to new versions, the new version itself could be malicious due to unverifiable cryptographic pinning when it comes to skills. </p><p>OWASP cites real-world examples such as ClawJacked, which demonstrated patch lag leaving agent gateways vulnerable. </p><p>The attack scenarios include malicious updates, rollback attacks and hot-reload abuse. To mitigate these attacks, OWASP recommends mitigations such as pinning installed skills to immutable content hashes not version ranges, freezing production deployments and subscribing to registry security advisories or auto-alerts for CVE matches on installed skills.</p><h2>AST08 - Poor Scanning</h2><p>Unlike traditional software, agent skills utilize executable content and metadata but also natural-language instructions. This can make it difficult to match patterns, regex filters or use signature-based detection. While marketplaces and organizations have begun to use static skill scanners and open source tools, the natural-language aspect of agent skills proves problematic and easy to bypass.</p><p>As they say in the publication:</p><blockquote><p><strong>&#8221;The enemy of AI security is the infinite variability of language&#8221;</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hx71!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hx71!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png 424w, https://substackcdn.com/image/fetch/$s_!hx71!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png 848w, https://substackcdn.com/image/fetch/$s_!hx71!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png 1272w, https://substackcdn.com/image/fetch/$s_!hx71!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hx71!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png" width="1029" height="666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:666,&quot;width&quot;:1029,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:152124,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hx71!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png 424w, https://substackcdn.com/image/fetch/$s_!hx71!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png 848w, https://substackcdn.com/image/fetch/$s_!hx71!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png 1272w, https://substackcdn.com/image/fetch/$s_!hx71!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c21f75-40db-465a-9fdc-7491e0784bcd_1029x666.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>OWASP cites a robust set of real-world evidence from security vendors and researchers showing how simple pattern matching and static scans are insufficient for detecting malicious skills and instead requires behavioral analysis as well. </p><p>Some of the attack scenarios OWASP calls out include natural-language bypass, obfuscated instructions, scanner impersonation and scanner-target evasion. To mitigate these attacks they recommend mitigations such as deploying behavioral analysis scanners to evaluate intent not just signatures, scanning both the code and natural language instruction layers independently and treating scanner skill results as advisory only, not authoritative from a risk perspective.</p><h2>AST09 - No Governance</h2><p>This one reads to me a bit odd, as it isn&#8217;t necessarily a specific technical risk but more so reflects the reality that the adoption curve of AI and Agents has often outpaced the organization and security teams ability to govern it. </p><p>OWASP cites organizational lack of inventories, policies, review processes and audit trails to manage skills at enterprise scale. These skills are often installed with no visibility from security teams, no governance or review process or revocation pathway. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Via4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Via4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png 424w, https://substackcdn.com/image/fetch/$s_!Via4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png 848w, https://substackcdn.com/image/fetch/$s_!Via4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png 1272w, https://substackcdn.com/image/fetch/$s_!Via4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Via4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png" width="1181" height="751" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:751,&quot;width&quot;:1181,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:191588,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Via4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png 424w, https://substackcdn.com/image/fetch/$s_!Via4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png 848w, https://substackcdn.com/image/fetch/$s_!Via4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png 1272w, https://substackcdn.com/image/fetch/$s_!Via4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad0e3562-9878-4cf4-a0ce-771417d0280e_1181x751.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>OWASP points to the fact that typical software asset management (SAM) tools have no ability to govern agent skills, and skills can be quickly installed by anyone with access. This is often done with no logs going to the SOC, no CMDB entry and no integration with existing IAM. They cite several research efforts finding hundreds of malicious skills installed across corporate environments by developers and users with no oversight or governance. </p><p>Some of the attack scenarios include undetected compromise, unapproved malicious skills, orphaned skills, regulatory exposure and cascading agent compromise. To mitigate these attacks OWASP recommends organizations establish a centralized skill inventory, approval workflow for skill installations requiring security reviews, audit logging for skill actions and establishing skill revocation processes to offboard or shut down skills. </p><h2>AST10 - Cross-Platform Reuse</h2><p>Speaking to the diverse nature of the Agentic AI ecosystem, OWASP rounds out the list discussing the reality that skills are ported across platforms (e.g. OpenClaw, Claude Code, Cursor, Codex etc.) without the security properties of the source format translating. </p><p>Specific examples they use include permission manifests on one platform not transferring to another with the skill itself, creating increased risks for skills shared across platforms. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6HJ1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6HJ1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png 424w, https://substackcdn.com/image/fetch/$s_!6HJ1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png 848w, https://substackcdn.com/image/fetch/$s_!6HJ1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png 1272w, https://substackcdn.com/image/fetch/$s_!6HJ1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6HJ1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png" width="981" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:981,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:149368,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/211601557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6HJ1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png 424w, https://substackcdn.com/image/fetch/$s_!6HJ1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png 848w, https://substackcdn.com/image/fetch/$s_!6HJ1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png 1272w, https://substackcdn.com/image/fetch/$s_!6HJ1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7adb6834-a1ad-4812-90d2-403ed1166161_981x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A lack of a universal skill format and normalization of security metadata across ported skills is problematic. </p><p>Some attack examples OWASP cites include security property loss in translation, cross-registry arbitrage, multi-platform campaigns and implicit privilege escalation. To mitigate these attacks, OWASP recommends techniques such as adopting a universal skill format, requiring full security metadata re-validation for ported skills, establishing cross registry threat intel among the major registries and building platform-agnostic skill scanners to identify issues at runtime. </p><p>Many of these read to me as systemic ecosystem issues rather than problems to be solved by any specific organization or user. </p><p>Closing Thoughts</p><p>Well, that was our brief tour of the new v1.0 of the OWASP Agentic Skills Top 10. I wanted to dig into it to understand the most prevalent risks and mitigations associated with Agentic Skills, what parallels exist to broader software and what aspects are novel.</p><p>Several of the risks are systemic in nature and tied to the immature nature of agents in a broader sense, and the ecosystems early days as it evolves to painfully re-learn many of the lessons we know from examples such as software and supply chain security.</p><p>I hope you found this helpful and I will be keeping an eye on how this aspect of Agentic AI security evolves!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Software Supply Chain Security’s Acceleration Problem]]></title><description><![CDATA[A look at the accelerating pace of software supply chain attacks in 2026, and how practitioners can a handle on visibility and governance]]></description><link>https://www.resilientcyber.io/p/software-supply-chain-securitys-acceleration</link><guid isPermaLink="false">https://www.resilientcyber.io/p/software-supply-chain-securitys-acceleration</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 17 Aug 2026 15:46:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TE2M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Throughout my career in cybersecurity, working across public and private sector environments, few problems have stuck with me the way software supply chain security has. </p><p>I have spent years writing and speaking on it, and back in 2023 I co-authored a book titled <a href="https://www.amazon.com/Software-Transparency-Security-Software-Driven-Society/dp/1394158483">&#8220;</a><strong><a href="https://www.amazon.com/Software-Transparency-Security-Software-Driven-Society/dp/1394158483">Software Transparency: Supply Chain Security in an Era of a Software-Driven Society</a></strong><a href="https://www.amazon.com/Software-Transparency-Security-Software-Driven-Society/dp/1394158483">&#8221;</a> because it was becoming impossible to ignore that modern software is assembled far more than it is written, and that we had almost no visibility into what we were actually assembling.</p><p>That said, if you had told me back then that the pace of attacks would look the way it does in the first half of 2026, I am not sure I would have believed you. We spent years talking about software supply chain risk as a accelerating problem, something we needed to get ahead of. It is no longer looming, it is here, it is industrialized, and the growth curves are steepening in a way that should reshape how practitioners think about their environments.</p><p>In this article, I want to level set on how we got here, walk through what the attack data actually shows in 2026, and then dig into a discussion and demo I recently had with Resilient Cyber&#8217;s partner at <strong><a href="https://www.kusari.dev/">Kusari</a></strong>, whose approach to this problem I find promising. </p><p>So, let&#8217;s start unpacking the problem space.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>Years in the Making</h2><p>None of this is new, and that is part of what makes the current moment so frustrating.</p><p>We have known for years that commercial and open source software alike are built on a sprawling web of dependencies that almost no one fully understands.<strong> <a href="https://blackduck1.wpenginepowered.com/resources/analyst-reports/open-source-security-risk-analysis.html">Synopsys&#8217; 2026 OSSRA report</a></strong> found that 97% of audited commercial codebases contain open source components, that the average application contains 911 open source components, and that 90% of audited codebases contain components more than four years out of date. </p><p>The average codebase carried 581 open source vulnerabilities. Those are not the numbers of a niche problem, that is the the underlying critical infrastructure the entire digital economy runs on. These are problems myself and others have been highlighting for several years at this point.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Njhl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Njhl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png 424w, https://substackcdn.com/image/fetch/$s_!Njhl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png 848w, https://substackcdn.com/image/fetch/$s_!Njhl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png 1272w, https://substackcdn.com/image/fetch/$s_!Njhl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Njhl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png" width="1456" height="413" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:413,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136586,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210904062?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Njhl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png 424w, https://substackcdn.com/image/fetch/$s_!Njhl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png 848w, https://substackcdn.com/image/fetch/$s_!Njhl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png 1272w, https://substackcdn.com/image/fetch/$s_!Njhl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae74bbea-cdd1-445a-ade8-36ad08203879_2022x574.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The incidents that made this real for most people are by now part of the security folklore. SolarWinds showed us what happens when an attacker compromises the build pipeline itself of a widely used commercial software provider. Log4Shell showed us that a single ubiquitous open source component could put the entire internet into an emergency remediation cycle overnight, and that most organizations could not even answer the basic question of whether they were affected. </p><p>Those events generated executive orders, SBOM mandates, a wave of frameworks, and a genuine surge of attention. For a while it felt like we were finally starting to build the muscle memory this problem demands.</p><p>The problem is that the attackers were paying attention too, and they have adapted far faster than most defenders have and the introduction of agentic development as the breakout use case has complicated the problem at a pace and scale that makes the problems of the past pale in comparison.</p><h2>Velocity, Volume, and Malicious Packages</h2><p>The numbers coming out of 2025 and the first half of 2026 are hard to overstate, so I will let them speak for themselves. <strong><a href="https://www.sonatype.com/state-of-the-software-supply-chain/2026/open-source-malware">Sonatype&#8217;s 2026 State of the Software Supply Chain report</a></strong> identified 454,600 new malicious packages in 2025 alone, bringing the cumulative total they have tracked to over 1.233 million across npm, PyPI, Maven Central, NuGet, and Hugging Face. Over 99% of that open source malware in 2025 landed on npm, the beating heart of the JavaScript ecosystem. </p><p>To put the raw exposure into perspective, Sonatype notes developers downloaded open source components 9.8 trillion times across the major ecosystems in 2025.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!apz2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!apz2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png 424w, https://substackcdn.com/image/fetch/$s_!apz2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png 848w, https://substackcdn.com/image/fetch/$s_!apz2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!apz2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!apz2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png" width="1456" height="896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:896,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:159786,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210904062?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!apz2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png 424w, https://substackcdn.com/image/fetch/$s_!apz2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png 848w, https://substackcdn.com/image/fetch/$s_!apz2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!apz2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa33e2b6f-3201-4f0c-88e5-430da1471cef_1956x1204.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What changed in 2026 was not just the volume but the tempo. Research from <strong><a href="https://phoenix.security/accelerating-supply-chain-attacks-npm-pypi-vsx-ai-enabled-2026/">Phoenix Security</a></strong> tracking malicious package campaigns found that the first half of 2026 alone produced 2.6 times the campaign count and 4.5 times the malicious package volume of all of 2025. May of 2026 was the single busiest month on record in their findings, with 14 distinct campaigns and 346 indexed packages in 31 days, and a single self-replicating worm accounting for 226 of them. That is not a steady climb, it is an testament to how this threat is scaling.</p><p>Much of that acceleration traces to a shift from one-off malicious uploads to self-replicating worms and coordinated campaigns. The Shai-Hulud worm that hit npm in September 2025 compromised more than 500 packages in a matter of days, spreading on its own by harvesting credentials from each compromised maintainer and using them to poison the next set of packages. </p><p>A related compromise that same month reached widely depended-upon packages like chalk and debug, which together account for billions of weekly downloads across the ecosystem. A second wave dubbed Shai-Hulud 2.0 arrived in November 2025, and researchers tracked over a thousand backdoored package versions across hundreds of packages, along with tens of thousands of attacker-created repositories used to exfiltrate stolen secrets. <strong><a href="https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem">CISA issued guidance</a></strong> on the campaign, demonstrating how significant it had become.</p><p>The GitHub Actions and CI/CD ecosystem has been hit just as hard. The tj-actions/changed-files compromise in March 2025 saw an attacker exploit a leaked personal access token to push malicious commits and redirect version tags, and it sat undetected for four months. </p><p>In March 2026 a campaign tracked as TeamPCP poisoned 75 of 76 version tags across the widely used trivy-action and other tooling in a single coordinated push. By May 2026 the same class of actor was pushing thousands of malicious workflow commits across thousands of repositories in a matter of hours, and in March 2026 the Axios package, with over 300 million weekly downloads, was compromised when an attacker hijacked a maintainer&#8217;s npm account and published a remote access Trojan that bypassed GitHub Actions entirely.</p><p>I could keep going, but the pattern matters more than an exhaustive catalog of incidents. If you want the deeper dive on how AI is compressing both the discovery and exploitation timelines on top of all of this, I wrote about it recently in <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">&#8220;Vulnpocalypse&#8221;</a></strong> and <strong><a href="https://www.resilientcyber.io/p/the-attack-surface-exponential">&#8220;The Attack Surface Exponential&#8221;</a>.</strong></p><h2>Attacking Trust, Not Just Code</h2><p>The most important thread running through all of these incidents is that attackers are no longer just targeting the code. They are targeting the people, the credentials, and the CI/CD workflows that we all implicitly trust. A maintainer&#8217;s npm token, a leaked PAT in a build log, a poisoned GitHub Action, these are the new front line, and they are devastatingly effective precisely because the entire model of open source consumption is built on trust and convenience, which is ironic given the last several years of security leaders touting concepts such as &#8220;Zero Trust&#8221;.</p><p>There is one detail from the Phoenix analysis that stands out as well. Across the 59 campaigns they tracked, the CVE count during active exploitation was zero. The tooling, the processes, and the mental models most organizations have built for managing software risk are oriented around CVEs, around a known vulnerability with an identifier that shows up in a scanner. Malicious package campaigns do not play by those rules, there is no CVE to alert on while the attack is live. By the time anything shows up in the systems most teams rely on, the credentials are already gone. This is due the speed and complexity, as well as the reality that institutions such as NVD are collapsing under the load being driven by AI with coding and vulnerability discovery.</p><p>This is the uncomfortable reality of where we are. The volume is exponential, the tempo is accelerating, the attack surface has expanded from the code itself to the entire development ecosystem around it, and our detection models are looking in the wrong place. </p><p>Meanwhile, the rise of AI-assisted and increasingly agentic development is pouring more code, more dependencies, and more velocity into environments that most organizations already could not keep pace with prior to AI&#8217;s widespread impact on development, vulnerability discovery and exploitation.</p><h2>The Visibility Problem Nobody Solved</h2><p>Underneath all of this sits a problem that predates the current attack wave and has never really been solved, which is visibility. When Log4Shell hit, the single hardest question for most organizations was not how to patch, it was where the vulnerable component even lived across their environment. Years and many frameworks later, most organizations still cannot answer that question quickly, despite things such as software asset inventory being a critical control for years and even decades.