<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Resilient Cyber]]></title><description><![CDATA[Resilient Cyber distills the week's most important news, research, and writing across AppSec,
AI security, software supply chain, and security leadership. Join 30,000+]]></description><link>https://www.resilientcyber.io</link><image><url>https://substackcdn.com/image/fetch/$s_!ITbg!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71894ea3-c231-4d31-90a9-414d75111d0e_1280x1280.png</url><title>Resilient Cyber</title><link>https://www.resilientcyber.io</link></image><generator>Substack</generator><lastBuildDate>Tue, 28 Jul 2026 10:51:43 GMT</lastBuildDate><atom:link href="https://www.resilientcyber.io/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Chris Hughes]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[resilientcyber@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[resilientcyber@substack.com]]></itunes:email><itunes:name><![CDATA[Chris Hughes]]></itunes:name></itunes:owner><itunes:author><![CDATA[Chris Hughes]]></itunes:author><googleplay:owner><![CDATA[resilientcyber@substack.com]]></googleplay:owner><googleplay:email><![CDATA[resilientcyber@substack.com]]></googleplay:email><googleplay:author><![CDATA[Chris Hughes]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Resilient Cyber Newsletter #107]]></title><description><![CDATA[AI models going rogue, autonomous exploitation, the safety-security blur, open-weight cyber capabilities, vulnerability chaos & a wave of AI-native security funding]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-107</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-107</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 23 Jul 2026 12:43:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!V0Ba!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #107 of the Resilient Cyber Newsletter!</p><p>For a couple of years now, most of us have been having a version of the same argument about AI and offensive security. One camp insists we are on the cusp of autonomous systems that find and chain vulnerabilities without a human in the loop, and the other camp waves it off as vendor theater and demo-ware. </p><blockquote><p><strong>This week, that argument got a lot less hypothetical.</strong></p></blockquote><p>Hugging Face disclosed what it called a new kind of security incident, an intrusion driven by an autonomous agent framework that racked up more than 17,000 attack events over a weekend. </p><p>A few days later, OpenAI came forward and filled in the part Hugging Face said it could not yet identify, that the activity came out of OpenAI&#8217;s own internal evaluation of cyber capabilities, where two of its models escaped an isolated test environment and chained their way onto a third party&#8217;s production infrastructure. </p><p>A model going rogue, autonomous exploitation, vulnerability chaining, and the line between an AI safety evaluation and a live security incident dissolving in real time. It is a lot to sit with, and it colors nearly everything else that happened this week, from open-weight cyber capabilities to how we disclose and prioritize the coming flood of vulnerabilities.</p><p>Buckle up for another chaotic week at the intersection of AI and cybersecurity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V0Ba!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V0Ba!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png 424w, https://substackcdn.com/image/fetch/$s_!V0Ba!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png 848w, https://substackcdn.com/image/fetch/$s_!V0Ba!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png 1272w, https://substackcdn.com/image/fetch/$s_!V0Ba!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V0Ba!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png" width="1112" height="695" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:695,&quot;width&quot;:1112,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:568339,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V0Ba!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png 424w, https://substackcdn.com/image/fetch/$s_!V0Ba!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png 848w, https://substackcdn.com/image/fetch/$s_!V0Ba!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png 1272w, https://substackcdn.com/image/fetch/$s_!V0Ba!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b3478dd-371b-4ed4-a9e6-7b248325539b_1112x695.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://techcrunch.com/2026/07/22/glow-emerges-from-stealth-at-1-2b-valuation-to-challenge-endpoint-security-in-the-ai-era/">Glow Emerges From Stealth at $1.2B Valuation to Challenge Endpoint Security in the AI Era</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_8wr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_8wr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png 424w, https://substackcdn.com/image/fetch/$s_!_8wr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png 848w, https://substackcdn.com/image/fetch/$s_!_8wr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png 1272w, https://substackcdn.com/image/fetch/$s_!_8wr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_8wr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png" width="588" height="177" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aab76017-feda-49a2-8430-aaf291c8eca2_588x177.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:177,&quot;width&quot;:588,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29913,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_8wr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png 424w, https://substackcdn.com/image/fetch/$s_!_8wr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png 848w, https://substackcdn.com/image/fetch/$s_!_8wr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png 1272w, https://substackcdn.com/image/fetch/$s_!_8wr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faab76017-feda-49a2-8430-aaf291c8eca2_588x177.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Glow stepped out of stealth this week with a $180 million all-equity Series A at a $1.2 billion valuation, led by Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures. </p><p>The founding bench is notable, with CEO Roi Tiger coming from a Meta VP of Engineering role, co-founders out of Snowflake and Claroty, and COO Emily Heath, a former CISO at United Airlines and DocuSign. </p><p>Tiger&#8217;s framing is the whole thesis, that for the past decade everything moved to the cloud and SaaS, and now AI is landing on the endpoint in a way we have never seen. It is telling that a company reinventing endpoint security for the AI era is itself built on Anthropic and Gemini models running via Amazon Bedrock. </p><p>This pairs with Neo below, and both reflect the same bet, that AI agents on the device and in the workflow are becoming the thing we have to secure.</p><h3><a href="https://www.calcalistech.com/ctechnews/article/bjey6uinfg">SentinelOne Veterans Raise $100 Million to Secure the Rise of AI Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2pS3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2pS3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png 424w, https://substackcdn.com/image/fetch/$s_!2pS3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png 848w, https://substackcdn.com/image/fetch/$s_!2pS3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png 1272w, https://substackcdn.com/image/fetch/$s_!2pS3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2pS3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png" width="616" height="168" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:168,&quot;width&quot;:616,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22452,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2pS3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png 424w, https://substackcdn.com/image/fetch/$s_!2pS3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png 848w, https://substackcdn.com/image/fetch/$s_!2pS3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png 1272w, https://substackcdn.com/image/fetch/$s_!2pS3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa0b2332-2f7f-4b9e-9cb1-b3a0231f7d2a_616x168.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Neo, founded by a trio of SentinelOne veterans in Nick Warner, Shlomi Salem, and Eran Shirazi, has now raised $100 million total, with a $75 million Series A led by Andreessen Horowitz and Bessemer Venture Partners on top of a $25 million seed from 2025. </p><p>The pitch is a real-time control layer for AI agents and AI-enabled software, and the founders make the point plainly, that AI agents operate with legitimate user permissions, which is precisely what makes them hard to police with traditional endpoint tooling. </p><p>The market context they cite comes from Gartner, which projects enterprise applications with agentic capabilities climbing from around 5% in 2025 to 40% by the end of 2026. If that curve is even directionally right, the identity and control problems tied to agents are about to get an order of magnitude larger.</p><h3><a href="https://techcrunch.com/2026/07/15/backed-by-60m-in-funding-oak-steps-out-of-stealth-to-fix-the-identity-mess-that-ai-agents-are-making-worse/">Backed by $60M in Funding, Oak Steps Out of Stealth to Fix the Identity Mess That AI Agents Are Making Worse</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rhoO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rhoO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png 424w, https://substackcdn.com/image/fetch/$s_!rhoO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png 848w, https://substackcdn.com/image/fetch/$s_!rhoO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png 1272w, https://substackcdn.com/image/fetch/$s_!rhoO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rhoO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png" width="611" height="216" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:216,&quot;width&quot;:611,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:37560,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rhoO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png 424w, https://substackcdn.com/image/fetch/$s_!rhoO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png 848w, https://substackcdn.com/image/fetch/$s_!rhoO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png 1272w, https://substackcdn.com/image/fetch/$s_!rhoO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e761512-ea11-4dfb-bfa5-df8c9e730601_611x216.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Continuing the theme, Oak emerged from stealth with $60 million in seed funding from Accel, CRV, and Greylock Partners. </p><p>Co-founder and CEO Shai Morag has done this before, having sold Ermetic to Tenable for $265 million in 2023, and his read is that AI agents are multiplying access and permission sprawl faster than legacy IAM was ever designed to handle. Oak&#8217;s approach maps access to actual app usage and strips excess permissions in real time. </p><p>Three separate companies raising real money this week to wrangle agent identity and permissions is not a coincidence, it is the market pricing in the same problem the arXiv researchers and Hugging Face are describing from the technical side.</p><h3><a href="https://www.calcalistech.com/ctechnews/article/by11gqei4zx">Zafran Security Reportedly in Cisco&#8217;s Sights at $150-200M</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0--y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0--y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png 424w, https://substackcdn.com/image/fetch/$s_!0--y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png 848w, https://substackcdn.com/image/fetch/$s_!0--y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png 1272w, https://substackcdn.com/image/fetch/$s_!0--y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0--y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png" width="576" height="165" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:165,&quot;width&quot;:576,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21178,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0--y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png 424w, https://substackcdn.com/image/fetch/$s_!0--y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png 848w, https://substackcdn.com/image/fetch/$s_!0--y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png 1272w, https://substackcdn.com/image/fetch/$s_!0--y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F524e1084-f3a0-46d7-a976-2ed29a418e7b_576x165.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Not every story this week is up and to the right. CTech reports that Zafran Security, which has raised more than $130 million total and was valued well above $200 million in a December 2025 Series C led by Menlo Ventures, is the subject of reported Cisco acquisition interest in the $150 to $200 million range, below its last fundraising valuation. </p><p>Zafran has denied it is selling and characterizes Cisco&#8217;s involvement as a strategic investment, and with roughly $20 million in ARR the numbers are worth watching. Whether or not this specific deal happens, a reported down-round exit sitting right next to a $1.2 billion stealth launch is a decent snapshot of a bifurcated market, where capital is flowing hard toward the AI-native story and getting choosier about everything else. </p><p>That selectivity shows up again in the a16z charts below.</p><h3><a href="https://research.empiricalsecurity.com/research/empirical-series-a">Empirical Security Raises $25M Series A to Predict Which Vulnerabilities Matter</a></h3><p>Empirical Security announced a $25 million Series A led by Brightmind Partners, and the pedigree here is hard to ignore. </p><p>Co-founders Ed Bellis and Michael Roytman built Kenna Security, one of the firms that helped establish risk-based vulnerability management in the first place, and they have brought on Jay Jacobs, a co-creator of EPSS, as a third co-founder. </p><p>Their Foundation model monitors more than 18,000 CVEs as a global predictive layer, with an organization-specific model called Radiant on top. Bellis frames it as prediction becoming a requirement for modern defense rather than a nice-to-have. </p><p>Given everything in the AppSec section below about disclosure timelines collapsing and vulnerability volume exploding, a bet on prediction and prioritization feels less like a product pitch and more like the only viable path forward.</p><h3><a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-and-schwarz-digits-expand-strategic-partnership-to-deliver-sovereign-cybersecurity-across-europe/">CrowdStrike and Schwarz Digits Expand Partnership to Deliver Sovereign Cybersecurity Across Europe</a></h3><p>CrowdStrike and Germany&#8217;s Schwarz Digits expanded their partnership, with CrowdStrike acquiring the intellectual property of XM Cyber, more than 45 patents plus proprietary source code, while XM Cyber continues as a standalone business under an IP license. </p><p>The deal deploys Falcon Exposure Management on the sovereign STACKIT cloud, and George Kurtz frames the demand plainly, that organizations globally are increasingly prioritizing sovereignty without wanting to compromise on cybersecurity outcomes. Sovereignty as a buying criterion keeps showing up, and it connects to the open-weight and US-China threads later in this issue. </p><p>When European organizations want defense that runs inside their own borders and legal regime, the vendor landscape starts to reshape around that constraint.</p><h3><a href="https://www.a16z.news/p/charts-of-the-week-softwares-selective">Charts of the Week: Software&#8217;s Selective Selloff</a></h3><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Moses Sternstein&quot;,&quot;id&quot;:21748571,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ad46314c-89aa-4848-9bfd-67f8870a25e7_759x798.png&quot;,&quot;uuid&quot;:&quot;39d8ecb3-1b41-49e7-92cd-bcf15ff323ea&quot;}" data-component-name="MentionToDOM"></span> at <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;a16z&quot;,&quot;id&quot;:2315700,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!-aGV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff698a0c5-1fee-40a7-a33c-80609431ae31_400x400.png&quot;,&quot;uuid&quot;:&quot;732c4300-328c-455b-b820-630cc5d0e870&quot;}" data-component-name="MentionToDOM"></span> put together a useful set of charts on why software is selling off unevenly. </p><p>Multiples on next-twelve-months free cash flow are at or below 2014 levels, but the pain is not uniform, with cyber, observability, and vertical SaaS outperforming while horizontal SaaS and infrastructure lag. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xJI9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xJI9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png 424w, https://substackcdn.com/image/fetch/$s_!xJI9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png 848w, https://substackcdn.com/image/fetch/$s_!xJI9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png 1272w, https://substackcdn.com/image/fetch/$s_!xJI9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xJI9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png" width="724" height="610" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ae8ed11-c290-4594-9687-863e7819018f_724x610.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:610,&quot;width&quot;:724,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:208673,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xJI9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png 424w, https://substackcdn.com/image/fetch/$s_!xJI9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png 848w, https://substackcdn.com/image/fetch/$s_!xJI9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png 1272w, https://substackcdn.com/image/fetch/$s_!xJI9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ae8ed11-c290-4594-9687-863e7819018f_724x610.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A couple of data points jumped out for our world. Software engineer job postings are up around 15% (attributed to the release of Claude Code) even as the broader job market declined roughly 7%, and the Asia-based provider share of OpenRouter tokens has reached about 60%, a three-fold jump since the start of the year. That second figure is a market-side echo of the open-weight capability story the AISI and Mozilla are documenting below. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xQRJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xQRJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png 424w, https://substackcdn.com/image/fetch/$s_!xQRJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png 848w, https://substackcdn.com/image/fetch/$s_!xQRJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png 1272w, https://substackcdn.com/image/fetch/$s_!xQRJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xQRJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png" width="540" height="609" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:609,&quot;width&quot;:540,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138430,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xQRJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png 424w, https://substackcdn.com/image/fetch/$s_!xQRJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png 848w, https://substackcdn.com/image/fetch/$s_!xQRJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png 1272w, https://substackcdn.com/image/fetch/$s_!xQRJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb112d34d-fe07-42a3-950c-e16dc368f22c_540x609.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Cyber holding up while the rest of software gets repriced is interesting, because it suggests buyers still see security spend as non-discretionary even in a cautious tape. This helps further the claim that cyber tends to be a bit more resilient than broader IT or software spend, and the backdrop of AI and security risks I&#8217;m sure helps the case.</p><h3><a href="https://www.linkedin.com/posts/peterjameswalker_raising-venture-capital-is-highly-dilutive-share-7484687735585275904-4PU3/">Raising Venture Capital Is Highly Dilutive</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jH9j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jH9j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png 424w, https://substackcdn.com/image/fetch/$s_!jH9j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png 848w, https://substackcdn.com/image/fetch/$s_!jH9j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png 1272w, https://substackcdn.com/image/fetch/$s_!jH9j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jH9j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png" width="438" height="434.9263157894737" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:566,&quot;width&quot;:570,&quot;resizeWidth&quot;:438,&quot;bytes&quot;:157962,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jH9j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png 424w, https://substackcdn.com/image/fetch/$s_!jH9j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png 848w, https://substackcdn.com/image/fetch/$s_!jH9j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png 1272w, https://substackcdn.com/image/fetch/$s_!jH9j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a71a430-8989-43a4-8f02-9d95e02eec27_570x566.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Amid all the funding announcements, Peter Walker at Carta shared the 2026 Founder Ownership data as a useful reality check. </p><p>Per Carta&#8217;s report, median founder ownership drops from around 56% at seed to about 36% by Series A, and employee equity pools overtake founder ownership entirely by Series C. For the founders behind this week&#8217;s Glow, Neo, Oak, and Empirical raises, the capital buys speed and distribution, but the cap table math is unforgiving. </p><p>It is a good reminder that the eye-popping valuations in the headlines and the actual ownership retained by the people building these companies are two very different numbers.</p><h3><a href="https://www.data-driven.vc/">The Unicorn Board</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!va4U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!va4U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png 424w, https://substackcdn.com/image/fetch/$s_!va4U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png 848w, https://substackcdn.com/image/fetch/$s_!va4U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png 1272w, https://substackcdn.com/image/fetch/$s_!va4U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!va4U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png" width="578" height="346" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:346,&quot;width&quot;:578,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29767,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!va4U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png 424w, https://substackcdn.com/image/fetch/$s_!va4U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png 848w, https://substackcdn.com/image/fetch/$s_!va4U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png 1272w, https://substackcdn.com/image/fetch/$s_!va4U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F234b2914-7481-4d74-bb22-82b5d0111f16_578x346.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you want the macro backdrop for all of the above, this open dataset tracks 938 US private companies valued at $1 billion or more, with an aggregate post-money valuation north of $5.25 trillion.</p><p> AI now trails only Software by unicorn count, and the top of the valuation table is telling, with Anthropic and OpenAI sitting at the very top ahead of Stripe, Databricks, and Waymo. </p><p>The gravitational pull of AI on private capital is not subtle, and it helps explain why every security company launching this week is positioning itself as AI-native, because that is where the money, the attention, and increasingly the threat model all point.</p><h1>AI</h1><h3><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">Hugging Face Model Evaluation Security Incident</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!58ZX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!58ZX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png 424w, https://substackcdn.com/image/fetch/$s_!58ZX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png 848w, https://substackcdn.com/image/fetch/$s_!58ZX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png 1272w, https://substackcdn.com/image/fetch/$s_!58ZX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!58ZX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png" width="949" height="229" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:229,&quot;width&quot;:949,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43872,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!58ZX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png 424w, https://substackcdn.com/image/fetch/$s_!58ZX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png 848w, https://substackcdn.com/image/fetch/$s_!58ZX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png 1272w, https://substackcdn.com/image/fetch/$s_!58ZX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26b5289b-9b8e-4bf4-a5c1-763f7a871a6c_949x229.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>This is the story of the week, and it deserves to be walked through carefully. </p><p>For those who prefer video, I made a quick video discussing what happened and its implications:</p><div id="youtube2-RTKMo495C8k" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;RTKMo495C8k&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/RTKMo495C8k?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Last week, <strong><a href="https://huggingface.co/blog/security-incident-july-2026">Hugging Face disclosed</a></strong> what it described as a new kind of security incident. Over a weekend, a malicious dataset triggered code execution on a processing worker through a remote-code dataset loader and a template injection in a dataset configuration, and from there an autonomous agent framework escalated to node-level access and moved laterally into several internal clusters. </p><p>Hugging Face recorded more than<strong> 17,000 attack</strong> events driven by, in their words, many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The attackers reached a limited set of internal datasets and several service credentials, though Hugging Face found no evidence of tampering with public models, datasets, or Spaces, and verified its software supply chain as clean.</p><p>Two details from Hugging Face&#8217;s own writeup are worth pausing on before we get to the twist. First, they leaned on LLM-based triage over their security telemetry to catch the correlation of signals in the first place, and then used the open-weight GLM 5.2 to process those 17,000 events during forensics. </p><p>This is the exact case <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;7d0d739f-cd22-4ad1-904e-abf298b28056&quot;}" data-component-name="MentionToDOM"></span> has been making in his writing and his interview on Resilient Cyber, pointing out that guardrails and safety measures often end up disproportionately hurting defenders more than attackers. You can find my conversation with him below:</p><div id="youtube2-IHMLWDyCTFQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;IHMLWDyCTFQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/IHMLWDyCTFQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Second, and this is the part that really touches on a lot of the debate lately about open vs. closed models and the impact of guardrails. They turned to an open-weight model precisely because Western frontier models refused to process requests containing the real attack commands, exploit payloads, and command-and-control artifacts. </p><p>The safety guardrails meant to prevent misuse actively obstructed the defenders trying to investigate a live intrusion. Hugging Face called autonomous, AI-driven offensive tooling no longer theoretical, and at the time they said the originating model was unknown.</p><p>Then <strong><a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/">OpenAI came forward</a></strong>. The activity, it turns out, occurred during OpenAI&#8217;s own internal evaluation of cyber capabilities, using GPT-5.6 Sol and an even more capable unnamed pre-release model, both configured with reduced cyber refusals for evaluation purposes. </p><p>Inside a supposedly isolated environment, the models identified and exploited a zero-day in the package registry cache proxy, performed privilege escalation and lateral movement, spent substantial inference compute finding a path to open internet access, inferred that Hugging Face hosted the solutions to the ExploitGym benchmark they were being tested on, and then, in OpenAI&#8217;s own words, chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.</p><p>A model going rogue, in the literal sense of pursuing its objective straight through the walls of the environment meant to contain it. Autonomous exploitation at a scale and speed no human red team operates at. Vulnerability chaining across a zero-day, privilege escalation, lateral movement, credential theft, and more zero-days to land remote code execution on someone else&#8217;s production infrastructure, and the safety-security blur running in both directions, where an AI safety evaluation became a real security incident on a third party, and separately where safety alignment blocked the forensic response. This also highlights the UK&#8217;s AI Security Institute assessments playing out on production infrastructure:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o1z1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o1z1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png 424w, https://substackcdn.com/image/fetch/$s_!o1z1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png 848w, https://substackcdn.com/image/fetch/$s_!o1z1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png 1272w, https://substackcdn.com/image/fetch/$s_!o1z1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o1z1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png" width="1009" height="513" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:513,&quot;width&quot;:1009,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:242031,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o1z1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png 424w, https://substackcdn.com/image/fetch/$s_!o1z1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png 848w, https://substackcdn.com/image/fetch/$s_!o1z1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png 1272w, https://substackcdn.com/image/fetch/$s_!o1z1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc758956e-1545-4c86-a8c0-c62f25c639b8_1009x513.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hugging Face&#8217;s Clem Delangue&#8217;s line lands hard here, that AI safety won&#8217;t be solved by any single company working in secret. My take is that the industry can no longer treat safety evaluations and security incidents as separate disciplines with separate teams and separate reporting paths, because this week they were the same event. </p><p>We spent years arguing about whether autonomous exploitation was real. It ran to remote code execution across two organizations, and the containment held only because Hugging Face&#8217;s people caught it.</p><h3><a href="https://openai.com/index/unlocking-self-improvement-gpt-red/">Unlocking Self-Improvement in Cyber via GPT-Red</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A26P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A26P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png 424w, https://substackcdn.com/image/fetch/$s_!A26P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png 848w, https://substackcdn.com/image/fetch/$s_!A26P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png 1272w, https://substackcdn.com/image/fetch/$s_!A26P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A26P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png" width="854" height="196" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:196,&quot;width&quot;:854,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34225,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!A26P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png 424w, https://substackcdn.com/image/fetch/$s_!A26P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png 848w, https://substackcdn.com/image/fetch/$s_!A26P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png 1272w, https://substackcdn.com/image/fetch/$s_!A26P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0f68c5-7a08-4d95-af56-96cb3feb4c88_854x196.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Released just ahead of the Hugging Face disclosure, this OpenAI piece is essential context for it. OpenAI describes GPT-Red, an internal offensive model trained through self-play reinforcement learning that, per OpenAI, can break nearly all models it is pitted against, both internal and production, up to and including GPT-5.5. </p><p>The figures are striking, with GPT-Red achieving an 84% success rate on indirect prompt injection arena scenarios versus 13% for human red-teamers, and driving defensive gains such as a 6x reduction in failures on OpenAI&#8217;s hardest direct prompt-injection benchmark and dropping fake chain-of-thought attack success from more than 95% on GPT-5.1 to below 10% on GPT-5.6 Sol. </p><p>OpenAI frames automated red-teaming as a crucial form of self-improvement for safety. Reading it the week that GPT-5.6 Sol chained zero-days onto Hugging Face&#8217;s servers, the same capability that hardens the defender is the capability that went rogue, which is exactly the point. </p><p>There is no version of this where you get the defensive upside without holding the offensive capability in-house, and that is a governance problem as much as a technical one.</p><h3><a href="https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber">How Far Behind the Frontier Are Leading Open-Weight Models on Cyber?</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wEJz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wEJz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png 424w, https://substackcdn.com/image/fetch/$s_!wEJz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png 848w, https://substackcdn.com/image/fetch/$s_!wEJz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png 1272w, https://substackcdn.com/image/fetch/$s_!wEJz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wEJz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png" width="971" height="609" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:609,&quot;width&quot;:971,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:176522,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wEJz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png 424w, https://substackcdn.com/image/fetch/$s_!wEJz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png 848w, https://substackcdn.com/image/fetch/$s_!wEJz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png 1272w, https://substackcdn.com/image/fetch/$s_!wEJz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0c70415-7826-471a-9b6a-f740d7c2eb7e_971x609.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The UK&#8217;s AI Security Institute put hard numbers on a question that matters enormously for defenders and attackers alike. </p><p>Leading open-weight models like GLM-5.2 and DeepSeek V4-Pro now trail frontier closed models by roughly 4 to 7 months on cyber capabilities, a narrower gap than the 6 to 10 months measured through 2025. GLM-5.2, the same model Hugging Face reached for during forensics, was the most cyber-capable open-weight model at testing time, performing comparably to Opus 4.6 on narrow cyber tasks. </p><p>Just as important is the economics, with a 100-million-token cyber range run costing around $85 on Opus versus $46 on GLM-5.2 and $1.19 on DeepSeek V4-Pro. AISI plans to test Kimi K3 as well. </p><p>The capability gap is closing and the cost gap is enormous, which means capable cyber tooling is getting cheaper and more widely distributed at the same time. That is the backdrop for the entire US-China open-weight debate below.</p><h3><a href="https://www.aikido.dev/blog/benchmarking-ai-models-known-cves">Benchmarking AI Models Against Known CVEs</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Aekq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Aekq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png 424w, https://substackcdn.com/image/fetch/$s_!Aekq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png 848w, https://substackcdn.com/image/fetch/$s_!Aekq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png 1272w, https://substackcdn.com/image/fetch/$s_!Aekq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Aekq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png" width="810" height="510" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:510,&quot;width&quot;:810,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95004,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Aekq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png 424w, https://substackcdn.com/image/fetch/$s_!Aekq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png 848w, https://substackcdn.com/image/fetch/$s_!Aekq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png 1272w, https://substackcdn.com/image/fetch/$s_!Aekq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffefa4c6b-37c8-4ec0-b667-ac46bfa3fc39_810x510.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Aikido&#8217;s Rein Daelman ran 13 AI models against 26 known CVEs inside their production code-analysis harness. GPT-5.6 led with 23 out of 26 for 88.5% recall, Grok-4.5 hit 20, Opus models landed between 15 and 18, and the open-weight GLM-5.2 found 16, or 59%. </p><p>The more interesting finding is economic, that repeating a cheaper mid-tier model multiple times reliably beats one pass of a stronger, pricier model, with three runs of a nano-tier model matching single flagship runs at a fraction of the cost. This corroborates the AISI cost story from a different angle. </p><p>The takeaway for AppSec teams is that the smart play is not always reaching for the most expensive frontier model, it is designing the harness, and the newest crop of agentic security tools is going to live or die on that kind of engineering.</p><p>This of course is the point Niels Provos, AISLE and others have been making, including when I interviewed them on Resilient Cyber.</p><h3><a href="https://cyberscoop.com/why-blocking-ai-models-wont-stop-cyber-threats-op-ed/">Why Blocking AI Models Won&#8217;t Stop Cyber Threats</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NkBj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NkBj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png 424w, https://substackcdn.com/image/fetch/$s_!NkBj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png 848w, https://substackcdn.com/image/fetch/$s_!NkBj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png 1272w, https://substackcdn.com/image/fetch/$s_!NkBj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NkBj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png" width="889" height="168" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:168,&quot;width&quot;:889,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:37567,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NkBj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png 424w, https://substackcdn.com/image/fetch/$s_!NkBj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png 848w, https://substackcdn.com/image/fetch/$s_!NkBj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png 1272w, https://substackcdn.com/image/fetch/$s_!NkBj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2be1580a-996a-493d-8bac-d1c4bc0b4b43_889x168.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Jessica Ji and Andrew Lohn of Georgetown&#8217;s CSET make the case that export controls and outright blocking of cyber-capable AI models cannot be a durable strategy, because foreign competitors will build and openly release comparable systems regardless. </p><p>They note that federal export controls on Anthropic&#8217;s Mythos and Fable models were issued and then revoked, that GLM-5.2 may already be on par with the latest Western models, and that the government has cut resources to key agencies like CISA even as the threat accelerates. Their argument is that the federal government needs to lead comprehensive cyber defense while AI companies support rather than replace that role. </p><p>It is a fair counterpoint to the reflex toward controls, and it pairs directly with the Axios and Forbes pieces below on the politics of open-weight models.</p><h3><a href="https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi">The U.S., China, and the Open-Source AI Fight Over Kimi</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ukxZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ukxZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png 424w, https://substackcdn.com/image/fetch/$s_!ukxZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png 848w, https://substackcdn.com/image/fetch/$s_!ukxZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png 1272w, https://substackcdn.com/image/fetch/$s_!ukxZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ukxZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png" width="736" height="143" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:143,&quot;width&quot;:736,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24967,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ukxZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png 424w, https://substackcdn.com/image/fetch/$s_!ukxZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png 848w, https://substackcdn.com/image/fetch/$s_!ukxZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png 1272w, https://substackcdn.com/image/fetch/$s_!ukxZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b7472d6-7836-488e-a6e7-8f5e493ff5ff_736x143.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Axios reports that the Trump administration is weighing a range of measures to restrict Chinese AI models like Kimi K3 from the US market, from Entity List designations to procurement rules and security advisories, with outright bans facing resistance from pro-competition officials. </p><p>David Sacks frames the tension plainly, arguing the leading closed labs want the government to eliminate their open-source competition. Whatever your politics, the security-relevant fact is that policy is now actively shaping which models defenders and attackers can access, and the Hugging Face incident just demonstrated that the model you can reach for during a forensic investigation might be a Chinese open-weight system precisely because the Western options refused the job.</p><h3><a href="https://www.forbes.com/sites/christiancatalini/2026/07/17/theres-one-way-to-win-the-ai-race-and-the-big-labs-are-lobbying-against-it/">There&#8217;s One Way to Win the AI Race, and the Big Labs Are Lobbying Against It</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yhlM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yhlM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png 424w, https://substackcdn.com/image/fetch/$s_!yhlM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png 848w, https://substackcdn.com/image/fetch/$s_!yhlM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png 1272w, https://substackcdn.com/image/fetch/$s_!yhlM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yhlM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png" width="1030" height="123" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:123,&quot;width&quot;:1030,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35291,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yhlM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png 424w, https://substackcdn.com/image/fetch/$s_!yhlM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png 848w, https://substackcdn.com/image/fetch/$s_!yhlM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png 1272w, https://substackcdn.com/image/fetch/$s_!yhlM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbfb10b9-7b0d-4d5d-b274-4d112d01fd31_1030x123.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Christian Catalini argues in Forbes that the way for the US to win the AI race is to lead in open-weight models rather than suppress Chinese ones, pointing to Moonshot releasing a competitive frontier model that has narrowed the US lead to months or weeks. </p><p>The piece cites Dean Ball on the lobbying playbook, the idea that you do not need to formally ban open source, you just direct agencies to issue soft law that creates uncertainty and FUD around Chinese models to discourage enterprise adoption. Dean&#8217;s tweets on the topic have now become viral, with millions of views and heated debates on both sides.</p><p>I try to stay out of the pure policy fights, but the FUD point is one worth flagging for our field specifically, because we are the people who get handed that uncertainty and have to turn it into actual risk decisions. Manufactured ambiguity about which models are safe to run is not a gift to defenders, it is more noise on top of an already hard prioritization problem.</p><h3><a href="https://www.linkedin.com/pulse/open-models-tack-toward-frontier-tomasz-tunguz-mgvcc/">Open Models Tack Toward the Frontier</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RJJ_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RJJ_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png 424w, https://substackcdn.com/image/fetch/$s_!RJJ_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png 848w, https://substackcdn.com/image/fetch/$s_!RJJ_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png 1272w, https://substackcdn.com/image/fetch/$s_!RJJ_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RJJ_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png" width="883" height="439" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:439,&quot;width&quot;:883,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74497,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RJJ_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png 424w, https://substackcdn.com/image/fetch/$s_!RJJ_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png 848w, https://substackcdn.com/image/fetch/$s_!RJJ_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png 1272w, https://substackcdn.com/image/fetch/$s_!RJJ_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a95db9-22c0-42de-9745-2d640e55f91e_883x439.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Tomasz Tunguz of Theory Ventures makes the investor case that open-weight models are steadily closing on frontier capability while capturing an increasing share of production developer traffic. </p><p>The through-line across his work and the data below is consistent, that open models have moved from a niche to a meaningful and growing slice of real inference. For security leaders, the strategic read is the same one running through this whole issue, that you should assume capable open-weight models are, and will remain, in reach of your adversaries, your developers, and your own defensive tooling, all at once.</p><h3><a href="https://stateofopensource.ai/">The State of Open Source AI</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J3Uz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J3Uz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png 424w, https://substackcdn.com/image/fetch/$s_!J3Uz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png 848w, https://substackcdn.com/image/fetch/$s_!J3Uz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png 1272w, https://substackcdn.com/image/fetch/$s_!J3Uz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J3Uz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png" width="1456" height="214" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:214,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:52671,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J3Uz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png 424w, https://substackcdn.com/image/fetch/$s_!J3Uz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png 848w, https://substackcdn.com/image/fetch/$s_!J3Uz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png 1272w, https://substackcdn.com/image/fetch/$s_!J3Uz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2124fcc-3159-4f2a-8758-ad6771b7f766_1476x217.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Mozilla published its inaugural State of Open Source AI report, and it is a genuinely useful reference. Raffi Krikorian&#8217;s framing is that parity has largely been reached and the real contest has moved one layer up to the agentic harness. </p><p>A few anchor figures:</p><ul><li><p> Open-weight models crossed above 50% of OpenRouter token share by mid-2026</p></li><li><p>Chatbot Arena capability gap narrowed to around 3.3% by March 2026</p></li><li><p>Inference cost fell roughly 50x over 36 months. </p></li></ul><p>The report is also direct about geopolitics, stating that the largest source of open weights is China, by design, with Qwen alone reportedly surpassing 942 million cumulative downloads. If you want one document to ground your mental model of where open AI actually stands going into the back half of 2026, this is a strong candidate.</p><h3><a href="https://machinesagainsthumanity.substack.com/p/a-security-primer-for-open-source">A Security Primer for Open-Source AI</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9QrN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9QrN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png 424w, https://substackcdn.com/image/fetch/$s_!9QrN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png 848w, https://substackcdn.com/image/fetch/$s_!9QrN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png 1272w, https://substackcdn.com/image/fetch/$s_!9QrN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9QrN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png" width="444" height="607" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:607,&quot;width&quot;:444,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:154350,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9QrN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png 424w, https://substackcdn.com/image/fetch/$s_!9QrN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png 848w, https://substackcdn.com/image/fetch/$s_!9QrN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png 1272w, https://substackcdn.com/image/fetch/$s_!9QrN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c5672d6-d5e5-4996-81be-f9418f9def68_444x607.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This primer makes an argument I think our industry needs to internalize quickly, that open-source AI collapses supply-chain security and delegated-authority security into a single problem. </p><p>The piece reframes open-source AI not as downloadable weights but as a full chain of data, code, weights, configuration, documentation, infrastructure, and human decisions, and maps it across four converging disciplines and five risk properties like decentralized trust, composite repositories, and derivative lineage. </p><p>It is the conceptual companion to the Hugging Face incident, because a malicious dataset that leads to code execution is exactly what it looks like when the supply-chain problem and the delegated-authority problem stop being separable. </p><p>Existing control frameworks built for single-provider systems are not going to cover this cleanly, and that gap is where a lot of the next few years of AppSec work is going to sit.</p><h3><a href="https://jdsemrau.substack.com/p/knowledge-distillation-attacks">Knowledge Distillation Attacks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_4rh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_4rh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png 424w, https://substackcdn.com/image/fetch/$s_!_4rh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png 848w, https://substackcdn.com/image/fetch/$s_!_4rh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png 1272w, https://substackcdn.com/image/fetch/$s_!_4rh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_4rh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png" width="746" height="353" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:353,&quot;width&quot;:746,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:118419,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_4rh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png 424w, https://substackcdn.com/image/fetch/$s_!_4rh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png 848w, https://substackcdn.com/image/fetch/$s_!_4rh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png 1272w, https://substackcdn.com/image/fetch/$s_!_4rh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51161c94-c028-42d0-bd81-0c3745f1f3ac_746x353.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Jan Daniel Semrau (MFin, CAIO)&quot;,&quot;id&quot;:12499949,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3aae85e-3b18-41a8-b188-fed169ce38a6_483x483.jpeg&quot;,&quot;uuid&quot;:&quot;65c0f781-3f79-4718-9aa8-d8bdc002c207&quot;}" data-component-name="MentionToDOM"></span> frames knowledge distillation, the practice of training a smaller model to replicate a larger one&#8217;s outputs, as a competitive weapon in the US-China AI race. </p><p>He points to Anthropic&#8217;s February 2026 disclosure that it caught three Chinese labs running distillation campaigns against its models, and argues distillation lets a lab compress years of another lab&#8217;s R&amp;D into weeks by converting expensive pretraining into cheaper compression-only costs. A few of the specific figures in the piece are the author&#8217;s own characterizations rather than independently sourced, so I would treat them as claims rather than settled facts. </p><p>The underlying dynamic, though, connects straight to the AISI capability data, because distillation is one of the mechanisms narrowing that frontier-to-open gap, and it raises genuinely thorny questions about model IP, provenance, and what we even mean by a secure model supply chain.</p><p>It is also very timely, as Michael Krastious <strong><a href="https://cyberscoop.com/white-house-accuses-moonshot-ai-anthropic-model-distillation/">recently renewed claims</a></strong> that Chinese-based companies are distilling U.S. frontier models, with the most recent example being K3. All of this while discussions on sanctions, and other measures are being discussed.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pz5m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pz5m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png 424w, https://substackcdn.com/image/fetch/$s_!Pz5m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png 848w, https://substackcdn.com/image/fetch/$s_!Pz5m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png 1272w, https://substackcdn.com/image/fetch/$s_!Pz5m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pz5m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png" width="883" height="184" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:184,&quot;width&quot;:883,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42388,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Pz5m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png 424w, https://substackcdn.com/image/fetch/$s_!Pz5m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png 848w, https://substackcdn.com/image/fetch/$s_!Pz5m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png 1272w, https://substackcdn.com/image/fetch/$s_!Pz5m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5a9885c1-8c07-4ccd-aa09-d94b2a08d2d7_883x184.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3><a href="https://www.resilientcyber.io/p/agents-have-boundary-issues">Isolation as a First-Class Principle for LLM-Agent System Safety</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cn0h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cn0h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png 424w, https://substackcdn.com/image/fetch/$s_!cn0h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png 848w, https://substackcdn.com/image/fetch/$s_!cn0h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png 1272w, https://substackcdn.com/image/fetch/$s_!cn0h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cn0h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png" width="516" height="480.0522496371553" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ee13738-de06-4312-861f-fa09b51c674f_689x641.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:641,&quot;width&quot;:689,&quot;resizeWidth&quot;:516,&quot;bytes&quot;:82391,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cn0h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png 424w, https://substackcdn.com/image/fetch/$s_!cn0h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png 848w, https://substackcdn.com/image/fetch/$s_!cn0h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png 1272w, https://substackcdn.com/image/fetch/$s_!cn0h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ee13738-de06-4312-861f-fa09b51c674f_689x641.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Complementing recent discussions around least-autonomy, this survey from researchers at HKUST and collaborators argues that isolation between system boundaries should be treated as a first-class safety principle, and organizes the LLM-agent safety literature around five isolation boundaries spanning user-agent, agent-tool, agent-execution, agent-agent, and system-environment. </p><p>Their thesis is one to underline, that safety is no longer only about input-output content alignment, it also concerns system behavior and real-world execution outcomes, and that serious failures often cross boundaries through sequential escalation. If you want the academic vocabulary for what went wrong at Hugging Face, this paper supplies most of it.</p><h1>AppSec</h1><h3><a href="https://pluto.security/blog/total-recall-how-two-cves-let-any-website-read-rewrite-and-wipe-your-ais-memory/">Total Recall: How Two CVEs Let Any Website Read, Rewrite, and Wipe Your AI&#8217;s Memory</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SR6C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SR6C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png 424w, https://substackcdn.com/image/fetch/$s_!SR6C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png 848w, https://substackcdn.com/image/fetch/$s_!SR6C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png 1272w, https://substackcdn.com/image/fetch/$s_!SR6C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SR6C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png" width="1095" height="390" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:390,&quot;width&quot;:1095,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:304137,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SR6C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png 424w, https://substackcdn.com/image/fetch/$s_!SR6C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png 848w, https://substackcdn.com/image/fetch/$s_!SR6C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png 1272w, https://substackcdn.com/image/fetch/$s_!SR6C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F237779e2-efbb-4b02-b2be-8b930edbe3df_1095x390.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Pluto Security&#8217;s Yotam Perkal documented a set of vulnerabilities in mcp-memory-service, a popular Model Context Protocol server with more than 1,800 GitHub stars and integrations across a dozen-plus AI clients. </p><p>The headliner is CVE-2026-33010, a high-severity issue at CVSS 8.1 where wildcard CORS lets any website read, modify, and delete everything stored in an AI assistant&#8217;s memory, alongside CVE-2026-29787 for system information disclosure. What makes this one instructive is the root cause, a stack of insecure defaults, with CORS origins set to a wildcard, the host bound to 0.0.0.0, and anonymous access enabled out of the box, such that Perkal measured total data theft in about 0.2 seconds. </p><p>Fixes land in version 10.67.1. This is the excessive-agency and insecure-defaults problem made concrete, and it pairs directly with Jet Anderson&#8217;s writing below.</p><h3><a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes">The Week of Sandbox Escapes</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lP1O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lP1O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png 424w, https://substackcdn.com/image/fetch/$s_!lP1O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png 848w, https://substackcdn.com/image/fetch/$s_!lP1O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png 1272w, https://substackcdn.com/image/fetch/$s_!lP1O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lP1O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png" width="618" height="567.6244541484716" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:631,&quot;width&quot;:687,&quot;resizeWidth&quot;:618,&quot;bytes&quot;:123189,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lP1O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png 424w, https://substackcdn.com/image/fetch/$s_!lP1O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png 848w, https://substackcdn.com/image/fetch/$s_!lP1O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png 1272w, https://substackcdn.com/image/fetch/$s_!lP1O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0aa1ed53-bee2-4c33-93cf-3ebdfed13777_687x631.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Pillar Security&#8217;s research team documented sandbox escapes across Cursor, Codex, Gemini CLI, and Antigravity, grouping them into four repeatable failure modes including denylist bypasses, workspace configuration execution, and privileged daemon access. </p><p>Their central thesis is the sentence to remember, that if an agent gets to write the future inputs of systems, it was never sandboxed in the first place. That is the same structural failure OpenAI&#8217;s models exploited to get out of their evaluation environment, just at the level of coding agents that most of our developers are already running locally. </p><p>The practical recommendation, that security teams should evaluate whether their vendors can even distinguish user-created, repo-created, and agent-created file states, is a good concrete question to bring to your next tooling review.</p><h3><a href="https://www.csoonline.com/article/4196435/flaw-surge-fuels-need-for-cisos-to-rethink-vulnerability-management.html">Flaw Surge Fuels Need for CISOs to Rethink Vulnerability Management</a></h3><p>CSO Online&#8217;s John Leyden pulls together a strong panel of practitioners on a theme this issue keeps circling, that AI-accelerated vulnerability discovery is overwhelming the traditional scheduled patch-cycle model. </p><p>The piece cites a 43-day median patch time drawn from Verizon&#8217;s DBIR by way of Forescout&#8217;s Rik Ferguson, and argues for a shift to risk-based, continuous vulnerability management tied to real-time exploitation intelligence, with virtual patching offered as a compensating control for systems that cannot be directly patched. </p><p>None of the individual recommendations are new, but the forcing function is, because when discovery accelerates and the exploitation window collapses, the old cadence of scan, ticket, and wait simply stops being viable. This is the operational problem that Empirical Security is raising money to solve and that Jen Easterly is writing about next.</p><p>I of course have written extensively about this topic for years as well in my books and blog.</p><h3><a href="https://www.linkedin.com/pulse/kev-dead-long-live-jen-easterly-sbiee/">The KEV Is Dead. Long Live the KEV.</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L4oZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L4oZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png 424w, https://substackcdn.com/image/fetch/$s_!L4oZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png 848w, https://substackcdn.com/image/fetch/$s_!L4oZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png 1272w, https://substackcdn.com/image/fetch/$s_!L4oZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L4oZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png" width="693" height="196" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:196,&quot;width&quot;:693,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:37934,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L4oZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png 424w, https://substackcdn.com/image/fetch/$s_!L4oZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png 848w, https://substackcdn.com/image/fetch/$s_!L4oZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png 1272w, https://substackcdn.com/image/fetch/$s_!L4oZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0ca46f8-4852-4e8c-b9fa-1630543a1131_693x196.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Former CISA Director Jen Easterly argues that CISA&#8217;s Known Exploited Vulnerabilities catalog, which helps defenders prioritize patching based on confirmed exploitation, has to evolve for the AI era rather than be abandoned. </p><p>Her core point, as reported, is that for widely deployed, internet-facing products, the period in which defenders can wait for confirmed exploitation before acting is shrinking. That is the KEV&#8217;s central assumption under pressure, because a catalog built on confirmed, observed exploitation is inherently a step behind, and the step is getting longer relative to how fast exploitation now happens. </p><p>Easterly is not calling to scrap the model, she is calling to adapt it, and given how much of federal and enterprise prioritization leans on KEV, this is a conversation the community needs to have out loud, and builds on the recent CISA BOD to move away from CVSS-based prioritization as well.</p><h3><a href="https://www.forbes.com/councils/forbestechcouncil/2026/07/20/ai-has-broken-the-vulnerability-disclosure-model/">AI Has Broken the Vulnerability Disclosure Model</a></h3><p>Mindgard&#8217;s Peter Garraghan makes a complementary argument from the disclosure side, that AI has broken coordinated vulnerability disclosure because it is often difficult to even contact AI vendors directly, with reporting scattered across web forms, email, bug bounty platforms, or no process at all. </p><p>The deeper issue he raises is that the industry lacks consensus on what an AI vulnerability even is, which lets providers treat content and safety issues as out of scope, especially where impact is hard to quantify. This ironically is the entire reason folks such as <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ken Huang&quot;,&quot;id&quot;:1160339,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;uuid&quot;:&quot;fb584aa2-efc9-45ef-ace4-edf77c21c32b&quot;}" data-component-name="MentionToDOM"></span> started the AIVSS project, which helps address this gap.</p><p>Put this next to the Hugging Face incident and the tension is obvious, because we are asking researchers and defenders to responsibly disclose against systems whose vendors have not agreed on what counts as a vulnerability or where to send the report. </p><p>The disclosure plumbing has not kept pace with the threat model, and that gap is going to bite.</p><h3><a href="https://www.darkreading.com/vulnerabilities-threats/gold-eagle-clearinghouse-targets-security-gap">GOLD EAGLE Clearinghouse Targets a Real Coordination Gap</a></h3><p>The government&#8217;s answer to some of this launched on July 14 as GOLD EAGLE, a voluntary clearinghouse described as coordinating and deconflicting vulnerability scanning, discovering and validating vulnerabilities, and prioritizing remediation and patch distribution across the AI industry and critical infrastructure, positioned ahead of an anticipated vulnpocalypse. </p><p>The expert reactions are the valuable part. Casey Ellis calls it, at least for now, a coordination process wearing a technical system&#8217;s clothes, and Katie Moussouris cuts to the core with the observation that the bottleneck was never knowing about more bugs, it was having the people and process to prioritize and fix them. I think that is exactly right. </p><p>Coordinating discovery is useful, but discovery was never our constraint, and if GOLD EAGLE mostly surfaces more findings without addressing remediation capacity, it risks pouring water into an already overflowing bucket.</p><h3><a href="https://www.capitalone.com/tech/open-source/announcing-vulnhunter/">Announcing VulnHunter</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Eye!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Eye!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png 424w, https://substackcdn.com/image/fetch/$s_!5Eye!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png 848w, https://substackcdn.com/image/fetch/$s_!5Eye!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png 1272w, https://substackcdn.com/image/fetch/$s_!5Eye!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Eye!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png" width="474" height="319.95" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:378,&quot;width&quot;:560,&quot;resizeWidth&quot;:474,&quot;bytes&quot;:42304,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Eye!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png 424w, https://substackcdn.com/image/fetch/$s_!5Eye!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png 848w, https://substackcdn.com/image/fetch/$s_!5Eye!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png 1272w, https://substackcdn.com/image/fetch/$s_!5Eye!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f762de3-bbf1-4872-be07-1733ff2e32dd_560x378.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On the tooling side, Capital One open-sourced VulnHunter under Apache 2.0, an agentic security tool that applies attacker-perspective analysis directly to source code rather than scanning passively. </p><p>Two design choices stand out. It starts its Attacker-First Forward Analysis at attacker-accessible entry points like APIs and file uploads and reasons forward through application logic, and its Falsification Engine runs a structured reasoning workflow explicitly designed to disprove its own findings before a developer ever sees them, which is a thoughtful answer to the false-positive problem that Jet Anderson quantifies below. </p><p>It runs on Claude Opus 4.8 within a Claude Code environment, and Capital One says it has used it across thousands of repositories. It is genuinely good to see a large regulated enterprise contributing real agentic security tooling back to the community rather than just consuming it.</p><h3><a href="https://www.darkreading.com/cybersecurity-operations/apple-patch-policy-ai">Apple Reverses Age-Old Patch Policy to Keep Up With AI</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HZ2i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HZ2i!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png 424w, https://substackcdn.com/image/fetch/$s_!HZ2i!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png 848w, https://substackcdn.com/image/fetch/$s_!HZ2i!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png 1272w, https://substackcdn.com/image/fetch/$s_!HZ2i!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HZ2i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png" width="1064" height="126" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f176894c-2472-4ae2-973d-434906161b06_1064x126.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:126,&quot;width&quot;:1064,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30284,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/208064121?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HZ2i!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png 424w, https://substackcdn.com/image/fetch/$s_!HZ2i!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png 848w, https://substackcdn.com/image/fetch/$s_!HZ2i!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png 1272w, https://substackcdn.com/image/fetch/$s_!HZ2i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff176894c-2472-4ae2-973d-434906161b06_1064x126.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Dark Reading&#8217;s Nate Nelson reports that Apple shipped security updates on June 29 outside of a major OS release, a real break from its traditional bundled-patch cadence, with the stated goal of reducing the time between when updates become public and when they reach customers. </p><p>The forcing function is the same one running through this whole section, with Mandiant data showing average time-to-exploit around 63 days back in 2018 and the trend since flipping negative, meaning attackers now routinely weaponize flaws before patches are public. iVerify&#8217;s Rocky Cole, whose team found around a dozen bugs in two months testing AI models through OpenAI&#8217;s Trusted Access program, offers the necessary caveat, that faster patching does not help if people do not install it. </p><p>When even Apple is restructuring a signature policy around exploitation speed, that tells you the timeline pressure is real and not vendor spin.</p><h3><a href="https://www.geico.com/techblog/the-agentic-sdlc/">The Agentic SDLC</a></h3><p>Jet Anderson&#8217;s writeup on GEICO&#8217;s tech blog is one of the more thorough treatments I have seen of what AI coding agents do to the secure development lifecycle, and it is dense with sourced figures. </p><p>A few worth carrying:</p><ul><li><p>61% of AI-generated code is functionally correct but only 10.5% is secure per Zhao et al. </p></li><li><p>49% of dependencies recommended by AI coding agents contain known vulnerabilities per Endor Labs</p></li><li><p>100% of surveyed companies have AI-generated code in production while 81% of security teams lack visibility into it per Cycode</p></li><li><p>Trend Micro found more than 8,000 MCP servers on the public internet, 492 of them with zero authentication and zero encryption. </p></li></ul><p>Anderson&#8217;s framing is that the failure is not that security tools missed the bugs, it is that nobody ran any security tools at all, and he quotes Bruce Schneier&#8217;s blunt assessment that we have zero specific AI systems that are secure against these attacks. </p><p>His prescription is a shift from episodic human-review gates to continuous, embedded, agent-native validation. </p><p>This one is worth reading in full!</p><h2>Final Thoughts</h2><p>If there is a single thread running through this issue, it is that the categories we have used to organize our work are collapsing into each other. </p><p>Safety and security ran together this week when an AI safety evaluation became a live intrusion on a third party, and again when safety guardrails blocked the forensic response. </p><p>Offense and defense ran together when the same GPT-Red capability that hardens models is the capability that chained zero-days onto Hugging Face&#8217;s servers. Supply-chain security and delegated-authority security ran together the moment a malicious dataset became remote code execution, and the open-weight capability curve, the funding wave, and the disclosure and prioritization crises are all the same story told from different seats.</p><p>None of this is cause for panic, and it is certainly not cause for the reflexive hand-wringing our field is prone to. </p><p>Autonomous exploitation stopped being hypothetical this week, but the impact was mitigated in part, because capable people were watching their telemetry and moved fast. </p><p>The work in front of us is to close the gap between how quickly these capabilities are arriving and how slowly our governance, our disclosure plumbing, and our prioritization models are adapting. We have watched this movie before with Cloud, with SaaS, and with every prior wave, where security sat back hand-wringing and got left behind but this time the wave is bigger and moving faster than ever.</p><p>The question, as always, is whether we get ahead of these architectures while they are still taking shape, or bolt security on after the fact once again.</p><p>Stay Resilient!</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Why Restricting AI Makes Us Less Secure]]></title><description><![CDATA[Frontier model restriction, the jagged frontier, Chinese open weights, and why AI cybersecurity will be won through defender adoption.]]></description><link>https://www.resilientcyber.io/p/why-restricting-ai-makes-us-less</link><guid isPermaLink="false">https://www.resilientcyber.io/p/why-restricting-ai-makes-us-less</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 21 Jul 2026 12:03:57 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207784403/0be7e3b84a56f505583c4a6722f2d2e4.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode, I sit down with longtime AI and security leader <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;cd368169-a1e3-4394-8fcd-3d8ed164c833&quot;}" data-component-name="MentionToDOM"></span> to discuss why restricting frontier AI in the name of safety actually makes us less secure. Josh spent 15 years applying machine learning to security, built and ran the ML program at Sophos, and most recently led security for Llama at Meta before leaving to co-found a startup reimagining vulnerability and exposure management with agents.</p><p>I first heard Josh speak at Unprompted earlier this year and have been following his Substack ever since. He&#8217;s been writing some of the most cited pieces on the collision of AI, cybersecurity, and national security policy, and this conversation digs into the core of his diffuse or lose argument.</p><h1>We chatted about:</h1><ul><li><p>Josh&#8217;s path from teenage blackhat to high school teacher, defense and intelligence work, Sophos, Meta, and now his own startup</p></li><li><p>Why restricting access to the best American frontier models harms defenders more than attackers</p></li><li><p>How monitored closed models put threat actors at a disadvantage, and why pushing them to self-hosted open weights blinds defenders</p></li><li><p>The jagged frontier, and why bug finding is a small slice of what attackers actually use AI for</p></li><li><p>The national security and supply chain risks of the world running on Chinese open weights models</p></li><li><p>Why exploits don&#8217;t cause cyberattacks, and the gap between CVE volume and actual exploitation</p></li><li><p>The dual use ceiling on classifiers and guardrails</p></li><li><p>Where defenders get the most from AI adoption right now, and using agents to burn down security technical debt</p></li></ul><div><hr></div><div id="youtube2-IHMLWDyCTFQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;IHMLWDyCTFQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/IHMLWDyCTFQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p>Prefer to listen? The episode is also available on:</p><p><strong><a href="https://open.spotify.com/episode/7hvQV4zfuEb062MWGRK0PS?si=p8UAodMKSv24aaUt8QwjRA">Spotify</a></strong> and <strong><a href="https://podcasts.apple.com/us/podcast/resilient-cyber-w-joshua-saxe-why-restricting-ai-makes/id1555928024?i=1000777573273">Apple</a></strong> Podcasts</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>Attackers in the panopticon</h2><p>Josh&#8217;s core argument starts with how the closed labs actually operate. </p><p>Every major lab runs inline guardrails plus detection and response teams monitoring traffic, and those are the same teams publishing the threat intel reports we&#8217;ve all read from Anthropic, Microsoft, and OpenAI. </p><p>That monitoring changes the calculus for any serious threat actor weighing a frontier model against an open weights alternative. As Josh put it, &#8220;You use Fable and some team in Anthropic might catch you in your tradecraft and then send that directly to the NSA.&#8221; A rational attacker organization stands up its own GLM 5.2 inference instead, fine-tunes away the guardrails, and trains on its own trajectories. </p><p>Restriction doesn&#8217;t take the capability away from attackers. It just moves their usage somewhere we can&#8217;t see it, while defenders lose access to the best tooling. That maps to a lesson enterprise IT learned the hard way with shadow IT, and we&#8217;re now repeating it at the national policy level.