Field notes. From the stack.
Analysis, frameworks, and honest takes on the platforms, architectures, and shifts that matter — from the team that operates the layer most consultants skip.
Your VPN is the front door — and attackers have the key
In June 2026 a critical Check Point VPN flaw was being exploited for weeks before anyone knew, with one case tied to a ransomware crew. Cisco's networking brain was hit the same week. Here is why the security box at your network edge keeps becoming the way in.
Attackers stopped stealing passwords — now they steal your tokens
In June 2026 a breach at a SaaS vendor most people had never heard of spilled Salesforce data from LastPass and a dozen security companies. No password was cracked. No MFA was beaten. The attackers used the OAuth tokens that quietly connect your apps to each other.
How one bug exposed 100+ universities — the ERP breach nobody saw coming
In June 2026 attackers used a single unpatched flaw in Oracle's PeopleSoft to break into the systems that hold students' most sensitive records — at more than a hundred organizations, most of them schools. Here is how the boring back-office system became the richest target in the room.
June 2026 in security — the breaches and bugs that mattered
A plain-language recap of the month's biggest cyber events: a wave of supply-chain breaches through trusted connections, a university-wrecking ERP zero-day, the largest Patch Tuesday on record, and the edge devices that keep getting torn open. What happened, and the one lesson from each.
The $25 million video call — how deepfake scams actually work
A finance worker joined a routine video call with his CFO and his colleagues. Every face on the screen except his own was fake. Here is exactly how it happened — and the one habit that would have stopped it.
Anatomy of a phishing email — the tells, and the one trick that still works
Phishing is the oldest trick on the internet and still the way most breaches begin. Here is how to read an email the way the attacker who wrote it wants you to — and the habit that beats it even when the email is perfect.
How hacked cameras took down the internet — DDoS attacks explained
In 2016, a botnet of hijacked security cameras and home routers knocked Twitter, Netflix, and Reddit offline across two continents. The weapon was built by a few college-age men. Here is how a DDoS attack actually works.
Zero trust architecture — what it means when you actually have to build it
Zero trust is the most-cited and least-finished idea in security. The vendors sell a product; the standard describes a journey. Here is the version that survives contact with a real network.
Ransomware readiness — the plan that holds up in the first hour
Every organization has a ransomware "plan." Most of them are a backup job and a hope. Here is what actually determines whether you recover in days or weeks.
Cloud misconfiguration — the breaches that start with a single setting
Most cloud breaches are not clever. They are a public bucket, an over-permissive role, or a key in a repo. The fix is not a product — it is a posture you can actually maintain.
Okta's blueprint — identity as the control plane, not the whole stack
Okta is not trying to be your endpoint, SIEM, CNAPP, or SASE vendor. It is betting that identity becomes the connective tissue across all of them. Here is the portfolio, the overlaps, and the honest caveats.
MCP security — what every team connecting agents to tools is missing
Model Context Protocol went from announcement to industry standard in a year. The security model is still being written. Here is what to harden before you ship.
AI incident response — when the breach is an agent, not a human
Most IR playbooks were written for human attackers operating manual tools. When the actor is an agent acting on injected instructions, the playbook needs to change.
The EU AI Act is enforceable — what SMB and enterprise actually have to do
Most organizations have not actually read the AI Act. The ones that did read it once in 2024 and assumed enforcement would slip. Enforcement is now active. Here is the practical checklist.
The agentic autonomous defense fabric — building an AI-native SOC
An interconnected operating model for autonomous SOC, self-healing detections, policy-aware defense, and continuous production protection.
Chromebook security in K-12 and higher ed — what telemetry you actually get
What you can monitor, what you do not get, and how AI-driven integration helps schools secure ChromeOS fleets without forcing a full Windows endpoint sensor.
The security analytics mesh — and why your SIEM might be the bottleneck
Vega's federated model points to where SecOps is heading: less data movement, more intelligence at the edge.
CUI scoping for security tools — why your EDR and SIEM are probably in scope
A decision framework for classifying endpoints, SIEM, and cloud services under CMMC 2.0. Scope follows data flows, not product categories.
Certificate authorities, HTTPS, and TLS — how secure websites actually work
An end-to-end blueprint of website identity, certificate issuance, browser verification, and encrypted connections. With real-world use cases.
The AI enterprise security blueprint — from perimeter to agent-aware control
A 13-slide reference architecture for securing AI across endpoint, network, data, and agent paths. The full framework.