All posts
Topic
Ciso
26 articles on ciso.
How AI Labs Detect and Disrupt Misuse: Lessons for CISOs
How AI labs detect AI misuse with monitoring, classifiers and threat intelligence, plus the AI trust and safety lessons CISOs can apply to their own AI.
September 11, 2026
When Your LLM Router Turns On You: Tool-Call Injection and Credential Theft
A defensive brief on a fast-rising risk class: malicious or compromised LLM routers and MCP gateways that inject unintended tool calls, steal credentials in transit, and pivot across hosts. What the attack looks like, why it scales, and the controls that actually contain it.
September 11, 2026
Cl0p Leak-Site Claims Four New Victims: A Defender's Brief on the Claim
Cl0p's dark-web leak site has listed four organizations as alleged victims. These are unverified extortion claims, not confirmed breaches. Here is how to read a leak-site listing, why Cl0p keeps hitting file-transfer software, and the defensive steps that actually matter.
September 10, 2026
Authenticator App Hygiene: Google & Microsoft Authenticator Done Right
A practical guide to using Google Authenticator and Microsoft Authenticator safely: TOTP vs push, number matching, resisting push-bombing, cloud backup risks, device binding, recovery, and where passkeys beat OTP. With personal and enterprise checklists.
September 10, 2026
Microsoft Teams Security Best Practices: A CISO's Hardening Guide
A concrete, admin-ready guide to hardening Microsoft Teams: external access and federation controls, guest and app governance, meeting policies, phishing defense, token-theft and Conditional Access, DLP, and Purview monitoring.
September 10, 2026
Zoom Security Best Practices: A CISO and IT Admin Configuration Guide
A practical guide to locking down Zoom: waiting rooms, passcodes, join restrictions, host controls, screen-share limits, E2EE trade-offs, recording retention, data residency, app governance, and SSO/SCIM, with a ready-to-use checklist.
September 10, 2026
Google Meet Security Best Practices for Google Workspace Admins
A CISO and Workspace admin guide to locking down Google Meet: Quick access and knocking, authenticated and same-org joins, moderation, dial-in, recording and Drive retention, Context-Aware Access, MFA, and audit logs.
September 10, 2026
Helpdesk Security: Defending the Service Desk Against Vishing Attacks
The IT service desk is now a primary attack surface. Learn the Scattered Spider playbook and the concrete identity-verification, monitoring, and Conditional Access controls that stop attackers from calling in to reset passwords and MFA.
September 10, 2026
The High-Risk User Checklist: Signals That Flag a Risky Identity
A concrete SOC and IAM watch-list of the behaviours and attributes โ impossible travel, MFA changes, privilege escalation, leaked credentials and more โ that should raise a user's risk score, why each matters, and how to respond.
September 10, 2026
FIDO2 and Passkeys: Benefits, Options, and How to Assess Them
A CISO and IAM architect's guide to FIDO2, WebAuthn, and passkeys: why they are phishing-resistant, platform vs hardware and device-bound vs synced options, attestation and AAGUID, and an assessment checklist for deployment.
September 10, 2026
Where Ransomware Crews Gather: A Defender's Map of the Underground
A defensive threat-intelligence explainer on the venue types that power the ransomware economy - forums, RaaS portals, initial-access brokers, leak sites - and how defenders and law enforcement monitor and disrupt them.
September 10, 2026
How Ransomware Crews Recruit: The Red Flags That Mean You're Being Groomed
A defensive awareness briefing for CISOs and staff on how ransomware operations recruit affiliates and insiders, the traits they hunt for as red flags, the manipulation tactics they use, the legal and personal consequences, and how to recognize and avoid being pulled in.
September 10, 2026
How Ransomware Crews Get Paid: Inside the Ransom Economy
An analytical look at the ransomware business: the RaaS affiliate model and revenue splits, how demands are sized and negotiated, the crypto rails crews use -- and how blockchain analysis and law enforcement follow and seize the money.