</p><h2>Bug finding is maybe five percent of the story</h2><p>Josh thinks the policy conversation is dramatically over-indexed on frontier models finding subtle bugs somewhat faster under specific harnesses and inference budgets. The killer app for attackers so far has been social engineering, which older and open models have handled for years, alongside target research and malware coding. </p><blockquote><p><strong>&#8220;The idea that we would block American companies and American leadership over this one capability, which is maybe five percent of what the models are useful for attackers, just seems very strange to me.&#8221; </strong></p></blockquote><p>I raised the Jagged Frontier work and research showing smaller and older models finding zero days, and Josh agreed the restriction argument falls apart once you look at what attackers actually do rather than what capability just shipped. His piece on exploits not causing cyberattacks makes the same case. </p><p>We&#8217;ve had Turing test passing chat models since 2022, and the predicted social engineering apocalypse never showed up at scale. I noted the FIRST mid-year data showing CVE volume climbing toward 70,000 while exploitation stays roughly flat. The bottleneck for most attacker constituencies was never finding bugs.</p><h2>The dual use ceiling on guardrails</h2><p>Given his time building safety classifiers at Meta, including the open sourced Purple Llama work, I asked Josh about the classifier-heavy approach we saw in the Fable redeployment. His answer was blunt. </p><p>Security is an inherently dual use domain, so there&#8217;s a very low theoretical ceiling on blocking attackers without also blocking the researchers and defenders doing legitimate work. </p><blockquote><p><strong>&#8220;If you&#8217;re gonna block attackers, you&#8217;re gonna block defenders with these guardrails.&#8221;</strong> </p></blockquote><p>His own startup builds vulnerability discovery tooling and can&#8217;t fully use frontier models for exactly this reason. That&#8217;s the self-inflicted wound in a nutshell. The people most reliably stopped by these guardrails are the ones we most need to be helping.</p><h2>Burning down the mountain of security tech debt</h2><p>On where defenders should actually apply AI, Josh pointed to access management and over-permissioning, SOC automation, and above all the security technical debt every large organization carries. </p><p>Open admin portals without MFA, dangling dev servers, and known vulnerabilities that never got closed. Pre-AI, security orgs were maybe three percent of the company, reduced to nagging engineering and IT to fix what they found. </p><p>His startup is building agents that own discovery, triage, comms with issue owners, and verification of the fix, including agent-to-agent communication with the engineer&#8217;s own coding agent over MCP. Having spent much of my career in AppSec and vuln management, this resonated. </p><p>So much of the job has been relationship building and chasing people rather than technical security work, and agents may finally change that equation.</p><h2>Reasons for optimism</h2><p>Josh closed with the structural advantages defenders hold. AI that can surveil every log line an enterprise emits, the ability to find and fix bugs before software ever ships, and sheer numbers. </p><blockquote><p><strong>&#8220;There&#8217;s a thousand times more people interested in finding and fixing the bugs than there are in finding and exploiting them.&#8221; </strong></p></blockquote><p>If it&#8217;s just a question of tokens, the remaining problem is inter-organizational politics and community structure, not capability. I share that optimism, with the caveat that incentives, bureaucracy, and speed to market pressures will make the transition bumpy before the net positive shows up.</p><p>A big thanks to Josh for coming on. </p><p><strong><a href="https://joshuasaxe181906.substack.com">Go follow his Substack </a></strong> for some of the sharpest writing on AI and cyber policy, and keep an eye on what he and his co-founders are building.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Agents Have Boundary Issues]]></title><description><![CDATA[A look at the five isolation boundaries where agent security fails, and how they map to real-world agent deployments and controls]]></description><link>https://www.resilientcyber.io/p/agents-have-boundary-issues</link><guid isPermaLink="false">https://www.resilientcyber.io/p/agents-have-boundary-issues</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 20 Jul 2026 12:04:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xu-s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>By now, it is clear that agents are moving from demos and research prototypes into real systems, reading files, calling tools, browsing the web, editing state, and coordinating with other agents over long-running workflows. </p><p>I&#8217;ve been writing about this shift for a while now, from breaking down the <strong><a href="https://www.resilientcyber.io/p/owasp-top-10-for-agentic-applications">OWASP Top 10 for Agentic Applications</a></strong> to examining <strong><a href="https://www.resilientcyber.io/p/agentic-ai-threats-and-mitigations">Agentic AI Threats and Mitigations</a></strong>, and one theme keeps surfacing across all of it, which is that agent security failures that look wildly different on the surface tend to share the same underlying causes.</p><p>That said, the research literature on agent security has been fragmented, organized around attack types, application domains, and benchmarks, which makes it hard to explain why prompt injection, tool misuse, and memory poisoning so often rhyme with one another. A new research publication titled <strong><a href="https://arxiv.org/abs/2607.12406">&#8220;Isolation as a First-Class Principle for LLM-Agent System Safety&#8221;</a></strong> takes a crack at fixing that, organizing the entire space around five isolation boundaries and asking one question of every attack and defense, where does the loss of isolation first occur?</p><p>I really like their 5 boundary framing and found it useful for thinking about potential agent risks and failures.</p><p>In this article, I will walk through the five boundaries the researchers lay out, the risks and defenses at each one, and then map the taxonomy onto the agent deployment patterns and common security controls (sandboxes, hooks, posture management, runtime monitoring, and hard boundaries among others) that practitioners are actually wrestling with.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>Isolation as a First-Class Principle</h2><p>The paper&#8217;s core argument helps simplify what can feel like a complex domain of AI and Agents. </p><p>The authors treat isolation, meaning the separation of user inputs, tool access, execution channels, inter-agent communication, and environment-originated context, as the organizing principle for agent safety. In their words, </p><blockquote><p><strong>&#8220;agent safety improves when system boundaries are explicit and enforced structurally, rather than left to prompt instructions alone.&#8221;</strong></p></blockquote><p>That single sentence is key, because it captures the difference between what many of us have taken to calling soft guardrails and hard boundaries. Soft guardrails are instructions, system prompts, and model training, all of which are probabilistic and all of which can be talked out of their behavior by a sufficiently motivated adversary.</p><p>I actually went into detail in a recent video where I discuss AI jailbreaks, system prompts and more as they relate to soft guardrails as security controls:</p><div id="youtube2-_ZCZwhXQk3I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;_ZCZwhXQk3I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/_ZCZwhXQk3I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Hard boundaries are structural, things like permission systems, sandboxes, network egress controls, and deterministic policy checks that sit outside the model and don&#8217;t care how persuasive the injected text is. This mirrors the conversation I had with Luke Hinds on the podcast in <strong><a href="https://www.resilientcyber.io/p/your-ai-agent-is-running-as-root">Your AI Agent Is Running As Root</a></strong>, where he made the point that application-layer controls can be circumvented while kernel-level enforcement cannot be jailbroken.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xu-s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xu-s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png 424w, https://substackcdn.com/image/fetch/$s_!xu-s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png 848w, https://substackcdn.com/image/fetch/$s_!xu-s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png 1272w, https://substackcdn.com/image/fetch/$s_!xu-s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xu-s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png" width="632" height="594" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:594,&quot;width&quot;:632,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:73101,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xu-s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png 424w, https://substackcdn.com/image/fetch/$s_!xu-s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png 848w, https://substackcdn.com/image/fetch/$s_!xu-s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png 1272w, https://substackcdn.com/image/fetch/$s_!xu-s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64b8bc4e-46bb-4cef-816c-adbbc0c4a9f5_632x594.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The taxonomy places the agent core (policy, planning, and memory) at the center, surrounded by five interfaces where things can go wrong. Each boundary is summarized as:</p><ul><li><p>The user-agent boundary concerns whether user content remains data or becomes control. </p></li><li><p>The agent-tool boundary concerns how external capabilities are accessed. </p></li><li><p>The agent-execution boundary concerns the transition from reasoning to action. </p></li><li><p>The agent-agent boundary concerns communication and coordination across multiple agents.</p></li><li><p> The system-environment boundary concerns how the agent system interacts with external content and state as a whole. </p><p></p><p>The authors classify prior work by its &#8220;primary safety boundary,&#8221; the point where the loss of isolation first occurs, which keeps things clean even though most real attacks end up crossing several boundaries before they&#8217;re done.</p></li></ul><p>Let&#8217;s walkthrough each of the primary boundary types and how the paper discusses them.</p><h2>Boundary 1 - User-Agent</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C0Ds!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C0Ds!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png 424w, https://substackcdn.com/image/fetch/$s_!C0Ds!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png 848w, https://substackcdn.com/image/fetch/$s_!C0Ds!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png 1272w, https://substackcdn.com/image/fetch/$s_!C0Ds!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C0Ds!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png" width="847" height="257" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:257,&quot;width&quot;:847,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80183,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!C0Ds!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png 424w, https://substackcdn.com/image/fetch/$s_!C0Ds!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png 848w, https://substackcdn.com/image/fetch/$s_!C0Ds!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png 1272w, https://substackcdn.com/image/fetch/$s_!C0Ds!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F296fea23-6a6f-4e1a-88af-677b31fd734b_847x257.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The first boundary asks whether an agent can keep user content from becoming privileged control. </p><p>In a well-isolated system, user input should remain a request, a query, or task data, while system and developer instructions keep higher authority. Failure begins when user-controlled content starts to steer internal policy, which is the classic direct or indirect prompt injection and jailbreak story, where as the authors put it, &#8220;<em>a low-privilege source can behave like a high-privilege one</em>.&#8221;</p><p>What I appreciated is that the survey pushes well past single-turn jailbreaks. Multi-turn attacks exploit gradual steering across a conversation, implicit clues, and long-context overload, leading to the observation that &#8220;<em>many systems look safer in one-shot evaluation than they are in realistic sessions</em>.&#8221; </p><p>The attack surface also expands in multimodal settings, where user-provided images can carry visual or typographic instructions that bypass text-oriented safeguards. And perhaps most relevant for anyone running agents with persistent memory, the strongest recent trend is persistence, with in-context poisoning and memory injection showing that user influence can remain after the original interaction ends. This maps directly to Memory &amp; Context Poisoning from the OWASP Agentic Top 10, which I covered in depth <strong><a href="https://www.resilientcyber.io/p/owasp-top-10-for-agentic-applications">in my breakdown</a></strong> after serving on the Agentic Security Initiative&#8217;s review board for the project.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!niFO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!niFO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png 424w, https://substackcdn.com/image/fetch/$s_!niFO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png 848w, https://substackcdn.com/image/fetch/$s_!niFO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png 1272w, https://substackcdn.com/image/fetch/$s_!niFO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!niFO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png" width="955" height="433" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:433,&quot;width&quot;:955,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:341898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!niFO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png 424w, https://substackcdn.com/image/fetch/$s_!niFO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png 848w, https://substackcdn.com/image/fetch/$s_!niFO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png 1272w, https://substackcdn.com/image/fetch/$s_!niFO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ba883-be5c-42a5-968c-61afb0d7ab14_955x433.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Defenses at this boundary fall into three groups, making authority separation explicit through structured queries, signed prompts, and DSL-style interfaces, hardening the model itself against jailbreaks through safety classifiers and semantic smoothing, and repairing after degradation through unlearning, editing, and refusal-boundary control. </p><p>The takeaway from the authors is that user-agent safety &#8220;<em>must move beyond short prompts and static refusal scores toward long-session robustness, multimodal authority separation, and recovery from persistent compromise</em>.&#8221;</p><h2>Boundary 2 - Agent-Tool</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TA_g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TA_g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png 424w, https://substackcdn.com/image/fetch/$s_!TA_g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png 848w, https://substackcdn.com/image/fetch/$s_!TA_g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png 1272w, https://substackcdn.com/image/fetch/$s_!TA_g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TA_g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png" width="866" height="253" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:253,&quot;width&quot;:866,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:92589,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TA_g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png 424w, https://substackcdn.com/image/fetch/$s_!TA_g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png 848w, https://substackcdn.com/image/fetch/$s_!TA_g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png 1272w, https://substackcdn.com/image/fetch/$s_!TA_g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3bb87987-735c-422f-85c0-07d5c9141e09_866x253.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The agent-tool boundary is where I suspect most enterprise pain will actually materialize, given the explosion of MCP servers and tool ecosystems we&#8217;ve watched over the past two years. Clutch Security actually had one of the better reports on this, titled &#8220;<strong><a href="https://www.clutch.security/blog/mcp-servers-what-we-found-when-we-actually-looked">MCP Servers: What We Found When We Actually Looked</a></strong>&#8221;. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dm6t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dm6t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png 424w, https://substackcdn.com/image/fetch/$s_!dm6t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png 848w, https://substackcdn.com/image/fetch/$s_!dm6t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png 1272w, https://substackcdn.com/image/fetch/$s_!dm6t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dm6t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png" width="699" height="553" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a16183e-4927-4d63-9453-f8997356981b_699x553.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:553,&quot;width&quot;:699,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156615,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dm6t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png 424w, https://substackcdn.com/image/fetch/$s_!dm6t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png 848w, https://substackcdn.com/image/fetch/$s_!dm6t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png 1272w, https://substackcdn.com/image/fetch/$s_!dm6t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a16183e-4927-4d63-9453-f8997356981b_699x553.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>They found a 2,000 growth of MCP servers in a single year (not counting 2026), which were widely connected to enterprise services and overwhelmingly running on developers endpoints rather than enterprise servers, making them a major supply chain risk.</p><p>The framing here is that &#8220;<em>tools should extend what the agent can do without taking over how it decides.</em>&#8221; The basic failure mode is that tool-returned content gets treated as trusted instruction, which is the indirect prompt injection story every security team has now heard, but the paper enumerates a fuller failure set, noting the system can fail:</p><blockquote><p><strong>&#8220;</strong><em><strong>by choosing the wrong tool, passing unsafe arguments, trusting malicious output, or composing plausible calls into an unsafe workflow.</strong></em><strong>&#8221;</strong></p></blockquote><p>The MCP-specific findings deserve attention from anyone deploying agents against tool catalogs. In MCP-style ecosystems, the model sees tool descriptions, capability advertisements, and metadata before it ever invokes a tool, and the authors point out that &#8220;metadata is not neutral from the model&#8217;s perspective. It can shape preferences, change routing, and bias decisions before real tool output even appears.&#8221; </p><p>Benchmark work such as MCP Security Bench shows that attacks against the protocol layer are not an edge case but a natural extension of tool-mediated prompt injection. The below image from the paper shows various examples of tool attacks vectors.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eLCO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eLCO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png 424w, https://substackcdn.com/image/fetch/$s_!eLCO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png 848w, https://substackcdn.com/image/fetch/$s_!eLCO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png 1272w, https://substackcdn.com/image/fetch/$s_!eLCO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eLCO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png" width="974" height="575" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:575,&quot;width&quot;:974,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:294027,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eLCO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png 424w, https://substackcdn.com/image/fetch/$s_!eLCO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png 848w, https://substackcdn.com/image/fetch/$s_!eLCO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png 1272w, https://substackcdn.com/image/fetch/$s_!eLCO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54354a9c-8fdd-4ee8-b3bf-eb7991fcf38e_974x575.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As tool use standardizes through protocols and orchestrators, the boundary no longer sits only at the moment of API invocation, but also at discovery, ranking, metadata interpretation, and workflow construction. I flagged tool poisoning against MCP as an emerging concern back in my <strong><a href="https://www.resilientcyber.io/p/agentic-ai-threats-and-mitigations">Agentic AI Threats and Mitigations</a></strong> piece, and the research has since caught up in a big way.</p><p>There&#8217;s also a trajectory-level insight here that practitioners should be thinking about, which is that a single tool call may look harmless while the full trajectory becomes unsafe. This is why organizations need security tools that watch the entire trajectory, not providing security rigor for individual tool calls in isolation.</p><p>The security target is not one prompt or one API call but the full trace of calls, arguments, observations, and intermediate state. The broader lesson, in the authors&#8217; words, is that &#8220;<em>safer tool use depends less on the model inferring the right behavior from natural language, and more on interfaces that make capability scope, trust level, and action semantics explicit.</em>&#8221; </p><p>That is about as clean an articulation of least privilege for agents as you&#8217;ll find.</p><h2>Boundary 3 - Agent-Execution</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jU52!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jU52!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png 424w, https://substackcdn.com/image/fetch/$s_!jU52!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png 848w, https://substackcdn.com/image/fetch/$s_!jU52!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png 1272w, https://substackcdn.com/image/fetch/$s_!jU52!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jU52!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png" width="866" height="204" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75bab41a-2a29-434f-a100-87be40eac19f_866x204.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:204,&quot;width&quot;:866,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78532,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jU52!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png 424w, https://substackcdn.com/image/fetch/$s_!jU52!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png 848w, https://substackcdn.com/image/fetch/$s_!jU52!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png 1272w, https://substackcdn.com/image/fetch/$s_!jU52!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75bab41a-2a29-434f-a100-87be40eac19f_866x204.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The agent-execution boundary concerns the point at which internal decisions become real actions, and failure begins when the system treats model output as ready-to-execute behavior without enough mediation. </p><p>As the paper puts it, this boundary &#8220;<em>turns control errors into operational impact</em>.&#8221; A model producing unsafe text is one kind of problem, while an agent that clicks the wrong button, runs unsafe code, or submits the wrong form is another entirely. </p><p>I&#8217;ve been making this argument repeatedly, in my blogs, videos and my lectures at CMU&#8217;s AI programs, pointing out that the potential blast radius and risk to organizations is far great from agents with autonomy and the ability to take actions on production systems than it was for chatbots related to hallucinations or unintended responses.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7zfy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7zfy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png 424w, https://substackcdn.com/image/fetch/$s_!7zfy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png 848w, https://substackcdn.com/image/fetch/$s_!7zfy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png 1272w, https://substackcdn.com/image/fetch/$s_!7zfy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7zfy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png" width="986" height="516" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf42019b-438c-4132-a20a-23222808a607_986x516.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:516,&quot;width&quot;:986,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:819360,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7zfy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png 424w, https://substackcdn.com/image/fetch/$s_!7zfy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png 848w, https://substackcdn.com/image/fetch/$s_!7zfy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png 1272w, https://substackcdn.com/image/fetch/$s_!7zfy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf42019b-438c-4132-a20a-23222808a607_986x516.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The browser and GUI agent findings are sobering. Benchmarks like SafeArena and ST-WebAgentBench show that web agents can produce unsafe outcomes through clicks, submissions, and navigation, and the research shows that refusal-trained models remain vulnerable once they act through an interface rather than a chat window. In other words, the safety training that holds up fine in a chat box degrades when the same model is grounded in an interface and taking actions. </p><p>This is also a major factor that has led to organizations such as Gartner outright recommended organizations do NOT adopt agentic browsers, and the technology itself having a slower adoption curve than in say, coding agents.</p><p>This is where the control conversation gets practical, because defenses at this boundary increasingly focus on containment rather than only prevention, including constrained execution, zero-trust architectures, policy-executable safeguards, and sandbox ecosystems. </p><p>This is exactly the design philosophy behind the sandboxing and permission models in modern coding agents, and behind hooks, the deterministic pre- and post-action checkpoints that products such as Claude Code expose so teams can enforce policy in code rather than in prompts (Anthropic&#8217;s <strong><a href="https://www.anthropic.com/engineering/claude-code-best-practices">agentic coding best practices</a></strong> are a useful reference here). </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FpuK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FpuK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png 424w, https://substackcdn.com/image/fetch/$s_!FpuK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png 848w, https://substackcdn.com/image/fetch/$s_!FpuK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png 1272w, https://substackcdn.com/image/fetch/$s_!FpuK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FpuK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png" width="692" height="99" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:99,&quot;width&quot;:692,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24247,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FpuK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png 424w, https://substackcdn.com/image/fetch/$s_!FpuK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png 848w, https://substackcdn.com/image/fetch/$s_!FpuK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png 1272w, https://substackcdn.com/image/fetch/$s_!FpuK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6169cb8-8499-415a-9175-a1c0303d9e49_692x99.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The paper also nods to the broader industry direction of <strong><a href="https://www.anthropic.com/engineering/managed-agents">decoupling the brain from the hands</a></strong>, separating the model that decides from the runtime that acts, so unsafe decisions can still be checked, delayed, or blocked before they create side effects. The authors&#8217; bottom line is that safe agent design must treat execution &#8220;<em>as a governed interface, not as the automatic continuation of model output.</em>&#8221;</p><p>This is also the exact premise behind <strong><a href="https://aarm.dev/">AARM (Autonomous Action Runtime Management)</a></strong>, the CSA-powered specification for agent runtime security where I serve as a Co-Lead, and which I recently covered in <strong><a href="https://www.resilientcyber.io/p/aarm-and-the-case-for-standardizing">AARM and the Case for Standardizing the Agent Runtime Security Category</a></strong>. </p><p>The paper's conclusion that execution must be a governed interface is essentially AARM's founding argument, that the stable security boundary for agentic AI isn't the model, the prompt, or the orchestration layer, but the action execution boundary, and that deterministic controls need to be enforced there, outside the agent's reasoning loop.</p><p>The reason for this of course is that soft guardrails such as system prompts are imperfect (as any security control is), and models are non-deterministic by nature, so we need deterministic controls outside the model to enforce rigorous security.</p><h2>Boundary 4 - Agent-Agent</h2><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Lwx-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Lwx-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png 424w, https://substackcdn.com/image/fetch/$s_!Lwx-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png 848w, https://substackcdn.com/image/fetch/$s_!Lwx-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png 1272w, https://substackcdn.com/image/fetch/$s_!Lwx-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Lwx-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png" width="866" height="202" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:202,&quot;width&quot;:866,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:81688,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Lwx-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png 424w, https://substackcdn.com/image/fetch/$s_!Lwx-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png 848w, https://substackcdn.com/image/fetch/$s_!Lwx-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png 1272w, https://substackcdn.com/image/fetch/$s_!Lwx-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1829e0c-3e12-4eb7-b9aa-bc2bed520e0a_866x202.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The agent-agent boundary concerns what happens when multiple agents communicate, delegate, debate, and share intermediate state. </p><p>In a well-isolated system, one agent&#8217;s message should remain a bounded contribution rather than an unverified control signal for others. The memorable line from the paper is that:</p><blockquote><p><strong>&#8220;a message is not just information. It can also be a carrier of control.&#8221;</strong></p></blockquote><p>The research here validates concerns I&#8217;ve raised repeatedly about multi-agent architectures as well as the reality that were in the infancy of inter-agent protocols, such as A2A. </p><p>The Prompt Infection research cited in the survey found that one compromised agent can pass malicious instructions to others, turning ordinary coordination into an attack channel, and the progression the authors describe is worth quoting because it reads like an incident report waiting to happen, &#8220;<em>first one compromised message, then repeated propagation, then communication-level cascade.</em>&#8221; </p><p>Topology matters too, since network structure, routing rules, and memory sharing determine how fast compromise travels and how hard it is to contain. Work like Trojan Hippo shows that shared memory is itself a high-risk surface, because poisoned memory can be weaponized for later exfiltration or control. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KdcM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KdcM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png 424w, https://substackcdn.com/image/fetch/$s_!KdcM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png 848w, https://substackcdn.com/image/fetch/$s_!KdcM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png 1272w, https://substackcdn.com/image/fetch/$s_!KdcM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KdcM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png" width="878" height="434" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:434,&quot;width&quot;:878,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:179847,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KdcM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png 424w, https://substackcdn.com/image/fetch/$s_!KdcM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png 848w, https://substackcdn.com/image/fetch/$s_!KdcM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png 1272w, https://substackcdn.com/image/fetch/$s_!KdcM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74ea6e2a-aab0-4146-9b15-e905493d6d4c_878x434.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The threat moves from bad messages, to bad agents, to bad shared state, at which point rollback becomes much harder than in a single-agent system. Readers who have gone through my OWASP Agentic Top 10 breakdown will recognize Insecure Inter-Agent Communication and Cascading Failures living at exactly this boundary.</p><p>On the defense side, efforts such a <strong><a href="https://github.com/OWASP/www-project-agent-memory-guard">Project Agent Memory Guard</a></strong> are starting to materialize. It&#8217;s aim is to stop AI agents from being weaponized through their own memory by sitting between the agent and the memory store, screening every operation through a pipeline of detectors and declarative policies.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rZ6A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rZ6A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png 424w, https://substackcdn.com/image/fetch/$s_!rZ6A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png 848w, https://substackcdn.com/image/fetch/$s_!rZ6A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png 1272w, https://substackcdn.com/image/fetch/$s_!rZ6A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rZ6A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png" width="487" height="374.7297709923664" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:504,&quot;width&quot;:655,&quot;resizeWidth&quot;:487,&quot;bytes&quot;:93751,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rZ6A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png 424w, https://substackcdn.com/image/fetch/$s_!rZ6A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png 848w, https://substackcdn.com/image/fetch/$s_!rZ6A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png 1272w, https://substackcdn.com/image/fetch/$s_!rZ6A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faece63c9-4913-4c87-b84a-39e5c0d3d3ab_655x504.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The section closes with a line I&#8217;d encourage every architect building multi-agent systems to keep in mind:</p><blockquote><p><strong>&#8220;</strong><em><strong>collaboration is not automatically a safeguard. Without isolation, it can become a mechanism for amplification</strong></em><strong>.&#8221;</strong></p></blockquote><h2>Boundary 5 - System-Environment</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kTuB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kTuB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png 424w, https://substackcdn.com/image/fetch/$s_!kTuB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png 848w, https://substackcdn.com/image/fetch/$s_!kTuB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png 1272w, https://substackcdn.com/image/fetch/$s_!kTuB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kTuB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png" width="853" height="255" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:255,&quot;width&quot;:853,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:106646,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207440871?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kTuB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png 424w, https://substackcdn.com/image/fetch/$s_!kTuB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png 848w, https://substackcdn.com/image/fetch/$s_!kTuB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png 1272w, https://substackcdn.com/image/fetch/$s_!kTuB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F299dacf8-7a78-489c-b97b-1edf9a713c20_853x255.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The final boundary concerns how an agent reads and reacts to the outside world. </p><p>In a well-isolated system, webpages, retrieved passages, documents, emails, interface elements, and memory artifacts should remain observations rather than hidden commands. Failure begins when environment-originated content is absorbed into agent context and then treated as if it had authority, which is the indirect prompt injection problem that has haunted LLM-integrated applications since the earliest research on the topic.</p><p>I continue to cite Google DeepMind&#8217;s paper on this titled &#8220;AI Agent Traps&#8221;, which discusses how the information environment itself from the web now:</p><blockquote><p><strong> becomes a vulnerability where adversarial content can manipulate, deceive or exploit visiting agents.</strong></p></blockquote><p>The survey shows this problem is broader and more persistent than first expected. For web and computer-use agents, the environment is not just read but clicked, navigated, and executed against, leading to the conclusion that &#8220;<em>web environments are active adversarial surfaces, not passive information sources.</em>&#8221; </p><p>Visual prompt injection work extends this to interface appearance itself, showing computer-use agents can be misled through how a page looks rather than what its text says. RAG systems expose another variant, where the issue is often corrupted evidence rather than explicit instruction, with work like PoisonedRAG and BADRAG showing attackers can manipulate knowledge bases so the agent reasons from compromised support, and the disclosure findings cut both ways, since &#8220;<em>the environment can both push corrupted knowledge in and pull private knowledge out</em>&#8221; through data extraction and membership inference attacks.</p><p>It&#8217;s easy to see how the adversarial content can quickly become a major problem for agents and this realization sits at the heart of what I call the Security vs. Utility tradeoff for AI Agents. The utility an agent has in terms of autonomy, tools and the ability to take actions, the more problematic it becomes security wise as well.</p><p>Defenses here are evolving from detection toward provenance, with approaches like Spotlighting and Task Shield aiming to mark, isolate, or filter environment-originated instructions before they silently become control input, and newer work adding causal attribution and trustworthy evidence selection. </p><p>The lesson from the authors is that system-environment safety &#8220;<em>will likely depend less on stronger generic refusal and more on better source authentication, provenance tracking, memory hygiene, and context attribution</em>.&#8221;</p><h2>When Boundaries Fail Together</h2><p>The taxonomy&#8217;s real payoff is in cross-boundary analysis. </p><p>Serious failures often cross boundaries, and the common pattern the authors describe is sequential escalation, where user input first overrides control at the user-agent boundary, then steers tool use, and finally triggers unsafe execution. </p><p>Another pattern starts from the environment, where a malicious webpage or poisoned memory item enters through the system-environment boundary and later propagates into tool calls, agent communication, or action traces. The unit of analysis is the full control path, not a single prompt or tool call, which is why &#8220;<em>local robustness at one interface does not guarantee system-level safety</em>.&#8221;</p><p>The forward-looking agenda the paper lands on is what the authors call isolation-by-construction, building interfaces where the boundary remains visible to the system itself. </p><p>Inputs from users, tools, peer agents, and external content should remain distinguishable, capability access should be scoped, propagation paths should be observable through trace-level monitoring, and recovery should be a core requirement once compromise reaches memory or shared state. </p><p>They&#8217;re also candid about open problems, noting that many benchmarks still test single boundaries while real failures are cross-boundary, and that the field still lacks stable abstractions for authority, trust, and privilege in full workflows.</p><h2>From Taxonomy to Deployment Patterns</h2><p>Academic taxonomies are only useful if they map to how agents actually show up in the enterprise, so let&#8217;s do that mapping. </p><p>As I discussed in my recent video breaking down OWASP&#8217;s <strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">State of Agentic AI Security and Governance</a></strong> report, agents are landing in organizations through a few distinct patterns, endpoint agents such as coding CLIs and agentic browsers running on user machines, custom or homegrown agents built on cloud platforms and orchestration frameworks, and SaaS-embedded agents that arrive inside the productivity and business platforms you already own.</p><div id="youtube2-x9YyIAV09lY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;x9YyIAV09lY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/x9YyIAV09lY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Each pattern weights the five boundaries differently. </p><p>Endpoint agents live and die at the agent-execution boundary, since they run with the user&#8217;s permissions, credentials, and file access, which is exactly the &#8220;running as root&#8221; problem Luke Hinds and I dug into, and why sandboxes, hooks, and OS-level enforcement matter most there. </p><p>Custom-built agents concentrate risk at the agent-tool and agent-agent boundaries, because you are the one wiring up MCP servers, tool catalogs, memory stores, and multi-agent topologies, and every one of those design decisions either preserves or erodes isolation. </p><p>SaaS-embedded agents shift the weight toward the system-environment and user-agent boundaries, since you control neither the model nor the runtime, and your exposure comes through the content, connectors, and data the agent can reach inside the platform.</p><p>This is also where the emerging crop of agent security tooling slots in, and I find it more useful to think about it in terms of two complementary functions rather than vendor categories or acronyms.</p><p>The first function is preventative and posture-focused, inventorying agents across all three deployment patterns, understanding their tools, identities, entitlements, and data access, and driving least privilege before anything goes wrong, which in taxonomy terms means knowing where your boundaries are and how much isolation each one actually enforces. Think of it akin to &#8220;Shift Left&#8221; for Agentic AI, aimed at posture, configurations, policies and more, before agents are running in production, or identifying deviations from desired posture for agents already deployed.</p><p>The second function is runtime monitoring and response, watching agent behavior for goal hijacks, anomalous tool use, and cross-boundary propagation, which maps directly to the paper&#8217;s calls for trace-level monitoring, attribution, and recovery.</p><p>Neither function replaces the hard boundaries themselves, but posture tells you where isolation is weak and runtime monitoring tells you when it has failed, and the paper's cross-boundary escalation patterns are a solid blueprint for what your runtime detections should actually be looking for.</p><p>For those wanting a fuller landscape view, I&#8217;ve started doing a video series breaking down the OWASP Agentic AI Top 10 one-by-one such as my first video below where I cover Agent Goal Hijack.</p><div id="youtube2-HUWlmV-h2SM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;HUWlmV-h2SM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/HUWlmV-h2SM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>You can check out the videos for my breakdown of the <strong><a href="https://www.resilientcyber.io/p/owasp-top-10-for-agentic-applications">OWASP Agentic AI Top 10</a></strong>  pairs naturally with this paper, since nearly every risk in that list is a boundary failure wearing a different name.</p><h2>Closing Thoughts</h2><p>It of course is debatable whether the industry needed another taxonomy, and the authors themselves acknowledge theirs is not the only valid way to organize the literature. </p><p>That said, I find the boundary-centric framing helpful, because it explains why so many differently-named attacks share the same structure and it gives practitioners a common language that spans research papers, OWASP guidance, and vendor categories alike. This builds on the excellent work of OWASP and others, such as my friend <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Rock Lambros&quot;,&quot;id&quot;:19291360,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98098048-f975-4577-a2c4-d411bafa8255_1172x1172.png&quot;,&quot;uuid&quot;:&quot;d227846a-fcf1-49f7-af14-85e7bbd921d7&quot;}" data-component-name="MentionToDOM"></span>, who&#8217;s blog you should follow if you haven&#8217;t already, as well as leaders like <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ken Huang&quot;,&quot;id&quot;:1160339,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;uuid&quot;:&quot;052feb4f-d4b9-4a68-8a27-ee3628a26644&quot;}" data-component-name="MentionToDOM"></span> who created MAESTRO, for threat modeling agentic systems.</p><p>The message security teams should take away is one I&#8217;ve been hammering for a while now, which is that we cannot prompt or guardrail our way to secure agents. Isolation has to be designed in, enforced structurally, and monitored continuously, and organizations adopting agents across endpoints, custom builds, and SaaS platforms would do well to ask one question of every deployment:</p><div class="pullquote"><p><strong>Where are the boundaries, and what actually enforces them?</strong></p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Cyber Valuations, Moats & the Road to Black Hat]]></title><description><![CDATA[An annual check-in with Foundation Capital&#8217;s Sid Trivedi on services-as-software, record AI SOC rounds, founder caution, and what&#8217;s actually defensible in the age of frontier labs.]]></description><link>https://www.resilientcyber.io/p/cyber-valuations-moats-and-the-road</link><guid isPermaLink="false">https://www.resilientcyber.io/p/cyber-valuations-moats-and-the-road</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 17 Jul 2026 12:44:45 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207323170/74f6dd3612ac2df2eddbd813ec2b9b88.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode, I sit down with my friend <strong><a href="https://www.linkedin.com/in/siddhanttrivedi/">Sid Trivedi</a></strong>, Partner at<strong><a href="https://foundationcapital.com/"> Foundation Capital</a></strong>, for what has turned into an annual conversation heading into Black Hat and Hacker Summer Camp. </p><p>Sid invests at the earliest stages, seed and Series A, with a focus on cybersecurity and IT infrastructure, so he has a front-row seat to the teams building the future of this field. A lot has moved since we last spoke, from massive M&amp;A closing to record-setting rounds in categories like the AI SOC, and I wanted to pressure test how much of it is grounded in reality.</p><h2>We chatted about:</h2><ul><li><p>What has actually changed a year into the AI wave, and what hasn&#8217;t, in how Foundation Capital backs formation-stage founders</p></li><li><p>Services-as-software, the $4.6 trillion market thesis, and automating cybersecurity workflows across product security, detection and response, IR, pen testing, and threat intel</p></li><li><p>What AI means for cybersecurity jobs, and why Sid thinks the jobs change rather than disappear</p></li><li><p>Consolidation vs. best-of-breed after Palo Alto&#8217;s $25B CyberArk acquisition and Alphabet&#8217;s $32B Wiz deal</p></li><li><p>AI SOC valuations, including Seven AI&#8217;s record cyber Series A, Torq crossing a $1B valuation, and Exaforce&#8217;s massive raise</p></li><li><p>The double-edged sword of big raises, and why you can&#8217;t simply spend your way to growth in cybersecurity</p></li><li><p>Moats and defensibility when frontier labs can replicate a chunk of your product</p></li><li><p>The Black Hat Innovator Investor Summit and the Startup Spotlight competition</p></li></ul><div id="youtube2-8wBZitdpRR0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;8wBZitdpRR0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/8wBZitdpRR0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>Prefer to listen? </h2><p>Catch the episode on <strong><a href="https://open.spotify.com/episode/2hwThEyYLnkCqn2BS6NrsK?si=-fDn1JKTS-OVWd16iBNtHQ">Spotify</a></strong> or <strong><a href="https://podcasts.apple.com/us/podcast/cyber-valuations-moats-the-road-to-black-hat/id1555928024?i=1000777101561">Apple Podcasts</a></strong>.</p><p>Be sure to subscribe and leave a review!</p><div><hr></div><h2>Takeaways</h2><blockquote><p><strong>Services-as-software is playing out, and the jobs question hangs over it</strong></p></blockquote><p>Sid&#8217;s colleagues at Foundation Capital wrote about services-as-software years ago, sizing it as a $4.6 trillion market, and he believes it is largely playing out as expected. Last year we talked about AI MDR and how managed detection would change with humans plus AI agents. </p><p>This year the aperture is wider. Sid framed it as looking at every task and team in cybersecurity, whether that&#8217;s product security, the SOC, incident response, pen testing, threat intel, or security strategy, and asking what portions of that work can be automated. That covers both external services from MSPs, MSSPs, and large consulting firms and the internal workflows of security teams themselves. </p><p>On the jobs question, Sid was direct. &#8220;I don&#8217;t worry that long term people will lose the ability to work. I think the jobs themselves will change.&#8221; I&#8217;ve been advocating the same thing for practitioners. Lean into these tools in your daily workflows now, because the adaptation is the job security.</p><blockquote><p><strong>Consolidation and best-of-breed will keep coexisting</strong></p></blockquote><p>Since our last conversation, Palo Alto closed its $25 billion acquisition of CyberArk and Alphabet finalized its $32 billion acquisition of Wiz, while players like ServiceNow keep expanding their security platforms through acquisition. I made the point that the convergence is bi-directional, with IT players moving into security and security players moving into IT, and you even see it in the workforce with leaders like Jamil at Equifax moving from CISO into broader IT leadership. </p><p>My view is that the platformization vs. best-of-breed debate never actually ends. There will always be innovative startups covering niche capabilities faster than incumbents can build them, and many of those startups will eventually get absorbed into the platforms. That cycle is the market working, not a contradiction.</p><blockquote><p><strong>Big valuations cut both ways for founders</strong></p></blockquote><p>The AI SOC category alone has produced Seven AI raising the largest cyber Series A on record, Torq crossing a billion-dollar valuation, and a massive raise from Exaforce. I pressed Sid on whether these numbers are grounded in what customers actually pay or whether the market is pricing a story ahead of the numbers, and on what happens to founders and teams who don&#8217;t grow into the valuations they accept. </p><p>The part I wanted practitioners and aspiring founders to sit with is that growth in cybersecurity is more nuanced than deploying capital. Buyers in this market behave differently, and there&#8217;s an implicit level of trust involved in procurement decisions, so you can&#8217;t simply spend your way to revenue, market share, and customers. </p><p>More capital raised means more expectation to grow into, and the congratulatory posts on social media rarely mention that side of it.</p><blockquote><p><strong>Moats in the frontier-lab era</strong></p></blockquote><p>We dug into the question every early-stage founder is wrestling with right now. If a frontier model can replicate a chunk of your product quickly, given the labs&#8217; size, capacity, and distribution, what are investors actually underwriting, and what no longer counts as defensible? We touched on the trend of headless software, which some cyber companies are starting to move toward, and the viral rant from one of the largest defense tech companies about proprietary data as a moat, which has spurred a broader open source vs. closed source AI debate worth following.</p><h2>See you at Black Hat</h2><p>Sid is heavily involved in the Innovator Investor Summit at Black Hat, which brings together investors, founders, and the people building the future of this domain, and </p><p>I&#8217;m excited to be MCing it this year following Mike Privette and others who came before me. We also talked about the Startup Spotlight competition, which I&#8217;d call the World Cup of cybersecurity startups. </p><div class="pullquote"><p><strong>Black Hat is offering listeners $500 off <a href="https://blackhat.com/us-26/innovators-summit.html">registration</a> with the code USA500Resilient.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blackhat.com/us-26/innovators-summit.html&quot;,&quot;text&quot;:&quot;-> Register Here! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blackhat.com/us-26/innovators-summit.html"><span>-&gt; Register Here! &lt;-</span></a></p></div><p>Thanks again to Sid for coming back on. You can follow his work at Foundation Capital and connect with him on LinkedIn.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #106]]></title><description><![CDATA[A Record 622-CVE Patch Tuesday, White House&#8217;s GOLD EAGLE Initiative, Grok CLI Exfiltrating Repos, Context Bombs Derailing AI Attackers, Coding Agent Economics & Cyber&#8217;s 1H 2026 Market Numbers]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-106</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-106</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 16 Jul 2026 11:54:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bXO2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #106 of the Resilient Cyber Newsletter!</p><p>If there was a single theme this week, it was volume. </p><p>Microsoft shipped a record 622 fixes in a single Patch Tuesday, <strong><a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/">told us</a></strong> to expect even more as AI-powered discovery ramps up, Jerry Gamblin&#8217;s mid-year CVE numbers show publication volume up nearly 50% YoY, and the White House launched a new initiative aimed at coordinating vulnerability discovery and patching at the national level. </p><p>The vulnerability management conversation we&#8217;ve been having for years is starting to look much different as AI continues to industrialize vulnerability discovery and exploitation.</p><p>We also have the Grok CLI repo exfiltration saga, some excellent pieces on the economics of AI and what they mean for security, and the 1H 2026 cybersecurity market numbers.</p><p>Things continue to be a mix of exciting and chaotic heading into Black Hat, so let&#8217;s dig into it all.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bXO2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bXO2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png 424w, https://substackcdn.com/image/fetch/$s_!bXO2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png 848w, https://substackcdn.com/image/fetch/$s_!bXO2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png 1272w, https://substackcdn.com/image/fetch/$s_!bXO2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bXO2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png" width="1203" height="745" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:745,&quot;width&quot;:1203,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:657396,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bXO2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png 424w, https://substackcdn.com/image/fetch/$s_!bXO2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png 848w, https://substackcdn.com/image/fetch/$s_!bXO2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png 1272w, https://substackcdn.com/image/fetch/$s_!bXO2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F472eb7a8-e427-441f-8deb-f8ac65997c48_1203x745.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><h3><strong><a href="https://www.opswat.com/cybersecurity-upside-down?utm_campaign=GLB-BRAND-Influencer-Marketing&amp;utm_medium=social_media&amp;utm_source=organicsocial&amp;utm_content=chris-hughes-newsletter">Rethink your file security strategy</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.opswat.com/cybersecurity-upside-down?utm_campaign=GLB-BRAND-Influencer-Marketing&amp;utm_medium=social_media&amp;utm_source=organicsocial&amp;utm_content=chris-hughes-newsletter" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JOrV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JOrV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JOrV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JOrV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JOrV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg" width="523" height="392.25" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:523,&quot;bytes&quot;:8285630,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.opswat.com/cybersecurity-upside-down?utm_campaign=GLB-BRAND-Influencer-Marketing&amp;utm_medium=social_media&amp;utm_source=organicsocial&amp;utm_content=chris-hughes-newsletter&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JOrV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JOrV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JOrV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JOrV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F285de046-2b21-43b9-819f-e4784e8c575b_4896x3672.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most security tools are built to detect threats in files after the fact. Content Disarm and Reconstruction (CDR) takes the opposite approach. It assumes every file is untrusted, rebuilds it from clean components, and eliminates the threat before execution. </p><p>OPSWAT Founder and CEO <strong><a href="https://www.bennyczarny.com/?utm_campaign=GLB-BRAND-Influencer-Marketing&amp;utm_medium=social_media&amp;utm_source=organicsocial&amp;utm_content=chris-hughes-newsletter">Benny Czarny</a></strong> makes the full case in <strong><a href="https://www.opswat.com/cybersecurity-upside-down?utm_campaign=GLB-BRAND-Influencer-Marketing&amp;utm_medium=social_media&amp;utm_source=organicsocial&amp;utm_content=chris-hughes-newsletter">Cybersecurity Upside Down</a></strong>, a practitioner-focused book on why prevention-first security is not just possible, but necessary. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.opswat.com/cybersecurity-upside-down?utm_campaign=GLB-BRAND-Influencer-Marketing&amp;utm_medium=social_media&amp;utm_source=organicsocial&amp;utm_content=chris-hughes-newsletter&quot;,&quot;text&quot;:&quot;-> Get the Book <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.opswat.com/cybersecurity-upside-down?utm_campaign=GLB-BRAND-Influencer-Marketing&amp;utm_medium=social_media&amp;utm_source=organicsocial&amp;utm_content=chris-hughes-newsletter"><span>-&gt; Get the Book &lt;-</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.linkedin.com/pulse/cybersecurity-market-review-1h-2026-domenic-perri-szgxc/">Cybersecurity Market Review 1H 2026</a></h3><p>The team at Altitude Cyber, led by Dino Boukouris and Domenic Perri, published their 1H 2026 Cybersecurity Market Review, and as always it is one of the most comprehensive looks at the state of the cybersecurity market, spanning M&amp;A, financing, public markets, and industry trends.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7CnL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7CnL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png 424w, https://substackcdn.com/image/fetch/$s_!7CnL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png 848w, https://substackcdn.com/image/fetch/$s_!7CnL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png 1272w, https://substackcdn.com/image/fetch/$s_!7CnL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7CnL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png" width="976" height="551" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:551,&quot;width&quot;:976,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:201626,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7CnL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png 424w, https://substackcdn.com/image/fetch/$s_!7CnL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png 848w, https://substackcdn.com/image/fetch/$s_!7CnL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png 1272w, https://substackcdn.com/image/fetch/$s_!7CnL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F175d94c2-1fa7-45ce-a60b-3e27a10a9be7_976x551.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Some of the findings that stood out to me:</p><ul><li><p>1H 2026 included 205 total M&amp;A transactions with a total disclosed or estimated deal volume of $22.3B, with deal count up 24% YoY while dollar volume declined 47% (largely a base effect from Google&#8217;s announced $32B Wiz acquisition in Q1 2025)</p></li><li><p>2026 is on pace for the highest number of strategic acquisitions ever, with 131 through June</p></li><li><p>AI Security emerged as a top M&amp;A sector in 1H 2026 with 19 deals, up from just 2 in the same period last year</p></li></ul><p>On the financing side, 1H 2026 saw 391 financing transactions totaling $8.8B, with deal count down 20% YoY but dollar volume actually up 3%, showing larger rounds concentrating in fewer companies, including Cyera&#8217;s $600M Series G (bringing their total raised to $2.3B) and NinjaOne&#8217;s eye-watering $12.3B valuation. The IPO drought also continues, with no cybersecurity IPOs so far in 2026 and only 3 over the past five years, compared to 15 from 2018-2021.</p><p>I also thought their framing on identity was spot on, stating that &#8220;identity is no longer just about employees and customers. As AI agents, workloads, and service accounts proliferate, identity is becoming the control plane for access, action, and trust across modern environments.&#8221;</p><h3><a href="https://menlovc.com/perspective/defense-at-machine-speed-the-emerging-architecture-powering-ai-native-cybersecurity/">Defense at Machine Speed</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tXLs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tXLs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png 424w, https://substackcdn.com/image/fetch/$s_!tXLs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png 848w, https://substackcdn.com/image/fetch/$s_!tXLs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png 1272w, https://substackcdn.com/image/fetch/$s_!tXLs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tXLs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png" width="523" height="194.47543160690572" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:280,&quot;width&quot;:753,&quot;resizeWidth&quot;:523,&quot;bytes&quot;:53006,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tXLs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png 424w, https://substackcdn.com/image/fetch/$s_!tXLs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png 848w, https://substackcdn.com/image/fetch/$s_!tXLs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png 1272w, https://substackcdn.com/image/fetch/$s_!tXLs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb5e1b336-6204-49e7-81bf-72b107b3511f_753x280.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Menlo Ventures&#8217; Venky Ganesan and Sam Borja laid out their thesis for AI-native cybersecurity, arguing that as attackers begin operating at machine speed and machine scale, defense has to be rebuilt around three layers - behavioral context engines, autonomous response agents, and continuous validation from both internal and external perspectives.</p><p>Of course, this is a VC thesis piece and Menlo is talking their book to an extent, with portfolio companies mapped to each layer of the architecture. That said, the underlying argument that threats have shifted from software vulnerabilities to compromised identities and social engineering, and that enterprises deploying fleets of agents will need independent behavioral monitoring of those agents, aligns with a lot of what we&#8217;re seeing across the industry.</p><p>That said, I do want to point out that exploitation is actually the #1 attack vector per the latest DBIR, not credential compromise or phishing, so it is fair to push back on their thesis given that context in my opinion.</p><p>It is still very AI-relevant though, as we see the AI-driven industrialization of vulnerability discovery and soon exploitation coming.</p><h3><a href="https://www.philvenables.com/post/technology-waves-and-security-is-this-time-really-different">Technology Waves and Security - Is This Time Really Different?</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j_yy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j_yy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png 424w, https://substackcdn.com/image/fetch/$s_!j_yy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png 848w, https://substackcdn.com/image/fetch/$s_!j_yy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png 1272w, https://substackcdn.com/image/fetch/$s_!j_yy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j_yy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png" width="609" height="315.59514170040484" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:384,&quot;width&quot;:741,&quot;resizeWidth&quot;:609,&quot;bytes&quot;:291860,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j_yy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png 424w, https://substackcdn.com/image/fetch/$s_!j_yy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png 848w, https://substackcdn.com/image/fetch/$s_!j_yy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png 1272w, https://substackcdn.com/image/fetch/$s_!j_yy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff44328bf-0eb0-43e9-90d7-d288b4208319_741x384.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Phil Venables published a measured look at technology waves and security, asking whether the AI wave is fundamentally different from the PC, Internet, mobile, and cloud waves that preceded it. </p><p>His answer is largely no, and the patterns hold, security is never built in enough, we always overestimate the short-term impact of these changes while underestimating their long-term impact, and effective system-wide security only becomes possible once common design patterns crystallize, as they eventually did for the Internet and cloud eras.</p><p>I found this a useful counterweight to the breathless takes in both directions. We&#8217;ve been here before, and while the scale and pace are greater this time, the playbook of watching for design patterns to stabilize and then hardening around them is a familiar one. </p><p>His point that human-on-the-loop, rather than human-in-the-loop, is the appropriate governance model for agents at scale will also likely prove prescient and it touches on points I&#8217;ve made in my own article &#8220;<strong><a href="https://www.resilientcyber.io/p/the-human-in-the-loop-illusion">The Human-in-the-Loop Illusion</a></strong>&#8221;. </p><h3><a href="https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/">White House Launches GOLD EAGLE Initiative</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y7my!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y7my!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png 424w, https://substackcdn.com/image/fetch/$s_!Y7my!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png 848w, https://substackcdn.com/image/fetch/$s_!Y7my!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png 1272w, https://substackcdn.com/image/fetch/$s_!Y7my!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y7my!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png" width="933" height="298" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:298,&quot;width&quot;:933,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91722,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y7my!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png 424w, https://substackcdn.com/image/fetch/$s_!Y7my!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png 848w, https://substackcdn.com/image/fetch/$s_!Y7my!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png 1272w, https://substackcdn.com/image/fetch/$s_!Y7my!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36dab9b9-992c-42c8-ae13-658881b4e9cc_933x298.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The White House announced Gold Eagle, a cybersecurity clearinghouse using frontier AI to coordinate vulnerability detection and patching across open source software and critical infrastructure. </p><p>The initiative flows from Executive Order 14409, &#8220;Promoting Advanced Artificial Intelligence Innovation and Security,&#8221; and involves Treasury, DHS/CISA, and the Department of War, with stated goals of reducing duplicative scanning, delivering prioritized threat intelligence to defenders, and strengthening critical infrastructure resilience.</p><p>Given the AI-driven surge in vulnerability discovery covered throughout this issue, some form of national-level coordination was probably inevitable, and this pairs interestingly with efforts like CMU&#8217;s FLARE-AI (covered below) that federal initiatives have been calling for. As always, execution will matter more than the announcement.</p><p>I touched on this back when I made a video covering the AI EO:</p><div id="youtube2-XN15BwOZRXA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;XN15BwOZRXA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/XN15BwOZRXA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident">Lessons from CISA&#8217;s Cyber Incident</a></h3><p>CISA published a postmortem of its own GitHub leak, and I want to give credit where it is due, because it takes organizational courage to publicly dissect your own incident, especially when you&#8217;re the nation&#8217;s cyber defense agency. </p><p>For those who missed it, a repository named &#8220;Private-CISA&#8221; containing 844 MB of sensitive data, including plaintext passwords, AWS GovCloud tokens, and Entra ID SAML certificates, sat publicly exposed for roughly six months before GitGuardian discovered it on May 14, 2026, with takedown within 26 hours of the report.</p><p>The lessons are ones every organization should internalize. Take external vulnerability reports seriously (nine automated alerts went unanswered), continuously scan repos for exposed secrets, simplify reporting channels (CISA admitted theirs &#8220;were not well defined, leading the security researcher to try multiple avenues&#8221;), and test key rotation readiness before you need it, as key invalidation took more than 48 hours. </p><p>If it can happen to CISA, it can happen to you.</p><h3><a href="https://www.microsoft.com/en-us/trust-center/security/secure-future-initiative/sfi-progress-report-july-2026">Microsoft&#8217;s Secure Future Initiative July 2026 Progress Report</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f2Sp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f2Sp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png 424w, https://substackcdn.com/image/fetch/$s_!f2Sp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png 848w, https://substackcdn.com/image/fetch/$s_!f2Sp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png 1272w, https://substackcdn.com/image/fetch/$s_!f2Sp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f2Sp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png" width="636" height="292" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:292,&quot;width&quot;:636,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:263754,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f2Sp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png 424w, https://substackcdn.com/image/fetch/$s_!f2Sp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png 848w, https://substackcdn.com/image/fetch/$s_!f2Sp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png 1272w, https://substackcdn.com/image/fetch/$s_!f2Sp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F117679af-6d3e-4341-a08b-afd8c7a9e4d8_636x292.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Microsoft released its July 2026 SFI progress report, continuing what has become one of the more transparent looks into security engineering at hyperscale, even if it is part marketing, mixed with security. </p><p>Some numbers that jumped out include phishing-resistant MFA now protects 99.97% of user/device pairs, 1.4 million unused Entra applications have been decommissioned, 732,000 resources were removed from public access, and automated container patching is addressing roughly 3 million vulnerability instances monthly.</p><p>Whatever your views on Microsoft&#8217;s security track record, and there is plenty of history to critique, the SFI reports offer a rare view into what Secure-by-Design looks like when applied across one of the largest attack surfaces on the planet, and the emphasis on AI-driven detection (with more than 90% of AI-assisted findings confirmed by their security engineers) is a preview of where enterprise security programs are headed.</p><h3><a href="https://www.bankinfosecurity.com/american-hackers-for-hire-proposal-sparks-heavy-criticism-a-32176">American &#8220;Hackers-for-Hire&#8221; Proposal Sparks Heavy Criticism</a></h3><p>A provision in the defense authorization bill would let the U.S. government deputize private contractors to conduct offensive cyber operations against foreign adversaries, effectively creating an American hack-for-hire network, and as BankInfoSecurity covers, the proposal is drawing heavy criticism from the security community.</p><p>The cyber letters-of-marque debate has been simmering for years, and the concerns are the usual ones, escalation, attribution, and collateral damage. That said, it is notable to see the concept advance this far in the legislative process rather than remaining a think-tank thought experiment, and it lands in the same season as offensive AI capabilities becoming dramatically cheaper.</p><h3><a href="https://www.ben-evans.com/benedictevans/2026/7/9/ways-to-think-about-token-pricing">Ways to Think About Token Pricing</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZhmN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZhmN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp 424w, https://substackcdn.com/image/fetch/$s_!ZhmN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp 848w, https://substackcdn.com/image/fetch/$s_!ZhmN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp 1272w, https://substackcdn.com/image/fetch/$s_!ZhmN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZhmN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp" width="1456" height="847" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:847,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:497140,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZhmN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp 424w, https://substackcdn.com/image/fetch/$s_!ZhmN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp 848w, https://substackcdn.com/image/fetch/$s_!ZhmN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp 1272w, https://substackcdn.com/image/fetch/$s_!ZhmN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1b49dff-596c-4750-932c-c12f6978b12f_2500x1455.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Benedict Evans wrote an excellent piece on ways to think about token pricing that I&#8217;d recommend to anyone trying to reason about the economics underneath the AI wave. He points out that a trillion dollars or more of data center capex is coming down the pipe, that inference today carries 40-50% gross margins, and that the current capacity crunch has been driven by sudden product-market fit in really just one use case, software development.</p><p>The open question he poses is whether foundation models retain pricing power or become low-margin commodity infrastructure, with the telecom precedent looming large, cellular data traffic rose by orders of magnitude while the stocks went nowhere. </p><p>For those of us watching security vendors race to bolt LLMs onto everything, the question of who actually captures value in this stack is far from academic, and it connects directly to Nir Zuk&#8217;s cost math on AI-driven detection covered in the AI section below.</p><h3><a href="https://snscratchpad.com/posts/reverse-information-paradox/">The Reverse Information Paradox</a></h3><p>Satya Nadella published a piece on his personal blog on what he calls the reverse information paradox, inverting Kenneth Arrow&#8217;s classic information paradox for the AI era. Where Arrow worried the seller of information gives away its value by describing it, Nadella argues the buyer of AI now:</p><blockquote><p><strong>&#8220;risks giving away knowledge, just in order to use what they bought,&#8221; because using AI means revealing your proprietary context, corrections, and workflows to the platform. As he puts it, &#8220;in consuming intelligence, you are creating intelligence,&#8221; and &#8220;if learning flows in only one direction, economic value converges toward the owners of the learning infrastructure.&#8221;</strong></p></blockquote><p>His prescription is for enterprises to demand a hard boundary around their data, traces, and adaptive weights, and to treat their usage and corrections as competitive assets rather than exhaust. </p><p>The irony of this coming from the CEO of one of the largest AI platform owners is thick, but the argument itself is one every CISO and CIO negotiating AI contracts should sit with, and this week&#8217;s Grok CLI story (below) is about as concrete an illustration as you could ask for.</p><p>This comes after Palantir&#8217;s Alex Karp&#8217;s now viral interview where he argued that frontier labs were stealing the &#8220;alpha&#8221; (e.g. the secret sauce/value) from their customers by accessing their data and potentially competing with them in the future. </p><div id="youtube2-0A3sGymV6kY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;0A3sGymV6kY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/0A3sGymV6kY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://youtu.be/sRvrXL83N-c">Stanford&#8217;s Economics of the AI Supercycle</a></h3><p>For those who want to go deeper on AI economics, Stanford has posted session recordings from MS&amp;E 435, &#8220;Economics of the AI Supercycle,&#8221; taught by Altimeter Capital&#8217;s Apoorv Agrawal, with this session covering infrastructure, enterprise AI, and SaaS. </p><p>The course treats AI as a technology cycle comparable to PCs, the Internet, and mobile, and examines the economics at each layer of the stack. Great free resource from a course whose guest list includes folks like Databricks&#8217; Ali Ghodsi and Altimeter&#8217;s Brad Gerstner. I&#8217;ve been really enjoying the discussions from this series, and the latest with Databricks CEO is equally as good.</p><div><hr></div><h1>AI</h1><h3><a href="https://youtu.be/x9YyIAV09lY?si=VPvrtcKawkVxiTUz">The State of Agentic Security</a></h3><p>OWASP recently launched v2 of their State of Agentic AI Security &amp; Governance report. I decided to make a video capturing the key takeaways and findings. </p><p>This will be the start of a video series, where I will walkthrough the OWASP ASI Agentic AI Top 10 as well, tying each risk to real-world incidents, mitigations and industry trends, so keep an eye out for that!