4.7K Followers
992 Following
14.9K Posts
Metacurity.com (https://metacurity.com) is the one-stop destination for leading infosec news and cybersecurity developments. Run by infosec writer and columnist Cynthia Brumfield, Metacurity draws from thousands of sources every day to deliver aggregated summaries of the latest infosec developments. If anyone wants to get in touch with me, on or off the record, you can reach me at cynthia [at] digitalcrazytown.com or on Signal via Cynthia.507. Sign up for our free daily emails at https://www.metacurity.com. Searchable
Metacurityhttps://metacurity.com
Blueskyhttps://bsky.app/profile/msbrumfield.bsky.social
Columnshttps://www.csoonline.com/author/Cynthia-Brumfield/
Bookhttps://www.amazon.com/Cybersecurity-Risk-Management-Mastering-Fundamentals/dp/1119816289
Coursehttps://www.oreilly.com/live-events/cybersecurity-risk-management-with-the-nist-20-framework/0636920081497/
Cynthia's Personal Ramblingshttps://bsky.app/profile/msbrumfield.bsky.social

Happy Saturday! Metacurity is proud to offer our free and premium subscribers a weekly digest of the best long-form (and longish) infosec-related pieces we couldn't properly fit into our daily news crush.

This week's selection covers

--The college kid who discovered the Kimwolf botnet,
--US AI build-out is dependent on Chinese-made electrical equipment,
--AI agent traps are the next big security challenge,
--AI bug discovery tilts the field toward attackers,
--Privatized offensive warfare could fuel a cyber arms race

https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-28-26/

Sign up today for a free subscription to check out our choices.

Best infosec-related long reads for the week of 3/28/26

The college kid who discovered the Kimwolf botnet, US AI build-out is dependent on Chinese-made electrical equipment, AI agent traps are the next big security challenge, AI bug discovery tilts the field toward attackers, Privatized offensive warfare could fuel a cyber arms race

Metacurity

Happy Saturday! Metacurity is proud to offer our free and premium subscribers a weekly digest of the best long-form (and longish) infosec-related pieces we couldn't properly fit into our daily news crush.

This week's selection covers

--The college kid who discovered the Kimwolf botnet,
--US AI build-out is dependent on Chinese-made electrical equipment,
--AI agent traps are the next big security challenge,
--AI bug discovery tilts the field toward attackers,
--Privatized offensive warfare could fuel a cyber arms race

https://www.metacurity.com/best-infosec-related-long-reads-for-the-week-of-3-28-26/

Sign up today for a free subscription to check out our choices.

Best infosec-related long reads for the week of 3/28/26

The college kid who discovered the Kimwolf botnet, US AI build-out is dependent on Chinese-made electrical equipment, AI agent traps are the next big security challenge, AI bug discovery tilts the field toward attackers, Privatized offensive warfare could fuel a cyber arms race

Metacurity
Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk
https://www.wired.com/story/meta-pauses-work-with-mercor-after-data-breach-puts-ai-industry-secrets-at-risk/
Meta Pauses Work With Mercor After Data Breach Puts AI Industry Secrets at Risk

Major AI labs are investigating a security incident that impacted Mercor, a leading data vendor. The incident could have exposed key data about how they train AI models.

WIRED

My work on the trans porter is doing great

#caturday #caturdayeveryday

It's finally Friday, but don't leave for the weekend before checking out today's Metacurity for the most critical infosec developments you should know, including

--Microsoft bets $10 billion on Japan’s AI buildout and cyber defenses,
--EU pins EC attack on TeamPCP,
--Iowa AG sues UnitedHealth over 2024 attack,
--Residential proxies pose problems for IP reputation systems,
--Him & Hers report Feb. data breach,
--TA416 refocuses efforts back to Europe,
--Former engineer admits to hacking employer in $750k extortion bid,
--Threat actors exploit Claude Code source code to deliver Vidar infostealer,
--An Ohio man was trapped in pre-trial imprisonment on hacking charges for nine years,
--ShinyHunters issue final warning to Cisco,
--Progress ShareFile can be chained to achieve file exfiltration,
--PCLOB praises Sec. 702,
--Insecure Amazon server exposed data from money transfer Duc App users,
--Check City Partnership data breach exposed data on 300k+ customers,
--Thousands of French gun owners' data stolen from government site,
--ClickFix-style attacks have just gotten easier,
--Florida congressman says Iran targeted him in a cyberattack,
--Stryker says it's fully operational three weeks after Handala attack,
--TeleGuard messaging app uses dodgy E2EE,
--CyberCorps grads are finding federal cyber jobs tough to find
https://www.metacurity.com/microsoft-bets-10-billion-on-japans-ai-buildout-and-cyber-defenses/

Microsoft bets $10 billion on Japan’s AI buildout and cyber defenses

EU pins EC attack on TeamPCP, Iowa AG sues UnitedHealth over 2024 attack, Residential proxies pose problems for IP reputation systems, Him & Hers report Feb. data breach, TA416 refocuses efforts back to Europe, Former engineer admits to hacking employer in $750k extortion bid, much more

Metacurity

The Army reduced the frequency of mandatory cybersecurity training to once every five years, axing an annual requirement and making individual commanders responsible for preparing their personnel for digital defense

#military #security #cybersecurity #hackers #hacking #hacked

https://defensescoop.com/2026/03/31/army-cybersecurity-training-policy-change/

Commanders now responsible for cybersecurity training after Army cuts online course requirement to once every 5 years

Commanders are now responsible for preparing their soldiers and civilians on cybersecurity, according to a senior service official who said the change was intended to give unit leaders more flexibility.

DefenseScoop

OMG, this man with autism, who was accused of hacking, spent *nine years* in pretrial lockup with no trial.

https://www.cleveland.com/court-justice/2026/04/north-royalton-hacking-suspect-released-after-9-years-in-jail-awaiting-trial.html

Anybody know which company this is?

A former infrastructure engineer at an industrial company headquartered in New Jersey admitted to hacking and extorting the company to try and collect $750,000 in Bitcoin, officials said.

https://www.nj.com/news/2026/04/man-tried-to-ransom-former-employer-out-of-750000-in-bitcoin-after-launching-a-cyber-attack-feds-say.html

Not good. The US federal government is hiring fewer and fewer people in cybersecurity roles in the face of budget slashing

Instead of the 75-plus agencies that typically showed up to the in-person fair, roughly 40 agencies were at February’s virtual event.

https://federalnewsnetwork.com/cybersecurity/2026/04/cybercorps-grads-consider-private-sector-as-fed-hiring-challenges-persist/

CyberCorps grads consider private sector as fed hiring challenges persist

The challenges faced by CyberCorps scholars threaten to upend a program that has shuttled early-career cyber talent to federal agencies for nearly 25 years.

Federal News Network

The breach resulted in “the extraction of commercial data contained in that account, some of which may include personal data of firearm owners as well as data relating to firearm transactions,” the ministry said.

Gun owners' personal data hacked in cyberattack of French government site
https://www.connexionfrance.com/news/gun-owners-personal-data-hacked-in-cyberattack-of-french-government-site/781978

French gun owners' data compromised in major government cyberattack

Discover how a cyberattack on France's firearms registry has exposed personal data of thousands of gun owners, prompting security enhancements and investigations.

connexionfrance