Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Supabase Data Exposure | 16,000+ Open Databases and What Security Teams Can Do

We found more than 16,000 Supabase databases sitting wide open, and over half held personal data like names, phone numbers and passwords. The organizations behind them ranged from a valet service to a government consulate, and in many cases the owners never checked the settings AI wrote. What is the Supabase data exposure? Anyone visiting these sites could read the data in their databases. Many belong to vibe-coded apps, where AI coding tools often handle the database setup.

Risk Acceptance Has a Shelf Life: Notes from the Aviation ISAC Cybersecurity Summit

The first Aviation ISAC summit, a little over a decade ago, was about forty people in a room in Miami, hosted by the Health ISAC. This year’s conference in Vancouver hosted more than five hundred: airlines, airports, OEMs, suppliers, and government, all in one place for three days. Many in the audience were new to the conference. One of the opening speakers asked first-timers to raise their hands, and a lot of hands went up around the room.

Managing Third-Party Cyber Risks in Complex Supply Chains

Big breaches often start somewhere boring. A refrigeration contractor with remote access to the network (Target, 2013). A file-transfer tool nobody on the security team had thought about in years (MOVEit, 2023). A compression library buried four layers deep in a Linux distro. Meanwhile most vendor reviews still run on an Excel questionnaire that gets filled in once, filed and forgotten, and attackers know that perfectly well.

The Interconnected Security Program: Managing Risk Across Cybersecurity Domains

Cybersecurity programs have become increasingly specialized and become a rather expansive enterprise responsibility. Protecting a modern organization can involve identity, endpoints, networks, applications and APIs, cloud infrastructure, data, threat intelligence, detection and response, governance, risk and compliance (GRC), incident response, and cyber resilience. Each discipline brings specialized technologies, processes, and expertise to the security program.

Preparing for an ISO 42001 Audit Rather Than Reading About It

Plenty of material explains what ISO/IEC 42001 contains. Clause by clause, control by control, with a checklist of documents to prepare. The standard itself is a management system specification rather than a control catalogue, and the distinction is where audit preparation goes wrong. ‍ The checklists share one omission.

Calibrating a Cyber Loss Model to One Environment

A model built on industry data produces an industry answer. The obvious next step is to calibrate it to the specific environment, and the obvious place to start is the threat picture, because every organization believes its own is distinctive. ‍ It is the wrong parameter to start with. Some inputs should stay general, some must be local, and the ones that must be local are the harder ones to observe, which is why they get left at a default. ‍

The Attribution Trap: What Happens When Threat Actors Manipulate the Story of an Attack?

Imagine waking up Monday morning to discover you’ve been breached. The attacker has stolen sensitive financial data, set up persistent access, and then greets you with a lovely ransom note at 8:00 a.m. demanding money in exchange for the encryption key. Immediately, you reach out to your security operations team, and they quickly begin assessing the damage and reviewing the breadcrumbs left behind.

AI Governance Where the Regulator Also Runs the Market

AI governance evidence is usually prepared for a neutral reader. A regulator with no stake in the market, an auditor with no competing product, an examiner who gains nothing from what the documentation contains. ‍ In securities and derivatives markets that assumption does not hold. Exchanges and clearing organizations register as self-regulatory organizations, and most of them operate the market while regulating its participants. The reader of your evidence is also an operator. ‍

The Cyber Risk Number That Goes to Three Different Committees

An exposure figure is produced once and read three times. The audit committee sees it, the risk committee sees it, and the board sees it, and each is answering a different oversight question. ‍ The figure travels well and the reasoning behind it does not. What arrives at the third reading is a number with no assumptions attached, and by then it reads as a fact. ‍

AI Governance Evidence That Costs Nothing to Produce

The usual case for governance return is that it speeds up enterprise sales, because buyers ask security questions and a prepared answer closes faster. It is true and it is the weaker argument. ‍ The stronger one is loss avoidance, and almost nobody makes it, because it needs a loss figure that most governance programs do not have. What makes it affordable is a distinction between two kinds of evidence. ‍

What an AI Correlation Rule Cannot See

A correlation rule can be tuned. The window can be widened, the join key improved, a source promoted from optional to required. Each of those is a parameter with a defensible setting. ‍ What remains after all of it is the residual, meaning the events that would produce a finding if a source existed for them, which is a form of residual risk expressed in detection terms. Naming it is the question an auditor asks after being shown a detection, and the answer is not a tuning exercise. ‍