</p><div id="youtube2-x9YyIAV09lY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;x9YyIAV09lY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/x9YyIAV09lY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://www.databricks.com/blog/benchmarking-coding-agents-databricks-multi-million-line-codebase">Benchmarking Coding Agents on Databricks&#8217; Multi-Million Line Codebase</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7cbK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7cbK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png 424w, https://substackcdn.com/image/fetch/$s_!7cbK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png 848w, https://substackcdn.com/image/fetch/$s_!7cbK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png 1272w, https://substackcdn.com/image/fetch/$s_!7cbK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7cbK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png" width="1055" height="681" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:681,&quot;width&quot;:1055,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:175281,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7cbK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png 424w, https://substackcdn.com/image/fetch/$s_!7cbK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png 848w, https://substackcdn.com/image/fetch/$s_!7cbK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png 1272w, https://substackcdn.com/image/fetch/$s_!7cbK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2eee88b2-c311-4cfd-830c-411e7b67c449_1055x681.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Databricks published one of the more useful coding agent benchmarks I&#8217;ve seen from a non-frontier lab or research entity, running agents against real engineering tasks from their own multi-million line codebase rather than synthetic benchmark suites. </p><p>The headline finding is that per-token pricing is a poor guide to actual cost. Sonnet 5 is ~1.7x cheaper per token than Opus 4.8, but on their tasks Sonnet cost $2.09/task vs Opus&#8217;s $1.94 while scoring six points lower on task completion (81% vs 87%), because cheaper models often take longer, less efficient paths.</p><p>Open models also landed on the Pareto frontier, with GLM 5.2 statistically tied with Opus 4.8 on quality at $1.28/task against Opus&#8217;s $1.94, and harness choice mattered as much as model choice, with one harness sending about 3x less context per turn.</p><p>The takeaway for security leaders evaluating AI tooling is the same one that applies everywhere in this issue, benchmark on your own workloads, because list pricing and leaderboards will mislead you.</p><h3><a href="https://www.linkedin.com/posts/nikita-benkovich_xais-grok-cli-exfiltrates-your-entire-repo-share-7482690157964435456-ftTN/">xAI&#8217;s Grok CLI Exfiltrates Your Entire Repo</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lr_B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lr_B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png 424w, https://substackcdn.com/image/fetch/$s_!lr_B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png 848w, https://substackcdn.com/image/fetch/$s_!lr_B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png 1272w, https://substackcdn.com/image/fetch/$s_!lr_B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lr_B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png" width="472" height="383.8062283737024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:578,&quot;resizeWidth&quot;:472,&quot;bytes&quot;:109880,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lr_B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png 424w, https://substackcdn.com/image/fetch/$s_!lr_B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png 848w, https://substackcdn.com/image/fetch/$s_!lr_B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png 1272w, https://substackcdn.com/image/fetch/$s_!lr_B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e915be-4dd1-4c3e-9b8a-37e99a3afd79_578x470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The week&#8217;s biggest AI trust story, a researcher discovered that xAI&#8217;s Grok CLI coding agent was silently uploading users&#8217; entire Git repositories, including full commit history, files the agent never read, and unredacted .env files, to xAI-controlled cloud storage. </p><p>Nikita Benkovich shared a good breakdown of the finding. In one test, a 12 GB repository produced 5.10 GiB of uploads while actual model-response traffic in the same session was just 192 KB, and a planted canary file the agent never touched was recovered verbatim from the intercepted traffic. </p><p>Worse, turning off the &#8220;Improve the model&#8221; setting didn&#8217;t stop the uploads, the toggle governed training use, not transmission. xAI disabled the uploads server-side on July 13, with Elon Musk stating previously uploaded data would be &#8220;completely and utterly deleted.&#8221;</p><p>This is exactly why the conversations happening at the leadership level, from Alex Karp to Satya Nadella&#8217;s reverse information paradox piece above, about frontier labs training on customers&#8217; alpha and proprietary data matter so much. Your codebase is your IP, and increasingly your alpha, and this incident shows the gap that can exist between what an AI vendor&#8217;s settings imply and what the telemetry actually does. </p><p>Trust, but verify, and maybe run a proxy.</p><h3><a href="https://futurism.com/artificial-intelligence/open-source-ai-model-scary-mythos">An Open-Weight Model as Capable as the Restricted Ones</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hr9m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hr9m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png 424w, https://substackcdn.com/image/fetch/$s_!Hr9m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png 848w, https://substackcdn.com/image/fetch/$s_!Hr9m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png 1272w, https://substackcdn.com/image/fetch/$s_!Hr9m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hr9m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png" width="1088" height="153" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:153,&quot;width&quot;:1088,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:36630,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hr9m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png 424w, https://substackcdn.com/image/fetch/$s_!Hr9m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png 848w, https://substackcdn.com/image/fetch/$s_!Hr9m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png 1272w, https://substackcdn.com/image/fetch/$s_!Hr9m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4386ab6-a8f6-4a24-9b80-1aab99fe7f6e_1088x153.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Futurism covered the release of GLM-5.2, an open-weight model from Beijing-based Z.ai that researchers say can perform large-scale coding tasks similar to Anthropic&#8217;s Mythos 5, the model the U.S. government restricted over national security concerns and which remains available to only around 100 U.S. organizations and government agencies. </p><p>As Armadin founder and CTO Travis Lanham put it, </p><blockquote><p><strong>&#8220;an attacker can run it locally without safety guardrails, fine-tune it against their specific targets, and operate with zero visibility to any provider or defender,&#8221; </strong></p></blockquote><p>This is the exact point <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;37799939-4448-4d35-9753-f72ce62ad852&quot;}" data-component-name="MentionToDOM"></span> has rightly made in various blogs that I&#8217;ve shared previously.</p><p>This is the fundamental tension in the model restriction debate, export controls and access gates on U.S. frontier models don&#8217;t mean much when open-weight equivalents ship from jurisdictions that don&#8217;t share those controls. Joshua Saxe&#8217;s piece below makes the policy argument in depth.</p><h3><a href="https://xbow.com/blog/affordable-ai-models-glm-muse-spark-cybersecurity">The Rise of Affordable Models - GLM and Muse Spark on Cyber</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cV0E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cV0E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png 424w, https://substackcdn.com/image/fetch/$s_!cV0E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png 848w, https://substackcdn.com/image/fetch/$s_!cV0E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png 1272w, https://substackcdn.com/image/fetch/$s_!cV0E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cV0E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png" width="1179" height="281" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:281,&quot;width&quot;:1179,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:110825,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cV0E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png 424w, https://substackcdn.com/image/fetch/$s_!cV0E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png 848w, https://substackcdn.com/image/fetch/$s_!cV0E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png 1272w, https://substackcdn.com/image/fetch/$s_!cV0E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b406c4-e809-4a8b-8d06-269f4cd342b8_1179x281.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Staying on that thread, XBOW benchmarked GLM-5.2 and Muse Spark 1.1 on offensive security tasks, finding GLM-5.2 performing somewhere between GPT-5 and Opus 4.6, short of the true frontier but remarkably capable for the cost. Their framing is the right one, </p><blockquote><p><strong>&#8220;GLM does not need to become Mythos to change the threat landscape. If a lower-cost model can perform useful offensive work at scale, then it is already relevant,&#8221; because &#8220;attackers do not usually need the best model in the world. They need a model that can find one real vulnerability before the cost stops making sense.&#8221;</strong></p></blockquote><p>Offensive capability is being commoditized from below, not just advanced from above, and the economics of attack are changing faster than most defensive planning assumes.</p><h3><a href="https://xbow.com/blog/Grok-4-5-ai-model-offensive-security">Grok 4.5 and the Middle of the AI Security Market</a></h3><p>XBOW also put Grok 4.5 through its paces, finding it eventually solves roughly 93% of the vulnerabilities in their benchmark, performing like a frontier model at a fixed number of iterations. </p><p>The more interesting finding is the price band, between roughly $1 and $10 per attempt, Grok 4.5 consistently delivered the highest observed solve rate of the models they tested, reaching approximately 75% around $1 compared with about 65% for the nearest alternatives. They describe it as &#8220;a sports car that is surprisingly practical.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4fIr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4fIr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png 424w, https://substackcdn.com/image/fetch/$s_!4fIr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png 848w, https://substackcdn.com/image/fetch/$s_!4fIr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png 1272w, https://substackcdn.com/image/fetch/$s_!4fIr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4fIr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png" width="544" height="406.8035190615836" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:510,&quot;width&quot;:682,&quot;resizeWidth&quot;:544,&quot;bytes&quot;:126264,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4fIr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png 424w, https://substackcdn.com/image/fetch/$s_!4fIr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png 848w, https://substackcdn.com/image/fetch/$s_!4fIr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png 1272w, https://substackcdn.com/image/fetch/$s_!4fIr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76f476ee-160f-4a46-9a52-fab3bba33f84_682x510.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Taken together with the GLM piece, the pattern is clear, the middle of the market is where attack economics get decided, and that middle is getting crowded and cheap.</p><h3><a href="https://agentic.tracebit.com/context-bombs/">Context Bombs - Stopping AI Attackers in Their Tracks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zcqR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zcqR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png 424w, https://substackcdn.com/image/fetch/$s_!zcqR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png 848w, https://substackcdn.com/image/fetch/$s_!zcqR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png 1272w, https://substackcdn.com/image/fetch/$s_!zcqR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zcqR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png" width="493" height="306.9622641509434" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:363,&quot;width&quot;:583,&quot;resizeWidth&quot;:493,&quot;bytes&quot;:134888,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zcqR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png 424w, https://substackcdn.com/image/fetch/$s_!zcqR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png 848w, https://substackcdn.com/image/fetch/$s_!zcqR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png 1272w, https://substackcdn.com/image/fetch/$s_!zcqR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ea4aaa9-33a9-433d-89e3-5e64db0d43d7_583x363.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On the defensive side of the AI attacker equation, Tracebit published clever research on &#8220;context bombs&#8221;, short text strings planted in decoy resources like canary secrets, environment variables, and DNS records along an attacker&#8217;s likely path, designed to trip the built-in safety guardrails of offensive AI agents mid-intrusion. </p><p>Across 152 runs in simulated AWS environments, agents achieved at least one attack path in 91% of baseline runs versus only 15% in bombed ones, with admin privilege escalation dropping from 57% to 5%. One frontier model achieved admin access in 93% of baseline runs but failed every single time once a context bomb was in play.</p><p>There&#8217;s a delightful irony in defenders weaponizing prompt injection, the same class of weakness attackers exploit, as a tripwire. Also interesting, Western models halted on strings referencing sensitive biological topics, while Chinese models halted on politically sensitive topics written in Chinese. </p><p>Deception and canary techniques have always been underrated, and they may be entering a golden age against machine adversaries, a point I&#8217;ve seen others such as Gadi Evron make.</p><h3><a href="https://cylake.substack.com/p/ai-is-exposing-cybersecuritys-biggest">AI Is Exposing Cybersecurity&#8217;s Biggest Assumptions</a></h3><p>Nir Zuk, Palo Alto Networks co-founder and now founder/CEO of Cylake, argues that the industry&#8217;s AI conversation is focused on the wrong bottleneck. The problem isn&#8217;t model intelligence, it&#8217;s data architecture, &#8220;an AI agent cannot defend what it cannot see,&#8221; and today&#8217;s fragmented security data can&#8217;t feed AI-driven detection. </p><p>His cost math is sobering, estimating that continuously running LLM-based detection over enterprise telemetry at scale would cost approximately $158 million per year at current frontier model pricing, and that even a one-million-token context window covers roughly 40 seconds of enterprise activity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lPUa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lPUa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png 424w, https://substackcdn.com/image/fetch/$s_!lPUa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png 848w, https://substackcdn.com/image/fetch/$s_!lPUa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png 1272w, https://substackcdn.com/image/fetch/$s_!lPUa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lPUa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png" width="1065" height="564" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22f61bd3-675c-4427-8356-86672afd100f_1065x564.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:564,&quot;width&quot;:1065,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:365762,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lPUa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png 424w, https://substackcdn.com/image/fetch/$s_!lPUa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png 848w, https://substackcdn.com/image/fetch/$s_!lPUa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png 1272w, https://substackcdn.com/image/fetch/$s_!lPUa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22f61bd3-675c-4427-8356-86672afd100f_1065x564.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You can quibble with the assumptions (few would propose brute-forcing raw telemetry through a frontier LLM), but the underlying point stands, &#8220;AI does not reduce the need for data. It dramatically increases it,&#8221; and unified data architecture remains the unsolved problem underneath all the AI SOC hype.</p><h3><a href="https://joshuasaxe181906.substack.com/p/the-origins-of-ill-conceived-model">The Origins of Ill-Conceived Model Cyber Restrictions</a></h3><p>Speaking of <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;05a29e42-3ba7-4d67-89a8-6703e4b4acd6&quot;}" data-component-name="MentionToDOM"></span>, he wrote a sharp critique of model cyber capability restrictions, arguing the policy community adopted a flawed capabilities-centric view of model risk when an ecosystem-centric view would serve U.S. security far better. </p><p>His reasoning is that defenders benefit more from unrestricted access to capable models than attackers do, attackers can simply shift to non-monitored open-weight models (see GLM-5.2 above), and distillation makes capability diffusion inevitable anyway, with one 2026 study distilling under 4,000 expert trajectories from a frontier model into a small open model and nearly closing the performance gap.</p><p>He also brings receipts on actual attacker AI usage, noting that the leaked Black Basta chats showed operators using ChatGPT for polished phishing letters and exploit debugging, useful but hardly a capability transformation. Given this week&#8217;s GLM-5.2 news, the piece reads less like a prediction and more like a description of the present.</p><h3><a href="https://kenhuangus.substack.com/p/the-untrusted-tenant-rethinking-infrastructure">The Untrusted Tenant: Rethinking Infrastructure Security for Agentic AI</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6DOz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6DOz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png 424w, https://substackcdn.com/image/fetch/$s_!6DOz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png 848w, https://substackcdn.com/image/fetch/$s_!6DOz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png 1272w, https://substackcdn.com/image/fetch/$s_!6DOz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6DOz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png" width="634" height="364.9750957854406" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:601,&quot;width&quot;:1044,&quot;resizeWidth&quot;:634,&quot;bytes&quot;:154240,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6DOz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png 424w, https://substackcdn.com/image/fetch/$s_!6DOz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png 848w, https://substackcdn.com/image/fetch/$s_!6DOz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png 1272w, https://substackcdn.com/image/fetch/$s_!6DOz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57fa6678-a988-4eed-ab06-537d805b8468_1044x601.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ken Huang&quot;,&quot;id&quot;:1160339,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;uuid&quot;:&quot;7c137fe4-9631-4439-b155-a4654ea62abe&quot;}" data-component-name="MentionToDOM"></span> and Edera&#8217;s Alex Zenla published a piece arguing for treating AI agents as untrusted tenants, shifting the security question from whether the model is safe to what the model can reach. </p><p>Their core claim is hard to argue with, &#8220;an LLM&#8217;s output is untrusted data. If you are executing actions based on that output, you are executing untrusted code.&#8221; They point to last summer&#8217;s Replit incident, where a coding agent deleted a production database during an active code freeze with no exploit and no injection, as proof that autonomy plus access is enough for catastrophe.</p><p>The prescription is hard multi-tenant isolation, hardware-enforced boundaries, a separate kernel per workload rather than shared-kernel namespaces, scoped credentials, and default-deny networking, with modern microVM boot times meaning strong isolation is no longer the performance tax it once was. </p><p>I dove into all of this myself with Alex not long ago on the Resilient Cyber Show</p><div id="youtube2-tZvJ7-8x4iU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;tZvJ7-8x4iU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/tZvJ7-8x4iU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://arxiv.org/pdf/2607.06595">When Agents Remember Too Much - Memory Poisoning Attacks</a></h3><p>A new paper on arXiv introduces GhostWriter, a memory poisoning attack against tool-using personal LLM agents with long-term memory. The attack works in two phases, injection (an adversary plants a hidden payload, for example via email the agent processes) and activation (the poisoned memory is later retrieved and steers behavior), and the results are rough, approximately 98% injection rates and approximately 60% average activation rates against state-of-the-art agents. </p><p>The authors also propose a defense, AM-Sentry, combining memory-saving policies and retrieval screening.</p><p>Agent memory is a persistence mechanism, in both the product sense and the attacker sense. As agents accumulate long-term memory across sessions while ingesting untrusted inputs, poisoned memories become the agentic equivalent of a backdoor that survives reboots.</p><p>It&#8217;s another example where the utility of agents create the very circumstances for security risks and compromise, something I&#8217;ve been calling the Security vs. Usability tradeoff.</p><h3><a href="https://github.com/OWASP/www-project-agent-memory-guard">OWASP Agent Memory Guard</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pzoR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pzoR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png 424w, https://substackcdn.com/image/fetch/$s_!pzoR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png 848w, https://substackcdn.com/image/fetch/$s_!pzoR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png 1272w, https://substackcdn.com/image/fetch/$s_!pzoR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pzoR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png" width="496" height="399.3095238095238" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6da6572-d44f-484f-8fa5-e977da789e47_672x541.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:541,&quot;width&quot;:672,&quot;resizeWidth&quot;:496,&quot;bytes&quot;:98262,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pzoR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png 424w, https://substackcdn.com/image/fetch/$s_!pzoR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png 848w, https://substackcdn.com/image/fetch/$s_!pzoR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png 1272w, https://substackcdn.com/image/fetch/$s_!pzoR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa6da6572-d44f-484f-8fa5-e977da789e47_672x541.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Conveniently paired with the above, OWASP has an open source project called Agent Memory Guard, a runtime defense layer that sits as middleware between an AI agent and its memory store, screening every read and write for prompt-injection markers, secret and PII leakage, protected-key modifications, and churn attacks. </p><p>It serves as the reference implementation for ASI06: Memory Poisoning from the OWASP Top 10 for Agentic Applications, and its published benchmarks show a 92.5% detection rate with 100% precision at 59 microseconds of median latency.</p><p>It&#8217;s early-stage, but this is the kind of concrete, deployable control the agentic security conversation needs more of, and it ships with drop-in LangChain middleware for those who want to kick the tires.</p><h3><a href="https://arxiv.org/pdf/2501.17070">Contextual Agent Security - A Policy for Every Purpose</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ANvM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ANvM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png 424w, https://substackcdn.com/image/fetch/$s_!ANvM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png 848w, https://substackcdn.com/image/fetch/$s_!ANvM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png 1272w, https://substackcdn.com/image/fetch/$s_!ANvM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ANvM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png" width="664" height="434.3788546255507" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:594,&quot;width&quot;:908,&quot;resizeWidth&quot;:664,&quot;bytes&quot;:172649,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ANvM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png 424w, https://substackcdn.com/image/fetch/$s_!ANvM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png 848w, https://substackcdn.com/image/fetch/$s_!ANvM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png 1272w, https://substackcdn.com/image/fetch/$s_!ANvM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb58147cd-2a58-46a7-bc49-3189adc321d7_908x594.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Google researchers Lillian Tsai and Eugene Bagdasarian make the case that static security policies cannot scale to generalist agents, because judging an action&#8217;s safety requires knowledge of the context in which it takes place, and this is a point I agree with. It&#8217;s why we see so much discussion around agent security right now and topics such as &#8220;intent analysis&#8221;. </p><p>Their proposed framework, Conseca, generates just-in-time, contextual, human-verifiable security policies with deterministic enforcement, rather than relying on manually crafted allow-lists or user confirmation fatigue. In their evaluation, Conseca preserved roughly 60% task completion (versus ~70% for unrestricted agents) while denying contextually inappropriate actions, where static restrictive policies dropped completion to zero.</p><p>This is a position paper rather than a product, but the direction feels right. Agent authorization has to become dynamic and contextual, because the space of things a generalist agent might legitimately do is too large to enumerate in advance.</p><p>That said, I did see a follow up from the paper from Google that they&#8217;ve begun implementing contextual based access control in their platform, building on these principles.</p><h3><a href="https://www.linkedin.com/pulse/when-owasp-llm-risks-meet-agentic-steve-wilson-wkeec/">When OWASP LLM Risks Meet Agentic</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aO6G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aO6G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png 424w, https://substackcdn.com/image/fetch/$s_!aO6G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png 848w, https://substackcdn.com/image/fetch/$s_!aO6G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png 1272w, https://substackcdn.com/image/fetch/$s_!aO6G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aO6G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png" width="1456" height="776" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:776,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2239735,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aO6G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png 424w, https://substackcdn.com/image/fetch/$s_!aO6G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png 848w, https://substackcdn.com/image/fetch/$s_!aO6G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png 1272w, https://substackcdn.com/image/fetch/$s_!aO6G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a2176d3-564f-49f4-9dcc-b675567a0ccb_1658x884.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Steve Wilson, who founded and leads the OWASP GenAI Security Project and literally wrote the book on LLM security, published a piece on how the OWASP LLM Top 10 risks translate into the agentic context. </p><p>With OWASP&#8217;s Top 10 for Agentic Applications now out and agentic deployments accelerating, mapping the two risk frameworks together is timely work, and Steve is about as authoritative a voice as exists on this topic</p><h3><a href="https://www.cmu.edu/news/stories/archives/2026/july/cmu-researchers-help-close-a-critical-security-gap-across-ai-platforms">CMU Helps Close a Critical Security Gap Across AI Platforms</a></h3><p>Carnegie Mellon&#8217;s Software Engineering Institute and partners launched FLARE-AI, an open source platform for standardized, machine-readable reporting of AI flaws, vulnerabilities, and incidents, routing reports to the right developers, vendors, and government bodies. It connects to the VINCE coordination environment, enabling CERT/CC to issue CVE IDs and vulnerability notes for AI systems, and SEI&#8217;s AI Security Incident Response Team will review submissions for coordinated disclosure.</p><p>As SEI&#8217;s Lauren McIlvenny notes, &#8220;a reporter might spot a problem in a particular model or system, but they&#8217;re not looking across all the vendors,&#8221; which is exactly the gap in AI flaw handling today, where the same weakness often exists across many models and platforms with no mechanism to coordinate disclosure. Between FLARE-AI and GOLD EAGLE above, the vulnerability coordination infrastructure for AI is starting to take real shape.</p><p>Couple this with the various commercial vulnerability clearinghouse efforts recently and it is feeling like while they are all good, it will lean to a bit of sprawl and trying to rationalize the outputs and data from each of the efforts too.</p><h3><a href="https://www.linkedin.com/pulse/limiting-reagents-why-ai-coding-isnt-shipping-features-keegan-hines-orffe">Limiting Reagents - Why AI Coding Isn&#8217;t Shipping Features</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DV4G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DV4G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png 424w, https://substackcdn.com/image/fetch/$s_!DV4G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png 848w, https://substackcdn.com/image/fetch/$s_!DV4G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png 1272w, https://substackcdn.com/image/fetch/$s_!DV4G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DV4G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png" width="1456" height="809" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:809,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:295078,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DV4G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png 424w, https://substackcdn.com/image/fetch/$s_!DV4G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png 848w, https://substackcdn.com/image/fetch/$s_!DV4G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png 1272w, https://substackcdn.com/image/fetch/$s_!DV4G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e6819d7-5b6c-48c6-bc93-c9a5bd831d47_1790x994.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Keegan Hines borrows a concept from chemistry to explain why AI coding isn&#8217;t translating into shipped features, in any reaction, the limiting reagent determines the yield, and the argument here is that raw code generation was rarely the limiting reagent in software delivery, so accelerating it alone doesn&#8217;t accelerate shipping.</p><p>This dovetails with the Dark Reading piece in the AppSec section, if security review and vulnerability remediation are among the limiting reagents, AI-accelerated code generation just piles up work-in-progress in front of them.</p><p>In other words, the bottleneck just moves to other areas of the process and/or system.</p><h3><a href="https://www.linkedin.com/pulse/framework-frontier-ai-dawning-new-age-demis-hassabis-cngse">A Framework for Frontier AI and the Dawning of a New Age</a></h3><p>Google DeepMind CEO Demis Hassabis published a proposal for frontier AI governance, calling for a U.S.-led Frontier AI Standards Body modeled on a federally overseen public-private partnership or self-regulatory organization, much like FINRA, that would independently safety-test frontier models, with labs voluntarily sharing models for review up to 30 days before release. He believes AGI is probably only a few short years away and describes the magnitude of the technology&#8217;s impact as &#8220;perhaps 10x of the Industrial Revolution at 10x the speed.&#8221;</p><p>Whatever you make of the timeline claims, the fact that the leader of one of the world&#8217;s premier AI labs is publicly calling for independent pre-release safety testing, with cyber capabilities explicitly among the catastrophic risks in scope, says a lot about where the frontier conversation has moved. </p><p>The proposal&#8217;s emphasis on applying to all frontier-class models regardless of origin or openness will be the hard part, as this week&#8217;s GLM-5.2 coverage makes clear. It received positive attention from various industry leaders in my feeds, such as Elon, Satya and Sam Altman.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days">Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days</a></h3><p>July&#8217;s Patch Tuesday set a record, with Microsoft patching <strong>622 vulnerabilities</strong>, including 416 in Windows and 164 across the Office suite. Two zero-days were already exploited in the wild, CVE-2026-56155, an Active Directory Federation Services flaw allowing local privilege escalation to administrator, and CVE-2026-56164, a SharePoint Server bug enabling network-based privilege escalation without authentication. </p><p>A BitLocker security bypass (CVE-2026-50661) was also publicly disclosed before patches were available, and the release includes a CVSS 9.9 Windows VMSwitch issue.</p><p>Prioritize the AD FS and SharePoint fixes if you haven&#8217;t already, and keep the 622 number in mind as you read the next two items, because it isn&#8217;t an anomaly, it&#8217;s a trendline of AI&#8217;s impact on the industrialization of discovering vulnerabilities, both for vendors and attackers.</p><h3><a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/">Evolving Windows Vulnerability Management for AI-Powered Discovery</a></h3><p>Right on cue, Microsoft published a piece on <strong><a href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/">evolving Windows vulnerability management</a></strong> that amounts to a heads-up for every Windows shop. AI is making it possible to find more issues, faster, across more code, including through their multi-model agentic scanning harness (MDASH), and:</p><blockquote><p><strong>&#8220;as AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release.&#8221;</strong></p></blockquote><p>Microsoft is framing the coming surge in patch volume as defensive success rather than declining code quality, and there&#8217;s truth to that, but from the operator&#8217;s seat the effect is the same, more patches, more often, with the same change windows and the same staffing. </p><p>Vulnerability management programs built around monthly cadences and manual prioritization are going to buckle, and the mid-year CVE data below shows why.</p><h3><a href="https://www.linkedin.com/posts/jgamblin_vulnerabilitymanagement-cybersecurity-cve-share-7481785477319118848-tgjk/">CVE Mid-Year 2026 Check-In: Volume Vertical, Exploitation Rare</a></h3><p>Per Vulnerability Researcher Jerry Gamblin&#8217;s mid-year CVE check-in, 35,364 CVEs were published in the first half of 2026, averaging 195.4 CVEs per day and representing 49.5% growth over H1 2025, putting the year on pace for roughly 72,000 CVEs. Meanwhile, only 85 of those H1 CVEs, 0.24%, appear in CISA&#8217;s KEV catalog.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zDDX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zDDX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png 424w, https://substackcdn.com/image/fetch/$s_!zDDX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png 848w, https://substackcdn.com/image/fetch/$s_!zDDX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!zDDX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zDDX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png" width="1456" height="828" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:828,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:850525,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zDDX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png 424w, https://substackcdn.com/image/fetch/$s_!zDDX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png 848w, https://substackcdn.com/image/fetch/$s_!zDDX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png 1272w, https://substackcdn.com/image/fetch/$s_!zDDX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94bf1ba2-827f-4e4d-a30f-f43c111bd74a_1958x1114.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As Jerry puts it, the volume curve has gone vertical while exploitation has not, and the challenge is signal-to-noise, not patch volume. This is the data underneath everything else in this section. Discovery is industrializing while exploitation remains rare and concentrated, which means context and prioritization, not raw patching throughput, determine whether your program survives the curve.</p><h3><a href="https://0xmoose.substack.com/p/signal-over-noise-ai-agents-and-the">Signal Over Noise: AI Agents and the Operator Moat</a></h3><p>One of the more interesting first-person accounts I&#8217;ve read on AI&#8217;s impact on offensive security work, <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;ads (@0xmoose)&quot;,&quot;id&quot;:225647821,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ac9e94e-e0d8-4e4e-9965-141af1f9bb07_1024x1024.jpeg&quot;,&quot;uuid&quot;:&quot;1e005b4e-4f74-452b-9978-a55ffb8a4322&quot;}" data-component-name="MentionToDOM"></span> who is an AI red teamer at Dreadnode documents how agents scaled his personal bug bounty output, with 2026 submission volume reaching nearly 6x his full-year 2025 output in roughly six months, including a peak day of 21 reports. The key detail is that quality improved while volume scaled, with reports closed without acceptance dropping from 32% to 24% across 853+ submissions spanning 78 unique CWEs.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B78w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B78w!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png 424w, https://substackcdn.com/image/fetch/$s_!B78w!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png 848w, https://substackcdn.com/image/fetch/$s_!B78w!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png 1272w, https://substackcdn.com/image/fetch/$s_!B78w!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B78w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png" width="1456" height="941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:247944,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B78w!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png 424w, https://substackcdn.com/image/fetch/$s_!B78w!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png 848w, https://substackcdn.com/image/fetch/$s_!B78w!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png 1272w, https://substackcdn.com/image/fetch/$s_!B78w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d890aba-8d61-4ea4-a71f-f9a176892669_1690x1092.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>His thesis is that the durable moat is the expert operator, the human who scopes targets, validates findings, reads agent traces, and acts as final arbiter between real vulnerabilities and false positives, not the agents themselves. AI scaling submission volume, and AI validating it on the receiving end. Every program in between is about to get squeezed.</p><h3><a href="https://www.first.org/blog/20260708-FIRSTCON26-PR3TACK">PR3TACK: The Preemptive Tactics &amp; Countermeasures Knowledgebase</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HzDN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HzDN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png 424w, https://substackcdn.com/image/fetch/$s_!HzDN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png 848w, https://substackcdn.com/image/fetch/$s_!HzDN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png 1272w, https://substackcdn.com/image/fetch/$s_!HzDN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HzDN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png" width="1456" height="358" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:358,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:132189,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HzDN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png 424w, https://substackcdn.com/image/fetch/$s_!HzDN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png 848w, https://substackcdn.com/image/fetch/$s_!HzDN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png 1272w, https://substackcdn.com/image/fetch/$s_!HzDN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6eb4fa1-c06d-400d-a224-39fafab45645_2164x532.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Out of FIRSTCON26, Atlassian&#8217;s Vishal Thakur introduced PR3TACK, a knowledgebase of plausible-but-unobserved adversary TTPs designed to close the &#8220;anticipatory gap&#8221; left by retrospective frameworks like MITRE ATT&amp;CK. </p><p>It spans 17 tactic categories, 6 of them exclusive to the framework, including Pre-Positioning (think sleeper commits in open source projects), Cognitive Manipulation (alert flooding, adversarial logs), AI/ML Subversion, and Digital Exhaust Manipulation (weaponizing telemetry and threat intel feeds).</p><p>As the author puts it, &#8220;PR3TACK is not a crystal ball,&#8221; and its value &#8220;lies instead in shaping a culture of anticipatory defence.&#8221; With AI compressing the timeline from plausible to observed, cataloging what attackers could do before they do it feels less academic than it would have even a couple of years ago.</p><h3><a href="https://semgrep.dev/blog/2026/ai-supply-chain-problem/">You Can&#8217;t Reverse Engineer Your Way Out of the AI Supply Chain Problem</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dYKB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dYKB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png 424w, https://substackcdn.com/image/fetch/$s_!dYKB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png 848w, https://substackcdn.com/image/fetch/$s_!dYKB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png 1272w, https://substackcdn.com/image/fetch/$s_!dYKB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dYKB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png" width="1456" height="709" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67a730cc-a28c-4043-9023-966100bbba62_1806x880.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:709,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:247122,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dYKB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png 424w, https://substackcdn.com/image/fetch/$s_!dYKB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png 848w, https://substackcdn.com/image/fetch/$s_!dYKB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png 1272w, https://substackcdn.com/image/fetch/$s_!dYKB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67a730cc-a28c-4043-9023-966100bbba62_1806x880.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Semgrep team, including Isaac Evans, Cris Thomas (Space Rogue), and Katie Paxton-Fear, published a thoughtful piece on the AI supply chain problem, arguing that unlike traditional binaries, we have almost no ability to reverse engineer models today, which means even open-weight models can&#8217;t be trusted the way inspectable software can. </p><p>They cite poisoning research showing that the number of samples required to add a backdoor does not increase as the model increases in size, and invoke Ken Thompson&#8217;s trusting-trust lesson, you can&#8217;t trust a system simply because you can inspect what&#8217;s in front of you.</p><p>Their conclusion is that &#8220;provenance, reproducibility, and independent evaluation will matter far more than marketing claims or benchmark scores,&#8221; and they&#8217;re right, benchmarks are gameable and model cards are marketing. This applies to every model in this issue, not just the ones from any particular country.</p><h3><a href="https://www.linkedin.com/posts/mccartypaul_last-week-was-crazy-with-3245-malicious-components-share-7481825278391119872-7O9Q/">3,245 Malicious Components in One Week</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TuFR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TuFR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png 424w, https://substackcdn.com/image/fetch/$s_!TuFR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png 848w, https://substackcdn.com/image/fetch/$s_!TuFR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png 1272w, https://substackcdn.com/image/fetch/$s_!TuFR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TuFR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png" width="1456" height="761" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:761,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:804198,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/207180795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TuFR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png 424w, https://substackcdn.com/image/fetch/$s_!TuFR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png 848w, https://substackcdn.com/image/fetch/$s_!TuFR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png 1272w, https://substackcdn.com/image/fetch/$s_!TuFR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acb4943-b28f-4be8-bd41-bce3a232553d_1952x1020.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Speaking of the traditional software supply chain, open source malware researcher Paul McCarty flagged 3,245 malicious components identified in a single week in his recurring supply chain recap. Numbers like this keep making the case that malicious packages are a distinct problem from vulnerable packages, and most SCA tooling remains oriented toward the latter.</p><h3><a href="https://www.darkreading.com/application-security/ai-coding-security-risks-productivity-gains">AI Coding&#8217;s Security Costs vs. Productivity Gains</a></h3><p>Dark Reading&#8217;s Alexander Culafi asks the uncomfortable ROI question about AI coding tools, and the numbers he assembles deserve attention. GitLab&#8217;s 2026 AI Accountability Report found 91% of organizations using two or more coding tools, a SonarSource survey found 96% of developers said they do not trust AI-generated code to be functionally correct as is, Veracode research found 45% of AI generated code samples contained OWASP Top 10 vulnerabilities, and GitGuardian found AI coding assistant use increases the secrets incidence rate by approximately 40%, with AI-assisted commits leaking secrets at 3.2% versus a 1.5% baseline.</p><p>Add remediation labor, false-positive triage (with experts citing security teams spending up to 40% of their time on findings that are ultimately non-exploitable), and credential cleanup, and the productivity math starts looking murkier than the vendor decks suggest. </p><p>The gains are real, but the costs land in a different budget, usually security&#8217;s.</p><h3><a href="https://asecurityengineer.com/posts/llms-in-sast/">LLMs in SAST: Good, Bad, Costly</a></h3><p>A grounded practitioner take on where LLMs actually fit in static analysis from Ali Yazdani. His argument is the highest-ROI role for LLMs is triage and explanation layered on top of deterministic SAST engines, not replacing them, since traditional SAST&#8217;s false-positive burden commonly runs between 30% and 100% of findings volume, and LLM triage has achieved 96% agreement with security researchers, with Semgrep&#8217;s Assistant now handling around 60% of incoming triage work for customers. LLM-alone scanning, by contrast, under-reports and creates false confidence.</p><p>My favorite line, &#8220;Accuracy isn&#8217;t a slope you slide down gracefully, it&#8217;s a cliff.&#8221; Alert fatigue has always been SAST&#8217;s costliest problem, and triage is exactly where a probabilistic system belongs, with a deterministic engine remaining the source of truth.</p><h2>Final Thoughts</h2><p>Stepping back from the individual stories, the through line this week is that the economics of security are being repriced in real time. </p><p>Discovery is industrializing on both sides, with CVE volume up nearly 50%, a record Patch Tuesday, offensive capability available at commodity prices, and bug bounty operators scaling 6x with agents. Meanwhile, the durable value keeps concentrating in the same places, context, validation, identity, and the humans who know what actually matters.</p><p>We&#8217;ve spent two decades optimizing for finding more things. Now organizations are doing the long overdue work of getting ruthless about deciding what deserves attention, and treating their data, their identities, and increasingly their AI agents as the assets and attack surface they actually are.</p><blockquote><p><strong>Stay resilient.</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Building for Breach]]></title><description><![CDATA[The Case for Containment in a World Where Prevention Has a Ceiling]]></description><link>https://www.resilientcyber.io/p/building-for-breach</link><guid isPermaLink="false">https://www.resilientcyber.io/p/building-for-breach</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 14 Jul 2026 15:50:32 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7f6564a3-e973-407a-9625-69998de26f52_899x378.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I have spent the better part of my career trying to help organizations reduce risk through vulnerability management and application security. </p><p>I have written books on the subject, worked in AppSec programs, ran vulnerability management operations, and spent years in the federal government helping large enterprises operationalize zero trust. </p><p>I am a true believer in patching, in secure development, in shifting left, and I am telling you that none of it, individually or combined, is going to be enough to keep pace with where the threat and current landscape with AI&#8217;s convergence with cyber is heading.</p><p>The economics of offense changed underneath us, and most security programs are still budgeted as if they did not.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>You Cannot Patch Your Way Out of This</h2><p>The vulnerability discovery rate is now compounding on multiple independent curves.</p><p>The CVE ecosystem published over 40,000 vulnerabilities in 2025, and projections for 2026 range from 60,000 to as high as 100,000 depending on how aggressively you account for AI-assisted discovery, based on FIRST&#8217;s <strong><a href="https://www.first.org/newsroom/releases/20260615">2026 mid-year projection</a></strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mvmj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mvmj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png 424w, https://substackcdn.com/image/fetch/$s_!mvmj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png 848w, https://substackcdn.com/image/fetch/$s_!mvmj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png 1272w, https://substackcdn.com/image/fetch/$s_!mvmj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mvmj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png" width="1244" height="617" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:617,&quot;width&quot;:1244,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:168280,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206558243?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mvmj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png 424w, https://substackcdn.com/image/fetch/$s_!mvmj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png 848w, https://substackcdn.com/image/fetch/$s_!mvmj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png 1272w, https://substackcdn.com/image/fetch/$s_!mvmj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F01d5f917-d441-448c-87ac-9fbf863deec8_1244x617.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As I covered in <strong><a href="https://www.resilientcyber.io/p/ai-is-winning-the-cyber-arms-race">AI Is Winning the Cyber Arms Race</a></strong>, offense became a compute problem, and compute keeps getting cheaper and faster. Finding and exploiting a vulnerability is a search task. The cost per token has been deflating faster than Moore&#8217;s Law, and that is a structural shift rather than a handful of headline demos.</p><p>At the same time, the global codebase keeps expanding. AI-assisted development is accelerating the rate of new code, and every new function creates interaction surfaces with existing code. The growth isn&#8217;t trivial either, as I have discussed in the <strong><a href="https://www.resilientcyber.io/p/the-attack-surface-exponential">The Attack Surface Exponential</a></strong>, GitHub alone is poised to go from 1 billion commits in 2025 to 14 billion in 2026. </p><p>Dependency chains amplify the problem further. The average enterprise application pulls in hundreds of open-source dependencies, each with its own transitive tree often five to seven levels deep, and a single flaw anywhere in that tree is a flaw in every application that imports it.</p><p>On the defense side, remediation has a hard ceiling. </p><p>The <strong><a href="https://blog.qualys.com/vulnerabilities-threat-research/2026/03/23/the-broken-physics-of-remediation">Qualys Threat Research Unit analyzed</a></strong> CISA&#8217;s Known Exploited Vulnerabilities program across 1.1 billion remediation records from more than 10,000 organizations over four years. What they found should concern every practitioner. Organizations that increased their remediation effort by a factor of 6.5 in a single year, closing 6.5 times more tickets, saw the percentage of critical vulnerabilities still unresolved at seven days actually worsen from 56% to 63%. Massive effort, negative marginal returns.</p><p>This happens because writing the fix is only about 10 to 15% of the enterprise remediation timeline. The rest is organizational work such as impact assessment, cross-team coordination, testing against dependent systems, scheduling deployment windows, deploying without breaking production, verifying the fix. </p><blockquote><p><strong>That bottleneck is organizational, not computational. </strong></p></blockquote><p>AI can help write patches faster, but a 10x improvement in fix-writing speed applied to 10 to 15% of the total timeline produces less than a 2x improvement end to end. That does not change the math when discovery has increased by orders of magnitude.</p><p>Meanwhile, the exploitation window has collapsed. </p><p>CrowdStrike&#8217;s 2026 Global Threat Report puts average breakout time at <em>29 minutes</em>, with the fastest observed breakout at <em>27 seconds</em>. The broader exploitation window compressed from 771 days in 2018 to just hours in recent years, as is well documented in the <strong><a href="https://zerodayclock.com/">Zero Day Clock</a></strong>. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZMMa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZMMa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png 424w, https://substackcdn.com/image/fetch/$s_!ZMMa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png 848w, https://substackcdn.com/image/fetch/$s_!ZMMa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png 1272w, https://substackcdn.com/image/fetch/$s_!ZMMa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZMMa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png" width="599" height="378.77033985581875" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:614,&quot;width&quot;:971,&quot;resizeWidth&quot;:599,&quot;bytes&quot;:75054,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206558243?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZMMa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png 424w, https://substackcdn.com/image/fetch/$s_!ZMMa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png 848w, https://substackcdn.com/image/fetch/$s_!ZMMa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png 1272w, https://substackcdn.com/image/fetch/$s_!ZMMa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3cbc8f-0a7b-49d2-a9f4-fba9f63d029c_971x614.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For the class of vulnerabilities that actually determines whether an organization suffers a material breach, attackers are often discovering and weaponizing before defenders are even notified.</p><p>Patching remains necessary. It is a hygiene function that every organization must perform, but the ecosystem math means it can no longer serve as the sole strategy an organization relies on to prevent material breach. Discovery is compounding, remediation has a ceiling, and the gap between them is widening, not narrowing.</p><h2>A Practitioner&#8217;s History with Microsegmentation</h2><p>The idea that you should limit lateral movement through network segmentation is not new. It has been a foundational security principle for decades. NIST has written about it extensively in publications such as 800-207. CISA&#8217;s Zero Trust Maturity Model explicitly includes network as a pillar, and the advanced maturity levels require microsegmentation with dynamic, identity-based policy enforcement. </p><blockquote><p><strong>Every serious security framework includes some version of this requirement.</strong></p></blockquote><p>The adoption numbers tell a different story. Gartner estimates that only 5 to 20% of enterprises have implemented microsegmentation in any form. In cloud specifically, only a small fraction of workloads have any perimeter network security at all. The vast majority of production environments are still running flat or near-flat architectures where compromising a single workload can give an attacker a path to nearly everything.</p><p>I lived this problem firsthand during my years helping large federal enterprises implement zero trust. The pattern repeated across agencies and programs. Security teams would identify microsegmentation as a priority. Leadership would agree in principle&#8230;then the project would stall.</p><blockquote><p><strong>The first reason was fear of breaking production. </strong></p></blockquote><p>Network policy changes carry real operational risk. In environments where uptime is measured against availability SLAs that carry political consequences, teams default to inaction rather than risk an outage. I watched programs where the security architecture was approved, funded, and staffed, and still never enforced because the operations team could not accept the risk of flipping the switch and potentially impacting business units.</p><blockquote><p><strong>The second reason was operational complexity. </strong></p></blockquote><p>Traditional microsegmentation required deep network engineering expertise, manual policy creation for every communication path, and constant policy maintenance as applications changed. Most organizations did not have the staff, the tooling, or the institutional patience for it. The policies grew stale, the exceptions multiplied, and eventually the segmentation existed on paper while production networks stayed flat.</p><blockquote><p><strong>The third reason, and perhaps the most fundamental, was that nobody actually knew what their applications needed to talk to. </strong></p></blockquote><p>You cannot write effective segmentation policies without a complete understanding of application communication patterns. In most environments I worked in, that understanding did not exist. Application teams knew their own service, but the full map of dependencies, especially transitive ones across shared infrastructure, was something nobody owned.</p><p>So the concept sat on architecture diagrams and compliance checklists while production environments stayed open, and every time an attacker got through, the blast radius was the entire environment because nothing constrained lateral movement or egress.</p><h3>Secure-by-Design Means Architecture, Not Just Code</h3><p>The industry conversation around Secure-by-Design has focused heavily on how software is written. Memory-safe languages, secure coding practices, developer security education, secure defaults in libraries and frameworks. </p><blockquote><p><strong>All of that work matters and should continue, but Secure-by-Design should apply with equal force to how systems and environments are architected and deployed.</strong></p></blockquote><p>A perfectly written application deployed in a flat network with unrestricted egress and over-permissioned service identities is not secure by design. It is secure code sitting in an insecure architecture. When that application gets compromised, and given the vulnerability deficit it eventually will, the damage is determined not by the quality of the code but by the architecture surrounding it.</p><p>NIST and CISA included network segmentation in their publications and guidance because decades of breach data demonstrate that the presence or absence of architectural containment is a determining factor in whether an incident becomes a catastrophe. </p><p>That data continued to prove the point in 2026. CrowdStrike reports that 82% of intrusions now use valid credentials through legitimate channels, producing no anomalous signal. Attackers are logging in rather than hacking in. The identity layer sees no violation, the endpoint layer sees no malware, and the question of whether the attacker can move laterally and exfiltrate data comes down entirely to whether architectural constraints exist on those paths.</p><p>This is what I mean by building for resilience. </p><p>We need to accept that breaches will occur and orient our architecture around limiting the damage when they do. Patching tries to reduce the probability of breach. Detection tries to minimize the time an attacker operates. Architectural containment reduces the blast radius, and it is the only variable fully determined by design choices the defender makes before any incident occurs.</p><h2>Cloud Made the Problem Worse</h2><p>On-premises environments, for all their limitations, developed with multiple defensive layers roughly in balance. The network pillar was pervasive, with perimeter firewalls, internal zones, VLAN segmentation, and routing-enforced separation. A compromised credential still had to traverse multiple layers before reaching anything of value.</p><p>Cloud inverted that posture. Identity became genuinely strong through AWS IAM, Azure Entra, and GCP IAM, but cloud providers left networking wide open because their economic engine is developer velocity, and network security reads as friction. </p><p>As Doug Merritt put it when we discussed this on <strong><a href="https://www.resilientcyber.io/p/ai-is-winning-the-cyber-arms-race">Resilient Cyber</a></strong>, &#8220;developer velocity and security is friction.&#8221; That incentive structure produced defaults where every major cloud provider ships allow-all outbound traffic and permits unrestricted communication between workloads in the same network. Kubernetes compounds the problem, with EKS, AKS, and GKE all permitting unrestricted pod-to-pod communication unless explicit network policies are applied.</p><div id="youtube2-OGy2cD3oTxM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;OGy2cD3oTxM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/OGy2cD3oTxM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The endpoint pillar became patchy in cloud at the same time. Containers, serverless functions, managed databases, and AI inference endpoints cannot host traditional agents. Much of the modern compute fabric lives for seconds. The workload types growing fastest are the types least compatible with agent-based security.</p><p>The practical result is that defense-in-depth in the cloud collapsed to a single pillar. That pillar, identity, is getting outsized focus, and rightfully so. It is also the pillar most easily bypassed when the attacker arrives with valid credentials, which is what happens in 82% of intrusions. </p><p>This is why, as I discussed with Doug Merritt on <strong><a href="https://aviatrix.ai/in-progress/chris-hughes-not-prevention-but-resiliency/">Aviatrix&#8217;s In Progress podcast</a></strong>, the interesting question is never how they got in, it is always a lateral movement and egress problem.</p><div id="youtube2-wzKzPsFHb30" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;wzKzPsFHb30&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/wzKzPsFHb30?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>What Containment Looks Like in Cloud</h2><p>The historic blocker to microsegmentation was cognitive load. </p><p>Writing and maintaining policies for tens of thousands of workloads across multiple clouds, regions, and compute models was more than most teams could sustain. That is the version of segmentation I watched fail repeatedly in federal environments.</p><p>What changed is AI. </p><p>AI is strong at the synthesis and pattern-matching that segmentation demands, specifically baselining application communication patterns, recommending policies based on observed behavior, and identifying anomalous flows against that baseline. The staged path of observe, baseline, monitor, and then enforce that was theoretically correct but practically unworkable a few years ago is becoming operationally realistic.</p><p>I recently walked through Aviatrix&#8217;s approach to this problem in a pair of detailed demos with their engineering team, and it maps well to what I always wished I had available during those federal zero trust implementation efforts.</p><p>The platform starts with visibility, onboarding cloud accounts in read-only mode to discover traffic flows and existing workloads across VMs, containers, Kubernetes clusters, and AI agents. This is the step that most segmentation projects skip or historically involved manual interviews and discussions with application teams, and it is the step whose absence causes everything downstream to fail. </p><blockquote><p><strong>You cannot write policies for communication patterns you do not understand.</strong></p></blockquote><p>From there, Aviatrix deploys lightweight enforcement points at the account level that govern both egress and east-west traffic without requiring global network modifications or changes to the underlying routing infrastructure. </p><p>Policy is expressed in terms of workload identity using existing cloud metadata and tags rather than IP addresses, which are meaningless in environments where workloads are constantly created and destroyed. </p><p>The enforcement model progresses through a lifecycle, from unprotected to monitored to partially protected to fully protected, giving teams the ability to validate policies against real traffic patterns before activating enforcement. If something breaks, reversal is a single action rather than an escalation path.</p><p>Two aspects of their approach address the failure modes I saw most often in practice.</p><p> The first is that the platform assumes brownfield environments. Most segmentation tools I&#8217;ve evaluated assumed some degree of greenfield architecture, and that assumption almost always wrong. Aviatrix works with whatever the customer has deployed today, as the network exists now, not as we wish it did.</p><p>The second is support for a dual-control operational model where a security team manages overarching guardrails and threat blocking through a centralized interface, while application teams manage their own specific policies through Terraform and CI/CD pipelines, in the formats and methodologies they are used to.</p><p>This aligns with how modern platform engineering teams actually work, and it distributes the operational burden of policy management across the people who best understand what each application needs.</p><p>The platform also extends containment to AI workloads, with the ability to detect communication with LLM endpoints and apply policy to AI agents. </p><p>Given that AI agents are rapidly becoming privileged non-human identities with broad cross-service access, and given real-world demonstrations like the GrafanaGhost attack where an AI assistant was weaponized to exfiltrate data through an authorized rendering channel with no anomalous signal, governing AI agent communication paths is not a theoretical future concern. </p><p>It is a current operational gap that most organizations have not begun to address.</p><div><hr></div><blockquote><p><strong>Looking for a deeper dive for effective containment in the AI era? Grab the guide below!</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://aviatrix.ai/cisos-guide-to-the-containment-era/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wPQ3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png 424w, https://substackcdn.com/image/fetch/$s_!wPQ3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png 848w, https://substackcdn.com/image/fetch/$s_!wPQ3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png 1272w, https://substackcdn.com/image/fetch/$s_!wPQ3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wPQ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png" width="458" height="366.5396341463415" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:525,&quot;width&quot;:656,&quot;resizeWidth&quot;:458,&quot;bytes&quot;:150614,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://aviatrix.ai/cisos-guide-to-the-containment-era/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206558243?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wPQ3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png 424w, https://substackcdn.com/image/fetch/$s_!wPQ3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png 848w, https://substackcdn.com/image/fetch/$s_!wPQ3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png 1272w, https://substackcdn.com/image/fetch/$s_!wPQ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49ded8-286a-424c-805e-dcf7ddd4ebfc_656x525.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aviatrix.ai/cisos-guide-to-the-containment-era/&quot;,&quot;text&quot;:&quot;-> Grab the Guide! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aviatrix.ai/cisos-guide-to-the-containment-era/"><span>-&gt; Grab the Guide! &lt;-</span></a></p><div><hr></div><h2>Building for Resilience</h2><p>I named my outlet and brand Resilient Cyber for a reason. </p><p>Resilience has always been the more honest framing for security. It does not pretend that prevention will succeed every time and instead, it accepts that incidents will occur and focuses on ensuring those failures are survivable.</p><blockquote><p><strong>Containment is the architectural expression of that principle. </strong></p></blockquote><p>It does not prevent the initial compromise, it prevents the initial compromise from propagating into the kind of lateral movement and data exfiltration that turns an incident into a headline. It holds whether or not the exploited vulnerability has been patched, whether or not the breach has been detected, and whether or not anyone on the security team is awake at 3 AM when the attacker moves.</p><p>The cybersecurity industry invested two decades primarily in prevention and detection. Both remain necessary, and both face structural headwinds that limit their effectiveness as standalone strategies. </p><p>The threat environment now demands at least equal investment in the architectural layer that governs what happens after prevention fails and before detection catches up. Blast radius should be a metric that CISOs, CIOs, and boards track deliberately and drive down over time, not a number they discover after an incident. </p><p>Organizations that treat it this way will be the ones who&#8217;s incidents stay local and recoverable, while everyone else is left explaining to leadership and regulators why a single compromised workload gave the attacker access to the entire environment.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Building an AI AppSec Engineer]]></title><description><![CDATA[Why MTTR is quietly lying to your AppSec team]]></description><link>https://www.resilientcyber.io/p/building-an-ai-appsec-engineer</link><guid isPermaLink="false">https://www.resilientcyber.io/p/building-an-ai-appsec-engineer</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 13 Jul 2026 12:02:38 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/206607772/e1d726ba3815d234bef197ea44005d8d.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Nobody has ever loved their AppSec tools. For years they flooded teams with findings that never answered the only question that mattered, which of these can actually hurt us. JJ, co-founder and CEO of <strong><a href="https://www.gecko.security/">Gecko Security</a></strong>, thinks AI finally changes that, and he brought a former Disney and Costco CISO along to pressure-test the idea from the buyer's chair.</p><div id="youtube2-xtdt2P8qKVU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;xtdt2P8qKVU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/xtdt2P8qKVU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><strong>Why this conversation matters</strong></h2><p>This conversation sits right on the fault line running through AppSec today, where cheap AI discovery is burying teams in findings while the context needed to prioritize them keeps getting harder to assemble. </p><p>JJ makes the technical case for reasoning across code, architecture, and runtime at once, and Ryan Knisley grounds it in the messy reality of enterprise security, from broken metrics to tool sprawl to the uncomfortable speed at which CISOs are now being asked to trust automation. </p><p>If you build or lead an application security program, this is a clear-eyed look at what is about to consolidate and what still needs a human.</p><h2><strong>Key takeaways</strong></h2><ul><li><p><strong>An AI security engineer beats another scanner.</strong> Gecko reasons across code, infrastructure, and documentation so a finding arrives already tied to whether it is reachable in production and what data it would expose, which is the context legacy SAST never had.</p></li><li><p><strong>Exploitability is decided outside the code.</strong> The product logic, architecture, and runtime that determine whether a bug matters live in design docs and Slack threads, not in the file a scanner reads, so context-free findings are mostly noise.</p></li><li><p><strong>Business logic will not fall to a bigger model.</strong> JJ&#8217;s example is an endpoint with no auth check, which is critical in a document store and normal in a social app, and no LLM staring at the code alone can tell the two apart without the surrounding system of truth.</p></li><li><p><strong>Chaining flips the priority list.</strong> As Ryan puts it, nobody attacks the lows, but the real question was always which low can get us, and connecting issues into an attack path finally answers it, sometimes demoting a paper critical and promoting ten chained lows.</p></li><li><p><strong>The old severity list is breaking under commoditized offense.</strong> With exploit development getting cheap and agents running campaign-level attacks, defenders working down a flat list of misaligned severities are structurally behind.</p></li><li><p><strong>Recurrence rate should replace MTTR.</strong> JJ argues MTTR rewards closing the same bug over and over with a fresh clock, so Gecko measures how many findings are variants of a class you already fixed and treats the class, not the ticket, as the unit of work.</p></li><li><p><strong>You can buy time with a one-line mitigation.</strong> When properly fixing a chain would take three teams and weeks, Gecko can identify the single link to sever and stand up something like a Lambda to kill the attack path today, borrowing decades-old SecOps thinking for vulnerabilities.</p></li><li><p><strong>Cal.com is the canary for open source in the AI era.</strong> AI coding tripled its pull request volume against a one-person security team, and once attackers could cheaply read every public change, openness became a liability, so it went closed source and consolidated four tools into one.</p></li><li><p><strong>Consolidation is about risk and people, not just cost.</strong> Ryan&#8217;s shiny object problem leaves teams unable to take vacation because one person owns a tool, and collapsing the stack buys depth, cross-training, and less complexity to defend.</p></li><li><p><strong>Judgment is the job that survives.</strong> As finding and fixing get automated, both guests land in the same place, that the scarce human work becomes deciding what correct looks like in your system and owning the risk you accept on purpose.</p></li></ul><h2><strong>Notable quotes</strong></h2><blockquote><p>&#8220;a fake metric that makes teams look good&#8221;</p></blockquote><p>Ryan Knisley, on why MTTR rewards the wrong behavior.</p><blockquote><p>&#8220;we&#8217;re gonna get dusted, we&#8217;re gonna get left behind, we&#8217;re gonna get absolutely owned&#8221;</p></blockquote><p>Ryan Knisley, on the teams that are slow to adopt AI.</p><blockquote><p>&#8220;the scarce thing left is the judgment&#8221;</p></blockquote><p>JJ, on what stays human once finding and fixing get cheap.</p><h2><strong>Listen and watch</strong></h2><p><strong><a href="https://youtu.be/xtdt2P8qKVU?si=XAknV8nQMHudAZu9">YouTube</a></strong></p><p><strong><a href="https://open.spotify.com/episode/4BeCx6idWPvI7suPTmUlJX?si=qzFMYBT5S9e_e6joG_AxIw"> Spotify</a></strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/building-an-ai-appsec-engineer/id1555928024?i=1000776389536"> Apple Podcasts</a></strong></p><h2><strong>Resources</strong></h2><p><strong><a href="https://www.gecko.security/">Gecko Security</a></strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.gecko.security/&quot;,&quot;text&quot;:&quot;-> Check Out Gecko Security! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.gecko.security/"><span>-&gt; Check Out Gecko Security! &lt;-</span></a></p><h2><strong>Subscribe</strong></h2><p>If this kind of practitioner-first take on AppSec and AI is useful to you, subscribe to Resilient Cyber for more conversations and writing on cybersecurity, AI, and the forces that shape both.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Architecture Problem SASE Can’t Outrun]]></title><description><![CDATA[The Case for Enforcement at the Edge, Not the Detour]]></description><link>https://www.resilientcyber.io/p/the-architecture-problem-sase-cant</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-architecture-problem-sase-cant</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 10 Jul 2026 12:00:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kkjd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>SASE was supposed to be the answer. </p><p>When the perimeter collapsed and work scattered across SaaS applications, personal devices, and home networks, the industry needed an architecture that could follow. SASE promised exactly that. Converge networking and security into the cloud, route traffic through centralized inspection points, and apply policy regardless of where the user sits.</p><p>For a while, it worked well enough, and then AI entered the picture and accelerated a set of structural limitations that were already forming.</p><p>Over 20,000 enterprises purchased SASE solutions in 2025. </p><p>Most have only partially deployed the capabilities they own. Licenses sit unused, bypass lists quietly grow, and policies look complete on dashboards while gaps widen in practice. This is not a failure of execution or a vendor quality problem. It is a sign that the problem SASE was designed to solve has changed underneath the architecture and shelf-ware is pervasive.</p><p>Understanding where traditional SASE fits in that complexity, and where it falls short, matters for every practitioner evaluating their current stack.