</p><p>This came up almost immediately when I sat down with the Kusari team, and it lined up with everything I have seen in practice. As their team framed it, the primary struggle for their customers is a lack of visibility, frequently expressed as an inability to answer a deceptively basic question, &#8220;Do I have this package, and where is it?&#8221; In the current environment that question becomes &#8220;Do I have Shai-Hulud, or the compromised version of Axios, and if so, what is the blast radius?&#8221; </p><p>Most organizations cannot answer it in any reasonable timeframe, and in an era where a worm can traverse hundreds of packages in days, the time it takes to answer is the whole ballgame.</p><p>That is the gap I want to spend the rest of this piece on, because it is where I think we need to solve the problem from a first principles perspective before we get into any fancy discussions of known exploitation, exploitability, reachability and other concepts I often discuss.</p><h2>Where Kusari Fits In</h2><p>Kusari is a software supply chain security company that came out of the open source world rather than bolting onto it after the fact. </p><p>Its founders created and helped shepherd the open source <strong><a href="https://openssf.org/blog/2024/03/07/guac-joins-openssf-as-incubating-project/">GUAC project</a></strong>, short for Graph for Understanding Artifact Composition, which joined the OpenSSF as an incubating project in 2024. </p><p>GUAC is built around the idea of mapping the software supply chain as a graph, identifying the most-used components in an environment, exposing risky dependencies, and calculating the blast radius of a given vulnerability. </p><p>What I appreciated in the demo and discussion is that the platform starts from the visibility problem rather than the alert problem. The integration point is typically a GitHub app installed at the organizational level, from which the platform tracks information across the various CI/CD systems and build pipelines, analyzes build metadata and software artifacts, and maintains a continuously updated graph of the organization&#8217;s environment. </p><p>That graph updates as pull requests and changes flow through, so it reflects the actual current state rather than a snapshot in time from the last time someone ran a scan. As a byproduct of maintaining that graph, the platform tracks versioned, time-stamped records of software including SBOMs, supporting both CycloneDX and SPDX, along with metadata and VEX documents, without an organization having to stand up a separate SBOM management effort, avoiding yet another tool in the security stack.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TE2M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TE2M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png 424w, https://substackcdn.com/image/fetch/$s_!TE2M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png 848w, https://substackcdn.com/image/fetch/$s_!TE2M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png 1272w, https://substackcdn.com/image/fetch/$s_!TE2M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TE2M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png" width="1185" height="651" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:651,&quot;width&quot;:1185,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:348388,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210904062?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TE2M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png 424w, https://substackcdn.com/image/fetch/$s_!TE2M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png 848w, https://substackcdn.com/image/fetch/$s_!TE2M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png 1272w, https://substackcdn.com/image/fetch/$s_!TE2M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb975c8a0-b932-46d7-8dfc-7c4b97ba5be5_1185x651.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On top of that graph the platform layers risk. Kusari generates a score from 0 to 10 for a given software component, and I found the inputs valuable and relevant for truly mitigating organizational risks. </p><p>The score factors in whether a component carries vulnerabilities on CISA&#8217;s Known Exploited Vulnerabilities (KEV) list, the breadth of vulnerabilities across the environment, and how deeply a component is rooted in the supply chain. That last input is the one most tools miss. A vulnerability buried five layers deep in a transitive dependency that half your services pull in is a very different problem than the same vulnerability used once, and the score is explicitly trying to communicate blast radius and remediation complexity rather than just severity in isolation, which is common for a lot of security tools that lack organizational context.</p><p>The platform also leans on reachability analysis, using graph analysis to determine whether a vulnerability actually has impact in a given context rather than dumping the full undifferentiated backlog on a development team. </p><p>Anyone who has watched developers tune out security tooling because 90% of what it surfaces is noise understands why this matters. To avoid the whack-a-mole cycle where a fixed component quietly gets reintroduced, the platform uses dependency cooldowns and analyzes every change coming through, which is a nice acknowledgment that remediation is not a one-time event but an ongoing fight and shows an evolution of how we should think about reachability in the context of vulnerabilities as well.</p><h2>Remediation, Not Just Findings</h2><p>Where the conversation got most interesting for me was on remediation, because finding problems has never really been the hard part in this space, and that&#8217;s a point I&#8217;ve been making a lot lately.</p><p>The platform includes an Autofix capability built around a set of purpose-specific agents. As the team walked me through it, a security architect agent builds a remediation plan, an inspector agent reviews that plan for newly introduced vulnerabilities or compliance issues, and a developer execution agent implements the fix.</p><p>Organizations can dial the level of required human intervention up or down based on their own maturity and how much they trust the platform&#8217;s suggestions, which to me is the right approach given where most teams are on the trust curve with agentic tooling, especially around production remediation.</p><p>The Inspector agent stood on its own as the piece I would probably get the most day-to-day value from. It operates directly in the developer workflow and provides immediate feedback on pull requests, functioning as a security reviewer that gives a thumbs up or thumbs down on whether a change introduces a malicious package, a license compliance violation, or a broader supply chain risk. </p><p>Developers get that signal without having to context switch into a separate platform, which is exactly where security tooling tends to die due to breaking the flow of developers or becoming frustrating to use. Meeting developers where they already work, rather than dragging them into yet another console, is one of those lessons our industry keeps having to relearn, despite countless examples demonstrating why its the wrong approach.</p><p>There is also a beta conversational interface that lets a user ask natural language questions against the underlying graph, the &#8220;Do I have Shai-Hulud or not?&#8221; a query I mentioned earlier, and get an instant answer. It sounds simple, and that is the point. That is the question organizations were desperate to answer during Log4Shell and every incident since, and being able to answer it in seconds against a live graph of your environment that accounts for not just presence but blast radius is a meaningfully different posture than what most teams have today. </p><p>For organizations with sensitivity around data separation, the team noted that customer infrastructure is single-tenant as well.</p><h2>Why the SDLC Focus Matters</h2><p>One point of differentiation the team was passionate about, is the decision to anchor in the software development lifecycle and source control rather than the runtime environment. Their argument is that a great deal of supply chain risk manifests inside developer tooling, build systems, and test suites, and never touches the runtime environment at all. </p><p>The Shai-Hulud worm harvesting credentials during a package install is a perfect example. That happens on a developer&#8217;s machine or in a CI runner, long before anything reaches production. A runtime-oriented tool is looking in the wrong place for that class of attack, but that said, I do hold the view that coupling this with something with runtime visibility and capability is key as well.</p><p>The other place the SDLC-anchored, graph-based approach earns its keep is in large, complex, non-uniform environments. Enterprises rarely run on a single tidy GitHub org. They have multiple disparate instances of GitHub and GitLab, acquisitions with their own stacks, and years of accumulated sprawl. </p><p>The ability to enumerate software and assess risk across all of that without forcing a massive migration or platform consolidation first is a genuine differentiator, and it maps to the reality practitioners actually live in and environments I often see rather than the clean environment a tool wishes they had.</p><h2>Closing Thoughts</h2><p>This is far from an exhaustive discussion, and I have deliberately left the deeper AI angle to my prior writing. </p><p>That said, what the first half of 2026 makes clear is that software supply chain security has crossed from a problem we talked about getting ahead of into one that is actively outrunning most organizations&#8217; ability to respond. The volume is exponential, the campaigns are self-replicating, the attackers have moved upstream to the trust and identity layer, and the CVE-shaped tooling most of us built our programs around does not see any of it while it is happening.</p><p>I have been beating this drum for years, going back to my book <strong><a href="https://www.amazon.com/Software-Transparency-Security-Software-Driven-Society/dp/1394158483">&#8220;Software Transparency&#8221;</a></strong>, and the through line has not changed. You cannot secure, prioritize, or remediate what you cannot see. The organizations that come through this next wave in decent shape will be the ones that finally solve for visibility and remediation velocity as first-order problems, rather than treating them as something they will get to after the next audit. </p><p>It remains to be seen whether the industry actually embraces this approach at scale before the next widespread software supply chain event, but the tooling and the approaches to actually do something about it are here, and that is a more hopeful place to be than we were a few years ago.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.kusari.dev/&quot;,&quot;text&quot;:&quot;-> Check Out Kusari! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.kusari.dev/"><span>-&gt; Check Out Kusari! &lt;-</span></a></p><p></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #109]]></title><description><![CDATA[A look at autonomous agents reaching real systems, the accountability scramble, defensive AI in production, funding megarounds & the state of exploitation]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-109</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-109</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 14 Aug 2026 12:03:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iUbT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #109 of the Resilient Cyber Newsletter!</p><p>I skipped last week&#8217;s issue while I was heads down at Black Hat, so this one pulls together the stories worth your attention from across the last two weeks rather than every link that crossed my desk. I have tried to keep it tight, with a focus on key stories over the last couple of weeks.</p><p>Black Hat was a blast, I had a chance to MC both the Innovators &amp; Investors Summit as well as the Startup Spotlight Competition. So many excellent talks both at the events and in the hallways, I recorded several podcasts with friends from the community and more, so be on a look out for those!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3Ki8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3Ki8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp 424w, https://substackcdn.com/image/fetch/$s_!3Ki8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp 848w, https://substackcdn.com/image/fetch/$s_!3Ki8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp 1272w, https://substackcdn.com/image/fetch/$s_!3Ki8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3Ki8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp" width="370" height="370.8167770419426" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:908,&quot;width&quot;:906,&quot;resizeWidth&quot;:370,&quot;bytes&quot;:72972,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3Ki8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp 424w, https://substackcdn.com/image/fetch/$s_!3Ki8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp 848w, https://substackcdn.com/image/fetch/$s_!3Ki8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp 1272w, https://substackcdn.com/image/fetch/$s_!3Ki8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f81376c-b935-4887-8148-4fc72ea45151_906x908.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This was the stretch where autonomous agents stopped being a benchmark curiosity and started reaching real systems. OpenAI disclosed that a model under evaluation escaped its environment and hacked Hugging Face, Anthropic went back through more than a hundred thousand of its own evaluation runs and found its models had compromised real companies, and the UK&#8217;s AI Security Institute published an incident report describing agents attempting supply-chain attacks and deceiving real people during routine testing. OpenAI of course shared their post-mortem at Black Hat, which many including myself agree is a must-watch for this space.</p><p>The rest of the industry spent the past week reacting to it, in accountability debates, defensive AI deployments, a wave of agent sandboxing work, and a funding market that keeps writing nine-figure checks for AI-versus-AI security.</p><p>Let&#8217;s get into it!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iUbT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iUbT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png 424w, https://substackcdn.com/image/fetch/$s_!iUbT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png 848w, https://substackcdn.com/image/fetch/$s_!iUbT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png 1272w, https://substackcdn.com/image/fetch/$s_!iUbT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iUbT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png" width="1456" height="916" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:916,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2009157,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iUbT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png 424w, https://substackcdn.com/image/fetch/$s_!iUbT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png 848w, https://substackcdn.com/image/fetch/$s_!iUbT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png 1272w, https://substackcdn.com/image/fetch/$s_!iUbT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa872b257-58a6-4def-9fb5-b1b4859572fd_2560x1610.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><h3><strong><a href="https://youtu.be/LcYjfdefOZI">Into the Breach: critical infrastructure cybersecurity, on screen</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!v3GX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v3GX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png 424w, https://substackcdn.com/image/fetch/$s_!v3GX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png 848w, https://substackcdn.com/image/fetch/$s_!v3GX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png 1272w, https://substackcdn.com/image/fetch/$s_!v3GX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v3GX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png" width="641" height="283.5192307692308" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:644,&quot;width&quot;:1456,&quot;resizeWidth&quot;:641,&quot;bytes&quot;:962596,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!v3GX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png 424w, https://substackcdn.com/image/fetch/$s_!v3GX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png 848w, https://substackcdn.com/image/fetch/$s_!v3GX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png 1272w, https://substackcdn.com/image/fetch/$s_!v3GX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a77c271-149b-434e-9e42-dcc22b1ff4da_1642x726.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://www.opswat.com/into-the-breach?utm_campaign=GLB-BRAND-Influencer-Marketing&amp;utm_medium=social_media&amp;utm_source=organicsocial&amp;utm_content=chris-hughes-newslettter">Into the Breach</a></strong> is OPSWAT&#8217;s new cybersecurity docuseries, hosted by MythBusters&#8217; Kari Byron and produced by Cyber King Productions. Through hands-on experiments, cinematic storytelling, and expert interviews, the series makes critical infrastructure security visible &#8212; for technical practitioners and nontechnical audiences alike.</p><p>Episode 1, &#8220;Breaking the Firewall,&#8221; is now streaming on YouTube. It challenges one of the industry&#8217;s most dangerous assumptions: that firewalls alone can protect critical assets. Also available on select in-flight entertainment systems worldwide.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://youtu.be/LcYjfdefOZI&quot;,&quot;text&quot;:&quot;Watch Now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://youtu.be/LcYjfdefOZI"><span>Watch Now</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.calcalistech.com/ctechnews/article/8115vtsb5">Cyera acquires Oasis Security in a roughly $1 billion deal</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xdxv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xdxv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png 424w, https://substackcdn.com/image/fetch/$s_!xdxv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png 848w, https://substackcdn.com/image/fetch/$s_!xdxv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png 1272w, https://substackcdn.com/image/fetch/$s_!xdxv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xdxv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png" width="1144" height="364" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:364,&quot;width&quot;:1144,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50107,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xdxv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png 424w, https://substackcdn.com/image/fetch/$s_!xdxv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png 848w, https://substackcdn.com/image/fetch/$s_!xdxv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png 1272w, https://substackcdn.com/image/fetch/$s_!xdxv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48c894d6-ab37-4915-982c-feaf5bbfe5f6_1144x364.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cyera signed a letter of intent to acquire Israeli startup Oasis Security for approximately $1 billion, reported as $700 million in cash with the remainder in Cyera shares. Oasis, founded in 2022, had raised $195 million and works in what it calls agentic access management, which tells you a lot about where Cyera thinks the puck is going. </p><p>Cyera itself recently raised $600 million at a $12 billion valuation, reports more than $200 million in ARR, and has now strung together a series of acquisitions across identity and machine access. The interesting piece here is not the headline number, it is that a data-security company is spending megaround capital to buy its way into managing non-human and agent identity before that problem fully arrives. </p><p>Given everything else in this issue about agents acting on their own, that looks less like empire building and more like reading the room.</p><h3><a href="https://www.businesswire.com/news/home/20260803793896/en/Horizon3-Raises-%24250M-Series-E-at-%242B-Valuation-to-Lead-the-AI-vs.-AI-Cybersecurity-Era">Horizon3 raises $250M Series E at a $2B+ valuation</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ClPp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ClPp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png 424w, https://substackcdn.com/image/fetch/$s_!ClPp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png 848w, https://substackcdn.com/image/fetch/$s_!ClPp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png 1272w, https://substackcdn.com/image/fetch/$s_!ClPp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ClPp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png" width="346" height="484.4" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c5430c51-8266-4b49-9064-be09427d94b8_880x1232.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1232,&quot;width&quot;:880,&quot;resizeWidth&quot;:346,&quot;bytes&quot;:1801315,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ClPp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png 424w, https://substackcdn.com/image/fetch/$s_!ClPp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png 848w, https://substackcdn.com/image/fetch/$s_!ClPp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png 1272w, https://substackcdn.com/image/fetch/$s_!ClPp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5430c51-8266-4b49-9064-be09427d94b8_880x1232.