Share this emailCopy the public link or share it on your favorite channel.
Weekly News Context July 24
Here's everything important that happened in the cybers this week!

The Accountability Void

Black swan
It's been a long week of AI news, so I want to step back and put the Hugging Face / OpenAI incident into the larger context. As a reminder, I'm not an attorney and this isn't legal advice. In case you missed it, on July 16, 2026, Hugging Face disclosed that autonomous AI agents had compromised their production infrastructure, executing …

Blog

Read more

Writing Your 2027 Security Budget After AI Vendors Set the House on Fire

Money Background with Dollars
If you're a CISO building your 2027 budget, you already know the old axiom: never let a good cybersecurity incident go to waste. Two incidents from this year have hit the mainstream media, law journals, and finance journals - and you're going to be tempted to work them into next year's budgetary planning exercise. On July 16, 2026, Hugging Face …

Blog

Read more

Security Communication Playbook: Making Security Reports That People Actually Read

So many words! Would you rather just watch this on YouTube? Security professionals have a communication problem they've earned because they produce detailed technical reports packed with vulnerability counts, patching rates, and system logs that executives ignore. Budget requests get denied, then everyone acts surprised when a breach happens and nobody approved the controls that would have prevented it. The …

Resource Library

Read more

When The Arsonist Sells Fire Insurance

Fire Insurance Adjuster
On July 16, 2026, Hugging Face disclosed a security incident unlike anything in their history where their production infrastructure had been compromised by an autonomous AI agent system executing thousands of actions across a swarm of short-lived sandboxes. On July 22, OpenAI admitted they were the attacker. This timeline raises immediate questions about why OpenAI only stepped forward after Hugging …

Blog

Read more

When Criminals Pretend to Be the FBI to Steal From Victims Again

PSA
The FBI's Internet Crime Complaint Center just released a Public Service Announcement updating an earlier alert about scammers impersonating IC3 personnel. The update was necessary because the scam's changed; criminals aren't just cold-calling your grandmother. They've moved on to building fake FBI infrastructure complete with AI-generated videos of senior Bureau leadership, spoofed .gov websites, and social media personas designed to …

Blog

Read more

What the SANS 2026 AI Survey Actually Tells Us

Compare and contrast
Every security survey released in 2026 has told roughly the same story: AI adoption's moving fast while governance crawls behind, and executives see things differently from practitioners. The question worth asking isn't whether this pattern holds. It's whether any single report actually adds insight beyond repeating what we already know. Matt Bromiley's July 2026 SANS AI Survey Insights landed on …

Blog

Read more

Black Hat/bSides Las Vegas

  • If you'll be there, reply to this email if you want to get a coffee or drinks.
  • If you're at bSides, come watch the presentation by the new speaker I'm mentoring!

Court cases I'm tracking

Something finally happened!

Order on Motion for Sanctions AND Order on Motion to Dismiss in Dawson v. Meta Platforms, Inc. (3:26-cv-00751) District Court, N.D. California. tl;dr: the motion to dismiss was granted but rule 11 sanctions were denied, and the plaintiffs can submit an amended complaint, so this isn't the end of the question about whether or not Meta can read WhatsApp messages.
Thanks, and have a great weekend! This newsletter is published every Friday I'm in the office.

Email Marketing Powered by MailPoet