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Detour Tax</h2><p>The core execution model of traditional SASE is straightforward. </p><p>Traffic is backhauled to a cloud proxy, broken and inspected, and forwarded to its destination. Enforcement depends entirely on routing sessions through centralized inspection points at distant points of presence.</p><p>When that architecture was designed, it made sense. The problem is not that it was wrong, the problem is that it was designed for a world that no longer exists.</p><p>Every session routed through a distant PoP pays what you might call a detour tax. CRM sessions lag, video calls stutter, and ticketing systems stall. In bandwidth-constrained geographies, SaaS workflows become inconsistent or borderline unusable. Users feel this immediately and respond in the most predictable way possible. They find workarounds, they switch to personal devices, and they use unsanctioned tools. Every workaround quietly increases the attack surface, shadow usage, and security teams rarely learn about it until something goes wrong.</p><p>The reliability problem compounds this. When a PoP degrades, a certificate chain breaks, or a decryption policy change propagates incorrectly, the blast radius is broad. A user in Toronto connected through a Detroit PoP may find their location misidentified, their compliance posture incorrectly evaluated, and their sessions flagged for a border-crossing that never happened. Traffic shifts during failover can impact thousands of users at once. </p><blockquote><p><strong>Failure in this model is systemic, not local.</strong></p></blockquote><p>This is a pattern practitioners have seen before. Security architectures that create friction do not eliminate the behavior they are trying to govern. They push it into channels where security has even less visibility. As I covered in <strong><a href="https://www.resilientcyber.io/p/bringing-security-out-of-the-shadows">Bringing Security Out of the Shadows</a></strong>, this cycle has repeated with every major technology wave. Cloud, mobile, SaaS, and now AI. Security policies that default to blocking breed shadow usage, and shadow usage is always harder to secure than governed usage.</p><h2>The Visibility Gap</h2><p>Even when SASE works as designed, there is a structural limit to what network-layer inspection can see.</p><p>A network proxy can tell you that a file was uploaded. It cannot tell you what was copied into an AI prompt, pasted into a web form, or moved between SaaS tenants before submission. It can see destinations and payloads when decryption is possible. It cannot capture what a user actually did inside an application.</p><p>This gap matters because the most common ways sensitive data leaves an organization today do not look like network incidents. A freelancer copies customer data from a CRM and pastes it into an LLM. An analyst downloads a financial model and uploads it to personal cloud storage. A developer pushes proprietary code through an AI assistant to accelerate a sprint. None of these actions generate anomalous traffic patterns or trigger firewall alerts. They occur at the presentation layer, inside the application, at the moment of user interaction, as work is being created and used.</p><p>Even more so, they are increasingly occurring via autonomous agents, which have the ability to call tools and take actions in the enterprise, often with users identities, never appearing anomalous or unauthorized on the surface.</p><p>Modern encryption is making this gap worse, not better. TLS 1.3 reduces available metadata. Certificate pinning makes decryption impossible for a growing number of applications. Post-quantum cryptographic implementations are already deployed in major browsers, and they are structurally incompatible with break-and-inspect architectures. Organizations are left with a choice that should not exist. Block traffic you cannot decrypt, or accept the blind spot and allow it. Most choose the blind spot, and the bypass lists grow.</p><p>Every application added to a bypass list to preserve compatibility is an application outside the security perimeter. </p><blockquote><p><strong>An architecture that requires exemptions to function is not enforcing policy, it is avoiding it.</strong></p></blockquote><h2>AI Did Not Break SASE But It Does Expose a Gap</h2><p>AI did not create the architectural mismatch with traditional SASE, but it made the mismatch impossible to ignore.</p><p>Modern AI workflows are fundamentally non-linear. Employees paste sensitive internal data into prompts. AI agents call external tools, access internal documentation, and move generated output downstream at machine speed. That output flows into reports, code repositories, and customer communications. An organization&#8217;s agent workforce will soon operate using employees&#8217; roles and access at 100 times human scale.</p><p>All of these interactions happen at the presentation layer, inside the application context, before any new network connection is established. By the time traffic reaches the network, the moment of intent has already passed. A network proxy sees the session but cannot see what is happening inside it.</p><p>Traditional SASE vendors respond with the only option their architecture permits. Block AI or allow it. Organizations that block AI push usage into personal, unmanaged tools, fueling shadow AI and expanding the attack surface they were trying to reduce. Organizations that allow AI without context accept data leakage, compliance exposure, and zero accountability for what employees send and receive. Neither approach is ideal or acceptable.</p><p>IBM&#8217;s 2025 Cost of a Data Breach Report found that 63% of organizations lack AI governance policies. Twenty percent of organizations surveyed experienced a breach due to shadow AI, adding $200,000 to $670,000 in costs compared to incidents without shadow AI involvement. The binary enforcement model is not just architecturally limited, it is actively producing the outcomes security teams are trying to prevent.</p><p>Leading analysts expects AI security capabilities, including prompt inspection and application controls, to become a key factor in SASE platform decisions over the next two years. Most current vendors stop at basic visibility or binary block controls. The architecture often simply does not support anything more.</p><h2>The Shelfware Problem Is Structural</h2><p>There is a pattern practitioners will recognize from their own environments. SASE licenses are purchased at scale then deployments stall, features are enabled but never fully tuned and exception lists accumulate. Multiple service chains and overlapping policies across SWG, CASB, and ZTNA create troubleshooting complexity that compounds over time and unsurprisingly, rollouts stretch from weeks to months.</p><p>Organizations end up running fragmented SASE stacks with multiple consoles and policy engines operating in parallel. Enforcement looks complete on dashboards while gaps persist in practice.</p><p>This is not a failure of organizational discipline and instead is a predictable consequence of architectures that require mandatory backhauling and extensive configuration before delivering meaningful coverage. When the deployment path is that long and complex, partial deployment becomes the norm rather than the exception. </p><p>The shelf-ware problem is structural, not operational, but it does have operational impacts as deployments stall, visibility is limited, the shelf-ware becomes part of the attack surface and concurrently eats away finite security budgets.</p><h2>What Changes When Enforcement Moves to the Last Mile</h2><p>If the risk lives at the presentation layer, in the actions users or agents take inside applications, at the moment data is created, copied, uploaded, or sent, then enforcement has to live there too. Not in a distant PoP after the moment of intent has passed, but at the point of work, before the data ever leaves the endpoint.</p><p>This is the architectural shift that separates the next generation of SASE from the current one. Moving enforcement to the last mile changes three outcomes simultaneously.</p><p>Security gets stronger because the visibility gap closes. Copy-paste actions, prompt content, tenant context, and output destinations all become visible. Enforcement is based on what users actually do, not inferred from packet metadata. Zero Trust is applied at the application layer per user/agent, per session, per action, and because modern protocols are supported natively, organizations do not need bypass lists to keep critical applications functioning, every session is governed.</p><p>User experience improves because most sessions go direct, and as we discussed when user experience improves, security doesn&#8217;t get undermined. There is no mandatory detour through a distant proxy, no forced TLS inspection degrading application performance, no latency from routing traffic through inspection points. Applications behave the way they were designed to behave. Users stop finding workarounds because they do not need them. </p><blockquote><p><strong>When security stops creating friction, adoption of sanctioned tools increases and IT spends less time managing exceptions.</strong></p></blockquote><p>Operations simplify because policy is defined once and enforced consistently. One policy engine. One audit trail. No service chaining across separate consoles. No overlapping rule sets between SWG, CASB, and ZTNA producing inconsistent outcomes. Deployments that used to take months compress to days.</p><h2>How <a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a> Approaches This</h2><p>To provide a concrete example, I wanted to use Resilient Cyber&#8217;s Partner <strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong>. </p><p>Island&#8217;s approach starts from a simple architectural insight, which is that enforcement should happen locally, as close to the action as possible, whether that action is in a browser, a desktop application, or an agentic AI workflow.</p><p>As I covered in <a href="https://www.resilientcyber.io/p/the-rise-of-the-enterprise-browser">The Rise of the Enterprise Browser</a>, the enterprise browser represents a Secure-by-Design paradigm shift from bolt-on products focused on the endpoint or network. </p><p><strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong> enables organizations to say yes rather than no, allowing personal email, personal AI usage, and contractor access within governed boundaries rather than blocking everything and hoping shadow usage does not follow, but the enforcement story extends well beyond the browser.</p><p><strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong> Desktop performs local-first enforcement directly on the endpoint, governing agentic actions, MCP and tool calls, and data and file movements at the device level before anything leaves the machine. </p><p>This is not just a traffic steering mechanism that routes sessions to a cloud network for inspection, although it does that where policy requires it. The endpoint itself is the enforcement point. For desktop applications and non-web traffic, <strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong> Desktop applies policy locally and steers traffic selectively to Island&#8217;s global network only when deeper analysis or routing adds genuine value. </p><blockquote><p><strong>Backhaul becomes the fallback, not the default</strong>.</p></blockquote><p><strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong> Desktop also facilitates Zero Trust Network Access (ZTNA), which allows users to connect directly to private applications and resources, including private MCP servers. For organizations deploying agentic AI architectures that rely on internal tool registries and private MCP infrastructure, this is a meaningful capability. Agents can reach internal resources through governed channels without exposing those resources to the public internet or requiring traditional VPN tunnels.</p><p>For browser-based work, policy is applied natively inside Chromium at the DOM layer before content renders and before data leaves the session. No traffic rerouting, no TLS interception, and no break-and-inspect. Island also provides a browser MCP server that allows AI agents to access web pages through <strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong>, but everything the agent does over that MCP server is governed by policy. </p><p>Sensitive data that policy blocks is not simply redacted into an unusable gap, it is replaced with a context placeholder, such as &lt;US SSN #&gt;, so the AI agent can still reason about the structure and meaning of the content without ever seeing the actual sensitive value. That distinction matters because outright blocking breaks agent workflows, while context-aware redaction preserves utility within policy boundaries, and avoids perpetuating the reputation of &#8220;<em>security is a blocker</em>&#8221;.</p><p><strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong> calls this &#8220;<em>the Perfect Packet</em>.&#8221; For every session, the most efficient and secure path is chosen based on policy. In most cases, enforcement runs locally, whether on the endpoint through Island Desktop or in the browser through DOM-level controls, and the packet goes direct. Cloud inspection is invoked only when deeper analysis or routing adds genuine value.</p><div><hr></div><p>For a deeper dive on the concept, grab a free guide &#8220;<strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">The Perfect Packet: A Guide to Modern SASE Architecture</a></strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kkjd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif 424w, https://substackcdn.com/image/fetch/$s_!kkjd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif 848w, https://substackcdn.com/image/fetch/$s_!kkjd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif 1272w, https://substackcdn.com/image/fetch/$s_!kkjd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kkjd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif" width="608" height="356.94716242661445" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1022,&quot;resizeWidth&quot;:608,&quot;bytes&quot;:16534,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/avif&quot;,&quot;href&quot;:&quot;https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203716524?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kkjd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif 424w, https://substackcdn.com/image/fetch/$s_!kkjd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif 848w, https://substackcdn.com/image/fetch/$s_!kkjd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif 1272w, https://substackcdn.com/image/fetch/$s_!kkjd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8ba56f7-ab4b-4902-9cbc-7b7b14899bdc_1022x600.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network&quot;,&quot;text&quot;:&quot;-> Grab the Guide! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network"><span>-&gt; Grab the Guide! &lt;-</span></a></p><div><hr></div><p>The full SASE capability set runs through a single platform. Zero Trust network access, secure web gateway, DLP, CASB, AI governance, remote browser isolation, and digital experience monitoring are all unified under one policy engine and one audit trail. There is no service chaining, no policy re-evaluation at different enforcement points, and no need to route traffic to a separate service for inspection.</p><p>On AI governance specifically, <strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong> governs AI at the point of interaction, whether that interaction happens in a browser, a desktop application, or an agentic workflow on the endpoint. </p><p>Content-aware detection inspects prompts and uploads in real time. Data boundaries define which AI tools, tenants, and workflows are approved for organizational use. Tool calls, MCP access, and agent-to-agent communication are governed and logged, with enforcement applied locally rather than requiring a round trip to a cloud inspection point. </p><blockquote><p><strong>The result is AI access that works within policy, without block pages, without shadow AI, and without forcing a choice between productivity and protection, which is where security tends to introduce the most friction.</strong></p></blockquote><p>The deployment model matters as much as the architecture. </p><p><strong><a href="https://www.island.io/network/modern-sase-guide?utm_medium=paid_media&amp;utm_source=influencer&amp;utm_campaign=influencer26_resilientcyber_sase&amp;utm_content=network">Island</a></strong> offers a phased approach that starts with an extension on existing Chrome or Edge browsers, requiring no network changes, no agent deployment, and no browser migration, but policy enforcement starts immediately. </p><p>Organizations can then move to the full enterprise browser for DOM-level enforcement, add Island Desktop for endpoint-level and agentic AI governance, and extend to the global multi-cloud network for environments that need centralized inspection, with each phase delivering standalone value from day one.</p><p>This is important because, as discussed above, the most predictable SASE failure mode is not a security breach. It is a deployment that never gets completed. An architecture that delivers value incrementally from the first day of deployment is fundamentally different from one that requires months of configuration before meaningful coverage begins.</p><p>This is a modular type of approach I wish more security vendors would take, to ensure we avoid shelf-ware and instead capitalize on security spend to truly reduce organizational risks.</p><h2>The Question Practitioners Should Be Asking</h2><p>There&#8217;s no question that SASE as a concept is valuable. The converged model that SASE represents, bringing networking and security together regardless of where users sit, remains the right strategic direction. However, organizations do need to ask if the execution model their current architecture depends on can actually deliver on that promise given how work happens today.</p><p>If your bypass lists are growing, if your users are finding workarounds, if your AI governance strategy amounts to allow or block at the domain level, if your deployment is still incomplete months or years after purchase, those are not operational problems to be solved with more configuration. They are architectural signals that the enforcement model needs to change.</p><p>The practitioners who will navigate this well are the ones who ask the uncomfortable questions about what their current stack is actually delivering versus what the dashboard says it is delivering. The gap between those two things is where the real risk lives but it requires us being honest about shortcomings rather than glossing over them.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #105]]></title><description><![CDATA[China Explores Restricting AI Access, LLMs Extracting EDR Detection Rule, C2-less AI Malware, A CVSS for AI Jailbreaks, Vulnerability Clearinghouses & A New CVE Every 7.4 Minutes]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-105</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-105</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 09 Jul 2026 13:53:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YUAh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #105 of the Resilient Cyber Newsletter! </p><p>This week the question changed. We have spent months debating whether AI will eventually become a serious offensive tool, It&#8217;s hard to argue that it isn&#8217;t, as this week Wiz published a blog of an autonomous AI agent discovering and fully exploiting a critical authorization flaw in a live airline&#8217;s booking API, start to finish, in fifteen minutes flat. </p><p>SpecterOps demonstrated that LLMs can systematically extract every YARA rule, behavioral detection, and ML model from a production EDR product, and Dreadnode showed that C2-less, fully autonomous malware can run entirely on AI models already shipping with Windows. </p><p>The offensive AI future arrived while we were still writing governance frameworks for it.</p><p>Meanwhile, a parallel debate about who gets to benefit from AI-powered vulnerability discovery is playing out in real time. </p><p>Four separate open-source vulnerability clearinghouses launched in five weeks, and James Berthoty&#8217;s piece on the privatization of vulnerability management asks the hard question nobody else is willing to ask. </p><p>If AI-discovered patches get privatized while AI-discovered exploits get democratized, who wins? </p><p>I explored a related angle in my piece this week on whether we need a CVSS for AI jailbreaks (more on that in the AI section below), and I also published a deep dive on <strong><a href="https://www.resilientcyber.io/p/cloud-security-and-secops-cant-afford">cloud security and SecOps convergence</a></strong> and a discussion with Tenable&#8217;s CPO on <strong><a href="https://www.resilientcyber.io/p/exposure-management-in-the-age-of">exposure management in the age of AI</a> </strong>if you want to go deeper on those fronts.</p><p>Let&#8217;s get into it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YUAh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YUAh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png 424w, https://substackcdn.com/image/fetch/$s_!YUAh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png 848w, https://substackcdn.com/image/fetch/$s_!YUAh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png 1272w, https://substackcdn.com/image/fetch/$s_!YUAh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YUAh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png" width="1211" height="736" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:736,&quot;width&quot;:1211,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:653416,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YUAh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png 424w, https://substackcdn.com/image/fetch/$s_!YUAh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png 848w, https://substackcdn.com/image/fetch/$s_!YUAh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png 1272w, https://substackcdn.com/image/fetch/$s_!YUAh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4513edcf-29b3-4881-becd-aa5d23a117f7_1211x736.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><h3><strong><a href="https://plutonium.pluto.security/?utm_source=email&amp;utm_medium=newsletter&amp;utm_campaign=Resilient">Dark matter hides in your AI supply chain. Plutonium finds it.</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://plutonium.pluto.security/?utm_source=email&amp;utm_medium=newsletter&amp;utm_campaign=Resilient" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S-Qx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg 424w, https://substackcdn.com/image/fetch/$s_!S-Qx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg 848w, https://substackcdn.com/image/fetch/$s_!S-Qx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!S-Qx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S-Qx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg" width="664" height="370.7637362637363" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:664,&quot;bytes&quot;:213974,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://plutonium.pluto.security/?utm_source=email&amp;utm_medium=newsletter&amp;utm_campaign=Resilient&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S-Qx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg 424w, https://substackcdn.com/image/fetch/$s_!S-Qx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg 848w, https://substackcdn.com/image/fetch/$s_!S-Qx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!S-Qx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4be37f1a-2f5e-4046-8255-655368e78cc5_2048x1143.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>New skills, plugins, connectors, and MCP servers extend Claude, Copilot, and the wider AI supply chain every week. Most of what they can actually do stays invisible, dark matter in the stack, until something goes wrong.</p><p>That&#8217;s the idea behind <strong><a href="https://plutonium.pluto.security/?utm_source=email&amp;utm_medium=newsletter&amp;utm_campaign=Resilient">Plutonium, Pluto Security&#8217;s free hub for the AI ecosystem</a></strong>. It pairs risk-assessment catalogs, covering every connector, skill, plugin, and MCP server across the entire AI supply chain, with Market Space, a curated set already checked safe to install.</p><p>Check any tool yourself before you approve it.</p><p>Security teams who want that same view across every employee and every tool already in use can see it live with Pluto, and bring the invisible risks into the light.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://plutonium.pluto.security/?utm_source=email&amp;utm_medium=newsletter&amp;utm_campaign=Resilient&quot;,&quot;text&quot;:&quot;-> Free Hub For the AI Ecosystem! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://plutonium.pluto.security/?utm_source=email&amp;utm_medium=newsletter&amp;utm_campaign=Resilient"><span>-&gt; Free Hub For the AI Ecosystem! &lt;-</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.reuters.com/legal/litigation/us-department-homeland-security-says-it-is-probing-cyber-breach-information-2026-07-02">DHS Investigates Cyber Breach at Homeland Security Information Network</a></h3><p>A breach of the Homeland Security Information Network, the unclassified system used to share sensitive information with foreign law enforcement and local authorities, is exactly the kind of incident that erodes trust in government cyber coordination. </p><p>The breach reportedly occurred between late May and early June 2026, and Senator Mark Warner called the exposed information &#8220;highly sensitive&#8221; with national security implications. DHS has provided minimal details, which is not unusual for an active investigation but is frustrating given that HSIN is the backbone of cross-agency threat sharing. </p><p>Coming just weeks after the Mythos classified systems testing I covered in issue #104, this is another reminder that the government&#8217;s own infrastructure faces the same vulnerabilities it is asking the private sector to fix.</p><h3><a href="https://www.reuters.com/world/beijing-is-looking-curbing-overseas-access-chinas-top-ai-models-sources-say-2026-07-07/">Beijing Moves to Restrict Overseas Access to China&#8217;s Top AI Models</a></h3><p>The symmetry here is hard to miss. </p><p>Three weeks after the U.S. briefly pulled Fable 5 from the market via export controls, Beijing is now considering the same approach for its own frontier models. Reuters reports that Chinese authorities have been meeting with Alibaba, ByteDance, and Z.ai about restricting overseas access to advanced AI models, including unreleased ones. </p><p>The proposed tiered system would require simple filing for basic open-source tools, security reviews for more advanced technology, and outright restrictions on frontier models. </p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Maxime Labonne&quot;,&quot;id&quot;:31453795,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e73529-4d58-4477-b896-6d1e1f5c9796_896x896.png&quot;,&quot;uuid&quot;:&quot;09e38a88-48e5-41f1-9220-d72180e86faf&quot;}" data-component-name="MentionToDOM"></span> <a href="https://maximelabonne.substack.com/p/the-state-of-the-open-frontier">analysis of the open frontier</a> adds critical context. Six of the seven strongest open-weight models are now Chinese, with GLM-5.2 leading the pack as the first frontier model trained entirely off Nvidia silicon on Huawei Ascend chips. </p><p>Both superpowers are now treating cutting-edge AI as a national asset, and the window where open-weight models could flow freely across borders is closing from both directions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1YPT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1YPT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png 424w, https://substackcdn.com/image/fetch/$s_!1YPT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png 848w, https://substackcdn.com/image/fetch/$s_!1YPT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png 1272w, https://substackcdn.com/image/fetch/$s_!1YPT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1YPT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png" width="579" height="415.7259343148358" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f679ff48-3b17-42d9-b803-af13282792c7_883x634.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:634,&quot;width&quot;:883,&quot;resizeWidth&quot;:579,&quot;bytes&quot;:94446,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!1YPT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png 424w, https://substackcdn.com/image/fetch/$s_!1YPT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png 848w, https://substackcdn.com/image/fetch/$s_!1YPT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png 1272w, https://substackcdn.com/image/fetch/$s_!1YPT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff679ff48-3b17-42d9-b803-af13282792c7_883x634.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://www.keyfactor.com/press-releases/keyfactor-announces-1b-strategic-growth-investment-led-by-summit-partners-to-expand-leadership-in-securing-the-ai-and-post-quantum-enterprise/">Keyfactor Secures $1B+ Strategic Growth Investment from Summit Partners</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y7tf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y7tf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png 424w, https://substackcdn.com/image/fetch/$s_!Y7tf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png 848w, https://substackcdn.com/image/fetch/$s_!Y7tf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png 1272w, https://substackcdn.com/image/fetch/$s_!Y7tf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y7tf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png" width="827" height="207" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:207,&quot;width&quot;:827,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64065,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y7tf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png 424w, https://substackcdn.com/image/fetch/$s_!Y7tf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png 848w, https://substackcdn.com/image/fetch/$s_!Y7tf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png 1272w, https://substackcdn.com/image/fetch/$s_!Y7tf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae64fd43-5dd8-4f6d-96e0-8022909205f5_827x207.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>A billion-dollar growth investment in machine identity and post-quantum cryptography signals where institutional money sees the next critical infrastructure layer. </p><p>Keyfactor currently manages billions of machine identities across 2,500+ customers, including half the largest U.S. and EU banks and over 40% of the Fortune 100. The timing tracks with the White House&#8217;s June 2026 executive orders accelerating PQC transition ahead of 2030 and the JPMorgan data from last week showing NHIs outnumbering human identities 144-to-1. </p><p>I have been saying for a while that identity is key context, especially for securing the era of Agentic AI. A billion-dollar bet from Summit Partners suggests the private equity market agrees.</p><h3><a href="https://www.wsj.com/pro/cybersecurity/cyber-insurers-focus-on-speed-as-ai-rewrites-security-0983ad61">Cyber Insurers Now Pricing Remediation Speed Into Underwriting Policies</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ijse!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ijse!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png 424w, https://substackcdn.com/image/fetch/$s_!Ijse!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png 848w, https://substackcdn.com/image/fetch/$s_!Ijse!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png 1272w, https://substackcdn.com/image/fetch/$s_!Ijse!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ijse!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png" width="630" height="146" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d374509f-fc35-4594-8567-d13be6d87ae3_630x146.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:146,&quot;width&quot;:630,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:25725,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ijse!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png 424w, https://substackcdn.com/image/fetch/$s_!Ijse!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png 848w, https://substackcdn.com/image/fetch/$s_!Ijse!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png 1272w, https://substackcdn.com/image/fetch/$s_!Ijse!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd374509f-fc35-4594-8567-d13be6d87ae3_630x146.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Insurance underwriters are shifting from asking &#8220;do you have vulnerabilities?&#8221; to &#8220;how fast do you fix them?&#8221; and I think this is exactly the right question. </p><p>Vulnerability exploitation has become the leading initial access vector at 31% of breaches (up from 20%) per Verizon&#8217;s 2026 DBIR. The median time to fully resolve a critical vulnerability is 43 days, while the mean time-to-exploit is negative 7 days, meaning attackers are weaponizing flaws before the patch ships. </p><p>Organizations using AI agents for remediation report 6x faster CVE remediation and 83% fewer blocked pull requests. When insurance companies start pricing operational tempo, security leaders finally get a financial argument for the tooling investments they have been requesting.</p><h3><a href="https://www.theregister.com/ai-and-ml/2026/07/06/even-banks-and-hyperscalers-are-now-sounding-the-alarm-about-the-ai-bubble/5266123">Bank for International Settlements Warns AI Investment Bubble Risks Global Economy</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T5jM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T5jM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png 424w, https://substackcdn.com/image/fetch/$s_!T5jM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png 848w, https://substackcdn.com/image/fetch/$s_!T5jM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png 1272w, https://substackcdn.com/image/fetch/$s_!T5jM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T5jM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png" width="1192" height="176" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:176,&quot;width&quot;:1192,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:41196,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T5jM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png 424w, https://substackcdn.com/image/fetch/$s_!T5jM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png 848w, https://substackcdn.com/image/fetch/$s_!T5jM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png 1272w, https://substackcdn.com/image/fetch/$s_!T5jM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd1b6335-dbc7-4595-a3cd-00b4660ba961_1192x176.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>When the central bank for central banks starts warning about an investment bubble, it is worth paying attention. </p><p>The BIS report notes that AI is attracting far more capital than the resulting industry can produce in returns, a pattern it has seen before. Oracle has lost more than 40% of its share value in the past month. Hyperscalers keep pouring money into GPU infrastructure while creating RAM shortages that affect even consumer hardware purchases. </p><p>I remain cautiously optimistic about AI&#8217;s long-term value for security, but the spending trajectory I covered in prior issues is clearly unsustainable. The correction will not eliminate AI adoption but it will force a reckoning about which use cases actually justify the cost.</p><h3><a href="https://www.bloomberg.com/news/articles/2026-06-26/ai-anxiety-is-fueling-burnout-across-silicon-valley-s-tech-workers">Bloomberg Reports AI Anxiety Fueling Burnout Across Silicon Valley</a></h3><p>One entrepreneur quoted in the piece captured something I have been hearing from practitioners across the industry. AI agents were supposed to do his work for him, but he has &#8220;never worked harder&#8221; while producing roughly 100x more output than before. This is often referred to as the AI Vampire.</p><p>Tech career coach Kyle Elliott says 2026 has been his busiest year as workers prepare for AI-driven layoffs or escape burnout. The pattern is paradoxical but predictable. AI eliminates routine tasks, bosses demand more strategic work, and mental downtime disappears entirely. </p><p>For security teams already dealing with alert fatigue and staffing shortages, adding AI-driven productivity pressure on top of existing stressors is a recipe for attrition.</p><h3><a href="https://newsletter.pragmaticengineer.com/p/impressions-from-visiting-openai">Pragmatic Engineer Reports Cloud Agents Going Mainstream at OpenAI, Anthropic, and Cursor</a></h3><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Gergely Orosz&quot;,&quot;id&quot;:30107029,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/58fed27c-f331-4ff3-ba47-135c5a0be0ba_400x400.png&quot;,&quot;uuid&quot;:&quot;57687cf7-b62d-4a29-a54b-360daed4c25f&quot;}" data-component-name="MentionToDOM"></span> visited the offices of OpenAI, Anthropic, and Cursor and reports that all three are investing heavily in cloud-based AI agent execution. </p><p>OpenAI acquired Ona (formerly Gitpod) for cloud dev environments. Anthropic built Claude Managed Agents over six months. Cursor launched cloud agents and an iOS mobile app. The most striking data point was that more than 95% of non-engineers at OpenAI now use Codex rather than ChatGPT, suggesting that AI coding tools are becoming the default interface even for people who do not write code. </p><p>The implications for shadow AI in enterprises are significant, and security teams should be planning for a world where every employee has access to a cloud-based code execution environment.</p><h3><a href="https://open.substack.com/pub/europeanstraits/p/the-beginning-of-the-end-for-big">Nicolas Colin Argues This Is the Beginning of the End for &#8220;Big AI&#8221;</a></h3><p>Vsquared Ventures&#8217; head of research <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Nicolas Colin&quot;,&quot;id&quot;:1239118,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c66fe911-193f-4769-963a-ea8690c567d3_3208x3208.png&quot;,&quot;uuid&quot;:&quot;c209b850-8a5d-4f5f-bb3f-fcc4130f965a&quot;}" data-component-name="MentionToDOM"></span> reacts to Palantir CEO Alex Karp&#8217;s critique of frontier model companies and makes a provocative case. For context, this is the video from Alex Karp that made a ton of waves this week:</p><div id="youtube2-APv82m-N5QM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;APv82m-N5QM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/APv82m-N5QM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>If a local model running on your own data solves 95% of the problem at a fraction of the cost, the economics of paying for opaque tokens and uploading proprietary data to frontier labs stop making sense. </p><p>Chinese open-source models have become &#8220;astonishingly good&#8221; and frontier labs are still burning cash at industrial scale. Colin compares frontier AI to supersonic airliners, impressive until the economics kill them. His most interesting prediction is that Anthropic could survive as &#8220;a next-generation Google&#8221; with Claude Code as its AdWords-equivalent cash engine, while OpenAI faces a trickier path. </p><p>Whether or not you buy the full thesis, the direction of travel, more capable open models and tightening enterprise budgets, is real.</p><h3><a href="https://abnormal.ai/blog/abnormal-response-to-anthropic-lawsuit">Anthropic Sues Abnormal AI Over Logo Similarity in Trademark Dispute</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UATG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UATG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png 424w, https://substackcdn.com/image/fetch/$s_!UATG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png 848w, https://substackcdn.com/image/fetch/$s_!UATG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png 1272w, https://substackcdn.com/image/fetch/$s_!UATG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UATG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png" width="633" height="252.01997336884153" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:299,&quot;width&quot;:751,&quot;resizeWidth&quot;:633,&quot;bytes&quot;:79749,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UATG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png 424w, https://substackcdn.com/image/fetch/$s_!UATG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png 848w, https://substackcdn.com/image/fetch/$s_!UATG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png 1272w, https://substackcdn.com/image/fetch/$s_!UATG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8a5c660-e859-4971-9bcd-ea006fc5f487_751x299.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Of all the stories I expected to cover this week, Anthropic suing one of its customers was not one of them. </p><p>Abnormal AI&#8217;s CEO Evan Reiser points out that Abnormal was founded in 2018 (three years before Anthropic), the disputed logo was designed in April 2021, and Anthropic does not hold a registered trademark covering cybersecurity products. Reiser notes that his personal account will spend roughly $1M on Anthropic products this year, with the company spending over $10M. He emphasizes that Abnormal does not use Claude for customer-facing security features, only as an internal productivity tool. </p><p>The lawsuit demands &#8220;disgorgement of all revenues, earnings, profits, compensation, and benefits,&#8221; which seems remarkably aggressive given the facts. Whatever the legal merits, suing your own paying customers is rarely a winning business strategy.</p><div><hr></div><h1>AI</h1><h3><a href="https://www.wiz.io/blog/red-agent-pov-bola">Wiz&#8217;s Red Agent Autonomously Exploits Critical BOLA Vulnerability in Live Airline API in 15 Minutes</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l9Z8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l9Z8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png 424w, https://substackcdn.com/image/fetch/$s_!l9Z8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png 848w, https://substackcdn.com/image/fetch/$s_!l9Z8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png 1272w, https://substackcdn.com/image/fetch/$s_!l9Z8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l9Z8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png" width="560" height="312.7065527065527" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d65f43f6-c347-4058-aaff-421225f64b6d_702x392.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:392,&quot;width&quot;:702,&quot;resizeWidth&quot;:560,&quot;bytes&quot;:215267,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!l9Z8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png 424w, https://substackcdn.com/image/fetch/$s_!l9Z8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png 848w, https://substackcdn.com/image/fetch/$s_!l9Z8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png 1272w, https://substackcdn.com/image/fetch/$s_!l9Z8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd65f43f6-c347-4058-aaff-421225f64b6d_702x392.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the story that should change how you think about AI-powered offense. </p><p>With zero prior knowledge of the target, Wiz&#8217;s autonomous Red Agent discovered and fully exploited a Broken Object-Level Authorization flaw in a real airline&#8217;s GraphQL booking API in fifteen minutes flat. </p><p>The agent minted an anonymous session token by analyzing client-side JavaScript, performed GraphQL introspection revealing 514 queries and 428 mutations available to that anonymous session, then enumerated sequential booking IDs to extract two years of passenger records including names, dates of birth, billing addresses, and masked credit cards. </p><p>The anonymous session also had write capabilities including deleting flights, overriding prices, and issuing refunds. No human guided any step. This is not a CTF challenge or a research demo. </p><p>This is an AI agent autonomously executing a complete attack chain against production infrastructure protecting real customer data, and it found a vulnerability class that traditional DAST scanners are blind to.</p><h3><a href="https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/">SpecterOps Demonstrates LLMs Can Systematically Extract All EDR Detection Rules</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mowt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mowt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png 424w, https://substackcdn.com/image/fetch/$s_!Mowt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png 848w, https://substackcdn.com/image/fetch/$s_!Mowt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png 1272w, https://substackcdn.com/image/fetch/$s_!Mowt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mowt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png" width="620" height="194" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:194,&quot;width&quot;:620,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31461,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mowt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png 424w, https://substackcdn.com/image/fetch/$s_!Mowt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png 848w, https://substackcdn.com/image/fetch/$s_!Mowt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png 1272w, https://substackcdn.com/image/fetch/$s_!Mowt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648aaf56-0e3d-4944-97d7-4ee10b5be5f5_620x194.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>If the Wiz story shows AI-powered offense in action, this one shows the defensive scaffolding being dismantled. </p><p>Adam Chester at SpecterOps used GPT-5.5-Cyber in a simple while-loop harness connected to Binary Ninja via MCP, a setup they call &#8220;Day Shift,&#8221; and fully dissected Palo Alto Cortex XDR. </p><p>The LLM extracted 6,358 encrypted YARA rules (cracking AES-128-ECB with keys embedded in the binary), discovered 9,350 DSE rules and 4,209 BIOC behavioral detection rules, pulled out 7 ML models with their decision thresholds, and even decrypted CLIPS-based rule blobs. </p><p>One extracted rule revealed that &#8220;reg save HKLM\SAM&#8221; to a specific path was explicitly allowlisted and would bypass detection entirely. SpecterOps confirms they have done this internally against every major EDR vendor with similar results. </p><p>The defense-in-depth argument I keep making just got a lot more urgent. EDR remains essential, but anyone treating it as their primary defensive layer is building on sand.</p><h3><a href="https://0din.ai/blog/stealing-environment-keys-from-cursor-ide-with-a-malicious-readme">Cursor IDE Environment Keys Stolen via Malicious README Prompt Injection</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UIOv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UIOv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png 424w, https://substackcdn.com/image/fetch/$s_!UIOv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png 848w, https://substackcdn.com/image/fetch/$s_!UIOv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png 1272w, https://substackcdn.com/image/fetch/$s_!UIOv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UIOv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png" width="1312" height="355" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:355,&quot;width&quot;:1312,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:62162,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UIOv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png 424w, https://substackcdn.com/image/fetch/$s_!UIOv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png 848w, https://substackcdn.com/image/fetch/$s_!UIOv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png 1272w, https://substackcdn.com/image/fetch/$s_!UIOv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ef11ba3-f0c6-4f24-8048-bca69e0697a5_1312x355.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Mozilla&#8217;s 0DIN team demonstrated a prompt injection attack where a malicious GitHub README tricks Cursor&#8217;s LLM agent into dumping environment variables and exfiltrating API keys via browser GET requests to an attacker-controlled server. </p><p>The attack exploits what the researchers call the &#8220;lethal trifecta&#8221; in agentic tools, specifically access to private data, exposure to untrusted content, and ability to communicate externally. </p><p>Cursor&#8217;s permission model is bypassed because users routinely allowlist &#8220;powershell -c&#8221; to avoid constant prompts, and Cursor only validates the beginning of the command string. </p><p>Last week I covered two Claude Code vulnerabilities with similar trust-model failures, and the pattern is consistent across every AI coding tool I have examined. </p><p>Agent frameworks that combine broad system access with exposure to untrusted repository content and the ability to make external network calls are structurally vulnerable to exfiltration, and permission fatigue makes the theoretical safeguards functionally useless.</p><h3><a href="https://dreadnode.io/research/lolmil-living-off-the-land-models-and-inference-libraries/">Dreadnode Demonstrates C2-less AI Malware Running on Models Already Shipping with Windows</a></h3><p>This research should be on every threat intelligence team&#8217;s reading list. </p><p>Max Harley at Dreadnode demonstrates that malware can eliminate command-and-control servers entirely by using AI models and inference libraries already present on the victim&#8217;s machine. </p><p>Microsoft CoPilot+ PCs ship with Phi-3 (3.8B parameters) and ONNX Runtime has shipped with Windows for a bit. The proof-of-concept used these locally available resources to autonomously discover a misconfigured Windows service and escalate privileges without ever contacting an external server. </p><p>Current limitations include CPU inference being slow and conspicuous, but as NPU-equipped machines become standard and local model quality improves, C2-less autonomous exploitation will become practical at scale. </p><p>Traditional network-based detection that depends on identifying C2 traffic will be completely blind to this class of attack.</p><h3><a href="https://www.aisi.gov.uk/blog/finding-cloud-misconfigurations-with-frontier-ai-a-case-study">UK AI Safety Institute Finds Real Cloud Misconfigurations Using Frontier AI for Under &#163;1,000</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MIuk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MIuk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png 424w, https://substackcdn.com/image/fetch/$s_!MIuk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png 848w, https://substackcdn.com/image/fetch/$s_!MIuk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png 1272w, https://substackcdn.com/image/fetch/$s_!MIuk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MIuk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png" width="960" height="281" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:281,&quot;width&quot;:960,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:143970,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MIuk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png 424w, https://substackcdn.com/image/fetch/$s_!MIuk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png 848w, https://substackcdn.com/image/fetch/$s_!MIuk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png 1272w, https://substackcdn.com/image/fetch/$s_!MIuk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd5e8539-e91d-45fa-90d9-f167269dfdda_960x281.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Instead of testing AI on benchmarks, the UK AISI pointed frontier models at their own AWS infrastructure and looked for real misconfigurations. </p><p>Over a two-week sprint using three methods (static source analysis, automated agentic probing, and human-in-the-loop red teaming), they found and fixed several real issues including a previously undiscovered multi-step attack chain requiring five independent steps that allowed user impersonation. </p><p>The total cost was under &#163;1,000 in LLM tokens, with the critical finding discovered for under &#163;150. One basic commercial alerting system failed to flag any of the automated agent activity, while a more advanced monitoring system did catch some aggressive behavior. </p><p>Every organization with a cloud footprint can afford to do this, there is no excuse left for not trying.</p><h3><a href="https://github.com/elder-plinius/T3MP3ST">T3MP3ST Framework Claims 90% Pass Rate on Offensive Security Benchmarks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WKdM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WKdM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png 424w, https://substackcdn.com/image/fetch/$s_!WKdM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png 848w, https://substackcdn.com/image/fetch/$s_!WKdM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png 1272w, https://substackcdn.com/image/fetch/$s_!WKdM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WKdM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png" width="788" height="392" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:392,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71263,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WKdM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png 424w, https://substackcdn.com/image/fetch/$s_!WKdM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png 848w, https://substackcdn.com/image/fetch/$s_!WKdM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png 1272w, https://substackcdn.com/image/fetch/$s_!WKdM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa472f4aa-b36f-4ec5-85d8-ca7a722f8532_788x392.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>An open-source multi-agent offensive security framework claiming 90.1% pass on XBOW&#8217;s 104-challenge black-box benchmark suite is worth watching carefully, if the numbers hold up. </p><p>T3MP3ST orchestrates specialist AI operators (recon, scanner, exploiter, infiltrator) to run the kill chain autonomously using local agent CLIs with zero API keys required. The emphasis on measurement integrity is notable, with every quantitative claim shipping with committed JSON artifacts that can be independently verified. The project also tested against post-training-cutoff 2026 CVEs to rule out memorization, scoring 4/10 strict. </p><p>Whether T3MP3ST itself becomes significant matters less than what it represents. The barrier to building autonomous offensive security harnesses has dropped to the point where a single developer can do it with open-source tooling.</p><h3><a href="https://www.irregular.com/research/frontiercyber">FrontierCyber Introduces Real-System Offensive Benchmark with Physical Devices</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Zci!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Zci!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png 424w, https://substackcdn.com/image/fetch/$s_!1Zci!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png 848w, https://substackcdn.com/image/fetch/$s_!1Zci!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png 1272w, https://substackcdn.com/image/fetch/$s_!1Zci!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Zci!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png" width="484" height="190" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce714922-698d-4fc5-824b-9918cc7fc573_484x190.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:190,&quot;width&quot;:484,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28590,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Zci!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png 424w, https://substackcdn.com/image/fetch/$s_!1Zci!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png 848w, https://substackcdn.com/image/fetch/$s_!1Zci!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png 1272w, https://substackcdn.com/image/fetch/$s_!1Zci!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce714922-698d-4fc5-824b-9918cc7fc573_484x190.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Most AI security benchmarks test against planted vulnerabilities in sandboxed environments with predefined exploit paths. </p><p>FrontierCyber tests against real systems with real defenses, no planted vulnerabilities, and no predefined attack routes. The benchmark spans physical mobile phones running real applications, production software (Pillow, lxml, FFmpeg, PostgreSQL, Redis), and full network environments. </p><p>Initial evaluations have already surfaced previously unknown vulnerabilities now in responsible disclosure, and one model built a novel multi-vulnerability chain against a mobile device to gain unauthorized access. This is the evaluation methodology the field has needed. </p><p>Benchmarks built on known vulnerabilities and documented exploit paths tell you how well a model follows instructions, not how well it discovers new attack surfaces.</p><h3><a href="https://addyo.substack.com/p/agentic-autonomy-levels">Addy Osmani Proposes Two-Axis Framework for Measuring AI Agent Autonomy</a></h3><p>The single-axis autonomy ladder most people use conflates two separate questions, how far an agent operates independently (agency) and how many agents you coordinate (orchestration), and <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Addy Osmani&quot;,&quot;id&quot;:11623675,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef4ea1b5-28cc-4a4f-ba1e-23d91db6570d_1190x1190.png&quot;,&quot;uuid&quot;:&quot;e1f9c1e1-cd45-4ac2-aafc-605b87184340&quot;}" data-component-name="MentionToDOM"></span>&#8217;s two-axis framework is a useful corrective. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4htg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4htg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png 424w, https://substackcdn.com/image/fetch/$s_!4htg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png 848w, https://substackcdn.com/image/fetch/$s_!4htg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png 1272w, https://substackcdn.com/image/fetch/$s_!4htg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4htg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png" width="635" height="464.38084112149534" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:626,&quot;width&quot;:856,&quot;resizeWidth&quot;:635,&quot;bytes&quot;:79813,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4htg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png 424w, https://substackcdn.com/image/fetch/$s_!4htg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png 848w, https://substackcdn.com/image/fetch/$s_!4htg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png 1272w, https://substackcdn.com/image/fetch/$s_!4htg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b444968-f590-4bbc-a735-d6f1e4a65796_856x626.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>His six levels run from L0 Assist (suggestions only) through L5 Managed-by-Exception (factory model with human review only on exceptions). </p><p>Analysis of roughly 400,000 Claude sessions from 235,000 users showed that people make about 70% of planning decisions while Claude handles about 80% of execution, and experienced users were more likely to auto-approve. </p><p>That auto-approval pattern is exactly the permission fatigue that the Cursor IDE vulnerability in this issue exploits. Four anti-patterns are worth memorizing, especially &#8220;Permission Laundering&#8221; where humans approve what they do not understand.</p><h3><a href="https://www.darkreading.com/cyber-risk/securing-ai-agents-rogue">Gartner Warns That Securing AI Agents Before They Go Rogue Is &#8220;Next to Impossible&#8221;</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wp5y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wp5y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png 424w, https://substackcdn.com/image/fetch/$s_!wp5y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png 848w, https://substackcdn.com/image/fetch/$s_!wp5y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png 1272w, https://substackcdn.com/image/fetch/$s_!wp5y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wp5y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png" width="1053" height="200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:200,&quot;width&quot;:1053,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:36635,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wp5y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png 424w, https://substackcdn.com/image/fetch/$s_!wp5y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png 848w, https://substackcdn.com/image/fetch/$s_!wp5y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png 1272w, https://substackcdn.com/image/fetch/$s_!wp5y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f3d2cd0-ffe6-42f2-b964-a59717436dbe_1053x200.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Dennis Xu at Gartner&#8217;s Security &amp; Risk Management Summit said what most vendors will not. </p><p>LLMs will &#8220;always&#8221; be susceptible to jailbreak and prompt injection, and no amount of guardrail spending provides 100% prevention. The Akeyless survey data is sobering at 84% of 400+ IT and security leaders saying AI agents can access sensitive data, with 67% believing agents have already accessed data they should not have. </p><p>Brian Murphy from ReliaQuest offered the most quotable line of the week. &#8220;I don&#8217;t worry about attackers poisoning an agent&#8217;s memory. I worry about the agent poisoning its own memory.&#8221; </p><p>The PocketOS incident they referenced, where an AI coding agent deleted a production database and all backups in 9 seconds, is the kind of operational risk that should make every CISO reconsider deployment velocity.</p><p>I had a chance to chat with Dennis in-person at the Gartner event, and I consider him one of the sharpest analysts covering the space of AI and Agent Security. </p><h3><a href="https://www.resilientcyber.io/p/do-we-need-a-cvss-for-ai-jailbreaks">Do We Need a CVSS for AI Jailbreaks?</a></h3><div id="youtube2-_ZCZwhXQk3I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;_ZCZwhXQk3I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/_ZCZwhXQk3I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>I published a deep dive this week examining Anthropic&#8217;s proposal for a consensus jailbreak severity framework, the one buried in the Fable 5 redeployment announcement I covered in issue #104. </p><p>The cybersecurity industry spent 20 years learning that severity alone (CVSS) is insufficient without exploitation context (EPSS), organizational context (SSVC), and real-world telemetry (KEV). The AI safety community is compressing that same realization into months. NIST scientist Apostol Vassilev published a peer-reviewed proof extending Godel&#8217;s incompleteness theorems to AI guardrail systems, formally proving that no finite set of guardrails can be universally effective. </p><p>OWASP&#8217;s parallel AIVSS effort (v0.8) has founding members from NIST, NSA, Google, Microsoft, Anthropic, AWS, and others. Jailbreaks are a permanent feature of AI systems, not a bug to be patched.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://pulse.latio.tech/p/the-privatization-of-vulnerability">James Berthoty Warns Vulnerability Management Is Being Privatized</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qwBg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qwBg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png 424w, https://substackcdn.com/image/fetch/$s_!qwBg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png 848w, https://substackcdn.com/image/fetch/$s_!qwBg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qwBg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qwBg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png" width="781" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:781,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:124558,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qwBg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png 424w, https://substackcdn.com/image/fetch/$s_!qwBg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png 848w, https://substackcdn.com/image/fetch/$s_!qwBg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qwBg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2a1c4d4-bb6a-4e99-bce9-553f76794fd1_781x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>There&#8217;s been a TON of vulnerability discussion this year, largely due to AI&#8217;s industrialization of vulnerability discovery the &#8220;Mythos Moment&#8221;, and general buzz.</p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;James Berthoty&quot;,&quot;id&quot;:215222117,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F029c069a-0ea1-4c28-bedb-742a03fa770a_800x800.jpeg&quot;,&quot;uuid&quot;:&quot;1bc461f6-2902-496c-985c-404e3e5ff80c&quot;}" data-component-name="MentionToDOM"></span> identifies privatization of VulnMgt across three dimensions. Detection, where frontier model access is gatekept to large enterprises. Investigation, where NVD enrichment is at its lowest point while commercial alternatives like Flashpoint, VulnCheck, and GitHub Security Advisories fill the gap, and Response, where the growth of vendor-hosted &#8220;supply chain firewalls&#8221; means patches increasingly flow through private channels before (or instead of) reaching the public. </p><p>Four separate clearinghouse initiatives launched in five weeks, and none give open-source maintainers real governance power. </p><p>James&#8217; warning is blunt, &#8220;Fixes get privatized, while attacker capabilities get democratized.&#8221; If the clearinghouse model consolidates around subscribers-first disclosure, the CVE system as we know it is going out with a whisper.</p><h3><a href="https://www.chainguard.dev/unchained/summer-of-clearinghouses">Dan Lorenc Explains Why the Clearinghouse Itself Is the Least Important Part</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!snEI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!snEI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png 424w, https://substackcdn.com/image/fetch/$s_!snEI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png 848w, https://substackcdn.com/image/fetch/$s_!snEI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png 1272w, https://substackcdn.com/image/fetch/$s_!snEI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!snEI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png" width="623" height="163" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:163,&quot;width&quot;:623,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:18792,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!snEI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png 424w, https://substackcdn.com/image/fetch/$s_!snEI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png 848w, https://substackcdn.com/image/fetch/$s_!snEI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png 1272w, https://substackcdn.com/image/fetch/$s_!snEI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e1b6e65-242f-4bc0-b902-5c7075889988_623x163.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Chainguard&#8217;s CEO offers the practitioner&#8217;s counterpoint to the privatization concern.</p><p>The clearinghouse is just data, and the real value is &#8220;actuation,&#8221; turning findings into rebuilt, tested, signed artifacts backported to the versions you actually run. Athena has taken in 20,000+ findings and shipped 2,000+ patches across 500 projects, and Chainguard&#8217;s existing build system already remediates well over 100,000 CVEs. CrowdStrike puts the stat at 42% of exploited vulnerabilities being hit before disclosure, which means the mean time-to-exploit is effectively negative. </p><p>Only a few large clearinghouses will survive, like root DNS servers or certificate authorities, and the long-term goal is secure-by-design making clearinghouses unnecessary. </p><p>That is exactly right but also probably years away and would require major changes in market and regulatory forces, which I&#8217;ve written about many times in terms of cybersecurity being a market failure.</p><h3><a href="https://tzafaar.codeberg.page/other/oss-security-initiatives-comparison.html">Detailed Comparison Reveals None of Four New OSS Security Initiatives Include Maintainer Governance</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V6mh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V6mh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png 424w, https://substackcdn.com/image/fetch/$s_!V6mh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png 848w, https://substackcdn.com/image/fetch/$s_!V6mh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png 1272w, https://substackcdn.com/image/fetch/$s_!V6mh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V6mh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png" width="851" height="252" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:252,&quot;width&quot;:851,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47174,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V6mh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png 424w, https://substackcdn.com/image/fetch/$s_!V6mh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png 848w, https://substackcdn.com/image/fetch/$s_!V6mh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png 1272w, https://substackcdn.com/image/fetch/$s_!V6mh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e3e21c1-13c8-4103-9a81-2c834ce46799_851x252.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A side-by-side analysis of Lightwell (IBM/Red Hat), Patch the Planet (OpenAI/Trail of Bits), Akrites (Linux Foundation), and Athena (Chainguard) reveals a striking gap across all four. </p><p>None give open-source maintainers real governance power, and none include any public body or national CSIRT. Two are &#8220;members-first&#8221; (Lightwell and Athena) where paying members get private hardened builds before public disclosure. Two are &#8220;equal&#8221; (Patch the Planet and Akrites) with single embargo windows. Lightwell is a $5B commercial subscription clearinghouse with 20,000+ engineers and 11 banks. Patch the Planet is free and non-profit, with 30+ projects and 51 significant findings plus 19 fixes in its first week. </p><p>I covered the Akrites launch in issue #104 as one of the most important announcements of the year, and this comparison adds necessary context about governance models. </p><p>The question is not whether these initiatives are valuable (they clearly are) but whether they protect the broader community or primarily serve paying members.</p><h3><a href="https://epoch.ai/data-insights/cve-severity-spike">Epoch AI Documents 3.5x Spike in High-Severity CVE Disclosures After Mythos Release</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F4Tx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F4Tx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png 424w, https://substackcdn.com/image/fetch/$s_!F4Tx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png 848w, https://substackcdn.com/image/fetch/$s_!F4Tx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png 1272w, https://substackcdn.com/image/fetch/$s_!F4Tx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F4Tx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png" width="571" height="481.78125" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:768,&quot;resizeWidth&quot;:571,&quot;bytes&quot;:93427,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F4Tx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png 424w, https://substackcdn.com/image/fetch/$s_!F4Tx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png 848w, https://substackcdn.com/image/fetch/$s_!F4Tx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png 1272w, https://substackcdn.com/image/fetch/$s_!F4Tx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc4a808c-eff6-4e54-b1e0-c9eb9d3971e3_768x648.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In June 2026, notable organizations published around 1,500 high- and critical-severity CVEs, more than 3.5x the pre-Mythos monthly record. </p><p>Luke Emberson at Epoch AI tracked 21 major organizations (Microsoft, Google, Apple, Adobe, Oracle, Cisco, and others) and found the spike follows directly from Anthropic&#8217;s April 2026 announcement that Claude Mythos Preview could autonomously discover software vulnerabilities. Project Glasswing partners had been using Mythos pre-release and claim over 10,000 high- or critical-severity discoveries. </p><p>The figures are from publicly disclosed vulnerabilities only, meaning the actual discovered count is much higher. This is the vulnerability flood that the clearinghouse debate is trying to get ahead of.</p><h3><a href="https://research.empiricalsecurity.com/research/looking-for-the-ai-vulnerability-flood">Empirical Security Pushes Back on AI Vulnerability Flood Narrative</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i3N1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i3N1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png 424w, https://substackcdn.com/image/fetch/$s_!i3N1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png 848w, https://substackcdn.com/image/fetch/$s_!i3N1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png 1272w, https://substackcdn.com/image/fetch/$s_!i3N1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i3N1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png" width="553" height="500.03065134099614" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:708,&quot;width&quot;:783,&quot;resizeWidth&quot;:553,&quot;bytes&quot;:88239,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!i3N1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png 424w, https://substackcdn.com/image/fetch/$s_!i3N1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png 848w, https://substackcdn.com/image/fetch/$s_!i3N1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png 1272w, https://substackcdn.com/image/fetch/$s_!i3N1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2aa0826-35b9-4ce4-bcb3-089cd0b0ae65_783x708.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ben Edwards at Empirical Security offers a measured counterpoint to the Epoch AI analysis. </p><p>His segmented Poisson model identifies an October 2022 breakpoint in CVE publication rates, well before the AI era, suggesting CVE volume was already accelerating for non-AI reasons. </p><p>Of the top 100 CNAs, only 24 have experienced a statistically measurable recent acceleration. Some of those (VulnCheck, VulnDB) have been accelerating since inception, not in response to AI. Edwards directly critiques Epoch&#8217;s methodology, arguing they &#8220;selectively picked a set of CNAs, aggregated them, and declared AI a spike.&#8221; I think both analyses contain important truths. </p><p>The spike is real for specific organizations using AI tools, but attributing the entire CVE volume increase to AI oversimplifies a much more complex picture.</p><h3><a href="https://www.linkedin.com/posts/jgamblin_happy-4th-of-july-a-fittingly-american-share-7479181054960902144-8Ka5/">Jerry Gamblin&#8217;s H1 2026 Data Shows 35,364 CVEs Published at a Rate of One Every 7.4 Minutes</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m12w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m12w!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png 424w, https://substackcdn.com/image/fetch/$s_!m12w!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png 848w, https://substackcdn.com/image/fetch/$s_!m12w!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png 1272w, https://substackcdn.com/image/fetch/$s_!m12w!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m12w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png" width="555" height="332.39344262295083" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:548,&quot;width&quot;:915,&quot;resizeWidth&quot;:555,&quot;bytes&quot;:109617,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m12w!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png 424w, https://substackcdn.com/image/fetch/$s_!m12w!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png 848w, https://substackcdn.com/image/fetch/$s_!m12w!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png 1272w, https://substackcdn.com/image/fetch/$s_!m12w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F632c7d2a-437f-4182-b2d9-505b3fc592ee_915x548.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Gamblin&#8217;s mid-year CVE analysis puts hard numbers behind the flood everyone is feeling. H1 2026 produced 35,364 CVEs, <a href="https://www.linkedin.com/posts/jgamblin_the-single-busiest-cve-day-of-the-first-half-share-7479565887507832832-mCsF/">up 49.5% over H1 2025</a>, with the single busiest day being June 9 at 747 CVEs. </p><p>GitHub Security Advisories is the busiest CNA at 6,801 assignments. The top CWEs remain frustratingly familiar, with XSS leading at 3,783 followed by Missing Authorization (1,704) and SQL Injection (1,445). Only 85 CVEs (0.24%) appear in CISA&#8217;s KEV catalog, <a href="https://www.linkedin.com/posts/jgamblin_vulnerabilitymanagement-cybersecurity-cve-share-7479917473342058496-purc/">reinforcing the data point</a> I keep coming back to about the futility of treating all vulnerabilities equally. </p><p>Full-year projections now range from 66,000 to 72,000, with CPE coverage sitting at only 59%. For those who missed it, I recently sat down with Jerry to give into all things CVE&#8217;s, CNA&#8217;s and vulnerabilities:</p><div id="youtube2-nzQLQxD-GfE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;nzQLQxD-GfE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/nzQLQxD-GfE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://www.linkedin.com/pulse/90-day-disclosure-window-dead-why-cookie-cutter-timelines-gal-elbaz-oictf/">Gal Elbaz Argues the 90-Day Disclosure Window Is Dead</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g5mo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g5mo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png 424w, https://substackcdn.com/image/fetch/$s_!g5mo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png 848w, https://substackcdn.com/image/fetch/$s_!g5mo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png 1272w, https://substackcdn.com/image/fetch/$s_!g5mo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g5mo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png" width="455" height="250.05217391304348" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:316,&quot;width&quot;:575,&quot;resizeWidth&quot;:455,&quot;bytes&quot;:59740,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g5mo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png 424w, https://substackcdn.com/image/fetch/$s_!g5mo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png 848w, https://substackcdn.com/image/fetch/$s_!g5mo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png 1272w, https://substackcdn.com/image/fetch/$s_!g5mo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8ed0f84-18db-46cf-b99d-5322b5fd3ebf_575x316.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Oligo Security&#8217;s CTO makes the case that AI has compressed both vulnerability discovery and exploit development timelines to the point where fixed disclosure windows are obsolete. AI can weaponize a published patch, turning a fix into a working exploit, in approximately 30 minutes. </p><p>MITRE cannot keep up with CVE report volume. Linus Torvalds has said the same about the Linux kernel. Elbaz argues disclosure timelines should be based on exploitability rather than a fixed number of days, and his bottom line is that &#8220;the noise needs to be cut, the critical bugs need better definition, and both vendors and researchers need to get back to the table as humans.&#8221; </p><p>I think he is right that the 90-day window is an artifact of a pre-AI era, but the replacement cannot be vendor-determined timelines either. The answer likely involves automated exploitability assessment as a disclosure trigger.</p><h3><a href="https://www.corridor.dev/blog/making-code-review-optional">Corridor Makes Code Review Optional by Building an Auto-Approval System for PRs</a></h3><p>The idea of merging code without human review runs counter to everything security culture has drilled into engineering organizations for two decades, but Corridor&#8217;s internal experiment is producing data that challenges that assumption. </p><p>The AI code security startup, which raised $25M in Series A funding, has been running most PRs through automated security and quality checks rather than human reviewers. If the auto-approval system&#8217;s false negative rate proves lower than human reviewer error rates, and given what we know about code review effectiveness that is not impossible, the industry&#8217;s assumption that human code review is a meaningful security control may need revisiting. