Blog
-
Night One at Black Hat 2026
Instead of my usual regulatory and legal commentary, I’ll be posting daily content from Black Hat / BSides through Thursday. Arrival at LAS Waiting at baggage claim gave me my first taste of the crowd this year. I made friends with a DEF CON hall pass goon (volunteer staff, in case you’ve never been to…
-
AI Standards Will Fracture Further By 2035
On July 16, 2026, an OpenAI model escaped its sandbox, exploited a zero-day vulnerability in a package proxy, and breached Hugging Face just to cheat on a cybersecurity benchmark. Earlier this year, an Anthropic model uploaded malware to PyPI during testing, infecting three organizations, including a cybersecurity firm. Capability has outpaced containment, and vendors responded…
-
Eight TPRM Questions That Actually Matter for AI Vendor Selection
Traditional vendor risk management assumes vendors and their products will behave as advertised. Third-party risk (TPRM) programs normally evaluate data privacy practices, cybersecurity posture, and IT resilience through lengthy security questionnaires, audit certificates, and financial checks. But these checks don’t catch AI-specific failures. The AISI research on frontier model evaluations from earlier this month found every…
-
Smart Glasses Get Banned in Courts and Conferences – Should Your Workplace Follow?
New York just became the first state to ban AI-enabled smart glasses across all 1,200+ state courthouses, and DEF CON 2026 did the same thing, calling them “pervert glasses” on Bluesky. Both bans landed in July 2026, within weeks of each other, and the reasoning behind them was the same: covert recording breaks consent and…
-
Heading to DEF CON? Don’t Trust the Network
Every August, tens of thousands of security professionals flood Las Vegas for Black Hat, BSides, and DEF CON. The industry has spent the last two years obsessing over AI security, LLM jailbreaks, and prompt injection demos, so it’s almost refreshing to see threat actors going old-school: compromising physical network gateways, poisoning DNS at the source,…
-
The Quantum Liability You Already Have
I was preparing for a call with the board of a post-quantum cryptography (PQC) company and, as a part of preparing, reviewed all my prior research into PQC. I’m sharing my thoughts here – not about the specific company – but rather what CISOs should do, because we’re going to keep hearing the PQC drumbeat….
-
The Accountability Void
It’s been a long week of AI news, so I want to step back and put the Hugging Face / OpenAI incident into the larger context. As a reminder, I’m not an attorney and this isn’t legal advice. In case you missed it, on July 16, 2026, Hugging Face disclosed that autonomous AI agents had…
-
Writing Your 2027 Security Budget After AI Vendors Set the House on Fire
If you’re a CISO building your 2027 budget, you already know the old axiom: never let a good cybersecurity incident go to waste. Two incidents from this year have hit the mainstream media, law journals, and finance journals – and you’re going to be tempted to work them into next year’s budgetary planning exercise. On…
-
When The Arsonist Sells Fire Insurance
On July 16, 2026, Hugging Face disclosed a security incident unlike anything in their history where their production infrastructure had been compromised by an autonomous AI agent system executing thousands of actions across a swarm of short-lived sandboxes. On July 22, OpenAI admitted they were the attacker. This timeline raises immediate questions about why OpenAI…
-
When Criminals Pretend to Be the FBI to Steal From Victims Again
The FBI’s Internet Crime Complaint Center just released a Public Service Announcement updating an earlier alert about scammers impersonating IC3 personnel. The update was necessary because the scam’s changed; criminals aren’t just cold-calling your grandmother. They’ve moved on to building fake FBI infrastructure complete with AI-generated videos of senior Bureau leadership, spoofed .gov websites, and…