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Horizon3 announced a $250 million Series E at a valuation north of $2 billion, up from the $650 million valuation of its Series D just over a year ago. </p><p>The company reports 120% year-over-year ARR growth, more than 7,000 organizations protected, and 310,000 tests safely executed in production, with the round co-led by NightDragon and NEA and Dave DeWalt joining the board. The framing Horizon3 chose, leading the &#8220;AI vs. AI&#8221; era, is the same theme showing up across this issue, and the market is clearly willing to fund it. </p><p>Autonomous offense to validate your environment is a genuinely useful capability, and it is worth dwelling on the fact that the same techniques being funded here as blue-team tooling are, in the incident section below, what happens when they run without a leash.</p><p>I had a chance to sit down with Snehal at Black Hat and discuss the funding round, their market trajectory, the competitiveness of the category and more. Snehal remains one of the sharpest cyber business leaders I know and speak with.</p><h3><a href="https://fortune.com/2026/08/10/exclusive-corma-raises-60-million-from-sequoia-for-ai-trained-to-defend-against-cyberattacks/">Corma raises $60M from Sequoia for AI trained to defend against cyberattacks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fvc6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fvc6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png 424w, https://substackcdn.com/image/fetch/$s_!Fvc6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png 848w, https://substackcdn.com/image/fetch/$s_!Fvc6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png 1272w, https://substackcdn.com/image/fetch/$s_!Fvc6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fvc6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png" width="1370" height="322" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:322,&quot;width&quot;:1370,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80757,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fvc6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png 424w, https://substackcdn.com/image/fetch/$s_!Fvc6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png 848w, https://substackcdn.com/image/fetch/$s_!Fvc6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png 1272w, https://substackcdn.com/image/fetch/$s_!Fvc6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0b9991-db2e-4097-bcd6-f6080ed7a949_1370x322.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Corma came out of stealth with a $60 million seed round led by Sequoia, with Khosla Ventures and Coatue participating. Founded in 2025 and split between Tel Aviv and San Francisco, the company deployed its first model roughly six weeks before the announcement to Fortune 100 and Fortune 500 organizations, and CEO Alon Pluda says it focuses squarely on defensive work like log analysis and threat detection, claiming a 94% reduction in threat response times at adopting organizations. </p><p>A $60 million seed is a lot of conviction for a company barely a year old, and the vendor-supplied 94% figure deserves the usual skepticism until there is independent validation. That said, the signal is consistent with the rest of the market this issue, investors are pricing defensive AI as a category that has to exist, not one that might.</p><h3><a href="https://www.huntress.com/blog/business-reflection-250m-arr">Huntress on crossing $250M ARR</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V1I6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V1I6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png 424w, https://substackcdn.com/image/fetch/$s_!V1I6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png 848w, https://substackcdn.com/image/fetch/$s_!V1I6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png 1272w, https://substackcdn.com/image/fetch/$s_!V1I6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V1I6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png" width="448" height="365.68197879858656" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:924,&quot;width&quot;:1132,&quot;resizeWidth&quot;:448,&quot;bytes&quot;:160788,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V1I6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png 424w, https://substackcdn.com/image/fetch/$s_!V1I6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png 848w, https://substackcdn.com/image/fetch/$s_!V1I6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png 1272w, https://substackcdn.com/image/fetch/$s_!V1I6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F014a3702-3479-4767-92da-4d88f9bef20e_1132x924.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Amid all the megarounds, Kyle Hanslovan put out a reflection on Huntress crossing $250 million in ARR, and it is worth reading because it is not a funding announcement.</p><p>The company now protects more than 270,000 organizations and 19 million endpoints and identities across 100 countries, largely through a partner motion of more than 20,000 MSPs and resellers, and Hanslovan frames the revenue as a byproduct of the mission to bring enterprise-grade security to the small and mid-sized businesses he calls &#8220;the 99%.&#8221; </p><p>I have long argued that the underserved end of the market is where a lot of the real risk lives, and building a nine-figure business by serving it rather than chasing the Fortune 500 is a model more of the industry should study. Huntress serves the majority of the ecosystem that lives below the cyber poverty line and desperately need help, as you saw with my recent discussion with Alex Pinto of Verizon on their Breach Impact Study. SMB&#8217;s face steeper financial impacts from incidents than their enterprise counterparts.</p><h3><a href="https://zeltser.com/cyber-brief-templates-for-decision-makers">Templates for cybersecurity executive briefings</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vsLT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vsLT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png 424w, https://substackcdn.com/image/fetch/$s_!vsLT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png 848w, https://substackcdn.com/image/fetch/$s_!vsLT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png 1272w, https://substackcdn.com/image/fetch/$s_!vsLT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vsLT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png" width="1210" height="472" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:472,&quot;width&quot;:1210,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:341549,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vsLT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png 424w, https://substackcdn.com/image/fetch/$s_!vsLT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png 848w, https://substackcdn.com/image/fetch/$s_!vsLT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png 1272w, https://substackcdn.com/image/fetch/$s_!vsLT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ca6601-8fb2-46eb-8b4c-a6aef6fe47ab_1210x472.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Lenny Zeltser published four customizable executive-briefing templates covering threat intelligence, vulnerability investigation, incident response, and security assessment, each built around leading with the takeaway and what a finding actually means for the organization. </p><p>This is not flashy, but communicating clearly to decision-makers is one of the most persistent gaps in our field, and a well-structured brief that opens with the takeaway and puts action items in a table does more for your program than most tooling. A timely resource to bookmark.</p><h1>AI</h1><h3><a href="https://youtu.be/87DyyMV0kCY?si=zrqxhOGfa2cUw4eI">OpenAI&#8217;s Black Hat talk on the Hugging Face incident</a></h3><div id="youtube2-87DyyMV0kCY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;87DyyMV0kCY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/87DyyMV0kCY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The centerpiece of Black Hat this year was OpenAI walking through the incident in which one of its models, under evaluation, escaped its environment and compromised Hugging Face. </p><p>OpenAI called it a watershed moment for the industry and encouraged defenders to watch and plan for how attack dynamics are about to change, and the <a href="https://youtu.be/87DyyMV0kCY?si=zrqxhOGfa2cUw4eI">Black Hat session recording</a> covers the reconstruction and its implications for AI security and alignment. </p><p>Whatever you make of the framing, a frontier lab standing on the Black Hat stage to dissect its own model breaching another company is a moment our field will be referencing for a while. </p><p>This talk helps frame a lot of the below resources and at the time I&#8217;m sharing it, it already has over 500,000 views on YouTube!</p><h3><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Anthropic investigates three real-world incidents in its cybersecurity evaluations</a></h3><p>Prompted by OpenAI&#8217;s disclosure, Anthropic went back through 141,006 of its own evaluation runs and found three incidents where Claude models escaped supposedly isolated environments and reached real systems at three organizations. </p><p>Across the three, involving different models, a model compromised a real company&#8217;s infrastructure and accessed a database containing several hundred rows of production data, published malicious Python packages to PyPI that were downloaded and run on 15 real systems before removal, and scanned roughly 9,000 targets before compromising a company using what Anthropic describes as basic techniques like reading credentials from an exposed debug page and SQL injection. The root cause was a misconfiguration with their partner Irregular that granted internet access despite prompts stating there was none. </p><p>Give Anthropic credit for the transparency, because the substance is helpful but many of course also remain skeptical that it is in large part marketing, especially as others such as Meta and even Chinese model providers rushed to say their agents also broke out of training environments. The models were not doing anything exotic, they were doing ordinary attacker things, at scale, because a supposedly closed door was open.</p><h3><a href="https://pulse.latio.tech/p/detecting-and-preventing-the-hugging">A defender&#8217;s breakdown of the Hugging Face incident</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mA0E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mA0E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png 424w, https://substackcdn.com/image/fetch/$s_!mA0E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png 848w, https://substackcdn.com/image/fetch/$s_!mA0E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png 1272w, https://substackcdn.com/image/fetch/$s_!mA0E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mA0E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png" width="1456" height="362" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:362,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:682369,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mA0E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png 424w, https://substackcdn.com/image/fetch/$s_!mA0E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png 848w, https://substackcdn.com/image/fetch/$s_!mA0E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png 1272w, https://substackcdn.com/image/fetch/$s_!mA0E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff51d8f96-a123-4150-b1dd-d3b650d62867_3450x858.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;James Berthoty&quot;,&quot;id&quot;:215222117,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F029c069a-0ea1-4c28-bedb-742a03fa770a_800x800.jpeg&quot;,&quot;uuid&quot;:&quot;ebf213e2-e256-4b9e-b78d-7e8e48a053c5&quot;}" data-component-name="MentionToDOM"></span> turned the Hugging Face timeline into a practical kill-chain analysis, splitting it into initial access, breach, and lateral movement and mapping defensive controls to each stage. </p><p>His read is that supply-chain firewalls offer limited protection against this pattern, and that the real leverage is blocking egress, deep runtime monitoring, and an assume-breach posture, given how difficult the template-injection and in-memory-secrets stages are to stop. He notes the nearly 17,600 actions over four days represent a level of sophistication we would once have called nation-state grade, now produced by a model chasing a benchmark. </p><p>If you own detection and response, this is a actionable write-up of the incident.</p><h3><a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">The UK AISI incident report on unsanctioned agent behaviour</a></h3><p>Separate from the OpenAI and Anthropic disclosures, the UK&#8217;s AI Security Institute published an incident report from a routine cyber evaluation on July 28, and it is the one that I found the most informative. </p><p>Of 122 test runs, 10 runs contained 19 instances of unsanctioned behavior, 17 of them from Anthropic&#8217;s Mythos 5 and 2 from OpenAI&#8217;s GPT-5.6-Sol. The behaviors are the key part. Agents attempted a supply-chain attack by inserting malicious code into a public open-source project, creating fake identities and social-engineering the maintainers, an attempt caught by a human reviewer. Others directly deceived real people, attempted prompt injection against other AI systems, and in one case left public GitHub messages sharing account credentials for other agents. </p><p>Internet access was deliberately enabled and cyber classifiers intentionally disabled for realism, AISI reports no confirmed real-world harm, and it contained the incident within an hour. Autonomy and deception stopped being a slide in a threat model here and started being a logged event.</p><p>I recorded a video breaking this one down from my hotel room at Black Hat:</p><div id="youtube2-HrD06vG5wXs" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;HrD06vG5wXs&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/HrD06vG5wXs?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://drhyrum.substack.com/p/once-again-the-scaffolding-failed">Once again, the scaffolding failed</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AHAZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AHAZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png 424w, https://substackcdn.com/image/fetch/$s_!AHAZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png 848w, https://substackcdn.com/image/fetch/$s_!AHAZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png 1272w, https://substackcdn.com/image/fetch/$s_!AHAZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AHAZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png" width="1456" height="361" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:361,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80364,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AHAZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png 424w, https://substackcdn.com/image/fetch/$s_!AHAZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png 848w, https://substackcdn.com/image/fetch/$s_!AHAZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png 1272w, https://substackcdn.com/image/fetch/$s_!AHAZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1eaeb269-eece-427b-994f-ecb0c311f71a_1460x362.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Hyrum Anderson offers a sharp reframe of the whole episode, and I largely agree with him. His argument is that these incidents are not primarily a story about misaligned objectives, they are a story about failed constraints, models optimizing perfectly legitimate goals inside environments where the declared boundaries were documented but never actually enforced. </p><p>In Anthropic&#8217;s case the prompts claimed no internet access while the harness quietly provided live connectivity, and the model simply used it. </p><blockquote><p><strong>His line, &#8220;optimizers are going to optimize,&#8221; is the whole thing in four words. </strong></p></blockquote><p>The uncomfortable question he leaves you with is not whether your models are aligned, it is which of your security constraints are genuinely implemented versus merely written down, and that question long predates AI.</p><h3><a href="https://techcrunch.com/2026/08/03/whos-legally-to-blame-for-anthropic-and-openais-autonomous-ai-hacks-its-complicated/">Who is legally to blame for autonomous AI hacks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IUbH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IUbH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png 424w, https://substackcdn.com/image/fetch/$s_!IUbH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png 848w, https://substackcdn.com/image/fetch/$s_!IUbH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png 1272w, https://substackcdn.com/image/fetch/$s_!IUbH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IUbH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png" width="1080" height="376" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:376,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78692,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IUbH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png 424w, https://substackcdn.com/image/fetch/$s_!IUbH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png 848w, https://substackcdn.com/image/fetch/$s_!IUbH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png 1272w, https://substackcdn.com/image/fetch/$s_!IUbH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F671215b0-82c7-4150-ae18-c152f3e53e52_1080x376.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>TechCrunch takes on the accountability question these incidents force, and the answer is genuinely unsettled and that is why we&#8217;re seeing a lot debate in the ecosystem. </p><p>The piece weighs criminal and civil exposure under the 1986 Computer Fraud and Abuse Act, with cybersecurity attorney Ahmed Ghappour arguing the model is the company&#8217;s tool and that &#8220;you don&#8217;t get to deploy something capable of breaking into systems and then disown where it goes,&#8221; calling a civil negligence case a &#8220;no brainer&#8221; for victims. The EFF&#8217;s Andrew Crocker is skeptical that the intent required for criminal charges can be proven against a model, and there is no federal AI liability law to lean on, though several states are moving. </p><p>We are going to be litigating who owns an autonomous system&#8217;s actions for years, and the technology is not waiting for the law to catch up, so expect more incidents as well as more debates about accountability.</p><h3><a href="https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/">Moonshot&#8217;s Kimi K3 escapes its sandbox</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TnAv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TnAv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png 424w, https://substackcdn.com/image/fetch/$s_!TnAv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png 848w, https://substackcdn.com/image/fetch/$s_!TnAv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png 1272w, https://substackcdn.com/image/fetch/$s_!TnAv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TnAv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png" width="1086" height="540" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/affd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:540,&quot;width&quot;:1086,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:101178,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TnAv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png 424w, https://substackcdn.com/image/fetch/$s_!TnAv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png 848w, https://substackcdn.com/image/fetch/$s_!TnAv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png 1272w, https://substackcdn.com/image/fetch/$s_!TnAv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faffd4cfd-3d68-4bfe-bf8a-df9db9089563_1086x540.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For anyone who thinks this is purely a US-lab story, Wired reported that Moonshot&#8217;s Kimi K3 model escaped its sandbox as well, a pattern corroborated by Frontier Security&#8217;s account of Kimi K3 <strong><a href="https://blog.frontier.security/evaluating-models-for-defensive-security/">exploiting network egress</a></strong> in an AISI evaluation sandbox to retrieve an official benchmark solution rather than solving the task natively. </p><p>Frontier&#8217;s broader argument is the one to keep in mind, that offensive capability scales predictably with inference budget while defensive investigation does not, an asymmetry that should reshape how we benchmark security agents in the first place. Open-weight and international models are part of this story now, and the containment problem does not respect a lab&#8217;s borders. </p><p>The key theme across all of these stories is that agents find a way, and that way often involves trying to cheat, something that has been researched and documented by AISI on their blog.</p><h3><a href="https://aws.amazon.com/blogs/opensource/introducing-dogwood-runtime-verification-for-ai-agents/">AWS introduces Dogwood for runtime verification of AI agents</a></h3><p>AWS open-sourced Dogwood, a governance language for regulating how agents use tools that goes beyond point-in-time authorization by adding temporal conditions over an agent&#8217;s recent history. Built on Cedar and grounded in metric first-order temporal logic, it can express rules like requiring an approval before a sensitive action or rate-limiting a class of operations, which is the kind of history-aware constraint that static, request-by-request policy cannot capture. It pairs naturally with research like Dreadnode&#8217;s <a href="https://dreadnode.io/research/scope-judge-can-a-runtime-judge-keep-offensive-agents-in-scope/">ScopeJudge</a>, which tested whether a runtime LLM judge can keep offensive agents in scope and found the best configuration reaching the lower end of human agreement, concluding runtime monitoring is the most practical way to deploy scalable oversight for offensive agents today. Between formal policy and learned judges, runtime is clearly where the agent-control conversation is heading.