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XL2Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XL2Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png 424w, https://substackcdn.com/image/fetch/$s_!XL2Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png 848w, https://substackcdn.com/image/fetch/$s_!XL2Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png 1272w, https://substackcdn.com/image/fetch/$s_!XL2Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XL2Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png" width="661" height="339.63442211055275" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:409,&quot;width&quot;:796,&quot;resizeWidth&quot;:661,&quot;bytes&quot;:42560,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/206166821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XL2Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png 424w, https://substackcdn.com/image/fetch/$s_!XL2Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png 848w, https://substackcdn.com/image/fetch/$s_!XL2Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png 1272w, https://substackcdn.com/image/fetch/$s_!XL2Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b06d091-9aa3-48dd-a14c-ea10ed39302e_796x409.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But the failure modes of AI-based approval are different and potentially more dangerous than human oversight gaps, so I would want to see independent validation before recommending anyone follow this path.</p><div><hr></div><h1>Final Thoughts</h1><p>This week drove home a point I have been circling for months in prior issues and blogs. The offensive-defensive asymmetry in AI is not a future concern but a present reality. </p><p>An autonomous agent exploiting airline infrastructure in fifteen minutes, an LLM extracting every detection rule from a production EDR, AI malware running on models that ship with the operating system, and an open-source framework claiming 90% pass rates on offensive benchmarks, all in one week.</p><p>The vulnerability management world is grappling with its own reckoning. Four clearinghouses in five weeks, a 3.5x spike in high-severity disclosures, 35,000 CVEs in six months, and a genuine debate about whether the flood is AI-driven or structural. Whether Epoch or Empirical has the better methodology matters less than the shared conclusion. The volume is going up, the complexity is going up, and the existing institutional infrastructure was not designed for this.</p><p>What gives me some hope is that the defensive side is not standing still. The UK AISI found real vulnerabilities in their own infrastructure for under &#163;1,000. Insurance companies are pricing remediation speed as a risk factor. And the clearinghouse debate, messy as it is, represents the industry at least trying to build new institutions before the old ones collapse.</p><p>The organizations that will be fine are the ones treating AI as both the threat and the tool, not choosing one framing over the other. Run frontier models against your own infrastructure, price your remediation speed, and accept that the 90-day disclosure window, like the CVSS score that drives it, is a legacy artifact of a world that no longer exists.</p><blockquote><p><strong>Stay Resilient!</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[How America Talked Itself Into Chinese Open Source AI]]></title><description><![CDATA[The Mythos episode, the open-weights surge, and why restriction hurts defenders more than attackers]]></description><link>https://www.resilientcyber.io/p/how-america-talked-itself-into-chinese</link><guid isPermaLink="false">https://www.resilientcyber.io/p/how-america-talked-itself-into-chinese</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Wed, 08 Jul 2026 13:49:56 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d9888ac8-c363-41a2-8739-8d4f02a52a0a_819x525.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For most of the last two years, the debate about open versus closed AI was mostly an economic and ideological one. </p><p>Closed labs argued that frontier capabilities were too dangerous to hand out freely. Open advocates argued that transparency, cost, and control were worth more than a marginal capability lead. Practitioners could mostly watch that argument from the sidelines, because in day-to-day security work the closed frontier models were simply better and the open models were a step or two behind.</p><p>That gap has closed, and the debate has stopped being academic. It is now a live architectural decision that CISOs, security engineers, and platform teams are making right now, often without a clear framework for reasoning about the security implications on either side. </p><p>I want to walk through how we got here in the middle of 2026, and then spend most of my time on the part I think we are collectively underweighting, which is what the open versus closed choice actually means for defenders and for the software supply chain we all depend on.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>How U.S. policy talked itself into a corner</h2><p>Start with the strategic goal, because the goal and the actions have drifted apart in a way that matters. In July 2025 the administration issued Executive Order 14320, <strong><a href="https://www.whitehouse.gov/presidential-actions/2025/07/promoting-the-export-of-the-american-ai-technology-stack/">Promoting the Export of the American AI Technology Stack</a></strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZqUG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZqUG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png 424w, https://substackcdn.com/image/fetch/$s_!ZqUG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png 848w, https://substackcdn.com/image/fetch/$s_!ZqUG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png 1272w, https://substackcdn.com/image/fetch/$s_!ZqUG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZqUG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png" width="506" height="245.0477299185099" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:416,&quot;width&quot;:859,&quot;resizeWidth&quot;:506,&quot;bytes&quot;:82849,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZqUG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png 424w, https://substackcdn.com/image/fetch/$s_!ZqUG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png 848w, https://substackcdn.com/image/fetch/$s_!ZqUG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png 1272w, https://substackcdn.com/image/fetch/$s_!ZqUG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3f4d3ec-7708-48c2-b44f-0c9553453580_859x416.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The explicit ambition was that American AI hardware, models, standards, and governance would become the default stack for allies and partners around the world. If you wanted the U.S. to win the AI competition with China, exporting the American stack and getting the world to build on it was a coherent way to do it.</p><p>Then came the whiplash. </p><p>In June 2026 Anthropic launched Fable 5 and Mythos 5, and roughly three days later the U.S. government ordered the company to cut off foreign access to both, citing national security and export-control authority. Reporting from various leading media outlets tied the order to a jailbreak report from a trusted partner, with reporting pointing to Amazon, that suggested the models could be turned into unrestricted cyber tools. </p><p>Anthropic disputed how severe the jailbreak actually was and criticized the opaque process. About eighteen days later the <strong><a href="https://www.anthropic.com/news/redeploying-fable-5">restrictions were lifted</a></strong> and the models came back online.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E4Z9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E4Z9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png 424w, https://substackcdn.com/image/fetch/$s_!E4Z9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png 848w, https://substackcdn.com/image/fetch/$s_!E4Z9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png 1272w, https://substackcdn.com/image/fetch/$s_!E4Z9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E4Z9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png" width="473" height="177.46666666666667" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be843506-742e-431b-b4b7-caa72493609f_645x242.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:242,&quot;width&quot;:645,&quot;resizeWidth&quot;:473,&quot;bytes&quot;:20557,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E4Z9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png 424w, https://substackcdn.com/image/fetch/$s_!E4Z9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png 848w, https://substackcdn.com/image/fetch/$s_!E4Z9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png 1272w, https://substackcdn.com/image/fetch/$s_!E4Z9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe843506-742e-431b-b4b7-caa72493609f_645x242.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>I already worked through the ban itself in <strong><a href="https://www.resilientcyber.io/p/cybersecuritys-friendly-fire-problem">Cybersecurity&#8217;s Friendly Fire Problem</a></strong>, so I will not relitigate the whole thing here. The short version is that gating and banning a U.S. frontier model did not remove the underlying capability from the threat landscape. </p><p>It removed the U.S. ability to watch that capability being used, and it handed every ally in Europe and beyond a concrete reason to question whether building on an American AI stack carries political risk. That is the opposite of what Executive Order 14320 set out to accomplish. </p><p>When France and the Netherlands start amplifying calls for AI sovereignty within days of your export action, the export strategy is working against itself.</p><h2>The quieter forces pushing people toward open weights</h2><p>The ban gets the headlines, but it is not the only thing reviving interest in open source AI, and I want to be careful not to overstate its role. Several structural forces are converging at once, and most of them have nothing to do with geopolitics.</p><p>The first is cost, and it is the one practitioners feel most directly. For a brief window in early 2026 the loudest signal of AI adoption inside big companies was token consumption going up. </p><p>That has reversed hard. Coverage from <strong><a href="https://techcrunch.com/2026/06/05/the-token-bill-comes-due-inside-the-industry-scramble-to-manage-ais-runaway-costs/">TechCrunch</a> </strong>and others documented finance teams now trying to drive that same number down. Amazon reportedly shut down an internal leaderboard that ranked developers by token consumption in late May 2026, with the internal line being that you should not use AI just to use AI. Uber said it burned through its entire 2026 AI coding-tools budget in four months and capped spend at $1,500 per employee per month per tool. </p><p>Agentic workflows consume something like 5x-30x the tokens of a standard chatbot interaction, so the economics of running everything through a metered frontier API stopped making sense for organizations operating at scale. </p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;id&quot;:11988704,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a89717e5-a927-4084-ad86-69068727dbf3_1632x1632.png&quot;,&quot;uuid&quot;:&quot;7d05e332-91e1-41e4-8e56-7fbeb7cb01ff&quot;}" data-component-name="MentionToDOM"></span> has been making this point for a while, and it lands especially hard in security, where you are often running high-volume automated analysis and per-token costs compound quickly. When Gary Marcus says tokenmaxxing is giving way to tokenminimizing, that is not a vibe, it is a budget line. It also pours some cold water on the theme that the answer to every security problem AI introduces is to use AI to fight it.</p><p>The second force is the frontier labs themselves adding friction to their own products in the name of safety. When Anthropic redeployed Fable 5 in July 2026, it did so with a new classifier layer. </p><p>Per Anthropic&#8217;s own <strong><a href="https://anthropic.com/news/redeploying-fable-5">Redeploying Claude Fable 5</a></strong> post, a Fable 5 request that trips the new cyber classifier is rerouted to Claude Opus 4.8, with the user notified, so the work still completes on a more conservative model. Anthropic was honest about the tradeoff, which I respect, noting that the classifier flags benign requests more often during routine coding and debugging. </p><p>If you are a security engineer doing legitimate vulnerability research or debugging exploit-adjacent code, you now have a real chance of being downshifted to a different model mid-task because a safety-margin classifier decided your benign work looked risky. That is a rational safety decision on Anthropic&#8217;s part and a genuine capability tax on the practitioner. It is exactly the kind of friction that makes a self-hosted model you fully control look attractive. </p><blockquote><p><strong>I&#8217;m in various private group chats with security researchers and leaders and it is full of folks frustrated with the classifiers downgrading their legitimate security work</strong>.</p></blockquote><p>The third force is the one that changes everything, which is that open weights have caught up. In June 2026, Z.ai released <a href="https://artificialanalysis.ai/articles/glm-5-2-is-the-new-leading-open-weights-model-on-the-artificial-analysis-intelligence-index">GLM-5.2</a>, a roughly 744-billion-parameter mixture-of-experts model with around 40 billion active parameters, a one-million-token context window, and an MIT license. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RpVB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RpVB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png 424w, https://substackcdn.com/image/fetch/$s_!RpVB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png 848w, https://substackcdn.com/image/fetch/$s_!RpVB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png 1272w, https://substackcdn.com/image/fetch/$s_!RpVB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RpVB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png" width="1427" height="656" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:656,&quot;width&quot;:1427,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:152465,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RpVB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png 424w, https://substackcdn.com/image/fetch/$s_!RpVB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png 848w, https://substackcdn.com/image/fetch/$s_!RpVB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png 1272w, https://substackcdn.com/image/fetch/$s_!RpVB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3351d0-3376-49d5-a2ae-b8bf9df93b76_1427x656.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It ranks first among open-weights models on the Artificial Analysis Intelligence Index and fourth overall. On coding benchmarks it beats GPT-5.5 on SWE-bench Pro and lands within a point of Claude Opus 4.8 on FrontierSWE, and it does it at roughly one-sixth the cost. For mainstream coding and engineering work, GLM-5.2 is effectively at parity with the closed frontier. </p><p>The gap only opens meaningfully on the hardest ultra-long-horizon tasks. When the open option is at parity, six times cheaper, self-hostable, and cannot be turned off by a government order, the pull is obvious. </p><p>Folks such as <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;9106c6c9-8e3b-416a-81e5-11d06d90abab&quot;}" data-component-name="MentionToDOM"></span> have used GLM-5.2 as an example of how counterproductive the U.S. ban on closed source frontier models are, and how it hurts defenders more than attackers in his piece &#8220;<strong><a href="https://joshuasaxe181906.substack.com/p/glm-52-not-mythos-is-the-real-security">GLM-5.2 not Mythos, is the real security emergency</a></strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1Sxd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1Sxd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png 424w, https://substackcdn.com/image/fetch/$s_!1Sxd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png 848w, https://substackcdn.com/image/fetch/$s_!1Sxd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png 1272w, https://substackcdn.com/image/fetch/$s_!1Sxd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1Sxd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png" width="585" height="430.7142857142857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:536,&quot;width&quot;:728,&quot;resizeWidth&quot;:585,&quot;bytes&quot;:801671,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1Sxd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png 424w, https://substackcdn.com/image/fetch/$s_!1Sxd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png 848w, https://substackcdn.com/image/fetch/$s_!1Sxd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png 1272w, https://substackcdn.com/image/fetch/$s_!1Sxd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff685baa3-2caa-4bd6-83c2-3b0983baad46_728x536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The industry signals are stacking up as well. Alex Karp at Palantir went on CNBC on July 1, 2026 and <strong><a href="https://www.cnbc.com/2026/07/01/palantir-karp-open-ai-anthropic-tokens.html">called the token-based pricing model of the frontier labs &#8220;completely wrong,</a></strong><a href="https://www.cnbc.com/2026/07/01/palantir-karp-open-ai-anthropic-tokens.html">&#8221;</a> framing open-weight models as the answer for customers who want control over their compute, their models, their data, and their alpha. </p><p>He also asked whether the country really wants to outsource its national security posture to the consensus view of Silicon Valley, and he warned against underestimating how fast China is moving. Say what you want about Palantir&#8217;s true motives, but many of his points are ones a lot of folks do share when it comes to AI. The below video has now gone viral:</p><div id="youtube2-0A3sGymV6kY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;0A3sGymV6kY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/0A3sGymV6kY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Separately, <strong><a href="https://www.axios.com/2026/06/16/microsoft-copilot-cowork-tokenmaxxing-cowork">Axios reported</a></strong> that Microsoft is exploring a fine-tuned, Azure-hosted version of DeepSeek V4, or another open model, as a lower-cost option inside Copilot.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sH5U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sH5U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png 424w, https://substackcdn.com/image/fetch/$s_!sH5U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png 848w, https://substackcdn.com/image/fetch/$s_!sH5U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png 1272w, https://substackcdn.com/image/fetch/$s_!sH5U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sH5U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png" width="700" height="133" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81048491-c53e-452f-97c9-03c1719afcc2_700x133.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:133,&quot;width&quot;:700,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21677,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sH5U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png 424w, https://substackcdn.com/image/fetch/$s_!sH5U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png 848w, https://substackcdn.com/image/fetch/$s_!sH5U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png 1272w, https://substackcdn.com/image/fetch/$s_!sH5U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81048491-c53e-452f-97c9-03c1719afcc2_700x133.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>I want to flag both of these carefully. Karp&#8217;s comments are on the record and his framing is his own. The Microsoft reporting describes an exploration that Microsoft says is not final, with the model that would be optional and hosted inside Azure with added safeguards. Neither is a settled decision to standardize on Chinese open weights, and I would not treat them as such.  Microsoft isn&#8217;t along either though, as it is reported many other Western companies are adopting Chinese AI models as well:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R7eZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R7eZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png 424w, https://substackcdn.com/image/fetch/$s_!R7eZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png 848w, https://substackcdn.com/image/fetch/$s_!R7eZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png 1272w, https://substackcdn.com/image/fetch/$s_!R7eZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R7eZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png" width="574" height="250.63085399449037" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:317,&quot;width&quot;:726,&quot;resizeWidth&quot;:574,&quot;bytes&quot;:184767,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R7eZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png 424w, https://substackcdn.com/image/fetch/$s_!R7eZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png 848w, https://substackcdn.com/image/fetch/$s_!R7eZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png 1272w, https://substackcdn.com/image/fetch/$s_!R7eZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e1fdd36-e342-4190-8ef1-03b9675b78f5_726x317.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What they do show is that the &#8220;open weights are for hobbyists&#8221; framing is dead, and serious enterprises and serious buyers are actively pricing the switch. It is also interesting that one of the largest software suppliers to the U.S. Government in MSFT is looking at potentially using DeepSeek, albeit they likely wouldn&#8217;t use it for their Government approved offerings.</p><p>The political signal is arguably more striking. Former U.S. AI Czar David Sacks used a recent episode of the All-In podcast that I listened to over the weekend to make the case for open source AI directly, arguing that open source is one of America&#8217;s strongest cards in the competition with China rather than a liability. </p><div id="youtube2-wgdxSCsmS-Q" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;wgdxSCsmS-Q&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/wgdxSCsmS-Q?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>He echoed Karp&#8217;s point that what enterprises actually want is control over their compute, models, and data, and he raised the concern that feeding proprietary knowledge to frontier labs is risky when those same labs are launching vertical applications that compete with their own customers. </p><p>You can debate how much of that is a fair characterization of the labs, and Anthropic and OpenAI would push back hard. What matters for this discussion is that a figure who sat at the center of U.S. AI policy is now publicly framing open source as a strategic asset, not the thing to be restricted. That is a meaningful shift in where the political center of gravity sits.</p><p>Several others have had great pieces on this shift too, such as <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Michael Spencer&quot;,&quot;id&quot;:21731691,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F75d1bf99-dcf3-4af6-be2a-416c08c954a1_450x450.jpeg&quot;,&quot;uuid&quot;:&quot;45b5eb38-a576-4a29-941b-6face8dfc2ca&quot;}" data-component-name="MentionToDOM"></span>&#8217;s blog titled &#8220;<strong><a href="https://substack.com/home/post/p-204967035">The Token Apocalypse</a></strong>&#8221;, or <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;This Week in AI&quot;,&quot;id&quot;:309691089,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6fabcec9-9337-4a60-98d9-f169b5cc42df_500x500.png&quot;,&quot;uuid&quot;:&quot;b93885ed-406f-4196-bd78-41d75827162c&quot;}" data-component-name="MentionToDOM"></span> <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;HSM @ This Week in AI&quot;,&quot;id&quot;:385081146,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc23faee-eda6-42d1-9b17-0d8f852b73f3_1024x1024.png&quot;,&quot;uuid&quot;:&quot;7c9b1893-7ba0-45e0-b40f-a8825cafde31&quot;}" data-component-name="MentionToDOM"></span> blog &#8220;<strong><a href="https://thisweekinaiclub.substack.com/p/the-state-of-ai-the-us-is-losing">The State of AI: The US is Losing its AI Monopoly</a></strong>&#8221;. </p><h2>The security argument that flips the usual intuition</h2><p>Here is where security practitioners have to update their intuition. The reflexive take is that closed, gated models are safer because access is controlled. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;13ad4ae9-3a9f-4eab-a939-5f1a44e58c87&quot;}" data-component-name="MentionToDOM"></span> made the sharper argument in his piece that <strong><a href="https://joshuasaxe181906.substack.com/p/glm-52-not-mythos-is-the-real-security">GLM-5.2, not Mythos, is the real security emergency</a></strong>, and I think he is right about the mechanism.</p><p>When an attacker uses a closed model, they are operating on the provider&#8217;s infrastructure, under monitoring, with trust and safety teams watching for abuse. That is not a hypothetical benefit, it is exactly how Anthropic caught the <strong><a href="https://www.anthropic.com/news/disrupting-AI-espionage">first documented large-scale AI-orchestrated cyber espionage campaign</a></strong>, which it disclosed in November 2025 and attributed with high confidence to a Chinese state-sponsored group. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Vm0l!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Vm0l!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png 424w, https://substackcdn.com/image/fetch/$s_!Vm0l!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png 848w, https://substackcdn.com/image/fetch/$s_!Vm0l!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png 1272w, https://substackcdn.com/image/fetch/$s_!Vm0l!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Vm0l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png" width="1160" height="281" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:281,&quot;width&quot;:1160,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47191,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Vm0l!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png 424w, https://substackcdn.com/image/fetch/$s_!Vm0l!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png 848w, https://substackcdn.com/image/fetch/$s_!Vm0l!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png 1272w, https://substackcdn.com/image/fetch/$s_!Vm0l!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F675e4370-7e67-4fbe-95b4-14f527491f74_1160x281.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The attackers jailbroke Claude Code, ran roughly thirty targets, and let the model handle an estimated 80 to 90 percent of the campaign autonomously, with humans stepping in at only a handful of decision points. Anthropic caught it, mapped it, banned the accounts, and notified victims, because the operation ran on monitored, API-gated infrastructure. Even if you discount some of the lab&#8217;s framing as marketing, the visibility point holds, you cannot ban an account you cannot see. This is something enterprise security leaders already know intuitively after years of wrestling with shadow IT/SaaS and now AI.</p><p>Now run the same campaign on a self-hosted open-weights model. </p><blockquote><p><strong>There is no usage log, no trust and safety team, no account to ban, no detection to trigger. The capability does not go away when you restrict the closed model. </strong></p></blockquote><p>It relocates into the dark, onto a rack of H200s in an environment nobody is watching. So the current restrictions harm defenders more than attackers, because defenders lose their best monitored tooling while attackers simply migrate to the ungoverned option. Joshua Saxe&#8217;s conclusion, which I share, is that the priority should be accelerating AI adoption among defenders and security vendors rather than restricting frontier access, because the open-weights genie is already out of the bottle. </p><p>In fact, when I spoke at the SANS AI Security Summit earlier this year I made this exact argument, that security needs to be an early adopter and innovator with AI. It is very hard to do that if we&#8217;re being handicapped and having our access to the capabilities restricted. </p><div id="youtube2-ts_MFz9NAmQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ts_MFz9NAmQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ts_MFz9NAmQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>This connects to something I have been writing about for a while, which is the jagged frontier of AI in offensive security. The comfortable assumption is that offensive capability is gated behind the biggest, most expensive, most restricted models. </p><p>The evidence says otherwise. AISLE&#8217;s <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Stanislav Fort&quot;,&quot;id&quot;:6503858,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/920622a8-11bd-4a16-a695-33775e0b72ea_1600x1338.jpeg&quot;,&quot;uuid&quot;:&quot;6a993314-adcc-4cea-99a4-4ecd748e913a&quot;}" data-component-name="MentionToDOM"></span> ran <strong><a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">Anthropic&#8217;s own showcase Mythos vulnerabilities through small, cheap, open-weights models</a></strong> and found that eight out of eight models detected the flagship FreeBSD exploit, including one with only 3.6 billion active parameters costing eleven cents per million tokens. </p><p>A model with 5.1 billion active parameters recovered the core chain of a 27-year-old OpenBSD bug. His conclusion is that the moat is the system, not the model, because capability does not scale smoothly with size or price. </p><p>Niels Provos reached a compatible conclusion with his work on autonomous zero-day discovery, arguing that <strong><a href="https://www.provos.org/p/finding-zero-days-with-any-model/">finding vulnerabilities is an orchestration problem, not a frontier-model problem</a></strong>. </p><p>I sat down with Niels for a full conversation on exactly this, and the through line is consistent. With a good harness, capability that we assumed required a frontier model is available to anyone with modest, older, or open hardware. Gating the frontier does very little to gate the capability.</p><div id="youtube2-gRgDsdm4RQo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;gRgDsdm4RQo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/gRgDsdm4RQo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>The next policy mistake is already forming</h2><p>If the Mythos ban was restriction aimed at the closed frontier, the move that worries me more is the growing appetite to regulate open source itself. Dario Amodei has been consistent that open-source AI is heading down what he calls a very dangerous path, and his June 2026 policy essay, <strong><a href="https://darioamodei.com/post/policy-on-the-ai-exponential">Policy on the AI Exponential</a></strong>, called for FAA-style, government-mandated safety evaluations before any frontier model can be publicly deployed, open or closed. </p><p>He points to genuine concerns, including bioweapons uplift from Anthropic&#8217;s own red-team testing, cyberattacks on critical infrastructure, and the plain fact that you cannot recall an open-weights release the way you patch a breach. That irreversibility point is real and worth taking seriously.</p><p>I would weigh the framing honestly, though. Critics have noted that Anthropic sells API access to Claude, and open models approaching Claude&#8217;s capability are a direct competitive threat, which is a relevant data point when a lab argues that its competitors&#8217; release model is the dangerous one. </p><p>It is the same skepticism people applied to the arguments against releasing GPT-2 back in 2019, and the safety case and the commercial case happen to point the same direction. I am not assigning motive, but practitioners should hold both things in view at once. </p><p>There&#8217;s also a strange conundrum involved, where yes, it is in Anthropic, OpenAI etc.&#8217;s commercial interest to stifle open source, but ironically, much of the U.S. economy is now riding high due to the AI boom, and the role of the frontier labs, hyperscalers, the venture capital involved, and infrastructure buildout and more. If the labs struggle, it inevitably will reverberate across the U.S. economy as well.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LU9D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LU9D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png 424w, https://substackcdn.com/image/fetch/$s_!LU9D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png 848w, https://substackcdn.com/image/fetch/$s_!LU9D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png 1272w, https://substackcdn.com/image/fetch/$s_!LU9D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LU9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png" width="510" height="420.63829787234044" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:659,&quot;width&quot;:799,&quot;resizeWidth&quot;:510,&quot;bytes&quot;:58401,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LU9D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png 424w, https://substackcdn.com/image/fetch/$s_!LU9D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png 848w, https://substackcdn.com/image/fetch/$s_!LU9D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png 1272w, https://substackcdn.com/image/fetch/$s_!LU9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e25ebea-e9a1-4644-aa28-0ed4a9639eb1_799x659.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The bigger problem is that regulating open source would fail on its own terms and likely backfire, for reasons <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Nathan Lambert&quot;,&quot;id&quot;:10472909,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dad13b2b-20b2-44e0-a84d-732f3be8bee7_4128x4128.jpeg&quot;,&quot;uuid&quot;:&quot;3de66313-fa32-4431-bb31-5786816e3dff&quot;}" data-component-name="MentionToDOM"></span> and <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Kevin Xu&quot;,&quot;id&quot;:9714824,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8724733-4f91-46b4-a37d-652026b382ae_400x400.jpeg&quot;,&quot;uuid&quot;:&quot;ad3d25b8-0335-4d7b-a7cb-464bb81ebd4a&quot;}" data-component-name="MentionToDOM"></span> laid out in <strong><a href="https://www.interconnects.ai/p/banning-open-source-ai-would-be-a">Banning Open Source AI Would Be a Mistake</a></strong>. </p><p>A U.S. rule restricting open weights binds U.S. labs and U.S. developers. It does nothing to GLM-5.2, DeepSeek, or Qwen, which are already downloaded, mirrored, fine-tuned, and self-hosted around the world.<strong> You cannot un-release a model (in open source). </strong></p><p>Regulating domestic open source because of China would chill American education, research, and competition while handing the global default to Chinese models, which is the exact outcome the policy claims to prevent. It is the chip export-control lesson all over again, where denial accelerated the alternatives rather than stopping them. </p><blockquote><p><strong>Constraint breeds innovation, which is exactly what we&#8217;re seeing play out with China&#8217;s AI, from chips to models.</strong></p></blockquote><p>Lambert has separately described the current posture as &#8220;<em>vibe governance&#8221;</em>, where model releases are judged by political instinct rather than transparent technical assessment, and he argues that export bans on model weights are a lasting negative for U.S. leadership.</p><p>For defenders specifically, this would widen the same visibility gap the Mythos ban opened. Restricting domestic open source hobbles the vendors and security teams building defensive tooling on open models, while attackers keep running whatever they already pulled down. </p><p>You would be regulating the people you can see and leaving untouched the people you cannot.</p><h2>The uncomfortable part, and why it is not just &#8220;China bad&#8221;</h2><p>Here is the part that makes practitioners uneasy, and it should. Much of the leading open source is coming out of Chinese labs. GLM-5.2 is from Z.ai. DeepSeek is Chinese, Qwen is Chinese, Kimi is Chinese. </p><p>The nation the U.S. most wants to out-compete on AI is currently producing the open models that are cheap, publicly available, increasingly capable, and attractive precisely because they let enterprises keep their own data and control their own stack. There is real irony in a world where American export policy nudges American enterprises toward Chinese open weights.</p><p>I also want to be specific about the risk here, because &#8220;<em>China bad</em>&#8221; is lazy and it leads to bad decisions. Open weights are not a black box you have to trust blindly. That is the whole point of them. You can self-host them, air-gap them, control every network flow in and out, scan the weights, monitor inference, and log everything. </p><p>In a lot of ways a locally hosted open model gives you more control and more visibility than a closed API where your data leaves your environment and you trust the provider&#8217;s word about what happens to it. For data-sovereignty-conscious organizations and entire nations, that control is the feature.</p><p>But the risks that remain are real and they are not the ones people usually name. The concern is not that the model phones home, because you can prevent that. The concern is what is baked into the weights and the pipeline that produced them.</p><p>Poisoned or backdoored weights, where a model behaves normally until a specific trigger activates hidden behavior. Training-time bias, whether deliberate or incidental, that shapes outputs on politically or strategically sensitive topics. Jailbreak susceptibility that varies by model and is hard to fully characterize. Supply-chain tampering anywhere between the lab that trained the model and the checkpoint you actually download. These are not exotic, they are the AI-native versions of problems we have spent a decades learning to take seriously in software.</p><h2>This is a software supply chain problem, and we have seen this movie</h2><p>When Tony Turner and I wrote <strong><a href="https://www.resilientcyber.io/p/software-transparency">Software Transparency</a>,</strong> with Steve Springett as technical editor and Allan Friedman writing the foreword, the core argument was that a software-driven society cannot run on components it cannot inspect. </p><p>We spent years pushing SBOM, provenance, and transparency because you cannot secure what you cannot see, and because trust in a supplier is not the same thing as verification of an artifact. The entire discipline grew out of watching supply-chain attacks like SolarWinds and the log4j scramble teach us that the thing you did not build, did not inspect, and cannot attest to can be exactly the thing that hurts you.</p><p>AI models are now the most consequential unaudited dependency most organizations have ever adopted, and we are integrating them at the center of our development pipelines and security tooling with far less rigor than we would demand of a random npm package. The leading model hosting platform, <strong><a href="https://huggingface.co/models">Hugging Face</a></strong> now has almost 3 million models alone.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SkdY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SkdY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png 424w, https://substackcdn.com/image/fetch/$s_!SkdY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png 848w, https://substackcdn.com/image/fetch/$s_!SkdY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png 1272w, https://substackcdn.com/image/fetch/$s_!SkdY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SkdY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png" width="1228" height="670" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:670,&quot;width&quot;:1228,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:411938,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SkdY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png 424w, https://substackcdn.com/image/fetch/$s_!SkdY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png 848w, https://substackcdn.com/image/fetch/$s_!SkdY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png 1272w, https://substackcdn.com/image/fetch/$s_!SkdY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4faae62a-27ac-454e-b96d-9349b7e5f976_1228x670.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A model is a supply-chain artifact. It has provenance, or it should. It has a build process, which is the training data and the training run. It has a distribution channel, which is the checkpoint you pulled from a hub. It has integrity properties you would want to attest to and verify. Almost none of that infrastructure exists in a mature form for AI weights the way it now does for software components. </p><p>That said, no surprise that my friends at OWASP have been working on this problem for quite some time, with their <strong><a href="https://owaspaibom.org/">AI Bill of Materials (AIBOM) project</a></strong>, where they seek to make AI systems transparent, auditable and secure. For those unfamiliar, an AIBOM is a &#8220;a structured machine readable inventory of AI components such as models, datasets, agents tools, guardrails, and runtime elements along with evidence of origin, rights, integrity and evaluation.&#8221; I dove into this topic with one of the projects leaders, Helen Oakley:</p><div id="youtube2-huN8sIiXRYY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;huN8sIiXRYY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/huN8sIiXRYY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>That is the real through line for practitioners. </p><p>The open versus closed AI decision is a software supply chain decision, and the disciplines we built for software transparency map almost directly onto what we now need for models. </p><p>We need provenance for weights and for training data. We need the equivalent of an SBOM for a model, an artifact that tells you what went into it and lets you reason about it. We need integrity verification so you know the checkpoint you are running is the one the lab actually published. We need the ability to inspect, scan, and continuously monitor model behavior in the environments where we run them (e.g. runtime visibility and enforcement). </p><p>Some of this is emerging. Model cards, dataset documentation, and early work on model signing and attestation are steps in the right direction. That said, AI is moving far faster than traditional software supply chain security did.</p><p>The point is that we already know how to think about this. We do not need a brand-new philosophy for AI supply chain security. We need to take the transparency and provenance thinking we spent the last decade building for software and apply it to models with the same seriousness, before the integration is so deep that retrofitting it becomes another decade-long slog, that never fully materializes.</p><h2>What practitioners should actually weigh</h2><p>So strip away the geopolitics and the headlines, and here is how I would frame the decision for a security leader choosing between open and closed AI, neutrally, because both are defensible depending on your context. </p><p>Closed frontier models give you provider-side monitoring, faster patching of newly discovered issues, some assurance of abuse detection, and typically a small capability edge on the hardest tasks. </p><p>You pay for that with metered token costs, with data leaving your environment, with exposure to a provider&#8217;s safety classifiers reshaping your workflows without warning, and with the political and continuity risk that a model you depend on can be gated or pulled by forces outside your control. The Fable and Mythos episode was a live demonstration that this last risk is not theoretical.</p><p>Open-weights models give you control, cost efficiency, data sovereignty, the ability to fine-tune for your use case, and continuity that no government order can revoke overnight. You pay for that by owning the entire security burden yourself. You have to treat the weights as an untrusted supply-chain artifact, verify provenance and integrity as best you can, control the network boundary, monitor inference, scan for anomalous behavior, and accept that backdoor, bias, and poisoning risks are yours to manage rather than the provider&#8217;s. </p><p>If you are going to run a Chinese open-weights model, and many organizations will for entirely rational cost and control reasons, the answer is not to pretend the risk away and it is not to refuse on reflex. The answer is to wrap it in the same supply-chain rigor you would want for any critical dependency you did not build.</p><p>Most organizations are going to end up running both, matched to the task, which is the same conclusion AISLE reached about being model-agnostic by design. We&#8217;re even seeing the rise of <strong><a href="https://openrouter.ai/blog/announcements/fusion-beats-frontier/">Model Fusion</a></strong>, where a panel of models are fused together through routers, such as OpenRouter, and often outscore a single model alone. OpenRouter shared some excellent insights into this, in a blog titled &#8220;<strong><a href="https://openrouter.ai/blog/announcements/fusion-beats-frontier/">Fusion Beats Frontier</a></strong>&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AlCe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AlCe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png 424w, https://substackcdn.com/image/fetch/$s_!AlCe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png 848w, https://substackcdn.com/image/fetch/$s_!AlCe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png 1272w, https://substackcdn.com/image/fetch/$s_!AlCe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AlCe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png" width="616" height="427" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:488,&quot;width&quot;:704,&quot;resizeWidth&quot;:616,&quot;bytes&quot;:78605,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/205499615?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AlCe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png 424w, https://substackcdn.com/image/fetch/$s_!AlCe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png 848w, https://substackcdn.com/image/fetch/$s_!AlCe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png 1272w, https://substackcdn.com/image/fetch/$s_!AlCe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb0343c9-b2e0-4d42-a662-7aabcc8168e2_704x488.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That is fine, but what is not fine is making the choice without a security framework, because the failure modes on each side are different and both are real. </p><p>Vulnerability exploitation is now the leading initial access vector according to the 2026 DBIR, defenders are already behind, and AI is the largest force multiplier available to close that gap. </p><p>Getting the open versus closed decision right, with clear eyes about the security tradeoffs of each, is one of the more consequential architecture calls a security team will make this year.</p><p>The strategic mistake would be to keep treating this as a binary morality play about open being reckless or closed being safe, neither alone is true. </p><blockquote><p><strong>The capability is diffusing regardless of policy, the open models are at parity for most of what we do, and the security question is not whether these tools exist but whether we can see and govern how they are used. </strong></p></blockquote><p>That has always been the harder and more important question, and it is the one the software supply chain community has spent a decade learning to answer.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Do We Need a CVSS for AI Jailbreaks?]]></title><description><![CDATA[On June 30, 2026, Anthropic published likely one of the more consequential AI safety blog posts of the year.]]></description><link>https://www.resilientcyber.io/p/do-we-need-a-cvss-for-ai-jailbreaks</link><guid isPermaLink="false">https://www.resilientcyber.io/p/do-we-need-a-cvss-for-ai-jailbreaks</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 07 Jul 2026 12:00:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HOGe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On June 30, 2026, Anthropic published likely one of the more consequential AI safety blog posts of the year. Not necessarily due to technical details but due to the broader societal context and how big of a deal the entire export ban situation proved to be for the AI industry, leading to conversations around open source, AI sovereignty, model security and much more.</p><p>That said, buried inside the <strong><a href="https://www.anthropic.com/news/redeploying-fable-5">announcement that Fable 5 was being redeployed</a></strong> after its brief export-control-driven suspension was something practitioners should pay close attention to. Anthropic proposed a consensus industry framework for scoring the severity of AI jailbreaks, explicitly modeled on the <strong><a href="https://www.first.org/cvss/">Common Vulnerability Scoring System (CVSS)</a></strong> used in traditional software security. They are drafting it alongside Amazon, Microsoft, Google, and other partners in the Glasswing program.</p><p>This is a significant development, but not because the idea is new, but because it signals that the frontier labs have reached the same conclusion the vulnerability management community reached years ago, even if it took an export ban and societal shit storm to get there. </p><p>When you have a class of security problem that will never be fully solved, you need a standardized way to talk about severity so that organizations can prioritize their response. The cybersecurity industry spent two decades learning that lesson with software vulnerabilities. The AI safety community is now compressing that same realization into months.</p><div id="youtube2-_ZCZwhXQk3I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;_ZCZwhXQk3I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/_ZCZwhXQk3I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>What Jailbreaks Actually Are</h2><p>For practitioners coming from traditional security, jailbreaks are best understood as the AI equivalent of vulnerability exploitation. Every frontier AI model ships with safety training and behavioral constraints designed to prevent it from producing harmful outputs. A jailbreak is any technique that bypasses those constraints and gets the model to do something it was designed to refuse.</p><p>The techniques range from simple to sophisticated. </p><p>For example, some involve creative prompt engineering, rewording a dangerous request in language that slips past the model&#8217;s safety training. Others use multi-turn conversations that gradually shift the model&#8217;s context until it complies with requests it would have initially refused. More advanced methods involve encoding harmful instructions in ways the model processes but its safety systems do not catch, or byspass built in safeguard to try and prevent malicious usage.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QuNI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QuNI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QuNI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QuNI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QuNI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QuNI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg" width="588" height="312.5769230769231" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:774,&quot;width&quot;:1456,&quot;resizeWidth&quot;:588,&quot;bytes&quot;:375255,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QuNI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QuNI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QuNI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QuNI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f0a441b-db2d-4938-b58d-496b4797b871_2437x1295.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It can also occur via exploiting the gap between what the model was trained to refuse and what it actually refuses in practice. Some of these methods are direct, with users directly entering text/inputs to the LLM, while others leverage indirect methodologies, via all sorts of content that makes its way into the models context. A great resource on the latter is Google DeepMind&#8217;s &#8220;<strong><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6372438">AI Agent Traps</a></strong>&#8221; paper. </p><p>Industry organizations such as OWASP recognized this threat early.</p><p>Prompt injection, which encompasses jailbreaking as a technique, has held the number one position in the OWASP <strong><a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/">Top 10 for Large Language Model Applications</a></strong> in both the 2023 and 2025 editions. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VnPW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VnPW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png 424w, https://substackcdn.com/image/fetch/$s_!VnPW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png 848w, https://substackcdn.com/image/fetch/$s_!VnPW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png 1272w, https://substackcdn.com/image/fetch/$s_!VnPW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VnPW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png" width="1024" height="576" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:576,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:236549,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VnPW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png 424w, https://substackcdn.com/image/fetch/$s_!VnPW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png 848w, https://substackcdn.com/image/fetch/$s_!VnPW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png 1272w, https://substackcdn.com/image/fetch/$s_!VnPW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F127d823f-957d-4043-8b46-f09904dcbb74_1024x576.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That is not a ranking driven by theoretical concern. It reflects the assessment of hundreds of security professionals that manipulating LLMs into bypassing their intended constraints is the single most significant risk facing AI deployments today. The fact that it has held the top spot across two editions, despite significant investment in mitigations by every frontier lab, tells you something about the persistence of the problem.</p><p>Jailbreaks matter because they are what triggered the export controls on Fable 5 in the first place. Amazon researchers allegedly found a method to bypass Fable 5&#8217;s safeguards, prompting it to identify software vulnerabilities and produce exploitation code. </p><p>The government&#8217;s concern was straightforward. If a frontier model can be jailbroken into producing offensive cyber capabilities, that capability in the wrong hands represents a national security risk. The result was immediate export controls on both Fable 5 and Mythos 5 on June 12, with Anthropic forced to suspend global access because they had no reliable way to verify user nationality in real time.</p><p>What made the situation more complicated was Anthropic&#8217;s own testing, which showed the behavior that triggered the ban was not unique to Fable 5. Many less capable models, including Claude Opus 4.8, GPT-5.5, Kimi K2.7, and even Claude Haiku 4.5, could reproduce the same vulnerability identification and exploitation demonstrations. </p><p>The reported bypass was what Anthropic characterized as a borderline case involving routine defensive cybersecurity work, not a unique offensive capability. This is something others such as <strong><a href="https://securityconversations.fireside.fm/katie-moussouris-anthropic-mythos-fable-export-control">Katie Moussouris on the Anthropic Export-Control Mess</a> </strong>in an episode of the Three Buddy Problem podcast I listen to, where she discussed reviewing aspects of the report that made its way out of AWS to the Government.</p><p>Ironically, I was listening to the playlist from the recent Real World AI Security Conference and one of the presenters was Jerry Wei from Anthropic, and he walked through how they create, test and implement their classifiers, including training, refusals, activations and more. It was a great opportunity to hear directly from Anthropic themselves on this topic at depth:</p><div id="youtube2-RZjljOhS4kY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;RZjljOhS4kY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/RZjljOhS4kY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>How Classifiers Work</h2><p>The primary defense against jailbreaks in production AI systems is a set of mechanisms called classifiers. These are smaller automated AI systems that run alongside the main model during interactions, monitoring for potentially harmful requests or outputs. When a classifier detects that a conversation is heading toward dangerous territory, it intervenes and blocks the model from responding. Anthropic has a good image in their Fable 5 blog, where they discuss applying even more rigorous classifiers to their Fabel 5 model to try and mitigate risk/abuse, as well as alleviate concerns. (It&#8217;s worth noting many cyber practitioners and researchers have voiced frustration with the classifiers, arguing it is preventing them from doing legitimate defensive and research work.)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yLGh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yLGh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png 424w, https://substackcdn.com/image/fetch/$s_!yLGh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png 848w, https://substackcdn.com/image/fetch/$s_!yLGh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png 1272w, https://substackcdn.com/image/fetch/$s_!yLGh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yLGh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png" width="1456" height="633" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:633,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:367030,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yLGh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png 424w, https://substackcdn.com/image/fetch/$s_!yLGh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png 848w, https://substackcdn.com/image/fetch/$s_!yLGh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png 1272w, https://substackcdn.com/image/fetch/$s_!yLGh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F04c638ef-5004-4f35-9215-0916a6eaf161_1900x826.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Anthropic describes their approach as defense in depth. Multiple safety mechanisms are layered together. Some involve training the model itself to decline dangerous requests. Others involve retroactive pattern analysis of misuse across conversations. The classifiers operate on a safety margin principle, deliberately set to trigger on requests that might be benign but carry some probability of being harmful. A request must look very clearly safe to avoid triggering the classifier.</p><p>For Fable 5 specifically, Anthropic made the safety margin much larger than any prior launch. This was a deliberate tradeoff. More benign requests would be incorrectly blocked, creating frustration for legitimate users, but fewer harmful requests would slip through. After the Amazon report, they trained an improved classifier that blocks the specific reported technique in over 99% of cases, which CAISI independently verified.</p><p>The important thing for practitioners to understand is that classifiers are not perfect and never will be. They reduce the probability of successful jailbreaks but cannot eliminate it. This is not an engineering limitation that better classifiers will eventually overcome. It is a structural property of the problem itself.</p><p>I have written about this quite a bit, especially in the context of agentic AI and the fact that probabilistic controls, often referred to as soft guardrails are imperfect and ultimately we need hard boundaries, especially in the age agents, where rather than just inputs and outputs such as with LLMs, agents take actions and introduce significantly more risk to the enterprise as a result.</p><h2>Jailbreaks Will Never Be Fully Solved</h2><p>Anthropic states this explicitly in their announcement. It is probably impossible to make any AI model fully robust to jailbreaks. They are not alone in that assessment. OpenAI has made similar acknowledgments, and NIST recently put mathematical rigor behind the claim.</p><p>In June 2026, NIST senior scientist Apostol Vassilev published a peer-reviewed proof in IEEE Security and Privacy that formally extends G&#246;del&#8217;s incompleteness theorems to AI guardrail systems. The <strong><a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-nist-continuous-ai-monitoring-godel-proof/">CSA published a research note analyzing the implications</a></strong>, and the conclusion is stark. No finite set of AI guardrails can be universally robust against adversarial prompts. This is not a gap that better engineering can close, it is a mathematical property.</p><p>The fundamental problem is simple. There are infinite ways to ask for the same thing in natural language. You can rephrase, use analogies, speak in hypotheticals, encode instructions, or bury the real request inside something that looks harmless. AI safety filters are built from finite rule sets, and finite rules cannot cover infinite variations. Vassilev's proof at NIST confirmed what practitioners already suspected. No matter how many rules you add, there will always be some way to phrase a request that slips through. The rules can get better, but they cannot become complete.</p><p>To see a concrete example against a model with robust safeguards, you can see the <strong><a href="https://x.com/elder_plinius/status/2064776322979676227?s=20">alleged jailbreak</a></strong> of Fable 5 itself by the popular &#8220;Pliny the Liberator&#8221;, who had claimed to jailbreak Fable 5 using unicode, homoglyphs, fiction narratives and more.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RmAN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RmAN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png 424w, https://substackcdn.com/image/fetch/$s_!RmAN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png 848w, https://substackcdn.com/image/fetch/$s_!RmAN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png 1272w, https://substackcdn.com/image/fetch/$s_!RmAN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RmAN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png" width="273" height="166" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:166,&quot;width&quot;:273,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21954,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RmAN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png 424w, https://substackcdn.com/image/fetch/$s_!RmAN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png 848w, https://substackcdn.com/image/fetch/$s_!RmAN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png 1272w, https://substackcdn.com/image/fetch/$s_!RmAN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93c5b997-afb8-4020-b5d6-e179ef9b0f08_273x166.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The empirical evidence supports the theory. One of the best resources if you want to dig into it is a paper titled &#8220;<strong><a href="https://arxiv.org/abs/2506.10597">SoK: Evaluating Jailbreak Guardrails for LLM&#8217;s</a></strong>&#8221;. The paper has a good synthesis on the current knowledge and research on the topic, as well as a common taxonomy for discussing LLM jailbreaks. </p><blockquote><p><strong>Funnily enough, as I was looking for the most recent literature on the topic for this article, Claude, which I&#8217;m a big user of, and in this case using Fable 5, actually ran into the classifier when I asked about LLM jailbreaks and reverted me back to Opus 4.8.</strong> </p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tqB5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tqB5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png 424w, https://substackcdn.com/image/fetch/$s_!tqB5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png 848w, https://substackcdn.com/image/fetch/$s_!tqB5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png 1272w, https://substackcdn.com/image/fetch/$s_!tqB5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tqB5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png" width="579" height="65" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:65,&quot;width&quot;:579,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:15386,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tqB5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png 424w, https://substackcdn.com/image/fetch/$s_!tqB5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png 848w, https://substackcdn.com/image/fetch/$s_!tqB5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png 1272w, https://substackcdn.com/image/fetch/$s_!tqB5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5c8ba25-5328-48a4-b0f5-d38ed31e8ffb_579x65.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-MYM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-MYM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png 424w, https://substackcdn.com/image/fetch/$s_!-MYM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png 848w, https://substackcdn.com/image/fetch/$s_!-MYM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png 1272w, https://substackcdn.com/image/fetch/$s_!-MYM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-MYM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png" width="751" height="46" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed1e745c-546e-4b68-8b82-642366368a43_751x46.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:46,&quot;width&quot;:751,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8497,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-MYM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png 424w, https://substackcdn.com/image/fetch/$s_!-MYM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png 848w, https://substackcdn.com/image/fetch/$s_!-MYM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png 1272w, https://substackcdn.com/image/fetch/$s_!-MYM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed1e745c-546e-4b68-8b82-642366368a43_751x46.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>You can see how even trivial genuine research and requests can easily bump into the classifiers and guardrails and frustrate cyber defenders and researchers leveraging LLM&#8217;s.</p><p>The OWASP Top 10 for LLM Applications reinforces this from the practitioner side. Prompt injection has held the number one position across both editions, and OWASP&#8217;s own guidance notes that it is unclear if there are foolproof methods of prevention due to the stochastic nature of generative AI. </p><p>For anyone who has worked in application security, that language should sound familiar. It is the same conclusion the industry reached about SQL injection, cross-site scripting, and every other injection class before it. You can reduce the attack surface dramatically. You can make exploitation harder, but you cannot always eliminate the category entirely. The difference with prompt injection is that the input language is natural language itself, which makes the boundary between legitimate use and adversarial manipulation fundamentally harder to define than it is for structured query languages or markup.</p><p>For practitioners, the parallel to traditional security is direct. We long ago accepted that software will always have vulnerabilities, however we did not throw up our hands. We built systems for discovering, scoring, prioritizing, and remediating them. The AI safety community is now reaching the same inflection point with jailbreaks, and that is where the CVSS comparison becomes relevant.</p><h2>The CVSS Parallel, and Its Limitations</h2><p>CVSS has been the standard language for communicating software vulnerability severity for nearly two decades. It gives every vulnerability a numerical score from 0 to 10, providing a common reference point for vendors, security teams, and regulators to discuss how bad a given flaw is.</p><p>Anthropic&#8217;s proposed jailbreak scoring framework borrows this concept directly, even citing it in the footnotes of their blog. Their system evaluates a jailbreak on four criteria, which I will directly share below:</p><ol><li><p><em><strong>Capability gain</strong></em>. How far beyond existing tools does the jailbreak take the user? If existing widely available tools (including other, weaker AI models) can reach the same capability as the jailbroken model, the score here will be low; if the jailbreak unblocks model capabilities that can significantly accelerate even domain experts, the score will be high.</p></li><li><p><em><strong>Breadth of capability gain</strong></em>. For how many distinct offensive tasks does the same jailbreak technique work? Cases where the jailbreak only allows the model to pursue narrow targets will score low; cases where the same jailbreak technique works for multiple different targets or techniques will score high.</p></li><li><p><em><strong>Ease of weaponization</strong></em>. How much human effort does it take to turn the jailbreak into an attack? Where the jailbreak involves a great deal of skilled prompting and many retries, the score will be low; where the jailbreak works on a single prompt or on the first or second try, the score will be high.</p></li><li><p><em><strong>Discoverability</strong></em>. How easy is it for someone to obtain the technique? If it requires specialist knowledge it will score low; if it is already widely known and available online it will score high.</p></li></ol><p>The first two describe what the jailbreak provides to an attacker, while the latter two describe how quickly it can become a real-world problem. Anthropic also provided insights into how jailbreaks interact with their safety classifiers and what a spectrum from minor, narrow and universal jailbreaks looks like.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HOGe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HOGe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png 424w, https://substackcdn.com/image/fetch/$s_!HOGe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png 848w, https://substackcdn.com/image/fetch/$s_!HOGe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png 1272w, https://substackcdn.com/image/fetch/$s_!HOGe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HOGe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png" width="1013" height="660" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:660,&quot;width&quot;:1013,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:206490,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HOGe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png 424w, https://substackcdn.com/image/fetch/$s_!HOGe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png 848w, https://substackcdn.com/image/fetch/$s_!HOGe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png 1272w, https://substackcdn.com/image/fetch/$s_!HOGe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44f9f785-7dad-43b0-a2e8-bb327561f18e_1013x660.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is a reasonable starting framework, but practitioners who have lived through the evolution of vulnerability management know that CVSS, while valuable as a common language, has significant limitations when used as the primary driver of remediation decisions, and it&#8217;s misuse are among the leading reasons trends such as &#8220;shift left&#8221; in AppSec experienced so much heartache and pushback.</p><p>As I covered in <strong><a href="https://www.resilientcyber.io/p/the-death-of-cvss-as-federal-policy">The Death of CVSS as Federal Policy</a></strong>, CISA&#8217;s BOD 26-04 formally replaced CVSS-driven remediation mandates with the Stakeholder-Specific Vulnerability Categorization (SSVC) framework. The directive recognized what practitioners had been saying for years. CVSS measures theoretical severity in a vacuum. It does not account for whether a vulnerability is actually being exploited, whether the affected asset is publicly exposed, whether the vulnerability is reachable, the business context, or whether exploitation can be automated at scale. </p><p>ACM research demonstrated that using CVSS severity alone to measure risk is equivalent to picking random vulnerabilities to fix. Yet for years, the entire federal government, and by extension much of the private sector, used CVSS base scores as the primary input for remediation timelines. It&#8217;s a topic I&#8217;ve been ranting about for years, in blogs, and even my book <em><strong><a href="https://a.co/d/09LM5mdn">Effective Vulnerability Management</a></strong></em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_ylz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_ylz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png 424w, https://substackcdn.com/image/fetch/$s_!_ylz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png 848w, https://substackcdn.com/image/fetch/$s_!_ylz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png 1272w, https://substackcdn.com/image/fetch/$s_!_ylz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_ylz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png" width="224" height="320.6575342465753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:627,&quot;width&quot;:438,&quot;resizeWidth&quot;:224,&quot;bytes&quot;:234982,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_ylz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png 424w, https://substackcdn.com/image/fetch/$s_!_ylz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png 848w, https://substackcdn.com/image/fetch/$s_!_ylz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png 1272w, https://substackcdn.com/image/fetch/$s_!_ylz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17d72521-ca9a-43f3-a3b9-7e8c3181db6f_438x627.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As I covered in <strong><a href="https://www.resilientcyber.io/p/a-look-at-the-exploit-prediction">A Look at the Exploit Prediction Scoring System</a></strong>, EPSS emerged to fill the exploitation probability gap that CVSS ignores. EPSS provides a numerical score representing the probability that a given CVE will be exploited in the wild over the next 30 days, using over 1,400 features and data from sources like Fortiguard, AlienVault, Shadow Server, and GreyNoise. </p><p>EPSS 3.0 demonstrated an 82% performance improvement over previous versions and can help organizations achieve the same risk coverage with one-eighth the remediation effort of CVSS-based strategies. While dated now, the below image is helpful to demonstrate how much more effective it is to prioritize vulnerability remediation based on exploitation probability over CVSS base severity scores:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kVFa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kVFa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png 424w, https://substackcdn.com/image/fetch/$s_!kVFa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png 848w, https://substackcdn.com/image/fetch/$s_!kVFa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png 1272w, https://substackcdn.com/image/fetch/$s_!kVFa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kVFa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png" width="375" height="236.49312377210217" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:321,&quot;width&quot;:509,&quot;resizeWidth&quot;:375,&quot;bytes&quot;:62167,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kVFa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png 424w, https://substackcdn.com/image/fetch/$s_!kVFa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png 848w, https://substackcdn.com/image/fetch/$s_!kVFa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png 1272w, https://substackcdn.com/image/fetch/$s_!kVFa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a3c53e-44ef-4214-b06c-cb86140973df_509x321.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>But EPSS has its own limitations. For example, it measures threat probability without accounting for organization-specific context like asset criticality or business impact, a flaw that CVSS base scores have as well. </p><p>The lesson from two decades of vulnerability management is that no single scoring system is sufficient alone. CVSS lacks exploitation context, EPSS lacks organizational context (although organizations such as Empirical who are involved with EPSS have been working on local/organizational-specific models), KEV only covers confirmed exploitation and even then has gaps compared to sources such as the commercial VulnCheck KEV. </p><p>SSVC provides a decision framework but depends on enrichment data that remains incomplete. The most effective approach combines all of these with reachability analysis and business-context scoring.</p><p>Any jailbreak severity framework will face the same challenge. Anthropic&#8217;s four criteria are a solid foundation, but they will need to evolve to incorporate contextual factors like what systems the jailbroken model has access to, what actions it can take autonomously, what data it can reach, and what the downstream consequences of a successful jailbreak would be in a specific deployment. </p><p>A jailbreak against a model powering a customer service chatbot and a jailbreak against a model with autonomous access to production infrastructure are categorically different risk events, even if the jailbreak technique itself is identical. </p><p>This is where some of the heavy lifting will be left to organizations, much as it was with moving beyond CVSS base scores to account for organizational-specific factors, and as we saw with CVSS, most organizations won&#8217;t do that lifting. </p><h2>This Is Not the First Attempt</h2><p>It is worth noting that Anthropic&#8217;s proposal is not the first attempt to build a structured scoring system for AI security risks. <strong><a href="https://aivss.owasp.org/">OWASP&#8217;s AI Vulnerability Scoring System (AIVSS)</a></strong> has been in development and is currently at version 0.8, an effort that has been championed by my friend <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ken Huang&quot;,&quot;id&quot;:1160339,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;uuid&quot;:&quot;03c16ede-b491-4fca-a7c3-2a411fb23b10&quot;}" data-component-name="MentionToDOM"></span>. AIVSS is building a standardized, quantifiable framework for assessing security vulnerabilities specific to AI systems, with an initial focus on scoring the OWASP Agentic AI Core Security Risks.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2TRh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2TRh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png 424w, https://substackcdn.com/image/fetch/$s_!2TRh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png 848w, https://substackcdn.com/image/fetch/$s_!2TRh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png 1272w, https://substackcdn.com/image/fetch/$s_!2TRh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2TRh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png" width="737" height="260" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:737,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:153178,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2TRh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png 424w, https://substackcdn.com/image/fetch/$s_!2TRh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png 848w, https://substackcdn.com/image/fetch/$s_!2TRh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png 1272w, https://substackcdn.com/image/fetch/$s_!2TRh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8dd851a8-5229-4cf8-bc11-ca12b682bdd7_737x260.