<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Resilient Cyber]]></title><description><![CDATA[Resilient Cyber distills the week's most important news, research, and writing across AppSec,
AI security, software supply chain, and security leadership. Join 30,000+]]></description><link>https://www.resilientcyber.io</link><image><url>https://substackcdn.com/image/fetch/$s_!ITbg!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F71894ea3-c231-4d31-90a9-414d75111d0e_1280x1280.png</url><title>Resilient Cyber</title><link>https://www.resilientcyber.io</link></image><generator>Substack</generator><lastBuildDate>Sat, 13 Jun 2026 08:52:13 GMT</lastBuildDate><atom:link href="https://www.resilientcyber.io/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Chris Hughes]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[resilientcyber@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[resilientcyber@substack.com]]></itunes:email><itunes:name><![CDATA[Chris Hughes]]></itunes:name></itunes:owner><itunes:author><![CDATA[Chris Hughes]]></itunes:author><googleplay:owner><![CDATA[resilientcyber@substack.com]]></googleplay:owner><googleplay:email><![CDATA[resilientcyber@substack.com]]></googleplay:email><googleplay:author><![CDATA[Chris Hughes]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Death of CVSS As Federal Policy]]></title><description><![CDATA[BOD 26-04 Kills the CVSS Patch Clock and Replaces It with Actual Risk Management]]></description><link>https://www.resilientcyber.io/p/the-death-of-cvss-as-federal-policy</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-death-of-cvss-as-federal-policy</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 12 Jun 2026 11:00:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IbVc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>CISA issued <strong><a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk">Binding Operational Directive 26-04</a></strong> on June 10, 2026, and it&#8217;s one of the more consequential vulnerability management policies the federal government has published in a long time. I say that as someone who has spent a large portion of his career in the U.S. public sector (e.g. Federal and DOW). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aFM_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aFM_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png 424w, https://substackcdn.com/image/fetch/$s_!aFM_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png 848w, https://substackcdn.com/image/fetch/$s_!aFM_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png 1272w, https://substackcdn.com/image/fetch/$s_!aFM_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aFM_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png" width="573" height="308.2298716452742" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2835646-ed40-493d-9b74-c5906c34b719_857x461.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:461,&quot;width&quot;:857,&quot;resizeWidth&quot;:573,&quot;bytes&quot;:517385,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201643881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aFM_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png 424w, https://substackcdn.com/image/fetch/$s_!aFM_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png 848w, https://substackcdn.com/image/fetch/$s_!aFM_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png 1272w, https://substackcdn.com/image/fetch/$s_!aFM_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2835646-ed40-493d-9b74-c5906c34b719_857x461.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I say this not because it invented anything new, but because it finally codified what practitioner have been arguing for years. </p><blockquote><p><strong>Prioritize remediation based on risk, not generic severity scores. Prioritize based on exploitation, exposure, and impact, not arbitrary CVSS thresholds. Stop pretending every critical vulnerability demands the same urgency.</strong></p></blockquote><p>The directive is titled &#8220;Prioritizing Security Updates Based on Risk,&#8221; and the name tells you everything about the shift. For the first time, U.S. Federal agencies are required to use Stakeholder-Specific Vulnerability Categorization (SSVC) rather than CVSS base scores to drive remediation timelines. It revokes both BOD 19-02 and BOD 22-01, replacing flat-deadline patch mandates with a risk-tiered framework built on four factors that actually matter.</p><p>I&#8217;ve been writing about this exact approach for years, including in my book <strong><a href="https://www.wiley.com/en-us/Effective+Vulnerability+Management%3A+Managing+Risk+in+the+Vulnerable+Digital+Ecosystem-p-9781394221219">Effective Vulnerability Management</a></strong>, and across dozens of Resilient Cyber articles. Seeing it formalized in a binding directive is a significant milestone. But formalization and execution are different things, and the gap between what BOD 26-04 demands and what agencies can actually deliver today is what I want to dive into and walkthrough.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>What BOD 26-04 Actually Requires</h2><p>The directive applies to all Federal Civilian Executive Branch agencies and the systems they operate, including third-party hosted and cloud environments. CISA acting director Nick Andersen signed it, and CISA&#8217;s Chris Butera and Jonathan Spring co-authored the accompanying blog post under the tagline &#8220;<strong><a href="https://www.cisa.gov/news-events/news/patch-smarter-not-harder">Patch Smarter, Not Harder.</a></strong>&#8221;</p><p>The core mechanism is a four-factor risk assessment that determines remediation timelines. Every vulnerability gets evaluated against four criteria. </p><ul><li><p><strong>Is the vulnerable asset publicly exposed? </strong></p></li><li><p><strong>Is the vulnerability listed in the KEV catalog? </strong></p></li><li><p><strong>Can exploitation be fully automated? </strong></p></li><li><p><strong>Does exploitation give attackers partial or total control of the system?</strong></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IbVc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IbVc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png 424w, https://substackcdn.com/image/fetch/$s_!IbVc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png 848w, https://substackcdn.com/image/fetch/$s_!IbVc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png 1272w, https://substackcdn.com/image/fetch/$s_!IbVc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IbVc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png" width="1179" height="767" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:767,&quot;width&quot;:1179,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:513427,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201643881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IbVc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png 424w, https://substackcdn.com/image/fetch/$s_!IbVc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png 848w, https://substackcdn.com/image/fetch/$s_!IbVc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png 1272w, https://substackcdn.com/image/fetch/$s_!IbVc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32423abe-c147-4e10-b5fc-63483e4f62e8_1179x767.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>(Image credit - <strong><a href="https://www.vulncheck.com/blog/cisa-bod-26-04">VulnCheck&#8217;s Blog</a></strong>)</p><p>The answers to those four questions determine whether you patch in 3 days, 14 days, 60 days, or defer to the next system upgrade. The highest-risk vulnerabilities, those that are publicly exposed, in the KEV catalog, automatable, and deliver total control, must be remediated within <em>72 hours</em>. </p><p>Those same vulnerabilities also require forensic triage before patching to determine whether the system has already been compromised. That forensic assessment requirement is entirely new and reflects a hard-won operational reality, and likely comes as a result of incidents some agencies have already experienced in the past.</p><blockquote><p><strong>Patching a system an attacker already controls doesn&#8217;t evict them.</strong></p></blockquote><p>At the other end of the spectrum, vulnerabilities that aren&#8217;t publicly exposed, aren&#8217;t in the KEV, can&#8217;t be automated, and only deliver partial impact can be deferred until the next scheduled system upgrade. CISA&#8217;s own analysis of one large federal agency found that only 1% of vulnerabilities fell into the 3-day window, while over 60% could be deferred. </p><p>That ratio alone tells you how much wasted effort the old approach generated. and it isn&#8217;t an outlier, as I have written about many times, true exploitation rates are a fraction of the overall CVE&#8217;s published in a given year.</p><p>Agencies must update vulnerability management policies immediately, achieve compliance with all remediation timelines within 180 days, and continuously identify and tag all agency-owned assets reachable from outside the network. </p><p>Asset tagging requirements include organization, operating environment, exposure status, asset type, and all associated IP addresses. Agencies without full CDM automation must submit vulnerability data to CISA every seven days in machine-readable format.</p><p>While I understand this requirement, this is also a very cumbersome activity, and based on my experience in the Federal space, by the time it gets ingested and reviewed, it is likely stale and warrants a new export anyways.</p><h2>The Death of CVSS as Federal Policy</h2><p>This directive formally kills CVSS as the driving prioritization mechanism for federal vulnerability management (beyond KEV&#8217;s) and that alone makes it historic.</p><p>For years, federal policy, PCI DSS, and countless enterprise vulnerability management programs treated CVSS base scores as the primary input for remediation timelines. Critical and high severity vulnerabilities got 7-to-30-day deadlines, Medium got 60-90 days, Low got deprioritized or ignored. </p><blockquote><p><strong>The problem is that CVSS measures theoretical severity in a vacuum, it doesn&#8217;t account for whether the vulnerability is actually exploited, whether the asset is exposed, or whether exploitation is automatable at scale.</strong></p></blockquote><p>This is a point I have made for years in various articles on here, CSO Online, my own book and in public talks.</p><p>As I covered in <strong><a href="https://www.resilientcyber.io/p/a-look-at-the-exploit-prediction">A Look at the Exploit Prediction Scoring System</a> (EPSS)</strong>, research from ACM demonstrated that:</p><blockquote><p><strong>Using CVSS severity alone to measure risk is equivalent to picking random vulnerabilities to fix. </strong></p></blockquote><p>Organizations can only remediate 5-20% of vulnerabilities per month, with a median around 15.5%. When you&#8217;re burning that limited remediation capacity on vulnerabilities that will never be exploited, you&#8217;re not managing risk, you&#8217;re performing compliance theater, another topic I have railed against.</p><p>BOD 26-04 replaces that theater with SSVC, the decision-tree model developed by CISA and Carnegie Mellon&#8217;s CERT/CC. I wrote about CISA&#8217;s own articulation of this framework back in 2022 in <strong><a href="https://www.resilientcyber.io/p/cisas-take-on-vulnerability-prioritization">CISA&#8217;s Take on Vulnerability Prioritization</a></strong>, when Eric Goldstein published &#8220;<strong><a href="https://www.cisa.gov/news-events/news/transforming-vulnerability-management-landscape">Transforming the Vulnerability Management Landscape</a></strong>.&#8221; </p><p>That publication outlined three pillars for change. Machine-readable advisories through CSAF, exploitability communication through VEX, and prioritization through SSVC and KEV. BOD 26-04 operationalizes that third pillar, and what&#8217;s insane is that it took four years to get from concept to mandate.</p><h3>The Data That Forced the Shift</h3><p>The Verizon 2026 DBIR found that <em>only 26%</em> of KEV catalog vulnerabilities were fully remediated by organizations in 2025, down from 38% the prior year. Median time for full resolution rose to 43 days. These aren&#8217;t obscure vulnerabilities buried in legacy systems. These are confirmed actively exploited vulnerabilities that CISA explicitly told organizations to fix, and remediation rates are getting worse, not better.The 2026 DBIR also showed that exploitation of software vulnerabilities is now the dominant initial access vector.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sFo6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sFo6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png 424w, https://substackcdn.com/image/fetch/$s_!sFo6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png 848w, https://substackcdn.com/image/fetch/$s_!sFo6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png 1272w, https://substackcdn.com/image/fetch/$s_!sFo6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sFo6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png" width="465" height="215.9217391304348" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:267,&quot;width&quot;:575,&quot;resizeWidth&quot;:465,&quot;bytes&quot;:44509,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201643881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sFo6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png 424w, https://substackcdn.com/image/fetch/$s_!sFo6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png 848w, https://substackcdn.com/image/fetch/$s_!sFo6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png 1272w, https://substackcdn.com/image/fetch/$s_!sFo6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1335429-3f1a-49b1-8bdb-ad1c223e3991_575x267.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The problem isn&#8217;t that organizations don&#8217;t care about patching. It&#8217;s that they&#8217;re drowning in volume and treating every vulnerability with the same urgency, which means nothing gets the urgency it actually deserves. </p><p>I covered this dynamic extensively in <strong><a href="https://www.resilientcyber.io/p/vulnerability-velocity-and-exploitation">Vulnerability Velocity and the Exploitation Enigma</a></strong>, where Mandiant&#8217;s M-Trends data confirmed vulnerability exploitation as the number one initial infection vector and year-over-year CVE growth was running at 30%. </p><blockquote><p><strong>The fundamental math doesn&#8217;t work when you try to patch everything at the same speed.</strong></p></blockquote><h2>The Vulnpocalypse Makes Prioritization Existential</h2><p>BOD 26-04 arrives in the middle of what I&#8217;ve been calling the <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">Vulnpocalypse</a></strong>, the structural asymmetry between AI-accelerated vulnerability discovery and organizations&#8217; capacity to remediate. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C67W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C67W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png 424w, https://substackcdn.com/image/fetch/$s_!C67W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png 848w, https://substackcdn.com/image/fetch/$s_!C67W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png 1272w, https://substackcdn.com/image/fetch/$s_!C67W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C67W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png" width="1307" height="641" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:641,&quot;width&quot;:1307,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:328953,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201643881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!C67W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png 424w, https://substackcdn.com/image/fetch/$s_!C67W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png 848w, https://substackcdn.com/image/fetch/$s_!C67W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png 1272w, https://substackcdn.com/image/fetch/$s_!C67W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997b19d2-0207-45df-afa0-3cf4f5c74cf6_1307x641.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>FIRST projects approximately 59,000 CVEs in 2026, with realistic upside approaching 100,000. Jerry Gamblin&#8217;s tracking data shows 27,758 vulnerabilities published by June 1, 2026 alone, a 39% increase over the same period in 2025.</p><p>AI hasn&#8217;t just accelerated discovery, it has industrialized it. Anthropic&#8217;s Claude Mythos discovered over 10,000 high and critical vulnerabilities across open-source software, including 271 zero-days in Firefox and a 27-year-old bug in OpenBSD. Researchers can now develop working exploits in 15 minutes using AI for a few dollars. </p><p>The window between vulnerability disclosure and weaponization has compressed from months to hours, and the volume of what gets disclosed is growing at a rate that makes blanket remediation physically impossible. This is captured perfectly in the <strong><a href="https://zerodayclock.com/">Zero Day Clock</a></strong>, which I have often shared.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UpiC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UpiC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png 424w, https://substackcdn.com/image/fetch/$s_!UpiC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png 848w, https://substackcdn.com/image/fetch/$s_!UpiC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png 1272w, https://substackcdn.com/image/fetch/$s_!UpiC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UpiC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png" width="966" height="594" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:594,&quot;width&quot;:966,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74699,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201643881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UpiC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png 424w, https://substackcdn.com/image/fetch/$s_!UpiC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png 848w, https://substackcdn.com/image/fetch/$s_!UpiC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png 1272w, https://substackcdn.com/image/fetch/$s_!UpiC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f033500-d35f-4aa9-b038-a04bb3e0c878_966x594.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>CISA explicitly acknowledges this in the directive. The AI threat is cited as a motivating factor, reflecting priorities from the recent AI Executive Order. That EO established constructs like the Treasury/CISA vulnerability clearinghouse and NSA frontier model benchmarking that are supposed to create infrastructure for managing AI-accelerated vulnerability discovery. </p><p>None of those constructs are operational yet, which means BOD 26-04 is the only concrete federal policy response to the Vulnpocalypse currently in effect. If you&#8217;re unfamiliar with the AI Executive Order, I did a breakdown below:</p><div id="youtube2-XN15BwOZRXA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;XN15BwOZRXA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/XN15BwOZRXA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>When you&#8217;re facing 59,000-plus CVEs per year and fewer than 5% will ever be exploited, risk-based prioritization isn&#8217;t a best practice, it&#8217;s the only viable strategy. Research found that 95-98% of all AppSec alerts can be safely deprioritized when context-based prioritization is applied, and only 2% truly pose risk and require action. CISA&#8217;s own finding that 60% of vulnerabilities at a large agency can be deferred to the next upgrade cycle aligns perfectly with this data.</p><h2>Beyond the Federal Perimeter</h2><p>BOD 26-04 technically binds only federal civilian agencies, but its impact will extend well beyond the public sector. CISA explicitly encourages state and local governments, critical infrastructure operators, and private sector organizations to adopt the same approach, and the procurement pipeline ensures it will spread. </p><p>Wiley Rein&#8217;s legal <strong><a href="https://www.wiley.law/alert-CISA-Directive-Highlights-Risk-Based-Vulnerability-Management">analysis flagged</a></strong> that government contractors should expect these requirements to flow down through Statements of Work and future contracts. Cloud Service Providers should plan for adoption in anticipation of FedRAMP updates.</p><p>This matters because the private sector faces the same structural problem. Average enterprise vulnerability backlogs exceed 100,000 findings and often can be in the hundreds of thousands to millions in large enterprise environments. </p><p>Remediation capacity runs at 5-20% per month. As I documented in <strong><a href="https://www.resilientcyber.io/p/the-evolution-of-appsec-from-shifting">The Evolution of AppSec</a></strong>, the average application faces 81 confirmed viable attacks per month on top of 10,000-plus probes, gains 17 new vulnerabilities per month, and fixes roughly 6. That gap only widens under CVSS-driven remediation timelines that don&#8217;t distinguish between theoretical severity and actual risk.</p><p>The <strong><a href="https://www.resilientcyber.io/p/vulnerability-management-evolves">evolution of vulnerability management</a></strong> toward Continuous Threat Exposure Management (CTEM) has been underway for several years and BOD 26-04 gives that evolution a federal stamp of approval. The directive&#8217;s requirement for continuous asset discovery, exposure-based tagging, and threat-informed prioritization maps directly to the CTEM framework. Organizations that have already adopted EPSS, KEV integration, reachability analysis, and business-context scoring are ahead of this curve. Organizations still running monthly scans and sorting by CVSS are now behind federal policy, not just best practice.</p><h2>The Infrastructure Gap</h2><p>The directive&#8217;s biggest vulnerability is the infrastructure it depends on. CISA&#8217;s Vulnrichment program provides SSVC decisions for only 45.8% of CVEs. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!umq1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!umq1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png 424w, https://substackcdn.com/image/fetch/$s_!umq1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png 848w, https://substackcdn.com/image/fetch/$s_!umq1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png 1272w, https://substackcdn.com/image/fetch/$s_!umq1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!umq1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png" width="559" height="315.08620689655174" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:425,&quot;width&quot;:754,&quot;resizeWidth&quot;:559,&quot;bytes&quot;:90458,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201643881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!umq1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png 424w, https://substackcdn.com/image/fetch/$s_!umq1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png 848w, https://substackcdn.com/image/fetch/$s_!umq1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png 1272w, https://substackcdn.com/image/fetch/$s_!umq1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d6f59b-16e6-458e-8a7b-7c04c6f8c84e_754x425.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That means agencies must manually assess automatability and technical impact for more than half of all vulnerabilities. VulnCheck&#8217;s Patrick Garrity <strong><a href="https://www.vulncheck.com/blog/cisa-bod-26-04">highlighted this gap </a></strong>immediately, noting that VulnCheck provides 90% SSVC coverage through automated generation. The fact that a private vendor covers twice as many CVEs as the government program the directive relies on tells you something about the execution challenge.</p><p>The NVD&#8217;s ongoing struggles compound the problem. As I&#8217;ve covered repeatedly, the NVD moved roughly 29,000 backlogged CVEs to &#8220;Not Scheduled&#8221; status, effectively reclassifying the backlog rather than solving it. If agencies can&#8217;t get enriched vulnerability data from the national database, the prioritization methodology BOD 26-04 requires becomes significantly harder to operationalize.</p><div id="youtube2-Q6AXQH0R5Rg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Q6AXQH0R5Rg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Q6AXQH0R5Rg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Then there&#8217;s the EPSS question. Despite being one of the most validated tools for exploitation probability assessment, EPSS is not explicitly mandated in the directive. The four-factor SSVC model captures exploitation status (via KEV) and automatability, but it doesn&#8217;t incorporate the probabilistic forward-looking assessment that EPSS provides. </p><p>An organization using KEV plus EPSS plus reachability analysis plus business context is making better prioritization decisions than the directive&#8217;s minimum requirements would produce. That&#8217;s not a criticism of the directive so much as an observation that policy rarely leads practice.</p><p>Kevin Greene <strong><a href="https://www.securityweek.com/cisa-directs-federal-agencies-to-prioritize-security-patches-based-on-risk/amp/">raised</a></strong> another gap. The SSVC model tells you how bad a single CVE&#8217;s blast radius is on its component, but it doesn&#8217;t account for whether that component sits on a path to a privilege plane. A CVE with a CVSS score of 10 that can&#8217;t reach the privilege plane is operationally ineffective. A CVE with a moderate score that chains into lateral movement and persistence can be devastating. The directive doesn&#8217;t address that downstream privilege debt.</p><p>In an era of AI-driven exploitation this is a key point, as research from the UK&#8217;s AISI has shown, frontier models are getting good at chaining vulnerabilities, moving laterally and not just isolating vulnerabilities in isolation either.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Asll!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Asll!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png 424w, https://substackcdn.com/image/fetch/$s_!Asll!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png 848w, https://substackcdn.com/image/fetch/$s_!Asll!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png 1272w, https://substackcdn.com/image/fetch/$s_!Asll!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Asll!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png" width="1035" height="670" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:670,&quot;width&quot;:1035,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:215499,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201643881?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Asll!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png 424w, https://substackcdn.com/image/fetch/$s_!Asll!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png 848w, https://substackcdn.com/image/fetch/$s_!Asll!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png 1272w, https://substackcdn.com/image/fetch/$s_!Asll!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91f3bec7-48f8-488e-827c-736992555e4a_1035x670.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What This Actually Means</h2><p>BOD 26-04 is the right policy at the right time, even if the execution infrastructure isn&#8217;t fully built yet. The 72-hour patch window for the highest-risk vulnerabilities is aggressive. Some have rightly said they remain skeptical that the three day deadline is an achievable patch cadence today, but it is a positive step, even if it is aspirational at best currently. </p><blockquote><p><strong>The directive&#8217;s real value isn&#8217;t the specific timelines, it&#8217;s the formal burial of CVSS-driven patch mandates and the institutionalization of risk-based prioritization as federal policy.</strong></p></blockquote><p>For practitioners who have been arguing for years that organizations should prioritize based on exploitation evidence, asset exposure, reachability, and business context rather than arbitrary severity scores, this directive validates the approach. </p><p>For vendors who have built products around KEV integration, EPSS scoring, reachability analysis, and exposure management, this creates a compliance driver that didn&#8217;t exist before. For CISOs trying to justify investment in modern vulnerability prioritization tooling, this is the policy backstop they needed.</p><p>Despite much of this being a positive direction and signal to the broader industry it remains to be seen whether the ecosystem, from NVD enrichment to SSVC coverage to agency operational maturity, can execute at the speed the directive demands. </p><p>When 98% of vulnerabilities are noise, the organizations that can identify and act on the remaining 2% fastest will define what effective vulnerability management looks like in the age of the Vulnpocalypse. BOD 26-04 just told the U.S&gt; Federal government to start acting like it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #101]]></title><description><![CDATA[Cyber ARR, Unpacking the AI EO, The Vulnpocalypse Goes GA, LLM ATT&CK Navigator, AI-Powered Autonomous Worms & fwd:cloudsec NA 2026]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-101</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-101</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 11 Jun 2026 12:03:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AHdy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #101 of the Resilient Cyber Newsletter! </p><p>If last week&#8217;s executive order set the policy table, this week the market and the models showed up to eat. CrowdStrike&#8217;s Q1 earnings told the story in a single line from George Kurtz, who called it &#8220;<em>the Mythos moment,</em>&#8221; and the numbers backed it up with $256 million in net new ARR. </p><p>Anthropic released Claude Fable 5, the first publicly available Mythos-class model, and if you think the vulnerability discovery wave was intense with Glasswing restricted to 200 partners, wait until every Pro subscriber has access. I wrote a full piece on what that means in <strong><a href="https://www.resilientcyber.io/p/the-vulnpocalypse-goes-ga">The Vulnpocalypse Goes GA</a></strong>.</p><p>Meanwhile, NIST dropped a mathematical proof showing that no finite set of guardrails can block every adversarial prompt, which is exactly the kind of foundational research that should reshape how we think about AI security. </p><p>Trail of Bits demonstrated that every major skill scanner can be bypassed in under an hour, and the Miasma supply chain worm compromised 73 Microsoft GitHub repositories through a self-propagating npm attack. </p><p>The lesson from this week is that both the offensive and defensive capabilities are accelerating, and the organizations that treat security as a continuous process rather than a static checkpoint will be the ones that survive.</p><p>Let&#8217;s get into it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AHdy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AHdy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png 424w, https://substackcdn.com/image/fetch/$s_!AHdy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png 848w, https://substackcdn.com/image/fetch/$s_!AHdy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png 1272w, https://substackcdn.com/image/fetch/$s_!AHdy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AHdy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png" width="615" height="373.37425910245554" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:717,&quot;width&quot;:1181,&quot;resizeWidth&quot;:615,&quot;bytes&quot;:624399,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AHdy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png 424w, https://substackcdn.com/image/fetch/$s_!AHdy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png 848w, https://substackcdn.com/image/fetch/$s_!AHdy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png 1272w, https://substackcdn.com/image/fetch/$s_!AHdy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F895153f7-ef78-4425-a047-4fbf3d0ed423_1181x717.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><h3><strong><a href="https://www.tines.com/webinars/150-hours-saved-in-one-month-inside-jamfs-it-ops-automation-strategy/?utm_source=ChrisHughes&amp;utm_medium=paid_media&amp;utm_content=newsletter-primary-1106">Inside Jamf&#8217;s IT Ops automation strategy</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.tines.com/webinars/150-hours-saved-in-one-month-inside-jamfs-it-ops-automation-strategy/?utm_source=ChrisHughes&amp;utm_medium=paid_media&amp;utm_content=newsletter-primary-1106" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yq8y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png 424w, https://substackcdn.com/image/fetch/$s_!Yq8y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png 848w, https://substackcdn.com/image/fetch/$s_!Yq8y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png 1272w, https://substackcdn.com/image/fetch/$s_!Yq8y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yq8y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png" width="512" height="409.6" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1000,&quot;resizeWidth&quot;:512,&quot;bytes&quot;:79444,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.tines.com/webinars/150-hours-saved-in-one-month-inside-jamfs-it-ops-automation-strategy/?utm_source=ChrisHughes&amp;utm_medium=paid_media&amp;utm_content=newsletter-primary-1106&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yq8y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png 424w, https://substackcdn.com/image/fetch/$s_!Yq8y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png 848w, https://substackcdn.com/image/fetch/$s_!Yq8y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png 1272w, https://substackcdn.com/image/fetch/$s_!Yq8y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9c70bf4-9b60-4e82-a599-c80629531aca_1000x800.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>500+ SaaS apps. Thousands of devices. A flood of help desk tickets. And a team of 30 people to manage all of it.</p><p>That&#8217;s the reality for Jamf&#8217;s IT team - but instead of drowning, they built their way out. On <a href="https://www.tines.com/webinars/150-hours-saved-in-one-month-inside-jamfs-it-ops-automation-strategy/?utm_source=ChrisHughes&amp;utm_medium=paid_media&amp;utm_content=newsletter-primary-1106">July 10th, join them live</a> to learn exactly how they replaced manual, ticket-based IT work with intelligent workflows. </p><p><strong> Join to hear:</strong></p><ul><li><p>The early use cases that proved the value of intelligent workflows</p></li><li><p>Where AI fits into their IT ops today - and where it&#8217;s going</p></li><li><p>How they compressed a year-long device audit into a matter of weeks</p></li><li><p>Plus, they&#8217;ll walk through a live demo of one of their most impactful workflows - Come ready to steal their playbook.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.tines.com/webinars/150-hours-saved-in-one-month-inside-jamfs-it-ops-automation-strategy/?utm_source=ChrisHughes&amp;utm_medium=paid_media&amp;utm_content=newsletter-primary-1106&quot;,&quot;text&quot;:&quot;REGISTER HERE&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.tines.com/webinars/150-hours-saved-in-one-month-inside-jamfs-it-ops-automation-strategy/?utm_source=ChrisHughes&amp;utm_medium=paid_media&amp;utm_content=newsletter-primary-1106"><span>REGISTER HERE</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.linkedin.com/posts/georgekurtz_ai-is-driving-demand-for-cybersecurity-q1-ugcPost-7468038947953098752-MDi4/">CrowdStrike Q1: The &#8220;Mythos Moment&#8221; Arrives with $256M in Net New ARR</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gi_o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gi_o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png 424w, https://substackcdn.com/image/fetch/$s_!gi_o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png 848w, https://substackcdn.com/image/fetch/$s_!gi_o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png 1272w, https://substackcdn.com/image/fetch/$s_!gi_o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gi_o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png" width="353" height="283.2455089820359" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:402,&quot;width&quot;:501,&quot;resizeWidth&quot;:353,&quot;bytes&quot;:191023,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gi_o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png 424w, https://substackcdn.com/image/fetch/$s_!gi_o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png 848w, https://substackcdn.com/image/fetch/$s_!gi_o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png 1272w, https://substackcdn.com/image/fetch/$s_!gi_o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5432f0a2-626e-4a4d-abbf-5594ccd803c9_501x402.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>George Kurtz framed CrowdStrike&#8217;s Q1 as the quarter &#8220;the worlds of cybersecurity and frontier AI collided.&#8221; The numbers are hard to argue with. Net new ARR hit $256 million, up 32% year-over-year, with total ARR crossing $5.51 billion. </p><p>The AI Detection and Response pipeline surged 250% sequentially, crossing $50 million for Q2. What I find most telling is that CrowdStrike raised its full-year ARR growth guidance by 520 basis points and still cautioned that market expectations around AI security demand are running ahead of reality. </p><p>That tension between demonstrable demand acceleration and the CEO tempering enthusiasm tells you exactly where we are in the cycle.</p><h3><a href="https://www.profgmedia.com/p/ipo-mania">IPO Mania: $350 Billion in New Equity on Deck</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vpKn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vpKn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png 424w, https://substackcdn.com/image/fetch/$s_!vpKn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png 848w, https://substackcdn.com/image/fetch/$s_!vpKn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png 1272w, https://substackcdn.com/image/fetch/$s_!vpKn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vpKn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png" width="468" height="369.05836575875486" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:608,&quot;width&quot;:771,&quot;resizeWidth&quot;:468,&quot;bytes&quot;:114273,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vpKn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png 424w, https://substackcdn.com/image/fetch/$s_!vpKn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png 848w, https://substackcdn.com/image/fetch/$s_!vpKn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png 1272w, https://substackcdn.com/image/fetch/$s_!vpKn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ae48cf1-20a2-4dcf-b882-20e5caf8ddeb_771x608.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Scott Galloway&quot;,&quot;id&quot;:451231761,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de3bcbbb-ac49-498d-ba5f-72d576a22d4b_2048x2048.jpeg&quot;,&quot;uuid&quot;:&quot;55c0787c-aea5-4b24-b68e-32dcbfd2fe60&quot;}" data-component-name="MentionToDOM"></span> laid out what might be the largest IPO year in history. SpaceX at $75 billion, Anthropic approaching $100 billion, OpenAI planning a record debut, and roughly $350 billion in total new equity supply. </p><p>For cybersecurity, the signal is that the capital flowing into AI companies will create enormous downstream demand for security infrastructure. The flip side is that peak exuberance often leaves retail investors holding the bag, and Galloway is not shy about making that point.</p><h3><a href="https://www.linkedin.com/posts/mikeprivette_babe-wake-up-a-new-cybersecurity-decacorn-share-7467927447720738816-a8By/">New Cybersecurity Decacorn Emerges</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_vIX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_vIX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png 424w, https://substackcdn.com/image/fetch/$s_!_vIX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png 848w, https://substackcdn.com/image/fetch/$s_!_vIX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png 1272w, https://substackcdn.com/image/fetch/$s_!_vIX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_vIX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png" width="1024" height="446" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:446,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:181930,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_vIX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png 424w, https://substackcdn.com/image/fetch/$s_!_vIX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png 848w, https://substackcdn.com/image/fetch/$s_!_vIX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png 1272w, https://substackcdn.com/image/fetch/$s_!_vIX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fb791b5-49bf-431a-ae77-2068b9b6e60d_1024x446.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Mike Privette flagged a new entry into the cybersecurity decacorn club, Cyera, continuing the pattern of massive private valuations before any of these companies test the public markets. </p><p>The timing is interesting given the IPO pipeline building up and the reality that SailPoint and Netskope both underperformed post-listing. Private markets continue to price cybersecurity at a premium that public markets have not validated yet. Whether the AI demand wave changes that equation is the question worth watching.</p><h3><a href="https://therecord.media/trump-considers-palantir-exec-to-lead-cisa">Trump Administration Considers Palantir CTO for CISA Director</a></h3><p>Palantir CTO Shyam Sankar is reportedly the frontrunner for the still-vacant CISA director role, though the White House later disputed the accuracy of this reporting. Sankar has spent over 20 years at Palantir in senior technical and operational roles. </p><p>If confirmed, placing a Palantir executive at the helm of CISA would signal a clear tilt toward AI-driven national cyber defense and platformization, which would align with the executive order&#8217;s push for rapid AI adoption across federal agencies.</p><p>I actually interviewed Shyam over a year ago on the Resilient Cyber Show, diving into both the tech and national security topics:</p><div id="youtube2-pr0QbhnhI3s" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;pr0QbhnhI3s&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/pr0QbhnhI3s?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://uk.news.yahoo.com/gchq-unveils-world-first-ai-065342109.html">GCHQ Unveils Plans for World-First National AI Cyber Defence System</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LYnB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LYnB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png 424w, https://substackcdn.com/image/fetch/$s_!LYnB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png 848w, https://substackcdn.com/image/fetch/$s_!LYnB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png 1272w, https://substackcdn.com/image/fetch/$s_!LYnB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LYnB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png" width="475" height="334.7275031685678" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:556,&quot;width&quot;:789,&quot;resizeWidth&quot;:475,&quot;bytes&quot;:680259,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LYnB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png 424w, https://substackcdn.com/image/fetch/$s_!LYnB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png 848w, https://substackcdn.com/image/fetch/$s_!LYnB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png 1272w, https://substackcdn.com/image/fetch/$s_!LYnB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4c4dbd-84dd-44c0-9ce8-dc263b882723_789x556.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>GCHQ director Anne Keast-Butler used the agency&#8217;s first annual lecture at Bletchley Park to announce a national AI cyber shield. The system would deploy agentic AI to detect and respond to threats across critical infrastructure, airlines, telecoms, and major corporations, with an operational target of five years. </p><p>The UK is explicitly framing this as agentic AI for defense, not just analytics, and the ambition of real-time autonomous detection at national scale is something no country has attempted at this level before.</p><h3><a href="https://www.politico.com/news/2026/06/07/frontier-ai-cybersecurity-china-race-00952786">Politico: Frontier AI Becomes Central to the U.S.-China Cybersecurity Race</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!49iv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!49iv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png 424w, https://substackcdn.com/image/fetch/$s_!49iv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png 848w, https://substackcdn.com/image/fetch/$s_!49iv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png 1272w, https://substackcdn.com/image/fetch/$s_!49iv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!49iv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png" width="411" height="291.94298921417567" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:461,&quot;width&quot;:649,&quot;resizeWidth&quot;:411,&quot;bytes&quot;:412347,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!49iv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png 424w, https://substackcdn.com/image/fetch/$s_!49iv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png 848w, https://substackcdn.com/image/fetch/$s_!49iv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png 1272w, https://substackcdn.com/image/fetch/$s_!49iv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce0fa445-4632-4977-b183-d3582f1c27a3_649x461.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Congress opened a joint investigation into Chinese AI model proliferation. The hearings examined how the U.S. leads with proprietary frontier models while China releases open-weight models freely, and the concern is that Chinese state actors could use those models to exploit vulnerabilities in critical infrastructure. </p><p>The geopolitical dimension of AI-enabled cybersecurity is no longer theoretical. It is now a formal congressional investigation. Speaking of AI&#8217;s intersection with U.S. interests and the broader cyber landscape, Jack Cable of Corridor and others recent testified in a Homeland Security event titled &#8220;The AI Security Landscape: How AI is Reshaping Cybersecurity and Critical Infrastructure Resilience&#8221; and it was an excellent listen.</p><div id="youtube2-5K_0etAPDxA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5K_0etAPDxA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5K_0etAPDxA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://www.nextgov.com/artificial-intelligence/2026/06/lawmakers-propose-ai-framework-would-preempt-state-laws-3-years/413975/">Lawmakers Propose Federal AI Framework That Would Preempt State Laws for Three Years</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y6QW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y6QW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png 424w, https://substackcdn.com/image/fetch/$s_!Y6QW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png 848w, https://substackcdn.com/image/fetch/$s_!Y6QW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png 1272w, https://substackcdn.com/image/fetch/$s_!Y6QW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y6QW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png" width="545" height="239.33174224343676" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:368,&quot;width&quot;:838,&quot;resizeWidth&quot;:545,&quot;bytes&quot;:354693,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y6QW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png 424w, https://substackcdn.com/image/fetch/$s_!Y6QW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png 848w, https://substackcdn.com/image/fetch/$s_!Y6QW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png 1272w, https://substackcdn.com/image/fetch/$s_!Y6QW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d217857-5bca-457a-8690-dd304fa8b8f7_838x368.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Representatives Obernolte and Trahan introduced draft legislation establishing a four-pillar federal AI governance framework that would override state AI regulations for three years. Advocacy groups immediately pushed back, arguing it sets a federal ceiling rather than a floor. </p><p>This is the legislative companion to the executive order I analyzed last week, and the pattern is consistent with the administration&#8217;s deregulatory posture toward AI development. If you missed my breakdown of the AI EO, you can find it below:</p><div id="youtube2-XN15BwOZRXA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;XN15BwOZRXA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/XN15BwOZRXA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4><a href="https://www.linkedin.com/posts/jaymcbain_we-are-entering-an-unprecedented-cycle-of-share-7468761249154125824-4JJc/">Jay McBain: An &#8220;Unprecedented Cycle&#8221; in Cybersecurity Channel Spending</a></h4><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Jay McBain&quot;,&quot;id&quot;:43538260,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b63cd93-471b-4647-ae68-fa837e0f680b_1081x1081.jpeg&quot;,&quot;uuid&quot;:&quot;88ef1b49-8c10-43c5-aac2-91364c5922dc&quot;}" data-component-name="MentionToDOM"></span>, Omdia&#8217;s Chief Analyst for Channels and Partnerships, is forecasting record growth in managed security and AI services heading into 2027. With 99% of MSPs deeply engaged in cybersecurity and the industry worth $87 billion on the vendor side, his argument is that the AI wave creates a generational channel opportunity. </p><p>The demand acceleration CrowdStrike reported in Q1 is the enterprise side of that same story.</p><h3><a href="https://www.cnbc.com/amp/2026/06/05/softbank-masayoshi-son-openai-model-super-intelligence.html">SoftBank&#8217;s Son: AI Superintelligence Within Two Years</a></h3><p>Masayoshi Son told CNBC that OpenAI&#8217;s next model is being designed by another AI model, accelerating his superintelligence timeline to within two years. He predicts AI will surpass human intelligence in 70-80% of subjects within that window. </p><p>The cybersecurity implications are worth thinking through. If Son is even directionally correct, the offensive capability acceleration we are tracking with Mythos and GPT-5.5-Cyber is still in its early innings.</p><div><hr></div><h1>AI</h1><h3><a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Anthropic Releases Claude Fable 5 and Claude Mythos 5</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XIc7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XIc7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png 424w, https://substackcdn.com/image/fetch/$s_!XIc7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png 848w, https://substackcdn.com/image/fetch/$s_!XIc7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png 1272w, https://substackcdn.com/image/fetch/$s_!XIc7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XIc7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png" width="503" height="348.9017341040462" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:865,&quot;resizeWidth&quot;:503,&quot;bytes&quot;:447819,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XIc7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png 424w, https://substackcdn.com/image/fetch/$s_!XIc7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png 848w, https://substackcdn.com/image/fetch/$s_!XIc7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png 1272w, https://substackcdn.com/image/fetch/$s_!XIc7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c48c49e-f3c5-4c67-836f-bd3866a198ae_865x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the biggest AI story of the week, and it changes the threat landscape in ways most organizations are not ready for. Anthropic released Claude Fable 5 on June 9, the first publicly available Mythos-class model, accessible to Pro, Max, Team, and Enterprise users. </p><p>Fable 5 delivers state-of-the-art performance on nearly all benchmarks and its capabilities exceed anything Anthropic has ever made generally available. The safeguards are conservative. Queries in high-risk areas like cybersecurity, biology, and chemistry fall back to Claude Opus 4.8 responses, triggering in less than 5% of sessions. </p><p>Separately, Claude Mythos 5 launched for vetted cyberdefenders and infrastructure providers through Project Glasswing, with the safeguards partially lifted. The pricing signals intent at $10 per million input tokens and $50 per million output. What keeps me up at night is the gap between when frontier capability becomes broadly available and when organizations update their defenses to match. That gap just got a lot wider.</p><h3><a href="https://www.csoonline.com/article/4180920/beware-the-son-of-mythos-security-experts-warn.html">Security Experts Warn of &#8220;Son of Mythos&#8221; Threat</a></h3><p>The concern is not just Mythos itself but what comes next. Security experts are warning that frontier AI models from Google and at least two Chinese labs are not far behind Mythos in cybersecurity capability, potentially compressing the disclosure-to-exploit window from months to hours. </p><p>Anthropic has expanded Glasswing to 200 partners, but that still leaves the vast majority of organizations without access to equivalent defensive tools. The asymmetry between offensive availability and defensive access is the structural problem nobody has solved yet.</p><h3><a href="https://red.anthropic.com/2026/attack-navigator/">Anthropic LLM ATT&amp;CK Navigator: 832 Banned Accounts Mapped to MITRE Framework</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UZk1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UZk1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png 424w, https://substackcdn.com/image/fetch/$s_!UZk1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png 848w, https://substackcdn.com/image/fetch/$s_!UZk1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png 1272w, https://substackcdn.com/image/fetch/$s_!UZk1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UZk1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png" width="653" height="364.49943502824857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:494,&quot;width&quot;:885,&quot;resizeWidth&quot;:653,&quot;bytes&quot;:137027,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UZk1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png 424w, https://substackcdn.com/image/fetch/$s_!UZk1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png 848w, https://substackcdn.com/image/fetch/$s_!UZk1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png 1272w, https://substackcdn.com/image/fetch/$s_!UZk1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d45f688-12bc-4576-bfd5-2ca4835aa61f_885x494.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Anthropic analyzed 832 accounts banned for cyber-related policy violations between March 2025 and March 2026, mapping 13,873 actions across 482 unique techniques and all 14 ATT&amp;CK tactics. The most common technique family was T1587 (Develop Capabilities), used by 574 actors, with malware development alone accounting for 560. </p><p>The percentage of medium-to-high-risk AI-enabled actors jumped from 33% to 56% in under a year. Anthropic partnered with Verizon to include findings in the 2026 DBIR, and the report argues that traditional risk signals no longer work because ATT&amp;CK lacks categories for autonomous agentic attacks.</p><h3><a href="https://www.nist.gov/news-events/news/2026/06/nist-mathematical-proof-supports-transition-continuous-monitor-and-update">NIST Proves No Finite Set of AI Guardrails Can Block Every Attack</a></h3><p>This one matters more than the headline suggests. NIST senior scientist Apostol Vassilev published a peer-reviewed proof in IEEE Security &amp; Privacy showing that for any finite set of guardrails, some adversarial prompt exists that can bypass them. </p><p>The proof extends Godel&#8217;s incompleteness theorems to AI security. The practical implication is clear and it aligns with what practitioners already know intuitively. Static guardrails are necessary but never sufficient. </p><p>Continuous monitoring, red teaming, and iterative updates are the only viable security model for AI systems, and organizations still treating AI safety as a deploy-and-forget exercise need to rethink their approach.</p><h3><a href="https://help.openai.com/en/articles/20001061-lockdown-mode">OpenAI Launches Lockdown Mode for Prompt Injection Defense</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Grw-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Grw-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png 424w, https://substackcdn.com/image/fetch/$s_!Grw-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png 848w, https://substackcdn.com/image/fetch/$s_!Grw-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png 1272w, https://substackcdn.com/image/fetch/$s_!Grw-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Grw-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png" width="644" height="231.15642458100558" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:257,&quot;width&quot;:716,&quot;resizeWidth&quot;:644,&quot;bytes&quot;:48279,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Grw-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png 424w, https://substackcdn.com/image/fetch/$s_!Grw-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png 848w, https://substackcdn.com/image/fetch/$s_!Grw-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png 1272w, https://substackcdn.com/image/fetch/$s_!Grw-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b49e8e6-0302-4f37-9dbb-d9d9e4503e43_716x257.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>OpenAI rolled out Lockdown Mode on June 4, an optional security setting that limits outbound network requests to prevent data exfiltration from prompt injection attacks. When enabled, it disables web access, image support, Deep Research, Agent Mode, and file downloads. </p><p>The tradeoff is explicit and honest. You lose capability in exchange for a substantially reduced attack surface. Lockdown Mode does not prevent prompt injections from occurring. It prevents the final stage of exfiltration. </p><p>This is defense-in-depth thinking applied to an LLM product, and while it is designed for a small set of security-conscious users handling sensitive data, the concept of hard boundaries at the product level is worth watching as a design pattern.</p><h3><a href="https://www.linkedin.com/pulse/authorization-denied-longer-enough-karl-mcguinness-y6sac/">Karl McGuinness: &#8220;Authorization Denied&#8221; Is No Longer Enough for Agent Identity</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wIQy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wIQy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png 424w, https://substackcdn.com/image/fetch/$s_!wIQy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png 848w, https://substackcdn.com/image/fetch/$s_!wIQy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png 1272w, https://substackcdn.com/image/fetch/$s_!wIQy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wIQy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png" width="587" height="319.56370656370655" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:423,&quot;width&quot;:777,&quot;resizeWidth&quot;:587,&quot;bytes&quot;:519885,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wIQy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png 424w, https://substackcdn.com/image/fetch/$s_!wIQy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png 848w, https://substackcdn.com/image/fetch/$s_!wIQy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png 1272w, https://substackcdn.com/image/fetch/$s_!wIQy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08d6925b-001c-44bd-a40c-7d028a8ef45d_777x423.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Okta&#8217;s former Chief Product Architect makes the case that existing identity infrastructure was built for humans or long-lived machines, not agents that spawn, collaborate, and disappear in seconds. </p><p>The Agent Identity Service he describes uses the AGNTCY Linux Foundation project with cryptographic badge generation for MCP servers and human-in-the-loop policy authorization for critical actions. </p><p>This is exactly the identity layer that agentic architectures need. Agents operating with probabilistic intent at machine speed require authorization models that go far beyond binary allow/deny decisions.</p><p>Karl is genuinely one of the sharpest people I&#8217;ve discussed Agentic IAM with, and I had a excellent conversation with him below: </p><div id="youtube2-PbxQwaHinwM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;PbxQwaHinwM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/PbxQwaHinwM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://cleverhans.io/latest-research.html">CleverHans Lab: Free AI Models Power Autonomous Computer Worms</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BgCa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BgCa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png 424w, https://substackcdn.com/image/fetch/$s_!BgCa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png 848w, https://substackcdn.com/image/fetch/$s_!BgCa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png 1272w, https://substackcdn.com/image/fetch/$s_!BgCa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BgCa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png" width="962" height="479" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:479,&quot;width&quot;:962,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:98875,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BgCa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png 424w, https://substackcdn.com/image/fetch/$s_!BgCa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png 848w, https://substackcdn.com/image/fetch/$s_!BgCa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png 1272w, https://substackcdn.com/image/fetch/$s_!BgCa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F64ed9d31-42e4-4f55-b05e-508f91c3e56c_962x479.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Researchers at the University of Toronto&#8217;s CleverHans Lab built a proof-of-concept AI worm using only small, free AI models that autonomously identifies vulnerabilities, reasons about attack strategies, and self-replicates across networks. </p><p>In seven days of fully autonomous operation, the worm identified an average of 31.3 vulnerabilities per target, successfully exploited 73.8% of the network, and replicated to 61.8% of hosts across up to seven generations. </p><p>Critically, it exploited three vulnerabilities disclosed in 2026, after the model&#8217;s training cutoff, by ingesting publicly available advisories at runtime. Nobody needs Mythos to build a chaos-causing worm, free open-source models work just fine.</p><h3><a href="https://www.langchain.com/blog/the-anatomy-of-an-agent-harness">The Agent Harness Problem: Anatomy and Technical Debt</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LSxB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LSxB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png 424w, https://substackcdn.com/image/fetch/$s_!LSxB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png 848w, https://substackcdn.com/image/fetch/$s_!LSxB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png 1272w, https://substackcdn.com/image/fetch/$s_!LSxB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LSxB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png" width="575" height="459.5472440944882" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:609,&quot;width&quot;:762,&quot;resizeWidth&quot;:575,&quot;bytes&quot;:155091,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LSxB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png 424w, https://substackcdn.com/image/fetch/$s_!LSxB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png 848w, https://substackcdn.com/image/fetch/$s_!LSxB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png 1272w, https://substackcdn.com/image/fetch/$s_!LSxB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc742d1d4-7d61-4c37-8dac-e7f443703e04_762x609.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>LangChain and Lee Hanchung both published complementary pieces this recently on agent harnesses, the infrastructure surrounding an AI model including tools, memory, sandboxing, and orchestration logic. </p><p>LangChain showed that harness improvements alone can significantly boost benchmark performance without changing the underlying model. Hanchung&#8217;s analysis goes further, arguing that most durable agent teams treat harnesses as 90-day artifacts and delete most code on model updates. </p><p>The security implication is that harness code is disposable by design, which means security controls embedded in the harness layer are likely to be discarded and rebuilt on every model upgrade cycle.</p><h3><a href="https://cybersec.pillar.security/s/agentic-ci-cd-security-risks-attack-vectors-and-controls-27707/2">Pillar Security: Agentic AI Risks in CI/CD Pipelines</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vGtH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vGtH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png 424w, https://substackcdn.com/image/fetch/$s_!vGtH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png 848w, https://substackcdn.com/image/fetch/$s_!vGtH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png 1272w, https://substackcdn.com/image/fetch/$s_!vGtH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vGtH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png" width="480" height="364.3853820598007" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:457,&quot;width&quot;:602,&quot;resizeWidth&quot;:480,&quot;bytes&quot;:341511,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vGtH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png 424w, https://substackcdn.com/image/fetch/$s_!vGtH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png 848w, https://substackcdn.com/image/fetch/$s_!vGtH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png 1272w, https://substackcdn.com/image/fetch/$s_!vGtH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92b9dec2-cc79-4a5a-a233-87307febfd9e_602x457.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Pillar Security documented how coding agents with read/write access to repositories and deployment keys create new attack surfaces in CI/CD pipelines. The risk model includes prompt injection, privilege escalation, and lateral movement through compromised containers. </p><p>This piece landed the around the same time that the Agent Control Standard (ACS) went public at v0.1.0 as the first open, MIT-licensed spec for runtime governance of AI agents. The pattern is becoming clear, agents are getting pipeline access before the governance frameworks exist to constrain them.</p><h3><a href="https://claude.com/blog/using-llms-to-secure-source-code">Anthropic: Using LLMs to Secure Source Code</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nB3Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nB3Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png 424w, https://substackcdn.com/image/fetch/$s_!nB3Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png 848w, https://substackcdn.com/image/fetch/$s_!nB3Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png 1272w, https://substackcdn.com/image/fetch/$s_!nB3Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nB3Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png" width="445" height="335.56296296296296" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:509,&quot;width&quot;:675,&quot;resizeWidth&quot;:445,&quot;bytes&quot;:59696,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nB3Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png 424w, https://substackcdn.com/image/fetch/$s_!nB3Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png 848w, https://substackcdn.com/image/fetch/$s_!nB3Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png 1272w, https://substackcdn.com/image/fetch/$s_!nB3Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfb08f5-2fc2-41c1-9fc8-32daacb10b3a_675x509.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The methodology here is worth paying attention to. A 6-stage loop for AI-driven code security spans threat modeling, sandbox creation, discovery, verification, triage, and patching. </p><p>Their own open source scanning has disclosed 1,596 items and validated over 500 high-severity vulnerabilities. The key insight I took from this is that discovery has become trivially parallelizable, but the bottleneck has shifted entirely to verification, triage, and patching. </p><p>That is the same bottleneck I keep coming back to in the vulnpocalypse discussion, and no amount of discovery tooling solves it without investing equally in the remediation pipeline.</p><h3><a href="https://airisk.mit.edu/priorities">MIT AI Risk Repository: 18 of 24 Domains Carry Catastrophic Risk</a></h3><p>MIT&#8217;s AI Risk Initiative surveyed experts across 200+ organizations and found that 18 of 24 AI risk domains carry at least a 10% probability of catastrophic outcomes within five years. Information, finance, and national security face the highest vulnerability. These are not fringe researchers making dramatic claims. </p><p>This is MIT putting probability estimates on AI-driven systemic risk across every major sector, and the numbers should inform how organizations think about AI governance.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://www.resilientcyber.io/p/the-vulnpocalypse-goes-ga">The Vulnpocalypse Goes GA</a></h3><p>I wrote a full piece this week on what Fable 5&#8217;s public release means for the vulnerability landscape. The vulnpocalypse is no longer a theoretical exercise gated behind Glasswing access. </p><p>With Mythos-class capability in the hands of every Pro subscriber, the volume of AI-discovered vulnerabilities is about to jump again, and the remediation bottleneck that was already stretched thin is going to break for organizations that have not invested in triage automation and risk-based prioritization. </p><blockquote><p><strong>The math has not changed. Discovery scales with compute, remediation scales with humans. That gap is the story of the next twelve months.</strong></p></blockquote><h3><a href="https://youtu.be/hObRMv6qCi0?si=mxm4Q7LTKuCQ1l6I">Palo Alto Networks CEO: &#8220;AI Found 5 Years of Bugs in 6 Weeks&#8221;</a></h3><div id="youtube2-hObRMv6qCi0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;hObRMv6qCi0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/hObRMv6qCi0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Nikesh Arora revealed that Mythos found years&#8217; worth of vulnerabilities in Palo Alto&#8217;s codebase in six weeks. They scanned over 130 products, uncovering 75 legitimate vulnerabilities that have since been patched. The company estimates organizations have three to five months before attackers broadly gain access to frontier AI cyber models. </p><p>Early models had false positive rates up to 30%, making them more effective for offense or testing than for immediate defense without proper contextualization. This is the same dynamics playing out everywhere. Discovery is outrunning remediation, and the window to get ahead of it is measured in months, not years.