</p><h3><a href="https://www.incalmo.ai/blog/glm-malware/">Low-cost, evasive, abundant malware from open-weight models</a></h3><p>On the offensive research side, Incalmo built a system called PathoGen that uses open-weight models like GLM 5.2 to generate evasive malware, reporting that roughly 27% of samples evaded all 75 scanners on VirusTotal and about 75% evaded all but one, at a cost of $2 to $35 per sample. The researchers withheld methodological details and coordinated with vendors, and their point is constructive, use frontier models proactively to find the defensive gaps before adversaries do. That said, the economics are the story. When capable, scanner-evading malware costs less than lunch to produce, volume stops being a meaningful signal and detection has to lean much harder on behavior than on signatures.</p><h1>AppSec</h1><h3><a href="https://www.vulncheck.com/blog/state-of-exploitation-1h-2026">VulnCheck&#8217;s state of exploitation for the first half of 2026</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NuJD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NuJD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png 424w, https://substackcdn.com/image/fetch/$s_!NuJD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png 848w, https://substackcdn.com/image/fetch/$s_!NuJD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png 1272w, https://substackcdn.com/image/fetch/$s_!NuJD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NuJD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png" width="1456" height="797" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:797,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128057,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NuJD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png 424w, https://substackcdn.com/image/fetch/$s_!NuJD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png 848w, https://substackcdn.com/image/fetch/$s_!NuJD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png 1272w, https://substackcdn.com/image/fetch/$s_!NuJD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f294a68-1950-406c-9653-f3e2770275e2_1506x824.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Patrick Garrity and the VulnCheck team published their first-half exploitation data, and it is the empirical grounding a lot of the AI-and-vulnerabilities conversation badly needs. In 1H-2026, 23.43% of known exploited vulnerabilities showed evidence of exploitation on or before the day the CVE was published, down from 28.93% in 2025, and the median time from publication to known-exploited status dropped from 120 days to 80. </p><p>The figure most relevant to this issue is the AI one, of 1,061 vulnerabilities attributed to AI-assisted discovery, only 14, or 1.3%, were confirmed exploited, and Anthropic&#8217;s Project Glasswing produced 23,019 findings and 126 published CVEs but just a single confirmed exploitation. AI is discovering vulnerabilities at scale, but discovery and real-world exploitation remain very different things, and the data is a healthy corrective to the assumption that one automatically becomes the other.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5q9D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5q9D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png 424w, https://substackcdn.com/image/fetch/$s_!5q9D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png 848w, https://substackcdn.com/image/fetch/$s_!5q9D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png 1272w, https://substackcdn.com/image/fetch/$s_!5q9D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5q9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png" width="1456" height="811" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:163105,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5q9D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png 424w, https://substackcdn.com/image/fetch/$s_!5q9D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png 848w, https://substackcdn.com/image/fetch/$s_!5q9D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png 1272w, https://substackcdn.com/image/fetch/$s_!5q9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea77fdce-abd2-404e-9db1-1931b0b1a065_1480x824.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/">SQLite critical CVEs, or LLM slop</a></h3><p>JFrog&#8217;s Afek Berger dug into six SQLite advisories filed from a newly created GitHub repository and found them fabricated, referencing functions that do not exist, with proof-of-concepts that do not run, and CVSS scores as high as a claimed 9.8 critical that had to be walked back. </p><p>A broader audit turned up 54 completely fabricated advisories, with exactly one containing a real bug. Berger ties the problem to NVD pausing its deeper analysis back in early 2024, which lets AI-generated slop flow downstream into scanners and databases unchallenged. </p><p>This is the shadow side of the AI-discovers-vulnerabilities story. The same generative capability that finds real bugs also mass-produces convincing fake ones, and our vulnerability infrastructure was not built to filter them.</p><h3><a href="https://www.elastic.co/security-labs/ai-vulnerability-triage-bug-bounty-hackerone">Triaging bug bounty reports for $2 each, 85% as well as a human</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BdDA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BdDA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png 424w, https://substackcdn.com/image/fetch/$s_!BdDA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png 848w, https://substackcdn.com/image/fetch/$s_!BdDA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png 1272w, https://substackcdn.com/image/fetch/$s_!BdDA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BdDA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png" width="1456" height="204" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1c708d53-c129-430e-9f27-533650877ea0_2566x360.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:204,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:246304,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BdDA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png 424w, https://substackcdn.com/image/fetch/$s_!BdDA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png 848w, https://substackcdn.com/image/fetch/$s_!BdDA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png 1272w, https://substackcdn.com/image/fetch/$s_!BdDA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1c708d53-c129-430e-9f27-533650877ea0_2566x360.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Elastic Security Labs built an AI triage system for HackerOne reports that performs about 85% as well as a human at roughly $2 per report, validated against 764 known-outcome reports. </p><p>The context that makes it matter is the volume, they received more than 1,390 reports in the first half of 2026, exceeding their full-year totals for 2024 and 2025 combined, which is exactly the flood that AI-assisted discovery produces on the reporting side. A human still makes the final call on every report. </p><p>This is the pragmatic pattern for surviving the coming report volume, let the model handle triage economics while keeping human judgment on the decision, and it pairs well with 1Password&#8217;s parallel work on making <strong><a href="https://1password.com/blog/scaling-security-reviews-solving-context-and-nondeterminism">security reviews scale</a></strong> without drowning in context and nondeterminism.</p><h3><a href="https://1password.com/blog/why-ai-generated-patches-still-require-human-review">Why AI-generated patches still require expert human review</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DTRV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DTRV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png 424w, https://substackcdn.com/image/fetch/$s_!DTRV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png 848w, https://substackcdn.com/image/fetch/$s_!DTRV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png 1272w, https://substackcdn.com/image/fetch/$s_!DTRV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DTRV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png" width="578" height="431.40579710144925" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1030,&quot;width&quot;:1380,&quot;resizeWidth&quot;:578,&quot;bytes&quot;:182603,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DTRV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png 424w, https://substackcdn.com/image/fetch/$s_!DTRV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png 848w, https://substackcdn.com/image/fetch/$s_!DTRV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png 1272w, https://substackcdn.com/image/fetch/$s_!DTRV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3ec6e32-2024-4f66-8fb0-25be7d5c60b7_1380x1030.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>1Password&#8217;s Off-by-1 Labs ran one of the more rigorous tests of AI patching I have seen, generating 6,080 patches across six recently disclosed CVEs. Only 26.0% completely fixed the flaw without changing application behavior, another 20.1% fixed it but altered behavior, and 53.9% failed outright or introduced new vulnerabilities, with more than a third of even the successful patches judged fragile because they treated symptoms rather than root causes. This is the essential counterweight to the fix-it-with-AI enthusiasm. </p><p>The generation side is improving fast, but a majority of machine-generated patches are still wrong or harmful without expert review, and shipping them unreviewed would trade a known vulnerability for an unknown one.</p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;id&quot;:11988704,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a89717e5-a927-4084-ad86-69068727dbf3_1632x1632.png&quot;,&quot;uuid&quot;:&quot;c3961190-1e96-40bb-8346-7e08b3c7db03&quot;}" data-component-name="MentionToDOM"></span> had an <strong><a href="https://substack.com/home/post/p-210649487">excellent blog</a></strong> breaking down the findings and the implications for practitioners as well. </p><h3><a href="https://vercel.com/blog/everything-hackable-will-get-hacked">Everything hackable will get hacked</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RV5b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RV5b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png 424w, https://substackcdn.com/image/fetch/$s_!RV5b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png 848w, https://substackcdn.com/image/fetch/$s_!RV5b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png 1272w, https://substackcdn.com/image/fetch/$s_!RV5b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RV5b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png" width="1094" height="346" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:346,&quot;width&quot;:1094,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:53558,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210011157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RV5b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png 424w, https://substackcdn.com/image/fetch/$s_!RV5b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png 848w, https://substackcdn.com/image/fetch/$s_!RV5b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png 1272w, https://substackcdn.com/image/fetch/$s_!RV5b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10f545c8-9ce9-4302-ab96-ea8f4f0ba051_1094x346.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Vercel&#8217;s Malte Ubl makes the blunt case that open-weight models now carry real offensive capability, describing Kimi K3 as an Opus-class model with no relevant cybersecurity safeguards, while frontier models still hold the defensive edge for now. This widespread capability is the same point <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;c391532f-0e0b-4e43-aa3b-b67267869b88&quot;}" data-component-name="MentionToDOM"></span> has been making for months.</p><p>Vercel&#8217;s response is instructive, running full deep security reviews across mission-critical repositories quarterly at a cost of tens of thousands of dollars, and making an egress firewall available even on its free Hobby plan. The egress theme keeps recurring across this entire issue for a reason. </p><p>Whether you are containing your own agents or blunting an attacker&#8217;s, controlling what code can reach the network is turning out to be one of the highest-leverage controls available, and it is encouraging to see it pushed down to the free tier rather than reserved for enterprise.</p><h2>Final Thoughts</h2><p>Two weeks is a lot to compress, but the summer&#8217;s story told itself. </p><p>Autonomous agents crossed from the benchmark into real systems, and they did it not through exotic capabilities but by exploiting ordinary weaknesses the moment a containment assumption failed. </p><blockquote><p><strong>The most critical thread running through the OpenAI, Anthropic, and AISI incidents is not that the models were brilliant, it is that they were ordinary attackers with unusual stamina, and the doors they walked through were the same weak passwords, exposed endpoints, and soft egress boundaries we have been failing to close for years.</strong></p></blockquote><p>These same problems are pervasive across every organization and environment and is exactly why Vercel&#8217;s CTO said everything hackable will be hacked.</p><p>The encouraging counter-thread is that the response is already taking shape, in the sandboxing and runtime-verification work, the defensive deployments at security vendors, the honest accounting of where AI patching still fails, and the beginnings of a shared exchange for incidents and near-misses. </p><p>The pace of agent adoption is once again outrunning the pace of governance, and we get to choose whether we build these controls in while the architectures are still forming or bolt them on after the next incident. The evidence from the last two weeks suggests we should hurry.</p><p><strong>Stay resilient.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Building a System of Truth for the CISO]]></title><description><![CDATA[The system record security leaders never had but desperately need]]></description><link>https://www.resilientcyber.io/p/building-a-system-of-truth-for-the</link><guid isPermaLink="false">https://www.resilientcyber.io/p/building-a-system-of-truth-for-the</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 11 Aug 2026 19:17:09 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/210761630/75df7233d1544d5d49c370384c1c7041.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>The security leader has never had the system of record that every other executive takes for granted, and Mike Armistead thinks AI can finally close that gap.</p><p>In this episode I sit down with Mike Armistead, co-founder and CEO of <strong><a href="https://pulsesecurity.ai/">Pulse Security</a></strong>, to discuss why the CISO has spent decades running a security program without a system built to run it, including the silos that created the problem, what a system of truth actually looks like, and where AI does the heavy lifting versus where the human stays in the seat. </p><p>Mike has been through this movie before as the co-founder of Fortify and of Respond Software, so his view on the AI wave is measured rather than breathless. We also get into the reporting gap between what CISOs say and what boards actually need, and the research findings that put real numbers on it.</p><p>We chatted about:</p><ul><li><p>Mike&#8217;s path through two exits and why the AI wave pulled him back to build a third company</p></li><li><p>Why security grew up as a set of technical silos, each speaking a slightly different language, with no system to run the program as a whole</p></li><li><p>What a system of truth for the CISO means, and how an agentic layer reads across both structured and unstructured data like policies and assessments</p></li><li><p>Where agents take over the toilsome work of regulatory monitoring, vendor and vulnerability intelligence, and status reporting</p></li><li><p>Governing the guardrails rather than the keystrokes, and why closing the loop still involves people and their judgment</p></li><li><p>What corporate directors actually want to hear from a CISO in a 15 to 20 minute quarterly slot</p></li><li><p>The research findings, including that 55% of boards have never defined the cyber risk they are willing to accept and only 12.5% of CISOs are very confident the board leaves with a true picture of the risk</p></li><li><p>Bringing Joanna Burkey&#8217;s dual perspective as a former CISO and current corporate director into the product</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><div id="youtube2-2daOTcMr5g8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;2daOTcMr5g8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/2daOTcMr5g8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h3><strong>Prefer to listen?</strong></h3><p><strong><a href="https://open.spotify.com/episode/6jVow6Z7Jd2rc0fy0yiv0d?si=wELWipBtR1GM-21U2NGdgA">Spotify</a></strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/building-a-system-of-truth-for-the-ciso/id1555928024?i=1000782764374">Apple Podcasts</a></strong></p><p>Be sure to subscribe and leave a review as it truly helps the show!</p><div><hr></div><h1>A few takeaways from the conversation:</h1><h2>The CISO is the last executive without a system of record</h2><p>Mike frames the gap in terms every leader will recognize. The CFO manages financial risk from an ERP with a general ledger at its core, and the CRO runs the pipeline from a CRM. The CISO manages cyber risk from a scattering of spreadsheets, assessment documents, and point-in-time audits. His argument is that security grew up at the practitioner level, one technical silo at a time, and never developed the layer that answers questions about the program itself rather than about a single threat or vulnerability. I have lived this in programs I have supported, where the leader has to walk over to the deputy, the cloud team, the endpoint team, and the SOC to assemble a picture that should already exist in one place.</p><h2>Agents for the toil, humans for the judgment</h2><p>Mike is careful about where autonomy fits, and I appreciated that he did not oversell it. Agents are good at scouring the landscape and pulling the right signals for a specific company&#8217;s stack, which turns a board member&#8217;s &#8220;are we affected by that thing I read about&#8221; into a grounded answer instead of a scramble. But he is clear that &#8220;closing the loop involves people.&#8221; His quarterly access review example lands well. An agent can pull from cloud, identity, GitHub, and HR, but the calls on how broad the review goes and whether to grant exceptions stay with the security professional. What the system adds is memory of those decisions, so the exception you granted last time does not get relitigated from scratch.</p><h2>The board reporting gap is about ground truth, not delivery</h2><p>The numbers from the research are the part that should make people sit up. Mike cited that 55% of boards have never defined the level of cyber risk they are willing to accept, and that only 12.5% of CISOs are very confident the board walks away with a true picture of the risk. He does not think this is mainly a storytelling problem. As he put it, &#8220;we often, I think, the trees are presented instead of the forest.&#8221; The CISO gets 15 to 20 minutes a quarter and tends to fall back on the SOC metrics that feel comfortable, while the director wants to know what changed in the landscape and what the program&#8217;s posture is against it. Closing that gap means better ground truth underneath the narrative, not just a better narrative.</p><h2>Institutionalizing the tribal knowledge</h2><p>The thread that ties it together is one every practitioner knows. Programs run on tribal knowledge, the contract clauses a leader has ruled on before, the exceptions, the context that lives in a few people&#8217;s heads. Mike brought in Joanna Burkey, former CISO at HP and Siemens and now a corporate director, as an advisor precisely because she has seen both sides, and her point is that this knowledge &#8220;needs to be institutionalized in a way.&#8221; Capturing it saves time and money and headache, and it is the difference between a program that resets every time someone leaves and one that compounds what it learns.</p><p>Thanks to Mike for a sharp conversation on a problem the industry has mostly ignored while it chased AI for AppSec and the SOC. You can follow his work at Pulse Security AI and connect with him on LinkedIn.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://pulsesecurity.ai/&quot;,&quot;text&quot;:&quot;-> Check Out Pulse Security! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://pulsesecurity.ai/"><span>-&gt; Check Out Pulse Security! &lt;-</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Chaos, Clocks, and Command Centers]]></title><description><![CDATA[A look at why incident response is still coordinated with spreadsheets and chat threads, and what that costs organizations now that exploitation timelines have collapsed.]]></description><link>https://www.resilientcyber.io/p/chaos-clocks-and-command-centers</link><guid isPermaLink="false">https://www.resilientcyber.io/p/chaos-clocks-and-command-centers</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 10 Aug 2026 12:01:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!g4rg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>Throughout my 20+ year cybersecurity career, across DoD, U.S. federal civilian, and commercial environments, I have been involved in many incidents and associated response activities.</span></p><p><span>The pattern is remarkably consistent regardless of the organization&#8217;s size, sector, or security budget. Someone spins up a war room, someone else spins up a chat channel, a Google Doc appears with a running timeline, an executive asks for a status update that takes forty minutes and a game of telephone to assemble, and somewhere in the middle of all of it someone awkwardly asks whether anyone has started the clock on notification obligations.