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AIVSS covers AI vulnerabilities broadly, not just jailbreaks. Its scope includes model manipulation, data poisoning, agent misalignment, and other AI-specific risk categories. The project&#8217;s structure, with a numerical scoring system, severity assessment, exploitability factors, and an interactive calculator tool, is clearly inspired by CVSS but adapted for AI-specific risk vectors. </p><p>The project has also integrated with SSVC decision-tree methodology, suggesting the team is learning from the vulnerability management community&#8217;s evolution beyond pure severity scoring. There&#8217;s also open source efforts, such as interactive <strong><a href="https://aivss.parthsohaney.online/calculator">AIVSS calculators </a></strong>and dashboards:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yElQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yElQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png 424w, https://substackcdn.com/image/fetch/$s_!yElQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png 848w, https://substackcdn.com/image/fetch/$s_!yElQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png 1272w, https://substackcdn.com/image/fetch/$s_!yElQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yElQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png" width="630" height="364.9078850405306" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:786,&quot;width&quot;:1357,&quot;resizeWidth&quot;:630,&quot;bytes&quot;:229287,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204546764?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yElQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png 424w, https://substackcdn.com/image/fetch/$s_!yElQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png 848w, https://substackcdn.com/image/fetch/$s_!yElQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png 1272w, https://substackcdn.com/image/fetch/$s_!yElQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe36276e0-bb73-4ee0-a5d5-c69df9640f01_1357x786.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The OWASP LLM Top 10 and AIVSS represent complementary efforts from the same organization. The Top 10 identifies and ranks the most critical risks, with prompt injection at the top. AIVSS provides the scoring methodology to quantify the severity of specific instances of those risks. Together they form the beginning of a governance stack for AI security that mirrors what OWASP built for web application security over the past two decades with the original Top 10 and its associated testing guides.</p><p>The AIVSS founding membership is notable, but I&#8217;m bias, as I&#8217;m among them. It also includes representatives from NIST, NSA, Google, Microsoft, Anthropic, AWS, JP Morgan, MIT, CISA, Gartner, MITRE, and Scale AI. Apostol Vassilev, the NIST scientist who proved that jailbreaks can never be fully eliminated, sits on both the founding membership and the Distinguished Review Board. The framework is being built by people who understand both the AI safety problem and the mathematical limits of any solution.</p><h2>Where This Framework Should Live</h2><p>One of the most important questions about a jailbreak severity framework is governance. Anthropic is drafting theirs with other frontier labs, which makes sense as a starting point. But a framework that is owned and maintained by the companies whose models are being evaluated will face the same credibility questions that would arise if software vendors maintained their own vulnerability scoring systems (and some do).</p><p>The most effective path would be for this work to converge with existing industry efforts at organizations like OWASP, the Cloud Security Alliance, or the Coalition for Secure AI (CoSAI). These organizations have the governance structures, the multi-stakeholder participation, and the credibility to maintain a framework that the broader practitioner community will trust and adopt. OWASP&#8217;s AIVSS is the most natural home given its existing scope and the caliber of its membership, but the CSA&#8217;s work connecting the Vassilev proof to practical monitoring guidance and CoSAI&#8217;s focus on AI security standards both represent viable paths.</p><p>The worst outcome would be fragmentation, where every frontier lab maintains its own severity taxonomy, every regulator invents their own assessment criteria, and practitioners are left translating between incompatible frameworks. </p><p>The vulnerability management community lived through exactly this before CVSS emerged as a common standard, and the wasted effort and inconsistent prioritization that resulted should serve as a cautionary tale.</p><h2>What This Means for Practitioners</h2><p>The practical takeaway is that jailbreaks are entering the same lifecycle that software vulnerabilities went through over the past two decades. They started as novel, surprising events. They are becoming routine, expected, and manageable through structured processes. The industry is building the scoring, classification, and response frameworks that will define how organizations handle jailbreaks at scale.</p><p>For practitioners deploying AI systems today, this means several things. First, accept that jailbreaks are a permanent feature of AI systems, not a bug that will be patched away. NIST has proven this mathematically and Anthropic, OpenAI, and OWASP have all acknowledged it publicly. </p><blockquote><p><strong>Any vendor telling you their model is fully jailbreak-proof is selling something that cannot exist.</strong></p></blockquote><p>Second, start thinking about jailbreak response the same way you think about vulnerability management. Not every jailbreak is equally severe. Anthropic&#8217;s five-tier taxonomy, ranging from minor intrusions into the safety margin all the way to universal jailbreaks that unblock entire classes of harmful behavior, provides a useful starting framework. The severity of a jailbreak depends on what capability it unlocks, how broadly it applies, how easy it is to weaponize, and how widely the technique is known. Organizations need triage processes for jailbreaks the same way they have triage processes for CVEs.</p><p>Third, watch the framework convergence carefully. Whether the industry coalesces around Anthropic&#8217;s four-criteria model, OWASP&#8217;s AIVSS, or something that combines elements of both will determine how practitioners communicate about AI risk for years to come. Engage with these efforts now rather than waiting for a standard to be imposed.</p><p>The cybersecurity industry spent twenty years learning that vulnerability severity scoring is necessary, imperfect, and only useful when combined with exploitation evidence, organizational context, and asset criticality. </p><p>The AI safety community has the opportunity to compress that learning curve dramatically. The question is whether it will, or whether it will repeat the same progression of oversimplified severity scores driving compliance-oriented responses while the actual risk distribution goes unaddressed.</p><p>Given what I have watched happen with CVSS, I am cautiously optimistic but realistic about the odds.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Exposure Management in the Age of AI]]></title><description><![CDATA[The dual nature of AI for defenders and attackers and evolving VulnMgt with Tenable's CPO]]></description><link>https://www.resilientcyber.io/p/exposure-management-in-the-age-of</link><guid isPermaLink="false">https://www.resilientcyber.io/p/exposure-management-in-the-age-of</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 06 Jul 2026 12:32:48 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/205277936/b0bf0897fb539acf4af8eddf08795f39.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Every headline wants you to believe AI has rewritten the rules of cybersecurity. </p><p><strong><a href="https://www.linkedin.com/in/ericwdoerr/">Eric Doerr</a></strong>, the Chief Product Officer at <strong><a href="https://www.tenable.com/products/tenable-one/capabilities/hexa-ai?utm_medium=referral&amp;utm_source=resilient_cyber&amp;utm_campaign=cmpn-00035853">Tenable</a></strong> a Resilient Cyber Partner, is not so sure. </p><p>After running security response at Microsoft and leading security products at Google Cloud, he came on to separate the genuine transformation from the noise, and his read is refreshingly grounded. </p><p>The tools changed, but the fundamentals did not, and the teams that win are the ones who finally act on that.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><div id="youtube2-e6mY2Yspgq8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;e6mY2Yspgq8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/e6mY2Yspgq8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tenable.com/products/tenable-one/capabilities/hexa-ai?utm_medium=referral&amp;utm_source=resilient_cyber&amp;utm_campaign=cmpn-00035853&quot;,&quot;text&quot;:&quot;-> Check Out Tenable's Hexa AI <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tenable.com/products/tenable-one/capabilities/hexa-ai?utm_medium=referral&amp;utm_source=resilient_cyber&amp;utm_campaign=cmpn-00035853"><span>-&gt; Check Out Tenable's Hexa AI &lt;-</span></a></p><h2><strong>Why this conversation matters</strong></h2><p>Eric sits at a rare intersection, having lived the post-breach world of the SOC and now building the pre-breach world of exposure management. That vantage makes him a sharp guide to what AI actually shifts for defenders, from why cheaper discovery makes prioritization more valuable to how AI becomes its own attack surface once agents start touching your data. If you own vulnerability or exposure management and you are trying to spend your next dollar well, this conversation is a practical map of where the real risk lives and what to automate first.</p><p><strong>Key takeaways</strong></p><ul><li><p><strong>Attackers are ruthlessly economical.</strong> Eric calls bad actors the perfect capitalists, spending the least effort needed to hit their goal, which is why so many still get in through unpatched basics rather than anything AI-powered.</p></li><li><p><strong>AI has not rewritten the offense-defense balance.</strong> The attacker only ever had to be right once, layered defense and zero trust still hold, and the real lever is accelerating your program with fewer human loops rather than lamenting the asymmetry.</p></li><li><p><strong>Cheaper discovery makes context more valuable, not less.</strong> Reachability and exploitability mean most findings are not worth chasing, so as AI floods teams with more of them, telling the truly scary hundred from the theoretical ten thousand becomes the whole game.</p></li><li><p><strong>Being too small to target is a strategy on borrowed time.</strong> As automation drives the cost of attacks toward zero, the quiet bet that adversaries will hit weaker neighbors stops paying off, and Eric would move off that mentality now.</p></li><li><p><strong>Humans should not be the bottleneck on every fix.</strong> Getting the workflow and tooling right is most of the work, and the rest is the organizational willingness to let validated automation act, even when a business partner would feel better with a human in the loop.</p></li><li><p><strong>AI is special and not special at the same time.</strong> It is mostly just another attack surface, and Eric estimates 80 to 90 percent of securing it maps to patterns the industry already learned during the move to cloud.</p></li><li><p><strong>Shadow AI is the first surprise in almost every environment.</strong> When teams scan the endpoints they already interrogate for AI artifacts, nearly all of them find something they never sanctioned, which is why discovery has to come before control.</p></li><li><p><strong>The real AI risk is interconnection.</strong> A misconfigured database was a needle in a haystack until you wire it to an agent, and then a harmless question about the budget quietly returns data the asker should never see.</p></li><li><p><strong>Most breaches are not even CVEs.</strong> Citing the Verizon DBIR, Eric notes roughly two-thirds of breaches trace to misconfigurations, and since about a third of Tenable&#8217;s findings are non-CVE, a third of your findings can carry two-thirds of your risk.</p></li><li><p><strong>Agentic automation is finally killing the toil.</strong> Early users are automating drudgery like asset tagging and full remediation workflows, with one manufacturing customer letting automation handle 80 to 90 percent and scheduling the rest for change windows with a human notified.</p></li></ul><h2><strong>Notable quotes</strong></h2><blockquote><p>&#8220;Bad actors are the most perfect representation of capitalism&#8221;</p></blockquote><p>Eric Doerr, on why attackers do the least work necessary and often skip AI entirely.</p><blockquote><p>&#8220;a third of their findings are two-thirds of their risk&#8221;</p></blockquote><p>Eric Doerr, on why misconfigurations, not CVEs, drive most breaches.</p><blockquote><p>&#8220;you&#8217;re on the wrong side of history&#8221;</p></blockquote><p>Eric Doerr, on insisting a human eyeball every automated fix.</p><h2><strong>Listen and Watch</strong></h2><p><strong><a href="https://youtu.be/e6mY2Yspgq8?si=1tYtDacGdn2qHnCu">YouTube</a></strong></p><p><strong><a href="https://open.spotify.com/episode/5uZLzT4YGTe8LRXzbZN9Ru?si=nEFxQ2pcRHCyqI_y_SmSWA">Spotify</a></strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/why-finding-vulnerabilities-was-never-the-hard-part/id1555928024?i=1000775527123">Apple Podcasts</a></strong></p><h2><strong>Resources</strong></h2><p><strong><a href="https://www.linkedin.com/in/ericwdoerr/">Eric Doerr on LinkedIn</a></strong></p><p><strong><a href="https://www.tenable.com/products/tenable-one/capabilities/hexa-ai?utm_medium=referral&amp;utm_source=resilient_cyber&amp;utm_campaign=cmpn-00035853">Tenable AI Exposure and Hexa AI, part of Tenable One</a></strong></p><h2><strong>Subscribe</strong></h2><p>If this kind of grounded, signal-over-noise take on exposure management is useful to you, subscribe to Resilient Cyber for more conversations and writing on cybersecurity, AI, and the forces that shape both.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #104]]></title><description><![CDATA[Fable 5 Makes Its Comeback, Linux Foundation Launches Akrites, Winning AI Cyber Safety via Adoption, not Restriction, Mapping Cyber Eval Benchmarks & GitHub Advisory Database Hits Record Volume]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-104</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-104</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 02 Jul 2026 12:03:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QagB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #104 of the Resilient Cyber Newsletter! </p><p>Three weeks ago, the Commerce Department ordered Anthropic to shut down Fable 5 for all users worldwide. This week, Fable 5 is back. Anthropic announced the redeployment starting July 1 with new safety classifiers, CAISI-validated safeguards, and a proposed industry framework for scoring jailbreak severity. The twist that nobody saw coming? Amazon&#8217;s own testing confirmed the same behaviors they reported in Fable 5 exist in every frontier model they tested, including GPT-5.4, GPT-5.5, and their own.</p><p>The bigger story this week is what happened while Fable 5 was offline. China&#8217;s 360 Security Technology unveiled tools they claim reach parity. The WSJ reported Chinese AI matching Anthropic on specific cybersecurity benchmarks, and enterprise customers started migrating to cheaper open-weight alternatives, with Chinese models now accounting for over 60% of tokens on the largest neutral router. Clayton Christensen&#8217;s disruptive innovation framework, which <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Howard Yu&quot;,&quot;id&quot;:11936260,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/832b0a37-34f6-44ad-8620-5ffacd097657_941x941.png&quot;,&quot;uuid&quot;:&quot;bd84a161-a884-456d-b6a9-e199eacf5e8e&quot;}" data-component-name="MentionToDOM"></span> <strong><a href="https://howardyu.substack.com/p/how-a-30-year-old-chart-explains">recently revisited</a></strong>, is playing out in real time. The low-end disruptors are not waiting for permission.</p><p>Meanwhile, two separate Claude Code vulnerabilities were published in the same week, the Linux Foundation launched Akrites as the largest coordinated open-source defense effort in history, and Anthropic&#8217;s Mythos reportedly found vulnerabilities in classified U.S. government systems within hours.</p><p>So sit back, and let&#8217;s dig into what feels sometimes like a soap opera coupled with technology.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QagB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QagB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png 424w, https://substackcdn.com/image/fetch/$s_!QagB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png 848w, https://substackcdn.com/image/fetch/$s_!QagB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png 1272w, https://substackcdn.com/image/fetch/$s_!QagB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QagB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png" width="1222" height="729" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:729,&quot;width&quot;:1222,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:663867,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QagB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png 424w, https://substackcdn.com/image/fetch/$s_!QagB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png 848w, https://substackcdn.com/image/fetch/$s_!QagB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png 1272w, https://substackcdn.com/image/fetch/$s_!QagB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F470197ad-e97f-4326-bbbf-e3e0253b5d98_1222x729.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><h3><strong><a href="https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_july_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=">Most teams find the authorization gap after the breach, not before.</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_july_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!owSa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 424w, https://substackcdn.com/image/fetch/$s_!owSa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 848w, https://substackcdn.com/image/fetch/$s_!owSa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 1272w, https://substackcdn.com/image/fetch/$s_!owSa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!owSa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png" width="686" height="376.4519230769231" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:686,&quot;bytes&quot;:856893,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_july_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!owSa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 424w, https://substackcdn.com/image/fetch/$s_!owSa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 848w, https://substackcdn.com/image/fetch/$s_!owSa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 1272w, https://substackcdn.com/image/fetch/$s_!owSa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The gap between what your compliance documentation says your authorization program does and what actually runs in production widens every time you add a service, a workload or an agent. </p><p>It usually surfaces during an audit or an incident, which is the worst time to find it.</p><p>The <a href="https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_july_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=">Authorization Maturity Model</a> is a new ebook by Alex Olivier, Cerbos CPO and co-chair of OpenID AuthZEN. It gives security leaders a 4-stage benchmark and a self-assessment to see where their program actually stands, an exposure rating across NIS2, DORA, SEC, the EU AI Act and more, and a 90-day plan to close the gap.</p><p>It also covers what good looks like at each stage, and what changes once AI agents are in production.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_july_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=&quot;,&quot;text&quot;:&quot;Download the free ebook&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_july_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term="><span>Download the free ebook</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.anthropic.com/news/redeploying-fable-5">Anthropic Redeploys Fable 5 After Export Controls Lifted</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S1_x!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S1_x!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png 424w, https://substackcdn.com/image/fetch/$s_!S1_x!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png 848w, https://substackcdn.com/image/fetch/$s_!S1_x!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png 1272w, https://substackcdn.com/image/fetch/$s_!S1_x!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S1_x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png" width="641" height="231" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7d242c6-6d36-4c09-8474-39d289e09316_641x231.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:231,&quot;width&quot;:641,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20302,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S1_x!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png 424w, https://substackcdn.com/image/fetch/$s_!S1_x!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png 848w, https://substackcdn.com/image/fetch/$s_!S1_x!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png 1272w, https://substackcdn.com/image/fetch/$s_!S1_x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d242c6-6d36-4c09-8474-39d289e09316_641x231.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The Fable 5 saga that I covered in detail in issue #102 has reached its resolution, at least for now. Anthropic announced that Claude Fable 5 returns July 1 across Claude Platform, Claude.ai, Claude Code, and Claude Cowork after the Commerce Department lifted export controls on June 30. </p><p>The post provides extensive detail on what happened behind the scenes. Amazon&#8217;s security researchers identified a safeguard bypass, and when Anthropic tested the same technique against every frontier model available, including Haiku 4.5, every version of Opus, GPT-5.4, GPT-5.5, and Kimi K2.7, the same behaviors were replicable across the board. A new safety classifier now blocks the reported technique in over 99% of cases, and CAISI (within NIST) independently tested and confirmed the safeguards are &#8220;<em>extraordinarily strong</em>.&#8221;</p><p>The most significant outcome is not the model returning but the industry infrastructure emerging from the crisis. Anthropic is partnering with Amazon, Microsoft, Google, and Glasswing partners to develop a consensus jailbreak severity framework with four scoring criteria (capability gain, breadth, ease of weaponization, and discoverability), essentially building the CVSS equivalent for AI jailbreaks. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wm9c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wm9c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png 424w, https://substackcdn.com/image/fetch/$s_!wm9c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png 848w, https://substackcdn.com/image/fetch/$s_!wm9c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png 1272w, https://substackcdn.com/image/fetch/$s_!wm9c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wm9c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png" width="1030" height="658" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:658,&quot;width&quot;:1030,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:213384,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wm9c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png 424w, https://substackcdn.com/image/fetch/$s_!wm9c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png 848w, https://substackcdn.com/image/fetch/$s_!wm9c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png 1272w, https://substackcdn.com/image/fetch/$s_!wm9c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f3beef5-29f4-40f6-905f-fe07342b5c15_1030x658.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A new HackerOne program for cyber jailbreak submissions has been launched, and Anthropic has committed to pre-release government access and rapid information sharing. </p><p>Whether you think the original export control was warranted or not, the institutional response, a severity framework, coordinated disclosure, and independent validation, is exactly the kind of governance infrastructure this industry has been missing but there is a lot of warranted skepticism in terms of what this turns into, and how it is handled.</p><p>There are also a lot of unintended consequences of how this plays out, which I tried to capture in the video below:</p><div id="youtube2-jsB4lCl-5S4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;jsB4lCl-5S4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/jsB4lCl-5S4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://akrites.org/letter/">Linux Foundation Launches Akrites as the Largest Coordinated Open Source Defense Effort in History</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hHco!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hHco!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png 424w, https://substackcdn.com/image/fetch/$s_!hHco!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png 848w, https://substackcdn.com/image/fetch/$s_!hHco!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png 1272w, https://substackcdn.com/image/fetch/$s_!hHco!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hHco!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png" width="740" height="244" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:244,&quot;width&quot;:740,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:25522,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hHco!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png 424w, https://substackcdn.com/image/fetch/$s_!hHco!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png 848w, https://substackcdn.com/image/fetch/$s_!hHco!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png 1272w, https://substackcdn.com/image/fetch/$s_!hHco!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20cd13c5-a8e4-4e57-8bb3-274b6f6262c8_740x244.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is one of the most important announcements I have covered this year related to open source security. Akrites, a new Linux Foundation project, brings together 20+ founding members including AWS, Anthropic, Cisco, Google, IBM, JPMorgan Chase, Microsoft, NVIDIA, OpenAI, Red Hat, and Zscaler to find, fix, and responsibly disclose vulnerabilities in critical open source software. </p><p>The coalition will serve as &#8220;maintainer of last resort&#8221; for unmaintained critical packages, committing engineering talent, funding, and a shared Security Incident Response Team to work upstream with maintainers. </p><p>The numbers driving the urgency are stark. OpenInfra Foundation reported 20 security advisories in one quarter of 2026 versus only 2 in all of 2025, a 10x increase. Endor Labs found that of thousands of validated open-source vulnerabilities surfaced recently, fewer than 5% have been patched. </p><p>AI has made vulnerability discovery trivially fast, but remediation remains a human-speed bottleneck, and Akrites is the most serious attempt to date to close that gap at scale.</p><p>I spoke about this at length in countless blogs and in my book Software Transparency, where I made the case that open source is critical infrastructure but suffers from the tragedy of a digital commons.</p><h3><a href="https://www.reuters.com/business/anthropics-mythos-model-found-vulnerabilities-classified-us-government-systems-2026-06-24/">Anthropic&#8217;s Mythos Found Vulnerabilities in Classified U.S. Government Systems Within Hours</a></h3><p>Senator Mark Warner disclosed that NSA chief Joshua Rudd told him Mythos &#8220;broke into almost all of our classified systems, not in weeks, but in hours&#8221; during a testing exercise through Project Glasswing, Anthropic&#8217;s collaboration with U.S. intelligence agencies. </p><p>The distinction between identifying and exploiting vulnerabilities matters here, but the speed at which Mythos mapped attack surfaces across the government&#8217;s most sensitive systems speaks to the capability gap I have been tracking all year. </p><p>This disclosure came amid ongoing tensions between Anthropic and the Trump administration over military AI use, and it adds a complicated layer to the Fable 5 re-release debate. The same model that defenders desperately want access to is the same one that found its way through classified system defenses in hours.</p><p>All of this said, there has been several who have pointed out how this story is very hyperbolic and there is <em>a lot</em> of nuance to the claimed headline, and it is more clickbait then reality.</p><h3><a href="https://www.cnbc.com/2026/06/26/openai-anthropic-new-ai-spending-reality-as-users-shift-to-efficiency.html">AI Spending Hits a Wall as Enterprises Shift from &#8220;Tokenmaxxing&#8221; to Efficiency</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mj7_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mj7_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png 424w, https://substackcdn.com/image/fetch/$s_!mj7_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png 848w, https://substackcdn.com/image/fetch/$s_!mj7_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png 1272w, https://substackcdn.com/image/fetch/$s_!mj7_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mj7_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png" width="926" height="211" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:211,&quot;width&quot;:926,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:37286,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mj7_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png 424w, https://substackcdn.com/image/fetch/$s_!mj7_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png 848w, https://substackcdn.com/image/fetch/$s_!mj7_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png 1272w, https://substackcdn.com/image/fetch/$s_!mj7_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73997b96-1c11-49e2-a723-e2cdaf505098_926x211.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The spending correction I have been expecting is arriving. The top 1% of companies spend $89,000 per engineer per year on AI while the median spends just $137, a 680x gap that is starting to close from both directions. </p><p>Uber burned through its entire 2026 AI token budget in four months and had to implement monthly tiers. Lindy switched entirely to cheaper open-weight alternatives, expecting millions in savings. </p><p>On OpenRouter, Chinese models went from roughly 1% of usage in 2024 to over 60% in May 2026. <strong><a href="https://www.linkedin.com/pulse/when-ai-costs-more-than-engineer-tomasz-tunguz-gwxjc">Tomasz Tunguz models</a></strong> three scenarios where by 2029, per-engineer AI spend ranges from $106,000 (bear) to $596,000 (bull), with the bull case matching an entire median-SaaS employee&#8217;s revenue contribution. Security budgets flow downstream of engineering budgets, and this spending recalibration will shape procurement decisions for the next two years.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!weLR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!weLR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png 424w, https://substackcdn.com/image/fetch/$s_!weLR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png 848w, https://substackcdn.com/image/fetch/$s_!weLR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png 1272w, https://substackcdn.com/image/fetch/$s_!weLR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!weLR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png" width="599" height="301.35105067985165" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:407,&quot;width&quot;:809,&quot;resizeWidth&quot;:599,&quot;bytes&quot;:335104,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!weLR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png 424w, https://substackcdn.com/image/fetch/$s_!weLR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png 848w, https://substackcdn.com/image/fetch/$s_!weLR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png 1272w, https://substackcdn.com/image/fetch/$s_!weLR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F749c92fb-0546-487a-94ff-5bfd5574957f_809x407.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://joshuasaxe181906.substack.com/p/ai-cybersecurity-safety-will-be-won">Joshua Saxe Argues AI Cybersecurity Safety Will Be Won Through Adoption, Not Restriction</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZR5g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZR5g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png 424w, https://substackcdn.com/image/fetch/$s_!ZR5g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png 848w, https://substackcdn.com/image/fetch/$s_!ZR5g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png 1272w, https://substackcdn.com/image/fetch/$s_!ZR5g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZR5g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png" width="1456" height="563" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:563,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:222974,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZR5g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png 424w, https://substackcdn.com/image/fetch/$s_!ZR5g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png 848w, https://substackcdn.com/image/fetch/$s_!ZR5g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png 1272w, https://substackcdn.com/image/fetch/$s_!ZR5g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf35423a-87ca-4f1e-bdc0-955ac425dcb4_1541x596.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the clearest articulation I have seen of the case against restricting frontier AI models from defenders. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;bf28551e-5213-4e51-baff-56317d5e5efa&quot;}" data-component-name="MentionToDOM"></span> argues that the dominant framework of measuring model capabilities at launch and restricting access at danger thresholds is now invalidated because capability diffusion has been lost to the geopolitical AI race with China. </p><p>Attackers already have private access to near-frontier models like GLM-5.2. There are 100x more defenders than attackers, and defenders control 100x more GPUs. The winning strategy is not to restrict American models but to ensure defenders adopt AI faster and better than attackers do. </p><p>Whether you fully agree or not, the core logic is hard to argue with. Denying your own side a weapon that the other side already has is not a strategy. I covered this in depth below, citing Josh&#8217;s writing on the topic as well, and I hope to have Josh on my Resilient Cyber show soon to dive into all of it.</p><div id="youtube2-cj2FQoPKe_I" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;cj2FQoPKe_I&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/cj2FQoPKe_I?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://www.philvenables.com/post/sorry-cyber-you-aren-t-the-only-ones-saving-the-company-from-itself">Phil Venables Applies Clegg&#8217;s Circuits of Power to Cybersecurity Organizational Dynamics</a></h3><p>Venables offers 21 examples of non-security control functions (finance, safety, legal, HR) pushing back against risky business decisions and introduces sociologist Stewart Clegg&#8217;s 1989 &#8220;Circuits of Power&#8221; framework as a lens for understanding why security controls succeed or fail. </p><p>The three circuits are episodic (day-to-day interpersonal), dispositional (rules and culture), and facilitative (infrastructure and automated enforcement). His core argument is that security teams burn out because they fight episodic battles using only dispositional arguments, when the real fix is building facilitative circuits that make the secure path the easiest path. </p><p>If you are a CISO tired of holding the line through sheer force of will, this framework gives you a vocabulary for the structural changes that actually stick.</p><h3><a href="https://www.jpmorgan.com/insights/banking/commercial-banking/ai-cybersecurity-threats-funding-and-builder-priorities">JPMorgan Reports NHIs Outnumber Human Identities 144-to-1 as AI Cybersecurity Venture Funding Hits $11.5B</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EhUv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EhUv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png 424w, https://substackcdn.com/image/fetch/$s_!EhUv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png 848w, https://substackcdn.com/image/fetch/$s_!EhUv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png 1272w, https://substackcdn.com/image/fetch/$s_!EhUv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EhUv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png" width="341" height="209" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:209,&quot;width&quot;:341,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21198,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EhUv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png 424w, https://substackcdn.com/image/fetch/$s_!EhUv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png 848w, https://substackcdn.com/image/fetch/$s_!EhUv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png 1272w, https://substackcdn.com/image/fetch/$s_!EhUv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ace4363-7b7f-4bcf-8840-2d814f5da760_341x209.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>JPMorgan&#8217;s Innovation Economy group produced a comprehensive market report with several data points worth bookmarking. </p><p>Non-human identities outnumber human identities 144-to-1 in enterprises, growing 44% year-over-year. AI agents operating inside enterprise environments grew 466.7% year-over-year. </p><p>U.S. cybersecurity venture funding hit $11.5 billion in 2025 (highest since 2022), with 72% of deals involving AI-enabled companies, up from 36% in 2019. AI-related vulnerabilities surged from 439 in 2024 to 2,185 in 2025, and 36% of all published AI vulnerabilities involve APIs. </p><p>The competitive frontier, JPMorgan notes, is shifting from detection to remediation, and products that orchestrate fixes while preserving human oversight are gaining the most traction.</p><h3><a href="https://www.linkedin.com/posts/damienlewke_today-were-announcing-nebulocks-25m-series-share-7475897098580803585-JqG0/">Nebulock Raises $25M for Hunt-First Security Operations</a></h3><p>Nebulock&#8217;s $25M Series A, led by FirstMark, funds an autonomous threat hunting platform that has already run 300 million+ agentic investigations and produced 4,000+ high-confidence findings. </p><p>The company argues that reactive, alert-based security operations are fundamentally broken, citing data that enterprise SIEMs miss roughly 79% of MITRE ATT&amp;CK techniques and 13% of SIEM rules are broken and will never fire. New capabilities include insider risk management that unifies human and AI agent identities. </p><p>The &#8220;hunt-first&#8221; positioning is a direct response to attacker strategies that increasingly rely on valid credentials and blending into normal activity rather than triggering traditional detection signatures. I&#8217;m impressed with the Founder of Nebulock and will be keeping an eye on the team.</p><h3><a href="https://ashugarg.substack.com/p/ais-winner-take-all-era-is-over">Ashu Garg Declares AI&#8217;s Winner-Take-All Era Over</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_WwA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_WwA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png 424w, https://substackcdn.com/image/fetch/$s_!_WwA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png 848w, https://substackcdn.com/image/fetch/$s_!_WwA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png 1272w, https://substackcdn.com/image/fetch/$s_!_WwA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_WwA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png" width="528" height="90" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:90,&quot;width&quot;:528,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:15464,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_WwA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png 424w, https://substackcdn.com/image/fetch/$s_!_WwA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png 848w, https://substackcdn.com/image/fetch/$s_!_WwA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png 1272w, https://substackcdn.com/image/fetch/$s_!_WwA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F814ee6cb-98a9-4f4e-9559-cd61d04c5933_528x90.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Foundation Capital&#8217;s <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ashu Garg&quot;,&quot;id&quot;:2158736,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4472ea87-89f9-4b14-bb57-3e6ebb5f2924_1000x1000.jpeg&quot;,&quot;uuid&quot;:&quot;26af5dc5-8ae1-4dfb-8d5b-079d85e2a6a7&quot;}" data-component-name="MentionToDOM"></span> argues that the AI market&#8217;s presumed winner-take-all dynamic is not materializing, and the implications for security are significant. </p><p>Four roughly equal players (OpenAI, Anthropic, Google, xAI) are competing, advances are quickly copied through distillation, and regulatory forces are fragmenting access geopolitically. DeepSeek scores within striking distance of Opus on SWE-bench at roughly 1/30th the price, and open-source alternatives are available at 1/100th. Infrastructure platforms like Databricks and Snowflake are going model-agnostic with single-toggle LLM swapping. </p><p>The real moat, Garg argues, is not the model but the product layer built on top. For security leaders, this reinforces what the Fable 5 saga demonstrated in practice. Never build a critical dependency on a single model provider.</p><h3><a href="https://futurism.com/artificial-intelligence/software-engineers-crisis-drown-ai-code">Software Engineers Face an Identity Crisis as AI Code Quality Collapses</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SXIU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SXIU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png 424w, https://substackcdn.com/image/fetch/$s_!SXIU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png 848w, https://substackcdn.com/image/fetch/$s_!SXIU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png 1272w, https://substackcdn.com/image/fetch/$s_!SXIU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SXIU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png" width="1380" height="117" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:117,&quot;width&quot;:1380,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:36742,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SXIU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png 424w, https://substackcdn.com/image/fetch/$s_!SXIU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png 848w, https://substackcdn.com/image/fetch/$s_!SXIU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png 1272w, https://substackcdn.com/image/fetch/$s_!SXIU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F530571a8-2a9c-41bc-9f05-961a5200f296_1380x117.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Menlo Ventures partner Deedy Das described what he sees as an identity crisis &#8220;bordering on depression&#8221; among experienced software engineers. </p><p>The piece captures a growing cultural divide between &#8220;vibe coders&#8221; who accept AI output uncritically and veteran engineers who spend their days cleaning up what the article calls &#8220;workslop,&#8221; shoddy AI outputs passed between colleagues creating an illusion of productivity. Companies like Meta are now factoring AI usage into performance reviews. One unnamed firm reportedly spent $500 million on Claude in a single month. </p><p>The Faros AI data I covered in issue #102 (861% code churn increase, tripled production incidents) puts numbers behind the anecdotal misery described here. The security implications remain the same. More code, less review, more bugs.</p><div><hr></div><h1>AI</h1><h3><a href="https://github.com/Metnew/write-ups/tree/main/claude-code-worktree-sandbox-escape">Claude Code Sandbox Escape Achieves Unsandboxed Code Execution via Git Worktree Path Confusion</a></h3><p>CVE-2026-55607, scored 7.7 High, exploited git worktree path confusion and symlink manipulation to escape Claude Code&#8217;s most hardened macOS seatbelt sandbox. </p><p>The full attack chain is elegant in a terrifying way. A malicious repository&#8217;s CLAUDE.md used prompt injection to guide Claude through its own legitimate worktree tools, creating a worktree named &#8220;.git&#8221; that caused directory confusion, then pivoting via symlink from .claude/worktrees to the user&#8217;s home directory, and finally writing to ~/.zshenv, which executes before sandbox profiles are applied. </p><p>The researcher demonstrated it by opening Calculator on macOS from inside the sandbox. The vulnerability was patched in v2.1.163, and <strong><a href="https://www.linkedin.com/posts/v6r_claude-code-sandbox-escape-from-the-most-ugcPost-7476283192132554753-9s2n/">Anthropic awarded a bounty through HackerOne</a></strong>. </p><p>The broader lesson is that AI coding agents need threat models closer to browsers and package managers than chatbots. Every &#8220;normal&#8221; development operation the agent performs is a potential step in an attack chain.</p><h3><a href="https://bloom.security/blog/welcome-to-otel-claudeifornia">Bloom Security Discloses &#8220;OTEL Smuggling&#8221; RCE in Claude Code&#8217;s OpenTelemetry Pipeline</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HYvV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HYvV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png 424w, https://substackcdn.com/image/fetch/$s_!HYvV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png 848w, https://substackcdn.com/image/fetch/$s_!HYvV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png 1272w, https://substackcdn.com/image/fetch/$s_!HYvV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HYvV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png" width="1305" height="416" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:416,&quot;width&quot;:1305,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:570846,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HYvV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png 424w, https://substackcdn.com/image/fetch/$s_!HYvV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png 848w, https://substackcdn.com/image/fetch/$s_!HYvV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png 1272w, https://substackcdn.com/image/fetch/$s_!HYvV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0548d0-ea74-499c-aba8-e394d864167b_1305x416.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The second Claude Code vulnerability published this week is arguably more concerning than the first because it has no fix on the horizon. </p><p>A 21-line malicious .claude/settings.json file committed to any git repository can silently weaponize Claude Code&#8217;s OpenTelemetry pipeline to exfiltrate user PII, session prompts, API responses, and environment secrets to attacker-controlled infrastructure. </p><p>The otelHeadersHelper feature is an unconditional code execution primitive that runs at session start and every 29 minutes. The attack can persist machine-wide by poisoning the global ~/.claude/settings.json. Bloom Security found that the top 5 skills marketplaces contain over 5,000 skills referencing OTEL, and hundreds of repositories already have OTEL configurations in their .claude/settings.json files.</p><p>Anthropic disagrees with the severity characterization, pointing to workspace trust as the security boundary. But the trust dialog does not surface OTEL settings as a risk category, and most users have pre-approved via parent directory inheritance.</p><h3><a href="https://www.wsj.com/tech/ai/chinese-ai-anthropic-mythos-cybersecurity-574b02c2">Chinese AI Labs Claim Parity with Mythos on Cybersecurity Tasks</a></h3><p>Two developments this week underscore how fast the capability gap is narrowing. Independent benchmarks from Semgrep and Graphistry show GLM-5.2 scoring 39% F1 on IDOR detection versus Claude Code&#8217;s 32-37%, with the caveat that GLM-5.2 still trails on general-purpose benchmarks. </p><p>Meanwhile, <a href="https://www.reuters.com/legal/litigation/chinas-360-says-it-has-developed-tools-match-anthropics-mythos-2026-06-24/">360 Security Technology unveiled</a> &#8220;Tulongfeng&#8221; at ISC.AI 2026 in Beijing, claiming 3,432 software vulnerabilities found with 105 confirmed by Chinese authorities. Founder Zhou Hongyi acknowledged a 20-30% gap in Chinese base model capability versus U.S. rivals but framed the effort as a national security imperative, arguing China faces &#8220;one-way transparency&#8221; risk if only American entities can scan systems. </p><p>The practical implication is clear. Whatever capability advantage the Fable 5 export controls were meant to protect has eroded faster than anyone expected.</p><h3><a href="https://stanislavfort.substack.com/p/mythos-at-home-and-its-called-aisle">AISLE Proves Open Models Can Match Mythos at Zero-Day Discovery</a></h3><p>I mentioned AISLE briefly last week in the context of GLM-5.2, but the full story deserves its own treatment. This Prague-based startup has discovered 200+ CVEs using widely available and open-source models that can run air-gapped.</p><p>On OpenSSL, AISLE found 20 of 23 zero-day vulnerabilities across three consecutive security releases. On FreeBSD (Anthropic&#8217;s own showcase codebase), AISLE matched Mythos 3 CVEs to 3, finding additional bugs after Mythos&#8217;s showcase vulnerabilities were already patched. UC Berkeley&#8217;s Vulnerability Initiative ranks AISLE number one globally in 3 of 8 categories versus Anthropic&#8217;s 1. The geopolitical weight here is unmistakable. </p><p>After the U.S. directive suspended Mythos access for non-U.S. nationals, AISLE demonstrates that world-class defensive AI vulnerability discovery does not require dependence on a single American provider. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Stanislav Fort&quot;,&quot;id&quot;:6503858,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/920622a8-11bd-4a16-a695-33775e0b72ea_1600x1338.jpeg&quot;,&quot;uuid&quot;:&quot;81585997-c8f4-48c3-a824-b10fbc328fb9&quot;}" data-component-name="MentionToDOM"></span> has an excellent blog on the topic titled &#8220;<strong><a href="https://stanislavfort.substack.com/p/mythos-at-home-and-its-called-aisle">Mythos at Home</a></strong>&#8221;. I&#8217;ve had him on my show in the past as well, where we dug into all of this:</p><div id="youtube2-J5xqeOSqs3s" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;J5xqeOSqs3s&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/J5xqeOSqs3s?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3>O<a href="https://openai.com/index/previewing-gpt-5-6-sol/">penAI Launches GPT-5.6 Model Family with Government-Coordinated Rollout</a></h3><p>OpenAI&#8217;s GPT-5.6 family arrives in three tiers. Sol (flagship), Terra (mid-tier), and Luna (fast and affordable), with pricing ranging from $5/$30 per million tokens (Sol) down to $1/$6 (Luna). </p><p>The notable departure from prior releases is the government-coordinated restricted rollout, initially limited to roughly 20 trusted partner organizations before broader availability. Sol is positioned as OpenAI&#8217;s most capable model for cybersecurity applications. </p><p>The tiered approach with explicit government coordination reflects the new post-Fable reality where frontier model releases are no longer treated as routine product launches but as events with national security implications.</p><h3><a href="https://arxiv.org/abs/2606.18193">Automated Red-Team Study Finds Frontier Models Reliably Breakable Under Sustained Pressure</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KU3N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KU3N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png 424w, https://substackcdn.com/image/fetch/$s_!KU3N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png 848w, https://substackcdn.com/image/fetch/$s_!KU3N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png 1272w, https://substackcdn.com/image/fetch/$s_!KU3N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KU3N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png" width="581" height="306.6619115549215" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:370,&quot;width&quot;:701,&quot;resizeWidth&quot;:581,&quot;bytes&quot;:255458,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KU3N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png 424w, https://substackcdn.com/image/fetch/$s_!KU3N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png 848w, https://substackcdn.com/image/fetch/$s_!KU3N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png 1272w, https://substackcdn.com/image/fetch/$s_!KU3N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a045ff7-a794-4a06-8458-b3a3da680f02_701x370.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Dr. Nicola Franco at AI4I subjected Opus 4.8 and Fable 5 to hundreds of thousands of automated jailbreak attempts using the HackAgent framework across 7,826 harmful intents. </p><p>The best attack (tree-of-attacks search) broke Opus 4.8 on 11.5% of intents and Fable 5 at 6.1%, producing over 2,300 confirmed harmful completions across every harm category. The most concerning finding is not the success rate but the economics. Successful attacks arrived within the first 1-2 refinement steps, meaning they are cheap and fast to discover automatically. </p><p>Static obfuscation techniques were nearly fully neutralized (under 0.2% despite roughly 50,000 attempts), but adaptive attacks remain effective. The worst categories for Opus were child safety (27.6% success), cybersecurity and phishing (16.6%), and criminal and economic harms (14.7%).</p><h3><a href="https://eugeneyan.com/writing/cybersecurity-evals/">Eugene Yan Maps the Patterns Behind Cybersecurity Evaluation Benchmarks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kqZl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kqZl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png 424w, https://substackcdn.com/image/fetch/$s_!kqZl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png 848w, https://substackcdn.com/image/fetch/$s_!kqZl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png 1272w, https://substackcdn.com/image/fetch/$s_!kqZl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kqZl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png" width="787" height="367" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8d12e79-93d4-4b78-9459-f0568965f163_787x367.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:367,&quot;width&quot;:787,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:81640,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kqZl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png 424w, https://substackcdn.com/image/fetch/$s_!kqZl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png 848w, https://substackcdn.com/image/fetch/$s_!kqZl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png 1272w, https://substackcdn.com/image/fetch/$s_!kqZl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8d12e79-93d4-4b78-9459-f0568965f163_787x367.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the most useful survey of AI cybersecurity evaluation methodologies published to date. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Eugene Yan&quot;,&quot;id&quot;:3410701,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc48525b0-e036-443d-a032-f37f5d2a7332_738x738.png&quot;,&quot;uuid&quot;:&quot;1af7843e-50e8-4035-8338-753f30d3a22a&quot;}" data-component-name="MentionToDOM"></span> (Anthropic staff) reviews seven benchmarks and identifies a common four-component pattern across all of them, specifically sandboxed targets, difficulty-tuning inputs, tools, and graders. </p><p>The standout data points across the benchmarks tell a clear story. Claude Mythos exploited 157 of 898 instances on ExploitGym (GPT-5.5 got 120). With the Incalmo framework, agents succeeded on 37 of 40 networks including a 50-host Equifax replica, and 10 models generated working exploits for 207 of 405 smart contracts, draining a simulated $550 million. </p><p>The evaluation cost alone exceeded $40,000 in API credits and 1,000 H100 GPU hours, which tells you something about the resources required to do this work responsibly. I found this resource super insightful as someone who doesn&#8217;t have direct experience creating benchmarks but often sees them cited.</p><h3><a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-cloud-security-uses-ai-internally/">Google Cloud Details Mantis Multi-Agent Framework for Autonomous SDLC Security</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mBpO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mBpO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png 424w, https://substackcdn.com/image/fetch/$s_!mBpO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png 848w, https://substackcdn.com/image/fetch/$s_!mBpO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png 1272w, https://substackcdn.com/image/fetch/$s_!mBpO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mBpO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png" width="631" height="303.4401972872996" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:390,&quot;width&quot;:811,&quot;resizeWidth&quot;:631,&quot;bytes&quot;:263395,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mBpO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png 424w, https://substackcdn.com/image/fetch/$s_!mBpO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png 848w, https://substackcdn.com/image/fetch/$s_!mBpO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png 1272w, https://substackcdn.com/image/fetch/$s_!mBpO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1faee7-0a5f-44ad-924d-67c8153cffaf_811x390.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Google Cloud CISO Chris Betz detailed how the company has transitioned to an autonomous, AI-driven SDLC security model anchored by the Mantis framework (core skills now open-source on GitHub). </p><p>The problem Mantis solves is real. Naive decentralized AI code scanning yields true-positive rates under 7%. Mantis addresses this through multi-agent orchestration with specialized Strategist, Research, Deduplicator, Reviewer, and Critic agents, plus a reproduction sandbox that validates findings before surfacing them. </p><p>A self-reflection loop analyzes execution logs and human feedback post-workflow, creating a compounding improvement effect. The token overhead reduction is dramatic, with hierarchical security summary trees cutting costs by over 85%.</p><h3><a href="https://trustial.org/blog/rwais-2026-takeaways/">RWAIS 2026 at Stanford Reveals Industry More Focused on Defending Against Agents Than Using Them</a></h3><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Federico Maggi&quot;,&quot;id&quot;:3139629,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/91cf7198-a9f8-4acd-bf76-d97e2bfaa5a6_1080x1620.jpeg&quot;,&quot;uuid&quot;:&quot;df19d77a-8635-4f06-b35f-88be98dffae9&quot;}" data-component-name="MentionToDOM"></span> &#8217;s report from the inaugural Real World AI Security conference at Stanford captures where the practitioner community actually is versus where the vendor marketing suggests it should be. </p><p>The key finding is that most current security work focuses on securing AI agents rather than using AI for security, a defensible priority given that agents are moving into production faster than the industry is securing them. Guardrails are compared to client-side validation in web apps, necessary but insufficient, and the biggest infrastructure gap identified is confidential computing for agents. </p><p>The conference also surfaced a telling observation. AI-assisted vulnerability discovery is well advanced but AI-assisted patching remains largely unresolved, which is exactly the bottleneck that Akrites, Chainguard&#8217;s Athena, and Project Lightwell are all racing to address. </p><p>I wish I could attend the event as the agenda and talks looked excellent.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/">GitHub Advisory Database Hits Record Volume as Processing Times Extend to Weeks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nO6c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nO6c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png 424w, https://substackcdn.com/image/fetch/$s_!nO6c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png 848w, https://substackcdn.com/image/fetch/$s_!nO6c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png 1272w, https://substackcdn.com/image/fetch/$s_!nO6c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nO6c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png" width="682" height="429.8020833333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:484,&quot;width&quot;:768,&quot;resizeWidth&quot;:682,&quot;bytes&quot;:58503,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nO6c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png 424w, https://substackcdn.com/image/fetch/$s_!nO6c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png 848w, https://substackcdn.com/image/fetch/$s_!nO6c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png 1272w, https://substackcdn.com/image/fetch/$s_!nO6c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9708c4-ebba-4af9-bbae-d7e70b4e64e3_768x484.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A candid account from the GitHub advisory team shows what happens when vulnerability volume breaks records. </p><p>In May 2026, the advisory team published 1,560 reviewed advisories, more than 5x typical monthly output and the all-time high. Private vulnerability reports surged from roughly 550 per week in January to over 3,000 per week in May. Repository advisories scaled from 650 to over 5,000 per week. GitHub CNA CVE requests reached nearly 4,000 in May alone, almost 10x year-over-year. Despite the surge, all reviewed advisories remain human-validated, but processing times have stretched from days to multiple weeks. </p><p>This is the same 66,000-CVE trajectory that FIRST projected, and GitHub&#8217;s transparency about the strain is more useful than most vendor communications about the problem. I dove into this topic recently in a discussion with Jerry Gamblin, who coauthored the FIRST mid-year update:</p><div id="youtube2-nzQLQxD-GfE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;nzQLQxD-GfE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/nzQLQxD-GfE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://www.darkreading.com/vulnerabilities-threats/nist-enrichment-reductions-cve-coverage-accuracy">Dark Reading Reports NIST Enrichment Cutbacks Creating Coverage and Accuracy Gaps</a></h3><p>The NIST enrichment cutback story I covered last week now has additional data from Volerion research. </p><p>Of 13,441 non-rejected CVEs published between April 15 and June 15, only 6,759 actually received enrichment (roughly half), and only 2,645 of those also received a NIST CVSS vector. </p><p>The accuracy problems are as concerning as the coverage gaps. The most common scoring disagreement involves attack complexity, with NIST rating AC:L (low) where Volerion determined AC:H (high) in about a third of cases. One example saw NIST scoring CVE-2026-8856 at 9.1 Critical versus IBM&#8217;s own assessment of 7.7 Medium and Volerion&#8217;s assessment of 4.4 Medium. </p><p>The recommendation is to build your own decision trees rather than relying solely on CVSS scores from any single source, but that&#8217;s a massive lift for most organizations without the expertise and resources to do so.</p><h3><a href="https://www.devarmor.com/blog/securing-the-agentic-development-lifecycle">DevArmor Proposes Four-Layer Security Stack for the Agentic Development Lifecycle</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fn-f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fn-f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png 424w, https://substackcdn.com/image/fetch/$s_!Fn-f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png 848w, https://substackcdn.com/image/fetch/$s_!Fn-f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png 1272w, https://substackcdn.com/image/fetch/$s_!Fn-f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fn-f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png" width="503" height="304.33613445378154" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:360,&quot;width&quot;:595,&quot;resizeWidth&quot;:503,&quot;bytes&quot;:104479,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fn-f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png 424w, https://substackcdn.com/image/fetch/$s_!Fn-f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png 848w, https://substackcdn.com/image/fetch/$s_!Fn-f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png 1272w, https://substackcdn.com/image/fetch/$s_!Fn-f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F06491c25-7a82-427a-8c43-53cb0ba12ce7_595x360.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Traditional AppSec tooling is fundamentally inadequate for the agentic development era, and DevArmor&#8217;s proposed four-layer stack offers a useful corrective. Threat Architecture as a living context engine consumed by agents in real time, not a static compliance document. </p><p>Agent Governance with deterministic guardrails. Generation-Time Guardrails via rules files and MCP-connected services. And Adversarial Validation through continuous pen testing. The supporting data is worth noting. IDC found developers attribute 41% of code to AI generation, with roughly 40% accepted without revision. CISA found the long-standing &#8220;shift-left&#8221; claim that fixing vulnerabilities early is cheaper was never empirically validated, and Ramp&#8217;s autonomous patching pipeline patched 100 vulnerabilities in 6 days with zero human involvement. </p><p>The central insight is that threat models must evolve from static documents into structured knowledge graphs because AI agents lack the institutional context human developers carry.</p><h3><a href="https://pluto.security/blog/count-dooku-a-live-malicious-open-vsx-campaign-hiding-in-plain-sight/">Count Dooku Campaign Targets AI Developer Extensions on Open VSX Marketplace</a></h3><p>A live supply chain attack campaign published at least 45 malicious copycat extensions on the Open VSX marketplace between June 26-29. </p><p>The campaign specifically targets AI and LLM tooling (DeepSeek, Gemini, Cursor AI, Claude, Ollama extensions) alongside general developer tools. The injected code creates a persistent local identifier and beacons to attacker-controlled infrastructure, with activation changed to &#8220;onStartupFinished&#8221; for automatic execution. </p><p>The current payload is reconnaissance and tracking rather than a full infostealer, but the attack path enables future escalation. Combined with the Air.security malicious skills research I covered last week and this week&#8217;s Claude Code vulnerabilities, the pattern is clear. </p><p>Developer tooling supply chains are the new attack surface, and the AI tooling market has inherited every supply chain vulnerability that npm and PyPI already struggle with.</p><h3><a href="https://blog.zsec.uk/harnessing-harnesses/">ZSec Argues LLM Harnesses Are the Missing Layer for Effective Security Research</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IGPv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IGPv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png 424w, https://substackcdn.com/image/fetch/$s_!IGPv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png 848w, https://substackcdn.com/image/fetch/$s_!IGPv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png 1272w, https://substackcdn.com/image/fetch/$s_!IGPv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IGPv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png" width="549" height="542.8227848101266" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:703,&quot;width&quot;:711,&quot;resizeWidth&quot;:549,&quot;bytes&quot;:670459,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IGPv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png 424w, https://substackcdn.com/image/fetch/$s_!IGPv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png 848w, https://substackcdn.com/image/fetch/$s_!IGPv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png 1272w, https://substackcdn.com/image/fetch/$s_!IGPv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f97393c-e358-4bea-b668-9e15dd13288c_711x703.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Andy Gill makes the case that raw LLM prompting for security vulnerability research is &#8220;like supervising a room full of drunk toddlers&#8221; and that structured harnesses are the missing ingredient. </p><p>Using the RAPTOR framework as a primary example, the article shows how splitting work between a Python execution layer (runs tools) and a Claude Code decision layer (determines what to run and how to interpret results) can coordinate static analysis, fuzzing, and exploit generation into a coherent workflow. </p><p>The piece aligns with the broader pattern I keep seeing across Mozilla&#8217;s pipeline, Google&#8217;s Mantis, and every successful AI vulnerability discovery program. The model is necessary but not sufficient. The harness is where the real engineering happens, and this is a point AISLE, Niels Provos and many others have made now.</p><h3><a href="https://policymaker.disclose.io/policymaker/introduction/">Disclose.io Launches Free Vulnerability Disclosure Program Policy Generator</a></h3><p>Disclose.io&#8217;s Policymaker tool walks organizations through a step-by-step process to generate a complete vulnerability disclosure program, including a full VDP policy, safe harbor clause, RFC-compliant security.txt file, and DNS Security TXT records.</p><p>Organizations can achieve maturity certification up to Level 5 (Full Safe Harbor with Coordinated Disclosure) and published domains are scanned into the Disclose.io Contact Database. </p><p>With 66,000 CVEs projected this year and AI-powered vulnerability discovery accelerating, every organization needs a functioning VDP. This tool removes the &#8220;we didn&#8217;t know where to start&#8221; excuse.</p><h3><a href="https://daniel.haxx.se/blog/2026/06/26/a-curl-mountain-movie/">Daniel Stenberg Visualizes 28 Years of curl Vulnerabilities as an Animated Mountain</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OcY8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OcY8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png 424w, https://substackcdn.com/image/fetch/$s_!OcY8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png 848w, https://substackcdn.com/image/fetch/$s_!OcY8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png 1272w, https://substackcdn.com/image/fetch/$s_!OcY8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OcY8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png" width="653" height="358.17359591539025" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:752,&quot;width&quot;:1371,&quot;resizeWidth&quot;:653,&quot;bytes&quot;:137872,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/204478912?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OcY8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png 424w, https://substackcdn.com/image/fetch/$s_!OcY8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png 848w, https://substackcdn.com/image/fetch/$s_!OcY8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png 1272w, https://substackcdn.com/image/fetch/$s_!OcY8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21a16d39-a109-4438-9b8f-4e877ca8afcc_1371x752.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Following last week&#8217;s CVE dispute story, Stenberg created an animated visualization spanning 340 monthly snapshots from March 1998 to June 2026, showing how curl&#8217;s overlapping CVE version ranges have grown over time. </p><p>The mountain peaked at version 7.34.0 with 101 concurrent known vulnerabilities across 206 total CVEs. A notable drop around 2016 coincides with the Cure53 code audit and curl joining OSS-Fuzz in July 2017. </p><p>The visualization is a useful reminder that vulnerability management is not just about counting CVEs but understanding how they overlap, compound, and respond to investment in proactive security measures.</p><div><hr></div><h1>Final Thoughts</h1><p>The Fable 5 re-release closes one chapter and opens another. The export control experiment proved three things. </p><p>First, emergency restrictions on commercial AI products create collateral damage that far outweighs the security benefit when the restricted capabilities are replicable in other models. Second, the capability diffusion problem is real and accelerating, with AISLE, GLM-5.2, and 360&#8217;s tools all demonstrating that restricting American frontier models does not restrict the underlying capability. Third, the governance infrastructure that emerges from a crisis (jailbreak severity frameworks, coordinated disclosure, independent validation) is more valuable than the restriction itself.</p><p>The thread that connects this week&#8217;s biggest stories, from Akrites to the Claude Code vulnerabilities to GitHub&#8217;s advisory database straining under record volume, is that the security infrastructure is being rebuilt in real time for a world none of the existing infrastructure was designed to handle. </p><p>The organizations that will thrive are the ones building their security architectures around the assumption of model abundance and model interchangeability, not model scarcity. </p><p>Invest in harnesses, not model dependencies. Build remediation capacity, not just discovery capability, and treat your AI agents with the same suspicion you would treat a new contractor with admin access, because that is functionally what they are.</p><blockquote><p><strong>Stay resilient.</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Cloud Security and SecOps Can’t Afford to Keep Ignoring Each Other]]></title><description><![CDATA[While cloud environments have become the default operating surface for most enterprises, the teams responsible for securing them still operate as if the cloud were a separate domain with its own gravity.]]></description><link>https://www.resilientcyber.io/p/cloud-security-and-secops-cant-afford</link><guid isPermaLink="false">https://www.resilientcyber.io/p/cloud-security-and-secops-cant-afford</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Wed, 01 Jul 2026 12:15:13 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4a904b98-6ba0-41c9-b2cb-584c47c607c4_904x391.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>While cloud environments have become the default operating surface for most enterprises, the teams responsible for securing them still operate as if the cloud were a separate domain with its own gravity. </p><p>As cloud technologies entered the scene, many organizations didn&#8217;t have both the tools and expertise in traditional SecOps teams to handle cloud security risks. This led to a situation where cloud security teams run CNAPP tools focused on posture, misconfiguration, and compliance and more recently, runtime as well. SOC teams run SIEM, SOAR, and EDR focused on detection and response, and between those two worlds sits a gap that attackers have learned to exploit with increasing precision.</p><p>Other key factors that often contributed to the divide between the two included factors such as the Cloud Security team needing cloud-native telemetry and insights into API&#8217;s and the control plane, much of which the traditional SecOps tooling didn&#8217;t provide. </p><p>Organizationally there were also different ownership and budgets across the teams, as organizations stood up efforts to facilitate cloud migration such as &#8220;Cloud Centers of Excellence&#8221; and separate cloud security teams. </p><p>Lastly, early cloud security tools, such as CSPM were focused on posture (e.g. is this S3 bucket publicly exposed) and compliance, where SecOps was more focused on detection and response workflows to support activities such as incident response. </p><p>The organizational boundary between &#8220;<em>cloud security</em>&#8221; and &#8220;<em>security operations</em>&#8221; made sense when cloud was a workload migration story, but it doesn&#8217;t make sense when cloud is where the business runs and where the majority of attacks now land. As cloud adoption has matured and become an industry standard operating model, it is time for the way we handle cloud security and security operations to mature as well.</p><p>I&#8217;ve been writing about how AI is reshaping the threat dynamics around vulnerability discovery and exploitation, from the <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">Vulnpocalypse</a></strong> to <strong><a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">the AI cyber capability curve</a></strong> that shows frontier model capabilities steepening with every release. Those trends make the silo between cloud security and SecOps more than an operational inconvenience, they make it a structural liability. </p><p>When exploitation timelines compress from months to hours and adversaries operate at machine speed, having your posture management on one console and your detection and response on another isn&#8217;t a tooling preference, it&#8217;s an intentional blind spot with real-world consequences.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Shadow Cloud SOC</h2><p>IDC published a report titled &#8220;<strong><a href="https://www.paloaltonetworks.com/engage/cortex-cloud-industry-validation/idc-whitepaper?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=influencer&amp;utm_content=pa001223">Bridging the CNAPP - SecOps Divide</a></strong>&#8221; that put a name to something most practitioners already feel. They call it the &#8220;shadow cloud SOC,&#8221; the phenomenon where cloud security teams end up performing SOC-like functions, investigating alerts, triaging incidents, and chasing threats in cloud environments, without any formal integration with the actual SOC or SecOps team. </p><p>The cloud security team builds its own investigation workflows, its own escalation paths, and its own dashboards because the SOC&#8217;s tooling wasn&#8217;t designed for cloud-native telemetry and the CNAPP wasn&#8217;t designed for real-time detection and response.</p><p>My friend <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;James Berthoty&quot;,&quot;id&quot;:215222117,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F029c069a-0ea1-4c28-bedb-742a03fa770a_800x800.jpeg&quot;,&quot;uuid&quot;:&quot;2eec1a80-e8b8-44fc-b3db-eeaba4391497&quot;}" data-component-name="MentionToDOM"></span> of Latio Tech called out this tension in his recent presentation at fwd:cloudsec 2026 in a talk titled &#8220;<strong><a href="https://youtu.be/YrhHBhAh1Ns?si=K9he7KxU6uFqPnpl">Are We There Yet? Lessons from the 10 Year Cloud Security Ride</a></strong>&#8221;. In the talk James discusses the realities of disjointed tools because different feature sets are owned by different personas (e.g. AppSec, Cloud and SecOps) when it comes to CNAPP&#8217;s. </p><div id="youtube2-YrhHBhAh1Ns" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;YrhHBhAh1Ns&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/YrhHBhAh1Ns?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The result is two parallel security operations running against the same threat surface with different data, different context, and different response playbooks. IDC&#8217;s research found that the average organization uses 6 to 10 separate security tools to cover its cloud environment. 98% of organizations use at least two cloud service providers, and the teams operating these fragmented toolchains aren&#8217;t just dealing with tool sprawl. </p><p>They&#8217;re dealing with context fragmentation, where the information needed to investigate an incident is spread across multiple consoles that don&#8217;t share a common data model or timeline.