Three Claude agents given conflicting orders sabotaged each other on a shared server — then didn’t tell users what they’d done
VentureBeat

Three Claude agents given conflicting orders sabotaged each other on a shared server — then didn’t tell users what they’d done

McGladrey reaches the same place from the audit side, where auditing outcomes is what remains. “We can audit code for compliance. We can audit code for security. We cannot audit code for ethics or bias, there is no scalable way to do that,” he put it. “I think that's going to be the only meaningful way to look at what an AI forward entity does.”
Grok 4.6 Arrives as SpaceX Claims All Employee Work as AI Training Material
Tech Times

Grok 4.6 Arrives as SpaceX Claims All Employee Work as AI Training Material

Kayne McGladrey, a senior member of the IEEE, has noted the structural distinction that explains why this matters for agent models specifically: "synthetic data lacks the unpredictability of human responses to the unexpected, such as when a window moves or is resized," and behavioral training data is what teaches a model "how tools flow together."
AI-Enabled Ghost Student Fraud: How IT Leaders Are Fighting Back
EdTech Magazine

AI-Enabled Ghost Student Fraud: How IT Leaders Are Fighting Back

“If you look at the successful investigations over the past five years, there’s been about $350 million in ghost student schemes that have been thwarted,” says Kayne McGladrey, a cybersecurity risk adviser and senior member of IEEE, a nonprofit professional organization that champions technical innovation.
What does a data breach cost? AI is a sizable factor
CSO Online

What does a data breach cost? AI is a sizable factor

Improving access controls on AI models is the most obvious security gap to close, according to Kayne McGladrey, a senior member of IEEE, CISSP-certified cybersecurity advisor, and independent virtual CISO. “Treat your models and their APIs like crown jewels,” says McGladrey. “If you wouldn’t expose your database to the public internet without identity and access controls, why would you do that for your AI model?”
The Shai-Hulud npm worm didn’t fake its security check — it earned a legitimate one
VentureBeat

The Shai-Hulud npm worm didn’t fake its security check — it earned a legitimate one

The pressure to fix this will not come only from threat reports. It is about to come through contracts. Kayne McGladrey, a senior member of the IEEE, told VentureBeat in an exclusive interview that enterprises are starting to push software security obligations onto the vendors and maintainers in their supply chains. "We're going to start seeing companies trying to contractually shift liability to other parties in their supply chain," he told VentureBeat. "We're using your technology, but we want you to do the security for it."
TechRound is excited to announce the winners of our HealthTech44 2026!
TechRound

TechRound is excited to announce the winners of our HealthTech44 2026!

As an independent virtual CISO with a background in risk management, cybersecurity, and regulatory compliance, I prefer facts over marketing claims. For TechRound’s HealthTech44 2026, I ranked the submissions on five evidence-based dimensions: stated security maturity, AI claim substantiation, clinical validity, patient impact, and the team’s credibility. Companies that scored higher had provided named certifications, published benchmarks, regulatory clearance, quantified outcomes, and experienced clinical leaders named in their submission. By comparison, entries with visible AI instructions, placeholder content, or contradictory claims were disqualified, and submissions that were primarily unsubstantiated product marketing ranked poorly with me.
New ransomware targets AI model weights and can’t even collect the ransom
VentureBeat

New ransomware targets AI model weights and can’t even collect the ransom

That figure makes the argument fundable. Kayne McGladrey, an IEEE Senior Member who has spent his career in identity security, told VentureBeat that security teams lose these fights by filing the exposure under the wrong heading. Companies "should be focused on business risks rather than some, you know, cybersecurity risk, because if it doesn't affect the business, like a loss or financial loss, in this case, predominantly, then nobody's going to pay any action to it, and they will not budget it appropriately, nor will they adequately put in controls to prevent it," he said. A destroyed model carries a known replacement cost, which is the version of this story a CFO acts on.
Hugging Face Incident Initial Post-Mortem
CSA

Hugging Face Incident Initial Post-Mortem

This AI security incident report is built for CISOs and security leaders operating AI agents today. Reviewed by hundreds of CISOs, this paper explains how the autonomous AI attack unfolded, what made it detectable, and what security teams should do next to secure agentic AI systems.
The credential that let OpenAI’s agents into Hugging Face exists in most enterprises right now
VentureBeat

The credential that let OpenAI’s agents into Hugging Face exists in most enterprises right now

IEEE Senior Member Kayne McGladrey has argued in previous VentureBeat interviews that enterprises keep cloning human user accounts onto agents that then wield far more permission than any human would, and this is what that looks like when the agent is a frontier model and the target is a production database.
Episode #19, July, 2026
Alice in Supply Chains Podcast - TPCRM News