</p><h3><a href="https://youtu.be/gluLrc71Jas?si=3nI8gfVlsUGocsMc">fwd:cloudsec North America 2026 Playlist</a></h3><p>The talks from fwd:cloudsec North America 2026 are live and it is full of excellent talks, including a CNAPP walkthrough on the paste and future from <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;James Berthoty&quot;,&quot;id&quot;:215222117,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F029c069a-0ea1-4c28-bedb-742a03fa770a_800x800.jpeg&quot;,&quot;uuid&quot;:&quot;351d4669-83bd-4157-b23b-143d15a40918&quot;}" data-component-name="MentionToDOM"></span>, great talks on topics such as Agentic IAM, and of course all things Cloud Security as well. </p><div id="youtube2-YrhHBhAh1Ns" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;YrhHBhAh1Ns&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/YrhHBhAh1Ns?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div id="youtube2-wWoA0Ct99Tc" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;wWoA0Ct99Tc&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/wWoA0Ct99Tc?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3><a href="https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/">Trail of Bits: The Sorry State of Skill Distribution</a></h3><p>Trail of Bits bypassed ClawHub&#8217;s malicious skill detector, Cisco&#8217;s agent skill scanner, and all three scanners integrated into skills.sh, with three of the four bypasses taking less than an hour. </p><p>Their simplest bypass prepended 100,000 blank lines to a malicious skill, causing ClawHub&#8217;s scanner to truncate the file before reaching the payload and mark it safe. The structural problem is damning. Arbitrary combinations of code, data, and natural language create the broadest possible attack surface, while the cost of inference motivates the use of weak models and truncated contexts. </p><p>Their recommendation is blunt and I agree with it. Public skill marketplaces are not safe for agents operating in sensitive contexts, curate your own.</p><h3><a href="https://labs.reversec.com/posts/2026/05/skill-issues-compromising-claude-code-with-malicious-skills-agents-part-1">Skill Issues: Compromising Claude Code with Malicious Skills and Agents</a></h3><p>ReverseC demonstrated that a single .md file can achieve a reverse shell through Claude Code with out-of-the-box settings. Dynamic context commands execute before the model sees the skill, meaning model-level prompt injection defenses never get a chance to intervene. </p><p>The broader data point from the ecosystem is sobering. If you installed a skill from ClawHub in the past month, there is a 13% chance it contains a critical security flaw. Skills supply chain security is rapidly becoming one of the most urgent problems in the agent ecosystem.</p><h3><a href="https://www.linkedin.com/posts/yotam-perkal_the-team-behind-the-miasma-supply-chain-worm-share-7469884310230249474-3o_R/">Miasma Supply Chain Worm Compromises 73 Microsoft GitHub Repositories</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AlUl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AlUl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png 424w, https://substackcdn.com/image/fetch/$s_!AlUl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png 848w, https://substackcdn.com/image/fetch/$s_!AlUl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png 1272w, https://substackcdn.com/image/fetch/$s_!AlUl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AlUl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png" width="467" height="299.3234421364985" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:1011,&quot;resizeWidth&quot;:467,&quot;bytes&quot;:244896,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200802651?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AlUl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png 424w, https://substackcdn.com/image/fetch/$s_!AlUl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png 848w, https://substackcdn.com/image/fetch/$s_!AlUl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png 1272w, https://substackcdn.com/image/fetch/$s_!AlUl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F218bf0d8-0e60-4727-a164-af75f9b7640b_1011x648.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the supply chain attack that should have everyone&#8217;s attention. Miasma, an evolved variant of the Shai-Hulud worm open-sourced by TeamPCP, compromised 32 packages across 90+ versions under the redhat-cloud-services npm scope through a hijacked CI/CD pipeline. </p><p>The malware stole SSH keys, CLI credentials, and browser data on developer systems, while in CI/CD environments it scraped GitHub Actions runner memory for secrets and republished poisoned packages with forged SLSA provenance. On June 5, GitHub disabled 73 Microsoft repositories after Miasma re-compromised Azure&#8217;s durabletask project. </p><p>The worm executes automatically when an infected repository is cloned and opened in Claude Code, Gemini CLI, Cursor, or VS Code. This is the software supply chain threat model operating at a level of sophistication that most organizations are not equipped to detect.</p><h3><a href="https://www.scworld.com/podcast-segment/14914-the-state-of-ai-in-secops-the-unintended-consequences-of-vulnmaxxing-and-the-news-filip-stojkovski-esw-462">The Unintended Consequences of Vulnmaxxing</a></h3><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Filip Stojkovski&quot;,&quot;id&quot;:40696750,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e5161d9-e2fd-457f-96f2-2545324d34ca_1840x1840.jpeg&quot;,&quot;uuid&quot;:&quot;229204a8-2750-4299-8cc7-3d4f6ac4ac3e&quot;}" data-component-name="MentionToDOM"></span> raised a point on Enterprise Security Weekly that I think deserves more attention. &#8220;Vulnmaxxing,&#8221; the practice of expensive AI-driven vulnerability discovery at industrial scale, threatens to create a two-tier security world where well-funded organizations race ahead while everyone else falls further behind. </p><p>If AI vulnerability discovery becomes a rich-organization sport, we end up widening the security inequality gap rather than closing it. The democratization of defensive capability is just as important as the democratization of discovery.</p><h3><a href="https://www.oreilly.com/radar/predict-dont-enumerate/">Predict, Don&#8217;t Enumerate</a></h3><p>O&#8217;Reilly published a piece advocating for EPSS-based exploit prediction over exhaustive vulnerability enumeration, referencing Anthropic&#8217;s April 2026 security guide. </p><p>The core argument is elegant. Since vulnerabilities are effectively infinite, the only viable strategy is prioritizing by exploitability rather than trying to catalog everything. This aligns with what I have been saying about risk-based prioritization for years, and the vulnpocalypse makes it even more urgent. The organizations still trying to chase zero CVEs are going to drown.</p><div><hr></div><h1>Final Thoughts</h1><p>This week crystallized something I have been building toward across the last several issues. The vulnpocalypse went from restricted preview to general availability. Fable 5 put Mythos-class capability in the hands of millions, and the market responded instantly. CrowdStrike reported its &#8220;Mythos moment&#8221; with record ARR, while the IPO pipeline suggests hundreds of billions in AI-adjacent capital is looking for a home. The demand signal for security is unmistakable.</p><p>But capability without governance is just chaos with better tooling. NIST proved mathematically that static guardrails will always be breakable. Trail of Bits showed that skill scanners can be bypassed in under an hour. Miasma demonstrated supply chain attacks operating at a sophistication level that forges provenance and spreads through developer tools automatically. </p><p>The lesson is not that we should stop building. It is that continuous monitoring, curated trust, and defense-in-depth are the only models that work when both the offensive and defensive sides are moving at AI speed.</p><p>The organizations that will thrive are the ones treating security as a continuous, adaptive process rather than a compliance checkbox. The building blocks exist. The challenge is building the muscle to use them before the window closes.</p><blockquote><p><strong>Stay resilient.</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Vulnpocalypse Goes GA]]></title><description><![CDATA[Fable 5, Vulnmaxxing, and the Circular Economics of AI-Driven Security]]></description><link>https://www.resilientcyber.io/p/the-vulnpocalypse-goes-ga</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-vulnpocalypse-goes-ga</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Wed, 10 Jun 2026 12:01:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vPJK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When Anthropic launched Claude Mythos Preview through <strong><a href="https://www.resilientcyber.io/p/the-receipts-are-in">Project Glasswing</a></strong> in April, the vulnerability discovery capabilities were staggering but access was restricted. Glasswing partners discovered over 10,000 high-or-critical-severity vulnerabilities across systemically important software, including 271 zero-days in Firefox alone and a 27-year-old bug in OpenBSD that had survived decades of human review. </p><p>As of today, the core model behind those capabilities is <strong><a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">generally available</a></strong>. Claude Fable 5, a Mythos-class model wrapped in safety classifiers, is now accessible to anyone with an API key at $10 per million input tokens and $50 per million output tokens. The capabilities that were gated behind government partnerships and vetted research programs two months ago are now commercially available.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vPJK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vPJK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png 424w, https://substackcdn.com/image/fetch/$s_!vPJK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png 848w, https://substackcdn.com/image/fetch/$s_!vPJK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png 1272w, https://substackcdn.com/image/fetch/$s_!vPJK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vPJK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png" width="609" height="397.77881619937693" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:629,&quot;width&quot;:963,&quot;resizeWidth&quot;:609,&quot;bytes&quot;:453263,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201363183?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vPJK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png 424w, https://substackcdn.com/image/fetch/$s_!vPJK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png 848w, https://substackcdn.com/image/fetch/$s_!vPJK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png 1272w, https://substackcdn.com/image/fetch/$s_!vPJK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F136a73b3-d6cc-4c54-9fe0-ececfa1dd48d_963x629.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As I wrote in <strong><a href="https://www.resilientcyber.io/p/claude-mythos-why-it-matters-and">Claude Mythos: Why It Matters (And Why It Doesn&#8217;t)</a></strong>, the significance of Mythos was never just about one model&#8217;s benchmarks. It was about what those benchmarks signaled for the structural economics of vulnerability discovery and exploitation. </p><p>With Fable 5, that signal goes from preview to production. The <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">Vulnpocalypse</a></strong> I&#8217;ve been writing about, the structural asymmetry between AI-accelerated discovery and the capacity to remediate, just became accessible to every organization and every adversary with a credit card.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Benchmarks</h2><p>Fable 5 leads or matches the best available models across virtually every coding and reasoning benchmark. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Kigz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Kigz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp 424w, https://substackcdn.com/image/fetch/$s_!Kigz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp 848w, https://substackcdn.com/image/fetch/$s_!Kigz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp 1272w, https://substackcdn.com/image/fetch/$s_!Kigz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Kigz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp" width="1456" height="1607" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1607,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:174872,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201363183?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Kigz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp 424w, https://substackcdn.com/image/fetch/$s_!Kigz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp 848w, https://substackcdn.com/image/fetch/$s_!Kigz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp 1272w, https://substackcdn.com/image/fetch/$s_!Kigz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49688273-ae45-4965-8c25-7a07ac32d74f_2600x2870.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On SWE-bench Verified it scores 95.0%, and on SWE-bench Pro it hits 80.3%, compared to 69.2% for Claude Opus 4.8, 58.6% for GPT-5.5, and 54.2% for Gemini 3.1 Pro. On Terminal-Bench 2.1 it scores 88.0%, on CursorBench it reaches 72.9% at max effort. </p><p>These aren&#8217;t marginal improvements, the gap between Fable 5 and the next best competitor on coding tasks is significant enough that it represents a qualitative shift in what autonomous coding agents can accomplish in production environments. In the PR from Anthropic they discuss how Stripe reported that Fable 5 completed a 50-million-line Ruby codebase migration in a single day, work that would have required two months of team effort.</p><p>The cybersecurity benchmarks come from the Mythos lineage, since Fable 5 and Mythos 5 share the same underlying model. During the Mythos Preview period, the model achieved a 73% success rate on expert-level CTF challenges, making it the first AI model to solve challenges at that difficulty tier. It completed a 32-step corporate network takeover simulation end-to-end as I discussed previously, in reporting from the UK&#8217;s AI Security Institute (AISI). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tkb1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tkb1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png 424w, https://substackcdn.com/image/fetch/$s_!Tkb1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png 848w, https://substackcdn.com/image/fetch/$s_!Tkb1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png 1272w, https://substackcdn.com/image/fetch/$s_!Tkb1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tkb1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png" width="954" height="525" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:525,&quot;width&quot;:954,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:147366,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201363183?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Tkb1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png 424w, https://substackcdn.com/image/fetch/$s_!Tkb1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png 848w, https://substackcdn.com/image/fetch/$s_!Tkb1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png 1272w, https://substackcdn.com/image/fetch/$s_!Tkb1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae0ea57d-a2ba-4c66-abd2-92948538e26e_954x525.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On ExploitGym, it successfully exploited 157 of 898 real-world vulnerabilities and developed 181 working exploits including a 20-gadget ROP chain against FreeBSD and a four-vulnerability browser sandbox escape. As I covered in <strong><a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">The AI Cyber Capability Curve</a></strong>, the capability curve for frontier models on cyber tasks has been steepening with every release. Fable 5 represents another significant step up that curve, and this time the step is commercially available rather than gated.</p><p>Anthropic&#8217;s own scan of over 1,000 open-source projects during the Glasswing preview estimated 23,019 total vulnerabilities, with 6,202 classified as high or critical. Cloudflare, one of the Glasswing partners, found 2,000 bugs across their codebase with 400 rated high or critical, and reported false positive rates better than human testers. Partners across the program saw greater than 10x improvement in bug-finding rates. These numbers should be familiar to readers who followed my coverage in <strong><a href="https://www.resilientcyber.io/p/the-receipts-are-in">The Receipts Are In</a></strong>, but they take on new weight now that the underlying model is generally available.</p><div id="youtube2-5DPQ3m3e8OE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5DPQ3m3e8OE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5DPQ3m3e8OE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>The Jagged Frontier</h2><p>One of the most important counterpoints to the Fable 5 narrative comes from research that Anthropic itself published alongside the launch, and from independent work by researchers like Niels Provos and AISLE. The capability distribution across AI models for cybersecurity tasks isn&#8217;t a smooth curve where bigger and more expensive models always win. It&#8217;s what AISLE calls a &#8220;<strong><a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">jagged frontier</a></strong>,&#8221; where rankings reshuffle completely depending on the specific task and where with effective harness engineering, zero day discovery can be available to anyone, even with older, smaller and less capable models.</p><p>The numbers here are striking as well. A 3.6-billion parameter model, running at $0.11 per million tokens, which is 600x cheaper than Mythos, correctly detected Mythos&#8217;s flagship FreeBSD exploit, identifying the stack buffer overflow, computing remaining buffer space, and assessing it as critical with RCE potential. </p><p>Eight out of eight models AISLE tested detected the same vulnerability, including open-weights models like GPT-OSS-120B with only 5.1 billion active parameters. Niels Provos built an open-source framework called IronCurtain that achieved autonomous discovery of new zero-days in foundational software using a mix of commercial and open-weight models, leading him to argue that &#8220;vulnerability discovery is an orchestration problem, not a frontier-model problem.&#8221; <strong><a href="https://blog.vidocsecurity.com/blog/we-reproduced-anthropics-mythos-findings-with-public-models">Vidoc Security</a></strong> independently reproduced Anthropic&#8217;s Mythos findings with publicly available models, reaching the same conclusion.</p><p>Both AISLE and Vidoc concluded that the real moat isn&#8217;t the model, it&#8217;s the security expertise to operationalize the bug discovery process, building the harness, validating the results, and triaging findings against actual exploitability. </p><p>This matters because it directly challenges one of the two core narratives that emerged from the Mythos marketing campaign, that only the most powerful and expensive frontier models can do this work, and that they do it autonomously. The research shows that cheaper models can find the same vulnerabilities, and that the orchestration and expertise surrounding the model matters more than the model itself.</p><p>But the practical reality for most attackers and security researchers is more nuanced. Building the orchestration harnesses, targeting logic, iterative deepening, validation pipelines, and triage workflows that Provos describes in his IronCurtain framework is itself a significant engineering effort. </p><p>Most researchers and most attackers won&#8217;t build that infrastructure. They&#8217;ll use the most capable generally available model they can access through an API, and as of today, that model is Fable 5. The jagged frontier is real and the research matters, but the GA release of a Mythos-class model changes the practical calculus for the vast majority of users who want capability without building custom harnesses.</p><h2>The Hype Cycle as Lead Funnel</h2><p>There&#8217;s a pattern worth examining honestly in how this release played out and it is one skeptics have been pointing out and I want to acknowledge it as well. In April, Anthropic gated Mythos behind a government partnership, published benchmark results showing unprecedented vulnerability discovery capabilities, and framed the model as too dangerous for general release. Two months later, the same underlying model is available to anyone with an API key. The framing shifted from &#8220;this is so dangerous we can&#8217;t release it publicly&#8221; to &#8220;here it is, with safety classifiers, for $10 per million input tokens.&#8221;</p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;id&quot;:11988704,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a89717e5-a927-4084-ad86-69068727dbf3_1632x1632.png&quot;,&quot;uuid&quot;:&quot;16888c24-2f62-418b-a82c-617868a8d623&quot;}" data-component-name="MentionToDOM"></span> <strong><a href="https://www.defendersinitiative.com/p/the-unintended-consequences-of-vulnmaxxing">wrote about this dynamic</a></strong> in his piece on what he calls &#8220;vulnmaxxing,&#8221; and his analysis raises some excellent points. Sanabria&#8217;s argument is that the Mythos launch wasn&#8217;t just a marketing campaign, it was a lead funnel. </p><p>Convince the world&#8217;s largest software makers that they need Mythos-class capabilities to find vulnerabilities in their code, and then you&#8217;ve created demand for the same AI to fix those vulnerabilities, because the volume of findings is too high for human remediation alone. The circular logic is hard to ignore, as AI finds the bugs, for a price and then AI fixes the bugs, for a price, and both sides of that equation run through the same vendor&#8217;s API.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qSUo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qSUo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png 424w, https://substackcdn.com/image/fetch/$s_!qSUo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png 848w, https://substackcdn.com/image/fetch/$s_!qSUo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png 1272w, https://substackcdn.com/image/fetch/$s_!qSUo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qSUo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png" width="485" height="405.3852596314908" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:499,&quot;width&quot;:597,&quot;resizeWidth&quot;:485,&quot;bytes&quot;:151729,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201363183?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qSUo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png 424w, https://substackcdn.com/image/fetch/$s_!qSUo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png 848w, https://substackcdn.com/image/fetch/$s_!qSUo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png 1272w, https://substackcdn.com/image/fetch/$s_!qSUo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfb970ed-f78b-4c2e-8151-2f6fbe8b2b7a_597x499.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The pricing tells part of the story. Fable 5 at $10/$50 per million tokens is double the cost of Claude Opus 4.8 at $5/$25. Mythos Preview ran at $25/$125. Anthropic gave away $100 million in free Mythos credits during the Glasswing preview, which seeded adoption and generated the vulnerability findings that are now cited as evidence that organizations need Mythos-class capabilities. Whether you see this as responsible scaling or as market creation depends on how much credit you give to the security narrative versus the commercial incentive structure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MOpm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MOpm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png 424w, https://substackcdn.com/image/fetch/$s_!MOpm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png 848w, https://substackcdn.com/image/fetch/$s_!MOpm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png 1272w, https://substackcdn.com/image/fetch/$s_!MOpm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MOpm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png" width="945" height="408" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c031d69e-b090-45a7-9237-ea3e34b73139_945x408.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:408,&quot;width&quot;:945,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:48345,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201363183?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MOpm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png 424w, https://substackcdn.com/image/fetch/$s_!MOpm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png 848w, https://substackcdn.com/image/fetch/$s_!MOpm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png 1272w, https://substackcdn.com/image/fetch/$s_!MOpm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc031d69e-b090-45a7-9237-ea3e34b73139_945x408.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Sanabria raises a related concern around the security poverty line. The 1% of companies with the largest engineering budgets can afford a Mythos-level audit of their codebases and the AI-assisted remediation that follows. </p><p>Everyone else either builds their own harnesses using cheaper models, which requires security expertise and engineering investment most organizations don&#8217;t have, or falls further behind. The gap between organizations that can afford AI-augmented security and those that can&#8217;t may widen rather than narrow with each frontier model release.</p><p>There&#8217;s also a question about the value of what&#8217;s being found. Cyentia&#8217;s research shows that 98% or more of all vulnerabilities are of low-to-no concern from an attacker&#8217;s perspective. The findings from Glasswing and Fable 5 scans will follow this same distribution. Anthropic&#8217;s marketing uses the language of &#8220;zero-day discovery,&#8221; but as Sanabria points out, a vulnerability with no value to an attacker is a software bug, not a meaningful security finding. </p><p>The volume of discoveries is impressive but the fraction of those discoveries that represent genuine risk to the organizations affected is a different and much smaller number. Organizations that can&#8217;t distinguish between the two will burn tokens and remediation cycles on findings that don&#8217;t actually reduce their risk. </p><p>This makes concepts such as effective vulnerability management (literally the title of a book I wrote) along with vulnerability prioritization (e.g. KEV, EPSS, reachability, business context etc.) even more critical.</p><h2>The Safeguards</h2><p>Anthropic&#8217;s approach to releasing Mythos-class capabilities to the general public hinges on three safety classifiers built into Fable 5 that aren&#8217;t present in the gated Mythos 5 deployment. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Nathan Lambert&quot;,&quot;id&quot;:10472909,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dad13b2b-20b2-44e0-a84d-732f3be8bee7_4128x4128.jpeg&quot;,&quot;uuid&quot;:&quot;2d7721de-f8da-4a40-b691-826c176efc0b&quot;}" data-component-name="MentionToDOM"></span> wrote an excellent piece diving into some of those safeguards titled &#8220;<strong><a href="https://open.substack.com/pub/robotic/p/claude-fable-5-and-new-ai-safety?r=1rnpiw&amp;utm_campaign=post-expanded-share&amp;utm_medium=post%20viewer">Claude Fab 5 and New AI Safety Fables</a></strong>&#8221;. </p><p>The cybersecurity classifier prevents exploitation and offensive cyber tasks, with Anthropic reporting over 1,000 hours of red-teaming that found no universal jailbreaks, and zero compliance on harmful single-turn cyberattack requests across 30 public jailbreak techniques. </p><p>The biology and chemistry classifier applies broad safeguards on dual-use research, tuned conservatively toward safety. The distillation prevention classifier blocks large-scale extraction attempts designed to train competing models, something we&#8217;ve even seen The White House release memos of concern on, especially when it comes to maintaining the edge in AI over China. When any classifier triggers, the request falls back to Claude Opus 4.8 rather than refusing outright, which Anthropic says happens in less than 5% of sessions on average.</p><p>Mythos 5, the version without these classifiers, remains gated. Cyber safeguards are lifted only for Project Glasswing partners working with the U.S. government. Biology and chemistry safeguards are lifted only for select researchers enrolled in Anthropic&#8217;s life sciences program. </p><p>This tiered approach, same model with different guardrail configurations depending on the use case and the vetting of the user, is Anthropic&#8217;s answer to the dual-use challenge. </p><p>Whether the cybersecurity classifiers hold against motivated adversaries over time is an open question that the red-teaming results can&#8217;t fully answer, because the adversarial community hasn&#8217;t had access to the GA model long enough to develop novel techniques against it. I will definitely be keeping an eye on this aspect of things in the coming days/weeks to see what jailbreaks do emerge as the community gets to it.</p><h2>Policy Is Already Behind</h2><p>The timing of this release is hard to ignore. The White House signed the &#8220;<strong><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">Promoting Advanced Artificial Intelligence Innovation and Security</a></strong>&#8220; executive order just last week, on June 2nd. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3HMM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3HMM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png 424w, https://substackcdn.com/image/fetch/$s_!3HMM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png 848w, https://substackcdn.com/image/fetch/$s_!3HMM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png 1272w, https://substackcdn.com/image/fetch/$s_!3HMM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3HMM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png" width="1143" height="416" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:416,&quot;width&quot;:1143,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:93937,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/201363183?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3HMM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png 424w, https://substackcdn.com/image/fetch/$s_!3HMM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png 848w, https://substackcdn.com/image/fetch/$s_!3HMM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png 1272w, https://substackcdn.com/image/fetch/$s_!3HMM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a1168dd-9ab6-482c-b7f7-addca9d3165d_1143x416.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>For those not familiar with it, I provided a detailed video breakdown of the EO:</p><div id="youtube2-XN15BwOZRXA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;XN15BwOZRXA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/XN15BwOZRXA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>That EO directs NSA to develop a classified benchmarking process within 60 days to determine which AI models qualify as &#8220;covered frontier models&#8221; and directs Treasury, NSA, and CISA to stand up an AI cybersecurity clearinghouse to coordinate vulnerability scanning and remediation. </p><p>As I discussed in my written and video coverage of the EO, none of those constructs exist yet. The NSA hasn&#8217;t designated any covered frontier models or likely even codified the criteria. The clearinghouse hasn&#8217;t been formed, the benchmarking process hasn&#8217;t been developed, and today, a Mythos-class model went GA.</p><p>This is the structural challenge I&#8217;ve been writing about. Policy operates on 30-day and 60-day timelines at best, often longer, while model capabilities advance on continuous deployment cycles. The Agentic SDLC runs on an entirely different pace than the regulatory and policy lifecycle does.</p><p>The EO&#8217;s vulnerability clearinghouse is a good idea, and the early access provision that gives government defenders a 30-day preview of frontier models before public release is a genuinely novel mechanism. But Fable 5 is available today, and the governance infrastructure the EO envisions won&#8217;t be operational for weeks or months. The models don&#8217;t wait for the institutions to catch up. </p><p>Even then, the 30d preview period will do little to nothing for actual remediation in real-world government and critical infrastructure environments where I&#8217;ve spent most of my carer, as the AI-driven vulnerability discovery meets the analog reality of the people, process and technology paradigm and massive vulnerability backlogs that existed well before the rise of LLM&#8217;s and Mythos class models.</p><p>The EO&#8217;s voluntary framework for industry participation makes this gap even more visible. Anthropic is voluntarily implementing safety classifiers, voluntarily gating Mythos, and voluntarily partnering with the government through Glasswing. </p><p>These are real commitments from a company that has consistently invested in safety research. But the framework depends on the frontier labs choosing to cooperate, and as I explored in <strong><a href="https://www.resilientcyber.io/p/the-regulation-pendulum-and-ais-national">The Regulation Pendulum</a></strong>, the open-weights ecosystem and smaller labs operating outside the voluntary framework face no equivalent constraints. The next model with Fable 5-class vulnerability discovery capabilities might not come with safety classifiers or government partnerships attached.</p><h2>What This Means for the Ecosystem</h2><p>The GA release of Mythos-class capabilities creates pressure across the entire software ecosystem, and the pressure is compounded by the dynamics Adrian Sanabria identifies.</p><p>For open-source maintainers, this is an acceleration of a problem that was already overwhelming and which has been well documented by industry leaders such as cURL&#8217;s Daniel Stenberg. </p><p>The Glasswing preview showed what happens when frontier AI models are pointed at large open-source codebases. Hundreds of high-severity vulnerabilities surface in projects maintained by small teams or individual developers who are already stretched thin. </p><p>This creates unintended outcomes and challenges in the real world. Code repositories are already going private as maintainers try to survive what he calls the vulnpocalypse through obscurity. As I&#8217;ve written about since <strong><a href="https://www.resilientcyber.io/p/death-knell-of-the-nvd">Death Knell of the NVD</a></strong>, the vulnerability data infrastructure is buckling under the volume of discoveries that existed before AI-accelerated scanning. The NVD backlog, the strain on CVE numbering authorities, and the remediation gap between discovery and fix are all structural problems that Fable 5&#8217;s general availability will intensify. The <strong><a href="https://www.resilientcyber.io/p/the-attack-surface-exponential">Attack Surface Exponential</a></strong> is real, and now anyone can point a Mythos-class model at it.</p><p>For enterprise security teams, the math gets harder in multiple dimensions. Organizations already drowning in vulnerability backlogs will face an acceleration in externally reported findings as researchers, bug bounty hunters, and automated scanning services adopt Fable 5. </p><p>The remediation capacity doesn&#8217;t scale at the same rate as the discovery capacity, and if the fix for AI-discovered vulnerabilities is AI-generated patches, organizations face a new set of unknowns. We have limited visibility into what vibe-coded patches are doing to the future security and stability of codebases, and the pace of AI-generated fixes may not leave time for the human review that historically catches the secondary bugs that patches introduce. </p><blockquote><p><strong>The core tension of the Vulnpocalypse, the gap between the velocity of findings and the velocity of quality fixes, just widened.</strong></p></blockquote><p>There is a genuine opportunity on the other side of this. The same capabilities that enable vulnerability discovery at scale can be turned inward. Organizations can use Fable 5 to scan their own codebases, identify high-severity vulnerabilities in their own products and internal tools, and fix them before external researchers or adversaries find them first. </p><p>Cloudflare&#8217;s results, 2,000 bugs identified with false positive rates better than human testers, show what AI-assisted internal hardening looks like when applied systematically, but we have to remember most security and engineering teams don&#8217;t look like Cloudflare&#8217;s. </p><p>Concerns about the security poverty line are real. The organizations best positioned to capture this opportunity are the ones with the engineering budgets, security expertise, and triage workflows to separate the 2% of findings that matter from the 98% that don&#8217;t. </p><p>For everyone else, the flood of AI-generated findings without the context to prioritize them risks becoming noise that makes an already impossible triage problem worse.</p><h2>Where This Leaves Practitioners</h2><p>The GA release of a Mythos-class model is a structural inflection point, but what practitioners do with that inflection depends on how clearly they see both the opportunity and the business model underneath it.</p><p>The capabilities are real, Fable 5 can find vulnerabilities that human reviewers miss, at a speed and scale that manual code review can&#8217;t match and genuinely do represent a step-change in frontier model capabilities. </p><p>The hardening opportunity is genuine, and organizations that use it to find and fix their own most critical vulnerabilities before adversaries do will have a meaningful defensive advantage, but the framing matters too. </p><p>Not every vulnerability AI discovers is a zero-day that demands urgent remediation. Most are software bugs that have no realistic exploitation path. The organizations that treat every AI-generated finding as a critical priority will burn budget and remediation capacity on work that doesn&#8217;t reduce risk. The ones that pair AI-assisted discovery with mature triage and exploitability analysis, informed by the same prioritization discipline practitioners have been building for years, will get the most value. This is also a topic my friend <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;James Berthoty&quot;,&quot;id&quot;:215222117,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F029c069a-0ea1-4c28-bedb-742a03fa770a_800x800.jpeg&quot;,&quot;uuid&quot;:&quot;68113cba-9de1-455d-96b0-7d7338077eda&quot;}" data-component-name="MentionToDOM"></span> has discussed in various pieces of his own as well.</p><p>The policy infrastructure the AI EO envisions, from the NSA&#8217;s frontier model designation to the vulnerability clearinghouse, is necessary but not yet operational, and the models aren&#8217;t waiting. </p><p>The jagged frontier research from AISLE and Provos should inform how security teams think about their own tooling strategy, because it means you don&#8217;t necessarily need the most expensive model to get meaningful results if you have the expertise to build the orchestration around cheaper alternatives.</p><p>The circular economics of AI finding bugs that AI then fixes, with both sides running through the same vendor&#8217;s API at double the cost of the previous generation, should be weighed with the same skepticism practitioners apply to any vendor&#8217;s pitch about why you need their product to solve a problem their other product helped create.</p><p>The Vulnpocalypse went GA today. </p><p>What practitioners do with it, whether they use it to harden their own code, get buried under the volume of findings, or recognize the commercial dynamics shaping how these capabilities are marketed, will depend on whether they approach it as a tool or accept it as a narrative.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Why Vulnerability Management Has to Become Autonomous]]></title><description><![CDATA[A Case For Why Defenders Need Agentic Workflows to Match AI-Augmented Exploitation]]></description><link>https://www.resilientcyber.io/p/why-vulnerability-management-has</link><guid isPermaLink="false">https://www.resilientcyber.io/p/why-vulnerability-management-has</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 09 Jun 2026 12:03:40 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/be29fa65-7c89-4fd8-88a3-ee973af9c732_2180x1432.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The math has been getting worse for years, but the acceleration over the last twelve months has moved the conversation from &#8220;<em>we need to get better at vulnerability management</em>&#8221; to &#8220;<em>the current model fundamentally cannot keep pace</em>.&#8221;</p><p>I&#8217;ve been tracking this trajectory across multiple articles, from <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">Vulnpocalypse</a></strong> and <strong><a href="https://www.resilientcyber.io/p/the-attack-surface-exponential">The Attack Surface Exponential</a></strong> to <strong><a href="https://www.resilientcyber.io/p/the-nvd-just-threw-in-the-towel-now">The NVD Just Threw in the Towel</a></strong>, and the 2026 Verizon DBIR confirmed what the trendlines have been screaming. Vulnerability exploitation is now the leading initial access vector in confirmed breaches, nearly doubling phishing for the first time in the report&#8217;s history.</p><p>That isn&#8217;t just a data point, it&#8217;s the clearest signal yet that the era of reactive, human-paced vulnerability management is ending, and that defenders need to match the speed and autonomy that attackers are already operating with to have any chance of keeping pace and effectively mitigating organizational risks.</p><div><hr></div><p>Most teams aren't short on vulnerability detections, they're drowning in them. </p><p>The signal-to-noise problem is the actual problem. Resilient Cyber&#8217;s partner, Zafran, put together &#8220;<strong><a href="https://www.zafran.io/get-ctem-guide?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=CTEM&amp;utm_content=blogpost">A Practical Guide: Evolving VM to CTEM</a></strong>&#8221; on moving from legacy VM to CTEM without boiling the ocean, start where you are, prioritize what's actually exploitable, iterate from there.</p><p>Worth the read if "we have 40,000 criticals" sounds familiar.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.zafran.io/get-ctem-guide?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=CTEM&amp;utm_content=blogpost" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fep7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png 424w, https://substackcdn.com/image/fetch/$s_!Fep7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png 848w, https://substackcdn.com/image/fetch/$s_!Fep7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!Fep7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fep7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png" width="493" height="328.779532967033" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:493,&quot;bytes&quot;:1842453,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.zafran.io/get-ctem-guide?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=CTEM&amp;utm_content=blogpost&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198542896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fep7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png 424w, https://substackcdn.com/image/fetch/$s_!Fep7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png 848w, https://substackcdn.com/image/fetch/$s_!Fep7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!Fep7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028df23b-a0ba-444d-a5e9-372281769912_2160x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.zafran.io/get-ctem-guide?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=CTEM&amp;utm_content=blogpost&quot;,&quot;text&quot;:&quot;-> Get the CTEM Guide! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.zafran.io/get-ctem-guide?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=CTEM&amp;utm_content=blogpost"><span>-&gt; Get the CTEM Guide! &lt;-</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Exploitation Timeline Has Collapsed</h2><p>The gap between vulnerability disclosure and active exploitation has compressed to the point where traditional remediation cycles are functionally irrelevant for the most critical findings. </p><p>As I covered in <strong><a href="https://www.resilientcyber.io/p/the-zero-day-clock-is-ticking-why">The Zero Day Clock Is Ticking</a></strong>, research tracking the median time-to-exploit found it collapsed from 771 days in 2018 to roughly 4 hours by 2024. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PWWN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PWWN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png 424w, https://substackcdn.com/image/fetch/$s_!PWWN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png 848w, https://substackcdn.com/image/fetch/$s_!PWWN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png 1272w, https://substackcdn.com/image/fetch/$s_!PWWN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PWWN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png" width="574" height="367.5979274611399" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:618,&quot;width&quot;:965,&quot;resizeWidth&quot;:574,&quot;bytes&quot;:75532,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198542896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PWWN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png 424w, https://substackcdn.com/image/fetch/$s_!PWWN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png 848w, https://substackcdn.com/image/fetch/$s_!PWWN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png 1272w, https://substackcdn.com/image/fetch/$s_!PWWN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27428171-4138-4f9a-9ca8-ce07cc068306_965x618.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <strong><a href="https://moak.ai/">MOAK</a></strong> autonomous exploitation project demonstrated that an AI system could exploit 174 out of 178 CISA Known Exploited Vulnerabilities in an average of 21 minutes each, with no human in the loop, and the 2026 DBIR found that organizations take a median of 43 days to remediate edge device vulnerabilities, with only 54% remediated within an entire year.</p><p>Those two numbers, 43 days versus 4 hours, tell the whole story of why exploitation has become the dominant attack vector. Defenders are operating on patch cycles measured in weeks and months while attackers, increasingly aided by AI tooling, are operating in minutes and hours. </p><blockquote><p><strong>The window between disclosure and exploitation that the entire vulnerability management model was built around has effectively closed.</strong></p></blockquote><p>This is compounded by the sheer volume. </p><p>FIRST projected approximately 59,000 new CVEs for 2025, a 50% increase over the prior year, and 2026 is on pace to exceed that. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pd_m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pd_m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png 424w, https://substackcdn.com/image/fetch/$s_!pd_m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png 848w, https://substackcdn.com/image/fetch/$s_!pd_m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png 1272w, https://substackcdn.com/image/fetch/$s_!pd_m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pd_m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png" width="1260" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e18af042-72c1-46db-a043-599930411909_1260x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:1260,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:187132,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198542896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pd_m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png 424w, https://substackcdn.com/image/fetch/$s_!pd_m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png 848w, https://substackcdn.com/image/fetch/$s_!pd_m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png 1272w, https://substackcdn.com/image/fetch/$s_!pd_m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe18af042-72c1-46db-a043-599930411909_1260x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As I wrote in <strong><a href="https://www.resilientcyber.io/p/the-nvd-just-threw-in-the-towel-now">The NVD Just Threw in the Towel</a></strong>, NIST reclassified roughly 29,000 backlogged CVEs to &#8220;<em>Not Scheduled</em>,&#8221; acknowledging that the data infrastructure the industry relies on for vulnerability prioritization can&#8217;t keep up with the input volume.</p><p>More vulnerabilities are being discovered than ever before, the enrichment data needed to prioritize them is arriving late or not at all, and the exploitation timeline has compressed to the point where &#8220;<em>patch quickly</em>&#8221; is no longer a viable strategy for the most dangerous findings.</p><h3>AI Is Accelerating Both Sides, But Not Equally</h3><p>I explored the broader dynamics of AI in cybersecurity in <strong><a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">The AI Cyber Capability Curve</a></strong>, and the core observation is playing out exactly as expected. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FI0S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FI0S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png 424w, https://substackcdn.com/image/fetch/$s_!FI0S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png 848w, https://substackcdn.com/image/fetch/$s_!FI0S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png 1272w, https://substackcdn.com/image/fetch/$s_!FI0S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FI0S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png" width="1064" height="649" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:649,&quot;width&quot;:1064,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:224828,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198542896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FI0S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png 424w, https://substackcdn.com/image/fetch/$s_!FI0S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png 848w, https://substackcdn.com/image/fetch/$s_!FI0S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png 1272w, https://substackcdn.com/image/fetch/$s_!FI0S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3afba872-e762-4102-bf5e-82af5e5141e8_1064x649.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI is amplifying capabilities on both sides of the security equation, but the attacker side is benefiting faster because offensive tasks are structurally simpler to automate and validate than defensive ones.</p><p>Generating a working exploit for a known vulnerability is a well-scoped, deterministic problem that AI excels at. Proof-of-concept code that once took researchers days to develop is now being generated in minutes. Researchers have demonstrated AI agents achieving an 87% success rate in autonomously identifying and exploiting one-day vulnerabilities in real-world software. Google DeepMind&#8217;s &#8220;Big Sleep&#8221; agent found a previously unknown vulnerability in SQLite, marking one of the first documented cases of AI discovering an exploitable memory safety bug in widely deployed software.</p><p>Defending against exploitation, by contrast, requires understanding organizational context, asset criticality, compensating controls, patch dependencies, business impact, and change management constraints. </p><p>These are exactly the kinds of multi-variable, context-dependent decisions that have historically resisted automation. The result is an asymmetry that grows wider with each generation of AI tooling. </p><blockquote><p><strong>Attackers are automating exploitation at machine speed. Defenders are still running remediation through human-paced processes that were designed for a world where they had weeks or months of lead time.</strong></p></blockquote><p>As I discussed in <strong><a href="https://www.resilientcyber.io/p/claude-mythos-why-it-matters-and">Claude, Mythos, and Why It Matters</a></strong>, Anthropic&#8217;s Mythos moment put a fine point on this. When a leading AI lab demonstrates advanced autonomous capabilities, the downstream implications for offensive security tooling are immediate and concrete. </p><p>There&#8217;s no longer a question whether AI will be weaponized for vulnerability exploitation at scale, it already has been. The question is whether defenders can operationalize AI and autonomy in their own workflows fast enough to close the gap, which has been a key recommendation in leading guidance, such as in Cloud Security Alliance&#8217;s &#8220;<strong><a href="https://cloudsecurityalliance.org/artifacts/the-ai-vulnerability-storm">Building a AI-Ready Vulnerability Security Program</a></strong>&#8221;.</p><p>Recent reports, such as the latest Verizon DBIR make the case even stronger, showing that patches are still taking weeks but exploitation has collapsed to hours. The <strong><a href="https://www.zafran.io/resources/patches-take-weeks-exploits-take-hours-the-2026-dbir-makes-the-math-brutal">latest DBIR found</a></strong> that exploitation of vulnerabilities is the #1 attack vector, twice as high as #2, and growing, as attackers continue to capitalize on remediation bottleneck.</p><h3>The Case for Autonomous Defensive Workflows</h3><p>The traditional vulnerability management lifecycle, scan, prioritize, ticket, patch, verify, was built for a tempo that no longer exists. </p><p>Each step in that chain introduces latency, and latency is the thing defenders can least afford when exploitation timelines are measured in hours. The industry has recognized this at the conceptual level, which is why frameworks like Continuous Threat Exposure Management (CTEM) have gained traction as the successor to legacy VM programs. </p><p>As I wrote in <strong><a href="https://www.resilientcyber.io/p/vulnerability-management-evolves">Vulnerability Management Evolves to CTEM</a></strong>, the shift from periodic scanning and static prioritization to continuous, context-aware exposure management represents a necessary evolution.</p><p>But CTEM as a framework still requires operationalization, and that&#8217;s where most organizations stall. They understand the need for continuous assessment, business-aligned scoping, and validation-driven prioritization. They struggle to execute it at the speed the threat environment demands because their workflows still depend on human analysts to interpret findings, human operators to implement remediations, and human decision-makers to approve changes. Each of those handoffs introduces hours or days of delay in a world where exploitation happens in minutes.</p><p>This is why I wrote in <strong><a href="https://www.resilientcyber.io/p/elevating-ctem-with-agentic-exposure">Elevating CTEM with Agentic Exposure Management</a></strong> that the next evolution of exposure management requires agentic AI workflows that can operate autonomously within defined guardrails. The concept isn&#8217;t replacing human judgment entirely, it&#8217;s removing humans from the steps that don&#8217;t require judgment, automating the repetitive, time-sensitive execution work so that human analysts can focus on the genuinely complex decisions that benefit from their expertise.</p><p>As I explored in <strong><a href="https://www.resilientcyber.io/p/vulnerability-management-in-the-age">Vulnerability Management in the Age of Autonomous Exploitation</a></strong>, where I unpacked CSA&#8217;s guidance, the organizations that will navigate this era successfully are the ones that can match autonomy with autonomy. </p><p>That means workflows that detect new exposures within hours of disclosure, assess exploitability against the organization&#8217;s actual environment and compensating controls, generate and route remediation actions through existing tooling, and execute compensating controls without waiting for a patch cycle. </p><p>This is not a future aspiration, it&#8217;s a current operational requirement for any organization facing the exploitation timelines documented in the 2026 DBIR and other sources.</p><h2>What Autonomous Workflows Look Like in Practice</h2><p>Describing autonomous defensive workflows in the abstract or publications is fairly straightforward. Operationalizing them is where the real challenge lives, because autonomy without context is just faster noise. An autonomous system that generates thousands of tickets for vulnerabilities that aren&#8217;t exploitable in your environment hasn&#8217;t solved the problem, it&#8217;s added to it and created the exact type of toil that had led to developers dreading engaging with us in cyber.</p><p>Resilient Cyber&#8217;s partner, Zafran&#8217;s <strong><a href="https://www.zafran.io/resources/introducing-the-zafran-zero-day-agent-an-autonomous-workflow-for-the-post-mythos-era?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=Mythos&amp;utm_content=AI-blogpost">Zero Day Agent</a></strong> is one example of how autonomous workflows can be operationalized against the AI-augmented exploitation problem. The approach is built around a core insight that most vulnerability management programs miss entirely. Not every vulnerability that scores a 9.8 on CVSS is actually exploitable in every environment, because the presence of compensating controls, network segmentation, runtime configurations, and defensive tooling already in place can neutralize many critical findings before a patch is ever applied.</p><blockquote><div id="vimeo-1189805770" class="vimeo-wrap" data-attrs="{&quot;videoId&quot;:&quot;1189805770&quot;,&quot;videoKey&quot;:&quot;&quot;,&quot;belowTheFold&quot;:true}" data-component-name="VimeoToDOM"><div class="vimeo-inner"><iframe src="https://player.vimeo.com/video/1189805770?autoplay=0" frameborder="0" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" loading="lazy"></iframe></div></div></blockquote><p>The Zero Day Agent&#8217;s workflow runs in a continuous loop. When a new zero-day or high-priority vulnerability is disclosed, the agent automatically identifies affected assets across the environment by cross-referencing against the organization&#8217;s software inventory and runtime presence data. </p><p>It then assesses whether the vulnerability is actually exploitable given the organization&#8217;s specific defensive posture, evaluating factors like internet reachability, existing firewall rules, EDR coverage, and WAF configurations.</p><p>For vulnerabilities where compensating controls already neutralize the risk, the agent documents that finding and moves on. For the subset that are genuinely exploitable, it automatically generates work items with pre-populated context, including affected assets, exploitability analysis, and recommended remediation steps, and routes them through existing ITSM tools.</p><p>We&#8217;ve seen the rise and popularity of &#8220;reachability analysis&#8221; in the SCA and runtime context for applications, and this sort of zero day agent helps take that a step further with broader organizational and environment context beyond just code.</p><p>This is a critical distinction from traditional vulnerability management, which treats every critical-severity finding as equally urgent regardless of environmental context. Zafran&#8217;s data suggests that roughly 90% of critical vulnerabilities are not exploitable in a given environment once compensating controls are properly mapped, which means the remediation effort can focus on the 10% that actually represent real risk. That&#8217;s the difference between an autonomous workflow that creates value and one that just creates velocity.</p><p>This sort of capability has been elusive for organizations both due to the level of effort needed to validate exposure, but also due to the comprehensive environmental and organizational context needed to determine it.</p><p>The practical impact is compressing the response timeline from weeks to hours. Instead of a vulnerability disclosure triggering a manual triage process that takes days to assess scope, additional days to prioritize against the backlog, and weeks to schedule and deploy patches, the autonomous workflow handles discovery, assessment, and routing within hours of disclosure. </p><p>For organizations operating under the exploitation timelines documented in the 2026 DBIR or M-Trends, that compression isn&#8217;t a nice-to-have, it&#8217;s the difference between responding before exploitation and performing incident response after it.</p><div><hr></div><p>As someone who literally wrote the book on effective vulnerability management, there&#8217;s no question to me that vulnerability management needs to become autonomous. Data in reports such as M-Trends, DBIR and broader industry trends has already answered that. </p><p>That said, many are looking for guidance on how to operationalize that autonomy. </p><blockquote><p>You can Join Zafran for the <strong><a href="https://go.zafran.io/webinar-operationalize-autonomous-defense-against-next-gen-exploits?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=Mythos&amp;utm_content=AI-blogpost">upcoming webinar</a></strong> With Zafran&#8217;s CISO Nate Rollings, along with Lawrence Pingree of <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;SACR&quot;,&quot;id&quot;:6770950,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1abfe3b-34cf-49c6-af16-c3961bb40c4f_512x512.jpeg&quot;,&quot;uuid&quot;:&quot;e9de003c-96d2-43cc-9b33-e5314ce421b6&quot;}" data-component-name="MentionToDOM"></span> where they&#8217;re dig deeper into what that operationalization looks like in practice and how to navigate the transition from traditional VM to autonomous workflows.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://go.zafran.io/webinar-operationalize-autonomous-defense-against-next-gen-exploits?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=Mythos&amp;utm_content=AI-blogpost" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mQPE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mQPE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mQPE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mQPE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mQPE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:450287,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://go.zafran.io/webinar-operationalize-autonomous-defense-against-next-gen-exploits?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=Mythos&amp;utm_content=AI-blogpost&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198542896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mQPE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mQPE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mQPE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mQPE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F131e1bda-c141-47bb-87b3-a730af243989_1200x630.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>From Maturity Model to Operational Reality</h2><p>The evolution from legacy vulnerability management through risk-based approaches to CTEM represents a maturity curve that most organizations are somewhere in the middle of navigating. Zafran&#8217;s <strong><a href="https://www.zafran.io/get-ctem-guide?utm_source=Resilient-Cyber&amp;utm_medium=referral&amp;utm_campaign=CTEM&amp;utm_content=blogpost">updated CTEM whitepaper</a></strong> adds a fifth stage to the maturity model, Autonomous Workflows, which represents the operational end-state that the current threat environment demands.</p><p>The progression is logical and aligns with the broader industry trends that warrant the organizational evolution of CTEM. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jHFC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jHFC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png 424w, https://substackcdn.com/image/fetch/$s_!jHFC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png 848w, https://substackcdn.com/image/fetch/$s_!jHFC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png 1272w, https://substackcdn.com/image/fetch/$s_!jHFC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jHFC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png" width="1456" height="956" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:956,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:480273,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198542896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jHFC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png 424w, https://substackcdn.com/image/fetch/$s_!jHFC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png 848w, https://substackcdn.com/image/fetch/$s_!jHFC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png 1272w, https://substackcdn.com/image/fetch/$s_!jHFC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F149e5446-8cf6-4463-a186-497d9baa9396_2180x1432.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><ul><li><p><strong>Stage one</strong> is scanner-focused vulnerability management, counting CVEs and generating reports. </p></li><li><p><strong>Stage two</strong> introduces basic prioritization, typically CVSS-driven. </p></li><li><p><strong>Stage three</strong> moves to risk-based vulnerability management, incorporating threat intelligence and asset context. </p></li><li><p><strong>Stage four</strong> is full CTEM, with continuous scoping, discovery, prioritization, validation, and mobilization. </p></li><li><p><strong>Stage five</strong> adds autonomous execution, where agentic AI systems handle the high-volume, time-sensitive operational work within human-defined policy guardrails.</p></li></ul><p>Most organizations I talk to are somewhere between stages two and four, and the jump to autonomous workflows feels daunting because it requires trust in automated systems making decisions that have traditionally been reserved for human analysts.</p><p>That concern is reasonable, but it needs to be weighed against the alternative, which is continuing to run human-paced processes against machine-speed exploitation. The organizations that insist on human review of every remediation decision are implicitly accepting that they will be slower than their adversaries on every critical vulnerability. In the current environment, that is a choice with real consequences for the organizations we&#8217;re supposed to be defending.</p><p>The guardrails matter as well and autonomous doesn&#8217;t mean uncontrolled. The most effective implementations maintain human oversight at the policy level, humans define which classes of actions the autonomous system can take, what severity thresholds trigger automated response, and what changes require approval, while delegating the execution of those policies to automated workflows. </p><p>The human role shifts from doing the work to governing how the work gets done, which is both a more efficient use of scarce security talent and a more sustainable operating model given the volume of findings most programs are managing.</p><h2>The Structural Shift Ahead</h2><p>The AI-driven exploitation era isn&#8217;t a temporary phase. Every structural trend in the data, more vulnerabilities, faster exploitation, expanding attack surfaces, degrading data infrastructure, AI-accelerated offensive tooling, points in the same direction. The organizations that will navigate this successfully are the ones that operationalize autonomy in their defensive workflows now, rather than waiting for the exploitation gap to widen further.</p><p>As I argued at the SANS Agentic AI Security Summit in D.C. in April this year, cyber needs to shift from being a late adopter and laggard to being an early adopter and innovator if we hope to have any chance of keeping pace with attackers in the AI era. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G3qR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G3qR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png 424w, https://substackcdn.com/image/fetch/$s_!G3qR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png 848w, https://substackcdn.com/image/fetch/$s_!G3qR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png 1272w, https://substackcdn.com/image/fetch/$s_!G3qR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G3qR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png" width="672" height="371.9294947121034" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:471,&quot;width&quot;:851,&quot;resizeWidth&quot;:672,&quot;bytes&quot;:445223,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198542896?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!G3qR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png 424w, https://substackcdn.com/image/fetch/$s_!G3qR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png 848w, https://substackcdn.com/image/fetch/$s_!G3qR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png 1272w, https://substackcdn.com/image/fetch/$s_!G3qR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ab99e31-d960-4df7-8794-e9f0a30b3d1c_851x471.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The frameworks exist, CTEM provides the conceptual architecture, industry guidance is encouraging this shift and agentic AI provides the execution capability. Solutions like Zafran&#8217;s Zero Day Agent demonstrate that autonomous defensive workflows aren&#8217;t theoretical or aspirational. They&#8217;re operational today, compressing response timelines from weeks to hours and focusing human expertise where it actually matters.</p><p>It&#8217;s time for security to be an innovator in this technological wave, rather than a laggard, and one of the areas most ripe for disruption for us is leveraging AI and Agents for the biggest bottleneck of all - remediation.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[AI Is Winning the Cyber Arms Race]]></title><description><![CDATA[A look at AI's impact on cyber and the case for orienting around limiting the blast radius]]></description><link>https://www.resilientcyber.io/p/ai-is-winning-the-cyber-arms-race</link><guid isPermaLink="false">https://www.resilientcyber.io/p/ai-is-winning-the-cyber-arms-race</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 05 Jun 2026 12:01:34 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/200439751/f05b7c5c6da07170c29d997dda76b6de.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>For twenty years the security playbook started in the same place, find a vulnerability, prioritize it, and patch it. Doug Merritt, CEO of Aviatrix and former CEO of Splunk, thinks that playbook is quietly breaking, and his explanation has nothing to do with anyone being careless. </p><p>The economics of offense changed underneath us, and most security programs are still funded as if they did not.