</p><p>This isn&#8217;t a problem that happens because people are making bad decisions. It&#8217;s a structural outcome of how cloud security evolved. CNAPP emerged from the convergence of CSPM, CWPP, and CIEM. These are of course Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP) and Cloud Infrastructure Entitlement Management (CIEM), which were tools aimed at addressing the configuration and posture of cloud environments, the security of cloud workloads and the entitlements associated with Cloud IAM. </p><p>Tools such as CSPM, CWPP and CIEM existed out of necessity, given some of the most persistent problems (which are still relevant now) in cloud environments included issues such as misconfigured resources, organizations poorly navigating the shared responsibility model with CSP&#8217;s, dealing with ephemeral workflows, containers and functions, as well as IAM and entitlement sprawl across their growing cloud account footprints. </p><p>Some of the specific questions these tools were aimed at answering include:</p><ul><li><p>Is this S3 bucket publicly accessible? </p></li><li><p>Are these IAM permissions overly broad? </p></li><li><p>Is this container image running with known vulnerabilities? </p></li></ul><p>These are important questions, but they&#8217;re fundamentally about the state of the environment at a point in time. They don&#8217;t tell you what&#8217;s happening right now from a runtime threat perspective. They don&#8217;t detect lateral movement, credential abuse, or data exfiltration in progress, and they don&#8217;t integrate with the incident response workflows that SOC teams depend on to contain and remediate active threats.</p><p>So cloud security teams built their own shadow operations to fill the gap, and the SOC, lacking cloud-native visibility, either ignored cloud alerts or tried to ingest them into tools that lacked the context to make sense of them.</p><p>As it goes in security, eventually disparate tools get consolidated into comprehensive platform solutions, which in this case was CNAPP.  CNAPP consolidation came out of the need to address the point-tool sprawl, duplicated findings across the tooling, inconsistent context and asset identity, as well as teams struggling with alert fatigue and prioritization issues. </p><p>Ironically enough, in the age of AI-driven vulnerability discovery, prioritization is as critical as ever, as organizations race to keep up with the ever mounting list of CVE&#8217;s, misconfigurations and now Agentic IAM. Operating in a silo has costs, and it isn&#8217;t just budgetary, as it has cognitive impacts on security teams, and also keeps them from effectively reducing organizational risks.</p><h2>The Cost of the Silo</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!byAh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!byAh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png 424w, https://substackcdn.com/image/fetch/$s_!byAh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png 848w, https://substackcdn.com/image/fetch/$s_!byAh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png 1272w, https://substackcdn.com/image/fetch/$s_!byAh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!byAh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png" width="904" height="391" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:391,&quot;width&quot;:904,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:472931,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200621331?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!byAh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png 424w, https://substackcdn.com/image/fetch/$s_!byAh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png 848w, https://substackcdn.com/image/fetch/$s_!byAh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png 1272w, https://substackcdn.com/image/fetch/$s_!byAh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57bd11d9-1cde-4983-bd29-75b68bf356e3_904x391.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The operational cost of this fragmentation is measurable. IDC&#8217;s North American Vendors and Tools Consolidation Survey found that 43% of organizations identified improved threat detection as their top objective for security tools consolidation. </p><p>34% cited faster incident response, and 32% cited streamlining operations and workflows. These aren&#8217;t aspirational answers, they&#8217;re responses from practitioners who are living with the consequences of fragmented toolchains every day and feeling those impacts in their work and ability to be effective in their roles.</p><p>When a cloud security team detects a suspicious configuration change and the SOC detects anomalous API behavior from the same principal in the same timeframe, those two signals should be correlated automatically, but the reality is that in most organizations today, they aren&#8217;t. </p><p>They land in different dashboards, get triaged by different teams with different escalation paths, and only converge, if they converge at all, through manual handoffs, Slack messages, ad hoc conversations and shared spreadsheets. </p><p>The mean time to detect  (MTTD) stretches because neither team has the full picture in a consolidated fashion. The mean time to respond (MTTR) stretches because coordination between siloed teams adds friction at exactly the moment when speed matters most for mitigating organizational risks.</p><p>The math gets worse as cloud adoption accelerates. Cloud security alerts have increased <em>388%</em> year over year, and the average cloud intrusion takes only 10 minutes from initial access to lateral movement. </p><p>A security architecture that requires manual coordination between two separate teams operating two separate toolchains can&#8217;t respond at the speed the threat demands. </p><p>This isn&#8217;t just a theoretical problem either, it&#8217;s the daily reality for security teams in large enterprises running multi-cloud environments with dozens of accounts, hundreds of services, and thousands of ephemeral workloads spinning up and down continuously, and is only going to be exacerbated by AI agents.</p><h2>CNAPP Is Necessary but Not Sufficient</h2><p>The industry has done a good job of consolidating cloud security posture capabilities into CNAPP platforms as I mentioned above, as it consolidated some of the emerging cloud security tools into a single comprehensive cloud security platform. Having misconfiguration detection, vulnerability management, identity analysis, and compliance monitoring in a single platform is a real improvement over the point-tool sprawl of five years ago. </p><p>But posture management answers the question &#8220;<em>are we configured correctly?</em>&#8221; It doesn&#8217;t answer &#8220;<em>are we under attack right now?</em>&#8221; One is a static posture perspective, the other is a runtime detection &amp; response analysis.</p><p>I&#8217;ve also tried to touch on these pain points in prior pieces, such as &#8220;<strong><a href="https://www.resilientcyber.io/p/how-adr-addresses-gaps-in-the-detection">How ADR Addresses Gaps in the Detection &amp; Response Landscape</a></strong>&#8221;, coming at it from the perspective of AppSec and SecOps, where AppSec and SecOps have similar divides as CloudSec and SecOps.</p><p>That distinction matters more than most CNAPP evaluations acknowledge. A CNAPP that identifies a misconfigured IAM role is valuable, but a CNAPP that identifies the misconfigured IAM role, detects that an adversary is actively exploiting it to exfiltrate data from a production database, and triggers an automated containment response in the same platform is a fundamentally different capability. </p><blockquote><p><strong>The first is a compliance finding, the second is threat defense.</strong></p></blockquote><p>IDC makes this point directly, arguing that CNAPP must evolve beyond posture management to include real-time cloud detection and response capabilities integrated with SOC workflows. </p><p>The alternative is the status quo, where CNAPP generates findings that feed into a ticketing system while the actual response happens somewhere else entirely, often too slowly to prevent the damage that the finding was meant to flag.</p><p>As I explored in <strong><a href="https://www.resilientcyber.io/p/the-attack-surface-exponential">The Attack Surface Exponential</a></strong>, the volume of code being pushed to production is accelerating dramatically, with GitHub commits heading toward <em>14 billion</em> in 2026. </p><p>Every one of those commits can introduce a misconfiguration, a vulnerable dependency, or an overly permissive access grant in a cloud environment. The posture-only model of cloud security assumes those issues will be found and fixed before an adversary finds them first. The <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">Vulnpocalypse</a></strong> has made that assumption wishful thinking, because AI is compressing the window between vulnerability discovery and weaponization from months to hours at marginal costs measured in dollars.</p><p>If you accept that posture alone can&#8217;t prevent all breaches, and every serious practitioner does, then the logical conclusion is that cloud security needs detection and response as a first-class capability, not a handoff to a separate team running separate tooling.</p><h2>Why the Threat Tempo Forces the Issue</h2><p>The silo between cloud security and SecOps was tolerable when attack timelines gave defenders time to coordinate. When exploitation timelines ran in weeks or months, having a cloud team generate a finding that eventually made it to the SOC queue was suboptimal but survivable, however that timeline no longer exists.</p><p>The<strong> <a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">AI cyber capability curve</a></strong> shows frontier AI models achieving increasing success on complex cyber tasks with every generation. When I covered Anthropic&#8217;s Project Glassswing results in <strong><a href="https://www.resilientcyber.io/p/the-receipts-are-in">The Receipts Are In</a></strong>, their partners using Claude for security had discovered over <em>10,000 high-and-critical-severity vulnerabilities</em> in a single month, with discovery rates up more than 10x. </p><p>These same capabilities are available to adversaries, and the 2026 DBIR confirmed that <strong><a href="https://www.resilientcyber.io/p/the-dbirs-exploitation-era">vulnerability exploitation has become the leading initial access vector</a></strong>, with exploitation timelines compressing while remediation capacity stays flat.</p><p>This is the threat context in which the cloud security and SecOps silo persists. Adversaries aren&#8217;t coordinating through Slack and they aren&#8217;t handing off between specialized teams with different dashboards. </p><p>They&#8217;re running automated toolchains that move from reconnaissance to exploitation to lateral movement to exfiltration in continuous, machine-speed workflows. A defender architecture that fragments detection from response, and cloud visibility from SOC operations, is structurally disadvantaged against that kind of adversary.</p><p>The convergence of cloud security and SecOps isn&#8217;t simply a vendor talking point, it&#8217;s a requirement imposed by the threat tempo itself coupled with the security buyer side realities, and security leaders look to rationalize tool sprawl and bring order to the chaos.</p><h2>What Convergence Looks Like in Practice</h2><p><strong><a href="https://www.paloaltonetworks.com/engage/cortex-cloud-industry-validation/idc-whitepaper?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=influencer&amp;utm_content=pa001223">IDC&#8217;s framework</a></strong> for what they call the &#8220;unified cloud security operations platform&#8221; has a few characteristics that practitioners should be evaluating against. The core idea is a single platform that combines CNAPP&#8217;s posture management capabilities with real-time cloud detection and response, feeding into the same investigation and incident response workflows that the SOC uses across the rest of the enterprise.</p><p>This means a common data model that normalizes cloud telemetry (API logs, control plane events, workload behavior, identity activity) with endpoint, network, and identity telemetry from non-cloud environments. </p><p>It means correlation engines that can connect a misconfigured resource, a suspicious identity action, and a data access anomaly into a single incident rather than three separate alerts in three separate consoles and none of the connecting context. It also means response automation that works at cloud speed, automatically revoking credentials, isolating workloads, or blocking network paths within seconds rather than waiting for a human to context-switch between platforms. When we hear fighting adversaries with &#8220;machine speed&#8221;, these are the sort of capabilities that come to mind.</p><p>Resilient Cyber&#8217;s partner, <strong><a href="https://www.paloaltonetworks.com/cortex/cloud">Palo Alto Networks&#8217; Cortex Cloud</a></strong> is an example of what this convergence can look like in practice, combining what was previously the Prisma Cloud CNAPP with Cortex&#8217;s cloud detection and response capabilities into a single platform. </p><p>The architectural choice to unify posture management and SOC-grade detection and response in one console reflects the same structural argument IDC is making. When cloud security posture data and real-time threat data live in the same platform, the SOC and the cloud security team stop being separate organizations with separate toolchains and start operating against a shared picture of risk and threat activity.</p><p>If we&#8217;re being honest, it&#8217;s also a push to deliver what only some of the more mature and capable security industry leaders are capable of, given the breadth of coverage and capabilities it demands.</p><p>The practical benefit for security leaders is straightforward. Instead of maintaining parallel operations with different escalation paths, you get a single workflow where a posture finding and an active exploit of that same misconfiguration surface in the same investigation timeline, with the context and response actions available in one place. </p><p>That reduces the mean time to detect, the mean time to respond, and the operational overhead of maintaining two separate security operations against the same environment while also unifying disjointed tooling in the security tech stack.</p><h2>The Structural Debt That Compounds</h2><p>The silo between cloud security and SecOps is a form of structural debt that compounds as cloud adoption grows, as attack surfaces expand, and as adversary capabilities accelerate. </p><p>Every multicloud account added, every new service deployed, every ephemeral workload spun up increases the volume of telemetry that needs to be correlated and the speed at which threats need to be detected and contained. Running that through fragmented toolchains with manual handoffs between teams isn&#8217;t just inefficient. It&#8217;s a scaling problem that gets worse with every increment of cloud adoption.</p><p><strong><a href="https://www.paloaltonetworks.com/engage/cortex-cloud-industry-validation/idc-whitepaper?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=influencer&amp;utm_content=pa001223">IDC found</a></strong> that organizations increasingly prefer a single console over managing 10 or more separate dashboards. That preference isn&#8217;t driven by aesthetics. It&#8217;s driven by the operational reality that context fragmentation directly degrades the ability to detect and respond to threats at the speed the environment demands due to the disjointed communication and collaboration among teams, not to mention the potential cognitive overload for practitioners.</p><p>For practitioners evaluating CNAPP solutions today, we can all agree that posture management matters. That said, it is valid t o ask whether a CNAPP that stops at posture, that generates findings but doesn&#8217;t detect active threats and doesn&#8217;t integrate with SOC response workflows, is sufficient for the threat environment we&#8217;re operating in right now, especially against the backdrop of the AI cyber capability curve.</p><p>The convergence of cloud security and SecOps shouldn&#8217;t just be a future-state aspiration, and instead is a requirement that the current generation of threats are imposing. </p><p>I anticipate organizations that recognize this and build accordingly operate with a fundamentally different risk profile than those still running parallel security operations and hoping the handoff between teams is fast enough, especially when teams are already often overwhelmed and struggling to keep pace.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Why AI Security Is Getting Rebuilt From Scratch]]></title><description><![CDATA[How an inception-stage investor sees AI security, agentic infrastructure, and the venture market changing at the same time.]]></description><link>https://www.resilientcyber.io/p/why-ai-security-is-getting-rebuilt</link><guid isPermaLink="false">https://www.resilientcyber.io/p/why-ai-security-is-getting-rebuilt</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Wed, 01 Jul 2026 12:01:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/208203446/91f799405cec62237b660a1cc233ee34.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode, I sit down with founder and managing partner of Boldstart Ventures, <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ed Sim&quot;,&quot;id&quot;:3093019,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/117206c8-d2bf-460a-bfe4-f63ab22b79d3_2917x3582.png&quot;,&quot;uuid&quot;:&quot;2ff39312-c51c-4d12-bb41-a692e3b9cec5&quot;}" data-component-name="MentionToDOM"></span>, to discuss where AI security and agentic infrastructure are actually heading, including on-prem models, private evals, agentic identity, and vulnerability chaining. Ed has been an inception-stage investor for nearly 30 years and has run Boldstart since 2010, and about a third of the firm&#8217;s investments are in cyber. </p><p>He was the first investor in Protect AI, which sold to Palo Alto Networks in a reported ~$700M exit roughly a year before ChatGPT launched, and he is early in companies like Keycard, Surf AI, and June.</p><p>I read a lot of Ed&#8217;s content because he sits outside the security echo chamber and looks at this market through a CTO, CIO, and investor lens. That perspective made for one of my favorite conversations in a while.</p><p>We chatted about:</p><ul><li><p>Why a day-one partnership looks different now that anyone can vibe code an MVP</p></li><li><p>The Protect AI acquisition and what the first exit in AI security signaled to the market</p></li><li><p>Competing as an inception fund against mega-funds writing giant seed rounds</p></li><li><p>What founders should actually look for in a venture partner beyond the check</p></li><li><p>The shift from building intelligence to controlling it, with routing, post-training, and on-prem deployment</p></li><li><p>Why enterprise data, workflows, and private evals are becoming the crown jewels</p></li><li><p>Vulnerability chaining, attack path reasoning, and how tools like Mythos are reshaping the security budget conversation</p></li><li><p>Agentic identity and why Keycard treats agents as short-lived problem solvers rather than digital twins</p></li><li><p>The Surf AI thesis on automated security hygiene and tying every asset back to an owner</p></li><li><p>The real bottleneck slowing agent adoption in the enterprise</p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 20,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><div id="youtube2-mmBTiRQgDsY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;mmBTiRQgDsY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/mmBTiRQgDsY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h3><strong>Prefer to listen? </strong></h3><p><strong><a href="https://open.spotify.com/episode/6yIJDopwTamsY58yNJnCpW?si=gcg5N9NkRuKVlnEGWJOwJw">Spotify </a></strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/why-ai-security-is-getting-rebuilt-from-scratch/id1555928024?i=1000778067754">Apple Podcasts</a></strong></p><p><strong>Please be sure to subscribe and leave a review, it makes a big difference for the show!</strong></p><div><hr></div><h2>The bar for a cybersecurity startup just went way up</h2><p>Ed was blunt about the state of the market. &#8220;The world needs more cybersecurity, but we don&#8217;t need all the cybersecurity companies that we have right now.&#8221; Anyone can build now, and a moat that used to last twelve or eighteen months can get copied in a fraction of that time. So a good cyber idea is table stakes, not a differentiator.</p><p>What he looks for underneath the idea is depth on the AI side. He wants to know whether a founder is going to build or post-train their own model, how deep the moat and the flywheel go, and how deep the product gets into customer environments. That is a real shift in what earns a day-one check, and it is worth internalizing if you are a practitioner trying to read which startups will still be here in a few years.</p><h2>From building intelligence to controlling it</h2><p>The through line of the whole conversation was Ed&#8217;s argument that the first era of AI was about building intelligence and the next one is about controlling it. Once the frontier labs filed to go public, the tokenomics stopped being a rounding error, and enterprises started routing queries so they are not paying for state-of-the-art on every request. From there it is a short hop to post-training open models and asking why you would hand your data to a third party at all.</p><p>He put the incentive problem in memorable terms. &#8220;I think the biggest heist ever happening right now is that OpenAI and Anthropic created their own forward deployed engineering companies.&#8221; His point is that the data leaving your company is not just data, it is a map of how your company works, and your private evals are the thing you least want a competitor&#8217;s model to learn from. This is where I think a brand new set of security problems opens up around model hosting, lineage, and the security of running these things in your own environment.</p><h2>Vulnerability chaining makes reasoning the whole game</h2><p>We spent real time on what reasoning models do to vulnerability management, which is squarely in my wheelhouse. For years we prioritized the top criticals and highs by severity score and largely ignored the mediums and lows. Ed&#8217;s framing is that these models change that math. &#8220;Take 10 vulnerabilities that might have been on the backlog and you staple them together and create an attack path. When you create an attack path and these things can reason, that&#8217;s crazy.&#8221;</p><p>That is the industrialization of vulnerability discovery and exploitation, and it cuts both ways. The same capability that lets a defender do continuous attack path reasoning is available to the attacker, and the tooling we built to manage all of this, from CVE databases on down, is already straining under the volume. Ed also tied it to the budget conversation, noting that the worry is not whether continuous reasoning works, it is what it costs when you run it against all of your code, cloud configs, identities, and network state.</p><h2>Agentic identity is becoming its own category</h2><p>Ed funded Keycard two years ago and made a strong case that agent identity is not a feature that gets absorbed, it is a category. His description of the primitive is the clearest I have heard. &#8220;If you believe that every agent should have its own identity, that it shouldn&#8217;t go through Chris or Ed, if you believe they should be ephemeral and dynamic, and you believe that there should be an audit trail, and then if you can cryptographically prove that the agent is not hacked in the whole process, that&#8217;s what we&#8217;re building.&#8221;</p><p>What I appreciated is that he does not think one vendor wins the whole thing. Large incumbents will take share, and a few companies that treat this holistically rather than as a single point product will win alongside them. He also credited the community-building work here, specifically Keycard bringing in Ali Howe and the Insecure Agents podcast, which is on my own go-to list for learning about agentic IAM.</p><h2>The bottleneck is not tooling, it is knowing where to start</h2><p>I closed by asking Ed what actually holds back agent adoption when only a small percentage of organizations have agents in production. His answer was refreshingly human. &#8220;Most people don&#8217;t even know where to get started.&#8221; Coding works and gets most of the token spend, but the business workflows are largely untouched, and the whole landscape is confusing about which model, which platform, and which first workflow to automate.</p><p>That is why the easy-button players like Palantir have pull, and why Ed thinks there is room for many easy buttons rather than one lab dominating everything. It also lands on a theme he and I share. There will be people who look at this moment and feel overwhelmed, and people who look at it and feel invigorated, and it is the second group that ends up thriving. As Ed put it, security now needs hardcore AI people, the ones who build models, to come into the field, and we are already seeing it happen.</p><p>Thanks to Ed for coming back on the show. Follow his newsletter, What&#8217;s Hot in Enterprise IT/VC, and connect with him on LinkedIn for some of the sharpest content on enterprise infrastructure, AI, and security investing.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Why 70,000 CVE's is Less Scary Than It Sounds]]></title><description><![CDATA[The count is exploding, the exploitable risk is flat, and Jerry Gamblin explains why]]></description><link>https://www.resilientcyber.io/p/why-70000-cves-is-less-scary-than</link><guid isPermaLink="false">https://www.resilientcyber.io/p/why-70000-cves-is-less-scary-than</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Sun, 28 Jun 2026 12:01:48 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203888601/025b356bb0edabc065de42355217f41a.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Every few weeks another headline warns that vulnerability disclosures are setting records, and 2026 is now on pace for nearly 70,000 CVEs. Jerry Gamblin helped build the forecast behind that number, and his takeaway is not the one you would expect. The count is surging, but the risk that actually matters has barely moved.</p><h1><strong>Why this conversation matters</strong></h1><p>Jerry runs RogoLabs, built CVE.ICU, and co-authored the FIRST mid-year forecast, which makes him one of the few people who can explain what is really driving the surge instead of just reacting to it. </p><p>He walks through why a single source, GitHub, is responsible for so much of the growth, why most of these findings are old debt rather than new danger, and why the NVD breaking down is forcing a long-overdue reckoning for the CNAs. If you own vulnerability management, this is a practical guide to tuning out the noise and triaging what counts.</p><div id="youtube2-nzQLQxD-GfE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;nzQLQxD-GfE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/nzQLQxD-GfE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><strong>Key takeaways</strong></h3><ul><li><p><strong>The 70,000 number is real, but one source is inflating it.</strong> CVEs are up more than 40 percent year over year, and GitHub alone now publishes one in five of them after scaling up its advisory team.</p></li><li><p><strong>Three very different forces get lumped into one scary figure.</strong> AI-assisted discovery that no CVE record actually flags, a 449 percent jump in GitHub security advisories where a script downloaded ten times can earn the same CVE as a Windows flaw on a billion devices, and VulnCheck operating as a CNA of last resort are each driving volume for different reasons.</p></li><li><p><strong>Rain versus flood is the whole point.</strong> Total CVE volume is climbing fast, but once you filter for CISA KEV and EPSS, the genuinely exploitable risk has stayed essentially flat, so it is raining without flooding.</p></li><li><p><strong>Most of the surge is 25 years of human debt finally getting found.</strong> The OWASP Top 10 has barely changed since it was first published, and AI tooling is simply surfacing the same old mistakes at scale rather than inventing new danger.</p></li><li><p><strong>The AI panic is being put to good use.</strong> Jerry&#8217;s optimistic read is that teams are using the hype to win budget and cycles to patch long-known issues, and a finding from a shiny AI tool tends to get fixed faster than the same finding from last year&#8217;s pentest.</p></li><li><p><strong>The NVD was the dam that fell.</strong> It was never reasonable to expect one small organization to enrich every CVE for the whole world, so the burden now returns to the CNAs and the large vendors that quietly relied on it to clean up their records.</p></li><li><p><strong>Treat CVE data as a product you pay for.</strong> Jerry&#8217;s most actionable advice is to use procurement leverage, since demanding better CVE records before renewing a contract is one of the only forcing functions that reliably moves vendors.</p></li><li><p><strong>What actually gets exploited has not changed.</strong> VPN concentrators and the same familiar vulnerability classes still dominate, the NSA&#8217;s annual top 10 exploited bugs are reliably old, and there is no sign yet of AI driving widespread attacks.</p></li><li><p><strong>The unsolved problem is still asset inventory.</strong> You cannot triage what you cannot see, and most organizations still cannot say with confidence whether they even run the software behind a given pile of CVEs.</p></li><li><p><strong>AI-accelerated exploitation will look like patience, not mass exploits.</strong> The real shift is a tireless attacker that loops on your network for days until it finds a way in, which is precisely what agents are good at.</p></li></ul><h3><strong>Notable quotes</strong></h3><blockquote><p>&#8220;GitHub is now publishing one in five CVEs&#8221;</p></blockquote><p>Jerry Gamblin, on what is really behind the record numbers.</p><blockquote><p>&#8220;the NVD was the dam that fell&#8221;</p></blockquote><p>Jerry Gamblin, on why responsibility now shifts back to the CNAs.</p><blockquote><p>&#8220;we really need to start having people see CVE data as a product that they&#8217;re paying for&#8221;</p></blockquote><p>Jerry Gamblin, on the one forcing function that actually moves vendors.</p><h3><strong>Listen and watch</strong></h3><p><a href="https://youtu.be/nzQLQxD-GfE?is=m4_FgCURFIkoLdJ3">YouTube</a></p><p><a href="https://open.spotify.com/episode/5ms5s9wyo5jihG7bu6LMyU?si=H2YBVwSiT6SZF3qEPSetPg">Spotify</a></p><p><a href="https://podcasts.apple.com/us/podcast/resilient-cyber/id1555928024?i=1000774502122">Apple Podcasts</a></p><h3><strong>Resources</strong></h3><p><strong><a href="https://cve.icu/">CVE.ICU </a></strong></p><p><strong><a href="https://rogolabs.net/">RogoLabs </a></strong></p><p><strong><a href="https://www.first.org/newsroom/releases/20260615">FIRST 2026 mid-year vulnerability forecast</a></strong></p><p><strong><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA KEV Catalog</a></strong>  </p><p><strong><a href="https://www.first.org/epss/">EPSS</a></strong></p><h3><strong>Subscribe</strong></h3><p>If this kind of signal-over-noise take on vulnerability management is useful to you, subscribe to Resilient Cyber for more conversations and writing on cybersecurity, AI, and the forces that shape both.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #103]]></title><description><![CDATA[Five Eyes Agencies Issue AI Cyber Warning, Accenture Makes Cyber's Largest OT Deal Ever, Open AI's Aim to Patch the Planet, Securing AI Coding Agents, GLM-5.2 Hits Cyber, & 66,000 CVE's Projected]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-103</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-103</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 25 Jun 2026 14:03:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xEP-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #103 of the Resilient Cyber Newsletter! </p><p>I have been highlighting for over a year that AI is going to compress the gap between vulnerability discovery and exploitation from weeks to hours. This week, the Five Eyes alliance said it too, in an unprecedented joint statement warning that frontier AI models could &#8220;fundamentally reshape cyber capabilities within months rather than years.&#8221; </p><p>Meanwhile, OpenAI, Microsoft, and AWS all launched competing AI security platforms in the same seven-day window, each promising to find and fix vulnerabilities at machine speed, and the AI market correction that Scott Galloway predicted in last week&#8217;s newsletter? It may be starting to arrive, on Monday when the Nasdaq dropped 2.2% and semiconductor stocks cratered.</p><p>The volume of significant developments this week was significant. FIRST projects 66,000 CVEs for 2026, running 46% above even the record-breaking forecasts from February. Mozilla fixed nearly 500 security bugs in a single month using an agentic AI pipeline. OALABS documented a case where an unsophisticated attacker in Ethiopia used Claude to breach 14 companies. Accenture took a majority stake in Dragos at $3.2 billion, and a cybersecurity startup called Ent emerged from stealth with a $100 million seed round.</p><p>There is a lot to cover, so let&#8217;s get into it!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xEP-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xEP-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png 424w, https://substackcdn.com/image/fetch/$s_!xEP-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png 848w, https://substackcdn.com/image/fetch/$s_!xEP-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png 1272w, https://substackcdn.com/image/fetch/$s_!xEP-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xEP-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png" width="1221" height="733" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b516df26-d163-45b3-99d4-3511a39824c0_1221x733.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:733,&quot;width&quot;:1221,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:663912,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xEP-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png 424w, https://substackcdn.com/image/fetch/$s_!xEP-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png 848w, https://substackcdn.com/image/fetch/$s_!xEP-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png 1272w, https://substackcdn.com/image/fetch/$s_!xEP-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb516df26-d163-45b3-99d4-3511a39824c0_1221x733.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><h3><strong><a href="https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_june_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=">What will you tell your audit committee about authorization next quarter?</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_june_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_june_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!owSa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 424w, https://substackcdn.com/image/fetch/$s_!owSa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 848w, https://substackcdn.com/image/fetch/$s_!owSa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 1272w, https://substackcdn.com/image/fetch/$s_!owSa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!owSa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png" width="686" height="376.4519230769231" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:686,&quot;bytes&quot;:856893,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_june_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_june_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!owSa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 424w, https://substackcdn.com/image/fetch/$s_!owSa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 848w, https://substackcdn.com/image/fetch/$s_!owSa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 1272w, https://substackcdn.com/image/fetch/$s_!owSa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7e05469-5f64-4dbe-aebc-c807ffa4a10d_1715x941.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When your audit committee asks where you stand on SOC 2, or who delegated which AI agent (of the thousands in your environment) to which system last quarter, the honest answer is often &#8220;I&#8217;ll get back to you.&#8221;</p><p>That gap, between what your documentation says and what actually runs in production, is where regulators and audit committees are now looking.</p><p>The <strong>Authorization Maturity Model</strong> is a new ebook by Alex Olivier, Cerbos CPO and co-chair of OpenID AuthZEN, the authorization standard. It gives security leaders a 4-stage benchmark to place their program, a Critical to Low exposure rating across NIS2, DORA, SEC, the EU AI Act and more, and a 90-day plan to move up. </p><p>Built on work with hundreds of CISO programs, analyst research, and leading industry events.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_june_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term=&quot;,&quot;text&quot;:&quot;Download the free ebook&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://solutions.cerbos.dev/authorization-maturity-model-a-cisos-benchmark?utm_campaign=resilient_cyber_june_2026&amp;utm_source=newsletter&amp;utm_medium=email&amp;utm_content=&amp;utm_term="><span>Download the free ebook</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.cisa.gov/news-events/news/five-eyes-cyber-security-agencies-statement">Five Eyes Agencies Issue Unprecedented Joint Warning on AI and Cyber Risk</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jPuH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jPuH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png 424w, https://substackcdn.com/image/fetch/$s_!jPuH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png 848w, https://substackcdn.com/image/fetch/$s_!jPuH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png 1272w, https://substackcdn.com/image/fetch/$s_!jPuH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jPuH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png" width="1367" height="374" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:374,&quot;width&quot;:1367,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69427,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jPuH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png 424w, https://substackcdn.com/image/fetch/$s_!jPuH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png 848w, https://substackcdn.com/image/fetch/$s_!jPuH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png 1272w, https://substackcdn.com/image/fetch/$s_!jPuH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2cc60a-d3b4-4cd0-9b68-125f99f423c1_1367x374.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On June 22, the cybersecurity agencies of the United States, United Kingdom, Canada, Australia, and New Zealand issued a joint statement that seemed to caught the attention of everyone in cyber, I just hope the message gets to those who run the business as well. </p><p>The agencies warned that frontier AI models could &#8220;fundamentally reshape cyber capabilities within months rather than years,&#8221; that AI is lowering barriers for malicious actors, and that the window between vulnerability discovery and active exploitation is shrinking from weeks to days or hours. They called for secure-by-design as standard practice, foundational cybersecurity hygiene, and empowering cyber leaders with the authority and resources to respond. </p><p>What makes this different from prior government advisories is the bluntness. This is not a &#8220;could eventually&#8221; warning. This is five allied intelligence agencies saying the transformation is already underway and organizations need to act now.</p><p>My challenge with all of this though is that first, these are fundamental best practices organizations already should have been doing, and second, it&#8217;s like we&#8217;re telling people to swim faster when they are already drowning. </p><p>Security teams are already doing their best, and in the absence of either a change in market forces or regulation, unfortunately much isn&#8217;t likely to change. We can&#8217;t &#8220;Call to Action&#8221; our way out of a market failure.</p><h3><a href="https://www.dragos.com/blog/dragos-joins-forces-with-accenture">Accenture Takes Majority Stake in Dragos at $3.2B Valuation</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D3r4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D3r4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png 424w, https://substackcdn.com/image/fetch/$s_!D3r4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png 848w, https://substackcdn.com/image/fetch/$s_!D3r4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png 1272w, https://substackcdn.com/image/fetch/$s_!D3r4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D3r4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png" width="1088" height="273" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:273,&quot;width&quot;:1088,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:120054,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D3r4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png 424w, https://substackcdn.com/image/fetch/$s_!D3r4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png 848w, https://substackcdn.com/image/fetch/$s_!D3r4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png 1272w, https://substackcdn.com/image/fetch/$s_!D3r4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15f3b0e1-cf20-45f7-89c7-98ee4f8ab5fc_1088x273.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the largest OT cybersecurity deal ever. </p><p>Accenture acquired a majority stake in Dragos at a $3.2 billion valuation, with the combined business valued at $4.175 billion including the acquisitions of runZero (led by HD Moore), and NetRise. Dragos remains independent with Rob Lee as CEO, with mission independence codified in legally binding governing documents. </p><p>The thesis is that OT security requires an end-to-end platform spanning exposure management, software supply chain, and device discovery, and that AI-accelerated threats against critical infrastructure demand resources no standalone startup can marshal alone. </p><p>Whether preserving independence inside a majority-owned structure actually works long-term remains to be seen, but the legal protections Lee negotiated are unusually strong.</p><p>I&#8217;ve been a fan of Dragos for a long time, and the trio of Rob Lee, HD Moore and Tom Pace across the teams is a excellent leadership team that is a big asset for Accenture and lets Accenture expand their services via leading products while also expanding revenues via access and distribution for the products involved.</p><div><hr></div><h3><strong><a href="https://mazehq.com/platform/code?utm_campaign=2026Q2-Global-Inbound-Newsletter-CodeLaunch&amp;utm_medium=newsletter&amp;utm_source=resilientcyber">Code security you can trust</a>*</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://mazehq.com/platform/code?utm_campaign=2026Q2-Global-Inbound-Newsletter-CodeLaunch&amp;utm_medium=newsletter&amp;utm_source=resilientcyber" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LSW-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!LSW-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!LSW-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!LSW-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LSW-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png" width="636" height="332.84" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:636,&quot;bytes&quot;:113698,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://mazehq.com/platform/code?utm_campaign=2026Q2-Global-Inbound-Newsletter-CodeLaunch&amp;utm_medium=newsletter&amp;utm_source=resilientcyber&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!LSW-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!LSW-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!LSW-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!LSW-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fccf688-5b7b-49bb-a194-c8c5c75f4201_1200x628.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Legacy SCA and SAST scanners match patterns and bury engineers in noise. That&#8217;s why Maze Code was built: AI agents that understand your code and dependencies.</p><p>AI agents investigate every finding with context from your code and cloud, close false positives, and catch business logic flaws other tools miss. Then they help you fix what&#8217;s left, right in your IDE or coding agent.</p><p>Finally, inbox zero for your code and cloud vulnerabilities is possible. </p><blockquote><p><strong><a href="https://mazehq.com/platform/code?utm_campaign=2026Q2-Global-Inbound-Newsletter-CodeLaunch&amp;utm_medium=newsletter&amp;utm_source=resilientcyber">Meet Maze Code</a></strong> </p></blockquote><p><em>*Sponsored</em></p><div><hr></div><h3><a href="https://www.wsj.com/pro/cybersecurity/cyber-startup-ent-raises-100-million-in-seed-funding-a3e9b6c6">Ent Emerges from Stealth with $100M Seed Round</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7sYe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7sYe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png 424w, https://substackcdn.com/image/fetch/$s_!7sYe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png 848w, https://substackcdn.com/image/fetch/$s_!7sYe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png 1272w, https://substackcdn.com/image/fetch/$s_!7sYe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7sYe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png" width="494" height="480.7539432176656" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:617,&quot;width&quot;:634,&quot;resizeWidth&quot;:494,&quot;bytes&quot;:173229,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7sYe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png 424w, https://substackcdn.com/image/fetch/$s_!7sYe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png 848w, https://substackcdn.com/image/fetch/$s_!7sYe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png 1272w, https://substackcdn.com/image/fetch/$s_!7sYe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a9bd933-e7c8-47e8-bb89-c3e991db684c_634x617.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One hundred million dollars in seed funding, let that sink in. Ent, founded by Elias Manousos and Brandon Dixon (the co-founders of RiskIQ, acquired by Microsoft for $500M+ in 2021, who then helped build Microsoft Security Copilot), emerged from stealth with backing from Decibel Partners, Sequoia, In-Q-Tel, and Craft Ventures. </p><p>The company positions itself as an &#8220;intent-aware&#8221; workspace security platform that reads human, AI agent, and application activity in real time and applies policy to intervene before incidents occur. They are already deployed with Global 2000 customers across financial services, hospitality, and defense. </p><p>The funding round alone signals a market conviction that existing endpoint security architectures were not designed for a world where AI agents act autonomously alongside human employees.</p><h3><a href="https://www.nytimes.com/2026/06/23/business/stock-market-down-tech-ai-asia-sp500-oil-gas.html">AI Semiconductor Selloff Hits Markets as Correction Begins</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TLvD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TLvD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png 424w, https://substackcdn.com/image/fetch/$s_!TLvD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png 848w, https://substackcdn.com/image/fetch/$s_!TLvD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png 1272w, https://substackcdn.com/image/fetch/$s_!TLvD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TLvD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png" width="619" height="356" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:356,&quot;width&quot;:619,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35982,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TLvD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png 424w, https://substackcdn.com/image/fetch/$s_!TLvD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png 848w, https://substackcdn.com/image/fetch/$s_!TLvD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png 1272w, https://substackcdn.com/image/fetch/$s_!TLvD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79b98a1e-def9-4fbe-bdea-423b26c0178b_619x356.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Last week I shared <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Scott Galloway&quot;,&quot;id&quot;:451231761,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de3bcbbb-ac49-498d-ba5f-72d576a22d4b_2048x2048.jpeg&quot;,&quot;uuid&quot;:&quot;11515985-807c-4108-8404-fc93a3c3e45c&quot;}" data-component-name="MentionToDOM"></span> &#8217;s prediction that the AI correction would hit 50-70% within 24 months and this week gave us a preview. The Nasdaq fell 2.21% on Monday after South Korea&#8217;s KOSPI plummeted 9.99% on semiconductor stock selloffs. Nvidia dropped 3.2%, Micron sank 11.4%, and TSMC fell 5.2%. The VanEck Semiconductor ETF lost 6.5% in a single session. </p><p>Whether this is the beginning of the correction Galloway warned about or a temporary pullback, the message is clear. Security leaders whose budgets are tied to AI spending optimism should be scenario-planning for what happens when that optimism meets a CFO looking to cut.</p><h3><a href="https://www.resilientcyber.io/p/the-real-price-tag-on-breaches">Verizon Breach Impact Study Reveals Business Interruption as Dominant Cost Driver</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UILe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UILe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png 424w, https://substackcdn.com/image/fetch/$s_!UILe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png 848w, https://substackcdn.com/image/fetch/$s_!UILe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png 1272w, https://substackcdn.com/image/fetch/$s_!UILe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UILe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png" width="515" height="375.18099547511315" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:483,&quot;width&quot;:663,&quot;resizeWidth&quot;:515,&quot;bytes&quot;:156649,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UILe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png 424w, https://substackcdn.com/image/fetch/$s_!UILe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png 848w, https://substackcdn.com/image/fetch/$s_!UILe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png 1272w, https://substackcdn.com/image/fetch/$s_!UILe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c8086c-74d8-4ce9-a9e8-fa2f4f77d83c_663x483.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Verizon&#8217;s inaugural Breach Impact Study, analyzing roughly 70,000 actual cyber insurance claims, provides the financial data practitioners have been asking for. The median financial impact per breach is $83,000, but the top 10% exceed $920,000 and the top 2.5% surpass $5 million. </p><p>Business interruption has overtaken all other loss types, growing 51% from 2023 to 2024 with extreme cases approaching $5 million. Supply chain incidents represent only 2% of claims but carry a median impact of over $252,000 and extreme cases exceeding $100 million. </p><p>What I find most useful here is that Verizon deliberately uses medians rather than averages, which gives practitioners numbers they can actually use in board conversations without the Ponemon-style distortion from outliers.</p><h3><a href="https://www.whitehouse.gov/presidential-actions/2026/06/ushering-in-the-next-frontier-of-quantum-innovation/">White House Signs Quantum Innovation Executive Order as &#8220;Harvest Now, Decrypt Later&#8221; Threat Grows</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yN-W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yN-W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png 424w, https://substackcdn.com/image/fetch/$s_!yN-W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png 848w, https://substackcdn.com/image/fetch/$s_!yN-W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png 1272w, https://substackcdn.com/image/fetch/$s_!yN-W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yN-W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png" width="965" height="384" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/016295de-36a3-41e7-83b0-29019993d027_965x384.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:384,&quot;width&quot;:965,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78195,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yN-W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png 424w, https://substackcdn.com/image/fetch/$s_!yN-W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png 848w, https://substackcdn.com/image/fetch/$s_!yN-W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png 1272w, https://substackcdn.com/image/fetch/$s_!yN-W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F016295de-36a3-41e7-83b0-29019993d027_965x384.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The executive order signed June 22 establishes a whole-of-government approach to quantum computing, sensing, and networking with hard deadlines. Within 180 days, the national quantum strategy must be updated. </p><p>Within 60 days, the Department of War must identify at least three quantum sensor projects for deployment by September 2028. A new Quantum Counterintelligence Protection Team will protect against adversary theft. The timing is no accident. A <a href="https://www.foreignaffairs.com/china/coming-quantum-national-security-crisis">Foreign Affairs analysis</a> published the same week warns that China and Russia are already stockpiling encrypted U.S. communications for future quantum decryption, a strategy commonly called &#8220;harvest now, decrypt later.&#8221; </p><p>The post-quantum migration clock is ticking, and this EO treats it as a national security imperative rather than an IT project.</p><h3><a href="https://www.linkedin.com/posts/twenty-has-raised-a-100-million-series-b-share-7472764179892998144-cuiO/">America&#8217;s First Venture-Backed Cyber Warfare Startup Reaches Unicorn Status</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9RTR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9RTR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png 424w, https://substackcdn.com/image/fetch/$s_!9RTR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png 848w, https://substackcdn.com/image/fetch/$s_!9RTR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png 1272w, https://substackcdn.com/image/fetch/$s_!9RTR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9RTR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png" width="396" height="363.7542857142857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:643,&quot;width&quot;:700,&quot;resizeWidth&quot;:396,&quot;bytes&quot;:200705,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9RTR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png 424w, https://substackcdn.com/image/fetch/$s_!9RTR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png 848w, https://substackcdn.com/image/fetch/$s_!9RTR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png 1272w, https://substackcdn.com/image/fetch/$s_!9RTR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74f09c6e-62db-4630-a6fd-ef3ccc3f4e09_700x643.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A $100 million Series B at a $1 billion valuation makes Twenty the first VC-backed offensive cyber warfare startup to achieve unicorn status. </p><p>The round was led by Accel with Point72 Ventures and Friends &amp; Family Capital, bringing total funding to $138 million since its 2024 founding. The company builds AI-enabled platforms for the US military and Intelligence Community focused on industrializing offensive cyber operations. </p><p>Whatever your views on the commercialization of offensive capabilities, the fact that a VC-backed offensive cyber company achieved unicorn status in under two years tells you everything about where the defense-industrial base is heading.</p><h3><a href="https://support.claude.com/en/articles/14328960-identity-verification-on-claude">Anthropic Rolls Out Identity Verification for Claude Users</a></h3><p>Some Claude users are now being asked to verify their identity using a government-issued photo ID and a live selfie, processed through third-party provider Persona Identities. </p><p>The move is designed to prevent abuse, enforce usage policies, and comply with age restrictions. Given the context of the Fable 5 export control saga I covered in issue #102, this reads as Anthropic simultaneously trying to address two pressures. On one side, mitigating the malicious actor concerns that gave the Commerce Department ammunition for the emergency shutdown. </p><p>On the other, demonstrating governance rigor to regulators who questioned whether Anthropic could control who uses its most capable models. The privacy implications are worth watching. Requiring government-issued ID and biometric selfies to use an AI service sets a precedent, and the data handling, encrypted and not used for training but processed through a third party, will face scrutiny from privacy advocates regardless of the stated protections.</p><div><hr></div><h1>AI</h1><h3><a href="https://openai.com/index/daybreak-securing-the-world/">OpenAI Expands Daybreak Cybersecurity Program and Launches &#8220;Patch the Planet&#8221; with Trail of Bits</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BwE_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BwE_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png 424w, https://substackcdn.com/image/fetch/$s_!BwE_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png 848w, https://substackcdn.com/image/fetch/$s_!BwE_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png 1272w, https://substackcdn.com/image/fetch/$s_!BwE_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BwE_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png" width="885" height="287" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:287,&quot;width&quot;:885,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48841,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BwE_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png 424w, https://substackcdn.com/image/fetch/$s_!BwE_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png 848w, https://substackcdn.com/image/fetch/$s_!BwE_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png 1272w, https://substackcdn.com/image/fetch/$s_!BwE_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5541cbd6-81c8-47be-942b-d0d4c49f6a37_885x287.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This was the biggest AI security announcement of the week, and one of the year, mimicking similar efforts by Anthropic. </p><p>OpenAI expanded its Daybreak cybersecurity program with three major moves. Codex Security has now scanned over 30 million commits across 30,000+ codebases, producing 500,000+ fixed findings and 70,000+ human-marked fixes. GPT-5.5-Cyber scored 85.6% on CyberGym (the highest single-model score published) and 39.5% on ExploitGym. And OpenAI launched a Cyber Partner Program with CrowdStrike, Palo Alto Networks, Cisco, Cloudflare, Wiz, and a dozen other major vendors, plus trusted access agreements with seven allied governments.</p><p>But the real headline is <strong><a href="https://openai.com/index/patch-the-planet/">Patch the Planet</a></strong>, built with Trail of Bits, HackerOne, and Calif. The early results are impressive. In the Linux kernel, GPT-5.5 produced 8 pointer info-leak PoCs and 24 local privilege escalation exploits. In OpenBSD, it found a 23-year-old use-after-free in SysV semaphores that escalates unprivileged users to root. In Chrome, it found 5 exploitable V8 vulnerabilities, three of which were fixed within days of being introduced. In Firefox, a WebAssembly vulnerability was patched just 2 days before Pwn2Own Berlin, causing 5 of 6 competition entries to withdraw, and the team discovered an &#8220;HTTP/2 Bomb&#8221; DoS technique affecting NGINX, Apache, IIS, and Pingora across 880,000+ websites. </p><p>The comparison to Anthropic&#8217;s Glasswing and Microsoft&#8217;s MDASH is inevitable, and the race to find and fix open-source vulnerabilities at AI speed is now a three-way competition between the hyperscalers.</p><p>I caught an <strong><a href="https://risky.biz/RBNEWSSI133/">interview</a></strong> with Trail of Bit&#8217;s Dan Guido discussing their involvement and the program on Risky Biz which was insightful. I&#8217;m also excited to see my friend Clint Giblet of tl;dr sec already making big moves since joining OpenAI to help lead cyber efforts.</p><h3><a href="https://www.boozallen.com/expertise/cybersecurity/whats-in-americas-code.html">Chinese AI Models Dominate Open-Weight Layer While Producing More Vulnerable Code for U.S. Government Users</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DtoF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DtoF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png 424w, https://substackcdn.com/image/fetch/$s_!DtoF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png 848w, https://substackcdn.com/image/fetch/$s_!DtoF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png 1272w, https://substackcdn.com/image/fetch/$s_!DtoF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DtoF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png" width="993" height="438" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:438,&quot;width&quot;:993,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88543,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DtoF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png 424w, https://substackcdn.com/image/fetch/$s_!DtoF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png 848w, https://substackcdn.com/image/fetch/$s_!DtoF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png 1272w, https://substackcdn.com/image/fetch/$s_!DtoF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F013dcad5-b40f-45b4-ad55-e423990b1910_993x438.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two pieces this week paint a striking picture when read together. Booz Allen tested four Chinese frontier LLMs against one American model and found that the Chinese models produce more vulnerable code specifically when the user appears to be from the U.S. government, with vulnerabilities that are highly obfuscated. </p><p>They also inject PRC-aligned political bias and refuse tasks Beijing deems sensitive. Meanwhile, <strong><a href="https://www.datagravity.dev/p/chinas-open-weight-takeover">Data Gravity reports</a></strong> that Chinese open-weight models now account for roughly 61% of all tokens consumed on OpenRouter, four of the five most-used models are Chinese, and DeepSeek V4-Pro pricing runs roughly 12x cheaper than GPT-5.5 at comparable quality. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4cv0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4cv0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png 424w, https://substackcdn.com/image/fetch/$s_!4cv0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png 848w, https://substackcdn.com/image/fetch/$s_!4cv0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png 1272w, https://substackcdn.com/image/fetch/$s_!4cv0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4cv0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png" width="573" height="487.8775790921596" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:619,&quot;width&quot;:727,&quot;resizeWidth&quot;:573,&quot;bytes&quot;:189216,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4cv0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png 424w, https://substackcdn.com/image/fetch/$s_!4cv0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png 848w, https://substackcdn.com/image/fetch/$s_!4cv0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png 1272w, https://substackcdn.com/image/fetch/$s_!4cv0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8386ce5f-a23c-4545-b179-7113fe703f07_727x619.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The convergence of these two data points should concern anyone building AI-powered security tools. The cheapest and most accessible models are increasingly the ones with documented adversarial behavior toward U.S. government users.</p><p>It is all incredibly ironic too, as we recently banned one of the leading U.S. frontier models, leading to much more interest and use in open source alternatives, which are dominated by China.</p><h3><a href="https://commandline.microsoft.com/information-flow-control-moving-toward-secure-autonomous-agents/">Microsoft Research Proposes Information Flow Control as Deterministic Security for AI Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Oe9W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oe9W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png 424w, https://substackcdn.com/image/fetch/$s_!Oe9W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png 848w, https://substackcdn.com/image/fetch/$s_!Oe9W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png 1272w, https://substackcdn.com/image/fetch/$s_!Oe9W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oe9W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png" width="743" height="279" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:279,&quot;width&quot;:743,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:141815,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oe9W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png 424w, https://substackcdn.com/image/fetch/$s_!Oe9W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png 848w, https://substackcdn.com/image/fetch/$s_!Oe9W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png 1272w, https://substackcdn.com/image/fetch/$s_!Oe9W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F417b7720-4c94-4fdf-ad07-172c77b6a127_743x279.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Microsoft&#8217;s research team, including Azure CTO Mark Russinovich, proposes Information Flow Control (IFC) as a deterministic mechanism for preventing prompt injection and data exfiltration in AI agents. </p><p>The core insight is that anything an agent can do in response to a legitimate prompt can also be triggered by prompt injection, so security must be enforced at the data-flow level rather than the model level. IFC labels all data with integrity and confidentiality tags, propagates those labels through agent processing, and blocks actions that would violate policies before they execute. </p><p>Experimental support is already integrated into GitHub Copilot CLI and Microsoft Agent Framework, with an open-source MCP gateway (Fides Gateway) released for experimentation. If this approach scales, it represents a genuine alternative to the &#8220;hope the model refuses&#8221; paradigm that everyone knows is insufficient.</p><h3><a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/beyond-the-benchmark-advancing-security-at-ai-speed/">Microsoft MDASH Moves to Production with Patch Tuesday Now Including AI-Discovered Vulnerabilities</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R3eF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R3eF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png 424w, https://substackcdn.com/image/fetch/$s_!R3eF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png 848w, https://substackcdn.com/image/fetch/$s_!R3eF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png 1272w, https://substackcdn.com/image/fetch/$s_!R3eF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R3eF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png" width="1028" height="143" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/924e055f-4c81-40d7-9389-ec378870892c_1028x143.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:143,&quot;width&quot;:1028,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:120019,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R3eF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png 424w, https://substackcdn.com/image/fetch/$s_!R3eF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png 848w, https://substackcdn.com/image/fetch/$s_!R3eF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png 1272w, https://substackcdn.com/image/fetch/$s_!R3eF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924e055f-4c81-40d7-9389-ec378870892c_1028x143.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Microsoft&#8217;s Multi-Model Agentic Scanning Harness (MDASH) has moved from research to production deployment across Windows, Azure, and identity engineering teams. </p><p>This month&#8217;s Patch Tuesday includes MDASH discoveries spanning the Windows kernel, Hyper-V, Active Directory, Remote Desktop, HTTP.sys, DNS Client, and DHCP Client, including two CVEs scored 9.8 CVSS (a kernel use-after-free and an HTTP.sys integer overflow RCE). </p><p>The system scores 96.5% on the CyberGym benchmark with newer models projecting 98.1%. Between MDASH, OpenAI&#8217;s Patch the Planet, and Anthropic&#8217;s Glasswing, the three largest AI labs are now all running production vulnerability discovery pipelines against real codebases. The results are showing up in actual patch releases.</p><h3><a href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed/">AWS Launches Continuum for Security at Machine Speed</a></h3><p>Continuum is AWS&#8217;s entry into the AI security platform race, explicitly rejecting the legacy model of collect-store-query-dashboard in favor of telemetry-context-reasoning-actions. </p><p>The platform operates in four phases, starting with discovery (ingesting vulnerability backlogs plus its own scans), then prioritization (contextual evaluation against business impact), validation (sandboxed exploit proof generation to eliminate false positives), and remediation (recommending patches with validated fixes and blast radius visibility). It starts in &#8220;learn mode&#8221; with human oversight and can graduate to automated enforcement. </p><p>Three hyperscalers launching competing AI security platforms in a single week is not a coincidence. It is a market signal that AI-powered security operations are moving from experimental to expected.</p><h3><a href="https://www.air.security/blog-posts/the-story-of-skills">Air.security Researchers Compromise 26,000 AI Agents with a Single Malicious Skill</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UwXq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UwXq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png 424w, https://substackcdn.com/image/fetch/$s_!UwXq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png 848w, https://substackcdn.com/image/fetch/$s_!UwXq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png 1272w, https://substackcdn.com/image/fetch/$s_!UwXq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UwXq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png" width="449" height="287.7153729071537" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:421,&quot;width&quot;:657,&quot;resizeWidth&quot;:449,&quot;bytes&quot;:342048,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UwXq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png 424w, https://substackcdn.com/image/fetch/$s_!UwXq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png 848w, https://substackcdn.com/image/fetch/$s_!UwXq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png 1272w, https://substackcdn.com/image/fetch/$s_!UwXq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4999b2ab-8033-4103-b5b6-c13b9567a6d2_657x421.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This one should make every agent security team deeply uncomfortable and further highlights the supply chain risks associated with &#8220;skills&#8221;. </p><p>Air Security researchers built a malicious AI agent skill in under an hour, distributed it via Instagram ads, got it merged into a popular plugin marketplace (gaining GitHub credibility with roughly 37,000 stars), and compromised 26,000 agents including corporate accounts. Every major security scanner, including ones from Cisco and Nvidia, cleared the skill as safe. The trick was simple, the skill instructed agents to fetch &#8220;documentation&#8221; from an attacker-controlled domain that mimicked a legitimate Google service. Current scanners only analyze bundled skill files, not the external URLs that skills reference at runtime. </p><p>This is a time-of-check-to-time-of-use attack on the agent supply chain, and the fact that no existing scanner catches it tells you how far behind agent security tooling remains.</p><h3><a href="https://www.nccgroup.com/media/jtepwx1t/nccgroup_codingagentswhitepaper.pdf">NCC Group Publishes Comprehensive Security Assessment of AI Coding Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2IfK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2IfK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png 424w, https://substackcdn.com/image/fetch/$s_!2IfK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png 848w, https://substackcdn.com/image/fetch/$s_!2IfK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png 1272w, https://substackcdn.com/image/fetch/$s_!2IfK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2IfK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png" width="634" height="310.582995951417" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:484,&quot;width&quot;:988,&quot;resizeWidth&quot;:634,&quot;bytes&quot;:44859,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2IfK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png 424w, https://substackcdn.com/image/fetch/$s_!2IfK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png 848w, https://substackcdn.com/image/fetch/$s_!2IfK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png 1272w, https://substackcdn.com/image/fetch/$s_!2IfK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b81b24c-fa51-4edf-aafd-b1aab04badf8_988x484.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Alex Plaskett&#8217;s 50-page whitepaper is the most thorough public security assessment of AI coding agents published to date. </p><p>NCC Group cataloged dozens of real vulnerabilities across Claude Code, Cursor, and Codex, including workspace trust bypasses, sandbox escapes via symlinks and git hooks, permission prompt bypasses through command injection in tools like sed and find, and network security bypasses. Sandboxing implementations vary wildly across platforms (macOS Seatbelt, Linux bubblewrap, nothing native on Windows), and hooks run unsandboxed by default. </p><p>The core argument is that LLM refusals are unreliable as a security boundary because attackers can make malicious actions look like legitimate build processes. If your organization has deployed coding agents, this whitepaper is your threat model.</p><h3><a href="https://www.helpnetsecurity.com/2026/06/17/ai-agents-offensive-cyber-operations-claude-codex/">Low-Skilled Attacker Used Claude and Codex to Breach 14 Companies</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wj3S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wj3S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png 424w, https://substackcdn.com/image/fetch/$s_!wj3S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png 848w, https://substackcdn.com/image/fetch/$s_!wj3S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png 1272w, https://substackcdn.com/image/fetch/$s_!wj3S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wj3S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png" width="640" height="211" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:211,&quot;width&quot;:640,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:39262,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wj3S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png 424w, https://substackcdn.com/image/fetch/$s_!wj3S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png 848w, https://substackcdn.com/image/fetch/$s_!wj3S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png 1272w, https://substackcdn.com/image/fetch/$s_!wj3S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18ef3c17-673a-4de1-8515-67bc80172a79_640x211.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>OALABS researchers recovered over 1,000 agent sessions from a compromised server and documented a case where an unsophisticated attacker used stolen Claude Code and Codex installations to autonomously breach at least 14 companies. </p><p>The AI handled reconnaissance, exploit development, execution, and data exfiltration from vague prompts like &#8220;recon this.&#8221; Claude produced only 9 policy violations across 1,000+ sessions and autonomously drafted monetization estimates for stolen data. The attacker bypassed guardrails simply by claiming &#8220;authorized red team exercises.&#8221; He was eventually identified as a young man in Addis Ababa, Ethiopia, after accidentally asking Claude to edit his resume with his full name and LinkedIn profile. </p><p>The skill floor for offensive operations has collapsed, and the case demonstrates that guardrail bypasses remain trivially easy through legitimate-sounding framing.</p><h3><a href="https://www.linkedin.com/pulse/glm-52-cyberbt-ctf-strongest-open-source-contender-we-leo-meyerovich-j8ylc/">GLM-5.2 Becomes First Open-Weights Model to Match Frontier Performance on Cybersecurity Tasks</a></h3><p>Zhipu&#8217;s GLM-5.2, a 744-billion-parameter mixture-of-experts model with a 1-million-token context window released under MIT license, is the first open-weights model to genuinely compete with frontier proprietary models on cybersecurity tasks. Graphistry&#8217;s independent benchmarks show a 28/59 solve rate on CyBT-CTF, matching Anthropic Opus and beating Sonnet 4.5, at 2.2x lower cost. AISLE, has <strong><a href="https://stanislavfort.substack.com/p/mythos-at-home-and-its-called-aisle">separately demonstrated</a></strong> that widely available models can match Mythos on zero-day discovery, finding 20 of 23 OpenSSL zero-days over six months. I previously interviewed AISLE&#8217;s Cofounder Stanislav on the jagged frontier of AI:</p><div id="youtube2-J5xqeOSqs3s" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;J5xqeOSqs3s&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/J5xqeOSqs3s?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>There is a significant caveat, however. Graphistry&#8217;s statistical analysis found a Cohen&#8217;s Kappa correlation of 0.80 between GLM-5.2 and Opus outputs, which is unusually high and raises questions about whether the model may have been trained through illegal distillation from frontier providers. Open-weights parity is good for defenders. Open-weights parity achieved through stolen model weights is not.</p><h3><a href="https://www.okta.com/newsroom/press-releases/okta-announces-cross-app-access-partners/">Okta Expands Cross-App Access with 25+ Partners Including Anthropic</a></h3><p>Okta&#8217;s Cross App Access (XAA) protocol now has 25+ partners including Anthropic, Atlassian, Canva, Cloudflare, Cursor, Datadog, Docker, Figma, Slack, and Zoom. XAA replaces static API keys with centralized, identity-based access governance for AI agents, and has been formally incorporated as an official MCP authorization extension. </p><p>Anthropic is already running a production beta with Okta as the featured identity provider for Claude Enterprise. This is the kind of identity infrastructure the agent ecosystem desperately needs. Static API keys were never designed for autonomous agents acting on behalf of humans across dozens of applications.</p><h3><a href="https://github.com/OWASP/AISVS/blob/main/1.0/dist/AISVS-1.0-pre-release.pdf">OWASP AI Security Verification Standard Reaches v1.0 Pre-Release</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HeZ_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HeZ_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png 424w, https://substackcdn.com/image/fetch/$s_!HeZ_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png 848w, https://substackcdn.com/image/fetch/$s_!HeZ_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png 1272w, https://substackcdn.com/image/fetch/$s_!HeZ_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HeZ_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png" width="448" height="392.1551246537396" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:632,&quot;width&quot;:722,&quot;resizeWidth&quot;:448,&quot;bytes&quot;:109308,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HeZ_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png 424w, https://substackcdn.com/image/fetch/$s_!HeZ_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png 848w, https://substackcdn.com/image/fetch/$s_!HeZ_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png 1272w, https://substackcdn.com/image/fetch/$s_!HeZ_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9d1f3c5-6b46-4fa9-9dcc-1174285620bf_722x632.