Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Who was behind the attack? Possibly nobody

The fever dream continues, and I'm not even in Vegas for Hacker Summer Camp. Last week I wrote about Anthropic disclosing that one of their models published live malware to PyPI while believing it was inside a simulation. I was running a fever when I read the report. The metaphor was too good: a model that couldn't tell simulation from reality, covered by a writer who wasn't sure which way was up. I thought that was a one-week story. Very naive of me to have so much faith, I know.

Your Scanners See a Different Internet Than Your Users Do

A few years ago, cloaking was mostly a black hat SEO problem. Someone would serve one version of a page to Googlebot and another to human visitors, and the worst outcome was a spammy search result. It has since become one of the more effective evasion techniques in the phishing and malvertising toolkit, and most security teams are still measuring their external exposure from a vantage point that attackers stopped caring about some time ago.

How Geo-Targeted Attacks Evade Detection

The era of spray-and-pray cyberattacks is effectively over. Modern threat actors do not launch global, noisy campaigns. They launch highly localized, surgical strikes. They analyze regional vulnerabilities. They deploy localized phishing lures. Most importantly, they perfectly mimic local network traffic. When an attack originates from an IP address that your security perimeter explicitly trusts, traditional alarms stay silent. This is the core danger of geo-targeted evasion.

How to Protect Your Repositories from Open-Source Supply Chain Attacks

The open-source trust model is broken. Not strained, not under review—broken. For years, your team has pulled third-party code into your repositories on the reasonable assumption that a widely used dependency is safe. Popularity looked like a proof. Millions of downloads looked like a security review. TeamPCP has proven otherwise.

Evil Twin Attack: What It Is, How It Works, and Why Your Customers Are the Target

An evil twin attack is a man-in-the-middle attack in which an attacker creates a rogue wireless access point that impersonates a legitimate network. Victims connect believing the network is genuine, allowing the attacker to intercept traffic or present fraudulent login experiences designed to capture credentials. Evil twin attacks have traditionally been treated as wireless-security incidents. For enterprises with large customer bases, however, the consequences extend well beyond the network layer.

The Hugging Face Incident: A CISO Wake-Up Call for the Agentic Era

Earlier this month, Hugging Face, an AI and machine learning platform company, revealed that an autonomous AI system had breached part of its production environment. The intrusion began in the platform’s dataset-processing environment and eventually involved higher-level access, credential exposure, and movement into internal clusters.

The Attacker Never Sleeps, Neither Can Your Testing

A few months ago, I wrote that AI is building your attack surface faster than you can test it. I stand by every word I wrote then. But in the months since, after more than a hundred conversations with CISOs, CIOs, and CTOs across nearly every industry and geography, I've watched the picture get sharper, and a lot more urgent. The attack surface was only half the story, because the attacker profile has changed too.