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><strong>Why this conversation matters</strong></h2><p>Doug has sat in two seats that give this argument weight. </p><p>At Splunk he evangelized detect and respond, and now at Aviatrix he is arguing that detect and respond, while still important, is no longer enough on its own. That is not a vendor pivot so much as an honest reading of the incentives, and it lands differently coming from someone who built a business on the previous era. </p><p>If you are a practitioner watching AI rewrite the attacker&#8217;s cost curve, or a leader trying to defend a prevention-heavy budget to a board, this conversation reframes where the money should actually go.</p><h2><strong>Key takeaways</strong></h2><ul><li><p><strong>Offense became a compute problem, and that is permanent.</strong> Finding and exploiting a vulnerability is a search task, and the cost per token has been deflating faster than Moore&#8217;s Law. That is why this is a structural shift rather than a few headline demos, and why throwing compute at offense keeps getting cheaper and faster.</p></li><li><p><strong>Patching has a ceiling that offense does not.</strong> Every patch carries the risk of breaking something, so testing, deployment, and organizational friction cap how fast defenders can move. When vulnerability discovery scales freely and patching cannot, &#8220;find more and patch faster&#8221; turns into a race you are structurally set up to lose.</p></li><li><p><strong>The interesting question is not how they got in, it is where they went.</strong> Attackers increasingly arrive with valid credentials and move through the trust graph that runs across cloud services and CI/CD pipelines, including malware injected into trusted repositories. Once they look legitimate inside the environment, lateral movement and egress are where the real damage happens.</p></li><li><p><strong>Cloud rewarded velocity, and security paid the bill.</strong> Cloud providers made identity default-deny because someone has to own and pay for a workload, but they left networking wide open because their economic engine is developer velocity and security reads as friction. New agentic frameworks inherit that same wide-open default, connected to the internet with little oversight.</p></li><li><p><strong>A strong identity stance is necessary and not sufficient.</strong> Identity answers whether someone is allowed to act, not whether the action is an attack, which is why attackers log in rather than hack in. Human, agent, and workload identities are genuinely different, and workload identity in particular has been underserved.</p></li><li><p><strong>Containment is about blast radius, not about keeping everyone out.</strong> The mindset shift is to accept that breaches will occur and to govern every path a workload can take, so an incident stays local and recoverable. Done well, containment holds firm whether or not anyone has detected the attack yet.</p></li><li><p><strong>Blast radius has to become a boardroom metric.</strong> Doug&#8217;s argument is that CISOs, CIOs, CEOs, and boards should be able to answer how reachable anything is from anything else, and treat that number as something to drive down deliberately rather than discover after an incident.</p></li><li><p><strong>AI is the reason containment is finally workable.</strong> The historic blocker to micro-segmentation was cognitive load across tens or hundreds of thousands of workloads. AI is strong at synthesis and pattern matching, which makes a staged path of observe, discover, monitor, and then enforce realistic, ideally starting with the internet-exposed workloads that have no filtering at all.</p></li></ul><h2><strong>Notable quotes</strong></h2><blockquote><p>&#8220;<strong>developer velocity and security is friction</strong>&#8221;</p></blockquote><p>Doug, on why cloud networking is wide open by default.</p><blockquote><p>&#8220;<strong>It always is a lateral movement and egress problem</strong>.&#8221;</p><p>&#8220;<strong>To say I&#8217;ve got a strong identity stance, therefore I&#8217;m good, is irresponsible.</strong>&#8221;</p></blockquote><h2><strong>Listen and Watch</strong></h2><div id="youtube2-OGy2cD3oTxM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;OGy2cD3oTxM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/OGy2cD3oTxM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong><a href="https://open.spotify.com/episode/5C4wEbC8Wa5eRCbPxD9WWC?si=dfUkzuO9TWu6EpnQz9WgDQ">Spotify</a></strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/ai-is-winning-the-cyber-arms-race/id1555928024?i=1000770964389">Apple Podcasts</a></strong></p><h2><strong>Resources</strong></h2><p><strong><a href="https://aviatrix.ai/threat-research-center/">Aviatrix Threat Research Center</a></strong></p><p><strong><a href="https://www.linkedin.com/in/doug-m-33169/">Doug&#8217;s LinkedIn</a></strong></p><h2><strong>Subscribe</strong></h2><p>If this kind of structural take on security is useful to you, subscribe to Resilient Cyber for more conversations and writing on cybersecurity, AI, and the incentives that shape both.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #100]]></title><description><![CDATA[White House AI EO, Mythos Headed for Public Release, Pentagon to Overhaul RMF, Calls for OSS Public-Interest Fund, 2026 Record CVE Growth & Zero Trust for AI Agents]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-100</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-100</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 04 Jun 2026 11:31:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iViU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #100 of the Resilient Cyber Newsletter!</p><p>One hundred issues in, and the pace has never been higher. As I get home from the Gartner Security &amp; Risk Summit in National Harbor this week, there&#8217;s a lot to cover.</p><p>The White House signed an executive order on June 2nd titled &#8220;Promoting Advanced Artificial Intelligence Innovation and Security,&#8221; and the most revealing thing about it is not what it mandates but what it does not. The order creates binding requirements for Federal agencies to accelerate AI-enabled cyber defense while keeping every meaningful obligation for the private sector entirely voluntary. I wrote a full breakdown in <strong><a href="https://www.resilientcyber.io/p/the-vulnpocalypse-wont-wait-for-interagency">The Vulnpocalypse Won&#8217;t Wait for Interagency Coordination</a></strong>, and the short version is that the voluntary model collides with exploit timelines measured in hours.</p><p>Meanwhile, Anthropic expanded Glasswing to 150+ new partners across 15 countries and began negotiations to give ENISA direct access to Mythos. Cisco scanned 1.8 billion lines of code in eight weeks using frontier AI, work that would have taken eight years, and the Nx Console supply chain compromise showed that 18 minutes of a malicious VSCode extension was enough to breach GitHub&#8217;s internal repositories.</p><p>On open source sustainability, Jen Easterly proposed a billion-dollar public-interest fund while Dan Lorenc at Chainguard committed $50 million and 100 engineers to become the &#8220;maintainer of last resort.&#8221; Both are direct responses to the human sustainability crisis I tracked through Daniel Stenberg&#8217;s posts in issues #97 through #99.</p><p>Root Evidence confirmed that only 1.4% of CVEs are ever exploited in the wild, the Pentagon&#8217;s new CISO announced plans to overhaul the Risk Management Framework, and the WSJ reported on &#8220;turncoat AI agents&#8221; as the new insider threat vector.</p><p>Let&#8217;s get into it!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iViU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iViU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png 424w, https://substackcdn.com/image/fetch/$s_!iViU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png 848w, https://substackcdn.com/image/fetch/$s_!iViU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png 1272w, https://substackcdn.com/image/fetch/$s_!iViU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iViU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png" width="723" height="431.18280542986423" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:659,&quot;width&quot;:1105,&quot;resizeWidth&quot;:723,&quot;bytes&quot;:533474,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!iViU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png 424w, https://substackcdn.com/image/fetch/$s_!iViU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png 848w, https://substackcdn.com/image/fetch/$s_!iViU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png 1272w, https://substackcdn.com/image/fetch/$s_!iViU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1728802e-22e8-45ed-b622-7247d1b53f32_1105x659.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p><div><hr></div><p><em><strong>Interested in sponsoring an issue of Resilient Cyber?</strong></em></p><p><em><strong>This includes reaching over 31,000 subscribers, ranging from Developers, Engineers, Architects, CISO&#8217;s/Security Leaders and Business Executives</strong></em></p><p><em><strong>Reach out below!</strong></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:sponsorships@resilientcyber.io&quot;,&quot;text&quot;:&quot;-> Contact Us! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="mailto:sponsorships@resilientcyber.io"><span>-&gt; Contact Us! &lt;-</span></a></p><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.resilientcyber.io/p/the-vulnpocalypse-wont-wait-for-interagency">The Vulnpocalypse Won&#8217;t Wait for Interagency Coordination</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f3Xo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f3Xo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png 424w, https://substackcdn.com/image/fetch/$s_!f3Xo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png 848w, https://substackcdn.com/image/fetch/$s_!f3Xo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png 1272w, https://substackcdn.com/image/fetch/$s_!f3Xo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f3Xo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png" width="682" height="255.82799634034765" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:410,&quot;width&quot;:1093,&quot;resizeWidth&quot;:682,&quot;bytes&quot;:92580,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!f3Xo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png 424w, https://substackcdn.com/image/fetch/$s_!f3Xo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png 848w, https://substackcdn.com/image/fetch/$s_!f3Xo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png 1272w, https://substackcdn.com/image/fetch/$s_!f3Xo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25017318-6f46-4604-b360-cdcceee3ffe1_1093x410.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I wrote a <a href="https://www.resilientcyber.io/p/the-vulnpocalypse-wont-wait-for-interagency">full analysis</a> of the June 2nd executive order on AI. The order creates binding 30-day and 60-day deadlines for Federal agencies, including CISA Binding Operational Directives for AI-enabled defense, a Treasury-led cybersecurity clearinghouse, and classified NSA benchmarking to define &#8220;covered frontier models,&#8221; while keeping every private sector obligation voluntary. </p><p>The order explicitly prohibits mandatory licensing or preclearance for AI model development. The deregulatory logic has merit, but the voluntary model faces a structural problem I have been tracking since Vulnpocalypse. AI has compressed exploit timelines from months to hours while the latest DBIR shows 43 days as the median to remediate KEV vulnerabilities. </p><p>The ambition is real, but whether the institutions can execute at the speed the threat demands is the question that will determine whether this EO matters.</p><h3><a href="https://www.cnbc.com/2026/06/02/anthropic-mythos-ai-project-glasswing.html">Glasswing Goes Global as Anthropic Adds 150 Partners Across 15 Countries</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rrnw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rrnw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png 424w, https://substackcdn.com/image/fetch/$s_!rrnw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png 848w, https://substackcdn.com/image/fetch/$s_!rrnw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png 1272w, https://substackcdn.com/image/fetch/$s_!rrnw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rrnw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png" width="982" height="217" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8468820b-0202-430b-881a-bd4449f26e3f_982x217.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:217,&quot;width&quot;:982,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:35511,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!rrnw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png 424w, https://substackcdn.com/image/fetch/$s_!rrnw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png 848w, https://substackcdn.com/image/fetch/$s_!rrnw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png 1272w, https://substackcdn.com/image/fetch/$s_!rrnw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8468820b-0202-430b-881a-bd4449f26e3f_982x217.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Project Glasswing is expanding from roughly 50 initial partners to over 200, adding sectors underrepresented in the first wave, including power, water, healthcare, and hardware. Anthropic also confidentially filed its IPO prospectus with the SEC. </p><p>The expansion validates the thesis I have been tracking since Glasswing launched. AI-driven vulnerability discovery at this scale cannot remain gated to a small group of technology companies, but widening the pipeline only works if the downstream systems can absorb it.</p><h3><a href="https://www.bloomberg.com/news/articles/2026-06-01/anthropic-to-give-eu-s-cybersecurity-agency-access-to-mythos">Anthropic Offers ENISA Direct Access to Mythos in a Move That Ends Weeks of Diplomatic Tension</a></h3><p>Anthropic communicated its decision to the European Commission over the weekend, making ENISA the first EU agency to receive access to Mythos. The move ends a weeks-long standoff in which Euro-area finance ministers, the European Central Bank, and multiple EU member states demanded access after learning Mythos had found vulnerabilities in systems European governments and critical infrastructure rely on daily. </p><p>This is the clearest signal yet that frontier AI models with security capabilities will be treated as strategic assets, subject to access negotiations that look more like arms export controls than software licensing.</p><h3><a href="https://www.forbes.com/sites/ronschmelzer/2026/05/29/anthropics-guarded-mythos-model-is-headed-for-wider-release/">Mythos-Class Models Are Headed for Public Release Within Weeks</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LPEP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LPEP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png 424w, https://substackcdn.com/image/fetch/$s_!LPEP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png 848w, https://substackcdn.com/image/fetch/$s_!LPEP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png 1272w, https://substackcdn.com/image/fetch/$s_!LPEP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LPEP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png" width="1003" height="124" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:124,&quot;width&quot;:1003,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:27589,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!LPEP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png 424w, https://substackcdn.com/image/fetch/$s_!LPEP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png 848w, https://substackcdn.com/image/fetch/$s_!LPEP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png 1272w, https://substackcdn.com/image/fetch/$s_!LPEP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d019e01-cc8f-4a36-b78a-a8fadbfc6038_1003x124.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Anthropic has made &#8220;swift progress&#8221; on safety safeguards that would allow Mythos-level models to be released to all customers within weeks. The public release timeline changes everything in the Mythos Scrutiny Arc since issue #95. Until now, disclosure volume was constrained by partner count. </p><p>A public release means anyone with an API key can run the same discovery pipeline. A Just Security analysis titled &#8220;<strong><a href="https://www.justsecurity.org/138011/too-dangerous-anthropic-mythos/">Too Dangerous to Deploy</a></strong>&#8220; questioned whether any safeguard can be sufficient at this scale. Given how trivial it&#8217;s been shown to jailbreak any model, it begs the question why Mythos would be viewed any differently.</p><h3><a href="https://www.govconwire.com/articles/pentagon-rmf-overhaul-aaron-bishop-ciso-cyber">The Pentagon&#8217;s New CISO Plans to Overhaul the Risk Management Framework</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PVbL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PVbL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png 424w, https://substackcdn.com/image/fetch/$s_!PVbL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png 848w, https://substackcdn.com/image/fetch/$s_!PVbL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png 1272w, https://substackcdn.com/image/fetch/$s_!PVbL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PVbL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png" width="598" height="370.2732558139535" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:426,&quot;width&quot;:688,&quot;resizeWidth&quot;:598,&quot;bytes&quot;:447682,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!PVbL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png 424w, https://substackcdn.com/image/fetch/$s_!PVbL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png 848w, https://substackcdn.com/image/fetch/$s_!PVbL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png 1272w, https://substackcdn.com/image/fetch/$s_!PVbL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F856e0ec6-d3f7-4e9f-a2b7-c7c7145d6ada_688x426.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>DoW CISO Aaron Bishop characterized the current RMF as having a &#8220;1990s mentality&#8221; that is too slow, too paperwork-heavy, and too disconnected from modern cyber operations. Six months after completing an RMF package, the documentation is already outdated and wrong. </p><p>The proposed reform replaces static documentation with telemetry-driven operational awareness. For those of us who have argued that GRC is still in the dark ages, this is an encouraging signal.</p><h3><a href="https://www.linkedin.com/pulse/open-source-runs-world-shouldnt-run-goodwill-alone-jen-easterly-9loxe">Jen Easterly Argues Open Source Needs a Billion-Dollar Public-Interest Fund</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nmpf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nmpf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png 424w, https://substackcdn.com/image/fetch/$s_!Nmpf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png 848w, https://substackcdn.com/image/fetch/$s_!Nmpf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png 1272w, https://substackcdn.com/image/fetch/$s_!Nmpf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nmpf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png" width="844" height="189" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/10afe925-c4c4-485d-b915-14476c4be36e_844x189.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:189,&quot;width&quot;:844,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43617,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Nmpf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png 424w, https://substackcdn.com/image/fetch/$s_!Nmpf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png 848w, https://substackcdn.com/image/fetch/$s_!Nmpf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png 1272w, https://substackcdn.com/image/fetch/$s_!Nmpf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10afe925-c4c4-485d-b915-14476c4be36e_844x189.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Easterly&#8217;s argument is simple. Open source sits underneath banks, hospitals, cloud platforms, and government systems, and the maintainers carry enormous responsibility with limited resources. Her proposal is a billion-dollar fund to secure the software commons, supported by frontier AI companies. </p><p>Combined with Stenberg&#8217;s &#8220;The Pressure&#8221; post and the Chainguard commitment below, the conversation has moved from abstract concern to concrete proposals with dollar amounts attached. The question is whether the funding arrives before the AI-accelerated disclosure pipeline overwhelms the maintainers holding critical infrastructure together on goodwill.</p><h3><a href="https://www.wsj.com/pro/cybersecurity/turncoat-ai-agents-emerge-as-the-new-inside-hackers-b0021e11">The WSJ Reports on &#8220;Turncoat AI Agents&#8221; as the New Insider Threat</a></h3><p>AI agents are always on, operate with persistent credentials, and can be hijacked without the agent or its operators knowing. The WSJ positions compromised agents as the next generation of insider threat, one that operates at machine speed without the behavioral tells traditional programs rely on. </p><p>The answer is the same one I have been writing about since my article on identity as the agentic AI problem. If you cannot answer &#8220;what can this agent do,&#8221; &#8220;on whose behalf,&#8221; and &#8220;who approved it&#8221; the same way you can for a human employee, you are not ready for the autonomy these systems are about to have.</p><h3><a href="https://www.linkedin.com/posts/jgamblin_cve-vulnerabilitymanagement-infosec-share-7467218793174441984-BqhC/">Congress Extends Cybersecurity Pressure as CVE Volume Hits Record Pace</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i3Ke!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i3Ke!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png 424w, https://substackcdn.com/image/fetch/$s_!i3Ke!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png 848w, https://substackcdn.com/image/fetch/$s_!i3Ke!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png 1272w, https://substackcdn.com/image/fetch/$s_!i3Ke!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i3Ke!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png" width="470" height="339.3198090692124" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:605,&quot;width&quot;:838,&quot;resizeWidth&quot;:470,&quot;bytes&quot;:164516,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!i3Ke!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png 424w, https://substackcdn.com/image/fetch/$s_!i3Ke!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png 848w, https://substackcdn.com/image/fetch/$s_!i3Ke!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png 1272w, https://substackcdn.com/image/fetch/$s_!i3Ke!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a254eaf-5ffb-41e4-8c23-2ac3cf17c7ef_838x605.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Jerry Gamblin&#8217;s data shows 27,758 vulnerabilities published by June 1, a 39% increase over the same period in 2025, which set a record with 48,185 total CVEs. Only 52% of 2025 CVEs have fully enriched NVD data. </p><p>AI-assisted discovery is not a spike but a permanent increase in baseline velocity. The organizations that will survive this volume are the ones prioritizing based on exploitability, reachability, and business context.</p><h3><a href="https://www.rootevidence.com/report">Root Evidence Confirms That Only 1.4% of CVEs Are Exploited in Real-World Attacks</a></h3><p>This is the data every security leader should bring to their next board meeting. Root Evidence&#8217;s Q1 2026 &#8220;Stop Counting CVEs&#8221; report found that only 1.4% of CVEs are known to be exploited in real-world attacks. </p><p>Common prioritization signals, including CVSS, EPSS, and Metasploit modules, all perform poorly as indicators of actual exploitation. When 98.6% of vulnerabilities are never exploited, the organizations chasing zero CVEs are doing risk theater, not risk management.</p><h3><a href="https://www.coalitionforsecureai.org/wp-content/uploads/2026/05/CoSAI-Shared-Responsibility-Framework.pdf">CoSAI Publishes the AI Shared Responsibility Framework</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GBIx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GBIx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png 424w, https://substackcdn.com/image/fetch/$s_!GBIx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png 848w, https://substackcdn.com/image/fetch/$s_!GBIx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png 1272w, https://substackcdn.com/image/fetch/$s_!GBIx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GBIx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png" width="501" height="532.5364806866953" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/676772b7-175a-45fd-bea9-d54b92188b96_699x743.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:743,&quot;width&quot;:699,&quot;resizeWidth&quot;:501,&quot;bytes&quot;:403897,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!GBIx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png 424w, https://substackcdn.com/image/fetch/$s_!GBIx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png 848w, https://substackcdn.com/image/fetch/$s_!GBIx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png 1272w, https://substackcdn.com/image/fetch/$s_!GBIx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F676772b7-175a-45fd-bea9-d54b92188b96_699x743.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>CoSAI released a five-layer model that maps accountability across the full AI stack and assigns exactly one responsible party to each component. When something goes wrong with an AI system, who is responsible? </p><p>The answer today for most organizations is &#8220;nobody, because we never defined it.&#8221; This framework, combined with OWASP&#8217;s AIUC-1 crosswalk, is closing the governance gap between AI capability and accountability.</p><div><hr></div><h1>AI</h1><h3><a href="https://blogs.cisco.com/news/8-years-of-security-research-in-8-weeks-transforming-cybersecurity-with-ai">Cisco Scanned 1.8 Billion Lines of Code in Eight Weeks Using Frontier AI Models</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EfXE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EfXE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png 424w, https://substackcdn.com/image/fetch/$s_!EfXE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png 848w, https://substackcdn.com/image/fetch/$s_!EfXE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png 1272w, https://substackcdn.com/image/fetch/$s_!EfXE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EfXE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png" width="1255" height="251" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:251,&quot;width&quot;:1255,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:191991,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!EfXE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png 424w, https://substackcdn.com/image/fetch/$s_!EfXE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png 848w, https://substackcdn.com/image/fetch/$s_!EfXE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png 1272w, https://substackcdn.com/image/fetch/$s_!EfXE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88e1f193-112c-468e-980a-2fd2d591cc6e_1255x251.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Cisco used a multi-model AI harness, including Claude Mythos Preview and GPT 5.5-Cyber, to scan 1.8 billion lines of code in over 25 languages. Their security research team estimated this would have taken eight years manually. </p><p>As a direct consequence, Cisco will shift to biweekly security disclosures starting in July. Cisco&#8217;s cadence change is the canary. Other large vendors will follow, and the organizations consuming those advisories need to be ready for twice the volume. This is not a temporary spike, it is the new normal.</p><h3><a href="https://cdn.prod.website-files.com/6889473510b50328dbb70ae6/6a1611a04085d7cd3dadc924_Claude-eBook-Zero-Trust-for-AI-Agents-05182026.pdf">Anthropic Publishes a Zero Trust Security Framework for AI Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9mYG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9mYG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png 424w, https://substackcdn.com/image/fetch/$s_!9mYG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png 848w, https://substackcdn.com/image/fetch/$s_!9mYG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png 1272w, https://substackcdn.com/image/fetch/$s_!9mYG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9mYG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png" width="416" height="268.90965732087227" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0741cf26-8908-4737-82f5-24a2960fac20_642x415.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:415,&quot;width&quot;:642,&quot;resizeWidth&quot;:416,&quot;bytes&quot;:30416,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!9mYG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png 424w, https://substackcdn.com/image/fetch/$s_!9mYG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png 848w, https://substackcdn.com/image/fetch/$s_!9mYG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png 1272w, https://substackcdn.com/image/fetch/$s_!9mYG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0741cf26-8908-4737-82f5-24a2960fac20_642x415.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This framework applies every core zero-trust principle to agentic workloads, identifying five agent-specific threats including prompt injection, tool poisoning, and identity abuse. Anthropic reports it blocked 95% of jailbreak attempts with minimal latency increase, and it is platform-agnostic. </p><p>As I wrote in &#8220;<strong><a href="https://www.resilientcyber.io/p/zero-trust-was-built-for-a-different">Zero Trust Was Built for a Different Kind of Trust Problem</a></strong>,&#8221; the principles translate but the implementation patterns are fundamentally different when the actor is an LLM with tool access rather than a human with a browser.</p><h3><a href="https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositories">The Nx Console Supply Chain Compromise Breached GitHub&#8217;s Internal Repositories in 18 Minutes</a></h3><p>Eighteen minutes. That is how long a trojanized Nx Console VSCode extension (version 18.95.0) needed to be live before automatic updates pushed it to every installed instance, compromising a GitHub employee&#8217;s device and exfiltrating internal repositories. CVE-2026-48027 has been added to the CISA KEV catalog. </p><p>In a separate &#8220;Megalodon&#8221; campaign, malicious GitHub Action workflows harvested CI/CD secrets and cloud credentials from public repositories. The development environment is now the primary attack surface.</p><h3><a href="https://www.chainguard.dev/unchained/the-hardest-fork">Chainguard Commits $50 Million and 100 Engineers to Become the Maintainer of Last Resort</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DhkT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DhkT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png 424w, https://substackcdn.com/image/fetch/$s_!DhkT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png 848w, https://substackcdn.com/image/fetch/$s_!DhkT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png 1272w, https://substackcdn.com/image/fetch/$s_!DhkT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DhkT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png" width="375" height="146" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:146,&quot;width&quot;:375,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:13010,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!DhkT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png 424w, https://substackcdn.com/image/fetch/$s_!DhkT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png 848w, https://substackcdn.com/image/fetch/$s_!DhkT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png 1272w, https://substackcdn.com/image/fetch/$s_!DhkT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4754b0d0-24cf-433c-a253-a2ba78840f1f_375x146.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Dan Lorenc&#8217;s post is one of the most significant commitments to open source sustainability from a commercial entity I have seen in 20 years. AI models like Mythos can find hundreds of vulnerabilities overnight across projects maintained by one person with no obligation to patch. </p><p>Chainguard will build trust infrastructure for open source consumption by becoming the &#8220;maintainer of last resort.&#8221; Lorenc outlines three futures. The naive one where we pretend the current model works. The chaotic one where disclosure floods the ecosystem. And the hard fork, a deliberate decision to build one disclosure pipeline that works at scale.</p><h3><a href="https://aws.amazon.com/blogs/security/secure-multi-tenant-ai-agents-with-amazon-bedrock-agentcore-resource-based-policies/">AWS Adds Resource-Based Policies for Multi-Tenant Agent Security in AgentCore</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8vCT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8vCT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png 424w, https://substackcdn.com/image/fetch/$s_!8vCT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png 848w, https://substackcdn.com/image/fetch/$s_!8vCT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png 1272w, https://substackcdn.com/image/fetch/$s_!8vCT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8vCT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png" width="850" height="518" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:518,&quot;width&quot;:850,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108266,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!8vCT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png 424w, https://substackcdn.com/image/fetch/$s_!8vCT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png 848w, https://substackcdn.com/image/fetch/$s_!8vCT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png 1272w, https://substackcdn.com/image/fetch/$s_!8vCT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ff7cb1e-bd77-4dcc-af8a-233eafeedc70_850x518.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AWS continues building out the AgentCore identity infrastructure. The new resource-based policies give SaaS providers centralized control over who can access AgentCore Runtime resources, with explicit Deny statements blocking requests not from approved VPCs and tool interceptors validating JWT claims. </p><p>Combined with AWS AgentCore OBO delegation, Uber&#8217;s agent identity architecture, and Google&#8217;s Agent Identity, the hyperscalers are converging on a shared pattern. Agent access is governed per-tenant, per-resource, and per-tool, with cryptographic attestation at each hop.</p><h3><a href="https://tessl.io/blog/securing-the-coder-not-the-code-notes-on-agentic-development-and-security/">Tessl Argues That Security Should Target the Coder, Not the Code</a></h3><p>When coding agents generate the majority of new code, scanning the output is necessary but insufficient. The leverage point is the agent itself, specifically the skills, instructions, and context that shape its behavior. </p><p>There is no established security infrastructure for agent skills yet. Tessl&#8217;s partnership with Snyk to bring scanning to every skill in the Tessl Registry addresses this gap. The unit of security in the agentic era is not the line of code. It is the agent and its capabilities.</p><h3><a href="https://support.claude.com/en/articles/15167101-get-started-with-claude-compliance-api-integrations">Claude Compliance API Now Connects to 28 Security and Compliance Platforms</a></h3><p>Anthropic&#8217;s Compliance API provides programmatic access to conversation content and activity event logs from Claude Enterprise, with 28 integrations spanning CrowdStrike, Purview, Okta, Wiz, Zscaler, and others. </p><p>Enterprise AI platforms are becoming first-class objects in security graphs. Governance and observability are the next gate for enterprise AI adoption, and Anthropic is treating them as first-class product requirements rather than afterthoughts.</p><h3><a href="https://www.nsa.gov/Cybersecurity/ZIG/">The NSA Launches Zero Trust Implementation Guidelines</a></h3><p>If you are implementing zero trust and want the most detailed government playbook available, this is it. The NSA&#8217;s interactive ZIG webpage defines 77 activities across two phases for transitioning to target-level zero-trust maturity, designed for DoD, DIB, and NSS organizations. </p><p>The interactive format with checklists and tasks moves zero trust from whiteboard strategy to executable work items. Combined with Anthropic&#8217;s Zero Trust for AI Agents framework, the zero-trust paradigm is extending from network architecture to agent architecture in real time.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://github.com/elementalsouls/Claude-BugHunter">A Claude Code Skill Bundle Brings 681 Vulnerability Patterns to Bug Hunters</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hG7g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hG7g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png 424w, https://substackcdn.com/image/fetch/$s_!hG7g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png 848w, https://substackcdn.com/image/fetch/$s_!hG7g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png 1272w, https://substackcdn.com/image/fetch/$s_!hG7g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hG7g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png" width="737" height="303" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:303,&quot;width&quot;:737,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74618,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!hG7g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png 424w, https://substackcdn.com/image/fetch/$s_!hG7g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png 848w, https://substackcdn.com/image/fetch/$s_!hG7g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png 1272w, https://substackcdn.com/image/fetch/$s_!hG7g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66f4de87-abfb-400a-a289-67455d5ccb2d_737x303.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Claude-BugHunter packages 51 skills across 24 vulnerability classes, drawing from 681 disclosed HackerOne report patterns. The capability of coding agents is increasingly defined by the skills they carry rather than the tools they connect to. Skills like these make agent security tooling more capable while raising the stakes for skill supply chain integrity.</p><h3><a href="https://www.linkedin.com/posts/patrickmgarrity_cybersecurity-infosecurity-riskmanagement-share-7466430252685164544-4i_p/">Patrick Garrity Maps the First Half of 2026 Vulnerability Data</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jr1O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jr1O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png 424w, https://substackcdn.com/image/fetch/$s_!Jr1O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png 848w, https://substackcdn.com/image/fetch/$s_!Jr1O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png 1272w, https://substackcdn.com/image/fetch/$s_!Jr1O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jr1O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png" width="603" height="334.595166163142" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20f1296d-880b-48ca-9cef-b284b9098087_993x551.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:551,&quot;width&quot;:993,&quot;resizeWidth&quot;:603,&quot;bytes&quot;:169750,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200483387?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Jr1O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png 424w, https://substackcdn.com/image/fetch/$s_!Jr1O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png 848w, https://substackcdn.com/image/fetch/$s_!Jr1O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png 1272w, https://substackcdn.com/image/fetch/$s_!Jr1O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20f1296d-880b-48ca-9cef-b284b9098087_993x551.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Garrity&#8217;s VulnCheck analysis provides the operational context that Gamblin&#8217;s macro numbers need. AI-assisted discovery is compressing time between publication and exploitation while volume outpaces every downstream system. </p><p>The organizations succeeding are the ones that have operationalized exploitability signals, reachability analysis, and business context into their prioritization workflows.</p><h3><a href="https://www.hapilabs.ai/blog/critical-entra-finding">The Entra Agent ID Administrator Role Could Escalate to Full Tenant Takeover</a></h3><p>The Agent ID Administrator role in Microsoft Entra ID could be exploited to take over arbitrary service principals beyond agent-related identities, reported in March and patched by April 9. The irony is hard to miss. </p><p>The agent identity infrastructure that is supposed to bring agents under governance was itself a privilege escalation vector. Every new identity primitive creates new attack surface.</p><h3><a href="https://www.linkedin.com/pulse/hackedin-thats-benchmark-jamieson-o-reilly-ryarc">HackedIn Benchmarks AI Coding Agents Against Real Penetration Testing Targets</a></h3><p>Jamieson O&#8217;Reilly&#8217;s work puts AI agents into the messier reality of actual penetration testing engagement scopes, adding practitioner context to the ExploitGym research. </p><p>The results confirm that AI offensive capability is real, measurable, and improving on a trajectory defenders need to take seriously. The offensive and defensive capability curves are both accelerating. The question is whether they accelerate symmetrically.</p><div><hr></div><h1>Final Thoughts</h1><p>Issue #100 arrives at a moment when the abstractions are falling away. Anthropic is giving Mythos access to EU sovereign agencies. Cisco condensed eight years of security research into eight weeks. The Nx Console compromise turned 18 minutes into a breach of GitHub&#8217;s internal repositories. Trusted publishing was exploited to distribute malware with valid provenance across 32 Red Hat packages.</p><p>The systems we built to manage security at human speed are failing at machine speed. But the responses are proportional to the challenge. Chainguard&#8217;s $50 million commitment. Easterly&#8217;s billion-dollar fund. Anthropic&#8217;s Zero Trust for AI Agents. Root Evidence&#8217;s data proving only 1.4% of CVEs are ever exploited, giving defenders a rational basis for prioritization.</p><p>You cannot patch your way to safety when AI finds vulnerabilities faster than humans can fix them. You can prioritize ruthlessly, build containment that limits blast radius, and invest in the open source infrastructure that everything else depends on.</p><p>One hundred issues in, and the work has never mattered more. </p><blockquote><p><strong>Stay resilient.</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Vulnpocalypse Won't Wait for Interagency Coordination]]></title><description><![CDATA[Why the June 2nd AI executive order's voluntary model collides with exploit timelines measured in hours]]></description><link>https://www.resilientcyber.io/p/the-vulnpocalypse-wont-wait-for-interagency</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-vulnpocalypse-wont-wait-for-interagency</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Wed, 03 Jun 2026 12:42:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TXhr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The White House signed an executive order on June 2nd titled &#8220;<strong><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">Promoting Advanced Artificial Intelligence Innovation and Security</a></strong>,&#8221; and the most revealing thing about it isn&#8217;t what it mandates, it&#8217;s what it doesn&#8217;t. </p><p>I spent some time yesterday heading back from the Gartner Security &amp; Risk Summit digging into it and wanted to walk through some key takeaways.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TXhr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png 424w, https://substackcdn.com/image/fetch/$s_!TXhr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png 848w, https://substackcdn.com/image/fetch/$s_!TXhr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png 1272w, https://substackcdn.com/image/fetch/$s_!TXhr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TXhr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png" width="1054" height="420" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:1054,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:92429,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200439766?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TXhr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png 424w, https://substackcdn.com/image/fetch/$s_!TXhr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png 848w, https://substackcdn.com/image/fetch/$s_!TXhr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png 1272w, https://substackcdn.com/image/fetch/$s_!TXhr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7f1ca6d-fe3a-4c80-87a3-8941769f6fe2_1054x420.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The order creates binding requirements for Federal agencies to accelerate AI-enabled cyber defense while keeping every meaningful obligation for the private sector entirely voluntary. </p><p>That split tells you everything about the administration&#8217;s theory of the case on AI governance, and it raises a question practitioners should be thinking hard about, such as whether voluntary frameworks can hold up against the fast moving threats AI is creating. </p><p>That said, as I have written about many times, despite cyber being a market failure, regulation can create its own problems, from perverse incentives, stifling innovation, economic ramifications and more. Safe to say, these aren&#8217;t easy challenges to solve regardless of which direction you choose.</p><p>I&#8217;ve been writing about this tension from several angles over the past year, from <strong><a href="https://www.resilientcyber.io/p/the-regulation-pendulum-and-ais-national">the regulation pendulum and AI&#8217;s national security reckoning</a></strong> to <strong><a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">the AI cyber capability curve</a></strong> that shows frontier model capabilities steepening with every release. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4UuB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4UuB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png 424w, https://substackcdn.com/image/fetch/$s_!4UuB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png 848w, https://substackcdn.com/image/fetch/$s_!4UuB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png 1272w, https://substackcdn.com/image/fetch/$s_!4UuB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4UuB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png" width="958" height="586" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa573501-274e-43a5-99f5-e8de51241e37_958x586.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:586,&quot;width&quot;:958,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:192294,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200439766?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4UuB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png 424w, https://substackcdn.com/image/fetch/$s_!4UuB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png 848w, https://substackcdn.com/image/fetch/$s_!4UuB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png 1272w, https://substackcdn.com/image/fetch/$s_!4UuB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa573501-274e-43a5-99f5-e8de51241e37_958x586.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This EO sits at the intersection of those threads.</p><p>It&#8217;s the administration&#8217;s attempt to reconcile a deregulatory posture with the reality that AI capabilities, offensive and defensive, are accelerating faster than the institutions meant to govern them.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>What the Order Actually Does</h2><p>The Federal-facing provisions are concrete and carry real deadlines. </p><ul><li><p>Within 30 days, CISA must release Binding Operational Directives to expedite cyber defense of civilian Federal systems and establish or expand programs that deliver AI-enabled defensive tools. </p></li><li><p>The Treasury Department, working with NSA and CISA, must stand up an AI cybersecurity clearinghouse to coordinate vulnerability scanning, discovery, validation, and patch distribution. </p></li><li><p>The Committee on National Security Systems and the Department of Defense must take immediate action to prioritize their own cyber defense postures. </p></li><li><p>OMB has 30 days to identify Federal grant programs with available funding that can be directed toward AI vulnerability detection. </p></li><li><p>OPM has 60 days to expand cybersecurity workforce hiring through the Tech Force pipeline, which had onboarded only 10 employees as of late May 2026.</p></li></ul><p>The classified side is notable too. </p><ul><li><p>Within 60 days, NSA must lead a benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold for designating a &#8220;covered frontier model.&#8221; </p></li></ul><p>That designation triggers the voluntary framework for the private sector, but the criteria for whaat counts as a frontier model remain classified, with NSA making the final call.</p><p>For industry, the operative word throughout the order is &#8220;<em><strong>voluntary</strong></em>.&#8221; </p><p>AI developers can choose to engage with the Federal Government to determine whether their models meet the frontier threshold. They can provide up to 30 days of early access before release to trusted partners, subject to confidentiality and intellectual property protections.  </p><p>On this note, I think 30 days is a little silly, given we know how long real-world remediation timelines are, for example the latest DBIR shows 43 days as the median to remediate KEV&#8217;s, let alone broader vulnerabilities, but if the early access period is too long, it could also impede the commercial ambitions of the frontier labs by delaying their model releases unreasonably.</p><p>They can participate in the cybersecurity clearinghouse as well, but none of it is required. The order includes explicit safeguard language stating that nothing:</p><blockquote><p><strong>&#8220;</strong><em><strong>shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models</strong></em><strong>.&#8221;</strong></p></blockquote><h2>The Deregulatory Logic</h2><p>This voluntary framing is consistent with the administration&#8217;s broader posture on AI. </p><p>As I wrote in <strong><a href="https://www.resilientcyber.io/p/the-regulation-pendulum-and-ais-national">The Regulation Pendulum and AI&#8217;s National Security Reckoning</a></strong>, the current administration has made a deliberate bet that innovation leadership, not regulatory guardrails, is the primary mechanism for maintaining U.S. advantage in AI. </p><p>The EO makes this explicit, declaring the policy of the United States is to: </p><blockquote><p>&#8220;<em><strong>continue to lead an America First cybersecurity effort that enhances both our national security and our global AI dominance</strong></em>.&#8221;</p></blockquote><p>The logic runs something like this when you unpack it. </p><p>Mandatory compliance frameworks slow down the companies building the most capable models. Slowing them down means ceding ground to China and other adversaries who face no equivalent regulatory friction. Therefore, keep the requirements on government, keep the private sector engagement collaborative, and trust that market incentives plus national security awareness will drive responsible behavior from the labs.</p><p>This is a reasonable framework if you believe the incentive structures between government and frontier labs are sufficiently aligned, and there&#8217;s a case to be made that they are, at least for the handful of companies building truly frontier systems. </p><p>Anthropic, OpenAI, and Google DeepMind already invest heavily in safety research and red-teaming. The 30-day early access provision isn&#8217;t asking them to do something fundamentally different from what they&#8217;re already doing internally. It&#8217;s asking them to share it with NSA and CISA before public release, giving government defenders preferential access to frontier cyber capabilities.</p><p>One big question mark is whether voluntary alignment holds as the ecosystem expands. Right now, frontier models come from a small number of well-capitalized labs with reputational incentives to cooperate. </p><p>But the open-weights ecosystem is growing fast, and the economics of AI are driving capability democratization. When smaller labs, open-source projects, and nation-state-backed efforts start producing models that cross the frontier threshold, voluntary frameworks have no mechanism to reach them. The classified benchmarking process can define what counts as a frontier model, but it can&#8217;t compel a non-cooperating developer to show up for review.</p><p>This is especially notable, as I have shown from teams such as AISLE and what they dub the &#8220;<strong><a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">Jagged Frontier</a></strong>&#8221;, as well as longtime industry leaders such as Niels Provos who both demonstrated in his blog &#8220;<strong><a href="https://www.provos.org/p/finding-zero-days-with-any-model/">Finding Zero-Days with Any Model</a></strong>&#8221; you can use smaller models, open source, or non-frontier models to find vulnerabilities effectively as well. I&#8217;ve also interviewed folks from Mother of All KEV&#8217;s (MOAK), who explained how they can autonomously develop exploits in minutes for nearly any CVE. You can catch both interviews below:</p><div id="youtube2-SHKYaV6srmA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;SHKYaV6srmA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/SHKYaV6srmA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div id="youtube2-J5xqeOSqs3s" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;J5xqeOSqs3s&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/J5xqeOSqs3s?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The DOJ AI Litigation Task Force adds another dimension to the deregulatory stance.</p><p>Within 30 days, DOJ must establish a task force specifically to challenge state AI laws that are inconsistent with the executive order&#8217;s federal AI policy. This is a preemption play, designed to prevent a patchwork of state-level AI regulations from creating compliance friction that slows innovation. </p><p>Whether you see this as streamlining or as removing necessary guardrails depends entirely on your assessment of whether the voluntary framework is sufficient on its own.</p><h2>The Threat the EO Is Trying to Meet</h2><p>The cybersecurity provisions of the order make the most sense when you read them against the backdrop of what AI has already done to the vulnerability and exploitation ecosystem. </p><p>The EO directs CISA to expand AI-enabled defensive tools and the Treasury clearinghouse (although many have argued why this resides with Treasury rather than say CISA or NSA) to coordinate vulnerability scanning and remediation at scale, which does seem very odd.</p><p>These aren&#8217;t abstract aspirations, and instead they&#8217;re responses to a threat dynamic that has been accelerating for months and I&#8217;ve been doing my best to document through interviews, videos and my own writing.</p><p>As I covered in &#8220;<strong><a href="https://youtu.be/q3n-hXHP88U?si=RVp-dBrV5Qls6wnI">Claude Mythos - Why It Matters (And Why It Doesn&#8217;t)</a>&#8221;</strong>, Anthropic&#8217;s frontier model achieved 73% success on expert-level CTF challenges and discovered thousands of high-severity vulnerabilities across major operating systems and browsers in its first month of operation. </p><p>In <strong><a href="https://www.resilientcyber.io/p/the-receipts-are-in">The Receipts Are In</a></strong>, I detailed how Anthropic&#8217;s partners using Claude for security discovered over 10,000 high-and-critical-severity vulnerabilities in a single month, with bug discovery rates up by more than 10x. </p><div id="youtube2-5DPQ3m3e8OE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5DPQ3m3e8OE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5DPQ3m3e8OE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The <strong><a href="https://www.resilientcyber.io/p/the-dbirs-exploitation-era">2026 DBIR confirmed</a></strong> that vulnerability exploitation is now the leading initial access vector, with exploitation timelines compressing while remediation capacity stays flat.</p><div id="youtube2-hOUZHgVq1uY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;hOUZHgVq1uY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/hOUZHgVq1uY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>This is the <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">Vulnpocalypse</a></strong> playing out in real time. </p><p>AI has industrialized vulnerability discovery and is compressing the window between discovery and weaponization from months to hours, at marginal costs measured in dollars. </p><p>The structural asymmetry between the rate at which vulnerabilities are found and the capacity to fix them is widening, not narrowing. And as I explored in <strong><a href="https://www.resilientcyber.io/p/the-attack-surface-exponential">The Attack Surface Exponential</a></strong>, GitHub commits are accelerating toward 14 billion in 2026 while AI simultaneously reduces the cost of finding and exploiting flaws in all that new code. </p><blockquote><p><strong>More code, worse code, cheaper exploitation.</strong></p></blockquote><p>The EO&#8217;s cybersecurity clearinghouse and AI-enabled defensive programs are direct responses to this dynamic. </p><p>The 30-day early access provision for frontier models, when read through this lens, isn&#8217;t primarily about regulation. It&#8217;s about giving government defenders a temporal advantage over adversaries, a head start on understanding what these models can do offensively before the capabilities become widely available. </p><p>That framing is sound but the challenge of course is execution. Remediation capacity and timelines have already lagged vulnerability discovery and disclosure and AI has collapsed exploitation timelines while not yet doing the same for remediation, which just exacerbates the gap even worse.</p><h2>The Execution Gap</h2><p>The ambition of the EO&#8217;s cybersecurity provisions runs into the same institutional constraints that have limited Federal cybersecurity capacity for years. </p><p>CISA is being asked to release Binding Operational Directives within 30 days to modernize civilian Federal cyber defense with AI-enabled tools. But CISA&#8217;s budget and staffing have been under pressure, and the agency is being asked to do this for Federal agencies while simultaneously making the same capabilities available to state and local authorities, rural hospitals, community banks, and local utilities. That&#8217;s an enormous scope expansion on an aggressive timeline.</p><p>The cybersecurity clearinghouse faces a coordination challenge that anyone who has worked in Federal interagency processes will recognize immediately. Getting Treasury, NSA, CISA, the National Cyber Director, and the private sector to coordinate and deconflict vulnerability scanning in 30 days is aspirational at best, and that&#8217;s coming from someone who has spent the majority of their career in the DoD and in and around Federal agencies </p><p>These agencies operate under different authorities, different classification regimes, and different institutional cultures. The intent is right, but standing up a functional coordination mechanism across those boundaries in a month would be historically unprecedented.</p><p>The workforce provisions reveal the gap most starkly. </p><p>The OPM directive to expand Tech Force cybersecurity hiring pathways within 60 days sounds promising until you learn the program had onboarded 10 employees as of late May. Scaling from 10 to a meaningful cybersecurity workforce capable of operating AI-enabled defensive tools across the Federal enterprise is a multi-year effort, not a 60-day sprint. This is especially acute given the Federal workforce, including in IT, just underwent massive changes through efforts such as DOGE as well.</p><p>The <strong><a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">cyber capability curve</a></strong> is steepening with every model release, and the government&#8217;s human capital pipeline is still operating at a pace that reflects a pre-AI threat tempo.</p><h2>The Agent Question</h2><p>The order&#8217;s DOJ provisions on AI agents are worth noting even if they aren&#8217;t the centerpiece. The Attorney General is directed to prioritize enforcement of existing criminal statutes, including identity fraud, computer fraud, and wire fraud, against anyone who uses AI agents to unlawfully access data or computer systems. No new criminal authority is created and instead the order sharpens enforcement of laws already on the books.</p><p>This is a pragmatic choice because creating new legal frameworks for AI agent liability would take years of congressional action and wouldn&#8217;t survive the administration&#8217;s own anti-regulatory framing. </p><p>Directing DOJ to enforce existing statutes against AI-enabled crime is something the executive branch can do immediately, and it sends a signal to developers and deployers that agent misuse will be prosecuted under current law. </p><p>Whether existing fraud and computer crime statutes are adequate for the novel challenges agents create, particularly around autonomy, delegation, and attribution, is a question this order punts to future policymakers.</p><p>What will be interesting here is seeing how they determine which attacks involved LLMs and Agents and how, and it will likely require close collaboration with the frontier labs, model providers and CSPs.</p><h2>What This Means for Practitioners</h2><p>For security leaders in the private sector, the practical impact of this EO is limited in the near term. Nothing compels industry participation, especially if you aren&#8217;t a frontier lab. </p><p>The voluntary framework creates an option for frontier labs to engage with government review, but for most enterprises, the meaningful signal is directional rather than operational. The administration is betting on AI as a force multiplier for cyber defense and expects the private sector to make the same bet on its own terms.</p><p>As I mentioned above, the real question is whether the voluntary model can keep pace with the threat dynamics it&#8217;s trying to address. The Vulnpocalypse isn&#8217;t waiting for interagency coordination to mature. </p><p>Frontier AI models and even smaller and open source models with effective harness engineering are compressing exploit timelines now, the attack surface is expanding now, and adversaries with access to the same models aren&#8217;t participating in voluntary review frameworks. </p><blockquote><p><strong>The EO acknowledges the urgency through its aggressive 30-day and 60-day timelines, but institutional capacity doesn&#8217;t bend to executive order deadlines the way policy language does.</strong></p></blockquote><p>What practitioners should be watching is whether the cybersecurity clearinghouse becomes a real coordination mechanism or another interagency structure that exists on paper while the actual work happens bilaterally between individual agencies and labs. </p><p>The early access provision for frontier models is genuinely novel and could give defenders an informational edge if implemented well. That said, the gap between the EO&#8217;s ambition and the government&#8217;s current capacity to absorb and operationalize AI-enabled defensive capabilities is the story underneath the story. </p><p>The order gets the direction right, however whether the institutions can execute at the speed the threat demands is the question that will determine whether this EO matters or whether it becomes another aspirational document that reads better than it performed.</p><p>Unfortunately, having spent most of my career in the public sector, I fear it will trend towards the former more so than the latter, but I do hope I&#8217;m wrong.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Data Layer Is the New Battleground for the Agentic SOC]]></title><description><![CDATA[The Data Layer Is the New Battleground for the Agentic SOC]]></description><link>https://www.resilientcyber.io/p/the-data-layer-is-the-new-battleground</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-data-layer-is-the-new-battleground</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 02 Jun 2026 12:03:51 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7396b364-ff8b-4743-9671-32516eb8781e_2560x1440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3>The Data Layer Is the New Battleground for the Agentic SOC</h3><p>The per-gigabyte pricing model that defined the SIEM for the past fifteen years was never really a storage decision, it was a coverage decision. </p><p>Security teams learned to ration data because ingestion costs forced them to, and the consequence of that rationing was entirely predictable. Logs got sampled, retention windows shrank to days or weeks, and high-volume sources like DNS, VPC flow, and netflow were exiled to S3 buckets where they sat effectively dead, queryable in theory but inaccessible in any timeframe that matters for detection or investigation.</p><blockquote><p><strong>You cannot detect what you never ingested, and you cannot investigate what you could not afford to keep. </strong></p></blockquote><p>That tension has always sat at the center of the SIEM&#8217;s economic model, and for years the industry treated it as a budgeting problem rather than a security architecture problem. It also made organizations implicitly accept risks due to cost considerations and constraints. </p><p>The conversation has shifted in 2026 because two forces are converging at once. The SIEM monolith is unbundling into best-of-breed layers, and the arrival of agentic AI in the SOC is making complete, queryable security data a hard operational requirement rather than a nice-to-have.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 30,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Unbundling</h2><p>The traditional SIEM bundled five functions into a single platform, handling ingest, storage, detection, investigation, and response. </p><p>That monolithic design made sense when log volumes were manageable and the primary consumer of the data was a human analyst running manual queries. It doesn&#8217;t hold up when organizations generate terabytes of security telemetry daily and the fastest-growing consumer of that data is an AI agent that needs sub-second query response across months or years of logs.</p><p>What&#8217;s happening now is the same decomposition that hit the data analytics world roughly a decade ago with the rise of Snowflake and Databricks, where storage decoupled from compute and the &#8220;lakehouse&#8221; architecture became the dominant pattern. Security is arriving at this same architectural inflection late, which itself is telling. </p><p>Cybersecurity has a consistent pattern of being a laggard culture when it comes to adopting architectural shifts that adjacent disciplines validated years earlier, a point I&#8217;ve made at the <strong><a href="https://youtu.be/ts_MFz9NAmQ?si=Z-1hwwsb765lxWe2">SANS AI Summit</a></strong> and one that keeps proving itself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hFS-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hFS-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png 424w, https://substackcdn.com/image/fetch/$s_!hFS-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png 848w, https://substackcdn.com/image/fetch/$s_!hFS-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png 1272w, https://substackcdn.com/image/fetch/$s_!hFS-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hFS-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png" width="630" height="349.17452830188677" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:848,&quot;resizeWidth&quot;:630,&quot;bytes&quot;:442756,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198868029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hFS-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png 424w, https://substackcdn.com/image/fetch/$s_!hFS-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png 848w, https://substackcdn.com/image/fetch/$s_!hFS-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png 1272w, https://substackcdn.com/image/fetch/$s_!hFS-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e16f783-cd49-4161-bb39-d2432eb7df52_848x470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The unbundled security stack has distinct layers emerging. A data lake layer handles storage and indexing. A detection-as-code layer runs rules against that data. An automation and orchestration layer, occupied by platforms like Torq and Tines, handles response workflows, and increasingly, an agentic layer sits on top, with AI agents consuming all three layers below through protocols like MCP. </p><p>The through line across all of it is the same principle, which is decoupling storage from compute so that the economics of keeping data doesn&#8217;t dictate the economics of using it and organizations don&#8217;t have to implicitly accept as much risk due to cost constraints.</p><h2>Why Now</h2><p>Three forces are driving this shift from theory to operational reality.</p><p>The first of those forces is volume. Cloud-native architectures, container orchestration, API-driven microservices, and distributed workloads generate orders of magnitude more telemetry than the on-prem environments the SIEM was originally designed to monitor. </p><p>Organizations running modern cloud infrastructure routinely produce terabytes of security-relevant logs per day, and the per-GB pricing model of legacy SIEMs makes ingesting all of it financially impossible. The rational response, and the one most security teams have adopted, is to drop, sample, or shorten retention on the highest-volume sources. The result is a detection gap that&#8217;s driven by economics, not by technology.</p><p>The second is the lakehouse pattern itself. The data analytics industry proved years ago that separating storage from compute allows organizations to keep everything and query it on demand without paying for always-on compute against cold data. Object storage in S3 or GCS costs a fraction of what SIEM-managed storage costs, and serverless compute can be invoked at query time and dismissed when the job finishes. </p><p>The architectural pattern is proven and the cost savings are real, but security tooling has been slow to adopt it because the query patterns are different. Security investigations require full-text search across semi-structured and unstructured data, not the SQL-based reporting that analytics platforms were optimized for.