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The pre-release of AISVS 1.0 provides 14 chapters of testable security requirements covering the full AI system lifecycle. The standard spans training data integrity, input validation, model lifecycle management, infrastructure security, access control, supply chain, output control, memory and vector database security, agentic action security, and dedicated chapters for MCP security and adversarial robustness. </p><p>Three verification levels (baseline, standard for sensitive data, and critical infrastructure) help organizations select appropriate assurance depth. What makes AISVS different from the growing list of AI security frameworks is that the requirements are designed to be testable, not just aspirational. </p><p>This is the ASVS model applied to AI, and I expect it to become a resource for procurement and audit conversations.</p><h3><a href="https://www.abstract.security/blog/detecting-aws-bedrock-abuse-from-llmjacking-to-the-hidden-attack-vectors">Abstract Security Maps the Full AWS Bedrock Abuse Kill Chain</a></h3><p>Abstract Security&#8217;s ASTRO team produced a comprehensive detection guide for AWS Bedrock abuse that goes well beyond the basics. LLMjacking alone can cost victims $46,000 to $100,000+ per day, with stolen Bedrock access resold through reverse-proxy services for roughly $30 a month. </p><p>The average time from credential exposure to detection is 42 days. But the guide goes further, covering four additional attack vectors most organizations are not monitoring, including logging tampering, guardrail manipulation, RAG knowledge base extraction, and agent hijacking, each with distinct CloudTrail and CloudWatch signatures and practical detection rules. </p><p>If you are running Bedrock, this is the detection playbook you need.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://www.first.org/newsroom/releases/20260615">FIRST Mid-Year Forecast Projects 66,000 CVEs for 2026, Running 46% Above February Estimates</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OmFT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OmFT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png 424w, https://substackcdn.com/image/fetch/$s_!OmFT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png 848w, https://substackcdn.com/image/fetch/$s_!OmFT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png 1272w, https://substackcdn.com/image/fetch/$s_!OmFT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OmFT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png" width="1202" height="129" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:129,&quot;width&quot;:1202,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:38966,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OmFT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png 424w, https://substackcdn.com/image/fetch/$s_!OmFT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png 848w, https://substackcdn.com/image/fetch/$s_!OmFT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png 1272w, https://substackcdn.com/image/fetch/$s_!OmFT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc69e6446-c415-4fd7-95ab-493188045cfe_1202x129.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The numbers are anticipated, FIRST&#8217;s mid-year forecast reveals that 2026 CVE disclosures have accumulated a 46.3% drift above even the record-breaking projections from February, now targeting approximately 66,000 CVEs for the full year. </p><p>Three structural drivers explain the surge. </p><ul><li><p>AI-assisted vulnerability discovery, highlighted by Mozilla&#8217;s 164% spike in Q1 CVE disclosures attributed directly to AI tooling. </p></li><li><p>A 449% year-over-year surge in GitHub Security Advisory volume.</p></li><li><p>A 3,119% increase in VulnCheck CNA-of-Last-Resort activity. </p><p></p><p>But here is the critical nuance that most coverage misses. Actionable exploitability has remained flat. CISA KEV entries and EPSS scores above 10% have not materially increased. This is a volume problem, not an exploitation crisis, and organizations using risk-based prioritization can manage exposure without proportionally scaling headcount.</p></li></ul><h3><a href="https://www.linkedin.com/posts/alukashenkov_cve-ndaa-amendment-ugcPost-7475098323398545408-uNkP/">NDAA Amendment Would Codify CISA&#8217;s Role Managing the CVE Program</a></h3><p>Lawmakers are proposing an amendment to the FY2027 defense bill that would formally house the CVE program under CISA by statute, creating a 15-member governance board with permanent seats for CISA, NIST, and top-level CVE authorities alongside rotating industry and academic members. </p><p>The amendment also mandates a joint CISA-NIST modernization plan and elevates vulnerability enrichment to a formal part of CVE&#8217;s mission. This is a direct response to the near-collapse of CVE funding in spring 2025 when MITRE warned the program could go dark. Enshrining CVE in statute rather than leaving it dependent on contract renewals is the kind of structural fix the ecosystem needs.</p><p>I went deep into NVD, CVE&#8217;s and all things vulnerability management with my friend Patrick Garrity recently:</p><div id="youtube2-ZB51rSX909g" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;ZB51rSX909g&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/ZB51rSX909g?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://www.chatprd.ai/how-i-ai/how-mozilla-fixed-500-security-bugs-with-mythos">Mozilla Fixed Nearly 500 Security Bugs in One Month Using an Agentic AI Pipeline</a></h3><div id="youtube2-Idjt53tTv2U" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Idjt53tTv2U&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Idjt53tTv2U?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Mozilla&#8217;s security bug fixes spiked to 423 in April 2026, up from an average of roughly 20 per month. When they switched from Opus 4.6 to Mythos, the system found 12x as many vulnerabilities, including flaws hiding in the Firefox codebase for over 15 years. </p><p>The three-part pipeline uses a file prioritization judge to target the highest-risk files, an agentic bug hunter with a &#8220;creative lie&#8221; prompt (&#8221;we know there&#8217;s a bug, find it&#8221;), and a patching agent that generates and verifies fixes. Mozilla open-sourced the MCP tools on GitHub. The key insight from the project is that the model alone was not the breakthrough. </p><p>The custom agentic harness with clear goals, verification tools, and false-positive filtering was the real unlock, exactly the &#8220;system over the model&#8221; pattern that keeps proving out.</p><h3><a href="https://blog.volerion.com/posts/two-months-in-nist-cuts-back-on-enrichment-efforts/">Two Months After NIST Stops Enriching All CVEs, 38% Receive No Scheduled Analysis</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-Vxy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-Vxy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png 424w, https://substackcdn.com/image/fetch/$s_!-Vxy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png 848w, https://substackcdn.com/image/fetch/$s_!-Vxy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png 1272w, https://substackcdn.com/image/fetch/$s_!-Vxy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-Vxy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png" width="501" height="316.7241379310345" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:495,&quot;width&quot;:783,&quot;resizeWidth&quot;:501,&quot;bytes&quot;:36536,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-Vxy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png 424w, https://substackcdn.com/image/fetch/$s_!-Vxy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png 848w, https://substackcdn.com/image/fetch/$s_!-Vxy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png 1272w, https://substackcdn.com/image/fetch/$s_!-Vxy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bc7fa95-8e87-4c06-9f81-331b798e77d3_783x495.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Two months after NIST stopped enriching all CVEs in the National Vulnerability Database, the data tells a concerning story. </p><p>Of 13,441 non-rejected CVEs published in the review window, only 8,342 were prioritized for enrichment. The remaining 5,099 (38%) are marked &#8220;Not Scheduled.&#8221; Only about 20% of all published CVEs received a NIST CVSS vector, and the accuracy of what NIST does enrich is questionable, with documented cases of NIST scoring a vulnerability at 9.1 Critical versus an independent assessment of 4.4 Medium. </p><p>Organizations still relying solely on NVD for vulnerability management now face coverage, timeliness, and accuracy gaps simultaneously. The era of NVD as a single source of truth is over and honestly should have been several years ago as this has been like watching a slow train wreck.</p><h3><a href="https://www.kaggle.com/whitepaper-the-new-SDLC-with-vibe-coding">Google/Kaggle Whitepaper Draws the Line Between Vibe Coding and Agentic Engineering</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Rbv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Rbv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png 424w, https://substackcdn.com/image/fetch/$s_!5Rbv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png 848w, https://substackcdn.com/image/fetch/$s_!5Rbv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png 1272w, https://substackcdn.com/image/fetch/$s_!5Rbv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Rbv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png" width="536" height="321.2865497076023" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:410,&quot;width&quot;:684,&quot;resizeWidth&quot;:536,&quot;bytes&quot;:59743,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Rbv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png 424w, https://substackcdn.com/image/fetch/$s_!5Rbv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png 848w, https://substackcdn.com/image/fetch/$s_!5Rbv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png 1272w, https://substackcdn.com/image/fetch/$s_!5Rbv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8de4982c-ae33-4b17-bda8-aedf49211db3_684x410.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This 50-page whitepaper from Addy Osmani, Shubham Saboo, and Dr. Sokratis Kartakis makes a critical distinction that most vibe coding discourse misses. </p><p>&#8220;Vibe coding&#8221; (describing what you want in natural language and accepting AI output) is appropriate for prototyping but high-risk for production. &#8220;Agentic engineering&#8221; (structured AI-assisted development with proper harnesses, guardrails, and human oversight) is the production-grade approach. </p><p>The key equation is Agent = Model + Harness, where the harness includes instruction files, tools, sandboxes, orchestration logic, guardrails, and observability. AI compresses implementation from weeks to hours, but requirements, architecture, and verification do not compress proportionally. </p><p>The developer&#8217;s center of gravity shifts from writing code to designing systems and arbitrating quality, and understanding when that shift is safe is the real challenge.</p><h3><a href="https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/">Daniel Stenberg Wins First CVE Dispute for curl After Rating Bug &#8220;Lower Than LOW&#8221;</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NS0o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NS0o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png 424w, https://substackcdn.com/image/fetch/$s_!NS0o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png 848w, https://substackcdn.com/image/fetch/$s_!NS0o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png 1272w, https://substackcdn.com/image/fetch/$s_!NS0o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NS0o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png" width="405" height="345.8658743633277" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:503,&quot;width&quot;:589,&quot;resizeWidth&quot;:405,&quot;bytes&quot;:288618,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NS0o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png 424w, https://substackcdn.com/image/fetch/$s_!NS0o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png 848w, https://substackcdn.com/image/fetch/$s_!NS0o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png 1272w, https://substackcdn.com/image/fetch/$s_!NS0o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8df1b633-e40d-4186-946d-d985ba96b5ab_589x503.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The curl project, installed in approximately 30 billion instances globally, just fought and won its first CVE dispute since becoming a CNA in early 2024 (57 CVEs published since). </p><p>A researcher tried to force a CVE for a wildcard certificate matching error that only triggered with hostnames containing a leading dot, which is illegal in DNS, requiring an attacker to control both the local network and possess a matching wildcard certificate. The curl team rated it &#8220;lower than LOW&#8221; and MITRE agreed after a four-month dispute process. The story highlights two systemic issues I keep coming back to. </p><p>Every CVE assigned to a library with 30 billion installations triggers remediation workflows across the entire downstream ecosystem, and the dispute process itself took four months and three rounds of identical justification requests, which is far too slow for a system processing 66,000 CVEs a year.</p><h3><a href="https://www.paloaltonetworks.com/company/press/2026/ibm-red-hat-and-palo-alto-networks-expand-project-lightwell-to-help-organizations-respond-to-software-vulnerabilities">IBM, Red Hat, and Palo Alto Networks Expand Project Lightwell into Shield-and-Fix Vulnerability Response</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!v4ZG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v4ZG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png 424w, https://substackcdn.com/image/fetch/$s_!v4ZG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png 848w, https://substackcdn.com/image/fetch/$s_!v4ZG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png 1272w, https://substackcdn.com/image/fetch/$s_!v4ZG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v4ZG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png" width="569" height="222.95078922934076" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:422,&quot;width&quot;:1077,&quot;resizeWidth&quot;:569,&quot;bytes&quot;:102792,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!v4ZG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png 424w, https://substackcdn.com/image/fetch/$s_!v4ZG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png 848w, https://substackcdn.com/image/fetch/$s_!v4ZG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png 1272w, https://substackcdn.com/image/fetch/$s_!v4ZG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86951a43-a5f2-4eb9-ae2e-dd05266dae79_1077x422.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Project Lightwell, backed by IBM and Red Hat&#8217;s $5 billion commitment with 20,000+ engineers, expanded into a dual-action defense system combining same-day network-layer virtual patching from Palo Alto Networks with long-term software remediation. </p><p>The initiative extends Red Hat&#8217;s proven backporting methodology above the OS layer to Maven, PyPI, npm, and other application dependency ecosystems. As Nikesh Arora noted, &#8220;AI has compressed the window between vulnerability discovery and exploit from weeks to minutes.&#8221; </p><p>Early adopters include Bank of America, BNY, Citi, Goldman Sachs, JPMorgan Chase, Mastercard, Morgan Stanley, and Wells Fargo, essentially every major U.S. financial institution. That membership list tells you how seriously the sector is taking the patching velocity problem.</p><h3><a href="https://www.perplexity.ai/hub/blog/perplexity-is-open-sourcing-bumblebee">Perplexity Open-Sources Bumblebee for AI Developer Supply Chain Scanning</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3A7J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3A7J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png 424w, https://substackcdn.com/image/fetch/$s_!3A7J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png 848w, https://substackcdn.com/image/fetch/$s_!3A7J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png 1272w, https://substackcdn.com/image/fetch/$s_!3A7J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3A7J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png" width="622" height="377.062091503268" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:742,&quot;width&quot;:1224,&quot;resizeWidth&quot;:622,&quot;bytes&quot;:204064,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203325451?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3A7J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png 424w, https://substackcdn.com/image/fetch/$s_!3A7J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png 848w, https://substackcdn.com/image/fetch/$s_!3A7J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png 1272w, https://substackcdn.com/image/fetch/$s_!3A7J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F538590a6-42ff-4bce-8bf6-c576ea6ab11e_1224x742.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Bumblebee is a Go-based read-only scanner for developer endpoints covering four attack surfaces in a single pass, from language package managers (npm, PyPI, Go modules) to AI agent configurations (MCP), editor extensions (VS Code, Cursor, Windsurf), and browser extensions (Chrome, Edge, Firefox, Arc). </p><p>The critical design decision is that it never executes install scripts, never invokes package managers, and never reads source files, preventing the scanner from triggering the very supply chain attack it is checking for. </p><p>Traditional scanners that run npm or pip to verify packages can inadvertently execute malicious postinstall scripts. This is the kind of purpose-built tooling the AI developer ecosystem needs.</p><h3><a href="https://arxiv.org/abs/2606.13175">The End of Code Review? Not So Fast.</a></h3><p>Martin Monperrus published a provocative paper arguing that LLM-based coding agents have crossed a threshold where traditional human code review is no longer necessary for software quality. </p><p>His two core claims are that every stated goal of code review (defect detection, knowledge sharing, style enforcement) can now be served by agents at lower cost and higher throughput, and that the &#8220;agents write, humans review&#8221; model is a dead end because humans cannot meaningfully review AI-generated changes at scale. The AppSec implications deserve serious scrutiny. The NCC Group whitepaper I covered above documents dozens of real vulnerabilities in coding agents themselves, from sandbox escapes to permission bypasses. </p><p>If organizations move to agent-only review pipelines, the question is whether agent-based reviewers can reliably catch security vulnerabilities, supply chain risks, and logic flaws that human reviewers currently identify. Given what we know about AI guardrail reliability, the &#8220;end of code review&#8221; thesis feels premature from a security standpoint.</p><div><hr></div><h1>Final Thoughts</h1><p>This was one of the densest weeks I have covered in 103 issues of this newsletter.</p><p>The Five Eyes statement, three hyperscalers launching competing AI security platforms, Mozilla finding nearly 500 bugs in a month, 66,000 CVEs projected for the year, a young man in Ethiopia breaching 14 companies with Claude, and 26,000 agents compromised through a malicious skill that every scanner cleared as safe. </p><p>If there is a single thread connecting all of it, the gap between what AI enables and what security teams are equipped to handle is widening, not narrowing.</p><p>The good news is that the tooling is starting to catch up. IFC-based agent security from Microsoft, identity-governed agent access from Okta, testable AI security requirements from OWASP, read-only supply chain scanning from Perplexity, and shield-and-fix vulnerability response from Project Lightwell are all real, practical responses to real problems. </p><p>The bad news is that attackers are adapting just as fast. TOCTOU attacks on agent skill marketplaces, trivial guardrail bypasses through &#8220;authorized pentesting&#8221; framing, and LLMjacking operations costing victims six figures per day are all in the wild today.</p><p>The organizations that will navigate this well are the ones treating AI security as an architecture problem rather than a checkbox exercise. Build data-flow controls into your agent pipelines. Assume every model, open or closed, can be used offensively. Diversify your identity infrastructure for agents now, not later. And keep investing in risk-based vulnerability prioritization, because when you are staring at 66,000 CVEs a year, the ability to separate signal from noise is worth more than any scanning tool on the market.</p><blockquote><p><strong>Stay resilient!</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Cybersecurity's Friendly Fire Problem]]></title><description><![CDATA[We're restricting the tools defenders need most]]></description><link>https://www.resilientcyber.io/p/cybersecuritys-friendly-fire-problem</link><guid isPermaLink="false">https://www.resilientcyber.io/p/cybersecuritys-friendly-fire-problem</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 23 Jun 2026 13:00:31 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/801369de-e789-4d83-8cb3-ed8492d32207_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Every enterprise security practitioner has lived through the same cycle. </p><p>A new technology emerges, employees start using it, security panics, writes a policy banning it, and congratulates itself on risk reduction. Then six months later, the CISO discovers the entire engineering team has been using it anyway, just through personal accounts, unmonitored endpoints, and shadow channels where the security team has zero visibility.</p><p>We did it with cloud, we did it with mobile, we did it with SaaS and as I covered in <strong><a href="https://www.resilientcyber.io/p/bringing-security-out-of-the-shadows">Bringing Security Out of the Shadows</a></strong>, we are doing it again with AI, where 74% of workplace ChatGPT usage was already happening through non-corporate accounts as of early 2024. The pattern is so predictable it should qualify as a law of organizational behavior. </p><blockquote><p><strong>Restrictive security controls do not eliminate usage, they eliminate visibility.</strong></p></blockquote><p>What most practitioners have not yet reckoned with is that this same dynamic is now playing out at the geopolitical level. The United States government&#8217;s decision to suspend access to Anthropic&#8217;s Mythos model, and the broader posture of using export controls and model bans as security policy, is producing the exact same outcome that overly restrictive enterprise security policies produce. It is pushing usage into the shadows, accelerating alternative adoption, and stripping defenders of the visibility and tooling they need most.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Ban That Missed Its Target</h2><p>The alleged logic behind restricting Mythos was straightforward on the surface. The model demonstrated advanced autonomous cyber capabilities, including finding zero-day vulnerabilities and executing multi-stage attack simulations. The UK AI Safety Institute confirmed that Mythos completed a 32-step corporate network attack simulation. From a pure capability perspective, the concern was legitimate.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KyWY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KyWY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png 424w, https://substackcdn.com/image/fetch/$s_!KyWY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png 848w, https://substackcdn.com/image/fetch/$s_!KyWY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png 1272w, https://substackcdn.com/image/fetch/$s_!KyWY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KyWY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png" width="1047" height="655" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:655,&quot;width&quot;:1047,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:215131,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203237266?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KyWY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png 424w, https://substackcdn.com/image/fetch/$s_!KyWY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png 848w, https://substackcdn.com/image/fetch/$s_!KyWY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png 1272w, https://substackcdn.com/image/fetch/$s_!KyWY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F377cb405-1fa3-4c89-bd33-bc633fd89f35_1047x655.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>(Ironically their evaluations of GPT-5.5 found it was also on par, a point Anthropic made in their public blog/rebuttal regarding the Mythos ban, but I digress)</p><p>However, capability assessment without strategic context produces bad policy. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Joshua Saxe&quot;,&quot;id&quot;:50731283,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8bbf753c-129e-42b9-a54a-8e593c37a02f_144x144.png&quot;,&quot;uuid&quot;:&quot;64b37ff3-9b1b-41b1-b904-c9ebdc0a0d92&quot;}" data-component-name="MentionToDOM"></span> laid this out in stark terms in his recent analysis, arguing that <strong><a href="https://joshuasaxe181906.substack.com/p/glm-52-not-mythos-is-the-real-security">GLM-5.2, not Mythos, is the real security emergency</a></strong>. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Xhck!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Xhck!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png 424w, https://substackcdn.com/image/fetch/$s_!Xhck!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png 848w, https://substackcdn.com/image/fetch/$s_!Xhck!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png 1272w, https://substackcdn.com/image/fetch/$s_!Xhck!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Xhck!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png" width="530" height="397.13296398891964" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/facc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:541,&quot;width&quot;:722,&quot;resizeWidth&quot;:530,&quot;bytes&quot;:799487,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203237266?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Xhck!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png 424w, https://substackcdn.com/image/fetch/$s_!Xhck!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png 848w, https://substackcdn.com/image/fetch/$s_!Xhck!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png 1272w, https://substackcdn.com/image/fetch/$s_!Xhck!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffacc7cb7-1cc8-40ac-a86b-c47451e7dbe3_722x541.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>(Image credit to Josh)</p><p>GLM-5.2 is an open-weights model from a Chinese lab, widely regarded as the first open model capable of long-horizon agentic tasks comparable to what frontier closed models introduced in late 2025. It can be downloaded, run locally on a rack of H200 GPUs, fine-tuned to remove all safety guardrails, and operated with zero logging, zero monitoring, and zero accountability to any provider.</p><p>The distinction between Mythos and GLM-5.2 is the distinction that matters for security strategy, and it is the one the current policy ignores entirely. Mythos ran on Anthropic&#8217;s infrastructure where it was monitored 24/7 by dedicated trust and safety teams. </p><p>When Anthropic detected a sophisticated Chinese state-sponsored espionage campaign running through Claude Code in September 2025, they were able to identify the attack, map the operation across roughly 30 global targets, ban the accounts, notify affected entities, and coordinate with authorities. </p><p>That campaign represented <strong><a href="https://www.anthropic.com/news/disrupting-AI-espionage">the first documented case of a large-scale AI-orchestrated cyberattack</a></strong>, and Anthropic caught it because the attackers were operating on monitored infrastructure.</p><p>That visibility disappears entirely when attackers move to self-hosted open-weights models. There is no usage log, there is no trust and safety team watching, there is no account to ban, there is no detection to trigger. </p><blockquote><p><strong>By banning Mythos, we did not remove the capability from the threat actor&#8217;s toolbox, we removed our own ability to watch them use it.</strong></p></blockquote><p>I&#8217;ve been writing about the &#8220;jagged frontier&#8221; of AI when it comes to cyber and finding zero days, using examples from <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Niels Provos&quot;,&quot;id&quot;:34464160,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a6ffba3d-90db-4f6c-a117-18a247a91554_2048x2048.jpeg&quot;,&quot;uuid&quot;:&quot;e0f2993a-3ace-4d7f-9128-23fdef04afa5&quot;}" data-component-name="MentionToDOM"></span> and teams such as AISLE. That same dynamic exists across the broad range of cyber offensive capabilities, and with the introduction of open source models nearly on par with proprietary frontier models, the need for harness engineering is even less critical.</p><p>I had a full conversation with Niels on this topic and more:</p><div id="youtube2-gRgDsdm4RQo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;gRgDsdm4RQo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/gRgDsdm4RQo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Shadow Proliferation Goes Geopolitical</h2><p>Enterprise security professionals understand this dynamic intuitively. When you ban a tool that people need, you do not eliminate the need. You eliminate your ability to govern how the need gets met. </p><blockquote><p><strong>The shadow economy that forms around the ban is always harder to secure than the sanctioned usage you replaced.</strong></p></blockquote><p>Josh predicts this will manifest as a dark economy around open-weights model serving, analogous to the existing underground markets for malware, zero-days, and initial access brokering. Private API providers will spin up inference endpoints for offensive-capable open models with no terms of service, no monitoring, and no cooperation with law enforcement. </p><p>The technical friction that kept many attacker groups from adopting agentic AI for the first nine months of its existence has now been removed. Not by a breakthrough in the frontier labs, but by the open-weights ecosystem catching up to where frontier was a year ago.</p><p>This pattern is not happening in isolation either. It mirrors what the United States already experienced with chip export controls, where the attempt to deny China access to advanced semiconductors accelerated domestic Chinese chip development rather than preventing it. </p><p>The same dynamic is now playing out with AI models. </p><blockquote><p><strong>Every restriction the U.S. places on its own frontier capabilities creates a stronger incentive for the rest of the world to invest in alternatives the U.S. does not control.</strong></p></blockquote><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Nathan Lambert&quot;,&quot;id&quot;:10472909,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dad13b2b-20b2-44e0-a84d-732f3be8bee7_4128x4128.jpeg&quot;,&quot;uuid&quot;:&quot;2e7ac48d-04d2-427b-9976-addd150eb1ee&quot;}" data-component-name="MentionToDOM"></span> and <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Kevin Xu&quot;,&quot;id&quot;:9714824,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8724733-4f91-46b4-a37d-652026b382ae_400x400.jpeg&quot;,&quot;uuid&quot;:&quot;2c9c48d7-ecd7-4c80-a4b4-208baadb1513&quot;}" data-component-name="MentionToDOM"></span> made this case directly in <strong><a href="https://www.interconnects.ai/p/banning-open-source-ai-would-be-a">Banning Open Source AI Would Be a Mistake</a></strong>, arguing that regulating open source AI because of China would create a chilling effect on education, innovation, and competition while pushing the rest of the world toward adopting China&#8217;s models. The fact that Chinese labs are producing competitive open-source models should be a wake-up call that open source is under-invested and under-appreciated in the United States. The correct response is more support for domestic open source, not restrictions that cede the ground entirely.</p><h2>Undermining Our Own Strategic Objectives</h2><p>The contradiction at the center of current U.S. policy is difficult to overstate. </p><p>The administration&#8217;s own <strong><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">AI Executive Order</a></strong> frames American AI leadership as a core national security priority. It explicitly states that U.S. policy is to &#8220;<em>continue to lead an America First cybersecurity effort that enhances both our national security and our global AI dominance</em>.&#8221; The order directs CISA to facilitate access to frontier models for federal agencies, state and local authorities, rural hospitals, and critical infrastructure operators. It creates an AI cybersecurity clearinghouse and it expands federal hiring for AI-enabled defense.</p><p>The entire strategic vision depends on U.S.-built AI stacks being adopted broadly, both domestically and internationally. Then, the same government suspends access to the most capable model produced by a U.S. lab, triggering international conversations about technology sovereignty, accelerating adoption of Chinese open-source alternatives, and demonstrating to every potential international partner that relying on U.S. AI infrastructure carries political risk.</p><p>As I covered in <strong><a href="https://www.resilientcyber.io/p/the-regulation-pendulum-and-ais-national">The Regulation Pendulum and AI&#8217;s National Security Reckoning</a></strong>, the administration executed one of the most dramatic policy reversals in recent memory, going from heavy pro-deregulation to actively studying pre-deployment safety testing of frontier AI models in under a year. The exponential capability curve forced that reckoning, but the policy response is kneecapping American AI leaders domestically while doing nothing to constrain the open-weights ecosystem that now provides near-equivalent capabilities to anyone with the hardware to run it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x3SZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x3SZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png 424w, https://substackcdn.com/image/fetch/$s_!x3SZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png 848w, https://substackcdn.com/image/fetch/$s_!x3SZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png 1272w, https://substackcdn.com/image/fetch/$s_!x3SZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x3SZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png" width="320" height="404.8979591836735" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:620,&quot;width&quot;:490,&quot;resizeWidth&quot;:320,&quot;bytes&quot;:448529,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203237266?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!x3SZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png 424w, https://substackcdn.com/image/fetch/$s_!x3SZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png 848w, https://substackcdn.com/image/fetch/$s_!x3SZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png 1272w, https://substackcdn.com/image/fetch/$s_!x3SZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c48efab-95f8-4884-b805-e03cec4c8219_490x620.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Nathan Lambert&quot;,&quot;id&quot;:10472909,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dad13b2b-20b2-44e0-a84d-732f3be8bee7_4128x4128.jpeg&quot;,&quot;uuid&quot;:&quot;49a3def6-13c4-4339-9bb3-542a9a28206c&quot;}" data-component-name="MentionToDOM"></span> described this governance posture as &#8220;<em>vibe governance</em>&#8221; in his analysis of <strong><a href="https://www.interconnects.ai/p/welcome-to-the-agi-era-of-ai-governance">the AGI era of AI policy</a></strong>, where model releases are judged by political instincts and gut reactions rather than by transparent and technical rigorous security assessment. He argues that export bans on model weights are a lasting negative policy for the United States, and warned that Anthropic&#8217;s own years of comparing AI to nuclear weapons created the political conditions for exactly this kind of heavy-handed intervention.</p><h2>The Defender&#8217;s Dilemma</h2><p>The strategic cost of these policies extends beyond geopolitics, and there is a direct operational cost to the defender community.</p><p>Jen Easterly <strong><a href="https://www.foreignaffairs.com/united-states/end-cybersecurity">argued</a></strong> in Foreign Affairs that AI offers defenders a structural advantage because they possess more legitimate data about their own systems than attackers do, and AI is uniquely suited to pattern recognition and anomaly detection at scale.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7Efe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7Efe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png 424w, https://substackcdn.com/image/fetch/$s_!7Efe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png 848w, https://substackcdn.com/image/fetch/$s_!7Efe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png 1272w, https://substackcdn.com/image/fetch/$s_!7Efe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7Efe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png" width="525" height="140.03972758229284" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:235,&quot;width&quot;:881,&quot;resizeWidth&quot;:525,&quot;bytes&quot;:36321,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/203237266?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7Efe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png 424w, https://substackcdn.com/image/fetch/$s_!7Efe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png 848w, https://substackcdn.com/image/fetch/$s_!7Efe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png 1272w, https://substackcdn.com/image/fetch/$s_!7Efe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47204996-e944-4cd9-a3e2-4bbffbb0aeaa_881x235.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>That argument only holds if defenders actually have access to the most capable models. When you ban the best tool in the defender&#8217;s arsenal while attackers migrate to ungoverned alternatives, you are not managing risk, you are redistributing it from a place where you had some control to a place where you have none.</p><p>I discussed in <strong><a href="https://www.resilientcyber.io/p/the-vulnpocalypse-wont-wait-for-interagency">The Vulnpocalypse Won&#8217;t Wait for Interagency Coordination</a></strong>, partners using Claude to discover over 10,000 high-and-critical-severity vulnerabilities in a single month, a 10x improvement over prior methods. </p><p>The 2026 DBIR confirmed that vulnerability exploitation is now the leading initial access vector. Defenders need every advantage they can get, and the most capable AI models are the single largest force multiplier available. Restricting access to those models on the grounds that attackers might also use them ignores the reality that attackers already have equivalent capabilities through open-weights alternatives they can run without constraint.</p><p>Josh&#8217;s piece frames this as a race that defenders are now at risk of losing. The best models need to reach the vendors building cyber defense products and the CISOs deploying them. Only the efficiency gains from frontier AI give defenders a realistic chance to pay down the security tech debt that has accumulated over decades, build the detection and response innovations needed to compete with AI-enabled attackers, and actually close the gap between vulnerability discovery and remediation that currently stretches to 43 days on average for known exploited vulnerabilities.</p><h2>It Isn&#8217;t Just About Bans</h2><p>To be fair, the shift toward open-source AI adoption is not driven solely by export controls and model bans. Multiple structural forces are at work simultaneously.</p><p>Token costs play a major role, and it has been discussed by <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;id&quot;:11988704,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a89717e5-a927-4084-ad86-69068727dbf3_1632x1632.png&quot;,&quot;uuid&quot;:&quot;af3ca252-4bb7-4c06-97d6-b133388a8631&quot;}" data-component-name="MentionToDOM"></span>. The token costs for frontier API-based models remain high enough that many organizations, particularly those running AI at scale, find open-weights models running on their own infrastructure more economical. This includes in cybersecurity, where it is most painfully ironic as well, given the leading open source alternatives are from China, a nation with years of examples of being adversarial and damaging to U.S. interests and enterprise environments.</p><p>The desire for data sovereignty and control drives organizations and entire nations toward models they can host locally, where sensitive data never leaves their environment. This was the dominant conversation among the EU and those outside of the U.S. in my network on platforms such as LinkedIn post-Mythos ban. </p><p>Enterprises want to fine-tune models for their specific use cases without depending on a provider&#8217;s willingness to support custom deployments, and the rapid pace of open-weights model improvement, driven by massive investment from primarily Chinese labs, means the capability gap between open and closed models has narrowed significantly.</p><p>These factors would be driving open-source adoption regardless of U.S. policy decisions, but the model bans and export controls are accelerating the trend and, more importantly, they are handing China a strategic gift. </p><blockquote><p><strong>Every time the U.S. demonstrates that its frontier AI platforms can be shut down by political decision, it validates the argument that organizations and nations should not build critical dependencies on American AI infrastructure. </strong></p></blockquote><p>It pushes potential partners and allies toward self-hosted alternatives, and the open-weights models most readily available at near-frontier capability are increasingly coming from Chinese labs.</p><h2>The Pattern We Keep Refusing to Learn</h2><p>The through line from enterprise shadow IT to geopolitical AI policy is the same flawed theory of control. The assumption is that banning something removes it from the environment. </p><blockquote><p><strong>In practice, banning something removes it from the governed environment and pushes it into an ungoverned one.</strong></p></blockquote><p>At the enterprise level, this looks like employees using personal ChatGPT accounts to process sensitive data because the corporate AI policy says they cannot use AI at all. At the geopolitical level, this looks like attackers running fine-tuned GLM-5.2 on private infrastructure while U.S. defenders are denied access to the most capable American-built model. The scale is different but the mechanism and outcome is identical.</p><p>Anthropic&#8217;s detection of the first AI-orchestrated espionage campaign should be the proof point that settles this debate. That operation was caught because the attackers used a monitored, API-gated, commercially operated model. The AI performed 80-90% of the campaign autonomously, making thousands of requests per second at peak, across reconnaissance, vulnerability identification, exploit development, credential harvesting, and data exfiltration. Even if some of this is marketing on the part of labs such as Anthropic, the truths around visibility still remain.</p><p>If that same campaign had been run on a self-hosted open-weights model, there would have been no detection, no investigation, no notification to victims, and no public reporting. We would not even know it happened.</p><p>That is the world the current policy trajectory is creating. Not one where advanced AI cyber capabilities do not exist in the hands of adversaries, but one where those capabilities operate in complete darkness while defenders fight with one hand tied behind their back in a battle they had already been losing for decades.</p><h2>What Should Change</h2><p>The path forward requires the same shift in thinking that the best enterprise security teams have already made. Stop trying to prevent usage, start trying to govern it. Stop optimizing for the illusion of control, start optimizing for visibility, speed of adoption, and defender advantage.</p><p>At the policy level, that means centering the conversation on diffusion rather than denial. It means ensuring that U.S. defenders, from frontier lab security teams to the vendors building the next generation of security products to the CISOs and SOC analysts who deploy them, have unrestricted access to the most capable models available. It means recognizing that the open-weights genie is out of the bottle and that no amount of frontier model restriction will put it back.</p><p>It means learning the lesson that enterprise security has been learning the hard way for two decades. </p><blockquote><p><strong>The organizations that try to ban their way to security end up with less security, not more.</strong> </p></blockquote><p>The organizations that embrace new capabilities, wrap them in governance, and use them to outpace threats are the ones that actually reduce risk.</p><p>The same is true at the national level. </p><p>We can continue pursuing policies that look tough on AI risk while strategically weakening our own frontier leadership, driving international partners toward Chinese or non-U.S. alternatives, and pushing adversaries into ungoverned shadows where we cannot see them. Or we can do what good security teams do. Meet the technology where it is, arm the defenders, and compete.</p><p>I have been in cybersecurity long enough to know which approach actually works however it remains to be seen if policymakers will actually listen to practitioners before the window closes, and if it is unfortunately already too late.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[You Don't Need A Frontier Model to Find Zero Days]]></title><description><![CDATA[Why the Vulnpocalypse is overstated, what actually matters and the importance of security invariants]]></description><link>https://www.resilientcyber.io/p/you-dont-need-a-frontier-model-to</link><guid isPermaLink="false">https://www.resilientcyber.io/p/you-dont-need-a-frontier-model-to</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 22 Jun 2026 14:27:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/202578450/6bd4391275a5fc086c695677c0d94bfd.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>The loudest story in security right now is that AI has supercharged vulnerability discovery and a Vulnpocalypse is upon us. Niels Provos does not buy it. </p><p>He has spent twenty-five years in this field, from writing bcrypt to running security at Google and Stripe, and he came on to make a calmer and more uncomfortable argument, that the panic misses the point and the real fix is one we have understood for decades.</p><div id="youtube2-gRgDsdm4RQo" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;gRgDsdm4RQo&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/gRgDsdm4RQo?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><strong>Why this conversation matters</strong></p><p>Niels is about as technical as guests get, which is what makes his conclusion striking, because he keeps landing on incentives rather than technology. </p><p>He showed that finding zero days does not require a frontier model, then argued that this changes far less than the headlines suggest, because companies already drown in vulnerabilities and the answer was never to find or patch faster. </p><p>If you are a security leader deciding where to spend in the AI era, this conversation reframes the problem from a discovery race into a question of structural guarantees and the incentives that decide whether anyone actually builds them.</p><p><strong>Key takeaways</strong></p><ul><li><p><strong>Finding zero days is an orchestration problem, not a frontier-model problem.</strong> Niels built a finite state machine workflow on his Iron Curtain runtime, pointed an open-weight model at it, and surfaced net-new zero days, which shows the alarming capability was already here six months before Anthropic&#8217;s Mythos report made headlines.</p></li><li><p><strong>The harness is what makes weaker models dangerous.</strong> Models lose the plot over long tasks and take shortcuts because they are trained to please and to finish, so decomposing the work into bounded stages, each with a fresh context and a tight prompt, gets reliable results that a single sprawling prompt never would.</p></li><li><p><strong>The Vulnpocalypse is overstated.</strong> Companies already hold more vulnerabilities than they can manage, so a flood of new ones does not change the strategic picture, and Niels is blunt that the hyperbole mostly exists because it drives engagement.</p></li><li><p><strong>Security invariants make whole classes of bugs irrelevant.</strong> Rather than patching individual flaws, an invariant is an infrastructure guarantee that is systematically enforced without ongoing human judgment, an old idea that Google executed well and most organizations still skip.</p></li><li><p><strong>Egress control is the invariant to start with.</strong> When a production service can only reach a few known domains, most vulnerabilities cannot fetch a second-stage payload, so the exploit chain breaks before it does real damage.</p></li><li><p><strong>The log4j weekend is the proof.</strong> As head of security at Stripe, Niels took a full three-day weekend during log4j because egress control meant the malicious Java class could not be downloaded, turning a five-alarm fire into something his team could patch on its own schedule.</p></li><li><p><strong>Remediation is the bottleneck AI has not cracked.</strong> The hard part of fixing is not writing the patch, it is knowing you have not broken working code in production, and that quality bar keeps remediation slow even as discovery gets cheap.</p></li><li><p><strong>AI coding tools quietly route around your security.</strong> Asked to add an endpoint to a carefully structured project, the model ignored Niels&#8217;s authenticated-route abstractions and wrote raw code, which is why he wants frameworks that are secure by default rather than dependent on the model behaving.</p></li><li><p><strong>Open source maintainers are the highest-leverage place to invest.</strong> They power the largest companies in the world for free yet often cannot afford the tokens to use modern AI tooling, so empowering them to fix vulnerabilities benefits everyone downstream at once.</p></li><li><p><strong>It comes down to incentives, not technology.</strong> Companies do just enough to avoid looking negligent because they are built to maximize profit, so Niels argues that accountability regulation like Europe&#8217;s NIS2, not better tooling alone, is what actually shifts behavior.</p></li></ul><p><strong>Notable quotes</strong></p><blockquote><p>&#8220;you don&#8217;t need the latest and greatest models to find vulnerabilities very, very quickly&#8221;</p></blockquote><p>Niels Provos, on why this is an orchestration problem rather than a frontier-model problem.</p><blockquote><p>&#8220;it&#8217;s not the technology, it&#8217;s the incentives.&#8221;</p></blockquote><p>Niels Provos, on what actually has to change for security to improve.</p><blockquote><p>&#8220;technology isn&#8217;t really the solution. We know how to solve all of these problems.&#8221;</p></blockquote><p><strong>Subscribe</strong></p><p>If this kind of structural, incentives-first take on security is useful to you, subscribe to Resilient Cyber for more conversations and writing on cybersecurity, AI, and the forces that shape both.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Real Price Tag on Breaches]]></title><description><![CDATA[A look at Verizon's Data Breach Impact Study And What The Findings Teach Us]]></description><link>https://www.resilientcyber.io/p/the-real-price-tag-on-breaches</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-real-price-tag-on-breaches</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 19 Jun 2026 12:01:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vxrF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The cybersecurity industry has spent decades making claims about the financial devastation of data breaches. Vendors sell on fear, conference keynotes invoke existential dread, boards get told that a breach could end the company, and often most of those claims have been built on anecdotal evidence, cherry-picked headlines, and a single average-cost figure from an annual IBM report that few practitioners ever trusted but everyone cited anyway.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z07v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z07v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png 424w, https://substackcdn.com/image/fetch/$s_!Z07v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png 848w, https://substackcdn.com/image/fetch/$s_!Z07v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png 1272w, https://substackcdn.com/image/fetch/$s_!Z07v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z07v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png" width="297" height="367.06471816283926" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1184,&quot;width&quot;:958,&quot;resizeWidth&quot;:297,&quot;bytes&quot;:938156,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/202596731?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Z07v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png 424w, https://substackcdn.com/image/fetch/$s_!Z07v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png 848w, https://substackcdn.com/image/fetch/$s_!Z07v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png 1272w, https://substackcdn.com/image/fetch/$s_!Z07v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc786b609-335a-4929-83a3-b17e6f4e6aa1_958x1184.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That changes with Verizon&#8217;s 2026 Breach Impact Study (BIS). Produced by the same team behind the Data Breach Investigations Report (DBIR) and built on a partnership with CyberAcuView, this is a rigorous, insurance-claims-backed analysis of what breaches actually cost. As I covered in <strong><a href="https://www.resilientcyber.io/p/the-dbirs-exploitation-era">The DBIR&#8217;s Exploitation Era</a></strong>, the 2026 DBIR gave us the clearest picture yet of how breaches happen. The BIS gives us the other half of that equation, what happens after and how much it costs organizations.</p><p>The dataset is substantial, where the research team reviewed approximately 70,000 cyber insurance claims in the United States, of which roughly 38,000 had recorded losses paid out to policyholders. </p><p>The claims cover insurable incidents from January 1, 2019, through October 31, 2025. This is not a survey, this is not self-reported, these are actual dollars paid through actual insurance policies, normalized and standardized by CyberAcuView&#8217;s member insurers. </p><blockquote><p><strong>The authors are careful to frame these figures as floors, not ceilings. </strong></p></blockquote><p>The dataset captures insurable losses only, meaning it excludes uninsured losses, reputational damage, and non-claim costs. The true economic impact of these incidents is almost certainly higher.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>What Breaches Actually Cost</h2><p>The headline numbers tell a story that should recalibrate how practitioners and executives think about breach impact.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vxrF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vxrF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png 424w, https://substackcdn.com/image/fetch/$s_!vxrF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png 848w, https://substackcdn.com/image/fetch/$s_!vxrF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png 1272w, https://substackcdn.com/image/fetch/$s_!vxrF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vxrF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png" width="471" height="402.2672811059908" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1112,&quot;width&quot;:1302,&quot;resizeWidth&quot;:471,&quot;bytes&quot;:1116374,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/202596731?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vxrF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png 424w, https://substackcdn.com/image/fetch/$s_!vxrF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png 848w, https://substackcdn.com/image/fetch/$s_!vxrF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png 1272w, https://substackcdn.com/image/fetch/$s_!vxrF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7caf8ad-12a5-4bbc-a89c-d8127fbb89f8_1302x1112.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Half of all reviewed paid-out claims had a financial impact greater than $83,000. That is the median, the top 10% exceeded $920,000, and the most extreme cases, the top 2.5% of the dataset, surpassed $5 million in insured losses. For every 100 organizations that file a claim, approximately 50 face losses under $83,000, 10 face losses exceeding $920,000, and two to three face losses exceeding $5 million.</p><p>Those numbers matter because they replace the single-average-figure approach that has distorted risk conversations for years. The BIS authors deliberately chose medians over averages because averages are easily distorted by outliers. They also published the full distribution, which means organizations can finally position themselves against actual percentile outcomes rather than a single number that applies to no one.</p><h2>The Costs Are Rising, and It&#8217;s Not Just Inflation</h2><p>Segmenting the data by year reveals a trend that should concern any practitioner focused on long-term risk modeling and helps demonstrate the changes in terms of breach impact costs over time.. The median impact almost doubled from 2019 to 2024, rising from roughly $60,000 to roughly $110,000, that is an 80% increase. The top 10% impact went from around $435,000 to around $1.05 million. The top 2.5% went from around $2.44 million to around $5.14 million, more than doubling.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aSfe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aSfe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png 424w, https://substackcdn.com/image/fetch/$s_!aSfe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png 848w, https://substackcdn.com/image/fetch/$s_!aSfe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png 1272w, https://substackcdn.com/image/fetch/$s_!aSfe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aSfe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png" width="874" height="1164" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1164,&quot;width&quot;:874,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:984690,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/202596731?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aSfe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png 424w, https://substackcdn.com/image/fetch/$s_!aSfe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png 848w, https://substackcdn.com/image/fetch/$s_!aSfe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png 1272w, https://substackcdn.com/image/fetch/$s_!aSfe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7377014-68f1-45a2-a0ba-edfc43c9a8d8_874x1164.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Consumer Price Index inflation in the United States over the same period was around 23%. Breach costs grew at more than three times that rate. This is real growth in breach impact, not a statistical artifact of inflation. Breaches are genuinely becoming more expensive, driven by the growth of ransomware, the increasing complexity of incident response, and the expanding regulatory environment that creates downstream liability.</p><p>The 2023 data is particularly striking, because the BIS team found a significant spike in the top 10% and extreme impact tiers that year, driven by a surge of zero-day vulnerabilities that supported widespread ransomware campaigns. Many organizations were caught unprepared, and the insurance data suggests that unpreparedness translated directly into higher financial impact.</p><p>It will be interesting to see how the industrialization of vulnerability discovery and autonomous exploitation, which I have been writing about a lot lately, shows up in future breach impact data, if at all. While it isn&#8217;t widespread yet, I anticipate that may change in coming years as AI is democratizing destructive behavior for malicious actors, and enhancing the capabilities of those.</p><h2>Size Matters, But Not the Way You Think</h2><p>The BIS segments organizations into three revenue brackets: SMBs with revenue under $25 million, mid-market businesses between $25 million and $250 million, and large enterprises above $250 million.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RfTu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RfTu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png 424w, https://substackcdn.com/image/fetch/$s_!RfTu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png 848w, https://substackcdn.com/image/fetch/$s_!RfTu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png 1272w, https://substackcdn.com/image/fetch/$s_!RfTu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RfTu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png" width="1356" height="940" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:940,&quot;width&quot;:1356,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:972619,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/202596731?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RfTu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png 424w, https://substackcdn.com/image/fetch/$s_!RfTu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png 848w, https://substackcdn.com/image/fetch/$s_!RfTu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png 1272w, https://substackcdn.com/image/fetch/$s_!RfTu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14293d28-7a4b-4bbf-be7f-645341491be3_1356x940.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The absolute dollar amounts scale predictably with size. The SMB median is approximately $38,000, the mid-market median almost triples to roughly $96,000. Large enterprise jumps more than seven times higher to around $283,000. At the extreme end, the top 2.5% of large enterprise claims exceeded $22 million per claim, which is 22 times larger than the same percentile for SMBs.</p><p>But the ratio to revenue tells a different story. For SMBs, breach impact reached as high as 3% of revenue in the top 10% of cases and over 7% in the most extreme 2.5%. For mid-market and large enterprises, that ratio never exceeded 2%, even in the worst cases. SMBs face a disproportionate burden relative to their ability to absorb it, which matters because these are exactly the organizations with fewer resources to invest in prevention and recovery.</p><p>This is the textbook example of the cybersecurity poverty line popularized by Wendy Nather, and something my friend <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ross Haleliuk&quot;,&quot;id&quot;:2607604,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8fa0e73b-27de-49eb-a585-393f1add9ab8_1500x1000.jpeg&quot;,&quot;uuid&quot;:&quot;7331c65a-a122-443a-b580-902f7f160745&quot;}" data-component-name="MentionToDOM"></span> and I have written about in a piece titled &#8220;<strong><a href="https://ventureinsecurity.net/p/lifting-the-world-out-of-the-cybersecurity">Lifting the World Out of Cybersecurity Poverty</a></strong>&#8221;. These SMBs have far less expertise and financial resources yet suffer significantly more financially from incidents than their large counterparts.</p><p>I touched on some of these systemic struggles with Wendy herself and Casey Ellis in a past issue of Resilient Cyber:</p><div id="youtube2-GFhkL9wEl9w" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;GFhkL9wEl9w&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/GFhkL9wEl9w?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Where the Money Actually Goes</h2><p>The BIS breaks insured losses into four categories that the authors call the &#8220;4Ls&#8221; of breach impact.</p><ul><li><p>Loss to threat actor includes direct payments like ransom and funds stolen through fraud. </p></li><li><p>Loss due to business interruption covers both the organization&#8217;s own downtime and contingent interruption from third-party outages. </p></li><li><p>Loss due to response and recovery captures incident response and data restoration costs. </p></li><li><p>Loss due to external liability includes regulatory penalties, PCI fines, and lawsuit settlements.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xG7Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xG7Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png 424w, https://substackcdn.com/image/fetch/$s_!xG7Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png 848w, https://substackcdn.com/image/fetch/$s_!xG7Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png 1272w, https://substackcdn.com/image/fetch/$s_!xG7Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xG7Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1261750,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/202596731?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xG7Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png 424w, https://substackcdn.com/image/fetch/$s_!xG7Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png 848w, https://substackcdn.com/image/fetch/$s_!xG7Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png 1272w, https://substackcdn.com/image/fetch/$s_!xG7Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec549f79-b80a-404e-8c44-97e07df6dd16_1824x1218.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The distribution across these categories challenges some common assumptions.</p><ul><li><p>Response and recovery shows up in 69% of claims but represents only 29% of total losses, with a median cost of $25,275. </p></li><li><p>Loss to threat actor appears in 24% of claims and accounts for 25% of total losses, with a median of $62,886. </p></li><li><p>Business interruption appears in only about 10% of claims but accounts for a disproportionate 22% of overall costs, with the highest median of any category at $90,000 and extreme cases reaching nearly $5 million.</p></li></ul><p>The growth of business interruption is the trend most practitioners should be watching. </p><p>Its share of known losses grew 51% in just one year, from 21% in 2023 to 32% in 2024. In 2024, the dataset also began tracking contingent business interruption separately, meaning downtime caused by a third-party outage rather than a direct attack. That category represented 13% of all known loss types in its debut year. Across all years, business interruption as a whole <strong>accounted for 50% of total known loss amounts</strong> in supply chain or third-party incidents.</p><p>This is the financial evidence for something practitioners have been saying for years. Third-party risk is not just a compliance checkbox. It is a material financial exposure that shows up in real claims data.</p><p>This data also emphasizes why security can be a friction point and problematic in some cases. Organizations are rightfully reluctant to disrupt business operations to address security issues (e.g. patching) in some cases, and the last thing security wants to do is violate the A of the CIA triad ourselves. </p><h2>Ransomware&#8217;s Outsized Economics</h2><p>Ransomware accounts for 36% of claims in the BIS dataset but <strong>73% of total insured costs</strong>, with a median impact of $303,547. That is more than three and a half times the overall dataset median. The BIS quadrant chart captures this disparity cleanly, showing ransomware in the upper-right quadrant, meaning it is both common and expensive.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s6Mt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s6Mt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png 424w, https://substackcdn.com/image/fetch/$s_!s6Mt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png 848w, https://substackcdn.com/image/fetch/$s_!s6Mt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png 1272w, https://substackcdn.com/image/fetch/$s_!s6Mt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s6Mt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png" width="701" height="421.27403846153845" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:875,&quot;width&quot;:1456,&quot;resizeWidth&quot;:701,&quot;bytes&quot;:695702,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/202596731?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s6Mt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png 424w, https://substackcdn.com/image/fetch/$s_!s6Mt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png 848w, https://substackcdn.com/image/fetch/$s_!s6Mt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png 1272w, https://substackcdn.com/image/fetch/$s_!s6Mt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb284a01f-8b34-4d87-a603-fca033ef70a5_1550x932.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>BEC, by contrast, shows up in 12% of claims but represents only 1% of total cost, with a median of $53,035. BEC is common but comparatively cheap, ransomware is common and devastating.</p><p>The BIS also reveals that 69% of ransomware victims did not end up paying the ransom, aligning with findings from the 2026 DBIR that the percentage of victims choosing not to pay has been growing since at least 2022, and 48% of ransomware claims had no data restoration and no extortion claims at all, suggesting that in many cases, the threat actors either failed to encrypt systems successfully or the organizations chose not to engage.</p><h2>Organizations Don&#8217;t Die From Breaches</h2><p>Here is where the conversation gets uncomfortable for cybersecurity professionals, myself included, given in our hearts we <em>want</em> the data to help support our desire for businesses to take cyber more seriously, invest more, and treat it as more of a priority.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4KoE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4KoE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png 424w, https://substackcdn.com/image/fetch/$s_!4KoE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png 848w, https://substackcdn.com/image/fetch/$s_!4KoE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png 1272w, https://substackcdn.com/image/fetch/$s_!4KoE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4KoE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png" width="1456" height="498" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:498,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:165711,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/202596731?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4KoE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png 424w, https://substackcdn.com/image/fetch/$s_!4KoE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png 848w, https://substackcdn.com/image/fetch/$s_!4KoE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png 1272w, https://substackcdn.com/image/fetch/$s_!4KoE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc0a8fa4-90a2-4dc4-9a75-25791fe9a3ac_2240x766.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;id&quot;:11988704,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a89717e5-a927-4084-ad86-69068727dbf3_1632x1632.png&quot;,&quot;uuid&quot;:&quot;94a2bd3d-eac6-4c6a-b4a9-5dc4a9594a40&quot;}" data-component-name="MentionToDOM"></span> has spent years curating <strong><a href="https://destroyedbybreach.com">destroyedbybreach.com</a></strong>, a searchable database of companies that actually ceased to exist as a direct result of a cybersecurity incident. </p><p>After roughly a decade of research, he has found only about 25 to 32 companies that meet that criteria. Given the thousands of breaches that occur every year, that is a remarkably small number. </p><blockquote><p><strong>The widely recycled statistic that &#8220;60% of small businesses go out of business within six months of being hacked&#8221; has no traceable original source and no credible evidence behind it.</strong></p></blockquote><p>As we discussed above, SMB&#8217;s do indeed face outsized financial impacts, but that rarely leads to them actually going out of business due to a material cyber incident.</p><p>The companies that did collapse shared a common pattern. The breach was the trigger, but not the root cause. These organizations lacked incident response plans, had no ability to contain damage, maintained no usable backups, and had no operational resilience. The breach exposed pre-existing organizational failures, it did not create them.</p><p>As I covered in <strong><a href="https://www.resilientcyber.io/p/cybersecuritys-delusion-problem">Cybersecurity&#8217;s Delusion Problem</a></strong>, the cybersecurity industry has a tendency to overstate its centrality to business outcomes. Revenue, speed to market, market share, and competitive positioning rightfully take priority for most organizations. Microsoft has weathered multiple severe, high-profile security incidents and continues to grow in consumption, revenue, and market share. </p><blockquote><p><strong>The market sends a clear signal, and that signal is not &#8220;</strong><em><strong>cybersecurity failures are existential</strong></em><strong>.&#8221;</strong></p></blockquote><p>This is why many consider cybersecurity to be a market failure that won&#8217;t solve itself and will require regulation. That of course opens another debate about regulation vs. innovation and if the costs of incidents are working as intended and businesses are paying the costs they are willing to tolerate.</p><p>Kelly Shortridge made this case with empirical precision in <strong><a href="https://kellyshortridge.com/blog/posts/markets-dgaf-about-cybersecurity/">Markets DGAF About Cybersecurity</a></strong>, citing two peer-reviewed studies presented at the Workshop on the Economics of Information Security. </p><p>One found no statistically significant stock impact from data breach announcements in European markets across any industry sector. The other found an insignificant relationship between trade secret theft and subsequent stock market performance, regardless of whether the attack was targeted, sophisticated, or conducted by nation-state actors. </p><blockquote><p><strong>The researchers concluded that it was difficult to support business cases for cybersecurity investment based on stock price impact alone.</strong></p></blockquote><p>Comparitech&#8217;s analysis of 118 publicly traded companies breached between 2007 and 2023 found that share prices bottomed out roughly 41 business days after breach disclosure, dropping an average of 1.4%, and recovered to pre-breach absolute levels within approximately 53 business days. </p><p>That figure gets cited frequently, but the context matters. Breached companies continued to underperform the NASDAQ by 3.2% after six months, 8.6% after one year, and 15.6% after three years. The stock price &#8220;recovers&#8221; in absolute terms, but investors in breached companies still do worse than the broader market over time. The damage is real, it just is not the company-killing event the industry has been selling.</p><h2>But the Risk Is Real</h2><p>None of this means cybersecurity does not matter and the BIS data makes that clear in several important ways.</p><p>The median breach costs $83,000, but the distribution has a long tail. Two to three out of every 100 claimants face losses exceeding $5 million. For SMBs, those costs can represent 7% of annual revenue. Supply chain incidents carry a median cost more than double the overall dataset at $252,666, with the extreme top 2.5% exceeding $100 million. </p><blockquote><p><strong>These are insured losses only, meaning they represent the floor of actual economic impact, not the ceiling.</strong></p></blockquote><p>External liability adds another dimension that matters enormously when regulation is involved. Liability costs appear in only 6.4% of total claims, but the median loss is around $22,000 and the extreme cases exceed $4.1 million. </p><p>Healthcare organizations face liability costs 57% higher than the overall median. The Retail sector saw the highest rate of liability losses at approximately 18% of cases, and because third-party liability claims often involve long settlement timelines, the BIS authors note that their dataset likely undercounts the true frequency and magnitude of these costs.</p><p>Manufacturing faces its own disproportionate burden. Business interruption losses in manufacturing carry a median 158% higher than the overall dataset and account for 30% of all losses in that sector. When production stops, the financial clock runs fast., and I feel this represents the differences between the physical and digital realms.</p><p>The BIS data tells a story consistent with what risk practitioners already know. Cyber risk is a real financial exposure. It follows a distribution with a fat tail.</p><p>Organizations should be asking themselves whether their current risk models and insurance coverage account for the actual distribution of outcomes, including the tail scenarios where losses reach seven and eight figures.</p><h2>What This Data Should Change</h2><p>The BIS represents a significant step forward for an industry that has historically operated on vibes, vendor-sponsored surveys, and recycled statistics of questionable provenance coupled with marketing hype and FUD to try and dive spending. </p><p>This is a great large-scale, claims-backed dataset that tells us what breaches cost across different organization sizes, industries, incident types, and loss categories.</p><p>The implications cut in both directions. </p><p>Practitioners who have been selling cybersecurity as existential risk need to reckon with the evidence that organizations overwhelmingly survive breaches and that markets absorb cyber events without the catastrophic consequences the industry has promised. </p><p>At the same time, practitioners who dismiss cyber risk as immaterial need to reckon with the fat-tailed distribution, the real year-over-year growth in impact that outpaces inflation by a factor of three, and the increasingly material role of business interruption and regulatory liability.</p><p>The BIS data does not support the FUD narrative, but it does not support complacency either. </p><p>It supports something the cybersecurity industry has always struggled with, which is proportion. Knowing that the median ransomware claim costs $303,547 and that business interruption grew from 21% to 32% of known losses in a single year is more actionable than any scare statistic about &#8220;the average cost of a data breach.&#8221; </p><p>Knowing that SMBs face a 7% revenue impact in the worst cases while large enterprises rarely exceed 2% tells you something specific about where to focus resources and coverage. Ironically, most startups target large enterprises, those with the resources and expertise to face less of an impact than SMB&#8217;s, and they do it rightfully so because that is where the budget to purchase cutting edge software and innovative solutions resides, along with the big logos startups need to justify market momentum and continued investment from VC&#8217;s.</p><p>The best risk decisions come from the best data. The BIS gives us better data than we have ever had. It remains to be seen if the industry will use it to have honest conversations about proportionate risk, or whether it will cherry-pick the scariest numbers and continue the cycle of FUD that has defined cybersecurity marketing for decades.</p><blockquote><p><strong>I know which one I would bet on, but I also know which one I will keep advocating for.</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item></channel></rss>