A One-in-Hundred-Year Cyber Loss Is Not a Schedule

A quantification exercise reports a one-in-hundred-year loss and the figure travels well. It sounds precise, it sounds severe, and everybody in the room believes they understand it. ‍ Most of them do not. The phrasing describes an annual probability and it reads as a statement about timing, and the two produce different decisions from the same number. ‍

Frontier AI Impact Series, Part 1: Why Attackers Stopped Waiting for Zero-Days | Bitsight

Frontier AI can shrink weeks of vulnerability research into exploitation in hours. What does that mean for the flaws your team deprioritized years ago? Bitsight’s Emma Stevens, Senior Threat Intelligence Advisor, breaks it down in the first video of our new series.

The AI Incident Reporting Duty Nobody Can Date

Compliance content answers the question of when an obligation starts. For the serious incident reporting duty in the AI Act, the honest answer is that it is disputed, and the dispute is not a failure of research. ‍ Two readings of the text point in different directions, neither is obviously wrong, and no authority has resolved it. What follows is the reasoning on both sides and what to do without picking one. ‍

Cyber Loss When the Inventory Itself Perishes

An outage is normally modeled as deferred revenue. Production stops, orders wait, operations resume and some of the backlog is recovered by running longer. ‍ Where the inventory perishes, none of that applies. The stock is destroyed during the incident, restoring the systems does not bring it back, and running longer afterward produces new product rather than recovering the old. ‍

Cyber Loss When the Stolen Asset Is a Trained Model

A trained model is expensive to produce, cheap to copy and impossible to recall. Where one is taken, the organization still holds it, and the loss is not that the asset is gone. ‍ What ends is exclusivity. Lost exclusivity is a different quantity from a destroyed asset, it carries no notification obligation, it appears in no breach cost dataset, and most estimates therefore put it at zero by omission rather than by judgment. ‍

The AI Marking Deadline That Applies Only to Systems Already Running

Transitional relief normally works one way. A new rule arrives, existing products are carved out or given years, and anything built afterwards complies from the start. ‍ The marking obligation for synthetic content inverts that. Article 50 has applied since 2 August 2026, and a targeted transitional period gives extra time to systems that were already on the market rather than to new ones.

Reading AI Use From the Browser When the Network Sees Nothing

A session to a sanctioned AI provider looks the same on the network whichever account it ran under and whatever was in it. Transport encryption means a proxy sees a connection to an approved domain and a payload size. ‍ Which is fine until somebody asks whether an exposure is reportable. The question turns on three facts the network never held, and none of them can be reconstructed from a log afterward. ‍

Cyber Loss in Rail and Signalling

Cyber risk in transport is usually framed around a collision. Signals manipulated, a train sent onto occupied track, an accident caused deliberately. ‍ Signalling is built to make that outcome unavailable. Any failure forces the system into its most restrictive state, so a compromise produces a halt rather than a crash. The loss is the halt, and rail is unusual in already having a published price for one. ‍

How to Evaluate and Choose the Best TPRM Software in 2026

Evaluating third-party risk management (TPRM) software in 2026? Every platform says it tracks your vendors. What a demo will not show you is whether it finds those vendors on its own, including the AI tools and shadow IT nobody logged, or waits for you to type them in. This video follows one vendor from the day it shows up in your environment through five criteria for judging any TPRM platform, and the question to ask a vendor on each one.

DEF CON 34: Lessons Beyond the Conference

Being part of the cybersecurity community means more than simply following the news or reading security research. It is about getting involved, having conversations, sharing experiences, discussing problems, and learning from peers who face similar operational challenges. Of course, all of this comes with an investment of time, energy, and a full day of travel to reach one of the world’s largest hacking conferences: DEF CON in Las Vegas.

The Cyber Risk Inputs That Move the Answer Most

A cyber loss model has dozens of inputs and every one of them can be argued about. Record counts, downtime costs, control effectiveness, secondary loss factors, event likelihoods. ‍ A few of them determine the answer and the rest barely move it. Knowing which is which tells you where estimation effort belongs, and more usefully which disagreements about the model are not worth having. ‍

Reconciling an AI Risk Estimate Against What Truly Happened

A model produces a figure, an event happens, and somebody asks whether the figure was right. It is the obvious question and it has almost no published answer, because the comparison is harder than it looks. ‍ A single realized loss cannot falsify a distribution. If a model puts a one percent chance on exceeding a threshold and the threshold is exceeded, the one percent case occurred, which is what the model said would sometimes happen. ‍