</p><p>The third, and the one that changes the urgency calculus, is the agentic inflection. As I wrote in <em>&#8220;Beyond the Hype of AI Agents in the SOC&#8221;</em>, the conversation around AI in security operations has moved from copilots assisting analysts to autonomous agents conducting investigations, triaging alerts, and executing response workflows with minimal human oversight. </p><p>AI agents are data-hungry by nature. They don&#8217;t sample, and they don&#8217;t accept a 15-day retention window. They need complete, fast, queryable access to the full breadth of security telemetry, and they need it in sub-second response times because an agent iterating through a triage workflow might run dozens of queries in a single investigation. The old SIEM only ever exposed the fraction of data that fit the budget, and that fraction is insufficient for the agentic model.</p><h2>What Scanner Is</h2><p>To ground this in a concrete example, Resilient Cyber&#8217;s partner <strong><a href="https://scanner.dev/?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive">Scanner.dev</a></strong> is a security data lake built from the ground up to solve the storage-compute coupling problem. </p><p>Founded by <strong><a href="https://www.linkedin.com/in/cliftoncrosland/">Cliff Crosland</a></strong> and <strong><a href="https://www.linkedin.com/in/swwu/">Steven Wu</a></strong> and backed by a <strong><a href="https://scanner.dev/blog/scanner-raises-series-a-led-by-sequoia-capital">$22 million Series A led by Sequoia Capital</a></strong> with participation from CRV and Mantis VC, <strong><a href="https://scanner.dev/?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive">Scanner&#8217;s</a></strong> architecture indexes logs directly in the customer&#8217;s own S3 or GCS buckets using inverted index files that compress to roughly 15% the size of the original dataset. </p><p>At query time, Rust-based AWS Lambda functions traverse those index files at speeds up to 1TB per second, scanning only the data regions relevant to the query rather than brute-forcing through the entire dataset.</p><p>The practical difference is stark, and it&#8217;s easy to see the potential for practitioners. In a demo I saw with Cliff, a query across 1.15 petabytes of log data returned results in seconds, a job he estimated would take Amazon Athena roughly 12 hours.</p><p><strong><a href="https://scanner.dev/customers/ramp">Ramp</a></strong>, the financial operations platform, moved from Athena queries that took 30 minutes to <strong><a href="https://scanner.dev/?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive">Scanner</a></strong> queries that run in under two minutes, while simultaneously extending their searchable data retention from 15 days to a full year. <strong><a href="https://scanner.dev/customers/lemonade-accelerates-security-operations-high-speed-security-data-lake">Lemonade</a></strong> went from 7-30 days of accessible logs, with expensive rehydration fees for anything older, to months of instantly queryable history.</p><p>From my discussion with Cliff, the schema-less design is deliberate. Scanner doesn&#8217;t require the ETL work that SQL-based analytics tools demand. It indexes messy, semi-structured, and unstructured logs without forcing them into rigid table schemas, which eliminates the data engineering overhead that has historically made security data lake projects stall before they deliver value.</p><p>On the detection side, <strong><a href="https://scanner.dev/?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive">Scanner</a></strong> provides over 400 out-of-the-box detection rules managed through GitHub, following the detection-as-code pattern that treats security logic the same way engineering teams treat application code. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Da9D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Da9D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png 424w, https://substackcdn.com/image/fetch/$s_!Da9D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png 848w, https://substackcdn.com/image/fetch/$s_!Da9D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png 1272w, https://substackcdn.com/image/fetch/$s_!Da9D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Da9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png" width="1400" height="700" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c5754336-8949-47d1-879c-125b5b382478_1400x700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:700,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:426361,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198868029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Da9D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png 424w, https://substackcdn.com/image/fetch/$s_!Da9D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png 848w, https://substackcdn.com/image/fetch/$s_!Da9D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png 1272w, https://substackcdn.com/image/fetch/$s_!Da9D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc5754336-8949-47d1-879c-125b5b382478_1400x700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Rules are pre-run and cached at indexing time so that detection logic doesn&#8217;t degrade search performance. The platform includes <strong><a href="https://scanner.dev/collect-enrich">Scanner Collect</a></strong> for data source ingestion, RBAC for access control, and offers both a fully managed deployment and a bring-your-own-cloud model where compute runs entirely within the customer&#8217;s AWS account.</p><div class="pullquote"><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ERbp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ERbp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png 424w, https://substackcdn.com/image/fetch/$s_!ERbp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png 848w, https://substackcdn.com/image/fetch/$s_!ERbp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png 1272w, https://substackcdn.com/image/fetch/$s_!ERbp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ERbp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png" width="1400" height="700" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:700,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:413738,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198868029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ERbp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png 424w, https://substackcdn.com/image/fetch/$s_!ERbp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png 848w, https://substackcdn.com/image/fetch/$s_!ERbp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png 1272w, https://substackcdn.com/image/fetch/$s_!ERbp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbebe4bc0-79c1-4890-9b62-787ed818ec4f_1400x700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></div><p>The pricing reflects the architectural difference as well. Scanner charges approximately $0.10 per million log events for detection rules, compared to roughly $5 per million at competitors offering similar platforms. For an organization analyzing a terabyte of logs daily, that translates to roughly $40,000 per year versus $1.8 million. The typical deployment runs $50,000-$100,000 for a 250TB dataset, which is 80-90% less than standard SIEM pricing for equivalent data volumes.</p><p>The data-stays-in-your-cloud posture is a deliberate trust and data gravity play and one I discussed specifically with Cliff during the demo. With the BYOC model, the customer retains full control over their data at all times, and switching away doesn&#8217;t require migrating petabytes of logs out of a vendor&#8217;s infrastructure. This was a specific design choice that Cliff pointed out in our discussion, and it gives organizations more control of their own data while minimizing concerns over vendor lock-in.</p><h2>The Agentic Bet</h2><p>This is <strong><a href="https://scanner.dev/?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive">Scanner&#8217;s</a></strong> most ambitious and testable claim. Within weeks of releasing their MCP server, nearly one-third of customers were already using it in production, and Cliff told me that agents now account for 80% of weekly queries on the platform. The heaviest users of the security data lake aren&#8217;t human threat hunters. They&#8217;re AI agents conducting investigations around the clock.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PHfU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PHfU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!PHfU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!PHfU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!PHfU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PHfU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:505256,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198868029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PHfU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!PHfU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!PHfU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!PHfU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F934dbfab-bc98-4c44-8e22-a0552b8b76fa_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://www.notion.com/blog/meet-scruff-securitys-new-ai-teammate">Notion&#8217;s security team built Scruff</a></strong>, an AI agent that uses <strong><a href="https://scanner.dev/?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive">Scanner</a></strong> as its primary data layer alongside integrations with Wiz and CrowdStrike Falcon. Scruff autonomously triages and investigates security alerts, correlates findings across logs, user activity, and system events, and saves the team over six hours per week. It handles the workload of multiple on-call analysts and scales automatically as the company grows, the kind of force multiplication that makes the agentic SOC argument concrete rather than theoretical.</p><p>Sequoia&#8217;s Bogomil Balkansky <strong><a href="https://www.securityweek.com/scanner-raises-22-million-for-ai-powered-threat-hunting/">framed Scanner as</a></strong> &#8220;<em>the only technology on the market today that manages security data at AI scale</em>&#8221; when leading the Series A. That claim rests on a specific architectural argument. Traditional SIEMs and even newer data lake tools like Athena and Presto weren&#8217;t built for the iterative, exploratory query patterns that AI agents use. </p><p>An agent investigating an alert might run 20-30 queries in rapid succession, each one refining a hypothesis based on the previous result. If each query takes 30 minutes, the agent is useless. If each query returns in seconds, the agent can conduct a thorough investigation faster than any human analyst.</p><p>This connects to the broader argument I&#8217;ve been making about where the real value sits in the agentic SOC. As I explored in <em>&#8220;AI SOC Got Commoditized, Now What?&#8221;</em>, the agent itself is rapidly becoming a commodity. </p><p>Every major security vendor is shipping some version of an AI-powered SOC agent, and the differentiation between them is narrowing. If the agent layer commoditizes, the durable value shifts to the infrastructure the agent depends on, and that infrastructure is the data layer. The agent is only as good as the data it can access, the speed at which it can query, and the completeness of the telemetry underneath it.</p><h2>Where the Agentic SOC Goes from Here</h2><p>The broader question isn&#8217;t about any single vendor&#8217;s roadmap. It&#8217;s about whether the industry recognizes that the data layer has become the constraining factor in how far the agentic SOC can go.</p><p>The early signals are starting to suggest it has. Security data lakes are increasingly serving as the infrastructure layer not just for in-house security teams but for AI-focused MDR providers building their own agent-driven products on top. I&#8217;ve previously worked with teams building security data lakes in large Federal enterprise environments and it is a complex endeavor, often requiring expertise beyond cyber into data science and other domains as well.</p><p>The pattern of deploying a data lake as a companion alongside an existing SIEM, offloading the highest-volume sources that the budget can&#8217;t justify ingesting at SIEM pricing, is already well-established. The more interesting question is what happens when organizations start running the majority of their detections and investigations on the data lake layer rather than the SIEM, and the SIEM&#8217;s role atrophies from platform to legacy integration point. That trajectory, from cost optimization companion to primary detection and investigation surface, will define the category over the next few years.</p><p>Detection-as-code managed through Git repositories represents a parallel bet on the continued convergence of security operations and software engineering practices and mimics what we&#8217;re seeing in other categories of cyber as well, such as the rise of GRC Engineering. </p><p>If SOC teams adopt GitOps workflows for managing their detection logic, the operational model for building and maintaining detections starts to look more like software development than it does like traditional rule management. As I discussed with Vineeth Sai Narajala in &#8220;<em>MCP, Potential and Pitfalls&#8221;</em>, MCP is growing at an extraordinary rate as the standard interface between AI agents and the tools they operate, and that growth accelerates the shift toward agent-consumable infrastructure across the SOC. </p><p>The organizations that expose their security telemetry through agent-friendly interfaces will be the ones whose agents can actually perform, and the organizations that keep their data locked behind slow, expensive, human-oriented query tools will be the ones wondering why their AI investments aren&#8217;t delivering results.</p><p>Data residency and control are also becoming a structural differentiator rather than a niche concern. As regulatory pressure around data sovereignty and third-party risk continues to build, keeping security telemetry in the customer&#8217;s own cloud environment rather than shipping it to a vendor&#8217;s SaaS platform becomes a genuine architectural advantage for organizations in regulated industries. </p><p>The bring-your-own-cloud (BYOC) model addresses the trust problem that has made enterprise security teams hesitant to move their most sensitive telemetry to external platforms, and it eliminates the vendor lock-in that makes switching costs a strategic liability, something I called out with Cliff as a common concern I hear among CISO&#8217;s.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://scanner.dev/demo?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive-demo" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LfLB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!LfLB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!LfLB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!LfLB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LfLB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png" width="453" height="453" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:453,&quot;bytes&quot;:1053693,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://scanner.dev/demo?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive-demo&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198868029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LfLB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!LfLB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!LfLB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!LfLB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F997fff4a-f640-48c0-a688-0111d9ca84ac_1080x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://scanner.dev/demo?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive-demo&quot;,&quot;text&quot;:&quot;-> Check out a demo of Scanner! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://scanner.dev/demo?utm_source=resilient_cyber&amp;utm_medium=newsletter&amp;utm_campaign=202606-blog-product-deep-dive-demo"><span>-&gt; Check out a demo of Scanner! &lt;-</span></a></p><div><hr></div><h2>The Architecture Decision in Front of Every CISO</h2><p>The question facing security leaders in 2026 isn&#8217;t which SIEM to buy. It&#8217;s whether to keep treating security data as something to ration or as infrastructure to query freely. The SIEM&#8217;s per-GB pricing model created a world where security teams made coverage decisions based on budget constraints rather than risk analysis, and the result was exactly the blind spots that attackers learned to live in.</p><p>The security data lake doesn&#8217;t solve every problem in the SOC. Detection engineering still requires skilled practitioners. Incident response still demands human judgment for high-stakes decisions, and the agentic SOC, for all its promise, is still early enough that the failure modes aren&#8217;t fully understood, something I explored in &#8220;<em>Orchestrating Agentic AI Securely&#8221;</em>. </p><p>But the data layer underneath all of those functions is no longer optional, and the economics of the old model are no longer defensible. When the most prolific users of your security data are AI agents that need sub-second access to complete telemetry, the cost of rationing isn&#8217;t just a budget line item. It&#8217;s a detection gap, an investigation bottleneck, and increasingly, the ceiling on what your agentic SOC can actually accomplish. </p><p>The organizations that figure out the data layer first will have a structural advantage in the agentic era, and the ones that keep rationing will keep wondering why their agents can&#8217;t find what they&#8217;re looking for, and potentially are missing critical risks to their organizations. </p><p>Making the right choices here will help define the true transformation that agents can deliver for SecOps. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Zero Trust Was Built for a Different Kind of Trust Problem]]></title><description><![CDATA[A look at Anthropic's Zero Trust for AI Agents Framework]]></description><link>https://www.resilientcyber.io/p/zero-trust-was-built-for-a-different</link><guid isPermaLink="false">https://www.resilientcyber.io/p/zero-trust-was-built-for-a-different</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 01 Jun 2026 14:37:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oUte!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>While enterprises have spent the better part of a decade trying to implement Zero Trust architectures for human users and traditional workloads, Anthropic just published a <strong><a href="https://claude.com/blog/zero-trust-for-ai-agents">framework</a></strong> that reveals how much harder the problem gets when the entities you&#8217;re trying to govern aren&#8217;t human at all. </p><p>AI agents, autonomous systems that can reason, plan, and take actions across enterprise environments, don&#8217;t just add another endpoint to secure. They fundamentally change what &#8220;<em>never trust, always verify</em>&#8221; means in practice.</p><p>I&#8217;ve written extensively about Zero Trust over the years, from <strong><a href="https://resilientcyber.substack.com/p/zero-trust-isnt-dead-but-its-implementation">the DoD&#8217;s Zero Trust Strategy</a></strong> and the implementation challenges it surfaced to <strong><a href="https://resilientcyber.substack.com/p/a-zero-trust-centric-approach-to">a Zero Trust-centric approach to cyber resilience</a></strong> that positioned ZT as a foundational design philosophy rather than a product category. </p><p>The core principles haven&#8217;t changed. Verify explicitly, enforce least privilege, and assume breach, but what those principles demand when applied to non-deterministic AI systems looks nothing like what they demand for a human sitting at a laptop authenticating through Okta.</p><p>Let&#8217;s take a look at Anthropic&#8217;s ZT for Agents framework and see where it leads.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://claude.com/blog/zero-trust-for-ai-agents" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oUte!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png 424w, https://substackcdn.com/image/fetch/$s_!oUte!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png 848w, https://substackcdn.com/image/fetch/$s_!oUte!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png 1272w, https://substackcdn.com/image/fetch/$s_!oUte!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oUte!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png" width="537" height="432.68536251709986" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:589,&quot;width&quot;:731,&quot;resizeWidth&quot;:537,&quot;bytes&quot;:127160,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://claude.com/blog/zero-trust-for-ai-agents&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200125051?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oUte!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png 424w, https://substackcdn.com/image/fetch/$s_!oUte!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png 848w, https://substackcdn.com/image/fetch/$s_!oUte!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png 1272w, https://substackcdn.com/image/fetch/$s_!oUte!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F829418d8-6740-4b6d-ac33-4f4a6dba05ce_731x589.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Unfinished Business of Zero Trust</h2><p>Before we talk about what agents break, it&#8217;s worth being honest about what we still haven&#8217;t finished building for humans. I spent a lot of my career over the past decades in the U.S. public sector, in the military, and supporting U.S. Federal agencies, including in their pursuits of implementing Zero Trust. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HI6j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HI6j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png 424w, https://substackcdn.com/image/fetch/$s_!HI6j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png 848w, https://substackcdn.com/image/fetch/$s_!HI6j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png 1272w, https://substackcdn.com/image/fetch/$s_!HI6j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HI6j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png" width="599" height="458.9431968295905" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:580,&quot;width&quot;:757,&quot;resizeWidth&quot;:599,&quot;bytes&quot;:146072,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200125051?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HI6j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png 424w, https://substackcdn.com/image/fetch/$s_!HI6j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png 848w, https://substackcdn.com/image/fetch/$s_!HI6j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png 1272w, https://substackcdn.com/image/fetch/$s_!HI6j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfa79e23-45e9-449f-8076-46c6e60edee1_757x580.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <strong><a href="https://www.cisa.gov/zero-trust-maturity-model">CISA Zero Trust Maturity Model</a></strong> lays out four maturity stages across five pillars, and the blunt reality is that years since its publication, most organizations are still somewhere between Traditional and Initial. The <strong><a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3690501/nsa-releases-zero-trust-maturity-guidance-for-the-network-and-environment-pillar/">NSA&#8217;s Zero Trust guidance</a></strong> for the network and environment pillars focuses on data flow mapping, macro and micro segmentation, and software-defined networking with granular access controls. </p><blockquote><p><strong>These are table-stakes capabilities that many large enterprises still struggle to operationalize at scale despite most practitioners agreeing they are fundamental.</strong></p></blockquote><p>The reasons aren&#8217;t mysterious either and I&#8217;ve lived the struggles first hand. Large organizations carry decades of technical debt, legacy systems that can&#8217;t support modern identity federation, flat networks that were never designed for micro-segmentation, and change management cycles that move at a pace fundamentally mismatched to the speed at which threats evolve. Couple that with internal politics, fiefdoms, competing priorities and more and it is a recipe for gridlock and struggles.</p><p>I spent years in Federal environments watching agencies struggle with exactly these challenges, and the private sector isn&#8217;t meaningfully ahead. A Fortune 500 with 200 business units, a decade of M&amp;A integration debt, and a patchwork of identity providers faces structural barriers every bit as daunting as a large Federal agency operating under executive mandates. </p><p>Implementing Zero Trust at enterprise scale isn&#8217;t a technology problem. It&#8217;s a structural and institutional challenge, shaped by budget constraints, workforce gaps, and competing priorities that pull attention in twelve directions at once.</p><p>This is the context into which AI agents are arriving. Not into mature, well-segmented, identity-aware environments with continuous monitoring and adaptive access controls, but into networks that are still trying to implement the fundamentals for human users, let alone autonomous agents powered by LLMs.</p><h2>What Agents Actually Break</h2><p>Anthropic&#8217;s framework starts from a refreshingly honest premise that most vendors building agentic capabilities won&#8217;t say out loud. </p><p>LLMs are, in Anthropic&#8217;s own words, &#8220;inherently somewhat insecure.&#8221; This isn&#8217;t a temporary limitation waiting for the next model release to fix. It&#8217;s a structural property of how these systems work. LLMs operate on natural language inputs that can be manipulated, they generate outputs probabilistically rather than deterministically, and they can be influenced by adversarial content embedded in the data they process. Anthropic calls this out in their section on threats, including examples such as prompt injection, instruction manipulation, tool and resource misuse and IAM abuse.</p><p>Traditional Zero Trust assumes the entity being governed, whether a user or a workload, will behave predictably within defined parameters. </p><p>A human user authenticated through MFA with a valid session token will interact with systems through well-defined interfaces. </p><p>A containerized microservice will make API calls according to its code. The trust decisions are binary and the behavior is bounded. </p><p>Agents break this assumption because their behavior isn&#8217;t fully predictable even to their developers, they are non-deterministic by their very nature, it isn&#8217;t a flaw. </p><p>An agent given access to a tool might use that tool in ways its designers didn&#8217;t anticipate, not because it&#8217;s been compromised but because that&#8217;s how generative models operate.</p><p>Anthropic identifies five agent-specific threat categories that don&#8217;t have clean analogs in traditional Zero Trust. </p><ul><li><p>Prompt injection allows adversaries to manipulate agent behavior through crafted inputs embedded in data the agent processes. </p></li><li><p>Tool poisoning targets the interfaces between agents and the systems they interact with. </p></li><li><p>Identity and privilege abuse exploits the fact that agents often operate with broader access than any single human task would require. </p></li><li><p>Memory and context poisoning corrupts the information an agent uses to make decisions, </p></li><li><p>Supply chain attacks target the growing ecosystem of third-party tools, plugins, and model providers that agents depend on.</p></li></ul><p>The common thread across all five is that the attack surface isn&#8217;t just the network perimeter or the authentication layer, it&#8217;s the reasoning process itself. You can&#8217;t firewall an agent&#8217;s chain of thought, although many are proposing various methods to try and govern what goes into an agents context window, what actions agents are allowed to take etc.</p><h2>The Unnamed Vulnpocalypse</h2><p>There&#8217;s a thread in Anthropic&#8217;s framework it opens with that anyone following my previous writing will recognize immediately, even though Anthropic doesn&#8217;t use the term. </p><p>They state plainly that:</p><blockquote><p><strong>&#8220;Frontier AI models are compressing the timeline between vulnerability and exploit from months to hours, at a marginal cost measured in dollars.&#8221;</strong> </p></blockquote><p>That&#8217;s the <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">Vulnpocalypse</a></strong> by another name, something I have <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">written about extensively</a></strong>. The industrialization of vulnerability discovery and autonomous exploitation, where the economics of finding and weaponizing flaws shift decisively in the attacker&#8217;s favor.</p><p>Anthropic&#8217;s framework treats this as a first-order design constraint rather than a background risk. When exploit windows collapse from months to hours, the traditional patch-and-pray cycle doesn&#8217;t just underperform, it becomes irrelevant and delusional as a single control. </p><p>Their emphasis on &#8220;dwell time&#8221; and &#8220;coverage&#8221; as the two metrics with the greatest leverage reflects this reality. If an AI agent can autonomously discover a vulnerability, generate a working exploit, and deploy it at machine speed, defenders need detection and containment that operates on the same timescale. Manual incident response procedures that route through a SOC analyst&#8217;s queue aren&#8217;t going to cut it.</p><p>This is why Anthropic pushes hard on automated response capabilities, from session termination and credential revocation at the Enterprise tier to full SOAR-integrated orchestrated response at the Advanced tier. </p><p>They frame it with a clear principle worth repeating. Automate the bookkeeping around incidents, not the decisions. Models should take notes, capture artifacts, pursue parallel investigation tracks, and draft the postmortem. Humans should make the containment calls, the disclosure calls, and the customer-comms calls. </p><p>That division of labor makes sense as a design principle, but it also reveals just how much infrastructure most organizations are missing. You can&#8217;t automate response to agent-speed threats if your detection pipeline still depends on a human triaging alerts in Splunk. Some of these challenges I have discussed with practitioners such as <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Filip Stojkovski&quot;,&quot;id&quot;:40696750,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e5161d9-e2fd-457f-96f2-2545324d34ca_1840x1840.jpeg&quot;,&quot;uuid&quot;:&quot;b4318d20-b0bc-4332-b971-323aea877c29&quot;}" data-component-name="MentionToDOM"></span> in an episode of Resilient Cyber titled &#8220;<strong><a href="https://www.resilientcyber.io/p/ai-soc-got-commoditized-now-what">AI SOC Got Commoditized - Now What</a></strong>?&#8221;</p><div id="youtube2-HiVYde9FMUY" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;HiVYde9FMUY&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/HiVYde9FMUY?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The convergence matters because the same AI capabilities that make agents valuable for defenders are the capabilities that make autonomous exploitation possible. Any organization deploying agents without accounting for the fact that their adversaries are deploying similar capabilities is operating with a structural blind spot.</p><h2>Least Agency, Not Just Least Privilege</h2><p>One of the more important conceptual contributions in Anthropic&#8217;s framework is the distinction between least privilege and what they call &#8220;<strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">least agency</a></strong>&#8221;, which has been championed by the OWASP Agentic Security Initiative (ASI) where I serve as a Distinguished member.</p><p>Least privilege, the idea that any entity should have only the minimum access rights needed to perform its function, is a foundational Zero Trust principle that translates directly to agents. An agent that only needs to read log files shouldn&#8217;t have write access to production databases, that part is straightforward.</p><blockquote><p><strong>Least agency goes further, because i argues that agents should be granted the minimum level of autonomy needed for a given task, not just the minimum access.</strong></p></blockquote><p>This means preferring structured, constrained tool interfaces over open-ended capabilities. If an agent needs to query a database, give it a parameterized query interface rather than raw SQL access. If it needs to modify a configuration, provide a scoped API that limits what can be changed rather than giving it shell access to the underlying system. The goal is to constrain not just what the agent can access but what it can decide to do.</p><p>This distinction matters because traditional access control assumes the entity with access will use it predictably. An agent with read access to a customer database and the ability to send emails could, through a prompt injection attack or simply through an unexpected reasoning chain, decide to exfiltrate data by composing and sending emails containing customer records. The access controls were technically correct, but the agent&#8217;s autonomy created a risk that access controls alone don&#8217;t address.</p><p>This concept is also important because remember, we&#8217;re assuming breach. If we assume an agent will get breached, and they will, they now have ramifications for the environment and enterprise they operate in. An agent with broad permissions and agencies poses much more risk if compromised than one with least-permissive access control/agency.</p><p>Anthropic frames this as a principle for system designers, not just security teams. The developers building agent capabilities need to think about autonomy constraints from the beginning, designing tool interfaces that are narrow by default and expanded only when the task genuinely requires it.</p><h2>Hard Boundaries and Soft Guardrails</h2><p>One of the most practically useful call outs in the framework is between hard boundaries and soft boundaries. Hard boundaries are deterministic, code-level controls that an agent cannot override regardless of what it&#8217;s been instructed to do. Hard boundaries are something I have been advocating for in my <strong><a href="https://zenity.io/blog/current-events/ai-agent-database-deletion-pocketos">writing</a></strong> and through my participation in groups such as <strong><a href="https://www.resilientcyber.io/p/aarm-and-the-case-for-standardizing">AARM</a></strong>. </p><p>These include things like tool-level access controls enforced by the infrastructure rather than by the model, session-scoped credentials that expire automatically, sandboxed execution environments that limit file system and network access, and rate limits that prevent runaway behavior. Hard boundaries don&#8217;t depend on the agent&#8217;s cooperation, they&#8217;re enforced by the system architecture itself, outside of the reasoning loop.</p><p>Soft boundaries, by contrast, are controls that rely on the agent&#8217;s reasoning to comply. These include system prompts that instruct the agent to ask for human approval before taking certain actions, hooks that intercept agent actions and route them through approval workflows, and human-in-the-loop checkpoints for high-stakes operations. Soft boundaries are important because not every action can be anticipated and blocked through hard constraints. </p><p>That said, they&#8217;re inherently less reliable because they depend on the agent correctly interpreting and following instructions, and we already know that prompt injection can subvert that compliance, as we saw in real-world examples, such as PocketOS, where the agent completely ignored its system prompt.</p><p>As I&#8217;ve written about in the context of securing agentic AI systems, the right architecture layers both. Hard boundaries establish the non-negotiable constraints, the blast walls that hold even if the agent is fully compromised. Soft boundaries add flexibility and human oversight within those constraints. </p><p>The mistake organizations make is treating soft boundaries as if they were hard ones, trusting a system prompt that says &#8220;<em>always ask before deleting files</em>&#8221; as though it were an immutable access control, when it isn&#8217;t. It&#8217;s a suggestion to a probabilistic system, and a sufficiently sophisticated attack, or even the agents own reasoning can make the system ignore it.</p><p>Anthropic is explicit about this hierarchy. Hard boundaries should be the first line of defense. Soft boundaries provide defense in depth but should never be the only thing standing between an agent and a catastrophic action.</p><h2>Blast Radius as the Design Principle</h2><p>The &#8220;<em>assume breach</em>&#8221; principle of Zero Trust takes on new urgency when applied to agents because the blast radius of a compromised agent can be far larger than that of a compromised user account. A human user works within a single session, typically interacting with a handful of applications through defined workflows. A compromised agent, depending on its configured capabilities, can execute actions across multiple systems at machine speed with no human in the loop.</p><p>Anthropic&#8217;s framework emphasizes blast radius containment as a primary design objective. This means session-scoped credentials that limit an agent&#8217;s access to the minimum time window needed, sandboxed execution environments that restrict what a compromised agent can reach, and architectural isolation that prevents one agent&#8217;s compromise from cascading to other agents or systems. </p><p>The goal isn&#8217;t to prevent all breaches, a premise that would be naive given the inherent insecurity Anthropic acknowledges, but to ensure that when a breach occurs, the damage is contained to the smallest possible scope.</p><p>This maps directly to the micro-segmentation principles that the NSA and CISA have been pushing for traditional networks, but with a critical twist. </p><p>Agent segmentation isn&#8217;t just about network boundaries. It&#8217;s about capability boundaries, temporal boundaries, and data boundaries. An agent operating in a sandboxed environment with scoped credentials that expire after a single task, limited to a narrow set of parameterized tools, with no ability to spawn additional agents or escalate its own permissions, presents a fundamentally different risk profile than an agent with persistent credentials, broad tool access, and the ability to chain actions autonomously across systems.</p><p>For organizations looking to get this right, it requires a design for containment from the beginning rather than trying to bolt it on after deploying agents with broad permissions and discovering the hard way what &#8220;inherently somewhat insecure&#8221; means in practice.</p><p>That said, as we know from all previous technology waves, governing how technologies get deployed in real-world environments is incredibly difficult and there are already agents being rolled out in enterprise environments everywhere that violate these principles, whether via SaaS/embedded agents, endpoint coding agents, custom homegrown agents and more.</p><h2>Where This Leaves Practitioners</h2><p>Anthropic&#8217;s Zero Trust framework for agents isn&#8217;t a departure from the principles that CISA, NSA, and commercial industry have been advancing for years. </p><p>It&#8217;s a stress test that reveals which parts of those principles are durable and which parts assumed a world of deterministic, human-driven interactions that no longer reflects reality.</p><p>The principles are still incredibly valid. Verify explicitly, enforce least privilege, and assume breach. </p><p>These are sound architectural commitments that apply to any entity operating in an enterprise environment. But the implementation demands are categorically different when the entity you&#8217;re governing can reason, improvise, and be manipulated through the data it processes, which for most agents is the entire Internet, and was something documented really well by Google&#8217;s Deep Mind in a paper on <strong><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6372438">AI Agent Traps</a></strong>, which I strongly recommend checking out.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gaUB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gaUB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png 424w, https://substackcdn.com/image/fetch/$s_!gaUB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png 848w, https://substackcdn.com/image/fetch/$s_!gaUB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png 1272w, https://substackcdn.com/image/fetch/$s_!gaUB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gaUB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png" width="541" height="688" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:688,&quot;width&quot;:541,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156631,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/200125051?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gaUB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png 424w, https://substackcdn.com/image/fetch/$s_!gaUB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png 848w, https://substackcdn.com/image/fetch/$s_!gaUB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png 1272w, https://substackcdn.com/image/fetch/$s_!gaUB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ff3dfb4-2acd-4400-aa25-d759e13c8e6b_541x688.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Least privilege has to expand into least agency. Verify explicitly has to account for non-deterministic behavior that changes between identical inputs. Assume breach has to drive blast radius containment as a first-order design constraint rather than an afterthought.</p><p>On top of all of that, the threat model has to account for the Vulnpocalypse. When AI compresses the vulnerability-to-exploit timeline from months to hours, the containment architecture for agents isn&#8217;t just a security best practice, it&#8217;s arguably a survival requirement. </p><p>An agent compromised through a vulnerability that was discovered, weaponized, and deployed autonomously in the time it takes a human analyst to finish their morning standup demands a defense posture that most organizations haven&#8217;t built yet. </p><p>On top of that, agents are being rolled out incredibly quickly, across SaaS, cloud, endpoints and more, most of which is ungoverned let alone hardened and secured, so the implications for agent compromise as it related to enterprise risks is daunting.</p><p>The hardest part for most enterprises won&#8217;t be understanding these concepts. Instead it will be implementing them on top of Zero Trust programs that are still immature for traditional workloads, let alone autonomous agents. </p><p>If your organization hasn&#8217;t achieved micro-segmentation for human users and machine workloads, the notion of implementing capability-scoped, session-limited, sandboxed agent environments feels like building the third floor while the foundation is still setting. </p><p>That tension, between the urgency of deploying agents for competitive advantage and the maturity required to deploy them safely, is the defining challenge of this era for cybersecurity in my opinion. </p><p>The organizations that acknowledge it honestly, rather than pretending their current security architecture is securely ready for autonomous AI, will be the ones that navigate it without a catastrophic dose or reality to go along with their delusion.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Securing the Agentic SDLC]]></title><description><![CDATA[In this episode of Resilient Cyber, I sit down with Katie Norton, Research Manager for DevSecOps and Software Supply Chain Security at IDC, to unpack what application security looks like as AI moves from copilot to autonomous teammate across the software development lifecycle.]]></description><link>https://www.resilientcyber.io/p/securing-the-agentic-sdlc</link><guid isPermaLink="false">https://www.resilientcyber.io/p/securing-the-agentic-sdlc</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Sat, 30 May 2026 12:02:48 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/199791353/57e42eaaa9634c7107d66724a657fbfd.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode of Resilient Cyber, I sit down with Katie Norton, Research Manager for DevSecOps and Software Supply Chain Security at IDC, to unpack what application security looks like as AI moves from copilot to autonomous teammate across the software development lifecycle.</p><p>We dig into AI&#8217;s accelerating impact on AppSec and the SDLC, the productivity-versus-risk equation now that agentic coding tools are landing pull requests with minimal human review, and the so-called &#8220;Vulnpocalypse&#8221; &#8211; the explosion of CVEs, AI-generated code, and the widening gap between vulnerability discovery and remediation capacity. We explore whether legacy AppSec tooling categories like SAST, DAST, SCA, and ASPM can keep pace, or whether they&#8217;re being fundamentally reinvented for an agentic world.</p><p>Katie also shares her perspective on the rise of autonomous pen testing and offensive security agents, what it means when attackers operate at machine speed while defenders are still triaging tickets, and how practitioners, CISOs, and security leaders should be rethinking team structure, skills, and governance for an agentic SDLC.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><div id="youtube2-nzOOpiS9ZIE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;nzOOpiS9ZIE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/nzOOpiS9ZIE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p><strong><mark data-color="#ffff00" style="background-color: rgb(255, 255, 0); color: rgb(0, 0, 0);">Prefer to Listen?</mark></strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/securing-the-agentic-sdlc/id1555928024?i=1000770220418">Apple Podcasts</a></strong></p><p><strong><a href="https://open.spotify.com/episode/2Cex7P4TlwX1SAcYdfg8ef?si=RViZaDFIRwGsNm6iL--fEg">Spotify</a></strong></p><p><strong>Be sure to subscribe and leave a review!</strong></p><div><hr></div><p><strong>Key Takeaways:</strong></p><ul><li><p><strong>AI is breaking the AppSec workload equation.</strong> Agentic coding tools have dramatically increased code velocity and volume, exposing the limits of human-paced security review and forcing organizations to rethink how AppSec scales.</p></li><li><p><strong>The &#8220;Vulnpocalypse&#8221; is real, but uneven.</strong> The gap between vulnerability discovery and remediation capacity is widening fast, and the organizations feeling it most are those still relying on legacy triage and ticketing models built for a pre-AI world.</p></li><li><p><strong>Legacy AppSec categories are being reinvented, not just extended.</strong> SAST, DAST, SCA, and ASPM weren&#8217;t designed for a world where AI agents author, review, and deploy code &#8211; and the tooling landscape is starting to reflect that reality.</p></li><li><p><strong>Autonomous offense is outpacing autonomous defense.</strong> With tools like XBOW, Project Naptime, and Project VAIL pushing the boundaries of agentic pen testing, defenders need to take the asymmetry seriously and invest accordingly.</p></li><li><p><strong>The agentic SDLC demands new governance, not just new tools.</strong> From AI-generated dependencies and hallucinated packages to MCP server integrity, supply chain risk is evolving &#8211; and the organizations that thrive will be the ones building governance models, skills, and team structures purpose-built for this era.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Frenemies at the Frontier]]></title><description><![CDATA[How the frontier lab&#8211;cybersecurity relationship became category-specific, not categorical]]></description><link>https://www.resilientcyber.io/p/frenemies-at-the-frontier</link><guid isPermaLink="false">https://www.resilientcyber.io/p/frenemies-at-the-frontier</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 29 May 2026 12:43:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Zyow!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On February 20, Anthropic shipped Claude Code Security as a research preview, an AI scanner that reviews full codebases, validates findings to reduce false positives, and suggests patches for human review. </p><p>The same week, Opus 4.6 reportedly surfaced over 500 high-severity vulnerabilities that had survived decades of expert review. The market&#8217;s read was immediate and unambiguous. </p><p>CrowdStrike dropped 8% and deepened toward 11% over the week, Zscaler fell 5.5% and kept sliding toward 10-11%, SailPoint dropped 9.4%, Okta 9.2%, JFrog 25%, Palo Alto 3.2%, and Cloudflare 8.1%. The Global X Cybersecurity ETF hit its lowest level since November 2023, down 4.9% in a single session.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ibY4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ibY4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png 424w, https://substackcdn.com/image/fetch/$s_!ibY4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png 848w, https://substackcdn.com/image/fetch/$s_!ibY4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png 1272w, https://substackcdn.com/image/fetch/$s_!ibY4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ibY4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png" width="1456" height="713" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:713,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1820120,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199422194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ibY4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png 424w, https://substackcdn.com/image/fetch/$s_!ibY4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png 848w, https://substackcdn.com/image/fetch/$s_!ibY4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png 1272w, https://substackcdn.com/image/fetch/$s_!ibY4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4649c976-3d12-4c7f-8e01-33a0221f6805_1976x968.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The thesis the market was pricing was simple and clean. Frontier labs will eat cybersecurity. If the model can find vulnerabilities, write detections, and suggest patches, the entire security vendor stack becomes a middleman awaiting disintermediation.</p><p>As I wrote at the time in <strong><a href="https://www.resilientcyber.io/p/when-the-frontier-labs-sneeze-the">When the Frontier Labs Sneeze, the Cybersecurity Market Catches a Cold</a></strong>, the selloff reflected a structural anxiety that frontier labs were moving up the stack into territory that historically belonged to standalone security vendors. </p><p>Three months later, the evidence says the thesis was half right and half backwards. The frontier lab is <em><strong>both</strong></em> competitor and partner, and which one depends entirely on the category and the offering. Recent week&#8217;s integrations are the clearest proof yet, and they tell a fundamentally different story from the one the market sold in February.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zyow!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zyow!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!Zyow!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!Zyow!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!Zyow!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zyow!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8919250,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199422194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Zyow!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!Zyow!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!Zyow!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!Zyow!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8a069b7-c01c-4003-a16b-74f9443c5237_2816x1536.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>The Reframe</h1><p>The analyst community pushed back on the February selloff almost immediately, and their reasoning holds up. Berenberg stressed that Claude Code Security sits in application security, roughly 1.2% of total cyber TAM, and drew a clear distinction between build-time vulnerability finding and runtime security across endpoint, network, and identity. The reaction was harsh relative to the actual surface area being threatened. </p><p>JPMorgan called the selloff indiscriminate and kept Overweight ratings on all five affected names. Baird&#8217;s Shrenik Kothari called it a panic-driven, narrative-led selloff. Wedbush labeled the entire episode &#8220;AI Ghost Trade fears&#8221; and called it an overreaction, arguing that cybersecurity is a key beneficiary of AI rather than a casualty and expecting OpenAI and others to follow Anthropic&#8217;s path. As an aside, the NYT recently <strong><a href="https://www.nytimes.com/2026/05/24/technology/ai-cybersecurity-jobs.html">highlighted</a></strong> how cybersecurity roles are in high-demand with the rise of AI, counter-acting the layoff narrative that many circulate. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e8c7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e8c7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png 424w, https://substackcdn.com/image/fetch/$s_!e8c7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png 848w, https://substackcdn.com/image/fetch/$s_!e8c7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png 1272w, https://substackcdn.com/image/fetch/$s_!e8c7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e8c7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png" width="1270" height="420" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:1270,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:236633,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199422194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e8c7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png 424w, https://substackcdn.com/image/fetch/$s_!e8c7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png 848w, https://substackcdn.com/image/fetch/$s_!e8c7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png 1272w, https://substackcdn.com/image/fetch/$s_!e8c7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b96292b-9fc6-430c-9015-0d6077bfccb7_1270x420.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>CrowdStrike CEO George Kurtz <strong><a href="https://youtube.com/shorts/fw4qmw4mxbc?si=oF9EdbIsT4xB2oY9">made the argument</a></strong> more directly and he&#8217;s right. AI increases the need for security, not less. Every enterprise AI deployment creates new surfaces to monitor, new data flows to govern, new identities to manage, and new compliance obligations to satisfy. The model doesn&#8217;t replace the security stack, it feeds it and in many ways, the rise of LLMs and Agents is a boon for cybersecurity as well. More attack surface, more code volume, more deployments, new novel attack vectors etc.</p><blockquote><p><strong>That framing sounded like corporate spin in February. By late May, it looks like a reasonable description of what&#8217;s actually happening.</strong></p></blockquote><p>The market data makes the reversal concrete. </p><p>On May 22, the same day Anthropic published its latest Glasswing update, which I published a comprehensive <strong><a href="https://www.resilientcyber.io/p/the-receipts-are-in">write-up</a></strong> and <strong><a href="https://youtu.be/5DPQ3m3e8OE?si=pvEWNDle8oVPHfzY">video</a></strong> on. </p><div id="youtube2-5DPQ3m3e8OE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5DPQ3m3e8OE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5DPQ3m3e8OE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The three largest public cybersecurity companies sat at or near all-time high market capitalizations. Palo Alto Networks crossed $211 billion. CrowdStrike reached $168 billion after its stock hit a record $674 and its ARR topped $5 billion. Fortinet approached $100 billion. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X2eQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X2eQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png 424w, https://substackcdn.com/image/fetch/$s_!X2eQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png 848w, https://substackcdn.com/image/fetch/$s_!X2eQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png 1272w, https://substackcdn.com/image/fetch/$s_!X2eQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X2eQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png" width="1456" height="803" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:803,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1166066,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199422194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!X2eQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png 424w, https://substackcdn.com/image/fetch/$s_!X2eQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png 848w, https://substackcdn.com/image/fetch/$s_!X2eQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png 1272w, https://substackcdn.com/image/fetch/$s_!X2eQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17406808-e95f-419a-be4a-b3379ab56711_2042x1126.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As <strong><a href="https://www.linkedin.com/posts/elad-erez_mythos-is-about-to-kill-cybersecurity-share-7465149355860070400-U-jG/">Elad Erez pointed out</a></strong>, the headline was supposed to be &#8220;Mythos is about to kill cybersecurity,&#8221; and instead the largest cyber companies were posting record valuations on the same day the lab&#8217;s most advanced offensive model shipped new results. The BUG ETF, which hit its lowest level since November 2023 during the February selloff, has fully recovered and then some.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Amjd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Amjd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png 424w, https://substackcdn.com/image/fetch/$s_!Amjd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png 848w, https://substackcdn.com/image/fetch/$s_!Amjd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png 1272w, https://substackcdn.com/image/fetch/$s_!Amjd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Amjd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png" width="1456" height="727" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:727,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:903320,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199422194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Amjd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png 424w, https://substackcdn.com/image/fetch/$s_!Amjd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png 848w, https://substackcdn.com/image/fetch/$s_!Amjd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png 1272w, https://substackcdn.com/image/fetch/$s_!Amjd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0a73edf-9a2d-4706-9458-a36051cc3580_2028x1012.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>The performance data underneath the headlines tells a more nuanced story. </strong></p></blockquote><p>As <strong><a href="https://www.linkedin.com/posts/nikolozk_cybersecurity-stocks-are-booming-in-2026-share-7465024173627760640-jpvx/">Nikoloz K. documented</a></strong>, the rally isn&#8217;t lifting all boats equally. </p><p>CrowdStrike is growing ARR at 24% at $5 billion scale. Zscaler is at $3.36 billion growing 26%. Palo Alto&#8217;s stock is up more than 30% this year following its $25 billion acquisition of CyberArk. </p><p>The companies winning are the ones that repositioned their messaging from &#8220;we sell security&#8221; to &#8220;we secure AI workloads, identities, and agents,&#8221; and the ones that leaned into platform consolidation as CISOs cut vendor counts. As I mentioned above, AI and the need to secure it is helping drive both revenue and market valuations for cybersecurity firms.</p><p>Meanwhile, Zscaler fell more than 50% from its 2025 highs before bouncing back, Check Point faces execution questions, and Microsoft quietly runs a $37 billion security business that&#8217;s larger than CrowdStrike, Palo Alto, and Zscaler combined. The gap between winners and losers in cyber has widened, but the category itself is growing, not shrinking. </p><blockquote><p><strong>That&#8217;s the opposite of what the February thesis predicted.</strong></p></blockquote><h2>What Shipped In Recent Weeks</h2><p>Between May 19 and 21, a wave of integrations landed that represent a fundamentally different relationship between Anthropic and the cybersecurity vendor ecosystem. </p><p>The enabling primitive is the <strong><a href="https://platform.claude.com/docs/en/manage-claude/compliance-api">Claude Compliance API</a></strong>, which opens Claude Enterprise&#8217;s activity, audit, and data-flow surface to the existing enterprise security stack. The throughline is that Claude Enterprise becomes a governed enterprise application that the existing security infrastructure now covers like any other SaaS  or application platform.</p><p>Wiz built an <strong><a href="https://www.wiz.io/blog/claude-wiz-integration">integration</a></strong> that pulls Claude Enterprise activity into the Wiz platform and onto its Security Graph, currently in Private Preview. The integration gives security teams visibility into how Claude is being used across their environment with the same posture management and risk contextualization that Wiz applies to cloud infrastructure.</p><p>Cyera extended its Omni DLP <strong><a href="https://www.cyera.com/blog/cyera-and-anthropic-integrate-to-bring-real-time-ai-security-to-claude-enterprise">through</a></strong> the Compliance API, adding data loss prevention, insider risk, and audit coverage over Claude Enterprise conversations, files, and user activity. Their public claims are that it delivers 95% precision on classification and risk scoring. Cyera CEO Yotam Segev framed it as "extending the same data security governance to AI that organizations already expect for every other enterprise application.</p><p>Datadog built an <strong><a href="https://docs.datadoghq.com/integrations/anthropic-compliance-logs/">integration</a></strong> that ingests Claude Platform audit logs into Datadog for SIEM and compliance purposes, covering admin activity, API key lifecycle, and authentication events.</p><p>The same week, KPMG <strong><a href="https://kpmg.com/xx/en/media/press-releases/2026/05/kpmg-and-anthropic-sign-global-alliance-and-launch-digital-gateway-powered-by-claude.html">announced</a></strong> a strategic alliance integrating Claude across its core business and 276,000-person workforce. </p><p>The trajectory is clear, Claude is entering enterprise environments at scale, and the security and governance requirements that come with enterprise deployment at scale are real, growing, and not something the lab is positioned to solve alone.</p><h2>Why This Is Not Glasswing</h2><p>The Glasswing comparison matters because both are alliances between Anthropic and major cybersecurity vendors, but they are fundamentally different models of collaboration, and conflating them misses key distinctions.</p><p><strong><a href="https://anthropic.com/glasswing">Project Glasswing</a></strong>, which launched earlier this spring, is a coalition using the unreleased Claude Mythos Preview model defensively to find and fix vulnerabilities <em><strong>in</strong></em> partners&#8217; own foundational systems. </p><p>The partner list includes AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks, among others. The work covers vulnerability detection, black-box binary testing, endpoint security, and penetration testing. </p><p>Mythos uncovered thousands of previously unknown zero-days across major operating systems and browsers, including a 27-year-old bug in OpenBSD. Anthropic committed $100 million in credits and $4 million in donations to open-source security.</p><p>Cisco&#8217;s <strong><a href="https://blogs.cisco.com/news/rising-to-the-era-of-ai-powered-cyber-defense">engagement</a></strong> illustrates the Glasswing model clearly. Cisco stress-tested its own products and infrastructure against Mythos, and CSO Anthony Grieco said Anthropic&#8217;s models forced a rethink of how Cisco builds and secures its products. That is the lab lending an offensive-grade model inward so a vendor can red-team and harden its own systems.</p><p>Others such as Palo Alto Networks (PANW) have done the same, and publicly have discussed how they have identified 7x their usual monthly volume of vulnerabilities in their products through its use. </p><p>Recent week&#8217;s integrations such as Cyera, Wiz and Datadog are a different collaboration model entirely. The two modes are worth unpacking due to their key differences. </p><p>Mode one is capability injection for hardening, where the lab lends a frontier model inward so vendors can red-team and patch their own systems, that is Glasswing. </p><p>Mode two is platform embedding and surface governance, where the vendor extends its platform across the lab&#8217;s enterprise footprint, and the lab opens an API so the vendor&#8217;s tooling can govern the new surface, that is this the recent announcements from Wiz, Cyera, Datadog and others. </p><p>Both are alliances, but they are not the same alliance, and the distinction matters because the economic logic, the direction of value flow, and the competitive dynamics are entirely different with each approach.</p><p>In Glasswing, the lab provides offensive capability and the vendor is the consumer. In the Compliance API integrations, the vendor provides governance capability. The lab is the consumer, and so is every enterprise that deploys Claude. The direction reverses, and the dependency runs the other way.</p><h2>The Economics</h2><p>The zero-sum framing that dominated February assumed a fixed pie. </p><p>The lab builds security capabilities, takes revenue from security vendors, and the vendors shrink. The positive-sum reality is more interesting and more supported by the evidence now that the initial panic has died down some.</p><p>For the labs, governance was a procurement blocker. Regulated industries need DLP over AI conversation data, audit trails for compliance, and visibility into how AI tools interact with sensitive information. </p><p>These are requirements that traditional tools were never built to monitor, and they were stalling enterprise sales cycles. By opening the Compliance API and enabling Wiz, Cyera, and Datadog to extend their platforms over Claude Enterprise, Anthropic de-risks adoption for the buyer, expands seats, and shortens the sales cycle. </p><p>The lab doesn&#8217;t need to build governance tooling itself. It just needs to make its surface governable. Mythos is a separate revenue lane on top, priced as premium API access for security research and hardening.</p><p>Another angle to the recent integrations and partnerships between Anthropic and cyber vendors is it helps the cyber vendors differentiate and bolster their products among competitors, providing visibility and coverage to the faster growing enterprise software arguably ever seen.</p><p>For the vendors, every Claude Enterprise deployment is a new monitored surface and a new SKU. Cyera and Wiz aren&#8217;t competing against Claude. They&#8217;re becoming the control plane for the fastest-growing enterprise application category. </p><p>Every organization that adopts Claude Enterprise and needs DLP, audit, or posture management becomes a potential customer for the vendor&#8217;s platform extension. The TAM doesn&#8217;t shrink, it expands, because the AI surface that needs governing didn&#8217;t exist two years ago and is growing faster than any other enterprise software category. This same dynamic exists for agents, as those proliferate as well.</p><p>CrowdStrike&#8217;s framing from its 2026 Global Threat Report is relevant here. The same frontier models that expand the attack surface hand defenders a capability advantage that didn&#8217;t exist a year ago, and that report found an 89% year-over-year rise in AI-driven adversary attacks. The threat generates the demand, and the lab&#8217;s enterprise expansion generates the surface. Both feed the security vendor&#8217;s addressable market.</p><p>The frame is straightforward and much different than the initial market driven panic narrativre. Zero-sum thinking said the lab eats cyber. </p><p>The positive-sum reality is the lab grows the enterprise AI surface, and cyber sells the governance that the lab will not build and cannot credibly sell itself. The stock market has already priced this in, with the companies that repositioned fastest around AI workloads, identities, and agent governance posting the strongest performance in 2026. </p><p>A frontier lab telling a regulated enterprise &#8220;trust us, we govern ourselves&#8221; is a structural conflict of interest that no compliance officer will accept, and that structural gap is where the vendor value lives.</p><h2>Where This Could Still Break</h2><p>I&#8217;ve been <strong><a href="https://www.resilientcyber.io/p/securitys-ai-driven-dilemma">skeptical of narratives that assume permanent alignment</a></strong> between parties whose incentives may diverge, and the same discipline applies here. Partner versus competitor is a roadmap decision, not a permanent state, and several dynamics could shift the boundary.</p><p>Code scanning genuinely pressures SAST and segments of application security, and nothing stops a lab from building natively into a category it partners on today. If Anthropic decides that first-party DLP or compliance tooling is a higher-value product than an open API that feeds third-party vendors, the partnership model changes overnight. The Compliance API is an invitation today, but it could become a competitive moat tomorrow if the lab decides to internalize the governance layer.</p><p>This is even more stark when you consider the funding and explosive growth of ARR companies like Anthropic have to deploy when it comes to building and shipping capabilities, which they&#8217;ve demonstrated to be excellent at. There is also another aspect, in the sense that each frontier lab is its own walled garden, much like CSP&#8217;s prior in the cloud security era, so security vendors can and should differentiate on multi-provider coverage (e.g. covering models and agents across the diverse landscape they are offered and can be deployed in). </p><p>Embedding and preferred-model status also raise concentration and lock-in questions. When your DLP, your SIEM integration, and your security graph are all built around one lab&#8217;s API and data schema, the switching cost isn&#8217;t just the model. It&#8217;s the entire governance architecture you&#8217;ve constructed on top of it. As I explored in <strong><a href="https://www.resilientcyber.io/p/orchestrating-agentic-ai-securely">Orchestrating Agentic AI Securely</a></strong>, the dependency surface of agentic AI extends well beyond the model itself, and every integration deepens that dependency.</p><p>The category boundary between build and partner is the whole story here, and it will move in time, as the market continues to evolve. It&#8217;s clear these partnerships are genuine today, in this moment. That said, the question is what structural incentives would cause the boundary to shift, and whether the organizations on either side of it are building with that possibility priced in, and going into the partnerships with eyes wide open versus rose colored glasses.