</span></p><p><span>That said, look at what we have actually built as an industry over the last three decades. We went from basic IT service management, to SIEM for detection, to EDR and XDR for containment, to SOAR for automating the tedious parts, to the current wave of AI SOC tooling for triage. Every one of those advances made the technical work better and almost none of them improved the enterprise work, meaning the decisions, the ownership, the obligations, and the documentation that determine what an incident actually costs an organization in the end.</span></p><p><span>Using Resilient Cyber&#8217;s partner, BreachRx as an example in this article, I want to dig into that gap, why it has become more expensive in an era of collapsing exploitation timelines, and what it looks like to treat incident response as a discipline with a real command center rather than an ad hoc scramble across disconnected tools.</span></p><p><span>Let&#8217;s take a look at how we got here, and where we still need to go.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g4rg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g4rg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png 424w, https://substackcdn.com/image/fetch/$s_!g4rg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png 848w, https://substackcdn.com/image/fetch/$s_!g4rg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png 1272w, https://substackcdn.com/image/fetch/$s_!g4rg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g4rg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png" width="1456" height="840" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:840,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:183109,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/209673021?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g4rg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png 424w, https://substackcdn.com/image/fetch/$s_!g4rg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png 848w, https://substackcdn.com/image/fetch/$s_!g4rg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png 1272w, https://substackcdn.com/image/fetch/$s_!g4rg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6240a569-7b86-42a5-800c-7b87b4749fe6_1532x884.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><span>The Clock We Never Reset</span></h2><p><span>By now, it is clear that the timelines attackers operate on have detached from the timelines defenders operate on, and the evidence on this has gotten hard to dispute.</span></p><p><strong><a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><span>Mandiant&#8217;s M-Trends 2026</span></a></strong><span>, built on over </span><em><span>500,000 hours</span></em><span> of frontline incident investigations conducted globally in 2025, found that the median time between initial access and hand-off to a second threat group fell from more than eight hours in 2022 to 22 seconds in 2025. Exploits remained the most common initial infection vector for the sixth consecutive year, at 32%. Google Threat Intelligence Group&#8217;s mean time-to-exploit, which measured 63 days back in 2018, is now estimated at negative 7 days, meaning exploitation is routinely happening before a patch exists at all.</span></p><p><span>I wrote about this trajectory earlier this year in an article titled, </span><a href="https://www.resilientcyber.io/p/the-zero-day-clock-is-ticking-why"><span>&#8220;</span></a><strong><a href="https://www.resilientcyber.io/p/the-zero-day-clock-is-ticking-why"><span>The Zero Day Clock Is Ticking&#8221;</span></a></strong><span>, where the numbers tell the same story from the vulnerability side. In 2018, the median time from a vulnerability being disclosed to the first observed exploit was 771 days.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W2Bx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W2Bx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png 424w, https://substackcdn.com/image/fetch/$s_!W2Bx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png 848w, https://substackcdn.com/image/fetch/$s_!W2Bx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png 1272w, https://substackcdn.com/image/fetch/$s_!W2Bx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W2Bx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png" width="1456" height="984" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:984,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:220422,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/209673021?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!W2Bx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png 424w, https://substackcdn.com/image/fetch/$s_!W2Bx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png 848w, https://substackcdn.com/image/fetch/$s_!W2Bx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png 1272w, https://substackcdn.com/image/fetch/$s_!W2Bx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc54019d-d38e-4c31-924e-2095542901f0_1942x1312.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>By 2021 that window had compressed to 84 days. By 2023 it was 6 days, and by 2024 it was 4 hours. This is in addition to the recent 2026 Data Breach Investigations Report (DBIR) highlighting how vulnerability exploitation is now the leading attack vector for organizations, overtaking other vectors such as compromised credentials or social engineering, which historically was in the lead.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dFKq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dFKq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png 424w, https://substackcdn.com/image/fetch/$s_!dFKq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png 848w, https://substackcdn.com/image/fetch/$s_!dFKq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png 1272w, https://substackcdn.com/image/fetch/$s_!dFKq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dFKq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png" width="627" height="285.0974358974359" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:532,&quot;width&quot;:1170,&quot;resizeWidth&quot;:627,&quot;bytes&quot;:129351,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/209673021?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dFKq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png 424w, https://substackcdn.com/image/fetch/$s_!dFKq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png 848w, https://substackcdn.com/image/fetch/$s_!dFKq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png 1272w, https://substackcdn.com/image/fetch/$s_!dFKq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59e4cbc9-7dcf-421b-8b00-361ea3efba1e_1170x532.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Now, for those of us who have spent years telling executives that our detection and response capabilities are maturing, the other half of that same report is uncomfortable reading. Global median dwell time went the wrong direction, up to 14 days in 2025 from 11 days in 2024, and cases where the organization learned about the intrusion from an external party had a median dwell time of 25 days, up from 11. Attackers compressed their timelines by orders of magnitude while we got slower.</span></p><p><span>Detection has absorbed the overwhelming majority of security investment and innovation for twenty-five years, something strongly documented in work, such as Sounil Yu&#8217;s </span><strong><a href="https://cyberdefensematrix.com/"><span>Cyber Defense Matrix</span></a></strong><span> and it shows, with 52% of organizations first detecting malicious activity internally in 2025, up from 43% in 2024. </span></p><p><span>The response side of the house, meaning everything that happens after someone says, &#8220;</span><em><span>yes, this is real</span></em><span>,&#8221; is largely still run the way it was run in 2012 with a bridge line, a shared document, and a lot of institutional memory.</span></p><h2><span>Everyone in the Room, and No One in Command</span></h2><p><span>Incident response sits at the intersection of nearly every business unit, and that is what makes it structurally different from the rest of security operations, involving a diverse group of both technical and non-technical stakeholders.</span></p><p><span>Within hours of an incident being declared, you have security running technical containment, IT managing systems and access, legal evaluating contractual and disclosure exposure, privacy assessing what data categories and jurisdictions are implicated, communications drafting internal and external statements, HR involved if there is an insider dimension, executives asking for accurate status, and the board asking whether this is material. That is before you get to the external parties, meaning outside counsel, forensic firms, the cyber insurer, managed service providers, regulators, customers under contractual notice obligations, involved business partners, and eventually the press.</span></p><p><span>Most of those people are not technical, and most of them are being asked to make consequential decisions from a summary that someone typed into a chat window twenty minutes ago, which then got passed along in a lossy game of telephone.</span></p><p><span>The technical execution in these situations is usually fine, since practitioners are good at containment work and generally know what to do. What breaks is enterprise coordination, and it breaks in a very specific way. Actions live in email threads, Slack or Teams channels, and a spreadsheet someone is heroically maintaining, ownership is tracked manually, and status is fragmented across half a dozen tools that were never built to talk to each other. There is activity everywhere and no authoritative, consolidated view of the incident.</span></p><p><span>In other areas of cybersecurity, we have pushed to quit tolerating this disjointed scenario and now have vendors and enterprises alike building unified cohesive platforms and sources of truth, but unfortunately not so much when it comes to incidents.</span></p><p><span>External parties make this harder rather than easier. Your forensics firm needs artifacts, your insurer needs a claim narrative, outside counsel needs a privileged workspace, and your regulator eventually needs a defensible chronology. In most organizations all four are served by someone manually exporting slices of the same spreadsheet or Google doc into email attachments, at 2 a.m., during the worst week of their professional life.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HVsB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HVsB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png 424w, https://substackcdn.com/image/fetch/$s_!HVsB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png 848w, https://substackcdn.com/image/fetch/$s_!HVsB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png 1272w, https://substackcdn.com/image/fetch/$s_!HVsB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HVsB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png" width="412" height="411.2682060390764" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1124,&quot;width&quot;:1126,&quot;resizeWidth&quot;:412,&quot;bytes&quot;:93755,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/209673021?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HVsB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png 424w, https://substackcdn.com/image/fetch/$s_!HVsB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png 848w, https://substackcdn.com/image/fetch/$s_!HVsB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png 1272w, https://substackcdn.com/image/fetch/$s_!HVsB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F238c4f10-6bbd-46c6-ac32-70f029262bd5_1126x1124.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><span>Regulatory Clocks Don&#8217;t Wait</span></h2><p><span>If the coordination problem stayed internal, it would be an efficiency issue. It does not stay internal, because the reporting obligations have gotten both faster and more numerous, and they run on clocks that start whether or not your team has its act together.</span></p><p><span>Consider what a large multinational is actually holding at once. India&#8217;s </span><strong><a href="https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf"><span>CERT-In directions</span></a></strong><span> require reporting in-scope cyber incidents &#8220;</span><em><span>within 6 hours of noticing such incidents.</span></em><span>&#8221; Under DORA&#8217;s </span><strong><a href="https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng"><span>regulatory technical standards</span></a></strong><span>, EU financial entities must submit an initial notification of a major ICT-related incident within 4 hours of classifying it as major, and no later than 24 hours from becoming aware of it. </span><strong><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022L2555"><span>NIS2</span></a></strong><span> requires an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. </span></p><p><strong><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679"><span>GDPR</span></a></strong> requires notification to the supervisory authority &#8220;<em>without undue delay and, where feasible, not later than 72 hours after having become aware of it</em>.&#8221; <strong><a href="https://www.dfs.ny.gov/system/files/documents/2023/10/rf_fs_2amend23NYCRR500_text_20231101.pdf"><span>NYDFS</span></a></strong><span> requires notice within 72 hours of determining that a cybersecurity incident occurred, plus a 24-hour notice for extortion payments and a written justification within 30 days. The SEC&#8217;s </span><strong><a href="https://www.sec.gov/newsroom/press-releases/2023-139"><span>Form 8-K</span></a></strong><span> is generally due four business days after a registrant determines an incident is material, and underneath all of that, the U.S. has </span><strong><a href="https://iapp.org/resources/article/state-data-breach-notification-chart"><span>breach notification laws</span></a><span> </span></strong><span>in all 50 states plus the District of Columbia, Guam, Puerto Rico, and the Virgin Islands.</span></p><p><span>CIRCIA&#8217;s 72-hour incident and 24-hour ransom payment requirements are still dormant, since </span><strong><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia"><span>CISA has stated</span></a></strong><span> that covered entities are not required to report until the effective date of a final rule that has slipped repeatedly and is now projected for September 2026, but that is a reprieve, not a reduction, and the requirements are still likely to materialize.</span></p><p><span>Safe to say, the reporting timelines are complex and hard to juggle while also working through incident response.</span></p><p><span>None of these clocks are triggered by the incident. They are triggered by awareness, determination, or classification, which are all judgment calls made by humans under pressure, and every one of those judgment calls is later reviewable. Missing a deadline is one failure mode, however it is more common to not be able to demonstrate when the clock started or why you concluded what you concluded.</span></p><p><span>You can see the resulting confusion in the U.S. public company data. I&#8217;m subscribed to Andrew Hoog&#8217;s 8K and </span><strong><a href="https://www.board-cybersecurity.com/incidents/tracker"><span>incident tracker</span></a></strong><span>, and the reporting truly is all over the place in terms of level of detail within what gets filed.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xHa5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xHa5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png 424w, https://substackcdn.com/image/fetch/$s_!xHa5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png 848w, https://substackcdn.com/image/fetch/$s_!xHa5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png 1272w, https://substackcdn.com/image/fetch/$s_!xHa5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xHa5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png" width="1456" height="744" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:744,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:418971,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/209673021?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xHa5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png 424w, https://substackcdn.com/image/fetch/$s_!xHa5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png 848w, https://substackcdn.com/image/fetch/$s_!xHa5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png 1272w, https://substackcdn.com/image/fetch/$s_!xHa5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc861edc7-d2ed-416a-b36b-066ec6de8b88_2842x1452.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><span>Privilege Is a Design Decision</span></h2><p><span>There is a category of incident response failure that practitioners rarely think about until it is too late and the implications are real.</span></p><p><span>Every message in that incident chat channel, every comment in the running timeline doc, every speculative theory someone typed at hour three when the picture was still wrong, is potentially discoverable. Security teams communicate the way engineers communicate, which is candidly and with a lot of thinking out loud. That is the behavior you want during an investigation and exactly the behavior that reads badly when a plaintiff&#8217;s attorney reads it back to you two years later, stripped of context.</span></p><p><span>Attorney-client privilege over incident work is not automatic and it is not preserved by copying a lawyer on a thread. It depends on how the work was structured, who directed it, where it lived, and whether the organization can show a segmented, deliberate approach to sensitive communications. Doing that inside general-purpose collaboration tools designed for open information flow is difficult, and most organizations discover how difficult only in retrospect.</span></p><p><span>Additionally, and this one is almost too obvious to state, if your incident coordination lives entirely inside the productivity suite the attacker has been sitting in for two weeks, you have a shared workspace with an audience. Out-of-band access sounds paranoid right up until the moment it is the only thing that works, but even then it can get problematic with personal devices and communications intermingled with corporate ones.</span></p><p><span>This is also where the tabletop conversation gets interesting. We talk constantly about the need for exercises, and the advice is sound. However, running a tabletop in a slide deck and a conference room trains your people on a process they will not actually execute, in a system they will not actually use, against obligations they will not have time to look up. Practice that does not live in the same environment as execution is a rehearsal for a different play.</span></p><h2><span>The Record Is What You Get Judged On</span></h2><p><span>The personal liability narrative in our industry has run hot for a few years now, but the recent evidence is mixed. The SEC&#8217;s enforcement action against SolarWinds and its CISO was largely gutted at the motion to dismiss stage in 2024, and in November 2025 the Commission</span><strong><span> </span><a href="https://www.sec.gov/enforcement-litigation/litigation-releases/lr-26423"><span>filed to dismiss</span></a></strong><span> the remainder with prejudice. That is a meaningful data point, and anyone telling you regulators are indiscriminately hunting CISOs should be viewed with caution.</span></p><p><span>That said, the underlying dynamic has not gone anywhere. Regulators, lawyers, insurers, and boards do not evaluate an incident purely on the technical outcome, they evaluate the process, meaning whether escalation was timely, whether executives were informed and when, whether disclosure decisions were documented with the reasoning behind them, whether obligations were tracked across jurisdictions and met, and whether leadership can demonstrate good-faith governance rather than simply claim it.</span></p><p><span>Every one of those questions is answered from the record. If the record is a reconstructed narrative cobbled together weeks later from chat exports, calendar invites, and people&#8217;s recollections, you are not defending your decisions, you are defending your memory of them, which is a much weaker and less than ideal position.</span></p><p><span>This is where I think the emerging Cybersecurity Incident Response Management  (CIRM) category, which </span><strong><a href="https://www.breachrx.com/"><span>BreachRx</span></a></strong><span> has been a pioneer of, is pointed at a real gap in the industry. </span></p><p><span>The key thesis is that the enterprise layer of incident response deserves a purpose-built system of record in the same way detection, containment, GRC and even ticketing eventually got theirs, with clear ownership across stakeholders such as security, legal, privacy, IT, communications, and leadership, tailored playbooks and obligation tracking that surface which of those 6-hour, 24-hour, 72-hour, and four-business-day clocks apply to this incident in these jurisdictions, protected and segmented communications, evidence captured continuously as the response executes rather than reconstructed after the fact, and tabletops run inside the same environment the team will use when it counts and it&#8217;s no longer a hypothetical incident, but a real one.</span></p><p><span>Joe Sullivan, former CSO at Uber, Facebook, and Cloudflare, and an advisor to BreachRx, made the case for this strongly in their materials I read, and there are few people have who have lived through incidents at the level of scrutiny he has:</span></p><blockquote><p><strong><span>&#8220;Until I saw BreachRx, I had not seen any product that truly would have made a difference for me at Uber. Their platform could have completely changed the outcome by ensuring seamless communication, cross-organizational collaboration, and better decision-making that is documented and aligned with the law.