Your Email Gateway Never Saw It Coming

How an innocent Google search can become tomorrow morning’s ransomware incident. Your security awareness program has spent years teaching employees to be suspicious of phishing emails. That’s still important. But what if there isn’t an email? Imagine one of your engineers needs a new developer tool. They open Google. Type the product name into the […]

The Vanishing Buffer

An hour over a Colorado pass, a sentence in a Google ballroom, and the disappearance of the one thing every previous technology revolution quietly handed us: time Pueblo, Colorado. Hours before sunrise. To the west, the mountains we would have to cross were still dark on dark, more shape than range. A slight breeze worked […]

Harmony, Abnormal, Proofpoint: What Matters In Email Security

Featured image for an email security blog showing a suspicious wire transfer email investigation with the title “What Matters in Email Security.”

Most email security products are about as effective as eating spaghetti with a spoon. I have used quite a few. Three stand out. That number may shrink or expand because security tools change and evolve constantly. A firewall product that led the market twenty years ago should not be anywhere near a data center today. […]

When the AI Bubble Deflates, What Survives

A coworker told me today that the AI bubble is going to pop. He did not say it as a provocation. He said it with the calm of someone who has already seen how this movie ends. I feel it too. The market is going to correct. The question that stayed with me is not […]

Browser Extensions Are the Quiet SSO Bypass

Most organizations have a process for evaluating software. Procurement reviews, security assessments, sometimes formal vendor questionnaires. Almost none of them have a process for evaluating what browser extensions their employees are running. That gap is exactly what this campaign exploits. Researchers at Socket documented 108 malicious Chrome extensions sharing a single command-and-control backend, collectively installed […]

The AI Agent Hype Cycle: When Viral Platforms Are More Human Than They Appear 

Two robotic hands suspended against a black background with puppet strings hanging from their fingers beneath the headline “Autonomous? Or Just Automated?”, symbolizing AI agent security and human-controlled automation.

A supposed social network for autonomous AI agents goes viral. Screenshots of AI conversations spread across LinkedIn and Twitter. Headlines suggest emergent machine behavior. Security professionals panic. Executives ask their CISOs what it means for their organization.  Then researchers look under the hood and find something far more mundane: humans with automation scripts.  The Promise […]

2025 Year in Review: Deepfakes, Quantum Realities, and the AI Governance Gap

Subscribe to The Audit Brief, where we break down the latest episode of The Audit Podcast. This Episode: As 2025 draws to a close, Joshua Schmidt takes us on a journey through the year’s most thought-provoking conversations—the episodes that challenged assumptions and revealed just how rapidly cybersecurity is transforming. This isn’t your typical year-end recap. […]

Cybersecurity Highlights of 2025 and IT Security Predictions for 2026

Laptop viewed from above with hands typing on a keyboard, a digital shield and lock icon on the screen, and text reading “2025 Recap + 2026 Outlook” and “Cybersecurity Trends and IT Security Strategy Heading Into 2026,” representing cybersecurity planning and risk management.

Cybersecurity in 2025 marked a turning point for organizations of all sizes. Threats became faster, more targeted, and more disruptive, while leadership teams placed greater emphasis on cybersecurity risk management and resilience. IT security was no longer viewed as a technical concern alone. It became a business priority tied directly to uptime, revenue, and trust.  […]

Warcraft to Warfare: Why Your Next SOC Analyst Might Be an AI Bot

Promotional graphic featuring a portrait of a man wearing glasses and a blue shirt on the left, set against a purple, tech-themed background with binary code and abstract shapes. Large text reads “The Future of AI Security,” with a highlighted callout that says “Solving Alert Fatigue with Edward Wu.”

The Real Talk: A Closer Look: The Irony of Alert Overload Edward Wu spent eight years building AI-powered detection systems that generated millions of security alerts. His penance? Founding DropZone AI to automate the investigation of those same alerts. The reality: Most security teams already have too many alerts. What they desperately need is help […]

Critical Infrastructure: Everything is Connected and Vulnerable

Promotional graphic showing a portrait of a woman with red hair styled in a braid, wearing a dark jacket, set against a blue cityscape background with network connection lines. Large text reads “Hackers Target Infrastructure,” with a highlighted label that says “Lesley Carhart of Dragos.”

Subscribe to The Audit Brief, where we break down the latest episode of The Audit Podcast. The Real Talk: A Closer Look: The Vulnerability You Can’t Patch Lesley Carhart, technical director of incident response at Dragos, delivers an uncomfortable truth: Industrial control systems are designed to be vulnerable. When someone hits the emergency stop button […]

Join Our Live Podcast | FRIDAY @ 2pm CT