</p><h2>Takeaways</h2><p>For practitioners, the operating model is straightforward. Treat every frontier lab relationship as category-specific rather than categorical. Claude Code Security is competitive pressure on AppSec, but even then AppSec programs are complex endeavors and code scanning is only a piece of that, and leading AppSec vendors also have various levels of differentiation from the labs native offerings. </p><p>The Compliance API integrations are partnership infrastructure for governance. Both can be true simultaneously, and the rational response is to evaluate each surface independently rather than making a binary bet on &#8220;lab as friend&#8221; or &#8220;lab as foe.&#8221;</p><p>For security leaders evaluating vendors, the Compliance API wave is a signal that the governance layer for enterprise AI and agents is going to be built by the security ecosystem, not by the labs themselves. </p><p>The vendors that move fastest to embed across the largest AI enterprise surfaces will have a structural advantage, and the organizations that wait for the lab to build governance natively will be waiting for a product the lab has no incentive to build well because it conflicts with the lab&#8217;s core commercial interest in frictionless adoption and even if it did come, it would be confined to that specific labs walled garden, rather than multi-lab coverage.</p><p>For investors, the February selloff priced the entire cybersecurity sector as a victim of frontier AI capability. The May integrations price a meaningful segment of it as a beneficiary. The truth is probably both, distributed unevenly across categories, and the allocation of winners and losers will track the build-versus-partner boundary as it moves over the next 12-24 months.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #99]]></title><description><![CDATA[Demand for Cyber Expertise Surges, Glasswing Reports 10,000 Bugs, Containing Claude & Agents, GOOGL & CRWD Takedown Glassworm Botnet, True Cost of AI Scanning & LLM Security Leaderboard]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-99</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-99</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 28 May 2026 13:12:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PTmh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #99 of the Resilient Cyber Newsletter! This week brought the first official numbers from Anthropic&#8217;s Project Glasswing, and they are staggering. Claude Mythos Preview identified over 10,000 vulnerabilities in its first month, with 6,202 rated high or critical severity. Dawn Song&#8217;s team at UC Berkeley showed that Mythos can autonomously exploit 157 out of 898 real-world vulnerabilities across userspace programs, V8, and the Linux kernel. And CrowdStrike and Google coordinated a simultaneous takedown of the Glassworm botnet, a sophisticated campaign that had been targeting software developers through poisoned VSCode extensions, npm packages, and 300+ GitHub repositories since early 2025.</p><p>On the market side, global AI spending hit $2.59 trillion in 2026, growing by roughly $1 trillion year over year. Cybersecurity stocks are surging. The Omdia Tech Titans index posted its strongest quarterly growth in 15 years. And Cloudflare cut 20% of its workforce while posting record revenue, with CEO Matthew Prince framing the layoffs as eliminating &#8220;measurers&#8221; in favor of builders and sellers.</p><p>Meanwhile, Anthropic published an engineering deep dive on how they contain Claude across products, Uber shipped a full agent identity architecture with attested actor chains, and Adversa AI found that the human approval prompt, the primary safety control in five major coding agents, can be bypassed through symlink manipulation.</p><p>Let&#8217;s get into it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PTmh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PTmh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png 424w, https://substackcdn.com/image/fetch/$s_!PTmh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png 848w, https://substackcdn.com/image/fetch/$s_!PTmh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png 1272w, https://substackcdn.com/image/fetch/$s_!PTmh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PTmh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png" width="1456" height="887" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:887,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1465685,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PTmh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png 424w, https://substackcdn.com/image/fetch/$s_!PTmh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png 848w, https://substackcdn.com/image/fetch/$s_!PTmh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png 1272w, https://substackcdn.com/image/fetch/$s_!PTmh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3225df82-2149-4d14-ba49-f38ed8db677e_2078x1266.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><blockquote><h3><strong><a href="https://lp.novee.security/novees-buyer-guide?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=resilient_cyber">The CISO&#8217;s Guide to AI Pentesting in 2026</a> </strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://lp.novee.security/novees-buyer-guide?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=resilient_cyber" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PUrL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png 424w, https://substackcdn.com/image/fetch/$s_!PUrL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png 848w, https://substackcdn.com/image/fetch/$s_!PUrL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!PUrL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PUrL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png" width="582" height="349.3598901098901" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:582,&quot;bytes&quot;:2955712,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://lp.novee.security/novees-buyer-guide?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=resilient_cyber&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!PUrL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png 424w, https://substackcdn.com/image/fetch/$s_!PUrL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png 848w, https://substackcdn.com/image/fetch/$s_!PUrL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png 1272w, https://substackcdn.com/image/fetch/$s_!PUrL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac9afa36-24db-45b0-b454-69c4d154c363_2000x1200.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Every security team is being asked the same question in 2026: how are we testing our AI applications and agents? Traditional pentesting wasn&#8217;t built for non-deterministic systems. DAST and SAST miss prompt injection, tool abuse, and the new attack surface that comes with agentic pipelines. That&#8217;s why AI pentesting is on every CISO&#8217;s evaluation list this year.</p><p>The Definitive Buyer&#8217;s Guide to AI Penetration Testing walks through why this category exists, what it actually does, and the eight questions that separate basic automated scanners from real offensive security platforms built for AI systems.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://lp.novee.security/novees-buyer-guide?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=resilient_cyber&quot;,&quot;text&quot;:&quot;Read it before your next vendor call.&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://lp.novee.security/novees-buyer-guide?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=resilient_cyber"><span>Read it before your next vendor call.</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><em><strong>Interested in sponsoring an issue of Resilient Cyber?</strong></em></p><p><em><strong>This includes reaching over 31,000 subscribers, ranging from Developers, Engineers, Architects, CISO&#8217;s/Security Leaders and Business Executives</strong></em></p><p><em><strong>Reach out below!</strong></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:sponsorships@resilientcyber.io&quot;,&quot;text&quot;:&quot;-> Contact Us! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="mailto:sponsorships@resilientcyber.io"><span>-&gt; Contact Us! &lt;-</span></a></p><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.linkedin.com/posts/markwoneill_ai-spending-is-growing-by-roughly-one-trillion-share-7462919762482855936-v_UF">AI Spending Grows by Nearly One Trillion Dollars in a Single Year</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y-VE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y-VE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png 424w, https://substackcdn.com/image/fetch/$s_!y-VE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png 848w, https://substackcdn.com/image/fetch/$s_!y-VE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png 1272w, https://substackcdn.com/image/fetch/$s_!y-VE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y-VE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png" width="596" height="381.09615384615387" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:931,&quot;width&quot;:1456,&quot;resizeWidth&quot;:596,&quot;bytes&quot;:1195015,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y-VE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png 424w, https://substackcdn.com/image/fetch/$s_!y-VE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png 848w, https://substackcdn.com/image/fetch/$s_!y-VE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png 1272w, https://substackcdn.com/image/fetch/$s_!y-VE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eb7c93-5ac3-4202-a774-61c1b03d1b9e_1702x1088.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Mark O&#8217;Neill framed the number that puts every other market discussion into perspective. Global AI spending will reach $2.59 trillion in 2026, a 47% increase year over year. </p><p>The growth alone, roughly $1 trillion, exceeds the entire cybersecurity market. Evercore and Bank of America estimate AI capital expenditure between $800 billion and $900 billion for 2026, with projections exceeding $1 trillion by 2027. As I discussed in issue #98 with the strange economics of cybersecurity, AI deflates costs everywhere except security. </p><p>Every dollar of that $2.59 trillion creates new identity vectors, new attack surfaces, and new governance requirements. The cybersecurity market is not just growing alongside AI. It is growing because of AI, and the ratio between AI investment and security investment tells you how wide the gap between capability and protection remains.</p><h3><a href="https://www.linkedin.com/posts/nikolozk_cyera-just-bought-a-5-months-old-5-person-share-7463129957100347392-qvjZ">Cyera Pays $50 Million for a Five-Month-Old, Five-Person Startup</a></h3><p>At a $9 billion valuation following its latest funding round, Cyera acquired Genie Security for $50 million. Genie was five months old with five employees, had raised $3 million in seed funding from Mensch Capital and Dynamic Loop, and had deployed across hundreds of endpoints. </p><p>Genie&#8217;s founders, Nadav Noy and Noam Dotan, built endpoint-based AI data protection technology that Cyera needed to extend its platform. Wiz co-founder Assaf Rappaport was among the early investors. The acquisition pace in cybersecurity right now reflects a market where high valuations fuel rapid consolidation and time-to-capability matters more than building in-house. </p><p>For founders, $50 million for a five-month-old company with five people is the kind of exit that reshapes how early-stage investors think about cybersecurity.</p><h3><a href="https://www.linkedin.com/posts/matthewball2_the-latest-omdia-tech-titans-index-shows-activity-7463248014774550528-47kz">Tech Titans Post Their Strongest Quarterly Growth in 15 Years</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DlqC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DlqC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png 424w, https://substackcdn.com/image/fetch/$s_!DlqC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png 848w, https://substackcdn.com/image/fetch/$s_!DlqC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png 1272w, https://substackcdn.com/image/fetch/$s_!DlqC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DlqC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png" width="607" height="619.2626262626262" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1212,&quot;width&quot;:1188,&quot;resizeWidth&quot;:607,&quot;bytes&quot;:1117397,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DlqC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png 424w, https://substackcdn.com/image/fetch/$s_!DlqC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png 848w, https://substackcdn.com/image/fetch/$s_!DlqC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png 1272w, https://substackcdn.com/image/fetch/$s_!DlqC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b128f97-9182-4a3a-8d6b-9f63befaf516_1188x1212.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Omdia Tech Titans index showed the 18 largest technology suppliers generated $694 billion in Q1 2026, a 28.3% year-over-year increase and the fastest quarterly growth since 2011. </p><p>The full-year forecast projects 26.8% revenue growth, tracking toward $3 trillion annually. Semiconductors and memory are showing the highest growth, driven by AI infrastructure demand from NVIDIA, Samsung, AMD, and Broadcom. <a href="https://www.linkedin.com/posts/jaymcbain_the-latest-omdia-tech-titans-index-shows-share-7463325361263636480-Qnzb">Jay McBain&#8217;s analysis</a> highlights that cloud growth from AWS, Google Cloud, and Microsoft is accelerating as AI workloads move from experimentation to production deployment. </p><p><a href="https://www.linkedin.com/posts/matthewball2_the-latest-omdia-tech-titans-index-shows-activity-7463248014774550528-47kz">Matthew Ball&#8217;s cybersecurity research</a> at Omdia projects cybersecurity spending at $311 billion in 2026, up 12%, with emerging categories like shadow AI governance, inference protection, and AI agent identity driving new budget allocation.</p><h3><a href="https://www.linkedin.com/posts/nikolozk_cybersecurity-stocks-are-booming-in-2026-share-7465024173627760640-jpvx">Cybersecurity Stocks Are Surging on AI-Driven Demand</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DGUY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DGUY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png 424w, https://substackcdn.com/image/fetch/$s_!DGUY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png 848w, https://substackcdn.com/image/fetch/$s_!DGUY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png 1272w, https://substackcdn.com/image/fetch/$s_!DGUY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DGUY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png" width="1456" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:907557,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DGUY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png 424w, https://substackcdn.com/image/fetch/$s_!DGUY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png 848w, https://substackcdn.com/image/fetch/$s_!DGUY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png 1272w, https://substackcdn.com/image/fetch/$s_!DGUY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f3c921e-55ac-41d2-a61b-3029c10b8d79_2034x1006.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The network security market is forecast to exceed $50 billion by year-end 2026. Fortinet, F5, Palo Alto Networks, CrowdStrike, and Cisco are leading the surge. </p><p>The structural drivers are ones I have been tracking across multiple issues. Zero-trust architecture adoption, hybrid cloud security requirements, and AI-generated attack surface expansion are creating sustained demand that makes cybersecurity one of the most recession-resistant sectors in technology. M&amp;A is reaccelerating with CrowdStrike acquiring Seraphic Security in January and Zscaler acquiring SquareX in February. </p><p>As I discussed in issue #98 with Check Point&#8217;s fourth Israeli acquisition, vendor consolidation continues to intensify. The public market performance validates the thesis that AI creates more security spending, not less.</p><h3><a href="https://www.linkedin.com/posts/edsim_must-read-from-matthew-prince-cloudflare-activity-7463223481481207809-mcJT">Cloudflare Cuts 20% of Its Workforce and the Reasoning Matters</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SPSM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SPSM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png 424w, https://substackcdn.com/image/fetch/$s_!SPSM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png 848w, https://substackcdn.com/image/fetch/$s_!SPSM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png 1272w, https://substackcdn.com/image/fetch/$s_!SPSM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SPSM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png" width="418" height="374.0825515947467" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:954,&quot;width&quot;:1066,&quot;resizeWidth&quot;:418,&quot;bytes&quot;:728314,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SPSM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png 424w, https://substackcdn.com/image/fetch/$s_!SPSM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png 848w, https://substackcdn.com/image/fetch/$s_!SPSM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png 1272w, https://substackcdn.com/image/fetch/$s_!SPSM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddb87b2a-c364-44c4-ae58-2780c77b8e3e_1066x954.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ed Sim&quot;,&quot;id&quot;:3093019,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/117206c8-d2bf-460a-bfe4-f63ab22b79d3_2917x3582.png&quot;,&quot;uuid&quot;:&quot;c267815c-cf8c-4a27-9812-8de34e5dfe24&quot;}" data-component-name="MentionToDOM"></span> flagged Matthew Prince&#8217;s internal memo as a must-read, and I agree. Cloudflare eliminated over 1,100 positions, roughly 20% of its workforce, despite posting record revenue. </p><p>Prince&#8217;s framing was unusually direct. The company exists to build product and sell product, everything else is friction. The positions eliminated were primarily what he called &#8220;measurers,&#8221; roles in middle management, finance, legal, internal audit, and revenue recognition. The argument is that AI agents can automate these functions, and organizations should restructure around builders (engineers) and sellers rather than measurer layers. </p><p>For cybersecurity, this is a preview of how AI-driven organizational restructuring will reshape the teams that security leaders work with. When the middle management layer thins, security governance that relied on those roles for enforcement needs new mechanisms. As I discussed in issue #98 with the headless architecture thesis, the enforcement points are moving.</p><h3><a href="https://www.theregister.com/security/2026/05/21/hackerone-takes-an-axe-to-its-bug-bounty-rewards/5244458">HackerOne Slashes Internet Bug Bounty Payouts</a></h3><p>The numbers tell the story on this one. Critical vulnerability rewards dropped from $9,250 to $2,257. High-severity payouts fell from $4,429 to $1,009. Medium went from $1,843 to $297. Low from $597 to $68. </p><p>HackerOne stated that the Internet Bug Bounty program is dynamic and bounty levels adjust based on active sponsor contributions. The program remains paused while they evaluate adjustments. Combined with the bug bounty structural damage I covered in issue #98, the economics of vulnerability research are being fundamentally reshaped. </p><p>When AI commoditizes discovery and platforms slash rewards simultaneously, the financial incentive that made bug bounties work for a decade is eroding from both sides. Daniel Stenberg&#8217;s observation that open source projects are experiencing DDoS-like effects from AI-generated reports adds another dimension. The entire researcher-platform-vendor triangle is under strain.</p><h3><a href="https://www.nytimes.com/2026/05/24/technology/ai-cybersecurity-jobs.html">NYT Reports Cybersecurity as One of the Hottest Job Markets in Tech</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1qN-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1qN-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png 424w, https://substackcdn.com/image/fetch/$s_!1qN-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png 848w, https://substackcdn.com/image/fetch/$s_!1qN-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png 1272w, https://substackcdn.com/image/fetch/$s_!1qN-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1qN-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png" width="576" height="207.79746835443038" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:456,&quot;width&quot;:1264,&quot;resizeWidth&quot;:576,&quot;bytes&quot;:105066,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1qN-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png 424w, https://substackcdn.com/image/fetch/$s_!1qN-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png 848w, https://substackcdn.com/image/fetch/$s_!1qN-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png 1272w, https://substackcdn.com/image/fetch/$s_!1qN-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc322164a-0d67-4dcf-9ee9-e28a00d2978a_1264x456.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>For anyone who thinks AI will eliminate security jobs, the data says otherwise. Cybersecurity job postings rose 11% year over year in Q1 2026 per Glassdoor. 64% of cybersecurity job listings now require AI, ML, or automation expertise. </p><p>41% of security teams cite AI as their top skill requirement. But the workforce gap has widened to 4.8 million unfilled positions globally, up 19% year over year. 70% of firms are prioritizing senior talent while only 12% focus on entry-level hiring. </p><p>The <a href="https://www.nytimes.com/2026/05/22/opinion/ai-job-crisis-goldman-sachs.html">Goldman Sachs CEO&#8217;s NYT essay</a> arguing that AI job fears are overblown seems to be correct, at least in cybersecurity. AI is creating more security work, not less. The challenge is that the skills required are evolving faster than the talent pipeline can adapt.</p><h3><a href="https://www.linkedin.com/posts/mrrobertgil_letter-from-congress-to-oncd-ugcPost-7463691310399496192-C1W8">Congress Pushes ONCD on Critical Infrastructure and Cybersecurity Grants</a></h3><p>A bipartisan congressional coalition sent a paper titled &#8220;Reinvigorating Federal Cybersecurity Initiatives&#8221; to the National Cyber Director, urging action across four priorities. </p><p>Finalize the structure replacing CIPAC for critical infrastructure partnerships. Complete CIRCIA rulemaking with public engagement. Reauthorize the Cybersecurity Information Sharing Act of 2015. And reauthorize the State and Local Cybersecurity Grant Program with meaningful appropriations. </p><p>Combined with the CISA credential leak we discussed in last weeks and the ongoing congressional scrutiny, federal cybersecurity governance is under more pressure than at any point since the SolarWinds response. The gap between strategic ambition and operational execution at the federal level continues to widen.</p><h3><a href="https://intelligence.weforum.org/topics/a1GTG0000041UzR2AU">The World Economic Forum Says 94% See AI as the Top Cybersecurity Change Driver</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ngpQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ngpQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png 424w, https://substackcdn.com/image/fetch/$s_!ngpQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png 848w, https://substackcdn.com/image/fetch/$s_!ngpQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png 1272w, https://substackcdn.com/image/fetch/$s_!ngpQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ngpQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png" width="517" height="504.2345679012346" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1106,&quot;width&quot;:1134,&quot;resizeWidth&quot;:517,&quot;bytes&quot;:455038,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ngpQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png 424w, https://substackcdn.com/image/fetch/$s_!ngpQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png 848w, https://substackcdn.com/image/fetch/$s_!ngpQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png 1272w, https://substackcdn.com/image/fetch/$s_!ngpQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff29c5f80-47ae-4c6d-bd10-f2b11cc1f76c_1134x1106.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The WEF Global Cybersecurity Outlook confirms what I have been tracking across every recent issue. 94% of respondents agree AI is the most significant cybersecurity change driver. 77% of organizations already use AI in cybersecurity operations. KPMG reports a 25% boost in threat intelligence efficiency. </p><p>Accenture moved analysis time from 15 minutes to one second. IBM&#8217;s ATOM automates 850+ analyst hours per month. But 87% flagged AI-related vulnerabilities as the fastest-growing risk category, and one-third of organizations have no process to assess AI tool security before deployment. </p><p>The report frames AI as something organizations must treat as a capability rather than a tool. Those that get the distinction right will convert cyber risk into competitive advantage. Those that do not will face threats that scale faster than their defenses.</p><div><hr></div><h3><strong><a href="https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad">[Expert Panel] Mythos: When Perception Becomes Reality</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pX_b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!pX_b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!pX_b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!pX_b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pX_b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png" width="604" height="302" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:604,&quot;bytes&quot;:121289,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!pX_b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!pX_b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!pX_b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!pX_b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee32a89-be16-4408-8843-e3fb590e543d_600x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Exploits used to take weeks to weaponize. With AI, hours. Patch cycles haven&#8217;t moved. CVE-driven prioritization isn&#8217;t keeping up. Brad Arkin (former Chief Trust Officer at Salesforce, Cisco, Adobe) joins Nadav Czerninski (CEO, Oligo) on what your stack actually has to do now.</p><p>You&#8217;ll learn how to prioritize exploitable exposures, move beyond CVE scores, &amp; tighten the window between disclosure and response.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad&quot;,&quot;text&quot;:&quot;-> Watch the recording now <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad"><span>-&gt; Watch the recording now &lt;-</span></a></p><p><em>*Sponsored</em></p><div><hr></div><h1>AI</h1><h3><a href="https://www.anthropic.com/research/glasswing-initial-update">Anthropic Publishes the First Glasswing Numbers and They Redefine the Vulnerability Landscape</a></h3><div id="youtube2-5DPQ3m3e8OE" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;5DPQ3m3e8OE&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/5DPQ3m3e8OE?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The data from Anthropic&#8217;s Glasswing initial update is the most significant vulnerability disclosure event since the creation of the CVE system. In its first month, Claude Mythos Preview identified over 10,000 vulnerabilities, with 6,202 rated high or critical out of 23,019 total findings across 1,000+ open-source projects. 1,726 were assessed as valid true positives at high or critical severity. </p><p>Cloudflare received 2,000 bug reports with 400 at high or critical severity. Mozilla had previously seen 271 Firefox vulnerabilities, a 10x improvement over the prior model. A wolfSSL certificate forgery flaw, CVE-2026-5194 at CVSS 9.1, allows attackers to masquerade as legitimate services. Average patching time for high-severity findings is two weeks, but some open-source maintainers are requesting a slower disclosure pace because the volume exceeds their remediation capacity. </p><p>As I discussed in a prior issue with the Glasswing partner sharing policy, the disclosure pipeline has widened while the remediation bottleneck has not. These numbers put concrete scale behind the crisis I have been tracking since Vulnpocalypse.</p><h3><a href="https://www.linkedin.com/pulse/can-ai-agents-turn-security-vulnerabilities-real-attacks-dawn-song-llmoe">AI Agents Can Now Exploit Real Vulnerabilities, Not Just Find Them</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C1j1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C1j1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png 424w, https://substackcdn.com/image/fetch/$s_!C1j1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png 848w, https://substackcdn.com/image/fetch/$s_!C1j1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!C1j1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C1j1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png" width="1456" height="787" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:787,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:272154,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!C1j1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png 424w, https://substackcdn.com/image/fetch/$s_!C1j1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png 848w, https://substackcdn.com/image/fetch/$s_!C1j1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png 1272w, https://substackcdn.com/image/fetch/$s_!C1j1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15a1d79a-5ac4-478c-b988-03d00867b56e_1884x1018.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Dawn Song&#8217;s team at UC Berkeley released ExploitGym, and the results should change how every defender thinks about the threat timeline. The benchmark comprises 898 instances from real-world vulnerabilities across userspace programs, Google&#8217;s V8 JavaScript engine, and the Linux kernel. </p><p>Claude Mythos Preview successfully exploited 157 of those 898 instances, a 17.5% success rate. GPT-5.5 exploited 120. The exploits remained effective even with standard security defenses like ASLR and V8 sandboxing enabled. This is fundamentally different from the vulnerability discovery story. Finding bugs is one thing. Autonomously converting them into working exploits against production-grade defenses is another. </p><p>Combined with ExploitBench from issue #98 and AISI&#8217;s 4.7-month doubling time, the exploitation capability curve is following the same trajectory as the discovery curve, just with a lag. That lag is the defensive window, and it is shrinking.</p><h3><a href="https://www.uber.com/us/en/blog/solving-the-agent-identity-crisis/">Uber Ships a Full Zero-Trust Identity Architecture for AI Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8-ms!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8-ms!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png 424w, https://substackcdn.com/image/fetch/$s_!8-ms!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png 848w, https://substackcdn.com/image/fetch/$s_!8-ms!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png 1272w, https://substackcdn.com/image/fetch/$s_!8-ms!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8-ms!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png" width="610" height="346.47664835164835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1456,&quot;resizeWidth&quot;:610,&quot;bytes&quot;:1927882,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8-ms!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png 424w, https://substackcdn.com/image/fetch/$s_!8-ms!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png 848w, https://substackcdn.com/image/fetch/$s_!8-ms!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png 1272w, https://substackcdn.com/image/fetch/$s_!8-ms!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9722498-e58d-4da7-8888-111ee7c56627_2166x1230.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the most comprehensive agent identity implementation I have seen from a non-hyperscaler. Uber rebuilt its identity and access technology stack with three components. </p><p>An Agent Registry for centralized agent identity management. An AI Agent Mesh for secure inter-agent communication and authorization, and a Security Token Service that embeds a full attested actor chain into each token, maintaining traceability from the originating user through every intermediate agent. </p><p>The problem they solved is real. Traditional identity models built around humans and workloads fail for agents because execution context gets dropped across agent hops, making it impossible to apply fine-grained access policies or maintain auditable chains. </p><p>As I wrote in my article on identity as the agentic AI problem and with other ecosystem activities such as AAuth, Entra Agent ID, Google Agent Identity, and AWS AgentCore OBO, the building blocks are converging. Uber&#8217;s implementation is the first end-to-end production deployment I have seen that maintains full actor chain attestation across an agent mesh.</p><p>Agentic identity is a topic I went deep into with prior guests, such as industry leader Karl McGuinness</p><div id="youtube2-PbxQwaHinwM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;PbxQwaHinwM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/PbxQwaHinwM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h4><a href="https://www.anthropic.com/engineering/how-we-contain-claude">Anthropic&#8217;s Engineering Team Explains How They Actually Contain Claude</a></h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nPMm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nPMm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png 424w, https://substackcdn.com/image/fetch/$s_!nPMm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png 848w, https://substackcdn.com/image/fetch/$s_!nPMm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png 1272w, https://substackcdn.com/image/fetch/$s_!nPMm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nPMm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png" width="1456" height="469" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:469,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:99888,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nPMm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png 424w, https://substackcdn.com/image/fetch/$s_!nPMm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png 848w, https://substackcdn.com/image/fetch/$s_!nPMm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png 1272w, https://substackcdn.com/image/fetch/$s_!nPMm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb69af149-1f14-48fe-b0c8-7164af5619e9_1994x642.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This engineering deep dive deserves careful reading because it explains why containment, not permission, is the right mental model for agent security. </p><p>Between mid-2025 and January 2026, Anthropic received vulnerability reports through responsible disclosure that included code executing before user consent and malicious .claude/settings.json hook injection. Their response philosophy is to supervise what agents can do, not what they do. </p><p>The implementation uses sandboxes, virtual machines, egress controls, and file access boundaries, but the most revealing data point is about approval fatigue. Users approve approximately 93% of permission prompts. Claude Code&#8217;s Auto Mode was designed specifically to automate safer approvals and reduce friction. </p><p>As I discussed previously with the Sondera analysis and Caleb Sima&#8217;s boring future of agents, the harness and containment layer is where the real security work happens. Anthropic&#8217;s own data confirms that user-in-the-loop approval is necessary but insufficient. Architectural constraints must limit blast radius regardless of user decisions.</p><h3><a href="https://www.microsoft.com/en-us/security/blog/2026/05/20/introducing-rampart-and-clarity-open-source-tools-to-bring-safety-into-agent-development-workflow/">Microsoft Open-Sources Rampart and Clarity for Agent Safety in Development</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QGDg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QGDg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png 424w, https://substackcdn.com/image/fetch/$s_!QGDg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png 848w, https://substackcdn.com/image/fetch/$s_!QGDg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png 1272w, https://substackcdn.com/image/fetch/$s_!QGDg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QGDg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png" width="1456" height="360" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:360,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:612810,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QGDg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png 424w, https://substackcdn.com/image/fetch/$s_!QGDg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png 848w, https://substackcdn.com/image/fetch/$s_!QGDg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png 1272w, https://substackcdn.com/image/fetch/$s_!QGDg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb45c44-bc86-4357-a90d-6347735e8eae_2392x592.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Microsoft&#8217;s philosophy here aligns with what I have been advocating. Safety must become a continuous engineering discipline, not a periodic checkpoint. Rampart is a pytest-native framework that encodes adversarial and benign scenarios as repeatable safety tests, runs in CI/CD pipelines, and creates regression coverage from red team findings and real incidents. </p><p>Clarity is a structured thinking tool for decision tracking and assumption pressure-testing before teams start building, but neither tool is a scanner. They are workflow instruments designed to embed safety into the development process where code originates. </p><p>Combined with Microsoft&#8217;s MDASH, the Foundry Security Spec from Cisco, and Anthropic&#8217;s containment engineering, the major AI infrastructure providers are converging on a shared insight. Agent safety is an engineering problem that requires engineering tools, not governance documents that nobody reads until after the incident.</p><h3><a href="https://adversa.ai/blog/the-approval-prompt-is-lying-to-you-symlink-rce-in-five-ai-coding-agents-claude-code-cursor-antigravity-copilot-grok-build">The Approval Prompt Is Lying to You</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vDHw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vDHw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png 424w, https://substackcdn.com/image/fetch/$s_!vDHw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png 848w, https://substackcdn.com/image/fetch/$s_!vDHw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png 1272w, https://substackcdn.com/image/fetch/$s_!vDHw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vDHw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png" width="1456" height="423" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:423,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1049771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vDHw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png 424w, https://substackcdn.com/image/fetch/$s_!vDHw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png 848w, https://substackcdn.com/image/fetch/$s_!vDHw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png 1272w, https://substackcdn.com/image/fetch/$s_!vDHw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F26645896-3aeb-4188-9fb2-cd9973949b1b_2050x596.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Adversa AI found a vulnerability class that defeats the primary safety control in five major AI coding agents. Claude Code, Cursor Agent CLI, GitHub Copilot CLI, Gemini CLI, and Grok Build are all affected. </p><p>The attack, dubbed SymJack, works by weaponizing symlinked destinations in malicious repositories. When a victim approves a copy operation that looks benign, the symlink secretly overwrites the agent&#8217;s configuration files. The human approval step, the control that every vendor leans on as the foundation of safety, is the vulnerability being exploited. Anthropic hardened its approval flow after disclosure. Google and Cursor declined to patch. xAI and GitHub have not responded. </p><p>Combined with IDEsaster and IDEsaster2, the pattern is unmistakable. The development environment is the new attack surface, and the safety mechanisms designed to protect developers are themselves exploitable. As I wrote in my coverage of the OWASP Agentic Top 10, defense-in-depth is the only viable path when individual controls can be bypassed.</p><h3><a href="https://assury.ai/blog/jit-wont-save-your-agent">JIT Credentials Alone Will Not Secure Your Agents</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zaIc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zaIc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png 424w, https://substackcdn.com/image/fetch/$s_!zaIc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png 848w, https://substackcdn.com/image/fetch/$s_!zaIc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png 1272w, https://substackcdn.com/image/fetch/$s_!zaIc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zaIc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png" width="1286" height="140" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1de43544-f954-4b62-a389-a968f76dade9_1286x140.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:140,&quot;width&quot;:1286,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:36284,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zaIc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png 424w, https://substackcdn.com/image/fetch/$s_!zaIc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png 848w, https://substackcdn.com/image/fetch/$s_!zaIc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png 1272w, https://substackcdn.com/image/fetch/$s_!zaIc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1de43544-f954-4b62-a389-a968f76dade9_1286x140.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Assury&#8217;s argument connects to a theme I have been building across the last several issues. Just-in-time credential management is necessary but insufficient for agent security. </p><p>JIT addresses the credential lifecycle, granting permissions only for the required duration, but it does not address what agents do with those permissions while they hold them. Assury&#8217;s Enforce platform adds OPA-based granular policy with policy-as-code using Rego, tenant scoping, and custom rules on top of JIT credentials. The broader point resonates with Anthropic&#8217;s containment philosophy from their engineering post this week. Single controls, whether JIT, approval prompts, or permission boundaries, are individually bypassable. </p><p>The organizations getting agent security right are the ones layering multiple controls. JIT for credential lifecycle, policy-as-code for runtime behavior, audit trails for accountability, and containment for blast radius. No single layer is sufficient on its own.</p><h3><a href="https://genai.owasp.org/resource/aiuc-1-crosswalks-owasp-top-10-for-agentic-applications/">OWASP Maps AIUC-1 to the Agentic Top 10 and the Gaps Are Revealing</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iM2N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iM2N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png 424w, https://substackcdn.com/image/fetch/$s_!iM2N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png 848w, https://substackcdn.com/image/fetch/$s_!iM2N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png 1272w, https://substackcdn.com/image/fetch/$s_!iM2N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iM2N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png" width="1456" height="253" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:253,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128744,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iM2N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png 424w, https://substackcdn.com/image/fetch/$s_!iM2N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png 848w, https://substackcdn.com/image/fetch/$s_!iM2N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png 1272w, https://substackcdn.com/image/fetch/$s_!iM2N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6c4bebd-e248-443b-8740-b4b4f1ec5361_2026x352.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>For those following my work on the OWASP Agentic Top 10, this crosswalk between AIUC-1 and the Agentic Top 10 provides the most detailed gap analysis to date. The bidirectional mapping covers agent goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, insecure inter-agent communication, cascading failures, trust exploitation, and rogue agents. </p><p>Eight priority areas for AIUC-1 enhancement were identified, with the most significant gaps in agent identity, runtime containment, architectural monitoring, supply chain attestation, and schema controls. The crosswalk confirms what I have been arguing since my earliest writing on the Agentic Top 10. Current compliance frameworks were not designed for autonomous agent systems. The mapping is the first step toward closing that gap.</p><h3><a href="https://www.primesec.ai/resources/www-primesec-ai-resources-most-developers-will-not-understand-security-in-5-years">Most Developers Will Not Understand Security in Five Years, and That Is the Wrong Problem to Solve</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TGxP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TGxP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png 424w, https://substackcdn.com/image/fetch/$s_!TGxP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png 848w, https://substackcdn.com/image/fetch/$s_!TGxP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png 1272w, https://substackcdn.com/image/fetch/$s_!TGxP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TGxP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png" width="1456" height="425" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:425,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136066,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TGxP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png 424w, https://substackcdn.com/image/fetch/$s_!TGxP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png 848w, https://substackcdn.com/image/fetch/$s_!TGxP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png 1272w, https://substackcdn.com/image/fetch/$s_!TGxP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d329e6d-b933-4ca6-9434-01caa5d8a8ed_1624x474.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>PrimeSec&#8217;s framing resonates with what I have been writing since Security Throwing Toil Over the Fence. The security bottleneck has gotten 5x worse as development velocity increases and AI coding tools explode. Security teams can only manually review 5-10% of development work. </p><p>The answer is not expecting developers to become security experts. It is embedding AI-driven security guidance directly into developer workflows. As I wrote in Vulnerability Management and Developer Toil, the Linux Foundation study called security a &#8220;soul withering chore&#8221; for developers. Rather than fighting that reality, the pragmatic response is to democratize security knowledge and embed it where the code originates. </p><p>Combined with Microsoft&#8217;s Rampart, SecureForge, and Anthropic&#8217;s containment engineering, the tools to make this possible are arriving faster than the organizational change required to adopt them.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://www.crowdstrike.com/en-us/blog/inside-crowdstrike-takedown-of-a-developer-targeting-botnet/">CrowdStrike and Google Take Down the Glassworm Botnet Targeting Developers</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gKDQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gKDQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png 424w, https://substackcdn.com/image/fetch/$s_!gKDQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png 848w, https://substackcdn.com/image/fetch/$s_!gKDQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png 1272w, https://substackcdn.com/image/fetch/$s_!gKDQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gKDQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png" width="1456" height="180" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:180,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gKDQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png 424w, https://substackcdn.com/image/fetch/$s_!gKDQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png 848w, https://substackcdn.com/image/fetch/$s_!gKDQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png 1272w, https://substackcdn.com/image/fetch/$s_!gKDQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5aabe713-bbfd-452a-8395-1a9924815f7c_1858x230.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>This is the supply chain attack story that brings everything together. On May 26 at 14:00 UTC, CrowdStrike, Google, and the Shadowserver Foundation executed a coordinated simultaneous strike against four Glassworm command-and-control channels. </p><p>Active since early 2025, Glassworm targeted software developers with source code and CI/CD access through three vectors. Malicious VSCode extensions. Poisoned npm and Python packages with postinstall hooks. And over 300 weaponized GitHub repositories. GlasswormRAT delivered information theft, credential harvesting, and full remote access across Windows, macOS, and Linux. The infrastructure used Solana blockchain, BitTorrent P2P, and Google Calendar for C2 communication. </p><p>As I wrote in <em>Software Transparency</em> and tracked across issues with PyTorch Lightning, Mini Shai-Hulud, and the TeamPCP open-sourcing of the Shai-Hulud worm, the threat actors are not targeting products anymore. They are targeting the developers who build them. Every compromised development environment is a supply chain entry point that propagates downstream to billions of users.</p><h3><a href="https://daniel.haxx.se/blog/2026/05/26/the-pressure/">Daniel Stenberg Documents the Human Cost of AI-Driven Vulnerability Discovery</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eibh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eibh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png 424w, https://substackcdn.com/image/fetch/$s_!eibh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png 848w, https://substackcdn.com/image/fetch/$s_!eibh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png 1272w, https://substackcdn.com/image/fetch/$s_!eibh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eibh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png" width="796" height="242" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:242,&quot;width&quot;:796,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28036,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eibh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png 424w, https://substackcdn.com/image/fetch/$s_!eibh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png 848w, https://substackcdn.com/image/fetch/$s_!eibh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png 1272w, https://substackcdn.com/image/fetch/$s_!eibh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faff71015-c6b7-49ca-aa2f-a768bfbf6e58_796x242.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I have been tracking Daniel Stenberg&#8217;s experience with Mythos, and this week&#8217;s post, titled simply &#8220;The Pressure,&#8221; is the most personal and concerning entry yet. curl is receiving security reports at 4-5x the rate of 2024 and 2x the rate of 2025, averaging more than one report per day. </p><p>Quality has significantly improved, the reports are detailed and comprehensive, but at the halfway point of the current release cycle, the project has already confirmed 12 vulnerabilities, on pace for 30 published CVEs in 2026. Stenberg describes an imbalanced work-life situation under sustained high workload. This is not a story about AI capability, it is a story about what happens to the humans maintaining critical infrastructure when AI accelerates the discovery pipeline beyond their capacity to process it. </p><p>As I wrote about with VulnCheck&#8217;s first CVE wave, AI-assisted discovery is a permanent increase in velocity. The downstream human systems were never built for this pace.</p><h3><a href="https://www.contrastsecurity.com/security-influencers/the-hidden-cost-of-ai-security-scanners">Contrast Security Quantifies the True Cost of AI Security Scanning</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OyeJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OyeJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png 424w, https://substackcdn.com/image/fetch/$s_!OyeJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png 848w, https://substackcdn.com/image/fetch/$s_!OyeJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png 1272w, https://substackcdn.com/image/fetch/$s_!OyeJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OyeJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png" width="1456" height="427" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:427,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:313203,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OyeJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png 424w, https://substackcdn.com/image/fetch/$s_!OyeJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png 848w, https://substackcdn.com/image/fetch/$s_!OyeJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png 1272w, https://substackcdn.com/image/fetch/$s_!OyeJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbac74f6-137a-4e08-b56b-89f7fc10571a_1502x440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If there is one piece this week that should be required reading for anyone evaluating AI scanning tools, this is it. Contrast Labs tested three AI scanning approaches against enterprise Java codebases and the economics are brutal. </p><p>A simple Sonnet scan reproduced only 17% of its findings across three runs. Claude Opus improved to 25% but showed a 28.6% swing between best and worst runs. Of 59 total findings, only 3, or 5%, were identified by all three tools. The headline number is that a $315 scanning fee translates into $128,000 in triage burden before the first fix. </p><p>AI scanning is valuable against certain problem classes like authorization logic, but using it as the foundation of a production AppSec program creates more work than it eliminates. As I have been writing since Vulnerability Management and Developer Toil, tools that generate volume without context are the definition of security theater, and yes, that can apply to using AI tooling too.</p><h4><a href="https://www.wiz.io/reports/sdlc-security-report-2026">Wiz Maps the Power-Law Distribution of SDLC Risk</a></h4><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L2X6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L2X6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png 424w, https://substackcdn.com/image/fetch/$s_!L2X6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png 848w, https://substackcdn.com/image/fetch/$s_!L2X6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png 1272w, https://substackcdn.com/image/fetch/$s_!L2X6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L2X6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png" width="1096" height="262" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:262,&quot;width&quot;:1096,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47890,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L2X6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png 424w, https://substackcdn.com/image/fetch/$s_!L2X6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png 848w, https://substackcdn.com/image/fetch/$s_!L2X6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png 1272w, https://substackcdn.com/image/fetch/$s_!L2X6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e7dbbb6-eda0-46c2-8f69-a3685e718907_1096x262.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Wiz&#8217;s SDLC Security Report makes an argument that I think is underappreciated. Risk follows a power-law distribution in software development environments. A small set of packages gets disproportionately reused, and weaknesses in that concentrated set propagate across entire organizations. </p><p>CI/CD pipelines, identity systems, developer tooling, and automation platforms create systemic exposure when trust and reuse concentrate. The report argues that organizations should focus on where trust concentrates rather than chasing isolated findings. </p><p>This connects to the supply chain thesis I have been tracking since <em>Software Transparency</em> and reinforces why the Glassworm takedown this week matters so much. When adversaries compromise the development infrastructure that sits at the center of the trust graph, the blast radius is not a single application. It is everything downstream.</p><h3><a href="https://novee.security/blog/novee-agentic-fix-automated-vulnerability-remediation">Novee Bridges the Gap Between Discovery and Remediation with Agentic Fix</a></h3><p>I have been tracking the discovery-remediation gap since Vulnpocalypse, and Novee&#8217;s Agentic Fix takes a different approach than most. Rather than building another scanner, Novee translates validated exploits from penetration testing directly into GitHub issues formatted for AI coding agents. </p><p>The platform is compatible with Claude, Copilot, Cursor, and Devin. The company raised $51.5 million within four months of inception, led by YL Ventures, Canaan Partners, and Zeev Ventures. The founding team includes national-level offensive security leaders. What makes this interesting is the directional bet. Instead of trying to fix the discovery problem, which AI has largely solved, </p><p>Novee is attacking the remediation bottleneck by feeding validated exploit context directly to the agents that write fixes. As I discussed with AISLE&#8217;s VulnOps model, the value chain is shifting from discovery to remediation, and the companies that close that loop will define the next era of vulnerability management.</p><h3><a href="https://www.provos.org/p/day-after-the-zero-days/">Niels Provos on Building Invariants for the Day After the Zero-Days</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HYPQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HYPQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png 424w, https://substackcdn.com/image/fetch/$s_!HYPQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png 848w, https://substackcdn.com/image/fetch/$s_!HYPQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png 1272w, https://substackcdn.com/image/fetch/$s_!HYPQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HYPQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png" width="1456" height="317" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:317,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71804,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HYPQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png 424w, https://substackcdn.com/image/fetch/$s_!HYPQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png 848w, https://substackcdn.com/image/fetch/$s_!HYPQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png 1272w, https://substackcdn.com/image/fetch/$s_!HYPQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe852b4ee-ddad-4ba9-9ccb-9e5705d35db3_1514x330.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Niels Provos delivered this talk at the CSA AI Summit on April 7, 2026, twelve years to the day after the OpenSSL Heartbleed disclosure. His central argument is that security strategy must shift from detecting zero-days to containing their impact through invariants built at the hardware and data layers. </p><p>2FA, default-deny egress, allowlisted execution, memory tagging, and context-aware access control create boundaries that hold even when the vulnerability is novel. Anthropic&#8217;s Mythos agent surfaced a bug in OpenBSD code from 27 years prior, which illustrates the point. If your security depends on finding every vulnerability before an attacker does, you have already lost. </p><p>The organizations that survive the next zero-day will be the ones that built containment in time. This aligns with Anthropic&#8217;s containment philosophy from their engineering post this week and with AISI&#8217;s 4.7-month capability doubling.</p><h3><a href="https://github.com/perplexityai/bumblebee">Perplexity Open-Sources Bumblebee for Supply Chain Scanning Without Execution</a></h3><p>Perplexity released its internal supply chain security scanner as open source on May 22, and the design philosophy matters as much as the functionality. Bumblebee is written entirely in Go with zero non-stdlib dependencies. </p><p>It earned 1,450+ GitHub stars and 112+ forks in less than a week. The core principle is &#8220;never execute anything.&#8221; It reads lockfiles directly without invoking npm, pip, bun, or any package manager. It never runs postinstall scripts, which are the primary attack vector in supply chain compromises like Mini Shai-Hulud. </p><p>The scanner covers npm, pnpm, Yarn, Bun, PyPI, Go modules, RubyGems, Composer, MCP configurations, editor extensions, and browser extensions. For security teams dealing with the Glassworm-style developer targeting described above, a read-only inventory tool that cannot trigger the attack vectors it is scanning for is exactly the right design.</p><h3><a href="https://www.linkedin.com/posts/helloamychang_aisecurity-llmsecurity-airedteaming-activity-7465435213037400064-bsGt">Cisco&#8217;s LLM Security Leaderboard Brings Transparency to Model Risk Evaluation</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZeTL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZeTL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png 424w, https://substackcdn.com/image/fetch/$s_!ZeTL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png 848w, https://substackcdn.com/image/fetch/$s_!ZeTL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png 1272w, https://substackcdn.com/image/fetch/$s_!ZeTL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZeTL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png" width="1456" height="712" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:712,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:606953,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198409181?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZeTL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png 424w, https://substackcdn.com/image/fetch/$s_!ZeTL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png 848w, https://substackcdn.com/image/fetch/$s_!ZeTL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png 1272w, https://substackcdn.com/image/fetch/$s_!ZeTL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07570c31-6dee-4ab9-86aa-6315773bf3b0_2850x1394.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Amy Chang&#8217;s work at Cisco on LLM adversarial evaluation addresses a gap I have been pointing to across multiple issues. How do you compare the security posture of different LLMs before selecting one for production? </p><p>Cisco&#8217;s LLM Security Leaderboard evaluates model susceptibility to malicious prompts, jailbreak attempts, and manipulation strategies. This is the kind of practical tooling that security teams need when the procurement decision includes choosing which model to deploy. Combined with Anthropic&#8217;s containment engineering, Microsoft&#8217;s Rampart, and ExploitBench. The ecosystem for measuring and testing AI security is rapidly maturing. </p><p>The question is whether organizations adopt these evaluation frameworks before or after the first breach involving a poorly chosen model.</p><h3><a href="https://blog.sondera.ai/p/agent-pbj-problem">The Sondera Agent PBJ Problem and Post-Prompt Policy Enforcement</a></h3><p>Sondera&#8217;s framing of the &#8220;PBJ problem&#8221; connects to the broader shift from prompt-level safety to architectural enforcement that I have been tracking. The argument is that agent governance cannot depend on what happens at the prompt layer. </p><p>It must enforce policies after the prompt, during execution, through deterministic control planes. Sondera implements this through Cedar Policy Language integration that hooks into coding agents at the API level, providing enforcement for Claude, Cursor, Gemini, and other tools. </p><p>As Anthropic&#8217;s containment engineering post confirmed this week, 93% of user permission prompts get approved. When the human-in-the-loop approval rate is that high, the approval step is not providing meaningful security. Post-prompt policy enforcement that operates regardless of user decisions is the architecture that actually reduces risk.</p><div><hr></div><h1>Final Thoughts</h1><p>This was the week that numbers replaced narratives. </p><p>Anthropic disclosed 10,000+ vulnerabilities from Glasswing&#8217;s first month. Dawn Song showed Mythos exploiting 17.5% of real-world vulnerabilities autonomously. VulnCheck documented CVE surges of 563% from AI-assisted discovery. </p><p>Contrast Security proved that AI scanning creates $128,000 in triage burden per $315 in scanning cost. Daniel Stenberg documented the human toll of receiving more than one security report per day against a 30-year-old codebase. And HackerOne slashed bounty rewards by 75%.</p><p>The story these numbers tell is consistent. The discovery problem is solved. AI finds vulnerabilities at a rate that exceeds every downstream system&#8217;s capacity to process them. The remediation problem, the prioritization problem, the human sustainability problem, and the economic incentive problem are all wide open.</p><p>The most encouraging developments this week were the ones that address those open problems. Uber&#8217;s agent identity architecture with attested actor chains. Anthropic&#8217;s containment engineering that supervises capabilities rather than individual actions. </p><p>Microsoft&#8217;s Rampart and Clarity for embedding safety into development workflows. Novee&#8217;s Agentic Fix that feeds validated exploits directly to coding agents. Perplexity&#8217;s Bumblebee that scans supply chains without executing anything. These are engineering solutions to engineering problems, and that is exactly what this moment requires.</p><blockquote><p><strong>Stay resilient.</strong></p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Receipts Are In]]></title><description><![CDATA[Walking through Anthropic's Project Glasswing Update]]></description><link>https://www.resilientcyber.io/p/the-receipts-are-in</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-receipts-are-in</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 25 May 2026 12:03:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xZfY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>For almost the past year, I&#8217;ve argued that the economics of vulnerability discovery are collapsing toward zero cost while remediation stays human-bound, that the NVD and the open-source maintainer ecosystem can&#8217;t absorb the flood, and that AI cyber capability is doubling on a months-long clock. Anthropic&#8217;s <strong><a href="https://www.anthropic.com/research/glasswing-initial-update">Project Glasswing initial update</a></strong>, published May 22, is the first large-scale empirical confirmation of all three.</p><p>Roughly 50 partners running Anthropic&#8217;s Mythos Preview model found over 10,000 high-and-critical-severity vulnerabilities in approximately one month. Several reported that their rate of bug finding increased by <em><strong>more than a factor of ten</strong></em>, and Anthropic&#8217;s own framing states the thesis almost verbatim, that &#8220;<em>progress on software security used to be limited by how quickly we could find new vulnerabilities</em>&#8221; and &#8220;<em>is now limited by how quickly we can verify, disclose, and patch</em>&#8221; them. In short, remediation is (and has been) the bottleneck, and now driven by AI is more problematic than ever.</p><p>This is not a new argument from me. It&#8217;s a collection on predictions I already made, the data just got a lot harder to argue with.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>What Glasswing Actually Reported</h2><p>Glasswing is Anthropic&#8217;s coordinated effort to apply its Mythos-class vulnerability research model across both commercial partners and open-source projects. </p><p>The update covers roughly one month of activity and includes results from partners like Cloudflare, Mozilla, Palo Alto Networks, Microsoft, and Oracle, alongside an independent open-source scanning effort.</p><p>The partner-side numbers are striking. Cloudflare <strong><a href="https://blog.cloudflare.com/cyber-frontier-models/">found 2,000 bugs</a></strong>, 400 of which were high or critical severity, with a false-positive rate that Cloudflare&#8217;s own team considers better than human testers. Mozilla <strong><a href="https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/">found</a></strong> and fixed 271 vulnerabilities in Firefox 150, over ten times more than they found in Firefox 148 using Claude Opus 4.6. Palo Alto Networks <strong><a href="https://www.paloaltonetworks.com/blog/security-operations/how-mythos-class-models-change-exposure-management/">shipped over five times</a></strong> as many patches as usual. Microsoft <strong><a href="https://www.microsoft.com/en-us/security/blog/2026/04/22/ai-powered-defense-for-an-ai-accelerated-threat-landscape/">reported</a></strong> that patch volumes will continue trending larger for some time.</p><p>On the open-source side, the model identified 23,019 total vulnerabilities across more than 1,000 projects, with 6,202 estimated as high or critical severity. Of the 1,752 that independent security firms assessed, 90.6% were confirmed as valid true positives and 62.4% confirmed as genuinely high or critical. That puts the project on track to surface approximately 3,900 confirmed high-and-critical vulnerabilities in open-source software from this single scan.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xZfY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xZfY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png 424w, https://substackcdn.com/image/fetch/$s_!xZfY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png 848w, https://substackcdn.com/image/fetch/$s_!xZfY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png 1272w, https://substackcdn.com/image/fetch/$s_!xZfY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xZfY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png" width="589" height="393.13805522208884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:556,&quot;width&quot;:833,&quot;resizeWidth&quot;:589,&quot;bytes&quot;:145589,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199058473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xZfY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png 424w, https://substackcdn.com/image/fetch/$s_!xZfY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png 848w, https://substackcdn.com/image/fetch/$s_!xZfY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png 1272w, https://substackcdn.com/image/fetch/$s_!xZfY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff24eb87a-ce6b-45ce-bee5-364ed0bbd283_833x556.