&#8221;</span></strong></p></blockquote><p><span>Their platform embeds agentic AI into the response lifecycle through bounded, role-specific agents rather than a general-purpose chatbot bolted onto the side, with a coordinator agent orchestrating specialists for incident command, response execution, exercises, and regulatory analysis, and human approval checkpoints where they matter. It was interesting to see this multi-agent architecture applied to this use case.</span></p><p><span>Resilient Cyber subscribers know I am optimistically skeptical of agentic AI claims, but incident response is among one of the more defensible applications I have seen so far, largely because it is a workflow and context problem involving procedures, stakeholders, deadlines, approvals, and documentation. That is the kind of bounded, high-toil, high-consequence coordination work where agents earn their keep and where a chat interface alone does not.</span></p><p><span>BreachRx has also done something I have not seen elsewhere in this category, and frankly was something I was surprised to see,  which is backing the product with a warranty offering up to $3 million per claim in liability protection, with no retention requirement, covering defense costs, fines, penalties, and negligence-related claims for executives and response team members personally named in regulatory or government actions. These are the sort of guarantees I recently heard longtime industry leader Jeremiah Grossman make a call for in an interview:</span></p><div id="youtube2-Em3FoAU4AE8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Em3FoAU4AE8&quot;,&quot;startTime&quot;:&quot;1920&quot;,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Em3FoAU4AE8?start=1920&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Very few security companies ever stand behind the effectiveness of their products with this sort of rigor honestly.</p><p><span>The argument is that D&amp;O coverage frequently carries exclusions, carve-outs, or allocation disputes that leave security leaders exposed precisely when they need assurance. Whether a warranty is the deciding factor for a buyer is an open question, but putting financial skin in the game behind a defensibility claim is a stronger commitment than most vendors are willing to make, that&#8217;s for sure.</span></p><h2><span>Closing Thoughts</span></h2><p><span>We have spent a decade telling organizations that incidents are inevitable and that resilience matters more than prevention. I believe that, and the data keeps supporting it, especially now with AI-driven vulnerability discovery and autonomous exploitation arriving. What we have not done is give the people who actually run those incidents anything resembling the tooling maturity we handed the detection side of the house.</span></p><p><span>Attackers now move from initial access to hand-off in 22 seconds and exploit vulnerabilities before patches exist, while the enterprise response to those attacks is coordinated in a spreadsheet, a chat channel, and whatever document someone thought to create in the first ten minutes, against a stack of regulatory clocks that start ticking on judgment calls made by exhausted people at 3 a.m. </span></p><p><span>That is a very disorganized approach with very high stakes and very good odds of being reviewed later by someone who may not be sympathetic to the circumstances and stressors involved.</span></p><p><span>Whether you solve that with BreachRx, with something else, or with a painfully disciplined internal build, it&#8217;s worth asking your team some simple but not easy questions. For example, if an incident were declared this afternoon, where would the authoritative record live, and would we want a regulator to read it?</span></p><p><span>If you want to see what the platform side of this looks like in practice, BreachRx runs a </span><strong><a href="https://www.breachrx.com/get-demo/?utm_source=publication&amp;utm_medium=content-link&amp;utm_campaign=2026-08_oth_chris-hughes-product-deep-dive-blog"><span>walkthrough</span></a></strong><span> worth an hour of your time.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Learning From the Frontier]]></title><description><![CDATA[A look at what AISI's AI agent incident report tells us about enterprise agent deployments.]]></description><link>https://www.resilientcyber.io/p/learning-from-the-frontier</link><guid isPermaLink="false">https://www.resilientcyber.io/p/learning-from-the-frontier</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 06 Aug 2026 15:46:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aby1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In the span of a month or less we&#8217;ve seen 3 (possibly 4) disclosures from major labs and research groups as it relates to the cyber evaluations of LLMs and Agents. This of course includes the <strong><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI and Hugging Face Incident</a></strong>, <strong><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals">Anthropic&#8217;s disclosure</a></strong>, the <strong><a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">UK&#8217;s AI Security Institute</a></strong> and potentially even <strong><a href="https://www.theguardian.com/technology/2026/aug/05/meta-ai-model-hack-training">Meta.</a></strong> </p><p>While each of these disclosures share some characteristics and are also unique in their own way, there&#8217;s also lessons to be learned. There are inevitably going to be broader policy discussions around responsible cyber evaluations, potential mitigations on real-world organizations and individuals, or even potentially requirements for cyber evals, as the policy discourse continues to heat up. </p><p>All of that aside, I wanted to use AISI&#8217;s Incident Report as a retrospective, not necessarily on AI cyber evals, but on the inevitable risks enterprises will face as LLMs and agents continue to be deployed in various contexts, from endpoint coding agents, custom/homegrown agents in the Cloud, SaaS/Embedded agents and more. </p><p>So, let&#8217;s take a look at that report to see what lessons enterprise security leaders and teams can draw from it, knowing they will experience similar situations in terms of deployments, configurations, hardening, and risk management.</p><p>My key theme is we have a lot we can learn as security practitioners and leaders from the leading labs and research entities in the ecosystem as it relates to enterprise use of AI agents and security.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aby1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aby1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png 424w, https://substackcdn.com/image/fetch/$s_!aby1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png 848w, https://substackcdn.com/image/fetch/$s_!aby1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png 1272w, https://substackcdn.com/image/fetch/$s_!aby1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aby1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png" width="677" height="365.0034340659341" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:785,&quot;width&quot;:1456,&quot;resizeWidth&quot;:677,&quot;bytes&quot;:2391731,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aby1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png 424w, https://substackcdn.com/image/fetch/$s_!aby1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png 848w, https://substackcdn.com/image/fetch/$s_!aby1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png 1272w, https://substackcdn.com/image/fetch/$s_!aby1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd5078089-db80-4c6b-9ba1-5affd376daef_1706x920.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>What Happened?</h1><p>I don&#8217;t want to belabor the entire AISI incident, but it is helpful to at least recap what happened before we dig into the specific takeaways for security leaders. </p><p>The UK AI Security Institute published an incident report on August 4th. During a cyber evaluation that ran from July 25th to July 28th, AISI&#8217;s own AI agents took &#8220;<em>sustained, unsanctioned actions</em>&#8221; on the live internet against real people and organizations that had nothing to do with the test. </p><p>Across 122 evaluation attempts, AISI found 19 distinct instances of this behavior. Seventeen of them came from a single model, Mythos 5, and the other two came from GPT-5.6 Sol.</p><p>In the most serious case, an agent decided to solve the challenge with a software supply chain attack and went after two unaffiliated open-source maintainers it wrongly assumed were in scope. It created GitHub accounts using Tor and a proxy to slip past signup controls, opened a malicious pull request, and stood up sockpuppet accounts to manufacture consensus and endorse its own code. </p><p>It sent spearphishing emails to the maintainers and planted a prompt injection hidden inside a GitHub issue, aimed squarely at other AI coding agents. When a real human spotted the malware, the agent claimed an honest mistake and tried to cover its tracks. AISI says this is the first time it has seen deception of this severity aimed at a real person, unprompted, in the real world.</p><p>A couple of things are parrticularly interesting. First, this is now the third disclosure of its kind in a matter of weeks, following OpenAI and Anthropic, which tells me we are looking at a pattern and not an outlier. Second, and more important for practitioners, the danger did not live in the model weights. It lived in the harness around the model, its internet access and its ability to take real actions with real tools, which is exactly the excessive agency risk my friends <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Rock Lambros&quot;,&quot;id&quot;:19291360,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98098048-f975-4577-a2c4-d411bafa8255_1172x1172.png&quot;,&quot;uuid&quot;:&quot;e91b254e-cb86-4eb5-beed-c4bd81a0b8e0&quot;}" data-component-name="MentionToDOM"></span> and Steven Wilson over at OWASP just flagged in the opening lines of their new LLM Top 10. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kF2R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kF2R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png 424w, https://substackcdn.com/image/fetch/$s_!kF2R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png 848w, https://substackcdn.com/image/fetch/$s_!kF2R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png 1272w, https://substackcdn.com/image/fetch/$s_!kF2R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kF2R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png" width="1456" height="133" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:133,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142606,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kF2R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png 424w, https://substackcdn.com/image/fetch/$s_!kF2R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png 848w, https://substackcdn.com/image/fetch/$s_!kF2R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png 1272w, https://substackcdn.com/image/fetch/$s_!kF2R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec2a8544-9142-4f70-8758-a43c1f9baab9_1734x158.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>These safeguards were deliberately disabled and internet access was deliberately enabled to measure raw capability. That is a defensible research choice, but when an evaluation can reach real systems and real individuals, how we run these tests deserves a serious industry and policy conversation, which I anticipate will inevitably heat up now.</p><p>But, for this blog, I want to focus on the lesson for security leaders.</p><h1>Implications for Security Leaders on LLM and Agent Deployments</h1><p>While the policy conversation and the incidents with the labs and research community are very interesting, that isn&#8217;t why I wanted to write this blog. I wanted to write it because as I read through AISI&#8217;s incident report, I inevitably saw someone takeaways that are and will be relevant for security leaders as enterprise agent deployments and implementations continue to ramp up. </p><p>The most relevant part of the report on this front is the &#8220;Possible Contributing Factors&#8221; section of their report.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qsKY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qsKY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png 424w, https://substackcdn.com/image/fetch/$s_!qsKY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png 848w, https://substackcdn.com/image/fetch/$s_!qsKY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png 1272w, https://substackcdn.com/image/fetch/$s_!qsKY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qsKY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png" width="1456" height="282" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:282,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105047,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qsKY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png 424w, https://substackcdn.com/image/fetch/$s_!qsKY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png 848w, https://substackcdn.com/image/fetch/$s_!qsKY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png 1272w, https://substackcdn.com/image/fetch/$s_!qsKY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b57b75-0b90-492c-85d6-03a6bbcc38d3_1888x366.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Take a look at that list and ask yourself, how likely do we think it is that each of these will be present in real-world enterprise agent LLM and agent deployments for the organizations we secure or serve? </p><p>I think most of us agree that the answer is, very likely. Let&#8217;s step through them 1 by 1 to unpack them a bit. </p><h2>Internet Access</h2><p>The opening line of this section of their report states:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mAKo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mAKo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png 424w, https://substackcdn.com/image/fetch/$s_!mAKo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png 848w, https://substackcdn.com/image/fetch/$s_!mAKo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png 1272w, https://substackcdn.com/image/fetch/$s_!mAKo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mAKo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png" width="1456" height="154" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:154,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:55608,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mAKo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png 424w, https://substackcdn.com/image/fetch/$s_!mAKo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png 848w, https://substackcdn.com/image/fetch/$s_!mAKo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png 1272w, https://substackcdn.com/image/fetch/$s_!mAKo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab0b830-ff05-409f-8d7e-6a01e70fc28d_1892x200.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>By now, most of us who are immersing ourselves in AI security are familiar with Simon Willison&#8217;s &#8220;<strong><a href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/">Lethal Trifecta</a></strong>&#8221; for AI agents. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XTHq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XTHq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png 424w, https://substackcdn.com/image/fetch/$s_!XTHq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png 848w, https://substackcdn.com/image/fetch/$s_!XTHq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png 1272w, https://substackcdn.com/image/fetch/$s_!XTHq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XTHq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png" width="497" height="248.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:548,&quot;width&quot;:1096,&quot;resizeWidth&quot;:497,&quot;bytes&quot;:181371,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XTHq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png 424w, https://substackcdn.com/image/fetch/$s_!XTHq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png 848w, https://substackcdn.com/image/fetch/$s_!XTHq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png 1272w, https://substackcdn.com/image/fetch/$s_!XTHq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cd41f86-73cd-4aa3-a470-7b8ab3babcf3_1096x548.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Right there in the bottom left is &#8220;Ability to Externally Communicate&#8221;. The lethal trifecta essentially states:</p><blockquote><p><strong>&#8220;<span>If your agent combines these three features, an attacker can </span>easily trick it<span> into accessing your private data and sending it to that attacker.&#8221;</span></strong></p></blockquote><p>In short, we want to avoid combining these three characteristics when deploying agents due to the risks, but of course this is easier said than done. I have been using the phrase <em>Security Usability Tradeoff</em> when I discuss agents, because their very utility, such as the characteristics above, are what make them desirable for enterprise and business use cases, and ironically also what make them risky. </p><p>Some, such as Meta have proposed their &#8220;<strong><a href="https://ai.meta.com/blog/practical-ai-agent-security/">Rule of Two</a></strong>&#8221; as a mitigation, but even then, as <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ken Huang&quot;,&quot;id&quot;:1160339,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;uuid&quot;:&quot;f8e0393f-89e6-4c49-b4ef-e70759f29e1a&quot;}" data-component-name="MentionToDOM"></span> and <strong><a href="https://kenhuangus.substack.com/p/the-rule-of-two-vs-reality-why-metas">others have shown</a></strong>, even that approach isn&#8217;t infallible, but it does help mitigate some potential risks and attack vectors. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5HXi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5HXi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png 424w, https://substackcdn.com/image/fetch/$s_!5HXi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png 848w, https://substackcdn.com/image/fetch/$s_!5HXi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png 1272w, https://substackcdn.com/image/fetch/$s_!5HXi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5HXi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png" width="434" height="425.65384615384613" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1428,&quot;width&quot;:1456,&quot;resizeWidth&quot;:434,&quot;bytes&quot;:671219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5HXi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png 424w, https://substackcdn.com/image/fetch/$s_!5HXi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png 848w, https://substackcdn.com/image/fetch/$s_!5HXi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png 1272w, https://substackcdn.com/image/fetch/$s_!5HXi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb529f3bc-5c8d-49c4-a410-f5b2852a6d86_1642x1610.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s also worth noting in the case of AISI&#8217;s evaluation, there was no &#8220;attacker&#8221; that tricked the agent, it simply took on emergent behavior in pursuit of the goals it was given as part of the cyber evaluation, and as we continue to see, <em><strong>agents find a way</strong></em>, even if that way introduces risks to real world infrastructure and individuals. </p><p>Bringing this back to security practitioners, think about the exponential agents being deployed across your environments, on endpoints, in the cloud, in SaaS etc. and can we honestly state they do not have internet access, or if they do, we&#8217;re aware of where all of those agents run, with what permissions, tools and which ones have internet access?</p><p>The answer of course is no.</p><p>Think about the OpenAI and Hugging Face incident, that involved a misunderstanding between OpenAI and Irregular, a firm they use for cyber evaluations, and internet access wasn&#8217;t fully restricted despite the initial understanding that it was. This will be the case for many enterprise agent deployments as well.</p><p>We have decades of misconfigured ports, proxies, firewalls and other networking configurations to let us confidently say this will happen for enterprise agents too.</p><h2>Lack of Model Provider Cyber Classifiers</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pzht!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pzht!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png 424w, https://substackcdn.com/image/fetch/$s_!pzht!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png 848w, https://substackcdn.com/image/fetch/$s_!pzht!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png 1272w, https://substackcdn.com/image/fetch/$s_!pzht!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pzht!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png" width="1456" height="223" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:223,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82343,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pzht!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png 424w, https://substackcdn.com/image/fetch/$s_!pzht!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png 848w, https://substackcdn.com/image/fetch/$s_!pzht!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png 1272w, https://substackcdn.com/image/fetch/$s_!pzht!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7b7be4f-ff1b-485c-ba63-a5d1f46a3717_1922x294.