Episode #19, July, 2026

Finally, Schrems III is nigh: with the US Supreme Court's ruling undermining the independence of agencies like the FTC — the very foundation of the EU-US Data Privacy Framework — Max Schrems is poised to strike down transatlantic data transfer agreement number three.
Episode 17 – Cardboard Confidential
IT Horror Stories with Jack Smith

Episode 17 – Cardboard Confidential

No one expects a cybersecurity incident to begin in the cardboard industry. Yet as our guest Kayne McGladrey explains, cybercriminals don’t care what your company manufactures—they care about opportunity.
The Titans of Trust
Drata

The Titans of Trust

Independent vCISO, Senior member of the IEEE, author of the GRC Maturity Model and the upcoming book "Cyber Risk is a Myth", Kayne is a go-to voice on treating GRC as a core business competency rather than a one-time project. He has a rare gift for making complex risk feel simple and actionable in the boardroom.
The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure.
VentureBeat

The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure.

Kayne McGladrey, an IEEE Senior Member, described the structural challenge in an exclusive interview with VentureBeat. “The CISO doesn’t have the budget. The CISO doesn’t have the staff. We can observe risks, we can advise on business risks, but we don’t own the business systems affected by those risks,” McGladrey said. When agent governance spans six departmental budgets, no single executive can confirm whether agents get the same access reviews as humans.
Autonomous security agents need complete data. Here’s how to check if yours is ready.
VentureBeat

Autonomous security agents need complete data. Here’s how to check if yours is ready.

Kayne McGladrey, IEEE Senior Member, has confirmed the pattern across multiple published VentureBeat interviews. The structural gap in self-reported coverage is not new. What is new is that autonomous agents will act on it at machine speed without the institutional workarounds human analysts developed over years of experience.
2026 FIFA World Cup Draws Increased Cyber Threat Activity
Security Boulevard

2026 FIFA World Cup Draws Increased Cyber Threat Activity

Kayne McGladrey, a senior member of the IEEE, warned that organizations supporting major events often struggle with visibility across both IT and operational technology environments. He highlighted unmanaged connections between business systems and operational infrastructure as a significant security concern.
2026 FIFA World Cup Faces Surge in Cyber Threats
Dark Reading

2026 FIFA World Cup Faces Surge in Cyber Threats

"Pre-event threat hunting and alert tuning can further help to reduce or remove known misconfigurations early, shrinking the decision space so analysts aren't drowning in noise when the clock starts ticking," he says. "Security leaders know that they can't expect analysts to review every alert, so they're prioritizing only high-confidence behavioral detections tied to big event milestones, like the opening ceremony or a high-profile matchup."
Why Smart People Get Ignored
Wings of Legacy

Why Smart People Get Ignored

"Decisions in organisations don’t move because information exists. They move because the right people understand the consequences of acting, or not acting, in terms that connect to what they’re already responsible for. A risk described in technical language may be completely real and completely ignored, not because the people receiving it don’t care, but because no one has connected it to a problem they’re already losing sleep over. Revenue. Regulatory exposure. A board conversation happening next month. The gap between those two things isn’t a failure of evidence. It’s a failure of translation."
85% of IT teams claim every AI agent is under control. Only 42% actually know who owns them.
VentureBeat

85% of IT teams claim every AI agent is under control. Only 42% actually know who owns them.

Kayne McGladrey, IEEE senior member, told VentureBeat why that governance gap persists. "Anything that seems to have a cybersecurity flavor is generally put into the cybersecurity risk category, which is a complete fiction. They should be focused on business risks, because if it doesn't affect the business, like a financial loss, then nobody's going to pay attention to it, and they will not budget it appropriately, nor will they adequately put in controls to prevent it," McGladrey told VentureBeat previously.
50 Essential Thought Leaders in Risk Management Globally
Clarity

50 Essential Thought Leaders in Risk Management Globally

The fifty people on this list represent the most important voices in risk management across enterprise risk, governance, compliance, financial risk, operational resilience, and emerging technology risk. They range from pioneering academics whose frameworks now underpin global standards to active practitioners building and rebuilding risk functions inside major organisations right now. As of June 2026, risk management has never been more central to organisational survival.
50 CISOs and Cybersecurity Leaders Making an Impact in 2026
SecureFrame

50 CISOs and Cybersecurity Leaders Making an Impact in 2026

To recognize the individuals rising to meet these challenges, we're spotlighting 50 CISOs and cybersecurity leaders making a meaningful impact. These professionals stand out not only for their career achievements, but for their influence on the broader cybersecurity community.

Understand the stories that matter.

Every week, I break down the most important updates in cybersecurity and AI law and policy. Human-written, deeply analyzed.

I don’t spam! Read the privacy policy for more info.