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The UK AI Safety Institute<strong><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities"> independently validated</a></strong> that Mythos Preview is the first model to solve both of their cybersecurity evaluation ranges end to end. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UZUf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UZUf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png 424w, https://substackcdn.com/image/fetch/$s_!UZUf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png 848w, https://substackcdn.com/image/fetch/$s_!UZUf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png 1272w, https://substackcdn.com/image/fetch/$s_!UZUf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UZUf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png" width="595" height="343.1544633901705" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:575,&quot;width&quot;:997,&quot;resizeWidth&quot;:595,&quot;bytes&quot;:159275,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199058473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UZUf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png 424w, https://substackcdn.com/image/fetch/$s_!UZUf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png 848w, https://substackcdn.com/image/fetch/$s_!UZUf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png 1272w, https://substackcdn.com/image/fetch/$s_!UZUf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4f68c367-631a-43f1-90df-98fd39c6ffb9_997x575.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One partner bank reported that Mythos Preview helped detect and prevent a fraudulent $1.5 million wire transfer, and the wolfSSL certificate-forgery vulnerability the model discovered, assigned CVE-2026-5194, demonstrated that Mythos can not only find bugs but construct working exploits against real cryptographic libraries.</p><h2>Validating Expectations</h2><p>I want to walk through the specific prior arguments that Glasswing&#8217;s data confirms, because the value here isn&#8217;t in the novelty of the findings, it&#8217;s in the structural pattern they validate.</p><h3>The Flood</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uJLy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uJLy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png 424w, https://substackcdn.com/image/fetch/$s_!uJLy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png 848w, https://substackcdn.com/image/fetch/$s_!uJLy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png 1272w, https://substackcdn.com/image/fetch/$s_!uJLy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uJLy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png" width="1111" height="620" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:620,&quot;width&quot;:1111,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1314063,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199058473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uJLy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png 424w, https://substackcdn.com/image/fetch/$s_!uJLy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png 848w, https://substackcdn.com/image/fetch/$s_!uJLy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png 1272w, https://substackcdn.com/image/fetch/$s_!uJLy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe225fa3b-0563-47a8-a171-09c42eefe89b_1111x620.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In <strong><a href="https://www.resilientcyber.io/p/vulnpocalypse-ai-open-source-and">Vulnpocalypse</a></strong>, I laid out the case that AI-accelerated vulnerability discovery would overwhelm every downstream system the industry depends on for triage, enrichment, and remediation. The argument was structural, not speculative due to the widespread systemic impacts of AI-driven vulnerability industrialization. </p><blockquote><p><strong>If the cost of finding vulnerabilities drops to near zero while the cost of fixing them stays constant, the backlog doesn&#8217;t grow linearly, it compounds. </strong></p></blockquote><p>Glasswing&#8217;s 10,000-in-a-month result against commercial targets, combined with the 6,200 high-and-critical findings in open source, is exactly the flood I described. Nicolas Carlini&#8217;s research estimating that AI vulnerability research capability doubles roughly every four months makes these numbers a floor, not a ceiling, especially as model improvements continue to compound with each release.</p><h3>The Capability Curve</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LwFe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LwFe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png 424w, https://substackcdn.com/image/fetch/$s_!LwFe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png 848w, https://substackcdn.com/image/fetch/$s_!LwFe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png 1272w, https://substackcdn.com/image/fetch/$s_!LwFe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LwFe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png" width="1068" height="648" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:1068,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:225005,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199058473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LwFe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png 424w, https://substackcdn.com/image/fetch/$s_!LwFe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png 848w, https://substackcdn.com/image/fetch/$s_!LwFe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png 1272w, https://substackcdn.com/image/fetch/$s_!LwFe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F160e434c-fd8b-4a00-8f43-b214bdec5136_1068x648.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In <strong><a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">The AI Cyber Capability Curve</a></strong>, I argued that offensive AI capability was tracking an exponential improvement curve and that defenders needed to plan for capability levels that didn&#8217;t exist yet but were months away from arriving. </p><p>The UK AISI&#8217;s confirmation that Mythos Preview is the first model to solve both of their cyber ranges end to end, followed by GPT-5.5 shortly after is exactly the kind of step-function capability jump that curve predicts. These evaluation ranges were designed to be hard. A model cleared them entirely, and the next generation will be better still.</p><h3>The NVD and Maintainer Collapse</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KRmx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KRmx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png 424w, https://substackcdn.com/image/fetch/$s_!KRmx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png 848w, https://substackcdn.com/image/fetch/$s_!KRmx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png 1272w, https://substackcdn.com/image/fetch/$s_!KRmx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KRmx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png" width="1175" height="641" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:641,&quot;width&quot;:1175,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1258361,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199058473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KRmx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png 424w, https://substackcdn.com/image/fetch/$s_!KRmx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png 848w, https://substackcdn.com/image/fetch/$s_!KRmx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png 1272w, https://substackcdn.com/image/fetch/$s_!KRmx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39881ea2-9302-417f-bd02-22432e3d4e06_1175x641.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In <strong><a href="https://www.resilientcyber.io/p/the-nvd-just-threw-in-the-towel-now">The NVD Just Threw in the Towel</a></strong>, I documented how NIST reclassified approximately 29,000 backlogged CVEs to &#8220;Not Scheduled,&#8221; effectively conceding that the system can&#8217;t keep pace with the current volume of incoming vulnerabilities, let alone an AI-accelerated one. </p><p>Glasswing&#8217;s open-source results now put concrete pressure on that already-broken system. The project disclosed 530 high-and-critical bugs to open-source maintainers in roughly a month, and maintainers responded exactly the way you&#8217;d expect an already-overloaded system to respond. Some asked Anthropic to slow down.</p><p>That last detail is the most telling data point in the entire update. Maintainers aren&#8217;t asking for better vulnerability reports. They&#8217;re asking for fewer of them. </p><blockquote><p><strong>The system&#8217;s constraint isn&#8217;t information (findings), it&#8217;s human capacity to act on information (remediation).</strong></p></blockquote><h2>The Bottleneck Moved and the Crisis Didn&#8217;t</h2><p>Glasswing&#8217;s patch-side data confirms the remediation crisis I&#8217;ve been tracking across multiple pieces. The average time to patch a high-or-critical bug disclosed through the project was two weeks. Only 75 of the 530 disclosed high-and-critical vulnerabilities have been patched so far, with just 65 receiving public advisories. That means less than 15% of the high-and-critical vulnerabilities Glasswing&#8217;s efforts have help expose are remediated. </p><p>This is relevant because it highlights the remediation bottleneck and also due to the fact that others, including malicious actors, are looking with alternative models and most certainly finding vulnerabilities.</p><p>Those numbers need context. The industry was already running a remediation deficit before AI-accelerated discovery entered the picture. FIRST projected a median of approximately 59,000 new CVEs for 2025, a roughly 50% increase over the prior year.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yx2R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yx2R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png 424w, https://substackcdn.com/image/fetch/$s_!yx2R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png 848w, https://substackcdn.com/image/fetch/$s_!yx2R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png 1272w, https://substackcdn.com/image/fetch/$s_!yx2R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yx2R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png" width="245" height="363.2758620689655" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:473,&quot;width&quot;:319,&quot;resizeWidth&quot;:245,&quot;bytes&quot;:90668,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/199058473?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yx2R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png 424w, https://substackcdn.com/image/fetch/$s_!yx2R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png 848w, https://substackcdn.com/image/fetch/$s_!yx2R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png 1272w, https://substackcdn.com/image/fetch/$s_!yx2R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc24bed76-2dcb-424d-84c9-97c3ab812373_319x473.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The 2026 DBIR showed that only 26% of critical KEV vulnerabilities were fully remediated, with a 43-day median to resolution, and the exploitation timeline has collapsed in the opposite direction. Sergej Epp&#8217;s Zero Day Clock research tracked the median time-to-exploit falling from 771 days in 2018 to roughly four hours by 2024.</p><blockquote><p><strong>The math is straightforward and unfavorable. Defenders measure their remediation timelines in weeks and months, attackers measure their exploitation timelines in hours. </strong></p></blockquote><p>Now the rate of vulnerability discovery has jumped by a factor of ten or more for organizations using Mythos-class models or even open source and alternative models coupled with effective harness engineering. The backlog doesn&#8217;t just grow, it grows faster than any organization&#8217;s ability to process it, which means the effective window of exploitability for every discovered vulnerability is expanding rather than shrinking.</p><p>Anthropic&#8217;s own <strong><a href="https://www.anthropic.com/product/security">Claude Security</a></strong> illustrates the asymmetry. Enterprise users patched 2,100 vulnerabilities in three weeks using the tool, a pace that looks fast only because enterprises fix their own code and skip the coordinated disclosure process entirely.</p><p>For open-source maintainers who don&#8217;t control the deployment environment and who rely on downstream consumers to actually apply the patch, the timeline stretches dramatically, and the 75-of-530 number is the honest measure of where the ecosystem actually stands.</p><h2>The Skeptic&#8217;s Read</h2><p>I&#8217;ve been critical of AI hype cycles in security throughout this newsletter and blog, including in <strong><a href="https://www.resilientcyber.io/p/securitys-ai-driven-dilemma">Security&#8217;s AI-Driven Dilemma</a></strong>, and I don&#8217;t intend to turn off that filter because the data happens to be compelling. There are several things practitioners should hold with appropriate skepticism.</p><p>The &#8220;<em>too dangerous to release</em>&#8221; framing around Mythos serves dual purposes. It is genuinely responsible to withhold a model that can find thousands of critical vulnerabilities per month from general availability, that said it is also a competitive moat. </p><p>Anthropic has first-mover advantage with a capability that it openly states will be available from multiple labs soon, and the window during which it&#8217;s the only organization with that capability is a strategic asset, the same applies to security vendors who have been part of the gated release. Both things can be true simultaneously, and the responsible thing for practitioners is to evaluate the data on its merits while recognizing the incentive structure behind the framing.</p><p>The 90.6% true-positive rate deserves scrutiny in terms of generalizability. That number comes from a triaged sample of 1,752 vulnerabilities assessed by independent security firms. </p><p>Whether that rate holds across the full 23,019 findings, or across different codebases and vulnerability classes, is a question the update doesn&#8217;t fully answer. A false-positive rate <em>better than human testers</em>, as Cloudflare reported, is meaningful, but the comparison benchmark matters. Human testers vary enormously in quality, and &#8220;<em>better than human testers</em>&#8221; at one organization may mean something very different at another.</p><p>The enterprise patching speed also needs honest framing. Two thousand vulnerabilities patched in three weeks sounds fast until you recognize that enterprise teams patching their own proprietary code have fundamentally different dynamics than open-source maintainers who are often unpaid, understaffed, and managing projects in their spare time. The speed difference isn&#8217;t a technology gap, it&#8217;s a resource and incentive gap, and AI-accelerated discovery doesn&#8217;t change the resource equation on the maintainer side at all.</p><p>And the most uncomfortable admission in the update is that even a throttled, carefully managed disclosure pace is adding load to an already-overloaded ecosystem. If Anthropic is disclosing responsibly and maintainers are still asking for a slowdown, the implication is clear. </p><blockquote><p><strong>The system as currently designed cannot absorb AI-scale vulnerability discovery regardless of how carefully you manage the pipeline. </strong></p></blockquote><p>Coordinated disclosure norms were built for a world where finding vulnerabilities was hard and slow, and that world doesn&#8217;t exist anymore.</p><h2>What Defenders Do Now</h2><p>The structural reforms I&#8217;ve argued for in prior pieces aren&#8217;t theoretical anymore, Glasswing puts empirical weight behind each of them.</p><p>Patch cycles need to compress dramatically. A two-week median for a high-severity fix was acceptable when the discovery rate was measured in dozens per quarter. At thousands per month, two weeks is too slow for the most critical findings and completely unworkable for the long tail. Organizations that can&#8217;t move to continuous deployment for security patches will be running an ever-expanding window of exploitable exposure.</p><p>Reachability-based prioritization becomes non-negotiable. When the volume of incoming vulnerabilities jumps by 10x, the only viable triage strategy is to focus on what&#8217;s actually reachable and exploitable in your specific environment rather than treating every high-CVSS finding as equally urgent. </p><p>As I wrote in <strong><a href="https://www.resilientcyber.io/p/vulnerability-management-in-the-age">Vulnerability Management in the Age of AI-Accelerated Everything</a></strong>, Endor Labs&#8217; research found that 92% of critical open-source vulnerabilities flagged by traditional scanners aren&#8217;t actually reachable in the application context. That 92% noise figure becomes the difference between a manageable workload and an impossible one when the denominator increases by an order of magnitude.</p><p>Memory-safe language mandates gain urgency with every one of these reports. A significant portion of the vulnerabilities AI models find are memory safety issues in C and C++ codebases, the same vulnerability class that&#8217;s been generating CVEs for decades. The structural fix is to stop writing new code in memory-unsafe languages, a position leaders such as Jen Easterly and Bob Lord advocated for during their tenure at CISA, and one that Glasswing&#8217;s data makes even harder to argue against.</p><p>Others, such as longtime security practitioner and leader Neils Provos have penned great articles such as &#8220;<strong><a href="https://www.provos.org/p/day-after-the-zero-days/">The Day After the Zero Days</a></strong>&#8221; pointing out that &#8220;patch faster&#8221; cannot keep up with AI-driven discovery, and instead argues for &#8220;structural invariants&#8221; to make bug classes irrelevant.</p><p>Niels states:</p><blockquote><p><strong>&#8221;The response is not to find bugs faster. It is to build infrastructure that takes attack classes off the critical path of ongoing human security decisions.&#8221;</strong></p></blockquote><p>The broader incentive question remains untouched as well. As Bruce Schneier has <strong><a href="https://dukakis.org/news-and-events/bruce-schneier-real-iot-security-can-only-be-achieved-through-regulation-by-the-government/">argued repeatedly</a></strong>, no industry in history has improved its safety practices without being forced to through regulation or liability. </p><p>The software industry&#8217;s current incentive structure rewards shipping fast over shipping secure, and nothing about AI-accelerated vulnerability discovery changes that calculus for the vendors producing the vulnerable software in the first place. If anything, it widens the gap between the organizations that can afford to respond and the ones that can&#8217;t.</p><p>That said, we&#8217;re currently in a deregulatory environment with the current U.S. presidential administration, and as others such as Jim Dempsey have <strong><a href="https://www.lawfaremedia.org/article/cyber-liability-fight-begins">pointed out</a></strong>, the topic of software liability is often considered a &#8220;third rail&#8221; of cybersecurity policy, meaning, no one typically wants to touch it.</p><p>Hence, many have considered cybersecurity a market failure and that&#8217;s unlikely to change in the current landscape.</p><h2>The Floor, Not the Ceiling</h2><p>The pattern I laid out in <strong><a href="https://www.resilientcyber.io/p/the-ai-cyber-capability-curve">The AI Cyber Capability Curve</a></strong> predicts that every one of these numbers will look quaint within 12 months. </p><p>If AI vulnerability research capability is doubling every four months, the 10,000-in-a-month figure from this update represents roughly two doublings ago by the time the next Glasswing update ships. Mythos-class models will be available from multiple labs and even among the open source community, as Anthropic itself acknowledges, which means the discovery rate will multiply across the industry, not just within one company&#8217;s partner program.</p><p>There&#8217;s no question whether AI will continue to find vulnerabilities faster than humans can fix them, as that&#8217;s settled and no longer debatable. </p><p>The question is whether the institutions, incentive structures, and economic models that govern software security can adapt fast enough to absorb what&#8217;s coming, or whether the industry will learn the same lesson every other safety-critical domain has already learned, that the forcing function for real structural change is sufficient consequences, not foresight.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Vulnpocalypse Playbook]]></title><description><![CDATA[Why the least glamorous discipline in security just became the most critical]]></description><link>https://www.resilientcyber.io/p/the-vulnpocalypse-playbook</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-vulnpocalypse-playbook</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Sun, 24 May 2026 13:23:21 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/199058747/a3eefc484aca41d756b4e8e7aa40ab92.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This week we sat down with Ivan Dwyer, Senior Product Marketing Strategist at Axonius, to work through what is shaping up to be a defining moment for vulnerability management.</p><p>In the span of a single week this April, two things happened that fundamentally changed the math. Anthropic announced Claude Mythos, a frontier model that autonomously found thousands of zero-days and wrote working exploits against code that had survived decades of human review. </p><p>Days later, NIST conceded it can no longer keep pace with CVE enrichment and moved everything published before March 2026 into a Not Scheduled status. With FIRST forecasting more than 50,000 new CVEs this year, the exploitation window is collapsing from weeks to hours at the exact moment our primary public source of vulnerability context is contracting.</p><p>Ivan and I dug into what this actually means for security teams on the ground. We talked through why programs built around periodic cadences break down when time disappears, why asset management is quietly becoming the most critical discipline in the stack, and how leaders should be answering the harder resilience questions now coming from the board. We also got into the fundamentals that compliance never quite covers, how to prioritize fixes against real business impact, and the remediation metrics that still matter when the volume explodes. </p><p>We closed on the question everyone is wrestling with, which is how much of security operations should be fighting AI with AI, and what the tradeoffs look like for the teams building it.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><div id="youtube2-Rrg9Rivgj24" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;Rrg9Rivgj24&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/Rrg9Rivgj24?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><ul><li><p>Why the Mythos and NVD one-two punch broke the cadence model, and the mindset shift teams need to make when exploitation windows shrink to hours</p></li><li><p>How boards are reframing resilience around the ability to absorb the incoming vulnpocalypse, and whether that actually unlocks budget or becomes another do more with less cycle</p></li><li><p>Why asset management is moving from unglamorous bedrock to critical discipline, and what is driving that shift in the market right now</p></li><li><p>The gap between 90% control coverage that passes the compliance bar and the weak auth, BYOD, and shadow IT exposures where exploits actually land</p></li><li><p>How to measure business impact when both the attack surface and the volume of disclosures are exploding at the same time</p></li><li><p>The remediation metrics that matter most in the AI era, including one measure most teams overlook</p></li><li><p>How much of security operations should be fighting AI with AI, and the real considerations and tradeoffs for those building AI for security</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #98]]></title><description><![CDATA[AI Breaks the Security Ecosystem, CISA's GitHub Exposure, EU AI Act Delays, Cloudflare Mythos Results, AI-driven CVE Wave & Vulnpocalypse Is Not the CISO's Problem]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-98</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-98</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 22 May 2026 13:11:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-n-X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #98 of the Resilient Cyber Newsletter!</p><p>This was the week the Mythos narrative shifted from hype to measured evaluation, and the results are more interesting than either the cheerleaders or the skeptics predicted. The UK AI Safety Institute published data showing autonomous AI cyber capability is doubling every 4.7 months, faster than Moore&#8217;s Law. Palo Alto Networks reported that frontier AI found 7x more vulnerabilities across its product portfolio in a single month than the typical baseline. </p><p>Cloudflare tested Mythos against 50 internal code repositories and concluded the jump from prior frontier models is &#8220;not just a refinement of what came before.&#8221; And Anthropic formally allowed its Glasswing partners to share Mythos cybersecurity findings publicly, a move that will reshape how threat intelligence flows across the industry.</p><p>On the supply chain front, the TeamPCP threat actor open-sourced the Shai-Hulud worm on GitHub, complete with deployment instructions. Socket hit a $1 billion valuation with a $60 million Series C. And the story of the week in operational security may have been a CISA contractor who left AWS GovCloud keys and dozens of plaintext passwords in a public GitHub repository for six months.</p><p>Meanwhile, the EU agreed to delay high-risk AI rules by 12 to 18 months, prompt injection researchers demonstrated that current defenses are fundamentally flawed, and VulnCheck documented what they are calling the &#8220;first CVE wave&#8221; with disclosure volumes surging up to 563% for some vendors.</p><p>There is a lot to unpack, so let&#8217;s get into it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-n-X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-n-X!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png 424w, https://substackcdn.com/image/fetch/$s_!-n-X!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png 848w, https://substackcdn.com/image/fetch/$s_!-n-X!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png 1272w, https://substackcdn.com/image/fetch/$s_!-n-X!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-n-X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png" width="657" height="401.77862595419845" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:721,&quot;width&quot;:1179,&quot;resizeWidth&quot;:657,&quot;bytes&quot;:618962,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-n-X!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png 424w, https://substackcdn.com/image/fetch/$s_!-n-X!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png 848w, https://substackcdn.com/image/fetch/$s_!-n-X!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png 1272w, https://substackcdn.com/image/fetch/$s_!-n-X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe33f570b-8730-4754-991e-b16a0ac0ebdb_1179x721.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><h3><strong><a href="https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad">[Expert Panel] Mythos: When Perception Becomes Reality</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SPDl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!SPDl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!SPDl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!SPDl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SPDl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png" width="674" height="337" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:674,&quot;bytes&quot;:122029,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!SPDl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!SPDl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!SPDl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!SPDl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0d75bff0-f2b9-4c35-8cd6-7a54ccfd5059_600x300.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Exploits used to take weeks to weaponize. With AI, hours. Patch cycles haven&#8217;t moved. CVE-driven prioritization isn&#8217;t keeping up. Brad Arkin (former Chief Trust Officer at Salesforce, Cisco, Adobe) joins Nadav Czerninski (CEO, Oligo) on what your stack actually has to do now.</p><p>You&#8217;ll learn how to prioritize exploitable exposures, move beyond CVE scores, &amp; tighten the window between disclosure and response.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad&quot;,&quot;text&quot;:&quot;Register for May 27th!&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://oligosecurity.registration.goldcast.io/webinar/b331a092-4010-47aa-b2df-4885756cba41?utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad"><span>Register for May 27th!</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><em><strong>Interested in sponsoring an issue of Resilient Cyber?</strong></em></p><p><em><strong>This includes reaching over 31,000 subscribers, ranging from Developers, Engineers, Architects, CISO&#8217;s/Security Leaders and Business Executives</strong></em></p><p><em><strong>Reach out below!</strong></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:sponsorships@resilientcyber.io&quot;,&quot;text&quot;:&quot;-> Contact Us! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="mailto:sponsorships@resilientcyber.io"><span>-&gt; Contact Us! &lt;-</span></a></p><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://youtu.be/OqCXWyvayI0?si=AEkEQl8SnBzeDvwY">AI Broke the Security Ecosystem</a></h3><div id="youtube2-OqCXWyvayI0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;OqCXWyvayI0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/OqCXWyvayI0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>I had a chance to sit down with The Secure Disclosure to cover a wide ranging interview on AI, Cyber, AppSec, and the software supply chain, ironically right before GitHub itself got involved in an incident.</p><p>In this episode of The Secure Disclosure, host sits down with Chris Hughes founder of Resilient Cyber, CISA Cyber Innovation Fellow, and a leading voice in cybersecurity. We dive deep into the chaotic and rapidly shifting landscape of software supply chain security, the sudden operational struggles of the National Vulnerability Database (NVD), and how AI is completely rewriting the rules of vulnerability management. </p><p>From the technical and social engineering risks plaguing open-source software to the "human-in-the-loop" delusion, Chris shares his honest, unfiltered takes on where the industry is heading and why things will likely get worse before they get better. The episode wraps up with a chaotic round of "Would You Rather," forcing Chris to choose between missing firewalls, permanent vulnerability freezes, and total AI "vibe coding."</p><h3><a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/">A CISA Contractor Left the Keys to the Kingdom on GitHub</a></h3><p>I want to be careful about how I frame this because it is genuinely painful. A contractor working for Nightwing, based in Dulles, Virginia, maintained a public GitHub repository called &#8220;Private-CISA&#8221; from November 2025 through mid-May 2026.</p><p>The repository contained AWS GovCloud administrative credentials, dozens of internal CISA system usernames and passwords in plaintext, and files literally named &#8220;importantAWStokens.&#8221; </p><p>The administrator had disabled GitHub&#8217;s default secret detection. GitGuardian researcher Guillaume Valadon called it &#8220;the worst leak that I&#8217;ve witnessed in my career.&#8221; <strong><a href="https://www.axios.com/2026/05/19/congress-cisa-briefing-credentials-leak">Congress is now demanding a classified briefing</a></strong>. </p><p>For the agency responsible for securing federal cybersecurity infrastructure, this is the kind of incident that erodes institutional credibility. The exposed credentials were reportedly still valid 48 hours after the repository was taken down. As I have been writing since Cybersecurity First Principles, the basics remain the hardest part. No amount of frontier AI capability matters if the people operating the infrastructure leave the keys in the open.</p><h3><a href="https://www.hoganlovells.com/en/publications/eu-legislators-agree-to-delay-for-highrisk-ai-rule">The EU Buys More Time on High-Risk AI Rules</a></h3><p>The Council of the EU and European Parliament agreed on May 7 to delay application dates for high-risk AI system rules. Standalone high-risk AI systems now face a December 2, 2027 deadline, and high-risk AI embedded in products gets pushed to August 2, 2028. </p><p>The original timeline had targeted August 2026. The delay is part of the European Commission&#8217;s &#8220;Digital Omnibus&#8221; initiative from late 2025, acknowledging that AI Act compliance requires significant preparation and that supporting technical standards are still being finalized. On the positive side, legislators added a new ban on AI-generated non-consensual sexual content. </p><p>For organizations planning AI governance programs, the extended timeline is a relief but not an invitation to wait. The regulatory direction remains unchanged. The compliance expectations remain unchanged. What changed is the calendar.</p><h3><a href="https://socket.dev/blog/socket-raises-60m-series-c-press-release">Socket Hits $1 Billion on the Supply Chain Security Thesis</a></h3><p>When I covered the PyTorch Lightning compromise in issue #96 and the Mini Shai-Hulud TanStack attack in issue #97, I wrote that the trust model in modern package ecosystems was not designed for the speed at which attacks now move. </p><p>Socket&#8217;s $60 million Series C at a $1 billion valuation validates that thesis with investor conviction. Led by Thrive Capital with participation from a16z, Abstract Ventures, and Capital One Ventures, the round brings total funding to $125 million.</p><p>Socket&#8217;s real-time dependency analysis detected the PyTorch Lightning compromise in 18 minutes. In a market where supply chain worms are self-propagating across ecosystems and threat actors are open-sourcing their frameworks, the ability to catch malicious packages before they propagate is not optional. It is infrastructure.</p><h3><a href="https://www.calcalistech.com/ctechnews/article/hku7df9jfg">Check Point&#8217;s Fourth Israeli Acquisition Signals a Strategy Shift</a></h3><p>Under CEO Nadav Zafrir, Check Point acquired Deepchecks, its fourth Israeli startup acquisition in 2026, following Cyclops and Cyata for a combined $150 million and an acqui-hire of Rotate. Deepchecks brings AI agent technology for network security operations. </p><p>The acquisition pace tells a story about where Check Point sees itself needing to catch up. The company has faced criticism for lagging in cloud and AI security, and Zafrir&#8217;s response has been to buy velocity through targeted acquisitions of Israeli security startups. For those tracking vendor consolidation across the cybersecurity market, Check Point&#8217;s strategy mirrors the broader pattern. Build the platform, buy the AI capabilities, integrate fast.</p><h3><a href="https://www.jit.io/blog/jit-joins-torq-to-advance-ai-powered-security-operations">Torq Acquires Jit for the AI SOC Context Graph</a></h3><p>Torq&#8217;s acquisition of Jit for approximately $70 million adds what they are calling the &#8220;grounding layer the AI SOC has been missing.&#8221; Jit&#8217;s Context Graph maps code, identities, roles, privileges, data sensitivity, and runtime behavior into a unified model that AI agents can reason over. </p><p>The problem this solves is real. AI security agents making prioritization and response decisions without organizational context produce noisy, low-confidence outputs. Jit&#8217;s technology translates agent actions into enterprise context, enabling better-informed decisions. Combined with Torq&#8217;s existing hyperautomation platform, the integrated offering targets the gap between AI speed and organizational understanding. </p><p>As I discussed in issue #97 with Microsoft&#8217;s MDASH, the trend is clear. Multi-agent security architectures require rich context layers to be effective.</p><h3><a href="https://lukaszostrowski.substack.com/p/the-strange-economics-of-cybersecurity">The Strange Economics of Cybersecurity in the AI Age</a></h3><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Lukasz Ostrowski&quot;,&quot;id&quot;:147444258,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c95711cf-0604-4af6-a3e0-47be3b58a2dd_1364x1364.jpeg&quot;,&quot;uuid&quot;:&quot;21cb0c4a-03c1-4ecd-aaa8-2da2cac36519&quot;}" data-component-name="MentionToDOM"></span> put his finger on something I have been observing for months. Cybersecurity is uniquely resistant to AI-driven cost deflation. While AI reduces costs across coding, design, support, and content creation, it drives spending increases in security. </p><p>Microsoft Security&#8217;s FY25 revenue hit approximately $37 billion, exceeding the entire global cybersecurity industry from 2016. Gartner projects global information security spending at $244 billion in 2026, up 13.3% year over year. The AI-Amplified Security sub-segment is projected to grow from $49 billion in 2025 to $160 billion by 2029. Every AI agent introduces new identity vectors and attack surfaces. </p><h3><a href="https://www.thestateofbrand.com/news/ai-subscription-time-bomb">The AI Subscription Time Bomb Goes Off</a></h3><p>If you built production workflows on AI pricing that felt too good to last, this is the week it caught up. Anthropic split Claude subscriptions into two separate usage pools effective June 15, 2026. GitHub Copilot transitioned to usage-based billing on June 1. Both OpenAI and Anthropic are on IPO timelines for H2 2026, and public markets demand unit economics, not subsidized growth. </p><p>The State of Brand reported that Uber burned through its entire 2026 AI budget by April, four months into the fiscal year. For security teams that have built agentic workflows and AI-powered scanning pipelines on flat-rate subscriptions, the economics are about to change materially. As Greg Notch noted this week, the <a href="https://www.linkedin.com/posts/gregnotch_the-token-budget-divide-is-going-to-make-activity-7461064402193154048-QCyn">token budget divide</a> is going to make the digital divide look quaint. NVIDIA is reportedly telling engineers to consume roughly 50% of their base salary in tokens. Budget planning for AI security operations just got a lot more complicated.</p><h3><a href="https://www.a16z.news/p/is-software-losing-its-head">Software Is Losing Its Head and Security Must Follow</a></h3><p>Seema Amble at a16z argues that software is collapsing under its own complexity, and AI exposed the problem rather than creating it. The future belongs to headless architectures where agents access systems of record directly through APIs rather than through human-facing interfaces. Salesforce&#8217;s headless API strategy for agentic access is the bellwether. </p><p>The security implication is significant. When agents interact with backend systems without a UI layer, the traditional enforcement points in the browser, in the session, in the user interaction disappear. As I discussed in issue #97 with Sysdig&#8217;s headless cloud security platform, the future of security is not a better dashboard. It is security that operates at the data layer, enforcing policy on agent requests that never touch a human interface. The organizations that redesign their security controls for headless access will have an advantage. Everyone else will be defending a perimeter that no longer exists.</p><h3><a href="https://www.nightdragon.com/insights/nightdragon-invests-armada-ai/">NightDragon Invests in Armada&#8217;s $230 Million Series B</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ySCh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ySCh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png 424w, https://substackcdn.com/image/fetch/$s_!ySCh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png 848w, https://substackcdn.com/image/fetch/$s_!ySCh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png 1272w, https://substackcdn.com/image/fetch/$s_!ySCh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ySCh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png" width="1456" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2335041-462d-4b6a-9881-34b4815aa007_1736x598.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1073164,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ySCh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png 424w, https://substackcdn.com/image/fetch/$s_!ySCh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png 848w, https://substackcdn.com/image/fetch/$s_!ySCh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png 1272w, https://substackcdn.com/image/fetch/$s_!ySCh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2335041-462d-4b6a-9881-34b4815aa007_1736x598.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Armada raised $230 million at a $2 billion pre-money valuation for modular AI data center infrastructure, with bookings jumping 540% between fiscal 2025 and fiscal 2026. Co-led by BlackRock, Overmatch, and 8090 Industries, with NightDragon participating as a strategic investor. </p><p>The edge AI infrastructure thesis is straightforward. Sovereign AI requirements, data residency regulations, and latency-sensitive workloads demand compute capacity that cannot live exclusively in centralized hyperscaler data centers. For cybersecurity, the implication is that security controls must follow the compute. Every modular data center at the edge is an attack surface that needs the same governance, monitoring, and access controls as a traditional data center. The compute is distributing, the security has to distribute with it.</p><h3><a href="https://cyberscoop.com/former-cisa-nominee-sean-plankey-named-us-ceo-of-defense-startup/">Sean Plankey Pivots from CISA Nominee to Defense Startup CEO</a></h3><p>After 13 months of his CISA director nomination languishing in the Senate without confirmation, Sean Plankey withdrew and within weeks was named U.S. CEO of UFORCE, a London-based defense startup founded by Ukrainians that builds combat drones and autonomous vessels. </p><p>The move from government cybersecurity leadership to defense technology is emblematic of a broader pattern where senior government cyber officials are finding faster impact in the private sector. First U.S.-made unmanned surface vessels are planned for summer 2026. The personnel pipeline between government cybersecurity and private sector defense technology continues to accelerate.</p><h3><a href="https://www.linkedin.com/posts/spacerogue_28-years-ago-today-seven-hackers-in-suits-share-7462189271529984000-jWqc">28 Years Since L0pht Told Congress They Could Take Down the Internet</a></h3><p>Space Rogue&#8217;s retrospective on the L0pht Heavy Industries congressional testimony hit its 28th anniversary this week. In May 1998, seven hackers in suits told the U.S. Senate they could take down the internet in 30 minutes. Two years later they founded stake. </p><p>The testimony was a pivot point that began normalizing security researcher perspectives in policy conversations. Space Rogue&#8217;s memoir, released in February 2026, provides essential historical context. As we debate AI model access, responsible disclosure, and the role of frontier AI in offensive security, it is worth remembering that we have been here before. The tools change. The tension between security researchers, policymakers, and the public interest remains constant.</p><div><hr></div><h1>AI</h1><h3><a href="https://www.aisi.gov.uk/blog/how-fast-is-autonomous-ai-cyber-capability-advancing">Autonomous AI Cyber Capability Is Doubling Every 4.7 Months</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6YEC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6YEC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png 424w, https://substackcdn.com/image/fetch/$s_!6YEC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png 848w, https://substackcdn.com/image/fetch/$s_!6YEC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png 1272w, https://substackcdn.com/image/fetch/$s_!6YEC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6YEC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png" width="1456" height="935" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:935,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:516381,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6YEC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png 424w, https://substackcdn.com/image/fetch/$s_!6YEC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png 848w, https://substackcdn.com/image/fetch/$s_!6YEC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png 1272w, https://substackcdn.com/image/fetch/$s_!6YEC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d2289bb-0dfb-4b0d-a06e-43d9a1f341e7_1990x1278.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the metric that should anchor every conversation about AI and cybersecurity strategy. The UK AI Safety Institute measured that the length of cyber tasks frontier AI models can complete has been doubling every 4.7 months since late 2024, an acceleration from the 8-month estimate they published in November 2025. Claude Sonnet 4.5 succeeds 80% of the time at cyber tasks that take human experts 16 minutes. </p><p>Claude Mythos Preview became the first model to complete two evaluated cyber ranges, including &#8220;Cooling Tower,&#8221; a 7-step industrial control system attack that no prior model had solved. METR&#8217;s independent measurement of a 4.2-month doubling time for software engineering tasks converges with this finding. When I covered the NCSC&#8217;s &#163;65 attack cost number in issue #96, the underlying concern was exactly this. The cost floor on sophisticated attacks is collapsing while capability is accelerating faster than Moore&#8217;s Law. </p><p>Defense strategies built on the assumption that human expertise remains the bottleneck are already outdated.</p><h3><a href="https://www.paloaltonetworks.com/blog/2026/05/defenders-guide-frontier-ai-impact-cybersecurity-may-2026-update/">Palo Alto Networks Reports 7x More Vulnerabilities from Frontier AI in a Single Month</a></h3><p>The numbers from Palo Alto Networks&#8217; May 2026 Defender&#8217;s Guide update are striking. Frontier AI models discovered 75 vulnerabilities across the company&#8217;s 130+ product portfolio in a single month, a 7x increase from the typical baseline of approximately five per month. </p><p>The AI accomplished the equivalent of a full year&#8217;s penetration testing effort in less than three weeks. The most concerning finding was not the volume but the sophistication. The models demonstrated exceptional capability at vulnerability chaining, combining multiple lower-severity issues into critical-level exploit paths that traditional scanning would have missed individually. Palo Alto estimates a 3-to-5-month strategic window for defenders to capitalize on this capability before it becomes universally accessible for offense. </p><p>As I discussed in my coverage of Microsoft&#8217;s MDASH in issue #97, the organizations investing in multi-agent vulnerability discovery infrastructure are finding real, Critical-severity flaws. The question is whether defenders or attackers industrialize these capabilities first.</p><h3><a href="https://blog.cloudflare.com/cyber-frontier-models/">Cloudflare Tested Mythos Against 50 Internal Repositories and the Results Are Nuanced</a></h3><p>Cloudflare&#8217;s write-up on Project Glasswing is the most technically grounded Mythos evaluation I have read. They tested the model against over 50 internal code repositories and identified two standout capabilities. First, exploit chain construction, where the model combines multiple vulnerability primitives into working exploits. Second, proof generation, where it writes code to trigger suspected bugs, compiles in a scratch environment, runs tests, and iterates. </p><p>The Cloudflare team concluded that the jump from previous frontier models to Mythos is &#8220;not just a refinement of what came before.&#8221; But they were equally clear that the model&#8217;s organic guardrails are &#8220;not consistent enough to serve as a complete safety boundary.&#8221; </p><p>Combined with Nikesh Arora&#8217;s comments on the <a href="https://www.nytimes.com/2026/05/15/podcasts/ai-safety-is-so-back-mythos-mayhem-with-nikesh-arora-hot-mess-express.html">NYT Hard Fork podcast</a> about Palo Alto receiving early access to both Mythos and GPT-5.5 Cyber, the emerging picture is that frontier AI for cybersecurity is real, differentiated, and insufficiently governed.</p><h3><a href="https://www.reuters.com/technology/anthropic-let-partners-share-mythos-cybersecurity-findings-with-others-2026-05-18">Anthropic Opens the Door for Glasswing Partners to Share Findings</a></h3><p>The disclosure pipeline for Mythos just widened significantly. Anthropic will now allow its Project Glasswing partners, which include Amazon, Microsoft, Nvidia, and Apple, to share cybersecurity findings with security teams, industry bodies, regulators, government agencies, open-source maintainers, and media. </p><p>The Pentagon is deploying Mythos for U.S. government vulnerability patching. This policy shift will have cascading effects on how threat intelligence flows. When the organizations with early access to the most capable offensive AI model can now share what they find, the volume of disclosed vulnerabilities will accelerate further. As I discussed in issue #97 with the HackerOne remediation gap, we are already finding vulnerabilities at dense-world rates while fixing them at sparse-world rates. </p><p>Opening the disclosure pipeline wider without solving the remediation bottleneck risks making the gap worse before it gets better.</p><h3><a href="https://www.linkedin.com/posts/sahar-abdelnabi_promptabrinjectionsabrsoabrback-activity-7462528091647614976-r3oR">Prompt Injection May Be an Unsolvable Problem</a></h3><p>If you are building agentic AI systems, the research Sahar Abdelnabi and Eugene Bagdasarian posted on May 17 should be required reading. Using Contextual Integrity theory, they demonstrated that the prevailing defense paradigm of data-instruction separation both fails to detect attacks and degrades legitimate behavior. Their impossibility result shows that adversaries can always construct contexts where blocked flows appear legitimate. </p><p>Tightening defense norms to block attacks necessarily blocks legitimate flows. If this holds, it means prompt injection is a fundamental vulnerability that cannot be fully resolved through any defense mechanism that relies on distinguishing data from instructions. As I have written since my early coverage of the OWASP Agentic Top 10, &#8220;if your defense can be prompt injected, it&#8217;s not a defense.&#8221; This research provides the theoretical grounding for that position. </p><p>Defense-in-depth, not single-point defenses, remains the only viable path.</p><h3><a href="https://blog.christianposta.com/aauth-full-demo/">AAuth Gets a Full Working Demo with Keycloak and A2A</a></h3><p>Christian Posta followed up on the on-behalf-of piece I covered in issue #97 with a full working demonstration of the AAuth protocol. The demo walks through Agent-to-Agent (A2A) communication using the Python AAuth Library, Agentgateway, and the AAuth resource proxy. It covers HWK and JWKS signature schemes, identity establishment, HTTP message signing, and backend signing flows. </p><p>The practical significance is that AAuth is no longer a theoretical specification. It is a working implementation that you can deploy today. Between AAuth, Microsoft Entra Agent ID, Google Agent Identity, AWS AgentCore OBO, and now the <a href="https://www.infoblox.com/news/news-events/press-releases/infoblox-and-godaddy-support-open-standards-for-ai-agent-discovery-identity-and-verification/">Infoblox/GoDaddy DNS-AID and ANS standards</a> for agent discovery and verification using existing DNS infrastructure, the agent identity ecosystem is maturing rapidly. </p><p>As I wrote in my article on identity as the agentic AI problem, the building blocks are taking shape. The convergence question is now a matter of market adoption, not technical feasibility.</p><h3><a href="https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/overview">Anthropic Ships MCP Tunnels for Secure Agent Access to Internal Systems</a></h3><p>MCP Tunnels allow Claude agents to connect to private Model Context Protocol servers without exposing internal infrastructure to the public internet. Traffic flows over outbound-only encrypted connections using cloudflared, with no need to open inbound firewall ports or allowlist Anthropic IP ranges. </p><p>Organizations can expose internal databases, APIs, ticketing systems, and knowledge bases to Claude agents while maintaining existing network security boundaries. The feature is in research preview. For security teams evaluating MCP adoption, this addresses one of the primary concerns I have heard repeatedly. How do you give agents access to internal systems without punching holes in your perimeter? MCP Tunnels answers that question with a design that respects existing security architecture. </p><p>Combined with Solo.io&#8217;s <a href="https://www.solo.io/blog/agentgateway-code-mode-for-openapi-to-mcp">AgentGateway</a> that converts OpenAPI specifications to MCP tools without code changes, the MCP infrastructure layer is becoming enterprise-ready.</p><h3><a href="https://aws.amazon.com/blogs/security/aws-security-agent-full-repository-code-scanning-feature-now-available-in-preview/">AWS Security Agent Now Scans Full Repositories in Preview</a></h3><p>The shift here is from pattern-matching to architecture reasoning. AWS Security Agent&#8217;s full repository code review performs context-aware security analysis of entire codebases, reasoning about application architecture, trust boundaries, and data flows rather than scanning for known vulnerability patterns. </p><p>Remediation suggestions tie to exact files and line numbers. The feature is available at no additional cost for existing customers in preview, with penetration testing already at general availability since March 31, 2026. As I have tracked across issues #96 and #97 with CodeMender, MDASH, and AISLE&#8217;s VulnOps model, the trend is unmistakable. </p><p>AI-powered security tools are moving from &#8220;find known patterns&#8221; to &#8220;understand the system and reason about where vulnerabilities can exist.&#8221; That architectural reasoning capability is what separates the current generation from traditional static analysis.</p><h3><a href="https://www.dragos.com/blog/ai-assisted-ics-attack-water-utility">Dragos Documents the First AI-Assisted Attack on Industrial Control Systems</a></h3><p>This is the story that brings the Mexico government breach from issue #96 into the OT domain. Between December 2025 and February 2026, an attacker used Claude and GPT models against the Monterrey metropolitan water utility in Mexico, building a 17,000-line Python attack framework with 49 offensive security modules. </p><p>Claude independently identified the OT environment as strategically significant, correctly recognized the vNode interface as a gateway to operational systems, and wrote sophisticated attack code. The attack ultimately failed to breach operational technology. No OT systems were compromised. But the capability demonstration is significant. This is the first documented case where commercial AI models were used to conduct intrusion activities specifically targeting industrial control systems. </p><h3><a href="https://www.linkedin.com/pulse/agents-boring-future-harness-caleb-sima-uojqe/">Caleb Sima on Why the Boring Future of Agents Is the Important One</a></h3><p>I mentioned Caleb Sima&#8217;s Unprompted conference in issue #97, and his latest piece makes a point that I think deserves wider attention. The important work in agentic AI security is not the flashy model capability demonstrations. It is the harnesses, the orchestration frameworks, the guardrails, and the governance layers that make agents safe enough to deploy in production. </p><p>The market is shifting from theoretical capability debates to practical deployment questions. How do you scope permissions? How do you audit agent actions? How do you ensure agents fail safely? These are not glamorous questions, but they are the ones that determine whether organizations can actually ship agentic AI into production. </p><p>As I discussed in issue #95 with the Sondera analysis of the Claude Code leak, the security of the harness layer is where the real work is.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://www.vulncheck.com/blog/ai-assisted-vulnerability-discovery">VulnCheck Documents the &#8220;First CVE Wave&#8221; from AI-Assisted Discovery</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D6hO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D6hO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png 424w, https://substackcdn.com/image/fetch/$s_!D6hO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png 848w, https://substackcdn.com/image/fetch/$s_!D6hO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png 1272w, https://substackcdn.com/image/fetch/$s_!D6hO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D6hO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png" width="1456" height="850" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:850,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1013547,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D6hO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png 424w, https://substackcdn.com/image/fetch/$s_!D6hO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png 848w, https://substackcdn.com/image/fetch/$s_!D6hO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png 1272w, https://substackcdn.com/image/fetch/$s_!D6hO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61285430-c8a7-4f15-a222-3278b09b51c7_2422x1414.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The data from VulnCheck tells the story of a structural shift. Year-to-date CVE disclosure volumes for 2026 show Chrome up 563%, VMware up 181%, Apache up 170%, Mozilla up 157%, HPE up 132%, and F5 up 114%. </p><p>The catalyst was the April 7, 2026 announcement of Project Glasswing and Claude Mythos Preview. VulnCheck notes that early submissions showed signs of &#8220;slop&#8221; from automated discovery, but quality has improved over subsequent months while volume sustained. <a href="https://cveforecast.org/">CVE Forecast</a>, maintained by Jerry Gamblin, projects 50,000+ CVEs in 2026, with FIRST estimating a median of approximately 59,427. Combined with my coverage of the HackerOne remediation gap in issue #97 and AISLE&#8217;s VulnOps model in issue #96, the pattern is clear. </p><p>AI-assisted discovery is not a temporary spike. It is a permanent increase in the velocity of vulnerability disclosure, and every downstream system from triage to remediation to patch management needs to adapt.</p><h3><a href="https://www.linkedin.com/posts/vbadhwar_teampcp-shaihulud-github-activity-7460780486475427840-Ultg">TeamPCP Open-Sourced the Shai-Hulud Worm on GitHub</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WbCQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WbCQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png 424w, https://substackcdn.com/image/fetch/$s_!WbCQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png 848w, https://substackcdn.com/image/fetch/$s_!WbCQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png 1272w, https://substackcdn.com/image/fetch/$s_!WbCQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WbCQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png" width="1456" height="733" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:733,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1467988,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WbCQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png 424w, https://substackcdn.com/image/fetch/$s_!WbCQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png 848w, https://substackcdn.com/image/fetch/$s_!WbCQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png 1272w, https://substackcdn.com/image/fetch/$s_!WbCQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa165bd06-641e-48f9-b78d-85f7eb741cfc_1918x966.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If the TanStack compromise from issue #97 demonstrated how dangerous Mini Shai-Hulud was as a weaponized supply chain worm, this week&#8217;s development makes it exponentially worse. </p><p>TeamPCP published the complete Shai-Hulud source code to GitHub, with deployment instructions. The worm searches for AWS, GCP, Azure, and GitHub credentials, then creates and publishes poisoned code for self-propagation through npm. As I wrote in <em>Software Transparency</em>, the trust model in package ecosystems was designed for a different threat landscape. </p><p>Open-sourcing a supply chain worm framework is the equivalent of publishing a recipe for mass credential theft. Every engineering team running npm dependencies, which is effectively every JavaScript shop on the planet, needs to evaluate their exposure to this threat vector immediately.</p><h3><a href="https://maccarita.com/posts/idesaster2/">IDEsaster2 Expands the Attack Surface Across AI Coding Tools</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ilK6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ilK6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png 424w, https://substackcdn.com/image/fetch/$s_!ilK6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png 848w, https://substackcdn.com/image/fetch/$s_!ilK6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!ilK6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ilK6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png" width="494" height="406.90751445086704" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1140,&quot;width&quot;:1384,&quot;resizeWidth&quot;:494,&quot;bytes&quot;:3286666,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ilK6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png 424w, https://substackcdn.com/image/fetch/$s_!ilK6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png 848w, https://substackcdn.com/image/fetch/$s_!ilK6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png 1272w, https://substackcdn.com/image/fetch/$s_!ilK6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffb1b0f99-e2ee-4c2b-a7b8-f339b743f3e7_1384x1140.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ari Marzouk&#8217;s IDEsaster research that I covered in issue #97 continues with IDEsaster2, expanding the vulnerability class across additional AI-integrated development tools. The core problem remains the same. AI coding IDEs fail to account for how AI features interact with existing IDE capabilities, enabling attackers to chain prompt injection with legitimate IDE functionality to achieve data exfiltration and remote code execution without user interaction. 100% of tested tools remain vulnerable. </p><p>The root cause is that IDE vendors treat AI features as inherently safe because the underlying IDE functions have existed for years. That assumption is wrong, and it continues to expose every developer using AI-powered coding tools to attacks that exploit the gap between AI behavior and IDE trust models.</p><h3><a href="https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim">XBOW Finds a Critical RCE in Exim and the Details Matter</a></h3><p>CVE-2026-45185, dubbed &#8220;Dead.Letter,&#8221; is a CVSS 9.8 use-after-free in Exim&#8217;s SMTP input handling when linked against GnuTLS. The vulnerability is triggered by a STARTTLS command followed by a BDAT chunking command. During TLS shutdown, Exim frees the transfer buffer but fails to clear lower-level receive pointers. A single newline character written to freed memory causes heap corruption leading to unauthenticated remote code execution. </p><p>Affected versions span Exim 4.97 through 4.99.x on GnuTLS-linked builds, making Debian, Ubuntu, and Debian-derived distributions the primary targets. OpenSSL builds are not affected. <a href="https://xbow.com/blog/mythos-offensive-security-xbow-evaluation">XBOW&#8217;s separate evaluation</a> of Mythos for offensive security showed the model is substantially better than prior models at source code vulnerability discovery but noted that many exploitable issues do not appear in source code. </p><p>They emerge from configuration, dependencies, and deployment choices. That nuance matters for calibrating expectations around AI-driven vulnerability discovery.</p><h3><a href="https://shubs.io/the-down-fall-of-bug-bounties/">The Bug Bounty Model Is Breaking Under AI Pressure</a></h3><p>For those who followed my coverage of the bug bounty slop problem in issue #96, this week brought more evidence that the structural damage is accelerating. Security researcher shubs documented 12-day response delays on PII leakage vulnerabilities and described how frontier AI models have commoditized the discovery process to the point where anyone with a Claude or GPT subscription can generate legitimate-looking reports. </p><p>The speed incentive that previously motivated researcher participation is evaporating. Platforms are deploying anti-AI controls, but the economic model itself is under stress. <a href="https://www.linkedin.com/posts/danielstenberg_curl-activity-7460801544993693696-HZYF">Daniel Stenberg reinforced this</a> by continuing to question Mythos&#8217;s real-world capability against curl&#8217;s codebase. And in a separate but related development, <a href="https://kabir.au/blog/the-ctf-scene-is-dead">the CTF scene is dying</a> for the same reasons. </p><p>Frontier AI has automated enough of the competitive leaderboard that CTFTime scores no longer reliably signal human skill. When AI commoditizes both the discovery and the competition, the institutions built around human expertise have to reinvent themselves or fade.</p><h3><a href="https://exploitbench.ai/">ExploitBench Asks the Right Question About AI Cyber Capability</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o075!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o075!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png 424w, https://substackcdn.com/image/fetch/$s_!o075!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png 848w, https://substackcdn.com/image/fetch/$s_!o075!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png 1272w, https://substackcdn.com/image/fetch/$s_!o075!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o075!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png" width="549" height="424.1913669064748" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:537,&quot;width&quot;:695,&quot;resizeWidth&quot;:549,&quot;bytes&quot;:77114,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o075!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png 424w, https://substackcdn.com/image/fetch/$s_!o075!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png 848w, https://substackcdn.com/image/fetch/$s_!o075!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png 1272w, https://substackcdn.com/image/fetch/$s_!o075!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F193f121f-8b7f-4e0d-b466-9cf651deca2e_695x537.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The way we measure AI cyber capability has been broken, and ExploitBench from CMU and Bugcrowd, released May 13, finally fixes it. Previous benchmarks asked whether a model could find a crash. ExploitBench decomposes exploitation into 16 measurable flags organized as a capability ladder, progressing from coverage through crash, sandbox primitives, arbitrary read/write, control-flow hijack, and finally arbitrary code execution. </p><p>The first benchmark targets V8, the JavaScript engine powering Chrome, Edge, Node.js, and Cloudflare Workers. This matters because it gives us a rigorous, reproducible way to track how quickly AI models climb the exploitation ladder over time. Combined with AISI&#8217;s 4.7-month doubling metric, ExploitBench provides the measurement framework the industry needs to move beyond marketing narratives about what AI can and cannot do offensively.</p><h3><a href="https://www.cybrsecmedia.com/the-vulnpocalypse-isnt-your-problem/">The Vulnpocalypse Is Real, but It Is Not the CISO&#8217;s Problem</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TSxM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TSxM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png 424w, https://substackcdn.com/image/fetch/$s_!TSxM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png 848w, https://substackcdn.com/image/fetch/$s_!TSxM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png 1272w, https://substackcdn.com/image/fetch/$s_!TSxM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TSxM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png" width="583" height="398" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:398,&quot;width&quot;:583,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:450988,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198593217?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TSxM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png 424w, https://substackcdn.com/image/fetch/$s_!TSxM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png 848w, https://substackcdn.com/image/fetch/$s_!TSxM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png 1272w, https://substackcdn.com/image/fetch/$s_!TSxM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7b6d8089-dabf-4632-a9b2-e475ec0d7314_583x398.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This piece reframes a debate I have been tracking since I first wrote about Vulnpocalypse. At RSAC 2026, only 16% of exhibitors believed the vulnpocalypse is a CISO problem, down from 29% at BlackHat 2025. The argument is that responsibility should shift to CIOs, CTOs, and heads of engineering. </p><p>As long as the CISO stands in front of the runaway train, nobody else will stop it. I think there is real merit to this framing. Traditional security operations, from CTI feeds through SIEM to analyst triaging, are running out of road as AI-driven discovery volumes surge. </p><p>The operational model has to change. But I would push back on the idea that ownership can simply be reassigned. The answer is not moving the problem from one executive to another. It is building operational frameworks like AISLE&#8217;s VulnOps that match the velocity of discovery with the velocity of remediation.