8 Followers
15 Following
78 Posts
I manage information security at Experian (formetly Tapad).
Write articles/book reviews on security, privacy, risk management.
Member of @CyberSecCanon
March had 90 publicly disclosed #ransomware attacks, 2nd month this year incidents exceeded 90. Orgs in US accounted for 60% of all reported attacks. Ransomware groups like #DragonForce & #Anubis still making a massive amount of $$. HT @blackfogprivacy. https://api.cyfluencer.com/s/the-state-of-ransomware-march-2026-26729
The State of Ransomware: March 2026

BlackFog's state of ransomware March 2026 report measures publicly disclosed and non-disclosed attacks globally.

BlackFog

๐Ÿ”“ Review Drop: Hacks, Leaks, and Revelations

This week, be sure to read Meghan Jacquot's CyberCanon Review of Micah Lee's ๐™ƒ๐™–๐™˜๐™ ๐™จ, ๐™‡๐™š๐™–๐™ ๐™จ, ๐™–๐™ฃ๐™™ ๐™๐™š๐™ซ๐™š๐™ก๐™–๐™ฉ๐™ž๐™ค๐™ฃ๐™จ ๐Ÿ‘‡

https://cybercanon.org/hacks-leaks-and-revelations-the-art-of-analyzing-hacked-and-leaked-data/

#CybersecurityBooks #Databreach | @micahflee

#CamoLeak is a high-severity #vuln in #GitHub #Copilot Chat (CVE-2025-59145, CVSS 9.6) that gives attackers ability to silently steal source code, API keys & secrets from private repos w/o executing any malicious code. Good overview from @blackfogprivacy. https://api.cyfluencer.com/s/camoleak-how-github-copilot-became-an-exfiltration-channel-26669
CamoLeak: How GitHub Copilot Became An Exfiltration Channel

CamoLeak turned GitHub Copilot into a silent data exfiltration channel via prompt injection and GitHub's own image proxy. CVSS 9.6.

BlackFog
My @OneRSAC information security book of the month review: Speak Security With A Business Accent: How to Communicate Cybersecurity Concepts Clearly, Ease Friction with Stakeholders & Influence Decisionโ€™ by Joshua Mason. Sage advice for #infosec pros. #RSAC https://www.rsaconference.com/library/blog/bens-book-of-the-month-speak-security
Ben's Book of The Month: Speak Security With A Business Accent: How to communicate Cybersecurity Concepts Clearly, Ease Friction with Stakeholders, and Influence Decisions

RSAC Conference
Built by a veteran #cybersecurity team & led by former @google and @Mandiant execs, Mallory AI is a new #AI intelligence platform & now in GA. Itโ€™s built for exposure investigation & intel workflows. Important for #infosec.
https://api.cyfluencer.com/s/mallory-goes-ga-introducing-our-ai-native-threat-intelligence-platform-26608 #MalloryAI #Mallory
Mallory goes GA: Introducing our AI-Native Threat Intelligence Platform

Today, we're launching Mallory, our AI-Native Threat Intelligence Platform built for exposure investigation. Here's why we built it, what it does, and what's ne

๐—”๐—œ ๐˜„๐—ถ๐˜๐—ต๐—ผ๐˜‚๐˜ ๐˜๐—ต๐—ฒ ๐—›๐˜†๐—ฝ๐—ฒ (๐—ผ๐—ฟ ๐—•๐—น๐—ถ๐—ป๐—ฑ ๐—ฆ๐—ฝ๐—ผ๐˜๐˜€) ๐Ÿฆพโš–๏ธ

For this week's review, Yisehak Lemma examines ๐™๐™๐™š ๐˜ผ๐™„ ๐˜พ๐™ค๐™ฃ๐™ช๐™ฃ๐™™๐™ง๐™ช๐™ข, written by the father-son duo of Caleb and Rex Briggs.

๐Ÿ”Ž Full review: https://cybercanon.org/the-ai-conundrum/

#CybersecurityBooks #AISecurity #AIGovernance

๐Ÿ›๏ธ ๐—›๐—ฎ๐—น๐—น ๐—ผ๐—ณ ๐—™๐—ฎ๐—บ๐—ฒ ๐—ฅ๐—ฒ๐—ฐ๐—ผ ๐—œ๐—ป๐—ฐ๐—ผ๐—บ๐—ถ๐—ป๐—ด!

Jack Freund, a man who knows a thing or two about cyber risk (author of the FAIR HoF book), provides a Hall of Fame nomination for ๐™Ž๐™ฉ๐™š๐™ฅ๐™ฅ๐™ž๐™ฃ๐™œ ๐™๐™๐™ง๐™ค๐™ช๐™œ๐™ ๐˜พ๐™ฎ๐™—๐™š๐™ง๐™จ๐™š๐™˜๐™ช๐™ง๐™ž๐™ฉ๐™ฎ ๐™๐™ž๐™จ๐™  ๐™ˆ๐™–๐™ฃ๐™–๐™œ๐™š๐™ข๐™š๐™ฃ๐™ฉ by Jennifer Bayuk.

๐Ÿ“ Read Jack's thorough assessment: https://cybercanon.org/stepping-through-cybersecurity-risk-management-a-systems-thinking-approach/

#CybersecurityBooks #CyberCanonReview #CyberCanonHallofFameCandidate #CyberRisk

The @OneRSAC Conference just wrapped & headline underneath every announcement is the same: Enterprises are deploying AI agents faster than #infosec teams can track them. This @AGATSoftware piece details #AI implementation work that needs to be done. https://api.cyfluencer.com/s/rsac-2026-what-ai-agent-security-looks-like-now-26300 #RSAC
Last week, @realDonaldTrump established a task force to eliminate fraud via executive order. However, like information risk, fraud canโ€™t be eliminated. What the Trump order doesnโ€™t deal with is clueless users vulnerable to financial fraudsters & scammers.
https://brothke.medium.com/scammers-reply-to-president-trumps-cyber-strategy-for-america-bring-it-on-5f1da8f668fb
Scammers reply to President Trumpโ€™s Cyber Strategy for America โ€” bring it on!

Trumpโ€™s Executive Order

Medium

โš› Review Day! โš›

Thomas Laugle provides a "niche" recommendation for Dr. Rogayeh Tabrizi's ๐˜ฝ๐™š๐™๐™–๐™ซ๐™ž๐™ค๐™ง๐™–๐™ก ๐˜ผ๐™„: ๐™๐™ฃ๐™ก๐™š๐™–๐™จ๐™ ๐˜ฟ๐™š๐™˜๐™ž๐™จ๐™ž๐™ค๐™ฃ ๐™ˆ๐™–๐™ ๐™ž๐™ฃ๐™œ ๐™ฌ๐™ž๐™ฉ๐™ ๐˜ฟ๐™–๐™ฉ๐™–

โœ๏ธ Read Thomas' thorough analysis: https://cybercanon.org/behavioral-ai-unleash-decision-making-with-data/

#CybersecurityBooks #AISecurity #GRC #SecurityAwareness