September 10, 2026
How Ransomware Crews Hide - And How They Get Caught
Inside the operational security ransomware operators use to stay anonymous, and the recurring OPSEC mistakes, blockchain tracing, infrastructure seizures and leaks that keep unmasking them anyway.
September 10, 2026
How to Prepare for a CISO Promotion or Transition Into a C-Suite Security Role
A practical roadmap for security leaders preparing to step into the CISO seat โ from closing executive skill gaps to practicing board-level decisions under pressure, with the tools and frameworks that actually build readiness.
August 9, 2026
Best Platforms for CISO Career Development and Executive Leadership Training in 2026
A practical comparison of the platforms security leaders are using in 2026 to develop executive skills, practise board communication, and prepare for the CISO role โ from simulation-based training to certifications and peer networks.
August 9, 2026
Best Interactive Incident Response Simulators for Security Leaders Preparing for Executive Roles in 2026
A comparison of the interactive incident response simulators available in 2026 for security leaders preparing for CISO and executive roles โ from AI-driven War Room scenarios to tabletop exercise platforms and cyber range tools.
August 9, 2026
Best Platforms for Practicing Board-Level Communication and Incident Reporting for Security Architects in 2026
Security architects eyeing executive roles need to master board-level communication and incident reporting. Here are the platforms and tools available in 2026 for practising these skills โ from AI-driven report coaches to crisis communication simulators.
August 9, 2026
How to Practice Handling a Major Security Breach as a CISO Candidate Before Stepping Into the Role
CISO candidates need to practise breach response at the executive level โ disclosure decisions, regulatory notifications, board communication, and crisis management โ before they are responsible for doing it for real. Here is how to build that muscle.
August 9, 2026
Shai-Hulud Took keyv โ and the Malware Shipped With Valid Provenance
A maintainer account compromise poisoned keyv, flat-cache, file-entry-cache and the rest of the family, then spread to 868 more packages across 1,381 versions โ over 2 billion monthly installs. The releases were signed by GitHub Actions and the provenance checks out. That is the part worth your attention.
August 4, 2026
An AI Agent Found 19 Redis Zero-Days โ in About 90 Minutes
Researchers say Kimi K3 agents chained a Redis streams double-free with a RedisBloom heap overflow into working authenticated RCE, with one exploit produced in 27 minutes. Redis shipped seven security releases in response. The claims are self-reported โ but the patches are real.
July 24, 2026
Your Smart TV Might Be Renting Out Your Internet Connection
Researchers found residential proxy SDKs in 42% of LG webOS apps and over 25% of Samsung Tizen apps, quietly turning hundreds of millions of home TVs into proxy nodes rented out to unknown third parties. LG is suspending non-compliant apps; Samsung has said nothing yet.
July 23, 2026
Real-Time Deepfakes Are Here: What Sub-40ms Face-Swaps Mean for Video-KYC and "the CEO on the Call"
Live video can now be edited faster than you can blink โ faces swapped, backgrounds changed, all in real time on a webcam stream. Here is why that breaks video-based identity verification, supercharges executive impersonation fraud, and what security leaders should do about it.
July 17, 2026
The Suno Breach: An npm Worm, a Scraped Training Set, and a Notification That Never Came
A hacker used the self-propagating Shai-Hulud npm worm to breach AI music company Suno, leaking source code that details how its training corpus was scraped โ plus customer emails, phone numbers, and Stripe data. Here is what actually happened and what security leaders should take from it.
July 16, 2026
D2D Agentic Architecture: How Domain-to-Domain AI Agents Coordinate at Scale
A deep dive into the Domain-to-Domain (D2D) agentic protocol โ the coordinator, worker, and killer node model that lets autonomous AI agents collaborate across security domains without human-in-the-loop bottlenecks.
July 13, 2026
Deploying D2D Agentic Architecture in a Real Security Operations Team
Lessons from wiring up a D2D multi-agent system to a production SOC: the PagerDuty integration, the human review queue, what broke, and what surprised us.
July 13, 2026