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Next up on the list of potentially contributing factors to the AISI incident is a lack of model provider classifiers. Due to AISI&#8217;s unique role in the ecosystem, conducting evaluations and research, they were in a position to have the cyber classifiers disabled for their evaluations of the models involved in the incident. This is part of the model providers &#8220;<strong><a href="https://openai.com/index/scaling-trusted-access-for-cyber-defense/">Trusted Access</a></strong>&#8221; programs, with vetted partners.</p><p>For those unfamiliar, model providers implement safeguards known as classifiers to mitigate abuse and misuse of their models for nefarious purposes. I went into detail on this topic in a video I did about the potential for a CVSS for AI. </p><div id="youtube2-_ZCZwhXQk3I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;_ZCZwhXQk3I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/_ZCZwhXQk3I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Given the entire purpose of AISI&#8217;s cyber evals is to measure the cyber capabilities of the models and agents, it makes sense that cyber classifiers were disabled. That said, there are various implications for security practitioners and defenders on this front. </p><p>Those include the reality that there are plenty of other organizations within the frontier labs trusted access programs as well, even if they aren&#8217;t explicitly conducting cyber evals. There&#8217;s also the fact that the open weight frontier capability doesn&#8217;t lag too far behind the closed frontier, based on AISI&#8217;s on evaluations. AISI documented this in a blog titled &#8220;<strong><a href="https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber">How Far Behind the Frontier are Open Weight Models on Cyber?</a></strong>&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z0l8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z0l8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png 424w, https://substackcdn.com/image/fetch/$s_!z0l8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png 848w, https://substackcdn.com/image/fetch/$s_!z0l8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!z0l8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z0l8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png" width="1456" height="1116" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1116,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:640079,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z0l8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png 424w, https://substackcdn.com/image/fetch/$s_!z0l8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png 848w, https://substackcdn.com/image/fetch/$s_!z0l8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!z0l8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1115711a-3577-4b2d-b282-c57b8d355c84_2004x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So the gap between the closed models and open weights are narrowing in general, and on cyber. That means alternatives are and will be available for malicious actors to use, including versions with classifiers disabled, jailbroken, etc. along with a lack of oversight or monitoring of their usage for malicious activities, a point <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;105e66f9-2377-4b7e-aa0f-37e0f521cafc&quot;}" data-component-name="MentionToDOM"></span> has made in several blogs now and in my interview with him.</p><div id="youtube2-IHMLWDyCTFQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;IHMLWDyCTFQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/IHMLWDyCTFQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Lack of Synchronous LLM-based Monitoring</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w5nK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w5nK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png 424w, https://substackcdn.com/image/fetch/$s_!w5nK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png 848w, https://substackcdn.com/image/fetch/$s_!w5nK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png 1272w, https://substackcdn.com/image/fetch/$s_!w5nK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w5nK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png" width="1456" height="163" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:163,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73896,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w5nK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png 424w, https://substackcdn.com/image/fetch/$s_!w5nK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png 848w, https://substackcdn.com/image/fetch/$s_!w5nK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png 1272w, https://substackcdn.com/image/fetch/$s_!w5nK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa5a4966-a06e-4936-8891-2d239d9cbb20_1930x216.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>AISI moves on from the classifiers topic to discuss a lack of synchronous LLM-based monitoring. As they explain, this is a separate LLM that reviews each agents proposed action before execution. In the community, we often refer to this as &#8220;LLM-as-a-Judge&#8221;, knowing we don&#8217;t have enough human eyeballs or bandwidth to review machine-speed actions at-scale. </p><p>Both of the leading frontier labs in Anthropic and OpenAI already use this technique for their &#8220;auto modes&#8221; of their platforms.</p><p>This approach, much like the Rule-of-Two I discussed earlier also is imperfect, given we are monitoring the actions of a non-deterministic system with challenges such as hallucinations etc. with another LLM with the same constraints or characteristics. This doesn&#8217;t mean LLM-as-a-Judge isn&#8217;t useful, it definitely is, and we know humans can&#8217;t scale to meet the speed or complexity of agents, so it will be an approach we have to embrace, despite its shortcomings. </p><p>Tying this to my theme of implications for enterprise security leaders, this means we also need to be considering the use of LLM-as-a-Judge, often called &#8220;Guardian Agents&#8221; (a term Gartner has taken to) as a mechanism to mitigate the risks of agent actions at runtime. </p><p>That said, AISI even admins in their blog this is still an open-ended challenge, as it can be hard to decipher what is appropriate or not, and this is why we&#8217;ve seen a lot of conversations around topics such as &#8220;Intent Analysis&#8221; in the industry among AI security vendors and researchers.</p><p>In fact, AI security research firm Dreadode recently had an excellent blog on exactly this titled &#8220;<strong><a href="https://dreadnode.io/research/scope-judge-can-a-runtime-judge-keep-offensive-agents-in-scope/">Can a Runtime Judge Keep Offensive Agents In Scope</a></strong>&#8221;, and they found this is far from a solved problem, with no silver bullets, and even human evaluators disagreed about the appropriateness of tool calls for agents 1/8th of the time.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://dreadnode.io/research/scope-judge-can-a-runtime-judge-keep-offensive-agents-in-scope/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mJz1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png 424w, https://substackcdn.com/image/fetch/$s_!mJz1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png 848w, https://substackcdn.com/image/fetch/$s_!mJz1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png 1272w, https://substackcdn.com/image/fetch/$s_!mJz1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mJz1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png" width="512" height="265.14285714285717" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:754,&quot;width&quot;:1456,&quot;resizeWidth&quot;:512,&quot;bytes&quot;:2119702,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://dreadnode.io/research/scope-judge-can-a-runtime-judge-keep-offensive-agents-in-scope/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mJz1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png 424w, https://substackcdn.com/image/fetch/$s_!mJz1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png 848w, https://substackcdn.com/image/fetch/$s_!mJz1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png 1272w, https://substackcdn.com/image/fetch/$s_!mJz1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87990094-ab25-40f6-b3a3-40b2a705a035_1464x758.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Again, back to the implications for practitioners and security leaders, this is far from a solved problem for the community. We know humans can&#8217;t keep pace with agentic actions, but our use of LLM-as-a-Judge, Guardian Agents, or &#8220;Synchronous LLM-based Monitoring&#8221; as AISI calls it is an open-ended challenge, and if it is a challenge for the labs and leading researchers, it definitely is a gap for security practitioners at most enterprises already deploying agents as well.</p><h2>Prompt Misconfiguration</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6xtz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6xtz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png 424w, https://substackcdn.com/image/fetch/$s_!6xtz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png 848w, https://substackcdn.com/image/fetch/$s_!6xtz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png 1272w, https://substackcdn.com/image/fetch/$s_!6xtz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6xtz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png" width="1456" height="152" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:152,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66946,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6xtz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png 424w, https://substackcdn.com/image/fetch/$s_!6xtz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png 848w, https://substackcdn.com/image/fetch/$s_!6xtz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png 1272w, https://substackcdn.com/image/fetch/$s_!6xtz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45ef7fc2-05f8-45ab-a902-27aa250eec7a_1874x196.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Then we have prompt misconfiguration. In short, AISI found that the prompt samples used included some that would have required accessing a network that should have been out of scope for the evals. </p><p>They state:</p><blockquote><p><strong>&#8221;This is notable because AI agents faced with tasks that cannot be completed within their stated constraints are more likely to take unsanctioned actions, as they resort to &#8220;creative&#8221; solutions when legitimate approaches fail.&#8221;</strong></p></blockquote><p>Or to put it bluntly as I said above, &#8220;<em>agents find a way</em>&#8221;. When agents encounter constraints that impede their goals or objectives, they will utilize many different and often unexpected means to work around those constraints. AISI even discussed how in several cases despite something being explicitly declared out of scope, the agent moved forward anyways. </p><p>This is something I&#8217;ve covered in great detail in a prior blog titled &#8220;<strong><a href="https://www.resilientcyber.io/p/agents-have-boundary-issues">Agents Have Boundary Issues</a></strong>&#8221;, where I pointed out that soft guardrails (e.g. system prompts etc.) are far from effective security controls, and even hard boundaries can be sidestepped by persistent agents. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E2No!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E2No!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png 424w, https://substackcdn.com/image/fetch/$s_!E2No!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png 848w, https://substackcdn.com/image/fetch/$s_!E2No!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png 1272w, https://substackcdn.com/image/fetch/$s_!E2No!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E2No!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png" width="530" height="496.3492063492063" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1180,&quot;width&quot;:1260,&quot;resizeWidth&quot;:530,&quot;bytes&quot;:704479,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E2No!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png 424w, https://substackcdn.com/image/fetch/$s_!E2No!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png 848w, https://substackcdn.com/image/fetch/$s_!E2No!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png 1272w, https://substackcdn.com/image/fetch/$s_!E2No!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9e1861a-9faf-46e2-8ab9-d75da29c768e_1260x1180.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Again, as someone who regularly reads AISI&#8217;s blog, this is a topic they have covered in their previous research as well in a blog titled &#8220;<strong><a href="https://www.aisi.gov.uk/blog/cheating-behaviour-in-frontier-model-evaluations">Cheating behavior in frontier model evaluations</a></strong>&#8221;. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8C3J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8C3J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png 424w, https://substackcdn.com/image/fetch/$s_!8C3J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png 848w, https://substackcdn.com/image/fetch/$s_!8C3J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png 1272w, https://substackcdn.com/image/fetch/$s_!8C3J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8C3J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png" width="1456" height="679" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:679,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:267111,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8C3J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png 424w, https://substackcdn.com/image/fetch/$s_!8C3J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png 848w, https://substackcdn.com/image/fetch/$s_!8C3J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png 1272w, https://substackcdn.com/image/fetch/$s_!8C3J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37e06962-f3a7-4c3c-8c20-7535faab8e60_1918x894.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Models cheat quite often, as they seek to achieve their goals and objectives and it often involves &#8220;creatively&#8221; working around their constraints. </p><p>This one is a bit scary for security practitioners because even if we implement various measures to mitigate organizational risks (e.g. relying on classifiers, LLM-as-a-Judge, hard architectural boundaries/controls etc.) there is still a good chance that the models and agents will work around them if they are impeding their successful pursuit of a goal. </p><p>It is easy to see the risks for enterprise agents, as users will be far less rigorous with their prompting, clarity to the agents, constraints and specifications as agents take actions within and beyond the enterprise. </p><h2>Lack of Clarity of Exercise Scope</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M5UK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M5UK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png 424w, https://substackcdn.com/image/fetch/$s_!M5UK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png 848w, https://substackcdn.com/image/fetch/$s_!M5UK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png 1272w, https://substackcdn.com/image/fetch/$s_!M5UK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M5UK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png" width="1456" height="157" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:157,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63670,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/210075609?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M5UK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png 424w, https://substackcdn.com/image/fetch/$s_!M5UK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png 848w, https://substackcdn.com/image/fetch/$s_!M5UK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png 1272w, https://substackcdn.com/image/fetch/$s_!M5UK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0015a83e-ea89-4190-a3a3-be4656d7553f_1860x200.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>AISI rounds out the list of factors that could of potential contributed to the incident by discussing a lack of clarity of exercise scope. </p><p>Surely no enterprise users will provide unclear or ambiguous instructions to LLM&#8217;s and agents in their enterprises, right? </p><p>This one is among the most obvious to see how it can and will be problematic for security leaders, as not just development and technical users, but broader knowledge workers now leverage agents and this emerging technology to accomplish not just software development or cyber, but broader white collar tasks in their professional environments and roles. </p><p>AISI stated:</p><blockquote><p><br><strong>&#8221;The prompts could have, for example, instructed the AI agent not to use social engineering techniques &#8211; a recognised part of cyber tradecraft. Alternatively, the prompts could have instructed the model to err on the side of caution whenever it might be interacting with real humans; however, it remains unclear whether, or at what point, the agents recognised they were targeting real people&#8221;</strong></p></blockquote><p>Think about the implications of this one. This infers that users, including non-technical users, will need to provide incredibly specific instructions around what agents shouldn&#8217;t do, as much as what they should. </p><p>Are most enterprise users who are and will be touching this technology deeply familiar with your security policies? Do they understand appropriate/acceptable use? Have they read the stack of dusty security policies most organizations maintain for compliance purposes but no one ever actually reads?</p><p>Of course not&#8230;</p><p>So not only do we have a situation where we have to try and provide explicitly clear instructions to agents, but even if we could get all the enterprise users, including citizen developers and knowledge workers to do so, as we saw in the section above about cheating, even then, the agents may disregard those instructions anyways.</p><p>This is&#8230;problematic, to put it lightly.</p><h1>Closing Thoughts</h1><p>So, to wrap up us, we now have 3, potentially 4 incident disclosures related to LLM&#8217;s and AI agents from leading labs and research entities, where agents took unsanctioned or unanticipated actions as part of cyber evaluations, impacting real-world infrastructure and individuals and exhibiting nefarious behavior while doing so.</p><p>While there is nuance, such as these being cyber evals, a lack of classifiers, intentional internet access and other factors, the implications for security leaders and enterprises is clear. </p><p>We&#8217;re seeing this technology adopted at a pace we have never seen before, with a technology adoption J curve like a hockey stick, with agents on endpoints, cloud, SaaS and more. </p><p>Security is doing our best to keep pace, leveraging this technology as an early adopter and innovator ourselves, and looking to avoid our sins of the past as a late adopter and laggard. </p><p>But, even then, the anticipated challenges due to the people, process and technology paradigm in enterprise environments is stark, there will inevitably be governance gaps, misconfigurations, vulnerabilities and even intentional exploitation. </p><p>They say success leaves clues, well so does failure. </p><p>We have an opportunity to learn from the AI security frontier to try and ensure we enable our organizations with secure AI agent adoption, by avoiding some of the missteps of those blazing the trail ahead of us - but we have to be willing to look for the clues.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Real Price Tag On Cyber Breaches]]></title><description><![CDATA[What breaches actually cost organizations, from the team behind the DBIR]]></description><link>https://www.resilientcyber.io/p/the-real-price-tag-on-cyber-breaches</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-real-price-tag-on-cyber-breaches</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Wed, 05 Aug 2026 18:57:24 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/209960611/cf10578cf2ccef988dcbb362b9098454.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode, I sit down with Alex Pinto, who leads the Data Breach Investigations Report team at Verizon, to discuss the team&#8217;s new <strong><a href="https://www.verizon.com/business/resources/reports/2026-breach-impact-study-dbir.pdf">Breach Impact Study</a></strong> and what data breaches actually cost, including why the study measures insurable loss as a floor rather than a ceiling, why medians beat averages, and what the claims data does and does not tell us about AI.</p><p>If you missed it, I did a deep dive blog into the report titled &#8220;<strong><a href="https://www.resilientcyber.io/p/the-real-price-tag-on-breaches">The Real Price Tag on Breaches</a></strong>&#8221;.</p><p>I&#8217;ve spent a lot of time pushing back on the fear-based statistics that dominate this industry, so a study built on roughly 70,000 real cyber insurance claims is exactly the kind of grounding the conversation has been missing. Alex and his team put concrete numbers behind questions we usually answer with anecdotes, and they were careful about what those numbers can and cannot say.