</p><h3><a href="https://www.gov.uk/guidance/ai-open-code-and-vulnerability-risk-in-the-public-sector">The UK Government Rejects Security-Through-Obscurity for Open Code</a></h3><p>The UK government published guidance explicitly rejecting blanket code closures based on concerns about AI-powered vulnerability discovery. Their position is clear. Remediation capacity matters more than code secrecy. </p><p>Making code private introduces delivery overhead while reducing both reuse and scrutiny. Open code allows faster identification through broader community review. The minimum standard requires clear ownership, secure-by-design principles, automated hygiene, and credible remediation capacity. This is a refreshingly pragmatic stance from a government body. </p><p>The temptation when confronted with AI-driven vulnerability discovery is to hide the code. The UK is arguing, correctly in my view, that the better response is to invest in the ability to fix issues faster. As I have been writing since <em>Software Transparency</em>, openness combined with operational maturity beats secrecy combined with patching debt.</p><h3><a href="https://www.chainguard.dev/unchained/building-for-the-ai-era-chainguard-partners-with-endor-labs">Chainguard and Endor Labs Partner for End-to-End Supply Chain Security</a></h3><p>I covered Chainguard&#8217;s one-day KEV SLA commitment in issue #96, and this partnership with Endor Labs extends their approach into the AI-generated code domain. The integration addresses a specific problem. AI coding agents generate code faster than humans can review it. </p><p>Chainguard ensures container infrastructure starts clean while Endor Labs provides function-level vulnerability analysis. AURI, Endor Labs&#8217; platform, integrates into Cursor, VS Code, GitHub Copilot, and Claude Code. Chainguard&#8217;s $140 million Series C for &#8220;securing the next frontier of AI workloads&#8221; signals that the investor community sees supply chain security as the critical enabling layer for enterprise AI adoption. </p><p>The partnership model, combining infrastructure-level and code-level security, is the right architecture for an era where the code is generated autonomously and the containers are deployed at machine speed.</p><h3><a href="https://www.linkedin.com/posts/lisaeinstein_secureforge-ugcPost-7461138094734622720-JtWv">SecureForge Tackles Vulnerabilities in LLM-Generated Code Through Prompt Optimization</a></h3><p>Here is a research direction that deserves more attention. SecureForge, highlighted by CISA Chief AI Officer Lisa Einstein, focuses on finding and preventing security vulnerabilities in LLM-generated code through prompt optimization techniques. </p><p>The research, published on arXiv with contributions from Stanford, demonstrates that the prompts used to generate code significantly affect the security properties of the output. This connects directly to the vibe coding crisis I covered in issue #97 where 380,000 publicly accessible vibe-coded apps had 5,000 actively leaking data. If the prompt shapes the security of the code, then prompt engineering for security becomes a first-class concern. </p><p>The fact that CISA&#8217;s AI leadership is signaling this research suggests it will inform future government guidance on AI-generated code security.</p><h3><a href="https://www.terra.security/blog/terra-security-launches-network-penetration-testing">Terra Security Unifies Offensive Testing Across Web, AI, and Network</a></h3><p>For those following my coverage of Terra Security&#8217;s OpenClaw vulnerability research in issue #97, the company expanded its agentic offensive security platform to include network infrastructure. The platform now covers web applications, AI systems, and network infrastructure through swarms of hundreds of AI agents paired with human-in-the-loop governance. </p><p>Findings are ranked by real exploitability and business impact rather than raw severity scores. The unification matters because offensive security has historically been fragmented, with separate vendors and separate outputs for each domain. When attack paths cross domains, as they almost always do in real-world breaches, siloed testing misses the connections. Continuous, unified offensive validation is the direction the market is heading.</p><div><hr></div><h1>Final Thoughts</h1><p>This week crystallized something I have been circling around for several issues. The frontier AI capability question has been largely answered. AISI measured a 4.7-month doubling time. Palo Alto Networks found 7x more vulnerabilities in a single month. Cloudflare confirmed that Mythos is a qualitative jump, not an incremental refinement. VulnCheck documented CVE surges of up to 563% in a single vendor&#8217;s disclosure volume. ExploitBench gave us a rigorous measurement ladder. The capability is real, it is accelerating, and it is available to both defenders and attackers.</p><p>The open questions are now operational. Who remediates the vulnerabilities being found at 7x the previous rate? Who governs the agents deployed by 80% of the Fortune 500 with strategies at only 10%? Who secures the supply chain when threat actors open-source their attack frameworks on GitHub? Who enforces policy in headless architectures where agents interact with systems of record without touching a human interface?</p><p>The CISA GitHub leak is a painful reminder that the basics still matter more than the frontier. No AI model can compensate for leaving AWS GovCloud keys in a public repository for six months. The organizations that will thrive in this environment are the ones investing simultaneously in operational fundamentals and next-generation capabilities. The ones that treat AI as a replacement for operational discipline rather than an accelerant for it will learn the lesson the hard way.</p><p><strong>Stay resilient.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[The DBIR’s Exploitation Era]]></title><description><![CDATA[Attackers measure time-to-exploit in hours. Defenders still measure remediation in weeks. The 2026 DBIR shows what that math produces at scale.]]></description><link>https://www.resilientcyber.io/p/the-dbirs-exploitation-era</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-dbirs-exploitation-era</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Thu, 21 May 2026 11:00:12 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/41d26900-9974-4111-b4e2-7fd2eebd3040_1608x724.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In 2024, I wrote that <strong><a href="https://www.resilientcyber.io/p/the-dbir-is-entering-its-vulnerability">the DBIR was entering its vulnerability era</a></strong>. </p><p>The 2025 report showed vulnerability exploitation surging as an initial access vector, closing the gap on credential-based attacks and signaling a structural shift in how breaches begin. </p><p>The 2026 report doesn&#8217;t just confirm that thesis, it blows past it. Vulnerability exploitation is now the leading initial access vector in confirmed breaches, and the gap between exploitation and every other method of entry is widening, not narrowing.</p><p>The 2026 DBIR analyzed <strong>22,624</strong> confirmed breaches across <strong>31,860</strong> security incidents, the largest dataset in the report&#8217;s 19-year history. The findings tell a story that anyone working in vulnerability management already feels in their bones, but now has the numbers to prove. Attackers aren&#8217;t waiting for defenders to catch up, if anything, they&#8217;re doubling down on their lead.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6E9t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6E9t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png 424w, https://substackcdn.com/image/fetch/$s_!6E9t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png 848w, https://substackcdn.com/image/fetch/$s_!6E9t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png 1272w, https://substackcdn.com/image/fetch/$s_!6E9t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6E9t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png" width="1456" height="656" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:656,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:961509,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198457172?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6E9t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png 424w, https://substackcdn.com/image/fetch/$s_!6E9t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png 848w, https://substackcdn.com/image/fetch/$s_!6E9t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png 1272w, https://substackcdn.com/image/fetch/$s_!6E9t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F822c38c6-d2f5-40c5-8d0c-78a48bfac67f_1608x724.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><em><strong>Interested in sponsoring an issue of Resilient Cyber?</strong></em></p><p><em><strong>This includes reaching over 31,000 subscribers, ranging from Developers, Engineers, Architects, CISO&#8217;s/Security Leaders and Business Executives</strong></em></p><p><em><strong>Reach out below!</strong></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;mailto:sponsorships@resilientcyber.io&quot;,&quot;text&quot;:&quot;-> Contact Us! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="mailto:sponsorships@resilientcyber.io"><span>-&gt; Contact Us! &lt;-</span></a></p><div><hr></div><h2>Exploitation Takes the Lead</h2><p>The headline number is stark and of course gets a lot of the attention, and rightfully so. </p><p>Exploitation of vulnerabilities now accounts for the largest share of initial access vectors in breaches, nearly doubling the share held by phishing. That&#8217;s a complete inversion of the hierarchy that dominated the DBIR for over a decade, where stolen credentials and social engineering sat comfortably at the top of the chart and vulnerability exploitation was a secondary concern.</p><p>This isn&#8217;t a marginal shift either. </p><p>The DBIR shows exploitation&#8217;s share growing year over year while credential-based initial access flattens and the structural reason is straightforward. The attack surface has expanded faster than any organization&#8217;s ability to defend it, and the math favors the attacker. </p><p>As I laid out in <strong><a href="link">The Attack Surface Exponential</a></strong>, the combination of cloud-native architectures, third-party dependencies, and sprawling SaaS footprints means there are simply more vulnerable entry points than any security team can monitor, let alone patch, in any reasonable timeframe.</p><p>The DBIR found that only 26% of critical KEV vulnerabilities were fully remediated in 2025, down from 38% the prior year, with a median time to full resolution of 43 days, almost two weeks more than the previous year. Edge devices sit at the boundary between the internet and the internal network, and attackers have learned to target them precisely because they're notoriously slow to patch and often lack the monitoring coverage that endpoints receive.</p><p>The exploitation pattern also shows up in the third-party data. Third-party involvement in breaches surged to 48%, a 60% year-over-year increase, driven in large part by exploitation of vulnerabilities in vendor software and edge infrastructure. When your perimeter is someone else&#8217;s code, your patch timeline is someone else&#8217;s priority.</p><h2>The Remediation Gap Is a Chasm</h2><blockquote><p><strong>The core problem isn&#8217;t that organizations don&#8217;t know about vulnerabilities. It&#8217;s that they can&#8217;t fix them fast enough to matter. </strong></p></blockquote><p>This is the remediation gap I&#8217;ve been writing about since <strong><a href="link">Vulnpocalypse</a></strong>, and the 2026 DBIR provides the clearest evidence yet that the gap isn&#8217;t just persistent. It&#8217;s accelerating.</p><p>On one side of the equation, the rate of vulnerability discovery continues to climb. FIRST projected a median of approximately 59,000 new CVEs for 2025, a 50% increase over the prior year. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L2cv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L2cv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png 424w, https://substackcdn.com/image/fetch/$s_!L2cv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png 848w, https://substackcdn.com/image/fetch/$s_!L2cv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png 1272w, https://substackcdn.com/image/fetch/$s_!L2cv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L2cv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png" width="1264" height="649" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db8e9278-19c9-4267-b298-c9768048faab_1264x649.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:649,&quot;width&quot;:1264,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:187331,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198457172?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L2cv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png 424w, https://substackcdn.com/image/fetch/$s_!L2cv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png 848w, https://substackcdn.com/image/fetch/$s_!L2cv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png 1272w, https://substackcdn.com/image/fetch/$s_!L2cv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb8e9278-19c9-4267-b298-c9768048faab_1264x649.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The actual numbers tracked close to that projection, and 2026 is on pace to exceed it. Every year produces more vulnerabilities than the last, and nothing about the current software ecosystem suggests that trajectory will flatten. More code is being written by more developers (and non-developers, e.g. vibe coding), with more dependencies, deployed into more environments, at faster release cadences than at any point in history.</p><p>On the other side, remediation capacity hasn&#8217;t scaled to match. </p><p>The DBIR&#8217;s 43-day median remediation figure for edge devices is actually an improvement over some industry benchmarks, but it&#8217;s meaningless against the exploitation timeline. Sergej Epp&#8217;s research tracking the &#8220;<strong><a href="https://zerodayclock.com/">Zero Day Clock</a></strong>&#8221; found that the median time-to-exploit collapsed from 771 days in 2018 to roughly 4 hours by 2024. </p><div id="youtube2-06ogpdOtEE8" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;06ogpdOtEE8&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/06ogpdOtEE8?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><blockquote><p><strong>The defenders are measuring their response in weeks or months and the attackers are measuring theirs in hours.</strong></p></blockquote><p>The MOAK autonomous exploitation project makes this concrete. Researchers demonstrated that an autonomous system could exploit 174 out of 178 CISA Known Exploited Vulnerabilities in an average of 21 minutes per vulnerability, with no human intervention. </p><div id="youtube2-SHKYaV6srmA" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;SHKYaV6srmA&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/SHKYaV6srmA?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>These aren&#8217;t theoretical proof-of-concept demonstrations against lab environments. These are real CVEs from CISA&#8217;s KEV catalog, the same vulnerabilities that federal agencies are mandated to patch, being exploited faster than most organizations can open a change management ticket.</p><p>As I covered in <strong><a href="link">Vulnerability Management in the Age of Autonomous Exploitation</a></strong>, the traditional vulnerability management model assumed that defenders had a meaningful window between disclosure and exploitation. That window functionally no longer exists. </p><p>The DBIR&#8217;s data on exploitation as the leading initial access vector is the downstream consequence of that collapsed timeline playing out at scale.</p><h2>The NVD and the Infrastructure That Isn&#8217;t There</h2><p>The vulnerability data infrastructure that the industry depends on is itself in crisis. As I wrote in <strong><a href="link">The NVD Just Threw in the Towel</a></strong>, NIST reclassified approximately 29,000 backlogged CVEs to a status of &#8220;Not Scheduled,&#8221; effectively acknowledging that it can&#8217;t keep pace with the volume of incoming vulnerabilities. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UQBB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UQBB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png 424w, https://substackcdn.com/image/fetch/$s_!UQBB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png 848w, https://substackcdn.com/image/fetch/$s_!UQBB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png 1272w, https://substackcdn.com/image/fetch/$s_!UQBB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UQBB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png" width="1193" height="641" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:641,&quot;width&quot;:1193,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1271321,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198457172?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UQBB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png 424w, https://substackcdn.com/image/fetch/$s_!UQBB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png 848w, https://substackcdn.com/image/fetch/$s_!UQBB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png 1272w, https://substackcdn.com/image/fetch/$s_!UQBB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e696790-dd53-430a-8420-9294e4b0df12_1193x641.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The National Vulnerability Database was designed for an era when vulnerability discovery was measured in thousands per year. At nearly 60,000 and climbing, the system has hit a structural scaling limit that no amount of incremental funding will solve.</p><p>This matters for the DBIR&#8217;s findings because the entire vulnerability management lifecycle, from discovery to prioritization to remediation, depends on accurate, timely enrichment data. </p><p>When the NVD can&#8217;t provide CVSS scores, CPE mappings, or affected product information within any reasonable timeframe, organizations are flying blind on which vulnerabilities actually affect their environment and which ones represent real exploitability risk. The prioritization models that security teams rely on to triage their backlogs are only as good as the data feeding them, and that data pipeline is increasingly unreliable.</p><p>The result is predictable and shouldn&#8217;t be surprising to anyone who&#8217;s been paying attention for years. Teams are drowning in vulnerability backlogs they can&#8217;t meaningfully prioritize, while attackers exploit the specific vulnerabilities that matter most. </p><p>The DBIR&#8217;s exploitation data isn&#8217;t just a story about attackers getting faster. It&#8217;s a story about the defensive infrastructure failing to provide the information defenders need to keep up.</p><h2>Ransomware, SMBs, and the Business Model That Works</h2><p>Ransomware was present in 48% of all breaches analyzed in the 2026 DBIR, up from 44% the prior year. For small and midsize businesses, the number was 88%. That&#8217;s not a typo. Nearly nine out of ten breaches affecting SMBs involved ransomware.</p><p>The economics explain why. </p><p>The median ransom payment declined to $139,875 down from $150,000, driven partly by the fact that 69% of victim organizations chose not to pay, up from 51% in 2022. But ransomware operators have adapted by shifting to volume over margin. They&#8217;re targeting smaller organizations that lack the security infrastructure, staffing, and incident response capabilities to prevent or recover from an attack. </p><blockquote><p><strong>When the cost of an attack is negligible and the success rate against SMBs is high, a lower per-target yield still produces enormous aggregate revenue.</strong></p></blockquote><p>The DBIR also surfaced a troubling pipeline between infostealers and ransomware. Roughly 50% of ransomware victims had a credential leak appear in infostealer logs within 95 days before the breach. This suggests that the ransomware attack chain is increasingly industrialized, with initial access brokers harvesting credentials at scale via infostealers and selling them to ransomware operators who handle the deployment. </p><p>The credential harvesting and the exploitation aren&#8217;t separate problems, they&#8217;re connected stages of the same kill chain.</p><p>This industrialization also shows up in the tooling data. Attacker use of remote monitoring and management tools increased by 240%, a signal that threat actors are increasingly leveraging legitimate administration tools to blend into normal network activity and avoid detection. </p><p>The line between &#8220;legitimate IT operations&#8221; and &#8220;active compromise&#8221; is blurring in ways that make traditional detection approaches less effective.</p><h2>GenAI and the Attacker Curve</h2><p>The 2026 DBIR introduces data on generative AI usage by threat actors, and while the findings are early, they track with what I&#8217;ve been writing about in <strong><a href="link">The AI Cyber Capability Curve</a></strong>. GenAI-generated content appeared in phishing emails at a growing rate, with synthetic text enabling more convincing and scalable social engineering. The report also found that 15% of non-malicious bot traffic is now AI-driven, growing at 21% month over month.</p><p>The more interesting finding is on the defender side. </p><p>The DBIR found that 45% of employees are regular users of AI tools in the workplace, but 12% of data loss prevention events flagged Shadow AI usage, meaning employees accessing AI tools outside of sanctioned enterprise channels. The security implications are twofold. Organizations are struggling to maintain visibility into how AI tools are being used internally, and the data flowing into unsanctioned AI services represents an expanding and largely unmeasured exfiltration risk.</p><p>This isn&#8217;t a future problem, it&#8217;s a present one. </p><p>The DBIR&#8217;s inclusion of GenAI metrics signals that the report&#8217;s authors see AI-enabled threats and AI-related risks as a permanent addition to the breach data taxonomy, not a passing trend.</p><p>I suspect we will see a surge in AI-assisted vulnerability exploitation in future years of the DBIR, driven by the industrialization of AI discovery and autonomous exploitation.</p><h2>Espionage and the Blurring of Motive</h2><p>One of the quieter but structurally significant findings in the 2026 DBIR is that espionage-motivated attacks accounted for 13% of breaches, with a notable overlap between espionage and financial motivation. Threat actors that historically operated with a single clear motive are increasingly pursuing both intelligence collection and monetization within the same campaign.</p><p>This blurring complicates the defender&#8217;s calculus. </p><p>An organization that assumed it wasn&#8217;t a target for state-sponsored activity because it lacks classified data or geopolitical significance may find itself compromised by an actor whose primary goal is espionage but who deploys ransomware as a secondary revenue stream, or as cover for the real objective. </p><p>The traditional segmentation between &#8220;nation-state threats&#8221; and &#8220;financially motivated cybercrime&#8221; is breaking down, and the DBIR&#8217;s data reflects that convergence.</p><h2>The Counter-Narrative Nobody Wants to Hear</h2><p>Here is where the analysis gets uncomfortable and even counter-intuitive, given much of the FUD the security industry uses to try and drive spending, using cyber attackers and impacts as a forcing function.</p><p>Despite 22,624 confirmed breaches in a single year's dataset, despite exploitation as the leading attack vector, despite ransomware hitting 88% of SMB breaches, the overwhelming majority of breached organizations are still in business.. The site <strong><a href="link">destroyedbybreach.com</a></strong>, run by <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Adrian Sanabria&quot;,&quot;id&quot;:11988704,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a89717e5-a927-4084-ad86-69068727dbf3_1632x1632.png&quot;,&quot;uuid&quot;:&quot;1c4f22b1-e9b6-4b2e-9c39-ced34692c5ea&quot;}" data-component-name="MentionToDOM"></span> tracks public companies that suffered major breaches and documents what happened to them afterward. The answer, in most cases, is not much. Stock prices recover, revenue continues, and customers often stay. </p><p>I will caveat this with those being public companies, which tend to be larger, more well resourced, and able to weather the storm of a cyber incident more so than SMB&#8217;s. This is a point others such as Kelly Shortridge have made, in her piece &#8220;<strong><a href="https://kellyshortridge.com/blog/posts/markets-dgaf-about-cybersecurity/">Markets DGAF About Cybersecurity</a></strong>&#8221;. Other resources <strong><a href="https://www.westbourne.partners/perspectives/the-financial-impact-of-cybersecurity-on-stock-price-and-corporate-valuation">report</a></strong> that while stock prices may drop 5.3% post breach, they tend to recover and even climb higher within 46 days of an incident. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TSLz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TSLz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png 424w, https://substackcdn.com/image/fetch/$s_!TSLz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png 848w, https://substackcdn.com/image/fetch/$s_!TSLz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png 1272w, https://substackcdn.com/image/fetch/$s_!TSLz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TSLz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png" width="649" height="329.6816367265469" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:509,&quot;width&quot;:1002,&quot;resizeWidth&quot;:649,&quot;bytes&quot;:289979,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198457172?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TSLz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png 424w, https://substackcdn.com/image/fetch/$s_!TSLz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png 848w, https://substackcdn.com/image/fetch/$s_!TSLz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png 1272w, https://substackcdn.com/image/fetch/$s_!TSLz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe01d135e-9020-49d2-b7fd-e661ed3463e7_1002x509.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>All that said, the lack of major systemic impacts, and continued revenue, stock price rebound etc. creates a perverse incentive structure that sits at the heart of why vulnerability management remains chronically underfunded and why exploitation keeps climbing as an initial access vector. </p><p>If breaches don&#8217;t destroy companies, the economic pressure to invest in prevention is weak. Boards and executives make rational capital allocation decisions based on observed consequences, and the observed consequences of most breaches are manageable. Insurance covers a portion of the loss, customers express concern but rarely leave. Regulatory fines exist but are typically absorbed as a cost of doing business.</p><p>The problem with this calculus is that it&#8217;s backward-looking. It assumes future breaches will carry the same consequences as past ones, even as the exploitation timeline collapses, autonomous attack tools proliferate, and regulatory regimes tighten. </p><p>That said, there is the reality that we&#8217;re currently in a deregulatory environment in the U.S. at the Federal level, so any concept of software liability is likely tabled for now, so vendors don&#8217;t feel the pressure to address the technical debt they ship downstream to consumers and society either. This of course is why many consider cybersecurity to be a market failure. </p><h2>Why Exploitation Stays at Number One</h2><p>The structural forces driving exploitation to the top of the DBIR&#8217;s initial access chart aren&#8217;t temporary, they&#8217;re compounding.</p><p>The attack surface continues to expand. Cloud adoption, third-party integrations, API proliferation, and the rise of agentic AI systems are all adding new categories of exploitable surface faster than security programs can inventory them, let alone secure them. </p><p>The NVD&#8217;s inability to keep pace with vulnerability enumeration means the data infrastructure that prioritization depends on is degrading at the same time that the volume of vulnerabilities is increasing. Autonomous exploitation tools are lowering the skill barrier and collapsing the time-to-exploit to hours, while defenders still operate on patch cycles measured in weeks and months, and the economic incentives to invest in vulnerability management remain structurally weak because breaches, so far, haven&#8217;t been existential events for most organizations.</p><p>This is the exploitation era. </p><p>Not because a single report declared it, but because every structural trend in the data points the same direction. </p><blockquote><p><strong>More vulnerabilities, faster exploitation, slower remediation, expanding attack surfaces, and insufficient economic consequences to force a different outcome.</strong></p></blockquote><p>The question the DBIR leaves unanswered isn&#8217;t whether exploitation will remain the leading initial access vector. The data makes that nearly certain for the foreseeable future. The real question is what it will take to change the incentive structure that makes this outcome rational. </p><p>Until the cost of inaction exceeds the cost of investment, the gap between what attackers can exploit and what defenders can remediate will continue to widen, and the DBIR will continue to document the consequences.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Agentic GRC Revolution]]></title><description><![CDATA[Rethinking legacy GRC through AI agents, autonomous workflows, and continuous assurance]]></description><link>https://www.resilientcyber.io/p/the-agentic-grc-revolution</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-agentic-grc-revolution</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Wed, 20 May 2026 12:03:40 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/198447588/5133b80c61f40449bcd6f6d210da9208.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode, we sat down with Richa Kaul, Founder and CEO of <strong><a href="https://www.complyance.com/">Complyance</a></strong>, the AI-native enterprise GRC platform that recently raised a $20M Series A led by Google Ventures and counts Dropbox, Major League Soccer, CVS Health, and other Fortune 500 brands as customers.</p><p>Richa brings a rare blend of perspectives to this conversation. She started her career on the policy side at McKinsey and the Commonwealth of Virginia, working on everything from drone privacy to autonomous vehicle policy, then moved into tech as Chief Strategy Officer at a legal tech company where she felt firsthand the impact of the regulations she had helped shape. </p><p><strong><a href="https://www.complyance.com/">Complyance</a></strong> is her answer to the question of how you let companies meet their regulatory obligations without burning the resources that should be going toward real security work.</p><div id="youtube2-CAVrnAt8Evs" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;CAVrnAt8Evs&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/CAVrnAt8Evs?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><p><strong>Prefer to Listen?</strong></p><p><strong><a href="https://podcasts.apple.com/us/podcast/the-agentic-grc-revolution/id1555928024?i=1000768612119">Apple Podcasts</a></strong></p><p><strong><a href="https://open.spotify.com/episode/3sGE9gxIU0GK2bEVI3106B?si=YmbQe9IxSFqB6c3jOaOSZg">Spotify</a></strong></p><p><strong>Be sure to leave a review and subscribe!</strong></p><div><hr></div><ul><li><p>Why the GRC market has a wide-open white space in the upper-right corner of the matrix, where enterprise customers meet truly agentic AI, and why the legacy incumbents and the modern startup-focused platforms have both missed it</p></li><li><p>The legacy GRC practices still running by default in large enterprises today, and why even with agents in production, mature enterprises still want a final human check before the auditor sees anything</p></li><li><p>How AI is letting enterprises leapfrog the technological waves they sat out, including the cloud-native, API-first, and automation eras that GRC largely missed</p></li><li><p>Why the GRC workforce conversation should not be about replacement, including a customer anecdote from Northeast Georgia Health System where AI agents are letting the security leader hire more junior analysts because the agents themselves carry the domain expertise and train the team</p></li><li><p>How Complyance navigates the SOC 2 commoditization and rubber-stamp crisis by drawing a hard commercial line, never selling external audits, never pushing audit partners, and never letting their agents touch the external assessment of controls</p></li><li><p>The &#8220;pane of glass&#8221; model for the auditor relationship, where internal AI agents and external assessor AI agents operate independently on each side, with humans signing off on both</p></li><li><p>What agentic GRC actually unlocks beyond the prior wave of integration-based continuous monitoring, including qualitative human-like assessments that catch scope drift, incomplete evidence, and gaps that red light / green light integration checks will never find</p></li><li><p>How Complyance architects against hallucination by running a multi-agent design where each agent has blinders on and operates only on the micro use case it has been assigned, with tight inputs producing tight outputs</p></li><li><p>A new approach to framework sprawl that flips the model, where instead of being reactive to thirty overlapping frameworks, organizations get proactive about their actual policies and let the agent map evidence into the relevant controls automatically</p></li><li><p>Richa&#8217;s five-year vision for the industry, and why she calls agentic AI the biggest transformation GRC has ever seen, with teams finally shifting from reactive fire drills toward building security culture and getting a real grasp of organizational risk</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Perimeter Problem Won't Go Away]]></title><description><![CDATA[A look at Intruder's 2026 Attack Surface Management Index]]></description><link>https://www.resilientcyber.io/p/the-perimeter-problem-wont-go-away</link><guid isPermaLink="false">https://www.resilientcyber.io/p/the-perimeter-problem-wont-go-away</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Tue, 19 May 2026 13:49:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ifcT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>While the industry obsesses over AI-generated exploits and autonomous attack chains, the<a href="https://www.intruder.io/downloads/attack-surface-management-index"> </a><strong><a href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=resilientcyber&amp;utm_medium=p_referral&amp;utm_campaign=global%7Cfixed%7Casm_index">2026 Attack Surface Management Index</a></strong> from<a href="https://www.intruder.io/"> </a><strong><a href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=resilientcyber&amp;utm_medium=p_referral&amp;utm_campaign=global%7Cfixed%7Casm_index">Intruder</a></strong> tells a more uncomfortable story.</p><p>The perimeter problems that organizations have been ignoring for years haven&#8217;t gone away, and the data on who is actually fixing them and how fast reveals structural gaps that no amount of AI hype addresses. Across thousands of organizations and the 12 months leading up to March 2026, the report analyzed real-world attack surface data to measure what&#8217;s exposed, how long it stays exposed, and which organizations are doing something about it.</p><p>This is the third piece I&#8217;ve written in collaboration with the Intruder team, following my analysis of the<a href="https://www.resilientcyber.io/p/exposure-management-metrics"> </a><strong><a href="https://www.resilientcyber.io/p/exposure-management-metrics">2025 Exposure Management Index</a></strong> and the<a href="https://www.resilientcyber.io/p/security-in-the-middle"> </a><strong><a href="https://www.resilientcyber.io/p/security-in-the-middle">Security Middle Child report</a></strong>, and the throughline across all three is consistent. The data keeps revealing the same structural pattern. Organizations know what&#8217;s exposed and they know what needs to be fixed. The gap is in the operational capacity to actually do it, and that gap widens predictably based on organization size, industry, and the maturity of the security program and AI is exacerbating all of the existing challenges, as the rate of vulnerability discovery and exploitation continues to collapse.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=resilientcyber&amp;utm_medium=p_referral&amp;utm_campaign=global%7Cfixed%7Casm_index" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ifcT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png 424w, https://substackcdn.com/image/fetch/$s_!ifcT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png 848w, https://substackcdn.com/image/fetch/$s_!ifcT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png 1272w, https://substackcdn.com/image/fetch/$s_!ifcT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ifcT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png" width="634" height="403.62389813907936" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:650,&quot;width&quot;:1021,&quot;resizeWidth&quot;:634,&quot;bytes&quot;:629072,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.intruder.io/blog/attack-surface-exposures?utm_source=resilientcyber&amp;utm_medium=p_referral&amp;utm_campaign=global%7Cfixed%7Casm_index&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198410670?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ifcT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png 424w, https://substackcdn.com/image/fetch/$s_!ifcT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png 848w, https://substackcdn.com/image/fetch/$s_!ifcT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png 1272w, https://substackcdn.com/image/fetch/$s_!ifcT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3759a507-f8e1-4bcd-b6a3-4877ec7cf85e_1021x650.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.intruder.io/blog/attack-surface-exposures?utm_source=resilientcyber&amp;utm_medium=p_referral&amp;utm_campaign=global%7Cfixed%7Casm_index&quot;,&quot;text&quot;:&quot;-> Check Out The Report! <-&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.intruder.io/blog/attack-surface-exposures?utm_source=resilientcyber&amp;utm_medium=p_referral&amp;utm_campaign=global%7Cfixed%7Casm_index"><span>-&gt; Check Out The Report! &lt;-</span></a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2><strong>What&#8217;s Actually Exposed</strong></h2><p>The report&#8217;s attack surface exposure data confirms what most practitioners already suspect but rarely have the aggregate data to prove. 60% of organizations had exposed HTTP admin panels, with WordPress Admin and phpMyAdmin leading the list. 49% had exposed ports and services, with Remote Desktop, SNMP, and UPnP among the most common. 42% had exposed databases, with MySQL and Postgres dominating, and 30% had exposed files and information, including API documentation, web.config files, and Apache configuration files.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kY-v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kY-v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png 424w, https://substackcdn.com/image/fetch/$s_!kY-v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png 848w, https://substackcdn.com/image/fetch/$s_!kY-v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png 1272w, https://substackcdn.com/image/fetch/$s_!kY-v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kY-v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png" width="483" height="483.739663093415" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:654,&quot;width&quot;:653,&quot;resizeWidth&quot;:483,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kY-v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png 424w, https://substackcdn.com/image/fetch/$s_!kY-v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png 848w, https://substackcdn.com/image/fetch/$s_!kY-v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png 1272w, https://substackcdn.com/image/fetch/$s_!kY-v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73536ae9-5abb-4a98-8aa6-a11c67189022_653x654.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The top 10 most common attack surface issues tell a story that should make every security team reflect on the effectiveness of their activities. Over a quarter of organizations, 26%, have an exposed MySQL database. One in six have an exposed Postgres database and more than one in seven have exposed API documentation, which ranked ahead of Remote Desktop in prevalence. These aren&#8217;t sophisticated misconfigurations buried deep in complex architectures. They&#8217;re basic exposure issues that have been well-understood for years, and they persist at scale because the incentive structure doesn&#8217;t force organizations to address them until something goes wrong. This of course is the longstanding bolting on rather than building in of security that we all painfully know so well.</p><p>The exposed API documentation finding is one that jumped out to me. Exposed Swagger or API docs give an attacker a complete roadmap to the backend, every endpoint, every parameter, every authentication requirement laid out in structured, machine-readable format. In a world where AI-powered reconnaissance tools can ingest that documentation and automatically generate attack payloads, leaving API docs publicly accessible isn&#8217;t just an information leak, it&#8217;s handing the attacker an instruction manual.</p><p>The database exposure figures are equally telling. The report references the 2020 PLEASE_READ_ME ransomware campaign that compromised over <strong>250,000</strong> databases by brute-forcing weak credentials on exposed MySQL instances. That was five years ago, and 26% of organizations still have MySQL databases visible on the internet.</p><p>This isn&#8217;t a knowledge problem, as security teams already know exposed databases are a risk. It&#8217;s a prioritization and visibility problem, where the exposed asset either isn&#8217;t known to the security team or sits in a remediation queue behind hundreds of other issues competing for the same limited engineering cycles.</p><h2><strong>The Midmarket Remediation Trap</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YV8S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YV8S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png 424w, https://substackcdn.com/image/fetch/$s_!YV8S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png 848w, https://substackcdn.com/image/fetch/$s_!YV8S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png 1272w, https://substackcdn.com/image/fetch/$s_!YV8S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YV8S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png" width="531" height="528.5753424657535" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:654,&quot;width&quot;:657,&quot;resizeWidth&quot;:531,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YV8S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png 424w, https://substackcdn.com/image/fetch/$s_!YV8S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png 848w, https://substackcdn.com/image/fetch/$s_!YV8S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png 1272w, https://substackcdn.com/image/fetch/$s_!YV8S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F78449bdf-eea5-4f2b-b251-9315646b9f5f_657x654.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The remediation data by organization size reveals a pattern I&#8217;ve been tracking across my prior work with Intruder, and it reinforces the structural argument from the<a href="https://www.resilientcyber.io/p/security-in-the-middle"> </a><strong><a href="https://www.resilientcyber.io/p/security-in-the-middle">Security Middle Child report</a></strong>. </p><p>The smallest organizations (1-250 employees) remediate fastest, averaging 14-18 days. The largest enterprises (50,000+ employees) are even faster at 11 days. But the organizations in between, specifically the 5,000 to 10,000 employee band, have the slowest average remediation time at 56 days.</p><p>That&#8217;s not a random distribution, but instead is a systemic signal. Small organizations have small attack surfaces and tight feedback loops between the person who finds the issue and the person who fixes it. Large enterprises have the budget, headcount, and tooling maturity to throw resources at the problem. The midmarket has the attack surface complexity of an enterprise without the resources to match.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D3k4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D3k4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png 424w, https://substackcdn.com/image/fetch/$s_!D3k4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png 848w, https://substackcdn.com/image/fetch/$s_!D3k4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png 1272w, https://substackcdn.com/image/fetch/$s_!D3k4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D3k4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png" width="676" height="360.2534161490683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:429,&quot;width&quot;:805,&quot;resizeWidth&quot;:676,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D3k4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png 424w, https://substackcdn.com/image/fetch/$s_!D3k4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png 848w, https://substackcdn.com/image/fetch/$s_!D3k4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png 1272w, https://substackcdn.com/image/fetch/$s_!D3k4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F102c8293-0b07-4e96-b406-47f84e1ef5ae_805x429.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The internet-facing asset counts make this concrete. Organizations with 5,000+ employees manage an average of nearly 1,700 external assets. That&#8217;s more than twice as many as those in the 1,000-5,000 band, and the inflection point in both scale and difficulty sits right in that middle range where headcount and tooling haven&#8217;t caught up to the size of the perimeter. As I covered in<a href="https://www.resilientcyber.io/p/security-in-the-middle"> </a><strong><a href="https://www.resilientcyber.io/p/security-in-the-middle">Security in the Middle</a></strong>, 42% of midmarket security teams describe themselves as stretched, overwhelmed, or consistently behind. The remediation data here explains why. These teams aren&#8217;t slow because they&#8217;re negligent. They&#8217;re slow because the ratio of exposed assets to available engineering capacity makes faster remediation physically impossible without either reducing the attack surface or significantly increasing the resources dedicated to managing it. Neither of these are an easily solved problem, as the security team can&#8217;t often dictate the asset footprint, the business does. Conversely, security also has to live within finite budgets and resources, leading to challenges with coverage.</p><p>The 56-day average for the 5,000-10,000 employee band compared to the 11-day average for organizations with 50,000+ employees isn&#8217;t a marginal difference. It&#8217;s a 5x gap that represents weeks of additional exposure during which any of those issues could be exploited. For the midmarket CISO reading this, the implication is that remediation speed isn&#8217;t primarily a process problem or a tooling problem. It&#8217;s a resource allocation problem that requires either a fundamentally different approach to attack surface management or a honest conversation with the board about what the current headcount can actually protect.</p><h2><strong>Industry Disparities Tell a Structural Story</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cfxG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cfxG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png 424w, https://substackcdn.com/image/fetch/$s_!cfxG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png 848w, https://substackcdn.com/image/fetch/$s_!cfxG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png 1272w, https://substackcdn.com/image/fetch/$s_!cfxG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cfxG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png" width="628" height="411.02477183833116" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c049402-6738-4534-88d3-3a57c1f70852_767x502.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:767,&quot;resizeWidth&quot;:628,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cfxG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png 424w, https://substackcdn.com/image/fetch/$s_!cfxG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png 848w, https://substackcdn.com/image/fetch/$s_!cfxG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png 1272w, https://substackcdn.com/image/fetch/$s_!cfxG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c049402-6738-4534-88d3-3a57c1f70852_767x502.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The industry-level remediation data is where the report gets genuinely interesting, because the variance across sectors reveals how much industry structure, regulatory pressure, and business model shape security outcomes.</p><p>Insurance organizations have the slowest average remediation time at 50 days, while Retail remediates fastest at 10 days. That&#8217;s a 5x gap between industries, and it maps cleanly to architectural and operational differences rather than to any measure of security investment or intention. Insurance also has the largest attack surface per asset at 4.1 internet-facing services per asset compared to the cross-industry average, which compounds the remediation challenge. More services per asset means more things that can go wrong per target, and more things that need to be fixed when they do.</p><p>The split between Banks and Financial Services is revealing. Banks remediate in an average of 11 days while the broader Financial Services category takes 24 days, more than twice as long. Both operate under heavy regulatory pressure, both presumably invest significantly in security, and both understand the consequences of a breach. The difference is likely architectural and operational. Banks tend to have more mature, more consolidated infrastructure with stronger central security governance, while the broader Financial Services category includes a wider range of organizational maturity and infrastructure complexity.</p><p>Pharmaceuticals and Biotech remediate at 43 days and Automobiles and Components at 43 days, both sectors with significant resources that you&#8217;d expect to move faster. But both also tend to have complex, legacy-heavy infrastructure with operational technology components that slow down patching cycles. Healthcare, which often gets positioned as the industry with the worst security posture, actually remediates at 15 days, faster than Financial Services, Insurance, Pharma, and Auto. That likely reflects the regulatory pressure from HIPAA combined with the relatively modern, cloud-hosted infrastructure that many healthcare organizations have adopted in recent years.</p><p>The practitioner takeaway from the industry data isn&#8217;t about ranking sectors from best to worst. It&#8217;s that remediation speed is a function of organizational structure, infrastructure architecture, regulatory pressure, and operational maturity, and those factors vary more within industries than the averages suggest.</p><p>An insurance company running a modern cloud-native stack will remediate faster than a software company running legacy infrastructure, regardless of what the industry averages say. The averages are useful as benchmarks, but the real value is understanding which structural factors in your own environment are constraining your remediation speed and whether those constraints are fixable or inherent.</p><h2><strong>The Persistence of Old Vulnerabilities</strong></h2><p>One of the most consistent findings across both this year&#8217;s report and the<a href="https://www.resilientcyber.io/p/exposure-management-metrics"> </a><strong><a href="https://www.resilientcyber.io/p/exposure-management-metrics">2025 Exposure Management Index</a></strong> I covered previously is that old vulnerabilities don&#8217;t go away. As I discussed in that earlier analysis, AI is lowering the technical barrier for exploitation, making it faster and more cost-effective for attackers to write new exploits targeting older CVEs that organizations left unpatched. The 2026 data reinforces this pattern. The same classes of exposures, open databases, exposed admin panels, publicly accessible configuration files, keep showing up year after year because organizations address individual instances without fixing the systemic conditions that produce them.</p><p>This is the remediation gap in its purest form. The rate at which new exposures appear, driven by infrastructure growth, cloud migration, shadow IT, and AI-accelerated development, consistently outpaces the rate at which security teams can identify and fix them. As I covered in<a href="https://www.resilientcyber.io/p/the-attack-surface-exponential"> </a><strong><a href="https://www.resilientcyber.io/p/the-attack-surface-exponential">The Attack Surface Exponential</a></strong>, GitHub is on pace for 14 billion commits in 2026, a 14x year-over-year increase driven by AI coding agents, and each of those commits potentially introduces new assets, new services, and new attack surface that the security team may not even know exists.</p><p>The exposed API documentation finding connects directly to this dynamic. As organizations deploy more APIs to support AI integrations, agent-to-agent communication, and microservices architectures, the number of potential information leaks and attack entry points multiplies. When 15% of organizations have API documentation publicly exposed and AI tools can automatically parse that documentation to identify exploitable patterns, the gap between how fast attack surface grows and how fast security teams can manage it becomes a strategic risk rather than an operational nuisance.</p><h2><strong>What Continuous Visibility Actually Changes</strong></h2><p>The structural argument running through all of this data is that periodic assessment can&#8217;t keep pace with continuous change. Running a quarterly penetration test or an annual vulnerability assessment against an attack surface that changes daily is the security equivalent of checking your bank balance once a year and assuming the number is still accurate. The organizations in this data set that remediate fastest aren&#8217;t doing so because they have better remediation processes. They&#8217;re doing so because they have continuous visibility into what&#8217;s exposed and can address issues as they appear rather than discovering them weeks or months later during a scheduled assessment.</p><p>This is where the shift from periodic vulnerability scanning to continuous attack surface management becomes a practical necessity rather than a vendor talking point. The data shows that the organizations with the fastest remediation times, the small organizations with tight feedback loops and the largest enterprises with mature tooling, share a common trait.</p><p>They&#8217;ve reduced the time between &#8220;something is exposed&#8221; and &#8220;someone knows about it&#8221; to near zero. The midmarket organizations struggling at 30-56 days haven&#8217;t necessarily failed to adopt the right tools or processes. They&#8217;ve failed to close the visibility gap, and until that gap closes, remediation will always lag behind exposure.</p><p>Intruder&#8217;s approach to this problem, continuous monitoring of internet-facing assets with automated discovery of unknown or unexpected services, directly addresses the visibility constraint that drives the remediation delays visible in the data. When a large portion of detected assets are unknown to the organization, and exposed databases persist at 26% prevalence five years after a mass exploitation campaign demonstrated the consequences, the problem isn&#8217;t that organizations don&#8217;t understand the risk. It&#8217;s that they can&#8217;t fix what they can&#8217;t see, and they can&#8217;t see what they aren&#8217;t continuously monitoring.</p><h2><strong>The Honest Conversation</strong></h2><p>The 2026 Attack Surface Management Index paints a picture that should be familiar to anyone who has been working in this space for more than a few years. The specific numbers change, remediation times improve in some categories, new exposure types emerge as architectures evolve, but the structural pattern holds.</p><p>Organizations are operating with more internet-facing assets than they realize, those assets expose basic security issues at rates that haven&#8217;t fundamentally changed, and the capacity to address those issues is distributed unevenly based on organizational size and industry structure.</p><p>The honest conversation this data forces is about expectations. If your organization sits in the midmarket band with 250 to 10,000 employees and your remediation times look anything like the 25-56 day averages in this report, the path forward isn&#8217;t telling your team to work harder or faster.</p><p>The path forward is either reducing the attack surface they&#8217;re responsible for, giving them continuous visibility into what&#8217;s actually exposed so they can prioritize based on real-time risk rather than periodic snapshots, or getting the headcount and budget that matches the actual size of the problem. Any other approach is asking people to bail water out of a boat faster than it&#8217;s coming in, and this data shows exactly how that works out.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Coding Agents, Competitive Dynamics and Cybersecurity]]></title><description><![CDATA[Why Coding Agents Are the (Current) Crown Jewel of Agentic AI Security]]></description><link>https://www.resilientcyber.io/p/coding-agents-competitive-dynamics</link><guid isPermaLink="false">https://www.resilientcyber.io/p/coding-agents-competitive-dynamics</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Mon, 18 May 2026 17:37:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yTGD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Coding agents are the first agentic workload that broke through to enterprise scale.</p><p>They&#8217;re also the first to inherit developer-level blast radius, with full access to source code, secrets, build pipelines, and production deployment paths. That combination is why coding agent security isn&#8217;t a niche within the broader agentic AI security conversation, it&#8217;s becoming the proving ground for the entire category. </p><p>Whatever security primitives mature here will define the playbook for every other agentic workload that follows.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yTGD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yTGD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!yTGD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!yTGD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!yTGD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yTGD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8346771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198245707?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yTGD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png 424w, https://substackcdn.com/image/fetch/$s_!yTGD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png 848w, https://substackcdn.com/image/fetch/$s_!yTGD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!yTGD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F899205e8-dcf5-4910-b798-9357e2052fcd_2816x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption"><strong>Thanks for reading the Resilient Cyber Newsletter! Subscribe for FREE and join 31,000+ readers to receive weekly updates with the latest news across AppSec, Leadership, AI, Supply Chain, and more for Cybersecurity.</strong></p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Coding Is the Breakout AI Use Case</h1><p>The data on coding agent adoption has moved past early-adopter territory and into enterprise-scale penetration. The <strong><a href="https://www.anthropic.com/economic-index">Anthropic Economic Index</a></strong> found that 36% of Claude.ai usage is coding, making it the single largest use case on the platform. Cursor hit $2B in annual recurring revenue in roughly 28 months. Claude Code reached a $2.5B run-rate in under 12 months. GitHub Copilot sits at 4.7M paid seats. </p><p>The JetBrains <strong><a href="https://blog.jetbrains.com/research/2025/10/state-of-developer-ecosystem-2025/">2025 Developer Survey</a></strong> found that 85% of developers now use AI tools regularly and 62% rely on at least one coding assistant as part of their daily workflow. The <strong><a href="https://octoverse.github.com/">Octoverse 2025 report</a></strong> found that 80% of new GitHub developers use Copilot in their first week on the platform. Gartner projects 90% of enterprise software engineers will use AI coding assistants by 2028, up from less than 14% in early 2024.</p><blockquote><p><strong>These aren&#8217;t projections about future adoption curves, they describe what&#8217;s already happening. </strong></p></blockquote><p>Coding agents have crossed the threshold from experimental tooling to default infrastructure in how software gets written, reviewed, and shipped.</p><h2>Code Volume Is Exploding</h2><p>The adoption numbers tell one story, but the code volume numbers tell another, and they&#8217;re harder to ignore. GitHub is on pace for 14 billion commits in 2026, a 14x increase year over year, with weekly commit volume hitting 275 million. </p><p>Claude Code alone accounts for an estimated 4% of public GitHub commits as of early 2026, a share that doubled in roughly six weeks and is projected to reach 20% or more by year end. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rhdZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rhdZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png 424w, https://substackcdn.com/image/fetch/$s_!rhdZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png 848w, https://substackcdn.com/image/fetch/$s_!rhdZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png 1272w, https://substackcdn.com/image/fetch/$s_!rhdZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rhdZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png" width="473" height="405.16184210526313" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:651,&quot;width&quot;:760,&quot;resizeWidth&quot;:473,&quot;bytes&quot;:237496,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198245707?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rhdZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png 424w, https://substackcdn.com/image/fetch/$s_!rhdZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png 848w, https://substackcdn.com/image/fetch/$s_!rhdZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png 1272w, https://substackcdn.com/image/fetch/$s_!rhdZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1dcd95e-c182-4c7b-894d-79bb596fa534_760x651.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Ramp AI Index for March 2026 showed Anthropic overtaking OpenAI in business adoption at 34.4% versus 32.3%, with Claude Code reaching 326,731 daily commits by mid-March.</p><p>This is the largest expansion of write-access to production code in the history of software development. The volume of code being generated, committed, and merged is growing at a rate that outpaces any human review capacity. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XGlm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XGlm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png 424w, https://substackcdn.com/image/fetch/$s_!XGlm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png 848w, https://substackcdn.com/image/fetch/$s_!XGlm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png 1272w, https://substackcdn.com/image/fetch/$s_!XGlm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XGlm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png" width="1173" height="660" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:660,&quot;width&quot;:1173,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:910532,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198245707?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XGlm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png 424w, https://substackcdn.com/image/fetch/$s_!XGlm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png 848w, https://substackcdn.com/image/fetch/$s_!XGlm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png 1272w, https://substackcdn.com/image/fetch/$s_!XGlm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F140c4cb1-e4f7-41c4-a78f-2075c8ca8a5e_1173x660.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>As I covered in <strong><a href="link">Vulnpocalypse</a></strong>, the math on vulnerability discovery and remediation was already unfavorable before coding agents entered the picture. The gap between the rate vulnerabilities are introduced and the rate they can be found and fixed was widening, not narrowing. Coding agents accelerate the introduction side of that equation dramatically while currently doing nothing to improve the remediation side, and the downstream implications for vulnerability management programs are significant.</p><p>The security question isn&#8217;t whether AI-generated code contains more or fewer vulnerabilities than human-written code.</p><blockquote><p><strong>It&#8217;s that the sheer volume of code entering production has grown by an order of magnitude while the capacity to review, test, and remediate has not scaled proportionally. </strong></p></blockquote><p>The denominator changed, but the security function didn&#8217;t.</p><h2>The Developer Is the Highest-Value Attack Vector</h2><p>The shift in attacker focus toward developer workstations and credentials isn&#8217;t new, but coding agents have made it structurally worse. </p><p>Developer machines hold source code, secrets, build pipeline configurations, cloud credentials, and now permanent agent runtimes with broad system access. The framing of developer workstations as the &#8220;<strong><a href="https://www.csoonline.com/article/4169635/developer-workstations-are-the-new-beachhead.html">new beachhead</a></strong>&#8221; captures the dynamic well. The workstation isn&#8217;t just where code gets written anymore. It&#8217;s where agents with persistent access to git, file systems, shell commands, and cloud SDKs operate continuously.</p><p>The open source supply chain attack data reinforces this. <strong><a href="https://www.sonatype.com/state-of-the-software-supply-chain/2026/open-source-malware">Sonatype&#8217;s 2026 report </a></strong>documented over 454,600 new malicious packages in 2025 alone, with 99% targeting npm. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P1AK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P1AK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png 424w, https://substackcdn.com/image/fetch/$s_!P1AK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png 848w, https://substackcdn.com/image/fetch/$s_!P1AK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png 1272w, https://substackcdn.com/image/fetch/$s_!P1AK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P1AK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png" width="932" height="565" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:565,&quot;width&quot;:932,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42579,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198245707?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P1AK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png 424w, https://substackcdn.com/image/fetch/$s_!P1AK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png 848w, https://substackcdn.com/image/fetch/$s_!P1AK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png 1272w, https://substackcdn.com/image/fetch/$s_!P1AK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c0c2921-8f10-49b9-a23f-956b5772dd45_932x565.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Shai-Hulud campaign became the first self-replicating npm worm, and its second wave (Shai-Hulud 2.0) compromised over 25,000 GitHub repositories and 600 to 800 npm packages. <strong><a href="https://unit42.paloaltonetworks.com/npm-supply-chain-attack/">Unit 42 assessed</a></strong> with moderate confidence that LLMs were used to generate parts of the payload. </p><p>The named campaigns of the past 12 months, including s1ngularity targeting Nx, the chalk and debug compromises, the axios supply chain attack, the LiteLLM credential harvesting operation, and the TanStack incident, all follow the same pattern. </p><blockquote><p><strong>They target the developer environment, they target credentials, and they increasingly target the tools developers trust.</strong></p></blockquote><p>Coding agents sit directly in this attack path. </p><p>They consume packages, execute shell commands, read configuration files, and interact with the same repositories and registries that attackers are poisoning. The Nx malware campaign specifically targeted Claude Code, using flags designed to bypass its guardrails. This isn&#8217;t hypothetical risk modeling, it&#8217;s observed adversary behavior adapting to the tools developers actually use.</p><h2>Coding Agents Amplify Every Existing Developer-Side Risk</h2><p>The risk profile of coding agents goes beyond their role as another tool in the developer&#8217;s stack. </p><p>They inherit the user&#8217;s permissions by default, which means full local file system access, shell execution, git credentials, IDE-stored secrets, dotfiles, and write access to production repositories through commits, pull requests, and CI/CD triggers. <strong><a href="https://www.upguard.com/press/new-research-from-upguard-1-in-5-developers-grant-ai-vibe-coding-tools-unrestricted-workstation-access">UpGuard&#8217;s 2026 research</a></strong> found that 1 in 5 developers grant AI coding tools unrestricted workstation access, and almost 20% allow the AI to automatically save changes to the project&#8217;s main code repository with no human review.</p><p>The CVEs are already here too. Cursor&#8217;s CVE-2026-26268 was a sandbox escape that enabled remote code execution through malicious git repositories, rated 9.9 out of 10 in severity. Check Point disclosed CVE-2025-59536 and CVE-2026-21852 in Claude Code, enabling RCE and API key theft through malicious repository configuration files. </p><p>A separate vulnerability in Claude Code&#8217;s deny-rule implementation allowed command chains exceeding 50 subcommands to silently bypass security restrictions. These aren&#8217;t theoretical attack surfaces. They&#8217;re patched vulnerabilities that demonstrate the blast radius when a coding agent&#8217;s trust model gets exploited.</p><h2>The Persistent Credential Problem Gets Worse</h2><p>Credential exposure and compromise has been a persistent attack vector in every major threat report for years. </p><p>M-Trends and the DBIR consistently rank stolen credentials among the top initial access methods. Coding agents make this problem structurally harder because they are themselves new non-human identities with high-trust scopes. </p><p>They mediate access to GitHub PATs, npm tokens, cloud keys, and MCP server connections by default. <strong><a href="https://nhimg.org/2025-state-of-non-human-identities-and-secrets-in-cybersecurity">Research</a></strong> found that 97% of NHIs are over-permissioned and that 0.01% of machine identities control 80% of cloud resources.