Category: Cybersecurity

  • Prompt injection in agent memory: the OWASP top 10 got the threat order wrong

    Prompt injection in agent memory: the OWASP top 10 got the threat order wrong

    The OWASP GenAI LLM Top 10 for 2026 still leads with prompt injection. The 2026 attack class is not the one the list leads with, and the gap is shaping what teams defend against first.

  • The DevSecOps Metrics That Matter in 2026

    The DevSecOps Metrics That Matter in 2026

    DevSecOps metrics in 2026 are not the metrics the security team has been quietly tracking, the mean time to remediation, the vulnerability density, the security debt. Those three are still the metrics the program is judged on. The honest version sits in the engineering culture, the developer experience, the security debt the program has been…

  • A Field Guide to the SIEM Detection Rule in 2026

    A Field Guide to the SIEM Detection Rule in 2026

    The SIEM detection rule has become the rule the SOC analyst has been writing, the rule the SIEM vendor has been shipping, the rule the breach disclosure will describe as the rule the enterprise should have had.

  • The SOC Analyst Burnout Rate in 2026

    The SOC Analyst Burnout Rate in 2026

    The SOC analyst burnout has become the metric the industry has been tracking for five years, the metric that has finally crossed the threshold the recruiter said would break the function. The analyst who left for the next role, the analyst who quit the function, the analyst who is still on the team but has…

  • Cookies Are Dead. Browser Fingerprinting Is Forever.

    Cookies Are Dead. Browser Fingerprinting Is Forever.

    The privacy debate of 2014 was about cookies. The privacy debate of 2026 is about a thing most people have never heard of, and the marketers have been quietly using it for years.

  • The npm Supply Chain Is the New Attack Surface

    The npm Supply Chain Is the New Attack Surface

    Every time you type npm install you are running code from an average of 1,400 strangers on a computer that holds your secrets. The trust assumption underneath the install command is the attack surface.

  • The Real Cost of a Data Breach After the Settlement in 2026

    The Real Cost of a Data Breach After the Settlement in 2026

    The data breach settlement has become the number the board has been reading about for three years, the number that the postmortem will reference, the number that the next security budget will be built around.

  • The CISO and the Board After a Breach in 2026

    The CISO and the Board After a Breach in 2026

    The CISO and the board after a breach is a relationship the CISO has been rehearsing in private for years, and the board has been hoping does not have to happen. When it does, the rehearsal is what shows.

  • MCP Is the USB Port of AI. Be Careful What You Plug In.

    MCP Is the USB Port of AI. Be Careful What You Plug In.

    Model Context Protocol, the standard Anthropic published in late 2024, has become the de facto way for agents to talk to the rest of the software stack. The convenience is real. So is the new attack surface.

  • Building a Virtual CISO Program in 2026

    Building a Virtual CISO Program in 2026

    The virtual CISO program in 2026 sits as the program the small enterprise has been quietly turning to, the program the consultant has been quietly building, the program the auditor has been quietly accepting.