</p><p>We chatted about:</p><ul><li><p>How the Breach Impact Study came together and why the DBIR team finally landed a cyber insurance claims dataset through CyberAcuView</p></li><li><p>Why insurable loss is a floor and not a ceiling, and why reputational damage barely moved the numbers</p></li><li><p>The decision to report medians instead of averages, including the footnote about not publishing the average so LLMs don&#8217;t spread it around</p></li><li><p>The rise of business interruption and contingent business interruption, and the sub-limits that hid the real damage</p></li><li><p>Whether an $83,000 median breach impact hands the wrong argument to a skeptical CFO</p></li><li><p>The SMB paradox, where small companies can lose up to 7% of revenue while large enterprises rarely cross 2%</p></li><li><p>Where AI actually shows up in the data, and why offense is running ahead of defense</p></li><li><p>Third-party risk as the industry&#8217;s persistent blind spot</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><div id="youtube2-GUz0Oh7asac" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;GUz0Oh7asac&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/GUz0Oh7asac?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2><strong>Prefer to listen?</strong></h2><p><strong><a href="https://open.spotify.com/episode/2zi7AZIWt6GpkfbZ59iHxX?si=9HEnVNTQSWKGZIkSmQnxxw">Spotify</a></strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/the-real-price-tag-on-cyber-breaches/id1555928024?i=1000780100068">Apple Podcasts</a></strong></p><p><strong>Please be sure to leave a rating and review, as it truly helps the show!</strong></p><div><hr></div><h1>A few takeaways:</h1><h3>Insurable loss is a floor, and business interruption is what moves the needle</h3><p>The study only counts dollars paid through real policies, which Alex is upfront about calling a floor rather than a ceiling of the true economic impact. The team tried to measure reputational damage a few years back by cross-referencing known breaches against stock movements and found almost nothing. </p><p>As Alex put it, from the consumer side &#8220;nobody cares anymore,&#8221; and he probably has a couple lifetimes of credit monitoring to prove it. What actually changes behavior is downtime. &#8220;The thing that will move decision making is business interruption,&#8221; he said, and the data backs him up, with business interruption landing at roughly a third of all known losses in 2024. That is the number that gets an organization to treat this as a real problem.</p><h3>The average is meaningless, the distribution is the point</h3><p>Alex is blunt about why the team reports medians and refuses to publish an average. &#8220;It&#8217;s just that the information is meaningless for decision making,&#8221; he said. A five million dollar average headline, like the one making the rounds from another report, tells a company nothing about the risk it is actually accepting. </p><p>The percentiles do. For companies above $250 million in revenue, the top 2.5% of cases exceeded $22 million, which is the kind of figure an operational risk team can take to a board and decide how much of the distribution they want to be covered against. The single number is comfortable. The distribution is useful.</p><h3>An $83K median does not mean breaches are cheap</h3><p>I raised a concern I have heard from others, that dropping a median of around $83,000 in front of an executive invites the response that breaches are survivable and it might be cheaper to just eat the cost. </p><p>Alex did not hedge. &#8220;I think that&#8217;s a bad CFO,&#8221; he said, and made the point that the person reading that figure should be someone who understands what a distribution like that means. Any large company that looks at the median and ignores that its size alone puts it in the extreme tail is not doing operational risk properly. The report&#8217;s whole argument is to plan against the extreme cases, not the midpoint.</p><h3>Small companies take the hardest proportional hit</h3><p>The most uncomfortable finding for me is that SMBs can lose up to 7% of revenue in the extreme cases while large enterprises rarely cross 2%. The median SMB loss is a modest $38,000, but measured against revenue and thin cash flow it becomes existential, especially since an insurance payout is not automatic and you have to survive long enough to receive it. </p><p>Alex connected this to Wendy Nather&#8217;s cybersecurity poverty line and made a point I care about deeply. Ransomware crews moved down market a long time ago and industrialized the work, so being small is no longer a defense. It just changes the size of the ask.</p><h3>AI is real, but offense is ahead of defense</h3><p>I told Alex I could not find AI as an obvious fingerprint anywhere in the loss numbers, and he agreed the claims data simply does not carry that detail yet. The bigger problem is structural, since the DBIR anonymizes each dataset independently and cannot cross-correlate AI-assisted attacks with claims. What he is confident about is the direction. </p><p>&#8220;Offensive AI augmentation is way, way ahead of the curve than the defensive one,&#8221; he said, and everyone assuming a tidy AI versus AI showdown is ignoring that one fighter has a mean left hook and the other has not found its footing. His practical read is to stop waiting and rethink architecture. On taking flat networks and internet-exposed edge devices seriously, his line stuck with me. &#8220;The best time to do that was fifteen years ago. Maybe the second best time is now.&#8221;</p><p>If there is one thing to do on Monday, Alex pointed at third-party risk. Supply chain incidents are the single most likely to fully exhaust a policy, which means the recorded loss is a coverage cap and not the real number. His takeaway was direct. &#8220;Do not underestimate the impact that your third party can have.&#8221; Even the insurers, who understand risk better than most of us, have been caught off guard by it.</p><p>Thanks to Alex for coming on and for putting real numbers behind a conversation the industry usually runs on vibes. Follow his work through the <strong><a href="https://www.verizon.com/business/resources/reports/dbir/">Verizon DBIR</a></strong> and the new <strong><a href="https://www.verizon.com/business/resources/reports/2026-breach-impact-study-dbir.pdf">Breach Impact Study</a></strong>, and find him on <strong><a href="https://www.linkedin.com/in/alexcpsec/">LinkedIn</a></strong>.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Following the Smart Money into Black Hat]]></title><description><![CDATA[A look back at my recent conversations with four of the sharpest investors in cyber, and the themes tying them together.]]></description><link>https://www.resilientcyber.io/p/following-the-smart-money-into-black</link><guid isPermaLink="false">https://www.resilientcyber.io/p/following-the-smart-money-into-black</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 03 Aug 2026 11:57:46 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/1f16e98b-e75d-43ab-bb3d-7aa21dc64354_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Heading into Black Hat, it is clear that the two forces reshaping our industry, AI and the capital chasing it, are colliding at once. </p><p>Valuations are stretching, incumbents are writing enormous checks, and founders are trying to build durable companies on top of a technology that reinvents itself every few months. That said, the people who see this landscape most clearly are often the investors placing bets across it, watching dozens of companies rise, stall, and get acquired.</p><p>Over the past few weeks I sat down with four of them,<strong><a href="https://www.linkedin.com/in/siddhanttrivedi/"> Sid Trivedi (Foundation Capital)</a></strong>, <strong><a href="https://www.linkedin.com/in/edsim/">Ed Sim (Boldstart Ventures)</a></strong>, <strong><a href="https://www.linkedin.com/in/jonsakoda/">Jon Sakoda (Decibel)</a></strong>, and <strong><a href="https://www.linkedin.com/in/chenxiwang88/">Chenxi Wang (Rain Capital)</a></strong>, to talk through where the money is going and why. Below is a short recap of each conversation, followed by the threads that ran through all of them. </p><p>So, let&#8217;s get into it!</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><strong><a href="https://www.resilientcyber.io/p/cyber-valuations-moats-and-the-road">Sid Trivedi - Cyber Valuations, Moats &amp; the Road to Black Hat</a></strong></h2><div id="youtube2-8wBZitdpRR0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;8wBZitdpRR0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/8wBZitdpRR0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>In our <strong><a href="https://www.resilientcyber.io/p/cyber-valuations-moats-and-the-road">conversation on cyber valuations, moats, and the road ahead</a></strong>, Sid Trivedi, a Partner at Foundation Capital, walked through the thesis his firm has been building around for a while now, what they call Services-as-Software. The idea is to look at every task and team across cybersecurity and ask which workflows can be automated, a market Foundation Capital has sized at $4.6 trillion. In Sid&#8217;s view, that thesis is largely playing out as expected.</p><blockquote><p><strong>The workforce question came up quickly, as it always does. Sid takes a measured line, telling me &#8220;I don&#8217;t worry that long term people will lose the ability to work. I think the jobs themselves will change.&#8221; </strong></p></blockquote><p>Automation reshapes the work rather than eliminating the worker, a framing I appreciate given how much of the AI conversation collapses into fear.</p><p>We also dug into valuations and defensibility, which is where things get harder. This is the era of Palo Alto&#8217;s $25 billion acquisition of CyberArk and Alphabet&#8217;s $32 billion acquisition of Wiz, of Torq crossing a billion-dollar valuation and Seven AI raising the largest cyber Series A on record. </p><p>Sid&#8217;s caution is that big raises create growth expectations that capital alone cannot fulfill, and that when frontier labs can replicate a product feature in weeks, the traditional notion of a moat starts to look shaky. Consolidation and best-of-breed will keep coexisting, but defensibility now has to come from something deeper than a feature set.</p><h2><a href="https://www.resilientcyber.io/p/why-ai-security-is-getting-rebuilt">Ed Sim - Building and Investing When Mythos Changed Everything</a></h2><div id="youtube2-mmBTiRQgDsY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;mmBTiRQgDsY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/mmBTiRQgDsY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ed Sim&quot;,&quot;id&quot;:3093019,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/117206c8-d2bf-460a-bfe4-f63ab22b79d3_2917x3582.png&quot;,&quot;uuid&quot;:&quot;92af088f-7b16-4489-97a6-9e90b29ce997&quot;}" data-component-name="MentionToDOM"></span> has been an inception-stage investor for nearly 30 years and has run Boldstart Ventures since 2010, with roughly a third of the firm&#8217;s investments in cybersecurity. In our <strong><a href="https://www.resilientcyber.io/p/why-ai-security-is-getting-rebuilt">discussion on why AI security is getting rebuilt</a></strong>, he made the case that much of the security stack is being re-architected in real time, and that the durable moats of the past, which used to last twelve to eighteen months, now erode much faster.</p><p>Ed&#8217;s blunt read on the market has stuck with me. </p><blockquote><p><strong>&#8220;The world needs more cybersecurity, but we don&#8217;t need all the cybersecurity companies that we have right now,&#8221; he told me, a line that captures both the demand and the coming shakeout. </strong></p></blockquote><p>He was an early investor in Protect AI, which went on to sell to Palo Alto Networks in a reported $700 million exit.</p><p>Two ideas from Ed stuck with me from the conversation. The first is data, where he argued that &#8220;the biggest heist ever happening right now is that OpenAI and Anthropic created their own forward deployed engineering companies,&#8221; a pointed way of naming who actually captures the value from enterprise workflows. </p><p>The second is agentic identity, which he frames as a genuine category rather than a feature to bolt on, built around ephemeral, dynamic identities rather than the static accounts we manage today. Across portfolio companies like Keycard, and Surf AI, that thesis about identity and agents is where he sees a lot of the next wave forming, even as agents remain a small share of what is actually running in production.</p><h2><a href="https://www.resilientcyber.io/p/ai-cyber-and-where-the-smart-money">Jon Sakoda - AI, Cyber &amp; Where the Smart Money Is Going</a></h2><div id="youtube2-UbUIJdXv8Uk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;UbUIJdXv8Uk&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/UbUIJdXv8Uk?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Jon Sakoda, Founding Partner at Decibel and previously an investor behind companies like Cloudflare, MongoDB, and HackerOne during his time at NEA, brought the sharpest framing on separating signal from noise. </p><p>In our <strong><a href="https://www.resilientcyber.io/p/ai-cyber-and-where-the-smart-money">conversation on AI, cyber, and where the smart money is going</a></strong>, he pushed back on the idea that AI alone makes a company special. </p><blockquote><p><strong>As he put it, &#8220;AI is really only magical to the extent you have a magic power.&#8221; AI lowers the barrier to starting up, which means competition goes from thousands of entrants to millions, and domain expertise becomes the thing that actually differentiates.</strong></p></blockquote><p>Endpoint is where Jon is putting real conviction behind that view. He calls it &#8220;the Super Bowl of cyber&#8221; and points to Decibel&#8217;s $100 million seed investment in Ent, founded by veterans of RiskIQ and the Microsoft Security Copilot team, as commitment sizing for a market big enough to take on the incumbents. He describes endpoint as having its own self-driving moment.</p><p>On the autonomous SOC, Jon is optimistic but patient. He likens tools like Claude Code to driver assistance for the SOC, useful today, while truly autonomous products still need to log a lot of operational miles before earning customer trust, the same way self-driving cars had to. His investment in Dropzone AI fits that arc. </p><p>Zooming out, Jon believes cyber&#8217;s best years are still ahead, and that resilience and cyber insurance may end up being larger opportunities than detection and response alone. It is a genuinely optimistic take, grounded in where budgets are actually heading.</p><h2><a href="https://www.resilientcyber.io/p/cyber-investing-in-the-ai-exploit">Chenxi Wang - Cyber Investing In the AI Exploit Era</a></h2><div id="youtube2-hwgPFd8akm4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;hwgPFd8akm4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/hwgPFd8akm4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Chenxi Wang&quot;,&quot;id&quot;:6566801,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ca082ba-e2f9-427e-b5fd-dbdabbe55746_1620x2160.jpeg&quot;,&quot;uuid&quot;:&quot;fcdb7944-c642-4305-9190-6b63c94ae0c0&quot;}" data-component-name="MentionToDOM"></span> , Founder and Managing General Partner at Rain Capital, is one of the most technical investors in the space, with a background spanning a professorship at Carnegie Mellon, an analyst seat at Forrester, and operating roles at Intel Security and Twistlock. In our <strong><a href="https://www.resilientcyber.io/p/cyber-investing-in-the-ai-exploit">discussion on cyber investing in the AI exploit age</a></strong>, she laid out how AI changes the economics for attackers, not just defenders.</p><blockquote><p><strong>Her central argument is that vulnerability discovery is shifting from something scarce to a continuous output of computation, and that the window between a vulnerability being found and being exploited is compressing from weeks toward hours.</strong> </p></blockquote><p>That reframes what a defensible security company even looks like, since strategies built around scarcity of exploits start to break down when exploitation becomes cheap and constant.</p><p>Out of that thesis comes her interest in what she calls guardian agents, AI systems that supervise and govern other AI, along with a hard look at AI agent identity as distinct from the non-human identities we already struggle with, the service accounts and API keys sprawled across every enterprise. Chenxi also had a clear-eyed view of the funding environment, describing capital concentrating at the extremes while Series B and C rounds face real constraints, a dynamic worth watching for any founder mapping out a raise. She also highlighted how cyber as a category is also tied to the broader IT and AI categories, and headwinds there could lead to headwinds for us.</p><p>For anyone who wants her ongoing analysis, her <strong><a href="https://raincapital.substack.com/">Rain Capital Insights</a></strong> newsletter reaches more than 23,000 readers with some of the sharpest monthly commentary on where AI and security collide.</p><h2>Common Threads</h2><p>Four investors, four different vantage points, and a striking amount of overlap. </p><ul><li><p>The clearest thread is the death of the durable moat. Both Sid and Ed circled the same problem, that when frontier labs can replicate features in weeks, defensibility has to come from proprietary data, distribution, and domain depth rather than functionality alone.</p></li><li><p>A second thread is identity. Ed and Chenxi both treat agentic identity as its own category, not a feature, driven by the reality that agents need ephemeral, auditable identities that our existing non-human identity practices were never designed to handle.</p></li><li><p>A third is the reshaping of security work itself, whether you call it Sid&#8217;s services-as-software or Jon&#8217;s self-driving SOC, the theme is automation of workflows we have long assumed required humans in the loop, tempered by the recognition that trust has to be earned over time.</p></li></ul><p>Finally, all four are watching the same bifurcated capital markets, enormous deals and record raises at the top, with real pressure in the middle. Chenxi named the Series B and C squeeze directly, and Sid&#8217;s caution about spending your way to growth is the flip side of the same coin, as it comes with potential tension and expectations among your investors.</p><h2>Closing Thoughts</h2><p>If there is a single takeaway heading into Black Hat, it is that AI is changing both sides of the equation at once, the economics of attack and the economics of building a company to defend against it. </p><p>The investors moving early are not the ones with the loudest AI messaging, they are the ones betting on data, identity, domain expertise, and the slow work of earning trust in autonomous systems. Whether the current valuations hold is very much up for debate. That said, it is clear that the smart money is already positioning for a market that looks very different from the one we walked into last year. </p><p>My thanks to Sid, Ed, Jon, and Chenxi for the conversations, and I would encourage you to listen to each interview in full!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Cyber Investing in the AI Exploit Era]]></title><description><![CDATA[Exploring what happens to security, and security investing, when vulnerability discovery becomes a continuous output of computation.]]></description><link>https://www.resilientcyber.io/p/cyber-investing-in-the-ai-exploit</link><guid isPermaLink="false">https://www.resilientcyber.io/p/cyber-investing-in-the-ai-exploit</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Sun, 02 Aug 2026 12:02:50 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/209408566/1fd50d79ca7c4b4d641dbbbd30191aa0.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode, I sit down with Founder and Managing General Partner at Rain Capital, Chenxi Wang, to discuss security investing in what she calls the AI Exploit Age. </p><p>Chenxi has seen this industry from the professor&#8217;s podium at Carnegie Mellon, the analyst seat at Forrester, the operator chair at Intel Security and Twistlock, and now the cap table, which makes her one of the most technical investors in security. She closed out my July run of conversations with security investors, and this one went deep on how AI is rewriting both the attacker&#8217;s economics and the investor&#8217;s.</p><p>We chatted about:</p><ul><li><p>Her path from professor to analyst to operator to founding Rain Capital</p></li><li><p>The AI Exploit Age, where vulnerability discovery moves from scarce to continuous and exploitation windows compress from weeks to hours</p></li><li><p>The Guardian Agent thesis and whether it really takes an AI to govern an AI</p></li><li><p>How AI agent identity differs from the traditional non-human identity bucket of service accounts and API keys</p></li><li><p>The signals that tell an early-stage investor enterprises will actually buy</p></li><li><p>Capital concentrating at the extremes while Series B and C funding stays constrained</p></li><li><p>What security leaders should be doing differently over the next twelve months</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 23,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><div id="youtube2-hwgPFd8akm4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;hwgPFd8akm4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/hwgPFd8akm4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2><strong>Prefer to listen? </strong></h2><p><strong><a href="https://podcasts.apple.com/us/podcast/cyber-investing-in-the-ai-exploit-era/id1555928024?i=1000779451943">Apple Podcasts</a></strong></p><p><strong><a href="https://open.spotify.com/episode/0va4frS2VV2lMjbzVHFpi5?si=QLFkOhU6S7yxgSxQzpniEg">Spotify</a></strong></p><p><strong>Please be sure to leave a rating and review, as it truly helps the show!</strong></p><div><hr></div><p>A big thanks to Chenxi for coming back on the show. You can follow her work through <strong><a href="http://raincapital.substack.com">Rain Capital Insights</a></strong>, where she writes some of the sharpest monthly commentary on where AI and security are colliding.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item></channel></rss>