</p><p>The breach pattern is already established. The incidents at Home Depot, Red Hat GitLab, Salesloft-Drift, and the Crimson Collective campaign all followed the same trajectory in 2025, which included leaked non-human identities to broad lateral movement. </p><p>Coding agents now sit at the intersection of all of these credential types, holding or mediating access to the same tokens and keys that attackers consistently target. The <strong><a href="https://owasp.org/www-project-non-human-identities-top-10/">OWASP Non-Human Identities Top 10</a></strong> exists for a reason, and coding agents are creating new NHI categories faster than most identity programs can inventory them.</p><h2>The Emerging Security Primitives</h2><p>The defensive stack for coding agents is taking shape across several layers, roughly in order of maturity.</p><p><em><strong>Visibility</strong></em> comes first because you can&#8217;t secure what you can&#8217;t see. Which agents are running, on whose machines, with which permission scopes, connected to which MCP servers, and executing which tool calls. Most organizations can&#8217;t answer these questions today. Agent inventory and scope mapping is the baseline requirement, and without it every other layer is built on assumptions rather than evidence.</p><p><em><strong>Posture management</strong></em> focuses on pre-deployment configuration. Deny rules, permission scoping, disabling dangerous flags like <code>--dangerously-skip-permissions</code>, and hardening agent configurations before they run in production environments. This is the prevention layer that reduces the attack surface before runtime, and it&#8217;s where organizations with mature configuration management practices have the clearest head start.</p><p><em><strong>Governance</strong></em> addresses the organizational questions. Who can install which agents, which models they connect to, which plugins and extensions are approved, and what policy frameworks govern their behavior. Only 41% of employers have a formal AI tools policy according to JetBrains&#8217; April 2026 research, which means the majority of organizations deploying coding agents are doing so without formal governance structures in place. That gap between adoption velocity and governance maturity is where the most preventable incidents will come from.</p><p><em><strong>Detection and response</strong></em> brings runtime telemetry to agent behavior.Various vendors work on runtime security for coding agents demonstrates what this looks like in practice, applying the same continuous monitoring principles from cloud workload protection to agent execution, catching anomalous behavior patterns in tool calls, file access, and network activity. The key shift here is extending detection beyond infrastructure-level telemetry into the agent&#8217;s reasoning and action layer, where the attacks that matter most for coding agents actually occur.</p><h2>Sandboxes as a Containment Boundary</h2><p>Sandboxing has emerged as one of the most tangible security primitives for coding agents, and it&#8217;s the one that most directly addresses the blast radius problem. The core logic is straightforward. If a coding agent inherits the user&#8217;s full permissions by default, then constraining the environment where the agent executes is the most direct way to limit what a compromised or misbehaving agent can actually reach.</p><p>I have dove into the topic of Sandboxes for Agents with several guests and industry experts, including Alex Zenla of Edera and Luke Hinds, creator of nono. </p><div id="youtube2-tZvJ7-8x4iU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;tZvJ7-8x4iU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/tZvJ7-8x4iU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div id="youtube2-h4TjA0IUpgQ" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;h4TjA0IUpgQ&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/h4TjA0IUpgQ?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>The implementations vary significantly across platforms, and the differences matter.</p><p>Claude Code&#8217;s sandbox uses OS-level primitives, specifically Linux bubblewrap and macOS seatbelt, to restrict file system access to the current working directory and route network traffic through an external proxy. </p><p>Anthropic <strong><a href="https://www.anthropic.com/engineering/claude-code-sandboxing">reported</a></strong> an 84% reduction in permission prompts with the sandbox enabled, which tells you something about how much unnecessary access agents were exercising by default before containment was in place. </p><p><strong><a href="https://cursor.com/blog/agent-sandboxing">Cursor&#8217;s sandbox</a></strong> takes a similar OS-native approach with Apple Seatbelt on macOS and seccomp plus Landlock on Linux, restricting file system writes to the workspace and /tmp while blocking network requests by default. </p><p>OpenAI&#8217;s Codex runs entirely in cloud-deployed microVMs with a dedicated filesystem, process space, and internet access disabled during execution, which is the strongest isolation model among the major coding agents but comes with the tradeoff of not running on the developer&#8217;s local machine.</p><p>GitHub Copilot&#8217;s cloud agent takes yet <strong><a href="https://devblogs.microsoft.com/all-things-azure/best-of-both-worlds-for-agentic-refactoring-github-copilot-microvms-via-docker-sandbox/">another approach</a></strong>, running in a sandboxed environment with a built-in firewall and recommended allowlist for package repositories and container registries. Organization admins can manage the firewall and custom allowlists across all repositories. The documentation is honest about limitations though. The firewall only applies to processes started by the agent via its Bash tool, not to MCP servers or processes started during setup steps.</p><p>The honest assessment of sandboxing is that it&#8217;s necessary but not sufficient, and the CVE history proves it. Cursor&#8217;s CVE-2026-26268 was specifically a sandbox escape. Shell built-in commands like export, cd, and echo are implicitly trusted and executed without confirmation in some implementations, creating bypass paths through environment variable manipulation. </p><p>The broader research on agent sandboxing consistently finds that environment variable exfiltration remains possible even in properly isolated sandboxes unless egress is explicitly restricted and secrets are scrubbed from the execution context. The UK&#8217;s AI Security Institute (AISI) for example <strong><a href="https://www.aisi.gov.uk/blog/what-can-sandboxed-ai-agents-learn-about-their-evaluation-environments">found</a></strong> sandboxed AI agents can still learn a great deal about their hosting environments.</p><p>What sandboxes do well is establish a containment boundary that limits the blast radius of the most common failure modes, accidental file system modifications, credential reads from files and config directories, and unauthorized network calls. </p><p>What they don&#8217;t do is protect against attacks that operate within the sandbox&#8217;s permitted scope, like prompt injection that causes the agent to write malicious code to the files it&#8217;s authorized to modify or commit backdoored changes to the repository it&#8217;s authorized to push to. </p><p>Sandboxing constrains where the agent can act. Hooks and runtime enforcement constrain what the agent can do within those boundaries.</p><h2>Hooks as a Key Security Primitive</h2><p>One of the most significant defensive primitive emerging for coding agents is hooks, and the distinction from both sandboxes and prompt-level guidance is worth discussing further. </p><p>CLAUDE.md files and system prompts are advisory. As I wrote in a recent blog post from my Zenity team, &#8220;<strong><a href="https://zenity.io/blog/current-events/ai-agent-database-deletion-pocketos">System Prompts Are Not Security Controls: A Deleted Production Database Proves It</a></strong>&#8221;, which was tied to the real-world PocketOS incident, where an agent outright ignored its system prompt and deleted production data.</p><p>The model can choose to follow them or not. Sandboxes constrain the execution environment but can&#8217;t evaluate the intent or appropriateness of actions within their permitted scope. Hooks are deterministic and semantic. They fire at the process level regardless of what the model decides, intercepting tool calls before execution and enforcing policy decisions that the agent cannot override or reason its way around.</p><p>As I covered in <strong><a href="link">A Look at an Emerging Runtime Enforcement Layer for Agents</a></strong>, hooks represent a convergence pattern across multiple agent platforms, with implementations showing up in Claude Code, Cursor, Windsurf, Cline, GitHub Copilot, and OpenClaw. </p><p>The data supports the distinction as well. Research on runtime policy enforcement found 48% policy compliance without a reference monitor compared to 93% with one. The difference between advisory guardrails and deterministic enforcement is the difference between hoping the agent behaves and ensuring it does.</p><p>There&#8217;s a caveat worth discussing as well, as attackers and researchers seem to have an infinite amount of ingenuity as we all painfully know.</p><p>Hooks themselves are now an attack surface. The <strong><a href="https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/">Check Point disclosure chain</a></strong> included malicious <code>.claude/settings.json</code> files that could manipulate hook configurations through compromised repositories. Trust the repo before you trust its hooks. This is the same lesson the industry learned with CI/CD pipeline configurations, where the policy enforcement mechanism is only as trustworthy as the supply chain that delivers it.</p><p>Where this is heading is becoming clearer. </p><p>Hooks become a policy-as-code layer for agentic development, playing the same role that infrastructure-as-code scanners played for cloud security. Sandboxes provide the containment boundary. Hooks provide the semantic enforcement within that boundary. Together they form the two-layer defense model that coding agent security is converging toward, one constraining the environment and the other constraining the behavior. The question isn&#8217;t whether both will be required but how fast the tooling matures to support them at enterprise scale.</p><h2>The Market Opportunity</h2><p>I watch this market closely, as I work at <strong><a href="https://zenity.io/">Zenity</a></strong>, one of the leading players in the Agentic AI Security space, where I serve as the VP Security Strategy. I&#8217;m seeing narrow focused startups focused on endpoint coding agents exclusively, as well as some agentic security/AI security startups pivot to emphasize their focus on endpoint coding agents given the market opportunity and momentum as well.</p><p>Our team at Zenity was <strong><a href="https://zenity.io/blog/current-events/company-to-beat">recently named</a></strong> <em><strong>the</strong></em> company to beat in Agent Governance. That said, I obviously am closely watching this category and market both as someone operating at a vendor building in this space, and looking to understand it both from the market and technical perspective.</p><p>The market dynamics reflect the adoption reality. </p><p>MarketsandMarkets <strong><a href="https://www.marketsandmarkets.com/PressReleases/agentic-ai-security.asp">sizes</a></strong> the agentic AI security market at $1.65 billion in 2026, growing to $13.52 billion by 2032 at a 42% compound annual growth rate. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IOm4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IOm4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png 424w, https://substackcdn.com/image/fetch/$s_!IOm4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png 848w, https://substackcdn.com/image/fetch/$s_!IOm4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png 1272w, https://substackcdn.com/image/fetch/$s_!IOm4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IOm4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png" width="989" height="426" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:426,&quot;width&quot;:989,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:137225,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/198245707?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IOm4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png 424w, https://substackcdn.com/image/fetch/$s_!IOm4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png 848w, https://substackcdn.com/image/fetch/$s_!IOm4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png 1272w, https://substackcdn.com/image/fetch/$s_!IOm4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4da58b31-5a81-450d-8ce0-7f29fd119df5_989x426.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Coding agent revenue is the leading indicator. Claude Code alone hit a $2.5B run-rate in under 12 months. Information Matters&#8217; Q1 2026 analysis <strong><a href="https://informationmatters.net/sizing-the-agentic-ai-market-40-billion-now-140-billion-by-2030-if-three-triggers-hit/">estimated</a></strong> the broader agentic AI market at $40 billion today with a path to $140 billion by 2030.</p><p>The procurement tailwind is worth acknowledging as real, given the various sources and metrics discussed.</p><p>The gap between coding agent adoption (<strong><a href="https://blog.jetbrains.com/research/2026/04/which-ai-coding-tools-do-developers-actually-use-at-work/">85% of developers using AI tools</a></strong>) and formal governance (only 18% of enterprises have guidelines for AI-generated code) creates the exact conditions that drive security platform buying and creates an opportunity for agentic AI security vendors. Every organization deploying coding agents without governance, visibility, and enforcement is a future buyer of these capabilities. </p><p>The security primitives maturing around coding agents today, from visibility and posture management to sandboxing, runtime detection, and hooks-based enforcement, are the same primitives that every other agentic workload category will need. The vendors building for coding agent security are building for the entire agentic security market.</p><h2>Where It Goes From Here</h2><p>Coding agents are the first agentic workload to hit production at scale, with measurable revenue, measurable adoption, and measurable risk. </p><p>The security category forming around them isn&#8217;t waiting for the rest of the agentic AI market to catch up, it&#8217;s setting the terms. The defensive primitives that win here, visibility, governance, sandboxing, runtime detection, and deterministic enforcement through hooks, will become the reference architecture for securing every agentic workload that follows.</p><p>Defenders who own the coding agent boundary today will own the agentic security category tomorrow.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Resilient Cyber Newsletter #97]]></title><description><![CDATA[Welcome to issue #97 of the Resilient Cyber Newsletter!]]></description><link>https://www.resilientcyber.io/p/resilient-cyber-newsletter-97</link><guid isPermaLink="false">https://www.resilientcyber.io/p/resilient-cyber-newsletter-97</guid><dc:creator><![CDATA[Chris Hughes]]></dc:creator><pubDate>Fri, 15 May 2026 12:01:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KvyU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to issue #97 of the Resilient Cyber Newsletter! </p><p>This was a week that tested every narrative we have been building about AI and cybersecurity. Microsoft unveiled MDASH, a multi-model agentic scanning harness that found 16 new vulnerabilities in the Windows networking stack, including four Critical remote code execution flaws. Google&#8217;s Threat Intelligence Group confirmed with high confidence that threat actors used an AI model to discover and exploit a zero-day for 2FA bypass, the first documented case of its kind. And the Mini Shai-Hulud worm struck TanStack, compromising 84 npm package artifacts across 42 packages in six minutes flat.</p><p>On the Mythos front, the scrutiny arc I have been tracking since issue #95 deepened. Rival Security found that one of Mythos&#8217;s celebrated discoveries was a CVE already present in its training data. Daniel Stenberg ran Mythos against curl&#8217;s 178,000 lines and concluded the results were no more advanced than existing tools. Meanwhile, Wired reported that nearly 380,000 vibe-coded apps are publicly accessible, with 5,000 of them leaking sensitive medical, financial, and corporate data.</p><p>The policy side moved too. The Trump administration formally listed offensive cyber operations as a counterterrorism tool, and both OpenAI and Anthropic announced enterprise services ventures that signal a structural shift in how AI labs compete for government and enterprise customers.</p><p>Let&#8217;s get into it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KvyU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KvyU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png 424w, https://substackcdn.com/image/fetch/$s_!KvyU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png 848w, https://substackcdn.com/image/fetch/$s_!KvyU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png 1272w, https://substackcdn.com/image/fetch/$s_!KvyU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KvyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png" width="1183" height="717" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:717,&quot;width&quot;:1183,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:615190,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KvyU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png 424w, https://substackcdn.com/image/fetch/$s_!KvyU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png 848w, https://substackcdn.com/image/fetch/$s_!KvyU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png 1272w, https://substackcdn.com/image/fetch/$s_!KvyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F962d2c6e-bc76-432a-9b76-68a3b9f5a586_1183x717.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><blockquote><h3><strong><a href="https://www.doppel.com/blog/social-engineering-attack-chain-new-standard-unified-defense?utm_source=ResilientCyber&amp;utm_medium=newsletter&amp;utm_campaign=fy27brandcampaign&amp;utm_content=attackchain">Social engineering has a new playbook.</a></strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E-O1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E-O1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg 424w, https://substackcdn.com/image/fetch/$s_!E-O1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg 848w, https://substackcdn.com/image/fetch/$s_!E-O1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!E-O1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E-O1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg" width="548" height="411" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:750,&quot;width&quot;:1000,&quot;resizeWidth&quot;:548,&quot;bytes&quot;:394443,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E-O1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg 424w, https://substackcdn.com/image/fetch/$s_!E-O1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg 848w, https://substackcdn.com/image/fetch/$s_!E-O1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!E-O1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F948f3261-cc86-42d5-b416-985f1b3926ac_1000x750.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Social engineering attacks are no longer isolated incidents; they follow a structured chain. Attackers gather context, build credible identities, and engage targets in ways that feel routine and trustworthy.</p><p>That&#8217;s what makes them difficult to detect. Each step is designed to blend in.</p><p>Defending against this kind of activity means understanding how attacks unfold from start to finish, across both multiple channels.</p><p><strong>Doppel</strong> breaks down how the modern social engineering attack chain works, and what it takes to identify and disrupt it earlier.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.doppel.com/blog/social-engineering-attack-chain-new-standard-unified-defense?utm_source=ResilientCyber&amp;utm_medium=newsletter&amp;utm_campaign=fy27brandcampaign&amp;utm_content=attackchain&quot;,&quot;text&quot;:&quot;Read More&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.doppel.com/blog/social-engineering-attack-chain-new-standard-unified-defense?utm_source=ResilientCyber&amp;utm_medium=newsletter&amp;utm_campaign=fy27brandcampaign&amp;utm_content=attackchain"><span>Read More</span></a></p><p><em>*Sponsored</em></p></blockquote><div><hr></div><h1>Cyber Leadership &amp; Market Dynamics</h1><h3><a href="https://www.nextgov.com/cybersecurity/2026/05/us-lists-offensive-cyberattacks-counterterrorism-strategy/413374/">Offensive Cyber Operations Get a Formal Counterterrorism Mandate</a></h3><p>I have been tracking the expanding role of offensive cyber in national security since the Pentagon&#8217;s 100,000 vibe-coded agents story in issue #95, and this week the Trump administration made it official. </p><p>The new counterterrorism strategy explicitly lists offensive cyber operations as a tool against narcoterrorists, transnational criminal organizations, and state-backed proxy groups. </p><p>This is the first time a U.S. counterterrorism strategy document has formally and publicly integrated offensive cyber capabilities alongside kinetic options. Whether you view this as overdue transparency or a troubling normalization of cyber offense as routine statecraft, the direction is unmistakable. Offensive cyber is no longer a classified footnote. It is a named instrument of national power.</p><h3><a href="https://techcrunch.com/2026/05/04/anthropic-and-openai-are-both-launching-joint-ventures-for-enterprise-ai-services/">AI Labs Are Becoming Services Companies</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GNXG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GNXG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png 424w, https://substackcdn.com/image/fetch/$s_!GNXG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png 848w, https://substackcdn.com/image/fetch/$s_!GNXG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png 1272w, https://substackcdn.com/image/fetch/$s_!GNXG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GNXG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png" width="1456" height="389" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:389,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:578858,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GNXG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png 424w, https://substackcdn.com/image/fetch/$s_!GNXG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png 848w, https://substackcdn.com/image/fetch/$s_!GNXG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png 1272w, https://substackcdn.com/image/fetch/$s_!GNXG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ebcf8ee-df39-4053-a4d3-f8c7318e5910_1465x391.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the story that should concern every traditional IT services firm. OpenAI launched Deployment Co., a consulting venture backed by $4 billion from 19 investment firms including TPG, Advent, and Bain Capital, valued at $10 billion. Anthropic announced its own enterprise services joint venture with Blackstone, Hellman &amp; Friedman, and Goldman Sachs, with $300 million committed from each partner and ecosystem support from Accenture, Deloitte, and PwC. </p><p>As I discussed in issue #96 when covering Anthropic&#8217;s $4.4 billion ARR, these companies are not just building models anymore. They are building the implementation layer. For cybersecurity, the implication is that the AI labs deploying frontier models into government and enterprise environments will also be the ones advising on how to secure those deployments. That is an unprecedented consolidation of capability and influence.</p><h3><a href="https://framesecurity.com/articles/frame-security-launches-with-50m-to-build-the-future-of-human-security/">Frame Security Enters the Human Risk Market with $50 Million</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SAjk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SAjk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png 424w, https://substackcdn.com/image/fetch/$s_!SAjk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png 848w, https://substackcdn.com/image/fetch/$s_!SAjk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png 1272w, https://substackcdn.com/image/fetch/$s_!SAjk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SAjk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png" width="579" height="320" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:320,&quot;width&quot;:579,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:246332,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SAjk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png 424w, https://substackcdn.com/image/fetch/$s_!SAjk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png 848w, https://substackcdn.com/image/fetch/$s_!SAjk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png 1272w, https://substackcdn.com/image/fetch/$s_!SAjk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd567d9f3-0d7f-4be3-bb02-932a344ffd3b_579x320.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here is a stat that should make every CISO pause. 96% of organizations run security awareness training, yet 90% of breaches still involve the human element. </p><p>Frame Security, backed by Index Ventures, Team8, and Picture Capital, is betting $50 million that the answer is not more slide decks. Their platform automates realistic attack simulations including deepfake audio and video scenarios, delivers role-based training, and provides real-time guidance. </p><p>Gartner&#8217;s 2025 data showed that 43% of CISOs had already experienced deepfake audio calls and 37% had encountered deepfake video. The traditional annual phishing simulation is starting to look like a relic. As AI-generated social engineering scales, defense has to match the personalization and speed of the attack.</p><h3><a href="https://risingincyber.com/">Rising in Cyber Tracks the Market&#8217;s Structural Transformation</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XX1_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XX1_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png 424w, https://substackcdn.com/image/fetch/$s_!XX1_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png 848w, https://substackcdn.com/image/fetch/$s_!XX1_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png 1272w, https://substackcdn.com/image/fetch/$s_!XX1_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XX1_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png" width="1185" height="654" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:654,&quot;width&quot;:1185,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:250531,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XX1_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png 424w, https://substackcdn.com/image/fetch/$s_!XX1_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png 848w, https://substackcdn.com/image/fetch/$s_!XX1_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png 1272w, https://substackcdn.com/image/fetch/$s_!XX1_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea740cfd-6692-45c6-bc70-ba9f8369ca35_1185x654.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Rising in Cyber report paints the macro picture for anyone who wants to understand where the cybersecurity market is headed. The market is projected to grow from $153 billion in 2025 to $255 billion by 2029. Series A and B funding dominated 2025 at over $10 billion, with $5.5 billion going to AI-native startups, the only segment that did not decline year over year. </p><p>Expected double-digit growth areas include IAM, data security, and cloud-native application protection. As I discussed in issue #96 with Sequoia&#8217;s Konstantine Buhler on narrative violation, the investors who recognized the AI-native shift early are positioned to capture the opportunity. Everyone else is recalibrating assumptions that should have been challenged a year ago. Yet, they also demonstrate just how fragmented the cybersecurity market is, despite how dominant some of the players seem based on brand name.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f3Xu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f3Xu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png 424w, https://substackcdn.com/image/fetch/$s_!f3Xu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png 848w, https://substackcdn.com/image/fetch/$s_!f3Xu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png 1272w, https://substackcdn.com/image/fetch/$s_!f3Xu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f3Xu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png" width="1368" height="656" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:656,&quot;width&quot;:1368,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:192751,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f3Xu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png 424w, https://substackcdn.com/image/fetch/$s_!f3Xu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png 848w, https://substackcdn.com/image/fetch/$s_!f3Xu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png 1272w, https://substackcdn.com/image/fetch/$s_!f3Xu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3968c7c2-c7a2-4e5a-a3ec-acf0af3281aa_1368x656.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><a href="https://www.linkedin.com/posts/calebsima_unprompted-2026-ai-security-conference-activity-7446349597427286016-53hc">The Unprompted Conference and What It Tells Us About AI Security&#8217;s Maturity</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!840P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!840P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png 424w, https://substackcdn.com/image/fetch/$s_!840P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png 848w, https://substackcdn.com/image/fetch/$s_!840P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png 1272w, https://substackcdn.com/image/fetch/$s_!840P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!840P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png" width="518" height="518" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:638,&quot;width&quot;:638,&quot;resizeWidth&quot;:518,&quot;bytes&quot;:72735,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!840P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png 424w, https://substackcdn.com/image/fetch/$s_!840P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png 848w, https://substackcdn.com/image/fetch/$s_!840P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png 1272w, https://substackcdn.com/image/fetch/$s_!840P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F991322ae-85dc-4055-9b03-23aa1b07c1b2_638x638.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Caleb Sima has been one of the most credible voices in AI security for years, and the Unprompted 2026 conference in San Francisco reflected the field&#8217;s growing maturity. The event featured real demos and sharp technical talks rather than the vendor pitch theater that dominates most security conferences. </p><p>With Caleb&#8217;s background as CSO at Robinhood and VP Security at Databricks, now leading White Rabbit as an AI-driven security venture studio, the conference curates from a practitioner perspective rather than an investor one. The AI security conversation needs more venues where the emphasis is on what works rather than what sells. </p><p>This is a great resource consolidating not just [un]prompted by many other conferences and talks into a single comprehensive resource.</p><div><hr></div><h3><a href="https://www.oligo.security/cadr-for-dummies?utm_campaign=391093448-Resilient%20Cyber%20April%202026&amp;utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad">Cloud attacks have a new entry point. It&#8217;s your running applications.</a>*</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!H3De!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!H3De!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png 424w, https://substackcdn.com/image/fetch/$s_!H3De!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png 848w, https://substackcdn.com/image/fetch/$s_!H3De!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png 1272w, https://substackcdn.com/image/fetch/$s_!H3De!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!H3De!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png" width="527" height="296.4375" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/255db86e-9ed9-4250-938b-864142ab724a_1500x844.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:527,&quot;bytes&quot;:905851,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!H3De!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png 424w, https://substackcdn.com/image/fetch/$s_!H3De!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png 848w, https://substackcdn.com/image/fetch/$s_!H3De!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png 1272w, https://substackcdn.com/image/fetch/$s_!H3De!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F255db86e-9ed9-4250-938b-864142ab724a_1500x844.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That&#8217;s why a new category is emerging: Cloud Application Detection and Response (CADR).</p><p>This new guide breaks down what CADR is, why runtime is the only place real attacks can be detected, and how security teams are protecting applications, cloud infrastructure, and AI systems in production.</p><p>If you&#8217;re responsible for securing modern cloud workloads, this is a concept you&#8217;ll want to understand.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.oligo.security/cadr-for-dummies?utm_campaign=391093448-Resilient%20Cyber%20April%202026&amp;utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad&quot;,&quot;text&quot;:&quot;Get the Guide&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.oligo.security/cadr-for-dummies?utm_campaign=391093448-Resilient%20Cyber%20April%202026&amp;utm_source=Resilient-Cyber&amp;utm_medium=newsletter&amp;utm_term=Resilient-Cyber-newsletter-traffic&amp;utm_content=newsletter-ad"><span>Get the Guide</span></a></p><p><em>*Sponsored</em></p><div><hr></div><h1>AI</h1><h3><a href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/">Microsoft Finds 16 Windows Vulnerabilities with a Multi-Model Agent Swarm</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ynR1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ynR1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png 424w, https://substackcdn.com/image/fetch/$s_!ynR1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png 848w, https://substackcdn.com/image/fetch/$s_!ynR1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png 1272w, https://substackcdn.com/image/fetch/$s_!ynR1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ynR1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png" width="1264" height="336" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:336,&quot;width&quot;:1264,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:277822,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ynR1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png 424w, https://substackcdn.com/image/fetch/$s_!ynR1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png 848w, https://substackcdn.com/image/fetch/$s_!ynR1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png 1272w, https://substackcdn.com/image/fetch/$s_!ynR1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fffa352ef-f23a-4295-a625-94db628e4ba9_1264x336.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is the kind of applied AI security work that moves the field forward. </p><p>Microsoft&#8217;s Autonomous Code Security team built MDASH, a multi-model agentic scanning harness that orchestrates over 100 specialized AI agents across an ensemble of frontier and distilled models. </p><p>The system found 16 new vulnerabilities in the Windows networking and authentication stack, including four Critical remote code execution flaws in the kernel TCP/IP stack and IKEv2 service. The architecture runs in stages. Specialized auditor agents scan, debater agents argue for and against exploitability, deduplication agents collapse semantically equivalent findings, and prover agents construct triggering inputs. </p><p>Combined with CodeMender from issue #96 and AISLE&#8217;s VulnOps model, this represents a clear trend. Multi-agent architectures are outperforming single-model approaches for vulnerability discovery, and the organizations investing in this infrastructure are finding real, Critical-severity flaws.</p><h3><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">Google Confirms the First AI-Generated Zero-Day Used in the Wild</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YrfE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YrfE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png 424w, https://substackcdn.com/image/fetch/$s_!YrfE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png 848w, https://substackcdn.com/image/fetch/$s_!YrfE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png 1272w, https://substackcdn.com/image/fetch/$s_!YrfE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YrfE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png" width="883" height="285" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:285,&quot;width&quot;:883,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:77444,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YrfE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png 424w, https://substackcdn.com/image/fetch/$s_!YrfE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png 848w, https://substackcdn.com/image/fetch/$s_!YrfE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png 1272w, https://substackcdn.com/image/fetch/$s_!YrfE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8722f6-5b85-44d3-935c-adb56b735633_883x285.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If there was a single story this week that validates the threat models I have been writing about since the OWASP Agentic Top 10, this is the one. </p><p>Google&#8217;s Threat Intelligence Group confirmed with high confidence that threat actors used an AI model to discover and exploit a zero-day vulnerability, creating a 2FA bypass. GTIG also documented UNC2814, a Chinese group targeting telecom and government sectors, using persona-driven jailbreaks for vulnerability research on embedded devices. </p><p>APT45, a North Korean group, sent thousands of repetitive prompts to recursively analyze CVEs and validate proof-of-concept exploits. As I wrote in my article on Agentic AI Threats and Mitigations, the use cases available to defenders are equally available to attackers. We now have documented confirmation from Google&#8217;s threat intelligence team that this is happening at the nation-state level.</p><h3><a href="https://blogs.cisco.com/ai/announcing-foundry-security-spec">Cisco Ships an Open Specification for Agentic AI Security Pipelines</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DIgQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DIgQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png 424w, https://substackcdn.com/image/fetch/$s_!DIgQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png 848w, https://substackcdn.com/image/fetch/$s_!DIgQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png 1272w, https://substackcdn.com/image/fetch/$s_!DIgQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DIgQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png" width="1241" height="345" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:345,&quot;width&quot;:1241,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:258793,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DIgQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png 424w, https://substackcdn.com/image/fetch/$s_!DIgQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png 848w, https://substackcdn.com/image/fetch/$s_!DIgQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png 1272w, https://substackcdn.com/image/fetch/$s_!DIgQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a38fcb1-7cad-4cfb-ac72-1307b1178533_1241x345.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What makes Cisco&#8217;s Foundry Security Spec interesting is what it is not. It is not a managed service or a proprietary platform. It is an open specification distilled from Cisco&#8217;s internal security evaluation systems, defining eight core agent roles including Orchestrator, Indexer, Detector, Triager, and Validator. </p><p>The specification is built alongside Foundation-sec-8B, an 8-billion-parameter security model built on Llama 3.1, and Foundation-sec-8B-Reasoning for multi-step security analysis. The design philosophy is that the need for orchestrators, detectors, and validators persists regardless of which underlying models evolve. </p><p>Combined with Microsoft&#8217;s MDASH and the Model Provenance Kit from issue #96, Cisco is building both the open standards and the open models for an agentic security ecosystem. That approach deserves attention from anyone building security tooling on top of foundation models.</p><h3><a href="https://cloudsecurityalliance.org/artifacts/ai-security-maturity-model">CSA Releases the AI Security Maturity Model</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xc5G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xc5G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png 424w, https://substackcdn.com/image/fetch/$s_!xc5G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png 848w, https://substackcdn.com/image/fetch/$s_!xc5G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png 1272w, https://substackcdn.com/image/fetch/$s_!xc5G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xc5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png" width="268" height="344.3393939393939" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:424,&quot;width&quot;:330,&quot;resizeWidth&quot;:268,&quot;bytes&quot;:237504,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xc5G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png 424w, https://substackcdn.com/image/fetch/$s_!xc5G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png 848w, https://substackcdn.com/image/fetch/$s_!xc5G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png 1272w, https://substackcdn.com/image/fetch/$s_!xc5G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36b9f773-9b5e-494e-8a61-656338e989b3_330x424.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Cloud Security Alliance released the AI Security Maturity Model after receiving over 600 comments from 60 international reviewers, and it fills a gap I have been pointing to across multiple issues. </p><p>Only 26% of organizations report having comprehensive AI security governance policies. 64% have some guidelines or are still developing them. The maturity model aligns with CSA&#8217;s Cloud Security Maturity Model and AI Controls Matrix, covering model security, AI infrastructure, agentic applications, MCP servers, and AI developer enablement. </p><p>CSA&#8217;s research shows that governance maturity is the strongest predictor of AI readiness. This connects directly to the shadow AI crisis I covered in issue #96, where 80% of Fortune 500 companies deploy agents but only 10% have a strategy to manage them. You cannot secure what you cannot measure, and the AISMM gives organizations a framework to start measuring.</p><h3><a href="https://www.sysdig.com/press-releases/sysdig-headless-cloud-security">Sysdig Launches a Headless Platform for Non-Human Identity Security</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q1xY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q1xY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png 424w, https://substackcdn.com/image/fetch/$s_!Q1xY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png 848w, https://substackcdn.com/image/fetch/$s_!Q1xY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png 1272w, https://substackcdn.com/image/fetch/$s_!Q1xY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q1xY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png" width="488" height="329" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:329,&quot;width&quot;:488,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:89392,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q1xY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png 424w, https://substackcdn.com/image/fetch/$s_!Q1xY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png 848w, https://substackcdn.com/image/fetch/$s_!Q1xY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png 1272w, https://substackcdn.com/image/fetch/$s_!Q1xY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9c63150-72ce-4eca-9b22-ca5bc80cb91f_488x329.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Machine identities outnumber human identities 40,000 to 1. They are 7.5 times more risky than human identities, and nearly 40% of breaches start with credential exploitation. </p><p>Sysdig&#8217;s response is what they call the industry&#8217;s first headless cloud security platform, designed not for human analysts clicking through dashboards but for AI agents operating at machine speed. The platform embeds full CNAPP capabilities directly into AI coding agents for real-time detection and response without requiring a human interface. </p><p>As I wrote in my article on What are Non-Human Identities and Why Do They Matter, the NHI challenge is not theoretical. It is the operational reality of every cloud-native environment. Sysdig&#8217;s headless approach acknowledges that the future of cloud security is not a better UI, it is no UI at all.</p><h3><a href="https://www.csoonline.com/article/4166171/poisoned-truth-the-quiet-security-threat-inside-enterprise-ai.html">The Poisoned Truth Inside Enterprise RAG Systems</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UoUj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UoUj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png 424w, https://substackcdn.com/image/fetch/$s_!UoUj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png 848w, https://substackcdn.com/image/fetch/$s_!UoUj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png 1272w, https://substackcdn.com/image/fetch/$s_!UoUj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UoUj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png" width="516" height="288.59838274932616" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5121505-8641-4595-8fe3-5f34179c0e17_742x415.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:415,&quot;width&quot;:742,&quot;resizeWidth&quot;:516,&quot;bytes&quot;:491522,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UoUj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png 424w, https://substackcdn.com/image/fetch/$s_!UoUj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png 848w, https://substackcdn.com/image/fetch/$s_!UoUj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png 1272w, https://substackcdn.com/image/fetch/$s_!UoUj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5121505-8641-4595-8fe3-5f34179c0e17_742x415.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>RAG has become the default architecture for grounding enterprise AI in organizational knowledge, and that creates a trust problem most security teams have not fully grasped. </p><p>Research accepted to USENIX Security 2025 demonstrated that injecting just five malicious texts into a database containing millions of documents achieved a 90% attack success rate. CrowdStrike has already detected data poisoning in the wild, including embedded hidden instructions in scripts. OWASP added LLM08:2025 (Vector and Embedding Weaknesses) to address these threats specifically. </p><p>The core issue is that LLMs cannot distinguish between legitimate and poisoned content. Everything retrieved is treated as ground truth. When you combine that with agentic systems that autonomously execute instructions from retrieved context, the attack surface expands from misinformation to arbitrary code execution. </p><p>As I discussed in Agentic AI Threats and Mitigations, the risks compound when agents act on poisoned inputs without human review.</p><h3><a href="https://www.csoonline.com/article/4165221/odni-to-cisos-on-threat-assessments-youre-on-your-own.html">ODNI Tells CISOs to Build Their Own AI Espionage Defenses</a></h3><p>The intelligence community is being unusually direct about a difficult reality. ODNI acknowledged AI-powered espionage as a growing national security threat and then essentially told CISOs they are on their own building defenses. In August 2025, an AI tool was used for data extortion against international government, healthcare, and public health sectors. </p><p>By May 2025, NSA, CISA, and FBI had issued a joint bulletin confirming that adversaries are poisoning AI systems across sectors by corrupting training data. The poisoned data can reshape how systems label financial transactions, interpret medical scans, or filter content without triggering alerts. Only 26% of organizations report comprehensive AI security governance policies, per CSA research. This reinforces the maturity model discussion above. The government is being transparent about the threat. It is less clear on who owns the solution.</p><h3><a href="https://posts.inthecyber.com/tales-of-an-ollama-honeypot-part-1-abuse-patterns-29ba0b000b7f">175,000 Ollama Servers and the Anatomy of LLM Infrastructure Abuse</a></h3><p>For anyone who thinks exposed LLM infrastructure is a theoretical risk, this honeypot data should recalibrate that assumption. Over 91,000 attack sessions were captured between October 2025 and January 2026, with more than 80,000 concentrated in an 11-day burst over the holidays.</p><p>Attackers follow systematic reconnaissance patterns. They start with simple queries to identify which models respond, then attempt SSRF exploitation through Ollama&#8217;s model pull functionality using attacker-controlled registry URLs, and finally deploy prompt injection to extract system prompts, environment variables, and container artifacts like Docker sockets and Kubernetes tokens. </p><p>With more than 175,000 Ollama servers exposed and estimated attack costs of $46,000 per day, this is not opportunistic scanning. It is organized, methodical infrastructure exploitation. The lesson for security teams deploying local LLMs is that anything exposed to the internet will be found and probed within hours.</p><h3><a href="https://corporate.comcast.com/stories/why-we-dont-need-to-wait-for-next-frontier-ai-models">You Do Not Need Frontier Models to Transform Security Operations</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N59H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N59H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png 424w, https://substackcdn.com/image/fetch/$s_!N59H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png 848w, https://substackcdn.com/image/fetch/$s_!N59H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png 1272w, https://substackcdn.com/image/fetch/$s_!N59H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N59H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png" width="941" height="521" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:521,&quot;width&quot;:941,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:101065,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N59H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png 424w, https://substackcdn.com/image/fetch/$s_!N59H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png 848w, https://substackcdn.com/image/fetch/$s_!N59H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png 1272w, https://substackcdn.com/image/fetch/$s_!N59H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd271680a-03b2-4bad-92bf-7f70b1b0a5db_941x521.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Comcast Business made an argument that I think deserves more airtime. Organizations do not need to wait for the next frontier model to realize meaningful security gains from AI. </p><p>Current AI and ML capabilities can already automate threat analysis, anomaly detection, and incident response at machine speed. The obsession with frontier model capabilities, while understandable given the Mythos attention cycle, risks creating a false dependency where teams delay security improvements because they are waiting for the next model generation. </p><p>A multi-layered approach combining current AI with human expertise is the pragmatic path. As I have been writing since the 2025 AI Security Rewind, the organizations getting the most value from AI in security are not the ones chasing the bleeding edge. They are the ones deploying proven capabilities at scale.</p><div><hr></div><h1>AppSec</h1><h3><a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised">Mini Shai-Hulud Devours TanStack in a Six-Minute Supply Chain Blitz</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ka9r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ka9r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png 424w, https://substackcdn.com/image/fetch/$s_!Ka9r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png 848w, https://substackcdn.com/image/fetch/$s_!Ka9r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png 1272w, https://substackcdn.com/image/fetch/$s_!Ka9r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ka9r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png" width="537" height="290.3948497854077" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:378,&quot;width&quot;:699,&quot;resizeWidth&quot;:537,&quot;bytes&quot;:275243,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ka9r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png 424w, https://substackcdn.com/image/fetch/$s_!Ka9r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png 848w, https://substackcdn.com/image/fetch/$s_!Ka9r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png 1272w, https://substackcdn.com/image/fetch/$s_!Ka9r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62aa2fe4-2d29-4fb9-a5c8-711b6028a9e6_699x378.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The speed and sophistication of this attack should be required reading for every engineering team. On May 11, 2026, the TeamPCP threat actor published 84 malicious versions across 42 @tanstack/* npm packages in six minutes. </p><p>The tanstack/react-router package alone receives roughly 12 million weekly downloads. Within 48 hours, the campaign expanded to 172 packages with 403 malicious versions across npm and PyPI. The attack chain exploited three GitHub Actions vulnerabilities in sequence, creating a fork with malicious code, poisoning the GitHub Actions cache, and extracting OIDC tokens from runner process memory for unauthorized package publishing. </p><p>The payload was a credential stealer targeting CI/CD tokens, cloud credentials from AWS IMDSv2, GCP, and Azure, Kubernetes service accounts, and HashiCorp Vault secrets. </p><p>As I wrote in <em>Software Transparency</em>, the trust model in modern package ecosystems was not designed for this kind of coordinated, multi-vector attack. Combined with the PyTorch Lightning compromise from issue #96, Mini Shai-Hulud demonstrates that supply chain worms are becoming self-propagating and cross-ecosystem.</p><h3><a href="https://rival.security/posts/mythos-discovered-a-cve-already-in-its-training-data---and-thats-still-worrying">Mythos Found a CVE That Was Already in Its Training Data</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DgPK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DgPK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png 424w, https://substackcdn.com/image/fetch/$s_!DgPK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png 848w, https://substackcdn.com/image/fetch/$s_!DgPK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png 1272w, https://substackcdn.com/image/fetch/$s_!DgPK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DgPK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png" width="599" height="408.6151351351351" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18194edc-7788-4c46-b58d-14a830467d1a_925x631.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:631,&quot;width&quot;:925,&quot;resizeWidth&quot;:599,&quot;bytes&quot;:713053,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DgPK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png 424w, https://substackcdn.com/image/fetch/$s_!DgPK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png 848w, https://substackcdn.com/image/fetch/$s_!DgPK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png 1272w, https://substackcdn.com/image/fetch/$s_!DgPK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18194edc-7788-4c46-b58d-14a830467d1a_925x631.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Mythos scrutiny arc that I have been tracking since issue #95 took another turn this week. Rival Security examined CVE-2026-4747, a remote code execution vulnerability in FreeBSD&#8217;s networked file system that Mythos reportedly discovered.</p><p>The vulnerable function matched CVE-2007-3999, which was patched in 2007, and the code was already present in Claude&#8217;s training data. Rival Security characterized this as &#8220;combinatorial creativity&#8221; rather than genuine novel discovery. </p><p>The AI rediscovered and recombined information it had already been trained on. This does not mean the finding is worthless. Rediscovery of latent vulnerabilities in active codebases has real value. But it does mean we need to be precise about what &#8220;AI-discovered vulnerability&#8221; actually means. The distinction between novel zero-day discovery and informed pattern matching matters for how we calibrate trust in AI security tools.</p><h3><a href="https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/">Daniel Stenberg Ran Mythos Against Curl and Was Not Impressed</a></h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K2PO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K2PO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png 424w, https://substackcdn.com/image/fetch/$s_!K2PO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png 848w, https://substackcdn.com/image/fetch/$s_!K2PO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png 1272w, https://substackcdn.com/image/fetch/$s_!K2PO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K2PO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png" width="441" height="211" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:211,&quot;width&quot;:441,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:20228,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K2PO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png 424w, https://substackcdn.com/image/fetch/$s_!K2PO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png 848w, https://substackcdn.com/image/fetch/$s_!K2PO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png 1272w, https://substackcdn.com/image/fetch/$s_!K2PO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5af8ef39-f461-4f7c-ac67-9305d590327e_441x211.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Nobody knows curl better than Daniel Stenberg, and his assessment of Mythos&#8217;s performance against the project&#8217;s 178,000 lines of code is worth reading carefully. Of five &#8220;confirmed security vulnerabilities&#8221; that Mythos identified, three were known issues already in the official documentation, one was a bug but not a security hole, and one was an actual low-severity vulnerability that was patched in late June.</p><p>Previous analysis with other AI tools including Zeropath, AISLE, and OpenAI&#8217;s Codex had identified 200-300 issues with a dozen or more confirmed vulnerabilities. Stenberg&#8217;s conclusion was blunt. He saw no evidence that Mythos finds issues to any higher or more advanced degree than existing tools. </p><p>Combined with Rival Security&#8217;s training data findings and the Glasswing Paradox from issue #96 where fewer than 1% of Mythos-found vulnerabilities were patched, the picture that emerges is of a capability that is real but substantially overhyped relative to the marketing narrative.</p><h3><a href="https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/">380,000 Vibe-Coded Apps and the Data Leaking from Them</a></h3><p>This is the vibe coding reckoning I warned about in Vibe Coding Conundrums and across newsletters #73, #76, and #78. RedAccess researchers identified approximately 380,000 publicly accessible applications created with vibe-coding platforms like Lovable, Replit, Base44, and Netlify. </p><p>Of those, 5,000 were actively leaking sensitive data including medical records, financial information, and corporate documents. 40% of examined applications had virtually no security or authentication. The examples are damning. A shipping company&#8217;s app exposed vessel routes. </p><p>A Brazilian bank&#8217;s financial data was publicly accessible. Unredacted customer service conversations were indexed by search engines. Platform responses ranged from ignoring findings to deflecting responsibility to users. As Andrej Karpathy defined it, vibe coding is for scenarios where you intentionally disregard code quality. </p><p>The problem is that thousands of people are shipping vibe-coded apps into production with real user data behind them.</p><h3><a href="https://www.wiz.io/blog/ai-threat-readiness-framework">Wiz Proposes an AI Threat Readiness Framework</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uUqO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uUqO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png 424w, https://substackcdn.com/image/fetch/$s_!uUqO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png 848w, https://substackcdn.com/image/fetch/$s_!uUqO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png 1272w, https://substackcdn.com/image/fetch/$s_!uUqO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uUqO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png" width="1456" height="783" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:783,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:512891,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uUqO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png 424w, https://substackcdn.com/image/fetch/$s_!uUqO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png 848w, https://substackcdn.com/image/fetch/$s_!uUqO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png 1272w, https://substackcdn.com/image/fetch/$s_!uUqO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8493384-93cd-4ca9-9ed1-39c2623a8814_1473x792.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Wiz framed the problem in a way that resonates with everything I have been tracking on the vulnerability management front. The gap between exposure and exploitation is shrinking, and security programs need to reduce the time between identification, validation, and remediation. </p><p>Their four-pillar framework is organized around two axes. Speed of Action and Breadth of Visibility. Wiz Defend provides runtime visibility and threat detection across workloads, cloud environments, Kubernetes, identities, and AI runtime activity. What I appreciate about this framework is the explicit acknowledgment that AI readiness is not just about deploying AI tools. </p><p>It requires comprehensive visibility across the full environment, from cloud infrastructure to code to SaaS to supply chain. As I wrote in my piece on the AI cyber capability curve, the organizations best positioned for the AI threat era are the ones that solved the visibility problem first.</p><h3><a href="https://blog.cloudflare.com/copy-fail-linux-vulnerability-mitigation/">Cloudflare&#8217;s Response to the Copy Fail Linux Privilege Escalation</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dq62!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dq62!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png 424w, https://substackcdn.com/image/fetch/$s_!dq62!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png 848w, https://substackcdn.com/image/fetch/$s_!dq62!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png 1272w, https://substackcdn.com/image/fetch/$s_!dq62!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dq62!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png" width="411" height="342.9892857142857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:701,&quot;width&quot;:840,&quot;resizeWidth&quot;:411,&quot;bytes&quot;:186841,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dq62!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png 424w, https://substackcdn.com/image/fetch/$s_!dq62!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png 848w, https://substackcdn.com/image/fetch/$s_!dq62!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png 1272w, https://substackcdn.com/image/fetch/$s_!dq62!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19bea6d2-4527-4698-9bf2-4143eb476a72_840x701.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>CVE-2026-31431 is the kind of vulnerability that keeps infrastructure teams up at night. An out-of-bounds write in the Linux kernel&#8217;s algif_aead crypto module, exploitable through splice() and page cache manipulation, affecting virtually every Linux distribution since 2017. </p><p>The exploit is deterministic, does not rely on race conditions, and can be implemented in approximately 732 bytes. Cloudflare&#8217;s Security and Engineering teams validated that their existing behavioral detections could identify the exploit pattern within minutes of disclosure, and no customer impact occurred. </p><p>What makes this worth highlighting is the operational maturity on display. The flaw existed for nine years across every major distribution, and Cloudflare&#8217;s defense-in-depth approach caught it before it mattered. That is the model. You cannot prevent every vulnerability from existing, but you can build detection and response capabilities that reduce the window between disclosure and mitigation to minutes rather than days.</p><h3><a href="https://simonwillison.net/2025/May/1/not-vibe-coding/">Simon Willison Corrects the Record on Vibe Coding</a></h3><p>Simon Willison&#8217;s clarification matters because the misuse of Andrej Karpathy&#8217;s term has real consequences for how we think about AI-generated code risk. Vibe coding does not mean using AI tools to help write code. It means generating code without caring about the output. </p><p>Karpathy coined it on February 6, 2025, for throwaway and experimental projects where code quality is intentionally disregarded. The tech publishing industry has conflated vibe coding with responsible AI-assisted development, and that conflation muddies every conversation about security implications. When I write about vibe coding risks, I am talking about the 380,000 publicly accessible apps that Wired documented this week, not about professional developers using AI with proper review. </p><p>The distinction between intentional disregard for quality and augmented professional development is the difference between a security crisis and a productivity gain. Getting the terminology right is the first step toward getting the governance right.</p><h3><a href="https://ramimac.me/spooky-skills/#lie-to-you">Rami McCarthy&#8217;s Spooky Skills and the Agent Trust Problem</a></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oa-P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oa-P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png 424w, https://substackcdn.com/image/fetch/$s_!oa-P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png 848w, https://substackcdn.com/image/fetch/$s_!oa-P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png 1272w, https://substackcdn.com/image/fetch/$s_!oa-P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oa-P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png" width="624" height="282" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:282,&quot;width&quot;:624,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:116949,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.resilientcyber.io/i/197562848?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oa-P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png 424w, https://substackcdn.com/image/fetch/$s_!oa-P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png 848w, https://substackcdn.com/image/fetch/$s_!oa-P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png 1272w, https://substackcdn.com/image/fetch/$s_!oa-P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87ca7114-2b68-4a37-9fe7-32025635dc7f_624x282.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Wiz Principal Security Researcher Rami McCarthy&#8217;s &#8220;spooky-skills&#8221; project highlights a risk that intersects directly with the OpenClaw backdoor discussed above and the broader supply chain concerns I have been tracking. </p><p>Agent skills, the extensible capabilities that allow AI agents to interact with external systems, represent a growing attack surface where misconfigured GitHub Actions, social engineering of maintainers, and credential hygiene failures converge. McCarthy&#8217;s research emphasizes that the same trust assumptions that created the npm and PyPI supply chain problems are being replicated in agent skill marketplaces. </p><p>As I wrote in issue #96 with the PyTorch Lightning compromise and in <em>Software Transparency</em>, the trust model has to evolve. Every new extension point for AI agents is a potential supply chain entry vector, and most organizations have zero visibility into the skills their agents are consuming.</p><div><hr></div><h1>Final Thoughts</h1><p>This week drove home a point that keeps sharpening with every issue. The Mythos hype cycle is colliding with operational reality, and operational reality is winning. Rival Security found a celebrated discovery that was already in the training data. </p><p>Daniel Stenberg found no evidence of capability beyond existing tools. Meanwhile, the actual threats are accelerating. Google confirmed the first AI-generated zero-day exploit used in the wild. Mini Shai-Hulud compromised 172 packages across two ecosystems in 48 hours. Every major AI coding IDE is vulnerable to IDEsaster attacks. And 380,000 vibe-coded apps are leaking real user data.</p><p>The positive developments are real but unevenly distributed. Microsoft&#8217;s MDASH found Critical Windows vulnerabilities with a 100-agent swarm. Cisco open-sourced both a security specification and an 8-billion-parameter security model. CSA gave us a maturity framework. Cloudflare demonstrated what operationally mature detection looks like against a nine-year-old Linux vulnerability. These are concrete, measurable advances.</p><p>But the gap I identified in issue #96 between discovery and remediation is widening, not narrowing. The Internet Bug Bounty paused new submissions. The organizations that will navigate this well are not the ones with the most advanced AI models. They are the ones building operational frameworks, identity infrastructure, and detection capabilities that match the speed of the threat. The race is not about who finds the most vulnerabilities. It is about who closes the loop fastest.</p><p><strong>Stay resilient.</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.resilientcyber.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.resilientcyber.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item></channel></rss>